Anthem, Apple and the Pentagon: A Data-Breach Cornucopia

A record fine and two new compromises kick off the autumn compromise season. Continue reading Anthem, Apple and the Pentagon: A Data-Breach Cornucopia

Anthem will pay $16 million to settle HIPAA violation due to 2015 breach

Anthem has agreed to pay $16 million to the U.S. Department of Health and Human Services, Office for Civil Rights (OCR) and take substantial corrective action to settle potential violations of the Health Insurance Portability and Accountability Act (HI… Continue reading Anthem will pay $16 million to settle HIPAA violation due to 2015 breach

Reaper authors Chinese, possibly linked to cyberspy group ‘Black Vine’

The authors of a sophisticated strain of malware that’s been attacking internet of things devices are almost certainly Chinese and could be connected to a Beijing-linked cyber-espionage group believed behind the Anthem health insurance hack, according to new research. Check Point Technologies — the Israeli cyber outfit that was the first to publicly identify the malware, known variously as Reaper or IoTroop — said in a technical report released this weekend that the malware authors and operators are operating out of China. “We have a very high degree of confidence about that judgement,” Yaniv Balmas, the firm’s security research group manager told CyberScoop. His conclusion comes from multiple independent factors. A unique feature of the malware, Balmas noted, was its use of a Lua environment. Lua is a lightweight, embeddable programming language designed to enable scripts to run. “We’ve never seen it [used in malware] before,” said Balmas, adding it made the malware “very agile … […]

The post Reaper authors Chinese, possibly linked to cyberspy group ‘Black Vine’ appeared first on Cyberscoop.

Continue reading Reaper authors Chinese, possibly linked to cyberspy group ‘Black Vine’

Anthem will pay $115 million in largest data breach settlement in history

Anthem Inc. agreed to pay $115 million in a deal to end a court battle over the 2015 data breach where hackers gained access to sensitive records for nearly 80 million Americans. The funds will go toward credit monitoring and reimbursement for customers, in addition to as much as $38 million in attorneys’ fees. The 2015 breach saw hackers access records including Social Security numbers, birthdays, addresses, detailed employment information and income data. Chinese state-sponsored attackers were suspected in the attack but there has been no official attribution. The settlement requires Anthem to guarantee “a certain level of funding for information security and to implement or maintain numerous specific changes to its data security systems, including encryption of certain information and archiving sensitive data with strict access controls,” according to a statement by the plaintiffs’ attorneys. “The settlement is designed to protect class members from future risk, provide compensation, and ensure best cybersecurity practices to […]

The post Anthem will pay $115 million in largest data breach settlement in history appeared first on Cyberscoop.

Continue reading Anthem will pay $115 million in largest data breach settlement in history