|
|
|
|
|
|
*
FBI, Congress Considers National Data-Breach Law : Thu 29 Oct 2009
During a cybersecurity discussion held Wednesday in Washington D.C., Jeffrey Troy, chief of the FBI's Cyber Criminal Section, said that law enforcement agencies could get a better grip on fighting the surge of cybercrimes if businesses were legally required to report data breaches to potential victims.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
*
Don't Relax On The Breach : Fri 9 Oct 2009
Data breaches that don't involve financial information sound relatively benign. But Paul Royal recently discovered that these kinds of breaches are often part of a multi-step attack aimed at stealing personal financial data.
|
|
|
|
|
|
|
|
|
*
Panel to vote on data privacy measure : Tue 29 Sep 2009
The House Energy and Commerce Committee is slated to vote Wednesday on legislation that would require strong security policies from firms that collect and store individuals' sensitive information and provide for nationwide notification in the event of a data breach.
|
|
|
*
UNC data breach exposes 163,000 SSNs : Fri 25 Sep 2009
The University of North Carolina at Chapel Hill on Friday began notifying about 163,000 women about the potential compromise of their Social Security numbers and other personal information after a hacker breached a system containing the data.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
*
HIPAA Breach Notice Rules to Take Effect : Wed 2 Sep 2009
The U.S. Department of Health and Human Services (HHS) has issued new regulations requiring health care providers, health plans and other entities covered by the Health Insurance Portability and Accountability Act (HIPAA) to notify individuals when their protcted health information (PHI) is breached.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
*
Electronic Health Records: Facing the Issues : Wed 12 Aug 2009
Over the past decade, electronic transactions have slowly supplanted paper-based systems in many industries. For example, individuals and Wall Street brokerage firms employ electronic trading; federal and state taxpayers increasingly e-file their returns; and attorneys e-file pleadings and federal court documents.
|
|
|
*
Cloud Changes Cost of Attacks : Wed 5 Aug 2009
One of the frustrations with information security is that it's always difficult � if not impossible � to quantify risk. Without the ability to quantify risk, it's often the case that solutions that would mitigate the risk are left unimplemented because there's no way to prove that the risk would turn into a breach, downtime, or other revenue impacting incident.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
*
Weak security opens door to hackers : Mon 6 Jul 2009
Every time you swipe your credit card and wait for the transaction to be approved, sensitive data including your name and account number are ferried from store to bank through computer networks, each step a potential opening for hackers.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
*
DoH blocks data breach database : Fri 12 Hun 2009
The government has blocked proposals for it to collect and publish data on all NHS security breaches, GP can reveal.In a letter to ministers, written last year and released under the Freedom of Information Act, DoH director of IT implementation Richard Jeavons argued that disciplining offences was the 'responsibility of individual organisations'.
|
|
|
*
Hackers going after medical records : Thu 4 Jun 2009
Hackers raided a server at the University of California, Berkeley last fall, stealing everything from Social Security numbers to immunization records in an episode that highlights one danger of moving health information from file cabinets to cyberspace, Forbes reports in a first-person account by one of the 160,000 victims.
|
|
|
*
Password breach at Customs leads to huge revenue loss : Sun 31 May 2009
Theft/unauthorized third-party use of customs officials' password for accessing the computer network (Customs Electronic Data Interchange or EDI) used by both the customs staff and the merchant community is causing loss of revenue, says an internal communication circulated to the offices at the Central Board of Excise and Customs (CBEC).
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
*
HHS Guidance on Data Breaches Describes 'Safe Harbor' : Fri 24 Apr 2009
The Department of Health and Human Services (HHS) issued guidance specifying the technologies and methods that HIPAA covered entities can use to make protected health information (PHI) unusable, unreadable or indecipherable, thereby qualifying for a safe harbor from the new federal breach notification requirement.
|
|
|
|
|
*
Congress Investigating P2P Data Breaches : Wed 22 Apr 2009
A key oversight panel in the House of Representatives said this week that it is re-opening an investigation into the "indavertent sharing" of sensitive government and consumer data through popular peer-to-peer file swapping programs such as BearShare and Limewire.
|
|
|
*
Proposed breach notification rule would affect more health vendors : Mon 20 Apr 2009
Rules proposed by the Federal Trade Commission on April 16 on disclosure of breaches of personal health information would greatly expand the number of companies that would be subject to notifying individuals if their personal health data was exposed because records were lost or stolen, or because a hacker broke into a computer health network.
|
|
|
*
Malware Had a Great Year in 2008 : Sat 18 Apr 2009
The year 2008 saw a huge increase in malicious code threats, and the United States retained the dubious distinction of being the top cyber sore spot, according to Symantec's Internet Security Threat Report for 2008.
|
|
|
*
Federal Trade Commission Issues Proposed PHR Breach Rule : Fri 17 Apr 2009
In compliance with the American Recovery and Reinvestment Act, the Federal Trade Commission has issued a proposed rule that would require personal health record vendors and related groups to notify customers if their identifiable health information is breached, Health Data Management reports.
|
*
The Cost of Data Breaches : Fri 10 Apr 2009
The total cost to a company of recovering from a single data breach reached $6.6 million in 2008, an increase of 4.5 percent from the $6.3 million cost in 2007, according to a recent benchmark study conducted by the Ponemon Institute and sponsored by PGP Corp.
|
*
Once more unto the breach : Fri 10 Apr 2009
As the country's top counter-terrorism officer resigns over photographs of sensitive papers, Steve Pratt blunders into the world of stolen laptops, missing memory sticks and top secrets exposed in public.
|
|
|
|
|
*
Rise of the 'bots' : Tue 7 Apr 2009
Getting hacked is like having your computer turn traitor on you, spying on everything you do and shipping your secrets to identity thieves.
|
|
|
*
Experts Warn of Heightened Data Security Risks as Economic Crisis Continues : Mon 6 Apr 2009
The economic crisis presents new data security risks for businesses worldwide, yet many are cutting back on protective measures due to tightening budgets, according to data security experts from Kroll's Fraud Solutions practice. The irony, advises Kroll, is that it's more important than ever for businesses to stay committed to the incident response plans and security measures needed to protect sensitive data.
|
|
|
|
|
|
|
|
|
|
|
*
Employees Highlighted for Data Loss : Thu 19 Mar 2009
According to a data security and encryption survey carried out by independent consulting and technical services company IT Force, 47.8% of IT decision makers consider their employees to be the biggest threat to sensitive data in their organisations.
|
|
|
|
|
|
|
|
|
|
|
*
California Looks to Expand Data Breach Notification Law : Fri 6 Mar 2009
Simitian, speaking at the Security Breach Notification symposium in Berkeley, said the new legislation would force organizations that are breached to admit the extent of the compromise, and to provide consumers with enough information to determine on their own whether they face a risk of harm.
|
|
|
|
|
*
File-sharing networks used to uncover thousands of medical records : Fri 27 Feb 2009
Just days after President Obama signed a law giving billions of dollars to develop electronic health records, a university technology professor submitted a paper showing that he was able to uncover tens of thousands of medical files containing names, addresses and Social Security numbers for patients seeking treatment for conditions ranging from AIDS to mental health problems.
|
*
Law requires health data breach notifications : Fri 27 Feb 2009
The recently enacted economic stimulus law includes new requirements for how companies must notify people of breaches to their protected health information. Some experts say the rules could lead to federal breach notification requirements for other types of data.
|
|
|
|
|
|
|
|
|
|
|
*
What are the security threats? : Wed 25 Feb 2009
"Security", as the first article in this series points out, can always be found near the top of the list of concerns of every IT manager and IT director. Unfortunately the same subject can also manage to not quite make it onto the more important list of things to do something about now.
|
|
|
*
FAA breach heightens cybersecurity concerns : Mon 23 Feb 2009
The Federal Aviation Administration was doing such a good job at protecting data in its computer systems that the Office of Management and Budget chose it in January to be one of four agencies to guide other federal agencies in their cybersecurity efforts.
|
|
|
|
|
*
Recycled Phones Found to Still Have Your Data : Sun 22 Feb 2009
Millions of cell phones are sold every year. Many are lost, stolen, millions more end up on eBay, recycled or tossed in the trash. Many of these phones still have enough data on them to commit identity theft or, in the wrong hands, make your life miserable.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
*
Keep your eyes open : Mon 16 Feb 2009
In times like these when you have no job or no more furniture to sell, what do you do? Sell sensitive information from your company, if you are the unscrupulous kind!
|
|
|
*
Kaspersky site hacked to exposed sensitive data : Sun 8 Feb 2009
I can just imagine the howls of laughter and high fives (virtual ones of course) that must have been going on as hackers managed to crack the security of Kaspersky's website this weekend. Apparently the breach cut deep into the company's database and provided access to customer information, activation codes, product bug lists and other admin related information.
|
|
|
*
Fannie Mae: 1 - Pissed off ex-employee: 0 : Thu 29 Jan 2009
According to the FBI affidavit (pdf) even though he was fired Unix engineer Rajendrasinh Babubha Makwana, 35, still had access to his computer access. Using that access Makwana wrote a logic bomb and planted it at the tail end of a legitimate script that was run every day on the Fanny Mae servers.
|
|
|
|
|
|
|
*
ITA 2000 Amendments - Impact on IT Companies : Wed 27 Jan 2009
The amendments passed on December 22/23 by the Parliament to the eight year old ITA 2000, has been watched keenly by IT and ITES companies. Many are happy since the resulting ITA 2000-Version 2008 which we prefer to call ITA 2008-has tried to address the demand for Data Protection.
|
|
|
|
|
|
|
|
|
*
Card-data theft puts legislation in spotlight : Sun 25 Jan 2009
Debie Keesee got the bad news four days before it hit the financial press Tuesday: Sophisticated hackers had intercepted vast streams of unencrypted data sent by one of the nation's largest bank-card processors, potentially exposing millions of consumers to fraud.
|
|
|
|
|
|
|
|
|
|
|
*
JournalSpace data loss terminal : Wed 7 Jan 2009
The folks behind blogging site JournalSpace.com have learned the hard way that RAID is not a substitute for backups, with the news that a disgruntled ex-employee has taken down the site completely.
|
|
|
|
|
|
|
*
Auditor: IRS still vulnerable to cyber breaches : Mon 19 Jan 2009
The US Internal Revenue Service (IRS) remains exposed to a wide range of cybersecurity problems, while the agency has fixed less than half of the problems identified in a November audit, according to a recent report by the US Government Accountability Office.
|
|
|
|
|
|
|
|
|
|
|
|
|
*
Crime, New Technologies, Thwart Security Progress : Tue 9 Dec 2008
Even as organizations invest millions of dollars in security mechanisms meant to defend them against potential threats, business initiatives such as outsourcing, combined with the seemingly unstoppable onslaught of cyber-crime, will continue make it hard to prevent attacks targeting electronic data in the coming year, according to a new research report.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
*
Mobile Handsets Becoming A 'Smoking Gun' : Mon 1 Dec 2008
As handheld devices gain more data features and storage, they also are increasingly becoming a smoking gun in an enterprise data breach, especially when it comes to the insider threat, security experts say. But getting hold of these devices and freezing the evidence on them isn't so easy.
|
*
Protecting Enterprise Data from Employees : Wed 3 Dec 2008
ID Analytics, a provider of on-demand identity intelligence, conducted an internal data theft study that provides an analysis of the behavior patterns associated with the misuse of identities stolen from the workplace by employees. The study's findings also provide an understanding of the harm resulting from an internal versus external data breach.
|
|
|
*
Massachusetts Passes Security Law : Sun 30 Nov 2008
The state law requires businesses that �own, license, store or maintain personal information� on customers to encrypt that data, especially on portable devices such as laptops. That responsibility is extended from the primary business to contractors, such as telemarketing firms, and it extends to transmissions on wireless devices such as BlackBerries.
|
|
|
*
The Corporate Data Cover-Up : Fri 28 Nov 2008
Data hackers are silently infesting corporate organisations and creating an invisible battlefield, but so many Boards of Directors will not admit to their vulnerabilities and weaknesses.
|
*
Data abuse is a rapidly growing problem : Thu 27 Nov 2008
Data abuse is a rapidly growing problem in the UK. In all walks of life, in both the private and public sectors, we hear of major security breaches over personal data, and public concern over such breaches is becoming more and more voluble. However, few commentators have highlighted the fact that personal data on the commercial markets is also subject to increasing levels of abuse.
|
*
Banking's data security crisis : Wed 26 Nov 2008
During the past year, banks have lost more of their customers' personal data than ever before.
According to numbers released Nov. 18 by the data breach tracking organization Identity Theft Resource Center, financial institutions were responsible for more than half the 33 million personal records known to be lost in all reported data breaches so far this year, compared with just 7% of known lost records in 2007.
|
|
|
|
|
|
|
|
|
*
Economic Bust, Cybercrime Boom : Wed 19 Nov 2008
The first ripples of a growing wave of cybercrime may be appearing. In the physical world, the connection between declining business and crime is simple enough: As the above-ground economy suffers, the underground economy swells.
|
*
PCI Compliance Coming to You : Wed 19 Nov 2008
Since June of 2008, all merchants accepting credit cards have been required to become PCI-DSS compliant. PCI-DSS is a security standard to help prevent and control loses from businesses losing card holder data, specifically credit card numbers.
|
|
|
*
On paper, a potential risk : Mon 17 Nov 2008
A newly formed group, the Alliance for Secure Business Information, recently released the results of a survey that found that nearly half of data breaches reported by respondents involved paper documents.
|
|
|
|
|
|
|
|
|
*
Poor data-loss prevention practices almost cost Intel a billion : Thu 13 Nov 2008
When it comes to data-loss prevention, good network security can make all the difference, as Intel
and its former employee, Biswamohan Pani, discovered. Pani was indicted by a grand jury last week for allegedly stealing more than $1 billion in Intel's intellectual property after the former design engineer jumped ship to competitor AMD.
|
|
|
*
Express Scripts warns of potential large data breach tied to threat : Thu 5 Nov 2008
St. Louis-based Express Scripts announced that it received a letter from an
unknown source trying to extort money from the company by threatening to expose millions of
the company's patient records. The pharmacy benefit management company said that the letter
included the personal information of 75 members, including their names, dates of birth,
social security numbers, and in some cases, their prescription information.
|
*
N.Y. man indicted for role in data breaches : Tues 4 Nov 2008
A New York man has been charged with providing co-conspirators with a "sniffer"
program for capturing payment card data as it traveled across corporate networks; he is
apparently the latest person to be indicted in connection with data breaches at TJX Companies
Inc. and other major retailers.
|
*
Privacy watchdog slams databases, year of data loss : Thu 30 Oct 2008
The number of data breaches reported to the U.K.'s Information Commissioner's
Office (ICO) has soared to 277 in almost a year, new figures released Wednesday revealed. In
almost 12 months, 80 of those breaches concerned the private sector, 75 within the NHS and
other health bodies, 28 reported by central government, 26 by local authorities and 47 by the
rest of the public sector, among others.
|
*
Crystal IT Offers Optimal IT Security : Tue 28 Oct 2008
Crystal IT ( www.crystalit.us), a provider of comprehensive data loss solutions
redefines data security with the introduction of its Avert(TM)-Access Control, the premier
front-end module for its comprehensive multi-level approach. As many data loss prevention
companies scramble to find a viable solution to handle the unprecedented levels of data
breaches, Crystal IT is moving forward to lead the industry.
|
|
|
|
|
|
|
*
Another Day, Another Data Loss : Sun 12 Oct 2008
Earlier this year the head of Revenue and Customs resigned after his department
lost the details of as many as 15 million child benefit claimants in what was believed
to be the world's biggest ID protection failures.
|
|
|
*
Lost Laptops = Lost Data : Mon 20 Oct 2008
Since the mid 1990s, private sector and
government researchers as well as the media
have tracked not only the growth of the laptop
market but also frequent losses. At the same
time, law enforcement and security professionals
quickly realized that laptop theft was a swift portal
to even more valuable confidential information.
|