iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Microsoft CEO Satya Nadella warns AI dominance could 'hollow out entire industries' Open-source Discord alternatives: What Stoat and Element actually fix - Engadget India launches producer price index; wholesale inflation gauge to be phased out in five years India, UK work to resolve issues holding up trade pact implementation, says official ‘Let the oil flow’: What Trump’s possible peace deal with Iran, Strait of Hormuz opening mean for India Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives Why UK data sovereignty is the next competitive advantage for digital industries Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed El Nino May Weaken India's Monsoon, Threaten Rice and Maize Output, FAO Warns Nigel Farage Warns UK Social Media Ban 'Unlikely to Work' Due to VPNs Microsoft CEO Satya Nadella warns AI dominance could 'hollow out entire industries' Open-source Discord alternatives: What Stoat and Element actually fix - Engadget India launches producer price index; wholesale inflation gauge to be phased out in five years India, UK work to resolve issues holding up trade pact implementation, says official ‘Let the oil flow’: What Trump’s possible peace deal with Iran, Strait of Hormuz opening mean for India Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives Why UK data sovereignty is the next competitive advantage for digital industries Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed El Nino May Weaken India's Monsoon, Threaten Rice and Maize Output, FAO Warns Nigel Farage Warns UK Social Media Ban 'Unlikely to Work' Due to VPNs
Home ›› Technology ›› Cybersecurity ›› 1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever

1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever

Troy Hunt loaded the 1,000th breach into Have I Been Pwned, highlighting that disclosure lag times are worsening despite GDPR and CCPA. Examples include Carnival's 43-day delay and Zara's 45-day silence after ShinyHunters attacks, leaving victims uninformed for weeks.

iG
iGEN Editorial
June 14, 2026
1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever

Troy Hunt, founder of Have I Been Pwned (HIBP), today loaded the 1,000th data breach into the service. Reflecting on that milestone, Hunt posed a simple question: why is the service still needed, especially after privacy regulations like GDPR and CCPA emerged over the 12.5 years since HIBP began? The answer, as Hunt wrote, is increasingly long lag times for breach disclosure.

A Growing Pattern of Delay

According to Hunt, the evidence of worsening disclosure lag is everywhere, though he acknowledges it is anecdotal. Two recent breaches involving the ShinyHunters group illustrate the trend. Both cases involved a 'pay or leak' attack, followed by wide distribution of stolen data, yet victims were notified weeks later.

Carnival's 43-Day Wait

On April 24, 2026, ShinyHunters published 8.7 million records stolen from cruise operator Carnival Corporation. The data included 7.5 million email addresses, plus loyalty program details, dates of birth, and location data. Carnival knew of the incident many days earlier — ShinyHunters had posted a threat on their dark-web site before leaking. Despite the public leak, Carnival did not notify victims until May 27, a full 43 days after learning of the breach. As Hunt noted, during that period some affected individuals who checked HIBP were told by Carnival that no breach existed.

Zara's 45-Day Silence

Just days later, another ShinyHunters victim emerged: fashion retailer Zara. Hunt reported that Zara took 45 days to disclose the breach — even longer than Carnival. The stolen data was broadly distributed across hacking forums, Telegram channels, and other platforms, making it widely accessible. According to Hunt, the delay at Zara was 'FFS. 45 days. Even worse than Carnival.'

Why the Disclosure Lag?

Hunt challenges the common rationale for delays: 'thorough and time-consuming analysis of the impacted data.' He argues that while understanding precise jurisdictional details and data scope takes time, extracting email addresses for early notification is straightforward. 'I've literally done it a thousand times now,' he wrote. The implication is that organizations prioritize comprehensive analysis over timely victim warnings.

Company Records Exposed Email Addresses Disclosure Delay
Carnival Corporation 8.7 million 7.5 million 43 days
Zara Not specified Not specified 45 days

Regulatory Context

Hunt's milestone — 1,000 breaches loaded into HIBP — comes after the introduction of GDPR in 2018 and CCPA in 2020, both of which mandate breach notification. Yet the disclosure lag appears to be worsening. Hunt's post is a stark reminder that regulations alone have not solved the problem. For enterprise technology leaders, these cases underscore the need for incident response plans that prioritize early, limited notification to affected individuals, even before full forensic analysis is complete.


Sources: Hacker News – Front Page

Keep Reading

Recommended Stories

CISA Mandates Rapid Bug Fixes Amid AI Threats Technology

CISA Mandates Rapid Bug Fixes Amid AI Threats

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to fix critical security vulnerabilities within three days. This move is in response to AI advancements that enable rapid exploitation of software bugs.

June 10, 2026
Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives Technology

Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives

Samsung MAX VPN ceased operations on June 15, 2026, affecting over 50 million users. The app remains as a dead shell unless uninstalled. Users are advised to switch to third-party VPNs for continued protection.

June 15, 2026
Adaptive Security Enlists Conan O'Brien for 15-Part Cybersecurity Training Series Targeting AI Fraud Technology

Adaptive Security Enlists Conan O'Brien for 15-Part Cybersecurity Training Series Targeting AI Fraud

New York-based cybersecurity firm Adaptive Security has partnered with talk show host Conan O'Brien to produce a 15-part training series addressing AI-enabled threats such as phishing, deepfakes, and voice cloning. The series, available to enterprise customers, aims to improve employee engagement and awareness of sophisticated cyber attacks.

June 15, 2026
Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations Technology

Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations

Oracle has issued a security advisory for a critical remote code execution vulnerability (CVE-2026-35273, CVSS 9.8) in PeopleSoft versions 8.61 and 8.62. The extortion group ShinyHunters is exploiting it, claiming to have breached over 100 organizations and exfiltrated data from ~300 instances. Google's Mandiant reported zero-day exploitation between May 27 and June 9, 2026, and alerted over 100 potentially vulnerable entities.

June 15, 2026