Canadian federal privacy commissioner says BMO security breach in 2017 affected 113,000 client accounts

James Bradshaw reports: A 2017 data breach that exposed personal information belonging to more than 113,000 Bank of Montreal customers exploited “significant weaknesses” in the bank’s safeguards that have since been strengthened, according to a report … Continue reading Canadian federal privacy commissioner says BMO security breach in 2017 affected 113,000 client accounts

10 countries simulate cyber attack on global financial system

Steven Scheer of Reuters reports: Israel on Thursday led a 10-country simulation of a major cyber attack on the global financial system in an attempt to increase cooperation that could help to minimise any potential damage to financial markets and bank… Continue reading 10 countries simulate cyber attack on global financial system

PNB denies cybersecurity firm’s claim that 180 million customers’ data was breached, but CyberX9 calls their denial “false and misleading”

Regina Mihindukulasuriya reports: The Punjab National Bank (PNB) has denied media reports that over 180 million customers’ data has been breached or exposed, adding that the bank is certified with ISO 27001 standards for information security practices…. Continue reading PNB denies cybersecurity firm’s claim that 180 million customers’ data was breached, but CyberX9 calls their denial “false and misleading”

Polish DPA: Bank Millennium fined 80,000 EUR for failure to notify the breach and the data subjects about the incident

22 November 2021 Background information Date of final decision: 14 October 2021 Cross-border case or national case: National case Controller: Bank Millennium S.A. Legal Reference: Notification of a personal data breach to the supervisory authority (Art… Continue reading Polish DPA: Bank Millennium fined 80,000 EUR for failure to notify the breach and the data subjects about the incident

US regulators order banks to report cyberattacks within 36 hours

Sergiu Gatlan reports: US federal bank regulatory agencies have approved a new rule ordering banks to notify their primary federal regulators of significant computer-security incidents within 36 hours. Banks are only required to report major cyberattac… Continue reading US regulators order banks to report cyberattacks within 36 hours

Attorney General James Directs Unregistered Crypto Lending Platforms to Cease Operations In New York, Announces Additional Investigations

NEW YORK – New York Attorney General Letitia James today announced new efforts she is taking to protect New York investors, and the trading markets more generally, from exploitation by high-risk virtual currency schemes. Virtual or “crypto” currency le… Continue reading Attorney General James Directs Unregistered Crypto Lending Platforms to Cease Operations In New York, Announces Additional Investigations

Millions of South Africans caught up in security incident after debt recovery firm suffers ‘significant data breach’

Jessica Haworth has more details on a breach previously reported on this site. More than a million South African citizens have potentially had their personal data exposed after a ransomware attack at a debt recovery services firm. The company in questi… Continue reading Millions of South Africans caught up in security incident after debt recovery firm suffers ‘significant data breach’