Security and privacy leaders are reporting increased pressure to improve attack surface visibility and strengthen privacy programs as digital transformation expands exposure across cloud, SaaS, APIs, endpoints, and third parties. A LinkedIn poll cited by SC Media ranked attack surface visibility as the top infrastructure security priority (40%), ahead of cloud/hybrid security and identity and access security (25% each), while a separate SC Media commentary tied modern privacy risk to the same drivers—rapidly growing environments and increasingly industrialized cybercrime—arguing that breach risk remains a direct threat to business resilience and consumer trust.
Multiple reports highlighted how breach activity and downstream abuse continue to shape priorities. DataBreaches.net relayed BBC reporting that criminals are buying stolen customer databases (including alleged data from Kering) to identify high-value targets and run tailored crypto scams, with one hacker claiming to have used cross-referenced breach data to steal from Coinbase users. In healthcare, a Fortified Health Security report cited by DataBreaches.net found breach frequency more than doubled in 2025 while exposed patient records decreased, attributing the shift to ransomware, identity compromise, and third-party weaknesses—a pattern emphasizing operational resilience over sheer record counts. Separately, figures reported for the UK’s North West Ambulance Service NHS Trust showed nearly 400 breach incidents over three years, with many categorized as confidentiality failures and misdisclosures, and the trust suggesting improved reporting/training may be contributing to higher counts. An ISACA study summarized by Help Net Security added that privacy teams face budget and staffing strain, and that AI use for privacy tasks (e.g., data discovery and monitoring) tends to correlate with program maturity and board support rather than urgency, while consistent privacy-by-design adoption remains uneven.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
Results from a LinkedIn poll reported by The Cyber Express showed attack surface visibility was the leading infrastructure security concern among CISOs, receiving 40% of votes. The findings reflected growing focus on inventorying and securing cloud, SaaS, API, endpoint, and third-party assets.
A BBC report described how criminals used breached personal data, including alleged Kering customer spreadsheets, to identify wealthy cryptocurrency holders and scam them. A hacker interviewed by the BBC claimed the campaign generated at least $1.5 million in stolen cryptocurrency.
An ISACA global study published in January 2026 reported that privacy teams are under pressure from breach risk, emerging technology, compliance demands, and staffing constraints. It also found uneven privacy-by-design adoption, limited AI use in privacy operations, and training weaknesses that contribute to privacy failures.
Fortified Health Security's 2025 report found that healthcare data breaches more than doubled over the year, while the number of exposed patient records fell significantly. The report attributed the pattern largely to ransomware, identity compromise, and third-party weaknesses.
In the most recent year covered by the figures, NWAS recorded 172 data breach incidents. The trust said part of the increase may reflect improved staff training and reporting practices.
The same multi-year figures show NWAS reported 143 data breach incidents in the year after 2022/23, indicating a marked year-on-year increase in reported privacy and information-handling incidents.
Figures later cited by Data Breach Claims UK show the North West Ambulance Service NHS Trust recorded 75 data breach incidents in the 2022/23 year, establishing the baseline for a subsequent rise in reported incidents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcescworld.com
Open sourcedatabreaches.net
Open sourcedatabreaches.net
Open sourcedatabreaches.net
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.