Data Breaches

Breaches aided by weak passwords, poor AV detection

February 09, 2012

Trustwave's annual review of its data breach response investigations concluded that franchises are now the prime target for hackers seeking customer data, such as credit card numbers.
 

Phishing email leads to Denver area health care breach

February 07, 2012

Hackers may have accessed the personal health data belonging to patients of Denver area-based Metro Community Provider Network, a nonprofit health care provider for low-income individuals and families.
 

Patient data at U of M hospital breached

February 06, 2012

A thief broke into a doctor's car and stole a briefcase containing a flash drive that held personal data on patients of University of Miami Miller School of Medicine.
 

Anonymous raids law firm over its defense of Marine

February 03, 2012

Anonymous stayed busy on Friday with the dump of 300 GB of emails and other communications, lifted from the law firm representing a U.S. Marine who recently escaped jail time for his role in a 2005 massacre.
 

Security breaches impacting VeriSign emerge in filing

February 02, 2012

The company responsible for ensuring that users reach the website they intend to reach admitted in an SEC filing that its network was breached numerous times in 2010.
 

Indiana University hospital hacked to steal data

February 01, 2012

Malware may have allowed attackers to make off with the personal information of thousands of people connected to Indiana University Health Goshen Hospital.
 

Central Kentucky's largest group practice hit with patient data breach

January 31, 2012

A laptop containing personal information of patients was stolen from the neurology department of Lexington Clinic on the night of Dec. 7, 2011.
 

Univ. of Hawaii settles with 98,000 over five breaches

January 27, 2012

The largest class-action settlement in Hawaii's history is related to data breaches at University of Hawaii campuses.
 

Some 2M possibly affected by NYSEG, RG&E data compromise

January 25, 2012

Unauthorized individuals gained access to the personal data belonging to customers of New York State Electric & Gas (NYSEG) and Rochester Gas & Electric (RG&E), which are owned by Iberdrola USA.
 

Symantec admits stolen source code impacts pcAnywhere

January 25, 2012

Big Yellow has done an about-face in light of new analysis that confirms users of its pcAnywhere software may be at risk to attack due to the disclosure of source code.
 

Make the first 24 hours of data breach resolution count

Ozzie Fonseca, senior director, Experian Data Breach Resolution January 19, 2012

If your company doesn't have a response plan, the unending spate of recent breaches is surely motivation enough to create one.
 

Zappos breach affects 24M, opens door for more attacks

January 16, 2012

Hackers breached a server belonging to online retailer Zappos and made off with the personal information of 24 million customers, though no credit card numbers were involved.
 

Symantec: Hackers did steal code, but it's old

January 06, 2012

Symantec confirmed late Thursday that hackers did in fact compromise a portion of its source code, but the stolen code is related to two enterprise security products that have been discontinued.
 

Stratfor subscribers receive phony emails

January 06, 2012

Some Stratfor subscribers received an email on Friday that claimed to come from the breached company's CEO, but actually was designed to publicize the hack and have some fun at the expense of the recipients.
 

Hackers say they have Symantec's Norton AV source code

January 05, 2012

A Symantec spokesman said the company isn't sure if the hackers claims are true, but said no source code -- only a document from 1999 -- has so far been publicly posted.
 

Loma Linda hospital worker fired for taking home private records

January 04, 2012

The private medical records belonging to some 1,300 patients and/or their guarantors at Loma Linda University Medical Center in California were compromised when a former hospital employee violated policy.
 

A resolution to measure more: Data breach consequences

Dan Srebnick, CISO, city of New York January 03, 2012

It's vital to understand how to talk about security to senior executives in order to prevent a data breach, says Dan Srebnick, CISO of the city of New York.
 

SC Magazine survey: Guarding against a data breach

January 03, 2012

Security conversations are as audible as ever, yet budgets remain largely flat. However, an expected influx of compliance audits may serve as the driver for more dollars. We polled 488 pros for their thoughts.
 

Anonymous shreds intelligence firm Stratfor in latest hack

December 25, 2011

In what may be its most devastating attack since HBGary, the Anonymous hacking collective "rooted" the database of security intelligence firm Stratfor to plunder a claimed 200 gigabytes worth of data.
 

U.S. Chamber of Commerce targeted in data heist

December 21, 2011

Hackers operating out of China are believed responsible for a major attack on the U.S. Chamber of Commerce in 2009 and 2010, but which was only revealed recently.
 

Hackers steal 200,000 card numbers from wholesaler

December 19, 2011

Hackers breached the systems of New York-based food services wholesaler Restaurant Depot, and stole hundreds of thousands of credit and debit card numbers.
 

GlobalSign says web server, not CA systems, hit by breach

December 16, 2011

GlobalSign, which briefly halted operations in September out of concern that it was the latest SSL certificate authority hacked, has determined that its CA infrastructure was never compromised.
 

Court tosses claims against Heartland Payment over breach

December 13, 2011

After more than two years of litigation, a U.S. District judge has dismissed nine of the 10 causes of action brought forth as part of a class-action lawsuit by nine banks.
 

Cyber crime aftermath: Beyond the indictment

Stephen Cobb, security evangelist at ESET December 09, 2011

The aftermath of a cyber crime takedown poses new challenges to law enforcement, like what to do about the victims' systems and data
 

Anonymous claims new Monsanto-related hack

December 08, 2011

The Anonymous hacktivist group claims it is responsible for putting a Washington, D.C. public relations firm, which formerly worked with the oft-criticized biotech giant Monsanto, out of business.
 

Podcast: Fixing the SSL certificate chain

November 30, 2011

In this podcast, Access' Gustaf Bjorksten discusses why the SSL system has failed and what is necessary to improve its existing design and implementation. He helped author a call-to-action paper, and believes the future trust and privacy of the internet relies on finding a solution.
 

Hackers steal credit card numbers from cash registers at UC Riverside

November 29, 2011

Hackers compromised cash registers at campus dining locations at the University of California, Riverside to hijack credit and debit card numbers.
 

Sutter Health faces lawsuit after lost computer

November 23, 2011

The unencrypted data of 4.2 million Sutter Health patients went missing last month, and now the health care providers faces legal action.
 

Sutter Health loses computer, data on 4.2 million

November 16, 2011

Northern California-based Sutter Health is the second major health care organization to fall victim to a major breach of unencrypted data.
 

VCU server hacked to compromise personal data of 175K

November 14, 2011

Hackers accessed a sensitive computer server containing the personal information of faculty and students at Virginia Commonwealth University (VCU) in Richmond.