Sergiu Gatlan reports: … IcedID is a modular banking trojan first spotted in 2017 and updated to also deploy second-stage malware payloads, including Trickbot, Qakbot, and Ryuk ransomware. Recently detected by the Microsoft 365 Defender Threat Intelligence Team, this phishing campaign seems to have found a way to bypass contact forms’ CAPTCHA protection to flood enterprises with a barrage…
Follow-up: Adventist Health Physician’s Network fined $40,000 for 2018 breach incident
Jeremy Childs reports: Adventist Health Physician’s Network, a hospital in Simi Valley, was fined $40,000 as part of a civil privacy settlement this week, according to the Ventura County District Attorney’s Office. The settlement stems from an incident in October 2018 when private medical files were found inside a storage unit in Simi Valley. The…
No password required: Mobile carrier exposes data for millions of accounts
Dan Goodin reports: Q Link Wireless, a provider of low-cost mobile phone and data services to 2 million US-based customers, has been making sensitive account data available to anyone who knows a valid phone number on the carrier’s network, an analysis of the company’s account management app shows. Read more on The Register. Opinion: I…
VA staffer used medical records to stalk and harass female vet, lawmakers demand reforms
Leo Shane III reports: A group of 50 House lawmakers is demanding immediate improvements to the Department of Veterans Affairs system for investigating sexual harassment complaints after a woman was stalked and intimidated by a call center employee who used his post to look up her personal information. In a letter sent this week to VA…
Ransomware attacks: Ansal fears data loss
PTI reports: Realty firm Ansal Housing on Friday said that the company had faced multiple ransomware attacks on its IT system since February 26, which may have resulted in some data loss. The e-mail system had been significantly impacted resulting in non-receipt of any e-mail communication on the e-mail accounts, it said in a regulatory…
Hogan Lovells Asia Pacific Data Protection and Cyber Security Guide 2021
Resource: Hogan Lovells Asia Pacific Data Protection and Cyber Security Guide 2021 (registration required to access it)