Doug Levin kindly alerted me that the Hartford Courant has a story on the Total Registration data security incident. … The school officials said that Total Registration, used by the district to register students for certain exams, informed them that certain information provided by students including name, grade level, gender, date of birth, address, email…
Category: U.S.
Seven months after learning of a breach, UCSD still has not notified HIV research participants whose privacy was breached
Brad Racino and Jill Castellano report on what sounds like either willful or negligent handling of highly sensitive information of research participants bu a non-profit participating in some university-funded research. In either event, the university was notified of a breach in October and STILL hasn’t notified the research participants with HIV whose data was available…
OKCPS confirms ransomware cyber-attack
Lili Zheng reports: Oklahoma City Public Schools have confirmed they are addressing a recent ransomware attack, compromising the district’s network. On Monday, OKCPS stated their network was “significantly compromised by a form of malware” and that the issue was “continuing to worsen.” Early Tuesday evening, an updated statement from the district confirmed that ‘form’ of…
Equitas Health notifies 569 members after discovering two employee email accounts had been compromised
Equitas Health, Inc. (“Equitas Health”) learned that it was the victim of a data incident and is notifying individuals whose information may have been affected. On January 8, 2019, Equitas Health became aware of unusual activity within an employee’s email account. Equitas Health conducted an internal investigation which revealed that an unauthorized individual had access…
Paterson Public Schools hacked, but when, and where are the data now? (UPDATE 1)
Jayed Rahman reports that Paterson Public Schools in New Jersey was hacked. The attacker allegedly acquired 23,103 account passwords and other computer access tokens. Information stolen in the breach includes desktop logins, email usernames and passwords, and laptop credentials. For example, the email usernames and passwords of all school district employees — including that of…
Twitter discloses a bug impacting collection and sharing of location data on iOS devices
Twitter’s online Help section has the following notice: You trust us to be careful with your data, and because of that, we want to be open with you when we make a mistake. We have discovered that we were inadvertently collecting and sharing iOS location data with one of our trusted partners in certain circumstances….