Same scam, opposite verdicts
Two companies lost customer data to someone pretending to be IT support. One was cleared, the other was fined €1.7m. The attack wasn't the difference.
Two regulators ruled on the same attack this week and reached opposite conclusions. In Australia, someone phoned a Qantas call centre pretending to be IT help and walked out with millions of customer records. The regulator closed the file. In Italy, people posing as support technicians talked their way into Wind Tre's systems through two retail shops. The Garante fined the company €1,715,600. The attack was essentially identical. What separated them was what each could show.
You can lose 5.7 million records and still comply
On 16 July, Privacy Commissioner Carly Kind closed preliminary inquiries into the 2025 Qantas breach without opening a formal investigation. A threat actor posing as "Qantas IT help" called the contact centre and talked an agent into connecting a customised Salesforce Data Loader to the CRM, then extracted roughly 5.7 million customer records. The OAIC assessed Australian Privacy Principles 1, 8 and 11 and found no contravention.
Kind's reasoning is worth reading twice: "in this instance I do not consider that the evidence supports the likelihood that a breach of privacy law occurred." The regulator found Qantas had addressed the risk and moved fast to contain and disclose, and noted the tactic was a rare one standard training does not usually cover. The finding is provisional, and a formal investigation remains available.
Why it matters: the test was never "did you get breached". It is whether you took reasonable steps. A big number in a headline is not a finding of fault.
What to do: what saved Qantas is what most teams cannot produce on demand. Not a control that worked, because the control did not, but evidence of the assessment, the decision, and the response. If your answer to "what reasonable steps did you take" lives in someone's memory, you do not have an answer.
What failing the same test looks like
The same day, Italy's Garante fined Wind Tre €1,715,600 over two unauthorised accesses that exposed data on more than 365,000 customers. For 41,359 of them, payment details went too: postal payment slips, IBANs, and partially masked card numbers with expiry dates. The company notified in February 2025.
The findings are where the contrast bites. The Garante said Wind Tre failed to adequately manage access credentials and digital certificates, and that its own security checks did not surface vulnerabilities a more thorough assessment would have found. It ordered better credential and certificate protection, and secure password management tooling.
Why it matters: side by side, these two decisions make "reasonable steps" clearer than any guidance document does. Qantas was hit by a tactic the regulator accepted was unusual, and could show it had done the work. Wind Tre was hit through a weakness its own testing should have caught. Only one became a fine.
What to do: look at what your security testing actually covers, specifically whether it would find the things you already suspect are weak. A test that never fails is not evidence of strength. It is evidence of a test that was not looking.
A Chinese open-weight model just landed at the frontier
Moonshot AI launched Kimi K3 on 16 July, a 2.8 trillion parameter mixture-of-experts model with a one million token context window. It sits just behind GPT-5.6 Sol and Fable 5 on the Artificial Analysis Intelligence Index and beats both on Arena.ai's front-end development leaderboard. API pricing is $3 per million input tokens and $15 per million output. The weights are not out yet: Moonshot promised release by 27 July, so treat the "open" part as a commitment, not a fact.
Why it matters: if a frontier-grade model becomes downloadable in ten days, the assumption that serious AI arrives through vendor contracts stops holding. Weights you run yourself come with no DPA, no sub-processor list, and nobody to ask about training data. Self-hosting can be the privacy-preserving choice. It just moves every obligation onto you.
What to do: check whether your AI policy assumes a vendor sits between you and the model. If it does, decide now what you would require before someone runs downloaded weights on your own infrastructure. That request is coming.
Apple sues OpenAI, and the trade secrets left on a laptop
Apple sued OpenAI on 10 July in the Northern District of California, naming OpenAI, chief hardware officer Tang Tan, and former Apple engineer Chang Liu. Apple claims Liu kept an Apple-issued laptop after leaving, used it to download confidential technical documents, and passed information to other Apple staff applying to OpenAI. Tan, who spent 24 years at Apple, allegedly used confidential project code names while recruiting and coached departing employees on getting round security procedures. OpenAI: "We have no interest in other companies' trade secrets."
Why it matters: strip out the two famous names and this is an offboarding story. A device never recovered, access that outlived employment, information that left on a hard drive. These are allegations and Apple has to prove them, but the mechanism described is the most common way confidential data leaves any company, and no amount of model-layer security touches it.
What to do: pull your leaver process and check the boring parts. When does access actually get revoked, who confirms the device came back, and can you evidence both. If Apple's asset recovery can allegedly miss a laptop, yours can.
Also worth your time
Mozilla tested six period trackers and found Stardust was the only one sharing health data with a third party: birth control type and symptoms, tied to an identifier rather than a name. Per the EDPB's draft anonymisation test, if you can still single out, link or infer, it is personal data. A vendor contract does not change that.
The Seventh Circuit rejected the Clearview AI settlement that would have handed the class a 23% equity stake, over unequal shares across state subclasses. The biometric scraping case is live again.
Thalha Jubair, 20, and Owen Flowers, 18, were each sentenced to five and a half years at Woolwich Crown Court for hacking Transport for London.
EDRi and 36 other organisations urged the Commission to reassess EU-US adequacy after Trump v. Slaughter.
New Hampshire amended the NHDPA to ban the sale of personal data of under-13s.
EFF found most smart watches, rings and bands lack basic transparency reporting. Ireland's NCSC issued cyber governance guidance for boards ahead of NIS2 implementation, and FPF published an issue brief on cross-border transfers in ASEAN.
The through line this week: nobody was punished for being attacked. They were punished, or not, for what they could show about the day before the attack.
If this was useful, restack it for someone who would sleep better after reading the Qantas decision, and subscribe for next week's.
— Abhishek
_Not legal advice. Talk to your own counsel for that._

