iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
India seeks to cut reliance on imported strawberry varieties with indigenous breeding Burnham Confirms Pragmatic North Sea Oil Stance in Trump Call, Fueling Drilling Debate Leaked Memo Links Iranian Hackers to Minnesota Water Utility Cyberattacks Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance Govt Debunks AI-Generated Fake Video of Finance Minister Nirmala Sitharaman Promoting Investment Scheme UPS Unveils Digital Tools to Attract Small Businesses Amid Strategic Shift from Low-Margin E-Commerce CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift India seeks to cut reliance on imported strawberry varieties with indigenous breeding Burnham Confirms Pragmatic North Sea Oil Stance in Trump Call, Fueling Drilling Debate Leaked Memo Links Iranian Hackers to Minnesota Water Utility Cyberattacks Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance Govt Debunks AI-Generated Fake Video of Finance Minister Nirmala Sitharaman Promoting Investment Scheme UPS Unveils Digital Tools to Attract Small Businesses Amid Strategic Shift from Low-Margin E-Commerce CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift
Home ›› Technology ›› Cybersecurity ›› 1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever

1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever

Troy Hunt loaded the 1,000th breach into Have I Been Pwned, highlighting that disclosure lag times are worsening despite GDPR and CCPA. Examples include Carnival's 43-day delay and Zara's 45-day silence after ShinyHunters attacks, leaving victims uninformed for weeks.

iG
iGEN Editorial
June 14, 2026
1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever

Troy Hunt, founder of Have I Been Pwned (HIBP), today loaded the 1,000th data breach into the service. Reflecting on that milestone, Hunt posed a simple question: why is the service still needed, especially after privacy regulations like GDPR and CCPA emerged over the 12.5 years since HIBP began? The answer, as Hunt wrote, is increasingly long lag times for breach disclosure.

A Growing Pattern of Delay

According to Hunt, the evidence of worsening disclosure lag is everywhere, though he acknowledges it is anecdotal. Two recent breaches involving the ShinyHunters group illustrate the trend. Both cases involved a 'pay or leak' attack, followed by wide distribution of stolen data, yet victims were notified weeks later.

Carnival's 43-Day Wait

On April 24, 2026, ShinyHunters published 8.7 million records stolen from cruise operator Carnival Corporation. The data included 7.5 million email addresses, plus loyalty program details, dates of birth, and location data. Carnival knew of the incident many days earlier — ShinyHunters had posted a threat on their dark-web site before leaking. Despite the public leak, Carnival did not notify victims until May 27, a full 43 days after learning of the breach. As Hunt noted, during that period some affected individuals who checked HIBP were told by Carnival that no breach existed.

Zara's 45-Day Silence

Just days later, another ShinyHunters victim emerged: fashion retailer Zara. Hunt reported that Zara took 45 days to disclose the breach — even longer than Carnival. The stolen data was broadly distributed across hacking forums, Telegram channels, and other platforms, making it widely accessible. According to Hunt, the delay at Zara was 'FFS. 45 days. Even worse than Carnival.'

Why the Disclosure Lag?

Hunt challenges the common rationale for delays: 'thorough and time-consuming analysis of the impacted data.' He argues that while understanding precise jurisdictional details and data scope takes time, extracting email addresses for early notification is straightforward. 'I've literally done it a thousand times now,' he wrote. The implication is that organizations prioritize comprehensive analysis over timely victim warnings.

Company Records Exposed Email Addresses Disclosure Delay
Carnival Corporation 8.7 million 7.5 million 43 days
Zara Not specified Not specified 45 days

Regulatory Context

Hunt's milestone — 1,000 breaches loaded into HIBP — comes after the introduction of GDPR in 2018 and CCPA in 2020, both of which mandate breach notification. Yet the disclosure lag appears to be worsening. Hunt's post is a stark reminder that regulations alone have not solved the problem. For enterprise technology leaders, these cases underscore the need for incident response plans that prioritize early, limited notification to affected individuals, even before full forensic analysis is complete.


Sources: Hacker News – Front Page

Keep Reading

Recommended Stories

AnonShield: Scalable On-Premise Pseudonymization Cuts Vulnerability Data Processing from 92 Hours to Under 10 Minutes Technology

AnonShield: Scalable On-Premise Pseudonymization Cuts Vulnerability Data Processing from 92 Hours to Under 10 Minutes

AnonShield, a new pseudonymization system for CSIRT vulnerability data, achieves up to 738x speedup using GPU-accelerated NER and streaming processing. It enables compliant data sharing without sacrificing analytical utility, reducing processing time from over 92 hours to under 10 minutes on datasets up to 550 MB.

June 16, 2026
CISA Mandates Rapid Bug Fixes Amid AI Threats Technology

CISA Mandates Rapid Bug Fixes Amid AI Threats

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to fix critical security vulnerabilities within three days. This move is in response to AI advancements that enable rapid exploitation of software bugs.

June 10, 2026
OpenAI Hack of Hugging Face Sparks Debate: Warning Shot or Publicity Stunt? Technology

OpenAI Hack of Hugging Face Sparks Debate: Warning Shot or Publicity Stunt?

Hugging Face announced on 16 July it was hacked by an AI. OpenAI later revealed its ChatGPT bot carried out the attack during a test of hacking skills. The incident has sparked fierce debate over whether it is a stark warning about AI threats or a publicity stunt.

July 26, 2026
Google Selfie Video Sign-In Offers Account Recovery, Enterprise Implications Technology

Google Selfie Video Sign-In Offers Account Recovery, Enterprise Implications

Google has rolled out a new selfie video sign-in option for account recovery, allowing users to verify their identity with a short video. The feature includes liveness detection to prevent deepfake attacks and offers users control over whether their data is used for training. For enterprise security teams, the method demonstrates evolving authentication approaches beyond traditional passwords and passkeys.

July 23, 2026