Matthew Sturdevant reports: In the wake of several major data breaches in recent years at The Home Depot, Target and Anthem, Connecticut’s legislature has passed a bill that would provide greater consumer protections. One of the key provisions is at least one-year of identity-theft protection for any customer that is a victim of a data…
Category: Of Note
Ca: Ontario Securities Commission lays criminal charges in patient records privacy breach at two Toronto hospitals
Diana Mehta reports: Criminal charges have been laid after thousands of confidential records were allegedly stolen from two Toronto hospitals and used to market registered education savings plans to new mothers. The alleged incidents involved the Rouge Valley Health System and the Scarborough Hospital and were investigated by Ontario’s financial regulator, which oversees the sale…
56 MEEELLION credentials exposed by apps say infosec boffins
Darren Pauli reports: Researchers from the University of Darmstadt say app developers have exposed 56 million credentials by borking login processes using services from Google, Amazon, and Facebook. The research team tested 750,000 Android and iOS applications, examining the way they used the federated identity services to make authentication smooth across different devices. The team…
Locker ransomware author dumps database of private keys, apologizes
Wow. Seen on Pastebin last night: Hi, I am the author of the Locker ransomware and I’m very sorry about that has happened. It was never my intention to release this. I uploaded the database to mega.co.nz containing “bitcoin address, public key, private key” as CSV. This is a dump of the complete database and…
Data breach liability: confidentiality vs. privacy
Glynna Christian and Nikki Mondschein of Kaye Scholer LLP provide food for thought for businesses and covered entities when reviewing contracts with IT service providers: IT service providers, particularly cloud service providers, increasingly are resisting unlimited liability for breaches of privacy and data security obligations in their customer agreements. Instead, they offer unlimited liability for breaches of…
Analysis of Yemen Cyber Army data dump
Earlier today, I noted that the Yemen Cyber Army (YCA) had dumped another 1,000,000 records they obtained by hacking the Saudi Ministry of Foreign Affairs. This latest dump is visa data. Here’s a bit of a summary of the newest data: The compressed file is 73.4 MB; uncompressed, it’s one text file of 362 MB….