Security News

Why pseudonymisation is important to protect personal data?
2021-02-04 04:00

The European Union Agency for Cybersecurity released its report on pseudonymisation for personal data protection, providing a technical analysis of cybersecurity measures in personal data protection and privacy. While not a new process, pseudonymisation came into the spotlight in 2018 with the enforcement of GDPR, which references it as a security and data protection by design mechanism.

Capcom Says Personal Data of Thousands More Stolen in Ransomware Attack
2021-01-14 13:19

Video game giant Capcom this week revealed that thousands more people than initially believed had their personal information stolen in a ransomware attack in November 2020. On November 4, the game maker announced that it detected unauthorized access to its network, and two weeks later confirmed that the attackers accessed the personal information of employees, as well as financial information, sales reports, and other business data.

Police Arrest 21 WeLeakInfo Customers Who Bought Breached Personal Data
2020-12-27 22:15

21 people have been arrested across the UK as part of a nationwide cyber crackdown targeting customers of WeLeakInfo[. A now-defunct online service that had been previously selling access to data hacked from other websites.

How to protect your personal data from being sold on the Dark Web
2020-12-01 21:28

Once your personal data is up for sale, buyers can use it for financial gain or for doxing, a practice where malicious actors publicly reveal private information about you for all to see. In a blog post published Tuesday, security provider Kaspersky looks at the sale of personal data on the Dark Web and offers advice on how to protect your own data.

Fitbit Spyware Steals Personal Data via Watch Face
2020-10-09 18:58

Kev Breen, director of cyber threat research for Immersive Labs, created a proof-of-concept for just that scenario, after realizing that Fitbit devices are loaded with sensitive personal data. Breen's efforts resulted in a malicious watch face, which he was then able to make available through the Fitbit Gallery.

Phishing attack spoofs IRS COVID-19 relief to steal personal data
2020-10-07 13:31

In this attack, the initial email promised an important update on the recipient's COVID relief funds to be disbursed to the person's address. The initial email snuck past Microsoft 365 email security because it didn't follow the usual traits of traditional phishing attacks, according to Armorblox.

Las Vegas Students’ Personal Data Leaked, Post-Ransomware Attack
2020-09-29 15:33

Personal information for students in the Clark County School District, which includes Las Vegas, has reportedly turned up on an underground forum, following a ransomware attack that researchers say was carried out by the Maze gang. In early September, the Associated Press reported that the district was crippled during its first week of school thanks to a ransomware attack, potentially exposing personal information of employees, including names and Social Security numbers.

Personal data from Experian on 40% of South Africa's population has been bundled onto a file-sharing website
2020-09-14 17:00

Personal data on 24 million South Africans, wrongfully sold by Experian to a person it claimed had "Pretended" to represent a "Legitimate client", is now not only circulating on the dark web - it's also on clearweb file-sharing sites, according to reports. Despite assurances from Experian in August that it had obtained an Anton Piller court order - a type of search warrant in legal proceedings - to seize and destroy the data it haplessly passed on, 40 per cent of South Africa's population is now living in the knowledge that any random bod browsing Swiss file-sharing site WeSendIt could have freely downloaded their personal data.

Dataguise Personal Data Discovery and Protection software simplifies security and privacy processes
2020-09-02 02:00

Dataguise announced a patent-pending method of projecting unique data counts that enables organizations to report the impact of a data breach faster and more accurately than ever before. This capability comes in the latest release of the company's Personal Data Discovery and Protection software, continuing its tradition of helping organizations manage risk and costs as they store and use personal data to drive business value.

Southern Water customers could view others' personal data by tweaking URL parameters
2020-08-28 11:40

Southern Water - British supplier of the liquid of life - botched its internal Sharepoint implementation so badly that a customer was able to view other people's account details. Reg reader Chris H discovered that the way Southern Water had set up Sharepoint to host customer information as a "Your account" style section of their website exposed URLs that could be tweaked to view other people's account information.