From the what-will-they-think-of-next department. Researchers at GeminiAdvisory.io have an interesting report out this morning about how criminals use donation sites to see if stolen card numbers are working. As a past victim of stolen card numbers, I am used to seeing fraudsters make small charges on the card just to see if it’s working. But I…
Author: Dissent
UK: Second MOD data breach uncovered putting safety of Afghan interpreters at risk
Lizzy Buchan reports that there was a second email gaffe that exposed additional Afghan interpreters. Once again, it seems, email addresses were visible to all addressees instead of being in the blind-copied fields. Some 55 people’s details were revealed, according to the BBC. The disastrous blunder comes after Defence Secretary Ben Wallace was forced to…
Illinois discloses breach involving access control to Illinois Integrated Eligibility System
KHQA reports that ten months after a data breach involving the Illinois Integrated Eligibility System (IES), the state is now disclosing the incident. But as I read the notice below, it seems like it was first discovered 10 months ago. When did this breach actually begin? From the state’s notice, republished on KHQA: Pursuant to…
NZ: Reserve Bank hit with compliance notice from Privacy Commissioner over data breach
Chris Keall reports: The Reserve Bank has suffered the ignominy of being the first organisation to be hit by a compliance notice under the new Privacy Act, which came into force in December last year. Privacy Commissioner John Edwards says an independent review carried out by KPMG after a December 2020 cyber attack “revealed multiple…
EU chief announces cybersecurity law for connected devices
Luca Bertuzzi reports: European Commission President Ursula von der Leyen announced on Wednesday (15 September) a Cyber Resilience Act aimed at setting common cybersecurity standards for connected devices. […] The Commission initiative adds to an existing proposal for a Directive on Security of Network and Information Systems, commonly known as the NIS2 Directive. NIS2 expands…
African Bank warns of data breach with personal details compromised
BusinessTech reports: African Bank has confirmed that one of its appointed professional debt recovery partners, Debt-IN, was targeted by cybercriminals in April 2021. At the time, expert security advice concluded that there was no evidence that the ransomware attack had resulted in a data breach – however, Debt-IN is now aware that the personal data…