Caredig ap Tomos reports: Sensitive data relating to students’ self-identification continued to be shared with students running elections on Cambridge Students’ Union’s voting platform months after the issue was originally raised. Sources have told Varsity that countless students were “effectively outed without even knowing it” because of the ‘breach’ of sensitive data, which took nine months to…
Ransomware gang steals data from KFC, Taco Bell, and Pizza Hut brand owner
Bill Toulas reports: Yum! Brands, the fast food brand operator of KFC, Pizza Hut, Taco Bell, and The Habit Burger Grill fast-food restaurant chains, has been targeted by a ransomware attack that forced the closure of 300 locations in the United Kingdom. Read more at BleepingComputer.
ICE releases thousands of immigrants affected by data breach
Hamed Aleaziz reports: Immigration and Customs Enforcement officials have released nearly 3,000 immigrants whose personal information, including birth dates and detention locations, was inadvertently posted on the internet by the U.S. government, according to government officials. Officials accidentally posted the names, birth dates, nationalities and detention locations of more than 6,000 immigrants who claimed to…
No evidence of personal data leak amid national security probe: NHIA
CNA reports: The National Health Insurance Administration (NHIA) on Thursday said there is no evidence that three current and former employees stole data amid a recent probe launched by prosecutors into the National Health Insurance (NHI) system. The suspects — a woman surnamed Hsieh (謝) who is a division chief at the NHIA, a male…
34,942 PayPal users notified of data security incident in December
PayPal has sent breach notifications to 34,942 users this week. Their notification reads, in part: On December 20, 2022, we confirmed that unauthorized parties were able to access your PayPal customer account using your login credentials. We have no information suggesting that any of your personal information was misused as a result of this incident,…
New Cybersecurity Directives (NIS2 and CER) Enter into Force in EU
Hunton Andrews Kurth writes: On January 16, 2023, the Directive on measures for a high common level of cybersecurity across the Union (the “NIS2 Directive”) and the Directive on the resilience of critical entities (“CER Directive”) entered into force. The NIS2 Directive repeals the current NIS Directive and creates a more extensive and harmonized set of rules on cybersecurity…