Sergiu Gatlan reports: The German data protection authority (BfDI) has fined Vodafone GmbH, the telecommunications company’s German subsidiary, €45 million ($51.4 million) for privacy and security violations. “Due to malicious employees in partner agencies who broker contracts to customers on behalf of Vodafone, there had been fraud cases due to fictitious contracts or contract changes at…
Category: Non-U.S.
100,000 UK taxpayer accounts hit in £47m phishing attack on HMRC
Nadeem Badshah reports: HM Revenue and Customs has lost £47m after a phishing scam breached tens of thousands of tax accounts, a group of MPs has heard. Two senior civil servants at the tax authority told the Treasury committee on Wednesday that 100,000 people had been contacted, or were in the process of being contacted,…
Ransomware group Gunra claims to have exfiltrated 450 million patient records from American Hospital Dubai (1)
A relatively new ransomware group calling themself “Gunra” has shown it has no compunction about attacking hospitals. They have reportedly locked — and have started leaking information from — the American Hospital in Dubai (AHD). In its first listing concerning this attack, Gunra claimed to have exfiltrated the entire Cerner Millenium database (now known as…
Fraudsters, murderers, students: who the GRU assembled a team of hacker provocateurs from and why it failed
The Insider reports: In September 2024, the FBI published an indictment against a group of hackers working for GRU Unit 29155, the same military unit that became famous for poisoning Skripal in Salisbury. It has long been known that the GRU has hacker units, The Insider was the first to prove this back in 2017, and then it was…
Order of Psychologists of Lombardy fined 30,000 € for inadequate data security protection and detection following ransomware attack
The Privacy Guarantor has fined the Order of Psychologists of the Lombardy Region [Ordine degli psicologi della Lombardia] for 30 thousand euros for not having adopted adequate technical and organizational measures to guarantee data security. The Guarantor intervened following some complaints and the notification of data breach made by the Order, which declared to have…
Australian ransomware victims now must tell the government if they pay up
Alexander Martin reports: Australia became on Friday the first country in the world to require victims of ransomware attacks to declare to the government any extortion payments made on their behalf to cybercriminals. The law, initially proposed last year, only applies to organizations with an annual turnover greater than AUS $3 million ($1.93 million) alongside a smaller…