On June 24, DataBreaches reported that the National Student Clearinghouse was one of the victims of the MOVEit breach by Clop, In that report, DataBreaches stated that the clearinghouse’s statements to date had not indicated whether they had paid any ransom demand, but DataBreaches had learned that their name had been removed from Clop’s leak…
Category: Hack
HHS Office for Civil Rights Settles HIPAA Investigation with iHealth Solutions Regarding Disclosure of Protected Health Information on an Unsecured Server for $75,000
HHS has announced another Security Rule enforcement action. This one involves iHealth Solutions (dba Advantum Health), a business associate. The incident involved an unsecured server where protected health information of patients was exfiltrated. The iHealth incident had been discovered by Kromtech Security and was first reported by DataBreaches on May 9, 2017. On May 10,…
LetMeSpy, a phone tracking app spying on thousands, says it was hacked
Zack Whittaker reports: A hacker has stolen the messages, call logs and locations intercepted by a widely used phone monitoring app called LetMeSpy, according to the company that makes the spyware. The phone monitoring app, which is used to spy on thousands of people using Android phones around the world, said in a notice on its…
Sweetwater Union High School District now admits February outage was a hack, but still hasn’t answered questions
There’s an update to a report in February about an outage that wasn’t described at the time as a hack or ransomware attack. Laura Acevedo reports: The Sweetwater Union High School District has confirmed a hack was the cause of a days-long system outage at their facilities, saying the personal information of employees, students, and families…
Four senior residences in Pennsylvania disclose a data security breach in April
Four senior residences have disclosed that they were the victims of a network intrusion in April that may have compromised residents’ personal and protected health information. Senior Choice, Inc., dba The Atrium in Johnstown, Beacon Ridge in Indiana, and The Patriot in Somerset reported an incident that occurred between April 18 and April 23. The…
Confused about the drama with the new BreachForums? Reading this will either help you or make your head spin.
[Please see corrections at end of post.] Over the past week, DataBreaches has been contacted by a few journalists who have been somewhat understandably confused about the situation with the original BreachForums and a new forum calling itself BreachForums. And from reading news reports this week, I see that some journalists are making errors, so…