Security
  • Menu
  • All Tips
  • FAQs
  • Categories
  • Guidelines
  • Data Security Support
  • Tools
  • Have I Been Pwned?
  • Pwned Passwords
  • Email Checker
  • Password Generator
  • My IP
  • Privacy
DATA PRIVACY NOTICE AND CONSENT FORM

Cloudstaff is committed to protecting the privacy of its data subjects, and ensuring the safety and security of personal data under its control and custody. This policy provides information on what personal data is gathered by Cloudstaff Security Tips about its current, past, and prospective employees; how it will use and process this; how it will keep this secure; and how it will dispose of it when it is no longer needed. This information is provided in compliance with the Philippine Republic Act No. 10173, also known as, the Data Privacy Act of 2012 (DPA) and its Implementing Rules and Regulations (DPA-IRR). It sets out Cloudstaffs’ data protection practices designed to safeguard the personal data of individuals it deals with, and also to inform such individuals of their rights under the Act.

The personal data obtained from this application is entered and stored within the Cloudstaff system and will only be accessed by the Cloudstaff’s authorized personnel. Cloudstaff have instituted appropriate organizational, technical and cloud security measures (Amazon Web Services Shared Responsibility) to ensure the protection of the users personal data.

Information collected will be automatically deleted after three (3) years inactivity.

Furthermore, the information collected and stored in the application are as follows:
  • Given Name
  • Family Name
  • Avatar [Profile Picture]

USER CONSENT

I have read the Data Privacy Statement and expressed my consent for Cloudstaff to collect, record, organize, update or modify, retrieve, consult, use, consolidate, block, erase or destruct my personal data as part of my information.

I hereby affirm my right to be informed, object to processing, access and rectify, suspend or withdraw my personal data, and be indemnified in case of damages pursuant to the provisions of the Republic Act No. 10173 of the Philippines, Data Privacy Act of 2012 and its corresponding Implementing Rules and Regulations.

If you want to exercise any of your rights, or if you have any questions about how we process your personal data, please contact Cloudstaff’s Data Protection Officer, through the following channel:

Email to privacy@cloudstaff.com

  • Log in Now
Kroll's Security Breach: Employee Targeted in SIM Swapping Incident

Kroll, a provider of financial advisory solutions, recently revealed an incident where one of its employees was targeted in an intricate SIM-swapping attack. On August 19, 2023, the episode focused on the employee's T-Mobile account. Unauthorized by Kroll or the employee, T-Mobile transferred the employee's phone number to the attacker's device as per their request. This breach enabled the assailant to access specific files containing personal information about bankruptcy claimants associated with BlockFi, FTX, and Genesis.

SIM swapping, typically a harmless process, was exploited to illegitimately activate a SIM card under their control with the victim's phone number. This allowed the interception of SMS messages, calls, and MFA-related notifications controlling online account access. The attacker often gathers personal details through methods like phishing or social media to convince the cellular carrier to transfer the victim's number to their SIM card.

Kroll has taken immediate measures to secure the affected accounts and has notified impacted individuals via email. Their ongoing investigation has not uncovered evidence of further compromised systems or accounts. This disclosure follows a recent lawsuit by Bart Stephens, co-founder of Blockchain Capital, against an anonymous hacker who allegedly executed a $6.3 million SIM swap attack.

The U.S. Department of Homeland Security's Cyber Safety Review Board (CSRB) has recently urged telecom providers to implement robust security protocols against SIM swapping, including customer account locking options and stringent identity verification.

The surge in SIM swapping attacks highlights the need for users to transition from SMS-based 2FA to more secure methods to protect online accounts from phishing attempts.


Source: https://thehackernews.com/2023/08/kroll-suffers-data-breach-employee.html


Caitlin Joyce (CaitlinG) Galanza | News
Created: August 29 2023 | Updated: on 8/29/23
Comments


  2021 © Mazer

Security Tips v2.0.1 | Crafted with by Saugi