Benjamin Freed reports: A school district in Coventry, Connecticut, notified families of its students this week that students’ data may have been swept up in a breach of one of its vendors earlier this year. The breach-notification letter, dated Tuesday, stated that data belonging to the roughly 1,700 students enrolled in Coventry Public Schools may have…
Category: Hack
Scott County, Iowa discloses data security incident
Seen on the county’s website, dated April 22, 2022: Notice of Data Privacy Event Scott County, Iowa (“Scott County”) is providing notice of a data privacy event. To date, we have no evidence of actual or attempted misuse of information as a result of this incident. In an abundance of caution, we are notifying potentially…
GitHub: Attacker breached dozens of orgs using stolen OAuth tokens
Sergiu Gatlan reports: GitHub revealed today that an attacker is using stolen OAuth user tokens (issued to Heroku and Travis-CI) to download data from private repositories. Since this campaign was first spotted on April 12, 2022, the threat actor has already accessed and stolen data from dozens of victim organizations using Heroku and Travis-CI-maintained OAuth apps, including…
Contra Costa County Employee Email Accounts Hacked In Data Breach
Be forewarned: the news story misspells”breach” as “breech.” I couldn’t bring myself to use their headline so fixed that, but am leaving this: Contra Costa County officials have begun sending out letters this week to potential victims of the “unauthorized access to certain county employee email accounts” in a computer breech between July to August…
Big Coral Gables mortgage servicer hit by data breach, exposing clients’ personal information
Andres Viglucci reports: One of the country’s largest mortgage servicers, a company based in Coral Gables, has reported what appears to be a significant data breach to customers three months after discovering it, prompting two separate federal lawsuits. In a letter to customers dated March 18, Lakeview Loan Servicing said it had uncovered “a security…
Spanish football federation reports data stolen by hackers
The Sun reports: The Spanish football federation (RFEF) said on Thursday it was victim of a hacking attack which resulted in the loss of data belonging to president Luis Rubiales. General secretary Andreu Camps also had text and audio data stolen, the RFEF said, and the loss had been reported to the police. Read more…