LATEST POST
Patients Allege Home Delivery Pharmacy Failed Timely Notification of Data Breach
Pharmacy Times reports: In January 2021, a nationwide mail-order pharmacy located in Massachusetts experienced a data breach. The pharmacy discovered the breach in May 2021 and investigated to determine its scope. Personally identifiable information (PII), including names and Social Security numbers for more than 75,000 customers, was breached. In February 2022, 9 months after the […]
U.S. seeks extradition of notorious hacker “Intelbroker” from France
When French law enforcement announced the arrest of four individuals alleged to be part of ShinyHunters, they also noted that a fifth individual, a British national known as “IntelBroker,” was arrested in France in February and detained. Hours later, the U.S. Attorney’s Office for the Southern District of New York announced that Intelbroker, whose real […]
France announces arrest of ShinyHunters members
Multiple French news outlets are reporting that four men in their 20’s, alleged to be members of the ShinyHunters hacking group, have been arrested. Their real names have not been released publicly, but their online monikers were “ShinyHunters,” “Noct,” “Depressed,” and “Hollow.” French law enforcement has not issued any official statement confirming any arrests or […]
New York State Department of Financial Services Issues Guidance on Cybersecurity, Sanctions, and Virtual Currency Following Escalation of Iran Conflict
From Covington and Burling: Read more at Inside Privacy.
Critical Fortinet Vulnerabilities Exploited by the Qilin Ransomware Group
NetSec reports: The Qilin ransomware group has been noticed exploiting two critical vulnerabilities present in FortiOS/FortiProxy equipment. Although the group seems to be focusing on countries with Spanish language, it is likely that attacks exploiting these vulnerabilities will spread to other countries. The Qilin ransomware-as-a-service (RaaS) operation appeared in August 2022, known first as Agenda. Although it is not […]
Texas Enacts Liability Shield From Punitive Damages for Certain Small Businesses That Adopt Cybersecurity Programs
From attorneys at Jackson Lewis: On June 20, 2025, Texas Governor Greg Abbott signed SB 2610 into law, joining a growing number of states that aim to incentivize sound cybersecurity practices through legislative safe harbors. Modeled on laws in states like Ohio and Utah, the new Texas statute provides that certain businesses that “demonstrate[] that at the time […]
Data of more than 740,000 stolen in ransomware attack on Michigan hospital network
The Record reports: Ransomware hackers stole the Social Security numbers and health insurance information for more than 740,000 people during an attack on a prominent Michigan hospital network. McLaren Health Care filed documents on Friday concerning a ransomware attack that took place in August 2024 — the second cyber incident to impact the healthcare giant in 12 months. The […]
AT&T to pay $177 million in data breach settlement affecting 109 million customers
Reuters reports: A U.S. judge granted preliminary approval on Friday to a $177-million settlement that resolves lawsuits against AT&T T.N over breaches in 2024 that exposed personal information belonging to tens of millions of the telecom company’s customers. U.S. District Judge Ada Brown in Dallas said in a ruling that the class-action settlement was fair and reasonable. […]
