Danny Yadron, Paul Ziobro and Charles Levinson report: The hackers who stole 40 million credit- and debit-card numbers from Target Corp. appear to have breached the discounter’s systems by using credentials stolen from a vendor. The finding will help to start unraveling the riddle of how the software that carried out the attack got into Target’s systems….
Category: Subcontractor
EasyDraft notifies Bright Horizons Family Solutions customers of breach involving bank information
eCommerce payment processor EasyDraft is notifying Bright Horizons Family Solutions customers of a breach that started in October 2012 with a misconfigured server. The breach wasn’t discovered until January 2014, however, when Bright Horizons contacted EasyDraft to alert them to the problem. In their report to the New Hampshire Attorney General’s Office, lawyers for EasyDraft write: We…
Connecticut Appellate Court affirms denial of coverage under CGL policy for data breach
Michael A. Hamilton and Christopher J. DiIenno of Nelson Levine de Luca & Hamilton LLC discuss a case that pre-dates this blog but litigation over the insurer’s obligations has only recently resulted in an appellate ruling: As more data breaches and information security events occur, the insurance industry will see more disputes over whether losses…
Is Easton-Bell Sports The Next Shoe Breach Experts Predicted?
J. Price reports: Another US company has revealed a data breach has hit the servers used in conducting e-commerce. Easton-Bell Sports, which makes sports equipment and clothing under the Bell Sports, Blackburn, Easton, Giro and Riddell brands, announced the breach but did not disclose the name of the vendor from whom Easton data was lifted. “(We)…
VA: Supt. of Loudoun County Public Schools statement on breach (updated)
Statement on the school district’s website from Supt. Dr. Edgar B. Hatrick: Recently, the school system was informed of a security breach involving one of our software vendors. The vendor, Risk Solutions International, maintains the school system’s Emergency Management Plans. The website contains some personal information about students and staff members that is normally restricted to…
T-Mobile USA customers to be notified of security breach at supplier’s (update 2)
It looks like T-Mobile USA will be sending out breach notification letters to customers after the New Year. A template of their notification letter, uploaded today to California’s breach site, explains: We are writing to inform you of a recent incident of unauthorized access to a file stored on servers owned and managed by a…