United Kingdom
University of Nottingham student record system breached by cybercriminals
- The University of Nottingham has suffered a major data breach after hackers infiltrated its student record system in June.
- Approximately 40 gigabytes of data containing 455,000 unique email addresses were stolen and published online, exposing financial details, National Insurance numbers, and tens of thousands of passport numbers belonging to current students and alumni.
- Experts believe the hackers weaponised vulnerabilities in a third-party software supplier that manages the university’s data, rather than targeting the institution directly.
- The sensitive information was leaked after the university rejected the cybercriminals’ financial extortion demands, triggering a criminal investigation by the East Midlands Special Operations Unit.
UK and EU expand data sharing to track overseas criminal vehicles
- The UK government has expanded its data-sharing partnership with the EU to give British police instant access to European vehicle registries, enhancing the country’s ability to tackle international smuggling and organised crime.
- This shift replacing a manual request system that previously took days or months to track suspects.
- This rapid access to data allows law enforcement to spot stolen or cloned cars, identify vehicles repeatedly used by trafficking networks, and disrupt cross-border supply chains for illegal migrants, weapons, and drugs.
United States
Anthropic shuts down top AI models over US cybersecurity concerns
- Anthropic has disabled access to its most powerful models, Claude Fable 5 and Mythos 5, for all global customers after the US government issued an urgent directive to block foreign nationals over cybersecurity jailbreaking concerns.
- While the Trump administration and the UK’s AI Security Institute flagged the model’s capability to exploit cyber defences, Anthropic claims the vulnerability is minor, fixable, and achievable on rival platforms like ChatGPT.
- The suspension has intensified European calls for technological sovereignty to reduce reliance on the US.
- Experts warn that unilaterally cutting off global access to advanced tools undermines collaborative cyber defence and limits the safe testing required to protect organisations against rapidly evolving AI threats.
ShinyHunters claims responsibility for Kodak cyber attack
- Kodak has launched an investigation with external cybersecurity experts and law enforcement after an unauthorised third party gained temporary access to a limited amount of company data.
- The ShinyHunters cybercrime group has claimed responsibility for the attack, threatening to leak over 2.2 million compromised records, including internal corporate data and customer personally identifiable information.
- Despite the group’s threat of further digital disruptions, Kodak has stated it is confident that there is currently no ongoing threat to its internal systems or operations.
Europe
Council of Europe investigates cybersecurity attack
- The Council of Europe (CoE) is investigating claims by the ShinyHunters extortion group that it has breached the organisation’s network and stolen nearly 300 gigabytes of data.
- The cybercriminals claim to have exfiltrated over 429,000 files, including medical records, financial details, and 15 years of payroll data for more than 10,000 staff members.
- Since CoE staff work on sensitive human rights cases, malicious actors could sell the information to parties seeking to pressure them or using the data to blackmail and target individuals.
France cut ties with Palantir moving towards domestic sovereignty
- French intelligence agency is replacing AI data tools from US firm Palantir with technology from French provider ChapsVision to eliminate strategic dependency on foreign powers.
- Driven by recent US restrictions on Anthropic’s AI models, Prime Minister Lecornu emphasised that France must build autonomy and not rely on partners who could abruptly cut off digital access.
- The transition mirrors wider European scepticism towards Palantir, with Germany’s military dropping the firm and the UK reviewing its NHS and police contracts.
- Alongside this, France is investing €655m in domestic AI infrastructure and rolling out a civil service chatbot built on models from French startup Mistral AI to mitigate security risks.
International
Singapore proposes new generative AI data guidelines
- Singapore’s Personal Data Protection Commission proposed non-binding guidelines applying the Data Protection Act across the entire generative AI supply chain, focusing on accountability, transparency, and risk mitigation.
- Companies can scrape publicly available data without consent if the use is reasonable. Data behind digital barriers (like paywalls) requires a case-by-case accessibility check and, ideally, source notification.
- For data collected directly from users, general terms like “product improvement” are invalid. Organizations must provide explicit, AI-specific notifications to obtain proper consent.
- The guidelines emphasise data minimisation and safeguards. A public consultation is open until 1 July 2026, specifically seeking feedback on downstream transparency and agentic AI risks.
Canada proposes new AI privacy bill
- Canada has introduced Bill C-36 to modernise its 25-year-old framework and address digital risks like AI, deepfakes, and automated decision-making.
- The bill recognises privacy as a fundamental right, enhances protections for children’s data, and grants consumers new powers to demand data deletion and transparency.
- Private-sector oversight would shift to a new independent regulator, the Digital Safety and Data Protection Commission, which can issue binding orders and fines up to CAD 25 million or 5% of global revenue.
- While welcomed for boosting digital trust, critics have raised concerns over compliance burdens and the decision to replace the existing parliamentary oversight model without deeper public consultation.
For the latest updates on the University of Nottingham data breach, AI security restrictions, major cyberattacks, data-sharing initiatives, and global privacy regulations, visit our Data Protection News hub.



