Connect with us

Infosecurity

Former UK privacy chief reportedly preparing legal action against woman who reported him, minister says

Published

on

John Edwards legal action

Minister reveals legal threat against whistleblower

Britain’s former Information Commissioner, John Edwards, is reportedly preparing to serve legal papers on a female employee who raised concerns about his conduct, the science and technology secretary told Parliament on Wednesday. Liz Kendall, speaking before the Science, Innovation and Technology Committee, said she was “absolutely appalled” by the development.

Kendall revealed that an independent investigation at the Information Commissioner’s Office (ICO) had upheld multiple allegations of “sexual harassment and bullying” against Edwards. The specific nature of the complaints had not been publicly disclosed until now.

“I’m also going to be launching an independent review of the culture, accountability and governance of the ICO,” Kendall told the committee. “I take very seriously what’s happened there and I will do everything I can to try and put this right.” She added that “the women who’ve spoken up have been incredibly brave.”

Edwards’ resignation and LinkedIn statement

Edwards formally resigned as Information Commissioner in June, after voluntarily stepping back from his duties in February. That move came amid an internal workplace investigation into what was initially described only as unspecified conduct.

In a LinkedIn post at the time, Edwards acknowledged his position had “become untenable.” He wrote: “From the time the investigation was launched, I have accepted that there have been occasions where I exercised poor judgment and made attempts at humor that were inappropriate and caused offense.”

He added that while he did not agree with how the investigation was conducted, he accepted that resigning was the appropriate course.

Government response and new leadership

Kendall told the committee the government will launch the recruitment process for Edwards’ successor next week. That process will run alongside “the appointment of a new board of non-executive directors, the majority of whom will be women.”

The minister also revealed the legal threat. “It has come to my attention that the former Information Commissioner is preparing to serve legal papers on one of the women at the ICO who raised concern about his behavior earlier this year,” she said.

“I don’t know who this woman is, but by reporting her concerns, she supported the independent investigation that upheld multiple allegations made against him. I have reached out as best I can and said they need to know that they will always be listened to without being put at personal risk. Quite frankly, I’m appalled by that behavior.”

ICO leadership under scrutiny

The ICO, which oversees Britain’s data protection and privacy regulations, has faced growing scrutiny over its internal culture. The independent review Kendall announced Wednesday aims to examine how the organization handles accountability and governance.

Edwards served as Information Commissioner from January 2022. Before that, he was New Zealand’s Privacy Commissioner. His tenure at the ICO included major decisions on WhatsApp HD photo sending and data-sharing rules, but his leadership is now overshadowed by the misconduct allegations.

The Department for Science, Innovation and Technology (DSIT) has not commented on the legal threat beyond Kendall’s remarks. Neither Edwards, the ICO, nor the government immediately responded to requests for comment.

Broader implications for workplace whistleblowing

Kendall’s disclosure raises questions about the protections available to whistleblowers in UK public bodies. The minister made clear she views the legal action as an attempt to intimidate someone who came forward in good faith.

Employment lawyers say that while individuals have a right to defend themselves against allegations, threatening legal action against a complainant can be seen as retaliation. Under UK employment law, whistleblowers are protected from detriment or dismissal for making protected disclosures.

The case could prompt wider discussions about how regulators handle internal complaints. The ICO, which enforces rules on data privacy, is now itself under investigation for its handling of workplace conduct.

For the women who spoke up, Kendall’s public support may offer some reassurance. But the prospect of facing legal proceedings from a former boss — one who once held one of the most powerful regulatory posts in the country — is daunting.

“The women who’ve spoken up have been incredibly brave,” Kendall repeated. “They need to know they will always be listened to without being put at personal risk.”

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

Hackers stole employee and customer data from Craneware, the software backbone of 2,000 US hospitals

Published

on

Craneware data breach

A quiet but serious intrusion

On Monday, Craneware — a British software firm whose products run across more than 2,000 U.S. hospitals — told investors that attackers broke into its internal network and made off with employee and customer records. The company, headquartered in Edinburgh and listed on London’s AIM market, said it detected unauthorized access to a “subset” of its data environment and has since called in outside forensic investigators.

The breach has been reported to the FBI and to the UK’s Information Commissioner’s Office. Craneware said the intrusion is contained and the attackers no longer have access to its systems. Crucially, the company added that neither its own operations nor the services it provides to hospitals were disrupted.

But the details that remain unknown are troubling. Craneware did not say who was behind the attack, when the hackers first got in, how long they roamed the network, or whether a ransom was demanded. It also did not name any of the affected customers — and it did not say whether patient health information was among the stolen files.

What was taken — and what wasn’t

Craneware disclosed that a large number of file names were viewed and copied out of its network. Most of that material was non-sensitive or already publicly available regulatory data, the company said. But some employee data and customer and partner records were definitely taken.

The company said it is still working to determine the full scope of the theft and expects to notify affected organizations and individuals once it has a clearer picture. That timeline is vague, which is not unusual for breaches of this scale, but it leaves hospitals and their staff in an uncomfortable limbo.

The biggest open question: was patient data involved? If the stolen records include protected health information, the breach would trigger notification requirements under the U.S. Health Insurance Portability and Accountability Act (HIPAA). Craneware has not addressed that directly.

A sprawling target in healthcare IT

Craneware was founded in 1999 and sells billing, pricing and pharmacy software to American healthcare providers. The company says its tools are used by more than 2,000 hospitals and close to 10,000 clinics and retail pharmacies across the United States.

That makes it a juicy target. Healthcare vendors hold a goldmine of sensitive data — patient records, insurance details, billing information, employee credentials. And attackers know it. In recent years, hackers have repeatedly targeted the vendors that hospitals rely on, often with devastating results.

In March 2026, software firm CareCloud warned that patients’ electronic health records may have been leaked after hackers gained access to its systems. Two weeks before that, healthcare analytics firm Insightin told state regulators that 1.1 million people were affected by a data theft that happened in September 2025.

Those are not isolated incidents. In 2024, hackers breached healthcare technology company TriZetto Provider Solutions, exposing the data of 3 million people. Another 5 million were impacted when technology firm Episource was attacked. The pattern is clear: cybercriminals are going after the vendors, not just the hospitals themselves.

Why vendor breaches hit harder

When a single hospital gets hacked, it’s bad. But when a vendor like Craneware gets compromised, the blast radius is enormous. A single intrusion can ripple across thousands of hospitals and clinics, each one potentially exposed by the same weak link in the supply chain.

That’s why the FBI is involved. And it’s why regulators on both sides of the Atlantic are likely to scrutinize Craneware’s response closely. The company said it has engaged outside forensic investigators, but it has not disclosed which firm is handling the probe.

For the hospitals using Craneware’s software, the immediate priority is damage control. They need to know whether their patients’ data was stolen, and they need to know fast. For the rest of the healthcare industry, this breach is yet another reminder that healthcare cybersecurity is only as strong as the weakest vendor in the chain.

What comes next

Craneware said the attackers no longer have a foothold in its systems. That’s the good news. The bad news is that the data is already out — copied and likely sold or leaked. The company’s forensic investigation will take weeks, possibly months, to fully map what was taken.

Affected employees, customers and business partners will be notified once that work is done. But for now, the clock is ticking. Every day without answers is a day the stolen data could be used for phishing, identity theft or extortion.

This breach is a stark reminder that the software that keeps hospitals running is also a high-value target. And as long as attackers see healthcare vendors as a soft underbelly, the attacks will keep coming.

Continue Reading

Infosecurity

Opera GX Zero-Click Flaw Allowed Websites to Auto-Install Mods and Steal User Data

Published

on

Opera GX flaw

No Clicks, No Permissions: How a Critical Opera GX Flaw Worked

A serious security hole in Opera GX, the gaming-focused browser from Opera, allowed any website to silently install a customization mod — and then use that mod to siphon data from sites the victim had visited. The attack required zero user interaction. No clicking. No permission prompts. Just a hidden frame loading a file.

Discovered by an independent researcher known as zhero_web_security, the Opera GX flaw exploited the browser’s GX Mods system. Unlike standard browser extensions, GX Mods are supposed to be lightweight — they customize the browser’s look, sounds, and website styling, but carry no permissions and can’t execute JavaScript. That’s what made the discovery so unsettling: the mods weren’t supposed to be dangerous. Yet the researcher found a way to weaponize them.

Auto-Install: The Core of the Opera GX Vulnerability

Here’s the mechanical problem. When a user downloads a GX Mod file, it installs automatically. No dialogue box asks for approval. No permission request pops up. The researcher realized that an attacker could place a mod file inside a hidden HTML frame on a malicious website. As soon as the page loads, the mod lands in the browser — completely silent.

Once installed, the mod’s CSS (cascading style sheets) applies to every single tab and page the victim opens. Ordinary CSS injection is usually confined to one page. This was different. The Opera GX vulnerability gave the attacker a persistent foothold across the entire browser session.

Gmail Addresses and Browser Crashes: Proof of Concept

CSS cannot read a page’s content directly. But it can be cleverly crafted to trigger network requests based on what a page contains. That technique, known as an XS-Leak (cross-site leak), lets an attacker extract data bit by bit, character by character.

Using this method, the researcher built a zero-click exploit that recovered a victim’s full Gmail address. The attack silently redirected the browser to a Google account page, then used the injected CSS to leak the email address character by character. The researcher noted the method is not limited to Gmail — any data rendered on a page could theoretically be targeted.

The same auto-install behavior also enabled a denial-of-service (DoS) attack against both Opera and Opera GX. Chromium-based browsers block extensions in private or Incognito windows. Forcing a mod to install in Incognito mode caused the browser to crash — and wiped all open tabs in the process. Any file with a .crx extension triggered the crash, whether or not it was a legitimate mod.

From Low Priority to Critical: Opera’s Bug Bounty Response

The researcher reported the Opera GX flaw in February 2024 through Opera’s Bugcrowd bug bounty program. Initially, the team triaged it as low priority. That changed quickly. Opera’s security team reassessed the issue and reclassified it as critical.

A patch shipped on May 8, 2024, and the researcher received a $5,000 bounty payment. The full proof of concept was published on July 3, tested against Opera GX version 127.0.5778.41 — after the fix had already been distributed.

What This Means for Browser Security and Users

This isn’t the first time browser customization features have opened unexpected attack surfaces. But the Opera GX vulnerability is a sharp reminder that even permissionless systems can be dangerous. GX Mods were designed to be safe because they lack extension-level privileges. But CSS injection, combined with auto-installation, turned that safety assumption into a liability.

For users, the fix is straightforward: update Opera GX to the latest version. The browser should update automatically, but it’s worth checking. Anyone running a version prior to the May 8 patch is still exposed.

For the broader security community, the case raises questions about how browsers handle file-based installations and whether similar flaws exist in other Chromium-based browsers. The researcher’s work demonstrates that even a seemingly harmless mod can become a data theft tool — as long as it arrives without a click.

Continue Reading

Infosecurity

23andMe Hit With $18m Settlement and Strict New Security Mandates After 2023 Breach

Published

on

23andMe data breach settlement

A Landmark Settlement for Genetic Privacy

More than two years after cybercriminals stole the genetic profiles of over six million people, 23andMe has agreed to pay $18 million and submit to a sweeping set of new security mandates. A bipartisan coalition of 42 US state attorneys general, led by New York Attorney General Letitia James, finalized the deal in July 2025.

The settlement is not just about the money. It forces the company—and its new owner, TTAM Research—to adopt a far stricter data protection regime. New York alone will receive more than $705,000 from the payout.

“Companies have a duty to protect their customers’ personal information from hackers, but 23andMe put millions of its customers at risk with its flimsy security measures,” James said in a statement. “New Yorkers trusted 23andMe with their sensitive and personal genetic data, only to find that data stolen and put up for sale on the dark corners of the internet.”

How the 23andMe Data Breach Happened

The October 2023 incident was not a sophisticated hack of 23andMe’s core servers. It was a credential stuffing attack—a brute-force method where attackers use usernames and passwords leaked from other sites to break into accounts.

The company admitted at the time that the breach was enabled by customers’ weak password habits and the widespread absence of multi-factor authentication (MFA). Once inside, the attackers scraped profile information tied to ancestry results, eventually accessing data from 6.9 million users.

The fallout was immediate and lasting. By March 2025, 23andMe filed for Chapter 11 bankruptcy protection. In June, James and 27 other attorneys general sued the company to safeguard Americans’ genetic information during the bankruptcy process.

What the $18m Settlement Requires

The settlement imposes several binding security requirements on 23andMe and TTAM Research, the nonprofit formed by former CEO Anne Wojcicki that purchased the customer data.

  • Mandatory risk analysis: The company must conduct regular, documented assessments of its security posture.
  • An Advisory Board on data security: A new oversight body will monitor compliance and recommend improvements.
  • Consumer right to delete: Customers must retain a clear, easy-to-use option to erase their genetic data from the company’s systems.

These measures are designed to prevent a repeat of the 2023 disaster. The settlement also prohibits misleading statements about data protection practices.

This is not the only financial penalty 23andMe faces. A US bankruptcy judge approved a separate $46.75 million fund on July 7, 2025, to compensate victims directly. However, on July 10, the same judge ruled that California cannot seek additional damages from the company due to the Chapter 11 reorganization plan, though the state has 14 days to amend its lawsuit to remove monetary claims.

Regulatory Fines Pile Up Globally

The US settlement is just one piece of a much larger global enforcement puzzle. In July 2026, the Spanish privacy watchdog fined 23andMe €2.4 million ($2.75 million) after finding that 2,642 customers residing in Spain were affected by the breach.

A year earlier, in June 2025, the UK’s Information Commissioner’s Office levied a £2.3 million ($3.1 million) fine for failing to protect customers’ special category data—a classification that includes genetic information, which is among the most sensitive types of personal data under UK law.

These overlapping penalties signal that regulators on both sides of the Atlantic are taking genetic privacy breaches with extreme seriousness.

What This Means for the Future of Genetic Testing

The 23andMe case is a cautionary tale for the entire direct-to-consumer genetic testing industry. When customers mail in a saliva sample, they are trusting the company with data that cannot be changed—unlike a password or credit card number. A leaked genetic profile is permanent.

The new security mandates at TTAM Research set a precedent. Other firms in the space, including AncestryDNA and MyHeritage, will be watching closely. If state attorneys general are willing to impose structural reforms—not just fines—on a bankrupt company, the bar for data protection across the industry just got higher.

For consumers, the lesson is blunt: enable MFA on every account that holds sensitive data, and think twice before sharing your DNA with any private company. The settlement may close the legal case, but the questions about trust in the genetic testing industry are far from settled.

Continue Reading

Trending