Security News

Personal data from Experian on 40% of South Africa's population has been bundled onto a file-sharing website
2020-09-14 17:00

Personal data on 24 million South Africans, wrongfully sold by Experian to a person it claimed had "Pretended" to represent a "Legitimate client", is now not only circulating on the dark web - it's also on clearweb file-sharing sites, according to reports. Despite assurances from Experian in August that it had obtained an Anton Piller court order - a type of search warrant in legal proceedings - to seize and destroy the data it haplessly passed on, 40 per cent of South Africa's population is now living in the knowledge that any random bod browsing Swiss file-sharing site WeSendIt could have freely downloaded their personal data.

Dataguise Personal Data Discovery and Protection software simplifies security and privacy processes
2020-09-02 02:00

Dataguise announced a patent-pending method of projecting unique data counts that enables organizations to report the impact of a data breach faster and more accurately than ever before. This capability comes in the latest release of the company's Personal Data Discovery and Protection software, continuing its tradition of helping organizations manage risk and costs as they store and use personal data to drive business value.

Southern Water customers could view others' personal data by tweaking URL parameters
2020-08-28 11:40

Southern Water - British supplier of the liquid of life - botched its internal Sharepoint implementation so badly that a customer was able to view other people's account details. Reg reader Chris H discovered that the way Southern Water had set up Sharepoint to host customer information as a "Your account" style section of their website exposed URLs that could be tweaked to view other people's account information.

Floating COVID incubation tank becomes data-leaking ransomware rustbucket: Carnival admits crims made off with personal data booty
2020-08-19 09:28

Now the industry's biggest player, Carnival Corporation, has also come down with a case of ransomware. The company on Tuesday issued a regulatory filing [PDF] in which it admitted: "On August 15, 2020, Carnival Corporation and Carnival plc... detected a ransomware attack that accessed and encrypted a portion of one brand's information technology systems. The unauthorized access also included the download of certain of our data files."

Amazon Alexa flaws could have revealed home address and other personal data
2020-08-13 13:06

The flaws could also have helped attackers obtain usernames, phone numbers, voice history, and installed skills, says Check Point Research. Silently installed skills and apps on a user's Alexa account.

Amazon Alexa ‘One-Click’ Attack Can Divulge Personal Data
2020-08-13 10:00

UPDATE. Vulnerabilities in Amazon's Alexa virtual assistant platform could allow attackers to access users' personal information, like home addresses - simply by persuading them to click on a malicious link. Researchers with Check Point found several web application flaws on Amazon Alexa subdomains, including a cross-site scripting flaw and cross-origin resource sharing misconfiguration.

iProov and Evernym partnership empowers people with control over their personal data
2020-08-12 22:30

iProov announced its partnership with self-sovereign identity specialists, Evernym. Evernym is the market leader in SSI, working with over 100 organizations in the technology, government, nonprofit, finance, insurance, communications, and healthcare sectors to issue, accept and verify portable digital identity credentials.

Researchers extract personal data from video conference screenshots
2020-07-14 03:30

Video conference users should not post screen images of Zoom and other video conference sessions on social media, according to Ben-Gurion University of the Negev researchers, who easily identified people from public screenshots of video meetings on Zoom, Microsoft Teams and Google Meet. While there have been many privacy issues associated with video conferencing, the BGU researchers looked at what types of information they could extract from video collage images that were posted online or via social media.

Collabera hacked: IT staffing'n'services giant hit by ransomware, employee personal data stolen
2020-07-14 02:49

Hackers infiltrated Collabera, siphoned off at least some employees' personal information, and infected the US-based IT consultancy giant's systems with ransomware. Collabera identified malware in its network system consistent with a ransomware attack.

Celebrity personal data taken in ransomware attack
2020-05-11 14:48

Rather than simply knocking the law firm out of action temporarily, the ransomware crooks are said to have stolen personal data from a laundry list of celebrity clients, too - allegedly more than 750GB in total including contracts, contact information and "Personal correspondence". In other words, the financial extortion is no longer just a "Kidnap ransom" to get your files back, but also a blackmail demand to stop the crooks leaking your data - or, worse still, your customers' data - to the world.