OIG audit of hospital’s cybersecurity finds vulnerabilities in common web applications

Chad van Alstin reports: The U.S. Department of Health and Human Services Office of the Inspector General (OIG) released a report focused on a “large Southeastern hospital” that the agency said had security vulnerabilities that could be vectors for a c… Continue reading OIG audit of hospital’s cybersecurity finds vulnerabilities in common web applications

Two Ivy League universities had donor information breaches. Will donors be notified?

Harvard University and the University of Pennsylvania (UPenn) have more in common than just being Ivy League universities. Both suffered data breaches involving donor information, and their stolen data was leaked. Harvard On November 18, Harvard discov… Continue reading Two Ivy League universities had donor information breaches. Will donors be notified?

Don’t panic: 0apt’s listings and data leaks are fakes — Researchers

If you noticed a lot of dark web leak site listings by a new group, 0apt, and have been concerned about whether they might be a dangerous and prolific group, the DataBreach[.]com team (no relationship to DataBreaches[.]net) has a reassuring message for… Continue reading Don’t panic: 0apt’s listings and data leaks are fakes — Researchers

Former Nuance Communications employee facing more charges in 2023 Geisinger data breach case

John Beauge reports an update to the previously reported case of a former Nuance Communications employee who compromised the protected health information of more than 1.3 million Geisinger Health patients two days after Nuance had terminated his employ… Continue reading Former Nuance Communications employee facing more charges in 2023 Geisinger data breach case

Ransomware attack compromised 377,000 people’s Social Security and driver’s license numbers from Texas gas station and convenience store chain

Kurt Knutsson recently reported on a ransomware attack in September that affected 377,082 individuals. Gulshan Management Services, Inc. is linked to Gulshan Enterprises, which operates around 150 Handi Plus and Handi Stop gas stations and convenience … Continue reading Ransomware attack compromised 377,000 people’s Social Security and driver’s license numbers from Texas gas station and convenience store chain

IA: Dallas County to pay $600,000 to security testers arrested in 2019

Phillip Sitter and William Morris report and update on a case in Iowa where security researchers were arrested — for doing what they had been hired to do. Add this to any list of legal threats researchers face. Dallas County is paying $600,000 to… Continue reading IA: Dallas County to pay $600,000 to security testers arrested in 2019

Under Pressure: Exploring the effect of legal and criminal threats on security researchers and journalists

“Dissent Doe,” DataBreaches.net admin@databreaches.net Zack Whittaker, this.weekinsecurity.com this@weekinsecurity.com February 2026. [Download .pdf version] Key takeaways Three-quarters of respondents in a pilot survey of journalists and s… Continue reading Under Pressure: Exploring the effect of legal and criminal threats on security researchers and journalists

Threats: Results of a pilot survey on threats, and a new category on DataBreaches.net

So Zack Whittaker (of TechCrunch and this week in security fame) and I were chatting about some of the many threats we’ve had to deal with over the years — threats of litigation, criminal charges,  and threats by criminals all leapt immedia… Continue reading Threats: Results of a pilot survey on threats, and a new category on DataBreaches.net

RINA Accountants & Advisors is creating $400K settlement fund to settle lawsuit over 2022 data breach

Mark Emem reports: A US accounting firm has agreed to pay hundreds of thousands of dollars to settle a class action lawsuit filed over a data breach. According to the settlement administrator’s portal, RINA Accountants & Advisors will set up a $400… Continue reading RINA Accountants & Advisors is creating $400K settlement fund to settle lawsuit over 2022 data breach