Uber has been ordered by the Dutch Data Protection Authority to pay a $324 million penalty over its alleged insecure transfer of European drivers' personal information to the U.S. for over two years, which was noted to be a significant violation of the European Union's General Data Protection Regulation.
Information leaked by the database included names, addresses, phone numbers, email addresses, partial credit card details, and HIPAA patient consent forms from health providers, restaurant chains, schools, homeowners, religious entities, and casinos as early as 2012.
Included in the data purportedly exfiltrated from AMD were communications from various sources, including "amdsso[.]okta[.]com," "idmprod[.]xilinx[.]com," which feature user credentials, descriptions, and case numbers, as well as assignment groups and internal resolutions, a posting on BreachForums showed.
While such devices contain sensitive law enforcement and classified national security information, appropriate classification labels were only applied by the FBI on servers and computers but not on the media extracted from them, as well as small flash drives.
The breach, uncovered on April 28 by Cybernews researchers, impacted 37,349 files containing sensitive data such as names, email addresses, home addresses, and order information.
Attackers who infiltrated Arden Claims Service's systems around Oct. 3, 2023, were able to exfiltrate individuals' names and other personally identifiable information, according to the notification letter provided to Vermont and Maine regulators.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.