John Leyden reports: US-based industrial computer supplier Logic Supply has reset user passwords following a suspected security breach. Unauthorised access through the firm’s website on 6 February may have exposed customer/company names, usernames and passwords, and order information. Payment card details were not exposed, Logic Supply reassured customers in a breach notification email (extract below) forwarded to El…
Category: U.S.
IL: Alton Steel employees report tax refund fraud following W-2 phishing incident (Updated)
Update: This incident actually was a phishing incident, and The Telegraph‘s story now reflects that, so I’m adding this one to the 2017 victims list. Originally, their story sounded like a straight-up hack. Their story now reads: The Alton steel company’s data system was victim to a “phishing expedition,” according to Alton Steel CEO Jim…
Multnomah County notified 1,700 patients after discovering employee was forwarding emails to personal account
From Multnomah County, Oregon: January 20, 2017 On August 24, 2012, a Health Department employee began automatically forwarding all emails received in the employee’s county email account to a personal Google email account not maintained by the county. Some of these emails included protected health information (PHI) subject to the Health Insurance Portability and Accountability…
Five months after learning of problem, Michigan cancer treatment provider notifies 22,000 patients
On October 21, 2016, Singh & Arora Oncology Hematology PC in Michigan notified HHS of a hacking incident that they reported impacted 16,000 patients. Today, we learn that 22,000 patients are first getting notification letters this week. Why has it taken more than three months since HHS was notified for patients to be notified? Jessica Dupnack reports: According to the letter, one of…
Princeton Pain Management notifies patients after hacker gains access to PHI
Princeton Pain Management is notifying 4,668 patients of a hack that was detected on November 28. Although they found no evidence that data were removed from their system, protected health information (PHI) was accessed. From their notification: What Information Was Involved We believe that this incident may have affected certain information stored in our systems including…
NJ: Little Egg Harbor Seeks Three Tiered Criminal Investigation into Stolen Data
Somebody is stealing confidential information from municipal computer systems in Little Egg Harbor and the township wants to know who and how they end up in the hands of a local political blogger each time. In a letter dated November 10, 2016, township attorney Robin LaBue sent a letter to the Ocean County Prosecutor’s Office,…