A Persistent Problem
In 2026, Troy Hunt reached a significant milestone with his project Have I Been Pwned (HIBP) by recording its thousandth data breach. While one would expect that disclosure delays would improve due to regulations like GDPR and CCPA, the reality is more grim. Organizations often take weeks or even months to notify affected users. The question is simple: why does this delay persist?
Case Study: Carnival Corporation
Consider the recent case of Carnival Corporation. In April 2026, the company was targeted by the hacker group ShinyHunters. Approximately 8.7 million records were compromised, including names, email addresses, birth dates, and loyalty program details. Even after this information was made public, Carnival took 43 days to alert its customers.
This disclosure delay is not an isolated case. A Verizon report indicates that 27% of data breaches go undiscovered for months, and 50% of those discovered are reported with significant delay. Why do companies take so long?
Reasons for the Delay
1. Legal Complexity
Data protection laws, while essential, add a layer of complexity. Companies often have to navigate through a maze of local and international regulations before they can disclose a breach.
2. Image Concerns
Organizations fear the repercussions of bad press. Rapid disclosure can lead to a loss of customer and partner trust. This pushes some companies to downplay or delay the announcement of the breach, hoping to manage the crisis internally.
3. Ongoing Investigations
Before disclosing, companies often conduct investigations to understand the extent of the breach. This can be a lengthy process, especially if the IT infrastructure is complex.
Impact on Victims
The delay in disclosure leaves victims in a vulnerable position. Without information on the extent of the exposure, they cannot take necessary steps to protect themselves, such as changing passwords or monitoring for suspicious activities.
Towards Better Accountability
To improve the situation, companies need to adopt a more proactive approach. This includes setting up clear incident response protocols, improving internal communication, and collaborating with cybersecurity experts to expedite investigations.
Conclusion
Timely disclosure of data breaches is crucial to protect users. Companies must overcome legal and organizational hurdles to reduce disclosure delays. This requires a strong commitment to transparency and accountability.
Let's discuss your project in 15 minutes.