Lawyer ⚖️, Historian, Navy vet ✈️, Philly and Penn State sports fanatic 🏈⚾🏀, Dad and Husband. Blogging at the intersection of state power and civil liberties.
Showing posts with label breach. Show all posts
Showing posts with label breach. Show all posts
18 January 2016
Hacked casino sues Trustwave over security breach cleanup
A Las Vegas-based casino, Affinity Gaming, hired Chicago-based security firm Trustwave, to investigate a data breach. According to Affinity, Trustwave claimed to have identified the source of the data breach and contained it. Instead, however, further investigation by Mandiant found that Trustwave failed to contain the breach, which continued to occur even while Trustwave was investigating. According to the ZDNet article linked below, Trustwave denied the claims and plans to defend itself in court.
The complaint filed in federal court is available here.
Affinity's claims are:
1) Fraudulent Enducement
2) Fraud
3) Constructive/Equitable Fraud
4) Violations of NRS Chapter 598; Fraud Upon Purchasers; Misrepresentation
5) Gross Negligence
6) Negligent Misrepresentation
7) Breach of Contract
8) Declaratory Judgment under 28 U.S.C. §§ 2201-2202
Here are links to articles from arstechnica, ZDNet, and TheHill.
12 June 2015
The OPM breach was really, really bad. The OPM response is really, really bad.
The breach was apparently discovered sometime last year (!) when a vendor was doing a product demo on the production network. The idea that a vendor was doing a sales presentation on their production network is terrifying. Nothing to see here!
So far, we're hearing that at least 4 million (but potentially as many as 14 million?!) government employees were affected. Also, not much mention of government contractors, although the second link above speculates on that (OPM says: "No contractors were affected unless they previously held Federal civilian positions."). I'm not comfortable with their confidence, so still waiting for that shoe to drop. I personally haven't heard a peep from Booz Allen. I expect we'll hear more about this soon.
So far, we're hearing that at least 4 million (but potentially as many as 14 million?!) government employees were affected. Also, not much mention of government contractors, although the second link above speculates on that (OPM says: "No contractors were affected unless they previously held Federal civilian positions."). I'm not comfortable with their confidence, so still waiting for that shoe to drop. I personally haven't heard a peep from Booz Allen. I expect we'll hear more about this soon.
After the breach, OPM contracted with an identity theft company called CSID to provide ID theft protection for all affected government employees. Then, CSID sent the employees a shady looking email from csid.com and as of today, many people still think the email is a phishing attempt. Users were told to delete any email claiming to notify them of the breach. At the same time, OPM published on its website for employees to expect the email from csid.com, and the FTC claims the emails are legit. You can't make this shit up.
Here is Teri Centner's blog post which nicely summarizes the issue.
Here is the announcement from OPM telling users to expect an email from opmcio@csid.com.
Here is the FTC page authenticating the CSID emails.
Subscribe to:
Posts (Atom)



