Showing posts with label leads. Show all posts
Showing posts with label leads. Show all posts

Hack of hospital chain leads to theft of up to 4.5M users' data

Community Health Systems oversees 206 hospitals in 29 states. Community Health Systems

One of the biggest hospital groups in the US revealed Monday that it suffered a monumental security breach, which possibly led to 4.5 million patients' data being stolen, according to Reuters.

Community Health Systems, which oversees 206 hospitals in 29 states, said the stolen information includes Social Security numbers, patient names and addresses, telephone numbers, and birth dates, according to Reuters. This is the largest known attack to involve hospital patient information since the US government began tracking these types of data breaches in 2009.

"One possible goal of this attack is to facilitate future targeted attacks," Elysium Digital data security expert Joseph Calandrino told CNET. "The type of data that was stolen from the hospital system is often used to verify a person's identify. The exposure of this data creates a risk that the hackers could leverage it to gain access to other accounts and information."

It's believed the cyberattack originated in China, according to Reuters. Security firm Mandiant, which investigated the breach in April and June, said the hackers belong to a group that targets defense, engineering, financial services, and health care companies. It's unclear if these hackers are affiliated with the Chinese government.

Related stories Hackers nab 1.2B passwords in colossal breach, says security firm Overseas hackers nab more than 1TB of data daily Anonymous hacks Ferguson, Mo., police site for dispatch tapes Vast majority of hackers believe they're above the law -- survey HealthCare.gov security -- 'a breach waiting to happen'

Various security experts have long accused China of waging a cyberwar on US government and private company websites. A report by Mandiant released in 2013 linked China's People's Liberation Army to a large number of cyberattacks on US soil. However, the Chinese government has flatly denied that it is involved in cyber-espionage or hacking.

The cyberattack on Community Health Systems is just one of many over the past few months. Last December, retailer Target revealed 110 million people's data was stolen in a breach, and retailers Neiman Marcus and Michaels Stores were also attacked around the same time. Earlier this month, cybersecurity firm Hold Security identified what is arguably the largest known data breach in history, in which a Russian cybergang allegedly stole 1.2 billion username and password combinations and more than 500 million email addresses.

Community Health Systems told Reuters it stopped the cyberattack by removing the malicious software used by the hackers. The hospital group is currently notifying its patients of the breach.

CNET contacted Community Health Systems for more information, we'll update the story when we hear back.

This content is rated TV-MA, and is for viewers 18 years or older. Are you of age? Yes No Sorry, you are not old enough to view this content.
Tags: Security Internet Hacking Malware About the author

Facial recognition tech leads feds to fugitive after 14 years

Facial recognition technology used on the photo in the Neil Stammer wanted poster led to his arrest. FBI

In 2000, after being accused of child sex abuse and kidnapping in New Mexico, Neil Stammer skipped town and went underground. Fourteen years later he was arrested in Nepal.

How did the authorities catch this fugitive? Facial recognition technology.

Stammer was first arrested in 1999 on multiple state charges, but after being released on bond, he never showed up for his arraignment. He was said to be a talented juggler who spoke a dozen languages and traveled the world as a street performer.

The FBI thought he could be anywhere. After years of trying to locate Stammer, with no luck, the feds decided to shelve the case.

Then, earlier this year, FBI Special Agent Russ Wilson was assigned to be a fugitive coordinator in New Mexico.

"In addition to the current fugitives, I had a stack of old cases," Wilson said in a statement, "and Stammer's stood out."

So, Wilson reissued Stammer's "Wanted" poster. At the same time, the Diplomatic Security Service, which cracks down on bogus US passports, had just begun testing facial recognition software designed to expose passport fraud.

Related stories NSA said to collect millions of images for facial recognition Al Franken gives thumbs-down to facial recognition tech Boston bombings: How facial recognition can cut investigation time to seconds The looming big business of facial recognition FTC releases guidelines for facial-recognition use

An agent from the Diplomatic Security Service ran the software on Stammer's poster and came up with something interesting -- a match with a passport photo of someone named Kevin Hodges. The agent contacted Wilson who quickly tracked down Stammer in Nepal. Stammer had been living under the alias of Kevin Hodges and was teaching English to Nepalese students.

"He was very comfortable in Nepal," Wilson said. "My impression was that he never thought he would be discovered."

Although facial recognition technology has attracted growing attention in recent years from law enforcement and commercial interests, its reception has been rocky. Privacy advocates raised concerns in April over a facial-recognition database being developed by the FBI that could hold 52 million images by next year. Sen. Al Franken (D-Minn.) has also questioned the FBI's use of facial recognition software, saying it could infringe on people's privacy.

According to a report from July 2011, it's not just the FBI employing facial recognition software -- around 40 law enforcement agencies across the US are attempting to use mobile facial recognition technology to identify individuals.

Tags: Security Facial recognition Privacy About the author