Data breach of two third-party payment operators affects more than 33 million in France: CNIL opens an investigation

Google translation of some of CNIL’s report: The CNIL was informed by Viamedis and Almerys of the computer attack to which they were victims at the end of January. These operators, who manage third-party payment for complementary health insurance… Continue reading Data breach of two third-party payment operators affects more than 33 million in France: CNIL opens an investigation

Ransomware Payments Exceed $1 Billion in 2023, Hitting Record High After 2022 Decline

Chainalysis got everyone’s attention with their new report. They write, in part: 2023 marks a major comeback for ransomware, with record-breaking payments and a substantial increase in the scope and complexity of attacks — a significant reversal … Continue reading Ransomware Payments Exceed $1 Billion in 2023, Hitting Record High After 2022 Decline

Reward Offers for Information to Bring Hive Ransomware Variant Co-Conspirators To Justice

Today, the Department of State is announcing a reward offer of up to $10,000,000 for information leading to the identification and/or location of any individual(s) who hold a key leadership position in the Hive ransomware variant transnational organize… Continue reading Reward Offers for Information to Bring Hive Ransomware Variant Co-Conspirators To Justice

Protect Good Faith Security Research Globally in Proposed UN Cybercrime Treaty

Statement to be submitted by the Electronic Frontier Foundation, accredited under operative paragraph No. 9 of UN General Assembly Resolution 75/282, on behalf of 124 signatories. We, the undersigned, representing a broad spectrum of the global securit… Continue reading Protect Good Faith Security Research Globally in Proposed UN Cybercrime Treaty

HHS’ Office for Civil Rights Settles Malicious Insider Cybersecurity Investigation for $4.75 Million

Today, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), announced a settlement with Montefiore Medical Center, a non-profit hospital system based in New York City for several potential violations of the Health Insu… Continue reading HHS’ Office for Civil Rights Settles Malicious Insider Cybersecurity Investigation for $4.75 Million

Cloudflare hacked using auth tokens stolen in Okta attack

Sergiu Gatlan reports: Cloudflare disclosed today that its internal Atlassian server was breached by a suspected ‘nation state attacker’ who accessed its Confluence wiki, Jira bug database, and Bitbucket source code management system. The t… Continue reading Cloudflare hacked using auth tokens stolen in Okta attack

Ex-CIA software engineer sentenced to 40 years for giving secrets to WikiLeaks

The Guardian reports: A former Central Intelligence Agency (CIA) software engineer who was convicted for carrying out the largest theft of classified information in the agency’s history and of charges related to child abuse imagery was sentenced to 40 … Continue reading Ex-CIA software engineer sentenced to 40 years for giving secrets to WikiLeaks

FTC Order Will Require Blackbaud to Delete Unnecessary Data, Boost Safeguards to Settle Charges its Lax Security Practices Led to Data Breach

FTC says company’s poor security allowed hacker to steal sensitive data of millions of consumers, go undetected for months South Carolina-based Blackbaud Inc. will be required to delete personal data that it doesn’t need to retain as part of a settleme… Continue reading FTC Order Will Require Blackbaud to Delete Unnecessary Data, Boost Safeguards to Settle Charges its Lax Security Practices Led to Data Breach