From the U.K.’s Information Commissioner’s Office (ICO): The ICO has fined Marriott International Inc £18.4million for failing to keep millions of customers’ personal data secure. Marriott estimates that 339 million guest records worldwide were affected following a cyber-attack in 2014 on Starwood Hotels and Resorts Worldwide Inc. The attack, from an unknown source, remained undetected until…
Category: Commentaries and Analyses
Pharma data breaches should stop once data protection law comes into force
Na Vijayshankar reports: Three major cyber attacks in the Indian pharma industry in the last few months have left people wondering whether there is a pattern indicating the reason for this spurt. First was the Breach Candy Hospital one in February 2020 where over 121 million medical records were compromised. Of these, 120 million were…
Federal agencies issue alert: credible information of increased and imminent threat of ransomware attacks on healthcare and public health sector
From a cybersecurity advisory that you need to drop everything and read and then react to proactively. Seriously. The summary alone should make you take note: This joint cybersecurity advisory was coauthored by the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Department of Health and Human Services (HHS)….
Russian Turla hackers breach European government organization
Sergiu Gatlan reports: Russian-speaking hacking group Turla has hacked into the systems of an undisclosed European government organization according to a new Accenture Cyber Threat Intelligence (ACTI) report. This attack perfectly lines up with Turla’s information theft and espionage motivation and its persistent targeting of government-related entities from a wide range of countries. Read more on BleepingComputer.
Aetna Pays $1,000,000 to Settle Three HIPAA Breaches
A new press release from HHS today reveals that multiple breaches in 2017 contributed to HHS finding significant problems with Aetna: Aetna Life Insurance Company and the affiliated covered entity (Aetna) has agreed to pay $1,000,000 to the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) and to…
An Interview with “UNKN” Sheds Light on REvil’s Operations & Future Victims
Yelisey Boguslavskiy writes: On October 23, 2020, a Russian-speaking tech blog YouTube channel “Russian OSINT” published an interview with one of the representatives of the REvil ransomware syndicate – “UNKN”/”Unknown”. A twenty-minute interview covers important subjects such as victims, tactics, and strategies employed by REvil. While some of the information shared by UNKN has already…