RackTop Systems

Topic · 9 articles

Breach Disclosure

Notification timelines, scoping windows, and what regulators now ask.

Spans Sector Spotlight, Threat Brief and Executive Briefing.

Sector Spotlight•October 1, 2026

Government data breaches in 2026: a running list, and the patterns underneath it

A running list of notable 2026 government data breaches, from county networks to the FBI and the Pentagon, updated monthly, with the patterns that repeat across them.

6 min read

Threat Brief•September 28, 2026

The Pentagon personnel breach: nine months of file access, and a scope still written as “may”

Unauthorized users accessed unencrypted military personnel files on a Defense Manpower Data Center file-sharing system for nine months before the flaw was found. The notice to victims does not say how many people were affected.

7 min read

Threat Brief•September 8, 2026

The reporting tool was a copy of everyone

The system breached at Mathspace was not the product. It was the internal reporting tool sitting behind it, holding a standing read view of more than a million students, staff, and parents.

6 min read

Threat Brief•September 2, 2026

Berlin will not pay. It still has to know what left.

Berlin refused a 30-bitcoin ransom after a data theft from one Senate department. The most detailed inventory of what left is still the attacker’s leak-site listing.

6 min read

Threat Brief•August 18, 2026

Six terabytes, allegedly: the hospital breach nobody can yet bound

A ransomware crew says it took six terabytes of the most sensitive records a health system holds. The health system says the claim is unverified. Weeks after the attack, both statements can still be true, and that gap is the leverage.

5 min read

Threat Brief•August 12, 2026

ExfilSquad skips the encryption and publishes stolen files as torrents

A new extortion crew surfaced in late July claiming fifteen victims in a single day, confirmed breaches at two UK institutions, and no ransomware at all. When deadlines passed, ExfilSquad began seeding stolen data as torrents, making the leak effectively permanent.

4 min read

Threat Brief•August 4, 2026

Six days inside, three months to say what left: the CareCloud breach

Attackers had access to a CareCloud electronic health record environment for six days in March. It took until late June to determine what they took, and until the end of July for at least 345,000 people to be told. The gap between intrusion and answer is an audit problem.

6 min read

Sector Spotlight•July 12, 2026

Why healthcare keeps paying the highest breach costs

Healthcare has carried the highest average breach cost of any industry for more than a decade. The five reasons why trace back to the data itself: sensitive, regulated, sprawling, and largely unstructured.

6 min read

Executive Briefing•June 30, 2026

Recovery time is now a disclosure question

Regulators, insurers, and customers increasingly ask the same two questions after an incident: how fast were you back, and what exactly was taken? Both answers are determined at the data layer, before the incident ever happens.

2 min read

See data-layer defense in your environment

In a 30-minute demo we’ll show Active Defense stopping an attack inline, immutable recovery, and surgical rollback — mapped to your data and your threats.

Breach Disclosure, Scoping & Notification | RackTop