data security

Data breach story with a happy ending? Sort of.

As detailed in this American Banker article, an FDIC employee who was leaving the agency copied over 40,000 records with PII onto a portable drive.  Although technically a data breach, the intent was apparently innocuous as the employee was copying various personal photos and other files (which probably shouldn't be on an FDIC work computer) on [...]

By |2017-11-18T15:32:41-05:00April 15th, 2016|data breach, data security, FDIC|Comments Off on Data breach story with a happy ending? Sort of.

Massive Turkey data breach affects nearly half of its citizens, is nearly double the size of the 2015 U.S. OPM breach

Yesterday's report of a massive data breach involving nearly half of the citizens of Turkey is the latest in a series of hacks designed to make a political or philosophical point.  In this case, the hacker (or "hacktivist") apparently had a beef with the Turkish government, although financial gain may also have been an objective.  While the [...]

By |2017-11-18T15:32:41-05:00April 6th, 2016|data breach, data security, EMV, PCI-DSS|Comments Off on Massive Turkey data breach affects nearly half of its citizens, is nearly double the size of the 2015 U.S. OPM breach

Path of least resistance: EMV adoption shifting fraudsters’ focus to ecommerce, data breaches continue

It's a well-understood phenomenon in the payments space:  Fraudsters are opportunists who will adapt their tactics to focus on the most vulnerable parts of the payments ecosystem.  Sort of a criminal version of "whack a mole". According to a report by TransUnion, adoption of EMV at the retail point of sale is causing a steep [...]

By |2016-03-29T19:29:34-05:00March 29th, 2016|authentication, Biometrics, data breach, data security, ecommerce, EMV, Experian, TransUnion|Comments Off on Path of least resistance: EMV adoption shifting fraudsters’ focus to ecommerce, data breaches continue

You can’t make this up: FTC wants to know whether assessors are helping clients achieve PCI-DSS compliance

The FTC has questions about how PCI-DSS Qualified Security Assessors (QSAs) conduct their audits and recently ordered itself to study the issue. Merchants and service providers whose processing volume exceeds established volume thresholds are required to use a QSA to assess PCI compliance.  The FTC wants to know (among other things) whether QSAs are allowing clients to remedy potential PCI issues before their [...]

By |2017-11-18T15:32:42-05:00March 11th, 2016|CFPB, data security, FTC, PCI-DSS|Comments Off on You can’t make this up: FTC wants to know whether assessors are helping clients achieve PCI-DSS compliance

Ouch! Home Depot’s 2014 data breach price tag: $161 million (so far)

What is it they say about an "ounce of prevention"? Home Depot's recent $19.5 million consumer compensation announcement brings their costs related to the 2014 data breach to $161 million, and that doesn't include costs to upgrade internal systems security and beef up their risk management team.   Even scarier:  Home Depot's lawyers say the settlement [...]

By |2017-11-18T15:32:42-05:00March 9th, 2016|data breach, data security|Comments Off on Ouch! Home Depot’s 2014 data breach price tag: $161 million (so far)
Go to Top