Your personal data may have been compromised, Malaysia Airlines tells its frequent flyer members

Shahrin Aizat Noorshahrizam reports: National carrier Malaysia Airlines informed members of its frequent flyer programme Enrich that there had been a “data security incident” at one of its third-party IT service providers. According to the airlines, th… Continue reading Your personal data may have been compromised, Malaysia Airlines tells its frequent flyer members

The Jones Day dump contains prescription drug records. Who’s notifying those patients of the breach?

By now, many are aware that Jones Day, a giant law firm, had some of its files stolen due to vulnerabilities in the standalone file transfer administration system by Accellion.  Jones Day is one of dozens of Accellion clients that have found themselves… Continue reading The Jones Day dump contains prescription drug records. Who’s notifying those patients of the breach?

French Regulator Lambasts Health Firms Over Mass Data Leak

Helene Fouquet reports: France’s privacy watchdog said it’s investigating the leak of sensitive health data on half a million people and said the companies involved could face heavy penalties if they don’t come forward with details of the breaches. The… Continue reading French Regulator Lambasts Health Firms Over Mass Data Leak

CISA Releases Joint Cybersecurity Advisory on Exploitation of Accellion File Transfer Appliance

The cybersecurity authorities of Australia, New Zealand, Singapore, the United Kingdom, and the United States have released Joint Cybersecurity Advisory AA21-055A: Exploitation of Accellion File Transfer Appliance. Cyber actors worldwide have exploited… Continue reading CISA Releases Joint Cybersecurity Advisory on Exploitation of Accellion File Transfer Appliance

Fears grow data hacked from Reserve Bank may be leaked by CLOP ransomware group

Tom Pullar-Strecker reports: A ransomware gang appears to be releasing confidential data obtained from the hack of customers of US software company Accellion, raising fears that New Zealand banks may be next to have data exposed. The Reserve Bank admit… Continue reading Fears grow data hacked from Reserve Bank may be leaked by CLOP ransomware group

FireEye and Accellion provide more details on attack

Andrew Moore, Genevieve Stark, Isif Ibrahima, Van Ta of FireEye write: Starting in mid-December 2020, malicious actors that Mandiant tracks as UNC2546 exploited multiple zero-day vulnerabilities in Accellion’s legacy File Transfer Appliance (FTA) to in… Continue reading FireEye and Accellion provide more details on attack

Kroger reports Accellion data breach affecting pharmacy records, associate HR data

Brian Planalp reports: Kroger is informing some customers and associates that a third-party software company it uses for data services recently suffered a data breach. Kroger’s own IT systems were not affected, and no grocery store data, credit or debi… Continue reading Kroger reports Accellion data breach affecting pharmacy records, associate HR data

Accellion’s data breach left clients in tough position: pay extortion to criminals, or have their data dumped

A breach involving Accellion‘s older file transfer application has left a number of its customers in the unenviable position of not only having a data breach to deal with, but with the added threat that their data and their clients’ data wi… Continue reading Accellion’s data breach left clients in tough position: pay extortion to criminals, or have their data dumped

California DMV halts data transfers with third-party company after security breach

Jonathan Ayestas reports: The California Department of Motor Vehicles announced Wednesday that a third-party company it shares data with has had a security breach. It is unclear if any DMV information was compromised at this time. Automatic Funds Trans… Continue reading California DMV halts data transfers with third-party company after security breach