The Tribune reports: An Air India flyer has sought damages from the airline after the recent leak of personal data of 4.5 million passengers, including hers and her husband’s. A legal notice was sent to Air India management on Sunday by Ritika Handoo in which she said that the airline informed her about the breach…
Hackety hack hack…
There are so many breach reports that it’s hard to even find all the notices and reports about them these days. These days, there are many breaches that I log in worksheets I compile for Protenus’s Breach Barometer annual report but never even post on this blog. Just today, for example, I found: a notice…
Canadian non-profit hit by malware gets help — from the threat actor
Good Shepherd Centres in Canada recently disclosed a breach involving protected health information that occurred on September, 27, 2020. On June 29, Good Shepherd posted a statement that explains that it had been the victim of an attempt to shut down its systems, but that the attacker(s) “quickly facilitated restoration after realizing that Good Shepherd…
Insurer Dominion National settles for $2 million in data breach lawsuit
Ax Sharma reports a settlement in litigation over a breach that was disclosed in 2019 but presumably began in 2010. Dominion National, Virginia-based insurance provider of dental and vision health benefits has reached settlement in the class action lawsuit concerning the decade-old data breach that exposed sensitive customer information of over 2.9 million patients. Although…
US chemical distributor shares info on DarkSide ransomware data theft
Sergiu Gatlan reports: World-leading chemical distribution company Brenntag has shared additional info on what data was stolen from its network by DarkSide ransomware operators during an attack from late April 2021 that targeted its North America division. Read more on BleepingComputer.
NYDFS Issues Guidance on Cybersecurity Controls to Combat Ransomware and Clarifies Reporting Obligations
Lance Taubin, Kate Hanniford, and Kimberly Peretti of Alston & Bird write: The New York Department of Financial Services (NYDFS) issued new guidance this week intended to assist organizations in thwarting ransomware attacks. The guidance clarifies the NYDFS’ expectation that NYDFS-regulated companies should “implement these controls whenever possible” and report any successful deployment of ransomware…