Doesn't the GDPR currently require companies to notify users about such attacks (does "personal data breach" also apply to client-side stored data)?
> When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.
> When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.
(Source: https://gdpr-info.eu/art-34-gdpr/)