Guidelines

I have established this blog as a means of transparency to the public, outreach to the community, and information dissemination to all who choose to look. Feedback is welcome, but because public participation is equally encouraged, appropriate language and decorum is mandatory.
Showing posts with label Cyber-crime. Show all posts
Showing posts with label Cyber-crime. Show all posts

Sunday, September 3, 2023

So What Does Fla. Stat. § 817.5685 Say, and What Does it Mean?

In the iconic opening credits sequence
of 1977's Saturday Night Fever, John
Travolta "struts" down the New York
street, carrying a can of paint.

I'm not a lawyer but I know several of them and I can read.  

So when I read the letter sent to law enforcement by the County Attorney in the aftermath of the recent data breach/theft of county records from the IT department-----I paid close attention to it.  The letter was sent to the State Attorney's Office in June, and a certain statute referenced in there piqued my interest. § 817.5685.  

This theft of information from the county which prompted the letter-- which breach subsequently led to confidential, private, privileged information being unlawfully possessed and disseminated by former county employee Jonathan Owens, a fact that he himself has admitted on the radio and in the news paper and a fact the attorneys for Rayme Edler have also confirmed --this theft is now being investigated by law enforcement.

And I am confident the authorities will find the guilty party who stole this protected, exempt information--whoever it was.

But even if someone other than Jonathan Owens actually stole the information and records (which I do not believe), and simply provided them to Jonathan while he was an employee of the county, as he, Jonathan, has publicly stated--it does not absolve Jonathan of any wrongdoing under this statute--because  according to this statute--the operative word is "possessed". Jonathan admitted to the PNJ in this article and on the radio on Tallman McKay's show that he not only read the text file and continues to possess it--- he's also  subsequently given it to others un-redacted. 

Because  he read it--Jonathan knew or should have known it contained exempt and personal identification information that should not only never be released--it should never even be possessed by anyone not specifically authorized to have it.  Jonathan is not authorized to have it--and he knows it.  

A thorough review of this file that Jonathan Owens unlawfully possessed, read, and then released un-redacted has now been completed--- and it has been revealed that this file contains more than 100 lines of exempt information.  (social security numbers of multiple persons, bank account numbers of multiple persons, loan numbers of multiple persons,  medical conditions, diagnoses and prognoses records of at least a dozen local citizens, security codes, access codes for premises, medical records and diagnoses on dependents on the county's medical plan as well as confidential medical information on citizens unaffiliated with the county that live out of state, privileged attorney client conversations,  and other sensitive information that would NEVER be released under any public records request, ever.).  

So why would someone who has handled a literal ton of public records requests (Owens, who was disgraced former D2 commissioner Doug Underhill's personal secretary and office manager) and who purportedly knows the rules and laws on this topic--supposedly------why would he release such information unredacted in contravention to Florida law?  Who knows, but he seems awfully proud about it.  Super proud and confident.  Almost as if he's strutting about it, like John Travolta in the opening scenes of "Saturday Night Fever." 

So What Does Fla. Stat. § 817.5685 Say, and What Does it Mean, and what penalties does it describe for violation, anyway?

Here is the relevant portion of the statute, verbatim

"817.5685 Unlawful possession of the personal identification information of another person.—

(1) As used in this section, the term “personal identification information” means a person’s social security number, official state-issued or United States-issued driver license or identification number, alien registration number, government passport number, employer or taxpayer identification number, Medicaid or food assistance account number, bank account number, credit or debit card number, and medical records.
(2) It is unlawful for a person to intentionally or knowingly possess, without authorization, the personal identification information of another person in any form, including, but not limited to, mail, physical documents, identification cards, or information stored in digital form.

(3)(a) A person who violates subsection (2) and in doing so possesses the personal identification information of four or fewer persons commits a misdemeanor of the first degree, punishable as provided in s. 775.082 or s. 775.083.
(b)1. Proof that a person used or was in possession of the personal identification information of five or more individuals, unless satisfactorily explained, gives rise to an inference that the person who used or was in possession of the personal identification information did so knowingly and intentionally without authorization.
2. A person who violates subsection (2) and in doing so possesses the personal identification information of five or more persons commits a felony of the third degree, punishable as provided in s. 775.082, s. 775.083, or s. 775.084."

 

Thursday, December 12, 2019

A Million Dollar Ransom for the City's Data????

One News Outlet is claiming there is a $1 Million Dollar Ransom Demand to release the City of Pensacola's data!


From Bleeping Computer:


"The operators behind the Maze Ransomware have claimed responsibility for the cyberattack affecting the City of Pensacola, Florida, but state that they are not affiliated with the recent shooting at NAS Pensacola.
In an email conversation with BleepingComputer, the operators of the Maze Ransomware stated that they were responsible for encrypting the city's data and have demanded a $1,000,000 ransom for a decryptor."
If this turns out to be a legit story and factual, this will be in incredibly steep price to protect the City's data.  Very bad turn of events.....

Monday, December 9, 2019

County's Proactive Response to recent City of Pensacola Ransomware Attack



from staff....

“With permission from the City of Pensacola’s IT Department,   I wanted to make you aware that FDLE is assisting the City of Pensacola with a cyber-attack that occurred over the weekend. 

  Once we found out that the breach had happened, BCC-IT shut their connection to the BOC network by disabling their two connections into our network. We also performed the following over the weekend:
1.       Notified our Security Operation Center(SOC) of the event and requested they put our network on high alert. This increased our alert activity through the day and our Cyber team has been responding to the events.
2.       Notified CISA and gave the City of Pensacola their contact information.
3.       Notified DHS and talked with them over the weekend.
4.       Monitored Firewall and Antivirus logs

Today we met as a Leadership team and have performed the following:
1.       Elevated our Antivirus policy to be more aggressive
2.       Continued to monitor our Firewall and Antivirus logs
3.       Continued to receive events from (SOC).
4.       Shared information with City of Pensacola and the Sherriff’s office.

To provide greater protection to the County network we plan to implement the following changes:
1.       Provide alerts on all emails coming from an external source.                
2.       Turn off the ability for employees to access their Personal Email and Social Media Accounts.
3.       Upon login, users will have to click an OK to a Legal notice which will basically state they should have no expectation of privacy while using a county device.
4.       Once logged in, a machine will automatically lock after 15 minutes of inactivity.  We will have an exception group, but it will be limited to business-critical operations.
5.       Limit the use of USB devices 
6.       Limit Administrative rights
7.       Not allow users to write to their local C: Drive
8.       Require users home PC be up to date with Endpoint protection and the latest Windows Security patches before remoting into a county device
9.       Implement a county Phishing Email campaign and Security Awareness training"