It’s been an expensive few weeks for Community Health Systems and CHSPSC. First, a few weeks ago, HHS announced that CHSPSC LLC, (“CHSPSC”) has agreed to pay $2,300,000 to the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) and to adopt a corrective action plan to settle potential…
Office of the Comptroller of the Currency fines Morgan Stanley $60 million for 2016 data breach
Brendan Pedersen reports: Morgan Stanley was slapped with a $60 million fine by regulators Thursday for risk management problems tied to a 2016 data breach. The consent order by the Comptroller of the Currency cited failures at both Morgan Stanley Bank, N.A., and Morgan Stanley Private Bank, N.A. related to the shutdown of two wealth…
Amid an Embarrassment of Riches, Ransom Gangs Increasingly Outsource Their Work
Brian Krebs reports: There’s an old adage in information security: “Every company gets penetration tested, whether or not they pay someone for the pleasure.” Many organizations that do hire professionals to test their network security posture unfortunately tend to focus on fixing vulnerabilities hackers could use to break in. But judging from the proliferation of…
Massachusetts school district shut down by ransomware attack
Lawrence Abrams reports: The Springfield Public Schools district in Massachusetts has become the victim of a ransomware attack that has caused the closure of schools while they investigate the cyberattack. Springfield is the third largest school district in Massachusetts with over 25,000 students, 4,500 employees, and more than sixty schools. Due to the COVID-19 pandemic,…
UK: Wisepay: School payments service hit by cyber-attack
BBC reports: Parents who made payments to UK schools in recent days via the Wisepay service have been warned their card details have been compromised. Wisepay said a hack of its website meant an attacker was able to harvest payment details between 2 and 5 October via a spoof page. Attempted payments to about 300…
Hall County, Georgia reports ransomware attack
Hall County first posted a notice about a ransomware attack on October 7. Since then, they have posted updates on their site, including the restoration of their phone services. Nothing has been revealed about who the attackers might be or what any ransom demand might have been. Thanks to @Chum1ng0 for submitting this link.