<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>The Compliance Brief on TrustCenter</title>
    <link>https://trustcenter.ca/brief</link>
    <atom:link href="https://trustcenter.ca/brief/feed.xml" rel="self" type="application/rss+xml"/>
    <description>A free weekly email on the breaches, settlements and vendor failures that change what buyers ask in a security review, and what to have ready.</description>
    <language>en-CA</language>
    <item>
      <title>Ottawa is looking at how a breach was disclosed, not only how it happened</title>
      <link>https://trustcenter.ca/brief/8-patch-netscaler-then-read-the-labcorp-terms</link>
      <guid isPermaLink="true">https://trustcenter.ca/brief/8-patch-netscaler-then-read-the-labcorp-terms</guid>
      <pubDate>Tue, 29 Sep 2026 13:00:00 +0000</pubDate>
      <description>Ottawa is looking at how a breach was disclosed, not only how it happened. Canada&#x27;s federal privacy regulator opened an investigation into IDScan following a data breach. Your AI agents are logging in as humans and SOC 2 cannot tell. A vendor-authored piece argues that AI agents often operate through human credentials, so actions taken by an agent look identical to actions taken by the person whose credentials it borrowed.</description>
    </item>
    <item>
      <title>Revolut handed over customer data to someone pretending to be a government</title>
      <link>https://trustcenter.ca/brief/7-fake-government-requests-real-ai-attacks</link>
      <guid isPermaLink="true">https://trustcenter.ca/brief/7-fake-government-requests-real-ai-attacks</guid>
      <pubDate>Tue, 22 Sep 2026 13:00:00 +0000</pubDate>
      <description>Revolut handed over customer data to someone pretending to be a government. Revolut confirmed that an unauthorized party obtained customer information by submitting a fraudulent data request from a legitimate government email domain.</description>
    </item>
    <item>
      <title>Trezor&#x27;s supplier breach keeps growing, and it was never Trezor&#x27;s system</title>
      <link>https://trustcenter.ca/brief/6-revolut-handed-data-to-a-fake-government-request</link>
      <guid isPermaLink="true">https://trustcenter.ca/brief/6-revolut-handed-data-to-a-fake-government-request</guid>
      <pubDate>Tue, 15 Sep 2026 13:00:00 +0000</pubDate>
      <description>Trezor&#x27;s supplier breach keeps growing, and it was never Trezor&#x27;s system. Trezor says a breach at its supplier ShipMonk is considerably worse than first reported, now affecting around 81,000 customers. Revolut gave customer data to someone posing as a government agency. Revolut disclosed a breach after sharing customer data with a threat actor impersonating a government agency. Delaware amends its privacy and breach notification laws. On September 2, 2026, Delaware&#x27;s governor signed HB 380 and HB 381.</description>
    </item>
    <item>
      <title>Thomson Reuters court software breached in March, disclosed in September</title>
      <link>https://trustcenter.ca/brief/5-court-records-drivers-licences-and-an-ftc-bill</link>
      <guid isPermaLink="true">https://trustcenter.ca/brief/5-court-records-drivers-licences-and-an-ftc-bill</guid>
      <pubDate>Tue, 08 Sep 2026 13:00:00 +0000</pubDate>
      <description>Thomson Reuters court software breached in March, disclosed in September. Thomson Reuters disclosed that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing unit, in March 2026. McKesson tells the SEC it was hit through third-party applications. McKesson disclosed a cybersecurity incident in which attackers got into third-party applications and stole data, with the intrusion detected on August 25, 2026. An ID verification vendor appears to be the source of 153 million licence scans. A new dark web identity theft service is selling digital scans of more than 153 million driver&#x27;s licences belonging to people in the United States and Canada.</description>
    </item>
    <item>
      <title>McKesson breach came through third-party applications</title>
      <link>https://trustcenter.ca/brief/4-what-cisas-two-red-teams-say-about-your-soc-2</link>
      <guid isPermaLink="true">https://trustcenter.ca/brief/4-what-cisas-two-red-teams-say-about-your-soc-2</guid>
      <pubDate>Tue, 01 Sep 2026 13:00:00 +0000</pubDate>
      <description>McKesson breach came through third-party applications. McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. Two arrests in the TeamPCP open-source supply chain spree. The Australian Federal Police arrested two men in Western Australia, aged 21 and 23, over alleged membership in TeamPCP.</description>
    </item>
    <item>
      <title>SickKids gets hit through somebody else&#x27;s software</title>
      <link>https://trustcenter.ca/brief/3-a-cvss-10-in-entra-id-and-a-breach-that-grew-tenfold</link>
      <guid isPermaLink="true">https://trustcenter.ca/brief/3-a-cvss-10-in-entra-id-and-a-breach-that-grew-tenfold</guid>
      <pubDate>Tue, 25 Aug 2026 13:00:00 +0000</pubDate>
      <description>SickKids gets hit through somebody else&#x27;s software. Toronto&#x27;s Hospital for Sick Children disclosed a security incident that exposed personal information belonging to some current and former employees and job applicants. Defence contractors do not believe their own CMMC scores. US defence contractors are reporting doubts about the accuracy of their own self-assessment scores under CMMC Phase I.</description>
    </item>
    <item>
      <title>LexisNexis pulled products offline over a third-party vendor incident</title>
      <link>https://trustcenter.ca/brief/1-a-250-000-penalty-and-a-vendor-that-went-dark</link>
      <guid isPermaLink="true">https://trustcenter.ca/brief/1-a-250-000-penalty-and-a-vendor-that-went-dark</guid>
      <pubDate>Tue, 11 Aug 2026 13:00:00 +0000</pubDate>
      <description>LexisNexis pulled products offline over a third-party vendor incident. LexisNexis took several services offline, including Diligence and the Metabase API, in response to unusual activity on servers hosted and managed by a third-party vendor it has not named. New York fined a money transmitter for a weak program, not a breach. The New York Department of Financial Services announced that Order Express, a licensed money transmitter, will pay a $250,000 penalty for violations of the DFS cybersecurity regulation, 23 NYCRR Part 500.</description>
    </item>
  </channel>
</rss>
