The same individual, “unu,” who has been exposing other web sites vulnerable to SQL injection, has issued some screen shots showing how the German site, StayFriends, left its over 7 million users’ personal information vulnerable to exposure or access. According to the account of the hack, the exposure involved names, email addresses, passwords, some credit…
Category: Non-U.S.
UK: Dental patient fraud pair jailed
A woman and her stepfather have been given jail terms for defrauding nearly £20,000 from patients at two dental practices in Glasgow. Receptionist Adele Ballantyne, 22, copied credit and debit card details and passed them to John Hill, 32, who then ordered goods for resale. Ballantyne was jailed for 12 months and Hill was sentenced…
More p2p fiascos
Rian from RedTeam Protection, a division of Tony Josephs and Sons Investigations Inc., just sent me another batch of p2p cockups that exposed personal — and in some cases — sensitive medical — information. In each case, RedTeam advised the entity and/or helped ensure removal of the filesharing application. Some of these breaches are more…
UK: ICO takes enforcement action against Hastings and Rother PCT for data loss
From the press release (pdf) from the Information Commissioner’s Office (ICO): The Information Commissioner’s Office (ICO) has taken enforcement action against Hastings and Rother Primary Care Trust (PCT) following a breach of the Data Protection Act. This is the eighth time the ICO has taken enforcement action against an NHS organisation for breaching the Data…
Ca: Privacy commissioner may investigate City of Regina privacy breach
Joe Couture reports: Contrary to statements made by a City of Regina executive, the Office of the Saskatchewan Information and Privacy Commissioner has not yet decided whether or not to undertake a formal investigation into the breach of privacy announced by the city yesterday. Read more in the Leader-Post
UK: Busy Bees childcare voucher data leak plugged – Update
A UK child care voucher scheme has been taken off line after user Nick Gibbins found that the “web” application was exposing personal data for over one hundred thousand users. Gibbins found that the Busy Bees childcare voucher system was actually implemented using Citrix Metaframe, exporting the user interface from a Windows 2000 application to…