Connect with us

Infosecurity

Beyond Brexit: Why GDPR Will Remain a Cornerstone of UK Data Protection

Published

on

Beyond Brexit: Why GDPR Will Remain a Cornerstone of UK Data Protection

The relationship between the GDPR UK Brexit timeline presents a unique regulatory puzzle. With the General Data Protection Regulation (GDPR) becoming enforceable across the EU in early 2018, and the United Kingdom’s formal departure from the bloc anticipated later that same year, a critical question emerged. Would British organizations treat GDPR as a transient European rule soon to be discarded? The reality, shaped by interconnected commercial, legal, and ethical imperatives, points decisively toward enduring alignment.

The Unavoidable Commercial Imperative of GDPR Compliance

First and foremost, economics dictate continuity. British and European businesses are deeply intertwined, and that trade relies on seamless data flows. Consequently, any UK company handling the personal data of EU residents must adhere to GDPR standards to operate in that market. Maintaining separate, weaker data protocols for UK customers alone makes little operational or financial sense for multinational firms. This creates a powerful market force for a unified, high-standard approach.

Building on this, the UK’s attractiveness as a destination for global investment hinges on regulatory stability. A nation crafting a data protection regime radically different from the world’s most influential standard—the GDPR—would risk alienating foreign direct investment. This is particularly acute for sectors like technology and cloud service providers choosing a European base. For commerce to thrive, regulatory harmony with neighboring markets is not just beneficial; it’s essential.

Legal Foundations and Future-Proofing UK Law

Therefore, the commercial drive feeds directly into legal reality. The UK’s own Data Protection Act has long been harmonized with previous EU directives. It is highly improbable that any future government would deliberately roll back privacy protections for its citizens, creating a perceived ‘data haven’ of lower standards. The political and public backlash would be significant.

In fact, the most plausible legal scenario involved absorbing the vast body of existing EU law, including data protection statutes, into domestic UK law. Overnight revocation would have created a chaotic vacuum, stripping businesses and individuals of established rights. The mechanism for this, the EU (Withdrawal) Act 2018, was designed to ensure precisely this kind of continuity, embedding principles like those in GDPR into the UK’s legal fabric.

The Role of International Courts and Human Rights

Moreover, the legal landscape extends beyond the EU itself. Importantly, the right to appeal to the European Court of Human Rights (ECHR) remains intact post-Brexit, as the UK’s membership in this Council of Europe body is separate. This provides a continued external avenue for justice in serious privacy violations, a safeguard many citizens would be reluctant to lose.

The Moral and Social Contract of Data Protection

Beyond spreadsheets and statutes lies a powerful moral argument. Regardless of one’s vote in the 2016 referendum, core GDPR UK Brexit principles command broad public support. Few individuals would genuinely wish to forfeit the right to be informed of a data breach or surrender the ‘right to be erased.’ These provisions empower individuals against large organizations.

This reflects a broader consensus. At its heart, the GDPR is about fundamental human dignity in the digital age—control over one’s personal information. Discarding such protections would represent a profound step backward, out of sync with public expectation and the global trend toward stronger privacy laws, as seen in regions from California to Japan. The UK’s stance on data privacy fundamentals thus reflects its values on the world stage.

Conclusion: Convergence, Not Divergence

In summary, the notion that Brexit would trigger a swift abandonment of GDPR was always a misconception. The regulation’s influence was set to persist through powerful channels: the brute force of commercial necessity, the inertia and sense of existing legal frameworks, and a societal demand for robust personal privacy. For UK businesses, a strategy of sustained compliance was the only rational path forward.

Ultimately, the UK’s data protection journey post-2018 demonstrates how global standards can transcend political unions. While the UK has since developed its own version, the UK GDPR, its core alignment with the EU regulation underscores a lasting truth. In an interconnected world, high standards of data protection are not a bureaucratic burden but a cornerstone of trust, trade, and modern rights. For further insight into evolving compliance strategies, explore our analysis on international data standards.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

Origin Energy confirms customer data breach, 5 million users at risk

Published

on

Origin Energy data breach

Origin Energy confirms breach after hacker claims

Australia’s largest electricity and gas retailer, Origin Energy, has confirmed that customer data was compromised in a security incident. The company, which serves nearly 5 million customers across the country, initially said on Wednesday it was investigating a ‘potential security incident’ after The Australian reported that a hacker had shared what they claimed was a sample of stolen records.

By Thursday, the Sydney-based energy giant issued a second update. The tone shifted. It was no longer a possibility — it was a confirmed breach. Origin said it is now working with federal agencies and independent cyber experts to understand the full scope of the attack.

What data was stolen in the Origin Energy cyberattack?

The stolen data includes names, addresses, dates of birth, and account information. More concerning for many customers: the breach also exposed the last four digits of credit card numbers and the last three digits of bank account numbers.

Origin has not yet said how many customers are affected. The company said it is ‘working to understand the total number of impacted customers.’ That investigation is ongoing.

For now, the company recommends customers monitor their accounts for suspicious activity. If you’re an Origin customer, it’s worth checking your bank statements and credit card transactions more closely than usual.

CEO Frank Calabria apologizes, promises action

Origin CEO Frank Calabria issued a public apology. ‘One of our key priorities is taking action to secure our systems and ensure no further unauthorised access,’ he said in a statement. ‘We are working with independent cyber experts to support Origin, and that work is continuing alongside the work of authorities.’

Calabria did not provide a timeline for when the investigation might conclude. He also did not say whether the company plans to offer credit monitoring or identity theft protection to affected customers — something that has become standard practice after major breaches in other countries.

A worrying pattern: Australian healthcare data also hit

This breach comes on the heels of another major Australian cyberattack. Partnered Health, a network of healthcare clinics, recently confirmed that patient medical records were stolen from at least 21 clinics. The two incidents — one targeting energy, the other healthcare — suggest Australian critical infrastructure is facing a sustained wave of attacks.

It’s a troubling pattern. In 2022, Optus suffered a massive breach affecting 9 million customers. Then came Medibank, which exposed the health data of millions. Now Origin Energy. The question isn’t whether another major Australian company will be hit — it’s which one, and when.

Energy companies are particularly attractive targets. They hold vast amounts of personal and financial data. They also operate systems that are critical to national infrastructure. A breach at an energy retailer isn’t just about stolen credit card numbers. It raises questions about grid security, operational technology, and the potential for more disruptive attacks.

What Origin customers should do right now

  • Check your account activity — log in to your Origin Energy account and look for any changes you didn’t make.
  • Monitor financial statements — watch for unauthorized transactions on credit cards and bank accounts.
  • Be alert for phishing — scammers often piggyback on data breaches with fake emails or calls pretending to be from the company.
  • Consider a credit ban — if you’re worried about identity theft, you can place a temporary ban on your credit file through agencies like Equifax or Experian.

Origin has not yet announced whether it will provide free credit monitoring services. In previous Australian breaches — like the Optus incident — the government eventually stepped in to mandate such protections. It may happen again.

The bigger picture: Australian cybersecurity under strain

The Origin Energy data breach is the latest in a string of high-profile cyberattacks hitting Australian companies. The government has responded by strengthening data breach notification laws and increasing penalties for companies that fail to protect customer data. But enforcement takes time. Meanwhile, hackers keep finding new ways in.

For energy companies, the stakes are especially high. A compromised customer database is bad enough. But if attackers were to pivot from IT systems to operational technology — the systems that actually control power generation and distribution — the consequences could be far more severe.

For now, Origin Energy customers are left waiting. Waiting for answers. Waiting to find out if their data was stolen. Waiting to see if the company will do more than apologize.

Continue Reading

Infosecurity

Researchers Uncover JadePuffer: The First Fully Agentic Ransomware Campaign Driven by an LLM

Published

on

fully agentic ransomware

AI Didn’t Just Assist—It Ran the Whole Show

Cloud security firm Sysdig has published details on what it calls the first ransomware campaign executed entirely by a large language model. No human hands on the keyboard. No experienced operator steering the malware.

Dubbed JadePuffer, the campaign exploited CVE-2025-3248 in an internet-facing Langflow instance. From there, the LLM agent ran an adaptive, fully automated playbook that ended with a devastating database extortion attack against a production server.

The attack took just 31 seconds to recover from a failed login attempt and keep moving. That speed is the new reality.

How JadePuffer Worked: A Multi-Stage, Self-Correcting Attack

Sysdig’s Threat Research Team described a campaign that didn’t rely on a human-driven toolkit. Instead, an LLM agent delivered all attack capabilities autonomously, retrying failed steps within refined parameters until it succeeded.

The multi-stage assault unfolded like this:

  • Exploited Langflow via CVE-2025-3248 to gain initial access
  • Conducted reconnaissance and harvested credentials—LLM API keys, cloud credentials, database logins
  • Stole local data, including Langflow’s own backing Postgres database
  • Mapped laterally to discover other services reachable from the compromised host
  • Enumerated a MinIO object store and grabbed more credentials
  • Created a cron job on the Langflow server for persistence
  • Gained access to a production MySQL server running Alibaba Nacos using root credentials
  • Targeted Nacos with multiple payloads, including exploitation of CVE-2021-29441

The goal wasn’t just extortion. It was mass data destruction.

Data Destroyed, Not Just Held Hostage

JadePuffer encrypted all 1,342 Nacos service configuration items and deleted the originals. But here’s the kicker: the AES key was generated as base64(uuid4().bytes + uuid4().bytes)—essentially random—and printed to stdout. It was never persisted or transmitted anywhere.

“The victim cannot recover the encrypted configurations even with payment,” Sysdig explained.

Captured payloads show the LLM escalating from row-level deletion to dropping entire database schemas, all while narrating its own targeting rationale. The IP address 64.20.53[.]230 only appears in this context, with no evidence that anything was backed up to it.

Four Takeaways for Security Teams

Sysdig highlighted four critical lessons from the JadePuffer discovery:

1. Ransomware No Longer Requires Skilled Operators

An LLM agent can carry out reconnaissance, credential theft, lateral movement, persistence, and destruction without any human expertise. The barrier to entry just dropped to zero.

2. Old Vulnerabilities Are Being Automated

This attack leaned on years-old issues: a 2021 Nacos auth-bypass and an unchanged default signing key. Neglected, internet-exposed infrastructure is a goldmine for agentic attackers.

3. New Detection Opportunities Emerge

An LLM narrates its own objectives in its payloads. That provides a new detection and triage opportunity for network defenders—if they’re paying attention.

4. Exfiltration Claims Are the Agent’s Own Assertion

The AES key was ephemeral and unrecoverable. The victim’s configurations are gone forever, even if a ransom were paid. There’s no leverage, only destruction.

The Age of Agentic Threat Actors Is Here

Heath Renfrow, co-founder and CISO at breach recovery firm Fenix24, warned that agentic threat actors (ATAs) will compress the time defenders have to respond.

“If an AI agent can compress what previously took an experienced operator several hours into a matter of minutes, defenders lose valuable time. That has implications across every phase of an incident, from detection and containment to recovery,” he said.

Renfrow urged organizations not to get distracted by whether an attacker is “AI-powered.” The outcome is the same: compromised identities, stolen credentials, encrypted or destroyed data, and business disruption.

“Security teams should continue prioritizing the fundamentals—rapid patching of internet-facing systems, strong identity protections, least privilege, network segmentation, continuous monitoring, and restricting unnecessary external exposure,” he added.

For more on AI-driven threats, read our coverage of the first reported AI-powered ransomware and how LLMs are reshaping cyberattacks.

Continue Reading

Infosecurity

Two-Thirds of Ransomware Victims Say AI Made the Attack Worse

Published

on

AI ransomware effectiveness

The Numbers Are Stark — and Getting Worse

Almost two out of every three organizations hit by ransomware say artificial intelligence made the attack more effective. That’s the headline finding from a new global survey of cybersecurity professionals conducted by Proofpoint. The figure: 65%.

The 2026 AI-Era Ransomware Report, published July 22, doesn’t mince words. Across the incidents studied, AI involvement was the norm, not the exception. Attackers are no longer just using brute force or luck. They are leaning on AI to craft phishing emails, impersonate trusted contacts, and steal credentials at a scale and polish that was impossible just a few years ago.

This isn’t a futuristic warning. It’s happening now.

How AI Changes the Entry Point

Ransomware doesn’t start with encryption. It starts with a click. According to the report, human interaction remains the primary entry vector. Of the incidents analyzed:

  • 47% involved a malicious link somewhere in the attack chain
  • 46% used a malicious attachment
  • 36% relied on credential harvesting

What’s changed is the quality of the lure. In the past, a phishing email might have clumsy phrasing, a mismatched logo, or a login page that felt off. Those small red flags gave employees a moment of pause. Not anymore.

Now, with AI tools, attackers can generate messages that look like legitimate business communications. No awkward grammar. No obvious tells. The report found that 40% of respondents said the initial lure appeared so legitimate that the employee simply didn’t suspect anything was wrong.

AI Doesn’t Reinvent Ransomware — It Supercharges It

Ryan Kalember, Proofpoint’s chief strategy officer, put it plainly: “AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware.”

He added that today’s attackers use AI to create highly convincing phishing emails, generate malware components like scripts, and run credential theft campaigns that exploit human trust at scale. His warning to organizations: if you still treat ransomware as an endpoint or recovery problem, you’re missing what these attacks most frequently begin with — people, identities, and trusted communications.

Security Controls Are Failing, Too

It’s not just human judgment that’s failing. Enterprise software defenses are also struggling. A third of surveyed organizations said their existing email security controls failed to detect the attack entirely. Another quarter cited misconfigurations or outright gaps in their security controls.

That means even companies with up-to-date email gateways, endpoint detection, and training programs are getting caught off guard. The attackers are using AI to bypass technical controls as well as human ones.

Proofpoint’s recommendation is blunt: organizations that want to reduce ransomware risk must focus on stopping attacks at the point of entry, protecting identities from compromise, and responding before attackers can turn access into extortion.

What This Means for Your Organization

The takeaway isn’t that AI is unbeatable. It’s that the bar for what looks suspicious has moved. Old-school phishing indicators — bad grammar, weird logos — are no longer reliable. Attackers can now generate polished, personalized lures at scale.

That means security teams need to shift their focus. Instead of relying solely on employees to spot a bad email, they should invest in identity protection, stronger authentication, and faster response times. Because by the time the ransomware payload drops, the real damage — the access, the credential theft, the foothold — has already happened.

For more on why ransomware remains one of cybersecurity’s most persistent threats, read our deep dive on the evolving ransomware landscape.

Continue Reading

Trending