New York updates its breach notification law in response to Equifax, GDPR

Businesses throughout the U.S. will now be required to notify New Yorkers as quickly as possible when their information is compromised in a security incident, under a bill that Gov. Andrew Cuomo signed Thursday. The consumer-friendly data protection law updates New York’s current rules to cover biometric data, and forces firms to alert consumers when their email address, combined with the corresponding passwords or security questions and answers, are compromised. The state legislature quietly passed the Stop Hacks and Improve Electronic Data Security Act, or SHIELD Act, in June. The law, which takes effect March 2020, requires companies to notify individuals “in the most expedient time possible and without unreasonable delay,” a time period that generally means 30 days, state Sen. Kevin Thomas, who re-introduced the SHIELD Act after it failed to pass in 2017, previously told CyberScoop. If the incident affects more than 500 New York residents, the affected business is required to provide written […]

The post New York updates its breach notification law in response to Equifax, GDPR appeared first on CyberScoop.

Continue reading New York updates its breach notification law in response to Equifax, GDPR

The Importance of Cybersecurity for Online Gaming

Casinos have been a target for scammers from the early days of their existence. The industry is highly connected with money, which makes it a prime target. Nowadays, more and more casino businesses are created on the internet, but the threat from fraud… Continue reading The Importance of Cybersecurity for Online Gaming

How well are healthcare organizations protecting patient information?

Healthcare organizations have high levels of confidence in their cybersecurity preparedness despite most of them using only basic user authentication methods in the face of an increasing number of patient identity theft and fraud instances in the marke… Continue reading How well are healthcare organizations protecting patient information?

Synthetic identity theft is the fastest-growing financial crime in the U.S.

A new kind of identity theft that combines stolen personal data with fabricated information is on the rise, and it’s helping more digital thieves ruin Americans’ credit without fear of detection, according to a new white paper from the U.S. Federal Reserve. Known as “synthetic identity theft,” the tactic is distinct from traditional forms of identity fraud. Instead of stealing a person’s name, Social Security number and opening lines of credit, thieves combine a fake name and other fictional personal data such as a date of birth with a true Social Security number. It’s the fastest-growing type of financial crime in the U.S. thanks mostly to a huge uptick of personal information exposed in data breaches in recent years, according to the paper published Monday. “With synthetic ID fraud you can run the same playbook over and over again with 10 or 20 identities and they can’t even track you […]

The post Synthetic identity theft is the fastest-growing financial crime in the U.S. appeared first on CyberScoop.

Continue reading Synthetic identity theft is the fastest-growing financial crime in the U.S.

Bitcoin verify your Identity phishing scam hosted on Microsoft Azure hosting

I  am seeing a bitcoin phishing scam campaign this morning hosted on Microsoft Azure/windows.net. The emails pretend to come from your own email address and are addressed to the same email address. All hosting companies get abused and used for malware,… Continue reading Bitcoin verify your Identity phishing scam hosted on Microsoft Azure hosting

voicemail phishing scam involving compromised OneDrive for business site

We see lots of phishing attempts for email credentials. This one is slightly different than many others and somewhat more  complicated. It pretends to be a message to download a voicemail. You can now submit suspicious sites, emails and files via our S… Continue reading voicemail phishing scam involving compromised OneDrive for business site