Thursday, August 18, 2016

Some notable hacks reported since my last post

But first, news related to the Shadow Brokers posting keys-to-the-kingdom:
WHAT IF the National Security Agency’s topgun hacking tools/code were exposed on the Internet?  Reports indicate that TAO (Tailored Access Operations) members of the agency’s hacking division seem to point to legitimacy of the code (related to zero-day and other coding flaws) that potentially exposes commercial name firewalls such as Cisco and Fortinet – used by government and large corporations.
A group calling themselves the Shadow Brokers used BitTorrent nd DropBox to deliver the content and is auctioning off the rest of the code to the highest bidder.  Hacker hoax, diversion tactics by whom, oops/mistaken upload, political opportunity….we’ll see
Source: washingtonpost.com 

And from privacyrights.org, at least August's list of reported hacks which contains mostly medical-type of data exposed/unauthorized access – interesting

  • HEI Hotels & Resorts (Marriott, Starwood, Sheraton, Westin) – Payment processing systems breach in several states and District of Columbia – total records unknown/not reported yet
  • John Gonzales DDS – Stolen briefcase with external hard drive with patient records (SSN, DL, DOB, Health info) – total records unknown/not reported yet [July]
  • Bon Secours Health System – Files inadvertently left visible/accessible via Internet totaling 655K patients (containing names, health insurance ID, SSN, clinical info) [April]
  • Valley Anesthesiology & Pain Consultants – Medical information along with SSN may have been compromised via 3rd-party [June]
  • Prosthetic & Orthotic Care, Inc. – Medical, cyberattack of 23K+ records [June]
  • Autism Home Support Services – Medical, unauthorized access of 533 records 
  • Brian D. Halevia-Goldman MD – Medial, 2 laptops stolen resulting in 2K+ records [July]
  • Professional Dermatology Care PC – Medical, unauthorized access of 13K+ records
  • Oracle’s MICROS PoS – Retail and Bank information, via customer support portal and over 700 infected systems
  • Newkirk Products – Health insurance via cybersecurity incident
  • 7-Eleven – Personal employee data via database [June]
  • Center for Minimally Invasive Bariatric and General Surgery – Medical data of unauthorized access reported by HHS
  • Banner Health – Medical information through unauthorized access on server