The 2013 breach at Maricopa County Community College District (MCCCD) in Arizona affected approximately 2.5 million faculty, staff, vendors, and students, making it the largest breach involving student information ever reported by a U.S. institution of higher education. A complaint by this privacy advocate alleges violations of the Safeguards Rule. Having researched and reported on breaches for about…
Category: Of Note
AU: Review blames Immigration for data breach exposing 10,000 detainees
Paul Farrell and Oliver Laughland report: A major data breach that exposed the personal details of almost 10,000 people in detention was caused by Immigration Department failures to check and approve documents for web publication, an independent review has found. The report by management consultants KPMG, which was published on Thursday, reveals that the document containing…
So how’s 2014 going, you ask? Not well, not well…..
Risk Based Security and Open Security Foundation have released a report for Q1 of 2014. The first bullet gives a good indication of what kind of year 2014 is turning out to be: There were 669 incidents reported during the first three months of 2014 exposing 176 million records. Of especial interest to me were…
New resource to help merchants understand PCI-DSS compliance
Back in 2010, while blogging about a POS breach at a small merchant, I noted that small merchants and Mom and Pop outfits weren’t getting enough information and support to be PCI-DSS compliant. One of my main resources for breaches in the hospitality sector has been Charles Hoff, JD, MBA. Charles has extensive experience representing…
INFORMATION SECURITY: Agencies Need to Improve Cyber Incident Response Practices – GAO
From the highlights of a newly released GAO report: Twenty-four major federal agencies did not consistently demonstrate that they are effectively responding to cyber incidents (a security breach of a computerized system and information). Based on a statistical sample of cyber incidents reported in fiscal year 2012, GAO projects that these agencies did not completely…
Paytime, Inc. breach affected over 216,000
One day, businesses will heed my sage advice not to stay in the news cycle by letting details dribble out piecemeal. Today is not the day, however, so thankfully, idRADAR did some digging and has found out that over 215,000 were affected by the Paytime, Inc. breach covered previously on this blog. Jeanne Price reports:…