It is bad enough when an employee falls for a phishing scheme that exposes fellow employees’ W-2 information. It is downright painful when an employee of a payroll services vendor falls for a scam and emails every clients’ W-2 data to criminals. Sadly, that is what happened to Alpha Payroll Services LLC. Read my story on Daily Dot.
Category: U.S.
PA Court Rejects Healthcare Data Breach Class Action Lawsuit
Elizabeth Snell reports an update to a 2010 breach previously covered on this site: The Pennsylvania Superior Court recently dismissed claims in a healthcare data breach class action lawsuit, explaining that the trial court needs to review the plaintiff’s claim under the Uniform Trade Practices and Consumer Protection Law (UTPCPL). In the case Baum v. Keystone Mercy Health…
How the Pwnedlist Got Pwned
Brian Krebs reports: Last week, I learned about a vulnerability that exposed all 866 million account credentials harvested by pwnedlist.com, a service designed to help companies track public password breaches that may create security problems for their users. The vulnerability has since been fixed, but this simple security flaw may have inadvertently exacerbated countless breaches by preserving the data lost in them…
Two more colleges report compromise of employee W-2 info
Two more colleges have reported breaches involving employee W-2 data. I’m late picking the first one up, but it seems Allegheny College employees reported problems when filing taxes. On April 14, Angela Mauroni reported that at least 74 non-student employees of the Pennsylvania college had reported such problems. The college believes the information was accessed through the hacking…
Federal contractor with cybersecurity ties notifies employees after W-2 info acquired by targeted phishing
I’ve continued to add entities to my list of firms or entities where employee W-2 information was successfully phished by emails purporting to be from an entity’s executive. One notification I read this morning made me cringe because the firm that was successfully phished has contracts with the government involving mission critical systems for U.S. and coalition…
Vibrant Body Wellness notifies patients after burglar steals hardware with PHI
Seen on Vibrant Body Wellness: We were robbed! Literally. Yes, it’s sad but true — our office at Vibrant Body Wellness was broken into during the weekend of March 5th to March 8th. Things were stolen and no one was physically injured. We are grateful for that, and have been sorting through the violation and…