Treasury agrees to block additional DOGE staff from accessing sensitive payment systems

Suzanne Smalley reports: The Treasury Department has agreed to temporarily block all but two members of the Trump administration’s Department of Government Efficiency (DOGE) team from accessing sensitive payment records and to limit their access to “re… Continue reading Treasury agrees to block additional DOGE staff from accessing sensitive payment systems

Nine months after discovering a ransomware attack, Teton Orthopaedics notifies patients

On March 25, DataBreaches entered Teton Orthopaedics’ name on a monthly worksheet this site uses for tracking breaches in the healthcare sector. The entry wasn’t based on any report by Teton Orthopaedics or media, and DataBreaches had been … Continue reading Nine months after discovering a ransomware attack, Teton Orthopaedics notifies patients

PowerSchool Incident: A few resources for teachers, parents, and former students

DataBreaches is trying to keep up with updates from PowerSchool, but from the outset, DataBreaches has recommended districts, parents, and teachers assume the worst — i.e., assume that all of the data really weren’t deleted permanently. On … Continue reading PowerSchool Incident: A few resources for teachers, parents, and former students

Nebraska AG becomes first state to sue Change Healthcare over massive data breach

Aaron Sanderford reports: Nebraska on Monday became the first state to sue Tennessee-based Change Healthcare over the company’s massive data breach that cost at least 575,000 Nebraskans their personal information and medical records. … The breach… Continue reading Nebraska AG becomes first state to sue Change Healthcare over massive data breach

New Australian Law Requires Victims To Disclose Ransom Payments

Maybe some victims will decide not to pay ransom since they will have to disclose the payment anyway?  Jayant Chakravart reports: The Australian government’s proposed cybersecurity legislation passed both houses of the Parliament on Monday, forma… Continue reading New Australian Law Requires Victims To Disclose Ransom Payments

Since June, two groups claim to have attacked The Eye Clinic Surgicenter. What do we know?

One cyberattack is distressing enough. But has The Eye Clinic Surgicenter been attacked by two different groups this year? Silence is not golden if patient data has already been leaked.  Last week, Meow Leaks added The Eye Clinic Surgicenter in Montana… Continue reading Since June, two groups claim to have attacked The Eye Clinic Surgicenter. What do we know?

SEC Charges Four Companies With Misleading Cyber Disclosures

Washington D.C., Oct. 22, 2024 — The Securities and Exchange Commission today charged four current and former public companies – Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies Ltd, and Mimecast Limited – with making materially mi… Continue reading SEC Charges Four Companies With Misleading Cyber Disclosures

Malaysia’s government to amend Personal Data Protection Act to require notification of data breaches

The Sun reports: The government is planning to amend the Personal Data Protection Act of 2010 to include breach notification requirements that compel companies to inform authorities when a data breach happens in commercial transactions, said Digital Mi… Continue reading Malaysia’s government to amend Personal Data Protection Act to require notification of data breaches