The first time DataBreaches remembers hearing about the man who calls himself “USDoD” was when he posted a sales listing for member data from InfraGard. He had not only managed to acquire data on 80,000 members of an organization dedicated to protecting critical infrastructure, but his revelation of his method exposed some embarrassingly inept security…
Sweden’s Privacy Protection Agency fines insurer Trygg-Hansa for exposing sensitive customer data
The following press release was issued August 30 by Sweden’s Authority for Privacy Protection (IMY): Trygg-Hansa’s security flaws have meant that information on 650,000 customers has been accessible via the internet. The Privacy Protection Agency (IMY) is now issuing an administrative sanction fee of SEK 35 million against the company. After receiving a tip, IMY began…
Personal Data Protection Commissioner of Singapore announces two decisions
The Personal Data Protection Commissioner of Singapore (PDPC) announced two decisions this week: A financial penalty of $3,000 was imposed on Autobahn Rent A Car for failing to put in place reasonable security arrangements to protect the personal data in its possession or under its control. Directions were also issued to strengthen access control measures…
BlackCat ransomware hits Azure Storage with Sphynx encryptor
Sergiu Gatlan reports: The BlackCat (ALPHV) ransomware gang now uses stolen Microsoft accounts and the recently spotted Sphynx encryptor to encrypt targets’ Azure cloud storage. While investigating a recent breach, Sophos X-Ops incident responders discovered that the attackers used a new Sphynx variant with added support for using custom credentials. Read more at BleepingComputer.
FTX restores claims portal after security breach incident
Haseeb Shaheen reports: In a recent turn of events, the claims portal for the globally renowned cryptocurrency exchange FTX has resumed its full-fledged operation. The operations were suspended following a security incident that took place with Kroll, the third-party agent responsible for handling the creditor claims amidst the ongoing FTX bankruptcy. The cybersecurity incident is just…
As AI boosts Texas cybercrime, challenges in bringing international criminals to justice remain
Eric Killelea reports: It used to be easier. Christopher Delzotto remembers the days not so long ago when many online financial scams could be spotted just by reading them. They were full of misspellings, poor grammar and awkward phrasing — all signs that they were created in other countries where a hacker’s first language isn’t English. The…