From Phishing Email to Wire Transfer: How Modern Social Engineering Actually Works
Arup and M&S look like different kinds of attacks on the surface — one a deepfake video call, one a ransomware breach. Underneath, they follow the same three-stage anatomy.
- The EU AI Act's High-Risk Deadline, and the Fight to Delay It
- Scattered Spider, DragonForce, and the Rise of Ransomware-as-a-Service
- DORA Turns Real: What 2026 Enforcement Actually Means for Financial Institutions
- Deepfakes Are a Legal Problem, Not Just a Technical One
- Why India's New Turnover-Based Licensing Rules Reshaped an Entire Compliance Industry
The Docket
All 20 briefs →From Phishing Email to Wire Transfer: How Modern Social Engineering Actually Works
Arup and M&S look like different kinds of attacks on the surface — one a deepfake video call, one a ransomware breach. Underneath, they follow the same three-stage anatomy.
The EU AI Act's High-Risk Deadline, and the Fight to Delay It
August 2026 was supposed to be the date the AI Act's toughest obligations landed. A year of negotiation over the Digital Omnibus has left that date in genuine doubt.
Scattered Spider, DragonForce, and the Rise of Ransomware-as-a-Service
The group behind the M&S attack doesn't write its own ransomware. It rents it — and the platform it rents from offers affiliates an 80% cut.
DORA Turns Real: What 2026 Enforcement Actually Means for Financial Institutions
The grace period for the EU's operational resilience regulation ended in 2025. This is the year supervisors stopped reviewing paperwork and started demanding proof.
Deepfakes Are a Legal Problem, Not Just a Technical One
The Arup fraud and cases like it are usually filed under cybersecurity. The harder questions they raise — evidentiary standards, corporate liability, verification duties — belong to lawyers as much as engineers.
Why India's New Turnover-Based Licensing Rules Reshaped an Entire Compliance Industry
A regulation change most consumers will never hear about quietly emptied out one of India's largest small-business licensing markets, overnight.
Seven Years, Over €7 Billion: What GDPR Enforcement Actually Looks Like in 2026
The regulation just passed another grim milestone in cumulative fines. The more interesting number is who is paying, and who is winning on appeal.
When a Fine Gets Overturned: The Amazon Annulment and Why Process Still Matters
A €746 million penalty being struck down on procedural grounds is not a defeat for GDPR — it's a reminder that even privacy regulators have to follow their own rulebook.
Consent Managers, Explained: India's New Middlemen in Data Protection
From November 2026, a new category of registered intermediary starts managing consent between individuals and the businesses that process their data. It has no close precedent in Indian law.
The UK's Data (Use and Access) Act: A Quieter Departure from GDPR
Royal Assent in June 2025 started a year of staged changes to UK data law. None of them are dramatic individually. Together, they mark the UK's first real divergence from the EU regime it inherited.
Written from inside compliance practice, not from the sidelines
Pillaraxis is written by Jefin Shaji, a law graduate working in regulatory compliance and increasingly the cybersecurity-related dimensions of client operations, alongside the Google Cybersecurity Professional Certificate. Each brief is grounded in verified reporting and primary regulatory sources, examined for what they mean for the people who have to comply.
More about this project →