Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - US Government Payment Service Leaks
News & Analysis

US Government Payment Service Leaks

ISBuzz TeamBy ISBuzz TeamSeptember 19, 2018Updated:December 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Insecure
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

It’s been reported this morning that a payment website – Government Payment Service Inc.-  used to process US government payments for traffic citations, court-ordered fines, bail payments and more has leaked more than 14 million customer records. The leak included names, addresses. phone numbers and sections of the credit card number used. IT security experts commented below.

Andy Norton, Director of Threat Intelligence at Lastline:

“Another day another breach. An abundance of caution has become the default cyber notification, philosophy or cyber risk culture advocated by legal counsel following a data breach. Unfortunately we need organisations to be abundantly cautious before, not after a data breach occurs. We need organisations to Adopt AI and behavioural intelligence to reduce the risk from malicious encounters. Every organisation has a responsibility to protect our sciences, culture and freedoms. We have unpredictable opponents with obscured intentions whose constant changes suppress our awareness to the actual dangers we face. Notifications out of an abundance of caution, are really just admissions of, “too little too late”. This is because we have not created a culture that addresses the asynchronous nature of cyber conflict, of unprepared defenders constantly underestimating and failing to resist the intentions of a more sophisticated attacker.”

James Hadley, CEO & Founder at Immersive Labs:

“While the article highlighted that the fix for these types of breaches is simple and incidents are preventable, these organisations should already know better and hold the security of their data to higher standards. With the ever-increasing cyber skills shortage, getting the right people to ensure these errors aren’t overlooked has proven to be increasingly difficult. One solution would be to provide better all-round cyber training on a continuous cycle to ensure cyber teams are kept up with the latest best practice. This could ensure that even non-cyber security professionals learn to be more security conscious and provide a bigger barrier when it comes to cyber criminals carrying out these easily preventable attacks.”

Lillian Tsang, Senior Data Protection and Consultant at Falanx Group:

“If we put it into context against the GDPR, the breach has resulted in a high risk to the rights and freedom of individuals. There is the potential for identity theft, fraud and even of cloning, depending on the full scale of the type of information leaked. The mastery held by hackers and the “trades” in personal information in the murky underworld is limitless.

Although the data has been leaked – this in itself is somewhere in the murky lands of it being potentially exchanged, manipulated and cloned. This part cannot be controlled. However, what can be controlled is the frequency of periodic reviews of systems and controls. GovPayNet acknowledges, “it did not adequately restrict access to authorised recipients”. This could have been picked up during a Data Protection By Design and Default approach or the use of DPIAs, particular for projects such as an online portal in this instance where the velocity and volume of personal data is incredibly high. Even where Data Protection by Design and Default has not been mandated in a country – its equivalent or standard risk assessments used in industry or specific sectors would be a good start for product and service development that processes personal data.

Whether there has been a leak of login details – naturally customers should be advised to change logins and passwords with advice on the strength of passwords.  “Cat” as a password may not cut it. “Cat2Twinkles6Liberty$” may.  Reciprocal approach – entities serves customers. Customers get informed as well.  Banks and relevant institutions ought to be notified. Several communications should be used, as opposed to a single contact channel and not part of a by-line with marketing material and general newsletters. Direct emails and SMS are good examples. Banners on corporate website and advertisement in print media may also be an avenue to explore.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}