Data Breaches
Hackers demand $15 million ransom from TransUnion after cracking “password” password
International credit bureau TransUnion says that hackers managed to breach a server operated by its South African division, and gained access to the personal information of individuals. According to an FAQ published by TransUnion South Africa, the cybercriminals gained access to the sensitive data by using the compromised credentials of one of…
Read More »SEC to Require Hacks to Be Reported Within Four Days
Wall Street’s watchdog voted to unveil a rule on Wednesday that aims to enhance how public companies disclose when they experience a breach, and how soon. Under the proposed Securities and Exchange Commission (SEC) measures, a company would have to spell out when it experiences a risk and what strategies…
Read More »Fraud and scam activity hits all-time high
Using data gathered from analyzing more than one billion sites, the 2022 State of Phishing and Online Fraud Report highlights the trends that drove digital scams in 2021. In this, the company’s third year of tracking phishing and scam data, we can see with no uncertainty how the pandemic has…
Read More »Telco fined €9 million for hiding cyberattack impact to customers
The Greek data protection authority has imposed fines of 5,850,000 EUR ($6.55 million) to COSMOTE and 3,250,000 EUR ($3.65 million) to OTE, for leaking sensitive customer communication due to a cyberattack. As the agency says in an announcement, COSMOTE infringed at least eight articles of the GDPR, including violating its duty to…
Read More »10 crisis communications tips for privacy breaches
Privacy breaches are happening all the time and they can have dire consequences. When (not if) you experience a breach, the stakeholder trust that’s been built in your organization is on the line. How you handle the breach can affect how you maintain and, if necessary, rebuild that trust. How you communicate when…
Read More »FTC warns companies to secure consumer data from Log4J attacks
The US Federal Trade Commission (FTC) has warned today that it will go after any US company that fails to protect its customers’ data against ongoing Log4J attacks. “The FTC intends to use its full legal authority to pursue companies that fail to take reasonable steps to protect consumer data…
Read More »Five common misperceptions about business cyberattacks
Most decision makers in IT management are having to spin so many plates, all at the same time, that there’s always a danger one of them will eventually fall to the floor and smash. The problem is, just because you’ve attended to a cyber security issue, or decided that it’s…
Read More »Black Hat: GDPR privacy law exploited to reveal personal data
About one in four companies revealed personal information to a woman’s partner, who had made a bogus demand for the data by citing an EU privacy law. The security expert contacted dozens of UK and US-based firms to test how they would handle a “right of access” request made in…
Read More »Hackers are exploiting a server vulnerability with a severity of 9.8 out of 10
In a development security pros feared, attackers are actively targeting yet another set of critical server vulnerabilities that leave corporations and governments open to serious network intrusions. The vulnerability this time is in BIG-IP, a line of server appliances sold by Seattle-based F5 Networks. Customers use BIG-IP servers to manage…
Read More »The Great $50M African IP Address Heist
A top executive at the nonprofit entity responsible for doling out chunks of Internet addresses to businesses and other organizations in Africa has resigned his post following accusations that he secretly operated several companies which sold tens of millions of dollars worth of the increasingly scarce resource to online marketers.…
Read More »