Katie Peralta reports: A partner of the Boy Scouts of America inadvertently exposed the personal information of children and their parents last month. What happened: Boy Scouts nationwide sell popcorn to raise funds for activities like camping trips — just like Girl Scouts sell cookies. To facilitate the sales process, Boy Scouts of America uses…
Category: U.S.
Oklahoma pension fund reports $4.2 million cyber theft
AP reports: The FBI is investigating after computer hackers managed to steal about $4.2 million in funds from a pension system for retired Oklahoma Highway Patrol troopers and other state law enforcement officers, state officials said Friday. A notice posted on the Oklahoma Law Enforcement Retirement System website said the agency notified the FBI and…
Unalaska recovers $2.3M after phishing email scam
Hope McKenney reports: More than $2.3 million dollars has been returned to the City of Unalaska, after a nearly two-month federal investigation into a fraudulent financial request. Between May 15 and July 9, the city paid out $2,985,406.10 to a fraudulent bank account as a result of a phishing email scam. The sender of the…
Alive Hospice’s breach notification required a second breach notification
It occasionally happens that a breach or incident response creates a second incident of its own. That seems to be the case with Alive Hospice, as this newest press release suggests, but does this require second notification to HHS/OCR? My first impression is that it would, but I’m interested to hear what HIPAA lawyers might…
No municipality paid ransoms in ‘coordinated ransomware attack’ that hit Texas
Catalin Cimpanu reports: A coordinated ransomware attack hit 22 Texas local governments, but none of the impacted municipalities paid ransom demands, Texas state officials said this week. Three weeks after the incident took place, the Texas Department of Information Resources (DIR) said that more than half of the impacted entities are now back to operations…
Meridian Community College discloses a breach that was discovered in January
A breach notification by Meridian Community College demonstrates once again, why entities should make determined efforts not to leave emails in employee accounts that may have personally identifiable information in attachments or the emails themselves. In this case, the types of personal information included name, Social Security number, driver’s license number, passport number, date of…