Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
breach-disclosure-notificationcybersecurity-regulationthird-party-vendor-breachhealthcare-sector-threat

US Data Breach Reporting Transparency and State Notification Enforcement Gaps

Updated 3mo agoFirst seen Feb 1, 20262 sources

The Identity Theft Resource Center (ITRC) reported a record 3,322 data breaches in the US last year, while noting that roughly 70% of breach notices lacked key incident details, limiting defenders’ ability to understand scope, root cause, and affected data. The reporting gap was attributed to inconsistent state breach-notification laws and uneven enforcement; while all states and several US territories require some form of consumer notification for certain PII exposures, only 34 states require breach reporting to state agencies. The ITRC also cited the PowerSchool incident as the largest US cyber incident of the year.

Separately, Blue Cross Blue Shield of Montana (BCBSMT) disclosed that up to 462,000 members may have been affected by a “cyber incident” at third-party vendor Conduent, and the matter is now trending toward litigation over whether the Montana State Auditor has authority to investigate under a new state breach-reporting law effective Oct. 1, 2025. BCBSMT argues the incident pre-dated the law’s effective date and that its notification to the auditor was a courtesy, while reporting also noted the apparent absence (as of publication) of a corresponding entry from BCBSMT or Conduent on the US HHS public HIPAA breach portal. A separate blog post about a purported “16 billion leaked credentials” compilation describes an aggregated infostealer-driven credential corpus rather than a single breach and does not materially relate to the US breach-notification transparency and enforcement issues described above.

Share:
US Data Breach Reporting Transparency and State Notification Enforcement Gaps
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 30, 20265mo ago

ITRC says 70% of breach notices lacked key details

The same report found that about 70% of breach notices omitted important incident information, attributing the transparency gap to inconsistent state laws, implementation, and enforcement.

ITRC reports record 3,322 U.S. data breaches in 2025

The Identity Theft Resource Center's 2025 Data Breach Report found that the United States recorded 3,322 data breaches in 2025, the highest annual total on record.

BCBSMT sues to challenge auditor's breach investigation

Blue Cross Blue Shield of Montana filed suit in Helena state district court, arguing that the Montana State Auditor lacks authority to investigate the breach and that the inquiry is unlawful.

Montana State Auditor opens investigation into BCBSMT breach

After the incident was reported to the Montana State Auditor’s office, the office opened an investigation into the Blue Cross Blue Shield of Montana data breach and related reporting obligations.

Conduent cyber incident exposes BCBSMT member data

A cyber incident affecting third-party vendor Conduent exposed data tied to Blue Cross Blue Shield of Montana members, with BCBSMT later stating that up to 462,000 members may have been affected.

Oct 1, 20259mo ago

Montana breach-reporting law takes effect

A new Montana data breach reporting law became effective, changing state notification requirements and becoming central to later questions about whether Blue Cross Blue Shield of Montana had to report the Conduent-related incident to the state auditor.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Organizations
3 linked
Government TechnologyPowerschoolIdentity Theft Resource Center
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.