Tag: gdpr
121 articles

Berlin Hit by Rhysida Ransomware, Data Theft Confirmed
Berlin's administrative network has been hit by a massive Rhysida ransomware attack, with hackers claiming to have stolen a whopping 5.79 TB of sensitive data, including 1.44 million files, and are now threatening to publish it unless paid a ransom. The breach exposes a vast array of confidential records, from government and financial data to personal info like names, email addresses, and phone numbers.

Brits Overwhelmingly Reject Government Access to Encrypted Messages
An overwhelming 93% of British adults believe they have a right to keep their online conversations private, with 89% agreeing that their personal messages should be off-limits without a court order.

Meta Overhauls Platforms Amid $18B Youth Safety Settlement
Meta is shelling out a whopping $18 billion to settle allegations that its platforms contributed to a mental health crisis among youth - and as part of the deal, it's making significant changes to its platforms to promote safer online experiences. This massive settlement could be a game-changer for social media, pushing other platforms to follow suit.

Manchester Airports Group Breach Exposes Customer Data
A massive data breach at Manchester Airports Group has exposed sensitive customer information, including email addresses, phone numbers, and vehicle registration numbers, across three major UK airports. The breach comes at a critical time, just before one of the busiest travel periods of the year.

UK Watchdog Fines Nuisance Call Blocker £190k for Illegal Marketing Tactics
The UK's Information Commissioner's Office has fined Nuisance Call Blocker, operating as Elderly Aids Ltd, a whopping £190k for making over 758,000 unsolicited calls to vulnerable people who'd specifically asked not to be contacted. This hefty penalty sends a strong warning to businesses that think they can flout the law with impunity.

Apollo Hit by Data Breach in Financial Sector Cyberattack Wave
Apollo Global Management recently fell victim to a data breach, with hackers gaining unauthorized access to its cloud platforms between July 6 and July 10, and sensitive personal data being compromised, discovered on August 12. The company swiftly responded to the incident, notifying law enforcement and bolstering its security protocols.

French Tax Authority Breach Exposes 600K Records
A data breach at the French General Directorate of Public Finances exposed a massive 600,000 records, including sensitive taxpayer and business information such as tax IDs, addresses, and phone numbers. For around 250 individuals, the breach went even deeper, compromising the actual contents of messages exchanged with the authority.

ETSI Advances 17 Cybersecurity Standards for EU Compliance
The European Telecommunications Standards Institute (ETSI) is pushing forward with 17 crucial cybersecurity standards to help vendors and buyers across the continent meet the EU's Cyber Resilience Act requirements. These draft standards cover 17 major product categories, setting a vital baseline for manufacturers to ensure their products are secure and compliant.

French Tax Authority Confirms Data Breach After Hacker Touts 2M Records
The French Tax Authority has confirmed a data breach after a hacker claimed to have stolen sensitive information from over 2 million taxpayers, exploiting stolen credentials and a security loophole. The breach was detected in June, and an immediate audit helped sever the unauthorized access.

Trezor Breach Exposes 13,000 Customers' Personal Data
A security breach at Trezor's logistics partner has compromised the personal data of over 13,000 customers, including names, email addresses, phone numbers, and shipping addresses, with the exposure window potentially stretching back 90 days. Trezor has confirmed the breach, which affects customers in several countries who ordered products between May and August.

UK Watchdog Reprimands ACRO for 2023 Data Breach Failings
A major security blunder at the Criminal Records Office (ACRO) left 10,920 people vulnerable to a data breach after a hacker gained unauthorized access to its website and content management system for a staggering eight months. The Information Commissioner's Office (ICO) has now reprimanded ACRO for its failings in preventing this massive breach.

NHS Trust Probes Unauthorized Access to Girl's Medical Records
NHS Tayside is launching an investigation into a disturbing data breach at Ninewells Hospital, where a nine-year-old girl's medical records were allegedly accessed without authorization by staff. The incident has triggered a probe into how sensitive patient information was compromised.

Ransomware gangs exploit victims' payments, extort again
Paying ransomware attackers doesn't always guarantee relief, with many victims being extorted again. A recent survey found 54% of organizations globally paid a ransom, yet it often doesn't end the attack.

Miinto Breach Exposes Customer Order Data to Unauthorized Access
Miinto recently suffered a data breach, allowing unauthorized access to its internal order management system, potentially exposing your order data. The company has notified affected customers and taken steps to address the issue, reporting it to the police and relevant data protection authorities.

NHS Targets Unauthorized Data Access with New Staff Guidance
The NHS is cracking down on staff who snoop through patient records, warning that such behavior is a disgraceful breach of trust and against the law. A new awareness campaign and guidance have been launched to prevent unauthorized data access and protect patient confidentiality.

EU Parliament Paves Way for Chat Control Reintroduction
The EU Parliament's move to revive Chat Control, despite opposition from most MEPs, has sparked concerns about democracy and mass surveillance. This development has left many questioning the integrity of the process.

Pegasus Spyware Targets European Parliament Investigator
In a shocking twist, a member of the European Parliament's PEGA Committee, Stelios Kouloglou, was targeted with the notorious Pegasus spyware - the very same spyware his committee is investigating. This brazen move raises serious concerns about surveillance and accountability.

Rights Groups Warn UK Over Biased AI Age Estimator for Asylum Seekers
Sixty-two leading rights organisations, including Amnesty International and Human Rights Watch, are urging the UK government to ditch its plans to use biased AI-powered facial age estimation on asylum seekers, citing substantial concerns about its fairness and accuracy. They're demanding answers on the technology's testing, training, and safeguards before it's rolled out in 2027.

UK Privacy Watchdog Resigns Amid Poor Judgment Admission
UK Privacy Watchdog John Edwards has resigned with immediate effect, admitting his position had become untenable after being under investigation since February. He announced his decision on LinkedIn, bringing a sudden end to a months-long probe.

UK Watchdog Cautions Healthcare Worker Over Royal's Medical Records Breach
When trust in healthcare settings is broken and personal info is mishandled, swift action is taken - as seen in the ICO's recent decision to issue a formal caution to a former healthcare professional for misusing sensitive patient data. The watchdog is clear: people's personal info must be safe from exploitation.

Ukrainian Hacker Pleads Guilty in Conti Ransomware Case
Meet Oleksii Lytvynenko, a Ukrainian hacker who just pleaded guilty to his role in the notorious Conti ransomware case, which targeted over 1,000 victims worldwide and raked in a staggering $150 million in ransom payments. He's now facing up to 20 years in prison for his involvement.

WhatsApp Disrupts NSO Group's Spearphishing Campaign
WhatsApp has successfully shut down a sneaky phishing campaign by notorious spyware firm NSO Group, which tried to trick users into clicking malicious links to spy on them. The messaging giant is now asking a US court to hold NSO Group accountable for violating a ban on targeting users.

Meta Disrupts NSO Group's WhatsApp Phishing Campaign
Meta detected and blocked a sneaky WhatsApp phishing campaign linked to NSO Group, where attackers tried to trick people into clicking malicious links that led to external websites. The company also filed a contempt order against NSO for allegedly violating a court injunction by targeting WhatsApp users.

UK Water Supplier Fined $1.3M for Data Exposure Lapse
A UK water supplier has been slapped with a $1.3 million fine after a devastating cyber attack exposed the personal data of nearly 664,000 customers and employees, with sensitive information even being published on the dark web. The hefty penalty was reduced by 40% after the company admitted liability and cooperated with investigators.