Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Monday, July 13, 2026 · 6:50 PM EDT

Key developments

SECURITYWEEK

Centers Laboratory breach affects 542,377 people

SecurityWeek's Eduard Kovacs reported that Centers Laboratory, a New Jersey testing and laboratory-services provider, notified the U.S. government that an August 2025 intrusion affected 542,377 individuals. Attackers accessed systems from August 9 to August 14 and exfiltrated personal and protected health information, including names, dates of birth, Social Security numbers, government IDs, passport numbers, health insurance information, and medical data. The HHS breach tracker supplied the affected-population figure, while WorldLeaks listed Centers Lab in October 2025 and claimed theft of more than 1.6 million files totaling 720 GB.

Why it matters

The breach combines high-risk medical and identity data with a long disclosure timeline, raising exposure to identity theft, medical fraud, and targeted phishing.

Sources & driving stories

SECURITYWEEK · Eduard Kovacs

SecurityWeek coverage
BLEEPINGCOMPUTER

Lidl discloses multi-country online shop breach

BleepingComputer's Sergiu Gatlan and TechRadar reported that Lidl notified online-shop customers in Germany, Belgium, and the Netherlands after attackers accessed a separately stored customer-data file at a third-party IT service provider. Exposed data included names, phone numbers, email addresses, dates of birth, and customer numbers; Lidl said the online shop's main system and customer accounts were not affected. The number of affected customers remains undisclosed, and reporting diverged on whether Lidl has fully ruled out passwords, addresses, and payment data.

Why it matters

Even without confirmed financial-data exposure, the stolen profile data can support convincing phishing and identity-fraud attempts across multiple EU markets.

Sources & driving stories

BLEEPINGCOMPUTER · Sergiu Gatlan

BleepingComputer coverage

CYBERNEWS · Anton Mous

Cybernews coverage
BLEEPINGCOMPUTER

CrashStealer macOS malware steals Keychain data

BleepingComputer's Bill Toulas reported that researchers began tracking a new macOS infostealer, CrashStealer, in May and observed it in attacks in early July. The malware impersonates Apple's crash-reporting tool as CrashReporter.app, uses a signed and Apple-notarized installer called Werkbit Setup to bypass Gatekeeper warnings, and displays a fake macOS password prompt to unlock the user's Keychain. Jamf researchers found it targets password managers, Keychain data, and more than 80 cryptocurrency wallet extensions, then encrypts stolen data with AES-256-GCM before exfiltration.

Why it matters

The campaign shows attackers using notarized macOS installers and system-tool impersonation to extract deeply sensitive credentials and wallet data from privacy-conscious users.

Sources & driving stories

BLEEPINGCOMPUTER · Bill Toulas

BleepingComputer coverage

Worth noting

WORTH NOTING

Serviceaide settles health breach litigation

Human Rights Research Center reported that Serviceaide agreed to pay $1.8 million to resolve litigation over a 2024 Catholic Health breach affecting more than 400,000 patients, with claims payments up to $5,000 for documented losses.

WORTH NOTING

Chat Control renewal passes

Hungarian Conservative reported that European Parliament rejection of Chat Control 1.0 failed 314-276 because 361 votes were required, leaving voluntary scanning of private messages in force until April 2028.

WORTH NOTING

First American faces DataTree privacy suit

National Mortgage News' Andrew Martinez reported that four residents filed a California federal class action alleging First American's DataTree platform used homeowner identity and contact attributes in a commercial sales funnel without consent.

Still unclear

OPEN QUESTION

How large is Lidl's exposure?

Lidl has not disclosed the number of affected customers, and reports conflict on whether passwords, addresses, bank details, or payment information are definitively excluded.

OPEN QUESTION

Why are health-breach notifications so delayed?

Centers Laboratory's public affected-person count arrived nearly a year after the intrusion window, limiting victims' ability to quickly protect medical and identity data.