Home Blog Page 86

Here’s a Guide to the New Federal Student Loan Rules that Every Borrower Needs to Know

The federal student loan system is undergoing its biggest shift in decades. The One Big Beautiful Bill Act, signed on July 4, 2025, is transforming long-standing lending practices. As a result, new rules set limits on how much you can borrow and how repayment will work.

If you plan to borrow for school or already have loans, this guide explains the upcoming changes and their impact, helping you make informed decisions.

Quick Insights

  • Federal borrowing will no longer match the full cost of attendance. Parent PLUS and Grad PLUS are capped or eliminated, significantly changing how families and graduate students finance education.
  • A single income-driven plan (RAP) will redefine repayment. RAP sets a $10 minimum payment, uses a bracket system tied to AGI, waives unpaid interest, and extends forgiveness to 30 years, creating a very different repayment landscape.
  • Three major IDR plans are ending. SAVE, PAYE, and most versions of ICR will be phased out by 2028, prompting millions of borrowers to shift to RAP or a revised IBR plan.
  • Program classification will matter more than ever. Only a handful of “professional programs” qualify for higher borrowing limits, leaving many expensive degrees (such as nursing and social work) with lower federal borrowing caps.
  • Interest resumes for SAVE borrowers in 2025, new caps and RAP start in 2026, and major plan closures occur in 2028.

Before we dive into the new Federal Student Loan rules, let’s first recap the big picture and understand why this major shift is taking place. This context will help clarify the reasons behind the upcoming changes.

The changes to federal student loans stem from the One Big Beautiful Bill Act. This law marks a major break from the old system that many Americans are accustomed to: students and parents borrowing up to the full cost of attendance at almost any school.

The system offered flexibility to many families. However, it also pushed the debt levels higher year after year. So lawmakers argue that the system needs limits to keep borrowing in check and prevent balances from spiraling out of control.

As a solution, the Trump administration rolled out a new structure to reset federal lending. These changes focus on three major areas: loan limits (particularly on Parent PLUS and graduate borrowers), the Grad PLUS program, and the current mix of income-driven repayment plans.

The old framework stays mostly in place through June 30, 2026. After that point, the first wave of new rules goes into effect. Starting on July 1, 2026, new borrowers will face updated loan caps and a new repayment plan called RAP, while existing borrowers will shift more gradually. By July 1, 2028, most people in SAVE, PAYE, or ICR will move to RAP or a revised version of IBR. Once this shift is complete, the new system will become the new norm for nearly everyone with federal loans.

Now that you have the context, let’s look at one of the most important elements—borrowing limits. What are the new borrowing limits, and what can you actually get?

Undergraduate borrowing limits remain mostly unchanged, but parents and graduate students face reduced options. Previously, Parent PLUS and Grad PLUS loans allowed borrowers to borrow up to the full cost of attendance. With the OBBB, this is no longer an option.

Starting July 1, 2026, the maximum amount any parent or combination of parents can borrow is $20,000 per year and $65,000 total per student. That said, if you’re sending a student to a private university that charges $75,000 a year, you may be looking at an annual shortfall of $20,000 or more. This new reality will likely influence which schools you’ll consider for your child to attend, or fill the gap with private loans or savings.

For graduate and professional students, the change will hit much harder. Grad PLUS loans will end for new borrowing on July 1, 2026. In their place, the federal government sets fixed borrowing caps for graduate study:

  • Graduate students in non-professional programs can borrow up to $20,500 per year and $100,000 total.
  • Students in designated professional programs (medicine, law, dentistry, veterinary medicine) can borrow up to $50,000 per year and $200,000 total.
  • Across all degrees combined, the overall federal borrowing limit becomes $257,500.

Take note: the definition of “professional program” is critical here, as only a few specific fields qualify for the higher limits. Many expensive programs you might expect to be eligible for actually don’t. For example, nursing, social work, engineering, and most allied health programs fall under the regular graduate limits. Please check the Federal Student Aid website or your school’s financial aid office to confirm whether your program qualifies for the higher limit.

With borrowing limits clarified, it’s time to turn to another major update: the repayment system. What is the new repayment system (RAP), and what does it mean to you as a new or existing borrower?

RAP becomes the main income-driven plan for new loans issued after July 1, 2026. Instead of several plans, borrowers choose RAP or updated IBR. Existing borrowers will gradually move to RAP as other plans phase out.

RAP uses a bracket system based on adjusted gross income (AGI): you pay 1% to 10% of your AGI. There’s no protected income zone like the current plans.

  • You pay a set percentage of your AGI based on your income bracket. No portion of income is protected like in SAVE, PAYE, or ICR.
  • Divide the annual payment by 12 for your monthly amount.
  • Subtract $50 for each dependent child from the monthly amount.
  • The minimum payment is $10; there is no $0 payment option under RAP.

Example: Earning $25,000 places you in the 2% bracket. That’s $500/year, or about $41.67/month with no dependents.

If your payment doesn’t cover interest, the unpaid interest is waived. If less than $50 goes to the principal, the government makes up the difference. These features keep balances from ballooning.

RAP lasts 30 years (360 payments), after which any remaining balance is forgiven. This is longer than current income-driven plans.

After reviewing the RAP details, you may be familiar with repayment plans such as SAVE, PAYE, and ICR. As these are phased out, what should you know to prepare?

If you’re currently enrolled in the SAVE plan, you’re facing immediate changes. Due to legal challenges and policy reversals, the interest freeze that has protected millions of SAVE borrowers will end on August 1, 2025. Even if you’re among the 7 to 8 million people currently in forbearance with no interest accruing, that protection disappears in August.

By July 1, 2028, SAVE, PAYE, and most versions of ICR will no longer be available for ongoing use. Borrowers will move into RAP or the updated IBR plan. For borrowers working toward Public Service Loan Forgiveness, they will continue to earn credit under RAP, though plan changes may affect how their payments are counted.

Suggestion: If you’re in SAVE now, review your servicer’s full payment history and confirm your progress toward forgiveness. Then compare how IBR and RAP would affect you based on your income, household size, and loan amounts.

Here are some strategic plans that every borrower could apply

The new rules impact borrowers differently. More than ever, you must understand these changes and adapt to avoid surprises. Every borrower—whether preparing for college, in school, or repaying—needs a tailored plan as the system transitions.

Here’s what we suggest:

  1. For parents and high school students, step back and reassess how you build your college lists. Since Parents PLUS loans will no longer cover the full gap between aid and tuition, attending dream schools (even the most expensive ones) may no longer be realistic with federal loans alone. It’s a sad reality, but choosing a college now involves more than academic fit and application strength—price tags play a much bigger role than before. Students and families may need to rely more on school-based aid, in-state options, or private loans with stricter terms. So, running the numbers early is crucial, especially since past borrowing options will no longer be available.
  2. Current undergraduates have some time before the borrowing caps shift, but planning still matters. If you’re considering graduate school, you should carefully review your loan usage now. That’s because keeping undergraduate debt lower can free up private borrowing later, especially if you’re entering programs that fall under the $100,000 federal graduate cap. Planning early gives you greater flexibility once the new limits take effect.
  3. Graduate students, pay close attention to which loans fall under the old rules and which fall under the new system. Many will end up with a mix of both (we’re sure of that). Because consolidating loans can reset forgiveness timelines or change which repayment plans you qualify for, it’s essential to avoid consolidating automatically. Instead, review each loan separately and understand how consolidation could affect your long-term repayment path.
  4. Recent graduates should review their status under SAVE or another income-driven repayment plan. As SAVE winds down and interest resumes in 2025, payments may increase. This is a good time to compare what you would pay under IBR and RAP and consider which plan aligns with your income and long-term goals. Acting early can help you avoid any surprises during the transition.
  5. Parent PLUS borrowers face a more complicated path. RAP will not be available for Parent PLUS loans, and the only way to enter an income-driven plan is to consolidate into ICR and then switch to IBR. Because these steps require specific timing, make sure to map out your strategy now. Understanding the process ahead of time will help you avoid missed windows or repayment problems later.

Wrapping up and preparing for the new normal

The new rules signal a broader shift in how the government views the role of federal student loans. Lawmakers argue that unlimited borrowing has driven up tuition and placed too much risk on taxpayers. By setting firm limits, they hope to slow the rise in college costs and make the system more predictable.

Critics worry that the changes will put more pressure on middle- and lower-income families. They also warn that students may be discouraged from entering fields like nursing or social work, which require costly degrees but offer modest salaries.

Regardless of where you fall in this debate, it’s essential to adapt to the rules now in place. Keep a detailed record of your loans, including balances, interest rates, disbursement dates, servicers, and repayment plans. Set reminders for significant dates such as August 1, 2025, and July 1, 2026. Remember that the system you started in may not be the one you finish in.

This is one of the most significant shifts in federal student lending in a generation. With careful planning and an understanding of the new rules, you can navigate this transition with greater clarity and fewer surprises.

Education Department Recalls Laid-Off Civil Rights Staff as Complaint Backlog Grows

0

Key Takeaways:

  • The Education Department is recalling dozens of employees slated for layoffs. Still, former officials say this short-term move does not address the structural staffing shortage that created a backlog of more than 25,000 civil rights complaints.
  • More than 200 OCR staff members were targeted for layoffs, and seven of twelve regional offices were closed. As a result, thousands of families report months-long delays in discrimination investigations.
  • Even with recalled workers, OCR lacks a sustainable plan for managing both the existing backlog and the steady flow of new complaints covering disability rights, race discrimination, sexual harassment, and other civil rights issues.
  • The administration’s interagency agreements shift major education programs to other federal departments, but provide no clear explanation of where OCR’s enforcement responsibilities would be housed if the department is eliminated.
  • Pennsylvania lawmakers are moving to establish a state-level civil rights office amid eroding federal capacity. Civil rights groups warn that the restructuring plan (described by the NEA as “cruel” and “shameful”) risks leaving vulnerable students with fewer avenues for protection.

The Trump administration is bringing back dozens of Education Department employees who were marked for layoffs, saying they are needed to work through a surging backlog of civil rights complaints.

The staffers, most of them from the department’s Office for Civil Rights (OCR), have been on administrative leave since March while the administration defended mass layoffs in court. They have been ordered to return to duty on December 15 to help process discrimination cases that have now ballooned to 25,000 cases/complaints.

A department spokesperson, Julie Hartman, said the administration still intends to complete the layoffs but will use these employees while litigation continues. In a statement, she said the department would “utilize all employees currently being compensated by American taxpayers.”

The recall comes after months of deep cuts across the department, with more than 200 OCR staff members targeted in a reduction-in-force that also closed 7 out of the office’s 12 regional branches. Overall, the Education Department’s workforce has fallen from about 4,100 employees at the start of Trump’s term to roughly half that number today.

Those cuts have had visible effects.

Since Trump took office back in January 2025, the OCR has had about 20,000 open discrimination complaints. And for less than a year, that caseload has since climbed to more than 25,000, even as staff numbers have dropped. As a result, families that filed complaints about disability discrimination, racial bias, and other violations say they have waited months without any word from the federal government.

With so many positions gone, former OCR employees argue “the math does not work.” Accordingly, they claim that there is no realistic way for the office to work through tens of thousands of pending cases while also taking on new ones.

The OCR is responsible for enforcing federal civil rights laws in schools and colleges. It handles complaints involving students with disabilities, racial and religious discrimination, sexual harassment, and other issues. With this, the office can cut off federal funding to institutions that refuse to comply with the law, though most cases end in negotiated agreements.

Although the temporary recall may help move some cases forward, former officials and civil rights advocates say it does not solve the larger capacity problem. New discrimination complaints continue to reach the office each week, and staffing levels remain far below the levels needed to meet federal civil rights requirements.

Recent lawsuits describe OCR as a “hollowed-out organization” that can no longer fulfill its basic responsibilities, and national reporting shows that thousands of investigations have stalled as the remaining staff struggle to keep pace. Even with recalled employees back on the job, the office lacks a long-term plan for handling both the backlog and the volume of new cases that will follow.

Still no clear plan for OCR

The recall is taking place as the administration moves forward with a broader plan to dismantle the department. In November, Education Secretary Linda McMahon signed a series of interagency agreements that begin shifting major programs to other cabinet departments.

The Department of Labor is set to manage key K-12 grant programs, including Title I funding for schools that serve large numbers of low-income students. The Interior Department will oversee a wide range of Native American education programs, while selected international education and foreign language initiatives will move to the State Department.

Those moves do not answer a central question: where civil rights enforcement would sit if the Education Department were to shut down?

McMahon has argued that federal civil rights protections will continue in some form, even if the department disappears. In a recent opinion piece, she wrote, “Protecting students’ civil rights is work that will never go away. Yet, so far, the administration has not identified a new home for OCR’s functions or explained how it would maintain the same level of oversight with a smaller staff spread across multiple agencies.

This uncertainty has prompted some states to explore their own options. In Pennsylvania, state Senator Lindsey Williams has announced plans to introduce legislation to create a civil rights office within the state’s Department of Education. The bill would give the state authority to investigate and enforce federal and state education civil rights laws.

Williams represents a region that lost its federal OCR office this spring—the Philadelphia Regional Office, which was closed in March. Complaints from that region now go to the Atlanta office. Williams said cases/complaints “may or may not be heard,” and argues that the state should not rely solely on a weakened federal system.

The concerns are not limited to numbers. Critics say the administration has also changed OCR’s priorities.

In recent months, the office has opened investigations into race-conscious scholarships and diversity programs at colleges and universities, following guidance that warns institutions against race-based preferences in admissions, financial aid, and campus initiatives. It has also launched probes of school policies that let transgender students use restrooms and other facilities that match their gender identity, drawing on complaints and new directives from Washington.

These actions have continued even as thousands of long-standing discrimination complaints remain unresolved. Families whose children face disability discrimination or racial harassment in their schools say they are left in limbo while high-profile enforcement efforts move ahead in other areas.

Education and civil rights advocates warn that the temporary recall of staff may offer only short-term relief. Leaders of the National Education Association even called the broader restructuring plan “cruel” and “shameful,” arguing that shifting key programs to other agencies abandons students who depend on federal support. The American Civil Liberties Union has said that moving core education and civil-rights offices out of the department “guts the structure Congress established in 1979” to guarantee equal access to education.

The administration cannot abolish the department on its own—only Congress can. Several Republican senators have already voiced support for shutting down the agency and introduced bills to that effect. Those proposals would still have to clear both chambers and confront questions about who would enforce civil rights law in education and how long-standing programs for low-income students and students with disabilities would be managed.

For now, families with pending complaints are waiting to see whether the return of laid-off staff will translate into action on their cases. More than 25,000 complaints remain in OCR’s backlog. The department has offered no public plan for how it will move through that caseload. At the same time, it pursues its goal of dramatically shrinking, or eventually closing, the agency that was created to protect students’ rights in schools and colleges.

Greenville Ransomware Attack Underscores Urgent Need for Stronger Cybersecurity in US Cities

0

A recent ransomware attack on Greenville’s computer network has caused the city to lose access to police databases, utility billing systems, and other city services. City officials said the breach began on August 5 and confirmed that many of the systems remain out of service nearly a month later as recovery work continues.

According to city records, emergency dispatch and 911 services remain intact, but the attack has forced widespread workarounds in the city. However, the Greenville Electric Utility System, or GEUS, has paused late fees and disconnections since customers cannot reach their billing accounts online.

Residents are being asked to make payments in person. According to city officials, any amount paid above what is owed will be rolled into the next bill, while shortfalls will be carried forward.

Residents have also reported intermittent phone outages, according to statements released by the city. Greenville has filed a catastrophe notice with the Texas Attorney General’s Office, delaying the release of public records until systems can be restored.

Officials said about 20 outstanding records requests remain unfulfilled and may not be processed for several weeks, though some could become available as early as next Tuesday.

The attack has prompted Greenville to bring in outside help from cybersecurity experts and law enforcement agencies to assist in recovery. As of today, no ransom demands or stolen sensitive resident data have been disclosed. The city’s focus is on rebuilding access to essential records and restoring daily operations.

The recent attack on Greenville underscores the growing vulnerability of local governments nationwide as cybercriminals escalate their targeting of municipal systems. According to the security firm Emsisoft, more than 117 government entities were hit by ransomware attacks in 2024, with the actual number likely much higher because many incidents go unreported.

Analysts say municipalities are particularly at risk because they often depend on aging technology while operating with small cybersecurity teams. A report earlier this summer found that more than 80 percent of local governments employ fewer than five dedicated cybersecurity staff.

Human error, most often through phishing emails, remains one of the main points of entry. However, training programs have proven to reduce this risk dramatically, lowering susceptibility rates from one-third of employees to fewer than 5% after sustained exercises.

The growing cyber attacks on municipal systems have reached Washington and reignited debates over how to help cities defend themselves. Lawmakers are considering a requirement for ransomware incidents to be reported within 72 hours, a rule that advocates say could enable federal agencies to provide quicker aid and coordination. Some are also pushing for increased federal funding, pointing to the strain cities face as they attempt to maintain critical services with limited resources.

While Greenville’s predicament highlights the costs of falling behind, some experts argue that cities can no longer rely solely on reacting after a breach. This situation is prompting organizations to execute proactive measures like simulated cyberattacks on their own networks or “red team” exercises to expose weak spots before adversaries exploit them.

Cybersecurity specialists say municipalities, in particular, would benefit from such approaches because the stakes involve public safety, financial stability, and residents’ trust in government institutions.

The Greenville ransomware attack is a part of a broader story that carries implications far beyond one Texas community. The apparent truth is, cities of all sizes are increasingly being targeted, and the federal government is under mounting pressure to help local governments prepare before the next wave of attacks arrives.

Jaguar Land Rover Shuts Down UK Production After Cyberattack Disrupts Systems

0

Jaguar Land Rover was forced to shut down production and retail systems this week after a cyberattack disrupted operations at key UK sites, including the Halewood plant in Merseyside, the company said on Tuesday. JLR described the disruption as “severe” and confirmed it had taken systems offline as a precaution while it works to restore operations in a controlled manner. The carmaker said there was no evidence that customer data had been stolen.

The incident began as Britain’s “75-plate” registrations hit showrooms, among the busiest weeks of the year for dealers. Workers at Halewood were told early on Monday not to report for duty as the company enacted a protective shutdown across applications that support manufacturing and sales. Dealers reported they could not register new cars on Monday, compounding the timing problem during plate-change week.

A group of English-speaking hackers with links to the attack on Marks & Spencer this year claimed responsibility on Wednesday via a Telegram channel that combines the names of Scattered Spider, Lapsus$, and ShinyHunters. The channel posted a screenshot that appeared to show access to internal JLR systems. Britain’s National Crime Agency said it was aware of the incident and was working with partners to understand its impact.

Operational fallout has extended beyond JLR’s plants. Industry sources told The Guardian that suppliers, which make just-in-time deliveries to JLR factories, could lose tens of millions of pounds in sales if stoppages persist. The dealer network’s registration issues on Monday added pressure during a crucial sales window.

The company’s parent, Tata Motors, told investors JLR was “working at pace” to resolve global IT problems affecting the business. Tata Motors shares fell about 0.9 percent in Mumbai on Monday after the disclosure.

The attack lands as JLR is managing a challenging year. Underlying pre-tax profit fell 49 percent to £351 million in the quarter to June. The company delayed the launches of its electric Range Rover and next-generation Jaguar models until 2026 and announced up to 500 management job cuts in July.

PB Balaji, currently Tata Motors’ chief financial officer, is due to become JLR’s chief executive in November, succeeding Adrian Mardell, who is retiring. Earlier this year, JLR paused exports to the United States amid tariff uncertainty; a subsequent UK–US deal reduced those car export tariffs, but only after the quarter in which profits fell.

This incident is not JLR’s first run-in with cybercriminals this year alone. In March, hackers affiliated with the HELLCAT group claimed to have leaked internal material, including source code and employee details, which researchers later reported a second data dump by a separate actor. While those earlier breaches focused on data, the current episode underscores the operational stakes when attackers reach systems tied to production and retail.

JLR has invested heavily in its digital backbone. In September 2023, it expanded a five-year partnership with Tata Consultancy Services valued at more than £800 million to simplify and manage its IT estate and accelerate digital transformation. That outlay is now being tested by the demands of recovery and the need to harden the boundary between administrative networks and factory-floor systems.

The company said it is restoring applications in phases and declined to provide a timeline for full resumption of normal operations. As of Tuesday, it maintained that no evidence had emerged of stolen customer data, even as manufacturing and retail remained severely disrupted.

Hackers Turn Personal, Targeting Google’s Defenders

0

On September 2, a hacker group calling itself the Scattered LapSus Hunters threatened Google with a data leak unless two of its top security experts, namely Austin Larsen and Charles Carmakal, were fired.

The demand, made through the messaging app Telegram, is unusual. Hackers typically threaten companies, not individuals. By naming names, the group has shifted the battle from a corporate fight to a personal one.

Google has not confirmed whether its systems were breached, but the threat alone points to a troubling change in how cybercrime is carried out.

Mr. Larsen and Mr. Carmakal are well-known inside Google’s security ranks. Both work in the Threat Analysis Group, a team that investigates major hacking operations.

Mr. Carmakal, once the chief technology officer at the cybersecurity firm Mandiant before Google bought it, has helped companies respond to some of the most significant data breaches of the last decade.

On the other hand, Mr. Larsen is recognized for his work tracking groups like Scattered Spider, a collective blamed for attacks on airlines, video game makers, and technology firms.

For the hackers, targeting these two men is about more than removing obstacles. It is about making the fight personal, and in doing so, undermining the confidence of the very people responsible for exposing their methods.

The coalition behind the threat appears to be a mix of three groups: Scattered Spider, Lapsu$, and ShinyHunters. Each has a history of bold attacks.

Scattered Spider is known for tricking employees into giving up login details, sometimes by hijacking phone numbers through a technique called SIM swapping. Lapsu$, which gained attention in 2022, broke into companies including Microsoft, Nvidia, and Okta, and often bragged about its successes online. ShinyHunters was behind a 2023 breach of the cloud company Snowflake, which exposed data from hundreds of corporate clients.

In early August, members of these groups began posting under the joint name Scattered LapSus Hunters. On Telegram, they shared stolen information, issued taunts, and made demands.

The channel was later banned, but not before showing how hackers now combine technical skills with intimidation tactics meant to pressure companies into compliance.

The personal targeting of Larsen and Carmakal illustrates how the fight has shifted. Cyberattacks are no longer only about stealing information or disrupting services.

They are now about weakening the people who protect against them, raising the risk of harassment, reputational damage, and personal stress for those on the front lines.

Experts say this new phase of cybercrime means companies must do more than secure their networks. They must also protect their staff.

That could mean limiting how much personal information about employees is publicly available, using stronger authentication for logins, monitoring for leaked data, and offering legal and emotional support when threats arise.

For Google, the demand tests its willingness to stand by its security team. For the wider industry, it marks a turning point. Hackers are no longer only attacking companies. They are naming individuals, bringing a corporate struggle into the personal lives of the people sworn to defend it.

A Decade-Old Bug Still Haunts America’s Smallest Agencies

0

When the FBI issued a public warning in August about Russian hackers abusing a long-known flaw in Cisco devices, the message wasn’t aimed at Wall Street or big tech. It was meant for the kinds of organizations most people rarely notice—local utilities and regional authorities that keep everyday services running and often operate with thin budgets and aging gear. On the same day, Cisco’s threat-intelligence team published technical details that underscored the risk.

The campaign is attributed to a Russian state-sponsored group that security researchers call Static Tundra, which they link to the F.S.B.’s Center 16 unit and to the broader cluster known as Energetic/Berserk Bear. According to US officials and Cisco researchers, the group has spent more than a decade compromising network devices as a beachhead for long-term espionage.

At the center is CVE-2018-0171, a vulnerability in Cisco’s Smart Install feature. Left unpatched, it exposes devices listening on TCP port 4786 and can allow attackers to crash equipment, seize control, or plant code that persists across reboots. Many victims, investigators say, are running end-of-life hardware that never received updates.

The FBI says the actors have recently collected configuration files from thousands of US networking devices tied to critical infrastructure, in some cases modifying settings to enable unauthorized access and reconnaissance. Cisco reports similar activity worldwide, with particular focus on Ukraine and allied countries since the war began.

While the current wave is aimed at data collection and access, the tradecraft echoes earlier router compromises. Investigators have tied the group to historic use of “SYNful Knock,” a stealthy firmware implant first documented in 2015 that gives attackers durable control over Cisco routers.

US agencies and Cisco urge organizations to take basic but often under-resourced steps: apply patches or disable Smart Install, implement phishing-resistant multifactor authentication, segment networks so a single failure doesn’t cascade, and audit internet-facing devices for unexpected changes. For small public agencies with limited staff, those measures can be difficult to sustain—yet they remain the strongest defense.

Vendor Weak Link: Allianz Life Breach Puts Third-Party Security Under the Microscope

0

In mid-July 2025, hackers gained unauthorized access to a cloud-based customer-management system used by Allianz Life Insurance Company of North America. The company disclosed the breach later that month.

The incident ranks as a significant breach at a major US life insurer in recent years, affecting a broad cross-section of the company’s policyholders, financial advisers, and employees.

Company officials said the attackers infiltrated the third-party platform on July 16 and retrieved a large set of personal records. The files contained routine identifiers—names, home and email addresses, phone numbers, and dates of birth—and, in some cases, more sensitive details such as Social Security numbers and tax identification numbers. Security experts note that once such identifiers are exposed, they can be exploited indefinitely for identity theft and fraud.

After identifying the intrusion, Allianz Life reported the breach to the Federal Bureau of Investigation. The company says there is no evidence that its internal corporate systems, including policy administration platforms and network infrastructure, were accessed. Early findings indicate the exposure was confined to a third-party system, though the scale of the incident has drawn scrutiny from regulators and consumer advocates.

By early August, Allianz Life had begun notifying affected individuals and offering 24 months of credit monitoring and identity-protection services at no cost. Consumer advocates caution that the risks can extend well beyond any monitoring period, because Social Security numbers and similar identifiers cannot be replaced or revoked.

Independent researchers, including the breach-reporting service Have I Been Pwned, as reported by SecurityWeek, have verified the scale of the leak and revealed that 72% of exposed email addresses had already appeared in prior breaches. This overlap enables criminals to combine older data with newly exposed details, building fuller profiles of victims that make phishing more persuasive and fraudulent account openings harder to detect.

The Allianz Life case also underscores the growing risk posed by outside vendors in financial services. According to Verizon’s 2025 Data Breach Investigations Report, about 30% of breaches involved third parties. That pattern points to a structural weakness: firms can invest heavily in their own defenses yet remain exposed through partners and contractors on which they rely.

Thus, the attack has renewed calls for stronger oversight of supply-chain partners and wider adoption of Zero Trust security models, which assume that no user or system should be trusted by default. Analysts say these approaches can be costly but remain among the most effective ways to limit the impact of intrusions of this kind.

Allianz Life has filed breach notices with several state attorneys general, including Maine and Washington, and reviews are underway. The case is likely to give added momentum to state privacy measures and to renew calls for a single, nationwide data-security standard.

For Allianz Life, the breach represents not only a technical incident but also a reputational test. Trust sits at the center of life insurance and retirement planning, and a public loss of confidence can carry lasting consequences.

With IronCircle’s Move, Maryland Pushes to Build the Nation’s Cyber Talent Hub

0

On an August morning in Columbia’s Merriweather District, Governor Wes Moore joined IronCircle executives to cut the ribbon on the company’s new global headquarters. The move from Florida to Howard County is expected to bring more than 200 jobs, and for Maryland officials, it represents another step in shaping the state into a hub for cybersecurity.

The decision to relocate was partly driven by geography because Columbia sits within a short drive of Fort Meade, home to the National Security Agency and U.S. Cyber Command. That proximity, combined with a dense network of contractors and technology firms, has made central Maryland one of the busiest cyber corridors in the country.

With such a concentration of federal agencies and private firms, Maryland has seen a surge in demand for skilled workers. State figures show that more than 24% of information technology job postings in Maryland now require cybersecurity skills.

However, even with starting salaries exceeding $100,000, employers continue to struggle with hiring. Across the United States, workforce trackers estimate that more than half a million cyber jobs were listed over the past year, leaving gaps that affect not just corporations but also schools, hospitals, and even local governments.

IronCircle has built its business model around this shortage through its training platform. It utilizes artificial intelligence to simulate cyberattacks and adjusts the difficulty level based on the learner’s skills. IronCircle claims to bridge the gap between classroom instruction and the speed of real-world threats. From its new Maryland base, the firm plans to expand its workforce and increase opportunities for contractors, instructors, and institutions that already utilize its platform.

For Moore, the relocation aligns with a broader strategy. His administration has directed millions of dollars to community colleges to expand cyber courses, including funding for new training labs. It has also steered money to programs such as Cyber Maryland, which aims to connect schools, businesses, and government agencies in developing the workforce.

State leaders argue that investments like these are already paying off. Maryland has nearly 19,000 information technology businesses, generating about $80 billion in annual output and employing more than 124,000 people. Howard County alone is home to almost 300 cybersecurity firms, a cluster that provides students and professionals with a direct path from training to employment.

James C. Foster, IronCircle’s chief executive, has warned that the gap remains even as training programs multiply and salaries climb. Forster argued that the shortage of cyber talent is “growing by the year,” and with advances in technology continually raising the bar, new demands continue to emerge that even schools and companies struggle to meet.

Artificial Intelligence, for example, illustrates that tension. Although the tool is being used to train workers and strengthen defenses, it is also available to attackers. Britain’s National Cyber Security Centre has cautioned that AI is lowering the barrier for would-be criminals and is likely to drive a rise in ransomware within the next two years.

That dynamic has made workforce development both an economic and a security concern for the state of Maryland. A vacancy can leave a small business, a hospital, or a school system more vulnerable. Filling that role not only brings a paycheck but also adds to the state’s resilience at a time when nearly every part of the economy depends on secure networks.

IronCircle’s new headquarters is one piece of that puzzle. Its presence in Columbia reflects the state’s bet that building the workforce will bring jobs and also strengthen its role in defending against the next wave of digital threats.

Cybersecurity Turns Proactive as Companies Attack Themselves Before Hackers Do

0

Security leaders are rethinking the way they defend their networks. What used to be a system that was built solely on the defensive has evolved into a more proactive approach, with companies choosing to attack themselves first to expose weaknesses.

This “new idea” of securing networks was recently highlighted in a TechRadar Pro analysis that detailed a significant shift in how organizations think about cybersecurity. For decades, cybersecurity networks were built on a defensive approach: create walls, patch systems, and respond when intruders broke through.

Today, as attacks become faster and more sophisticated, many security teams are turning to controlled intrusions through staging their own red team exercises, automating penetration tests, and simulating exploits to determine weaknesses before criminals do.

And this approach is being driven by a new reality—AI.

Cyberattacks have not only grown in number in recent years but also in sophistication, with artificial intelligence powering everything from malware that adapts in real time to phishing emails that look indistinguishable from genuine communication.

While exact figures vary, the damage is rising. For example, average ransomware payments passed the million-dollar mark, more than twice the level of the previous quarter, according to ITPro. Investigators say the surge is less about one-off cases and more about a shift in tactics.

Criminal groups are leaning on AI tools to automate tasks that once slowed them down—writing convincing phishing messages, tailoring malware on the fly, and scaling campaigns that previously required large crews.

The speed and scale made possible by artificial intelligence are what alarm researchers most. They point out that the very tools helping criminals accelerate their operations could just as easily be placed in the hands of defenders. And that tension has led many in the field to call AI a double-edged sword. The same algorithms that allow attackers to scan entire networks for misconfigurations or generate new exploits in minutes can also be used by security teams to probe their own systems with equal intensity.

Academic studies have shown that AI can accelerate the discovery of weaknesses, but most experts caution against overstating precision metrics. What is clear, however, is that AI has collapsed timelines on both sides of the battle.

One instance is that the Cybersecurity and Infrastructure Security Agency has repeatedly encouraged critical infrastructure operators to adopt proactive security practices. In recent advisories, the agency pointed to red team assessments and the testing of AI models under stress as examples of methods that can strengthen resilience.

The Department of Homeland Security even went further in 2024 by publishing AI safety and security guidelines that urged operators to move beyond static defenses and treat cyber readiness as a continuous process.

For many security officers, the shift is not about abandoning traditional safeguards but about changing the timeline. Firewalls, detection systems, and antivirus software remain essential, but they are no longer seen as enough on their own.

The priority is to discover vulnerabilities during a drill, not in the middle of a crisis. The strategy, however, is not without complications. Misconfigured test environments can cause outages, and some organizations worry about blurring the line between a controlled simulation and a real-world breach.

Despite the risks, momentum is building. Analysts and industry experts believe that offensive testing, powered in part by AI, will move steadily into the mainstream. Within a few years, many expect it to be a standard part of security programs across both business and government.

What is emerging is a new kind of playbook. Security teams are no longer content to defend passively. Instead, they are trying to think like their adversaries, act first, and build systems that can withstand the next wave of attacks before it arrives.

New Mexico Colleges Take a $102 Million Blow as Federal Research Stalls, With Tribal Schools Bracing for Deeper Cuts

State officials in New Mexico say public colleges face about $102 million in losses from canceled federal research grants, stop-work orders, and delayed projects. The state Higher Education Department says the disruption is already affecting public colleges, special schools, and the University of New Mexico Health Sciences Center, with the heaviest losses at research-reliant campuses.

The New Mexico Institute of Mining and Technology faces the largest gap at $32 million, followed by New Mexico State University at $19 million and New Mexico Highlands University at $18 million. Stephanie Rodriguez, New Mexico’s higher education secretary, said her agency is tracking the impact on campuses and sharing the information with the governor’s office and the Department of Finance and Administration to inform decisions in the 2026 session.

The budget strain comes as the department conducts its annual capital outlay assessments through visiting campuses to review infrastructure needs ahead of funding decisions. This year, higher education institutions requested nearly $500 million for construction and repairs. Still, the department estimates only about $300 million will be available, which means many projects will be delayed even without the federal funding disruption.

Tribal colleges and universities in New Mexico and across the country are facing an even more acute threat. The administration’s fiscal year 2026 budget proposal would reduce operations funding for Bureau of Indian Education post-secondary programs from about $183.3 million to $22.1 million, an 88% cut that would take effect on October 1, 2025, if Congress enacts it. Those programs include career and technical schools, community colleges, and four-year institutions that serve Native students.

According to the American Indian Higher Education Consortium, tribal colleges depend on federal funding for about three-quarters of their operating budgets. Leaders have warned that if the proposal is enacted, some campuses could close, eliminating jobs and displacing students. At the Institute of American Indian Arts in Santa Fe, where roughly 80% of students are Native and 92 federally recognized tribes are represented, administrators have been working with New Mexico’s congressional delegation to preserve funding.

The funding debate comes against a backdrop of longstanding underinvestment in tribal higher education. A 2024 investigation by ProPublica and The Hechinger Report found that Congress underfunds the nation’s 37 tribal colleges by about $250 million each year compared with what federal law authorizes. The 1978 Tribally Controlled Colleges and Universities Assistance Act sets base funding at $8,000 per Native student, adjusted for inflation, but appropriations have rarely met that level. Advocates argue the shortfall undermines commitments tied to the federal trust responsibility to Native nations.

State and federal officials have not yet said how they will address the looming gaps. In Washington, a House panel advanced an Interior–Environment spending bill that provides overall funding for the Bureau of Indian Education but does not spell out post-secondary program levels. In Santa Fe, HED is feeding impact data to state budget officials as they prepare recommendations for the 2026 session, while college leaders say the outcome in Congress could determine whether some campuses can continue operating.