From the Wyoming Department of Health, a report involving another GitHub leak: Exposure of Laboratory Test Result Data Described April 27, 2021 The Wyoming Department of Health (WDH) is announcing a mistaken exposure of laboratory test result data involving the health information of thousands of Wyoming residents and others, as well as describing its plan…
Ransomware gang targets Microsoft SharePoint servers
Catalin Cimpanu reports: The group behind the attacks targeting SharePoint servers is a new ransomware operation that was first seen at the end of 2020. The group is tracked by security vendors under the codenames of Hello or the WickrMe ransomware—because of its use of Wickr encrypted instant messaging accounts as a way for victims to reach out and…
District Court in Third Circuit Confirms That, When it Comes to Data Breaches, Actual Misuse Must be Alleged
Aaron C. Garavaglia of Squire Patton Boggs writes: Every federal lawsuit requires standing for the court to have subject matter jurisdiction to hear the case, and standing requires an injury-in-fact. As seen from our coverage this morning out of the Second Circuit. In Derrick McCray v. John E. Wetzel & President, No. 3:20-cv-139, 2021 U.S. Dist. LEXIS…
Is It Ethical To Buy Breached Data?
Gary Stevens writes: Research that’s done on malicious breaches of data presents a unique conundrum for the security professionals who are doing the investigating: should access to sets of breached raw data become available to public users and, if so, how? In light of the pandemic, the acceleration toward location-distributed work has the potential to…
In major ruling, 2nd Circuit says no circuit split on data breaches and standing
Alison Frankel reports: For years, I’ve been writing about a split among the federal circuits on whether data breach victims can establish a right to sue in federal court merely by showing that they are at increased risk of identity theft. Just a couple of months ago, when the 11th U.S. Circuit Court of Appeals held in…
FJ: Cyber attack disrupts government online services
On April 14, Luke Nacei reported: A cyber attack resulted in disruptions to some of Government’s online services and networks, including GovNet, on Monday. Attorney-General and Minister for Communications Aiyaz Sayed-Khaiyum said as a measure of extreme precaution, advice had been disseminated across Government to protect network integrity resulting in a temporary disruption to the…