Showing posts with label data breach. Show all posts
Showing posts with label data breach. Show all posts

Monday, July 17, 2023

Like stealing healthcare data from a law firm

from here and here

Apparently if you suffer a data breach, the data in question may at some point end up in the hands of a law firm. The problem, however, is that law firms are not magically secure, so it's possible for the data to be stolen a second time - which one law firm is finding out the hard way. As data breaches continue I have a feeling we may see this happen more frequently.

Monday, June 26, 2023

Stolen And Purchased

from here and here

I'm kind of surprised that SAP's first clue they had a data breach was when they purchased their own hard drive off of Ebay. But if people can just waltz out of their data center with hard drives in their pockets or something then I guess I shouldn't be surprised after all.

Wednesday, June 21, 2023

Got it, got it, need it, got it

from here and here (source article)

I knew crooks used the MOVEit vulnerability to breach a lot of organizations, but when the number is so high that you start assuming all breaches are the same group, then things start to get a little ridiculous.

Tuesday, June 20, 2023

Moving your data into their hands

from here and here (image source)

The MOVEit vulnerability has been exploited far and wide, but this latest one involving the DMV seems particularly far reaching.

Monday, June 12, 2023

Choose your email provider wisely

from here and here

So apparently the settlement checks from the class action lawsuit against Yahoo! are finally going out, and it sounds like they're not quite the pittance I was expecting, although they're not as big as I would have hoped for either.

Friday, June 2, 2023

As if you need more reasons to hate going to the dentist

from here and here

A dental health insurance company was breached and ransomed, but because they didn't pay, the data got leaked. I suppose if the crooks are going to ransom a company over it's data a health insurance company seems like a pretty good bet. They've got lots of money and I don't think they can arbitrarily pass on the additional cost to their customers.

Tuesday, April 18, 2023

Hey guys, look at my top secret clearance

from here and here

There's a pretty surprising detail about the alleged leaker of classified documents on discord. I'm not sure how such a character trait slips through the vetting process. There IS a vetting process, right? I'm sure they don't just give every Tom, Dick, and Harry top secret clearance. Right?!

Wednesday, March 29, 2023

Nominative determinism in cybercrime

from here and here

The notorious BreachForums was taken down after a new admin found evidence that law enforcement had breached it following the arrest of the previous admin, and the idea that a site nick-named "Breached" got breached is just too fitting. If you're going to call it Breached, don't be surprised when it gets breached.

Friday, January 20, 2023

Are they trying to set a record?

from here and here

Eight breaches in five years is a bit over the top, if you ask me. I wonder what would happen if the fines scaled up for each breach you had. How many breaches until companies ACTUALLY took the security of our data seriously?

Tuesday, January 17, 2023

First time cyber

from here and here

I don't know why I've never heard of cybercrime against a liquor store before, especially since it's such a staple of real-life crime. I know we've already seen it happen to convenience stores.

Thursday, January 5, 2023

Assuming Twitter still has anyone left to send them

from here and here

Well, it was only a matter of time before Twitter suffered a large data breach if Peiter Zatko is to be believed. I don't know how they're going to tell the affected users now that they have no communications team. I guess Elon is going to have to do it himself.

Wednesday, January 4, 2023

Sorry for the data breach

from here and here

Companies are always trying to assure you that they take your privacy and/or security seriously, but they say it so often (and apparently do so little to back it up) that it's become meaningless. 

It would almost be better if they said "sorry for the data breach", in the same vein as "sorry for your loss", except that they are ultimately responsible for it.

On second thought, it would be better if they just put their money where there mouths are and actually did the work required to protect us properly.

Monday, December 26, 2022

Wishful thinking

from here and here

The sellers are telling Twitter to buy their data back before someone else does. A ransom by any other name would smell as dirty, but I can't help but think these cybercrime chuckleheads are barking up the wrong tree. Twitter might not even be around long enough for the European Union to find them guilty of a GDPR violation over this. 

Friday, December 23, 2022

The last straw for LastPass

from here and here

How does a password management company make such a grave error as not protecting URLs? Knowing you have an account on a questionable website is sensitive in and of itself, without giving away the username or password, and by sensitive I mean it can get folks killed in some places.

This metadata will also be useful for phishing attacks, so if you're a LastPass user, you might see an increase in phishing emails. However, since the breach itself was months ago, the increase might have already happened.

Password managers are still good, of course, but maybe not this particular one, and maybe not online ones. Online password managers are incredibly valuable targets, while each of us individually is  generally not. An offline password manager would require someone getting through your own defenses to compromise you instead of compromising millions of users at once. 

Tuesday, September 27, 2022

Taking your privacy seriously

from here and here

That's not the problem they want to solve. It's cheaper and easier to change the company's appearance than it is to change the company's business model.

Wednesday, September 21, 2022

It's not much of a fine if it's fine with them

from here and here

Thousands of unencrypted hard drives and tapes full of millions of customer records, and Morgan Stanley only has to pay $35M to make up for failing to wipe them before they got sold off to 3rd parties. That's maybe a couple dollars per affected customer. You'd think a financial institution of their calibre would be able to afford a couple more zeros.

Tuesday, September 20, 2022

Who doxes the doxers?

from here and here

I for one am not got to lose any sleep over the possibility of Kiwi Farms getting breached and their emails and passwords leaked. It's challenging to imagine a more deserving group of people for that kind of outcome. 

Thursday, August 18, 2022

They had a doodie to protect their customers

from here and here

If you received the gift of poop and wondered who sent it, finding out may now be possible. Anonymity was necessary for a site like this because taking an action like this has consequences, and now those consequences can play out because the anonymity has been lost.

Wednesday, April 6, 2022

Better hope they forget their passwords

from here and here

If your company is in the technology industry, you should certainly know better than to allow people to retain access to your systems when they're no longer employed by your company, and even more so if your company deals with banking or other financial services.

Friday, March 25, 2022

Security by self-pwn

from here and here

If you beat the attackers to the punch when it comes to leaking your data then I suppose technically you weren't hacked - but does it matter? Your secrets and dirty laundry still get aired that way regardless of who is responsible.