Key developments
Dutch regulator links breach surge to AI phishing
The Dutch Data Protection Authority’s Datalekkenrapportage 2025 reported 39,407 data breach notifications, up from 37,839 in 2024, according to TechTimes' Chase Fiorini. Cyberattack-driven breaches rose 58% to 2,428, while account-takeover incidents increased from 607 to 1,742; the authority tied the growth to AI-assisted phishing and commercial phishing kits. One ransomware attack on AddComm, a Dutch customer communications provider for banks and utilities, generated 5,407 downstream breach notifications after attackers encrypted systems and exfiltrated customer data.
Why it matters
The report shows AI-assisted credential theft moving from theoretical risk to measurable breach volume, with regulators pushing phishing-resistant authentication and board-level security accountability.
Sources & driving stories
TECHTIMES · Chase Fiorini
TechTimes coverageJapan advances AI training exception for sensitive data
Japan’s Cabinet approved amendments to the Act on the Protection of Personal Information that would allow companies to use sensitive personal data for AI model training without individual consent, CryptoBriefing reported. The exception applies when identifying information is removed to a government-defined pseudonymization standard, and it covers categories including medical histories and racial information. The bill has cleared the Lower House, with implementation expected in late 2026 or early 2027 after final Diet approval and Cabinet orders.
Why it matters
The proposal would materially shift Japan’s consent baseline for AI development while testing whether pseudonymization can adequately protect high-risk personal data.
Sources & driving stories
CRYPTOBRIEFING
CryptoBriefing coverageFlock license-plate systems face new scrutiny
Jalopnik reported that The Drive executive Joel Feder and his wife were detained in Plymouth, Minnesota after Flock cameras allegedly flagged a Range Rover press car as using stolen plates. A VIN check was clean, but a California data-entry error omitted digits from a New Jersey manufacturer plate format, causing automated alerts that police said had tracked the vehicle for days. Separately, the Detroit Free Press reported Westland, Michigan will not renew its Flock contract when it expires at the end of July after council division and resident concerns over surveillance oversight and retention.
Why it matters
The incidents connect privacy objections to concrete operational risk: inaccurate structured data in automated surveillance systems can escalate into armed police encounters and contract cancellations.
Sources & driving stories
JALOPNIK
Jalopnik coverageDETROIT FREE PRESS
Detroit Free Press coverageWorth noting
WORTH NOTING
Meta hardens glasses recording indicator
Engadget's Karissa Bell reported Meta is mandating a software update that disables the camera on its smart glasses if the recording LED is physically tampered with, while users describe reducing public use after privacy backlash.
WORTH NOTING
Healthcare vendor breach exposure grows
DataBreachToday reported HHS data showing business associates were involved in 145 of 351 major 2026 health breaches, affecting 9.94 million people, as experts warn AI-enabled reconnaissance and exploit generation could intensify vendor attacks.
WORTH NOTING
Pakistani police biometrics targeted
The Record's Alexander Martin reported SentinelOne research finding separate China- and India-linked espionage campaigns against Balochistan Police systems holding criminal records, biometrics, personnel files, identity-linked registrations and citizen complaints.
Still unclear
OPEN QUESTION
Will pseudonymization be enough for AI training exceptions?
Japan’s proposed APPI changes rely on government-defined de-identification for sensitive data, but critics point to re-identification risks when health or biometric-adjacent data is linked with external datasets.
OPEN QUESTION
Who audits ALPR data quality before police action?
The Flock-related detention shows that a formatting or entry error can propagate through automated alerts and create physical risk before anyone validates the underlying record.
