Catalin Cimpanu reports on a rare bit of good news on the malware front, although the threat actors appear to have gotten the upper hand again: In the cyber-security industry, there’s a very dangerous moral line when it comes to exploiting bugs in malware, a line many security companies won’t cross, fearing they might end…
Category: Of Note
Medical records for cardiac patients left unsecured online
On August 2, a researcher contacted DataBreaches.net about a misconfigured Amazon s3 storage bucket they had discovered. The bucket contained more than 10,000 files, recently updated, with protected health information of patients seen by or involved with BioTel Heart cardiac data network. Sometimes it is easy to figure out the likely owner of an Amazon…
Three more medical practices hit by ransomware
Atlanta does not seem to be a safe place for cybersecurity of orthopedic patients’ data. In 2016, orthopedic clinics in Atlanta got clobbered by two big breaches involving thedarkoverlord. The first was a hack and extortion demand on Athens Orthopedic Clinic, an organization that had more than a dozen locations but somehow didn’t have enough…
Travelex Forced into Administration After Ransomware Attack
After all these years of reporting on breaches, it’s still unusual to read that a company has folded as a result of a data breach, but we live in different times because of the added burden of the pandemic. Phil Muncaster reports: Ransomware victim Travelex has been forced into administration, with over 1000 jobs set…
Due to HHS intervention, an FTP leak in 2018 is finally reported to patients
It looks like HHS followed up on a leak first reported by DataBreaches.net in May, 2018. At the time, this site noted that two MedEvolve clients had exposed data. One of them was Beverly Held, M.D. A researcher had found .dat files exposed without any login required and estimated that there were approximately 12,000 SSNs…
SPARTOO: sanction of 250,000 euros and injunction under penalty to comply with the GDPR
From the CNIL, the French data protection authority: SPARTOO is specialized in the online shoe sales sector. For this activity, it has a website accessible in thirteen countries of the European Union. The CNIL inspected the company in May 2018, and noted shortcomings concerning the data of customers, prospects and employees. The President of the CNIL therefore…