Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
25 articles found · #nis-2 · Veille Luxgap
15 August 2026: the Dutch Cybersecurity Act (NIS 2 NL) has entered into force
As of 15 August 2026, the Dutch NIS 2 law (Cyberbeveiligingswet) applies. For groups in Luxembourg with activities or providers in the Netherlands, obligations now apply on both sides of the border.
DGFiP: 600,000 tax records for sale — warning on stealth exfiltration
On 14 August 2026, France’s Finance Ministry confirmed a DGFiP breach with over 600,000 tax records exported. A stealth exfiltration via a spoofed VPN, fueling targeted fraud risks.
PNLD: 135,000 police and partner contacts published on the dark web
The UK’s Police National Legal Database (PNLD) confirmed 1.9 GB of data was posted online: 114,000 PNLD subscribers and 21,000 “Ask the Police” users. The attack, claimed by ExfilSquad, was detected on July 26, 2026.
Liechtenstein: UBO register hacked (31,000 individuals affected)
Liechtenstein confirms data exfiltration from its UBO register (VwbP), affecting around 31,000 individuals. A stark reminder: these registers hold highly sensitive data that must be protected as critical assets.
Coca‑Cola/Fairlife: ransomware, production halt and data theft
Coca‑Cola confirms data theft following a ransomware attack against Fairlife. U.S. production was suspended mid‑July; the Anubis group claims up to 1 TB of data.
Secureholiday (Ctoutvert): 41,577 Dutch campers affected
Ctoutvert (Secureholiday) confirms a breach affecting 41,577 Dutch campers. No IBANs or cards leaked, but emails, phone numbers and stay dates exposed and used for targeted fraud.
Six weeks of downtime: German SME goes insolvent after cyberattack
On 14 July 2026, ZEGO (Aschaffenburg, DE) filed for insolvency after a March 29 cyberattack halted production for nearly six weeks—an explicit illustration of the operational cost of incidents for manufacturers.
KDDI: 12.23M emails and 7.62M passwords compromised
On July 7, 2026, KDDI confirmed unauthorized access to ~12.233M emails and ~7.616M passwords from its ISP email platform—an emblematic supply chain case with lessons for European companies.
Nextcloud: 367,000 records exposed (invoices, emails, scripts)
Cybernews reports an exposed Nextcloud ElasticSearch database with ~367,000 records (~8 GB) of staff and clients: invoices, emails, and scripts. The exposure was closed on May 27, 2026.
Medtronic notifies 3.8M+ people after data breach
Medtronic confirms an April 2026 intrusion exposed personal and health data. More than 3.8 million people have been notified since July 2, 2026.
ENISA issues Frontier AI recommendations for cybersecurity
On 7 July 2026, ENISA released an actionable report to help authorities, defenders and operators prepare for the Frontier AI era, aligned with NIS 2, the CRA and the AI Act.
Italy: €100,000 fine against Lepida over LepidaID shortcomings
Italy’s DPA fined Lepida S.c.p.A. €100,000 for GDPR violations in managing LepidaID (>1.5M users). Transparency, data minimization, and excessive log retention were flagged.