Archive for the ‘Privacy Incidents’ Category

Use This RBS Worldpay News Report For Training

Thursday, February 5th, 2009

On November 8, 2008 more than 130 ATM machines in 49 cities throughout the world were hit by a group of cybercriminals during a 30-minute period.

(more…)

Txt Phishing (Vishing) In Iowa: MetaBank NOT Calling!

Monday, February 2nd, 2009

Boy, all throughout the day I heard on the radio, and it was all over the noon and evening news, that Iowa customers of MetaBank were receiving text messages on their phones to call MetaBank about unusual activity in their account…

(more…)

Business Info Fact of the Day: PII Increasingly Stored On MP3 Players

Monday, January 26th, 2009

Over the past few months during some of my presentations I’ve discussed how easily PII can be stored on mobile storage devices that most business leaders and information security folks often do not think about or overlook. One of those devices is the innocent-looking and seemingly benign MP3 player, such as the cool ipod. You gotta love’em! I know I love mine. However, a couple of times when I talked about how easy it is to store large amounts of company data, including personally identifiable information (PII), onto MP3 players, I got some noticeable snickers and sneers from a few in the audience who apparently thought such an idea was preposterous!
Well, here are a couple of different news articles that demonstrates otherwise; both about the same incident, but each with slightly different information…

(more…)

Business Info Fact of the Day: PII Increasingly Stored On MP3 Players

Monday, January 26th, 2009

Over the past few months during some of my presentations I’ve discussed how easily PII can be stored on mobile storage devices that most business leaders and information security folks often do not think about or overlook. One of those devices is the innocent-looking and seemingly benign MP3 player, such as the cool ipod. You gotta love’em! I know I love mine. However, a couple of times when I talked about how easy it is to store large amounts of company data, including personally identifiable information (PII), onto MP3 players, I got some noticeable snickers and sneers from a few in the audience who apparently thought such an idea was preposterous!
Well, here are a couple of different news articles that demonstrates otherwise; both about the same incident, but each with slightly different information…

(more…)

Business Info Fact Of The Day: PII Sent Through The Mail Is Often Stolen Or Lost

Tuesday, January 13th, 2009

Over the years I have heard many times by my various government friends, even following too many mis-deliveries and lost packages to enumerate here, that packages and letters sent via the US postal service, and even through other delivery organizations such as UPS, FedEx and DHL, are considered as “secure” and that delivery is expected to be “guaranteed” or a “sure thing.” One time a couple of years ago an IRS employee told me curtly, “If we mailed it to you through the USPS then we can legally assume you received it.”
NOT!

(more…)

Business Info Fact Of The Day: Banks In Maine Spent $2.1 Million Responding To Breaches In 2007 & 2008

Monday, January 12th, 2009

Maine’s Bureau of Financial Institutions, a division of the Department of Professional and Financial Regulation, conducted the survey at the direction of the state legislature that revealed the costs of Maine’s banks and credit unions when responding to breaches…

(more…)

Business Info Fact Of The Day: 78% Of Breaches Caused By Insiders

Friday, January 9th, 2009

Here’s another study about the increase in privacy breaches in 2008, and how most of them are caused by insiders…

(more…)

Twitter Accounts Hacked; Including Barack Obama’s and Britney Spear’s

Tuesday, January 6th, 2009

Yesterday Twitter reported here and here that several (33 to be exact) Twitter accounts were hacked into. This is in addition to the current, but separate, Twitter phishing…otherwise known as “twishing“…exploit that is simulatenously going on.

(more…)

Audit’s Role in Privacy Breach Response

Monday, January 5th, 2009

Next week, on Wednesday, January 14, I will be in Minneapolis, MN speaking at the Minneapolis Gateway Hotel for the ISACA Winter Quarterly Meeting/Social.
My topic will be, “Internal Audit’s Role in Responding to Privacy Breaches.”
Here’s a synopsis…

(more…)

HIPAA Violation: Medical Clinic Leaves Box With PHI On Public Dumpster

Tuesday, December 30th, 2008

This summer I had planned to do a dumpster-diving project with my sons, but then the Iowa floods postponed those plans. However, after reading the following I’m motivated to plan to do this in the spring after basketball and G&T activities are finished for the winter…

(more…)