US Data Breach Reporting Transparency and State Notification Enforcement Gaps
The Identity Theft Resource Center (ITRC) reported a record 3,322 data breaches in the US last year, while noting that roughly 70% of breach notices lacked key incident details, limiting defenders’ ability to understand scope, root cause, and affected data. The reporting gap was attributed to inconsistent state breach-notification laws and uneven enforcement; while all states and several US territories require some form of consumer notification for certain PII exposures, only 34 states require breach reporting to state agencies. The ITRC also cited the PowerSchool incident as the largest US cyber incident of the year.
Separately, Blue Cross Blue Shield of Montana (BCBSMT) disclosed that up to 462,000 members may have been affected by a “cyber incident” at third-party vendor Conduent, and the matter is now trending toward litigation over whether the Montana State Auditor has authority to investigate under a new state breach-reporting law effective Oct. 1, 2025. BCBSMT argues the incident pre-dated the law’s effective date and that its notification to the auditor was a courtesy, while reporting also noted the apparent absence (as of publication) of a corresponding entry from BCBSMT or Conduent on the US HHS public HIPAA breach portal. A separate blog post about a purported “16 billion leaked credentials” compilation describes an aggregated infostealer-driven credential corpus rather than a single breach and does not materially relate to the US breach-notification transparency and enforcement issues described above.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
6 events from the most recent confirmed update back to the earliest known activity.
ITRC says 70% of breach notices lacked key details
The same report found that about 70% of breach notices omitted important incident information, attributing the transparency gap to inconsistent state laws, implementation, and enforcement.
ITRC reports record 3,322 U.S. data breaches in 2025
The Identity Theft Resource Center's 2025 Data Breach Report found that the United States recorded 3,322 data breaches in 2025, the highest annual total on record.
BCBSMT sues to challenge auditor's breach investigation
Blue Cross Blue Shield of Montana filed suit in Helena state district court, arguing that the Montana State Auditor lacks authority to investigate the breach and that the inquiry is unlawful.
Montana State Auditor opens investigation into BCBSMT breach
After the incident was reported to the Montana State Auditor’s office, the office opened an investigation into the Blue Cross Blue Shield of Montana data breach and related reporting obligations.
Conduent cyber incident exposes BCBSMT member data
A cyber incident affecting third-party vendor Conduent exposed data tied to Blue Cross Blue Shield of Montana members, with BCBSMT later stating that up to 462,000 members may have been affected.
Montana breach-reporting law takes effect
A new Montana data breach reporting law became effective, changing state notification requirements and becoming central to later questions about whether Blue Cross Blue Shield of Montana had to report the Conduent-related incident to the state auditor.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


