Texas Medical Liability Trust updates its data breach notification; now provides notification on behalf of almost 60,000 individuals

In March, Texas Medical Liability Trust on behalf of itself and its affiliates, Texas Medical Insurance Company, Physicians Insurance Company, and Lone Star Alliance, Inc., a Risk Retention Group (collectively “TMLT”) filed a breach notification with the Maine Attorney General’s Office. That submission indicated that 625 individuals had been affected by a breach that...

Facebook Messenger phishing wave targets 100K business accounts per week

Bill Toulas reports: Hackers use a massive network of fake and compromised Facebook accounts to send out millions of Messenger phishing messages to target Facebook business accounts with password-stealing malware. The attackers trick the targets into downloading a RAR/ZIP archive containing a downloader for an evasive Python-based stealer that grabs cookies and passwords stored...

U.K. ICO prosecution: Rachel Anderton

From the U.K.’s Information Commissioner’s Office: A former family intervention officer at St Helens Borough Council has been sentenced for unlawfully accessing social services records. Rachel Anderton was prosecuted for viewing records on the council’s case management system between 17 January 2019 and 17 October 2019 without having a business need to do so....

MI: Cybercrime investigation causes half-day for East Jackson schools

Mitchell Kukulka reports: A potential cybercrime is causing classes to be cut to a half day in East Jackson Community Schools on Tuesday, Sept. 12, officials said. The incident currently is under investigation by the Blackman-Leoni Department of Public Safety. School officials learned of the potential cybercrime Tuesday morning, Superintendent Steve Doerr said. Read...

Save the Children confirms systems breach

Claudia Glover reports: Save the Children appears to have been hacked by the Chinese data extortion gang BianLian, according to data posted to the latter’s victim blog. Though it does not mention the charity by name, the cybercrime organisation claims to have stolen up to 8GB of files from an international NGO “employing over...

MGM Resorts hit in disruptive cyberattack

Long-time readers may recall a story in January 2017 about a luxury hotel that reportedly paid extortion to ransomware attackers because guests were locked in their rooms. Some of the story was ultimately considered to be fake news, although the whole scenario initially seemed possible at the time. Fast forward more than six years...

Bloom Health Centers discloses data breach involving mental health data of 1,545 patients

Updated September 13: This incident was reported to HHS as affecting 1,654 patients. On September 11, Psych Associates of Maryland LLC d/b/a Bloom Health Centers (“Bloom Health”), a mental health service provider, announced a data security incident that involved the personal and protected health information of some clinicians and patients. Before digging into the...

California Privacy Protection Agency publishes new draft regulations addressing AI, risk assessments, cyber audits

Philip N. Yannella, Gregory P. Szewczyk, and Timothy Dickens of Ballard Spahr write: The California Privacy Protection Agency (CPPA) recently published two new sets of draft regulations addressing a range of cutting-edge data protection issues.  Although the CPPA has not officially started the formal rulemaking process, the Draft Cybersecurity Audit Regulations and the Draft Risk Assessment Regulations will...