Jul 12, 2017

Verizon security breach exposes millions of customers' info

Elise Amendola / AP

When researcher Chris Vickery told Verizon last month it was the victim of a cyber breach, it took over a week to secure the data that had been exposed, ZDNet reports. More than 14 million U.S. customers had their data exposed, including their addresses, names, phone numbers, and account PINs, according to security firm UpGuard, where Vickery works.

What it means: That's enough to get you into someone's account, even if there's two-factor authentication. European telecoms provider Orange may have also had some data on the exposed server.

How it happened: Verizon said an employee at NICE Systems, a third-party vendor, incorrectly left the sensitive data on an unprotected Amazon S3 storage server. CNN reports Verizon gave a third party access to this information to facilitate customer service calls (only customers who called customer service in the last six months had their information exposed).

85 of the Fortune 100 are NICE customers and the company has been linked with government intelligence agencies around the world, per Privacy International.

Implications: Charles Goldberg, Senior Director of Product for Thales e-Security, pointed out that while "an unfortunate incident in its own right, the Verizon leak is not a solitary occurrence. Amazon S3 buckets are vulnerable to data leaks…even very well trained professionals can find it challenging to manage access controls."

Verizon's take: Verizon said 6 million customers' personal data was leaked, rather than 14, according to CNN. There is "no indication that the information has been compromised."

What to watch: If the FCC investigates the breach. (Cosumer rights group Public Knowledge has called on the FCC to do so.)

Go deeper

Federal court temporarily halts "Remain in Mexico" program

Migrant wearing a cap with U.S. flagin front of the border between Guatemala and Mexico. Photo: Jair Cabrera Torres/picture alliance via Getty Image

The 9th Circuit Court of Appeals upheld a lower court's earlier injunction on Friday, temporarily stopping the Trump administration from enforcing the Migrant Protection Protocols (MPP) — known as the "Remain in Mexico" policy.

Why it matters: Tens of thousands of migrants seeking asylum have been forced to wait out their U.S. immigration court cases across the border in Mexico under the policy. The Trump administration has long credited this program for the decline in border crossings following record highs last summer.

Go deeperArrowUpdated 2 hours ago - Politics & Policy

Coronavirus updates: WHO raises global threat level to "very high"

Data: The Center for Systems Science and Engineering at Johns Hopkins, the CDC, and China's Health Ministry. Note: China numbers are for the mainland only and U.S. numbers include repatriated citizens.

The World Health Organization raised its global risk assessment for the novel coronavirus to "very high" Friday, its highest risk level as countries struggle to contain it. Meanwhile, National Economic Council director Larry Kudlow this morning tried to reassure the markets, which continued to correct amid growing fears of a U.S. recession.

The big picture: COVID-19 has killed more than 2,860 people and infected about 83,800 others in almost 60 countries and territories outside the epicenter in mainland China. The number of new cases reported outside China now exceed those inside the country.

Go deeperArrowUpdated 3 hours ago - Health

Bernie's plan to hike taxes on some startup employees

Illustration: Sarah Grillo/Axios

Sens. Bernie Sanders (D-VT) and Chris Van Hollen (D-MD) introduced legislation that would tax nonqualified stock options at vesting, rather than at exercise, for employees making at least $130,000 per year.

The big picture: Select employees at private companies would be taxed on monies that they hadn't yet banked.