Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

Data Privacy Weekly: Your Industry News Series

success-story

Quick answer: This is the July 1, 2023 edition of Data Privacy Weekly. The biggest story this week: French ad tech firm Criteo was fined €40 million by CNIL, France’s data protection authority, for GDPR violations tied to non-consensual tracking cookies. Recommended action: audit your organization’s cookie consent flows against GDPR requirements before your next compliance review.

This week’s stories:

  • Criteo fined €40M by CNIL for GDPR violations tied to non-consensual tracking cookies (~370 million EU users affected).
  • iHealth Solutions (Advantum Health) pays a $75,000 HIPAA fine after a 2017 data exfiltration breach.
  • RateForce exposes driver’s licenses and insurance documents in an unsecured database.
  • NSA and CISA release joint guidelines for securing CI/CD pipelines.
  • Microsoft warns of rising Midnight Blizzard and APT28 attacks tied to Russian state-sponsored threat actors.

Published: July 2023. Updated: August 2026 (formatting and analysis refreshed; the news content below is an accurate historical record and has not been altered). Reviewed by Encryption Consulting’s Threat Intelligence team.

About this series: Data Privacy Weekly is Encryption Consulting’s ongoing digest of notable data privacy and security news, curated and summarized from third-party reporting. Catch up on the previous edition (June 18, 2023) or jump ahead to the next edition (July 12, 2023).

01. French Ad Tech Firm Fined with €40M for GDPR Breach

French ad tech firm Criteo has been fined €40 million by the French privacy regulator, CNIL (France’s data protection authority), for breaching the General Data Protection Regulation (GDPR). The company was found to have used website tracking cookies without users’ consent and failed to adequately inform users about how their data was being processed. CNIL’s investigation was prompted by complaints from civil rights organizations.

Criteo plans to appeal the fine, arguing that it uses pseudonymized and non-sensitive data in its activities and that CNIL’s claims are inconsistent with legal rulings. The violations are estimated to have impacted 370 million users in Europe.

Enterprise implication: Regulators are treating consent-banner design and cookie-disclosure language as core GDPR compliance, not a legal afterthought, and fines now scale with the volume of impacted users.

Recommended action: Audit your organization’s cookie consent banners and privacy disclosures against GDPR requirements, and review Encryption Consulting’s guidance on data sovereignty and regional compliance before your next audit cycle.

Criteo was fined €40 million by CNIL for GDPR violations involving non-consensual tracking cookies
Kentucky-based iHealth Solutions paid a $75,000 HIPAA fine after a 2017 patient data breach

02. Patient Information Compromised in Kentucky-based Firm’s Cybersecurity Incident

Kentucky-based firm iHealth Solutions, also known as Advantum Health, will pay a $75,000 fine under the Health Insurance Portability and Accountability Act (HIPAA) to federal regulators following a data exfiltration breach in 2017. The breach compromised patient information stored on an unsecured network server, affecting 267 individuals. The Department of Health and Human Services (HHS) found that iHealth had not conducted a comprehensive security risk analysis.

As part of the settlement, iHealth will implement a corrective action plan, including conducting a thorough security risk analysis and developing a risk management plan. HHS will monitor iHealth’s compliance for two years.

Enterprise implication: HHS enforced the requirement for a documented, comprehensive HIPAA security risk analysis years after the underlying breach occurred, meaning the missing analysis, not just the breach itself, drove the penalty.

Recommended action: Confirm your organization has a current, documented HIPAA security risk analysis, and see Encryption Consulting’s guidance on PKIaaS for regulated industries, including healthcare, for compliance-aligned controls.

03. Massive Data Leak Exposes Personal Details of Thousands from US Auto Insurance Comparison Site RateForce!

RateForce, a US auto insurance price comparison site, has suffered a massive data breach exposing the personal information of thousands of individuals. The breach involved an unsecured database containing scans and images of various documents, including driver’s licenses, insurance cards, and vehicle registrations. The breach was discovered by a security researcher who contacted the insurer, USA Underwriters, but received no response.

The researcher eventually managed to secure the database with the help of the insurer. The breach revealed that a third-party vendor, RateForce, was the owner of the compromised database, highlighting the risks associated with such vendors and the need for robust security measures.

Enterprise implication: The exposed database belonged to a third-party vendor rather than the insurer directly, underscoring how vendor and supply chain security gaps become an organization’s own breach liability.

Recommended action: Review third-party vendor contracts for mandatory database security controls and breach notification timelines before onboarding new data-sharing partners.

RateForce has suffered a massive data breach exposing the personal information of thousands of individuals.
The NSA and CISA have released guidelines to secure CI/CD environments against cyberattacks.

04. NSA and CISA Join Forces to Shield Your Software

The National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA) have released guidelines to secure CI/CD (Continuous Integration/Continuous Deployment) environments against cyberattacks. Recommendations include minimizing long-term credentials, implementing two-person rules for code updates, securing user accounts, enforcing least-privilege policies, adopting secure code signing, implementing network segmentation, conducting regular vulnerability scanning, and integrating security measures throughout the CI/CD pipeline.

These guidelines aim to mitigate unauthorized access, supply chain compromise, and code injection attacks. This follows a report by Kaspersky showing high malware infection rates in the industrial sector in 2022.

Enterprise implication: The joint guidance treats CI/CD pipelines as critical attack surface, meaning weak credential hygiene or unsigned code in a pipeline is now a compliance and security gap regulators and auditors expect organizations to close.

Recommended action: Review third-party CI/CD credential hygiene and code-signing practices against the new NSA/CISA guidance; see Encryption Consulting’s guidance on PKIaaS for internal developer platforms and CI/CD pipeline certificates.

05. Microsoft Sounds Alarm on Rising Russian Hacker Attacks

Microsoft reveals an increase in credential-stealing attacks by Russian hacker groups Midnight Blizzard (formerly Nobelium) and APT29, both Advanced Persistent Threat (APT) groups. Midnight Blizzard targets governments, IT service providers, NGOs, defence, and critical manufacturing sectors using residential proxy services to hide their IP addresses.

Despite being exposed in the SolarWinds compromise, they continue using undisclosed tools and techniques. APT28 conducts spear-phishing campaigns, exploiting vulnerabilities in Roundcube webmail software and a Microsoft Outlook zero-day flaw to target government and military entities in Ukraine.

Enterprise implication: Nation-state actors are increasingly routing attacks through residential proxies and exploiting known but unpatched software, so perimeter IP-reputation checks alone will not catch this activity.

Recommended action: Patch Roundcube and Outlook environments promptly, and add residential-proxy traffic patterns to your threat detection rules.

Microsoft reveals an increase in credential-stealing attacks by Russian hacker groups Midnight Blizzard (formerly Nobelium) and APT29

This Week at a Glance

StoryCategoryReal-World Impact
01. Criteo GDPR fineRegulatory enforcement (GDPR)€40 million fine; ~370 million EU users affected; Criteo plans to appeal
02. iHealth Solutions HIPAA fineHealthcare data breach (HIPAA)$75,000 fine; 267 individuals affected; two years of HHS monitoring
03. RateForce data leakThird-party vendor exposureDriver’s licenses, insurance cards, and vehicle registrations exposed in an unsecured database
04. NSA/CISA CI/CD guidelinesGovernment guidance (supply chain security)New joint federal guidelines for securing CI/CD pipelines industrywide
05. Microsoft Russian APT warningNation-state threat activityGovernments, IT providers, NGOs, defense, and manufacturing sectors targeted by Midnight Blizzard and APT28

Limitations

  • This edition is a curated selection of publicly reported data privacy and security news from around July 1, 2023, not an exhaustive record of every incident during that period.
  • All facts, figures, and quotes are sourced from the third-party outlets cited below; Encryption Consulting has not independently verified claims made by the original reporting organizations.
  • Fine amounts, affected-user counts, and case statuses reflect what was publicly reported as of the original publish date and may have changed since, for example through appeals or settlements.
  • This content is provided for informational purposes and does not constitute legal or compliance advice.

Frequently Asked Questions

What was Criteo fined for, and how much?

French ad tech firm Criteo was fined €40 million by CNIL, France’s data protection authority, for violating GDPR. Investigators found the company used website tracking cookies without proper user consent and failed to adequately disclose how visitor data was processed. Criteo has said it plans to appeal, arguing its use of pseudonymized data does not warrant the fine.

Why was iHealth Solutions fined under HIPAA?

Kentucky-based iHealth Solutions (Advantum Health) agreed to pay a $75,000 fine to the Department of Health and Human Services after a 2017 data exfiltration breach exposed information for 267 individuals. Investigators found the company had never conducted a comprehensive HIPAA security risk analysis. The settlement requires iHealth to complete a corrective action plan under two years of HHS monitoring.

What data was exposed in the RateForce leak?

RateForce, a US auto insurance comparison site, left an unsecured database exposing scans of driver’s licenses, insurance cards, and vehicle registrations. A security researcher discovered the exposure, initially received no response from insurer USA Underwriters, and later helped secure the database directly. The incident highlights the risk third-party vendors pose to consumer data, even when the vendor is not the primary brand.

What do the NSA and CISA recommend for securing CI/CD pipelines?

The NSA (National Security Agency) and CISA (Cybersecurity and Infrastructure Security Agency) jointly recommend minimizing long-term credentials, enforcing a two-person rule for code changes, applying least-privilege access, adopting secure code signing, segmenting networks, and running regular vulnerability scans across CI/CD (Continuous Integration/Continuous Deployment) environments to reduce supply chain and code injection risk.

More from Data Privacy Weekly

This edition is part of Encryption Consulting’s ongoing Data Privacy Weekly series. Read the previous edition (June 18, 2023) or continue to the next edition (July 12, 2023).

References