Red Cross Blood Service Admits To Personal Data Breach Affecting Half a Million Donors (abc.net.au) 32
The personal data of 550,000 blood donors that includes information about "at-risk sexual behaviour" has been leaked from the Red Cross Blood Service in what has been described as Australia's largest security breach. From an ABC report:The organisation said it was told on Wednesday that a file containing donor information was placed on an "insecure computer environment" and "accessed by an unauthorised person." The file contained the information of blood donors from between 2010 and 2016. The data came from an online application form and included "personal details" and identifying information including names, gender, addresses and dates of birth, a Red Cross statement said. Red Cross Blood Service chief executive Shelly Park said "due to human error" the unsecured data had been posted on a website by a contractor who maintains and develops the Red Cross website.
They won't take my blood (Score:1)
American Red Cross doesn't like good English blood! (probably because giants on bean stalks can smell it and get irate at the smell) I've tried several times but they're scared I have mad cow disease.
Don't know if the Aussies would take my blood, they're already mad, but they can't have it now.
Re: (Score:2)
Translation. . . (Score:2)
. . . somebody copied the database to a thumb drive, OR somebody emailed the file outside the corporate network. . .
Or, the short version, somebody did something stupid that they were likely specifically told NOT to do in a security briefing that they either scanned or pencil-whipped. . . .
Re: (Score:2)
contractor who maintains and develops the Red Cross website.
so they want with the low bidder over seas guys?
Re: (Score:2)
Well this is the year 2016 where hackers are no longer the equivalent of nuisance where their attacks were just a mild inconvenience. Today such breaches are serious and can affect people's lives. The Red Cross should had filled the USB ports with Glue and locked down the PC's to prevent some stupid person from accidentally leaking a major problem.
Worse than Ashley Madison (Score:3)
Blood donations forms typically include very sensitive questions like your number of sex partners, if it is not a clear "are you cheating?".
With Ashley Madison, where the mere presence of an account is a very weak proof of infidelity. In fact, considering the number of actual women present of the site, the chance of a husband cheating his wife through this site is almost zero (unless bots count). But if you answer "yes" to one of the sensitive questions in a blood donor questionnaire, it can be considered a definite proof.
Re: (Score:2)
Not true, at least in the US. It asks about paying for sex, travel, and man on man sex in the history. Not number of partners.
That could still theoretically be bad for a man if he is married to a woman and answers yes to any of those questions.
Re: (Score:2)
So . . .what you're saying is. . .
"Wimmen, Dey Took Er Jerbs" ????
(grin)
Re: (Score:2)
The Red Cross along with a select other few entities such as the NY Times still solicits my long dead grandfather once a year who passed back in the late 90s.
Maybe they figure they can get more blood than normal from him since he's not using it anymore?
Doesn't make sense (Score:5, Insightful)
Why would the website developer have access to the donor database?
"due to human error"? (Score:3)
[...] the unsecured data had been posted on a website by a contractor who maintains and develops the Red Cross website.
Sorry, but could someone please explain to me how is it even possible to do that accidentally?
Re: (Score:2)
[...] the unsecured data had been posted on a website by a contractor who maintains and develops the Red Cross website.
Sorry, but could someone please explain to me how is it even possible to do that accidentally?
Hellary and the DNC did it on purpose. And Mexican rapists. And that Baldwin guy. And Megyn Kelly. And Muslims and Bill Maher.
It all makes perfect sense now doesn't it?
Re: (Score:2)
Are you having a stroke?
of genius - yes indeedy!
AUSTRALIA (Score:2)
Neither TFA nor the summary make it clear that this was just the Australia Red Cross. No indications so far that any other countries have suffered a similar breach.