I overlooked it given all the new articles about Kazu that popped up this morning but they had taken down the various posts about MMH in their channel as well as the Tor ransom page.
I overlooked it given all the new articles about Kazu that popped up this morning but they had taken down the various posts about MMH in their channel as well as the Tor ransom page.
app.managemyhealth.co.nz/authenticati...
app.managemyhealth.co.nz/authenticati...
I filed an OIA with MoH who just said they're transferring it back to Te Whatu Ora 🤦
fyi.org.nz/request/3340...
I filed an OIA with MoH who just said they're transferring it back to Te Whatu Ora 🤦
fyi.org.nz/request/3340...
MMH state police advice is to not interact with hackers, they will behind notifying patients in the next 24 hours via email, they are establishing an advisory board and their mobile app will instead redirect to their web app temporarily.
MMH state police advice is to not interact with hackers, they will behind notifying patients in the next 24 hours via email, they are establishing an advisory board and their mobile app will instead redirect to their web app temporarily.
They said they "refer to my blog post" but it isn't explicitly clear to me if they are implying that "information obtained from it" means they would like me to remove or redact it?
They said they "refer to my blog post" but it isn't explicitly clear to me if they are implying that "information obtained from it" means they would like me to remove or redact it?
At a previous company I worked at, our customers (businesses) would keep putting their customers (citizens) credit card numbers in an unencrypted notes field.
That product team tried blocking CC formats, putting a banner, all sorts
At a previous company I worked at, our customers (businesses) would keep putting their customers (citizens) credit card numbers in an unencrypted notes field.
That product team tried blocking CC formats, putting a banner, all sorts
I have been touching grass for a couple hours so I'm just catching up now
I have been touching grass for a couple hours so I'm just catching up now
cdn.utf9k.net/documents/00...
I haven't been following the story myself so I'm not sure if the stats are new: 213 million lines of data totalling 150GB (according to the seller's listing)
No real technical insight at all
cdn.utf9k.net/documents/00...
I haven't been following the story myself so I'm not sure if the stats are new: 213 million lines of data totalling 150GB (according to the seller's listing)
No real technical insight at all
This article removed that contradiction in my mind and explains how both can be true
I'll surface this one part as it's important but only a claim.
> Kazu also claimed they would delete records belonging to minors and elderly patients regardless of whether a ransom was paid.
www.nzherald.co.nz/nz/hacker-cl...
This article removed that contradiction in my mind and explains how both can be true
I'll share a copy (if the publishers notes allow) once I get it.
I guess DocumentCloud is what you're meant to use but I don't use MuckRock 😄
I'll share a copy (if the publishers notes allow) once I get it.
I guess DocumentCloud is what you're meant to use but I don't use MuckRock 😄
They also scrubbed the contents of the original forum post advertising the MMH data for sale, about 30 minutes ago.
Perhaps they are getting annoyed at all the incoming media questions
They also scrubbed the contents of the original forum post advertising the MMH data for sale, about 30 minutes ago.
Perhaps they are getting annoyed at all the incoming media questions
If we're talking biz this is terrible ROI for a lot of work, though I guess it's not like they burned any valuable oday for it, so... ¯\_(ツ)_/¯
If we're talking biz this is terrible ROI for a lot of work, though I guess it's not like they burned any valuable oday for it, so... ¯\_(ツ)_/¯
That said, it seems like all of the major news outlets are in direct contact with Kazu (a few I gave directions on how) so hopefully I have now put myself out of a job
Thanks for everyone who took an interest in my updates!
That said, it seems like all of the major news outlets are in direct contact with Kazu (a few I gave directions on how) so hopefully I have now put myself out of a job
I'll surface this one part as it's important but only a claim.
> Kazu also claimed they would delete records belonging to minors and elderly patients regardless of whether a ransom was paid.
www.nzherald.co.nz/nz/hacker-cl...
I'll surface this one part as it's important but only a claim.
> Kazu also claimed they would delete records belonging to minors and elderly patients regardless of whether a ransom was paid.
www.nzherald.co.nz/nz/hacker-cl...
They tend to stop responding around 4pm (10pm CST) and I've seen them online as early as midnight (6am CST)
Earlier today, they quote an excerpt from Simeon Brown about forensics working to narrow down the country in their Telegram with a caption that they're in Cuba.
No way to verify that but they did also express their reaction to the investigation with a popcorn eating sticker
They tend to stop responding around 4pm (10pm CST) and I've seen them online as early as midnight (6am CST)
I had also asked, in the event that I learn anything useful, where can I send it because their reporting forms are not geared towards generic tips
I had also asked, in the event that I learn anything useful, where can I send it because their reporting forms are not geared towards generic tips
and diagnoses; personal information, such as patient contact details, dates of birth and addresses; and (cont...)
not limited to Northland patients.
not limited to Northland patients.
Change the URL to 2+PS.pdf for the publishers notes if you're interested
cdn.utf9k.net/documents/Ma...
Change the URL to 2+PS.pdf for the publishers notes if you're interested
cdn.utf9k.net/documents/Ma...
The giveaway is that pixellation done via @cleanshot.bsky.social and watching it float around is quite fun
Obviously, if it was art or an original creation, I'd be disappointed
I was quite surprised how far they zoomed in so good thing I used a retina display
The giveaway is that pixellation done via @cleanshot.bsky.social and watching it float around is quite fun
Obviously, if it was art or an original creation, I'd be disappointed
I was quite surprised how far they zoomed in so good thing I used a retina display