Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Monday, July 6, 2026 · 6:50 PM EDT

Key developments

THE RECORD

Medtronic notifies 3.8 million after cyberattack

The Record's Suzanne Smalley reported that Medtronic notified more than 3.8 million people after an unauthorized party accessed data in certain corporate IT systems, with California's attorney general publishing the notice June 29. OODA Loop reported that ShinyHunters listed Medtronic on a Tor leak site April 17 and claimed theft of more than 9 million personal-information records and terabytes of corporate data; notices beginning this week identified names, contact details, dates of birth, Social Security numbers and health-related information. Federman & Sherwood's Caroline Chesher reported a Vermont filing covering about 8,668 residents.

Why it matters

The combination of healthcare data and government identifiers creates elevated medical identity theft, fraud and breach-litigation risk.

Sources & driving stories

THE RECORD · Suzanne Smalley

The Record coverage

FEDERMAN & SHERWOOD · Caroline Chesher

Federman & Sherwood coverage
REUTERS

Blank Rome faces client-data breach lawsuits

Reuters' Karen Sloan reported that Laura Delapaz filed a proposed class action Monday in Pennsylvania federal court alleging Blank Rome failed to protect data for 57,554 current, former and prospective clients after a May 21 breach. Bloomberg Law reported two proposed class actions by Delapaz and Anthony Santana alleging exposure of Social Security numbers, contact details, dates of birth, taxpayer IDs, government IDs, financial-account and payment-card information, and medical and health insurance information. Blank Rome said a cybercriminal impersonated its IT department and induced an attorney to upload files to an external file-hosting site, while denying network access or operational disruption.

Why it matters

The suits show law firms' sensitive client data remains a growing target for social engineering and privacy class actions.

Sources & driving stories

REUTERS · Karen Sloan

Reuters coverage
SCHNEIER ON SECURITY

France to stop certifying legacy encryption

Schneier on Security's Bruce Schneier reported that France's cybersecurity agency ANSSI will stop certifying security products that lack quantum-resistant encryption starting in 2027. ANSSI chief of staff Samih Souissi said at the France Quantum conference that businesses should buy only quantum-safe products by 2030. Because ANSSI approval is required for cryptographic use by French government agencies and critical infrastructure operators, the move functions as a phase-out of older encryption systems.

Why it matters

The policy turns post-quantum migration from a planning exercise into a procurement and compliance deadline for critical systems.

Sources & driving stories

SCHNEIER ON SECURITY · Bruce Schneier

Schneier on Security coverage

Worth noting

WORTH NOTING

Reddit expands EU age checks

Reclaim The Net's Ken Macon reported Reddit began a June 24 rollout in the EU and Norway requiring users flagged as possibly under 18 to verify age with government ID or a live face scan via Persona for mature communities, raising biometric and third-party data-collection concerns.

WORTH NOTING

Australia breach reports hit record

Publicnow reported that Australia's OAIC received 1,205 Notifiable Data Breach notifications in 2025, up 8% from 2024, with cyber hacking accounting for 716 reports and health service providers leading sectors with 225.

WORTH NOTING

Geofence warrant limits advance

Docket Alarm reported that the Supreme Court's June 29 action in the Okello Chatrie geofence dispute extended Fourth Amendment privacy protections to cellphone location data gathered through geofence methods and remanded for further proceedings.

Still unclear

OPEN QUESTION

Can critical operators meet ANSSI's 2027 deadline?

French government and critical-infrastructure users may need rapid vendor upgrades or replacement plans if non-quantum-safe products lose certification next year.

OPEN QUESTION

Will breach cases turn on concrete harm?

The Medtronic and Blank Rome matters involve sensitive identifiers and health or client data, but courts continue to scrutinize whether plaintiffs can show actual injury from exposure.