<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Endpoint Security Info &#187; In the News</title>
	<atom:link href="http://www.endpoint-security.info/category/in-the-news/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.endpoint-security.info</link>
	<description>Endpoint Security in the News. Learn to protect your data by controlling removable storage devices.</description>
	<lastBuildDate>Wed, 08 Feb 2012 13:33:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Zappos and Amazon face consequences of data breach</title>
		<link>http://www.endpoint-security.info/2012/01/24/zappos-and-amazon-face-consequences-of-data-breach/</link>
		<comments>http://www.endpoint-security.info/2012/01/24/zappos-and-amazon-face-consequences-of-data-breach/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 19:27:33 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[credit card information]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[hacker attach]]></category>
		<category><![CDATA[lawsuit]]></category>
		<category><![CDATA[negligence]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[Zappos]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=834</guid>
		<description><![CDATA[When you are the lead artist of a security mishaps that ended up in a data breach affecting some 24 million people, consequences are bound to catch up with you. And they just have caught up with shoe retailer Zappos.com and the bigger online fish behind them, Amazon.com. The two companies are being sued by [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F01%2F24%2Fzappos-and-amazon-face-consequences-of-data-breach%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F01%2F24%2Fzappos-and-amazon-face-consequences-of-data-breach%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>When you are the lead artist of a security mishaps that ended up in a data breach affecting some 24 million people, consequences are bound to catch up with you. And they just have caught up with shoe retailer Zappos.com and the bigger online fish behind them, Amazon.com. <a href="http://www.darkreading.com/authentication/167901072/security/privacy/232500341/zappos-amazon-sued-over-data-breach.html" target="_blank">The two companies are being sued by the customers affected by the data breach</a>, being accused of negligence.</p>
<p>A woman from Texas seems to be the main promoter in this Kentucky lawsuit. She claims that she and millions of other customers were harmed by the exposure of their personal account information. Zappos and Amazon have not commented on the lawsuit as of earlier today. <span id="more-834"></span></p>
<p>The Zappos data breach was made public on Sunday when the company emailed employees and customers to let them know that names, phone numbers and email addresses of customers might have been accessed in a hacker attack.  The same statement reassured them that credit card and payment information had not been stolen. Zappos also advised its customers to reset account passwords on their site and any other sites where similar passwords were being used.</p>
<p>The attorneys of the Texas woman are seeking class-action status on behalf of the 24 million affected customers, claiming the security breach was actually a violation of the federal Fair Credit Reporting Act. The sum the lawsuit seeks has not been specified, but it is in the range of millions of dollars in compensatory and exemplary damages for emotional distress and loss of privacy. It also seeks to have Zappos court-ordered to pay for credit monitoring and identity theft insurance, plus periodic audits, for all those affected by the data breach.</p>
<p>&nbsp;</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2010/11/01/one-million-pay-for-citibank-credit-card-account-theft/" rel="bookmark" class="crp_title">Court orders one million pay restitution for Citibank credit card accounts theft</a></li><li><a href="http://www.endpoint-security.info/2008/06/29/montgomery-ward-kept-customers-in-the-dark-on-data-theft/" rel="bookmark" class="crp_title">Montgomery Ward Kept Customers in the Dark on Data Theft</a></li><li><a href="http://www.endpoint-security.info/2009/02/04/tjx-sale-for-data-brech/" rel="bookmark" class="crp_title">TJX finds closure for breach in big time sale</a></li><li><a href="http://www.endpoint-security.info/2012/01/26/data-breach-exposes-records-of-1-8-million-new-york-utilities-customers/" rel="bookmark" class="crp_title">Data breach exposes records of 1.8 million New York utilities customers</a></li><li><a href="http://www.endpoint-security.info/2011/07/28/hackers-will-always-have-their-stolen-data/" rel="bookmark" class="crp_title">Hackers will always have their stolen data</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2012/01/24/zappos-and-amazon-face-consequences-of-data-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ramnit worm steals 45000 Facebook users&#8217; credentials</title>
		<link>http://www.endpoint-security.info/2012/01/09/ramnit-worm-steals-45000-facebook-users-credentials/</link>
		<comments>http://www.endpoint-security.info/2012/01/09/ramnit-worm-steals-45000-facebook-users-credentials/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 15:05:15 +0000</pubDate>
		<dc:creator>cristina</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[Malware Infections]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Ramnit]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=824</guid>
		<description><![CDATA[The Ramnit worm, first discovered a year and a half ago, a malware that used to target online banking and FTP credentials, makes victims among UK and French Facebook users. A new version of the worm managed to steal more than 45000 Facebook usernames and passwords and tried to attack the e-mail accounts and virtual [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F01%2F09%2Framnit-worm-steals-45000-facebook-users-credentials%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F01%2F09%2Framnit-worm-steals-45000-facebook-users-credentials%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The Ramnit worm, first discovered a year and a half ago, a malware that used to target online banking and FTP credentials, makes victims among UK and French Facebook users.</p>
<p>A new version of the worm managed to steal more than 45000 Facebook usernames and passwords and tried to attack the e-mail accounts and virtual private networks of affected persons. The worm has sent malicious links to victims&#8217; friends, links that downloaded malware to the person&#8217;s computer, which helped spread the worm even faster.</p>
<p>It seems like the attackers are adapting to market tendencies, targeting social networks rather than traditional communication means (such as email).</p>
<p>For more details, you can read the <a href="http://www.techweekeurope.co.uk/news/facebook-ramnit-worm-variant-stole-uk-log-in-credentials-report-claims-52733">techweekeurope.co.uk</a> report.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2010/09/20/stuxnet-worm-threatening-scada-systems-and-other-industrial-environments/" rel="bookmark" class="crp_title">Stuxnet Worm: New threat targets Scada Systems and other industrial environments</a></li><li><a href="http://www.endpoint-security.info/2011/02/04/facebook-fixes-data-theft-issue/" rel="bookmark" class="crp_title">Facebook fixes data theft issue</a></li><li><a href="http://www.endpoint-security.info/2008/12/02/us-army-bans-usb-devices-to-stop-worm-from-spreading/" rel="bookmark" class="crp_title">US Army bans USB devices to stop worm from spreading</a></li><li><a href="http://www.endpoint-security.info/2009/05/13/i-spy-with-my-little-eye/" rel="bookmark" class="crp_title">I Spy with My Little Eye&#8230;.</a></li><li><a href="http://www.endpoint-security.info/2011/01/03/new-variations-of-the-stuxnet-worm-expected-to-emerge-in-2011/" rel="bookmark" class="crp_title">New variations of the Stuxnet worm expected to emerge in 2011</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2012/01/09/ramnit-worm-steals-45000-facebook-users-credentials/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK&#8217;s ICO takes serious measures to enforce data protection</title>
		<link>http://www.endpoint-security.info/2011/11/08/the-ico-takes-serious-measures-to-enforce-data-protection/</link>
		<comments>http://www.endpoint-security.info/2011/11/08/the-ico-takes-serious-measures-to-enforce-data-protection/#comments</comments>
		<pubDate>Tue, 08 Nov 2011 13:03:00 +0000</pubDate>
		<dc:creator>cristina</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[Laws & Standards]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[memory stick encryption]]></category>
		<category><![CDATA[portable device encryption]]></category>
		<category><![CDATA[Rochdale Metropolitan Borough Council]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=799</guid>
		<description><![CDATA[The ICO conducted an investigation on a case of hardware loss in May at the Rochdale Metropolitan Borough Council. The incident consisted in the loss of an unencrypted memory stick by a Council’s finance department employee, stick which contained names, addresses and payment details for 18.000 residents. The missing hardware was not found to the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F08%2Fthe-ico-takes-serious-measures-to-enforce-data-protection%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F08%2Fthe-ico-takes-serious-measures-to-enforce-data-protection%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The ICO conducted an investigation on a case of hardware loss in May at the Rochdale Metropolitan Borough Council. The incident consisted in the loss of an unencrypted memory stick by a Council’s finance department employee, stick which contained names, addresses and payment details for 18.000 residents. The missing hardware was not found to the date.</p>
<p>The investigation concluded that the Rochdale Council has breached the Data Protection Act by not providing employees with encrypted memory sticks (although it was a known fact that these devices would be used to transfer private information) and by not training their employees to properly use portable devices for work purposes.</p>
<p>Sally Anne Poole, ICO’s head of enforcement qualifies this mishap as ‘unacceptable’ and says ‘This incident could have been easily avoided if adequate security measures had been in place.’ in a quote by <a href="http://www.eweekeurope.co.uk/news/ico-slams-rochdale-for-data-loss-44870">eWeek</a>.</p>
<p><a href="http://www.endpointprotector.com/"><img style="border: 0pt none;" title="en-leaderboard.png" src="/wp-content/uploads/banners_2011/en-leaderboard.png" alt="en-leaderboard.png" width="472" height="59" align="middle" border="0" /></a></p>
<p>The measures taken by the ICO in this case consist of signing an undertaking of actions to take to implement data protection policies by 31<sup>st</sup> March 2012.</p>
<p>Let’s hope that more than one private data handling organization learns from this incident and encrypts their portable devices using proper <a href="http://www.endpointprotector.com/en/index.php/products/easylock">solutions</a>.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/02/25/british-local-council-gets-fine-for-mishandling-of-data/" rel="bookmark" class="crp_title">British local council gets fine for mishandling of data</a></li><li><a href="http://www.endpoint-security.info/2011/11/03/the-theft-of-laptops-doesnt-stop-organizations-dont-learn-their-lesson/" rel="bookmark" class="crp_title">The theft of laptops doesn&#8217;t stop, organizations don&#8217;t learn their lesson</a></li><li><a href="http://www.endpoint-security.info/2011/07/01/security-study-most-government-employees-fall-for-planted-usb-sticks/" rel="bookmark" class="crp_title">Security study &#8211; Most government employees fall for planted USB sticks</a></li><li><a href="http://www.endpoint-security.info/2011/04/19/edmonton-school-board-data-breach-affected-7000-people/" rel="bookmark" class="crp_title">Edmonton School Board data breach affected 7,000 people</a></li><li><a href="http://www.endpoint-security.info/2012/01/26/easylock-2-cross-platform-portable-data-encryption-solution-from-cososys/" rel="bookmark" class="crp_title">EasyLock 2 &#8211; Cross-platform portable data encryption solution from CoSoSys</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/11/08/the-ico-takes-serious-measures-to-enforce-data-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The theft of laptops doesn&#8217;t stop, organizations don&#8217;t learn their lesson</title>
		<link>http://www.endpoint-security.info/2011/11/03/the-theft-of-laptops-doesnt-stop-organizations-dont-learn-their-lesson/</link>
		<comments>http://www.endpoint-security.info/2011/11/03/the-theft-of-laptops-doesnt-stop-organizations-dont-learn-their-lesson/#comments</comments>
		<pubDate>Thu, 03 Nov 2011 15:44:38 +0000</pubDate>
		<dc:creator>cristina</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[device monitoring]]></category>
		<category><![CDATA[encrypt data]]></category>
		<category><![CDATA[encyption]]></category>
		<category><![CDATA[hardware loss]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[laptop lost]]></category>
		<category><![CDATA[portable device use]]></category>
		<category><![CDATA[track use of portable devices]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=795</guid>
		<description><![CDATA[A whole lot was written on loss/theft of hardware (laptops, USB sticks, external hard drives, etc.) and we had thought that organizations would learn their lesson and encrypt sensitive data on such supports. Apparently, things aren&#8217;t quite like that and two recent incidents come to prove it. A resident student at Vancouver Coastal Health lost [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F03%2Fthe-theft-of-laptops-doesnt-stop-organizations-dont-learn-their-lesson%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F03%2Fthe-theft-of-laptops-doesnt-stop-organizations-dont-learn-their-lesson%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>A whole lot was written on loss/theft of hardware (laptops, USB sticks, external hard drives, etc.) and we had thought that organizations would learn their lesson and encrypt sensitive data on such supports. Apparently, things aren&#8217;t quite like that and two recent incidents come to prove it.</p>
<p>A resident student at Vancouver Coastal Health lost a <a href="http://www.ctvbc.ctv.ca/servlet/an/local/CTVNews/20111027/bc_steele_privacy_breach_111027/20111027/?hub=BritishColumbiaHome">laptop and a USB stick</a> (there is a high probability that the hardware was stolen) at the Toronto Airport. The information stored on the drives was password protected but it wasn&#8217;t encrypted.</p>
<p>A Vancouver Coastal Health official calls the incident &#8216;unfortunate&#8217; and says that &#8216;This is the way physicians and other health care workers need to do their job. They need to use these devices.&#8217; He admits that many professionals use laptops and that the agency has some issues handling mobile technologies.</p>
<p>Another mishap took place in the United Kingdom and the <a href="http://www.guardian.co.uk/government-computing-network/2011/oct/28/newcastle-youth-offending-team-data-breach-ico">theft of a laptop</a> that stored personal information of 100 young people who participated in inclusion programs. This laptop was in the house of a contractor of the Newcastle Youth Offending Team organization. The ICO (Information Commissioner&#8217;s Office) has established a fine for this organization for not encrypting the data. According to Sally-Anne Poole &#8216;Encryption is a basic procedure and an inexpensive way to ensure that information is kept secure.&#8217; She underlines the fact that organizations working with contractors must make sure that the latter ones align to their security policies.</p>
<p>It&#8217;s so simple and cheap to <a href="http://www.endpointprotector.com/">track the use of portable devices</a> and <a href="http://www.endpointprotector.com/en/index.php/products/easylock">encrypt sensitive data</a> stored on them, that we really ask ourselves why don&#8217;t organizations do it?</p>
<p>Let&#8217;s hope that at least legal constraints will force private data handlers to implement solutions and politics to maintain their data safe and secure.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/11/08/the-ico-takes-serious-measures-to-enforce-data-protection/" rel="bookmark" class="crp_title">UK&#8217;s ICO takes serious measures to enforce data protection</a></li><li><a href="http://www.endpoint-security.info/2008/11/13/self-encrypting-laptop-from-dell/" rel="bookmark" class="crp_title">Self-encrypting laptop from Dell</a></li><li><a href="http://www.endpoint-security.info/2008/10/20/deloitte-lost-hundreds-of-thousands-of-pension-details/" rel="bookmark" class="crp_title">Deloitte Lost Hundreds of Thousands of Pension Details</a></li><li><a href="http://www.endpoint-security.info/2011/02/25/british-local-council-gets-fine-for-mishandling-of-data/" rel="bookmark" class="crp_title">British local council gets fine for mishandling of data</a></li><li><a href="http://www.endpoint-security.info/2011/09/10/data-breach-roundup-missing-hardware/" rel="bookmark" class="crp_title">Data breach roundup: Missing hardware</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/11/03/the-theft-of-laptops-doesnt-stop-organizations-dont-learn-their-lesson/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>This time it seems to be too much</title>
		<link>http://www.endpoint-security.info/2011/10/12/this-time-it-seems-to-be-too-much/</link>
		<comments>http://www.endpoint-security.info/2011/10/12/this-time-it-seems-to-be-too-much/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 10:17:41 +0000</pubDate>
		<dc:creator>mateusz</dc:creator>
				<category><![CDATA[In the News]]></category>
		<category><![CDATA[Malware Infections]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=759</guid>
		<description><![CDATA[What you can see in the picture is belonging to US Navy Drone Reaper. It is remotly controlled air vehicle used during combat missions in Afghanistan. A machine that is capable of neutralising targets or performing reckon missions. What would you say if you found out, that every &#8220;step&#8221; of the machine was tracked by [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F10%2F12%2Fthis-time-it-seems-to-be-too-much%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F10%2F12%2Fthis-time-it-seems-to-be-too-much%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>What you can see in the picture is belonging to US Navy Drone Reaper. It is remotly controlled air vehicle used during combat missions in Afghanistan. A machine that is capable of neutralising targets or performing reckon missions. What would you say if you found out, that every &#8220;step&#8221; of the machine was tracked by a computer virus - a keylogger? <a href="http://www.wired.com/dangerroom/2011/10/virus-hits-drone-fleet/">dangerroom</a> says that no more than 2 weeks ago on computers in Creech Air Force Base in Nevada. Since then, pilots are still performing overseas missions, and also there were several attempts to remove the malware. However,</p>
<blockquote><p>We keep wiping it off, and it keeps coming back</p></blockquote>
<p><img class="alignnone" title="Drone Reaper" src="http://www.nationspresse.info/wp-content/uploads/2011/04/ReaperUAV.jpg" alt="" width="400" height="270" /></p>
<p>It does not sound promising if one of most important America&#8217;s weapons is infected. It is not sure whether the infection was done on purpose or it was accidental. The virus is believed to be spread with removable devices, that are used to load map updates and transport mission videos from one computer to another.<span id="more-759"></span></p>
<p>Good thing is that there is no record of data breach, since the computers are not directly connected with the Internet. However, the malware hit both, classified and unclassified machines in the base, raising the risk that data might have been exposed to people out of military chain of command. One of the consequences is also ban on usage of removable devices in the base, as it is common in military computer networks.</p>
<p>It is not the first problem with information security of drones &#8211; there was already a case where fighters in Afghanistan could listen to the transmissions with 26 USD computer program.</p>
<p>It actually proves, how much security protocols are required in such facilities and how valuable can be device control in regard to even closed operations like Creech Air Force Base in Nevada.  In 2008, removable drives enabled to introduce <a href="http://www.wired.com/dangerroom/2008/11/army-bans-usb-d/">agent.btz worm</a> to Department&#8217;s of Defense Computer and still after 3 years, they are tryin to remove the virus. Let&#8217;s hope in this case the outcome will be different.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2010/08/26/pentagon-confirms-us-military-breach/" rel="bookmark" class="crp_title">The Pentagon finally confirms the most significant breach of US military computers ever</a></li><li><a href="http://www.endpoint-security.info/2008/12/02/us-army-bans-usb-devices-to-stop-worm-from-spreading/" rel="bookmark" class="crp_title">US Army bans USB devices to stop worm from spreading</a></li><li><a href="http://www.endpoint-security.info/2010/02/28/pentagon-lifts-ban-usb-flash-drives/" rel="bookmark" class="crp_title">US thumb drives finally allowed on Pentagon premises</a></li><li><a href="http://www.endpoint-security.info/2008/02/05/usb-with-nato-sensitive-data-found-in-swedish-library/" rel="bookmark" class="crp_title">USB with NATO Sensitive Data Found in Swedish Library</a></li><li><a href="http://www.endpoint-security.info/2010/10/01/stuxnet-and-cyber-warfare/" rel="bookmark" class="crp_title">Stuxnet and cyber warfare &#8211; the future is now</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/10/12/this-time-it-seems-to-be-too-much/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hardware loss in a hospital endangers data of 1.6 million people</title>
		<link>http://www.endpoint-security.info/2011/10/10/hardware-loss-in-a-hospital-endangers-data-of-1-6-million-people/</link>
		<comments>http://www.endpoint-security.info/2011/10/10/hardware-loss-in-a-hospital-endangers-data-of-1-6-million-people/#comments</comments>
		<pubDate>Mon, 10 Oct 2011 12:46:02 +0000</pubDate>
		<dc:creator>cristina</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[hardware loss]]></category>
		<category><![CDATA[personal data loss]]></category>
		<category><![CDATA[unencrypted backup tapes]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=753</guid>
		<description><![CDATA[Nemours, an American organization for children’s health announces through a press release the loss of three unencrypted backup tapes that contained information such as the name, address, date of birth, social security number, insurance and medical treatment information and bank account information of 1.600.000 patients and employees. The three backup tapes were stored in a [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F10%2F10%2Fhardware-loss-in-a-hospital-endangers-data-of-1-6-million-people%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F10%2F10%2Fhardware-loss-in-a-hospital-endangers-data-of-1-6-million-people%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Nemours, an American organization for children’s health announces through a press release the loss of three unencrypted backup tapes that contained information such as the name, address, date of birth, social security number, insurance and medical treatment information and bank account information of 1.600.000 patients and employees.</p>
<p>The three backup tapes were stored in a cabinet that might have disappeared during a facility modernization project.</p>
<p>So far, there is no evidence that the tapes were stolen, accessed or used for fraudulent purposes.</p>
<p>Nemours offers free credit monitoring, identity theft protection and call center support.</p>
<p>Find their press release here: <a href="http://www.nemours.org/mediaroom/news/2011/missingtapes.html">http://www.nemours.org/mediaroom/news/2011/missingtapes.html</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2012/02/02/stolen-flash-drive-exposes-data-of-1200-university-of-miami-patients/" rel="bookmark" class="crp_title">Stolen Flash Drive Exposes Data of 1,200 University of Miami Patients</a></li><li><a href="http://www.endpoint-security.info/2011/03/04/data-breaches-caused-by-storage-device-theft-hit-again/" rel="bookmark" class="crp_title">Data breaches caused by storage device theft hit again</a></li><li><a href="http://www.endpoint-security.info/2008/06/14/billing-records-of-over-2-million-utah-patients-stolen/" rel="bookmark" class="crp_title">Billing Records of Over 2 Million Utah Patients Stolen</a></li><li><a href="http://www.endpoint-security.info/2008/05/04/88000-patients-exposed-to-identity-theft/" rel="bookmark" class="crp_title">88,000 Patients Exposed to Identity Theft</a></li><li><a href="http://www.endpoint-security.info/2008/05/29/breach-at-new-york-bank-exposes-millions-to-high-risks/" rel="bookmark" class="crp_title">Breach at New York Bank Exposes Millions to High Risks</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/10/10/hardware-loss-in-a-hospital-endangers-data-of-1-6-million-people/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A virus exposes private data of 3000 patients of an american clinic</title>
		<link>http://www.endpoint-security.info/2011/09/02/a-virus-exposes-the-data-of-3000-patients-of-an-american-clinic/</link>
		<comments>http://www.endpoint-security.info/2011/09/02/a-virus-exposes-the-data-of-3000-patients-of-an-american-clinic/#comments</comments>
		<pubDate>Fri, 02 Sep 2011 10:37:17 +0000</pubDate>
		<dc:creator>cristina</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[Malware Infections]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[private information exposed]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=733</guid>
		<description><![CDATA[An investigation inside the Living Healthy Clinic of Wisconsin, US has revealed the existence of a virus on a computer in the network that exposed 3000 patient records. The experts have concluded that the attack was not targeted, as it was reported that the same type of virus was found on other computers in the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F09%2F02%2Fa-virus-exposes-the-data-of-3000-patients-of-an-american-clinic%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F09%2F02%2Fa-virus-exposes-the-data-of-3000-patients-of-an-american-clinic%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>An investigation inside the Living Healthy Clinic of Wisconsin, US has revealed the existence of a virus on a computer in the network that <a href="http://www.thenorthwestern.com/article/20110826/OSH0101/110826101/Computer-breach-exposes-personal-records-Living-Health-Clinic-patients?odyssey=tab|topnews|text|FRONTPAGE">exposed 3000 patient records</a>.</p>
<p>The experts have concluded that the attack was not targeted, as it was reported that the same type of virus was found on other computers in the US that had nothing to do with the clinic.</p>
<p>The information exposed after the attack included names, addresses, social security numbers and medical records of some patients.</p>
<p>The officials will announce the affected persons on the security breach and they will inform them on the measures to take to protect themselves.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2012/02/07/three-recently-disclosed-data-breaches-share-common-cause-stolen-laptops/" rel="bookmark" class="crp_title">Three recently disclosed data breaches share common cause &#8211; stolen laptops</a></li><li><a href="http://www.endpoint-security.info/2011/08/29/new-data-breaches-reported-by-healthcare-companies/" rel="bookmark" class="crp_title">New Data Breaches Reported by Healthcare Companies</a></li><li><a href="http://www.endpoint-security.info/2008/06/05/the-army-investigates-breach-exposing-1000-to-identity-theft/" rel="bookmark" class="crp_title">The Army Investigates Breach Exposing 1,000 to Identity Theft</a></li><li><a href="http://www.endpoint-security.info/2011/01/03/stolen-laptop-jeopardizes-more-than-3000-patients/" rel="bookmark" class="crp_title">Stolen laptop jeopardizes more than 3000 patients</a></li><li><a href="http://www.endpoint-security.info/2008/05/04/88000-patients-exposed-to-identity-theft/" rel="bookmark" class="crp_title">88,000 Patients Exposed to Identity Theft</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/09/02/a-virus-exposes-the-data-of-3000-patients-of-an-american-clinic/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A recruitment company reveals the salaries of RBS contractors</title>
		<link>http://www.endpoint-security.info/2011/08/25/a-recruitment-company-reveals-the-salaries-of-rbs-contractors/</link>
		<comments>http://www.endpoint-security.info/2011/08/25/a-recruitment-company-reveals-the-salaries-of-rbs-contractors/#comments</comments>
		<pubDate>Thu, 25 Aug 2011 13:51:13 +0000</pubDate>
		<dc:creator>cristina</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[confidential data exposed]]></category>
		<category><![CDATA[insider data breach]]></category>
		<category><![CDATA[RBS]]></category>
		<category><![CDATA[salaries exposed]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=726</guid>
		<description><![CDATA[An unauthorized email sent by the recruitment company Hays to 800 RBS (Royal Bank of Scotland) employees has uncovered the amounts paid to contractors working temporarily for the bank. Even though the people who received the email are employees of the bank and therefore obliged to keep the confidentiality of the information they have found [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F08%2F25%2Fa-recruitment-company-reveals-the-salaries-of-rbs-contractors%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F08%2F25%2Fa-recruitment-company-reveals-the-salaries-of-rbs-contractors%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>An unauthorized email sent by the recruitment company Hays to 800 RBS (Royal Bank of Scotland) employees has uncovered the amounts paid to contractors working temporarily for the bank.</p>
<p>Even though the people who received the email are employees of the bank and therefore obliged to keep the confidentiality of the information they have found out, RBS says they are ‘extremely disappointed’ and they are collaborating with Hays to recover the exposed data. The recruitment company has already started an investigation on this breach.</p>
<p>After this incident, discussions on the big salaries offered to contractors by a bank that is majority-owned by the state were started.</p>
<p>More information on this insider data leak <a href="http://www.computerweekly.com/Articles/2011/08/24/247707/RBS-pay-leak-reveals-the-contractors-paid-1632000-a.htm">here</a>.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/08/26/wonder-if-they-sell-private-records-on-ebay/" rel="bookmark" class="crp_title">Wonder if They Sell Private Records on eBay&#8230;</a></li><li><a href="http://www.endpoint-security.info/2008/06/28/dca-security-breach-exposes-private-records-of-5000/" rel="bookmark" class="crp_title">DCA Security Breach Exposes Private Records of 5,000</a></li><li><a href="http://www.endpoint-security.info/2008/10/13/caught-in-the-act-it-contractor-stole-shell-oil-employee-data/" rel="bookmark" class="crp_title">Caught in the Act: IT Contractor Stole Shell Oil Employee Data</a></li><li><a href="http://www.endpoint-security.info/2008/05/29/breach-at-new-york-bank-exposes-millions-to-high-risks/" rel="bookmark" class="crp_title">Breach at New York Bank Exposes Millions to High Risks</a></li><li><a href="http://www.endpoint-security.info/2010/12/27/private-data-stolen-from-state-computers/" rel="bookmark" class="crp_title">Private data stolen from state computers</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/08/25/a-recruitment-company-reveals-the-salaries-of-rbs-contractors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June, the month with the most data breaches of 2011 so far</title>
		<link>http://www.endpoint-security.info/2011/08/16/june-the-month-with-the-most-data-breaches-of-2011-so-far/</link>
		<comments>http://www.endpoint-security.info/2011/08/16/june-the-month-with-the-most-data-breaches-of-2011-so-far/#comments</comments>
		<pubDate>Tue, 16 Aug 2011 09:00:03 +0000</pubDate>
		<dc:creator>cristina</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[hacking attack]]></category>
		<category><![CDATA[laptop theft]]></category>
		<category><![CDATA[LulzSec]]></category>
		<category><![CDATA[personal information disclosure]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=704</guid>
		<description><![CDATA[According to datalossdb.org, a site belonging to the Open Security Foundation, that publishes the latest news regarding data loss and data breaches, the month of 2011 with the largest number of such incidents was June, when 90 cases were recorded. The causes of these incidents were very diverse: from the ever-present theft of computers, laptops [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F08%2F16%2Fjune-the-month-with-the-most-data-breaches-of-2011-so-far%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F08%2F16%2Fjune-the-month-with-the-most-data-breaches-of-2011-so-far%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>According to <a href="http://datalossdb.org/" target="_blank">datalossdb.org</a>, a site belonging to the Open Security Foundation, that publishes the latest news regarding data loss and data breaches, the month of 2011 with the largest number of such incidents was June, when 90 cases were recorded.</p>
<p>The causes of these incidents were very diverse: from the ever-present theft of computers, laptops or hard drives and other portable devices, to fraud, hacking attacks, personal information disclosed on websites, viruses, documents thrown in the dustbin, etc.</p>
<p>The most significant breach from June was the one produced at Sony Pictures, when the LulzSec hackers have accessed one million records of Sony clients in Belgium and the Netherlands.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/11/01/2011-brings-major-changes-in-the-biggest-data-breaches-of-all-times-top/" rel="bookmark" class="crp_title">2011 Brings Major Changes in the Biggest Data Breaches of All Times Top</a></li><li><a href="http://www.endpoint-security.info/2011/06/03/hackers-target-sony-once-more-thousands-of-customer-records-exposed/" rel="bookmark" class="crp_title">Hackers Target Sony Once More, Thousands of Customer Records Exposed</a></li><li><a href="http://www.endpoint-security.info/2011/09/05/are-hackers-going-to-be-this-year%e2%80%99s-top-news-item/" rel="bookmark" class="crp_title">Are Hackers Going to Be This Year’s Top News Item?</a></li><li><a href="http://www.endpoint-security.info/2011/08/16/more-data-breaches-caused-by-improper-use-of-flash-drives-and-laptops/" rel="bookmark" class="crp_title">More data breaches caused by improper use of flash drives and laptops</a></li><li><a href="http://www.endpoint-security.info/2011/06/20/hacks-and-stolen-hardware-top-data-breach-causes/" rel="bookmark" class="crp_title">Hacks and Stolen Hardware, Top Data Breach Causes</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/08/16/june-the-month-with-the-most-data-breaches-of-2011-so-far/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers Partially Close down the Hong Kong Stock Exchange</title>
		<link>http://www.endpoint-security.info/2011/08/11/hackers-partially-close-down-the-hong-kong-stock-exchange/</link>
		<comments>http://www.endpoint-security.info/2011/08/11/hackers-partially-close-down-the-hong-kong-stock-exchange/#comments</comments>
		<pubDate>Thu, 11 Aug 2011 10:13:25 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[In the News]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Hong Kong]]></category>
		<category><![CDATA[Internet safety]]></category>
		<category><![CDATA[stock exchange]]></category>
		<category><![CDATA[web threats]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=700</guid>
		<description><![CDATA[Hackers targeting the Hong Kong stock exchange have managed to do enough damage to force them to close afternoon trading for seven listed companies. The attack targeted the news section of the stock exchange and managed to severely disrupt day-to-day activities. The news website, which publishes companies&#8217; regulatory filings, started going down at noon, however [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F08%2F11%2Fhackers-partially-close-down-the-hong-kong-stock-exchange%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F08%2F11%2Fhackers-partially-close-down-the-hong-kong-stock-exchange%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.endpoint-security.info/wp-content/uploads/2011/08/Hong-Kong-stock-exchange.jpg"><img style="float: left; margin-right: 10px" title="Hong Kong stock exchange" src="http://www.endpoint-security.info/wp-content/uploads/2011/08/Hong-Kong-stock-exchange.jpg" alt="" width="159" height="240" /></a>Hackers targeting the Hong Kong stock exchange have managed to do enough damage to force them to close afternoon trading for seven listed companies. The attack targeted the news section of the stock exchange and managed to severely disrupt day-to-day activities.</p>
<p>The news website, which publishes companies&#8217; regulatory filings, started going down at noon, however according to Hong Kong stock exchange representative, the trading part of the website had not been breached. The <a href="http://www.computerweekly.com/Articles/2011/08/11/247591/Hong-Kong-Stock-Exchange-suspends-trading-after-hackers-close-news.htm" target="_blank">stop in trading</a> that affected HSBC, Cathay Pacific Airways and the Hong Kong Exchanges &amp; Clearing, which runs the stock exchange, was a necessary measure as all had released price-sensitive information earlier in the day. As the fresh news could not be accessed, it was safer to end the afternoon trading for the seven companies. <span id="more-700"></span></p>
<blockquote><p>&#8220;Our current assessment is that this is a result of a malicious attack by outside hacking,&#8221; said Charlies Li, chief executive of Hong Kong Exchanges &amp; Clearing.</p></blockquote>
<p>The partially closed trading session affected stocks that made up 18% of the Hang Seng index’s weight. Moreover, this is a historic first – the first time the Hong Kong stock exchange has to suspend trading for technical reasons.</p>
<p><a href="http://www.flickr.com/photos/jlascar/4565449622/sizes/s/in/photostream/" target="_blank"><em>Photo source</em></a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/09/05/are-hackers-going-to-be-this-year%e2%80%99s-top-news-item/" rel="bookmark" class="crp_title">Are Hackers Going to Be This Year’s Top News Item?</a></li><li><a href="http://www.endpoint-security.info/2008/04/30/data-on-700-children-with-social-and-developmental-problems-lost/" rel="bookmark" class="crp_title">Data on 700 Children with Social and Developmental Problems Lost</a></li><li><a href="http://www.endpoint-security.info/2008/03/26/stolen-agilent-laptop-with-records-of-51000-employees/" rel="bookmark" class="crp_title">Stolen Agilent Laptop with Records of 51,000 Employees</a></li><li><a href="http://www.endpoint-security.info/2011/06/22/whos-the-next-big-gaming-company-to-be-hacked/" rel="bookmark" class="crp_title">Who&#8217;s the Next Big Gaming Company to Be Hacked?</a></li><li><a href="http://www.endpoint-security.info/2011/09/15/data-breach-exposes-40000-credit-and-debit-cards/" rel="bookmark" class="crp_title">Data breach exposes 40,000 credit and debit cards</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/08/11/hackers-partially-close-down-the-hong-kong-stock-exchange/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

