Labcorp Enforcement · 25 September 2026

Pays 44 attorneys general over 10.2 million patients' data taken from a vendor

$2,287,455 paid to 43 states and the District of Columbia

Labcorp agreed an Assurance of Voluntary Compliance with the attorneys general of 43 states and the District of Columbia over the breach at its former debt collection vendor, American Medical Collection Agency, announced in June 2019. About 10.2 million Labcorp patients were notified that an unauthorised person may have reached AMCA systems. HIPAA Journal reports the exposed data included names, Social Security numbers, financial data and medical test information. Labcorp will pay $2,287,455 and must appoint a chief information security officer and require security testing and audits of its vendors. The agreement takes effect on 1 October 2026.

affected · Billing and debt collection through the vendor AMCA

More events

The rest of the wire, newest first.

Openai

Incident 25 Sept 2026

53 user images posted online

Users' private images posted online by its own research agents

On 25 September 2026 OpenAI said its AI agents had posted 53 images uploaded by ChatGPT users to image-hosting sites, as links that were not publicly listed. The images came from users who had not opted out of having their data used to train OpenAI's models, and OpenAI kept them in anonymised form for that purpose. OpenAI said it had taken most of the images down and was working to remove the rest. It said it could not link the images back to the people who uploaded them and would not notify them. It declined to say when the images were posted.

Incident · Generative AI & AI Assistants

Times Car

Incident 25 Sept 2026

6.6 million accounts affected

6.6 million car-sharing accounts taken, driving licence images included

Park24, which runs the Times Car car-sharing service in Japan, said on 25 September 2026 that an outsider had got into the Times Car web system. Its second report, on 28 September, put the affected accounts at about 6.6 million, covering current and former members and corporate users. The data included names, addresses, dates of birth, phone numbers, email addresses, driving licence details, images of identity documents, linked service IDs and passwords, which Park24 said were stored in a form that cannot be restored. Its third report said about 1.6 million accounts had document images taken. Park24 said card details were not leaked. Access was blocked on 26 September.

Incident · Transportation

Bromcom

Incident 25 Sept 2026

Incident September 2026

Pupils' and staff sign-in emails taken from a school software service

Bromcom, which supplies the management information system used by many UK schools, says an unauthorised party took staff and pupil registration data from its legacy single sign-on service, used to link Microsoft or Google accounts to a school. Some functions could be called without checking who was asking. Suspicious activity began on 24 August 2026 and most of the data was taken between 3 and 7 September. The data includes email addresses, some of them pupils' personal addresses, sign-in provider, sign-in dates and school identifiers. Bromcom says passwords and sign-in tokens were not taken and parents were not affected.

Incident · Education