Catalin Cimpanu reports: Vulnerabilities known as IODR (Insecure Direct Object References) were found and fixed in Worldpay, an online secure payments platform, security researcher Randy Westergren reports. An IODR vulnerability is when users have access to information they should not see, either because it belongs to another user or originates from an account with higher privileges. In…
Category: U.S.
Former Energy Department worker sentenced in email ‘spear-phishing’ attempt
Spencer S. Hsu reports: A former Energy Department employee was sentenced to 18 months in prison after offering to help a foreign government infiltrate the agency’s computer system to steal nuclear secrets and then attempting an email “spear-phishing” attack in an FBI sting operation. Charles Harvey Eccleston, an environmental scientist formerly employed by the department…
More than 100 Randolph College employees report recent identity theft (Updated)
Tim Saunders reports: More than 100 people who work for Randolph College in Lynchburg have encountered problems this year while trying to file their tax returns. That’s because their personal information was stolen in what appears to be a data breach. […] As of Monday 103 people who work for Randolph have reported a recent…
FL Dept. of Health Palm Beach County Notification of Breach
From their public statement today: Florida Department of Health in Palm Beach County is issuing a public notice of an unauthorized disclosure and/or use of protected health information pertaining to some clients of its Health Centers. Federal law enforcement officials informed the department they had obtained a list of names, birth dates, social security numbers,…
Lamar County School District: 28 employees’ personal information exposed in data breach (UPDATED)
Jacque Masse reports on another breach that is linked to Innovak: Some Lamar County School District employees’ had their personal information compromised after an employee portal experienced a data breach. According to Lamar County Superintendent Tess Smith, the district uses a company called INNOVAK that allows staff to access their pay stubs and W2s through the…
Lessons from the Olympus Mortgage vs. Guaranteed Rate Case
Craig Nazarro of Baker Donelson writes about an insider breach case previously covered on this blog: Late last month a jury awarded Mount Olympus Mortgage Company (MOMC) more than $25 million for their claims against Guaranteed Rate (Guaranteed), which alleged Guaranteed along with other former employees of MOMC illegally transferred hundreds of loan files from…