Posts

Showing posts with the label KrebsOnSecurity

Crooks Steal Phone, SMS Records for Nearly All AT&T Customers

Image
By  KrebsOnSecurity AT&T Corp . disclosed today that a new data breach has exposed phone call and text message records for roughly 110 million people — nearly all of its customers. AT&T said it delayed disclosing the incident in response to “national security and public safety concerns,” noting that some of the records included data that could be used to determine where a call was made or text message sent. AT&T also acknowledged the customer records were exposed in a cloud database that was protected only by a username and password (no multi-factor authentication needed). In a regulatory filing with the U.S. Securities and Exchange Commission today, AT&T said cyber intruders accessed an AT&T workspace on a third-party cloud platform in April, downloading files containing customer call and text interactions between May 1 and October 31, 2022, as well as on January 2, 2023. The company said the stolen data includes records of calls and texts for mobile providers...

Data Breach on DEA Law Enforcement System Grants Cyber Criminals Access to 16 Databases

By Alicia Hope, CPO Magazine U.S. Drug Enforcement Agency (DEA) is investigating a potential law enforcement system data breach associated with an online harassment community that impersonates police officers. KrebsOnSecurity journalist Brian Krebs received a tip that hackers gained unauthorized access to the esp.usdoj.gov data portal, the Law Enforcement Inquiry and Alerts (LEIA) system. Krebs obtained the information from the administrator of the Doxbin cyberbullying community identified as “KT” with links to the LAPSUS$ hacking group. Doxbin members post personal information online and participate in “swatting,” while LAPSUS$ was responsible for high-profile data breaches on Microsoft, NVIDIA, Okta, Samsung, and others. LAPSUS$ also sells a service for making Emergency Data Requests to tech companies, social media platforms, and mobile service providers. The imposters trick organizations by claiming that the data requests could not wait for warrants because of their emergency nature...

Senators Urge FTC to Probe ID.me Over Selfie Data

Image
By  KrebsOnSecurity Some of more tech-savvy Democrats in the U.S. Senate are asking the Federal Trade Commission (FTC) to investigate identity-proofing company ID.me for “deceptive statements” the company and its founder allegedly made over how they handle facial recognition data collected on behalf of the Internal Revenue Service, which until recently required anyone seeking a new IRS account online to provide a live video selfie to ID.me. In a letter to FTC Chair Lina Khan, the Senators charge that ID.me’s CEO Blake Hall has offered conflicting statements about how his company uses the facial scan data it collects on behalf of the federal government and many states that use the ID proofing technology to screen applicants for unemployment insurance. The lawmakers say that in public statements and blog posts, ID.me has frequently emphasized the difference between two types of facial recognition: One-to-one, and one-to-many. In the one-to-one approach, a live video selfie is compare...