Seen on FB:
Dissent Doe 
Blogger/journalist at databreaches.net and pogowasright.org. As a retired healthcare professional, breaches in the healthcare sector are my priority.
The header pic is Indy, a Siberian husky we rescued in 2016 after I read how nobody wanted her because she was so difficult. She is now living her best life and is a mushball with me.
South Korea is cracking down on companies with major data breaches to push them to be more proactive. As seen in Korea JoongAng Daily:
"Starting Friday, companies found to have leaked the personal data of 10 million or more people through intent or gross negligence can be fined up to 10 percent of their total revenue as part of a broader overhaul under the revised Personal Information Protection Act that is set to take effect the same day. Even if a leak hasn’t been confirmed, companies must notify users within 72 hours if the risk of exposure is high.
[…]
Under the enforcement decree, the cap applies to companies that repeatedly commit intentional or grossly negligent violations within three years, or that fail to comply with a corrective order and go on to suffer a breach as a result. Fines are calculated based on the nature and severity of the violation, the circumstances involved and the scale of the damage.
Link: https://www.koreajoongangdaily.com/business/korea-raises-data-breach-fines-to-10-of-revenue/12869899
In the past, South Korea's financial regulators have also fined executives and prohibited some card issuers and banks from signing up any new customers for months as a consequence of big breaches.
I wonder if their efforts/consequences are actually effective in getting more entities to take infosecurity and cybersecurity more seriously.
And I bet we can all think of U.S. companies that might qualify to get hit with such huge penalties.
#databreach #accountability #legislation #SouthKorea #infosecurity #cybersecurity
NEW by me:
The U.S. military leaked more than 93,000 tips via insecure P3 Global Intel. Has anyone been notified?
I had reported on the school-related tips in the Navigate360 breach, and then the Crime Stoppers tips. In this post, I looked at the tips to the U.S. military.
#Navigate360 #P3GlobalIntel #databreach #cybersecurity #incidentresponse

NEW, by me:
Silent Ransom Group Hacked Greenberg Traurig; Who notifies the 126k Affected?
GT says they notified a small number of affected clients. But more than 126,000 clients were affected.
We dug into the data tranche, obtained exclusive details from the threat actors, and asked Yelisey Bohuslavskiy for his thoughts on the group and attempts to prevent their attacks.
#databreach #infosec #cybersecurity #hack #extortion #SilentRansomGroup #SRG #GreenbergTraurig
RE: @josephcox@infosec.exchange
This may be the most horrifying and infuriating piece I've ever read about the dangers of ChatGPT. Great reporting, as always, by @josephcox@infosec.exchange and @404mediaco@mastodon.social
NEW by me:
Navigate360 may soon release a public notice about its horrific breach, but will any individuals be notified?
#databreach #infosec #cybersecurity #incidentresponse #notification #Navigate360 #P3GlobalIntel
The city manager of the City of Coweta is refusing to even contact unnamed threat actors and says the city will not pay any ransom in response to a recent ransomware attack.
Why? Because the city manager was with another city that was attacked; even though that city paid the ransom, it was reinfected two weeks later. So now she is very anti-paying.
Read more at KTUL:
https://ktul.com/news/local/city-of-coweta-refuses-to-pay-ransom-after-system-wide-cyberattack-08-08-2026
And as I previously reported on this incident, the city has an offsite backup they say they can use to restore all city files after they clean the servers of ransomware.
Good for her and the city.
One of the dozens of new #ransomware groups this year is a group calling itself #Orova. Since early May, they appear to have dozens of victims in about half a dozen countries.
Three of the listings are U.S. medical entities, so, of course, I reached out to them to find out more.
My new report:
Cardiology Associates of Port Huron remains silent although they were allegedly hacked and had patient data stolen in June.
#databreach #healthsec #cybersecurity #extortion #encryption
New York State Department of Financial Services announced on August 5 that Order Express, Inc., a licensed money transmitter, will pay a $250,000 penalty for violations of DFS’s cybersecurity regulation (23 NYCRR Part 500).
Order Express suffered a ransomware attack in 2022, which they reported appropriately. But then the DFS's investigation revealed that the entity did not have adequate cybersecurity risk assessment or plan.
Read more at: https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20260805
#NYSDFS #OrderExpress #databreach #cybersecurity #FinSec #ransomware #riskassessment



