A grand jury in the Southern District of New York indicted seven Iranian individuals who were employed by two Iran-based computer companies, ITSecTeam (ITSEC) and Mersad Company (MERSAD), that performed work on behalf of the Iranian Government, including the Islamic Revolutionary Guard Corps, on computer hacking charges related to their involvement in an extensive campaign…
Month: March 2016
Crooks Steal, Sell Verizon Enterprise Customer Data
Brian Krebs reports: Verizon Enterprise Solutions, a B2B unit of the telecommunications giant that gets called in to help Fortune 500’s respond to some of the world’s largest data breaches, is reeling from its own data breach involving the theft and resale of customer data, KrebsOnSecurity has learned. Earlier this week, a prominent member of a…
Elliot J. Martin Chiropractic notification to patients of HIPAA breach
Ah. I was waiting for an explanation of an entry in HHS’s breach tool about a Long Island chiropractic practice incident that impacted 1,200 patients. Here it is, below. I’m pleased to see that the doctor is now removing some identity information from the system. I wish more practices would do that. This Notice of Potential Breach of Personal…
When do covered entities need to report ransomware incidents to HHS?
At the PHI Protection Network conference last week, we spent a lot of time discussing the increasing rate of ransomware attacks. I asked a number of people whether they thought that ransomware attacks that (merely) locked up the data with no evidence of exfiltration had to be reported to HHS. I got a variety of…
Ontario hospital website may have infected visitors with ransomware, security firm says
Emily Chung reports: The website of an Ontario hospital may have infected the computers of patients and staff with ransomware planted on the site during a hack attack, the internet security company Malwarebytes warns. Norfolk General Hospital, located in Simcoe, Ont., confirms its website was hacked by cybercriminals, but denies that visitors were ever at risk. […] Jérôme Segura, a senior security researcher with Malwarebytes, reported in a blog…
AU: Hack attempt forces WA public transport systems offline
Allie Coyne reports: Western Australia’s public transport department has taken its websites and internal systems offline after detecting an attempted hack this morning. The Public Transport Authority, which runs the state’s trains, buses and ferries, shut down the websites for Transperth, RightTrack, School Bus Services, Get on Board and its own PTA website just before…