Edfinancial and OSLA student loan account registration info hacked in Nelnet breach; 2.5 million affected

Many student loan borrowers caught a huge break this week with government forgiveness of some student loan debt. But for 2.5 million student loan borrowers, the week also brought news of a breach of their contact information and Social Security numbers… Continue reading Edfinancial and OSLA student loan account registration info hacked in Nelnet breach; 2.5 million affected

Facebook-Cambridge Analytica data breach lawsuit ends in 11th hour settlement

Mark Townsend reports: Facebook has dramatically agreed to settle a lawsuit seeking damages for allowing Cambridge Analytica access to the private data of tens of millions of users, four years after the Observer exposed the scandal that mired the tech … Continue reading Facebook-Cambridge Analytica data breach lawsuit ends in 11th hour settlement

NHS cyberattack causing ‘total chaos’ in hospitals could take a year to recover

Rebecca Thomas reports: It could take more than a year for hospitals to recover patient record systems following the recent NHS cyberattack, The Independent has learned. Hospitals impacted are likely to need two weeks to recover for every day the situa… Continue reading NHS cyberattack causing ‘total chaos’ in hospitals could take a year to recover

New ‘Donut Leaks’ extortion gang linked to recent ransomware attacks

Lawrence Abrams reports: A new data extortion group named ‘Donut Leaks’ is linked to recent cyberattacks, including those on Greek natural gas company DESFA, UK architectural firm Sheppard Robson, and multinational construction company Sand… Continue reading New ‘Donut Leaks’ extortion gang linked to recent ransomware attacks

OCR Settles Case Involving Decade-Long Improper Disposal of Protected Health Information

There is an enforcement update to an incident noted on this site in 2018. The incident that involved New England Dermatology P.C., d/b/a New England Dermatology and Laser Center (“NDELC”) was summarized by HHS in their resolution agreement and correcti… Continue reading OCR Settles Case Involving Decade-Long Improper Disposal of Protected Health Information

Ex-Twitter exec blows the whistle, alleging reckless and negligent cybersecurity policies

By Donie O’Sullivan, Clare Duffy and Brian Fung, CNN Business Video by John General, Zach Wasser and Logan Whiteside, CNN Business Portraits by Sarah Silbiger for CNN Twitter has major security problems that pose a threat to its own users’ … Continue reading Ex-Twitter exec blows the whistle, alleging reckless and negligent cybersecurity policies

From the “What Could Possibly Go Wrong Department” after it went wrong, Monday edition

In June, many of us first became aware that Facebook was receiving sensitive medical information from hospital websites. Of 33 hospital websites that The Markup tested, 10 of them had trackers (“Meta Pixels”) which sent information to Faceb… Continue reading From the “What Could Possibly Go Wrong Department” after it went wrong, Monday edition