Well, folks, it's Tuesday, which means it's time for yet another company you've probably given your personal information to announce that hackers walked off with all of it.
This week's lucky winner is a household-name service that says "a limited number of customers" were affected, which is corporate-speak for "we have no idea how bad this is yet, but our lawyers suggested this phrasing." According to the company's official statement, which was clearly written by someone who gets paid by the word, the breach was discovered during a "routine security review." Translation: an intern noticed something weird, and three weeks later, after a series of increasingly panicked meetings, they finally told the public.
The stolen data reportedly includes names, email addresses, phone numbers, and for roughly a third of affected users, some combination of billing info and hashed passwords.
Security researchers who looked at the breach have already pointed out the obvious: the company was storing sensitive data in a way that would make a freshman cybersecurity student wince.
One expert described the setup as "a locked door with the key taped to it," which feels generous.
Another noted that the breach likely happened months ago and was only disclosed now because a mandatory reporting deadline was creeping up.
Nothing says "we care about your privacy" like waiting until the last possible second.
If you're wondering whether you're affected, the company has helpfully set up a website where you can enter your email address to find out.
Yes, the same email address that may or may not have been compromised.
No, they did not think through how that looks.
If you'd rather not hand over more data to the people who just lost your data, you can also just assume you're affected, because statistically speaking, you probably are.
Here's the part where I'm supposed to tell you to change your passwords, enable two-factor authentication, and freeze your credit.
But let's be honest about the bigger picture: this is the fourth major breach this year, and we're not even halfway through.
At some point, "change your password" stops being advice and starts being a coping mechanism.
The company is offering affected users a full year of free credit monitoring, which is the corporate equivalent of setting your house on fire and then handing you a small extinguisher.
It's something, but it's not nothing, and it's definitely not enough.
Meanwhile, executives will likely face zero consequences, the stock price will recover in a week, and we'll all be back here in a month talking about the next one.
Your data is out there whether you like it or not, and the companies holding it are treating security like a box to check rather than a thing to actually do.
Final Thoughts
Assume you're compromised, act accordingly, and maybe stop giving your phone number to every app that asks for it.