Key points: More than half of ransomware victims reportedly pay ransom, but there is an absence of quality data and reporting that would enable better analyses. As payouts have increased, the number of customers electing to have cyberinsurance coverage (the take-up rate) has increased, although SMBs lag behind mid- to large-sized entities. As payouts have…
One Employee’s Accidental Email Leads To A Significant Data Breach Ruling in Federal Appeals Court
Jeffrey Csercsevits of Fisher Phillips writes: A federal appeals court recently addressed whether employees had standing to bring a lawsuit when their personally identifiable information (PII) was inadvertently circulated to other employees at the company, with no indication of misuse or external disclosure. In McMorris v. Carlos Lopez & Associates, LLC, the 2nd Circuit Court of…
OH: Marietta City Schools Email Hack
Christopher Schmitt reports: The Marietta Police Department is investigating a number of Marietta City School employees’ emails being hacked. It was just released that Marietta Superintendent Will Hampton reached out to the Marietta Police last week. It was reported to the police that a number of employees’ email accounts could have been compromised since 2018….
After Colonial Pipeline Hack, U.S. to Require Operators to Report Cyberattacks
Rebecca Smith reports: The Transportation Security Administration intends to release the first of at least two security directives that would require pipeline operators to notify it when they are targets or victims of cyberattacks, according to senior officials at the Department of Homeland Security. The action, expected this week, also will require each company to…
Having your ePHI dumped on the dark web by threat actors doesn’t necessarily give you standing to sue
In May, 2020, Assured Imaging in Arizona experienced a ransomware attack that they revealed in August, 2020.The incident reportedly impacted 244,813 patients. The data dump by the Pysa threat actors contained a lot of ePHI that appeared to be mostly mammography pre-screening histories or forms with data types such as medical record number, names, addresses,…
Law Firm Responds To Data Breach Claim By… Leaking Data. Checkmate!
Joe Patrice reports: Law firms must always be supremely cautious with private information, but you can’t help but think a firm would add that little extra attention to the task when their client has already been sued for a data breach. Not only would another leak damage the client’s reputation further, you already know that…