On October 5, Salud Family Health in Colorado notified HHS of a breach, but only provided a “marker” of 501 affected. On November 4, they provided notice that said the types of information that might have been accessed or taken included in a cyberattack included: patients’ name, Social Security number, driver’s license number or Colorado…
Whoosh confirms data breach after hackers sell 7.2M user records
Bill Toulas reports: The Russian scooter-sharing service Whoosh has confirmed a data breach after hackers started to sell a database containing the details of 7.2 million customers on a hacking forum. Whoosh is Russia’s leading urban mobility service platform, operating in 40 cities with over 75,000 scooters. On Friday, a threat actor began selling the…
Avamere Health Services updates its breach disclosure
Back in July, DataBreaches reported on an Avamere Health Services breach. Avamere has now updated their breach notification. Their newer notice is being provided on behalf of the following entities to whom Avamere is a Business Associate as defined under the Health Insurance Portability and Accountability Act (“HIPAA”): A-One Home Health Services, LLC Avamere at…
Mass Email Extortion Campaign Claims Server Hack; Tries to Extort Troy Hunt
Phil Muncaster reports: Security experts have revealed a new extortion campaign threatening to leak sensitive corporate data unless a Bitcoin payment is made. Microsoft regional director and HaveIBeenPwned founder, Troy Hunt, revealed the unsolicited email in a social media post. It claimed that the fraudsters had hacked his site by exploiting some unnamed vulnerabilities and…
Hong Kong regulator issues investigative report on 2021 Fotomax ransomware incident
The Office of the Privacy Commissioner for Personal Data (PCPD) in Hong Kong published an investigation report today concerning a ransomware attack on the database of Fotomax (F.E.) Limited. From the news release: The investigation arose from a data breach notification lodged by Fotomax with the PCPD on 1 November 2021, which reported that the…
Booz Allen Hamilton Holding Corporation notifies employees of insider breach
Booz Allen Hamilton Holding Corporation has disclosed an insider breach involving the sensitive, personally identifiable information (PII) of active employees as of March 29, 2021. According to their notification, a copy of which was submitted to the Montana Attorney General’s Office, Booz Allen recently learned that while employed by Booz Allen, a former employee obtained…