Al Restar writes: Two popular cashback services have leaked nearly two terabytes worth of personally identifiable information (PII) and account data in an unprotected Elastic database. The two cashback websites have been operating mostly in the United Kingdom and India. Cybersecurity experts from the Security Detectives (sic) Research team discovered an unprotected Elasticsearch database containing at…
Category: Exposure
Report: MCMC ends contract with company after massive 2017 phone data leak
Azril Annuar reports: The Malaysian Communications and Multimedia Commission (MCMC) has terminated the services of a firm hired back in 2017 to protect the personal data of mobile phone users. Thus comes after the personal data of the users, including details such as MyKad numbers were reportedly leaked by the same company. Online portal Malaysiakini reported that…
UK: Patient’s private answerphone message became Devon hospital’s voicemail
Okay, this is a bit different as far as breaches go. Anita Merritt reports: A Devon hospital has apologised after a caller’s voicemail, containing personal patient details, became the hospital’s answerphone message for more than seven hours. During that time the caller was inundated with calls from patients giving details about their health problems believing…
Philly health department website exposed names of thousands of people with hepatitis
Nathaniel Lash reports: A public-data tool built by the Philadelphia Department of Public Health to track the prevalence of hepatitis infections left individuals’ health records accessible, compromising the names, addresses, Social Security numbers, and intimate health records of thousands of people receiving medical care in Philadelphia. The department learned of the breach Friday when an…
UK: ‘I feel violated’ – Hospital sends personal details of 11 patients to wrong address
David Hannant reports: A disabled mother-of-two says she feels violated after personal details about her sent by her hospital were delivered to the wrong address. Cireena Read, of Northrepps, was distraught when she opened a letter from the Norfolk and Norwich University Hospital informing her of the error, which saw personal and medical details about…
Waitematā DHB sent private mental health notes to wrong patient, inquiry launched
Hannah Martin reports: A mother who requested her son’s medical records claims she was also sent “fully identifiable” mental health notes about another patient. The Auckland woman, who Stuff has chosen not to name for privacy reasons, said Waitematā District Health Board’s error was a “completely unacceptable” breach of patient privacy. Read more on Stuff.