ctipilot.ch

Home · Briefs · CTI Weekly Summary — 2026-W25 (Jun 15 – Jun 21, 2026)

Insider and process failures — Munich school data, a lost SSD, and an NHS records caution

From CTI Weekly Summary — 2026-W25 (Jun 15 – Jun 21, 2026) · published 2026-06-22

Several of the week's incidents were not external intrusions at all. Munich's municipal IT subsidiary is investigating ~120,000 student records suspected on the darknet, with a terminated employee under investigation (Heise, 2026-06-17; daily 06-17). The Kyushu Electric SSD loss (§ 4) was a physical-custody failure. And the UK ICO closed a two-year criminal investigation into deliberate misuse of Catherine, Princess of Wales' medical records at The London Clinic with a formal caution (ICO, 2026-06-19; daily 06-19). The common thread: privileged-insider and data-custody controls — offboarding, removable-media encryption, and access auditing on sensitive records — are as consequential as perimeter defence.