Updated March 15: This incident was reported to HHS on March 3 as affecting 35,068 health plan members, so it likely included former employees as well as current ones. DPS’s notice can be found on their website. Nate Lynn reports: Personal information belonging to some 15,000 Denver Public Schools (DPS) employees was stolen in what…
Category: U.S.
Another ransomware-related lawsuit settles: Preferred Home Care
Top Class Actions reports there is a settlement involving Preferred Home Care in New York. The lawsuit alleged the provider failed to protect employee and patient data from an attack in January 2021. The data breach allegedly compromised the information of 92,283 patients and employees, including sensitive health information and personal identifiers such as Social…
Oakland continues to work on recovery from ransomware attack; Play claims responsibility
As the City of Oakland continues to work to recover from a ransomware attack that began on February 8 and that resulted in the city declaring a state of emergency on February 14, the Play ransomware group has claimed responsibility for the attack. Play does not indicate how much data they acquired, but threaten to…
FTC Publishes Blog Post on Data Security Practices for Complex Systems
Caleb Skeath, Shayan Karbassi, and Ashden Fein of Covington & Burling write: In February, the Federal Trade Commission (“FTC”) published a blog post that elucidated key security principles from recent FTC data security and privacy orders. Specifically, the FTC highlighted three practices that the Commission regards as “effectively protect[ing] user data.” These practices include: (1) offering multi-factor…
Hackers steal gun owners’ data from firearm auction website
Lorenzo Franceschi-Bicchierai reports: Hackers breached a website that allows people to buy and sell guns, exposing the identities of its users, TechCrunch has learned. The breach exposed reams of sensitive personal data for more than 550,000 users, including customers’ full names, home addresses, email addresses, plaintext passwords and telephone numbers. Also, the stolen data allegedly…
Cyber Plan Would Hold Software Makers Responsible in Hacks
Katrina Manson reports: The Biden administration is set to release an aggressive new national cybersecurity strategy on Thursday that seeks to shift the blame from companies that get hacked to software manufacturers and device makers, putting it on a potential collision course with big technology companies. The 35-page strategy, shared in advance with a group…