home.social

Search

213 results for “zacpwhite”

  1. The NYS Department of Financial Services announced that they settled charges against Delta Dental Insurance Co. and Delta Dental of New York stemming from the 2023 Clop/MOVEit data breach.

    The state's investigation found that Delta had violated NYS cybersecurity regs in a number of ways.

    Delta has agreed to pay $2.25 million, none of which can be paid by their insurers and they can accept any reimbursement for the payment from any source.

    I wonder how many other MOVEit customers who do business in New York are also dealing with NYSDFS.

    databreaches.net/2026/05/01/ny

    #databreach #hackandleak #supplychain #0day #DeltaDental #MOVEit #Clop #NYSDFS

    @campuscodi @zackwhittaker

  2. The NYS Department of Financial Services announced that they settled charges against Delta Dental Insurance Co. and Delta Dental of New York stemming from the 2023 Clop/MOVEit data breach.

    The state's investigation found that Delta had violated NYS cybersecurity regs in a number of ways.

    Delta has agreed to pay $2.25 million, none of which can be paid by their insurers and they can accept any reimbursement for the payment from any source.

    I wonder how many other MOVEit customers who do business in New York are also dealing with NYSDFS.

    databreaches.net/2026/05/01/ny

    #databreach #hackandleak #supplychain #0day #DeltaDental #MOVEit #Clop #NYSDFS

    @campuscodi @zackwhittaker

  3. The NYS Department of Financial Services announced that they settled charges against Delta Dental Insurance Co. and Delta Dental of New York stemming from the 2023 Clop/MOVEit data breach.

    The state's investigation found that Delta had violated NYS cybersecurity regs in a number of ways.

    Delta has agreed to pay $2.25 million, none of which can be paid by their insurers and they can accept any reimbursement for the payment from any source.

    I wonder how many other MOVEit customers who do business in New York are also dealing with NYSDFS.

    databreaches.net/2026/05/01/ny

    #databreach #hackandleak #supplychain #0day #DeltaDental #MOVEit #Clop #NYSDFS

    @campuscodi @zackwhittaker

  4. The NYS Department of Financial Services announced that they settled charges against Delta Dental Insurance Co. and Delta Dental of New York stemming from the 2023 Clop/MOVEit data breach.

    The state's investigation found that Delta had violated NYS cybersecurity regs in a number of ways.

    Delta has agreed to pay $2.25 million, none of which can be paid by their insurers and they can accept any reimbursement for the payment from any source.

    I wonder how many other MOVEit customers who do business in New York are also dealing with NYSDFS.

    databreaches.net/2026/05/01/ny

    #databreach #hackandleak #supplychain #0day #DeltaDental #MOVEit #Clop #NYSDFS

    @campuscodi @zackwhittaker

  5. The NYS Department of Financial Services announced that they settled charges against Delta Dental Insurance Co. and Delta Dental of New York stemming from the 2023 Clop/MOVEit data breach.

    The state's investigation found that Delta had violated NYS cybersecurity regs in a number of ways.

    Delta has agreed to pay $2.25 million, none of which can be paid by their insurers and they can accept any reimbursement for the payment from any source.

    I wonder how many other MOVEit customers who do business in New York are also dealing with NYSDFS.

    databreaches.net/2026/05/01/ny

    #databreach #hackandleak #supplychain #0day #DeltaDental #MOVEit #Clop #NYSDFS

    @campuscodi @zackwhittaker

  6. @zackwhittaker
    Constitution...?
    We don't need no stinkin' Constitution.

    USA...! USA...! USA...! USA...! etc.
    ☠️ 🇺🇸 ☠️
    #doomed #worsttimeline

  7. @zackwhittaker It's gotten FAR worse, in just one day: Amazon has gone into a deal with Anthropic on AI infrastructure.

    #BoycottAmazon #BoycottAI

  8. Updating my update: I got answers from Dos-OP in response to Nova RaaS's objections to the reporting. They also sent me a 66-page file on Nova, under embargo. I've updated my post with publicly available info and their responses to specific claims by Nova. databreaches.net/2025/11/30/br

    It seems kind of stupid for threat actors to claim that IP addresses are all wrong when there's publicly available evidence linking them to the IP addresses.

    Updating: Nova contacted me this morning to dispute the claims in the report. I've forwarded their criticisms to Dos-OP for response.

    ------ original post:

    BREAKING: Dos-OP exposes the Nova RaaS gang

    Dos-OP, in collaboration with CBSecurity, has released a preliminary version of the first part of their planned 3-part report on the Nova RaaS gang and its affiliates.

    Information and more details have reportedly already been provided to law enforcement.

    It's something else to be thankful for this week, if it's correct.

    Read my post at databreaches.net/2025/11/30/br

    #ransomware #Nova #RaaS #databreach #cybersecurity #doxxing

    @campuscodi @zackwhittaker @euroinfosec @amvinfe

  9. RE: mastodon.social/@zackwhittaker

    Everyone was today years old when they learned about parametric cyber insurance.

    Like any CxOs are on the Fedi. So tell your CISO.

    #aws #cyberinsurance #parametrics

  10. @hardly @zackwhittaker That’s some #bothsides reasoning right there, how is it that you’re more upset at Democrats being silent about Republican crimes than you are at Republicans committing crimes?

  11. And it's out!

    Zack Whittaker and I have released our report on the pilot survey we conducted to increase awareness about threats security researchers and journalists who report on cybersecurity and cybercrime experience.

    We are grateful to all those who responded to the survey and shared a bit of their experiences. Based on what we found in a pilot survey with a non-random sample, I really think we need to do a bigger study that can also do a deeper dive into some questions.

    You can read the report in html or download the .pdf version:

    html: databreaches.net/2026/02/02/un

    pdf: databreaches.net/wp-content/up

    In conjunction with the release of the report, I've also added a new "Threats" category to DataBreaches.net.

    You can also read some overview comments from Zack at
    this.weekinsecurity.com/new-su

    My post explaining how this all started is at databreaches.net/2026/02/02/th

    #cybersecurity #securityresearch #legalthreats #threats #criminals #databreach #vulernabilities #malware #lawsuit #survey

    @zackwhittaker @campuscodi @amvinfe @jgreig @dangoodin @GossiTheDog @lawrenceabrams @euroinfosec

  12. So many news reports have repeated the BBC's mistaken estimate about the number of customers affected by the Kering data breaches. So...

    No, folks, it's not 7.4 million affected or fewer. It's a lot more because the BBC's estimate was based on just the second and smaller breach (Balenciaga, Brioni, and Alexander McQueen), and not the Gucci data which allegedly has more than 43 million records. Even assuming repeat customers are in there, there are likely a lot of unique customers in the Gucci data.

    If we use the same percent based on 7.4 million out of almost 13 million recordsin the second data set, then that would yield 24-25 million unique email addresses for the Gucci data set, for an estimated total of more than 31 million customers all told.

    I didn't estimate the number of unique customers in my reporting because it's too sloppy. But it's highly unlikely to be 7.4 million or fewer as BBC reported.

    #Kering #Gucci #Balenciaga #Brioni #AlexanderMcQueen #databreach #Salesforce #ShinyHunters #UNC6040 #incidentresponse #transparency

    My reports:
    databreaches.net/2025/09/11/ex

    databreaches.net/2025/09/15/up

    @euroinfosec @zackwhittaker

  13. @rzeta0 : I think you're going too far by stating that NOT criticising Israel by IT journalists implies propaganda.

    In fact, he has been reporting about Israel, albeit a tiny bit, for example in mastodon.social/@zackwhittaker.

    In the US you get cancelled for speaking the truth. I don't understand why Donald Trump is still president. Why don't all pro-democracy people go on strike,at least all (unpayed!) civil servants?

    It's scare tactics and it works. Without organisation lone protestors are near suicidal.

    Note: my account on infosec.exchange was blocked for speaking out the truth. I've had a good life, but most people have to make a living.

    @zackwhittaker

    #USterroristCountry #USAterroristCountry #DonaldTrumpToICC #FrancescaAlbaneseIsRight

  14. @zackwhittaker huh. any details from actual #cellular #lte knowers on where the whole "send gps coords" part normally happens? i wonder why this wasn't discussed much before

  15. @zackwhittaker On Monday my daughter competed in her first national-level fencing competition. Seeded mid-20s (out of 40) she finished 10th, just outside the cut for the quarter-finals. She out-performed all the fencers present that she'd lost to while qualifying to represent her region, while hobbled through not having her coach present (only me, and I don't fence with her weapon) and managing her period.
    It was a storming result for her, AND she knows how she could have done better!
    #fencing