Big_Bear
8 years ago
This is not an identity breach per se, but it would be pretty easy to connect the dots and get the names of who is deployed where.

How many on this board got a fitbit for Christmas? What about Alexa? Google home? "Smart TV" with built in camera and microphone connect to the internet? Same goes for your smart phone.


= = = = = = =


Data from fitness app Strava highlights locations of soldiers, U.S. bases

CBS/AP January 28, 2018, 9:22 PM

= = = = = = =

https://www.cbsnews.com/news/fitness-devices-soldiers-sensitive-military-bases-location-report/ 

= = = = = = =

WASHINGTON -- An interactive map of exercise location data from users of the popular Strava tracking app has inadvertently raised security concerns about personnel at U.S. military bases in sensitive areas around the world. The online map shows the accumulated tracks created by running and biking activities of people who use GPS-enabled fitness devices such as Fitbit watches.

The Global Heat Map, published by the GPS tracking company Strava, uses satellite information to map the locations and movements of subscribers to the company's workout tracking service over a two-year period, illuminating areas of activity, The Washington Post reported Sunday.




.
Big_Bear
8 years ago
RE post 155 above



The Equifax Hack Exposed More Data Than Previously Reported

= = = = = = =

https://www.msn.com/en-us/news/technology/the-equifax-hack-exposed-more-data-than-previously-reported/ar-BBIZAbV?OCID=ansmsnnews11 

= = = = = = =

Last year’s worst hack exposed even more information than previously believed, further highlighting vulnerabilities created by the credit-monitoring system.

Between May and July of last year, hackers stole 145 million Americans’ Social Security numbers, birthdays, driver’s license numbers, and addresses from Equifax, one of the three largest credit reporting agencies in the country. The Wall Street Journal, reviewing documents submitted to Congress, now reports that stolen data also included tax identification numbers and driver’s license states and issuance dates. Some email addresses were also acquired by hackers.

The additional data could make it even easier for hackers to open credit lines or otherwise exploit victim’s identities. The theft of tax ID numbers is particularly concerning, since it may increase the risk of fraudulent tax filings.



.
Big_Bear
8 years ago
Thousands of FedEx customer records exposed by unsecured server

= = = = = = =

https://www.msn.com/en-us/money/companies/thousands-of-fedex-customer-records-exposed-by-unsecured-server/ar-BBJb0NW?OCID=ansmsnnews11 

= = = = = = =

Global package delivery company FedEx said Thursday it has secured some of the customer identification records that were visible earlier this month on an unsecured server and so far has found no evidence that private data was "misappropriated."

The server stored more than 119,000 scanned documents from U.S. and international citizens, such as passports, driving licenses, and security identification, according to a report from security research firm Kromtech.

Kromtech said its researchers found the unsecured server on Feb. 5 and it was closed to public access on Wednesday.

The data was stored on a Amazon S3 storage server and collected by a company FedEx acquired in 2014, Bongo International, which calculated international shipping prices and provided other services. FedEx later discontinued the service.




.
Big_Bear
8 years ago
Panera reportedly ignored a breach that exposed thousands of customers' information for 8 months

= = = = = = =

http://www.businessinsider.com/panera-data-breach-reportedly-remained-unsolved-for-months-2018-4 

= = = = = = =

Panera Bread is under fire for reportedly spending months ignoring a website flaw that exposed thousands of customers' personal information.

For at least eight months, Panera's website leaked customer records, cyber security blog KrebsOnSecurity reported Monday. Information reportedly included the names, email and physical addresses, birthdays, and partial credit card numbers of any customer who signed up to order Panera online.

According to KrebsOnSecurity, security researcher Dylan Houlihan realized that the information was visible and easily accessible in plain text from Panera's site in August. Houlihan reportedly reached out to Panera, but he says the company failed to make any changes.

"The flaw never disappeared," Houlihan told KresbsOnSecurity. "I checked on it every month or so because I was pissed."
Big_Bear
7 years ago
GovPayNow Data Leak

= = = = = = =

https://www.informationsecuritybuzz.com/expert-comments/govpaynow-data-leak/ 

= = = = = = =

It has been reported by Krebs that Government Payment Service Inc. — a company used by thousands of U.S. state and local governments to accept online payments for everything from traffic citations and licensing fees to bail payments and court-ordered fines — has leaked more than 14 million customer records dating back at least six years, including names, addresses, phone numbers and the last four digits of the payer’s credit card. IT security experts commented below.

Pravin Kothari “Recently acquired by Securus Technologies, a Carrollton, Texas-based company, GovPayNet is a major provider of credit and debit card payments to government agencies. They process millions of payments annually to over 2,600 agencies across the United States. This past month their website GovPayNow.com exposed what has been described as at least 14 million customer receipts dating back to 2012. Securus has had other issues with cybersecurity over the past few years including the misuse of a service that tracked convicted felons’ cellphones, hackers penetrating this same system and subsequently stealing logins and legitimate credentials, and finally another flaw in May that allowed unauthorized access to accounts by guessing answers to the security questions.”




.
Big_Bear
7 years ago
Facebook unearths security flaw affecting 50 mln users

= = = = = = =

Munsif Vengattil
Reuters
09/28/2018

= = = = = = =

Facebook Inc has discovered a security flaw affecting about 50 million user accounts which could have allowed attackers to take over the accounts, the social networking company said on Friday.

Facebook has since fixed the vulnerability and informed law enforcement, it said.

Attackers stole Facebook access tokens through its "view as" feature, which they could then use to take over people's accounts. "View as" is a feature that allows users to see what their own profile looks like to someone else.

Facebook has reset the access tokens of the 50 million affected accounts, it said. As a precaution, the company has reset access tokens for another 40 million accounts that have looked up through the "view as" option in the last year.

https://newsroom.fb.com/news/2018/09/security-update .

Facebook shares fell 3 percent to $163.78 in afternoon trading, weighing on major Wall Street stock indexes.

About 90 million people will have to log back in to Facebook or any of their apps that use a Facebook login, the company said.

Facebook also said it was temporarily turning off the "view as" option.
Users browsing this topic