Times Now reports: The special task force of the Uttar Pradesh police has arrested four persons for allegedly stealing the credit card data of 50,000 users. The victims include both police and army officers some of whom were duped. The accused have been identified as Sanjit alias Sandeep, Baldev, Tapeshwar and and Gajendra, all of…
Category: Business Sector
Google says it stored some G Suite passwords in unhashed form for 14 years
Catalin Cimpanu reports: Google today revealed that a bug in an old G Suite tool has resulted in the company storing customer passwords in an unhashed — but encrypted — form for nearly 14 years, between 2005 and 2019. The company said that only G Suite enterprise customers were impacted, but not regular Gmail accounts….
Open Enrollment: How HCL Exposed Employee Passwords and Project Data
UpGuard reports: In the course of performing data leaks investigation on behalf of an UpGuard client, a member of the UpGuard Data Breach Research team discovered publicly accessible information belonging to technology services provider HCL. The public data included personal information and plaintext passwords for new hires, reports on installations of customer infrastructure, and web…
Millions of Instagram influencers had their private contact data scraped and exposed
Zack Whittaker reports: A massive database containing contact information of millions of Instagram influencers, celebrities and brand accounts has been found online. The database, hosted by Amazon Web Services, was left exposed and without a password allowing anyone to look inside. At the time of writing, the database had over 49 million records — but…
Louisville Regional Airport Authority hit by ‘ransomware’ attack
WDRB has only a short item on this, but reportedly no ransom has been paid and the airport is restoring from backup. Operations and security systems were reportedly not impacted.
Lithuanian watchdog issues first GDPR fine
Sam Clark reports: Lithuania’s data protection authority has fined a payments processing company for breaching three provisions of the GDPR. The State Data Protection Inspectorate has levied a €61,500 fine against fintech company MisterTango for inappropriate data processing, disclosing personal data and failing to report a breach, it said today. The authority said that the…