<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>data breaches Archives - Quayside Technical Services</title>
	<atom:link href="https://www.qts-ltd.com/tag/data-breaches/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.qts-ltd.com/tag/data-breaches/</link>
	<description>Delivering effective IT &#38; telecoms services &#38; support across Devon &#38; The South West.</description>
	<lastBuildDate>Tue, 24 Sep 2024 21:38:57 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.0.12</generator>

<image>
	<url>https://www.qts-ltd.com/wp-content/uploads/2019/07/cropped-quayside-favicon-32x32.png</url>
	<title>data breaches Archives - Quayside Technical Services</title>
	<link>https://www.qts-ltd.com/tag/data-breaches/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Teenager Arrested In Connection With TfL Cyber Attack</title>
		<link>https://www.qts-ltd.com/teenager-arrested-in-connection-with-tfl-cyber-attack/</link>
					<comments>https://www.qts-ltd.com/teenager-arrested-in-connection-with-tfl-cyber-attack/#respond</comments>
		
		<dc:creator><![CDATA[staff]]></dc:creator>
		<pubDate>Sat, 21 Sep 2024 09:50:12 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Stop-Press]]></category>
		<category><![CDATA[Computer Misuse Act]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[Oyster]]></category>
		<category><![CDATA[Shashi Verma]]></category>
		<category><![CDATA[TfL]]></category>
		<category><![CDATA[Transport for London]]></category>
		<guid isPermaLink="false">https://www.qts-ltd.com/?p=128672</guid>

					<description><![CDATA[<p>A 17 year old male has been arrested on suspicion of Computer Misuse Act offences in relation to a cyber attack on Transport for London (TfL) on the 1st September 2024. Although TfL reported on its website on 5th September that “there is no evidence that any customer data has been compromised”, it has since [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/teenager-arrested-in-connection-with-tfl-cyber-attack/">Teenager Arrested In Connection With TfL Cyber Attack</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div>
<p>A 17 year old male has been arrested on suspicion of Computer Misuse Act offences in relation to a cyber attack on Transport for London (TfL) on the 1st September 2024.</p>
</div>
<div>
<p>Although TfL reported on its website on 5th September that “there is no evidence that any customer data has been compromised”, it has since been reported that a further investigation has revealed that this may not be the case.</p>
</div>
<div>
<p>It’s been reported that Shashi Verma, TfL’s chief technology officer has said that investigations have now revealed that <i>“certain customer data has been accessed”</i> which could include “some customer names and contact details”, which may include some email and physical addresses. Also, it’s been reported that some customer Oyster card refund data may also have been accessed which may include <i>“bank account numbers and sort codes”</i>. The teenage suspect, believed to be from Walsall, was arrested on 5th September, questioned and bailed.</p>
</div>
<div>
<p>TfL has now referred itself to the Information Commissioner’s Office (ICO), says it is working with its partners to progress the investigation, and says it will be contacting customers directly about the matter. TfL also says it has implemented new IT security measures add extra protection to all its safety critical systems and processes.</p>
</div>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/teenager-arrested-in-connection-with-tfl-cyber-attack/">Teenager Arrested In Connection With TfL Cyber Attack</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.qts-ltd.com/teenager-arrested-in-connection-with-tfl-cyber-attack/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Shadow AI and Shadow SaaS Risks?</title>
		<link>https://www.qts-ltd.com/shadow-ai-and-shadow-saas-risks/</link>
					<comments>https://www.qts-ltd.com/shadow-ai-and-shadow-saas-risks/#respond</comments>
		
		<dc:creator><![CDATA[staff]]></dc:creator>
		<pubDate>Wed, 17 Jul 2024 09:10:13 +0000</pubDate>
				<category><![CDATA[Tech Insight]]></category>
		<category><![CDATA[ai]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[Infosecurity Europe 2024]]></category>
		<category><![CDATA[Next DLP survey]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[RSA Conference 2024]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[security risk]]></category>
		<category><![CDATA[Shadow AI]]></category>
		<category><![CDATA[Shadow SaaS]]></category>
		<category><![CDATA[shadow technology]]></category>
		<category><![CDATA[software as a service]]></category>
		<guid isPermaLink="false">https://www.qts-ltd.com/?p=128503</guid>

					<description><![CDATA[<p>A Next DLP survey has revealed how the rise of ‘Shadow SaaS’ and ‘Shadow AI’ may be putting businesses at risk of data loss, lack of oversight and data breaches. What are Shadow SaaS and Shadow AI?  Shadow SaaS refers to the use of software as a service (SaaS) applications within an organisation without explicit [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/shadow-ai-and-shadow-saas-risks/">Shadow AI and Shadow SaaS Risks?</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A Next DLP survey has revealed how the rise of ‘Shadow SaaS’ and ‘Shadow AI’ may be putting businesses at risk of data loss, lack of oversight and data breaches.</p>
<h5><strong>What are Shadow SaaS and Shadow AI? </strong></h5>
<p>Shadow SaaS refers to the use of software as a service (SaaS) applications within an organisation without explicit approval from the IT department. Similarly, Shadow AI involves the deployment of AI tools and solutions without official oversight. The issue for businesses is that these shadow technologies often bypass the stringent security protocols and oversight that sanctioned IT solutions are subjected to, thereby creating potential vulnerabilities.</p>
<h5><strong>Prevalent </strong></h5>
<p>The Next DLP survey, conducted at RSA Conference 2024 and Infosecurity Europe 2024, established that the prevalence of SaaS applications in organisations is high, with 73 percent of security professionals admitting to using SaaS applications that had not been provided by their company’s IT team in the past year.</p>
<h5><strong>Key findings from the Next DLP survey </strong></h5>
<p>The Next DLP survey appears to have revealed some of the more potentially negative implications of the use of Shadow SaaS and Shadow AI in organisations. The survey reveals three primary areas of concern: data loss, lack of oversight and data breaches.</p>
<h5><strong>Data loss </strong></h5>
<p>The unregulated nature of Shadow SaaS and Shadow AI can mean that sensitive data can easily be transferred, shared, or stored outside the secure confines of the company’s IT infrastructure. However, one key issue highlighted by the Next DLP survey, is the apparent disparity between employee confidence in using unauthorised tools and the organisation’s ability to mitigate the risks. For example, 65 percent of respondents named data loss as a top risk of using unauthorised tools, and according to 40 percent of security professionals, it appears that employees may not fully understand the data security risks posed by Shadow SaaS and Shadow AI.</p>
<p>The survey respondents noted multiple instances where critical business data was inadvertently exposed or lost due to the use of unauthorised applications and AI tools. This data loss can not only hamper business operations but also puts companies at risk of non-compliance with data protection regulations.</p>
<h5><strong>Lack of oversight</strong></h5>
<p>Another significant challenge highlighted by the survey is the lack of visibility of shadow technologies. Without proper oversight, IT departments cannot track or manage these applications, making it difficult to enforce security policies or detect anomalies.</p>
<p>The survey indicated, for example, that 62 percent of respondents are concerned about the lack of full visibility and control of the SaaS and AI tools being used within their organisations, thereby leading to unmanaged risks and potential security gaps.</p>
<h5><strong>Data breaches</strong></h5>
<p>The integration of unauthorised applications and AI tools also significantly increases the risk of data breaches for organisations. Shadow technologies often lack the strong security measures that are standard in approved IT solutions.</p>
<p>The Next DLP survey reflected this with 52 percent of respondents seeing data breaches as a top risk of using unauthorised tools. The survey also reported an apparent surge in security incidents linked to shadow applications, with many businesses experiencing breaches that compromised sensitive information. For example, 10 percent of respondents admitted they were certain their organisation had suffered a data breach or data loss as a result of Shadow SaaS usage.</p>
<p>Data breaches not only result in financial losses but also damage the reputation of the affected companies.</p>
<h5><strong>Understanding of Shadow SaaS and AI risks </strong></h5>
<p>As previously touched upon, the Next DLP survey also revealed gaps in employee training and awareness regarding Shadow SaaS and AI risks in their organisation. For example, it showed that 40 percent of security professionals believe employees do not understand these risks, and only 37 percent have developed clear policies and consequences for unauthorised tool use. 20 percent admitted to being unaware of their company’s policy updates or training on these risks and 20 percent also said they hadn’t received any guidance and updated policies in the past six months.</p>
<p>Such findings, therefore, appear to highlight the need for improved awareness and education on managing shadow technologies.</p>
<h5><strong>What to do? </strong></h5>
<p>To mitigate the risks associated with Shadow SaaS and Shadow AI, businesses may, therefore, benefit from adopting a proactive approach and using key strategies such as:</p>
<ul>
<li>Enhanced monitoring: implementing advanced monitoring tools to detect and manage unauthorised applications.</li>
<li>Employee education: training employees on the risks of using unapproved technology and the importance of adhering to company policies.</li>
<li>Robust policies: developing and enforcing clear and comprehensive IT policies that address the use of SaaS and AI tools.</li>
<li>Promote approved alternatives: for example, encouraging the use of approved and secure alternatives to unauthorised applications can help reduce reliance on risky shadow technologies. Currently, only 28 percent of organisations promote such alternatives.</li>
<li>Regular audits: conducting regular audits to identify and remediate any instances of shadow technology usage.</li>
</ul>
<h5><strong>What does this mean for your business? </strong></h5>
<p>The findings from the Next DLP survey reveal a critical need for businesses to address the growing risks associated with Shadow SaaS and Shadow AI. The prevalence of unauthorised tools, combined with the significant risks of data loss, lack of oversight and data breaches, all highlight the urgency for a strategic response.</p>
<p>For businesses, this means taking proactive steps to manage and mitigate these risks. For example, implementing advanced monitoring tools can help detect and control the use of unsanctioned applications and AI tools. By gaining full visibility into the tools employees use, businesses can better enforce security policies and detect anomalies early.</p>
<p>Employee education is another way to mitigate the risks. Training staff about the dangers of using unauthorised technologies and the importance of adhering to company policies can significantly reduce the likelihood of data breaches and other security incidents. Developing and enforcing clear and comprehensive IT policies can also help ensure that all employees understand the consequences of using unapproved tools.</p>
<p>Promoting the use of approved, secure alternatives, encouraging employees to rely on sanctioned applications, and having regular audits, are also ways that businesses can minimise the risks associated with Shadow SaaS and Shadow AI, identify and address any instances of shadow technology usage, and ensure continuous compliance and security.</p>
<p>Adopting these kinds of proactive strategies may mean that businesses can safeguard against the vulnerabilities posed by unauthorised applications and AI tools, protect their sensitive data, and enhance their overall security posture, thereby helping to avoid the pain of financial losses and reputational damage.</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/shadow-ai-and-shadow-saas-risks/">Shadow AI and Shadow SaaS Risks?</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.qts-ltd.com/shadow-ai-and-shadow-saas-risks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Toyota Hack Warning</title>
		<link>https://www.qts-ltd.com/toyota-hack-warning/</link>
					<comments>https://www.qts-ltd.com/toyota-hack-warning/#respond</comments>
		
		<dc:creator><![CDATA[staff]]></dc:creator>
		<pubDate>Thu, 14 Dec 2023 15:56:40 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Stop-Press]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Medusa ransomware]]></category>
		<category><![CDATA[Toyota]]></category>
		<guid isPermaLink="false">https://www.qts-ltd.com/?p=127564</guid>

					<description><![CDATA[<p>Toyota Financial Services (TFS), a subsidiary of Toyota Motor Corporation, has warned customers that it recently suffered a data breach which exposed sensitive personal and financial data. &#160; The correspondence with affected customers follows Toyota confirming last month that unauthorised access on some of its Europe and Africa systems had been detected. Medusa ransomware reported [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/toyota-hack-warning/">Toyota Hack Warning</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div>
<p>Toyota Financial Services (<a href="https://www.toyota.co.uk/personal-finance/my-finance/about-toyota-finance">TFS</a>), a subsidiary of <a href="https://global.toyota/en/">Toyota Motor Corporation</a>, has warned customers that it recently suffered a data breach which exposed sensitive personal and financial data.</p>
</div>
<div>
<p>&nbsp;</p>
</div>
<div>
<p>The correspondence with affected customers follows Toyota confirming last month that unauthorised access on some of its Europe and Africa systems had been detected. Medusa ransomware reported that it was behind Toyota’s system being compromised and issued Toyota with an $8,000,000 ransom request to have the stolen data deleted.</p>
</div>
<div>
<p>&nbsp;</p>
</div>
<div>
<p>The advice from TFS to its customers is to contact their bank to take additional security precautions, add 2FA to their online accounts, monitor any unusual activities, and obtain a current credit report from Schufa, a German credit rating agency. Toyota has also said that it has informed the responsible state data protection officer for North Rhine-Westphalia in compliance with GDPR.</p>
</div>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/toyota-hack-warning/">Toyota Hack Warning</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.qts-ltd.com/toyota-hack-warning/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ChatGPT Release Linked To Massive Phishing Surge</title>
		<link>https://www.qts-ltd.com/chatgpt-release-linked-to-massive-phishing-surge/</link>
					<comments>https://www.qts-ltd.com/chatgpt-release-linked-to-massive-phishing-surge/#respond</comments>
		
		<dc:creator><![CDATA[staff]]></dc:creator>
		<pubDate>Thu, 09 Nov 2023 18:54:56 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Stop-Press]]></category>
		<category><![CDATA[ChatGPT]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[emails]]></category>
		<category><![CDATA[LLM chatbots]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[SlashNext’s State of Phishing 2023]]></category>
		<category><![CDATA[Threat Detection Technology SlashNext]]></category>
		<guid isPermaLink="false">https://www.qts-ltd.com/?p=127343</guid>

					<description><![CDATA[<p>Threat Detection Technology SlashNext has reported that in the 12 months that ChatGPT has been publicly available, the number of phishing emails has jumped 1,265 per cent, with credential phishing, a common first step in data breaches, seeing a 967 per cent increase. &#160; SlashNext’s State of Phishing 2023 report notes that cyber criminals may have [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/chatgpt-release-linked-to-massive-phishing-surge/">ChatGPT Release Linked To Massive Phishing Surge</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div>
<p>Threat Detection Technology SlashNext has reported that in the 12 months that <a href="https://chat.openai.com/auth/login">ChatGPT</a> has been publicly available, the number of phishing emails has jumped 1,265 per cent, with credential phishing, a common first step in data breaches, seeing a 967 per cent increase.</p>
</div>
<div>
<p>&nbsp;</p>
</div>
<div>
<p><a href="https://slashnext.com/state-of-phishing-2023/">SlashNext’s State of Phishing 2023</a> report notes that cyber criminals may have been leveraging LLM chatbots like ChatGPT to help write more convincing phishing emails and to launch highly targeted phishing attacks. Generative AI chatbots may also have lowered the barriers for any bad actors wanting to launch such campaigns, by giving less skilled cyber criminals the tools to run more complex phishing attacks.</p>
</div>
<div>
<p>&nbsp;</p>
</div>
<div>
<p>Businesses can safeguard against phishing attacks by taking measures such as educating employees to recognise fraudulent communications, enforcing strong password policies, using MFA, keeping software up to date and installing antiphishing tools, and by having an effective incident response plan to mitigate damage from breaches.</p>
</div>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/chatgpt-release-linked-to-massive-phishing-surge/">ChatGPT Release Linked To Massive Phishing Surge</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.qts-ltd.com/chatgpt-release-linked-to-massive-phishing-surge/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
