Another data theft in the education sector. And yet again, no one did anything wrong because there was never any policy. Yesterday I added a breach to DataLossDB involving the Morgan Road Middle School in Georgia. A flash drive with unencrypted student information, including SSNs, was stolen from an teacher’s unattended car. A gradebook was…
Category: Of Note
Shades of 2003: Have contractors started holding individuals’ PII hostage again?
It’s been a long time since I’ve seen any report that a contractor or their employees were holding an organization’s client or patient data hostage as part of a dispute. To my surprise, however, there have been two such reports like that recently. One case is in the healthcare sector and I’ll be blogging about…
Inadequate security of personal, private, and sensitive Information in school districts’ mobile computing devices – audit
I’ve often pointed out my concerns that public schools – at least those in New York that I’ve been in – do not seem to have adequate security in place for the vast troves of sensitive and confidential information they collect and retain. So I was unsurprised to read that a recent Office of the…
Verizon FIOS allegedly hacked; 300,000 records dumped; more than 3 million acquired? NO! (updated to include Verizon statements)
Update Sunday 3:34 pm: In response to follow-up questions, Verizon spokesperson Alberto Canal informed this site last night: Some were Verizon customers, most were not. In regards to the number of individuals, the total was about 10% of what was originally reported. In answer to your question about a vulnerability: No there was not. There…
One year later, Jetro/Restaurant Depot is breached again (update2)
It was last year at about this time that we first got wind of an incident involving food services wholesaler Jetro/Restaurant Depot. Malware inserted in their card payment system had exfiltrated mag stripe data (names, card numbers, card expiration dates, and cvv codes) to a server in Russia between late September 2011 and early November…
Update and commentary on SCDOR breach: Where would they be without media coverage?
I’ve been pretty critical of the South Carolina Department of Revenue breach and the state’s incident response. Some will think my criticism is well-deserved, while others may feel I’ve been too harsh. But it is now six weeks since we first learned of the breach and here is what hasn’t happened so far: Notification letters…