ABC News reports: Baltimore County Public Schools failed to act on several state recommendations to help mitigate cyber attacks before a hack disrupted school operations and cost the school system millions of dollars in damages and repairs, according to a report from a state inspector general. BCPS was hacked using a phishing email in November 2020 —…
Category: U.S.
IN: Wawasee Hit With Ransomware
David Slone reports: Wawasee Community School Corporation is dealing with a possible ransomware attack that began late last week. Ransomware is a type of malicious software that is designed to block access to a computer system until money is paid. According to a statement released to parents Friday, provided by Superintendent Dr. Steve Troyer to…
LastPass owner GoTo says hackers stole customers’ backups
Carly Page reports: LastPass’ parent company GoTo — formerly LogMeIn — has confirmed that cybercriminals stole customers’ encrypted backups during a recent breach of its systems. The breach was first confirmed by LastPass on November 30. At the time, LastPass chief executive Karim Toubba said an “unauthorized party” had gained access to some customers’ information stored in a third-party…
OK: Charged with sex crime, former Byng Public Schools employee had 200 community members’ images
Tres Savage reports: A former information technology professional at Byng Public Schools in Pontotoc County has been charged with three felonies for allegedly accessing a teacher’s personal Snapchat account, stealing her private nude photos and attempting to trade them for other nude photos with at least one district student. According to state law enforcement, Zachary…
TSA ‘no fly’ list leaked after being found on unsecured airline server
Chris Pandolfo reports: The Swiss hacker known as “maia arson crimew” blogged Thursday that she discovered the Transportation Security Administration “no fly” list from 2019 and a trove of data belonging to CommuteAir on an unsecured Amazon Web Services cloud server used by the airline. The hacker told The Daily Dot the list appeared to have more…
BlackCat adds NextGen to its leak site, but …. where did it go?
On January 17, BlackCat (aka ALPHV) added NextGen to their leak site. On January 19, DataBreaches sent an email inquiry to NextGen asking when they were attacked, whether files had been encrypted, and whether any employee data or patient data had been accessed or exfiltrated. NextGen responded promptly and then sent the following statement: NextGen…