It has now been about two years since I filed a complaint with the FTC to alert them to all the data security breaches involving Experian’s credit report database. And while I continue to wait to see the FTC take action against Experian over their numerous breaches involving misuse of clients’ login credentials, Experian…
Category: Commentaries and Analyses
2013 Exposed Records Sets the Stage for Massive Identity Theft
From Risk Based Security: We are pleased to release our Data Breach Quick view report that shows 2013 broke the previous all-time record for the number of exposed records caused by reported data breach incidents. The 2,164 incidents reported during 2013 exposed over 822 million records, nearly doubling the previous highest year on record (2011). Although overshadowed…
Hackers post hundreds of thousands of user credentials on web
Doug Drinkwater reports: Swiss infosecurity and computer forensics company High-Tech Bridge carried out the research recently and found that 311,095 user credentials – comprising log-in and password pairs – for various services, websites and emails have been compromised on Pastebin. Read more on SC Magazine. Interestingly, their analysis of data leaked on Pastebin does not suggest a…
What is “Expedient” Notification of a “Data Breach?”
Craig Hoffman and Charlie Shih write: One of the first questions companies ask us when we are hired to help them respond to a new security incident is how fast they have to notify if the investigation shows that a “breach” occurred. Except for a couple of states that require notification to occur no later…
Why otherwise adequate breach response plans may fail
One of the recurring themes by commenters on this blog is that they got a breach notification that offered them free credit monitoring services, but: 1. They can’t access the site they’re directed to; 2. They are alarmed that the site asks them for their personal information; and/or 3. They have no reason to trust…
South Korea regulator reaffirms harsher measures against card firms over data leak
Yonhap News reports that in addition to some stiff penalties imposed by its financial regulator on credit card firms who suffered data leaks, the government continues to look at ways to strengthen the protection of private data: In a report to the parliament, FSC chairman Shin Je-yun said the regulator plans to suspend the card…