❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

NYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services Entities

By: Dissent
12 September 2026 at 18:15
New York State Department of Financial Services (DFS): September 10, 2026 New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow today issued new cybersecurity guidance outlining the Department’s expectations for DFS-regulated entities’ on conducting risk assessments sufficient to inform their cybersecurity programs. The guidance outlines requirements regarding scope, frequency, and the role...

Source

Personal Information Exposed in Apollo Global Data Breach

By: Dissent
24 August 2026 at 08:22
Eduard Kovacs reports: Private equity giant Apollo Global Management has disclosed a data breach that exposed sensitive personal information. According to a data breach notice sent to affected individuals, a social engineering attack enabled threat actors to access some of the company’s cloud platforms between July 6 and 10. An investigation is ongoing, but Apollo determined recently...

Source

Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’

24 August 2026 at 15:06

As part of its “economic D-Day” against Iran, the Treasury Department designated four Iranians for sanctions Monday stemming from their alleged role in hacking critical infrastructure targets and waging cybertheft against the United States.

It’s the second time in as many weeks that the Trump administration has taken aim at the same group of alleged hackers, following on an indictment recently unsealed against cybercriminals that federal law enforcement authorities say are affiliated with the Tehran-based Mabna Institute.

A Treasury Department release points the finger at three people — Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i and Mojtaba Ghal’eh-Kuhi — as specifically conducting the hacks.

“Since at least late 2023, these three individuals have successfully compromised and exfiltrated data from multiple U.S. companies in various critical infrastructure sectors, including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions,” the release states.

A fourth individual included in Monday’s sanctions, Mojtaba Ghal’eh-Kuhi, is listed as one of the leaders of the gang carrying out the Ministry of Intelligence and Security (MOIS)-directed attacks. Another listed leader, Behzad Mesri, first faced sanctions in 2018, as part of another round of sanctions focused on the Mabna Institute.

Finally, the Treasury Department designated one additional person Monday over related activity, Arman Kahzadian, for his alleged role in receiving or using business information stolen via cyber-enabled means.

The department said the Iranian hackers sometimes turn their gaze to domestic targets.

“The members of this group are also heavily motivated by personal enrichment and greed, leading some members to prioritize their own profits over operations that benefit the MOIS,” it said. “This has driven some of the group to target Iranian companies.“

Hackers that the U.S. government has identified as Iranian have been behind a spate of attacks on U.S. water facilities, despite denials from President Donald Trump himself about Iranian culpability.  The Treasury Department did not immediately respond to a request for comment Monday about whether the sanctions designees were involved in those attacks, nor has the National Security Agency responded to requests for comment on whether Iran was responsible for attacks at the center of an alert about attacks on water facilities.

Treasury Secretary Scott Bessent announced a fuller list of sanctions Monday as the war with Iran nears its five-month anniversary with no end in apparent sight.

“In the Second World War, D-Day marked the historic beginning of a campaign with our allies to target and drive the enemy from its positions, including those in third countries,” he said. “Today, in that same spirit, we are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone.”

There are questions about whether the sanctions themselves are likely to change any behavior, particularly based on how they will be enforced. Iran has vowed “consequences” for the United States.

As part of the sanctions announced Monday, according to the department, “Treasury is expanding the categories of Iran-related conduct that may be subject to secondary sanctions in the future, making it easier to take action against those facilitating the regime. Treasury has issued determinations against five critical sectors –– digital assets, technology, gold, aviation, and shipping––  that the Iranian regime uses to try to prop up its failing economy.”

The post Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ appeared first on CyberScoop.

More than 2 million user records from TaxAct allegedly acquired; 450k already leaked (with correction)

By: Dissent
17 August 2026 at 09:23
On August 13, DataBreaches was contacted anonymously on Signal by someone reporting that they had acquired more than 2 million records with clients’ phone numbers, usernames, and email addresses from TaxAct, which is owned by Cinven. TaxAct operates under its parent company and holding entity, Taxwell. Not all the phone numbers were real, they reported,...

Source

Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers

By: Dissent
17 August 2026 at 09:19
Olivier Acuna reports: Cryptocurrency broker Bits of Gold said personal data belonging to roughly 200,000 customers was stolen by hackers, the company reported. The Tel Aviv, Israel-based company reported the security breach on Sunday, saying a hacker gained unauthorized access to a third-party data analytics network and gained access to customers’ names, national ID numbers, emails,...

Source

New York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc.

By: Dissent
7 August 2026 at 17:50
A press release from the NYS DFS: August 5, 2026 New York State Department of Financial Services Acting Superintendent Kaitlin Asrow announced today that Order Express, Inc., a licensed money transmitter, will pay a $250,000 penalty for violations of DFS’s cybersecurity regulation (23 NYCRR Part 500). DFS investigators identified deficiencies in the company’s cybersecurity program...

Source

Hackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too. (Corrected)

By: Dissent
27 July 2026 at 15:20
Three times may be a charm for some things, but not for data security incidents. Frontier Airlines allegedly has had a third data security incident this year. First, it was BobDaHacker publishing a blog post on June 16 titled “Your Boarding Pass Is a Skeleton Key.” Frontier Airlines Doesn’t Care. According to the post, Frontier...

Source

Most federal cybersecurity reporting rules are duplicative, study finds

22 July 2026 at 17:04

Seven out of 10 federal cyber regulations requiring written reports to federal agencies are duplicated elsewhere, a report from a government watchdog found in a report to Congress Wednesday.

And so far, efforts to de-conflict haven’t had much success, the report from the Government Accountability Office concluded.

At the request of two top lawmakers, the GAO examined federal cyber regulations at 37 agencies. It counted 80 out of 117 rules that “either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.”

The desire to harmonize those conflicting rules gathered steam under the Biden administration, as it undertook a more aggressive push to regulate cybersecurity than prior administrations. It has continued into the second Trump administration.

The GAO scrutinized regulations that required the private sector to report cybersecurity incidents, plans and reviews to federal agencies, as part of a study sought by House Homeland Security Chairman Andrew Garbarino, R-N.Y., and the top Democrat on the Senate counterpart to Garbarino’s panel, Gary Peters, D-Mich.

In some cases, a single critical infrastructure sector could have duplication with several agencies. For example, the Cybersecurity and Infrastructure Security Agency has been working on a regulation stemming from the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which would require critical infrastructure owners and operators to report when they are the victims of major attacks or make ransomware payments.

Elements of the financial services sector might fall under one of 15 preexisting cybersecurity reporting rules, depending on the agency that has oversight, but they may also be subject to the pending CIRCIA rules, GAO noted.

A 2024 national security memorandum tasked the Office of the National Cyber Director and the Department of Homeland Security to harmonize conflicting regulations, and both agencies made some progress on those goals.

But the executive branch paused some of those efforts after Trump issued an executive order in March of last year while the administration conducted a study of the 2024 memo, a study that was still underway as of last month, according to the GAO.

As such, on harmonization, “many past federal efforts have experienced delays and made limited progress,” the GAO concluded in its report Wednesday, its latest on the topic. 

Congress has also looked at ways to streamline cybersecurity regulations.

GAO’s study was focused only on federal rules. BreachRx, a cyber incident response firm, published its own report Wednesday looking at major cyber incidents and how overlapping regulatory reporting obligations came into play, folding in regulations from states and other sources.

The post Most federal cybersecurity reporting rules are duplicative, study finds appeared first on CyberScoop.

❌
❌