Security News

Geico data breach exposed customers' driver's license numbers
2021-04-19 22:27

Car insurance provider Geico has suffered a data breach where threat actors stole the driver's licenses for policyholders for over a month. Geico is the second-largest car insurance company in the United States, with over 17 million policies for more than 28 million vehicles.

Indian Brokerage Firm Upstox Suffers Data Breach Leaking 2.5 Millions Users' Data
2021-04-12 09:04

Online trading and discount brokerage platform Upstox has become the latest Indian company to suffer a security breach of its systems, resulting in the exposure of sensitive information of approximately 2.5 million users on the dark web. Reacting to the development, the company however said it had recently upgraded its security systems following reports of "Unauthorized access into our database" while stressing that users' funds and securities remained protected.

S3 Ep27: Census scammers, beg bounties and data breach fines [Podcast]
2021-04-08 18:16

How scammers copied a government website almost to perfection. What to do about those fake "Bug" hunters who ask for payment for finding "Vulnerabilities" that aren't.

Belden Says Health-Related Information Exposed in Data Breach
2021-04-08 14:19

Specialty networking solutions provider Belden on Wednesday shared an update on the data breach disclosed in November 2020, and said health-related information was also exposed. Belden revealed in November that it had detected a data breach that resulted in the theft of some information pertaining to business partners, as well as current and former employee data.

Too slow! Booking.com fined for not reporting data breach fast enough
2021-04-06 22:22

The Dutch Data Protection Authority - the country's data protection regulator - has fined online travel and hotel booking company Booking.com almost half a million Euros over a data breach. The Dutch Data Protection Authority has imposed a €475,000 fine on Booking.com because the company took too long to report a data breach to the DPA. When the breach occurred, criminals obtained the personal data of over 4,000 customers.

Capital One notifies more clients of SSNs exposed in 2019 data breach
2021-04-02 15:46

US bank Capital One notified additional customers that their Social Security numbers were exposed in a data breach announced in July 2019. The day the breach was disclosed, the Department of Justice arrested and indicted the suspected hacker, former Amazon Web Services employee Paige Thompson, who posted about stealing data on GitHub after infiltrating Capital One's AWS cloud servers.

Ubiquiti Shares Dive After Reportedly Downplaying 'Catastrophic' Data Breach
2021-04-01 14:30

Shares of New York City-based IoT device maker Ubiquiti fell significantly this week following a report claiming that the recently disclosed data breach was "Catastrophic" and that its impact was downplayed. Cybersecurity blogger Brian Krebs reported on Tuesday, March 30, that he learned from someone involved in the response to the breach that Ubiquiti "Massively downplayed" an incident that was actually "Catastrophic," in an effort to minimize impact on its value on the stock market.

Leading Indian fintech platform MobiKwik denies data breach
2021-03-30 15:20

Indian digital financial services platform Mobikwik denies claims that almost 8 TB of data put up for sale was allegedly stolen from its servers. The threat actor who put the allegedly stolen data up for sale also created a search portal to allow anyone to check if their data is included in the stolen data.

FatFace sends controversial data breach email after ransomware attack
2021-03-27 13:41

British clothing brand FatFace has sent a controversial 'confidential' data breach notification to customers after suffering a ransomware attack earlier this year. This week, customers began receiving data breach notifications revealing that the popular lifestyle clothing brand, FatFace, had suffered a data breach after a cyberattack on January 17th, 2021.

Report: US Gov Executive Order to Mandate Data Breach Disclosure
2021-03-26 16:54

A proposed executive order would set new rules on the disclosure of data breaches that also affect United States government agencies, according to a Reuters news report. The report said the executive order, which could be released as soon as the next week, would require software vendors to notify U.S. government customers of cyber-security breaches that also affect them.