Users of the MyAtriumHealth patient portal, formerly MyCarolinas, between January 2015 and July 2019 may have had their names, home and email addresses, phone numbers, treatment or provider details, IPs, and browser cookies exposed to Meta, Google, and other third-party vendors.
Information allegedly exfiltrated by 8Base included invoices, receipts, personal and confidential data, accounting documents, employment contracts, confidential agreements, certificates, and other sensitive details.
While Sirius XM has allegedly engaged in the sharing of sensitive user data with unaffiliated third parties and other groups without notifying users and obtaining their consent, the MyRadar weather app, Miles travel rewards app, and Tapestri information rewards app have been accused of failing to secure data sharing permissions and inform users regarding their data privacy rights.
Such a crackdown on Manson Market — which commenced in late 2022 following a reported increase in fake phone calls spoofing bank employees — also resulted in the seizure of more than 50 of its servers containing over 200 TB of data, as well as the arrests of suspected hackers from Austria and Germany.
Virginia-based Gravy Analytics and its subsidiary Venntel have been accused by the FTC of leveraging consumer location details without consent, as well as peddling health information, religious views, political activities, and other data to others.
Such a rule, which is open for public comments until March 2025, would not only mandate explicit customer authorization for the sale of data but also strengthen protections against the exploitation of collected data.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.