Chuck Miller reports: Three men have been arrested in Tallahasee, Fla., in connection with the Heartland Payment Systems data breach, authorities said. The men, Tony Acreus, Jeremy Frazier and Timothy Johns, each were charged with multiple counts of credit card fraud, police said. The arrests were part of a larger investigation into the breach, […]…
Category: Breach Incidents
More p2p fiascos
Rian from RedTeam Protection, a division of Tony Josephs and Sons Investigations Inc., just sent me another batch of p2p cockups that exposed personal — and in some cases — sensitive medical — information. In each case, RedTeam advised the entity and/or helped ensure removal of the filesharing application. Some of these breaches are more…
VA suspends contractor over patient data security
Adam Levine reports: The Department of Veterans Affairs has suspended a contractor for failing to follow the department’s policies for securing sensitive data about patients, the department said. A routine inspection revealed that a transcription contractor, with access to information including name, Social Security number and diagnosis, was using computers that did not follow guidelines…
UK: ICO takes enforcement action against Hastings and Rother PCT for data loss
From the press release (pdf) from the Information Commissioner’s Office (ICO): The Information Commissioner’s Office (ICO) has taken enforcement action against Hastings and Rother Primary Care Trust (PCT) following a breach of the Data Protection Act. This is the eighth time the ICO has taken enforcement action against an NHS organisation for breaching the Data…
Ca: Privacy commissioner may investigate City of Regina privacy breach
Joe Couture reports: Contrary to statements made by a City of Regina executive, the Office of the Saskatchewan Information and Privacy Commissioner has not yet decided whether or not to undertake a formal investigation into the breach of privacy announced by the city yesterday. Read more in the Leader-Post
UK: Busy Bees childcare voucher data leak plugged – Update
A UK child care voucher scheme has been taken off line after user Nick Gibbins found that the “web” application was exposing personal data for over one hundred thousand users. Gibbins found that the Busy Bees childcare voucher system was actually implemented using Citrix Metaframe, exporting the user interface from a Windows 2000 application to…