Thousands of US medical professionals have data exposed in major data breach


Researchers have found a database backup belonging to Florida-based recruitment company MNA Healthcare left unsecured online, leaving the details of thousands of workers open to anyone.

The company offers staffing services for healthcare workers and matches them with hospitals and organizations across nine states. The leaked information included full names, addresses, phone numbers, job titles, work experience, and encrypted Social Security numbers (SSNs).

Read more…
Source: Tech Radar News


Sign up for our Newsletter


Related:

  • Missouri Vows to Prosecute ‘Hacker’ Who Informed State About Data Leak

    October 15, 2021

    The St. Louis Post-Dispatch newspaper recently found a huge security blunder: The Missouri educational agency’s site was displaying 100,000+ clearly visible Social-Security numbers for school teachers, administrators and counselors in its HTML source code. The newspaper verified its findings with a cybersecurity professor and then informed the agency responsible for the leaking site – the Department ...

  • The Telegraph exposes 10 TB database with subscriber info

    October 5, 2021

    ‘The Telegraph’, one of the UK’s largest newspapers and online media outlets, has leaked 10 TB of data after failing to properly secure one of its databases. The exposed information includes internal logs, full subscriber names, email addresses, device info, URL requests, IP addresses, authentication tokens, and unique reader identifiers. Bob Diachenko, the researcher who discovered the ...

  • RaidForums data marketplace accidentally exposes private staff page

    September 22, 2021

    Underground marketplace and hacker forum, RaidForums, recently exposed internal pages from its website, meant for staff members only. RaidForums is a data breach marketplace where threat actors often sell or leak illicitly obtained data dumps. Read more… Source: Bleeping Computer  

  • Microsoft Exchange Autodiscover bugs leak 100K Windows credentials

    September 22, 2021

    Bugs in the implementation of Microsoft Exchange’s Autodiscover feature have leaked approximately 100,000 login names and passwords for Windows domains worldwide. In a new report by Amit Serper, Guardicore’s AVP of Security Research, the researcher reveals how the incorrect implementation of the Autodiscover protocol, rather than a bug in Microsoft Exchange, is causing Windows credentials to ...

  • Database containing personal info on 106m people who traveled to Thailand found open to the internet – report

    September 21, 2021

    A database containing personal information on 106 million international travelers to Thailand was exposed to the public internet this year, a Brit biz claimed this week. Bob Diachenko, head of cybersecurity research at product-comparison website Comparitech, said the Elasticsearch data store contained visitors’ full names, passport numbers, arrival dates, visa types, residency status, and more. It ...

  • Is it OK to use stolen data? What if it’s scientific research in the public interest?

    September 20, 2021

    There’s a fine line between getting hold of data that may be in the public interest and downright stealing data just because you can. And simply because the data is out there – having been stolen by online intruders and then leaked – does not mean it is right to use it. A paper published in ...