Personal data of 1.4M Washington unemployment claimants exposed in hack
sao.wa.gov
sao.wa.gov
The Employment Security Department has basically been on fire for the past year with the fraud, delayed payments, and then demanding return of some payments. The woman leading the department was a big donor to the campaign of the current governor. However she's finally facing accountability for her departments failure, by being chosen to lead a Federal Sub-Agency, focused on state unemployment benefits[0].
I wish I was joking.
[0] - https://mynorthwest.com/2521710/suzi-levine-unemployment-exp...
A few months later I got a letter asking me to pay it pay it back.
Later I got very badly injured. Like brain damage level. Got laughed At when applying for disability. Apparently if you have a stroke, then a desk job is fine, since you just need to sit there.
There is a narrow range between deathly ill and dead that you can obtain assistance.
Disability was private company though.
I am one of them who is in process proving identity for a few months now.
1.4 million (same number of people) cut off on January 1 because needed to prove their identity.
California agency backing off on this, probably because of intense human cost of that many.
In other places these things aren't treated so lightly.
Netherlands government (Prime Minister and cabinet) recently resigned over a scandal where about 40,000 people in a country of 17 million, so like 800,000 in proportion in USA, were kicked off family benefits and accused of fraud, often for BS like forgetting to sign a document.
It's bad.
Read as: "It's too bad this happened to you :shrug-emoji:"
They list some big clients on their website - Kaiser Permanente, KPMG, the NHS, etc.
> Prevent breaches and compliance violations with total visibility and control over IP, PII, PHI and all sensitive content exchanged with third parties
edit: The Reserve Bank of New Zealand and the Australian Securities and Investments Commission were also breached, news articles pin the blame on a SQL injection in Accellion's File Transfer Appliance (FTA)
https://www.databreachtoday.com/australian-financial-regulat...
"A representative for Accellion told The Times that the breach involved a 20-year-old “legacy product” which the company has been encouraging customers to stop using."
Basically, you can either blame Accellion for not supporting old products enough, or you can blame the State Auditor's office for not upgrading in a timely manner, depending on your POV. I think 20 years old is enough that I'll blame the Auditor's office.
That said a SQL Injection vulnerability in a 20 year old product definitely raises certain, questions.
Tangentially, I wonder: has anyone built a friendly browse/search interface for all-time CVE data [0]? This makes me curious about what the history of SQL injection vulnerability discovery looks like.