
CyberWire Daily And the Breachies go to…
8 snips
Dec 24, 2025 Dive into the alarming world of data breaches exposed at the Electronic Frontier Foundation’s Breachies. Discover how companies mishandle data, like Mixpanel's vague disclosures and dating apps leaking sensitive biometric information. Learn about significant misconfigurations, such as Blue Shield’s analytics blunder and TransUnion's vulnerability through third-party apps. The podcast also humorously reimagines Christmas in a cybersecurity context with 'The 12 Days of Malware,' making complex topics entertaining and accessible.
AI Snips
Chapters
Transcript
Episode notes
Data Minimization Reduces Breach Harm
- Companies routinely collect and retain far more personal data than necessary, increasing risk when breaches occur.
- Data minimization would dramatically reduce the harm from many of the Breachies described.
Analytics Vendor's Vague Disclosure Backfires
- Mixpanel quietly collected user data for many apps and offered an unclear public disclosure after being breached.
- OpenAI dropped Mixpanel and disclosed details Mixpanel omitted, showing downstream impacts of vague breach statements.
Third-Party ID Collection Exposes Users
- Discord's age-verification data leaked via a breach at Zendesk, exposing selfies, IDs, and billing details.
- The incident shows that collecting IDs 'just in case' creates predictable, high-value targets for attackers.
