£3 million fine for healthcare MSP with sloppy security after it was hit by ransomware attack.
Sensitive data related to almost 80,000 people exposed, and NHS services disrupted.
Read more in my article on the Exponential-e blog: https://www.exponential-e.com/blog/3-million-fine-for-healthcare-msp-with-sloppy-security-after-it-was-hit-by-ransomware-attack
Tennessee-based Numotion, which advertises itself as the largest provider of wheelchairs and other mobility solutions in the United States, has suffered a #databreach impacting nearly 500,000 people.
https://www.securityweek.com/numotion-data-breach-impacts-nearly-500000-people/
Oracle, 23andMe, and a new contender for Breach of the Year: X
#News #TechNews #Cybersecurity #DataBreach #privacy #healthcare #education #banking
Daily podcast: Oracle, 23andMe, and a new contender for Breach of the Year: X
#News #TechNews #Cybersecurity #DataBreach #privacy #healthcare #education #banking #podcast
Shoot the Messenger, Sunday Edition: Reporting on a leak is not unethical, Hamilton County
See the Chattanooga Times Free Press's full OpEd at: https://www.timesfreepress.com/news/2025/mar/30/opinion-reporting-on-a-leak-is-not-unethical/
Hartsfield-Jackson Atlanta International Airport hit by cyberattack
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/hartsfield-jackson-atlanta-international-airport-hit-by-cyberattack-0-2-c-z-7/gD2P6Ple2L
Here's another notification where it sounds like the victim paid the extortion demand but doesn't come right out and say that. Instead, their notification letter says that the data had temporarily been posted online but "The data is no longer posted on the dark web and, at this time, Kronick has no reason to believe this data was retained by the unknown third party or that any additional data was taken."
They don't name the attackers, but this was an incident involving #Rhysida that Rhysida had claimed on August 22, 2024.
Given how often we are told that these ransomware groups do retain data even after pinky-swearing and providing videos of it supposedly being destroyed forever, should entities like the law firm above say they have no reason to believe that their data was retained?
The notification letter by Kronick Moskovitz Tiedemann & Girard can be found at https://oag.ca.gov/system/files/KMTG_Individual%20Notice%20Letter%20Sample%203.28.2025_0.pdf
Cloud-based streaming company StreamElements confirms it suffered a #databreach at a third-party service provider after a threat actor leaked samples of stolen data on a hacking forum.
If the latest alleged data breach at X is accurate, can we please, pretty please, *follow and enforce* the obligation of transparency, accountability, and prompt disclosure in Europe under the GDPR?
I mean, failing to comply with the breach notification requirements could result in fines of *just* around 2% of X's annual turnover
#OracleHealth breach compromises patient data at US hospitals
Twitter, #X, hit by massive data breach potentially impacting 2.8 billion users, inside job suspected - “A data leak involving a whopping 2.87 billion Twitter (X) users has surfaced on the infamous Breach Forums. According to a post by a user named ThinkingOne, the leak is the result of a disgruntled X employee who allegedly stole the data during a period of mass layoffs. If true, this would be the largest social media data leak in history, but surprisingly, neither X nor the broader public appears to be aware of it.” #DataBreach #DataPrivacy #opsec #infosec #Twitter #privacy
https://hackread.com/twitter-x-of-2-8-billion-data-leak-an-insider-job/
No DMs.
"A data leak involving a whopping 2.87 billion Twitter (X) users has surfaced on the infamous Breach Forums. According to a post by a user named ThinkingOne, the leak is the result of a disgruntled X employee who allegedly stole the data during a period of mass layoffs. If true, this would be the largest social media data leak in history"
https://hackread.com/twitter-x-of-2-8-billion-data-leak-an-insider-job/
No disgruntled employees here, just tired furries.
https://hackread.com/twitter-x-of-2-8-billion-data-leak-an-insider-job/
Odd how so many outlets are reporting "FBI is investigating" the Oracle Health #databreach. Is this to redirect our attention to the FBI and away from Oracle Health's security and PR mess?
"FBI is investigating..." ranks right up there in my list with "80 gadzillion law firms have opened investigations into.... "
Maybe I just need more coffee... ?
Parcel Plus tax preparation service reports data breach affecting customer tax returns
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/parcel-plus-tax-preparation-service-reports-data-breach-affecting-customer-tax-returns-5-0-g-6-j/gD2P6Ple2L
Data breach exposes sensitive military information in India
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/data-breach-exposes-sensitive-military-information-in-india-0-d-b-f-z/gD2P6Ple2L
Oracle Health breach compromises patient data at US Healthcare organizations
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/oracle-health-breach-compromises-patient-data-at-us-healthcare-organizations-m-0-8-c-g/gD2P6Ple2L
The Federal Bureau of Investigation (FBI) is probing the cyberattack at Oracle that has led to the theft of patient data. #databreach
Hackers breached Oracle's Cerner servers after January 22, stealing patient data to extort US medical providers. The FBI is now investigating. #Oracle #Cerner #CyberSecurity #DataBreach #FBI #HealthcareSecurity #MedicalData #TechNews #Ransomware