Normal view
Unlimited Technology Systems Data Breach Affects 3.8 Million Patients
-
DataBreaches.Net
- AU: Updoc patients notified of security breach where personal information may have been stolen
AU: Updoc patients notified of security breach where personal information may have been stolen
-
DataBreaches.Net
- The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.
The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.
CareCloud Data Breach Impacts Over 350,000
-
DataBreaches.Net
- AU: GO2 Health medical clinic in Brisbane waited almost three months to alert patients it was hacked
AU: GO2 Health medical clinic in Brisbane waited almost three months to alert patients it was hacked
Mon General Hospital notifies patients of phishing attack and breach
AMGEN reports breach to SEC
Family says woman violated HIPAA, ‘weaponized’ info
-
DataBreaches.Net
- Accountant laundered $5.3 million stolen from Children’s Healthcare of Atlanta by hacker, prosecutors say (1)
Accountant laundered $5.3 million stolen from Children’s Healthcare of Atlanta by hacker, prosecutors say (1)
-
DataBreaches.Net
- Developing: AnMed reports phone and internet outage impacting all hospital locations; ERs remain open
Developing: AnMed reports phone and internet outage impacting all hospital locations; ERs remain open
-
DataBreaches.Net
- AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’
AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.
Proxy SDK prevalence among smart TV apps for LG (webOS) and Samsung (Tizen OS) televisions. Image: Spur.us.
On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one’s television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components.
Responding to questions about Spur’s research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended.
“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said. “If this option is not removed, these apps will be suspended.”
Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company’s review of those apps is “well underway now.”
“As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs,” Taylor wrote in an emailed statement.
App makers looking for ways to monetize their creations can turn to residential proxy providers, which pay developers to include SDKs that turn the user’s device into a residential proxy node that is rented to paying customers. In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and file utilities.
A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node. Image: Spur.us.
Spur’s report found the residential proxy network Bright Data accounted for a majority of proxy SDKs across both Samsung and LG smart TVs. In a statement shared with KrebsOnSecurity, Bright Data said its network is built on consent and responsibility and operates by LG and Samsung terms.
“Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC,” the statement reads. “We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain.”
Bright Data and other proxy providers named in Spur’s report all say they follow rigorous know-your-customer processes to validate legitimate uses of their services, which is often heavily tied to content-scraping activities by said customers. The proxy companies also say they incorporate technological countermeasures to prevent proxy service customers from being able to interact with and control other devices on the proxy user’s local network.
Spur argues the problem is not that residential proxy networks exist, but rather that they are being embedded at scale in devices that most consumers do not think of as computers and are not equipped to audit.
“A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight,” Spur’s Trevor Sutter wrote. “The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors.”
LG’s announcement that it is culling residential proxy SDKs from its app store is welcome news, but the company recently came under fire for another questionable partnership: Pimping McAfee security products via software drivers included in its high-end LCD monitors.
Earlier this week, the Youtube channel Gamers Nexus showed that certain LG LCD monitors will automatically install an app that promotes paid McAfee antivirus subscriptions, and that the app arrives through Windows Update without an approval prompt.
Update, July 22, 1:06 p.m. ET: Added statement from Bright Data.
-
DataBreaches.Net
- Medical giant Abbott investigates two cyber incidents as ShinyHunters and ShadowByt3$ both claim breaches
Medical giant Abbott investigates two cyber incidents as ShinyHunters and ShadowByt3$ both claim breaches
-
DataBreaches.Net
- NY Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic Data
NY Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic Data
-
CyberScoop
- State officials, election experts pan Trump speech: ‘This is what desperation looks like’
State officials, election experts pan Trump speech: ‘This is what desperation looks like’
State and local officials and election security experts largely panned a Thursday night primetime speech by President Donald Trump, saying it was reflective of White House “desperation” to find any credible evidence to support their claims that U.S. elections have been rigged against the two-term president.
While the White House teased explosive new claims about the potential compromise of U.S. elections by China, Trump’s speech was a rehash of claims that both have no supporting evidence and have been repeatedly debunked when investigated.
David Becker, executive director of the Center for Election Innovation and Research and a former voting and civil rights attorney at the Department of Justice, said none of Trump’s claims or allegations were new or substantively different from previous theories he’s been espousing over the past six years.
“The White House promised a bombshell and they delivered a dud,” Becker said on a call with reporters Friday. “There was nothing that even calls into question past elections — certainly not the 2020 election.”
The administration declassified a huge tranche of documents from the intelligence agencies, and news outlets continue to sift through them, but thus far nothing has been found that remotely validates the administration’s claims about foreign interference from China costing Trump the 2020 election.
In fact, some of the most relevant documents found at this point have supported the opposite conclusion, with agencies assessing that while China engaged in influence campaigns around the election, it was not attempting to outright interfere with U.S. election infrastructure, hack voting machines or manipulate ballots.
John Solomon, a former journalist and opinion writer at The Hill brought in by the White House to lead the investigation, also told reporters Thursday that his search hasn’t turned up evidence that the 2020, 2022 or 2024 elections were affected by fraud.
The one new major claim by Trump — that the Department of Homeland Security determined hundreds of thousands of noncitizens were registered to vote across four states — is almost certainly false or overinflated, given that it contradicts post-election state audits that have routinely found single or double-digit numbers of noncitizens registered to vote within a single state across multiple elections.
Over the past six years, similar claims by GOP secretaries of state and political activists purporting to find mass numbers of noncitizens registered to vote have turned out to be grossly inflated due to shoddy data analysis, and the vast majority of cases involving “suspected noncitizens” turn out to be U.S. citizens who are legally registered to vote.
The White House has provided little to no information on the methodology used to flag and identify supposed noncitizen voters, other than alluding to the use of “commercial data” and federal databases. A federal court recently ordered DHS to dismantle the SAVE database, its primary database for verifying the citizenship status of U.S. voters, because it was unreliable and violated longstanding privacy laws.
Apart from DHS admitting its own data on citizenship is incomplete, Becker said using a list that relies on matching voter files with commercial data is not a reliable way of determining citizenship.
“It is impossible to take a public voter file with very little information that is uniquely identified, like a driver’s license number, and compare it to a commercial database and say for sure the Maria Rodriguez or the John Lee or the Shawn O’Hara you have on that is the same person,” he said.
Election officials also responded forcefully. Nevada Democratic Secretary of State Francisco Aguilar said that Trump has spent a decade attempting to manufacture a crisis around voter fraud and the president’s speech Thursday night was an extension of that effort.
“As Nevada’s chief elections officer, it’s my job to call balls and strikes — so when the President lies, I am obligated to call him out,” Aguilar said in a statement. “The facts have not changed: Nevada’s elections are among the safest, most secure and accessible in the nation.”
It’s not just Democrats that have objected to the administration’s efforts. GOP states have gone to court to block the Department of Justice from obtaining their voter data, and Idaho’s Republican secretary of state responded to a DOJ letter threatening prosecution of election officials as “not well met” and potentially illegal under state ethics laws.
Trump’s speech potentially casts additional light on recent White House decisions, such as firing all three commissioners on the Election Assistance Commission. The agency helps certify voting machines for security, and all three commissioners have served across administrations and maintain close relationships with state and local election officials.
Pamela Smith, CEO of the nonprofit Verified Voting, said that while the EAC can’t take certain actions that need commissioner approval, “critical functions like voting system testing and certification can continue under the existing framework and should not be affected.”
In 2020, Trump’s initial claims of widespread election fraud were undercut by leaders at the Cybersecurity and Infrastructure Security Agency, which said there was no evidence the election was compromised. The removal of EAC commissioners could represent an attempt to preempt any efforts to rebut or criticize White House claims that elections and voting machines have been compromised.
Some have worried that Trump could use the speech as a pretext to declare a national emergency or cancel elections.
Tom Lopach, CEO of the Voter Participation Center, said “you don’t dismantle election security infrastructure if you’re serious about protecting elections.”
“You dismantle it if you’re planning to claim, without evidence, that the system failed you,” he said.
While Becker takes Trump’s broadsides against state election authority seriously, he also said it’s important not to lose sight of the fact that, in his view, the administration is losing the argument across the board.
More than a dozen federal courts have unanimously rejected the federal government’s attempts to forcibly obtain state voter data, while other courts have rejected core pieces of his election-related executive orders. State officials have publicly — and at times, angrily — pushed back on the administration’s demands as blatant federal overreach.
Becker predicted that such an act would be quickly shot down by courts as well, noting that the U.S. has never canceled or postponed an election in its 250-year history, including when British troops were marauding on American soil during the War of 1812 or even at the height of the Civil War.
It’s important not to conflate the White House’s bluster and intentions with its actual authorities or capability to seize control of U.S. elections.
“This is what panic and desperation look like,” Becker said. “They’ve had 18 months in total control of the federal government and they have found nothing that would support President Trump’s lies about the 2020 election, and so they’re just trying to grab as much garbage as they can and throw it up against the wall, and it’s not sticking.”
The post State officials, election experts pan Trump speech: ‘This is what desperation looks like’ appeared first on CyberScoop.
AU: Partnered Health Data Breach Exposes Patient Records at Family Clinics
Finland issues wanted notice for hacker behind massive psychotherapy data breach
States are building their own election defense networks as federal support evaporates
The Trump administration’s abrupt firing of Election Assistance Commission commissioners last week and a Department of Justice warning threatening states with criminal prosecution have created new legal peril for officials who run, administer and secure elections.
The EAC is an obscure but important agency that oversees testing and standards for voting machines, including around security. While federal certification is voluntary, states have until now relied upon their stamp of approval when purchasing voting machines.
On July 10, Democratic Commissioners Ben Hovland and Thomas Hicks were fired by the White House, while reports indicate that a third Commissioner, Republican Christy McCormick, resigned. While Congress mandated the commission be bipartisan, the Supreme Court has recently given the President broad authority to fire executive branch officials at will.
In an interview with NPR, Hovland said he worried the firings would further erode trust that the commission was working in a bipartisan manner.
“And as you eliminate things – or if you get rid of commissioners, for example – or as you eliminate some of these other sort of safeguards or norms, it certainly strains the system,” said Hovland. “And it certainly also likely causes people to lose faith in our democracy and in the process and their confidence in our elections. And that’s very concerning.”
A letter also sent last week to all 50 states by the DOJ said the department will investigate and prosecute any election official “who knowingly retains non-citizens on the state’s voter registration list or facilitates noncitizens in receiving and casting ballots.”
CyberScoop spoke with several Secretaries of State who said that the number one threat facing elections in their state is not from a foreign country or AI but their own federal government.
Tobias Read, the Democratic Secretary of State for Oregon, told CyberScoop that his office is focused on providing the state’s 36 county clerks with the resources and support they need to carry out a smooth election. But he acknowledged that his office is “playing defense in a lot of ways [from] the intrusion from the federal government” that continues to assert its authority over local elections.
“If the president were actually serious about election security, he would be sending more resources to local election officials and bolstering the system rather than cutting it,” said Read.
This year, several counties in Oregon will offer voters access to a new ballot tracking system that provides text or email updates when a voter’s ballot is moving through mail and has been certified. Reed estimated at “pennies per voter per election” and called it a good option for cash-strapped counties to assure voters their ballots are secure and properly tracked.
At the same time, Read said federal agencies like the Cybersecurity and Infrastructure Security Agency – which once regularly deployed cybersecurity and technical expertise to help states fix vulnerabilities and share threat intelligence – have largely gone quiet.
Oregon ranks in the top ten states for voter participation and relies heavily on mail-in voting. However, state officials like Read lack confidence in the US Postal Service. Though a recent Supreme Court decision blocked an executive order giving the service control over mail-in ballot distribution, officials like Read are urging voters to take other measures to use drop boxes instead as a safer alternative to ensure their vote is counted.
Adrian Fontes, Arizona’s Secretary of State and a Democrat running for reelection, said his office is focused on primary elections and processing the mail ballots that have been arriving “for a while.”
After Iranian hackers defaced Arizona’s candidate bio portal last year, Fontes moved to fill a widening gap: the Trump administration’s withdrawal of federal foreign interference training and support. His office is now directly supporting local jurisdictions on election security while coordinating more closely with state law enforcement, intelligence agencies, and other states.
But it’s being done with a fraction of the resources and coordination that the federal government brought to bear under both the Biden and first Trump administrations. While Fontes said he maintains positive personal relationships within the Department of Homeland Security, his office does not have a formal relationship with CISA.
“We’ve hobbled together a loose and often informal network of information sharing – that doesn’t violate any rules, it doesn’t break any laws – but it is certainly not anywhere near as robust as it would be if we had a responsible federal agency that was interested in the security of American elections,” said Fontes.
He said even if CISA offered such services today, he wouldn’t accept it, citing the lack of trust between states and the Trump administration.
“They have proven through their actions that they don’t want to be effective partners in protecting the American electorate and protecting American voters,” said Fontes. “Because of that, the clear answer, the only sensible answer for someone like me, would be to say ‘No, I don’t want the help of people I cannot trust.’ People who have demonstrably and explicitly threatened me and local election administrators of all political stripes with criminal prosecution.”
After this story’s initial publication, CISA acting director Nick Andersen said the agency remains committed working with “with critical infrastructure owners and operators to assist them in securing both the physical security and cybersecurity of the systems and assets that support the nation’s election process.”
“We provide state and local election officials, upon request, no-cost voluntary services such as the sharing of threat information, technical expertise, vulnerability scanning, and resilience-building support,” said Andersen in a statement sent to CyberScoop. “Our regional teams assist partners across the country by assessing risks, helping entities bolster defenses and improve resilience, and responding promptly to threats. We are committed to supporting state and local elections officials to protect election infrastructure and safeguard our democracy.”
Secretaries of State in Colorado, Nevada, Minnesota, Rhode Island, and others have also called the DOJ letters an attempt at federal intimidation of election officials.
Others, like West Virginia Republican Secretary of State Kris Warner, have reiterated their refusal to hand over state voter data. On Monday, a federal judge upheld his right to do so.
Warner wrote to the DOJ in response to say the state was “available to discuss our existing voter registration list maintenance” but “West Virginia law prohibits the disclosure of sensitive personally identifiable information contained in voter registration records.”
It’s leading some states to take new precautions.
Read said he was working with Oregon county officials to make sure “county clerks have the number of their county counsel on speed dial” and know how to distinguish between a legitimate and illegitimate federal warrant or subpoena.
Additionally, FBI raids of election offices around the country to seize ballots records related to the 2020 and 2024 elections have been a cause for Read’s concern. By state law, Oregon and other states must keep copies of the ballot records and other election data they receive from counties for a certain time according to state law, after which they must eventually archive or destroy them according to ballot retention schedules.
Read emphasized that “it’s important to destroy those ballots at the appropriate time,” The Trump administration has used the raids to further the impression of electoral fraud, despite the absence of credible evidence.
“We can see when people are not on top of that, then you expose yourself to other vulnerabilities like the federal government seizing those ballots in Maricopa County [Arizona] and Fulton County [Georgia] as well,” said Read.
A former CISA official estimated that on Election Day in 2024, more than 1,000 representatives from federal, state and local governments, election technology vendors and other election stakeholders sat together in a room to communicate and coordinate.
Less than two years later, Read called his office’s interactions with CISA “minimal.” He recalled that upon taking office as Secretary of State in Jan 2025, one of his first conversations was with one of CISA’s regional advisors. A week later, those advisors were summarily fired by the Trump administration.
UPDATE: 7/14/2026, 11:15 a.m.: Updated with comments from CISA acting director Nick Andersen.
The post States are building their own election defense networks as federal support evaporates appeared first on CyberScoop.
-
DataBreaches.Net
- Patients Sue Healthcare Corporations Over Data Breaches, Sharing of Personal Information