Key developments
Texas vendor breach exposes 3.1 million IDs
Security Boulevard's John Kevin Hao reported that the Texas Parks and Wildlife Department disclosed unauthorized access at an external license-system vendor used for hunting and fishing licenses and permits. Texas Cyber Command's investigation assessed potential exposure for 3,087,721 customers, including driver's license information, passport numbers, email addresses, phone numbers, and residential addresses; TPWD said Social Security numbers, dates of birth, and credit card data were not affected. Rescana reported the timeline included state cybersecurity notification on May 13, a June 12 data security incident notice, and June 18 public disclosure.
Why it matters
The breach combines large scale, government-held identity data, and third-party vendor exposure, creating elevated fraud and phishing risk for affected residents.
Sources & driving stories
SECURITY BOULEVARD · John Kevin Hao
Security Boulevard coverageRESCANA
Rescana coverageNintendo employee data stolen through TinyPulse
Rescana reported that Nintendo of America confirmed internal employee survey data was stolen after a cyberattack on TinyPulse, a SaaS employee-engagement platform owned by WebMD Health Services. The report said Nintendo found no compromise of its own systems and no customer or financial data access, but threat actor Shadowbyt3$ claimed about 1GB of data including employee names, emails, survey and analytics data, bank statements, W-9 forms, employee IDs, progress plans, and reports spanning 2016 to 2026. The actor allegedly demanded $2 million and threatened to leak the data.
Why it matters
The incident underscores privacy risk from HR and employee-engagement SaaS vendors, where sensitive workforce data can be exposed even when a company’s internal systems remain uncompromised.
Sources & driving stories
RESCANA
Rescana coverageMorocco warns Fortinet leak exposed VPN credentials
Morocco World News's Asmae Daoudi reported that Morocco's General Directorate for Information Systems Security issued a June 18 alert about FortiBleed, a large-scale leak affecting Fortinet appliances. DGSSI said attackers targeted internet-facing FortiGate firewalls and SSL VPN gateways, allegedly exposing administrator credentials and VPN access information valid for nearly 75,000 devices worldwide, including several Moroccan organizations. The agency recommended immediate password resets, multi-factor authentication, restricted administrative access, log reviews, and FortiOS updates.
Why it matters
Credential exposure at perimeter security devices can enable follow-on intrusions and downstream data breaches across affected organizations.
Sources & driving stories
MOROCCO WORLD NEWS · Asmae Daoudi
Morocco World News coverageWorth noting
WORTH NOTING
California ALPR class-action exposure widens
Mondaq reported that after Bartholomew v. Parking Concepts and the California Supreme Court's May 13 denial of review, plaintiffs have filed class actions against retailers, malls, hotels, parking operators, and ALPR vendors over alleged failures to post required license-plate-reader privacy policies.
WORTH NOTING
Idaho age-estimation law nears
The Lewiston Tribune reported in an opinion article that Idaho's July 1 social media law will require platforms to estimate the age of all users and obtain parental consent for users who appear 16 or younger, raising broader profiling concerns.
WORTH NOTING
Nigeria regulator presses election commission
Vanguard reported that Nigeria's Data Protection Commission has twice requested records of processing activities from the Independent National Electoral Commission amid allegations of a breach affecting electoral-database integrity.
Still unclear
OPEN QUESTION
Which vendor controls failed?
The Texas breach has no named vendor or disclosed initial-access method, while the Nintendo incident points to SaaS exposure, leaving limited visibility into how organizations should benchmark third-party privacy risk.
OPEN QUESTION
Will age checks expand user profiling?
Idaho's law targets minors but requires age estimation across all users, creating tension between child-safety regulation and minimization of behavioral tracking.
