Connect with us

Massachusetts

‘Don’t assume you are safe’: Data breaches spike in Massachusetts, following national trend – The Boston Globe

Published

on

‘Don’t assume you are safe’: Data breaches spike in Massachusetts, following national trend – The Boston Globe


Micale said she quickly called up her bank and put a freeze on her account. But that put her trip to Boston with her husband, the first after over a year of long COVID, on hold.

“It was really stressful,” she said. “I had to cancel all my reservations and start over from scratch.”

Micale is far from the only Massachusetts resident to be impacted by a data breach in recent years.

A new Globe analysis of state data shows just how off-the-charts the problem has become. In 2022, 1.9 million Massachusetts resident accounts were impacted by data breaches. The following year, that number spiked to more than 6.9 million accounts, fueled in part by large-scale breaches, including one that affected more than 2 million Harvard Pilgrim Health Care accounts.

Advertisement

So far this year, the numbers are already above the historical average, though not quite as striking as 2023, with 1.8 million accounts breached through September.

The overall uptick is “a trend around the world,” said Stuart Madnick codirector of MIT’s flagship cybersecurity consortium. “It’s no surprise that Massachusetts is part of the uptick.”

As more data than ever, including sensitive personal banking and health care information, is stored on the internet, breaches are becoming increasingly common, he and others said. Meanwhile, hacker groups are also becoming more sophisticated, putting more people at risk of fraud and identity theft.

Advertisement
Stuart Madnick, professor at MIT, held one of the letters he received regarding data breaches. Suzanne Kreiter/Globe Staff

Across the United States, an estimated 353 million accounts fell victim to data breaches last year, according to the Identity Theft Resource Center, a national nonprofit that provides cost-free assistance to identity theft victims. The total number of breaches was 72 percent higher than the previous record year of 2021.

Data breach victims can suffer serious financial and personal repercussions after their information is compromised. For consumers, their financial information could be sold on the dark web, where scammers can purchase it and rack up debt in their name.

The burden of dealing with the consequences, such as contesting fraudulent charges, often falls on consumers.

Doing so can prove challenging even for tech-savvy people like Leigh Graham, a Johns Hopkins researcher, whose personal data has been breached at least twice in the past year, including when her employer was breached.

Graham, who lives in Northampton, said she struggled to navigate credit bureau websites to freeze her credit report after she noticed that someone spent $550 on Ticketmaster in her name.

“I’m 49, but I feel like I don’t understand what I’m looking at,” she said. “The onus is so on the individual consumer to fix everything.”

Advertisement

Companies impacted by data breaches may find themselves paying hefty ransom to keep their clients’ data from being published online.

That’s what happened to Change Healthcare, a subsidiary of United Health, a national conglomerate. It paid a $22 million ransom earlier this year to a hacking group that stole protected health information from their systems. The health care group acknowledged that the stolen data could include information on a “substantial proportion of people in America.” Massachusetts data indicates that tens of thousands of residents were caught up in the breach.

Screenshots of some of the hacked data ended up online, despite the ransom payment. The hack also reportedly led to problems for patients in getting prescriptions approved at hundreds of medical facilities across the country.

In Massachusetts, both national behemoths, like T-Mobile, and smaller organizations, like the Roman Catholic Diocese of Fall River, have been hit by data breaches in recent years, data shows. Even state government employees have been targeted.

At smaller organizations, experts say it’s a daunting task for IT teams with limited resources to compete with large international hacking organizations.

Advertisement

“A lot of [small] organizations have to face a cost-benefit tradeoff, and sometimes just have to accept a certain level of risk,” said Saroja Hanasoge, director of advisory services at CyberTrust Massachusetts, which partners with cities and organizations across the state to beef up their cybersecurity.

The largest reported hack affecting Massachusetts residents since 2017 happened last year, when Harvard Pilgrim Health Care revealed a breach that affected over 2.1 million state client accounts. Harvard Pilgrim is a subsidiary of Point32Health, the second biggest health insurance company in the state, and provides coverage at dozens of hospitals in Massachusetts alone.

In an open letter written to clients after the hack, the nonprofit said hackers may have gotten access to files containing client names, Social Security numbers, dates of birth, tax identification numbers, and patient clinical information, such as medical diagnoses and treatments.

chart visualization

“We want to assure you that we are taking this incident extremely seriously, and we deeply regret any inconvenience this incident may cause,” the group’s letter said.

A spokesperson for Harvard Pilgrim declined to speak about the breach.

Advertisement

Bad actors are becoming more sophisticated

Experts say it’s now far easier for bad actors to go online and buy hacking services at low cost, often using cryptocurrencies like Bitcoin.

For-hire hacking groups do a lot of the technical work that everyday thieves would ordinarily not have the know-how to pull off, said Kevin Powers, director of the cybersecurity program at Boston College. Some of the hacking groups even offer affordable subscriptions.

For as little as $40 a month “you can get yourself a monthly subscription for a criminal enterprise,” Powers said.

He added that schemers also now use artificial intelligence services available on the dark web that are built to make hacking easy. Many hacking groups have begun using the AI services to make highly personalized phishing emails that are much harder to spot as fraudulent.

Advertisement

Even in cases where federal investigators manage to shut down a big hacking network, they will often reappear online, sometimes from a different country.

Hackers also have the benefit of bigger and easier targets to crack in recent years, as a growing number of companies are putting troves of data on poorly set up cloud servers with minimal protections.

“The bad guys are getting badder faster than the good guys are getting better,” Madnick of MIT said.

Some of those bad guys have even managed to break into Madnick’s accounts multiple times.

“You can be the most careful person in the world and there is no way to guarantee they won’t break in,” he said. “Don’t assume you are safe.”

Advertisement

Scooty Nickerson can be reached at scooty.nickerson@globe.com.





Source link

Massachusetts

“Missed jury duty” scam involving Bitcoin ATMs targets Massachusetts residents, sheriff warns

Published

on

“Missed jury duty” scam involving Bitcoin ATMs targets Massachusetts residents, sheriff warns


Two Massachusetts women recently lost a combined $6,700 to a “missed jury duty” phone scam that utilized Bitcoin ATMs, Norfolk County Sheriff Patrick McDermott said.

According to the sheriff, there’s been an increase in calls from scammers who claim to work for local law enforcement and demand money from residents who have supposedly missed jury duty. They threaten to arrest those who don’t agree to pay.

“The Norfolk County Sheriff’s Office never makes calls like this, and neither do local police departments,” McDermott said in a statement Wednesday. “Just hang up on anyone who is demanding money and acting like they are from our office, or another law enforcement agency, threatening you with arrest or detainment for things like ‘missed jury duty’ or an ‘outstanding warrant.’”

Scammers used Bitcoin ATMs

Both of the victims came to the sheriff’s office after sending money to the scammers. One was a woman from Sharon who paid $5,250 via a Bitcoin kiosk.

Advertisement

“She told our officer she was there to clear up an issue about missing jury duty after transferring the money as demanded,” the sheriff said. 

The woman said she saw a sign on the Bitcoin machine warning about scams, but the person on the phone told her should would be detained for 10-12 days if she didn’t pay.

Just 90 minutes later, the sheriff said a woman from Dedham came into the office to report that she paid a $1,450 “bond” through a Roslindale Bitcoin kiosk. The scammer reportedly sent her a “fraudulent court document to back up his claims,” the sheriff said, and threatened that she’d be arrested and detained for 72 hours unless she paid immediately.  

Scam warnings

The city of Gloucester recently banned Bitcoin ATMs, saying they’re concerned the machines could be used by scammers to prey on elderly victims. And in Waltham this summer, a police officer stopped an elderly man from sending $12,000 to scammers via a Bitcoin machine. 

In August, the Federal Trade Commission warned that scammers pretending to be police are calling up Americans and directing them to fake websites to pay a fine for missing jury duty. 

Advertisement

“It might ask you to pay up to $10,000 in fines on the site, or send you to a “government kiosk” (no such thing) to pay by cryptocurrency,” the FTC said. “But every bit of this is a scam.”



Source link

Advertisement
Continue Reading

Massachusetts

State senator shuts down session to ‘send a loud message’ about shutdown blame game

Published

on

State senator shuts down session to ‘send a loud message’ about shutdown blame game


Republican Sen. Ryan Fattman shut down the Senate’s session after just a few minutes Monday morning, saying he hoped to “send a message” about the Healey administration pointedly blaming President Donald Trump for a lapse in SNAP benefits in official state communications.

With SNAP benefits at risk of lapsing lapsing for about 1.1 million Bay Staters starting Saturday as a result of the federal government shutdown, the Massachusetts Department of Transitional Assistance website says that “President Trump is currently choosing to not issue November SNAP benefits that help you and many families put food on the table,” and the same language went out in emails and text messages to SNAP recipients.

“People need to be adults and act as such,” Fattman told NBC10 Boston. “The immaturity, the political gamesmanship, it all has to stop.”

Senator Fattman halted the Senate’s Monday session by doubting the presence of a quorum in protest of the politicization of this issue.

Advertisement

Fattman told the State House News Service that he has been trying to help constituents access SNAP benefits and started seeing the department’s messaging over the weekend as state-funded emails and text messages started going out.

“We’ve seen the federal government play this political game using taxpayer resources to say crazy messages and now Massachusetts is doing it under the Healey Administration,” Fattman said. “I felt that was wrong. I wanted to send a loud message that this needs to end.”

Gov. Maura Healey said that President Donald Trump has the power to distribute federal dollars that serve as a lifeline for many residents, but that Massachusetts does not have the money to cover the benefits if they are lost.

Fattman brought about an early end to Monday’s Senate session by doubting the presence of a quorum. Because a quorum of senators was not on hand and could not be rallied in about 10 minutes, the branch adjourned until Thursday. Sen. Sal DiDomenico of Everett was presiding over Monday’s session and Millbury Sen. Michael Moore arrived in the chamber about 10 minutes after Fattman’s motion.

Republicans and Democrats in Washington have been unable to agree on bills to fund government operations for the last four weeks and leaders of the two major parties have blamed each other for the shutdown.

Advertisement

Healey on Monday reiterated her stance about Trump’s role in the SNAP funding sitaution, and she wasn’t alone among Democratic politicians.

“They’re trying to make their resources stretch when Republicans are cutting food assistance,” Congresswoman Lori Trahan said.



Source link

Advertisement
Continue Reading

Massachusetts

Massachusetts woman worries for family in Jamaica as Hurricane Melissa could bring mud slides, flooding

Published

on

Massachusetts woman worries for family in Jamaica as Hurricane Melissa could bring mud slides, flooding


A woman in Massachusetts is worried for her family in Jamaica as Hurricane Melissa could bring catastrophic flooding to the island. 

Hurricane Melissa is currently a Category 4 hurricane, but could strengthen to a Category 5 before it hits Jamaica and Haiti in the coming days. The storm could bring up to 30 inches of rain to the island and cause damage to infrastructure.

“I am really concerned about mud slides,” Framingham resident and real-estate agent JoAnn Frye said.  

Frye owns an Airbnb in Ocho Rios, Jamaica, at Pyramid Point. She said that she has already lost power to her outdoor video cameras and that her home manager moved everything inside in anticipation of the storm. 

Advertisement

“I’m very nervous. I’ve been watching this WhatsApp group because that’s how we communicate in the community,” Frye said.  

Residents in Jamaica prepare for Hurricane Melissa

Jamaica’s Prime Minister, Andrew Holness, urged residents to take the storm very seriously.

“We’ve been prepared for a couple of days now. We have gas generators. We have extra water in the rooms, and then we have some larger tanks of water prepared for that, just in case power goes out. We have some solar lights,” said Frye’s cousin, Mark Walker, who lives on the island.

He plans on hunkering down with his family for the next few days. 

“It’s one of those scenarios where it’s not just us, it’s everyone else, but we have a pretty good group of neighbors and friends that are close by, kind of looking out for each other,” Walker said.

Advertisement

Joanne says she’s glad she’s not there, but is praying for her people in Jamaica.  

I’m still scared for the people I know and love there. I’m scared for the community,” Frye said.

She said that she plans to fly down once the storm passes to check on her loved ones and her home. 

For more information on Hurricane Melissa and to see its potential path, click here. 

Advertisement



Source link

Continue Reading

Trending