Let’s start with Zippy’s notice, posted April 27 on their site: Notice to Customers of Payment Card Security Incident On March 9, 2018, Zippy’s Restaurants learned of a security incident involving its credit and debit card processing system. Zippy’s immediately began an investigation, and engaged independent computer forensic experts to assist. On April 4, 2018,…
Category: Breach Incidents
Access Group notifies borrowers of data security incident
It’s not just edtech vendors students need to watch out for when it comes to privacy and data security. Vendors that help process student loans may also put you at risk, as this notification from AccessLex Institute (dba Access Group) reminds us. The nonprofit organization, which provides financial education resources and services, writes: Dear [Name]:…
Careem knew – or should have known – that they had a serious problem last year: researcher
Mark Sutton has some follow-up commentary on the Careem breach reported on this site yesterday: Gregg Petersen of Veeam Software said that not alerting customers to the breach for so long “isn’t acceptable”, and that organisations need to work faster to maintain the trust of their customers. Jordanian cybersecurity expert Raed Nesheiwat also said that…
What led to Nova Scotia’s privacy breach
CBC News has an update to a government leak incident noted previously on this site. This is a case where the government’s response to their security failure was to criminalize the behavior of the teen who downloaded what were freely available reports. When the public went up in arms over the government’s attempt to cast him…
Illinois incorrectly mailed out personal information to more than 4,000 people
Bill Lukitsch reports: Personal financial and medical information of more than 4,000 people was mailed to the wrong addresses earlier this year, two state agencies announced Friday. “Notices containing personal information were mailed to 4,136 individuals at incorrect addresses,” a news release from the Illinois Department of Healthcare and Family Services and Department of Human…
Sangamo Therapeutics Says Co Announced A Data Security Incident Involving Compromise Of A Senior Executive’s Company Email Account
Reuters points us to an 8-k filing by Sangamo Therapeutics in California that discloses a data breach: On April 17, 2018, Sangamo Therapeutics, Inc. (the “Company”) announced a data security incident involving the compromise of a senior executive’s Company email account. Upon learning of the incident on March 28, 2018, external network security experts were promptly engaged,…