Yazılar

Australia Regulator Sues FIIG Securities for Cybersecurity Failures

The Australian Securities and Investments Commission (ASIC) announced on Thursday that it is suing FIIG Securities, a fixed-income broker, accusing the company of failing to implement proper cybersecurity measures over a four-year period. These alleged failures allowed a hacker to infiltrate FIIG’s IT network, resulting in the theft of approximately 385 gigabytes of confidential data.

The breach, which occurred between May 19 and June 8, 2023, affected 18,000 clients, who were notified that their personal information may have been compromised. Some of the stolen client data was later found on the dark web.

ASIC’s lawsuit claims that from March 2019 to June 2023, FIIG failed to take necessary steps to ensure the security of its digital infrastructure. The regulator stated that the company lacked adequate cyber risk management systems, which directly contributed to the attack.

“Advancing digital safety and resilience is a strategic priority for ASIC, and we have been actively engaging with companies to support the continuous improvement of cyber and operational resilience practices,” said ASIC Chair Joe Longo.

During the period when the cybersecurity issues occurred, JPMorgan held assets for FIIG and its clients, ranging in value from A$2.89 billion ($1.83 billion) to A$3.7 billion. However, JPMorgan declined to comment on the matter when contacted by Reuters, and FIIG did not respond to requests for comment.

According to ASIC, the deficiencies alleged include FIIG’s failure to adequately update and patch its software, as well as its insufficient resources to protect against and prevent cyberattacks.

Sony Extends PlayStation Plus Membership After Global Outage

Sony has announced a five-day extension for all PlayStation Plus subscribers following a global outage that disrupted the PlayStation Network (PSN) for nearly 18 hours on Friday and Saturday. The company confirmed that network services had been fully restored by Saturday evening and expressed regret for the inconvenience caused to users.

The outage, which began late on Friday, prevented users from signing in, playing online games, or accessing the PlayStation Store. Sony did not specify the cause of the disruption in its update. At its peak, the outage affected nearly 8,000 users in the U.S. and over 7,300 in the UK, according to Downdetector.com, which tracks service interruptions.

This incident is the latest in a series of PSN outages, though Sony has faced more severe disruptions in the past. A cyberattack in 2014 forced the network offline for several days, and a significant data breach in 2011 compromised the personal information of millions of users, resulting in a month-long service shutdown and a regulatory investigation.

Despite the inconvenience, the extended PlayStation Plus membership is seen as a way to compensate users for the lost time. One user on X (formerly Twitter) humorously remarked that Sony had “saved millions of gamers’ Sunday” after the outage impacted their Saturday.

Data Breach Reveals Exact Location Data of Millions from Popular Smartphone Apps

A significant data breach has compromised the sensitive location information of millions of smartphone users who utilize popular apps, including dating platforms, gaming apps, email clients, and even a period tracking app. The breach occurred when a hacker managed to infiltrate Gravy Analytics, a data broker that aggregates and sells location data from various apps on iOS and Android devices. The hacker was able to access data that includes precise location details, potentially revealing users’ home addresses, workplaces, and other personal movements. While iOS users may have been partially protected due to a privacy feature introduced in iOS 14.5, the breach still affected many devices across both platforms.

Gravy Analytics, which collects and monetizes location data, was targeted through a “misappropriated key” that allowed the hacker to gain access to the company’s cloud-based storage. The incident occurred on January 4, but the full scale of the breach remains unclear, as the company’s disclosure to Norwegian authorities provided limited details. The data compromised in the breach consists of extensive customer lists and real-time location tracking, which provides insight into the precise movements of individuals. The data affected includes smartphone data from millions of users, posing significant privacy concerns.

The leaked data, according to Baptiste Robert, the CEO of Predicta Lab, contains “tens of millions of location data points,” including sensitive locations such as military bases, the Kremlin, the White House, and the Vatican. This revelation highlights the extent of the breach and the level of detail that the stolen data contains. The breach not only exposes personal privacy but also raises security concerns, especially with the targeting of sensitive locations like government buildings and military sites.

This breach serves as a stark reminder of the vulnerabilities associated with the collection and storage of location data by third-party companies. While users may not always be aware of the extent to which their movements are being tracked, this incident underscores the risks involved in the widespread sharing of personal information by popular apps. As the investigation into the breach continues, it remains crucial for companies to implement stronger security measures and for users to stay vigilant about the permissions they grant to apps on their devices.