<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/data-leakage"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Data-leakage ]]></title>
                <link>https://www.itpro.com/uk/tag/data-leakage</link>
        <description><![CDATA[ All the latest data-leakage content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Thu, 19 Jun 2025 09:50:48 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Scania admits leak of data after extortion attempt ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/scania-admits-leak-of-data-after-extortion-attempt</link>
                                                                            <description>
                            <![CDATA[ Hacker stole 34,000 files from a third-party managed website, trucking company says ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dKZpVaVmtNyw6ris6vVNEE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/A5ibroMjY7mAsEMiBasQdC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Jun 2025 09:50:48 +0000</pubDate>                                                                                                                                <updated>Thu, 19 Jun 2025 11:21:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/A5ibroMjY7mAsEMiBasQdC-1280-80.jpg">
                                                            <media:credit><![CDATA[Scania Press]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Scania truck driving through the country]]></media:description>                                                            <media:text><![CDATA[A Scania truck driving through the country]]></media:text>
                                <media:title type="plain"><![CDATA[A Scania truck driving through the country]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/A5ibroMjY7mAsEMiBasQdC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Swedish trucking giant Scania has confirmed the hack of a third-party website leaked 34,000 files, but says the impact is so far "very limited."</p><p>Last week, a hacker <a href="https://x.com/H4ckmanac/status/1933102217562562836">claimed</a> to have breached an insurance subdomain at Scania's website, claiming to have accessed and exfiltrated 34,000 files – which were then offered for sale on the <a href="https://www.itpro.com/infrastructure/network-internet/362740/five-secrets-about-the-dark-web-you-didnt-know">dark web</a>. </p><p>The website that was impacted is part of Scania Corporate Insurance services, and Scania told media that the site is operated by a third-party, adding that "current indications suggest the impact is very limited." The hacker reportedly attempted to extort the company and its employees before listing the data for sale online. </p><p>The attack comes amid a rise in <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a>, which could be worse if <a href="https://www.itpro.com/security/ransomware/ransomware-attacks-reporting-fbi">companies are quietly paying</a> out without reporting such incidents. Manufacturing companies, including the automotive sector, are increasingly becoming victims, with <a href="https://www.itpro.com/security/ransomware/tata-technologies-hit-by-ransomware-attack">Tata Technologies</a> hit by a ransomware attack earlier this year that forced systems offline, and <a href="https://www.itpro.com/security/cyber-attacks/toyotas-cyber-woes-continue-as-latest-breach-marks-fifth-major-it-incident-in-two-years">Toyota hit five times in two years</a>. </p><p>"Criminals continue to target the automotive industry due to its profitability through the vast amounts of sensitive data it holds," said Andrew Lintell, General Manager for EMEA at Claroty.</p><p><strong>What happened</strong></p><p>The company told the <a href="https://www.bleepingcomputer.com/news/security/scania-confirms-insurance-claim-data-breach-in-extortion-attempt/"><em>BleepingComputer</em></a> security site that the hackers used credentials stolen using malware to access the insurance claim documents at the end of May, and later emailed Scania employees with ransom demands under threat of leaking the data, before listing it for sale online. </p><p>"We can confirm there has been a security-related incident in the application "<em>insurance.scania.com</em>", the application is provided by an external IT partner," a Scania spokesperson said in a statement supplied to the publication. "On the 28th and 29th of May, a perpetrator used credentials for a legitimate external user to gain access to a system used for insurance purposes; our current assumption is that the credentials used by the perpetrator were leaked by a password stealer malware."</p><p>The statement added: "Using the compromised account, documents related to insurance claims were downloaded."</p><p>According to the statement, the extortion emails arrived the next day  to "a number of Scanio employees" with threats to disclose the data. "A follow-up email with similar content came later from an unrelated third party whose email had been compromised," the company added. </p><p>A Scania spokesperson told <em>ITPro</em>: "The application was immediately shut down, and an investigation was initiated. Relevant authorities have been notified. Our current assessment is that the impact is very limited, the investigation is ongoing."</p><p><strong>Partner risks</strong></p><p>Claroty's Lintell noted that the breach highlighted the challenge of keeping corporate data safe when working with partners and suppliers. </p><p>"Scania's recent data breach stemmed from third-party compromise, showing how easy it is for attackers to spread through vulnerabilities in external vendors," said Lintell. "Once inside, attackers can gain unrestricted access to data within the wider network and cause operational disruptions."</p><p>He added: "Though Scania's operational impact has been limited, the breach will still have reputational impacts and potential financial losses through the leak of documents containing sensitive data."</p><p>Lintell said companies in the automotive industry needed to step up their security to more proactive techniques to avoid becoming victims of such attacks. </p><p>"To mitigate against third-party attacks, organisations need to move beyond siloed security practices and adopt a unified, proactive approach to security. This means enforcing multi-factor authentication and improving visibility with advanced detection," he said. "Just as critical is a well-drilled incident response plan to empower staff to act quickly and decisively. This is key for the automotive sector to drive resilience."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Toyota customers in Asia & Oceania at risk following recent data leak ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/toyota-customers-in-asia-and-oceania-at-risk-following-recent-data-leak</link>
                                                                            <description>
                            <![CDATA[ The incident marks the third data leak in the space of a year for Toyota ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">X9VMNBQS9caxGgHXxL2XBk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uA28QY8bdyYK55RqhffdiP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 31 May 2023 11:11:14 +0000</pubDate>                                                                                                                                <updated>Wed, 31 May 2023 12:14:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uA28QY8bdyYK55RqhffdiP-1280-80.jpg">
                                                            <media:credit><![CDATA[Yiuchi Yamazaki/AFP via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Toyota logo pictured outside the Japanese car maker&#039;s headquarters in Tokyo, Japan.]]></media:description>                                                            <media:text><![CDATA[Toyota logo pictured outside the Japanese car maker&#039;s headquarters in Tokyo, Japan.]]></media:text>
                                <media:title type="plain"><![CDATA[Toyota logo pictured outside the Japanese car maker&#039;s headquarters in Tokyo, Japan.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uA28QY8bdyYK55RqhffdiP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Data belonging to Toyota customers in Asia and Oceania may have been “publicly accessible” between October 2016 and May 2023 due to a cloud misconfiguration, the company has revealed. </p><p>In an advisory, the car manufacturer revealed exposed data includes names, addresses, phone numbers, email addresses, vehicle identification numbers, and registration details.</p><p>Critical data, such as credit card information, was not exposed in the leak, the manufacturer insisted.</p><p>Toyota said the leak was caused by a cloud misconfiguration as a result of human error, adding that the flaw has since been remediated. </p><p>“Some of the files that TC (Toyota Connected Corporation) manages in the cloud environment for overseas dealers&apos; maintenance and investigation of systems were potentially accessible externally due to a misconfiguration,” the company <a href="https://global.toyota/en/newsroom/corporate/39241625.html" target="_blank"><u>said in a statement</u></a>. </p><p>“After this matter was discovered, we took steps to block access from outside the company.”</p><p>Toyota did not disclose the exact number of customers affected. It also said a preliminary investigation found no evidence any of the exposed data had been accessed or maliciously exploited. </p><p>“We have also investigated whether, with this incident, there was any secondary use or if third-party copies remain on the internet, and no evidence of such has been found. At present, we have not confirmed any secondary damage,” it said.</p><h2 id="recurring-toyota-data-leaks">Recurring Toyota data leaks</h2><p>This latest disclosure follows an investigation into a similar data leak in early May in which data belonging to more than 2.15 million customers in Japan was <a href="https://www.itpro.com/cloud/cloud-security/cloud-system-error-left-toyota-customer-data-exposed-for-ten-years"><u>left accessible for nearly a decade</u></a>. </p><p>At the time, Toyota said a worker at the firm was believed to have set a cloud system’s access level to ‘public’ instead of ‘private’, meaning that data pertaining to vehicle locations and identification numbers was exposed. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="L47gbigPjNi8zfgWvSgmk3" name="L47gbigPjNi8zfgWvSgmk3.png" caption="" alt="Whitepaper cover with title, text, and SWOT analysis chart" src="https://cdn.mos.cms.futurecdn.net/L47gbigPjNi8zfgWvSgmk3.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Magic quadrant for Security Information and Event Management (SIEM)</strong></p><p class="fancy-box__body-text"><em>Assessing the current solutions in the market for threat detection, investigation, and response capabilities</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/security-information-and-event-management-siem/369560/2022-magic-quadrant-for-security"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>This incident sparked a probe at the car manufacturer to improve monitoring of its internal systems and bolster employee data protection practices. Toyota said it has since introduced new rules and processes to monitor cloud configurations across its global operations. </p><p>“As we believe that this incident also was caused by insufficient dissemination and enforcement of data handling rules, since our last announcement, we have implemented a system to monitor cloud configuration,” the company revealed. </p><p>“Currently, the system is in operation to check the settings of all cloud environments and to monitor the settings on an ongoing basis. In addition, we will work closely again with TC to explain and thoroughly enforce the rules for data handling.”</p><p>This is also the third data breach of its kind in the space of a year for Toyota. In October 2022, the manufacturer revealed that data <a href="https://www.itpro.com/security/data-breaches/369292/toyota-discovers-five-year-old-email-leak-risks-phishing-attacks"><u>belonging to nearly 300,000 customers was exposed online</u></a>. </p><p>An access key was found to have been left publicly available on <a href="https://www.itpro.com/software/development/359246/how-to-download-from-github">GitHub</a> for nearly five years. This particular incident affected Toyota’s T-Connect service and allowed access to a server containing customer email addresses. </p><p>The incident prompted Toyota to warn customers that they could face an onslaught of <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> threats in the wake of the leak.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Capita tells pension provider to 'assume' nearly 500,000 customers' data stolen ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/capita-tells-pension-provider-to-assume-500000-customers-data-stolen</link>
                                                                            <description>
                            <![CDATA[ Capita told the pension provider to “work on the assumption” that data had been stolen ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">L9foKH5XMX7XyCgEJp9Vvb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hNeb92R4GXQ7o3vP9D58JU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 12 May 2023 14:41:44 +0000</pubDate>                                                                                                                                <updated>Mon, 15 May 2023 10:45:26 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hNeb92R4GXQ7o3vP9D58JU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Capita logo appearing on a smartphone that&#039;s being held out in the fingertips of two hands, the arms of which are visible, appearing form each side of the frame, all silhouetted]]></media:description>                                                            <media:text><![CDATA[Capita logo appearing on a smartphone that&#039;s being held out in the fingertips of two hands, the arms of which are visible, appearing form each side of the frame, all silhouetted]]></media:text>
                                <media:title type="plain"><![CDATA[Capita logo appearing on a smartphone that&#039;s being held out in the fingertips of two hands, the arms of which are visible, appearing form each side of the frame, all silhouetted]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hNeb92R4GXQ7o3vP9D58JU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK pension fund USS has confirmed that nearly half a million customers may have been impacted by the recent Capita data breach. </p><p>In a statement today, USS revealed it was told on Thursday that member data held on Capita servers was accessed by threat actors during a security incident last month. </p><p>USS said that exposed information could include names, dates of birth, USS member numbers, and national insurance numbers. </p><p>The data potentially accessed by hackers dates back to early 2021, and covers “around 470,000 active, deferred, and retired members”. </p><p>According to USS, Capita said it cannot “currently confirm” if this data was exfiltrated by threat actors, but recommended the pension provider to “work on the assumption that it was”. </p><p>“We are awaiting receipt of the specific data from Capita, which we will, in turn, need to check and process,” the company said in a statement. </p><p>“We will be writing to each of the members affected by this – and, where applicable, their employers – as soon as possible to make them aware, to apologize for any distress or inconvenience caused, and to provide ongoing support and advice.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Z9ggB3xs29f2quPySea2Xc" name="Nine steps to proactively manage data privacy and protection_listing.jpg" caption="" alt="Whtiepaper cover with green title over image of female wearing glasses smiling at camera" src="https://cdn.mos.cms.futurecdn.net/Z9ggB3xs29f2quPySea2Xc.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Nine steps to proactively manage data privacy and protection</strong></p><p class="fancy-box__body-text"><em>Build trust with your employees, customers, and third parties</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/370011/nine-steps-to-proactive-manage-data-privacy-and"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The USS statement may raise concerns among other clients at the embattled IT outsourcing firm, which was rocked by a security incident last month. </p><p>Initially, Capita said there was “no evidence” that customer data had been compromised. </p><p>However, it later issued a follow-up confirmation <a href="https://www.itpro.com/security/data-breaches/capita-finally-admits-breach-affecting-4-of-its-servers"><u>stating that there was “some evidence of limited data exfiltration”</u></a> and that this “might include” customer, supplier, or colleague data.</p><p>Earlier this week, Capita revealed that the security incident <a href="https://www.itpro.com/security/capita-cyber-attack-could-cost-firm-up-to-dollar25-million-in-fees"><u>could cost upwards of $25 million</u></a> due to recovery and remediation costs and third-party consultancy fees. </p><p>Immanuel Chavoya, senior manager of product security at SonicWall told <em>ITPro </em>that the latest update highlights the potential long-term impact that this breach could have on Capita partner organizations. </p><p>The outsourcing giant provides services for both public and private sector clients, including the UK Ministry of Defence. </p><p>“Cyber attacks such as the one on Capita require a bit of long-tail analysis to capture a clear understanding of impact, but what is known is that the ripple effect of a cyber attack like the one on Capita can be far-reaching, extending beyond the organization itself to shake customer trust, disrupt essential services, and reverberate throughout communities”.</p><p>USS has urged members to remain vigilant for potential scams in the wake of the discovery, warning that they could be subject to heightened threats such as <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a>. </p><p>“We would encourage members to only ever give out personal information if they are absolutely sure they know who they are communicating with,” the company said. </p><p>“We are sorry that member data has been accessed in this way. We are proactively engaging with Capita in respect of their ongoing investigations and are considering the next steps available to us. We also continue to engage with them about the ongoing support they will be providing to those affected.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloud system error left Toyota customer data exposed for ten years ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/cloud-system-error-left-toyota-customer-data-exposed-for-ten-years</link>
                                                                            <description>
                            <![CDATA[ Toyota customers in Japan may have been at risk since 2013 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ch58NGWNB72zswFFCwNb4R</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uA28QY8bdyYK55RqhffdiP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 12 May 2023 10:29:16 +0000</pubDate>                                                                                                                                <updated>Mon, 15 May 2023 11:04:03 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uA28QY8bdyYK55RqhffdiP-1280-80.jpg">
                                                            <media:credit><![CDATA[Yiuchi Yamazaki/AFP via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Toyota logo pictured outside the Japanese car maker&#039;s headquarters in Tokyo, Japan.]]></media:description>                                                            <media:text><![CDATA[Toyota logo pictured outside the Japanese car maker&#039;s headquarters in Tokyo, Japan.]]></media:text>
                                <media:title type="plain"><![CDATA[Toyota logo pictured outside the Japanese car maker&#039;s headquarters in Tokyo, Japan.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uA28QY8bdyYK55RqhffdiP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Data belonging to more than 2 million Toyota customers in Japan was left ‘publicly available’ for ten years due to a cloud configuration error, the company has revealed. </p><p>The car manufacturer said that around 2.15 million customers may have been affected by the leak, which saw data left at risk between November 2013 and April this year. </p><p>Toyota said that the leak was due to a <a href="https://www.itpro.com/cloud/361113/the-rise-of-cloud-misconfiguration-threats-and-how-to-avoid-them"><u>misconfigured setting in its cloud environment</u></a> and caused by human error. </p><p>A worker at the firm is believed to have set a cloud system’s access level to ‘public’ instead of ‘private’, meaning that data pertaining to vehicle locations and identification numbers was exposed. </p><p>Customers of Toyota’s T-Connect network are among those impacted by the incident, along with G-Link users. </p><p>G-Link is a service for Lexus vehicle owners that offers premium services and emergency support features. </p><p>A spokesperson for Toyota said there has been no sign of malicious activity due to the data leak. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rNAQoa9nwMcMG72HQokQfh" name="rNAQoa9nwMcMG72HQokQfh.jpg" caption="" alt="Whitepaper cover with title over a grey rectangle with header graphic and ESG logo" src="https://cdn.mos.cms.futurecdn.net/rNAQoa9nwMcMG72HQokQfh.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Storage&apos;s role in addressing the challenges of ensuring cyber resilience</strong></p><p class="fancy-box__body-text"><em>Understanding the role of data storage in cyber resiliency</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/368461/storages-role-in-addressing-the-challenges-of-ensuring-cyber"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The firm insisted that it took immediate action to block access to the affected data after the issue was revealed. </p><p>A comprehensive review of how the firm monitors its cloud environments is also underway across the breadth of its global operations. </p><p>“Customer information that may have been viewed from the outside will not identify the customer based on this data alone, even if accessed from the outside,” a spokesperson said. </p><p>“Since the discovery of this matter, we have not confirmed any secondary use of customer information on the internet by a third party.”</p><p>In the wake of the incident, the company plans to implement changes to its cloud processes. </p><p>The vehicle manufacturer said it will introduce systems to “audit and monitor cloud settings continuously”. </p><p>The firm will also “thoroughly educate employees” to improve data handling.</p><p>Gary Cannon, transport practice commercial director at NCC Group told ITPro that incidents such as the Toyota cloud error are uncommon, but when they do occur can have disastrous implications. </p><p>“It&apos;s not very common for an internal member of staff to accidentally set a cloud system to public instead of private,” he said. “However, it can happen, especially if the person responsible for the cloud system is not familiar with its configuration or if they are rushing to get something done.”</p><p>“It&apos;s important to note that setting a cloud system to public instead of private can have serious security implications, as it could expose sensitive data or services to unauthorized access.”</p><h2 id="recurring-data-leaks-at-toyota">Recurring data leaks at Toyota</h2><p>This latest data leak marks the second incident of its kind for Toyota in the space of a year. </p><p>In October 2022, the car manufacturer revealed that data belonging to nearly 300,000 customers was exposed after an <a href="https://www.itpro.com/security/data-breaches/369292/toyota-discovers-five-year-old-email-leak-risks-phishing-attacks"><u>access key was left publicly available on GitHub for around five years</u></a>. </p><p>At the time, Toyota said that 296,019 customers were impacted by the breach, which also affected its T-Connect service. </p><p>This issue was compounded by the fact that leaked source code included access keys to a server containing customer email addresses. </p><p>In the wake of the incident, Toyota warned customers to remain vigilant for a potential onslaught of <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> scams. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Gumtree site code made personal data of users and sellers publicly accessible ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/361854/gumtree-html-makes-user-data-publicly-accessible</link>
                                                                            <description>
                            <![CDATA[ Anyone could scan the website's HTML code to reveal personal information belonging to users of the popular second-hand classified adverts website ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uoWQJGDi8y3ECzfDXHm3m7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cEYzcPSx7QUSBKd4UL4nkC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Dec 2021 11:18:49 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cEYzcPSx7QUSBKd4UL4nkC-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[HTML code written in an integrated developer environment]]></media:description>                                                            <media:text><![CDATA[HTML code written in an integrated developer environment]]></media:text>
                                <media:title type="plain"><![CDATA[HTML code written in an integrated developer environment]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cEYzcPSx7QUSBKd4UL4nkC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have discovered that data belonging to customers of online marketplace Gumtree may have been leaked through the site's HTML code.</p><p>User data such as GPS location, full names, email addresses, and postcodes of users and sellers, could all be accessed through the site's publicly accessible site code, according to researchers from Pen Test Partners.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" data-original-url="/data-protection/34061/what-is-the-data-protection-act-2018">What is the Data Protection Act 2018?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">What is the Information Commissioner’s Office (ICO)?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/28020/data-protection-principles" data-original-url="/data-protection/28020/data-protection-principles">Data protection principles</a></p></div></div><p>Simply opening up the HTML code of the website using a tool like Google Chrome's 'inspect element' was all that was required to view the information in question.</p><p>Pen Test Partners <a href="https://www.pentestpartners.com/security-blog/gumtree-leaking-your-data-and-not-really-listening">said</a> the site "was super leaky" and that every listing on Gumtree would include the seller's postcode or GPS coordinates, even if the seller requested their location to be hidden.</p><p>Gumtree's website operates on a first name basis - users and sellers only ever see each other's first names and use a private messaging service built into the site for communication, avoiding emails.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QDksvAYJFwkcCugTbPvwS9" name="QDksvAYJFwkcCugTbPvwS9.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/QDksvAYJFwkcCugTbPvwS9.png" mos="https://cdn.mos.cms.futurecdn.net/QDksvAYJFwkcCugTbPvwS9.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Protecting every edge to make hackers’ jobs harder, not yours</strong></p><p class="fancy-box__body-text">How to support and secure hybrid architectures</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/firewalls/361592/protecting-every-edge-to-make-hackers-jobs-harder-not-yours" data-original-url="/security/firewalls/361592/protecting-every-edge-to-make-hackers-jobs-harder-not-yours">FREE DOWNLOAD</a></p></div></div><p>But email addresses were visible in the <a href="https://www.itpro.com/business-strategy/careers-training/358369/front-end-developer-career-guide-7-skills-a-front-end" data-original-url="https://www.itpro.com/business-strategy/careers-training/358369/front-end-developer-career-guide-7-skills-a-front-end">HTML code</a> and user surnames could also be viewed by exploiting an insecure direct object references (IDOR) vulnerability. The vulnerability was found in an <a href="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know" data-original-url="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know">API</a> used exclusively for iOS users, Pen Test Partners said, and one of its endpoints was vulnerable to a simple unauthenticated IDOR attack.</p><p>IDOR attacks can be carried out in a number of ways, but commonly attackers can cross-reference account IDs with a website's backend <a href="https://www.itpro.com/data-insights/databases/358688/five-database-problems-and-how-to-solve-them" data-original-url="https://www.itpro.com/data-insights/databases/358688/five-database-problems-and-how-to-solve-them">database</a> and pull personal information using it. They can then modify the ID to pull data from other user accounts too.</p><p>Before publicly disclosing the leak this week, Pen Test Partners attempted to alert Gumtree via its third-party bug bounty programme. Run by Netherlands-based Zerocopter, the bug bounty programme required researchers to sign a non-disclosure agreement (NDA) as part of the submission, something the researchers were reluctant to do. Instead, they decided to alert Gumtree directly through its customer service team.</p><p>Gumtree has since fixed the issues causing the information leak and said it self-reported to the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner's Office</a> (ICO).</p><p>"People have the right to expect that organisations will handle their personal information securely and responsibly," said an ICO spokesperson to <em>IT Pro</em>. "If an individual has concerns about how their data has been handled, they should raise it with the organisation first, then report them to us if they are not satisfied with the response.</p><p>"Gumtree made us aware of an incident. After carefully reviewing the information, we decided no formal action was required and we provided data protection advice to the organisation."</p><p>Gumtree told <em>IT Pro</em> it remediated the issues raised by Pen Test Partners "within hours" of being made aware of them and all issues with the website, both with the iOS API and other backend code are fully resolved.</p><p>"In response to these issues, we reported the incident to the Information Commissioner’s Office (ICO) outlining our actions already taken, and planned, to monitor the issue," it said.</p><p>"These included fixing the vulnerabilities, updating our safety messaging on site and mitigating against future issues. We did not notify our users and are confident that our response to the reported issues was timely, appropriate and proportionate. We have communicated proactively with the regulator as these issues came to light and as we were taking remedial actions. We will take any appropriate further action should that be required."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Pizza chain exposed 100,000 employees' Social Security numbers  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/361613/pizza-chain-exposed-100000-employees-social-security-numbers</link>
                                                                            <description>
                            <![CDATA[ Former and current staff at California Pizza Kitchen potentially burned by hackers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rHhAr72DCYFijjkVFQNwco</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gHNiUjQYVyD9LijbZKkbGi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Nov 2021 18:00:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gHNiUjQYVyD9LijbZKkbGi-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[California Pizza Kitchen store]]></media:description>                                                            <media:text><![CDATA[California Pizza Kitchen store]]></media:text>
                                <media:title type="plain"><![CDATA[California Pizza Kitchen store]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gHNiUjQYVyD9LijbZKkbGi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Restaurant chain California Pizza Kitchen has exposed over 100,000 current and former employees' data to potential theft, the company admitted this week. The data at risk included staff names and Social Security numbers. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/361146/twitch-confirms-data-breach-server-error" data-original-url="/security/data-breaches/361146/twitch-confirms-data-breach-server-error">Twitch confirms data breach after server configuration error</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/361136/it-pro-news-in-review-windows-11-launch-facebook-outage-coinbase-data-breach" data-original-url="/software/361136/it-pro-news-in-review-windows-11-launch-facebook-outage-coinbase-data-breach">IT Pro News in Review: Windows 11 launch, Facebook outage, Coinbase data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/361107/46-million-neiman-marcus-customers-data-compromised-in-a-breach" data-original-url="/security/data-breaches/361107/46-million-neiman-marcus-customers-data-compromised-in-a-breach">Neiman Marcus data breach hits 4.6 million customers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/cryptocurrencies/361101/coinbase-data-breach-6000-customers" data-original-url="/technology/cryptocurrencies/361101/coinbase-data-breach-6000-customers">Coinbase notifies 6,000 customers of data breach</a></p></div></div><p>The data breach <a href="https://apps.web.maine.gov/online/aeviewer/ME/40/ea812f00-c605-4b8e-a6e2-9dd53169b256.shtml">filing</a> with the Maine Attorney General reported a total of 103,767 affected people, including eight residents of that state. The filing said the company discovered suspicious activity in its computing environment on September 15 and launched an investigation. </p><p>On October 4, it confirmed hackers could have accessed some files and then discovered the extent of the data theft by October 13. </p><p>The data that might have been compromised included names and Social Security numbers, the company said. </p><p>"There is no indication that individuals’ specific information was accessed or misused," said the document. "However, CPK is notifying all potentially impacted individuals out of an abundance of caution." </p><p>The company is offering a year of credit monitoring to those whose data might have been stolen. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QDksvAYJFwkcCugTbPvwS9" name="QDksvAYJFwkcCugTbPvwS9.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/QDksvAYJFwkcCugTbPvwS9.png" mos="https://cdn.mos.cms.futurecdn.net/QDksvAYJFwkcCugTbPvwS9.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Protecting every edge to make hackers’ jobs harder, not yours</strong></p><p class="fancy-box__body-text">How to support and secure hybrid architectures</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/firewalls/361592/protecting-every-edge-to-make-hackers-jobs-harder-not-yours" data-original-url="/security/firewalls/361592/protecting-every-edge-to-make-hackers-jobs-harder-not-yours">FREE DOWNLOAD</a></p></div></div><p>The Costa Mesa, California-based restaurant chain has nearly 200 restaurants across eight countries. Last month, it announced its expansion into Canada. The company, which filed for bankruptcy protection at the height of the pandemic last year, was reportedly considering a sale or IPO to refinance debt in July this year. </p><p>While the US still lacks a federal data breach notification law, each state has passed legislation requiring private businesses to notify individuals when their information is breached. Some, such as <a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa" data-original-url="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">California</a> and <a href="https://www.itpro.com/policy-legislation/data-protection/358769/virginia-passes-consumer-data-protection-law" data-original-url="https://www.itpro.com/policy-legislation/data-protection/358769/virginia-passes-consumer-data-protection-law">Virginia</a>, have gone further with strict data protection laws that impose penalties for mishandling of personal data. </p><p>In June, Senator Kirsten Gillibrand (D-NY) <a href="https://www.itpro.com/policy-legislation/data-protection/359924/senator-reintroduces-federal-data-protection-bill" data-original-url="https://www.itpro.com/policy-legislation/data-protection/359924/senator-reintroduces-federal-data-protection-bill">introduced</a> a bill to create a federal data privacy regulator.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 83% of critical infrastructure companies have experienced breaches in the last three years ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/361518/83-of-critical-infrastructure-companies-have-experienced-breaches-in</link>
                                                                            <description>
                            <![CDATA[ Survey finds security practices are weak if not non-existent in critical firms ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">taY7Sdn9hRATWvB2cRUJvw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sAYacHDkbrjfh7ZUh3Akj7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Nov 2021 17:07:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sAYacHDkbrjfh7ZUh3Akj7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Nuclear power plant behind power lines]]></media:description>                                                            <media:text><![CDATA[Nuclear power plant behind power lines]]></media:text>
                                <media:title type="plain"><![CDATA[Nuclear power plant behind power lines]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sAYacHDkbrjfh7ZUh3Akj7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Eighty-three percent of firms in the energy and other <a href="https://www.itpro.com/infrastructure" data-original-url="https://www.itpro.com/infrastructure">critical infrastructure</a> industries have had at least one operational technology (OT) cyber security breach in the prior 36 months.</p><p>Many organizations underestimate the risk of a cyber attack, with 73% of CIOs and CISOs "highly confident" their organizations will not suffer an OT breach in the next year, according to a new survey by IT <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> firm Skybox Security. This is compared to only 37% of plant managers, who have more first-hand experiences with the repercussion of attacks. Skybox Security said this underlined the CISO disconnect between perception and reality.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/server-storage/361513/why-faster-refresh-cycles-and-modern-infrastructure-management" data-original-url="/infrastructure/server-storage/361513/why-faster-refresh-cycles-and-modern-infrastructure-management">Why faster refresh cycles and modern infrastructure management are critical to business success</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/it-infrastructure/361442/it-pro-2020-the-future-of-it-infrastructure" data-original-url="/business-strategy/it-infrastructure/361442/it-pro-2020-the-future-of-it-infrastructure">IT Pro 20/20: The future of IT infrastructure</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/hybrid-cloud/361164/building-a-cloud-native-hybrid-multi-cloud-infrastructure" data-original-url="/cloud/hybrid-cloud/361164/building-a-cloud-native-hybrid-multi-cloud-infrastructure">Building a cloud-native, hybrid-multi cloud infrastructure</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/360973/vmware-vcenter-server-critical-flaw" data-original-url="/security/vulnerability/360973/vmware-vcenter-server-critical-flaw">Critical flaw in vCenter Server could give hackers infrastructure access</a></p></div></div><p>The study questioned OT security decision makers in the US, UK, Germany, and Australia. Many respondents were from companies with $1 billion or more in revenue within the manufacturing, energy, and utility industries. </p><p>The new research, “<a href="https://www.skyboxsecurity.com/wp-content/uploads/2021/10/OT_trends_report-skybox-2021_10-25.pdf">Operational Technology Cybersecurity Risk Significantly Underestimated</a>,” found that 40% of all respondents said OT is an afterthought to other digital initiatives, highlighting that cyber security is often at risk from apathy.</p><p>The increasingly complex nature of networks in modern critical infrastructure companies was top of mind for respondents. Seventy-eight percent said complexity due to multivendor technologies is a challenge in securing their OT environment. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ebWTwtZnKEPD3hvMervZkk" name="ebWTwtZnKEPD3hvMervZkk.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" mos="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The truth about cyber security training</strong></p><p class="fancy-box__body-text">Stop ticking boxes. Start delivering real change.</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361094/the-truth-about-cyber-security-training" data-original-url="/security/cyber-security/361094/the-truth-about-cyber-security-training">FREE DOWNLOAD</a></p></div></div><p>In addition, 39% of all respondents said a top barrier to improving security programs is decisions are made in individual business units with no central oversight. Almost half of CISOs and CIOs said disjointed architecture across IT and OT pose the greatest security risk in their OT environment.</p><p>There were also major concerns about third-party risks. Forty percent of all respondents said supply chain/third-party access to the network is one of the top-three highest security risks. Yet, less than half said their organization has a third-party access policy that applied to OT.</p><p>Skybox Security Research Lab threat intelligence lead, Sivan Nir, argued that new OT vulnerabilities were up 46% compared to the first half of 2020. “Despite the rise in vulnerabilities and recent attacks, many security teams do not make OT security a corporate priority,” he said.</p><p>“Why? One of the surprising findings is that some security team personnel deny they are vulnerable yet admit to being breached. The belief that their infrastructure is safe — despite evidence to the contrary — has led to inadequate OT security measures."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Identity Automation launches credential breach monitoring service ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/361129/identity-automation-launches-credential-breach-monitoring-service</link>
                                                                            <description>
                            <![CDATA[ New monitoring solution adds to the firm’s flagship RapidIdentity platform ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aYPk61rvRnxBWikzDSztPN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YxZtwZyGKSnRCJ2kCzDod3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 05 Oct 2021 17:03:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YxZtwZyGKSnRCJ2kCzDod3-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Corporate ID badge stuck on a fishing hook]]></media:description>                                                            <media:text><![CDATA[Corporate ID badge stuck on a fishing hook]]></media:text>
                                <media:title type="plain"><![CDATA[Corporate ID badge stuck on a fishing hook]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YxZtwZyGKSnRCJ2kCzDod3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Identity Automation has announced a new compromised credentials monitoring service for K-12 schools and universities.</p><p>The service, which adds to Identity Automation's RapidIdentity platform, scans the dark web for hacked usernames and passwords, enabling swift and effective protection against ransomware threats and data breaches, according to the company. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/360714/credential-theft-most-prevalent-threat-to-corporate-inboxes" data-original-url="/security/phishing/360714/credential-theft-most-prevalent-threat-to-corporate-inboxes">Credential theft most prevalent threat to corporate inboxes</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/361042/hackers-spoof-zix-in-credential-phishing-attack" data-original-url="/security/phishing/361042/hackers-spoof-zix-in-credential-phishing-attack">Hackers spoof Zix in credential phishing attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/360980/microsoft-warns-of-bulletprooflink-phishing-as-a-service-enterprise" data-original-url="/security/phishing/360980/microsoft-warns-of-bulletprooflink-phishing-as-a-service-enterprise">Microsoft exposes BulletProofLink 'phishing as a service' criminal enterprise</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/microsoft-office/360802/microsoft-outlook-shows-real-contact-details-in-some-phishing" data-original-url="/software/microsoft-office/360802/microsoft-outlook-shows-real-contact-details-in-some-phishing">Microsoft Outlook shows real contact details in some phishing emails</a></p></div></div><p>Powered by SpyCloud, the service also alerts school IT administrators to compromised managed identities, including students, faculty, staff, parents, alumni, and external third parties, via a daily status report.</p><p>Users can create custom automated responses via RapidIdentity, enabling actions such as monitoring identity information, ending sessions with compromised credentials, locking accounts, requiring a password reset before restoring users’ privileges, or implementing <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">multi-factor authentication</a> for affected users.</p><p>Administrators can automatically assign users to pertinent groups and distribution lists, revoke access based on provisioning policies, and more through dynamic role management.</p><p>"Preventing ransomware is possible by negating the top attack vector: credentials that have been exposed in data breaches. This service gives schools early identification of compromised accounts, enabling them to take action quickly and prevent cyber attacks that leverage recently-breached identity data,” explained Cassio Mello, senior vice president of business development at SpyCloud. </p><p>Identity Automation's credentials monitoring service also includes support for secure remote access and <a href="https://www.itpro.com/security/27098/best-vpn-services" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">virtual private network (VPN)</a> logins. Additionally, RapidIdentity facilitates single sign-on for security assertion markup language (SAML)-compatible mobile applications.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ebWTwtZnKEPD3hvMervZkk" name="ebWTwtZnKEPD3hvMervZkk.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" mos="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The truth about cyber security training</strong></p><p class="fancy-box__body-text">Stop ticking boxes. Start delivering real change.</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361094/the-truth-about-cyber-security-training" data-original-url="/security/cyber-security/361094/the-truth-about-cyber-security-training">FREE DOWNLOAD</a></p></div></div><p>Institutions can also leverage pre-built connectors for integration with Text/Flat File (csv, xml), web services (SOAP/REST), and command line interface (CLI), among others.</p><p>Identity Automation <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do" data-original-url="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do">CEO</a> Jim Harold said: "Our compromised credentials monitoring service can help schools avoid the fate of other education organizations that have paid out hundreds of thousands of dollars in ransom or suffered massive data loss from a hacking incident.” </p><p>"And because it's integrated with the RapidIdentity platform, IT administrators can automate responses and focus on singular threat vectors instead of analyzing credential issues. This approach is more secure and more efficient."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Neiman Marcus data breach hits 4.6 million customers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/361107/46-million-neiman-marcus-customers-data-compromised-in-a-breach</link>
                                                                            <description>
                            <![CDATA[ The breach took place last year, but details have only now come to light ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6vmTLdnJx5d4HVcLXxytWt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gAAJmKCtTaxEAvpy7VeJbQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Oct 2021 13:22:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gAAJmKCtTaxEAvpy7VeJbQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Neiman Marcus sign on a white brick building]]></media:description>                                                            <media:text><![CDATA[Neiman Marcus sign on a white brick building]]></media:text>
                                <media:title type="plain"><![CDATA[Neiman Marcus sign on a white brick building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gAAJmKCtTaxEAvpy7VeJbQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Department store Neiman Marcus is notifying 4.6 million customers that their details were compromised after a 2020 data breach.</p><p>The <a href="https://www.neimanmarcusgroup.com/2021-09-30-Neiman-Marcus-Confirms-Unauthorized-Access-to-Customer-Online-Accounts">store chain said in a statement</a> an “unauthorized party” obtained personal information associated with certain Neiman Marcus customers' online accounts. The information included names and contact information; payment card numbers and expiration dates (without CVV numbers); Neiman Marcus virtual gift card numbers (without PINs); and usernames, passwords, and security questions and answers associated with Neiman Marcus online accounts.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/cryptocurrencies/361101/coinbase-data-breach-6000-customers" data-original-url="/technology/cryptocurrencies/361101/coinbase-data-breach-6000-customers">Coinbase notifies 6,000 customers of data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/360954/mod-data-breach-afghan-lives-at-risk" data-original-url="/security/data-breaches/360954/mod-data-breach-afghan-lives-at-risk">MoD data breach ‘put lives of Afghan interpreters at risk’</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/mobile-phones/360678/nokia-subsidiary-reveals-data-breach-following-conti-ransomware-raid" data-original-url="/mobile/mobile-phones/360678/nokia-subsidiary-reveals-data-breach-following-conti-ransomware-raid">Nokia subsidiary reveals data breach following Conti ransomware raid</a></p></div></div><p>The incident occurred in May 2020, but the store has only just addressed the breach.</p><p>It added that around 3.1 million payment and virtual gift cards were affected, more than 85% of which are expired or invalid. Data of Bergdorf Goodman and Horchow, which are part of the Neiman Marcus Group, were not affected by the breach. </p><p>"At Neiman Marcus Group, customers are our top priority," CEO Geoffroy van Raemdonck said in a statement. "We are working hard to support our customers and answer questions about their online accounts. We will continue to take actions to enhance our system security and safeguard information."</p><p>The company has notified law enforcement and is working with Mandiant to investigate the <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> breach. The company has set up a <a href="https://c212.net/c/link/?t=0&l=en&o=3308904-1&h=4131342021&u=https%3A%2F%2Fwww.neimanmarcus.com%2F2021-customer-online-account-info&a=https%3A%2F%2Fwww.neimanmarcus.com%2F2021-customer-online-account-info">website</a> to help affected customers.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iAVch4E74nXskoYH6rVd54" name="iAVch4E74nXskoYH6rVd54.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/iAVch4E74nXskoYH6rVd54.png" mos="https://cdn.mos.cms.futurecdn.net/iAVch4E74nXskoYH6rVd54.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Modernise endpoint protection and leave your legacy challenges behind</strong></p><p class="fancy-box__body-text">The risk of keeping your legacy endpoint security tools</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/360946/modernise-endpoint-protection-and-leave-your-legacy-challenges" data-original-url="/security/endpoint-security/360946/modernise-endpoint-protection-and-leave-your-legacy-challenges">FREE DOWNLOAD</a></p></div></div><p>George Papamargaritis, MSS Director of Obrela Security Industries, told <em>IT Pro</em> that this is a concerning incident given that the attack appears to have gone unnoticed for well over a year.</p><p>“As Neiman Marcus continues to investigate the breach, more information about exactly who’s personal data was impacted will come to light, however, in the meantime anyone notified about the breach should carefully review their bank statements between now and May last year to spot any fraudulent transactions. Any unfamiliar activity should then be reported to their bank. It will also be worthwhile working with credit reference agencies to also make sure no fraudulent credit applications have been taken out in their name,” he said.</p><p>Martin Jartelius, CSO, Outpost24, told <em>IT Pro</em> a shallow glance at this makes it look like yet another personal data breach, but this one is a bit different. </p><p>“According to the information, not only have credit card numbers leaked which means that the company has been storing credit card numbers in a readable format, but also that 85% of those would have expired meaning that the organization had little to no justification to keep processing and storing those cards. While the breach notification is good, the lack of hygiene, in this case, is considerable,” he said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Indiana notifies 750,000 after COVID-19 tracing data accessed ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/360616/indiana-notifies-750000-after-covid-19-tracing-data-accessed</link>
                                                                            <description>
                            <![CDATA[ The state is following up to ensure no information was transferred to bad actors ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wpdQ7UJdeXxg9SqEqpF9cS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fMbMro3SjAzTb5vKxrzNfc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Aug 2021 12:46:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fMbMro3SjAzTb5vKxrzNfc-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data Breach overlaying a circuitboard]]></media:description>                                                            <media:text><![CDATA[Data Breach overlaying a circuitboard]]></media:text>
                                <media:title type="plain"><![CDATA[Data Breach overlaying a circuitboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fMbMro3SjAzTb5vKxrzNfc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Indiana officials at the Department of Health have notified around 750,000 residents that a company improperly accessed personal data from the state’s online COVID-19 contact tracing survey.</p><p>The agency said the state was notified on July 2 that a company gained unauthorized access to data, including names, addresses, dates of birth, emails, and gender, ethnicity and race data.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/360581/t-mobile-confirms-data-breach" data-original-url="/security/data-breaches/360581/t-mobile-confirms-data-breach">T-Mobile confirms it was hit by a data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/big-data/360525/data-breach-exposes-details-on-millions-of-us-seniors" data-original-url="/data-insights/big-data/360525/data-breach-exposes-details-on-millions-of-us-seniors">Data breach exposes millions of seniors' data</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/360389/data-breach-costs-surge-to-record-high-in-2021" data-original-url="/security/data-breaches/360389/data-breach-costs-surge-to-record-high-in-2021">Data breach costs surge to record high in 2021</a></p></div></div><p>Indiana’s <a href="https://www.itpro.com/strategy/28223/cio-job-description-what-does-a-cio-do" data-original-url="https://www.itpro.com/strategy/28223/cio-job-description-what-does-a-cio-do">chief information officer (CIO)</a> Tracy Barnes said the agency took “the security and integrity of our data very seriously.”</p><p>“The company that accessed the data is one that intentionally looks for <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a> vulnerabilities, then reaches out to seek business. We have corrected the software configuration and will aggressively follow up to ensure no records were transferred,” she said.</p><p>State Health Commissioner Kris Box said the risk to residents of the state was low. “We do not collect Social Security information as a part of our contact tracing program, and no medical information was obtained,” she said.</p><p>Indiana’s Department of Health will send letters to affected residents notifying them the state will provide one year of free credit monitoring and is partnering with Experian to open a call center to answer questions. The Indiana Office of Technology also said it will continue its regular scans to ensure information was not transferred to another party.</p><p>Trevor Morgan, product manager at comforte AG, told <em>ITPro</em> our personal information, especially when wrapped in the context of our health records, is not something we want unauthorized people or companies to access. </p><p>“We place our faith in the assumption that agencies and other organizations which collect and process that data also put forward the strongest effort to guard that information. For any company like this which processes PII or PHI, data-centric security can add another, more appropriate safeguard against unauthorized access alongside more traditional perimeter-based defenses,” Morgan said.</p><p>“Methods like tokenization replace sensitive data elements with representational tokens, so even if it falls into the wrong hands the sensitive information is indecipherable and cannot be leveraged. While this incident could have been worse, we’d all feel better knowing that our sensitive personal information could never be compromised, no matter who gets their hands on it."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZExAov8zyEmxT8mafdUAuP" name="ZExAov8zyEmxT8mafdUAuP.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" mos="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The technology of trust</strong></p><p class="fancy-box__body-text">How to protect your most valuable commodity</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/customer-experience-cx/359630/the-technology-of-trust" data-original-url="/marketing-comms/customer-experience-cx/359630/the-technology-of-trust">FREE DOWNLOAD</a></p></div></div><p>Erich Kron, <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> awareness advocate at KnowBe4, told <em>ITPro</em> it appears the company accessed the data in a way that did not put it at risk of cyber criminals obtaining it. </p><p>“Unfortunately, ‘software configuration’ errors such as this often lead to the data being accessed by bad actors, putting the users of the systems at risk,” he said. “Incidents such as this are learning opportunities for any organization that handles sensitive data. It also drives home the need for constant security testing and for ensuring processes are in place to help protect data, especially when configuration changes are being made."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Pearson fined $1 million for downplaying severity of 2018 breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/360605/pearson-fined-1-million-for-downplaying-the-severity-of-2018-breach</link>
                                                                            <description>
                            <![CDATA[ The SEC found the London-based firm made “misleading statements and omissions” about the intrusion ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">stDj1kqDXVkDukAcpECLT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UahVFYX8a3cgJavFQrXDrc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Aug 2021 13:51:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UahVFYX8a3cgJavFQrXDrc-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Pearson sign and logo on a building]]></media:description>                                                            <media:text><![CDATA[Pearson sign and logo on a building]]></media:text>
                                <media:title type="plain"><![CDATA[Pearson sign and logo on a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UahVFYX8a3cgJavFQrXDrc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Securities and Exchange Commission (SEC) has ordered UK-based Pearson Education to pay $1 million to settle charges it misled investors about a 2018 data breach that resulted in millions of stolen student records.</p><p><a href="https://www.sec.gov/news/press-release/2021-154">The SEC announced the settlement</a> after it found Pearson made “misleading statements and omissions” about the intrusion that involved the theft of student data and administrator log-in credentials of 13,000 school, district, and university customer accounts.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/360581/t-mobile-confirms-data-breach" data-original-url="/security/data-breaches/360581/t-mobile-confirms-data-breach">T-Mobile confirms it was hit by a data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/big-data/360525/data-breach-exposes-details-on-millions-of-us-seniors" data-original-url="/data-insights/big-data/360525/data-breach-exposes-details-on-millions-of-us-seniors">Data breach exposes millions of seniors' data</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/360389/data-breach-costs-surge-to-record-high-in-2021" data-original-url="/security/data-breaches/360389/data-breach-costs-surge-to-record-high-in-2021">Data breach costs surge to record high in 2021</a></p></div></div><p>In its semi-annual report filed in July 2019, the SEC said Pearson referred to a <a href="https://www.itpro.com/tag/data-privacy" data-original-url="https://www.itpro.com/tags/data-privacy">data privacy</a> incident as a hypothetical risk, despite the fact the breach had already occurred. In a <a href="https://www.pearson.com/news-and-research/announcements/2019/07/pearson-customer-notification.html">statement published that same month</a>, Pearson said the breach may include dates of birth and email addresses, but it already knew such records were stolen.</p><p>The SEC also said Pearson had "strict protections" in place, “when, in fact, it failed to patch the critical vulnerability for six months after it was notified.” </p><p>“As the order finds, Pearson opted not to disclose this breach to investors until it was contacted by the media, and even then, Pearson understated the nature and scope of the incident, and overstated the company’s data protections,” said Kristina Littman, chief of the SEC Enforcement Division’s Cyber Unit. “As public companies face the growing threat of cyber intrusions, they must provide accurate information to investors about material cyber incidents.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZExAov8zyEmxT8mafdUAuP" name="ZExAov8zyEmxT8mafdUAuP.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" mos="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The technology of trust</strong></p><p class="fancy-box__body-text">How to protect your most valuable commodity</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/customer-experience-cx/359630/the-technology-of-trust" data-original-url="/marketing-comms/customer-experience-cx/359630/the-technology-of-trust">FREE DOWNLOAD</a></p></div></div><p>Dominic Trott, UK product manager at Orange Cyberdefense, told <em>IT Pro</em> the $1 million settlement agreed between Pearson and the SEC comes as the education sector faces increasing hostility from malicious actors. </p><p>“As the threat landscape evolves and while education remains firmly in the crosshairs, it is more important than ever to maintain an open dialogue. Only through collaboration and transparency can cyber researchers and technologists begin to turn the tide against cybercriminals intent on wreaking havoc in the sector,” Trott said. </p><p>“As Pearson has learned, failure to properly disclose a breach can also be far more damaging to an organization’s reputation and can incur severe legal penalties, particularly when customer data is involved.</p><p>"Breach disclosure processes should form part of an organization’s blended approach to cyber <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a>, layering a combination of people, process and enabling technologies to reduce the risk, minimize the impact of a breach should one occur, and demonstrate diligence and best practice to both customers and governing bodies.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ “Great resignation” sparks concern over insider data leaks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/360576/great-resignation-sparks-concern-over-insider-data-leaks</link>
                                                                            <description>
                            <![CDATA[ New research unearths direct correlation between employees leaving and data theft ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fF2neDERtruoN2st852Qkx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GtXuTkZnZVR7vyiU92xATQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Aug 2021 12:55:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GtXuTkZnZVR7vyiU92xATQ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man leaving a job with box of personal items]]></media:description>                                                            <media:text><![CDATA[Man leaving a job with box of personal items]]></media:text>
                                <media:title type="plain"><![CDATA[Man leaving a job with box of personal items]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GtXuTkZnZVR7vyiU92xATQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>According to new research, there is a direct correlation between resignations, departing employees, and data exposure through theft and leaks.</p><p>Mark Wojtasiak, vice president of Portfolio Marketing at <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> company Code42, said that in an analysis of data-exposure telemetry from devices using the company’s <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a>, data was leaving organizations at the same time as employees were handling in letters of resignation.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/359862/personal-data-exposed-in-mcdonalds-data-breach" data-original-url="/security/data-breaches/359862/personal-data-exposed-in-mcdonalds-data-breach">Personal data exposed in McDonald’s data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359413/tens-of-thousands-of-pennsylvanians-health-data-exposed" data-original-url="/policy-legislation/data-protection/359413/tens-of-thousands-of-pennsylvanians-health-data-exposed">Tens of thousands of Pennsylvanians health data exposed following data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/357947/canon-employee-data-exposed-in-ransomware-attack" data-original-url="/security/ransomware/357947/canon-employee-data-exposed-in-ransomware-attack">Canon employee data exposed in ransomware attack</a></p></div></div><p>“Our analysis shows a direct correlation between resignations, departing employees, and exposure events. Turns out, when people leave, so do source code, patent applications, and customer lists,” he said.</p><p>The company looked at data from over 700,000 endpoints running Code42’s Incydr software between January 1 and June 30, 2021. The research found that not only was there an 40% increase in data exposure events between H2 2020 and H1 2021, but there was also a 61% increase quarter-over-quarter within the first half of 2021.</p><p>The three-month period between April and June 2021 saw 61% more exposure events than the previous quarter and accounts for 86% of all exposure events (across all vectors) experienced by organizations throughout the previous half (July through December 2020). Data exposure peaked at the same time the US experienced a massive shift in employment.</p><p>The research also found that source code exposure has increased three times over the past year. During Q2 2021, source code accounted for 11% of all data exposure events. Plus, Q2 2021 accounted for 47% of all source code exposed within the past year, confirming the ties between massive job shifts and valuable, sensitive information exposure.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NbL4bsEWBgYWJXNmhVccek" name="NbL4bsEWBgYWJXNmhVccek.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/NbL4bsEWBgYWJXNmhVccek.png" mos="https://cdn.mos.cms.futurecdn.net/NbL4bsEWBgYWJXNmhVccek.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Employees behaving badly?</strong></p><p class="fancy-box__body-text">Why awareness training matters</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/356982/employees-behaving-badly" data-original-url="/security/cyber-security/356982/employees-behaving-badly">FREE DOWNLOAD</a></p></div></div><p>Removable media, primarily UBSs, represented the most widely used exposure vector. Removable media accounted for 42% of all exposure events, making it the top single exfiltration vector. The second-highest single exfiltration vectors were cloud sync agents at 37%.</p><p>The data also revealed that Google Chrome accounted for 52% of all application exposure not tied to a cloud sync agent or removable media. Wojtasiak said that rather than indicating that Google Chrome is particularly problematic — it instead denotes its dominant market share within professional environments.</p><p>“Our analysis illustrates that many of these employees will likely take data with them to their next company,” said Wojtasiak. “When data falls into the wrong hands, it’s devastating to a company’s competitive position and jeopardizes the financial, reputational, or operational well-being of a company, its employees, customers, and partners.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data breach exposes millions of seniors' data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-insights/big-data/360525/data-breach-exposes-details-on-millions-of-us-seniors</link>
                                                                            <description>
                            <![CDATA[ Misconfigured S3 bucket had exposed personal information on three million people ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cgSPviDz9MyPZBaPKeqjEw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JtMF52dubT4BPNVVtmKMZ8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Aug 2021 17:43:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JtMF52dubT4BPNVVtmKMZ8-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data breach]]></media:description>                                                            <media:text><![CDATA[Data breach]]></media:text>
                                <media:title type="plain"><![CDATA[Data breach]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JtMF52dubT4BPNVVtmKMZ8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">Security</a> researchers have found a major breach that exposed the details of over three million US seniors.</p><p><a href="https://www.wizcase.com/blog/senioradvisor-breach-report">According to WizCase</a>, the data breach affected SeniorAdvisor, “one of the largest consumer ratings and reviews websites for senior care and services across the US and Canada.” Among the exposed details were users’ names, surnames, phone numbers, and more.</p><p>Researchers at WizCase discovered a misconfigured Amazon S3 bucket belonging to the website containing over 1 million files and 182GB of data. Contact dates from the files suggest they are from 2002 to 2013, though the files had a 2017 timestamp.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/360389/data-breach-costs-surge-to-record-high-in-2021" data-original-url="/security/data-breaches/360389/data-breach-costs-surge-to-record-high-in-2021">Data breach costs surge to record high in 2021</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/360338/gun-owners-urged-to-be-vigilant-following-data-breach" data-original-url="/security/data-breaches/360338/gun-owners-urged-to-be-vigilant-following-data-breach">UK gun owners urged to be ‘vigilant’ after Guntrader data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/360126/british-airways-settles-2018-data-breach-case-on-confidential-terms" data-original-url="/security/data-breaches/360126/british-airways-settles-2018-data-breach-case-on-confidential-terms">British Airways settles with 2018 data breach victims</a></p></div></div><p>“The majority of data exposed was in the form of leads, a list of potential customers whose details were collected by SeniorAdvisor presumably via their email or phone call campaigns,” said researchers.</p><p>Researchers also unearthed 2,000 “scrubbed” reviews. These are reviews where the user’s sensitive information has been wiped or redacted.</p><p>“However, this scrubbing process is useless if you have the corresponding information. The scrubbed reviews had a lead id which could be used to trace the review back to who originally wrote it,” researchers said. As both lead data and these scrubbed reviews were in the same database, supposedly anonymous reviewers could have their identity revealed with a simple search operation.</p><p>WizCase researchers said since the breach contained data from a section of the public more vulnerable to scams, the risks were higher. In a <a href="https://www.ftc.gov/reports/protecting-older-consumers-2018-2019-report-federal-trade-commission">2018-2019 report</a>, the <a href="https://www.itpro.com/tag/ftc" data-original-url="https://www.itpro.com/tags/ftc">Federal Trade Commission (FTC)</a> noted that people who filed a fraud complaint between 60 and 69 years old lost $600 per scam on average. The amount rose in older groups, culminating in $1700 on average per scam for people between 80 and 89.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="46MS25Ne58gQYeTNcHoXhW" name="46MS25Ne58gQYeTNcHoXhW.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/46MS25Ne58gQYeTNcHoXhW.png" mos="https://cdn.mos.cms.futurecdn.net/46MS25Ne58gQYeTNcHoXhW.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>From zero to hero: The path to CIAM maturity</strong></p><p class="fancy-box__body-text">Your guide to the CIAM journey</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/identity-and-access-management-iam/360519/the-path-to-ciam-maturity" data-original-url="/security/identity-and-access-management-iam/360519/the-path-to-ciam-maturity">FREE DOWNLOAD</a></p></div></div><p>“In particular, the report found senior citizens were more likely to fall for digital scams such as tech support scams, prize/sweepstakes scams, online shopping scams, and especially phone scams,” said researchers. “As shown, senior citizens are at greater risk for online fraud than the rest of the population, and therefore should be even more careful in their online behavior.”</p><p>Researchers urged people using such services to input the bare minimum of information when making a purchase or setting up an online account.</p><p>“The less information hackers have to work with, the less vulnerable you are,” warned researchers. Researchers have since contacted the company, and the bucket has since been secured.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CVS Health data breach leaves a billion records exposed ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/359907/cvs-health-data-breach-leaves-a-billion-records-exposed</link>
                                                                            <description>
                            <![CDATA[ A misconfigured cloud service is the suspected cause of the exposure ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kwdCccUkiEtT7E9ZDisZ5P</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PosA3YzA5GdSaJeYGnP3U9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Jun 2021 19:48:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PosA3YzA5GdSaJeYGnP3U9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[CVS health sign on a white building]]></media:description>                                                            <media:text><![CDATA[CVS health sign on a white building]]></media:text>
                                <media:title type="plain"><![CDATA[CVS health sign on a white building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PosA3YzA5GdSaJeYGnP3U9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A misconfiguration in a CVS Health <a href="https://www.itpro.com/cloud" data-original-url="https://www.itpro.com/cloud">cloud</a> database left over a billion records exposed, according to an <a href="https://www.websiteplanet.com/blog/cvs-health-leak-report">investigation by WebsitePlanet</a> in cooperation with security researcher Jeremiah Fowler. </p><p>The roughly 240GB database was not password protected, meaning anyone who knew where to look could find the records held within.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/359637/misconfigured-cloud-services-exposed-100-million-android-users-data" data-original-url="/security/data-breaches/359637/misconfigured-cloud-services-exposed-100-million-android-users-data">Misconfigured cloud services exposed 100 million Android users' data</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358261/misconfigured-git-servers-lead-to-nissan-data-leak" data-original-url="/security/hacking/358261/misconfigured-git-servers-lead-to-nissan-data-leak">Misconfigured Git servers lead to Nissan data leak</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357514/government-agencies-see-misconfigured-cloud-services-as-top-security-threat" data-original-url="/security/357514/government-agencies-see-misconfigured-cloud-services-as-top-security-threat">Government agencies see misconfigured cloud services as top security threat</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/automation/357281/how-to-avoid-cloud-misconfigurations-for-operational-excellence" data-original-url="/business-strategy/automation/357281/how-to-avoid-cloud-misconfigurations-for-operational-excellence">How to avoid cloud misconfigurations for operational excellence</a></p></div></div><p>A total of 1,148,327,940 records belonging to the US health care and pharmaceutical behemoth, which owns CVS Pharmacy and Aetna, were found. The database contained production records that exposed Visitor ID, Session ID, and device information (i.e., iPhone, Android, iPad, etc.). </p><p>Worryingly, the files also gave threat actors a clear understanding of configuration settings, where data is stored, and a blueprint of how the logging service operates from the backend.</p><p>Researchers also found multiple records of visitors’ search histories, including medications, COVID-19 vaccines, and other CVS products.</p><p>"Hypothetically, it could have been possible to match the Session ID with what they searched for or added to the shopping cart during that session and then try to identify the customer using the exposed emails," researchers said.</p><p>The investigation also carried out a sampling search query that revealed emails hackers could target in a <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> attack or potentially use to cross-reference other actions.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hqxjmaqbxyxnQ7e4kT2cXa" name="hqxjmaqbxyxnQ7e4kT2cXa.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/hqxjmaqbxyxnQ7e4kT2cXa.jpg" mos="https://cdn.mos.cms.futurecdn.net/hqxjmaqbxyxnQ7e4kT2cXa.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The secure cloud configuration imperative</strong></p><p class="fancy-box__body-text">The central role of cloud security posture management</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/359672/the-secure-cloud-configuration-imperative" data-original-url="/cloud/359672/the-secure-cloud-configuration-imperative">FREE DOWNLOAD</a></p></div></div><p>After discovering the unprotected database on March 21, the researchers immediately sent a responsible disclosure notice to CVS Health. The company restricted public access the same day.</p><p>In a statement, CVS Health said, “We were able to reach out to our vendor and they took immediate action to remove the database. Protecting the private information of our customers and our company is a high priority, and it is important to note that the database did not contain any personal information of our customers, members or patients.”</p><p>Paul Norris, a senior systems engineer at Tripwire, told <em>ITPro</em> that misconfigurations like these are <a href="https://www.itpro.com/security/data-breaches/359637/misconfigured-cloud-services-exposed-100-million-android-users-data" data-original-url="https://www.itpro.com/security/data-breaches/359637/misconfigured-cloud-services-exposed-100-million-android-users-data">becoming all too common</a>. </p><p>“Exposing sensitive data doesn’t require a sophisticated vulnerability, and the rapid growth of cloud-based data storage has exposed weaknesses in processes that leave data available to anyone. A misconfigured database on an internal network might not be noticed, and if noticed might not go public, but the stakes are higher when your data storage is directly connected to the Internet,” he said.</p><p>“Organizations should identify processes for securely configuring all systems, including cloud-based storage, like Elasticsearch and Amazon S3. Once a process is in place, the systems must be monitored for changes to their configurations. These are solvable problems, and tools exist today to help."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Millions of Volkswagen customers affected by data breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/359866/millions-of-volkswagen-customers-affected-by-data-breach</link>
                                                                            <description>
                            <![CDATA[ The incident stems from a vendor that left customer information unsecured ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">b8Bv5MXmBP56kG2nWarch5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KwnNbqHS3iyhvmnK4embF6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Jun 2021 13:33:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KwnNbqHS3iyhvmnK4embF6-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Volkswagen logo on a sign]]></media:description>                                                            <media:text><![CDATA[Volkswagen logo on a sign]]></media:text>
                                <media:title type="plain"><![CDATA[Volkswagen logo on a sign]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KwnNbqHS3iyhvmnK4embF6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A data breach at the US subsidiary of the Volkswagen Group has affected 3.3 million customers after a vendor left unsecured data exposed on the internet.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/software-development/358588/volkswagen-to-tap-azure-for-self-driving-software-updates" data-original-url="/development/software-development/358588/volkswagen-to-tap-azure-for-self-driving-software-updates">Volkswagen to tap Azure for self-driving software updates</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/automation/355884/argo-ai-closes-26b-deal-with-volkswagen" data-original-url="/business-strategy/automation/355884/argo-ai-closes-26b-deal-with-volkswagen">Argo AI closes $2.6 billion deal with Volkswagen</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/digital-transformation/33776/volkswagen-accelerates-digital-transformation-with-sap" data-original-url="/digital-transformation/33776/volkswagen-accelerates-digital-transformation-with-sap">Volkswagen accelerates digital transformation with SAP</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/33334/aws-makes-double-swoop-for-volkswagen-and-standard-bank" data-original-url="/cloud/33334/aws-makes-double-swoop-for-volkswagen-and-standard-bank">AWS makes double swoop for Volkswagen and Standard Bank</a></p></div></div><p>Volkswagen Group of America, Inc. (VWGoA) is the North American subsidiary of the German Volkswagen Group that looks after Volkswagen, Audi, Bentley, Bugatti, and Lamborghini operations in the US and Canada. </p><p>According to data breach notifications filed with the attorneys general of California and Maine, the company believed that the data was obtained when a vendor left electronic data unsecured at some point between August 2019 and May 2021.</p><p>According to a <a href="https://oag.ca.gov/system/files/Audi%20Notification%20Letter%20Template.pdf">notification letter</a> sent to customers, on March 10, the company was alerted that an unauthorized third party may have obtained certain customer information.</p><p>The letter read: “We immediately commenced an investigation to determine the nature and scope of this event.” The investigation confirmed the third party obtained limited personal information received from or about customers and interested buyers, from a vendor used by Audi, Volkswagen, and some authorized dealers in the United States and Canada. The letter didn’t state who the offending vendor was.</p><p>“This included information gathered for sales and marketing purposes from 2014 to 2019. We believe the data was obtained when the vendor left electronic data unsecured at some point between August 2019 and May 2021, when we identified the source of the incident,” the letter continued.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xZtyiaXQCu9ykhJkEdAxYb" name="xZtyiaXQCu9ykhJkEdAxYb.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/xZtyiaXQCu9ykhJkEdAxYb.jpg" mos="https://cdn.mos.cms.futurecdn.net/xZtyiaXQCu9ykhJkEdAxYb.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>A guide to enterprise detection and response providers</strong></p><p class="fancy-box__body-text">The 12 providers that matter most and how they stack up</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/359585/the-forrester-wavetm-enterprise-detection-and-response-q1-2020" data-original-url="/security/359585/the-forrester-wavetm-enterprise-detection-and-response-q1-2020">FREE DOWNLOAD</a></p></div></div><p>Among the data exposed were customers’ first and last names, personal or business mailing addresses, email addresses, and phone numbers. In some instances, the data also included information about a vehicle purchased, leased, or inquired about, such as the vehicle identification number (VIN), make, model, year, color, and trim packages.</p><p>"The data also included more sensitive information relating to eligibility for a purchase, loan, or lease. More than 95% of the sensitive data included was driver’s license numbers. There were also a very small number of dates of birth, Social Security or social insurance numbers, account or loan numbers, and tax identification numbers,” the letter stated.</p><p>A <a href="https://apps.web.maine.gov/online/aeviewer/ME/40/393b88dc-2f68-4aa7-8d97-f4b26ca58904/0c33a0f7-4865-4c71-9d31-f4a5bf943bf1/document.html">letter</a> from the company’s lawyers said that for the 90,000 customers who had more sensitive data exposed, the company would provide free credit protection services, $1 million of insurance, and assistance in the event of identity theft. </p><p>VWGoA is now notifying affected customers of the breach and warning them to remain alert for suspicious emails or other communications. </p><p>VWGoA is conducting a full <a href="https://www.itprotoday.com/security">security</a> review with the vendor to identify if further security enhancements are reasonable and appropriate, according to the lawyers’ letter.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Misconfigured cloud services exposed 100 million Android users' data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/359637/misconfigured-cloud-services-exposed-100-million-android-users-data</link>
                                                                            <description>
                            <![CDATA[ Mobile apps reveal user data, including emails, chat messages, location, and passwords ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kvKnNupYhdUky5n3ne8u18</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jeU6Bb4BZDZw2w88Gir7Aj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 May 2021 14:36:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jeU6Bb4BZDZw2w88Gir7Aj-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Thumb touching a phone&amp;#039;s screen within the Android App store]]></media:description>                                                            <media:text><![CDATA[Thumb touching a phone&amp;#039;s screen within the Android App store]]></media:text>
                                <media:title type="plain"><![CDATA[Thumb touching a phone&amp;#039;s screen within the Android App store]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jeU6Bb4BZDZw2w88Gir7Aj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">Security</a> researchers have discovered 23 Android applications that potentially exposed over 100 million users’ personal data through various misconfigurations of third-party <a href="https://www.itpro.com/cloud" data-original-url="https://www.itpro.com/cloud">cloud</a> services.</p><p>According to <a href="https://blog.checkpoint.com/2021/05/20/misconfiguration-of-third-party-cloud-services-exposed-data-of-over-100-million-users">Check Point Research</a>, the data exposed from these apps included emails, chat messages, location, passwords, and photos. This left users exposed to fraud, identity theft, and service swipes (using the same username-password combination on other services).</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358261/misconfigured-git-servers-lead-to-nissan-data-leak" data-original-url="/security/hacking/358261/misconfigured-git-servers-lead-to-nissan-data-leak">Misconfigured Git servers lead to Nissan data leak</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357514/government-agencies-see-misconfigured-cloud-services-as-top-security-threat" data-original-url="/security/357514/government-agencies-see-misconfigured-cloud-services-as-top-security-threat">Government agencies see misconfigured cloud services as top security threat</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/354611/misconfigured-security-command-exposes-250-million-microsoft-customer" data-original-url="/security/data-breaches/354611/misconfigured-security-command-exposes-250-million-microsoft-customer">Misconfigured security command exposes 250 million Microsoft customer records</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32732/nasa-employee-data-exposed-for-at-least-three-weeks-due-to-misconfigured-web-app" data-original-url="/security/32732/nasa-employee-data-exposed-for-at-least-three-weeks-due-to-misconfigured-web-app">NASA employee data exposed for at least three weeks due to misconfigured web app</a></p></div></div><p>Researchers said, “there was nothing in place to stop the unauthorized access from happening.”</p><p>“Modern cloud-based solutions have become the new standard in the mobile application development world,” researchers said. “Services such as cloud-based storage, real-time databases, notification management, analytics, and more are simply a click away from being integrated into applications. Yet, developers often overlook the security aspect of these services, their configuration, and of course, their content.”</p><p>The first problem researchers discovered was the misconfiguration of real-time databases developers used to store data in the cloud and synchronize with connected clients.</p><p>In 13 Android apps, which saw download numbers range from 10,000 to 10 million, no authentication was in place to prevent hackers from accessing these databases containing email addresses, passwords, private chats, device location, user identifiers, and more.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bKtjyXWcdfnqeGjgXiLXeC" name="bKtjyXWcdfnqeGjgXiLXeC.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/bKtjyXWcdfnqeGjgXiLXeC.jpg" mos="https://cdn.mos.cms.futurecdn.net/bKtjyXWcdfnqeGjgXiLXeC.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Building a data-driven enterprise of the future</strong></p><p class="fancy-box__body-text">Top five trends that will shape the future of organisational resiliency and effectiveness</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/data-management/359617/building-a-data-driven-enterprise-of-the-future" data-original-url="/data-insights/data-management/359617/building-a-data-driven-enterprise-of-the-future">FREE DOWNLOAD</a></p></div></div><p>In one app, T’Leva, a taxi app with over 50,000 downloads, researchers could access chat messages between drivers and passengers. They could also access users’ full names, phone numbers, and locations (destination and pick-up) – all by sending one request to the database.</p><p>A second issue was with push notifications. “Most push notification services require a key (sometimes, more than one) to recognize the identity of the request submitter,” said researchers. “When those keys are just embedded into the application file itself, it is very easy for hackers to take control and gain the ability to send notifications which might contain malicious links or content to all users on behalf of the developer.”</p><p>The third problem occurred in cloud storage. In one app, researchers could access cloud storage keys embedded into the app and all stored fax transmissions.</p><p>“With just analyzing the app, a malicious actor could gain access to any and all documents sent by the 500,000 users who downloaded this application,” said researchers.</p><p>Researchers said they approached Google and each app developer before publishing its research to share their findings. Researchers said only a few of the apps have since changed their configurations.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data breach exposes widespread fake reviews on Amazon ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/359460/data-breach-exposes-widespread-fake-reviews-on-amazon</link>
                                                                            <description>
                            <![CDATA[ IT security researchers found an unsecured database that shows how the scam is organized ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bojEWmxzuU9u94o6fY8s3v</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gtbDy3WCEqSs6wVEXAf2ej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 May 2021 17:01:30 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mike Brassfield ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gtbDy3WCEqSs6wVEXAf2ej-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Amazon logo on building]]></media:description>                                                            <media:text><![CDATA[Amazon logo on building]]></media:text>
                                <media:title type="plain"><![CDATA[Amazon logo on building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gtbDy3WCEqSs6wVEXAf2ej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">Cyber security</a> researchers have discovered an unsecured database exposing a widespread scam in which Amazon customers write fake reviews in exchange for free products from Amazon vendors.</p><p>IT security experts with <a href="https://www.safetydetectives.com/blog/amazon-reviews-leak-report">the Safety Detectives</a>, an antivirus review website, found an unclaimed <a href="https://www.itpro.com/malware/33107/hackers-target-elasticsearch-clusters-in-fresh-malware-campaign" data-original-url="https://www.itpro.com/malware/33107/hackers-target-elasticsearch-clusters-in-fresh-malware-campaign">ElasticSearch server</a> with no encryption or password protection.</p><p>“The server contained a treasure trove of direct messages between Amazon vendors and customers… potentially implicating more than 200,000 people in unethical activities,” <a href="https://www.safetydetectives.com/blog/amazon-reviews-leak-report">the researchers wrote</a>. “While it is unclear who owns the database, the breach demonstrates the inner workings of a prevalent issue affecting the online retail industry.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/359142/amazon-supports-proposed-biden-tax-hike" data-original-url="/business/policy-legislation/359142/amazon-supports-proposed-biden-tax-hike">Amazon supports proposed Biden tax hike</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/amazon-web-services-aws/359078/amazon-to-take-on-custom-chip-production-for-aws" data-original-url="/cloud/amazon-web-services-aws/359078/amazon-to-take-on-custom-chip-production-for-aws">Amazon is reportedly developing custom networking chips</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/amazon-web-services-aws/359044/amazons-new-lookout-for-metrics-monitors-your-organizations" data-original-url="/cloud/amazon-web-services-aws/359044/amazons-new-lookout-for-metrics-monitors-your-organizations">Amazon’s new Lookout for Metrics monitors your organization’s KPIs</a></p></div></div><p>The data breach exposed more than 13 million records and 7GB of data. The database was secured about a week after the cyber security team found it, but it remains unclear who controls it. The server’s owner appears to be based in China.</p><p>Data found on the ElasticSearch server showed how this scam works: </p><p>Shady Amazon vendors send these fake reviewers the names of products they want 5-star reviews for. The reviewers buy the products and post their “reviews” soon afterward. </p><p>Then the reviewer sends the vendor their PayPal information and Amazon profile. The reviewer secretly gets a refund from the vendor, so they keep the product for free. </p><p>“The refund for any purchased goods is actioned through PayPal and not directly through Amazon’s platform,” the Safety Detectives <a href="https://www.safetydetectives.com/blog/amazon-reviews-leak-report">said</a>. “This makes the five-star review look legitimate, so as not to arouse suspicion from Amazon moderators.”</p><p>So, not only does this ElasticSearch database facilitate a widespread scam, but its owners’ carelessness exposed users’ personal data.</p><p>“It’s reasonable to estimate that around 200,000-250,000 people were affected by this breach,” the cybersecurity researchers said. “The server appeared to be located in China, and it is thought the leak affected citizens from Europe and the USA at a minimum.”</p><p>Messages on the server included the fake reviewers’ Amazon and PayPal account details, and email addresses. Vendors’ email addresses were exposed, as well as their WhatsApp and Telegram contact info.</p><p>“Although a lot of people providing fake reviews likely know what they’re doing, we must also highlight how vendors don’t advertise that fake reviews are illegal,” the cybersecurity researchers <a href="https://www.safetydetectives.com/blog/amazon-reviews-leak-report">said</a>. “Unassuming people may have been targeted by Amazon vendors with the offer of free products in return for a review.” </p><p>“What’s clear is that whoever owns the server could be subject to punishments from consumer protection laws, and whoever is paying for these fake reviews may face sanctions for breaking Amazon’s terms of service.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Peloton security bug could expose user data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/359440/peloton-security-bug-could-expose-user-data</link>
                                                                            <description>
                            <![CDATA[ Exposed API could let hackers access customer data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rw1P4aVYg53n45dQMuU2kb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/h5khw3UFUrtYZczcKGu84c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 May 2021 14:10:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/h5khw3UFUrtYZczcKGu84c-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Peloton bike&amp;#039;s wheels with a person&amp;#039;s feet on the pedals]]></media:description>                                                            <media:text><![CDATA[Peloton bike&amp;#039;s wheels with a person&amp;#039;s feet on the pedals]]></media:text>
                                <media:title type="plain"><![CDATA[Peloton bike&amp;#039;s wheels with a person&amp;#039;s feet on the pedals]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/h5khw3UFUrtYZczcKGu84c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A flaw in how Peloton fitness bikes communicate with the company’s <a href="https://www.itpro.com/hardware" data-original-url="https://www.itpro.com/hardware">servers</a> could have inadvertently allowed anyone to access customers’ private data.</p><p>According to <a href="https://www.pentestpartners.com/security-blog/tour-de-peloton-exposed-user-data/?=050420210000">investigations</a> carried out by Pen Test Partners, the mobile, web application, and back-end APIs had several endpoints that revealed users’ information to authenticated and unauthenticated users.</p><p>Jan Masters, a security researcher at Pen Test Partners, spotted the vulnerability in January. He discovered he could make unauthenticated requests to the fitness firm’s API for account data. According to Masters, there were no checks to ensure he was allowed to request the data.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/358394/president-bidens-peloton-raises-cyber-security-risks" data-original-url="/security/cyber-security/358394/president-bidens-peloton-raises-cyber-security-risks">President Biden’s Peloton raises cyber security concerns</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/big-data-analytics/34112/from-the-peloton-to-the-cloud-how-data-keeps-the-tour-de-france-running" data-original-url="/big-data-analytics/34112/from-the-peloton-to-the-cloud-how-data-keeps-the-tour-de-france-running">From the Peloton to the Cloud: How data keeps the Tour de France running</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359226/irish-dpc-launches-inquiry-into-facebook-data-leak" data-original-url="/policy-legislation/data-protection/359226/irish-dpc-launches-inquiry-into-facebook-data-leak">Irish data watchdog to investigate Facebook data leak</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358510/foxtons-customer-data-found-available-on-dark-web" data-original-url="/security/data-breaches/358510/foxtons-customer-data-found-available-on-dark-web">Foxtons customer data leaked onto the dark web</a></p></div></div><p>The exposed API allowed the researcher to access a range of information, such as a user’s age, gender, location, weight, workout stats, and birthday, even when a user makes their profile page private.</p><p>Master notified Peloton of his findings via its vulnerability disclosure program in the middle of January with a 90-day deadline to fix the issues. That deadline came and went with Peloton only acknowledging the problem and not fixing it.</p><p>In early February, Peloton quietly and partly resolved the unauthenticated API endpoint issue. Still, Masters pointed out this meant user data was now only available to all authenticated Peloton users who had taken out a monthly subscription to the service.</p><p>Master then asked for an update, given that Peloton had made a partial fix, but Peloton didn’t respond.</p><p>After 90 days, Master contacted a journalist at <em>TechCrunch</em>, who then <a href="https://techcrunch.com/2021/05/05/peloton-bug-account-data-leak/?guccounter=1&guce_referrer=aHR0cHM6Ly93d3cudGhldmVyZ2UuY29tLw&guce_referrer_sig=AQAAAEadAVfr6v8nF8CvNC5Z-ZuBjAGUNVZRznCCpopOq0Gl-TD8nkiKyEiTI_FSi9gVJWurKpZ4ymWEWZBpi5zaHHYaa_9_B9Z8lbFQebdBiR3fjC_umjqrLw8hHErgYS6CwvmFnzFbKbtEb3CUK1Zx9Z6D8XmNHQ2S-cVHdCyVMUHM">broke the story</a>. “This started a constructive conversation and resulted in the vulnerabilities being largely resolved,” said Masters.</p><p>“A full investigation should be conducted by Peloton to improve their security, especially now that famous individuals are openly using this service,” added Masters.</p><p>Since contacting the press, Peloton’s new CISO has remained in contact with him over the flaws. The company fixed most of them in a week.</p><p>“It’s a shame that our disclosure wasn’t responded to in a timely manner and also a shame that we had to involve a journalist in order to get listened to,” he added.</p><p>The Peloton bike has gained popularity over the years to keep fit at home, especially since the coronavirus pandemic hit the world last year. Earlier this year, President Biden was <a href="https://www.itpro.com/security/cyber-security/358394/president-bidens-peloton-raises-cyber-security-risks" data-original-url="https://www.itpro.com/security/cyber-security/358394/president-bidens-peloton-raises-cyber-security-risks">prevented from bringing his Peloton into the White House</a> over concerns that it could be a security risk. It seems now that those concerns were well-founded.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Tens of thousands of Pennsylvanians health data exposed following data breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/359413/tens-of-thousands-of-pennsylvanians-health-data-exposed</link>
                                                                            <description>
                            <![CDATA[ Coronavirus tracing company is at the heart of the exposure ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iU9jEXf7Q6DYEcYtKnBMpu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GWE6DgNLHRCjKq6yzG6iJe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 May 2021 12:52:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GWE6DgNLHRCjKq6yzG6iJe-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Locks on a screen with one open and in red]]></media:description>                                                            <media:text><![CDATA[Locks on a screen with one open and in red]]></media:text>
                                <media:title type="plain"><![CDATA[Locks on a screen with one open and in red]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GWE6DgNLHRCjKq6yzG6iJe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A data breach at a coronavirus contact tracing company has exposed the personal health information of tens of thousands of Pennsylvanians.</p><p>According to a <a href="https://www.post-gazette.com/news/crime-courts/2021/04/29/Contact-tracing-breach-impacts-private-info-of-72K-people-Insight-Global-Pennsylvania/stories/202104290159">report from the Pittsburgh Post-Gazette</a>, officials at Pennsylvania’s Department of Health alleged that employees at Atlanta-based Insight Global “disregarded security protocols established in the contract and created unauthorized documents” outside the state’s <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">secure</a> data system.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/359180/apple-and-google-block-new-nhs-covid-19-app-update" data-original-url="/security/privacy/359180/apple-and-google-block-new-nhs-covid-19-app-update">Apple and Google block NHS COVID-19 app update</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/357049/how-businesses-were-left-to-scramble-over-data-collection" data-original-url="/policy-legislation/data-protection/357049/how-businesses-were-left-to-scramble-over-data-collection">How businesses were left to scramble over data collection for coronavirus contact tracing</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/public-sector/356139/the-governments-contact-tracing-app-was-always-going-to-be" data-original-url="/business-strategy/public-sector/356139/the-governments-contact-tracing-app-was-always-going-to-be">The government’s contact tracing app was always going to be DOA</a></p></div></div><p>In an email, the agency’s spokesman Barry Ciccocioppo said "we are extremely dismayed that employees from Insight Global acted in a way that may have compromised this type of information and sincerely apologize to all impacted individuals."</p><p>He added that the state’s computer systems, including Pennsylvania's contact tracing app, were not implicated. The exposed information included names, phone numbers, emails, genders, ages, sexual orientations, and COVID-19 diagnoses and exposure status.</p><p>WPXI-TV in Pittsburgh first reported the data breach. Former employees of Insight Global told the TV station they told supervisors that information had been improperly secured, but the company took no action. A spokesperson for Insight told WPXI that contract tracing information "may have been made accessible to persons beyond authorized employees and public health officials."</p><p>Pennsylvania will not be renewing the company’s contract, which expires in three months. Free credit monitoring and identity protection services will be available to affected people.</p><p>Trevor J. Morgan, product manager at Comforte AG, told <em>ITPro</em> the situation is a cautionary tale. Whether through contractual obligation or regulatory mandate, enterprises working with sensitive data need to meet the acceptable threshold of data security.</p><p>“However, vendors can’t trust that sensitive data such as PHI will always remain protected if it travels outside protected perimeters because data is vulnerable even when resting within the security perimeters,” he said.</p><p>Morgan added that when data is on the move, it is especially prone to mishandling and compromise, which means that a more data-centric approach to <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> should be part of those minimum data security standards.</p><p>“Data-centric security such as tokenization and format-preserving encryption replaces sensitive data with benign representational information, so even if it falls into the wrong hands the data cannot be compromised by the wrong parties. For more and more regulatory agencies and individual enterprises, data-centric security measures are now part of minimum data security standards because of the ability to protect data even while in motion,” he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Reverb exposes 'millions' of customer records on unsecured server ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/359350/millions-of-reverb-users-data-exposed-on-an-unsecured</link>
                                                                            <description>
                            <![CDATA[ Leaked records contained data including full names, email addresses,phone numbers and mailing addresses ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6yWnKUxoCgZgfomCoGmo4t</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kdrHdsYq3SUjeJx86ppg2j-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 27 Apr 2021 13:31:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kdrHdsYq3SUjeJx86ppg2j-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Blue binary data on a black background]]></media:description>                                                            <media:text><![CDATA[Blue binary data on a black background]]></media:text>
                                <media:title type="plain"><![CDATA[Blue binary data on a black background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kdrHdsYq3SUjeJx86ppg2j-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Online musical instrument marketplace Reverb has warned customers of a data breach affecting the website and 5.6 million user records.</p><p><a href="https://www.linkedin.com/pulse/more-than-56-million-records-reverb-sellers-details-leaked-diachenko">According to security researcher Bob Diachenko</a>, he discovered an unsecured Elasticsearch server earlier this month containing over 5.6 million records. These records contained data about individual listings on Reverb, including full names, email addresses, phone numbers, mailing addresses, PayPal emails, and listing/order information.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/357947/canon-employee-data-exposed-in-ransomware-attack" data-original-url="/security/ransomware/357947/canon-employee-data-exposed-in-ransomware-attack">Canon employee data exposed in ransomware attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34671/us-military-data-exposed-in-179gb-autoclerk-leak" data-original-url="/security/34671/us-military-data-exposed-in-179gb-autoclerk-leak">US military data exposed in 179GB Autoclerk leak</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-breaches/34347/monstercom-job-seeker-data-exposed-in-third-party-leak" data-original-url="/data-breaches/34347/monstercom-job-seeker-data-exposed-in-third-party-leak">Monster.com job seeker data exposed in third-party leak</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/30971/linkedin-autofill-plugin-bug-left-user-data-exposed" data-original-url="/security/30971/linkedin-autofill-plugin-bug-left-user-data-exposed">LinkedIn AutoFill plugin bug left user data exposed</a></p></div></div><p>“Upon closer inspection, I noticed that there are many '<em>test</em>' emails coming from @reverb.com domain. I decided to verify shop slugs against real URLs on Reverb site and quickly confirmed the initial thought - it was all Reverb users’ data,” Diachenko said.</p><p>He then ran a quick check to see who the sellers were. He found the details of several high-profile sellers, including Bill Ward of Black Sabbath, Jimmy Chamberlin of Smashing Pumpkins, Alessandro Cortini of Nine Inch Nails, and more.</p><p>Reverb has started notifying customers that the breach exposed potentially sensitive information.</p><p>In an email to users, Reverb wrote: “We take our users’ privacy and security very seriously. Out of an abundance of caution, we wanted to inform you that Reverb recently became aware of an issue relating to user contact information.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jfMfftdRc8Sostbdck8Fqk" name="jfMfftdRc8Sostbdck8Fqk.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/jfMfftdRc8Sostbdck8Fqk.png" mos="https://cdn.mos.cms.futurecdn.net/jfMfftdRc8Sostbdck8Fqk.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>NETSCOUT threat intelligence report</strong></p><p class="fancy-box__body-text">Cyber crime: Exploiting a pandemic</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/359329/netscout-threat-intelligence-report" data-original-url="/security/cyber-crime/359329/netscout-threat-intelligence-report">FREE DOWNLOAD</a></p></div></div><p>“At this time, we believe that contact information, including name, address, phone number, and email, was publicly accessible for a short period of time. We do not have reason to believe that any of this information has been misused, nor do we believe that password or payment information were involved.”</p><p>Paul Norris, senior systems engineer EMEA at Tripwire, told <em>IT Pro</em> that misconfigurations like these are becoming all too common.</p><p>“Exposing sensitive data doesn’t require a sophisticated vulnerability, and the rapid growth of cloud-based data storage has exposed weaknesses in processes that leave data available to anyone. A misconfigured database on an internal network might not be noticed, and if noticed might not go public, but the stakes are higher when your data storage is directly connected to the Internet,” he said.</p><p>“Organizations should identify processes for securely configuring all systems, including cloud-based storage, like Elasticsearch. Once a process is in place, the systems must be monitored for changes to their configurations.”</p><p>Sergio Loureiro, cloud security director at Outpost24, told <em>IT Pro</em> that everyone needs to be “playing from the same music sheet when it comes to security and with the countless possibilities of ‘quickly deploying a system in the cloud,’ security is -still- often overlooked by organizations.”</p><p>“As datasets grow to these sizes, the data is becoming increasingly valuable to businesses and in some cases even more valuable than money. Unfortunately, not everyone protects it like the valuable asset it is,” Loureiro said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers sell $38 million in gift cards on Russian marketplace ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/359137/38m-in-gift-cards-sold-on-russian-hacking-marketplace</link>
                                                                            <description>
                            <![CDATA[ Amazon, Nike, Walmart, and Target among the brands targeted by Russian hacking dark web forum ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rKcPAukZQSL4Jb4KCBTeUm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YdYSJd6dezvDQuLyVm5YnM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 07 Apr 2021 14:20:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YdYSJd6dezvDQuLyVm5YnM-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Unknown hacker on a computer in a dark room]]></media:description>                                                            <media:text><![CDATA[Unknown hacker on a computer in a dark room]]></media:text>
                                <media:title type="plain"><![CDATA[Unknown hacker on a computer in a dark room]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YdYSJd6dezvDQuLyVm5YnM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers have sold more than $38 million in gift cards from US retailers on an underground Russian hacking marketplace.</p><p>According to Gemini Advisory’s <a href="https://geminiadvisory.io/gift-card-shop-breached">investigation</a>, hackers were observed offering to sell 895,000 stolen gift cards from 3,010 companies in early February. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/359070/homeland-security-heads-email-hacked-in-solarwinds-attack" data-original-url="/security/cyber-security/359070/homeland-security-heads-email-hacked-in-solarwinds-attack">Head of Homeland Security had his email hacked in SolarWinds attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/359106/n-korean-hackers-targeting-security-researchers-with-fake-social-media" data-original-url="/security/hacking/359106/n-korean-hackers-targeting-security-researchers-with-fake-social-media">North Korean hackers target security researchers with fake social media accounts</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/exploits/358971/f5-networks-big-ip-flaw-the-latest-to-be-exploited-by-hackers" data-original-url="/security/exploits/358971/f5-networks-big-ip-flaw-the-latest-to-be-exploited-by-hackers">F5 Networks BIG-IP flaw is the latest to be exploited by hackers</a></p></div></div><p>The hackers claimed they had a database of over 3,000 brand-name gift cards. Affected companies included Airbnb, Amazon, American Airlines, Chipotle, Dunkin Donuts, Marriott, Nike, Subway, Target, and Walmart. The database may have originated from an older breach at online discount gift card shop Cardpool.com.</p><p>Before closing in early 2021, Cardpool.com operated as a gift card marketplace where individuals could sell unwanted gift cards to the shop. Cardpool.com would then resell those cards to others for less than their face value. </p><p>The hackers started the auction at $10,000 with a $20,000 buy-now price. According to security researchers, the gift cards were bought by another actor soon after they were posted for sale.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uZXV3vAfY2MsMRm4tSjJfE" name="uZXV3vAfY2MsMRm4tSjJfE.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/uZXV3vAfY2MsMRm4tSjJfE.png" mos="https://cdn.mos.cms.futurecdn.net/uZXV3vAfY2MsMRm4tSjJfE.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The business guide to ransomware</strong></p><p class="fancy-box__body-text">Everything you need to know to keep your company afloat</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/357745/the-business-guide-to-ransomware" data-original-url="/security/ransomware/357745/the-business-guide-to-ransomware">FREE DOWNLOAD</a></p></div></div><p>The original hacker listed data from another 330,000 payment cards on the same forum the next day. This data included payment card number, expiration date, and bank name but not the CVV or cardholder name. Bidding for these details started at $5,000, but there was a $15,000 buy-now price. The payment cards sold within days of the hacker listing them for sale, but not as quickly as the gift cards.</p><p>Gemini Advisory’s analysis concluded that the 330,000 payment cards likely came from a Cardpool.com breach between February 4, 2019 and August 4, 2019. </p><p>Researchers said the lack of CVV data indicates that the actor likely acquired the cards by gaining backend access to Cardpool.com, which would have enabled them to steal the gift card data and previous shoppers’ payment card data directly from the site’s databases.</p><p>“Attackers can acquire backend access to online shops through a variety of methods, including exploiting vulnerabilities in sites’ content management systems (CMS) and brute-forcing admin login credentials,” said researchers.</p><p>According to the researchers, the Cardpool.com case “offers a valuable glimpse into the ecosystem of carding.”</p><p>“The trick is not in acquiring stolen cards but in devising the most efficient way to cash out the funds on the cards before financial institutions can flag them as compromised,” they said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Personal data of 533 million Facebook users found on hacking forum ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/359114/facebook-data-breach-533-million-hacking-forum</link>
                                                                            <description>
                            <![CDATA[ The leaked records contained users' phone numbers, Facebook IDs, full names and relationship status ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5XzvJhVUhrc9gcxSBVacLs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WGCsRefGv8J2gf78DhKqj8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 05 Apr 2021 18:20:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WGCsRefGv8J2gf78DhKqj8-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Facebook sign at entrance of its campus]]></media:description>                                                            <media:text><![CDATA[Facebook sign at entrance of its campus]]></media:text>
                                <media:title type="plain"><![CDATA[Facebook sign at entrance of its campus]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WGCsRefGv8J2gf78DhKqj8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Facebook was at the center of a data privacy storm over the weekend after a hacker published 533 million users’ details on a low-level hacking forum.</p><p>The data was downloadable for free and allowed anyone downloading it to look up a Facebook user's record using their phone number.</p><p>The records, representing roughly a fifth of the company's entire user base, contained users' phone numbers, Facebook IDs, full names, previous locations, birth dates, relationship status, and biographies. It also includes some of their email addresses.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/359031/cma-raises-concerns-over-facebooks-giphy-deal" data-original-url="/business-strategy/mergers-and-acquisitions/359031/cma-raises-concerns-over-facebooks-giphy-deal">UK watchdog says Facebook's Giphy acquisition may stifle competition</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/358962/copperstealer-malware-hijacks-facebook-business-accounts-to-run-malicious" data-original-url="/security/malware/358962/copperstealer-malware-hijacks-facebook-business-accounts-to-run-malicious">CopperStealer malware hijacks Facebook business accounts to run malicious ads</a></p></div></div><p>Alon Gal, chief technology officer of cyber crime intelligence company Hudson Rock, <a href="https://twitter.com/UnderTheBreach/status/1378314424239460352">tweeted</a> the news on Saturday after discovering the data posted for free on a forum. It followed a tweet he posted in January this year, warning that a vulnerability had allowed the database to be created in early 2020. The January tweet warned that the user had created a Telegram bot that would allow anyone to query the database for a low fee, allowing people to find phone numbers linked to many Facebook accounts.</p><p>The January tweet showed the data breach contained 32.3 million US Facebook accounts, representing just under 10% of the entire US population.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YnLJtg57DtFNyLpfRR5ogY" name="YnLJtg57DtFNyLpfRR5ogY.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/YnLJtg57DtFNyLpfRR5ogY.jpg" mos="https://cdn.mos.cms.futurecdn.net/YnLJtg57DtFNyLpfRR5ogY.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>IT Pro 20/20: Meet the companies leaving the office for good</strong></p><p class="fancy-box__body-text">The 15th issue of IT Pro 20/20 looks at the nature of operating a business in 2021</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/359086/it-pro-2020-meet-the-companies-leaving-the-office-for-good" data-original-url="/business/business-strategy/359086/it-pro-2020-meet-the-companies-leaving-the-office-for-good">FREE DOWNLOAD</a></p></div></div><p>According to a statement Facebook sent to <em>Business Insider,</em> the first outlet to report the news, these stolen credentials aren’t new. Facebook said that it stemmed from a vulnerability it patched in 2019. However, once the hacker stole the data from its network, little can the company do to stop it from spreading online.</p><p>"Bad actors will certainly use the information for social engineering, scamming, hacking and marketing," Gal said on Twitter.</p><p>Security research Troy Hunt <a href="https://haveibeenpwned.com/PwnedWebsites#Facebook">added</a> the data to his website over the weekend to allow people to see if their email addresses are part of the breach. At the time of this writing, he hadn’t yet entered the stolen phone numbers and was considering what to do with that information.</p><p>This isn’t the first time Facebook has come under fire for privacy and security issues. In 2019, the FTC <a href="https://www.itpro.com/policy-legislation/34015/facebook-s-historic-5bn-ftc-settlement-branded-a-sweetheart-deal" data-original-url="https://www.itpro.com/policy-legislation/34015/facebook-s-historic-5bn-ftc-settlement-branded-a-sweetheart-deal">fined</a> Facebook $5 billion for misleading users over how it shared their data with third parties and for failing to change its privacy practices following a 2011 FTC settlement.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ubiquiti insider says the company downplayed the severity of a major breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/359092/ubiquiti-insider-says-the-company-downplayed-the-severity-of-a-major</link>
                                                                            <description>
                            <![CDATA[ Attackers reportedly accessed company source code ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i2D7VL1oFMCnoSG6WzzzsJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2QVtGsQqwJmbv96BVLpaAJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 31 Mar 2021 17:35:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2QVtGsQqwJmbv96BVLpaAJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of a cyber criminal using several computers in a dark room ]]></media:description>                                                            <media:text><![CDATA[Image of a cyber criminal using several computers in a dark room ]]></media:text>
                                <media:title type="plain"><![CDATA[Image of a cyber criminal using several computers in a dark room ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2QVtGsQqwJmbv96BVLpaAJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/cloud-computing/28037/what-is-iot" data-original-url="https://www.itpro.com/cloud-computing/28037/what-is-iot">Internet of things (IoT)</a> manufacturer Ubiquiti allegedly downplayed the severity of a <a href="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach" data-original-url="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach">data breach</a> it revealed in January, <a href="https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-breach-catastrophic">according to reports</a>.</p><p>Security blogger Brian Krebs, a former Washington Post reporter, spoke to a security professional claiming to work for Ubiquiti. The employee said the breach was "catastrophic", and the company downplayed the fallout to minimize the effect on its share price.</p><p>Ubiquiti makes IoT equipment, including <a href="https://www.itpro.com/wifi-hotspots/31707/best-mesh-wi-fi" data-original-url="https://www.itpro.com/wifi-hotspots/31707/best-mesh-wi-fi">mesh Wi-Fi</a> systems. In January, it <a href="https://community.ui.com/questions/Account-Notification/96467115-49b5-4dd6-9517-f8cdbf6906f3">warned customers</a> that intruders accessed systems hosted by a third-party <a href="https://www.itpro.com/cloud" data-original-url="https://www.itpro.com/cloud">cloud</a> provider. "We are not currently aware of evidence of access to any databases that host user data, but we cannot be certain that user data has not been exposed," Ubiquiti said at the time. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/126605/adobe-set-to-buy-buzzword-maker-virtual-ubiquity" data-original-url="/126605/adobe-set-to-buy-buzzword-maker-virtual-ubiquity">Adobe set to buy Buzzword maker Virtual Ubiquity</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358793/star-alliance-passenger-data-stolen-in-sita-data-breach" data-original-url="/security/data-breaches/358793/star-alliance-passenger-data-stolen-in-sita-data-breach">Star Alliance passenger data stolen in SITA data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358635/donald-trumps-one-time-law-firm-allegedly-suffers-data-breach" data-original-url="/security/data-breaches/358635/donald-trumps-one-time-law-firm-allegedly-suffers-data-breach">Donald Trump’s one-time law firm allegedly suffers data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358406/pixlr-data-breach-exposes-over-19m-users-info" data-original-url="/security/data-breaches/358406/pixlr-data-breach-exposes-over-19m-users-info">Pixlr data breach exposes over 1.9 million user records</a></p></div></div><p>Exposed data might include names, email addresses, and encrypted account passwords, the company added, before encouraging people to change their passwords as a cautionary measure.</p><p>The security professional said the breach was far worse than the company let on. “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk,” he told Krebs.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="L8vUrzgp7mhwUJ5GEHSyyi" name="L8vUrzgp7mhwUJ5GEHSyyi.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/L8vUrzgp7mhwUJ5GEHSyyi.png" mos="https://cdn.mos.cms.futurecdn.net/L8vUrzgp7mhwUJ5GEHSyyi.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Managing security risk and compliance in a challenging landscape</strong></p><p class="fancy-box__body-text">How key technology partners grow with your organisation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/354266/managing-security-risk-and-compliance-in-a" data-original-url="/business-strategy/digital-transformation/354266/managing-security-risk-and-compliance-in-a">FREE DOWNLOAD</a></p></div></div><p>According to Krebs' source, the cloud service provider was <a href="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach" data-original-url="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach">Amazon Web Services</a>, and the hackers got full administrative access to servers there after finding a Ubiquiti employee's password. This allegedly allowed them read/write access to Ubiquiti's databases, cryptographic secrets for users' online sessions, and sign keys and source code. </p><p>The breach also gave the attackers root access to all of the companies' AWS accounts, including all S3 data buckets, the source continued.</p><p>This reportedly enabled the attackers to authenticate remotely to Ubiquiti devices worldwide.</p><p>Ubiquiti reportedly found a back door the attackers left in the system, but the attackers tried to blackmail the company for 50 bitcoins to stay quiet. The company refused to engage the attackers, according to Krebs' story.</p><p>Instead of suggesting a password change, the company should have forcibly changed them, along with reverting device access permissions, the source said. However, the company's legal department overrode those requests.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Forex broker FBS leaves millions of customer records exposed ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/359027/forex-broker-fbs-exposes-millions-of-customer-records</link>
                                                                            <description>
                            <![CDATA[ Data includes names, passwords, emails, passport numbers, credit cards, financial transactions, and more ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7AezKTSumH8inriAULxtqm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ixgCiTr9KNj9SCsJC6HshS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 Mar 2021 16:23:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ixgCiTr9KNj9SCsJC6HshS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Foreign currency symbols on a screen]]></media:description>                                                            <media:text><![CDATA[Foreign currency symbols on a screen]]></media:text>
                                <media:title type="plain"><![CDATA[Foreign currency symbols on a screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ixgCiTr9KNj9SCsJC6HshS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">Security</a> researchers have discovered a data breach at a major foreign exchange (forex) broker.</p><p><a href="https://www.wizcase.com/blog/fbs-leak-research">According to WizCase</a>, online forex trading site FBS left nearly 20 TB of data exposed on an unsecured ElasticSearch server containing over 16 billion records.</p><p>The broker had over 16 million traders on its platform spanning 190 countries. According to WizCase web security expert Chase Williams the data contained millions of confidential records, including names, passwords, email addresses, passport numbers, national IDs, credit cards, financial transactions, and more.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358793/star-alliance-passenger-data-stolen-in-sita-data-breach" data-original-url="/security/data-breaches/358793/star-alliance-passenger-data-stolen-in-sita-data-breach">Star Alliance passenger data stolen in SITA data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach" data-original-url="/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach">Ten ways to protect your company from the next big data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358635/donald-trumps-one-time-law-firm-allegedly-suffers-data-breach" data-original-url="/security/data-breaches/358635/donald-trumps-one-time-law-firm-allegedly-suffers-data-breach">Donald Trump’s one-time law firm allegedly suffers data breach</a></p></div></div><p>There were also files uploaded by users for verification, including personal photos, national ID cards, drivers’ licenses, birth certificates, bank account statements, utility bills, and unredacted credit cards. Among the blog’s redacted pictures were French and Swedish credit cards, a Portuguese password, and details of a $500,000 transaction.</p><p>A team of <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hat hackers</a> led by Ata Hakcil of WizCase discovered the ElasticSearch server. The team discovered the leak on October 1 and contacted FBS the next day. FBS secured the server on October 5. It’s unknown how long FBS left the server unprotected before that. </p><p>“Despite containing very sensitive financial data, the server was left open without any password protection or encryption. The WizCase team found that the FBS information was accessible to anyone. The breach is a danger to both FBS and its customers. User information on online trading platforms should be well secured to prevent similar data leaks,” said Williams.</p><p>Williams added that hackers could use the personally identifiable information (PII) exposed by the leak in fraudulent authentication across other platforms. Threat actors can also use the leaked information to launch scams, <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, and <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware attacks</a> against FBS users. </p><p>“The data could be the basis for establishing trust to encourage clicks, malware downloads, and the availing of more confidential information. Armed with the sensitive authentic data, a cybercriminal will sound more credible when they request for information over the phone or email,” Williams said.</p><p>WizCase urged users to change their passwords, use <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication</a> on the platform, and watch for unusual and fraudulent activity on financial statements. Experts also advise FBS customers not to share any personal confidential information requested over email or the phone by potential scammers.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Third-party attacks expose 12 million health care records ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/358864/third-party-attacks-expose-12m-health-care-records</link>
                                                                            <description>
                            <![CDATA[ A single breach accounted for 10 million exposed records, report finds ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tWfuqwyWAJHHBpYvtJCTMJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fMbMro3SjAzTb5vKxrzNfc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Mar 2021 15:18:27 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fMbMro3SjAzTb5vKxrzNfc-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data Breach overlaying a circuitboard]]></media:description>                                                            <media:text><![CDATA[Data Breach overlaying a circuitboard]]></media:text>
                                <media:title type="plain"><![CDATA[Data Breach overlaying a circuitboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fMbMro3SjAzTb5vKxrzNfc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>New analysis from <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">cyber security</a> firm Tenable has found that third-party breaches accounted for over a quarter of the tracked breaches. These breaches accounted for nearly 12 million records exposed in the health care sector.</p><p>The firm’s <a href="https://www.tenable.com/profile/security-response-team">security response team</a> found 237 breaches in the health care sector in 2020. According to Tenable, breaches are set to continue unabated in 2021, with 56 breaches already disclosed through February. </p><p>The research found that in a quarter of cases, breaches occurred due to a separate breach at a third-party organization. This happens when hackers breach a third-party vendor that a health care organization uses, giving attackers access to data the health care provider's stores on the third-party system. Its analysis found that third-party breaches accounted for nearly 12 million exposed records. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358793/star-alliance-passenger-data-stolen-in-sita-data-breach" data-original-url="/security/data-breaches/358793/star-alliance-passenger-data-stolen-in-sita-data-breach">Star Alliance passenger data stolen in SITA data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach" data-original-url="/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach">Ten ways to protect your company from the next big data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358635/donald-trumps-one-time-law-firm-allegedly-suffers-data-breach" data-original-url="/security/data-breaches/358635/donald-trumps-one-time-law-firm-allegedly-suffers-data-breach">Donald Trump’s one-time law firm allegedly suffers data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations" data-original-url="/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations">How much will a data breach really damage your organisation’s reputation?</a></p></div></div><p>A single breach accounted for over 10 million of these records. “This breach has been linked back to 61 of their healthcare customers, with the number of exposed records expected to increase as more of these impacted customers disclose their numbers,” researchers said.</p><p>Of all the health care breaches disclosed between January 2020 and February 2021, 93% of them included confirmed record exposure. Researchers admitted that one obstacle with accurately tracking breaches is that public disclosures can occur days, months, or even years after the event. Even then, the level of detail available may be scant.</p><p>Of these 293 breaches analyzed, 57.34% of the affected organizations have publicly disclosed how many records the breach exposed. The number of records exposed in this period reached nearly 106 million — 76.45% of these were disclosed in 2020. </p><p>The research found that ransomware was the most prominent cause of health care breaches, accounting for 54.95%. Other leading causes included email compromise/phishing (21.16%), insider threat (7.17%), and unsecured databases (3.75%).</p><p>Boris Cipot, senior security engineer at Synopsys, told <em>ITPro</em> that this research shows that resilience is much more than the deployment of mitigation procedures, and it starts with software design. </p><p>“As software is the cornerstone of life today, it is important to apply security during the development process. If not, mitigation techniques will act simply as “band-aids on bullet holes,” Cipot said. </p><p>“It is normal to see cybercriminals focused on exploiting known security holes in commonly used software. It is also normal that phishing campaigns are deployed with the intention of gaining information that can help them to further infiltrate critical infrastructure. It is worrying how these things are considered to be normal.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft and FireEye push for corporate breach reporting rules ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/358707/big-tech-executives-urge-congress-to-create-corporate</link>
                                                                            <description>
                            <![CDATA[ The two companies believe companies should be able to report breaches without legal retribution ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qnE648uEw3n3nXiy4kFSNG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/f9EEH2EWrUUYcjAWLCcdHR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Feb 2021 18:12:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/f9EEH2EWrUUYcjAWLCcdHR-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft sign on a building]]></media:description>                                                            <media:text><![CDATA[Microsoft sign on a building]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft sign on a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/f9EEH2EWrUUYcjAWLCcdHR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft and FireEye executives have urged Congress to create laws requiring firms to disclose security breaches in the wake of <a href="https://www.itpro.com/security/358111/solarwinds-confirms-cyber-attack" data-original-url="https://www.itpro.com/security/358111/solarwinds-confirms-cyber-attack">the SolarWinds hack</a>.</p><p>According to <em><a href="https://thehill.com/policy/cybersecurity/540178-microsoft-fireeye-mandatory-breach-reporting-solarwinds-hack">The Hill</a>,</em> Microsoft president Brad Smith said in written testimony to the Senate Intelligence Committee there is a “need to impose a clear, consistent disclosure obligation on the private sector.” He added that “silence reigns” when companies are hacked.</p><p>“This is a recipe for making a formidable problem even worse, and it requires all of us to change,” he added. “We need to replace this silence with a clear, consistent obligation for private sector organizations to disclose when they’re impacted by confirmed significant incidents.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/358646/weekly-threat-roundup-solarwinds-style-hack-macos-big-sur" data-original-url="/security/vulnerability/358646/weekly-threat-roundup-solarwinds-style-hack-macos-big-sur">Weekly threat roundup: SolarWinds-style hack, macOS Big Sur, Telegram</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/358618/france-identifies-wide-reaching-solarwinds-esque-cyber-attack" data-original-url="/security/cyber-attacks/358618/france-identifies-wide-reaching-solarwinds-esque-cyber-attack">France uncovers SolarWinds-esque cyber attack targeting Centreon</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/358541/solarwinds-expands-response-capabilities-following-hack" data-original-url="/security/cyber-attacks/358541/solarwinds-expands-response-capabilities-following-hack">SolarWinds bolsters its security response capabilities following hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/358509/beleaguered-solarwinds-hit-with-fresh-vulnerabilities" data-original-url="/security/vulnerability/358509/beleaguered-solarwinds-hit-with-fresh-vulnerabilities">Beleaguered SolarWinds hit with fresh vulnerabilities</a></p></div></div><p>FireEye CEO Kevin Mandia, whose company discovered the breach, said companies should be able to report breaches that could have national security ramifications without fear of retribution.</p><p>“The US government should consider a federal disclosure program for not only sharing threat indicators but for also providing notification of a breach or incident,” he said.</p><p>According to White House officials, the SolarWinds breach affected nine federal agencies and 100 private companies. Intelligence officials have said the <a href="https://www.itpro.com/security/358240/solarwinds-hack-likely-russian-in-origin-says-fbi" data-original-url="https://www.itpro.com/security/358240/solarwinds-hack-likely-russian-in-origin-says-fbi">attacks likely originated in Russia</a>.</p><p>Smith added that substantial evidence points to the Russian foreign intelligence agency’s involvement and nowhere else. He and Mandia said companies such as theirs had no legal obligation to disclose breaches, but a “duty nonetheless” to customers, the government, and the public.</p><p>“We will not secure this country without that kind of sharing,” said Smith.</p><p>Currently, breach notification occurs at the state level, and years of federal efforts to develop laws have netted no changes. This means the full extent of breaches remains unknown.</p><p>Mandia added that while the SolarWinds breach was stopped, another will happen, and this highlights the need for stronger breach notification requirements.</p><p>“This attacker, maybe their pencil is down for a few months, but the reality is they are going to come back,” Mandia said. “How they break in is always evolving, and all we can do is close the window and close the security gap better next time.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Four tips for keeping your business secure during mass remote work ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/358666/four-tips-for-keeping-your-business-secure-during-mass</link>
                                                                            <description>
                            <![CDATA[ How to maintain a resilient cyber security strategy when your employees are outside the company firewall ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7wQPshUVGxz29TQTBKNADa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Pr8PmHbiSxYvpUaoatf3eN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Feb 2021 16:13:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Gabriella Buckner ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Pr8PmHbiSxYvpUaoatf3eN-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person in a home office at a computer with an unlocked lock on it]]></media:description>                                                            <media:text><![CDATA[Person in a home office at a computer with an unlocked lock on it]]></media:text>
                                <media:title type="plain"><![CDATA[Person in a home office at a computer with an unlocked lock on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Pr8PmHbiSxYvpUaoatf3eN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While some of us may be working in pyjamas and enjoying a much more relaxed commute—shuffling last-minute from the bedroom to the home office or dining table—data protection laws certainly haven’t relaxed, and it’s imperative that your organisation maintain the same attitude toward security that it would if everyone was in the office.</p><p>Extended perimeters and the use of personal devices and networks, in combination with the proliferation of the cloud, make data security a lot more difficult. And when everyone is <a href="https://www.itpro.com/business/business-strategy/356096/remote-working-are-you-ready-for-the-new-normal" data-original-url="https://www.itpro.com/business/business-strategy/356096/remote-working-are-you-ready-for-the-new-normal">working from home</a>, communicating and managing security measures and monitoring for breaches can be a struggle.</p><p><a href="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations" data-original-url="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations">A serious breach can be fatal</a> for your business, whether it’s through crippling regulatory action or through a tarnished reputation, and even a relatively small incident can stymie the success of your business. So even though it might seem like the world’s upside down sometimes, keeping on top of data security will contribute to your business weathering the storm and coming out strong on the other side.</p><h3 class="article-body__section" id="section-1-update-your-cyber-security-policy"><span>1. Update your cyber security policy</span></h3><p>While your existing policy may have fit office life, you’ll almost certainly need to adapt it to the realities of a distributed workforce, if you haven’t already.</p><p>Push updates to all company devices, systems, and programs to maintain good data hygiene and get the latest security patches. Also make sure that employees know to update their personal devices, and when not to - in the case of a software vulnerability.</p><p>Your home working policy should also cover how employees should deal with data when working remotely, including transportation, storage, and disposal, which are all important components of GDPR. Make your policy known company-wide, invite questions, and highlight the responsibility of every employee to stick to it.</p><h3 class="article-body__section" id="section-2-encrypt-and-control-access"><span>2. Encrypt and control access</span></h3><p>As part of your strategy, you’ll want to limit an attacker’s reach in the event of a data breach, and one of the simplest and most effective ways to do this is through <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encryption</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/flexible-working/358420/what-are-employers-responsibilities-when-we-use-personal" data-original-url="/business-strategy/flexible-working/358420/what-are-employers-responsibilities-when-we-use-personal">What are employers' responsibilities when we use personal tech to work from home?</a></p></div></div><p>Your IT team will be used to having the ability to monitor server security and the network from within the office, but encrypting all of your employees’ devices, including personal devices and work phones, can achieve the same effect from home. </p><p>Using a VPN to create an encrypted connection to corporate servers also helps maintain data privacy for employees working from any location, particularly as you can’t always ensure that every remote employee is using a secure, private network.</p><p>Another method of limiting the spread of a data breach is by limiting the access each employee has.</p><p>If an attack is made through an employee who only has access to the resources they need for their daily work, then an attacker will have difficulty reaching some of the more critical areas of your network.</p><p>A <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust" data-original-url="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">zero-trust model</a>, in which it’s assumed that no user or device inside or outside the network can be trusted, is a holistic approach to cyber security through limiting user access. Even by picking out components of the model, like multi-factor authentication, you can set up several barriers against potential breaches fairly easily.</p><h3 class="article-body__section" id="section-3-train-employees-in-security-awareness"><span>3. Train employees in security awareness</span></h3><p>Even if you have great policies and the best cyber security tech, they won’t save you if your employees aren’t properly trained in your policies and basic <a href="https://www.itpro.com/security/357406/four-tips-for-building-effective-security-awareness-training" data-original-url="https://www.itpro.com/security/357406/four-tips-for-building-effective-security-awareness-training">security awareness</a>.</p><p>Encrypting your devices and using <a href="https://www.itpro.com/security/27098/best-vpn-services" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">VPNs</a> and/or zero-trust security measures is important, but you also need to educate your employees on the dangers of setting their home Wi-Fi passwords as ‘password’, or connecting through unsecure public hotspots.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">Secure your Wi-Fi against hackers in 10 steps</p></div></div><p>Employees will typically represent the biggest vulnerability in your security posture, whether that’s due to malicious insider attacks or, as is most often the case, human error of some kind.</p><p>Train your workers to recognise phishing emails through some form of company-wide cyber security awareness training. This type of attack increased internationally by <a href="https://www.interpol.int/en/News-and-Events/News/2020/INTERPOL-report-shows-alarming-rate-of-cyberattacks-during-COVID-19?utm_source=xp&utm_medium=blog&utm_campaign=content">59%</a> in the first few months of the pandemic and, followed by stolen credentials, remains the <a href="https://enterprise.verizon.com/resources/reports/2020-data-breach-investigations-report.pdf">most common vector of attack</a>.</p><p>According to the <a href="https://www.mediapro.com/report-2020-state-of-privacy-security-awareness">2020 State of privacy and security awareness report</a>, 43% of employees are not aware that clicking a suspicious link or opening an unknown attachment in an email is likely to lead to a malware infection.</p><h3 class="article-body__section" id="section-4-stick-to-gdpr-guidelines-if-a-breach-does-occur"><span>4. Stick to GDPR guidelines if a breach does occur</span></h3><p>It’s still possible your organisation gets hit with a data breach, and if it does, you still have the same responsibilities as before the pandemic.</p><p>While the <a href="https://ico.org.uk">Information Commissioner’s Office</a> said in a <a href="https://ico.org.uk/global/data-protection-and-coronavirus-information-hub/coronavirus-recovery-data-protection-advice-for-organisations/regulatory-approach">notice</a> published in September 2020 that it’s committed to an ‘empathetic and pragmatic approach’ that takes into account how difficult times are right now, organisations are still required to report breaches to the ICO within 72 hours of becoming aware of them - provided the incident is likely to infringe on the rights of the data subject.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation" data-original-url="/endpoint-security/34536/mastering-endpoint-security-implementation">Mastering endpoint security implementation</a></p></div></div><p>With a third of respondents in the <em>2020 State of privacy and security awareness report</em> saying they would ‘probably’ report a security incident and 19% saying they weren’t sure or simply wouldn’t report it, it’s clear that some work is still needed to ensure that employees take responsibility for their own cyber security. Part of this is ensuring they understand when a data breach has occurred, but it’s also important that you foster a culture that makes it clear that accidents can happen and employees shouldn’t feel embarrassed about reporting even the smallest of incidents. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kia Motors allegedly suffers a ransomware attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/358648/kia-motors-allegedly-suffers-a-ransomware-attack</link>
                                                                            <description>
                            <![CDATA[ Hackers demanding a $20 million ransom to release a decryptor ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ka1iDbkbgeD8gQRfdoM34G</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/z3xFeKHfKcBaHARwyjncWM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Feb 2021 15:15:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/z3xFeKHfKcBaHARwyjncWM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Kia sign with a red background]]></media:description>                                                            <media:text><![CDATA[Kia sign with a red background]]></media:text>
                                <media:title type="plain"><![CDATA[Kia sign with a red background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/z3xFeKHfKcBaHARwyjncWM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kia Motors America has been hit with a $20 million ransom by the hackers behind the DoppelPaymer ransomware.</p><p>The attack has taken the car manufacturer’s systems offline, and the gang has threatened to leak sensitive information if the company didn’t pay up. So far, the attack has seen a nationwide outage of internal websites used by dealers. Kia Motors </p><p>A ransom note sent to Kia’s parent company, Hyundai Motor America, and <a href="https://www.bleepingcomputer.com/news/security/kia-motors-america-suffers-ransomware-attack-20-million-ransom">seen by Bleeping Computer</a> said to prevent the data leak and receive a decryptor, the company must pay the hackers 404 bitcoins (approximately $20 million). If Kia fails to pay, the ransom increases to 600 bitcoins (roughly $30 million).</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358635/donald-trumps-one-time-law-firm-allegedly-suffers-data-breach" data-original-url="/security/data-breaches/358635/donald-trumps-one-time-law-firm-allegedly-suffers-data-breach">Donald Trump’s one-time law firm allegedly suffers data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations" data-original-url="/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations">How much will a data breach really damage your organisation’s reputation?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358454/citrix-employees-win-2" data-original-url="/security/data-breaches/358454/citrix-employees-win-2">Citrix employees win $2.3m settlement over 2019 data breach</a></p></div></div><p>According to reports, DoppelPaymer hackers haven’t said what data they’ve stolen.</p><p>Kia Motors America denied that it suffered a ransomware attack but did admit it was “experiencing an extended systems outage.”</p><p>Sam Curry, chief security officer at Cybereason, told <em>ITPro</em> if news reports are accurate, Kia Motors has long since passed the panic mode in dealing with a massive ransomware attack that has affected operations for more than five days.</p><p>“From afar, it appears the attackers have taken Kia Motors to its knees. Think about the scale of the problem for a company of this size with tens of thousands of employees and thousands of dealerships. Every additional hour and day they are incapacitated is costing the company tens of millions of dollars that will not be recouped,” Curry said.</p><p>Natalie Page, threat intelligence analyst at Talion, told <em>ITPro</em> DoppelPaymer is a problematic strain we’ve seen successfully infiltrate numerous large-scale global organizations recently. It’s infamous for its initial immense ransom demands, often negotiated to a much smaller amount if the organization chooses to pay.</p><p>“Unfortunately for Kia there is no guarantee that if the ransom is paid, DopplePaymer’s operators shall not leak any sensitive data,” she said. “Whichever eventuality the company selects, as stressful as the situation will currently be for Kia, for the salvation of the company’s reputation the priority going forward needs to be their clients and shareholders. Communication is key.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Donald Trump’s one-time law firm allegedly suffers data breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/358635/donald-trumps-one-time-law-firm-allegedly-suffers-data-breach</link>
                                                                            <description>
                            <![CDATA[ Hackers claimto have stolen 100GB of confidential files belonging to the Jones Day law firm ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xxyxmAzU1ZkmwBLRJ9REjM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JtMF52dubT4BPNVVtmKMZ8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Feb 2021 14:49:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JtMF52dubT4BPNVVtmKMZ8-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data breach]]></media:description>                                                            <media:text><![CDATA[Data breach]]></media:text>
                                <media:title type="plain"><![CDATA[Data breach]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JtMF52dubT4BPNVVtmKMZ8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers claim to have stolen confidential files belonging to the Jones Day law firm, which once represented former-president Donald Trump. The hackers allegedly posted sensitive files on the dark web, but the law firm denies the breach occurred.</p><p><em><a href="https://www.databreaches.net/threat-actors-claim-to-have-stolen-jones-day-files-law-firm-remains-quiet">DataBreaches.net</a></em> initially reported the attack, which is thought to involve the Clop ransomware gang. The hackers claimed to have obtained 100GB of data from the law firm and published redacted files to prove their attack. The gang has demanded a $20 million ransom payment in return for a decryption key.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations" data-original-url="/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations">How much will a data breach really damage your organisation’s reputation?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach" data-original-url="/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach">Ten ways to protect your company from the next big data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358454/citrix-employees-win-2" data-original-url="/security/data-breaches/358454/citrix-employees-win-2">Citrix employees win $2.3m settlement over 2019 data breach</a></p></div></div><p>The law firm disputed the hackers' claims that they breached its network. However, it did say a file-transfer platform it used was recently compromised, affecting the firm’s data. The compromised platform belongs to California-based <a href="https://www.itpro.com/cloud" data-original-url="https://www.itpro.com/cloud">cloud</a> computing company Accellion.</p><p>“Jones Day has been informed that Accellion’s FTA file transfer platform, which is a platform that Jones Day—like many law firms, companies, and organizations—used was recently compromised and information taken,” a spokesperson for the firm said in a <a href="https://news.bloomberglaw.com/business-and-practice/jones-day-hit-by-data-breach-as-vendor-accellion-hacks-widen">statement</a> to Bloomberg Law. </p><p>“Jones Day continues to investigate the breach and has been, and will continue to be, in discussion with affected clients and appropriate authorities.”</p><p>The <a href="https://www.wsj.com/articles/hacker-claims-to-have-stolen-files-belonging-to-prominent-law-firm-jones-day-11613514532?utm_campaign=Eskenzi%20Daily%20News%20Bulletin&utm_medium=email&_hsmi=111534519&_hsenc=p2ANqtz-8VaQ04cUoBD7O5NR6ZXqQQJgR9szqFEs7ra6EwAmE8lXatCe52Qt8im5wSKfDqvdpgVCzOEkkxVd6fYkLQ4_tYJApX4g&utm_content=111534519&utm_source=hs_email"><em>Wall Street Journal</em> said</a> it’s not only seen some breached files, but it could also “see the existence of many more files — mammoth in size — also purported to belong to Jones Day.”</p><p>James McQuiggan, Security Awareness Advocate at KnowBe4, told <em>IT Pro</em> that like the <a href="https://www.itpro.com/security/358288/solarwinds-hackers-breached-systems-september-2019" data-original-url="https://www.itpro.com/security/358288/solarwinds-hackers-breached-systems-september-2019">SolarWinds supply-chain attack</a>, the cyber criminals are focusing their attacks on those third parties and service providers that support many customers.</p><p>“These organizations will want to review and elevate their security programs to ensure they do not suffer a breach, leading to a similar compromise. These attacks damage the organization’s customers and clients and damage the reputation and possible bottom line for that organization,” McQuiggan said. </p><p>“With an organization that provides large file transfers, one consideration for them to protect their data is to encrypt the data before transferring it and to protect it from the third-party provider. Upon delivery to the receiver, they would have the key to decrypt and view the data."</p><p>Martin Jartelius, CSO at Outpost24, told <em>IT Pro</em> what we’re seeing now are the effects of the Accellion intrusion from December.</p><p>“It’s an external file sharing solution that’s decades-old and has been used by several organizations. As we are seeing more and more data related to the breach hitting the news, other organizations that have used the services should review and prepare processes to inform any clients and any individuals for whom data has been processed on this platform,” Jartelius said. </p><p>“Noting that we are approaching a two-month mark from when the breach likely occurred, those who suspect they may be affected should consider informing any affected data subjects at the soonest in line with current privacy legislation and not wait and hope for the best.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ten ways to protect your company from the next big data breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach</link>
                                                                            <description>
                            <![CDATA[ Even big-name corporations can’t prevent all breaches, but there are ways to protect your business ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tBsMFeT2LundVwQcCR5Fhb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wPmCm58bH4X4vShukhSrAQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 Jan 2021 13:41:09 +0000</pubDate>                                                                                                                                <updated>Fri, 18 Feb 2022 15:10:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tyler Omoth ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wPmCm58bH4X4vShukhSrAQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Shutterstock]]></media:description>                                                            <media:text><![CDATA[Close up of network cables with data breach label]]></media:text>
                                <media:title type="plain"><![CDATA[Close up of network cables with data breach label]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wPmCm58bH4X4vShukhSrAQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Your company deals with sensitive information — all companies do. Whether it’s customers’ private information, your company’s financial records and accounts, or that new top-secret project you don’t want getting out just yet, keeping your data secure is a top priority. Unfortunately, it seems to be getting harder all the time.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nrLP4J9zrGeXVej3Fjg2DP" name="nrLP4J9zrGeXVej3Fjg2DP.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/nrLP4J9zrGeXVej3Fjg2DP.png" mos="https://cdn.mos.cms.futurecdn.net/nrLP4J9zrGeXVej3Fjg2DP.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Secure hybrid cloud for dummies</strong></p><p class="fancy-box__body-text">Accelerate transformation with hybrid cloud</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/hybrid-cloud/362139/secure-hybrid-cloud-for-dummies" data-original-url="/cloud/hybrid-cloud/362139/secure-hybrid-cloud-for-dummies">FREE DOWNLOAD</a></p></div></div><p>We’ve seen many major data breaches at many big name companies, including <a href="https://www.itpro.com/security/data-breaches/358221/hackers-breach-t-mobile-customer-records" data-original-url="https://www.itpro.com/security/data-breaches/358221/hackers-breach-t-mobile-customer-records">T-Mobile</a>, <a href="https://www.itpro.com/hacking/29736/microsoft-downplayed-internal-database-hack" data-original-url="https://www.itpro.com/hacking/29736/microsoft-downplayed-internal-database-hack">Microsoft</a>, and <a href="https://www.itpro.com/security/data-breaches/355097/ge-employees-hit-by-canon-data-breach" data-original-url="https://www.itpro.com/security/data-breaches/355097/ge-employees-hit-by-canon-data-breach">General Electric</a>. Even the Internal Revenue Service (IRS) fell victim to a major data breach. </p><p>It doesn’t matter if you’re in charge of a Fortune 500 company or a small business, you must protect your data. While there's no foolproof way to secure all of your sensitive data, these steps can help prevent a data breach.</p><h2 id="data-breach-defined">Data breach defined</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="e7vfvjoAdsyGB7mFPYhK9i" name="" alt="A woman examining on-screen data read outs" src="https://cdn.mos.cms.futurecdn.net/e7vfvjoAdsyGB7mFPYhK9i.jpg" mos="https://cdn.mos.cms.futurecdn.net/e7vfvjoAdsyGB7mFPYhK9i.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Although the exact definition <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">can vary between regulators</a>, a data breach usually occurs when any unauthorised party gains access to confidential information.</p><p>The term usually covers everything from one of your own employees logging into a file without permission, to cyber criminals hacking into your systems and taking the personal information of employees and customers.</p><p>Normally a breach also involves the <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">failure of a security layer</a>, which results in the <a href="https://www.itpro.com/security/cyber-crime/356898/ex-cisco-engineer-charged-with-wiping-16000-internal-webex-teams" data-original-url="https://www.itpro.com/security/cyber-crime/356898/ex-cisco-engineer-charged-with-wiping-16000-internal-webex-teams">accidental or purposeful destruction</a>, <a href="https://www.itpro.com/security/357570/trump-site-hacked-in-second-successive-cyber-breach" data-original-url="https://www.itpro.com/security/357570/trump-site-hacked-in-second-successive-cyber-breach">alteration</a>, <a href="https://www.itpro.com/security/data-breaches/358221/hackers-breach-t-mobile-customer-records" data-original-url="https://www.itpro.com/security/data-breaches/358221/hackers-breach-t-mobile-customer-records">theft</a>, or <a href="https://www.itpro.com/security/data-breaches/358510/foxtons-customer-data-found-available-on-dark-web" data-original-url="https://www.itpro.com/security/data-breaches/358510/foxtons-customer-data-found-available-on-dark-web">disclosure of protected data</a>. It is considered a breach if an unauthorised individual simply looks at the data. The consequences can be severe for business, regardless of its exact nature.</p><h2 id="the-consequences-of-a-data-breach">The consequences of a data breach</h2><p>The consequences of a data breach can be as varied as the different forms of breaches themselves. It could be as small as a single employee finding out his peers’ salaries and threatening to sue for higher pay. Alternatively, it could be as severe as cyber criminals or hackers accessing your system’s files and encrypting them before demanding a ransom.</p><p>If you follow recent news, you might have seen a variety of data breaches making the headlines which often involve accessing customer data, like addresses, names, social security numbers, and even credit card numbers. These breaches can cost the companies who are affected millions of dollars in lawsuits and lost business.</p><p>After a breach has occurred, detecting, defining, and recovering from the incident can be a long and slow process for an organisation. Although the consequences of this kind of leak can be brutal for larger corporations, they can be the death knell for a small business. The best strategy is to be prepared if it occurs and prevent it from ever happening.</p><h2 id="10-steps-to-keeping-your-data-safe">10 steps to keeping your data safe</h2><p>While there is no surefire way to eliminate all data breaches, these nine steps will help your business prevent catastrophic leaks.</p><h3 class="article-body__section" id="section-1-hire-a-professional"><span>1. Hire a professional</span></h3><p>You probably have a financial controller or accountant in charge of payroll and accounts payable. Why would you not have a specialized IT security person to safeguard the entirety of your business?</p><p>Technology changes quickly, and <a href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs" data-original-url="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs">you need someone dedicated and accountable</a> who can find your vulnerabilities and help you shore them up. This IT watchdog can be your best bet in defending your business from external and internal data breaches.</p><h3 class="article-body__section" id="section-2-separate-your-business-and-personal-accounts"><span>2. Separate your business and personal accounts</span></h3><p>Keeping your business and personal accounts separate should be obvious, but we’re not talking just about bank accounts and credit cards. This separation also goes for all of your accounts, including email and data storage. Keep them separate and have unique passwords for everything.</p><p>The last thing you need is someone hacking into your personal email and suddenly having access to sensitive business data.</p><p>Make sure everyone in your company follows this practice too. It only takes one small mistake to expose the whole company.</p><h3 class="article-body__section" id="section-3-checkout-finra"><span>3. Checkout FINRA</span></h3><p>The Financial Industry Regulatory Authority (FINRA) is a government-authorized nonprofit organization that oversees US broker-dealers and has a pretty good handle on what it takes to have top-notch cybersecurity.</p><p>It has put together a <a href="https://www.finra.org/compliance-tools/cybersecurity-checklist">Small Firm Cybersecurity Checklist</a> that’s a handy tool for any business looking to up its <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> game. It’s free to download and could help you secure some aspects of your business you hadn’t thought about before.</p><h3 class="article-body__section" id="section-4-restrict-access-as-much-as-possible"><span>4. Restrict access as much as possible</span></h3><p>As much as possible, <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust" data-original-url="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">limit each employee's access to data</a>. That means any employee who doesn’t need access to a program or data file doesn’t get access.</p><p>By all means, provide each employee with the permissions she needs to do their job, but limit anything that isn’t necessary. The fewer people accessing data, the lower the risk of a breach—accidental or otherwise.</p><h3 class="article-body__section" id="section-5-minimize-your-data"><span>5. Minimize your data</span></h3><p>Think of your business as your home, and all that data is the stuff in your home. The more things you have cluttering an area up, the harder it is to keep track of the important stuff. It’s time to clean up.</p><p>Eliminate old programs or data files that serve no purpose. <a href="https://www.itpro.com/security/34049/how-to-build-a-comprehensive-cyber-security-strategy" data-original-url="https://www.itpro.com/security/34049/how-to-build-a-comprehensive-cyber-security-strategy">Team up with your IT security officer to establish the proper procedures</a> for identifying and eliminating unnecessary files.</p><p>Keeping your data tidy can also help you identify a breach problem sooner too.</p><h3 class="article-body__section" id="section-6-encryption"><span>6. Encryption</span></h3><p>Today’s technology offers <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">plenty of avenues for encrypting your data</a>. Use them. Don’t just encrypt data sitting in files; use encryption for files on the move through email and other means.</p><h3 class="article-body__section" id="section-7-educate-your-employees"><span>7. Educate your employees</span></h3><p>One of the most common ways data breaches occur is through an honest employee mistake. You must teach your employees how to create unbreakable passwords and how to identify potential phishing scams and other security threats.</p><p>Train, test, and educate your employees on the importance of information security. It can be a tough job to get your employees on board with cyber security training, but it’s essential.</p><h3 class="article-body__section" id="section-8-get-the-c-suite-on-board"><span>8. Get the C-suite on board</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wDQfXhNPUxQ6TfnH5UYHo3" name="" alt="A person on a laptop to depict hacking" src="https://cdn.mos.cms.futurecdn.net/wDQfXhNPUxQ6TfnH5UYHo3.jpg" mos="https://cdn.mos.cms.futurecdn.net/wDQfXhNPUxQ6TfnH5UYHo3.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Shutterstock </span><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Cyber security awareness and understanding must start at the top. <a href="https://www.itpro.com/cyber-security/32788/the-c-suite-could-be-the-blind-spot-in-your-cyber-security-strategy" data-original-url="https://www.itpro.com/cyber-security/32788/the-c-suite-could-be-the-blind-spot-in-your-cyber-security-strategy">If the company’s executives don’t fully understand the threat and consequences</a>, it will create a difficult hurdle for each step of the process.</p><p>Cyber security is an investment, and like any investment a company makes, the C-suite needs to see the benefit before they’ll be willing to pay for it.</p><h3 class="article-body__section" id="section-9-don-t-ignore-hard-copies"><span>9. Don’t ignore hard copies</span></h3><p>Data breaches don’t always happen online. <a href="https://www.itpro.com/security/29965/documents-the-security-risk-you-hadnt-thought-of" data-original-url="https://www.itpro.com/security/29965/documents-the-security-risk-you-hadnt-thought-of">Printed documents can cause equal damage in the wrong hands</a>. Keep all sensitive files in a locked cabinet and designate a gatekeeper who only gives access to those who truly need it.</p><p>Also, invest in a quality crosscut paper shredder to properly destroy any documents you need to eliminate.</p><h3 class="article-body__section" id="section-10-have-a-data-breach-response-plan"><span>10. Have a data breach response plan</span></h3><p>While preventing a data breach is always the number one goal, your company needs to have an action plan for handling a breach. The ability to quickly detect a breach can save millions of dollars in some situations.</p><p>Talk with a cyber security professional and establish steps to identify, contain, and then recover from a data breach.</p><h2 id="data-protection-is-an-ongoing-process">Data protection is an ongoing process</h2><p>Once you’ve completed all 10 steps, get ready to do them all over again. Technology changes quickly, and cyber criminals are continually finding new ways to break into sensitive information and profit from it.</p><p>If you want to avoid becoming a victim of the next big data breach, stay one step ahead of the game. Companies that become complacent with their cyber security end up being vulnerable to attack.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Pixlr data breach exposes over 1.9 million user records ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/358406/pixlr-data-breach-exposes-over-19m-users-info</link>
                                                                            <description>
                            <![CDATA[ Bad actors could use the breached data in targeted phishing and credential-stuffing attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wKxTmcPXhkgHTNcwdyvM5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bBtqwcJG7cMwwtt4T6VgMf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Jan 2021 15:53:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bBtqwcJG7cMwwtt4T6VgMf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Pixlr website on a computer screen]]></media:description>                                                            <media:text><![CDATA[Pixlr website on a computer screen]]></media:text>
                                <media:title type="plain"><![CDATA[Pixlr website on a computer screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bBtqwcJG7cMwwtt4T6VgMf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For-profit hacker ShinyHunters has leaked 1.9 million Pixlr user records, including information bad actors could use to carry out targeted phishing and credential-stuffing attacks. Pixlr is a free online photo-editing application.</p><p>Experts believe the alleged Pixlr database that ShinyHunters posted may include 1,921,141 user records. Within these records are email addresses, login names, SHA-512 hashed passwords, a user's country, whether they signed up for the newsletter, and other sensitive information.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/357770/hackers-steal-83m-user-records-from-123rf" data-original-url="/security/357770/hackers-steal-83m-user-records-from-123rf">Hackers steal 8.3 million user records from 123RF</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/162240/demand-for-tougher-data-breach-legislation" data-original-url="/162240/demand-for-tougher-data-breach-legislation">Demand for tougher data breach legislation</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/613798/what-to-do-in-case-of-a-data-breach" data-original-url="/613798/what-to-do-in-case-of-a-data-breach">What to do in case of a data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/92440/three-aol-employees-depart-following-data-breach" data-original-url="/92440/three-aol-employees-depart-following-data-breach">Three AOL employees depart following data breach</a></p></div></div><p>According to a <em>Bleeping Computer</em> <a href="https://www.bleepingcomputer.com/news/security/hacker-posts-19-million-pixlr-user-records-for-free-on-forum">report</a>, ShinyHunters shared the database on the dark web. The hacker claimed they stole the database during their November <a href="https://www.itpro.com/security/357770/hackers-steal-83m-user-records-from-123rf" data-original-url="https://www.itpro.com/security/357770/hackers-steal-83m-user-records-from-123rf">breach of 123rf</a>, which shares the same parent company as Pixlr. </p><p>In the 123rf breach, hackers stole over 8.3 million user data records. These records contained email addresses, MD5 hashed passwords, company names, phone numbers, addresses, PayPal emails, and IP addresses.</p><p>ShinyHunters has also been responsible for data breaches at Minted, Chatbooks, Wattpad, and others.</p><p>Stephen Kapp, CTO and founder at Cortex Insight, told <em>IT Pro</em> that<em> </em>the Pixlr breach shows how cyber criminals are actively targeting organizations to monetize data.</p><p>“To help limit the damage, Pixlr should look to improve its internal processes by holding user information within application databases or dedicated SSO systems, such as those offered by AWS. This would allow for dedicated password hashing that includes a Salt Work Factor to help mitigate against brute force attacks,” Kapp said.</p><p>Boris Cipot, senior security engineer at Synopsys, told <em>IT Pro</em> that in the wake of this breach, users should change their password on Pixlr. They should also change the password on other sites where they may have reused their Pixlr password, as hackers can sometimes revert hashed passwords. </p><p>“Users should also be prepared for possible phishing attacks. They should not blindly click on links sent via email. These links may lead you to a malicious site where you will be encouraged to 'change' your password. The same goes for documents - do not download anything without first verifying the authenticity of the sender. Cybercriminals will try to abuse every piece of information they have on you for their own personal gain; therefore, think twice before actioning any emails," Cipot said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Capcom data breach adds another 40,000 estimated victims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/358308/capcom-adds-another-40000-users-to-its-estimated-data-leak</link>
                                                                            <description>
                            <![CDATA[ The gaming company now estimates up to 390,000 have been affected ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">byuzVoW188oJbqbigrMYx2</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/inhWNtU8E8gaZ5bxFD8aGP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Jan 2021 15:00:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/inhWNtU8E8gaZ5bxFD8aGP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[CAPCOM logo on a smartphone screen]]></media:description>                                                            <media:text><![CDATA[CAPCOM logo on a smartphone screen]]></media:text>
                                <media:title type="plain"><![CDATA[CAPCOM logo on a smartphone screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/inhWNtU8E8gaZ5bxFD8aGP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> attack launched against gaming company Capcom last November is much worse than originally reported.</p><p>In a statement, the company behind games such as Resident Evil, Street Fighter, and DarkStalkers said the attack potentially compromised up to 390,000 users’ data - 40,000 more than the company initially thought.</p><p>Capcom discovered the data breach, which the company said impacted personal and corporate data, in early November 2019.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/357681/capcom-ransomware-attack-350000-users" data-original-url="/security/hacking/357681/capcom-ransomware-attack-350000-users">Up to 350,000 people affected by Capcom ransomware attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/151440/ransomware-in-the-wild-again" data-original-url="/151440/ransomware-in-the-wild-again">Ransomware in the wild again</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/24703/ransomware-attacks-android-devices-with-500-fee" data-original-url="/mobile/24703/ransomware-attacks-android-devices-with-500-fee">Ransomware attacks Android devices with $500 fee</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/24870/click-fraud-becomes-entry-route-for-ransomware-attacks" data-original-url="/security/24870/click-fraud-becomes-entry-route-for-ransomware-attacks">'Click fraud' becomes entry route for ransomware attacks</a></p></div></div><p>Initially, the company confirmed the data leak affected only nine people and <a href="https://www.itpro.com/security/hacking/357681/capcom-ransomware-attack-350000-users" data-original-url="https://www.itpro.com/security/hacking/357681/capcom-ransomware-attack-350000-users">estimated the total impact to be 350,000 people</a>. In a new <a href="https://www.capcom.co.jp/ir/english/news/html/e210112.html">update</a>, Capcom said the company has verified that the breach compromised an additional 16,406 users' personal information, bringing the number of confirmed users impacted to 16,415.</p><p>The company said its investigations were ongoing, and it's “possible that new facts may come to light going forward.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="L8vUrzgp7mhwUJ5GEHSyyi" name="L8vUrzgp7mhwUJ5GEHSyyi.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/L8vUrzgp7mhwUJ5GEHSyyi.png" mos="https://cdn.mos.cms.futurecdn.net/L8vUrzgp7mhwUJ5GEHSyyi.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Managing security risk and compliance in a challenging landscape</strong></p><p class="fancy-box__body-text">How key technology partners grow with your organisation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/354266/managing-security-risk-and-compliance-in-a" data-original-url="/business-strategy/digital-transformation/354266/managing-security-risk-and-compliance-in-a">FREE DOWNLOAD</a></p></div></div><p>“Capcom offers its sincerest apologies for any complications and concerns that this may bring to its potentially impacted customers as well as to its many stakeholders,” the statement said.</p><p>Capcom added that none of the at-risk data contains credit card information. “All online transactions etc. are handled by a third-party service provider, and as such Capcom does not maintain any such information internally,” read the statement.</p><p>The company also said the areas this attack impacted are unrelated to systems used when connecting to the internet to play or purchase the company's games online. These have continued to use an external third-party server or an external server. </p><p>“As such, these systems have been unaffected by this ransomware attack and it is safe for Capcom customers or others to connect to the internet to play or purchase the company's games online,” the company said.</p><p>Niamh Muldoon, global data protection officer at <a href="https://u7061146.ct.sendgrid.net/ls/click?upn=4tNED-2FM8iDZJQyQ53jATUTgSYqpKpZkGs3reYKZeA92SBzcMaOzop5cHCwbvE020YMKH_IGQ5mBX-2BK4JtcLmRVjpnFXpCOkHgRjcLOBod1NRoFEOamaq93V3pkGH6tv2UbmQHNsNTzXQczlZbuUXCHK8USdjzNtbrpkt9wLy2nqbZ-2FnWJgL5mAEKpt9xQUJVCXUJNIz1U2DqbDunQdp0mOZOhvXzxK0drLXJ-2F-2BDqc-2FZOq7b1zENo3qmZPnUL8pmLMmEnr6DLEV-2FdGdjg0OdXg7ID84A-2BUOqQTSVs71JKpSDBhBUoGcnWXi4ph6NOdxNI1hYLOhNi-2FyrK1Pf-2Fd1iCvNDrD7HYilhm4vWCVXifNzT6wxikp718PT-2FcnV86An81in6q0TcyvZxG8gQm4lyhCI66x0SJlZBKkqGBCD09JORfzRm4-3D">OneLogin</a>, told <em>IT Pro</em> that ransomware is the one activity that has a high direct return on investment out of all the cyber crime activities. </p><p>“Taking the global economic environment and current market conditions into consideration cybercriminals will, of course, continue to focus on their efforts to this revenue-generating stream. Remember that your employees are your most valuable assets both from a security threat awareness perspective but to provide valuable insights into the pulse and culture of the organization so it's important to keep a close eye on the ground,” Muldoon said.</p><p>“The key message here is no one, industry or company, is exempt from the ransomware threat and it requires constant focus, assessment, and review to ensure you and your critical information assets remain safeguarded and protected against it."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Parler suffers data leak before being taken offline ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/marketing-comms/social-media/358294/parler-suffers-data-leak-before-being-taken-offline</link>
                                                                            <description>
                            <![CDATA[ Hackers could combine leaked data with phishing emails to exploit users ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tSeJ1bGrYP4oQWphuQtKf3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FKxvXPHGoaXjSxHB5MzbDi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 12 Jan 2021 15:58:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FKxvXPHGoaXjSxHB5MzbDi-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Parler and Twitter app logos on a screen]]></media:description>                                                            <media:text><![CDATA[Parler and Twitter app logos on a screen]]></media:text>
                                <media:title type="plain"><![CDATA[Parler and Twitter app logos on a screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FKxvXPHGoaXjSxHB5MzbDi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Parler, the right-wing <a href="https://www.itpro.com/technology/social-media" data-original-url="https://www.itpro.com/tags/social-media">social media</a> platform used in the recent insurrection at the Capitol, has been hit by a massive data-scrape campaign, resulting in 70TB of leaked data. </p><p>According to a <a href="https://blog.knowbe4.com/social-media-parler-in-troubling-times-new-opportunities-for-malicious-actors">blog post</a> by cyber security firm KnowBe4, hackers could use this leaked data, which included user profile data, admin rights data, videos, and live and deleted posts, to mount various nefarious campaigns aimed at Parler users.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358284/united-nations-reveals-potential-data-breach" data-original-url="/security/data-breaches/358284/united-nations-reveals-potential-data-breach">United Nations suffers potential data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358186/stolen-card-details-now-selling-for-225-higher-than-in-2018" data-original-url="/security/data-breaches/358186/stolen-card-details-now-selling-for-225-higher-than-in-2018">Stolen card details now selling for 225% higher than in 2018</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/358288/solarwinds-hackers-breached-systems-september-2019" data-original-url="/security/358288/solarwinds-hackers-breached-systems-september-2019">SolarWinds hackers first breached systems in September 2019</a></p></div></div><p>“We anticipate that bad actors will fill the gap by launching <a href="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack" data-original-url="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack">phishing</a> campaigns that offer users bogus web sites with fake, malicious Parler downloads or even malware-infected versions of Parler. They may also set up fake web sites and push malicious online advertising to do the same,” said Eric Howes, principal lab researcher at KnowBe4.</p><p>Before Parler went offline but after the website was no longer able to use phone or email verification, Twitter user <a href="https://twitter.com/donk_enby/status/1348281459031814146">@donk_enby</a> collected 70TB of posts, messages, and videos. This is around 99.9% of all content ever posted to the site.</p><p>The breach was possible because the “forgot password” link that would normally require verification was no longer working. Anyone could then override this to log in to accounts that weren’t theirs. Once in, they could log in to accounts with administrator access and create new accounts, also with administrator access. Hackers used these accounts to dump data from the website.</p><p>Howes added that Parler-themed <a href="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack" data-original-url="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack">phishing emails</a> could take at least two forms. First, spoofed Parler emails offering alternative download/install links. And second, fake right-wing/conservative emails denouncing Google and Apple’s actions and offering alternative download/install links.</p><p>“This massive haul of leaked data could allow malicious actors to individually target Parler users in spear phishing campaigns as well as all manner of online scams,” Howes warned.</p><p>Howes said his company had developed a handful of simulated phishing emails to be used by customers to test their staff. </p><p>“In addition to using these new templates to phish your users, it would also be a good idea to alert your employees and users to the danger that they could be encountering phishing emails as well as fake web sites and deceptive online advertising offering them alternative download sources for Parler that, in reality, will be pushing malware instead,” he said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ United Nations suffers potential data breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/358284/united-nations-reveals-potential-data-breach</link>
                                                                            <description>
                            <![CDATA[ Hackers could have breached the database long before the UN applied a patch ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4asumLLJc7f7PYKVRGBP17</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wxmFuGAysszb6GMiVhjCw-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 Jan 2021 16:15:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wxmFuGAysszb6GMiVhjCw-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The UN building with flags in front]]></media:description>                                                            <media:text><![CDATA[The UN building with flags in front]]></media:text>
                                <media:title type="plain"><![CDATA[The UN building with flags in front]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wxmFuGAysszb6GMiVhjCw-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have uncovered vulnerabilities in the United Nations Environmental Program (UNEP) computer systems that could have exposed 100,000 personal data records. </p><p>According to a <a href="https://johnjhacking.com/blog/unep-breach">report</a> by the ethical hacking company Sakura Samurai, which looked at the UN network’s strength, they obtained this data in less than 24 hours. By identifying an endpoint that exposed Git credentials, the researchers used the credentials to download Git repositories and identify user data and personally identifiable information (PII).</p><p>“In total, we identified over 100K+ private employee records. We also discovered multiple exposed .git directories on UN owned web servers [ilo.org], the .git contents could then be exfiltrated with various tools such as “git-dumper”,” said researchers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/354673/united-nations-hit-by-possible-state-sponsored-attack" data-original-url="/security/hacking/354673/united-nations-hit-by-possible-state-sponsored-attack">United Nations hit by possible state-sponsored attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/637519/plugging-public-sector-data-leaks" data-original-url="/637519/plugging-public-sector-data-leaks">Plugging public sector data leaks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/142494/everybody-suffers-data-leakage-study-finds" data-original-url="/142494/everybody-suffers-data-leakage-study-finds">Everybody suffers data leakage, study finds</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/633397/facebook-app-data-leak-could-hit-millions" data-original-url="/633397/facebook-app-data-leak-could-hit-millions">Facebook app data leak could hit 'millions'</a></p></div></div><p>Travel and employee data was among the findings. Records contained employee IDs, names, employee groups, travel justification, start and end dates, approval status, destination, and the length of stay. Researchers also found HR data, such as nationality, gender, and pay grade, on thousands of employees.</p><p>“In total, we found 7 additional credential-pairs which could have resulted in unauthorized access of multiple databases. We decided to stop and report this vulnerability once we were able to access PII that was exposed via Database backups that were in the private projects,” said researchers.</p><p>Javvad Malik, security awareness advocate at KnowBe4, told <em>IT Pro</em> it’s easy for organizations, especially global ones, to have data spread across various systems and platforms. </p><p>“Keeping track of all these disparate systems can be challenging enough and ensuring the right security settings are applied and that credentials are appropriately managed is key,” Malik said. “While many technologies and processes exist to help secure organizations to prevent these kinds of issues, it is essential that organizations cultivate a culture of security so that everyone is aware of the role they have to play in securing the organization as it's not something a security department can do on their own."</p><p>Martin Jartelius, CSO at Outpost24, told <em>IT Pro</em> the flaws we see in this case are all related to users configuring those servers, leaving files exposed and software misconfigured. </p><p>“Those are flaws in usage, not flaws in software. It is in parts further concerning as those systems were internet exposed, and in turn, held credentials for other systems,” he said.</p><p>“With access to some of the indicated information and the simplicity of the breach, attackers may well have access to this information. It is one of the basic controls any experienced analyst performs against a system they are auditing, yet it is still surprisingly often a rewarding path to take provided the attack surface is sufficiently large, such as a full organization."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Misconfigured Git servers lead to Nissan data leak ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/358261/misconfigured-git-servers-lead-to-nissan-data-leak</link>
                                                                            <description>
                            <![CDATA[ Leak stemmed from Nissan using of default “admin” password ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vMyhT8cAxNSX8SzvmxmKCE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/su3ZiZU7Byzie5sSGRfxuF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Jan 2021 17:22:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/su3ZiZU7Byzie5sSGRfxuF-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Nissan sign on a background of the sky]]></media:description>                                                            <media:text><![CDATA[Nissan sign on a background of the sky]]></media:text>
                                <media:title type="plain"><![CDATA[Nissan sign on a background of the sky]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/su3ZiZU7Byzie5sSGRfxuF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Swiss-based software engineer and <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> researcher Tillie Kottmann has discovered the source code for Nissan North America’s internal mobile apps and tools on a misconfigured Git server.</p><p>Kottmann said in a <a href="https://twitter.com/antiproprietary/status/1346238588476915713">tweet</a> he’d found a “complete dump” of all Git repositories from Nissan NA. The dump included sources for the Nissan NA mobile apps, some parts of the ASIST diagnostics tool, and the dealer business systems and portal.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/614860/nissan-europe-faces-up-to-data-transfer-challenge" data-original-url="/614860/nissan-europe-faces-up-to-data-transfer-challenge">Nissan Europe faces up to data transfer challenge</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/637816/nissan-signs-up-for-microsoft-dynamics-crm-cloud" data-original-url="/637816/nissan-signs-up-for-microsoft-dynamics-crm-cloud">Nissan signs up for Microsoft Dynamics CRM cloud</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/25867/anonymous-takes-down-nissan-in-dolphin-culling-protest" data-original-url="/security/25867/anonymous-takes-down-nissan-in-dolphin-culling-protest">Anonymous takes down Nissan in dolphin culling protest</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/356768/nissan-to-migrate-simulation-workloads-to-oracle" data-original-url="/cloud/cloud-computing/356768/nissan-to-migrate-simulation-workloads-to-oracle">Nissan to migrate simulation workloads to Oracle</a></p></div></div><p>The researcher also found details on Nissan’s internal core mobile library, NCAR/ICAR services, client acquisition and retention tools, sale/market research tools and data, various marketing tools, and vehicle logistics portal.</p><p>The leak stemmed from a Git server that was left visible online with its default username and password combo of “admin.” Nissan is probing the leak, and the Git server was taken offline after the data started disseminating on Monday via Telegram channels and hacking forums.</p><p>The security researchers who uncovered the misconfigurations received a tip about Nissan's Git server after they found a similarly misconfigured GitLab server in May 2019.</p><p>Martin Jartelius, CSO at Outpost24, told ITPro that it’s a basic security control to change the vendor default passwords when deploying a system. </p><p>“From the nature of the content, this should be a production system and reviewed prior to having the source code uploaded. This basic control forms part of most organizations ISMS standards, i.e., ISO27001 policies and regulations internally. As Nissan Japan had their 9001 certificate revoked in 2017 by authorities it is not the first time the successful implementation of good plans and strategies has not reached all the way to execution in the large organization,” Jartelius said.</p><p>Mark Bower, SVP at comforte AG, told ITPro that this leak was a "classic example of the security being only as good as the weakest link".</p><p>"Most likely, in this case, [this is] down to both human error and lack of process for risk scanning of critical infrastructure for vulnerable credentials and effective data security,” Bower said. "The recent Solarwinds situation should have prompted organisations across the industry to revisit their supply chain security, data security and authentication as a matter of priority – including any internet-facing or cloud components."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers breach T-Mobile customer records ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/358221/hackers-breach-t-mobile-customer-records</link>
                                                                            <description>
                            <![CDATA[ The breach, which affects around 200,000 customers, contains data types the FCC considers "highly sensitive" ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">47iwP2j7YcVGnkxVKG36g7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/V5A6EmYNxCzZRGWtWLi2XW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Jan 2021 17:12:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/V5A6EmYNxCzZRGWtWLi2XW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Customers line up outside a T-Mobile store]]></media:description>                                                            <media:text><![CDATA[Customers line up outside a T-Mobile store]]></media:text>
                                <media:title type="plain"><![CDATA[Customers line up outside a T-Mobile store]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/V5A6EmYNxCzZRGWtWLi2XW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>T-Mobile has suffered a data breach affecting information government agencies consider highly sensitive. The breach is the company's fourth since 2018.</p><p>The breach affected about 200,000 customers, according to reports, and T-Mobile <a href="https://www.t-mobile.com/responsibility/consumer-info/security-incident">said</a> the breach impacted a range of information, including customer phone numbers, the number of lines subscribed on their account, and possibly call-related information collected as part of their cellular service.</p><p>It didn't affect personally identifiable information, such as names, addresses, email addresses, financial data, social security numbers, or PINs.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/613798/what-to-do-in-case-of-a-data-breach" data-original-url="/613798/what-to-do-in-case-of-a-data-breach">What to do in case of a data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357555/amazon-data-breach-sacks-employee" data-original-url="/security/357555/amazon-data-breach-sacks-employee">Amazon sacks employee over data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/357314/blackbaud-admits-bank-data-lost-during-may-breach" data-original-url="/security/data-breaches/357314/blackbaud-admits-bank-data-lost-during-may-breach">Blackbaud admits bank account details were lost in May data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357556/vastaamo-data-breach-ransom-patients" data-original-url="/security/357556/vastaamo-data-breach-ransom-patients">Hackers demand ransom from therapy patients after clinic data breach</a></p></div></div><p>The information affected still represents a serious risk. The leaked data is known as customer proprietary network information (CPNI), and the <a href="https://www.itpro.com/policy-legislation/34526/what-is-the-federal-communications-commission-fcc" data-original-url="https://www.itpro.com/policy-legislation/34526/what-is-the-federal-communications-commission-fcc">Federal Communications Commission (FCC)</a> <a href="https://www.fcc.gov/general/customer-privacy">considers it</a> "some of the most sensitive information that carriers and providers have about their customers." CPNI includes the phone numbers the customer called, when they made the calls, and how long the calls were. This is otherwise known as call metadata, and intelligence agencies have long <a href="https://www.itpro.com/security/cyber-security/355044/what-is-the-usa-patriot-act" data-original-url="https://www.itpro.com/security/cyber-security/355044/what-is-the-usa-patriot-act">sought it</a> for surveillance purposes.</p><p>"Our Cybersecurity team recently discovered and shut down malicious, unauthorized access to some information related to your T-Mobile account," T-Mobile said in the statement on its website.</p><p>"We immediately started an investigation, with assistance from leading cybersecurity forensics experts, to determine what happened and what information was involved. We also immediately reported this matter to federal law enforcement and are now in the process of notifying impacted customers."</p><p>This isn't the first data breach T-Mobile has suffered. In 2018, the company <a href="https://www.t-mobile.com/customers/6305378821">warned users</a> someone had unauthorized access to information, including their phone number, email address, account number, and date of birth. </p><p>In November 2019, T-Mobile <a href="https://www.itpro.com/security/data-breaches/354192/t-mobile-data-breach-affects-more-than-a-million-users" data-original-url="https://www.itpro.com/security/data-breaches/354192/t-mobile-data-breach-affects-more-than-a-million-users">admitted</a> a systems breach had affected over 1 million customers. That heist targeted information related to prepaid wireless accounts and included names, addresses, phone numbers, and other CPNI data. In March 2020, the company also <a href="https://www.t-mobile.com/customers/6305378821">notified customers</a> that the breach might have compromised their personal and financial information.</p><p>In April 2020, T-Mobile US completed its $26 billion merger with US carrier Sprint Corporation to build a nationwide 5G network.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How much will a data breach really damage your organisation’s reputation? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations</link>
                                                                            <description>
                            <![CDATA[ It’s not just fines that can hurt in the wake of a data breach – your reputation can take a hit, too ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oT2hu6ZvYq9xpWHb7PnaTg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aYr9nnLneXPbLj2m49JiYk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Nov 2020 20:49:52 +0000</pubDate>                                                                                                                                <updated>Fri, 05 Feb 2021 16:15:52 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aYr9nnLneXPbLj2m49JiYk-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Security privacy concept]]></media:description>                                                            <media:text><![CDATA[A glowing blue padlock disintegrates against a black background]]></media:text>
                                <media:title type="plain"><![CDATA[A glowing blue padlock disintegrates against a black background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aYr9nnLneXPbLj2m49JiYk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Most conversations surrounding the cost of a data breach are around fines or compensation.</p><p>Financial costs are definitely important as we see an onslaught of regulatory legislation around the world. Many countries have followed in the footsteps of the EU’s implementation of <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a>, like California’s CCPA and Brazil’s LGPD.</p><p>Since 2021 is likely to see increased safeguards on consumer privacy and, in the past year, employees have had access to more data at work, the <a href="https://www.infosecurity-magazine.com/news/volume-size-data-breaches-rise">number and value</a> of data breach fines are also expected to increase. </p><p>However, an important aspect of data breach cost that is often overlooked is reputational damage. </p><p>A good reputation is usually hard to build, but once you’ve gained it, it can sustain a business through tougher times like what we’re currently going through. Back in 1997, Apple was on the verge of bankruptcy and playing second fiddle to Microsoft, but in 2018 it became the first publicly traded American company worth more than a trillion dollars. </p><p>Today’s consumers often put a lot of stock in reputation and are loyal to brands that they’ve had good experiences with, so it can be nearly impossible to bounce back from any damage to your rep. </p><p>The reputational repercussions of a data breach can last much longer than the short-term fine, causing damage to your bottom line in the long run when customers don’t trust you enough to do business with you, and potentially dealing your organisation a blow from which it will never recover. </p><h3 class="article-body__section" id="section-in-the-media-glare"><span>In the media glare</span></h3><p>In the immediate wake of a data breach, there’s a lot to take in. What was lost? Was it an attack or an accident? Has the breach been closed?</p><p>If you’re a household name, such as <a href="https://www.itpro.com/tag/talktalk" data-original-url="https://www.itpro.com/search/talktalk">TalkTalk</a>, Equifax or <a href="https://www.itpro.com/tag/yahoo" data-original-url="https://www.itpro.com/search/yahoo">Yahoo</a> – or involved in something salacious like <a href="https://www.itpro.com/security/25171/ashley-madison-data-breach-leads-to-112m-settlement" data-original-url="https://www.itpro.com/security/25171/ashley-madison-data-breach-leads-to-112m-settlement">Ashley Madison</a> – you will likely find yourself in the unenviable position of doing these initial investigations in the full glare of the media spotlight.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach" data-original-url="/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach">Ten ways to protect your company from the next big data breach</a></p></div></div><p>For such businesses, especially nowadays, the reputational impact will be immediate. Depending on the size of the data breach and how it happened, big businesses are likely to find themselves on the front pages of the papers and in the broadcast headlines too. In this kind of situation, the axiom that “all publicity is good publicity” falls very flat.</p><p>Even if your own organisation’s data breach doesn’t warrant a spot on the evening news, that doesn’t mean you will have escaped public condemnation: Disgruntled customers – or now former customers – will be disavowing you on social media for having shown little care for their personal information, potentially for years to come.</p><p>It’s not just the act of losing control over customers’ personal data that can harm a business’ reputation, either. Speaking as a guest on the <em>IT Pro Podcast</em>, <a href="https://www.itpro.com/security/data-breaches/357063/the-it-pro-podcast-the-myth-of-reputational-damage" data-original-url="https://www.itpro.com/security/data-breaches/357063/the-it-pro-podcast-the-myth-of-reputational-damage">Dr Rois Ni Thuama, head of cyber governance at Red Sift</a>, pointed to the fallout of the <a href="https://www.itpro.com/security/23593/sony-pictures-hack-hackers-used-apple-ids-of-employees-to-gain-access-1" data-original-url="https://www.itpro.com/security/23593/sony-pictures-hack-hackers-used-apple-ids-of-employees-to-gain-access-1">2014 Sony Pictures hack</a> as one example.</p><p>“You had large dumps of Sony data … you’ll remember there was a lot of stuff on actor compensation, there [were] embarrassing email exchanges. One of the key players (co-chairperson, Amy Pascal) sent something that was racially insensitive,” said Ni Thuama.</p><p>“People lost their jobs… their careers and their professional lives were damaged, particularly the woman (Pascal) who sent the charged emails, and then there was definitely a loss of reputation over the actors’ compensation,” she added.</p><h3 class="article-body__section" id="section-the-importance-of-accountability"><span>The importance of accountability</span></h3><p>Away from the data breach itself, how the organisation acts once the incident can have a major impact on the depth and permanence of the damage an organisation faces.</p><p>Gabriel Friedlander, the founder of security awareness training firm Wizer, tells <em>IT Pro</em>: “Yahoo, <a href="https://www.itpro.com/data-breaches/30010/uber-hack-a-lesson-in-how-not-to-handle-a-data-breach" data-original-url="https://www.itpro.com/data-breaches/30010/uber-hack-a-lesson-in-how-not-to-handle-a-data-breach">Uber</a> and Anthem are three data breaches that stand out in the US because of the lack of accountability, lack of transparency, and length of time between a breach happening and the truth coming out.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/358417/whatsapp-could-face-eu50-million" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/358417/whatsapp-could-face-eu50-million">WhatsApp could face €50 million GDPR fine</a></p></div></div><p>“Companies also invest a lot in ‘values’, so when companies lie or try to hide a breach, it ruins the trust and goodwill that has been built up over years with many of their customers, some of whom will quickly look to the competition for a more safe and secure alternative,” he adds.</p><p>Simon Smith, a specialist in cybercrime and computer forensics, feels similarly.</p><p>“Trust is the driver for any business success. If trust is lost then some businesses may never recover,” Smith tells <em>IT Pro</em>.</p><p>“It can depend a lot on the nature of the breach and how the company reaches and remedies the breach. Dishonesty or non-disclosure can cause a great loss of trust that could easily destroy any business after only one incident. Customers, the authorities and society will be concerned about a company's security and ability to protect data if systems are not in place to handle and mitigate the problem.”</p><h3 class="article-body__section" id="section-small-business-big-problems"><span>Small business, big problems</span></h3><p>Sadly, when it comes to reputational damage, <a href="https://www.itpro.com/security/357783/ransomware-remains-the-top-cyber-security-risk-for-smbs" data-original-url="https://www.itpro.com/security/357783/ransomware-remains-the-top-cyber-security-risk-for-smbs">SMBs often fare worse than larger ones</a>.</p><p>“We see a 60% failure rate among the SMB market after a company discloses a breach within 6-12 months,” says Friedlander. “This partly due to confidence issues, partly due to recovery challenges, etc. </p><p>“The SMB market is crowded. Think about a restaurant, if it gets breached people have many options for going to eat somewhere else, and if your accountant got breached, you will probably leave and find someone else.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358454/citrix-employees-win-2" data-original-url="/security/data-breaches/358454/citrix-employees-win-2">Citrix employees win $2.3m settlement over 2019 data breach</a></p></div></div><p>Bigger businesses, on the other hand, may be harder to move away from. It’s also likely they have greater resources to put towards crisis management, as well as to pay any regulatory fines and settle lawsuits.</p><p>Smith adds that SMBs can suffer worse damage to their reputation as they may not realise their responsibilities or act appropriately.</p><p>“Small businesses make up the majority of all business, but as many are not publicly listed, they feel they do not have to disclose every event. This in itself causes a major problem as it is now considered a regulatory issue across the world where businesses of all sizes can be fined for breaching the obligation to secure personal records,” he says.</p><p>“Any size business is equally at risk because somewhere along the way, they got the attitude that ‘it can’t happen to us’, or, ‘it can’t happen to us again’. Without proper process, project, policy and infrastructure governance in place to protect their systems, it is always going to be a ticking time bomb,” he adds.</p><p>If you survive the initial damage, the lasting impact may not be quite as catastrophic as one would imagine, though – as they say, time heals all wounds.</p><p>“Long term, there is an argument that there’s little consequence as humans have short memories,” says Friedlander. “There’s a plethora of breaches and companies get lost in the mix.”</p><p>Nevertheless, while there are methods to mitigate reputational damage in the wake of a data breach – including the passage of time – it pays to put as much effort into preventing one happening in the first place. Not only do you reduce the risk of harm, but if a breach does happen the reaction will likely be more sympathetic if it can be shown it happened despite you having ample defences and procedures in place.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers steal 8.3 million user records from 123RF ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/357770/hackers-steal-83m-user-records-from-123rf</link>
                                                                            <description>
                            <![CDATA[ Stolen data contained users’ names, addresses, hashed passwords ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eKmAjje4gmHATPwwJZLthR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fMbMro3SjAzTb5vKxrzNfc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Nov 2020 18:34:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fMbMro3SjAzTb5vKxrzNfc-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data Breach overlaying a circuitboard]]></media:description>                                                            <media:text><![CDATA[Data Breach overlaying a circuitboard]]></media:text>
                                <media:title type="plain"><![CDATA[Data Breach overlaying a circuitboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fMbMro3SjAzTb5vKxrzNfc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers have stolen 8.3 million user data records from royalty-free stock photo website 123RF. The cyber criminals breached a server belonging to 123RF’s parent company, Inmagine Group, to access the data.</p><p>According to a <a href="https://www.bleepingcomputer.com/news/security/popular-stock-photo-service-hit-by-data-breach-83m-records-for-sale">report from <em>Bleeping Computer</em></a>, a known data breach broker began selling the data containing user information last weekend. The data reportedly includes 123RF members' full names, email addresses, MD5 hashed passwords, company names, phone numbers, addresses, PayPal emails and IP addresses. However, it’s not thought to contain financial information, such as credit card numbers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/162240/demand-for-tougher-data-breach-legislation" data-original-url="/162240/demand-for-tougher-data-breach-legislation">Demand for tougher data breach legislation</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/140448/revenue-head-quits-after-massive-data-breach" data-original-url="/140448/revenue-head-quits-after-massive-data-breach">Revenue head quits after massive data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/146769/data-breaches-hit-driver-agency-building-society" data-original-url="/146769/data-breaches-hit-driver-agency-building-society">Data breaches hit driver agency, building society</a></p></div></div><p>Inmagine Group said: "We are actively notifying the necessary authorities and 123RF.com members to work with them to remedy the situation. We are also tightening the security policies to include tighter passwords and IP detection to combat suspicious log-ins."</p><p>"Our security infrastructure is always under a constant state of security testing, penetration, and development, especially in the past year. We wish to reiterate that we take the privacy and data of our customers seriously and have at all times been vigilant with the handling of our customer’s data."</p><p>Chris Hauk, consumer privacy champion at Pixel Privacy, told <em>IT Pro</em> that the state of online <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> makes New York City in the early 1970s look safe by comparison. He added that while passwords were encrypted, hackers could use online <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">password cracking</a> tools to retrieve credentials for many accounts. </p><p>“This means that 123RF members that reused that same password on another site(s) are in danger of having those accounts accessed. So, this brings an added bit of urgency to the usual ‘change your password and check to make sure none of your online accounts use the same password’ advice,” Hauk said.</p><p>Niamh Muldoon, senior director of trust and security at OneLogin, told <em>IT Pro</em> that it’s unclear how this breach occurred in the first place; however, what is known is the information is out there, and cybercriminals are likely already taking advantage of it.</p><p>“The MD5 hashed passwords are easily hacked, for instance, so they will likely carry out credential stuffing attacks to access other user accounts. Affected individuals would do well to change all passwords immediately, particularly if the same password was used for their PayPal account. A password manager would be useful as well to ensure that passwords are no longer reused across services and to help with crafting long and complex passwords,” Muldoon said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hotel booking firm exposes data on "millions" of guests ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/357693/prestige-software-data-breach-millions-hotel-guests-exposed</link>
                                                                            <description>
                            <![CDATA[ Reservation platform used byHotels.com, Booking.com and Expedialeft sensitive data exposed on a misconfiguredAWS S3 bucket ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m16QpoLUoLkstQHWUnjwS2</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eV4qqSCkmiRENYYBbcyNFK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Nov 2020 09:49:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Carly Page ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/haaytLZQLzJxCzMHFEeyiZ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eV4qqSCkmiRENYYBbcyNFK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The homepage of the official website for Hotels.com, a site for booking hotel rooms online,]]></media:description>                                                            <media:text><![CDATA[The homepage of the official website for Hotels.com, a site for booking hotel rooms online,]]></media:text>
                                <media:title type="plain"><![CDATA[The homepage of the official website for Hotels.com, a site for booking hotel rooms online,]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eV4qqSCkmiRENYYBbcyNFK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Prestige Software, a hotel reservation platform used by Hotels.com, Booking.com, and Expedia, left data belonging to “millions” of guests exposed on a misconfigured Amazon Web Services (AWS) S3 bucket.</p><p>According to <a href="https://www.websiteplanet.com/blog/prestige-soft-breach-report" target="_blank"><em>Website Planet</em></a>, the highly-sensitive information dates back as far back as 2013. It reports that the Spanish company, which sells a channel management platform called Cloud Hospitality that allows hotels automate their availability on online booking websites, was storing years of hotel guest and travel agent data without any protection in place.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/357600/marriott-international-fined" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/357600/marriott-international-fined">Marriott International fined £18.4m for 2014 data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/632452/top-10-most-embarrassing-data-breaches" data-original-url="/632452/top-10-most-embarrassing-data-breaches">Top 10 most embarrassing data breaches</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/357407/uk-gov-data-breaches-2019-2020" data-original-url="/security/data-breaches/357407/uk-gov-data-breaches-2019-2020">FOI requests reveal "thousands" of government data breaches</a></p></div></div><p>As a result, Prestige Software exposed over 10 million individual log files in total. Each of these records exposed sensitive and personally identifiable information (PII), including names, email addresses, national ID numbers, phone numbers, reservation information, and credit card details, including CVV and expiration date.</p><p><em>Website Planet</em> reports that the S3 bucket contained over 180,000 records from August 2020 alone, despite global hotel bookings being at an all-time low for this period.</p><p>However, it's difficult to say how many people were affected due to the amount of data exposed. The report notes the actual number of people exposed could be much higher than the number of reservations logged as many of the data logs contained PII data for numerous people on one booking.</p><p>While the scope of the data breach remains unknown, it could lead to all too common risks with hotel data exposures, such as credit card fraud, <a href="https://www.itpro.com/605226/analysis-the-biggest-identity-fraud-in-history" target="_blank" data-original-url="https://www.itpro.com/605226/analysis-the-biggest-identity-fraud-in-history">identity theft</a>, and <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing scams</a>. Perpetrators could even use the data to steal someone else's reservation.</p><p><em>Website Planet</em> said the hole was closed a day after telling AWS about the exposure, adding that Prestige Software confirmed it was the owner of the data and the party responsible for the leak.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HuVkXKYxS9nVFkEwoBk7MR" name="HuVkXKYxS9nVFkEwoBk7MR.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/HuVkXKYxS9nVFkEwoBk7MR.png" mos="https://cdn.mos.cms.futurecdn.net/HuVkXKYxS9nVFkEwoBk7MR.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Don’t just educate: Create cyber-safe behaviour</strong></p><p class="fancy-box__body-text">Designing effective security awareness and training programmes</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/training/356984/dont-just-educate-create-cybersafe-behaviour" data-original-url="/business-strategy/training/356984/dont-just-educate-create-cybersafe-behaviour">FREE DOWNLOAD</a></p></div></div><p>Due to the fact that Prestige Software is based in Spain, with offices in Madrid and Barcelona, the company could face GDPR action as a result of the breach. If it failed to follow the strict rules set out within the legislation, which includes a requirement to report the breach within 72 hours, the company could be fined €20 million (about £18 million) or 4% of annual global turnover.</p><p>Earlier this month, the Information Commissioner's Office (ICO) <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/357600/marriott-international-fined" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/357600/marriott-international-fined">hit Marriott International with an £18.4 million fine</a> for a data breach that affected 339 million guest records worldwide.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers demand ransom from therapy patients after clinic data breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/357556/vastaamo-data-breach-ransom-patients</link>
                                                                            <description>
                            <![CDATA[ Vastaamo CEO Ville Tapio was reportedly fired for obscuring information about the incident for more than two years ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3KABxZ2wwdp6NYoR9DskxV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WKmpDZhNi7Vj58R7vQSpNd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 27 Oct 2020 11:27:34 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WKmpDZhNi7Vj58R7vQSpNd-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Distressed girl talks to shrink with notepad ]]></media:description>                                                            <media:text><![CDATA[Distressed girl talks to shrink with notepad ]]></media:text>
                                <media:title type="plain"><![CDATA[Distressed girl talks to shrink with notepad ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WKmpDZhNi7Vj58R7vQSpNd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A hacker is trying to blackmail thousands of Finish patients after gaining access to their personal information via a psychotherapy company. </p><p>Police have said that an unknown party started demanding ransom from more than 40,000 patients whose data was stolen from the Vastaamo psychotherapy centre, according to <a href="https://www.hs.fi/kotimaa/art-2000006699117.html" target="_blank">local media reports</a>. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/632452/top-10-most-embarrassing-data-breaches" data-original-url="/632452/top-10-most-embarrassing-data-breaches">Top 10 most embarrassing data breaches</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-breaches/30010/uber-hack-a-lesson-in-how-not-to-handle-a-data-breach" data-original-url="/data-breaches/30010/uber-hack-a-lesson-in-how-not-to-handle-a-data-breach">Uber hack: A lesson in how not to handle a data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="/security/28084/what-is-ransomware">What is ransomware?</a></p></div></div><p>The data was taken during a cyber attack in November 2018, and potentially again in March 2019, the Helskinki-based centre said in a statement.</p><p>The company is cooperating with the police, but it's reported that some 300 records have already been published on the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web" target="_blank" data-original-url="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a>. It is also being <a href="https://yle.fi/uutiset/osasto/news/vastaamo_board_fires_ceo_says_he_kept_data_breach_secret_for_year_and_a_half/11614603" target="_blank">reported</a> that the firm's CEO, Ville Tapio, has been fired for obscuring information about the data breach for more than two years. </p><p>The hackers originally sought to extort a <a href="https://www.itpro.com/security/28084/what-is-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware#:~:text=Ransomware%20is%20a%20type%20of,which%20it%20can%20be%20spread.">ransom</a> from the centre's management but changed tactics over the weekend to elicit payments from individuals that had used the service. </p><p>Various patients have spoken to media outlets to say that the hackers have contacted them and threatened to leak mental health records onto the internet unless they provide payment in Bitcoin. Some of the people whose data has been stolen are also underage. </p><p>One patient told the <a href="https://www.bbc.co.uk/news/technology-54692120" target="_blank"><em>BBC</em></a> that the hacker said Vastaamo had refused to pay 40 <a href="https://www.itpro.com/strategy/28296/what-is-bitcoin" target="_blank" data-original-url="https://www.itpro.com/strategy/28296/what-is-bitcoin">Bitcoin</a> (£403,000) and he would now have to pay €200 worth in order to stop his information being released - this included session notes from when he was a teenager. </p><p>"I'm anxious about the fact that the attackers are in possession of my notes and conversations from those psychiatrist sessions," he said. "Those notes contain things I'm not ready to share with the world. And having someone threaten me with said notes certainly makes me extremely uncomfortable."</p><p>The patient's notes had been taken in a physical notebook and he/she wasn't told these would be uploaded to a server. The country's prime minister Sanna Marin <a href="https://twitter.com/MarinSanna/status/1320086110681387008?s=20" target="_blank">tweeted</a> that the Finish government was looking into ways to support the victims of what he called a "shocking" hack. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Amazon sacks employee over data breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/357555/amazon-data-breach-sacks-employee</link>
                                                                            <description>
                            <![CDATA[ The worker leaked customer email addresses to an unidentified third-party ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4sv4sdpCwsKQYjigefW7rS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KKqfgc7BTLfrN6weuwha3c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 27 Oct 2020 11:23:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KKqfgc7BTLfrN6weuwha3c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A concept image of a hacker behind a stream of binary]]></media:description>                                                            <media:text><![CDATA[A concept image of a hacker behind a stream of binary]]></media:text>
                                <media:title type="plain"><![CDATA[A concept image of a hacker behind a stream of binary]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KKqfgc7BTLfrN6weuwha3c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Amazon has contacted a portion of its customers to inform them an employee has been discharged from their role after leaking their personal information to an unidentified third-party.</p><p>The individual who lost their job for leaking customer email addresses has been referred to the police, <a href="https://www.vice.com/en/article/dy8zwz/amazon-fired-employee-leaking-customer-emails">according to <em>Motherboard</em></a>, with criminal investigations now ongoing. The incident highlights the continued threat of insider security risks. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/357545/insider-data-breaches-third-2021" data-original-url="/security/data-breaches/357545/insider-data-breaches-third-2021">Insider data breaches set to increase due to remote work shift</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/609902/how-to-prevent-insiders-destroying-your-network" data-original-url="/609902/how-to-prevent-insiders-destroying-your-network">How to prevent insiders destroying your network</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/357314/blackbaud-admits-bank-data-lost-during-may-breach" data-original-url="/security/data-breaches/357314/blackbaud-admits-bank-data-lost-during-may-breach">Blackbaud admits bank account details were lost in May data breach</a></p></div></div><p>No matter how many cyber security precautions an organisation takes, it’s difficult to guard against <a href="https://www.itpro.com/security/data-breaches/357545/insider-data-breaches-third-2021" target="_blank" data-original-url="https://www.itpro.com/security/data-breaches/357545/insider-data-breaches-third-2021">either human error or malicious intent</a>, as has been the case with the leakage of Amazon customers’ email addresses.</p><p>"We are writing to let you know that your e-mail address was disclosed by an Amazon employee to a third-party in violation of our policies,” the company wrote in a message to customers affected. </p><p>“As a result, we have fired the employee, referred them to law enforcement, and are supporting law enforcement criminal prosecution.”</p><p>There are few details as to how many customers were affected, or the identity of the third-party to which the customer email addresses were leaked. The news circulated online over the weekend after a number of Twitter users posted <a href="https://twitter.com/zainjaffer/status/1319799750900785157?s=20">copies of the message they received from Amazon</a>.</p><p>“The fact that a number of Tweets that have appeared over the last few days from Amazon customers stating that they have been the victim of a data breach will rightfully be a worry to consumers," said Jo O’Reilly, digital privacy expert at ProPrivacy.</p><p>“Finding out that an Amazon employee has been passing customer emails to a third party is particularly concerning, especially as Amazon appears to have been very vague about the details.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="vZwDresbVrqLoLLvDPvMg3" name="vZwDresbVrqLoLLvDPvMg3.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/vZwDresbVrqLoLLvDPvMg3.png" mos="https://cdn.mos.cms.futurecdn.net/vZwDresbVrqLoLLvDPvMg3.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The State of Email Security 2020</strong></p><p class="fancy-box__body-text">Email security insights at your email perimeter, inside your organisation, and beyond</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/356964/the-state-of-email-security-2020" data-original-url="/security/cyber-security/356964/the-state-of-email-security-2020">FREE DOWNLOAD</a></p></div></div><p>“The online retail giant has confirmed that they are working directly with the authorities and that the employee in question has been fired however more transparency with the consumer impacted and what this means for their online privacy is now needed. It's entirely possible that they will now find themselves falling victim to phishing attacks, to prevent this Amazon need to be upfront about exactly who these emails have been shared with.”</p><p>This incident bears striking similarity to one in January 2020, in which several Amazon employees were fired after sharing customer email addresses and phone numbers with a third-party.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fitness Depot notifies customers of data breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/355962/fitness-depot-notifies-customers-of-data-breach</link>
                                                                            <description>
                            <![CDATA[ The fitness retailer has said its ISP was to blame for a breach of its online store ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5EWjnSB9x3ehsj5XsCKuSA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wyRiG6qUGMqWvRX8Sn3viS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Jun 2020 14:30:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sarah Brennan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wyRiG6qUGMqWvRX8Sn3viS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person types on laptop in the dark]]></media:description>                                                            <media:text><![CDATA[Person types on laptop in the dark]]></media:text>
                                <media:title type="plain"><![CDATA[Person types on laptop in the dark]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wyRiG6qUGMqWvRX8Sn3viS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Fitness Depot notified its customers that their personal and financial information may have been stolen as part of an attack impacting the company's e-commerce platform.</p><p>The Canadian retailer was informed of the data breach on May 20, and recently sent a <a href="http://www.documentcloud.org/documents/6937614-Fitness-Depot-Notice-of-Data-Breach.html">breach notification letter</a> to all potentially impacted customers.</p><p>Per Fitness Depot’s letter, attackers compromised the company’s online store and gained access to customers’ personal and financial information. Information accessed by the attackers may have included customers' names, addresses, contact information and credit card numbers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/608334/lessons-to-learn-from-a-year-of-data-breaches" data-original-url="/608334/lessons-to-learn-from-a-year-of-data-breaches">Lessons to learn from a year of data breaches</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/632452/top-10-most-embarrassing-data-breaches" data-original-url="/632452/top-10-most-embarrassing-data-breaches">Top 10 most embarrassing data breaches</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/140448/revenue-head-quits-after-massive-data-breach" data-original-url="/140448/revenue-head-quits-after-massive-data-breach">Revenue head quits after massive data breach</a></p></div></div><p>Based on the breach notification letter, all signs point to Fitness Depot having suffered from a <a href="https://www.itpro.com/exploits/34009/thousands-of-sites-fall-to-magecart-spray-and-pray-attack" data-original-url="https://www.itpro.com/exploits/34009/thousands-of-sites-fall-to-magecart-spray-and-pray-attack">Magecart attack</a>. In these attacks, Magecart groups hack an e-commerce store’s checkout page and inject malicious JavaScript-based scripts that steal customer information entered into online payment forms. </p><p>Though Fitness Depot discovered the breach on May 20, 2020, it dates as far back as Feb. 18, 2020. While customers who placed orders for home delivery were impacted between Feb. 18 and April 27, any customer who ordered products for home delivery or in-store pick-up would have been affected between April 28 and May 22.</p><p>"Once our customers where (sic) redirected to this form the customer information was copied without the authorization or knowledge of Fitness Depot," the company explained. "This is how the personal information was captured and stolen."</p><p>While Fitness Depot has stated "personal information was captured and stolen" during the breach, the company also shared it "has no knowledge that any of our customer information was compromised in any manner." Regardless, Fitness Depot has advised customers to protect themselves against <a href="https://www.itpro.com/marketing-comms/digital-marketing/355765/equifax-introduces-the-response-digital-solution-suite" data-original-url="https://www.itpro.com/marketing-comms/digital-marketing/355765/equifax-introduces-the-response-digital-solution-suite">identity fraud</a> by monitoring their credit reports and reviewing account statements regularly.</p><p>Fitness Depot blames its internet service provider for the data breach, claiming it "neglected to activate the anti-virus software on our account." It’s unclear what Fitness Depot is referring to since it’s not typically an ISP’s job to equip its customers' e-commerce platforms with anti-virus software.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Printing company exposes 343GB of sensitive military data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/355056/vpnmentors-web-mapping-project-finds-more-exposed-military-files-via</link>
                                                                            <description>
                            <![CDATA[ The leak is the latest in a series of data blunders discovered by vpnMentor's web-mapping project ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4yX8XeEPNcY9LpTgh6uHpj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6xwTpE9mkWmaQEpQtq4fUR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Mar 2020 11:57:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6xwTpE9mkWmaQEpQtq4fUR-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6xwTpE9mkWmaQEpQtq4fUR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK Printing company Doxzoo inadvertently exposed 343GB of data through a misconfigured Amazon Web Services (AWS) S3 bucket, including sensitive information said to relate to branches of the UK and US military.</p><p>Potentially more than 100,000 users were affected by the data leak, with approximately 270,000 records exposed including personal information and payment information, as well as order details, passport information, and the contents of printing orders.</p><p>Among the exposed data was the copyrighted and sensitive work of Doxzoo clients, who spanned from military personnel to screenwriters. <a href="https://www.vpnmentor.com/blog/report-doxzoo-leak" target="_blank">Researchers with vpnMentor</a>, led by Noam Rotem and Ran Locar, found a wide range of information including university course material, screenplays, and internal military documents, some of which contained classified information.</p><p>“The items contained this leak often hold private and/or confidential information within,” said vpnMentor’s research team. </p><p>“The promise of secure facilities and systems are key selling points for clients such as the military, and the breach of that guarantee is not only a failure in service, but also potentially holds a security risk along with it.”</p><p>The security firm has been finding pockets of exposed information for many months as part of a wider web-mapping project, and have recently detailed finding several alarming troves of exposed data.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/exploits/34009/thousands-of-sites-fall-to-magecart-spray-and-pray-attack" data-original-url="/exploits/34009/thousands-of-sites-fall-to-magecart-spray-and-pray-attack">Thousands of sites fall to Magecart 'spray and pray' attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/amazon-web-services-aws/354261/aws-plugs-leaky-s3-buckets-with-cloudknox-integration" data-original-url="/cloud/amazon-web-services-aws/354261/aws-plugs-leaky-s3-buckets-with-cloudknox-integration">AWS plugs leaky S3 buckets with CloudKnox integration</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/354532/huge-data-leak-exposes-british-consultancy-firms-and-thousands-of" data-original-url="/security/data-breaches/354532/huge-data-leak-exposes-british-consultancy-firms-and-thousands-of">‘Huge’ data leak exposes British consultancy firms and thousands of consultants</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-breaches/34347/monstercom-job-seeker-data-exposed-in-third-party-leak" data-original-url="/data-breaches/34347/monstercom-job-seeker-data-exposed-in-third-party-leak">Monster.com job seeker data exposed in third-party leak</a></p></div></div><p>These findings include a database of <a href="https://www.itpro.com/security/cyber-security/354246/millions-of-text-messages-leaked-through-exposed-truedialog-server" data-original-url="https://www.itpro.com/security/cyber-security/354246/millions-of-text-messages-leaked-through-exposed-truedialog-server">604GB of text messages run by US-based communications firm TrueDialog</a>, as well as sensitive information from <a href="https://www.itpro.com/security/data-breaches/354532/huge-data-leak-exposes-british-consultancy-firms-and-thousands-of" data-original-url="https://www.itpro.com/security/data-breaches/354532/huge-data-leak-exposes-british-consultancy-firms-and-thousands-of">British consultancy firms and consultants</a> such as passport scans and financial documents.</p><p>The firm previously <a href="https://www.itpro.com/security/34671/us-military-data-exposed-in-179gb-autoclerk-leak" data-original-url="https://www.itpro.com/security/34671/us-military-data-exposed-in-179gb-autoclerk-leak">discovered exposed US military data in October 2019</a> due to a flaw in a reservations management system owned by the Best Western hotel chain. Personnel working for the US Department for Homeland Security (DHS) and the military was seen by researchers from vpnMentor, including travel arrangements both past and future.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="29GMe8oeDBrrJwcb7ccQSV" name="29GMe8oeDBrrJwcb7ccQSV.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/29GMe8oeDBrrJwcb7ccQSV.jpg" mos="https://cdn.mos.cms.futurecdn.net/29GMe8oeDBrrJwcb7ccQSV.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How enterprises are embracing cyber security challenges</strong></p><p class="fancy-box__body-text">Enterprises across Europe, the Middle East and Africa are undergoing a significant transformation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/355055/how-enterprises-are-embracing-cyber-security-challenges" data-original-url="/security/cyber-security/355055/how-enterprises-are-embracing-cyber-security-challenges">FREE DOWNLOAD</a></p></div></div><p>The countries affected include not just the US and the UK, but clients in Sri Lanka, Nigeria and India, according to researchers. The UK-based printing company has a number of high profile clients and projects, including full-length books and sought-after paid wellness plans.</p><p>Doxzoo could have avoided this leak if they had taken basic security measures to protect the S3 bucket, vpnMentor said, including securing their servers, implementing proper access rules, and preventing system that don't need authentication from being accessed by the public through the internet.</p><p>The firm first discovered the exposed database on 22 January, before notifying the company four days later. Because Doxzoo didn’t respond to vpnMentor’s communication attempts, Amazon was notified on 5 February, and the bucket was finally closed on 11 February.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to stop a DDoS attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ddos/28039/how-to-stop-a-ddos-attack</link>
                                                                            <description>
                            <![CDATA[ DDoS attacks are on the rise - here's how to fight back ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2D3ypyfyPsQfPcaPMoiGZG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/48SvkRxBH5mjkLniYoHtw-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 25 Oct 2019 10:03:00 +0000</pubDate>                                                                                                                                <updated>Wed, 23 Dec 2020 10:32:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/48SvkRxBH5mjkLniYoHtw-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[DDoS attack]]></media:description>                                                            <media:text><![CDATA[DDoS attack]]></media:text>
                                <media:title type="plain"><![CDATA[DDoS attack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/48SvkRxBH5mjkLniYoHtw-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Of all the ways a hacker can disrupt a business, a <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" target="_blank" data-original-url="https://www.itpro.com/security/28026/what-is-a-ddos-attack">DDoS</a> attack is arguably the most annoying. DDoS stands for distributed denial of service and it has become very popular to cybercriminals looking to infiltrate, or merely disrupt, businesses. </p><p>What’s more, attacks can be administered by anyone, from novice hackers to seasoned pros, and done so virtually. The tools are easily deployed and widely available. It's a case of simply bombarding a targeted website with artificial traffic until it crashes. When a computer visits a website, it requests access to the content of the site and a DDoS attack exploits this by sending more requests than a server can cope with in one go. The attack clogs up the system, causing long delays or even the complete failure of the server. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rVG8VUdynajTcMzJo4xDsW" name="" alt="DDoS" src="https://cdn.mos.cms.futurecdn.net/rVG8VUdynajTcMzJo4xDsW.jpg" mos="https://cdn.mos.cms.futurecdn.net/rVG8VUdynajTcMzJo4xDsW.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><h3 class="article-body__section" id="section-ddos-attacks-are-on-the-rise"><span>DDoS attacks are on the rise</span></h3><p>The sad fact of life for many organisations is that DDoS attacks are increasing. In the first half of 2020, DDoS attacks increased by a whopping 542%, according to NexusGuard. </p><p>The largest DDoS attack ever recorded thus far was in 2017. Google <a href="https://www.itpro.com/security/357465/google-reveals-blocking-record-breaking-25tbps-ddos-attack-in-2017" data-original-url="https://www.itpro.com/security/357465/google-reveals-blocking-record-breaking-25tbps-ddos-attack-in-2017">revealed</a> that its infrastructure absorbed a 2.5Tbps distributed denial of service (DDoS) attack in 2017, the largest such attack in terms of its sheer volume ever recorded. This was four times larger than the record-breaking 623 Gbps attack from the Mirai botnet a year earlier.</p><p>In 2018, Amazon Web Services (AWS) reportedly blocked an attack that measured at 2.3Tbits/sec. This, it said, was 44% larger than anything it had dealt with before. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/distributed-denial-of-service-ddos/356237/most-intense-ever-ddos-attack-targets-large" data-original-url="/security/distributed-denial-of-service-ddos/356237/most-intense-ever-ddos-attack-targets-large">'Largest ever' DDoS attack targets European bank</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" data-original-url="/security/28026/what-is-a-ddos-attack">What is a DDoS attack?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/5g/354286/why-5g-could-be-a-cyber-security-nightmare" data-original-url="/mobile/5g/354286/why-5g-could-be-a-cyber-security-nightmare">Why 5G could be a cyber security nightmare</a></p></div></div><p>But, it's not just the big-name players on the internet who are at risk from DDoS attacks. According to Kaspersky Lab, 27% of businesses caught up in such an incident think they were collateral damage, rather than being the intended target. This reiterates the need for all organisations to know how to protect themselves from a DDoS attack.</p><p>In the UK, it has been calculated that <a href="https://www.itpro.com/security/33279/ddos-attacks-could-cost-the-uk-1bn" data-original-url="https://www.itpro.com/security/33279/ddos-attacks-could-cost-the-uk-1bn">DDoS attacks could cost the country almost £1 billion</a> per year, according to Netscout's Worldwide Infrastructure Security Report.</p><p>While the cloud has been a boon to many, it has also been sadly useful to criminals. <a href="https://www.itpro.com/public-cloud/31884/public-cloud-used-to-power-supercharged-ddos-attacks" data-original-url="https://www.itpro.com/public-cloud/31884/public-cloud-used-to-power-supercharged-ddos-attacks">According to research</a> by Link11's Security Operation Center (LSOC), the public cloud was used in a quarter of DDoS attacks in a year.</p><h3 class="article-body__section" id="section-ddos-safeguarding"><span>DDoS safeguarding</span></h3><p>Rather than over-provisioning, simple things such as bandwidth buffering can allow for traffic spikes including those associated with DDoS attacks, and give you time to both recognise the attack and react to it.</p><p>It's also probably worth putting into place other basic safeguards that can gain you a few precious minutes: rate-limiting your router, adding filters to drop obvious spoofed or malformed packets, and setting lower drop thresholds for ICMP, SYN, and UDP floods. All these will buy you time to try and find help.</p><p>It is also a good idea to familiarise yourself with your website's inbound traffic characteristics. The more you know about what looks normal, the easier it becomes to identify anomalous traffic and take action. It is also a good idea to be able to tell the difference between a sudden surge of normal visitors and the start of a DDoS attack.</p><h3 class="article-body__section" id="section-ddos-response-planning"><span>DDoS response planning</span></h3><p>The first thing every organisation should do when suspecting a DDoS attack is confirmed it actually happened. Once you've discounted <a href="https://www.itpro.com/domain-name-system-dns/30228/what-is-dns" target="_blank" data-original-url="https://www.itpro.com/domain-name-system-dns/30228/what-is-dns">DNS</a> errors or upstream routing problems, then your DDoS response plan can kick in.</p><p>What should be in that response plan? Contact relevant members of your incident response team, including leads from applications and operations teams, as both are likely to be impacted.</p><p>Then contact your ISP, but don't be surprised if it black-holes your traffic. A DDoS attack costs it money, so null routing packets before they arrive at your servers is often the default option. It may offer to divert your traffic through a third-party scrubber network instead; these filter attack packets and only allow clean traffic to reach you.</p><p>Be warned, this is likely to be a more expensive emergency option than had you contracted such a content distribution network (CDN) to monitor traffic patterns and scrub attack traffic on a subscription basis.</p><h3 class="article-body__section" id="section-ddos-prioritisation"><span>DDoS prioritisation</span></h3><p>Ensure the limited network resources available to you are prioritised - make this is a financially driven exercise as it helps with focus. Sacrifice low-value traffic to keep high-value applications and services alive. Remember that DDoS response plan we mentioned?</p><p>This is the kind of thing that should be in it, then these decisions aren't being taken on the fly and under time pressure. There's no point allowing equal access to high-value applications, whitelist your most trusted partners and remote employees using <a href="https://www.itpro.com/security/27098/best-vpn-services" target="_blank" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">VPN</a> to ensure they get priority.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2QVtGsQqwJmbv96BVLpaAJ" name="" alt="Image of a cyber criminal using several computers in a dark room" src="https://cdn.mos.cms.futurecdn.net/2QVtGsQqwJmbv96BVLpaAJ.jpg" mos="https://cdn.mos.cms.futurecdn.net/2QVtGsQqwJmbv96BVLpaAJ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><h3 class="article-body__section" id="section-multi-vector-ddos-protection"><span>Multi-vector DDoS protection</span></h3><p>Multi-vector attacks, such as when a DDoS attack is used to hide a data exfiltration attempt, are notoriously difficult to defend against. It's all too easy to say that you must prioritise data protection, but the smokescreen DDoS remains a very real attack on your business.</p><p>The motivation behind a DDoS is irrelevant, they should all be dealt with using layered DDoS defences. These should include the use of a CDN to deal with volumetric attacks, with web application firewalls and gateway appliances dealing with the rest. A dedicated DDoS defence specialist will be able to advise on the best mix for you.</p><h3 class="article-body__section" id="section-ddos-mitigation-services"><span>DDoS mitigation services</span></h3><p>For businesses particularly susceptible to DDoS attacks, for example, enterprises and larger organisations, investing in mitigation services, or at the very least assessing available options, may be worth your time.</p><p>Cloudflare offers perhaps one of the most well-known such services, offering DDoS protection for several high-profile organisations including WikiLeaks, as well as having worked to mitigate many high-profile attacks. The <a href="https://www.itpro.com/security/29331/ddos-attacks-blamed-on-70000-strong-android-botnet" data-original-url="https://www.itpro.com/security/29331/ddos-attacks-blamed-on-70000-strong-android-botnet">WireX botnet</a> and the <a href="https://www.itpro.com/hacking/19837/spanish-police-arrest-alleged-spamhaus-hacker" data-original-url="https://www.itpro.com/hacking/19837/spanish-police-arrest-alleged-spamhaus-hacker">Spamhaus attack of 2013</a> serve as the best examples.</p><p>There are many alternatives in the field of DDoS protection services, and many network and application delivery optimisation firms also offer mitigation against DDoS attacks. The WireX botnet, for example, was taken down as a result of a collaboration between several companies, including Cloudflare, but also RiskIQ, Flashpoint, Team Cymru, and Google.</p><p>Other companies that fall into the camp include Akami, NETSCOUT Arbor, F5 Networks, Imperva, and Verisign. This is alongside many other options that perhaps don’t have the profile of the aforementioned group, including Neustar, DOSarrest, and ThousandEyes.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WtzrNvmRpYZTPfVKS7jGfh" name="WtzrNvmRpYZTPfVKS7jGfh.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/WtzrNvmRpYZTPfVKS7jGfh.jpg" mos="https://cdn.mos.cms.futurecdn.net/WtzrNvmRpYZTPfVKS7jGfh.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Securing remote workers in the age of teleworking</strong></p><p class="fancy-box__body-text">Using foundational network infrastructure</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/357411/securing-remote-workers-in-the-age-of-teleworking" data-original-url="/security/cyber-security/357411/securing-remote-workers-in-the-age-of-teleworking">FREE DOWNLOAD</a></p></div></div><p>A handful of these providers also offer emergency coverage, as it’s known, which can be purchased when a DDoS attack is already in progress, to protect the business and its services against the worst elements of the wave. Others, meanwhile, require a longer-term contract when arranging mitigation for such attacks.</p><p>For businesses or organisations using other products from these companies may also want to seek out adding DDoS protection to the overall package. For those using another network optimisation company, alternatively, besides those listed, it would be worth examining what DDoS protection options are on offer, and how much it would cost. ISPs may also offer some form of DDoS mitigation, especially in the form of emergency cover, but this may or may not be as comprehensive as some of the options provided by specialist companies.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Equifax data breach: Ex-CIO to serve four months in prison for insider trading ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-breaches/29418/equifax-data-breach-cost-14-billion-so-far</link>
                                                                            <description>
                            <![CDATA[ Jun Ying “abused the trust placed in him” to profit from advanced knowledge of the disastrous data breach ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Nxi5btsBeuNbtDqVcGDB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aCjSxfQi98yYmBQHkLLNcF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Jul 2019 12:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aCjSxfQi98yYmBQHkLLNcF-1280-80.jpg">
                                                            <media:credit><![CDATA[Bigstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital padlock hovering over a screen]]></media:description>                                                            <media:text><![CDATA[Digital padlock hovering over a screen]]></media:text>
                                <media:title type="plain"><![CDATA[Digital padlock hovering over a screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aCjSxfQi98yYmBQHkLLNcF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The former chief information officer (CIO) of embattled firm Equifax has been sentenced to four months in prison and handed a substantial fine for insider trading following the company's data breach disaster.</p><p>Jun Ying, 44, was found guilty of selling $950,000 worth of company shares in March after learning that Equifax had sustained a data breach in 2017, <a href="https://www.justice.gov/usao-ndga/pr/former-equifax-employee-sentenced-insider-trading" target="_blank">according to the US Attorney's Office for the Northern District of Georgia</a>.</p><p>This amounted to illicit trading because Ying managed to avoid losses of $117,000 through the sale, before the data breach news became known to investors, or entered the public domain.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33242/the-equifax-effect-explaining-the-biggest-security-disaster-of-the-21st-century" data-original-url="/security/33242/the-equifax-effect-explaining-the-biggest-security-disaster-of-the-21st-century">The Equifax Effect: Explaining the biggest security disaster of the 21st century</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29224/the-cyber-security-threat-in-charts" data-original-url="/security/29224/the-cyber-security-threat-in-charts">The cyber security threat in six charts</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-leakage/26498/equifax-suffers-data-breach-losing-431000-workers-details" data-original-url="/data-leakage/26498/equifax-suffers-data-breach-losing-431000-workers-details">Equifax 'suffers data breach, losing 431,000 workers' details'</a></p></div></div><p>Alongside a four-month prison sentence, the ex-CIO was last week ordered to pay restitution amounting to $117,117.61, as well as a $55,000 fine. </p><p>"Ying thought of his own financial gain before the millions of people exposed in this data breach even knew they were victims," said US Attorney Byung J Pak.</p><p>"He abused the trust placed in him and the senior position he held to profit from inside information."</p><p>The former company executive texted a colleague on 25 August that the breach "sounds bad" and that the company itself may have been the victim.</p><p>The following week, Ying made internet searches to learn about the impact of Experian's data breach on the firm's stock price. He then exercised his stock options to receive 6,815 shares of Equifax stock, which he then sold immediately.</p><p>Equifax hadn't publicly declared the breach until 7 September in 2017, after which point the firm's stock price fell considerably.</p><p>Ying is the second Equifax employee to have been found guilty of insider trading following the data breach. Sudhakar Reddy Bonthu, a former manager at the company, pleaded guilty to insider trading last year.</p><p><strong>13/05/19: Incident has cost the firm $1.4 billion so far</strong></p><p>The greatest security catastrophe of modern times has cost Equifax more than a billion dollars to date, according to the firm's latest financial results.</p><p>The 2017 data breach incident saw the US-based credit rating agency expose more than 145 million people's personal records to hackers due to flaws in its systems. The breach was sizeable, but <a href="https://www.itpro.com/security/33242/the-equifax-effect-explaining-the-biggest-security-disaster-of-the-21st-century" target="_blank" data-original-url="https://www.itpro.com/security/33242/the-equifax-effect-explaining-the-biggest-security-disaster-of-the-21st-century">deemed highly alarming due to the nature of the information stolen</a>; ranging from full names and addresses to credit card information.</p><p>Equifax has now revealed that costs relating to the incident, as well as expenditure on IT and data security, have reached $1.35 billion, excluding a raft of legal fees for lawsuits that are yet to be seen.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33242/the-equifax-effect-explaining-the-biggest-security-disaster-of-the-21st-century" data-original-url="/security/33242/the-equifax-effect-explaining-the-biggest-security-disaster-of-the-21st-century">The Equifax Effect: Explaining the biggest security disaster of the 21st century</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29224/the-cyber-security-threat-in-charts" data-original-url="/security/29224/the-cyber-security-threat-in-charts">The cyber security threat in six charts</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-leakage/26498/equifax-suffers-data-breach-losing-431000-workers-details" data-original-url="/data-leakage/26498/equifax-suffers-data-breach-losing-431000-workers-details">Equifax 'suffers data breach, losing 431,000 workers' details'</a></p></div></div><p>This stands at more than 350 times the average cost relating to a data breach, according to IBM research released last year, which found that <a href="https://www.itpro.com/security/31489/mega-data-breaches-cost-megabucks-says-ibm" target="_blank" data-original-url="https://www.itpro.com/security/31489/mega-data-breaches-cost-megabucks-says-ibm">these costs normally average $3.86 million for a large breach</a>. Even for US-based breaches, which cost $7.91 million on average, Equifax's costs are 170 times greater.</p><p>For the first quarter of 2019 alone the company incurred $786.8 million dollars in costs, including $690 million in legal expenditure. The total sum also included $82.8 million for technology and data security, $12.5 million for legal and investigative fees, and $1.5 million for product liability.</p><p>The company's chief executive Mark Begor told investors in a conference call that Equifax had made progress since the 2017 breach, according to WABE. This is notably by settling legal action brought against the firm.</p><p>While costs relating to the Equifax breach are extraordinary by conventional standards, they fall short of the gargantuan $4 billion 'worst-case' figure once tied with the 2011 Epsilon breach.</p><p>This sum was determined by research into the incident at the time, which suggested the estimated total damage could hit between $3 to $4 billion over time, when forensic audits, monitoring, litigation and lost business were taken into account.</p><p><strong>20/09/18: Equifax hit with maximum 500,000 fine after a massive security breach</strong></p><p>The <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner's Office (ICO)</a> has fined Equifax 500,000 for failing to protect millions of UK citizens' personal data during a cyber attack last year.</p><p>Contact information, email addresses and credit card information of 15 million UK Equifax customers were compromised in a massive hack on its US parent company, Equifax Inc, between 13 May and 30 July 2017.</p><p>Although systems in the US were targeted, the ICO found the credit agency's UK arm failed to take appropriate steps to ensure its parent firm, which processed this data on its behalf, had protected the information.</p><p>"The loss of personal information, particularly where there is the potential for financial fraud, is not only upsetting to customers, it undermines consumer trust in digital commerce," said Information Commissioner Elizabeth Denham.</p><p>"This is compounded when the company is a global firm whose business relies on personal data. We are determined to look after UK citizens' information wherever it is held.</p><p>"Equifax Ltd has received the highest fine possible under the 1998 legislation because of the number of victims, the type of data at risk and because it has no excuse for failing to adhere to its own policies and controls as well as the law."</p><p>The hack led to the theft of 146 million customers' data from around the world. Although the vast majority of the <a href="https://www.itpro.com/data-breaches/29418/equifax-data-breach-cost-14-billion-so-far" target="_blank" data-original-url="https://www.itpro.com/data-breaches/29418/equifax-data-breach-cost-14-billion-so-far">15 million UK users affected only had their contact information stolen</a>, it is thought 30,000 also lost their email addresses, and a further 15,000 had partial credit card information stolen.</p><p>Equifax received the ICO's Monetary Penalty Notice on Wednesday, and are considering the points made in the document, a spokesperson confirmed. It also once again apologised for the incident.</p><p>"Equifax has cooperated fully with the ICO throughout its investigation, and we are disappointed in the findings and the penalty," a spokesperson from its UK arm said.</p><p>"As the ICO makes clear in its report, Equifax has successfully implemented a broad range of measures to prevent the recurrence of such criminal incidents and it acknowledges the strengthened procedures which are now in effect.</p><p>"Data security and combatting criminal digital activity is an ongoing battle for all organisations that requires continued innovation and attention. We have acted and continue to act to make things right for consumers. They will always be our priority."</p><p>The 500,000 fine is the culmination of up to a year's long investigation the ICO has been conducting in tandem with the Financial Conduct Authority (FCA).</p><p>It has been adjudicated under the <a href="https://www.itpro.com/data-protection/28085/what-is-the-data-protection-act-1998" target="_blank" data-original-url="https://www.itpro.com/data-protection/28085/what-is-the-data-protection-act-1998">Data Protection Act 1998 (DPA)</a>, as opposed to the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">EU's General Data Protection Regulation (GDPR)</a>, since the cyber attack occurred before the new laws came into force on 25 May.</p><p>The joint probe revealed multiple failures at the credit agency, including that data was retained longer than necessary, and that personal information was vulnerable to unauthorized access.</p><p>Investigators also found significant problems with data retention, IT system patching, and its auditing procedures. The US Department of Homeland Security, moreover, had warned its parent firm about a critical vulnerability as far back as March 2017. Steps to address this vulnerability were not taken, and a user-facing portal was not appropriately patched.</p><p>"Many of the people affected would not have been aware the company held their data; learning about the cyber attack would have been unexpected and is likely to have caused particular distress," Ms Denham added.</p><p>"Multinational data companies like Equifax must understand what personal data they hold and take robust steps to protect it. Their boards need to ensure that internal controls and systems work effectively to meet legal requirements and customers' expectations.</p><p>Denham added that Equifax showed "serious disregard" for their customers and the personal information that it held.</p><p>This massive penalty follows the <a href="https://www.itpro.com/policy-legislation/31483/facebook-fined-500000-by-the-ico-following-cambridge-analytica-data-scandal" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/31483/facebook-fined-500000-by-the-ico-following-cambridge-analytica-data-scandal">ICO's intent to fine Facebook 500,000</a> in light of the Cambridge Analytica scandal, with notice issued in July.</p><p>However, an ICO spokesperson confirmed the regulator has yet to issue the fine itself, having until January to do so. This means Equifax Ltd becomes the first company to be fined the maximum permitted under the DPA.</p><p>Telecoms firm TalkTalk was fined 400,000 in 2016 for a data breach involving over 150,000 customers, and then 100,000 after the discovery of a second hack that occurred earlier in 2014, and therefore collectively has faced similar financial penalties.</p><p>Although GDPR has been in force for nearly four months, the ICO has yet to conclude any of its ongoing investigations into breaches of the new legislation.</p><p>This includes the breach on <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31438/ticketmasters-data-breach-could-be-the-litmus-test-for" target="_blank" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31438/ticketmasters-data-breach-could-be-the-litmus-test-for">Ticketmaster's systems in late June</a>, which could be a litmus test for how the ICO will regulate organisations under GDPR. <a href="https://www.itpro.com/data-breaches/31854/british-airways-reveals-massive-data-breach-could-face-500m-fine-under-gdpr" target="_blank" data-original-url="https://www.itpro.com/data-breaches/31854/british-airways-reveals-massive-data-breach-could-face-500m-fine-under-gdpr">British Airways could potentially face a 500 million fine</a>, though this would be the maximum.</p><p>While the maximum fine under the DPA 1998 is 500,000, breaches of GDPR could see <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid" target="_blank" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid">organisations hit with a penalty of up to 17 million</a>, or 4% of an organisation's annual turnover, whichever is higher.</p><p><strong>13/02/18: Equifax admits even more data stolen than previously thought</strong></p><p>Equifax has admitted that the hack on its systems in late 2017 was far worse than previously thought and that criminals were able to steal sensitive personal information on 145 million customers in the US, UK and Canada.</p><p>The international credit agency previously said that hackers were able to access names, addresses, dates of birth and credit score data from user accounts during the breach, as well as financial information and driver licences in some instances.</p><p>Although the vast majority of the 15 million UK users affected had only their contact information stolen, it was thought that 30,000 also had their email addresses leaked, and around 15,000 had partial credit card information stolen.</p><p>However, it's now emerged that hackers were also able to access US taxpayer ID numbers and their associated email addresses and phone numbers, according to documents disclosed by Equifax to the US Senate Banking committee, seen by the <a href="https://apnews.com/2a51e3e5f9a945978df4ad96246b8ecc" target="_blank"><em>Associated Press</em></a>.</p><p>The documents, provided by Senator Elizabeth Warren's office, also revealed that finer details, such as credit card expiry dates and issuing states for driving licences associated with the taxpayer records had also been leaked.</p><p>Equifax spokeswoman Meredith Griffanti said that "in no way did we intend to mislead consumers", and that the company wished only to "act with the greatest clarity" when it decided to disclose only those details relating to the greatest number of users.</p><p>She added that the document provided detailed every potential data type that may have been accessed by criminals, but that as a whole they affected a relatively small proportion of users.</p><p>"When you are making that kind of announcement, where do you draw the line? If you saw the list we provided the banking finance committee it was pretty exhaustive," said Griffanti, speaking to the Associated Press. "We wanted to show them that no stone was left unturned."</p><p>However, this will likely be seen as yet another example of the company trying to mitigate the fallout from a catastrophic data breach. Equifax was first criticised for waiting months before disclosing the hack to the public, and then again when it repeatedly revised up the number of those affected and the types of data potentially lost.</p><p>In October the UK Treasury Committee called the company to answer questions relating to its failure to patch a well known Apache Struts flaw, which was thought to have created a hole in its security systems. This was shortly followed by the news that the Financial Conduct Authority would be investigating the hack, including Equifax's subsequent handling of it.</p><p>Outside of regulatory investigations, the company also faces hundreds of lawsuits brought by customers, and is thought to have set aside almost $90 million to deal with the fallout.</p><p><strong>13/11/2017: Hack costs Equifax $87.5 million, as income plummets</strong></p><p>Equifax's data breach has cost the company $87.5 million, its <a href="https://investor.equifax.com/news-and-events/news/2017/11-09-2017-211550295" target="_blank">latest financial results</a> reveal.</p><p>The credit monitoring agency's failure to patch a server flaw over summer resulted in hackers potentially stealing 143 million US citizens' data, and that of 700,000 Brits.</p><p>It's set aside $87.5 million ($59.3 million net of tax) to deal with the fallout from the hack, recording the expense in its July-September financial quarter.</p><p>Releasing its results for the quarter last week, Equifax revealed that its operating income fell by 28% year-on-year to $152.9 million as a result of the financial hit.</p><p>However, it could get even worse, with the firm admitting the total cost of the hack could hit $110 million.</p><p>Of the money it's set aside, $55.5 million accounts for the cost of providing hack victims with a free credit file monitoring and identity theft protection service, with a further $17.1 million spent on professional services. Customer support is costing Equifax $14.9 million.</p><p>The results update read: "We have incurred $4.7 million through September 30, 2017 [due to the breach] and have estimated a range of additional costs between $56 million and $110 million.</p><p>"We have recorded a liability for the low end in the range as we do not believe that any amount within the range is a better estimate than any other amount."</p><p>Hack victims who haven't signed up for Equifax's free credit file monitoring and identity theft protection service have until 31 January 2018 to do so.</p><p><strong>26/10/2017: Credit agency says victims can still sue, despite rule change</strong></p><p>Equifax has denied customers affected by the hack that saw the personal details of millions taken by cyber criminals will be unable to sue the company.</p><p>It had been speculated that those affected would be prevented from suing the company, after the US Senate yesterday repealed a law that prohibited "covered providers of certain consumer financial products and services from using an agreement with a consumer that provides for arbitration of any future dispute between the parties to bar the consumer from filing or participating in a class action concerning the covered consumer financial product or service".</p><p>Equifax, however, is standing by earlier statements that customers will be able to file a lawsuit if they wish.</p><p>In a statement, the company told <em>IT Pro</em>: "Enrolling in the free credit file monitoring and identity theft protection products that we are offering as part of this cyber security incident does not prohibit customers from taking legal action. The congressional action overturning the CFPB's rule does not change our position."</p><p>The mention of the free credit file monitoring and identity theft protection products is significant in itself. When these initiatives were first launched, there was a clause in the terms of use that it appeared would have prevented customers for suing the company for the breach. Following public outcry, however, the company clarified that the stipulation referred only to these products, not to the breach itself.</p><p>Over 140 million consumers globally were affected by the hack, which took place between May and July 2017, but wasn't discovered until 29 July. No public announcement was made until mid-September.</p><p><strong>25/10/2017: Hack victims may not be able to sue Equifax</strong></p><p>The US Senate voted early this morning to remove a federal rule that would have allowed people affected by the Equifax hack to sue the company.</p><p>A 50/50 tie-break in the Senate was broken by vice-president Mike Pence casting a deciding vote in favour of the joint resolution to get rid of the rule, <em><a href="https://www.google.com/url?q=https%3A%2F%2Ftechcrunch.com%2F2017%2F10%2F24%2Fcongress-votes-to-disallow-consumers-from-suing-equifax-and-other-companies-with-arbitration-agreements%2F" target="_blank">TechCrunch</a> </em>reported.</p><p>The rule in question stops financial services companies that bind their users by arbitration agreements from preventing them from suing as a class.</p><p>It was <a href="https://www.google.com/url?q=https%3A%2F%2Fwww.gpo.gov%2Ffdsys%2Fgranule%2FFR-2017-07-19%2F2017-14225%2Fcontent-detail.html" target="_blank">entered</a> into the Federal Register in July by the Bureau of Consumer Financial Protection, with the joint resolution to nullify it - <a href="https://www.google.com/url?q=https%3A%2F%2Fwww.congress.gov%2Fbill%2F115th-congress%2Fhouse-joint-resolution%2F111%2Ftext" target="_blank">H.J Res.111</a> - submitted the next day.</p><p>The rule says: "The final rule prohibits covered providers of certain consumer financial products and services from using an agreement with a consumer that provides for arbitration of any future dispute between the parties to bar the consumer from filing or participating in a class action concerning the covered consumer financial product or service."</p><p>Equifax pointed customers affected by its huge data breach to sign up to its TrustedID Premier service in the aftermath of the hack. TrustedID offers identify theft insurance and scans the web to see if customers' social security numbers have been used illegally.</p><p>Initially, the terms of service of TrustedID made clear that signing up to use it prevented users from suing the company and ensured any disputes it had would need to be resolved through arbitration.</p><p>Equifax then removed the arbitration clause last month, and said in an FAQ that neither the TrustedID terms of use nor Equifax's own terms of use would prevent people from taking legal action.</p><p>It still reads: ''We will not apply any arbitration clause or class action waiver against consumers for claims related to the free products offered in response to the cybersecurity incident or for claims related to the cybersecurity incident itself''.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="cLwZjGMFRNiMeSPQAtQr77" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/cLwZjGMFRNiMeSPQAtQr77.png" mos="https://cdn.mos.cms.futurecdn.net/cLwZjGMFRNiMeSPQAtQr77.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em><a href="https://www.equifaxsecurity2017.com/frequently-asked-questions/#tab-2" target="_blank">From Equifax's TrustedID Premier FAQ</a></em></p><p>Despite this, it remains unclear what users have signed up for and whether the striking of this federal rule will affect them.</p><p><em>IT Pro</em> has asked Equifax whether people will still be able to use TrustedID Premier, and Equifax's credit monitoring services, and be able to sue it over its cyber security breach, if the rule is nullified.</p><p>All that is needed for the rule to be thrown out is for the joint resolution to be signed by president Donald Trump.</p><p><strong>24/10/2017: FCA opens investigation into Equifax hack</strong></p><p>The Financial Conduct Authority (FCA) has confirmed it's investigating the Equifax hack in which the details of 700,000 Brits were leaked. </p><p>The financial watchdog said it was confirming the investigation "given the public interest in these matters."</p><p>"The FCA announces today that it is investigating the circumstances surrounding a cybersecurity incident that led to the loss of UK customer data held by Equifax Ltd on the servers of its US parent," the watchdog said, giving no other detail on the inquiry. </p><p>In a <a href="http://www.cityam.com/274455/equifax-hack-being-investigated-financial-conduct-authority">statement</a>, Equifax said it looked forward to the results of the investigation. "We welcome this opportunity to learn the lessons from this criminal cyber attack in order for all businesses to better protect consumers in the future," it said. "Cybercrime is a real and ever-present risk faced by all companies, so it is important that government, regulators and businesses work together to combat this growing threat. We see today's announcement as a continuation of that process."</p><p>As many as 143 million Americans were affected by the data breach, alongside 700,000 in the UK, but Equifax took months to notify victims. Leaked details included phone numbers, driving licence numbers, usernames and passwords, and emails. </p><p><strong>13/10/2017: UK Treasury Committee chair demands answers from Equifax over data leak</strong></p><p>Equifax could potentially face political backlash over its handling of its recent data leak, as the chairman of the House of Commons has now demanded answers as to why it took so long for UK customers to be alerted.</p><p>The head of the treasury select committee, Nicky Morgan, has <a href="http://www.parliament.uk/business/committees/committees-a-z/commons-select/treasury-committee/news-parliament-2017/equifax-data-breach-chairs-statement-17-19" target="_blank">written a letter</a> to the credit agency's European chief Patricio Remon asking for the full scope of the data breach, and what compensation will be provided to those affected. A letter has also been sent to the Financial Conduct Authority (FCA) to see whether the watchdog plans to move against the UK arm of Equifax.</p><p>The company revealed on 7 September that a data breach on its systems in mid-May had resulted in the leak of 143 million data records, later revised up to 145 million. The hack, which was thought to have affected mainly the US systems, was blamed on the company failing to apply an Apache Struts patch, which was known to have been vulnerable.</p><p>The company also initially said that 400,000 UK customers had been indirectly affected by the breach, but that no financial details had been accessed.</p><p>However, on Tuesday Equifax made yet another revision, admitting that a file containing data on 15.2 million UK records was accessed during a data breach in May, giving access to names and contact details, and of that figure almost 700,000 accounts had had partial credit information and email addresses stolen.</p><p>"Equifax has taken too long to notify those affected by its widespread cyber-security breach," said Morgan. "People have been left in the dark for too long, which has increased the risk that they fall victim to identity theft and fraud."</p><p>She added that the Treasury Committee will "consider taking public evidence from Equifax, particularly if it does not receive a full and timely response to these questions".</p><p>Equifax is facing mounting pressure from both customers and lawmakers to explain why customers are only hearing about the data leak now, and why the company continues to botch its handling of the situation weeks after going public.</p><p>Part of the investigations will look into Equifax's handling of its customer help website, which was forced offline this week over concerns it contained malware. An independent security analyst discovered that customers were being asked to download outdated versions of flash player, according to <em><a href="https://arstechnica.com/information-technology/2017/10/equifax-website-hacked-again-this-time-to-redirect-to-fake-flash-update" target="_blank">Ars Technica</a></em>, although Equifax said its systems "were not compromised and that the reported issue did not affect our customer online dispute portal".</p><p>The company also used the website 'equifaxsecurity2017.com' as its official breach handling portal, which understandably drew complaints that it looked like a phishing site, and customers complained that its site designed to inform users if their data had been leaked was returning false results.</p><p>Political movements in the US are seeking to clamp down on credit agencies in the wake of the industry's largest ever data breach. Democratic senator Elizabeth Warren said last week that "Equifax and this whole industry, should be completely transformed", the <a href="https://www.ft.com/content/52f4e97a-ad45-11e7-aab9-abaa44b1e130" target="_blank"><em>Financial Times</em></a> reports, and that the Equifax data breach, which affected almost half of the American adult population, is evidence of a disregard for the security of customers.</p><p>It's likely that Equifax will be asked to appear before a UK committee, although there are no specific demands in place. Equifax's US boss Rick Smith, who stepped down in the wake of the data breach, was asked explain himself in front of a US house committee last week.</p><p><strong>11/10/2017: Nearly 700,000 Brits affected by Equifax breach</strong></p><p>Nearly 700,000 UK citizens were badly affected by Equifax's data breach, the credit monitoring agency admitted yesterday, revising its initial figure of 400,000.</p><p>A huge data set of 15 million UK credentials was also attacked during the raid between May and July, though once Equifax analysed the data it found only 694,000 UK customers who it needed to contact - many of the remaining records consisted of spurious fields and duplicated entries, though others contained names and dates of birth.</p><p>"Whilst this does not introduce any significant risk to these people Equifax is sorry that this data may have been accessed," the company said in a statement.</p><p>The 694,000 Equifax is now writing to had various data leaked - the vast majority had their phone numbers leaked, 30,000 had their email addresses breached, and 15,000 had their login details and partial credit card details from 2014 leaked, despite earlier statements saying that UK financial data had not been accessed.</p><p>Equifax alerted the UK's National Cyber Security Centre, which has put out an <a href="https://www.ncsc.gov.uk/news/ncsc-advice-equifax-customers-0" target="_blank">advisory statement</a> to affected customers.</p><p>"Equifax has today confirmed that a file containing 15.2m UK records dating from between 2011 and 2016 was attacked in the cyber incident that took place in May 2017," A NCSC statement said on Tuesday.</p><p>"If you have been told by Equifax that security details from your Equifax.co.uk membership account - such as password and secret questions - have been accessed, you should ensure those details are not used on any other accounts."</p><p>Equifax reported in September that it had been the victim of a major data breach between May and July this year, in which 143 million US customers were thought to have been affected, and an undisclosed number of UK and Canadian customers. That figure has since risen to 145.5 million, and recent reports have suggested that as many as 11 million US driver's licenses were leaked during the raid.</p><p>It was later found that hackers were able to exploit a months-old flaw in the application framework Apache Struts, which had a patch available, though Equifax failed to apply it. Social security numbers, dates of birth, addresses, credit card details and security information were all thought to have been compromised during the breach.</p><p>The NCSC believes the greatest risk will come from subsequent phishing campaigns using leaked personal data. Customers have been warned that given the nature of the data leak, fraudsters will likely use real names in the emails to make the phishing attacks look more genuine.</p><p>"The NCSC, with Equifax and partners including the NCA, ICO and FCA, continues to examine this incident and should further information come to light about the extent and nature of the impact on the UK, we will provide further updates and advice as soon as we can," a spokesperson said.</p><p>Patricio Remon, president for Europe at Equifax's UK unit, <a href="https://www.equifax.co.uk/about-equifax/press-releases/en_gb/-/blogs/equifax-ltd-uk-update-regarding-the-ongoing-investigation-into-us-cyber-security-incident" target="_blank">said</a>: "Once again, I would like to extend my most sincere apologies to anyone who has been concerned about or impacted by this criminal act. Let me take this opportunity to emphasise that protecting the data of our consumers and clients is always our top priority."</p><p>"It has been regrettable that we have not been able to contact consumers who may have been impacted until now, but it would not have been appropriate for us to do so until the full facts of this complex attack were known, and the full forensics investigation was completed."</p><p><em>Main image credit: Bigstock</em></p><p><strong>03/10/2017: Equifax's systems were vulnerable since March</strong></p><p>Equifax's systems have been vulnerable since March, though hackers didn't take advantage of the flaws until May.</p><p>Former Equifax CEO Richard Smith stated in a written testimony that the data breach occurred as a result of both human error and technology failures, according to a report from <a href="http://uk.reuters.com/article/us-equifax-breach/equifax-failed-to-patch-security-vulnerability-in-march-former-ceo-idUKKCN1C71VY" target="_blank"><em>Reuters</em></a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33242/the-equifax-effect-explaining-the-biggest-security-disaster-of-the-21st-century" data-original-url="/security/33242/the-equifax-effect-explaining-the-biggest-security-disaster-of-the-21st-century">The Equifax Effect: Explaining the biggest security disaster of the 21st century</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29224/the-cyber-security-threat-in-charts" data-original-url="/security/29224/the-cyber-security-threat-in-charts">The cyber security threat in six charts</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-leakage/26498/equifax-suffers-data-breach-losing-431000-workers-details" data-original-url="/data-leakage/26498/equifax-suffers-data-breach-losing-431000-workers-details">Equifax 'suffers data breach, losing 431,000 workers' details'</a></p></div></div><p>Additionally, Equifax <a href="https://investor.equifax.com/news-and-events/news/2017/10-02-2017-213238821" target="_blank">announced</a> that an extra 2.5 million US consumers may have been affected by the data breach, taking the total number up to 145.5 million.</p><p>The investigation into how UK consumers have been affected by the breach has been completed and the information is now being analysed by the firm.</p><p>Smith's testimony is scheduled to be shared with Congress today. It outlines how on 15 March the company's information security department carried out scans to identify any vulnerabilities in the system, but these failed to do so.</p><p>"The vulnerability remained in an Equifax web application much longer than it should have," Smith said. "It was this unpatched vulnerability that allowed hackers to access personal identifying information."</p><p>Smith added that the first date he believes hackers accessed private information may have been on May 13. He wrote: "between May 13 and July 30, there is evidence to suggest that the attacker(s) continued to access sensitive information."</p><p>Security personnel noticed suspicious activity on 29 July and ended the hacking on 30 July by disabling the web application. Smith said he was alerted the day after but did not realise the extent of the stolen data.</p><p>Equifax told the FBI on 2 August and retained a law firm and consulting firm as advisors. Smith told the board's lead director on 22 August.</p><p>Smith will testify at three different congressional hearings this week.</p><p>Furthermore, an extra 2.5 million US consumers have been identified as potentially being affected by the hack following the completion of a forensic investigation carried out by cybersecurity firm Mandiant. The firm said it hadn't identified any additional or new attacker activity within Equifax's systems too.</p><p>Equifax highlighted that the review determined that there is no evidence the attackers accessed databases located outside of the US.</p><p>"I want to apologise again to all impacted consumers. As this important phase of our work is now completed, we continue to take numerous steps to review and enhance our cybersecurity practices. We also continue to work closely with our internal team and outside advisors to implement and accelerate long-term security improvements," said interim CEO Paulino do Rego Barros.</p><p>Equifax CEO Smith announced his retirement last week, following the data breach in which up to 400,000 UK citizens' personal details and millions of US customers' information was revealed.</p><p>Smith was the third executive to leave the company after the breach, as the CIO and CSO also retired after it emerged that the company had failed to protect its customers sufficiently.</p><p><strong>27/09/2017: Equifax CEO 'retires' in data breach aftermath</strong></p><p>Equifax CEO Richard Smith has announced his retirement, following a serious data breach that revealed up to 400,000 UK citizens' personal information and millions of US customers' details.</p><p>Smith is the third executive to leave the credit monitoring agency after the CIO and CSO also officially retired following the revelations the company failed to protect its customers sufficiently.</p><p>"Serving as CEO of Equifax has been an honour, and I'm indebted to the 10,000 Equifax employees who have dedicated their lives to making this a better company," Smith said in his departing statement.</p><p>"The cyber security incident has affected millions of consumers, and I have been completely dedicated to making this right. At this critical juncture, I believe it is in the best interests of the company to have new leadership to move the company forward."</p><p>Board member Mark Feidler will become non-executive chairman, while Paulino do Rego Barros Jr, who most recently served as president of the company's Asia Pacific region, has been appointed as interim chief executive officer, while the company fills the three roles for the long term.</p><p>"The board remains deeply concerned about and totally focused on the cybersecurity incident," Feidler said. "We are working intensely to support consumers and make the necessary changes to minimise the risk that something like this happens again.</p><p>"Speaking for everyone on the board, I sincerely apologise. We have formed a special committee of the board to focus on the issues arising from the incident and to ensure that all appropriate actions are taken."</p><p><strong>20/09/2017: Equifax admits it suffered an earlier leak in March</strong></p><p>Credit agency Equifax, which lost 143 million customer data records through a data breach in May, has said it suffered a similar leak back in March, casting doubt over whether executives were entirely ignorant of the incidents when selling company shares. </p><p>The company were spurred to admit the earlier breach after sources familiar with the leaks had passed information over to <a href="https://www.bloomberg.com/news/articles/2017-09-18/equifax-is-said-to-suffer-a-hack-earlier-than-the-date-disclosed"><em>Bloomberg</em></a>, stating that the widely reported data leak in May was in fact a second breach.</p><p>Equifax reportedly hired a security team to investigate the leak and informed its customers, but chose not to inform the individuals it held data on because they were technically not customers of the company.</p><p>"Earlier this year, during the 2016 tax season, Equifax experienced a security incident involving a payroll-related service," the company said in a later statement to <a href="https://gizmodo.com/equifaxs-troubles-grow-with-news-of-prior-breach-doj-i-1818529191">Gizmodo</a>. "The incident was reported to customers, affected individuals and regulators. This incident was also covered in the media,"</p><p>"The March event reported by Bloomberg is not related to the criminal hacking that was discovered on 29 July. The criminal hacking that was discovered on 29 July did not affect the customer databases hosted by the Equifax business unit that was the subject of the March event."</p><p>Despite the claim the two leaks were unrelated, sources speaking to <em>Bloomberg</em> believe there is evidence to suggest the hacks were carried out by the same individual or group.</p><p>Equifax reportedly informed five organisations affected by the breach in March and admitted the incident in a letter to the New Hampshire attorney general. However, the company is facing mounting backlash for its handling of its second breach in May, as those affected were informed four months after its investigation concluded.</p><p>During that time, Equifax executives were able to sell off their stocks in the company, activity that is now being investigated by the US Justice Department as there is suspicion that insider trading was taking place. Although the company has maintained that its executives were unaware of May's data breach, the existence of an earlier incident casts doubt over how ignorant they were.</p><p>One report by <a href="http://www.thinkadvisor.com/2017/09/18/equifax-stock-sales-said-to-be-focus-of-us-crimina?slreturn=1505898879"><em>ThinkAdvisor</em></a> claims CFO John Gamble, president of US information solutions Joseph Loughran, and president of workforce solutions Rodolfo Ploder, are all currently under investigation. The three are thought to have sold off shares valued almost $1.8 million in early August, one month before the breach was made public.</p><p>Shares in the company plummeted by 17% following the news of the breach, wiping almost $3 billion off the value of the company. Equifax announced on Friday that both its CIO and CSO would be immediately leaving the company as a result of the breach.</p><p><strong>18/09/2017: Equifax data breach: 400,000 UK customers' data at risk in Equifax hack</strong></p><p>Up to 400,000 Brits' data has been leaked in the Equifax hack, the credit monitoring agency has finally revealed.</p><p>Data including names, dates of birth, email addresses and telephone numbers "may potentially have been accessed" by hackers who also stole 143 million US consumers' personal data, Equifax said.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33242/the-equifax-effect-explaining-the-biggest-security-disaster-of-the-21st-century" data-original-url="/security/33242/the-equifax-effect-explaining-the-biggest-security-disaster-of-the-21st-century">The Equifax Effect: Explaining the biggest security disaster of the 21st century</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29224/the-cyber-security-threat-in-charts" data-original-url="/security/29224/the-cyber-security-threat-in-charts">The cyber security threat in six charts</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-leakage/26498/equifax-suffers-data-breach-losing-431000-workers-details" data-original-url="/data-leakage/26498/equifax-suffers-data-breach-losing-431000-workers-details">Equifax 'suffers data breach, losing 431,000 workers' details'</a></p></div></div><p>The company added that home addresses, passwords and financial data were not included in the UK breach, which occurred as a result of a "process failure" that saw some UK data stored on US servers between 2011 and 2016.</p><p>Equifax said its UK systems were not affected by the data breach, which was the result of an Apache Struts flaw the company left unpatched.</p><p>Patricio Remon, president at Equifax, said: "We apologise for this failure to protect UK consumer data. Our immediate focus is to support those affected by this incident and to ensure we make all of the necessary improvements and investments to strengthen our security and processes going forward."</p><p>UK businesses' data was not included in the breach, though Equifax has only confirmed this is the case 10 days after publicly announcing the breach, which it discovered way back in late July.</p><p>A spokesman for the UK's data watchdog, the Information Commissioner's Office (ICO), said: "The ICO has been pressing the firm to establish the scale of any impact on UK citizens and has also been engaging with relevant US and UK agencies about the nature of the data breach.</p><p>"It can take some time to understand the true impact of incidents like this, and we continue to investigate. Members of the public should remain vigilant of any unsolicited emails, texts or calls, even if it appears to be from a company they are familiar with. We also advise that people review their financial statements regularly for any unfamiliar activity.</p><p>"If any financial details appear to have been compromised, victims should immediately notify their bank or card company. If anyone thinks they may have been a victim of a cyber crime they should contact Action Fraud."</p><p>Equifax believes identity theft is unlikely based on the leaked data, but will write to the affected customers to offer them a free identity protection service that monitors their personal data, including credit card details, and alerts them to possible fraud.</p><p>The news came alongside Equifax's announcement last Friday that both its CIO and chief security officer (CSO) are "retiring".</p><p>In their place, Mark Rohrwasser will serve as interim CIO effective immediately after leading the firm's international IT operations since last year, and vice-president of IT, Russ Ayres, has been appointed CSO, reporting to Rohrwasser.</p><p>The company said: "Equifax's internal investigation of this incident is still ongoing and the company continues to work closely with the FBI in its investigation."</p><p><strong>14/09/2017: Equifax hackers used a months-old Apache Struts flaw</strong></p><p>The massive hack on credit monitoring agency Equifax was carried out using an Apache Struts flaw that was first revealed in March, the company has admitted.</p><p>The huge cyber attack resulted in the theft of social security numbers, names, dates of birth and other personal data from 143 million US residents, and more than 200,000 credit card numbers. Equifax still hasn't revealed how many UK customers were affected.</p><p>But the company yesterday admitted that it was indeed a flaw in Apache's development framework Struts that had led to the attack.</p><p>In <a href="https://www.equifaxsecurity2017.com">an updated statement</a>, it said: "We know that criminals exploited a U.S. website application vulnerability. The vulnerability was Apache Struts CVE-2017-5638. We continue to work with law enforcement as part of our criminal investigation, and have shared indicators of compromise with law enforcement."</p><p>The hack was carried out in mid-May, according to Equifax, well over a month after the flaw was disclosed and a patch issued. The vulnerability was <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5638">categorised as 'critical'</a>, allowing remote code execution with no privileges and little technical knowledge to carry out.</p><p>An Apache Struts flaw was also pointed to as the cause of the breach shortly after it was announced. <em><a href="https://qz.com/1073221/the-hackers-who-broke-into-equifax-exploited-a-nine-year-old-security-flaw">Quartz</a></em> initially identified the vulnerability as CVE-2017-9805, which was disclosed earlier in September, although this turned out to be incorrect.</p><p>The Apache Foundation has said that the breach was a result of Equifax's inability to patch its systems, rather than flaws in its software. </p><p>"This vulnerability was patched on 7 March 2017, the same day it was announced," <a href="https://blogs.apache.org/foundation/entry/media-alert-the-apache-software">the Foundation's blog post</a> read. "In conclusion, the Equifax data compromise was due to their failure to install the security updates provided in a timely manner."</p><p>The revelation comes as evidence of lax cyber security protocols emerges. <a href="https://krebsonsecurity.com/2017/09/ayuda-help-equifax-has-my-data">Security expert Brian Krebs</a> discovered that corporate tools used by Equifax's Argentinian arm used 'admin' as the default username and password, giving him access to the national identity numbers of thousands of Argentinians.</p><p>The company has stated that this was completely unrelated to the incident in the US and that no customers have been affected. It has also taken action to address the problem, it said.</p><p>Equifax's response to the attack has led to criticism from all sides. Its cyber security practices are unsurprisingly coming under scrutiny, and US senators are also calling for investigations of the company executives who offloaded their stocks following the breach's discovery.</p><p>The data obtained in the breach is hugely valuable for thieves. Not only can it be leveraged for widespread identity theft, but cyber security firm Intsights has calculated that the database itself could fetch upwards of $32 million on dark web black markets.</p><p><strong>13/09/2017: Chatbot helps users sue Equifax for data breach</strong></p><p>A chatbot originally developed to help people appeal against parking and speeding fines has been re-purposed to help customers affected by the Equifax data breach sue the company.</p><p>DoNotPay, which was created by a British student studying at Stanford University, has been programmed to automatically file claims against the credit checking company, which suffered a breach leaking the details of up to 143 million US customers.</p><p>Data from UK customers were also stolen, although the company hasn't revealed how many.</p><p>The bot works by asking those it thinks are affected various questions it has developed for the case, changing them according to previous answers and how severely the person was impacted. It then provides the documents the user needs to make a claim formally.</p><p>The bot has so far helped 375,000 people claim against parking tickets, although developer Joshua Browder hasn't revealed how many Equifax customers have used it yet.</p><p>"We pride ourselves on being a leader in managing and protecting data, and we are conducting a thorough review of our overall security operations," said Richard Smith, Equifax chairman and chief executive, when the breach was revealed.</p><p>All those that think they were affected by the breach have been encouraged to check online and if they have, Equifax is offering them access to its credit and identity theft monitoring tools for free. Security experts have warned against using these due to waivers people must agree to that would prevent them from taking legal action, though Equifax has claimed these waivers don't apply to the cybersecurity incident.</p><p>DoNotPay has been used for a number of other small claims cases, including helping asylum seekers with their immigration applications to gain entry to the US and receive financial support fro the state.</p><p><strong>11/09/2017: Equifax's data breach response draws experts' ire</strong></p><p>Security experts have slammed Equifax for its actions in the wake of a cyber attack that has hit upwards of 143 million customers.</p><p>The credit check agency was hacked in May, then discovered the breach on 29 July, but only revealed it to customers last week (see below), blaming a "US website application vulnerability" without going into any greater detail.</p><p>Customers' social security numbers, driving license numbers, dates of birth and addresses have all been stolen, while some customers lost credit card numbers and other personally identifiable information.</p><p><a href="https://www.equifaxsecurity2017.com">An information page for US users</a> requires them to enter their name and last six digits of their social security numbers to determine if their social security number has been stolen, but nothing exists for UK users yet.</p><p>Free threat protection and credit monitoring services offered by Equifax include clauses that prevent consumers from suing Equifax or joining class action lawsuits. However, Equifax said these waivers don't apply to this cybersecurity incident.</p><p>Nevertheless, Jeff Pollard, principal analyst at research firm Forrester, warned affected customers against using these services.</p><p>He added: "We need more information from Equifax other than 'your information was or possibly was accessed'. </p><p>"What's even more concerning about this longer term is that Equifax is a major data aggregator, broker, and analytics firm. Given that we don't know the extent of the information breached, it's likely this reaches further into data that Equifax transforms as part of its marketing and analytic services. </p><p>"What kind of data did Equifax have, what did they do with it, and what is now in the adversaries' hands? How much do they know about us [and how much of this] is based on these analytics services?" </p><p>A class-action lawsuit has already been filed in Portland, Oregon, according to <em><a href="https://www.cyberscoop.com/equifax-lawsuit-class-action-data-breach" data-original-url="//www.cyberscoop.com/equifax-lawsuit-class-action-data-breach">Cyberscoop</a></em>, warning that costs resulting from the suit could hit $68.6 billion.</p><p>Meanwhile, Twitter users have criticised the effectiveness of a call centre deployed by Equifax to handle customer queries. Callers were put on hold or disconnected reports the <a href="https://www.theguardian.com/technology/2017/sep/08/equifax-hack-credit-social-security-helpline-response-criticism"><em>Guardian</em></a>. One user who was disconnected nine times eventually got through, only to be referred to a general information website.</p><p>Equifax said it has tripled its customer service agents to 2,000 and is continuing to add more.</p><p><strong>Did an Apache Struts bug allow Equifax to be hacked?</strong></p><p>The root cause of the hack remains unclear, but <em>Quartz</em> claimed last week that it was related to <a href="https://www.itpro.com/hacking/29398/critical-apache-flaw-puts-over-50-of-fortune-100-at-risk" data-original-url="https://www.itpro.com/hacking/29398/critical-apache-flaw-puts-over-50-of-fortune-100-at-risk">a bug in Apache Struts</a>, a Java-building framework. This flaw, dubbed CVE-2017-9805, was reported publicly last week after being patched in July, and security researchers found it allowed hackers to remotely execute code on businesses' networks.</p><p>With Equifax having been hacked in May, the Apache Software Foundation <a href="https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax">issued a rebuttal of the claim</a> over the weekend, saying the breach referred to by Quartz was identified and patched in July, meaning hackers must have either used an earlier reported flaw on an unpatched Equifax server or discovered a zero-day exploit.</p><p>"At this point in time it is not clear which Struts vulnerability would have been utilized if any," said Ren Gielen, VP for Apache Struts.</p><p><em><a href="https://qz.com/1073221/the-hackers-who-broke-into-equifax-exploited-a-nine-year-old-security-flaw">Quartz</a></em> has since updated its article to claim the bug may have been one reported back in March, rather than September.</p><p><strong>08/09/2017: Credit agency Equifax hit by major data breach</strong></p><p>Credit check agency Equifax has fallen victim to a major data breach, which has affected 143 million customers in the US and an undisclosed number in the UK and Canada.</p><p>The attack took place between mid-May and July, according to a statement, with the company discovering the breach on 29 July. A public statement has only just been made, however.</p><p>According to the company, the intrusion was made via "a US website application vulnerability to gain access to certain files".</p><p>"The company has found no evidence of unauthorized activity on Equifax's core consumer or commercial credit reporting databases," the organisation said.</p><p>That doesn't mean the breach is insignificant, though, with information on US customers including social security numbers, dates of birth, addresses and driver's license numbers all being stolen. Additionally, some 209,000 customers had their credit card numbers stolen and 182,000 had dispute documents with personally identifiable information accessed.</p><p>It's unclear at this time whether or not the information taken was encrypted or not, nor who the perpetrators may be.</p><p><em>IT Pro</em> has contacted Equifax in the UK to find out how many customers are affected and the nature of the breach here, as well as to clarify the encryption question, but hadn't received a response at the time of publication.</p><p>The Information Commissioner's Office takes a hard line on data breaches but it nevertheless willing to lend its aid. </p><p>"Reports of a significant data loss at US-based Equifax and the potential impact on some UK citizens gives us cause for concern. We are already in direct contact with Equifax to establish the facts including how many people in the UK have been affected and what kind of personal data may have been compromised," said ICO Deputy Commissioner James Dipple-Johnstone. </p><p>"We will be advising Equifax to alert affected UK customers at the earliest opportunity.</p><p>"In cyber attack cases that cross borders the ICO is committed to working with relevant overseas authorities on behalf of UK citizens."</p><p>The company has set up a dedicated website, www.equifaxsecurity2017.com for US customers to find out if they've been affected by the hack.</p><p>For UK customers, there's currently no site or specific advice available from the agency.</p><p>Security analyst Graham Cluley told <em>IT Pro</em>: "This isn't a case of 'change your passwords'. You don't have the option of changing your name, date of birth, social security number and other personal information.</p><p>"The cruel irony of millions of identities being stolen from an organisation that offers identity theft monitoring isn't lost on anyone. This will be very hard for Equifax to live down."</p><p>He added: "My advice for companies who don't want to find themselves in similar hot water is to 'hack themselves before someone hacks you'. Find the weaknesses and vulnerabilities by conducting your own penetration tests, as it may protect your company prevent you putting others at risk."</p><p>Quocirca analyst Clive Longbottom largely agreed with Cluley's sentiments.</p><p>"This is a real bad one for Equifax. The PII that has leaked includes social security numbers, addresses, names and so on the sort of information that forms the basis for criminals to create a false identity.</p><p>"If it also includes the rest of a person's Equifax data banks, loans, credit card details, for example, then it puts the people concerned in a very bad place," he told <em>IT Pro. "T</em>his is not a username/password issue: there is not much that an individual can do on this."</p><p>"To leave a month and a bit between finding out and disclosure is pretty unforgivable in this case," he added.</p><p>In his analysis of the hack, security researcher Brian Krebs <a href="https://krebsonsecurity.com/2017/09/breach-at-equifax-may-impact-143m-americans/#more-40626">said</a>: "That the intruders were able to access such a large amount of sensitive consumer data via a vulnerability in the company's Web site suggests Equifax may have fallen behind in applying security updates to its Internet-facing Web applications.</p><p>"Although the attackers could have exploited an unknown flaw in those applications, I would fully expect Equifax to highlight this fact if it were true if for no other reason than doing so might make them less culpable and appear as though this was a crime which could have been perpetrated against any company running said Web applications."</p><p>He also pointed out that the company was until very recently looking for a vice president of cybersecurity a role equivalent to a CISO according to Equifax and suggested this may have been a contributing factor to web applications potentially being left unpatched.</p><p><em>Main image credit: Bigstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 30% of CEOs have had their credentials leaked ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/29810/30-of-ceos-have-had-their-credentials-leaked</link>
                                                                            <description>
                            <![CDATA[ Username and password re-use potentially puts corporate information at risk - study ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6s7mtHZDnqCHjhNxDeufsx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/K2Aut2t2RfngjyUyX28mET-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 25 Oct 2017 09:51:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/K2Aut2t2RfngjyUyX28mET-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[stressed man]]></media:description>                                                            <media:text><![CDATA[stressed man]]></media:text>
                                <media:title type="plain"><![CDATA[stressed man]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/K2Aut2t2RfngjyUyX28mET-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Almost one in three CEOs have had their usernames and passwords leaked as part of a data breach, new figures have shown.</p><p>Infosec company F-Secure analysed the known email addresses of more than 200 CEOs from top businesses across ten countries, comparing these details to leaked spam lists and account databases distributed by hackers.</p><p>It found that 30% of CEOs had their password leaked when a service they had signed up for with their corporate account fell victim to a breach.</p><p>The biggest cause of this was professional networking service LinkedIn, which was linked to 53% of the leaked accounts F-Secure analysed. Hackers infiltrated the service back in 2012, then last year <a href="https://www.itpro.com/security/26572/117m-linkedin-account-details-for-sale" target="_blank" data-original-url="https://www.itpro.com/security/26572/117m-linkedin-account-details-for-sale">released the account details of 117 million people</a>.</p><p>Next on the list was Dropbox, which 18% of CEOs had signed up to. F-Secure did, however, point out the caveat that someone else could have used a CEO's email address to attempt to sign up for a service.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach" data-original-url="/security/28810/how-to-react-to-a-data-breach">Data breach response: How to react when your business gets hit</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/22197/how-secure-is-your-password" data-original-url="/security/22197/how-secure-is-your-password">How secure is your password?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/26638/reddit-resets-100000-passwords-in-wake-of-linkedin-hack" data-original-url="/security/26638/reddit-resets-100000-passwords-in-wake-of-linkedin-hack">Reddit resets 100,000 passwords in wake of LinkedIn hack</a></p></div></div><p>The issue of password re-use - where people use the same login details for multiple services - means that CEOs may need to change the passwords for other services than those their email addresses were leaked by.</p><p>For instance, hackers could try CEOs' credentials leaked in the LinkedIn and Dropbox breaches to attempt to gain access to sensitive corporate information through credential re-use attacks.</p><p>"This study once again underscores the importance of proper password hygiene," said F-Secure CISO Erka Koivunen. "The CEO's credentials may have leaked even when they have done nothing wrong.</p><p>"We can assume that many of the services we've created an account in have already been compromised and the old passwords are out there on the internet, just waiting for targeted, motivated attackers to try them against other services."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach" data-original-url="/security/28810/how-to-react-to-a-data-breach">Data breach response: How to react when your business gets hit</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/22197/how-secure-is-your-password" data-original-url="/security/22197/how-secure-is-your-password">How secure is your password?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/26638/reddit-resets-100000-passwords-in-wake-of-linkedin-hack" data-original-url="/security/26638/reddit-resets-100000-passwords-in-wake-of-linkedin-hack">Reddit resets 100,000 passwords in wake of LinkedIn hack</a></p></div></div><p>In addition to this, more than 80% of CEOs were found to have had personal information - including email addresses, physical addresses, phone numbers and dates of birth - exposed via leaked marketing databases and spam lists.</p><p>In fact, less than one in five CEOs had no leaks whatsoever associated with their email address.</p><p>On the other hand, Koivunen also pointed out that signing up to services with a privately-controlled email account may not necessarily be any more secure.</p><p>"When using a private email, a personal phone number or a home address to register for a service that the CEO uses to conduct official business, the CEO effectively denies the company's IT, communications, IPR, legal, and security teams a chance to protect the credentials, monitor their misuse or attempts to compromise them and makes it nearly impossible to recover them later," he said.</p><p>"To an attacker, a CEO who uses private email to register for a service they use in an official capacity spells a loner - someone who goes it alone and doesn't bother to rely on his/her staff to provide protection."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Plastic surgery clinic hit by hackers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/29801/plastic-surgery-clinic-hit-by-hackers</link>
                                                                            <description>
                            <![CDATA[ Dark Overlord hackers steal data from London Bridge Plastic Surgery clinic ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">duVzNKnyup32nbgLiUXNPF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ipj9hW5ZqpWsFkggNe2ZH9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Oct 2017 14:11:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ipj9hW5ZqpWsFkggNe2ZH9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ipj9hW5ZqpWsFkggNe2ZH9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A London-based plastic surgery clinic has been hit by hackers, potentially leaking sensitive patient data online.</p><p>The London Bridge Plastic Surgery which, despite the name, is based in Marylebone admitted it had been hit by an attack, but couldn't yet say what data had been leaked.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/innovation-at-work/29792/the-truth-about-hacking" data-original-url="/security/innovation-at-work/29792/the-truth-about-hacking">The truth about hacking</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27288/canadian-pleads-guilty-to-yahoo-hack" data-original-url="/security/27288/canadian-pleads-guilty-to-yahoo-hack">Canadian pleads guilty to Yahoo hack</a></p></div></div><p>"We can confirm that the Clinic has been the victim of a cyber attack," the company said in a statement. "We took measures to block the attack immediately in order to protect patient information and we informed the Metropolitan Police who launched an investigation."</p><p>"Regrettably, following investigations by our IT experts and the police, we believe that our security was breached and that data has been stolen," the statement added. "We are still working to establish exactly what data has been compromised."</p><p>The clinic said it was "deeply saddened" that its security was breached, claiming it used "market leading technology" and updated systems daily.</p><p>A report on the <a href="https://www.thedailybeast.com/hackers-steal-photos-from-plastic-surgeon-to-the-stars-claim-they-include-royals">Daily Beast</a> identified the hackers as a group called The Dark Overlord, noting they often used extortion against their victims. The hackers claimed to have stolen terabytes of data and graphic photos of famous patients, including "royal families".</p><p>The clinic has swathes of famous patients, including Katie Price who posted on Instagram photos of her own surgery there last month, suggesting not everyone undergoing such work is necessarily embarrassed by it. However, the Daily Beast report suggested sensitive photos had been leaked and could be posted online. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US security secrets stolen in Russian NSA hack: reports ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-leakage/29651/us-security-secrets-stolen-in-russian-nsa-hack-reports</link>
                                                                            <description>
                            <![CDATA[ Hacking tools allegedly snatched when worker loaded them onto home computer ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4pLoUkho22dYB8ArKEwDHX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Oct 2017 09:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NSA data]]></media:description>                                                            <media:text><![CDATA[NSA data]]></media:text>
                                <media:title type="plain"><![CDATA[NSA data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Russian state-sponsored hackers stole highly classified US cyber security information from the NSA in 2015, it has been claimed.</p><p>According reports from the <em><a href="https://www.wsj.com/articles/russian-hackers-stole-nsa-data-on-u-s-cyber-defense-1507222108" target="_blank">Wall Street Journal</a></em> and <em><a href="https://www.washingtonpost.com/world/national-security/russian-government-hackers-exploited-antivirus-software-to-steal-us-cyber-capabilities/2017/10/05/a01bf546-a9fc-11e7-92d1-58c702d2d975_story.html?hpid=hp_hp-more-top-stories-2_nsahack-740pm%3Ahomepage%2Fstory&utm_term=.0d3f8ddd0355" target="_blank">Washington Post</a></em>, the breach occurred when a person working in the US spy agency's "elite hacking unit" Tailored Access Operations (TAO) loaded the information onto their home computer.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29234/shadow-broker-exploit-dumps-five-million-cyber-attacks" data-original-url="/security/29234/shadow-broker-exploit-dumps-five-million-cyber-attacks">Shadow Broker exploit dumps five million cyber attacks</a></p></div></div><p>TAO is the division of the NSA that "develops tools to penetrate computers overseas to gather foreign intelligence", according to the <em>Washington Post's</em> sources. In particular, the information taken by the person involved included hacking tools that were being developed to replace those considered compromised in the Snowden leaks.</p><p>It's currently unclear if the individual was an independent contractor, as claimed by the <em>WSJ</em>, or an employee, as claimed by the <em>Washington Post</em>, but they are unified in their claim that Kaspersky Lab antivirus software installed on the individual's computer was used as the conduit to identify and access the material.</p><p>Kaspersky Lab has hit back at the allegations, reiterating it "does not have inappropriate ties to any government, including Russia, and the only conclusion seems to be that Kaspersky Lab is caught in the middle of a geopolitical fight".</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/916016575853064193"></a></p></blockquote><div class="see-more__filter"></div></div><p>The statement also hints at what some independent security researchers had speculated that its software detected the programmes brought home by the individual and classified them as threats, uploading their signatures and other information to its database of threats.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/915989588690182145"></a></p></blockquote><div class="see-more__filter"></div></div><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/915990527509762050"></a></p></blockquote><div class="see-more__filter"></div></div><p>The <em>Washington Post</em> claims the incident, which resulted in the person being removed from their post in November 2015, is still under investigation.</p><p>This is the latest in a series of embarrassing breaches for the NSA. While the leaks from Edward Snowden in May 2013 may be the most famous, another contractor Harold Martin was arrested last year in relation to a separate 2013 breach. Then, in 2016, hacking group Shadow Brokers stole a vast cache of hacking tools, once again linked to TAO, from the NSA and leaked them to the public.</p><p>These latest reports haven't been confirmed by the NSA, however, with the agency telling <em><a href="https://www.reuters.com/article/us-usa-cyber-nsa/russian-hackers-stole-u-s-cyber-secrets-from-nsa-media-reports-idUSKBN1CA2DO" target="_blank">Reuters</a></em>: "[We] never to comment on our affiliates or personnel issues."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Nottingham County Council fined £70,000 for data leak ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/29379/nottingham-county-council-fined-70000-for-data-leak</link>
                                                                            <description>
                            <![CDATA[ The data of 3,000 vulnerable people was accessible through Google ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5KTpmcudMKFhTeeuACXNUy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/R6QraVRxtZD28vnE3pNARK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Sep 2017 07:46:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/R6QraVRxtZD28vnE3pNARK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Series of locks on binary code with one unlocked]]></media:description>                                                            <media:text><![CDATA[Series of locks on binary code with one unlocked]]></media:text>
                                <media:title type="plain"><![CDATA[Series of locks on binary code with one unlocked]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/R6QraVRxtZD28vnE3pNARK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The ICO has hit Nottingham County Council with a 70,000 fine for failing to safeguard its citizens' data, which led to anyone being able to view the information online.</p><p>The problem was exposed when a member of the public was able to read the data online stored in the council's Home Care Allocation System (HCAS) following a Google search. Nottingham County Council didn't implement any kind of security to stop people being able to access files, such as a login.</p><p>The data, which is thought to have been accessible for over five years, held details on whether disabled and elderly people were in hospital and included the gender, addresses, postcodes and care requirements of the individuals. The concern was that criminals could access the data and use the information to break into peoples' homes while they were away.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29205/ico-fines-talktalk-100k-for-data-breach" data-original-url="/security/29205/ico-fines-talktalk-100k-for-data-breach">ICO fines TalkTalk £100k for data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/29092/ico-fines-moneysupermarket-80k-for-spamming-customers" data-original-url="/data-protection/29092/ico-fines-moneysupermarket-80k-for-spamming-customers">ICO fines MoneySuperMarket £80k for spamming customers</a></p></div></div><p>"This was a serious and prolonged breach of the law. For no good reason, the council overlooked the need to put robust measures in place to protect people's personal information, despite having the financial and staffing resources available," ICO Head of Enforcement Steve Eckersley said.</p><p>"Given the sensitive nature of the personal data and the vulnerability of the people involved, this was totally unacceptable and inexcusable. Organisations need to understand that they have to treat the security of data as seriously as they take the security of their premises or their finances."</p><p>The breach was first reported in June 2016, when it contained a directory of 81 service users and the data of more than 3,000 people. Not included in the data was the patients' names, although the ICO said it would be easy enough for people to find this information out from other sources if they wanted to.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Canadian university loses $11.8m in email phishing scam ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/29367/canadian-university-loses-118m-in-email-phishing-scam</link>
                                                                            <description>
                            <![CDATA[ Employees at MacEwan University were led to believe a client was changing account details ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9Wgeuwm374KevhqfJo8eHc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2imj6aJdYQvrFHsXsKTVp8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Sep 2017 08:59:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2imj6aJdYQvrFHsXsKTVp8-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2imj6aJdYQvrFHsXsKTVp8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A Canadian university has lost almost C$12 million after a phishing scam tricked staff into paying money into a fraudulent bank account.</p><p>Employees at MacEwan University in Alberta received emails that suggested one of its main clients was changing its banking details and that future funds should be routed to the new account.</p><p>The university said the change resulted in C$11.8 (7.5 million) being sent to the account thought to have belonged to the vendor, but realised soon after that it had been a phishing scam.</p><p>The majority of the funds has been traced to accounts in Canada and Hong Kong, according to a <a href="http://www.macewan.ca/wcm/MacEwanNews/PHISHING_ATTACK" target="_blank">statement</a> released by the university on Thursday. It added that the suspected accounts had been frozen pending civil action to recover the funds.</p><p>"There is never a good time for something like this to happen," said university spokesperson David Beharry. "But as our students come back to start the new academic year, we want to assure them and the community that our IT systems were not compromised during this incident."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="/security/29093/what-is-phishing">What is phishing?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29300/cryptocurrency-phishing-scams-cost-users-225m-this-year" data-original-url="/security/29300/cryptocurrency-phishing-scams-cost-users-225m-this-year">Cryptocurrency phishing scams cost users $225m this year</a></p></div></div><p>Personal and financial information, including any details relating to recent transactions, were unaffected by the scam and remain secure, according to the statement.</p><p>The university said it is working with the Edmonton Police Service, as well as law enforcement agencies in Montreal, Hong Kong, and security departments of the banks affected.</p><p>Although controls have now been put in place to prevent a similar incident in the future, the university said it had identified that safeguards around the changing of banking details had been inadequate, and that numerous opportunities to detect the fraud had been missed.</p><p><a href="https://www.itpro.com/security/27096/employees-still-falling-for-phishing-scams" target="_blank" data-original-url="https://www.itpro.com/security/27096/employees-still-falling-for-phishing-scams">Research conducted last</a> year found that almost a third of employees were still falling for phishing scams of this kind, which is particularly concerning given that only one malicious email needs to bypass detection to cause serious damage to an organisation.</p><p>The university said it is working to ensure that the incident does not impact the academic and business operations of the institute, and that further updates will be released in the coming weeks.</p><p><a href="https://commons.wikimedia.org/wiki/File:Grant_MacEwan_North_Towers_Edmonton_Alberta_Canada_02.jpg" target="_blank">Photo</a> by WinterE229 / CC BY 2.0</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>