June 10, 2016
Ransomware, malware that encrypts a victim’s files until they pay for a decryption key, is a serious problem in data security. There are two types of ransomware:
(1) Crypto Ransomware — it encrypts files
(2) Locker Ransomware — it locks computers, preventing its use.
It is a bad problem that is getting worse. It is commonly preventable with tight security measures, adequate and up to date software,proper training and protocols and regular if not daily back ups of data. The sort of thing that many organisations in Australia don’t have because of a poor privacy culture brought about by inadequate regulation.
The BBC highlights the problem in Read the rest of this entry »
Posted in Privacy
|
1 Comment »
June 7, 2016
Telcos tend to be prone to privacy breaches. In Australia Optus has been the subject of an enforceable undertaking and Telstra has been the subject of determinations made against it by the Privacy Commissioner. In New Zealand Vodafone breached a customer’s privacy when providing an woman’s ex phone account details. This is reported in Vodafone apologises for privacy breach.
This is a more common mistake than one would think. It is hugely embarrassing and Read the rest of this entry »
Posted in Privacy
|
1 Comment »
Regulators around the world highlight in their guidances, press releases, speeches and, sometimes, enforcement actions the need for strong passwords and, preferably two factor authentication. But strong and unpredictable passwords are vital. Something Mark Zuckerberg, as in Facebook Zuckerberg, should have known. But he didn’t and his password to his social media accounts were hacked as reported in Mark Zuckerberg’s social media accounts compromised due to weak password. It is gravely embarrassing and Read the rest of this entry »
Posted in Privacy
|
1 Comment »
June 5, 2016
Hackers are equal opportunity pilferers. They go where the weakness lies and the money resides. As the reported hack on Read the rest of this entry »
Posted in Privacy
|
1 Comment »
May 31, 2016
The consequences of a data breach can sometimes take an age to resolve. The ongoing reputational damage can be excrutiating. As Tumblr is discovering. In 2013 there was a security breach into the Zendesk styem which resulted in data breaches into three of their clients; Twitter, Pinterest and Tumblr. This was reported by Wired in Zendesk Security Breach Affects Twitter, Tumblr and Pinterest.
Tumbler has just notified its users Read the rest of this entry »
Posted in Privacy
|
1 Comment »
May 27, 2016
It is quite common for equitable claims for breach of confidence relate to private commercial information being taken by ex employees to be used by competitors. A new take is Read the rest of this entry »
Posted in UK Information Commissioner's Office
|
1 Comment »
The need to keep proper data security comes into focus when the stories about the need to notify users that passwords have been compromised and need to be reset. LinkedIn has been through that particular nightmare recently while Reddit has been forced to reset 100,000 passwords as reported in Reddit Forced to Reset 100,000 Passwords After ‘Uptick’ In Hacked Accounts.
Compromised passwords mean Read the rest of this entry »
Posted in Privacy
|
1 Comment »
May 26, 2016
The credit reporting provisiosns and protections incorporated into the Privacy Act in December 2012 and taking effect on 12 March 2014 are designed to provide real and detailed controls on the use and disclosure of credit information and improve the accuracy of data collected by credti reporting agency. This was part of the Read the rest of this entry »
Posted in Privacy
|
1 Comment »
May 25, 2016
Cyber attacks on banks are becoming a very significant problem alongside pervasive ransomware attacks. Recently a cyber attack on Bangladesh Central Bank resulting in a theft of $81 million.
This issue has been highlighted by the international financial network SWIFT’s CEO Gottfried Leibbrandt who delivered the keynote address at the 14th annual European Financial Services Conference in Brussels. He announced Read the rest of this entry »
Posted in Privacy
|
1 Comment »
In Email fail at Do Not Call Register, thousands of contacts exposed CRN reports on a significant data breach involving the release of thousands of emails when an email was sent on behalf of the Don Not Call Register. Interestingly ACMA in DNCR: enforcement outcomes sets out the consequences of breaches of the Do Not Call Register. As late as Read the rest of this entry »
Posted in Privacy
|
1 Comment »