Nine to Noon reports: Inland Revenue’s data protection protocols are being questioned after a woman received information about a stranger’s child support in a copy-and-paste error. The Wellington woman got a letter from Inland Revenue addressed to her that included the full name of a father who was paying child support, and his child. She…
Category: Exposure
TX: Statement and Frequently Asked Questions about the 2018 ERS OnLine Security Incident
From the Employees Retirement System of Texas, this breach information notice. Note that this was reported to HHS with ERS listed as a health plan, and the breach was reported as affecting 1,248,263 members, but also note that no medical or health information was reportedly involved. On August 17, 2018, the Employees Retirement System of…
Work Study Documents Accidentally Released to College Community
Saadya Chevan reports: Last April, the College’s Financial Aid office uploaded and accidentally made visible to students, faculty, and staff two confidential documents containing federal work-study (FWS) balances of 107 students from two Spring 2018 pay-periods. The documents also reveal by implication that all of these students had applied for and received financial aid awards…
Tumblr’s ‘recommended blogs’ feature exposed user data
Julia Alexander reports: A security bug that hit Tumblr’s recommended blogs module may have exposed users’ private information, according to an open letter. Information like email addresses, passwords, IP addresses, and self-reported locations may have become exposed due to the bug if individual accounts were hit. It’s unclear if the bug affected individual accounts, according…
A Washington ISP exposed the ‘keys to the kingdom’ after leaving a server unsecured
Zack Whittaker reports: A Washington state internet provider left an unprotected server online without a password, exposing network schematics, passwords and other sensitive files for at least six months. Worse, it took the company a week to shut off the leak, despite several phone calls and emails warning of the exposure. The little-known internet provider,…
VA: Norfolk school parents notified of medical data breach
Sara Gregory reports: Norfolk school officials this week notified the parents of students and employees whose medical information was publicly disclosed in school crisis plans online for a year until August. After staff and attorneys reviewed the plans, the district identified a total of 308 students and staff who were referenced in the school crisis…