Data Breaches

Avoid data breaches by knowing the latest important data breaches with our unique insights. We identify data breaches on which we can do case studies to help you learn and improve. A data breach is a type of privacy incident that happens whenever an unauthorised person could have gotten access to someone else’s personal data.

Only some are linked below. To read all previous insights and be alerted to future insights, join the relevant Michalsons programme. You can view the public and the “Members only” ones if you are a member and logged in.

Standard Bank | Data breach

Standard Bank, Africa’s largest bank, has disclosed a data breach affecting a number of its clients. This raises concerns about rising cybersecurity risks across South Africa’s financial sector. Standard Bank directly communicated with their clients and confirmed that someone had […]

Webinar | Sustaining your compliance efforts

We bring you up to speed with our insights on the latest legal developments regarding digital, data and tech. We help you consider the practical actions you should take to sustain your compliance efforts. We filter out the noise for [...]

Case study: 23andMe data breach

The 23andMe data breach exposed highly sensitive personal and genetic information. Canadian and UK regulators found that 23andMe failed to implement adequate security measures and violated their respective data protection laws. This breach highlights how poor security and slow response [...]

By |2025-07-03T11:08:33+02:00June 26th, 2025|Categories: POPI and Data Protection|Tags: , , |

Notification of security compromise to the Information Regulator | Guideline and support

The information regulator published a Guideline on notification of security compromises to the information regulator in July 2020. The guideline explains the procedure responsible parties or information officers should follow to notify the regulator of a security compromise or data [...]

Matric results leak | Data breach

The recent matric results leak has raised serious concerns about data security and unauthorised access to student information. The breach, involving the early release of National Senior Certificate (NSC) results, has led to a criminal investigation and regulatory intervention. Here’s [...]

By |2025-01-31T11:35:22+02:00January 31st, 2025|Categories: POPI and Data Protection|Tags: , |

Employee cybercrime in your backyard

Employee cybercrime is a growing threat that can impact any organisation, regardless of size or industry. While many businesses focus on external cyber threats, the risks posed by insiders often go unnoticed until it’s too late. Recent events illustrate just [...]

By |2025-01-08T16:44:48+02:00January 8th, 2025|Categories: Cybercrime|Tags: , , |

Lancet Laboratories enforcement action | Security

The Information Regulator issued a POPIA enforcement notice against Lancet Laboratories in September 2024 for failing to comply with the breach notifications required by POPIA. The Information Regulator conducted a POPIA compliance assessment following the numerous security compromises experienced by [...]

NYOB’s complaint against EU parliament | Data breach

The protection of personal data is crucial, especially for institutions like the European Parliament. NYOB's complaint against the EU parliament has shed light on serious data breaches in the Parliament’s recruitment platform, PEOPLE. These breaches have compromised the personal information [...]

By |2024-08-28T14:07:09+02:00August 22nd, 2024|Categories: POPI and Data Protection|Tags: , , , |