Sindhu Ajay reports: The US Office of the Comptroller of the Currency, the Federal Reserve Board, and the Federal Deposit Insurance Corporation Friday proposed a new computer-security incident notification requirement for banking organizations and their bank service providers. The proposed rule would require a banking organization to provide its primary federal regulator a prompt notification of…
Category: Financial Sector
NEXA Mortgage sued over broker’s alleged data theft
James Kleimann reports: In a lawsuit filed last week, a mortgage brokerage claimed that one of its former loan officers stole a database containing client names and information and brought it with him to a new job at NEXA Mortgage. Smart Mortgage, which operates in Illinois, Indiana, Colorado and Florida, filed suit against former senior loan…
Investigation into Desjardins’ compliance with PIPEDA following a breach of personal information between 2017 and 2019
From the moment it was disclosed, it seemed clear that the Desjardins breach of 2019 that involved a rogue employee was going to cause big trouble for Desjardins. And sure enough, in one day, they were hit with two potential class action lawsuits. Desjardins subsequently announced they were expanding the mitigation services being offered, but…
Thai securities trading firm goes offline after cyberattack
It seems that yet another group of threat actors are trying the double-extortion method, replete with trying to get media coverage. “ALTDOS,” as they call themselves, contacted a number of news outlets in Thailand and online news sites to announce that they had attacked CGSEC on December 4. “A large Thailand SET public listed company…
River City Bank notifies customers after discovering insider wrongdoing
River City Bank had some explaining to do to customers. As described in their notification, a copy of which was submitted to the California Attorney General’s Office, the bank discovered a problem on September 29. An employee downloaded customer data to a personal storage drive and later sent it to a third party. The download…
Cayman Islands investment fund left entire filestore viewable by world+dog in unsecured Azure blob
Gareth Corfield reports: A Cayman Islands-based investment fund has exposed its entire backups to the internet after failing to properly configure a secure Microsoft Azure blob. Details of the fund’s register of members and correspondence with its investors could be freely read by anyone with the URL to its Azure blob, the Microsoft equivalent of…