Fi: Hacker could have personal information of every schoolkid in Helsinki, City says

YLE News reports: The perpetrator of a major hacking of the City of Helsinki’s education division’s database could have accessed the personal information of all compulsory school aged children in the capital, as well as their parents or gua… Continue reading Fi: Hacker could have personal information of every schoolkid in Helsinki, City says

HHS launches $50M security initiative to thwart hospital ransomware

Chad Van Alstin reports: The U.S. Department of Health and Human Services (HHS) is launching a $50 million incentive program to encourage hospitals to improve their cybersecurity. Dubbed the Universal Patching and Remediation for Autonomous Defense—or … Continue reading HHS launches $50M security initiative to thwart hospital ransomware

Swiss law enforcement actions appear linked to seizure of BreachForums

There have been a few developments likely related to the seizure of BreachForums. As a preview, recall that Kantonspolizei Zürich was one of the cooperating entities in the takedown and that the seizure notice had two avatars behind bars. One avatar wa… Continue reading Swiss law enforcement actions appear linked to seizure of BreachForums

British Library’s candid ransomware comms driven by ’emotional intelligence’

Connor Jones reports: Emotional intelligence was at the heart of the British Library’s widely hailed response to its October ransomware attack, according to CEO Roly Keating. The British Library’s (BL) ransomware attack last year was one of… Continue reading British Library’s candid ransomware comms driven by ’emotional intelligence’

Utah Updates to Breach Notification Requirements Take Effect

Dorothy Parson McDermott of JacksonLewis writes: On May 1, 2024, amendments to Utah’s cybersecurity and data breach notification law took effect. The state’s cybersecurity and data breach notification law requires an organization that conducts business… Continue reading Utah Updates to Breach Notification Requirements Take Effect

SEC amends Reg S-P to require data breach notification within 30 days

Aaron Nicodemus reports: The Securities and Exchange Commission (SEC) will require broker-dealers and registered investment advisers to adopt written policies and procedures for handling data breaches of customer data and notify affected customers with… Continue reading SEC amends Reg S-P to require data breach notification within 30 days

Guthrie Lourdes Hospital still struggling with effects of Ascension cyberattack

Phoebe Taylor-Vuolo, Report for America corps member, reports: Guthrie Lourdes Hospital in Binghamton continues to feel the impact of a recent cyberattack on Ascension, its former parent organization. Ascension said it was hit with a ransomware attack … Continue reading Guthrie Lourdes Hospital still struggling with effects of Ascension cyberattack

BreachForums seized by FBI and law enforcement partners; administrator arrested (1)

It probably will not surprise anyone who has checked BreachForums recently, but there is now a seizure notice on the forum. The notice claims that BreachForums is under the control of the FBI and has been taken down by the FBI and DOJ with assistance f… Continue reading BreachForums seized by FBI and law enforcement partners; administrator arrested (1)

‘Got that boomer!’: How cybercriminals steal one-time passcodes for SIM swap attacks and raiding bank accounts

Here’s your “definitely want to read this one today” piece. Zack Whittaker reports: The incoming phone call flashes on a victim’s phone. It may only last a few seconds, but can end with the victim handing over codes that give cybercri… Continue reading ‘Got that boomer!’: How cybercriminals steal one-time passcodes for SIM swap attacks and raiding bank accounts