Data Protection & AI

Data Breach: The Devil Never Sleeps

What Austrian companies can learn from the incident at a major US law firm

In May 2026, a caller at a US law firm posed as the firm's own IT department and induced an attorney to upload files to an external Google Drive account. No bypassed firewall, no zero-day vulnerability, no ransomware—just a phone call. According to subsequent lawsuits, the incident affected 57,554 current, former, and prospective clients, with leaked data reportedly including names, Social Security numbers, ID and passport numbers, bank and payment details, and health data. The firm stated that it detected the incident within approximately two hours and had the files deleted from the unauthorized account. However, it did not notify the affected individuals until five weeks later.

In early July, three class-action lawsuits followed, which the plaintiffs withdrew at the end of July due to a jurisdictional issue. This does not mean the matter is resolved. Just five days after the incident, the FBI had published a FLASH warning describing how a group of attackers has been specifically calling US law firms for years, posing as internal IT, and persuading employees to participate in a remote support session. Since the spring of 2026, the perpetrators have sometimes even appeared in person at the office. Whether the incident can be attributed to this group has not been publicly confirmed.

For Austrian companies, the case is instructive for two reasons. No IT budget failed here; rather, a human being did what they were politely asked to do. At the same time, the clock ticks differently in Europe, where five weeks to notify those affected would be a whole issue in itself.

Laptop is losing data

Table of Contents

When in the EU...

Article 4 (12) of the GDPR defines a „personal data breach“ (aka „data breach“) as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.

Uploading data to a third-party cloud account certainly falls under this.

To the data protection authority within 72 hours

As soon as the controller becomes aware of the breach, they must notify the supervisory authority—in Austria, the DSB—without undue delay and, where feasible, not later than 72 hours after having become aware of it. Exceptions apply to cases where the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons, which is almost never the case with customer data. The 72 hours do not constitute a strict deadline. Anyone who reports later must, of course, justify the delay.

Two points are regularly overlooked in practice.

  1. Phased notification: Article 33(4) GDPR allows subsequent notifications. Not all details of the incident have to be provided all at once—waiting for further information cannot justify an excuse for missing a deadline. A common mistake is reporting late and completely rather than on time and provisionally. Added to this is a point that hurts operationally: the 72-hour deadline does not recognize weekends; it runs continuously by the calendar. An incident confirmed on Friday afternoon must be reported by Monday afternoon. Many attackers time things accordingly, and not entirely by coincidence.
  2. Data Processing Agreement (DPA): As a rule, the service provider reports to the controller rather than the supervisory authority, and the controller's deadline begins upon receipt of the notification. What „undue delay“ means in Art 33 para 2 GDPR should be specified in the DPA. The EDPB recommends a specific number of hours and a designated contact point. Take a look at your contracts!

Information of those affected

If there is a likely high risk to the rights and freedoms of natural persons, for example because account, ID, or health data has been leaked, those affected must be informed without undue delay and in clear, plain language. This is the moment of maximum reputational risk and precisely the moment when most companies hesitate for too long. Blank Rome took five weeks; in Austria, that would require some explaining.

Article 34 paragraph 3 GDPR provides for exceptions, and one of them is the best argument for any encryption project that is currently stuck in the budget. If the affected data was effectively encrypted and the key has not been compromised, the notification of the data subjects is waived. The notification to the supervisory authority remains unaffected by this.

Drama, Baby, Drama!

The range of fines for violations of Articles 33 and 34 of the GDPR extends up to EUR 10 million or 2 % of global annual revenue (Article 83(4) of the GDPR). That is still the „moderate“ threat. Anyone who, in the same incident, has also violated Articles 5 or 6 of the GDPR—for example, because the leaked data should not have been processed (anymore)—will face the upper limit of EUR 20 million or 4 % of global annual revenue.

The understandable focus on fines often overshadows what other regulatory sanctions threaten and what other consequences a data breach can have. The far-reaching corrective powers of the data protection authority under Article 58 of the GDPR are frequently underestimated in risk analyses. The Austrian DPA can do much more than „just“ impose penalties: it can order controllers to adapt processing operations or, as its sharpest weapon, pronounce a temporary or permanent restriction of processing up to a complete ban on data processing (Article 58(2)(f) GDPR). For any company whose operational business relies on customer data, such a regulatory prohibition is tantamount to an operational cardiac arrest.

These official interventions are often flanked by massive reputational damage (especially if the incident is not handled professionally). The moment you have to explain to customers or business partners that their sensitive data has fallen into the wrong hands—possibly for avoidable reasons—represents a fundamental breach of trust. Such a damaged image in the market cannot be restored by an IT backup and often leads to permanent customer loss, the economic damage of which can in the long run even exceed the actual fine.

Damages and collective legal enforcement

This is where US law firms come in, and this is probably where the difference to the EU is greatest. Pursuant to Article 82 of the GDPR, any person who has suffered material or non-material damage as a result of an infringement has the right to compensation. Over time, the case law of the CJEU has somewhat shaped this provision, revealing a nuanced picture that cannot be pinned down in headlines. In principle, there is no de minimis or materiality threshold (CJEU C-300/21). Negative feelings such as worry or annoyance as a result of a loss of control can also constitute compensable non-material damage (CJEU C-655/23, Quirin Privatbank). Even the well-founded fear of future misuse is sufficient (CJEU C-340/21), whereas a purely hypothetical risk is not (CJEU C-687/21).

A mere violation is not sufficient for a claim for damages. The Austrian Supreme Court (OGH) has summarized the rule for Austria (6 Ob 113/24x): There must be a violation, a damage that has actually occurred, and causality between them, whereby the damage must be specifically demonstrated and unsubstantiated claims will fail. Article 82 GDPR serves a purely compensatory function; there is no US-style punitive damages. Furthermore, the degree of fault of the controller does not affect the amount of the claims. This puts the individual sum an affected party can receive into perspective, but it does not make a data breach risk-free from a damage law perspective. In the DACH region, mostly low three-digit to mid four-digit amounts are awarded, but multiplied by tens of thousands of affected parties (in the initial case: 57,554), this results in a figure that one must first be able to explain internally without suffering damage. Also to be factored into the risk assessment in this context is the burden of proof. In legal proceedings, it is the controller who must prove that the security measures were appropriate (Art. 5(2), Art. 24, Art. 32 GDPR, ECJ C-340/21).

Since July 18, 2024, a dedicated instrument has existed EU-wide, and thus also in Austria, for pooling such claims for damages: the representative action for redress (Sections 623 et seq. of the Code of Civil Procedure in conjunction with the Qualified Entities Act). A Qualified Entity—alongside the Chamber of Labour (AK) and the Consumer Information Association (VKI), this also includes organizations like noyb—can assert the pooled claims of at least 50 consumers before the Vienna Commercial Court; participation is by opt-in, and third-party funding is permissible. Austria is thus still a far cry from U.S.-style conditions. However, the infrastructure for class actions is in place and will certainly become more effective over time, thereby becoming a more relevant threat in the event of a data breach.

Soon another deadline regime will be added

Whoever believes that a GDPR notification is a sustainable solution has clearly turned a deaf ear to the topic of cybersecurity over the past few months. With the NISG 2026 (Federal Law Gazette I 94/2025), Austria is implementing the NIS 2 Directive, which has been widely discussed for years, roughly two years after the implementation deadline has passed.

Starting October 1, 2026, mandatory risk management and reporting obligations will apply to approximately 4,000 essential and important entities across 18 sectors, with even tighter timelines than those of the GDPR:

  • Early warning within 24 hours,
  • Notification within 72 hours,
  • Final report within one month (§ 34 NISG 2026).

The notification addressee is the newly created Federal Office for Cybersecurity (Cybersecurity Authority). When applying the NISG 2026, it is important not to get the following data wrong:

  • Effective October 1, 2026, the substantive obligations—namely risk management, governance (discussed below), and reporting obligations—will apply without any further grace period.
  • By December 31, 2026, registration with the cybersecurity authority will be added (§ 29), an administrative step that says nothing about the status of implementation.
  • By September 30, 2027, a structured self-declaration on the implemented risk management measures must then be submitted (§ 33). This final deadline is not an implementation deadline, but a reporting deadline. Anyone who only begins working in the summer of 2027 informs the authority in writing that they have been working illegally for eleven months.

For managing directors and board members, the regulations under the heading „Governance“ in Section 31 of the NISG 2026 (Article 20 of the NIS-2 Directive) represent a significant innovation. Management bodies must approve risk management measures, monitor their implementation, and complete training themselves. Cybersecurity is therefore definitively no longer an IT department issue, but rather a duty of care for executive management.

Practically speaking, two notification logics exist side by side, and they are not congruent. The GDPR ties into personal data, whereas the NISG 2026 ties into significant cybersecurity incidents. A case like Blank Rome would clearly be a data breach under the GDPR, but likely not a reportable incident under the NISG 2026. Conversely, a system outage at a company within the scope of application can be reportable solely under the NISG 2026 even without any data exfiltration. Anyone who pours both into a single process must query two thresholds and generate two different reports.

Therefore, in an emergency, reports must be made twice. And those not directly covered are frequently held to the same standards contractually through the supply chain obligations of their NIS-2-bound clients.

Conclusion

An excellent reputation protects neither against attackers nor against subsequent lawsuits. The GDPR does not demand error-free IT; it requires appropriate technical and organizational measures and functioning crisis management. One should not rely on the argument that a single employee simply failed. Fines directly affect the legal entity, even without a specific natural person being named. Within the scope of the GDPR, there is no room for Section 11 of the Austrian Data Protection Act (DSG) (warning instead of penalties) and Section 33a of the Austrian Administrative Offences Act (VStG) because EU law takes precedence (Federal Administrative Court [BVwG], Mar 24, 2026, W298 2323263-1). Anyone hoping for national mitigation mechanisms is therefore hoping in vain.

Anyone who can demonstrate measures, training, and a documented reporting process is in a significantly better position after an incident than someone who merely claims to have had bad luck. The difference costs a few days of work beforehand and often an order of magnitude more afterward.

Frequently Asked Questions (FAQs)

From when do the 72 hours start?

From the time the controller becomes aware. Awareness exists as soon as it is established with reasonable certainty that a security incident has led to a personal data breach. A short verification phase is permissible, but it must not become a delaying tactic. If a processor becomes aware, it must inform the controller without undue delay. According to EDPB Guidelines 9/2022, the controller's time limit then begins with the notification by the processor.

 

Must every data breach be reported?

No. The notification is not required if the breach is unlikely to result in a risk to the rights and freedoms of natural persons, for example in the case of a document sent to the wrong internal department without sensitive content. The incident must still be documented, including the justification for why it was not reported (Art. 33(5) GDPR).

 

When do we additionally have to inform the data subjects?

If there is a likely high risk, in particular regarding identity, account, health, or access data. The information must be provided without undue delay and in clear and plain language. It may be omitted under certain risk-mitigating circumstances (Art. 34(3) GDPR).

 

Is our company covered by the NISG 2026?

Sector and size are decisive. Covered are entities from 18 sectors that generally have at least 50 employees or more than 10 million euros in annual turnover or balance sheet total; a few activities are covered regardless of company size. The classification must be carried out independently; there is no official notification. Even those not directly covered should check whether NIS-2-obligated customers pass on the requirements via supply chain clauses.

 

What claims for damages can realistically be expected in Austria in the event of a data breach (based on previous experience)?

In individual cases mostly in the low three-figure to mid four-figure range, depending on the data category, intensity, and duration of the infringement. The claim requires concretely demonstrated damage; the mere violation is not sufficient (OGH 6 Ob 113/24x). The actual risk lies in the multiplication across a large number of affected parties and in the burden of proof, since the controller must prove the appropriateness of the security measures.

 

Are you prepared for the worst-case scenario, or are you already right in the middle of it?

ATB.LAW assists you with GDPR compliance, reviews your contracts with IT service providers, and stands by your side in an emergency, from reporting to the data protection authority to defending against claims for damages. Contact us before trouble knocks at your door. Contact Stefan Knotzer and Roman Taudes at any time under office@atb.law or by phone at 01 39 12345 for a non-binding initial consultation.

More articles

EU Commission CRA Guidelines

Cyber Resilience Act: EU Commission guidelines published

Get companies out of standby mode and into the fast lane for the CRA.
Picture of Stefan Knotzer
Stefan Knotzer

When the model sings: Copyright limits of AI training after the Suno ruling

Where AI & Copyright Hit a Sour Note
Picture of Stefan Knotzer
Stefan Knotzer
AI Act Transparency Guidelines

AI Transparency under the AI Act

What companies need to know about the new EU guidelines
Picture of Stefan Knotzer
Stefan Knotzer