Marianne Kolbasuk McGee reports that Aveanna Healthcare has been sued over a July, 2019 breach that it discovered in August, 2019. The breach was disclosed in February of 2020 as potentially impacting more than 166,000 patients. The incident was one of all-too-many incidents where threat actors gained access to a number of employees’ email accounts,…
Judge Pushes Back Accused LinkedIn Hacker’s Trial One Last Time Over COVID-19 Concerns
Ross Todd reports that a federal judge in San Francisco has once again delayed the resumption of the criminal trial of Yevgeniy Aleksandrovich Nikulin, the Russian man accused of hacking LinkedIn, Dropbox and Formspring. Read more on Law.com.
Indiana covered entities discover that their documents storage and secure destruction vendor dumped records improperly
I know the arguments against holding covered entities for auditing and monitoring their business associates periodically for compliance with any contracts, but when you don’t hold covered entities really accountable for checking that their vendors or business associates are living up to their contracts, stuff like this happens. And it can go on for years….
Agromart’s data up for auction while threat actors read — and publish — their victim’s emails about the attack
According to their website, The Agromart Group in Canada provides crop nutrients, seed, crop protection products, custom application and associated services to agricultural producers across Eastern Canada. Last month, they experienced a ransomware attack by the Sodinokibi/REvil threat actors. That in and of itself would be newsworthy, but then the threat actors decided to try…
Sekhmet ransomware team claims to have hit international IT firm “very hard”
Sekhmet ransomware operators claim to have hit an international IT firm, Excis, “very hard.” The attack reportedly occurred on May 30, and the threat actors are pressing hard to get the firm to pay an undisclosed amount of ransom. The attack was revealed yesterday on Sekhmet’s website. We are sharing a big part of their…
Amtrak resets user passwords after Guest Rewards data breach
Sergiu Gatlan reports: The National Railroad Passenger Corporation (Amtrak) disclosed a data breach that led to the exposure of personal information of some Guest Rewards members. … “On the evening of April 16, 2020, Amtrak determined that an unknown third party gained unauthorized access to certain Amtrak Guest Rewards accounts,” Amtrak Guest Rewards Senior Director…