Posts

Latest on the Currys PC World Data Breach Impacting 10 Million Customers

Following further investigations, Currys PC World today confirmed 10 million of their customer personal details may have been stolen by hackers, a revised number from the 1.2 million customers and 5.9 million payment cards it advised back in June. In June 2018, the company said t here was "an attempt to compromise" 5.8 million credit and debit cards but only 105,000 cards without chip-and-pin protection had been leaked after hackers attempted access to company's payment processing systems. The hack was said to have occurred nearly a year before it was disclosed, so it either went undetected, which is common where there is inadequate security monitoring in place, or the business knew about the breach but choose not to disclose it to their impacted customers. The Information Commissioner's Office (ICO) fined the Dixons Carphone £400,000 for a data in 2015 breach, however, Currys PC World stated the incidents were not connected. The business stressed it has now impro...

Cyber Security Roundup for July 2018

The importance of assuring the security and testing quality of third-party provided applications is more than evident when you consider an NHS reported data breach of 150,000 patient records this month. The NHS said the breach was caused by a coding error in a GP application called SystmOne, developed by UK based 'The Phoenix Partnership' (TTP). The same assurances also applies to internally developed applications, case-in-point was a publically announced flaw with Thomas Cook's booking system discovered by a Norwegian security researcher . The research used to app flaw to access the names and flights details of Thomas Cook passengers and release details on his blog . Thomas Cook said the issue has since been fixed. The Information Commissioner's Office (ICO) fined Facebook £500,000 , the maximum possible, over the Cambridge Analytica data breach scandal, which impacted some 87 million Facebook users . Fortunately for Facebook, the breach occurred before the General D...

Cyber Security Roundup for June 2018

Dixons Carphone said hackers attempted to compromise 5.9 million payment cards and accessed 1.2 million personal data records . The company, which was heavily criticised for poor security and fined £400,000 by the ICO in January after been hacked in 2015 , said in a statement the hackers  had attempted to gain access to one of the processing systems of Currys PC World and Dixons Travel stores. The statement confirmed 1.2 million personal records had been accessed by the attackers. No details were disclosed explaining how hackers were able to access such large quantities of personal data, just a typical cover statement of "the investigation is still ongoing".  It is likely this incident occurred before the GDPR law kicked in at the end of May, so the company could be spared the new more significant financial penalties and sanctions the GDPR gives the ICO, but it is certainly worth watching the ICO response to a repeat offender which had already received a record ICO fine this...

Cyber Security Roundup for May 2018

I'm sure the release of the GDPR on 25th May hasn't escaped anyone's attention. After years of warnings about the EU parliament's intended tough stance on enforcing the human right to privacy in the digital realm, a real 'game changer' of a global privacy regulation has finally landed, which impacts any organisation which touches EU citizen personal data.  The GDPR's potential hefty financial penalties for breaching its requirements is firmly on the radar of directors at large enterprises and small businesses alike, hence the massive barrage of emails we have all have received in recent weeks, on changes to company privacy statements and requesting consent, many of which I noted as not being GDPR compliant as obtaining "explicit consent" from the data subject. So there is a long way to go for many organisations before they become truly GDPR compliant state based on what I've seen so far in my mailbox. Cybercriminals have been quick to take ...

Application Development GDPR Compliance Guidance

Last week  IBM developerWorks released a three-part guidance series I have written to help  Application Developers develop GDPR compliant applications. Developing GDPR Compliant Applications Guidance Part 1: A Developer's Guide to the GDPR Part 2: Application Privacy by Design Part 3: Minimizing Application Privacy Risk The GDPR The General Data Protection Regulation (GDPR) was created by the European Commission and Council to strengthen and unify Europe's data protection law, replacing the 1995 European Data Protection Directive. Although the GDPR is a European Union (EU) regulation, it applies to any organizations outside of Europe that handle the personal data of EU citizens. This includes the development of applications that are intended to process the personal information of EU citizens. Therefore, organizations that provide web applications, mobile apps, or traditional desktop applications that can indirectly process EU citizen's personal data ...

Cyber Security Roundup for April 2018

The fallout from the F acebook privacy scandal rumbled on throughout April and culminated with the closure of the company at the centre of the scandal, Cambridge Analytica . Overview of Facebook and Cambridge Analytica Facebook's Zuckerberg faces formal summons from MPs Facebook to contact 87 million users affected by data breach Canada data firm AIQ may face legal action in UK Facebook to vet UK political ads for May 2019 local elections Facebook to exclude billions from European privacy laws Ikea was forced to shut down its freelance labour marketplace app and website 'TaskRabbit'  following a 'security incident'. Ikea advised users of TaskRabbit   to change their credentials if they had used them on other sites, suggesting a significant database compromise. TSB bosses came under fire after a botch upgraded to their online banking system , which meant the Spanished owned bank had to shut down their online banking facility, preventing usage by over 5 mi...

Cyber Security Roundup for March 2018

In the wake of the global political fallout over the Salisbury nerve agent attack, there are reports of a growing threat of Russian state or Russian state-affiliated hacking groups conducting cyber attack reprisals against UK organisations, government officials have directly warned bosses at electricity, gas and water firms, Whitehall departments and NHS hospitals to prepare for a state-sponsored cyber assault .  Russian group Fancy Bear (APT28) were suspected of being behind an unsuccessful attack against the UK anti-doping agency , and China tied hacking group APT15 were found to have infiltrated a UK government contractor’s computer systems by NCC researchers . Large-scale data breaches were disclosed with Under Armour’s Fitness App MyFitnessPal (1.5 million personal records compromised) , Orbitz (880k payment cards at risk) , and at a Walmart partner (1.3 million personal records compromised) . The latter was caused when an AWS S3 bucket holding a Walmart dat...