Indiana, Cybersecurity Vendor Dispute Circumstances of Data Breach

Indiana officials say that an unauthorized party recently accessed the personal information of about 750,000 state residents from a COVID-19 contact-tracing database, identifying it as a cybersecurity vendor “that intentionally looks for software vulnerabilities, then reaches out to seek business.” They say the vulnerability was immediately corrected after the breach, but the company – independently identified as UpGuard – held onto the data for several weeks before contacting them.
🔒 Members Only · Cyber & Privacy BriefYou’ve reached the member portion of this brief.Members read the full analysis and the source documents in every case digest, six days a week.
$750/year
