J. Craig Anderson reports: The names, addresses and Social Security numbers of roughly 2,100 Mainers who receive foster care benefits were accidentally posted to a public website in September, the Maine Office of Information Technology said Monday. The incident was the responsibility of an employee of a contractor, Knowledge Services, who still has a contract…
Category: Exposure
Fasten data leak: Nearly 1 million users’ sensitive data mistakenly exposed by US ride-hailing firm
India Ashok reports: Over one million users’ personal and financial data was inadvertently publicly exposed by US-based ride hailing firm Fasten. The leaked data includes names, emails, phone numbers, credit card data, links to photos, device IMEI numbers, GPS data and users’ taxi routes. The firm also exposed sensitive information of its own drivers, including…
Cook County Health and Hospitals System Patients Impacted by Experian Health Breach
HIPAA Journal reports: Cook County Health and Hospitals System, a health system comprising two hospitals and more than a dozen community health centers in Cook County Illinois, has alerted patients to a breach of their protected health information. The breach occurred at Experian Health, a business associate of Cook County Health and Hospitals System. Experian…
Security flaw may have exposed personal info on 21,000 Utah Express Pass users
Oops? Art Raymond reports: A vigilant UDOT Express Pass customer discovered a glaring security breach in the third-party website that manages pass accounts, but state officials don’t yet know if the personal information of approximately 21,000 current and former customers has been compromised. That information on customers who have purchased passes for accessing HOV lanes…
Eavesdropper: The Mobile Vulnerability Exposing Millions of Conversations
Michael Bentley writes: Appthority has discovered a significant data exposure vulnerability we’ve named Eavesdropper that affects almost 700 apps in enterprise environments. The vulnerability is caused by including hard coded credentials in mobile applications that are using the Twilio Rest API or SDK. By hard coding their credentials, the developers have effectively given global access…
Jaywing suffers data breach affecting CollectPlus, Vodafone and other clients
Jennifer Faull reports: Digital and CRM agency Jaywing has suffered a security breach after its intranet was exposed following a routine update, leaking private information from client CollectPlus as well as internal documents for Vodafone. The intranet – usually a depository for internal material like training manuals – underwent an upgrade on 17 September. However,…