Key developments
Medtronic notifies 3.8 million after cyberattack
The Record's Suzanne Smalley reported that Medtronic notified more than 3.8 million people after an unauthorized party accessed data in certain corporate IT systems, with California's attorney general publishing the notice June 29. OODA Loop reported that ShinyHunters listed Medtronic on a Tor leak site April 17 and claimed theft of more than 9 million personal-information records and terabytes of corporate data; notices beginning this week identified names, contact details, dates of birth, Social Security numbers and health-related information. Federman & Sherwood's Caroline Chesher reported a Vermont filing covering about 8,668 residents.
Why it matters
The combination of healthcare data and government identifiers creates elevated medical identity theft, fraud and breach-litigation risk.
Sources & driving stories
THE RECORD · Suzanne Smalley
The Record coverageOODA LOOP
OODA Loop coverageFEDERMAN & SHERWOOD · Caroline Chesher
Federman & Sherwood coverageBlank Rome faces client-data breach lawsuits
Reuters' Karen Sloan reported that Laura Delapaz filed a proposed class action Monday in Pennsylvania federal court alleging Blank Rome failed to protect data for 57,554 current, former and prospective clients after a May 21 breach. Bloomberg Law reported two proposed class actions by Delapaz and Anthony Santana alleging exposure of Social Security numbers, contact details, dates of birth, taxpayer IDs, government IDs, financial-account and payment-card information, and medical and health insurance information. Blank Rome said a cybercriminal impersonated its IT department and induced an attorney to upload files to an external file-hosting site, while denying network access or operational disruption.
Why it matters
The suits show law firms' sensitive client data remains a growing target for social engineering and privacy class actions.
Sources & driving stories
REUTERS · Karen Sloan
Reuters coverageBLOOMBERG LAW
Bloomberg Law coverageFrance to stop certifying legacy encryption
Schneier on Security's Bruce Schneier reported that France's cybersecurity agency ANSSI will stop certifying security products that lack quantum-resistant encryption starting in 2027. ANSSI chief of staff Samih Souissi said at the France Quantum conference that businesses should buy only quantum-safe products by 2030. Because ANSSI approval is required for cryptographic use by French government agencies and critical infrastructure operators, the move functions as a phase-out of older encryption systems.
Why it matters
The policy turns post-quantum migration from a planning exercise into a procurement and compliance deadline for critical systems.
Sources & driving stories
SCHNEIER ON SECURITY · Bruce Schneier
Schneier on Security coverageWorth noting
WORTH NOTING
Reddit expands EU age checks
Reclaim The Net's Ken Macon reported Reddit began a June 24 rollout in the EU and Norway requiring users flagged as possibly under 18 to verify age with government ID or a live face scan via Persona for mature communities, raising biometric and third-party data-collection concerns.
WORTH NOTING
Australia breach reports hit record
Publicnow reported that Australia's OAIC received 1,205 Notifiable Data Breach notifications in 2025, up 8% from 2024, with cyber hacking accounting for 716 reports and health service providers leading sectors with 225.
WORTH NOTING
Geofence warrant limits advance
Docket Alarm reported that the Supreme Court's June 29 action in the Okello Chatrie geofence dispute extended Fourth Amendment privacy protections to cellphone location data gathered through geofence methods and remanded for further proceedings.
Still unclear
OPEN QUESTION
Can critical operators meet ANSSI's 2027 deadline?
French government and critical-infrastructure users may need rapid vendor upgrades or replacement plans if non-quantum-safe products lose certification next year.
OPEN QUESTION
Will breach cases turn on concrete harm?
The Medtronic and Blank Rome matters involve sensitive identifiers and health or client data, but courts continue to scrutinize whether plaintiffs can show actual injury from exposure.
