Okay, so two exemplars doesn’t prove any kind of trend, but I’m glad to see some entities now taking steps to reduce how much PHI is stored in employee email accounts. Here are two recent incidents, both reported to HHS in December: Healthcare Administrative Partners (HAP) is a Pennsylvania-based business associate under HIPAA. On December…
UK: Home addresses of Elton John, Gabby Logan, Nadiya Hussain and every other recipient on New Year’s Honours list – including senior police and anti-terrorism officials – are accidentally published by the Cabinet Office
Oops. Ryan Fahey reports: The Cabinet Office uploaded the home and work addresses of more than 1,000 recipients of New Years’ Honours, including Elton John, Ben Stokes, Iain Duncan Smith and TV chef Nadiya Hussain. The work and home addresses of counter-terrorism officials, senior police and Ministry of Defence (MoD) staff were also included in…
IoT provider Wyze confirms server leak
Suzanne Larosa reports: Wyze, a company that sells smart devices such as security cameras, smart plugs, smart light bulbs and smart door locks, today confirmed a server leak that exposed the details of approximately 2.4 million customers. The leak occurred after an internal database was accidentally exposed online, Wyze co-founder Dongsheng Song said in a…
160,000 Belgian Allianz Partners clients affected by data theft
Oscar Schneider reports: An Allianz Partners strongbox containing back-up copies of data related to disaster claims was stolen in the Netherlands in August, the insurance and assistance company disclosed on Friday. According to an audit and analysis of the documents concerned, the strongbox contained data on 160,000 Belgian customers who had filed claims for disasters…
Ransomware at IT Services Provider Synoptek
Brian Krebs reports: Synoptek, a California business that provides cloud hosting and IT management services to more than a thousand customers nationwide, suffered a ransomware attack this week that has disrupted operations for many of its clients, according to sources. The company has reportedly paid a ransom demand in a bid to restore operations as…
Vistaprint Logomaker files viewable due to insecure Amazon s3 bucket
Vistaprint. Everyone knows it and probably almost everyone knows somebody who has used the firm to design or print business cards, brochures, or other business-related stationery or marketing-related materials. Recently I was on Vistaprint’s site to create a new logo for ctrlbox.com. To my unpleasant surprise, I discovered that the preview of my logo displayed…