Murfreesboro Medical Clinic & SurgiCenter ransomware attack affected 559,000 patients

On May 6 and May 7, DataBreaches reported that the attack on Murfreesboro Medical Clinic & SurgiCenter (“MMC”) appeared to be the work of the ransomware group known as BianLian. On June 14, MMC issued an updated notice on their website, as noted by… Continue reading Murfreesboro Medical Clinic & SurgiCenter ransomware attack affected 559,000 patients

ARx Patient Solutions and ARx Patient Solutions Pharmacy notify patients of a March, 2022 breach

ARx Patient Solutions and its affiliate pharmacy, ARx Patient Solutions Pharmacy, have issued a press release about a data breach affecting patient data. Their notice states, “It was determined that in March 2022, an employee email account was co… Continue reading ARx Patient Solutions and ARx Patient Solutions Pharmacy notify patients of a March, 2022 breach

San Bernardino Sheriff’s Department update: can’t rule out that PII and PHI were accessed in ransomware attack

The Fontana Herald News alerts us to an update by the San Bernardino County Sheriff’s Department concerning the ransomware attack they experienced in early April. The county now states that they have been unable to determine definitively if perso… Continue reading San Bernardino Sheriff’s Department update: can’t rule out that PII and PHI were accessed in ransomware attack

16-year-old youth among 13 arrested for alleged involvement in banking-related malware scams in Singapore

The Straits Times/ANN reports: Thirteen people, including a 16-year-old youth, were arrested for their suspected involvement in the recent spate of banking-related malware scam cases. Preliminary investigations showed that 10 of the 13 suspects, aged b… Continue reading 16-year-old youth among 13 arrested for alleged involvement in banking-related malware scams in Singapore

Mount Desert Island Hospital notifies 24,180 patients of April network attack

On June 30, Mount Desert Island Hospital in Maine reported a breach to HHS that affected 24,180 patients. The hospital had previously disclosed the incident on June 5, when they posted a notice on their website that said that they had detected unusual … Continue reading Mount Desert Island Hospital notifies 24,180 patients of April network attack

TSMC confirms data breach after LockBit cyberattack on third-party supplier

Carly Page reports: Taiwan Semiconductor Manufacturing Company (TSMC), the world’s largest contract chipmaker, has confirmed it’s experienced a data breach after being listed as a victim by the LockBit ransomware gang. The Russia-linked LockBit r… Continue reading TSMC confirms data breach after LockBit cyberattack on third-party supplier

Breach Victims Have Standing When Data Misused, 1st Circuit Says

Christopher Brown reports: A data-breach victim whose personal information was subject to actual misuse has standing to sue the entity that suffered the breach, a federal appeals court said. Plaintiff Alexsis Webb plausibly alleged an injury-in-fact su… Continue reading Breach Victims Have Standing When Data Misused, 1st Circuit Says

I had been chatting with a blackhat. They had been working with a whitehat. We were both dealing with the same person.

On April 18, DataBreaches reported that more details had emerged on the arrest of three men by Dutch police in January. The three were suspected of hacking and extorting victims in the Netherlands and elsewhere, obtaining and selling data online, and m… Continue reading I had been chatting with a blackhat. They had been working with a whitehat. We were both dealing with the same person.

At least 100,000 could have had data exposed after US health department was hit by global MOVEit cyberattack

Sean Lyngaas reports: At least 100,000 people could have had their data compromised by a hack of contractors at the Department of Health and Human Services, a department official said Thursday, making it the latest US government agency to be caught up … Continue reading At least 100,000 could have had data exposed after US health department was hit by global MOVEit cyberattack