Weekly Privacy Roundup: Historic $966M Uber Fine & The Growing Threat of Fourth-Party Breaches
A $966M regulatory fine for Uber and a wave of third-party healthcare and corporate breaches dominate this week's data privacy roundup.
Welcome to this week's PrivaScan privacy roundup. This week, regulatory enforcement hit historic heights with a massive fine in Europe targeting automated decision-making, while the healthcare and financial sectors continue to grapple with severe data exposures. From third-party vendor vulnerabilities to sophisticated social engineering, these incidents underscore the critical need for businesses to maintain strict control over their data inventories and digital supply chains.
Regulatory Enforcement & Settlements
- Dutch Regulator Fines Uber $966 Million: In a major enforcement action, the Dutch data protection authority has fined Uber $966 million. The penalty stems from the company's use of automated systems to suspend drivers, highlighting the intense regulatory scrutiny surrounding automated decision-making and algorithmic profiling under European privacy standards.
- DAP Health Settles Class Action for $1.3 Million: Healthcare provider DAP Health has agreed to a $1,300,000 settlement to resolve legal claims arising from a past data breach, demonstrating the high financial stakes of post-breach litigation.
Healthcare Sector Under Continuous Pressure
The medical and healthcare industries remain prime targets for cyber incidents, with several notable breaches reported this week:
- Connecticut Medicaid Portal Exposures: Connecticut's Department of Social Services (DSS) reported that a portal breach exposed the personal data of 41,000 Medicaid (HUSKY) members. This marks the second portal-related security incident for the state agency this year, prompting offers of free identity monitoring for affected individuals.
- CareCloud and Surgeons Choice Breaches: CareCloud experienced a breach exposing highly sensitive medical records, Social Security Numbers (SSNs), and banking details. Similarly, Surgeons Choice Medical Center faced a breach that compromised patient SSNs, sparking potential class-action interest.
- International Incidents & Product Vendors: Canada’s Hospital for Sick Children fell victim to a cyberattack targeting employee data, marking another disruptive incident for the institution. Meanwhile, an unnamed health product company reported a data breach impacting approximately 48,000 residents in Vermont.
Corporate and Third-Party Risks
Modern organizations rely heavily on external vendors, but this week's news highlights how easily third- and fourth-party relationships can introduce severe security gaps:
- U.S. Bank Points to Fourth-Party Incident: U.S. Bank clarified that recent data breach claims targeting the institution actually originated from a security incident at a fourth-party vendor, illustrating how deep and complex digital supply chains can be.
- Apollo Global Management Hit by Social Engineering: Asset management giant Apollo Global Management suffered a data breach impacting SSNs following a social engineering attack, highlighting that human-centric vulnerabilities remain a primary entry point for attackers.
- Troutman Pepper Locke Client Leak: The recently merged law firm Troutman Pepper Locke has remained silent as threat actors reportedly leaked sensitive client data, including tens of thousands of Social Security Numbers.
- Retail and Security Firm Targets: The largest franchisee of Applebee's confirmed that hackers stole sensitive corporate or customer data. Additionally, cybercriminal group ShinyHunters claimed to have breached cybersecurity firm ReliaQuest, though the claims remain unconfirmed by the company.
Government, Infrastructure & Geopolitical Threats
- CISA Staffing Cuts Under Scrutiny: U.S. lawmakers are calling for an official investigation into how proposed staffing cuts at the Cybersecurity and Infrastructure Security Agency (CISA) might impact national cyber defense capabilities.
- Federal Hacking Tools Review: A U.S. Senator has formally requested the government watchdog to review how federal agencies deploy and manage hacking tools, raising questions about oversight and privacy.
- State-Sponsored and Geopolitical Attacks: A Russian network monitoring firm confirmed it was hit by a cyberattack claimed by pro-Ukraine hackers. Concurrently, researchers identified a Chinese espionage campaign dubbed "SilkParasite" targeting Central Asia using AI-assisted malware.
What This Means for You
This week’s headlines demonstrate that data liabilities rarely stay confined to your own servers. Whether it is a fourth-party vendor vulnerability at a major financial institution or automated processing liabilities like those faced by Uber, businesses must have complete visibility over their data flows.
To mitigate these risks, organizations should maintain a comprehensive GDPR Article 30 data inventory to map exactly where personal data travels. Furthermore, because third-party scripts on websites can quietly leak user data to external networks, utilizing tools like PrivaScan's pre-consent tracker scanning and cross-border detection can help ensure your digital properties remain compliant and secure before data is ever transmitted.
Disclaimer: This roundup is provided for informational purposes only and does not constitute legal advice. For specific compliance guidance, please consult with a qualified legal professional.
Sources
- HUSKY Members In CT Offered Free Identity Monitoring After DSS Data Breach - CT News Junkie — CT News Junkie
- ShinyHunters claims hack of ReliaQuest; no confirmation by ReliaQuest (1) — DataBreaches.net
- Connecticut says data from 41,000 Medicaid members exposed in portal breach; the second portal incident this year — DataBreaches.net
- Apollo Global Management Hit by Social Engineering Attack and Data Breach - PYMNTS.com — PYMNTS.com
- Lawmakers call for investigation into impact of CISA staffing cuts — The Record
- Surgeons Choice Medical Center Data Breach Exposes SSNs - ClassAction.org — ClassAction.org
- EXCLUSIVE: Dutch regulator fines Uber $966 million for automating driver suspensions - Reuters — Reuters
- Troutman Pepper Locke Silent as Threat Actors Leak Client Data, Tens of Thousands of SSNs — DataBreaches.net
- U.S. Bank says breach claims related to fourth-party incident — The Record
- DAP Health Settles Data Breach Lawsuit for $1,300,000 - The HIPAA Journal — The HIPAA Journal