Compliance: National Credit Union Administration issues letter on cyber incident reporting notification requirements

CUNA reports: NCUA issued a Letter to Credit Unions (23-CU-07) on the cyber incident notification requirements that go into effect Sept. 1. Credit unions will be required to notify the NCUA no later than 72 hours after the credit union reasonably belie… Continue reading Compliance: National Credit Union Administration issues letter on cyber incident reporting notification requirements

Proposed Second Amendment to NYDFS Cybersecurity Regulations: Comments Due August 14

Micaela McMurrough and Caleb Skeath of Covington & Burling write: Following up on the recent release by the New York Department of Financial Services (“NYDFS”) of an updated proposed second amendment to its “first-in-the-nation” Cybersecurity Regul… Continue reading Proposed Second Amendment to NYDFS Cybersecurity Regulations: Comments Due August 14

16-year-old youth among 13 arrested for alleged involvement in banking-related malware scams in Singapore

The Straits Times/ANN reports: Thirteen people, including a 16-year-old youth, were arrested for their suspected involvement in the recent spate of banking-related malware scam cases. Preliminary investigations showed that 10 of the 13 suspects, aged b… Continue reading 16-year-old youth among 13 arrested for alleged involvement in banking-related malware scams in Singapore

Pk: Tension within SECP escalates as it tries to downplay data breach

Umar Cheema reports: Sensitive data of the Securities and Exchange Commission of Pakistan (SECP) has allegedly been stolen which has resulted in a tug of war between the chairman and the relevant commissioner. The latter claims she was kept in dark abo… Continue reading Pk: Tension within SECP escalates as it tries to downplay data breach

US regulator urges MFA and puts banks on notice – not reasonably protecting data is illegal

Jim Nash reports: A U.S. consumer finance regulator has published a circular warning that insufficient security for consumer biometric and other personal data is illegal under federal law. Multi-factor authentication is singled out as a method of makin… Continue reading US regulator urges MFA and puts banks on notice – not reasonably protecting data is illegal

Malaysian payment gateway platform iPay88 suffers data leak, card data may be compromised

Raymond Saw reports: If you typically use contactless payment methods, chances are that you’ve used iPay88 even without realising it. iPay88 is one of Malaysia’s biggest payment gateway platforms, providing point-of-sale solutions for plenty of merchan… Continue reading Malaysian payment gateway platform iPay88 suffers data leak, card data may be compromised