The Standard reports: Authorities are now mulling to introduce a law on cyber security and will strengthen communications with overseas agencies, said I&T minister Sun Dong following a recent hacking on Cyberport’s computer system. Some 400 gigabytes of data, including HKID card numbers, bank statements and resumes, was stolen and released on the dark web…
Category: Business Sector
Covington Client Intervenes in SEC Battle, Objecting to Disclosure of Identity
Abigail Adcox reports: A Covington & Burling client whose information may have been exposed in a 2020 cyberattack is insisting that its identity should not be disclosed to the Securities and Exchange Commission, which had sought out client names in a subpoena to the law firm. The client, following a subpoena battle between Covington and SEC,…
Law Firm Accused of Waiting More Than a Year to Inform Affected Parties About Data Breach
Riley Brennan reports: Los Angeles-based law firm Hill, Farrer & Burrill was slapped with a data breach class action over allegations it detected a data breach in March 2022 but waited over a year to inform affected individuals their personal information had been leaked. […] According to the complaint, Hill Farrer determined that cybercriminals gained…
Sweden’s Privacy Protection Agency fines insurer Trygg-Hansa for exposing sensitive customer data
The following press release was issued August 30 by Sweden’s Authority for Privacy Protection (IMY): Trygg-Hansa’s security flaws have meant that information on 650,000 customers has been accessible via the internet. The Privacy Protection Agency (IMY) is now issuing an administrative sanction fee of SEK 35 million against the company. After receiving a tip, IMY began…
Personal Data Protection Commissioner of Singapore announces two decisions
The Personal Data Protection Commissioner of Singapore (PDPC) announced two decisions this week: A financial penalty of $3,000 was imposed on Autobahn Rent A Car for failing to put in place reasonable security arrangements to protect the personal data in its possession or under its control. Directions were also issued to strengthen access control measures…
BlackCat ransomware hits Azure Storage with Sphynx encryptor
Sergiu Gatlan reports: The BlackCat (ALPHV) ransomware gang now uses stolen Microsoft accounts and the recently spotted Sphynx encryptor to encrypt targets’ Azure cloud storage. While investigating a recent breach, Sophos X-Ops incident responders discovered that the attackers used a new Sphynx variant with added support for using custom credentials. Read more at BleepingComputer.