{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Daily Security Review","title":"750,000 Records Exposed: Inside the TADTS Data Breach by BianLian","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/7f448784\"></iframe>","width":"100%","height":180,"duration":3809,"description":"In July 2024, The Alcohol & Drug Testing Service (TADTS), a Texas-based company handling sensitive employment-related data, suffered a catastrophic data breach. Nearly 750,000 individuals had personal information compromised—Social Security numbers, financial data, driver’s licenses, health insurance info, and even biometric identifiers. The attack was claimed by the BianLian ransomware group, which has shifted its strategy away from encryption to pure data theft and extortion.\nDespite the scope of the breach, TADTS waited nearly a year to notify victims and has not offered free identity theft protection, even though the stolen data includes everything needed to commit large-scale identity fraud. In this episode, we unpack the incident, explore BianLian's evolving tactics, and highlight the regulatory and legal implications for companies that fail to secure consumer data.\nYou’ll learn:\nHow BianLian transitioned from ransomware encryption to data-only extortion\nWhy the IMSI data and biometric exposure raise the stakes for victims\nThe technical tactics used by BianLian—custom backdoors, PowerShell abuse, RDP exploitation, credential dumping, and data syncing via tools like Rclone and Mega\nThe alarming delay in breach disclosure—nearly 365 days late\nWhat Texas law and federal regulations require in such breaches—and whether TADTS violated them\nThe class action lawsuit risks now emerging\nWhat individuals can do to defend themselves: credit freezes, fraud alerts, password changes, and monitoring\nWe also look at the broader cybersecurity implications: why sectors handling biometric and medical data must implement MITRE ATT&CK-aligned defenses, enforce multi-factor authentication, and maintain robust backup strategies to prevent and recover from modern extortion campaigns.","thumbnail_url":"https://img.transistorcdn.com/pL79_MJFeJHamQ_ztImsGmDSMdl27VMk_30TAkieujE/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNzg5/ZjlhNzM5Y2M4Njli/NjkxNzgyODA2Nzhi/MDI2ZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}