Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Massachusetts Opens Data Breach Notification Archive to Public

The Commonwealth of Massachusetts this week made an important step toward improving data breach transparency, as the Office of Consumer Affairs and Business Regulation (OCABR) made its Data Breach Notification Archive publicly available online.

The Commonwealth of Massachusetts this week made an important step toward improving data breach transparency, as the Office of Consumer Affairs and Business Regulation (OCABR) made its Data Breach Notification Archive publicly available online.

As its name suggests, the Data Breach Notification Archive was meant to keep records of accidental or intentional/malicous compromise of personal information. The archive was built as notifications came from entities that keep a Massachusetts resident’s personal information, because all are required by the Massachusetts Data Security Law to notify affected residents, OCABR, and the Attorney General’s Office of such incidents.

Previously, the information maintained by OCABR was available only through Public Records Requests, but that changed yesterday when the archive became publicly accessible.

The data breach reports are available on OCABR’s website in the form of PDF files that include information on when the breach was reported, the affected organization, the number of impacted residents, and information on the type of compromised personal information.

The reports include details on cyber-attacks, as well as information on incidents that occur in the physical word. Information on external hacks, unintentional data leaks, insider attacks, misplaced documents or devices, and other similar incidents is included in these reports.

Data included in the reports was gathered from various industries, including financial, manufacturing, retail, healthcare, hospitality, education, and more. Each entry is marked as an electronic (cyber) compromise or not.

A quick look at the 2016 Data Breach Report (PDF) shows that hundreds of such incidents have been reported last year, and that tens of thousands of Massachusetts residents were affected. Some 33,000 were impacted by the malware attack that hit Eddie Bauer stores, for example, while the Omni Hotels incident impacted only 1,000.

“The Data Breach Notification Archive is a public record that the public and media have every right to view. Making it easily accessible by putting it online is not only in keeping with the guidelines suggested in the new Public Records law, but also with Governor Baker’s commitment to greater transparency throughout the Executive Office,” Consumer Affairs Undersecretary John Chapman said.

Advertisement. Scroll to continue reading.

Related: MIT Network Under Frequent DDoS Assault: Report

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

Incident Response

Microsoft has rolled out a preview version of Security Copilot, a ChatGPT-powered tool to help organizations automate cybersecurity tasks.

Data Breaches

GoTo said an unidentified threat actor stole encrypted backups and an encryption key for a portion of that data during a 2022 breach.

Application Security

GitHub this week announced the revocation of three certificates used for the GitHub Desktop and Atom applications.

Incident Response

Meta has developed a ten-phase cyber kill chain model that it believes will be more inclusive and more effective than the existing range of...

Cloud Security

VMware described the bug as an out-of-bounds write issue in its implementation of the DCE/RPC protocol. CVSS severity score of 9.8/10.