Have I Been Pwned Hits 1000 Data Breaches, But Reveals a Worrying Reality
The service by Troy Hunt has just crossed the milestone of 1000 data breaches, exposing an uncomfortable reality: twelve and a half years after the launch of the platform, the notification times for data breaches have worsened. Despite the massive global adoption of high-profile privacy regulations, such as the European GDPR or the California CCPA, the handling of security incidents is increasingly moving away from transparency on the ground, favoring legal protection over timely user information.
The analyzed data leaves no room for doubt. The Carnival cruise line, which fell prey to the cybercriminal group ShinyHunters, saw the online publication of 8.7 million customer records, including 7.5 million email addresses and loyalty program data. A staggering 85% of this information was already present in the HIBP archive. The company formalized notification to the affected users only after a long 43 days from detecting the intrusion in their systems, justifying the delay with the need to conduct a complex internal analysis.
Legal defense prevails over user protection. The report by Troy Hunt reveals that, in the meantime, customers received official denials from support channels. A similar scenario involved the clothing giant Zara, also under attack by ShinyHunters, which took 45 days to admit the loss of 197,000 unique email addresses, customer support logs, and order details.
This delaying behavior responds to precise and calculated logic. The uncontrolled proliferation of class action lawsuits immediately following a breach pushes companies to adopt a posture solely focused on litigation. The goal becomes, in short, the protection of shareholders and the minimization of the risk of billion-dollar compensations, relegating customer security to the background. These are necessary compromises for companies, which skillfully exploit the loopholes offered by the same privacy regulations.
In a post published on his official blog, Hunt highlights how regulations impose mandatory notification only in the presence of a high risk to individuals' rights or extremely strictly defined sensitive data. Since information such as emails or support logs often does not fall into these special categories, companies choose legal silence. This way, the historical weaknesses of corporate cybersecurity remain uncorrected, leaving the burden of notifying exposed users on the web to independent services of proven technological reliability.