Week in Breach 7/5-7/11/2023 | CloudSmart IT

Week in Breach 7/5-7/11/2023

This week: A cyberattack shuts down Japan’s largest port, some big healthcare hits, and major malware attacks are making things a headache across industries and putting businesses and customers alike at risk. 

Let us help you stay cyber-secure in a time of uncertainty. Check out our offerings for a safer business here: CloudSmart IT Cyber Security


The Law Foundation of Silicon Valley

https://therecord.media/thousands-affected-by-ransomware-on-law-firm

Exploit: Ransomware

The Law Foundation of Silicon Valley: Non-Profit

cybersecurity news represented by agauge showing severe risk

Risk to Business: 1.886 = Severe

A ransomware attack on a California law firm that provides free services to those in need has resulted in data exposure for an estimated 42,000 people. The Law Foundation of Silicon Valley notified regulators in California and Maine this week that the February ransomware attack on their offices resulted in a data breach. That impacted both clients and staff members. Exposed information includes Social Security numbers, medical records, immigration numbers, financial data, driver’s license numbers, financial account/payment card information, passport/government identification, taxpayer numbers, dates of birth and digital signatures. The AlphV/Black Cat ransomware group has claimed the attack. 

How It Could Affect Your Customers’ Business: This data breach is going to cost a fortune after state regulators get finished with this California-based organization.

 

National Institutes of Health Federal Credit Union (NIHFCU)

https://www.jdsupra.com/legalnews/nih-federal-credit-union-notifies-14-1232621/

Exploit: Credential Compromise

National Institutes of Health (NIH) Federal Credit Union: Financial Institution

cybersecurity news represented by agauge showing severe risk

Risk to Business: 1.876 = Severe

The National Institutes of Health Federal Credit Union (NIHFCU) filed a notice of data breach with the Attorney General of Maine on July 5. NIHFCU said that it had discovered that bad actors had gained access to an employee email account, which resulted in those bad actors gaining access to consumers’ sensitive information, including their names and Social Security numbers.

How It Could Affect Your Customers’ Business The financial sector has consistently been among the top sectors that cybercriminals have been attacking in the last few years.

 

Advanced Medical Management

https://www.hipaajournal.com/advanced-medical-management-reports-data-breach-affecting-319485-individuals/

Exploit: Supply Chain Attack

Advanced Medical Management: Healthcare Management Services

cybersecurity news represented by agauge showing severe risk

Risk to Business: 1.669 = Severe

Advanced Medical Management has disclosed a data breach that impacted 319,485 people. The company discovered that portions of the company’s IT network that were designed and maintained by third-party vendors were accessible to an unauthorized party. Advanced Medical Management explained in a data breach notice that the incident resulted in an unauthorized party being able to access consumers’ sensitive information between May 10, 2023, and May 13, 2023. The data exposed includes names, Social Security numbers, addresses, email addresses, phone numbers, dates of birth, driver’s license numbers, protected health information, and health insurance information.

How It Could Affect Your Customers’ Business: Security awareness training isn’t just for cyberattacks, it also helps employees become more conscientious about security overall to limit mistakes.

 

Pepsi Bottling Ventures

https://www.securityweek.com/28000-impacted-by-data-breach-at-pepsi-bottling-ventures/

Exploit: Hacking

Pepsi Bottling Ventures: Soft Drink Distributor

cybersecurity news represented by agauge showing severe risk

Risk to Business: 2.149 = Severe

Pepsi Bottling Ventures has admitted that it suffered a data breach between December 23, 2022, and January 19, 2023, that resulted in the personal, financial, and health information of the company’s employees being accessed by an unauthorized party. The breach was discovered on January 10.  The compromised data belongs to current and former employees and to contractors. That data is comprised of names, addresses, email addresses, financial account information, ID numbers, driver’s license numbers, Social Security numbers, digital signatures, medical history details and health insurance information.  

How It Could Affect Your Customers’ Business: Employee data is a treasure trove for bad actors as it can contain PHI, PII, financial details and other information that sells fast.

 


Sun Life

https://www.ctvnews.ca/business/global-cyberattack-affected-some-sun-life-members-information-company-says-1.6472126

Exploit: Supply Chain Risk

Sun Life: Insurer

cybersecurity news represented by agauge showing severe risk

Risk to Business: 2.637 = Severe

Sun Life, one of Canada’s leading insurance providers, says the personal data of some of its U.S. customers has been compromised after one of its vendors was caught up in the MOVEit exploit attack spree. Sun Life made it clear that while it doesn’t use MOVEit, one of its vendors, Pension Benefit Information (PBI) did use it and some members’ personal information was accessed by an unauthorized third party using the exploit. Bad actors may have gained access to information including a client’s name, Social Security ‎Number, policy and account number, and/or date of birth. However, no financial information like account values or medical claims was exposed.

How it Could Affect Your Customers’ Business: Supply chain relationships have become increasingly fraught for businesses and that trend will continue.

 


Scotland – The University of the West of Scotland (UWS)

https://news.stv.tv/west-central/university-of-west-of-scotland-working-with-police-and-government-after-cyber-attack

Exploit: Hacking

The University of the West of Scotland (UWS): Institution of Higher Learning

cybersecurity news represented by a gauge indicating moderate risk

Risk to Business: 2.766 = Moderate

The University of the West of Scotland is experiencing an ongoing cyber incident that is affecting a number of its digital systems. The university’s website is currently down and other digital systems at the university have reportedly been down for days. The university is working with experts from Police Scotland, the National Cyber Security Centre and the Scottish government in the investigation. University officials were quick to reassure the public that graduations are continuing as planned this week with no interruption.

How it Could Affect Your Customers’ Business: Targets from every part of the education sector have been popular because of the often time-sensitive nature of their business.

 


Australia – Ventia

https://www.securityweek.com/critical-infrastructure-services-firm-ventia-takes-systems-offline-due-to-cyberattack/

Exploit: Hacking

Ventia: Critical Infrastructure Management

cybersecurity news gauge indicating extreme risk

Risk to Business: 1.707 = Severe

Ventia, a Sydney-based company that provides long-term management, maintenance and operations services for critical infrastructure organizations has announced that it is taking some systems offline due to a weekend cyberattack. While the company has not confirmed the nature of the attack, experts are pointing to ransomware. The company says that it has engaged with external experts and law enforcement to investigate the incident, and all operations are expected to return to normal within the following days. 

How it Could Affect Your Customers’ Business: Infrastructure attacks and attacks on companies that support it have been continuing to increase worldwide.



Japan – The Port of Nagoya

https://www.darkreading.com/attacks-breaches/ransomware-halts-operations-at-japan-port-of-nagoya

Exploit: Ransomware

The Port of Nagoya: Seaport 

cybersecurity news gauge indicating extreme risk

Risk to Business: 1.443 = Extreme

The largest seaport in Japan and the central shipping hub for Toyota, the Port of Nagoya, experienced a ransomware attack last Tuesday that led to a total shutdown. The port’s operator, Nagoya Harbor Transportation, disclosed that it received a ransom demand from LockBit 3.0 immediately following the beginning of systems failure in the early morning. All cargo operations, including the loading and unloading of containers onto trailers, were suspended as of July 4 but port officials expected to resume operations within a few days.  

How it Could Affect Your Customers’ Business: This is a good example of the destructive power of cyberattacks against infrastructure. For something like a port, even a few hours of downtime is a disaster.



1 – 1.5 = Extreme Risk

1.51 – 2.49 = Severe Risk

2.5 – 3 = Moderate Risk

Risk scores for The Week in Breach are calculated using a formula that considers a wide range of factors related to the assessed breach.

View All News & Articles

Ready to customize an IT solution that fits YOUR business goals? Get free guidance from our CEO.

Ready to customize an IT solution that fits YOUR business goals?

Get free guidance from CloudSmart IT.

Book a call or call us at 615.610.3500 today for your no-cost, no-obligation consultation.