Luxottica Agrees $250,000 Settlement to Resolve Data Breach Litigation
Luxottica, the world’s largest eyewear company, has agreed to settle class action data breach litigation related to a 2020 hacking incident that involved unauthorized access to an appointment scheduling application that contained the personal and protected health information of more than 829,000 patients of its eye care partners. The unauthorized access occurred between August 5 and August 9, 2020, and the affected individuals were notified in November of that year. The breached data included names, health information, financial information, and Social Security numbers. Several individuals affected by the data breach took legal action seeking damages and restitution. The lawsuits were consolidated into a single action – In re: Luxottica of America Inc. Data Security Breach Litigation – in the District Court for the Southern District of Ohio. The lawsuits alleged Luxottica failed to implement reasonable and appropriate safeguards, and had those measures been implemented, the data breach could have been prevented. Luxottica maintains there was no wrongdoing but chose to settle...
Health Sector Warned About Ongoing Credential Harvesting Campaigns
The Health Sector Cybersecurity Coordination Center (HC3) has issued an updated Analyst Note about credential harvesting, which includes a warning about an active credential harvesting campaign targeting grantees in the health sector. The cybersecurity Cofense has also issued an alert about a credential harvesting campaign spoofing the email security companies Proofpoint, Mimecast, and Virtru. Credential harvesting is a term covering the collection of login credentials – usernames and passwords – by malicious actors, either for use in future cyberattacks or to sell on or trade with other threat actors. The theft of the credentials of a single user can have far-reaching consequences. One only needs to look at the February 2024 ransomware attack on Change Healthcare to see the huge harm that can be caused. The ransomware attack on Change Healthcare saw an affiliate of the BlackCat ransomware group steal an estimated 100 million healthcare records. The credentials of a low-level customer support employee were obtained by a ransomware affiliate. The credentials had been posted on...
Texas Attorney General Sues New York Doctor for Providing Abortion Pills to Texas Resident
Texas Attorney General Ken Paxton has filed a lawsuit in the District Court of Collin County, Texas, against a New York doctor accused of mailing abortion pills to a Texas telemedicine patient, in violation of multiple state laws. Dr. Margaret Daley Carpenter, co-founder of the Abortion Coalition for Telemedicine, is alleged to have prescribed abortion medications to a 20-year-old patient in Collin County Texas, knowing the woman lived in Texas, which prohibits physicians and medical suppliers from providing abortion-inducing medications via the mail service or courier delivery. The State of Texas Health & Safety Code requires any physician performing or inducing an abortion to be licensed to practice medicine in the state of Texas and they must hold admitting privileges at a hospital no further than 30 miles from the location where the abortion procedure takes place. The Texas Admin Code requires physicians who treat patients or prescribe medications to Texas residents through telehealth services to hold a valid Texas medical license. Dr. Carpenter does not have a license to...
CISA Seeks Comment on National Cyber Incident Response Plan Update
The Cybersecurity and Infrastructure Security Agency (CISA) is seeking comment on the draft National Cyber Incident Response Plan (NCIRP) Update, published in the Federal Register on December 16, 2024. Comments will be accepted on the draft update until January 15, 2025. The NCIRP is a national strategic framework for coordinated response to cyber incidents and was first published in 2016. The update was issued in response to the changing cyber threat landscape, and addresses significant changes in policy and federal law, and the new organizational capabilities since the NCIRP was released 8 years ago. The NCIRP concerns cyber incidents of severity Level 2 or above per the Cyber Incident Severity Scheme, which means the incidents may impact public health or safety, national security, economic security, foreign relations, civil liberties, or public confidence. The NCIRP covers four main areas of effort: Asset Response, Threat Response, Intelligence Support, and Affected Entity Response, and includes coordination mechanisms, key decision points, and priority activities. The NCIRP...
BD Identifies High Severity Vulnerability in its Diagnostic Solutions Products
Becton, Dickinson, and Company (BD) has discovered a high-severity vulnerability affecting several of its BD Diagnostic Solutions Products. The vulnerability, tracked as CVE-2024-10476 (CVSS v3, 8.0), is due to the use of default credentials, which were intended for use only by BD technical support teams within the clinical setting. Exploitation of the vulnerability could potentially allow a threat actor to access, modify, or delete data, including personally identifiable information (PII) and protected health information (PHI). The vulnerability could be exploited in a low-complexity attack, which could cause a system shutdown or impact the availability of the system. The vulnerability affects all versions of the following products: BD BACTEC Blood Culture System BD COR System BD EpiCenter Microbiology Data Management System BD MAX System BD Phoenix M50 Automated Microbiology System BD Synapsys Informatics Solution Exploitation of the vulnerability would require a threat actor to have direct access (logical or physical) to the affected product, so a threat actor would need to...



