Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
21 articles found · #ransomware
WEBA (BE) hit by Qilin: ransomware, customer data accessed, 48 h recovery
On August 10, 2026, Belgian retailer WEBA was hit by a ransomware attack. Customer data was accessed; operations resumed on August 12. Qilin claimed responsibility on August 16; WEBA says no ransom was paid.
FortiBleed targets 430k FortiGate — continuous VM to meet NIS 2
FortiBleed (Lynx/INC) mass-stole Fortinet credentials. Here’s how continuous Vulnerability Management operationalizes NIS 2 Article 21 and reduces exposure before the next campaign.
CSSF 25/892: quantifying ICT incident costs — adopt 3‑2‑1‑1‑0 immutable backups
Since 28/05/2025, the CSSF requires annual aggregated estimation of costs/losses from major ICT incidents (JC 2024 34). Immutable, isolated 3‑2‑1‑1‑0 backups cut financial impact and provide the required evidence.
LastPass (ICO, 20/11/2025): £1.23M for an exfiltrated backup
The UK ICO fined LastPass UK Ltd £1,228,283 after a backup repository was exfiltrated. Why to move to immutable, isolated backups (DORA Art. 12) and how to evidence compliance.
ANSSI ReCyF: immutable, isolated backups to meet DORA Art. 12
ANSSI’s ReCyF (17/03/2026) calls for immutable, isolated backups to counter ransomware. Here’s how to deploy them and evidence compliance with DORA Art. 12 and NIS 2.
Coca‑Cola/Fairlife: ransomware, production halt and data theft
Coca‑Cola confirms data theft following a ransomware attack against Fairlife. U.S. production was suspended mid‑July; the Anubis group claims up to 1 TB of data.
Lithuania: €450,000 GDPR fine for lack of MFA at InMedica
Lithuania’s DPA fined InMedica €450,000 over two incidents (2024 breach, 2025 ransomware), citing lack of MFA and poor access controls under GDPR Articles 5(1)(f), 24(1) and 32(1)(b).
CSSF 26/906: governance and DORA-grade immutable backups by June 30
CSSF 26/906 requires PSPs/EMIs to reassess governance and risk management by 30 June 2026. Immutable, isolated backups are the DORA-proof of ransomware resilience.
Clinical Diagnostics (NL): gynecological records leak — GDPR-aligned DLP
After the massive leak at Clinical Diagnostics, a modern DLP aligned with GDPR (Art. 32 and 44–49) reduces exfiltration and provides the evidence authorities expect.
ENISA 2026: Separate, tested backups aligned with DORA
ENISA updates its SME guide: backups separated from production, encrypted and end-to-end tested. How immutable, isolated vaults meet DORA Art. 12 and thwart ransomware.
Foxconn hit by Nitrogen: 8 TB stolen — PAM becomes non-negotiable
On 13/05/2026, Foxconn confirmed an attack claimed by Nitrogen: 8 TB and 11M+ files stolen, with slowdowns at North American plants. A zero-trust PAM meets NIS 2 art. 21 and severs admin access that enables such attacks.
RUAG pays a ransom to Akira: red alert for executive boards
On 6 June 2026, RUAG confirmed it paid a ransom to the Akira gang after its US subsidiary was hit. A rare admission that quantifies ransomware’s economic impact: paying, even a “small amount,” to retrieve data.