Legal News, Vendor News
March 28, 2025
449 views 0 secs 0

British company Advanced fined £3m by privacy regulator over ransomware attack

The Record reports: Advanced, a business that provides IT services to numerous healthcare providers in the United Kingdom, has been fined £3.1 million (about $4 million) by the country’s privacy regulator over a ransomware attack in 2022. The company had initially faced a fine of £6 million before coming to a voluntary settlement with the Information Commissioner’s […]

Data Breach News, News, Vendor News
March 18, 2025
1096 views 2 mins 0

Over 50 U.S. school districts impacted in retirement service provider breach

In December 2024, EdTech vendor PowerSchool was hit with a major attack that reportedly affected more than 60 million students and employees throughout the country. But that wasn’t the only major attack affecting an education sector vendor in December. Teiss reports that a retirement services vendor was also the victim of an attack: About 50 […]

Legal News, News, Vendor News
March 16, 2025
1013 views 2 mins 0

TRICARE Contractor Resolves $11M False Claims Act Liability for Known Cybersecurity Violations

Tycko & Zavareei Whistleblower Practice Group writes: February 2025 saw an important False Claims Act settlement involving allegations of known cybersecurity failures by Health Net Federal Services Inc. (HNFS), a government contractor that provides TRICARE healthcare management services to active duty military members and their families. HNFS as well as its parent corporation Centene agreed […]

Vendor News, Data Breach News
February 04, 2025
1105 views 29 secs 0

Deloitte providing $5M to cover expenses related to RI data breach — and that’s just part of what they’ll pay

There is another update to Rhode Island’s incident response to a cyberattack last year that involved their vendor, Deloitte. Data from the state’s portal called RIBridges was acquired and leaked by threat actors when their ransom demands were not paid. Now WPRI reports: An outside consulting group will provide Rhode Island with millions in funding […]

Vulnerabilities, Vendor News
January 24, 2025
284 views 4 secs 0

Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug in Meeting Management

Another day, another critical patch. The Register reports: Cisco has pushed a patch for a critical, 9.9-rated vulnerability in its Meeting Management tool that could allow a remote, authenticated attacker with low privileges to escalate to administrator on affected devices. Cisco Meeting Management is the management software for the tech giant’s on-premises video meeting platform. […]

Commentaries and Analyses, Vendor News
December 03, 2024
1199 views 12 secs 0

Tips for Vacation Rental, Property Mgmt. Businesses Facing Vendor Cybersecurity Risk

Lawyers at JacksonLewis write: Last year, as reported on the Maine Attorney General’s Office website, Resort Data Processing (RDP) experienced a data breach affecting over 60,000 individuals caused by a “SQL injection vulnerability which allowed an unauthorized third party to redirect payment card information from in-process transactions on our RDP’s clients’ on-premises Internet Reservation Module (“IRM”) […]

Data Breach News, Vendor News
November 12, 2024
864 views 8 secs 0

Form I-9 Compliance updates its breach report once again; number affected keeps climbing

Employee eligibility verification solutions provider Form I-9 Compliance suffered a data breach on February 5, 2024. Its impact is way, waaaaay bigger than initially reported. Security Week reports: In late May, the company started informing customers that someone had gained unauthorized access to its network in early February. The intrusion was detected on April 12 […]