Dennis Green and Mary Hanbury report: At least 15 separate security breaches occurred at retailers from January 2017 until now. Many of them were caused by flaws in payment systems, either online or in stores. Data breaches are on the rise for both retailers and other businesses. A recent report published by cybersecurity firm Shape…
Category: U.S.
Some Kanawha County employees receive data breach notices after ComplyRight breach
Rick Steelhammer reports: Some Kanawha County employees whose health insurance coverage is issued through the county may have had personal information accessed during a data breach of the website of a cloud-based human resources servicing firm. Florida-based ComplyRight, which offers an array of HR-related data services to small businesses and government organizations, informed Kanawha County…
NorthStar Anesthesia notifies patients after employee email accounts compromised
Between May 23 and 24, 2018, NorthStar learned of an email phishing campaign that resulted in the compromise of certain employees’ email credentials. NorthStar immediately took steps to respond and commenced an investigation to determine the nature and scope of the incident, as well as determine what information may be affected. The investigation included working…
Short Circuit: How a Robotics Vendor Exposed Confidential Data for Major Manufacturing Companies
The UpGuard Cyber Risk team can now disclose that sensitive documents for over a hundred manufacturing companies were exposed on a publicly accessible server belonging to Level One Robotics, “an engineering service provider specialized in automation process and assembly for OEMs [original equipment manufacturers], Tier 1 automotive suppliers as well as our end users.” Among…
Ballad Health employee fired after accessing patients’ records without permission
Slater Teague reports: Ballad Health says an employee has been fired for accessing patients’ records without an appropriate reason to do so. The health system says it learned of the data breach on May 28. According to Ballad, the former employee viewed patients’ records, accessing both demographic and clinical information. Read more on WJHL.
Samsam infected thousands of LabCorp systems via brute force RDP
Steve Ragan reports: LabCorp, one of the largest clinical labs in the U.S., said the Samsam ransomware attack that forced their systems offline was contained quickly and didn’t result in a data breach. However, in the brief time between detection and mitigation, the ransomware was able to encrypt thousands of systems and several hundred production…