Sean Lyngaas reports: Halvor Molland was asleep on a brisk night in Oslo, Norway’s capital, two years ago when his phone rang around 3 a.m. The computer servers of Norsk Hydro, the global aluminum producer where Molland is senior vice president for communications, had seized up as a crippling ransomware infection spread through the company’s networks….
Category: Commentaries and Analyses
Phone numbers for 533 million Facebook users leaked on hacking forum
Catalin Cimpanu reports: A threat actor has published the phone numbers and account details for an estimated 533 million Facebook users —about a fifth of the entire social network’s user pool— on a publicly accessible cybercrime forum. According to samples reviewed by The Record today, the leaked data includes information that users posted on their profiles. Information…
Buying Breached Data: When Is It Ethical?
Jeremy Kirk reports: Security practitioners often tread a fine and not entirely well-defined legal line when conducting data breach research. This research can also pose ethical questions when commercial sources for stolen data fall into a gray area. Kirk’s article on DataBreach Today provides a good overview of the issue. And I totally agree with…
“Anonymous” tries to get this site’s post on MobiKwik censored
On March 30, DataBreaches.net posted an update to a controversial data breach that MobiKwik denies (previous coverage can be found here). The controversy subsequently escalated on Twitter when people started complaining that they had found their data in the leaked database and that it corresponded to what they had on file with MobiKwik. In addition…
A first in Canada: Class action over loss of personal information dismissed on the merits
Stéphane Pitre, Anne Merminod, Alexandra Hebert, Alexis Leray of BLG Law Firm write: On March 26, 2021, the Superior Court rendered a landmark judgment dealing with the loss of personal information, Lamoureux c. OCRCVM, 2021 QCCS 1093. Madam Justice Florence Lucas, J.C.S. dismisses the class action filed by the plaintiff, Danny Lamoureux in its entirety in…
Update: BioTel Heart notifies patients of vendor leak. Did vendor fail to notify them?
A cardiac monitoring firm is now notifying patients after a Google search on their name in January led them to an August, 2020 report on this site about a vendor’s leak. But why didn’t they know about it already from the vendor last year or from the notifications this site had sent them last year?…