Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Sunday, July 5, 2026 · 6:48 PM EDT

Key developments

SECURITY AFFAIRS

Medtronic notifies 3.8 million after breach

Medtronic is notifying 3,834,294 individuals after unauthorized access to corporate IT systems between April 13 and April 19, 2026, according to Security Affairs’ Pierluigi Paganini. The company said potentially affected data includes names, contact information, dates of birth, Social Security numbers and health-related information, while ShinyHunters claimed theft of more than 9 million records. Medtronic says it has found no impact to products, patient safety, manufacturing, distribution, financial reporting or care delivery, and no evidence the data was posted publicly.

Why it matters

The incident is a large healthcare privacy breach involving PHI and SSNs, with unresolved questions about the gap between confirmed notifications and the threat actor’s claimed data volume.

Sources & driving stories

SECURITY AFFAIRS · Pierluigi Paganini

Security Affairs coverage
THE HACKER NEWS

Case study details alleged county extortion payment

The Hacker News reports that a Ransom-ISAC case study by Rakesh Krishnan traced an approximately $1 million payment to an extortion group calling itself Kairos. The unnamed victim is not confirmed, but negotiation artifacts point to Union County, Ohio, which disclosed a May 2025 incident affecting 45,487 residents and staff and involving data such as Social Security numbers, financial details, fingerprints and passport numbers. Krishnan found no evidence of encryption tooling, describing the case as data-theft extortion, with about 9.44 bitcoin routed toward wallets tied to Bybit, OKX and BELQI.

Why it matters

The reporting highlights the privacy risk of “ransomware” incidents where stolen data, not locked systems, becomes the primary leverage and deletion promises remain unverifiable.

Sources & driving stories

DOCKET ALARM

Supreme Court preserves FCC penalty process

Docket Alarm reports that the Supreme Court decided FCC v. AT&T, Inc. on June 4, 2026, holding that the FCC’s forfeiture process does not violate the Seventh Amendment. The underlying enforcement actions sought roughly $57 million from AT&T and $47 million from Verizon over alleged failures to safeguard customer location data. The ruling leaves intact the FCC’s administrative civil-penalty pathway for privacy and sensitive-data enforcement.

Why it matters

The decision preserves a major enforcement mechanism for telecom privacy cases involving location data, vendor oversight and sensitive-data governance.

Sources & driving stories

Worth noting

WORTH NOTING

ACCC breach settlement claims due

Scamicide reports that American Consumer Credit Counseling’s breach settlement allows eligible class members to seek up to $3,500 for documented losses, up to $80 for lost time or a $45 alternative cash payment, with claims due Sept. 16, 2026.

WORTH NOTING

Coupang scrutiny intersects Trump trades

Korea Herald and Dynamite News report that Donald Trump’s financial disclosures list 18 Coupang stock transactions while US officials criticized South Korean investigations into a Coupang data breach affecting about 33 million users.

WORTH NOTING

LACUNA tests LLM unlearning precision

Let’s Data Science reports that a July 2 arXiv paper introduces LACUNA, a testbed that injects synthetic PII into predefined OLMo model weights to evaluate whether unlearning removes targeted knowledge internally, not just from outputs.

Still unclear

OPEN QUESTION

Will Medtronic reconcile victim and theft counts?

Medtronic is notifying 3.8 million people, while ShinyHunters claimed more than 9 million records, leaving uncertainty about scope, duplication and whether additional data categories are involved.

OPEN QUESTION

How should deletion claims be verified?

The Kairos case underscores that payment-for-deletion in data-theft extortion offers victims little technical assurance that copied sensitive files were actually destroyed.