article thumbnail

Congressional Report on the 2017 Equifax Data Breach

Schneier on Security

The US House of Representatives Committee on Oversight and Government Reform has just released a comprehensive report on the 2017 Equifax hack. Here is my testimony before before the House Subcommittee on Digital Commerce and Consumer Protection last November. Lance Spitzner also commented on this.

article thumbnail

LifeLock Bug Exposed Millions of Customer Email Addresses

Krebs on Security

Identity theft protection firm LifeLock — a company that’s built a name for itself based on the promise of helping consumers protect their identities online — may have actually exposed customers to additional attacks from ID thieves and phishers. million customer accounts. Update, 7:40 p.m.:

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

FTC issues cybersecurity warning to Chegg

CyberSecurity Insiders

Such practices in-turn led to 4 security breaches since 2017 and so the company was asked to revamp its security practices while collecting and storing data with authentication and biometrics that need to be followed by the staff.

article thumbnail

Uber agrees to pay $148 million in massive 2016 data breach settlement

Security Affairs

In November 2017, the Uber CEO Dara Khosrowshahi announced that hackers broke into the company database and accessed the personal data (names, email addresses and cellphone numbers) of 57 million of its users, the disconcerting revelation was that the company covered up the hack for more than a year. ” continues the AP.

article thumbnail

Me on the Equifax Breach

Schneier on Security

Hearing on "Securing Consumers' Credit Data in the Age of Digital Commerce". Subcommittee on Digital Commerce and Consumer Protection. 1 November 2017. The particular vulnerability was fixed by Apache in a security patch that was made available on March 6, 2017. It confessed to another data leak in January 2017.

article thumbnail

Facebook sued for siphoning facial recognition data without consent

Malwarebytes

The company updated and implemented this technology in December 2017 to assist users in managing their identity on the platform by helping them “find photos that you’re not tagged in and help you detect when others might be attempting to use your image as their profile picture.”

article thumbnail

Scary Fraud Ensues When ID Theft & Usury Collide

Krebs on Security

” In 2017, the Consumer Financial Protection Bureau sued four tribal online payday lenders in federal court — including Mountain Summit Financial — for allegedly deceiving consumers and collecting debt that was not legally owed in many states.