Brian Krebs reports: Peter is an IT manager for a technology manufacturer that got hit with a Russian ransomware strain called “Zeppelin” in May 2020. He’d been on the job less than six months, and because of the way his predecessor architected things, the company’s data backups also were encrypted by Zeppelin. After two weeks…
Category: Of Note
Vanuatu island hit by ransom attack, cripples government
WION reports: The small archipelago of the South Pacific Ocean, Vanuatu, was attacked by ransomware on 4 November, Friday and stranded the country for over a week. According to civil servants in the government, they noticed that their official emails started bouncing back from government addresses, this was the first sign when they found that…
PA: Media’s reporting on breach led to new state data breach law
Rick Earle reports: An exclusive Target 11 investigation into a massive data breach last year has led to a new state law meant to protect every citizen of the Commonwealth. Target 11 Investigator Rick Earle broke the story of that data breach last April and now because of his reporting, state lawmakers passed legislation requiring timely notification of…
New South Wales gets first state-based data breach notice scheme
Justin Hendry reports: New South Wales will have Australia’s first mandatory data breach notification scheme for public sector entities in place within a year after state government legislation passed Parliament. The Privacy and Personal Information Protection Amendment Bill underpinning the long-promised regime sailed through the Legislative Council last night without amendment, having passed the Legislative Assembly…
Five Former Methodist Hospital Employees Charged with HIPAA Violations
Criminal prosecutions under HIPAA are still relatively rare. Here’s one reported by the U.S. Attorney’s Office in the Western District of Tennessee on November 10: Memphis, TN – A federal grand jury has indicted five former Methodist Hospital employees for conspiring with Roderick Harvey, 40, to unlawfully disclose patient information in violation of the Health Insurance…
U.K.: Suffolk police publish sensitive info of sexual assault victims online in data protection failure
Why would other victims ever come forward and report their assaults when they cannot trust the police to protect their reports? This is an appalling breach, and an “investigation” isn’t going to undo any harm that has been done. What exactly is going to be done to mitigate harm to the victims of this data…