Tag: healthcare
-
French hospital fined Euro500,000 after breach exposes data of 727,000
France’s data protection authority (CNIL) has fined Hôpital privé de la Loire Euro500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/
-
French hospital fined Euro500,000 after breach exposes data of 727,000
France’s data protection authority (CNIL) has fined Hôpital privé de la Loire Euro500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/
-
French hospital fined Euro500,000 after breach exposes data of 727,000
France’s data protection authority (CNIL) has fined Hôpital privé de la Loire Euro500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/
-
French hospital fined Euro500,000 after breach exposes data of 727,000
France’s data protection authority (CNIL) has fined Hôpital privé de la Loire Euro500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/
-
French hospital fined Euro500,000 after breach exposes data of 727,000
France’s data protection authority (CNIL) has fined Hôpital privé de la Loire Euro500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/
-
Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program.”The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help…
-
Critical Infrastructure Security
Critical infrastructure supports the systems and services that modern society depends on every day. Electricity generation and distribution, water treatment, transportation, telecommunications, healthcare, financial services, energy production, and other essential sectors rely on increasingly connected digital technologies. As these environments… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/critical-infrastructure-security/
-
Health data of more than 9.5 million people leaked from Aesto record system
The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December. First seen on therecord.media Jump to article: therecord.media/health-data-aesto-cyberattack-leak
-
Irish Privacy Watchdog Details Psychiatric Data Breaches
Medical Records ‘Contaminated by Animal Droppings’ Recovered From Disused Sites. Rotting old mental health records stored on paper contaminated by animal droppings and left in abandoned psychiatric hospitals in Ireland have led to the country’s privacy watchdog reprimanding and fining the national health service for GDPR violations and demanding security improvements. First seen on govinfosecurity.com…
-
The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security
Tags: breach, control, credentials, cyber, edr, framework, group, hacker, healthcare, ransomware, technologyThe Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework named TukTuk, alongside EDR-disabling tooling, DLL sideloading research, and datasets apparently stolen from technology and healthcare organizations. Analysis of a Finland-hosted server identified what researchers assess as the complete TukTuk development project, providing an unusually detailed view into the group’s post-compromise capabilities.…
-
Nutex Health Says Patient Data Stolen, Hackers Threaten Leak
The US healthcare provider confirmed that sensitive patient and employee data, alongside financial and business information, were exfiltrated by a third party First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/nutex-patient-data-stolen/
-
Fake Microsoft Edge, Kaspersky and Razer Installers Used to Compromise Windows Systems
Tags: cyber, government, healthcare, infrastructure, kaspersky, malware, microsoft, software, technology, windowsAn active malware campaign that abuses counterfeit download pages for trusted software brands including Microsoft Edge, Kaspersky and Razer to compromise Windows devices. Victims span healthcare, manufacturing, gaming, technology, logistics, government and education, highlighting the broad appeal of software-download lures. Microsoft has not attributed the activity to a nation-state actor, but the campaign’s infrastructure, payload…
-
Survey: Patients Want Disclosure on AI Use in Healthcare
More Than 70% Say AI Use in Any Medical Scenario Should Be Disclosed. A Pew survey of nearly 5,000 U.S. adults found broad demand for disclosure when healthcare providers use AI, underscoring growing concerns over consent, privacy, accuracy and physician oversight as clinical AI tools spread. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/survey-patients-want-disclosure-on-ai-use-in-healthcare-a-32713
-
Healthcare facilities operator Nutex says patient, employee data stolen in August incident
Cybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators. First seen on therecord.media Jump to article: therecord.media/nutex-health-data-breach
-
Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records
Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025,…
-
Healthcare Giant McKesson Investigates Data Breach Incident
ShinyHunters claims to have stolen 284 million records from McKesson First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/healthcare-mckesson-investigates/
-
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
Tags: authentication, cisa, cve, cybersecurity, exploit, flaw, healthcare, infrastructure, kev, office, remote-code-execution, software, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)addedthe following vulnerabilities to itsKnown Exploited Vulnerabilities (KEV) catalog: PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578,…
-
McKesson copes with fallout from data theft extortion attack
The major healthcare sector vendor did not identify the attackers, but ShinyHunters, a prolific group increasingly targeting the sector, claimed responsibility. First seen on cyberscoop.com Jump to article: cyberscoop.com/mckesson-data-theft-extortion-attack-shinyhunters/
-
ShinyHunters Threatens to Leak Millions of McKesson Records
Medical Products Supplier Reports Hack to SEC as Tuesday Data Leak Deadline Looms. Medical product and pharmaceutical distributor McKesson is the latest healthcare sector supplier responding to a recent data theft incident. Extortion gang ShinyHunters is threatening to leak 284 million records of sensitive McKesson data, including patient information, unless a ransom is paid. First…
-
Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson
The company, which distributes medicines and medical devices to hospitals and healthcare practices across the U.S., said it was hacked and expects intermittent service degradation. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/31/hackers-claim-millions-of-patient-records-stolen-during-data-breach-at-healthcare-giant-mckesson/
-
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Threat actors with ties to the Democratic People’s Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession.The ongoing insider threat is part of what has been described as the…
-
Pharmaceutical giant McKesson warns of ‘service degradation’ following cyberattack
The pharmaceutical and healthcare technology company McKesson informed regulators it is in the early stages of investigating a cybersecurity incident involving an unnamed third-party application. First seen on therecord.media Jump to article: therecord.media/mckesson-cyberattack-ransomware-pharma
-
ShinyHunters claims it stole 284 million patient records from McKesson
Healthcare company McKesson disclosed a cybersecurity incident in which hackers got into third-party applications and stole data. McKesson is a major U.S. healthcare company … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/31/healthcare-company-mckesson-data-breach/
-
HIPAA Risk Assessments 2026: Continuum GRC Healthcare Audits
In 2026, healthcare organizations face increasing pressure to maintain robust data protection measures under evolving regulatory landscapes. HIPAA risk assessments remain a cornerstone of compliance, helping providers identify vulnerabilities and safeguard protected health information. As cyber threats grow more sophisticated, proactive compliance assessments become essential for decision-makers seeking to minimize liability and ensure operational resilience.”¦…
-
Kidney Transplant Registry Hack Raises Safety Concerns
Alleged DireWolf Attack Highlights Risks to Critical Healthcare Suppliers, Patients. An alleged extortion hack on a organization that helps facilitate nationwide organ transplants is the latest reminder of the potential disruption and harm posed to healthcare organizations, patients and their sensitive data in attacks on critical medical suppliers and other third parties. First seen on…
-
North Korean Hackers Target Healthcare: What You Need to Know
North Korean cyberattacks reveal how trusted identities and workflows create healthcare cybersecurity risk, and how security teams can test them. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/north-korean-hackers-target-healthcare-what-you-need-to-know/
-
Huntress Uncovers Five Cases of North Korean Operatives Posing as Remote IT, Sales and Healthcare Workers
Cybersecurity firm Huntress has confirmed five separate incidents this year in which suspected North Korean operatives were successfully hired into legitimate organisations under false identities, in a wave of activity researchers say shows how the country’s so-called >>remote IT worker<< scheme has expanded well beyond IT roles. The cases, disclosed in a new advisory, involved…
-
MyChart Portal Phishing Scams Target Patients Nationwide
Dozens of Health Systems Warn of Emails, Texts and Calls Using Epic’s MyChart Brand. Dozens of U.S. healthcare systems are warning patients about potential email phishing, text and phone scams involving their MyChart patient portals. MyChart vendor Epic also issued a public warning about the scams, which offer patients a senior package, Medicare wellness benefits…
-
How ‘Subtractive’ Security Erases Attack Paths
Chris Frenz, Rectangle Health CISO, on Reducing Risk From Attackers in Healthcare. Healthcare security teams can reduce cyber risk by removing attacker options before an incident occurs rather than relying primarily on detection and response, said Chris Frenz, CISO at Rectangle Health, describing a new subtractive-hardening architecture standard he developed for OWSAP. First seen on…

