Week in Breach 6/7-6/13/2023 | CloudSmart IT

Week in Breach 6/7-6/13/2023

 A major healthcare provider’s network is sick from hacking and several big government agencies from around the world suffer big attacks that tanks, planes, and guns cannot do anything about. Staying cyber-secure is really hard, see some ways you can be protected:

Click here to see some of the ways CloudSmart IT can help you with your Cyberseurity needs!


Ascension Seton 

Ascension Seton 

https://www.kut.org/health/2023-06-07/ascension-seton-austin-hospital-data-breach

Exploit: Hacking

Ascension Seton: Healthcare System 

cybersecurity news represented by agauge showing severe risk

Risk to Business: 1.886 = Severe

Austin’s Ascension Seton hospital system has announced that two of its websites have experienced a data breach. In a statement last Tuesday, the healthcare provider said that two of its legacy websites Seton.net and DellChildrens.net were breached on March 1 and 2, 2023. Both sites were operated by the technology service provider Vertex. Some users’ personal details, such as name, address, Social Security number, credit card numbers and insurance information may be at risk if they were entered through Seton.net or DellChildrens.net. Ascension Seton has replaced the hacked sites with new sites that it is hosting in-house.  

How It Could Affect Your Customers’ Business: The combination of the incident on two websites plus any data loss fines will be very expensive.


Canada – The Government of Nova Scotia

https://www.cbc.ca/news/canada/nova-scotia/ns-government-cyberattack-data-personal-information-criminal-1.6871682

Exploit: Hacking

The Government of Nova Scotia: Regional Government 

cybersecurity news represented by agauge showing severe risk

Risk to Business: 1.876 = Severe

The government of Nova Scotia announced last week that an estimated 100 million records containing people’s personally identifiable information were stolen in a cyberattack identified last week. A wide variety of people have been impacted including 55,000 records of past and present teachers in the province, records of 26,000 students over the age of 16 and records of 5,000 short-term housing accommodations owners, 3,800 people who applied for jobs with Nova Scotia Health, about 1,400 Nova Scotia pension recipients and 1,085 people who have been issued parking tickets in Halifax have been identified as potential victims so far. Current and past employees of Nova Scotia Health, the IWK Health Centre and the provincial civil service may also be impacted. The attack came as the result of ransomware gang Cl0p’s exploitation of the MOVEit file transfer protocol. The incident remains under investigation, with a strong possibility of more victims being uncovered.  

How It Could Affect Your Customers’ Business Many exploits can be avoided by regularly patching and updating software and systems.

amy

Jamaica – The Ministry of National Security (MNS)

https://www.jamaicaobserver.com/latest-news/jamaicaeye-hit-by-cyber-attack-security-ministry/

Exploit: Hacking

The Ministry of National Security (MNS): Government Agency

cybersecurity news represented by a gauge indicating moderate risk

Risk to Business: 2.769 = Moderate

The Ministry of National Security (MNS) disclosed that a cyberattack has affected access to the JamaicaEye website. The popular website came about as a result of the island’s National Closed-Circuit Television Surveillance Programme. Launched in 2018, citizens and business owners with cameras pointing in the public space have been able to voluntarily input their feeds into the national system. MNS has not commented on whether or not any data was stolen about camera owners who participate in the program. A team from the ministry, the Jamaica Constabulary Force and the Major Organised Crime & Anti-Corruption Agency are investigating the incident. 

How It Could Affect Your Customers’ Business: There has been an increase in hacking of security and surveillance cameras.


South America – Argentina’s National Securities Commission (CNV) 

https://www.benzinga.com/government/23/06/32809480/medusa-ransomware-targets-argentinas-securities-commission

Exploit: Ransomware

Argentina’s National Securities Commission (CNV): Government Agency

cybersecurity news represented by agauge showing severe risk

Risk to Business: 2.149 = Severe

A ransomware group named Medusa is behind the cyberattack on Argentina’s National Securities Commission (CNV). The gang has demanded $500,000 within a week, threatening to leak the purported 1.5 terabytes of the commission’s confidential records, files, documents and databases that it stole in the incident. The incident is under investigation.

How It Could Affect Your Customers’ Business: Records like these are highly desirable on the dark web because the data can be used to facilitate many cybercrimes.


Russia – Infotel JSC

https://www.bleepingcomputer.com/news/security/ukrainian-hackers-take-down-service-provider-for-russian-banks/

Exploit: Hacking (Nation-State)

Infotel JSC: Telecommunications Company 

cybersecurity news gauge indicating extreme risk

Risk to Business: 1.337 = Extreme

A Ukrainian hacking team known as the Cyber.Anarchy.Squad has claimed responsibility for a cyberattack that took down Russian telecom provider Infotel JSC last Thursday evening. That attack sent shockwaves through the Russian banking world. Infotel JSC is a Moscow-based provider of connectivity services between the Russian Central Bank and other Russian banks, stores and credit institutions. Reports say that multiple Russian banks were hamstrung after the attack. The telecom had admitted that the attack took place and noted that some of its network equipment was damaged in the incident. As proof of their success, the Ukrainian hackers released screenshots of a diagram of Infotel’s network and a compromised email account. 

How it Could Affect Your Customers’ Business: The conflict between Russia and Ukraine has featured a flurry of hacking.

Germany – Pflegia

https://securityaffairs.com/147227/security/pflegia-leaks-sensitive-job-seeker-info.html

Exploit: Misconfiguration

Pflegia: Healthcare Recruiter

cybersecurity news represented by agauge showing severe risk

Risk to Business: 1.826 = Severe

Researchers have identified a leaking Amazon Web Services (AWS) bucket as belonging to German Healthcare recruiting company Pflegia. The leaky cloud instance contained over 360,000 files about German job seekers. Data exposed may include a job seeker’s full name, date of birth, occupation history, home address, phone number and email address. The bucket has since been reconfigured to stop the data leak.

How it Could Affect Your Customers’ Business: Employee data handling and security mistakes can be just as costly and difficult to clean up as a cyberattack.

UK – Ofcom

https://therecord.media/ofcom-cyberattack-uk-regulator-moveit-vulnerability

Exploit: Hacking

Ofcom: Communications Regulator

cybersecurity news represented by agauge showing severe risk

Risk to Business: 1.607 = Severe

Ofcom, Britain’s communications regulator, admitted on Monday that confidential information about the companies it regulates was stolen in a cyberattack. The attack involved exploiting the MOVEit file transfer protocol by the busy cybercrime gang Cl0p. The gang claims to have hit hundreds of organizations using the exploit. Ofcom said that information about companies it regulates as well as the personal data of 412 Ofcom employees, was downloaded during the attack. The incident is under investigation.  

How it Could Affect Your Customers’ Business: Intrusions like this are good sources of multiple types of valuable data for bad actors.


Australia – FIIG Securities

https://www.abc.net.au/news/2023-06-12/russian-hackers-claim-to-steal-data-from-australian-bond-broker/102469572

Exploit: Ransomware

FIIG Securities: Bond Brokerage

cybersecurity news represented by agauge showing severe risk

Risk to Business: 1.783 = Severe

A cyberattack on Australian bond broker FIIG Securities late last week was the work of the notorious cybercrime gang BlackCat. The group said that they snatched 385 gigabytes of data. FIIG Securities began contacting clients to inform them that their personal data including their names, addresses, birth dates, driver’s license information, passport scans, bank accounts and tax file numbers might have been compromised in the attack. No ransom information was available at press time. The incident has been reported to the Office of the Australian Information Commissioner. 

How it Could Affect Your Customers’ Business: Te combination of financial data as well as PII makes this a profitable data score for BlackCat and an expensive nightmare for FIIG Securities.

 

1 – 1.5 = Extreme Risk

1.51 – 2.49 = Severe Risk

2.5 – 3 = Moderate Risk

Risk scores for The Week in Breach are calculated using a formula that considers a wide range of factors related to the assessed breach.

View All News & Articles

Ready to customize an IT solution that fits YOUR business goals? Get free guidance from our CEO.

Ready to customize an IT solution that fits YOUR business goals?

Get free guidance from CloudSmart IT.

Book a call or call us at 615.610.3500 today for your no-cost, no-obligation consultation.