{"id":23344,"date":"2023-11-09T06:10:24","date_gmt":"2023-11-09T14:10:24","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2023\/11\/09\/news-17074\/"},"modified":"2023-11-09T06:10:24","modified_gmt":"2023-11-09T14:10:24","slug":"news-17074","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2023\/11\/09\/news-17074\/","title":{"rendered":"Nude \u201cbefore and after\u201d photos stolen from plastic surgeon, posted online, and sent to victims&#8217; family and friends"},"content":{"rendered":"\n<p>The FBI is investigating a data breach where cybercriminals were able to steal patients\u2019 records from a Las Vegas plastic surgeon&#8217;s office, and then post the details online which included nude photos.<\/p>\n<p>In February, cybercriminals gained access to Hankins &amp; Sohn&#8217;s network, which has offices in both Henderson and Las Vegas. From there, the cybercriminals were able to download patient information.<\/p>\n<p>The practice sent a letter to patients in March and April notifying them of the breach.<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>\u201cOn or about February 23, 2023, Hankins &amp; Sohn became aware of suspicious activity relating allegations by an unknown actor that data was stolen from our network. We quickly took steps to investigate the validity of the claims and to assess the nature and scope of the activity and what information may have been affected. We are also working with law enforcement to investigate the activity. We learned that files were taken by the unknown actor prior to this date.\u201d<\/p>\n<\/blockquote>\n<p>Apparently, the cybercriminals didn&#8217;t get what they wanted from Hankins &amp; Sohn and started posting the information online. Several patients and court documents say that the stolen data included sensitive personal information, such as names and Social Security numbers, but also nude photos of patients taken before and after surgery.<\/p>\n<p>They cybercriminals didn&#8217;t stop at that. They sent the data, along with the nude photos, to family and friends through patients\u2019 email accounts.<\/p>\n<p><a href=\"https:\/\/www.8newsnow.com\/investigators\/hackers-target-las-vegas-plastic-surgeons-post-patient-information-naked-photos-online\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to 8NewsNow<\/a>, about a dozen women have since filed a lawsuit against the firm, claiming they did not do enough to protect their private and personal information. None of the documents posted online were encrypted. It was unclear Monday if Hankins &amp; Sohn was storing its data per HIPAA rules. A spokesperson for the office that oversees HIPAA-related investigations declined to comment.<\/p>\n<p>HIPAA is short for Health Insurance Portability and Accountability Act. HIPAA is a federal law that required the creation of national standards to protect sensitive patient health information from being disclosed without the patient&#8217;s consent or knowledge.<\/p>\n<p>The victims claim that the Hankins and Sohn failed to implement adequate and reasonable cybersecurity procedures and protocols to protect their <a href=\"https:\/\/www.malwarebytes.com\/glossary\/pii\">Personally Identifiable Information (PII)<\/a> and Protected health information (PHI).<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-data-breach\">Data breach<\/h3>\n<p>There are some actions you can take if you are, or suspect you may have been, the victim of a data breach.<\/p>\n<ul>\n<li>Check the vendor\u2019s advice. Every breach is different, so check with the vendor to find out what\u2019s happened, and follow any specific advice they offer.<\/li>\n<li>Change your password. You can make a stolen password useless to thieves by changing it. Choose a&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/computer\/how-to-create-a-strong-password\" target=\"_blank\" rel=\"noreferrer noopener\">strong password<\/a>&nbsp;that you don\u2019t use for anything else. Better yet, let a&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/what-is-password-manager\" target=\"_blank\" rel=\"noreferrer noopener\">password manager<\/a>&nbsp;choose one for you.<\/li>\n<li>Enable two-factor authentication. Where possible, use a FIDO2 2FA device. Some forms of&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/glossary\/multi-factor-authentication-mfa\" target=\"_blank\" rel=\"noreferrer noopener\">two-factor authentication (2FA)<\/a>&nbsp;can be phished just as easily as a password. 2FA that relies on a FIDO2 device can\u2019t be phished.<\/li>\n<li>Watch out for fake vendors. The thieves may contact you posing as the vendor. Check the vendor website to see if they are contacting victims, and verify any contacts using a different communication channel.<\/li>\n<li>Take your time. Phishing attacks often impersonate people or brands you know, and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.<\/li>\n<\/ul>\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\" \/>\n<p><strong>We don&#8217;t just report on threats &#8211; we help safeguard your entire digital identity<\/strong><\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Protect your and your family&#8217;s personal information by using&nbsp;<a target=\"_blank\" href=\"https:\/\/www.malwarebytes.com\/identity-theft-protection\" rel=\"noreferrer noopener\">Malwarebytes Identity Theft Protection<\/a>.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2023\/11\/nude-before-and-after-photos-stolen-from-plastic-surgeon-posted-online-and-sent-to-victims-family-and-friends\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> The FBI is investigating a data breach where cybercriminals were able to steal patients\u2019 records from a Las Vegas plastic surgeon&#8217;s office and then publish them online. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[11172,6627,32,26699,30481],"class_list":["post-23344","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-data-breach","tag-fbi","tag-news","tag-personal","tag-plastic-surgery"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23344","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=23344"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23344\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=23344"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=23344"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=23344"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}