"Your Information Technology Leader"

Client Portal Payment Portal

Blog

InTegriLogic Blog

InTegriLogic has been serving the Tucson area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

The Week in Breach News: 01/17/24 – 01/23/24

Breach-2

This week: Nobelium uses an old trick to sneak into Microsoft and a Canadian energy company loses $1.5 million to an account takeover attack.

 

Microsoft

https://www.bleepingcomputer.com/news/security/russian-hackers-stole-microsoft-corporate-emails-in-month-long-breach/#google_vignette

Exploit: Password Spraying

Microsoft: Software Company

cybersecurity news represented by a gauge indicating moderate risk

 

Risk to Business: 2.302 = Moderate

Microsoft has disclosed that several of its corporate email accounts were breached by a Russian state-sponsored hacking group Midnight Blizzard. The company detected the attack on January 12, 2024. Microsoft’s internal investigation concluded that the attack was conducted by a group of Russian threat actors associated with Nobelium/APT29 (sometimes known as Midnight Blizzard or Cozy Bear). The software titan said that the threat actors breached their systems in November 2023 by conducting a password spray attack to access a legacy non-production test tenant account. Microsoft says the hackers accessed a “small percentage” of Microsoft’s corporate email accounts for over a month including accounts tied to the company’s leadership team and employees in the cybersecurity and legal departments. The company speculates that the threat actors were looking for information about their own gang.

How It Could Affect Your Business: Even the biggest companies can be brought low by a simple cybersecurity problem.


 

Kansas State University

https://www.bleepingcomputer.com/news/security/kansas-state-university-cyberattack-disrupts-it-network-and-services/

Exploit: Hacking

Kansas State University: Institution of Higher Learning

cybersecurity news represented by agauge showing severe risk

 

Risk to Business: 1.691 = Severe

Kansas State University (K-State) has announced that it is dealing with a cybersecurity incident that has disrupted some of its network systems. The impacted systems include its VPN, K-State Today emails and video services on Canvas and Mediasite. Printing, shared drives and mailing list management services (Listservs) were also knocked out. Services are slowly being restored, sometimes in a limited capacity. The college says that it has engaged a third-party cybersecurity firm to aid in its investigation.

How It Could Affect Your Business: Schools at every level have been prime targets for ransomware attacks and that looks set to continue.


 

Cooper Aerobics 

https://thecyberexpress.com/cooper-aerobics-data-breach-exposes-info/

Exploit: Hacking

Cooper Aerobics: Healthcare Company

cybersecurity news represented by agauge showing severe risk

 

Risk to Business: 1.643 = Severe

Cooper Aerobics, comprised of Cooper Clinic, P.A., Cooper Medical Imaging, LLP and Cooper Aerobics Enterprises, Inc., has disclosed that it has experienced a data security incident. The company began notifying clients on January 5, 2024, that an unauthorized party gained access to its data. The compromised data includes names, addresses, phone numbers, email addresses, financial details (credit/debit card numbers, expiration dates, account/routing numbers), tax identification numbers, driver’s license or government identification details, passport numbers, usernames and passwords, Social Security numbers and other sensitive health-related data (medical records, patient account numbers, prescription information, medical providers, procedures, health insurance details). 

How It Could Affect Your Business: This is a treasure trove of valuable data for bad actors but losing this data could be punishingly expensive for this healthcare provider..


 

Clearview Resources Ltd.

https://thecyberexpress.com/clearview-cyberattack-results-millions-loss/

Exploit: Account Takeover

Clearview Resources Ltd.: Energy Company

cybersecurity news gauge indicating extreme risk

 

Risk to Business: 1.462 = Extreme

Canadian energy producer Clearview Resources Ltd. has disclosed that it suffered an account takeover attack in December 2023 that cost the company $1.5 million. In the incident, bad actors were able to compromise a corporate email account, enabling them to execute an account takeover (ATO) and redirect company funds to a third-party account. The company said that the attack did not have a material impact on its operations, and it is working with a third-party cybersecurity firm to investigate the incident as well as law enforcement in the hope of recovering the stolen funds.

How It Could Affect Your Business: ATO is incredibly dangerous and can lead to huge financial losses like this one or even worse.


 

Tilbury District Family Health Team (TDFHT)

https://cknewstoday.ca/chatham/news/2024/0/20/ransomware-attack-spreads-to-tilbury-district-family-health-team

Exploit: Supply Chain Attack

Tilbury District Family Health Team (TDFHT): Healthcare Provider

cybersecurity news represented by agauge showing severe risk

 

Risk to Business: 1.702 = Severe

Tilbury District Family Health Team (TDFHT) has announced that patient data may have been compromised in a recent cyberattack on one of its service providers, Transform. The stolen data may include the patient’s first and last name, date of birth, address, and health card number, as well as medical status, patient medication summaries, immunization records and therapy status summaries. Officials reassured the public that no patient social insurance numbers or any credit card, financial or banking information was stolen. Other healthcare providers including Chatham-Kent Health Alliance, Erie Shores HealthCare, Bluewater Health, Windsor Regional Hospital and Hôtel-Dieu Grace Healthcare were also clients of the same service provider and have experienced data security problems as a result of the attack as well.

How it Could Affect Your Business: Supply chain cyberattacks will continue to become an increasing problem for businesses as the world becomes ever more interconnected.


 

The Netherlands – DENHAM the Jeanmaker

https://thecyberexpress.com/denham-cyberattack-tce-exclusive/

Exploit: Ransomware

DENHAM the Jeanmaker: Fashion Brand

cybersecurity news represented by a gauge indicating moderate risk

 

Risk to Business: 2.736 = Moderate

Amsterdam-based fashion house DENHAM the Jeanmaker has disclosed that it has been the victim of a ransomware attack. The Akira ransomware group is suspected of being the culprit. The fashion brand said that the cyberattack was first discovered on December 27, 2023. The cyberattack on DENHAM did not impact the brand’s in-store or online retail operations. However, the bad actors did manage to steal some corporate and proprietary data. The brand was quick to reassure clients that no consumer data or credit card information was stolen. 

How it Could Affect Your Business: Proprietary data like intellectual property is valuable and desirable for cybercriminals too.


 

Czech Republic – Trezor

https://beincrypto.com/trezor-hardware-wallet-phishing-security-breach/

Exploit: Supply Chain Attack

Trezor: Cryptocurrency Wallet

cybersecurity news represented by a gauge indicating moderate risk

 

Risk to Business: 2.736 = Moderate

In a rare Defi story that doesn’t involve a crypto company being hacked for millions, crypto wallet company Trezor is informing users that it has experienced a data breach as the result of an attack on one of its service providers. The company said that the contact details of 66,000 users who accessed Trezor Support since 2021 may have been compromised. The exposed data could include names, nicknames and email addresses. The service provider has not been identified.  

How it Could Affect Your Business: Data thieves don’t just want financial or personal data; stolen intellectual property also has the potential for a big profit.


 

Taiwan – Foxsemicon

https://therecord.media/foxsemicon-ransomware-attack-taiwan

Exploit: Misconfiguration

Foxsemicon: Semiconductor Manufacturer

cybersecurity news represented by agauge showing severe risk

 

Risk to Business: 1.602 = Severe

Major semiconductor manufacturer Foxsemicon has fallen victim to a ransomware attack by the LockBit ransomware group. The gang posted a notification on Foxsemicon’s website stating they had taken it over and stolen 5TB of the company’s client data. Foxsemicon did not disclose any information about the ransom demanded by the hackers. It also has not confirmed whether any personal information about its customers or employees was leaked. Foxsemicon is a subsidiary of electronics giant Foxconn. 

How it Could Affect Your Business: Ransomware actors have been ramping up pressure on key points in the supply chain to push for a big, fast payday.


 

The Week in Breach News: 01/24/24 – 01/30/24
The Week in Breach News: 01/10/24 – 01/16/24

Customer Login

News & Updates

InTegriLogic is proud to announce the launch of our new website at www.integrilogic.com. The goal of the new website is to make it easier for our existing clients to submit and manage support requests, and provide more information about our services for ...

Contact us

Learn more about what InTegriLogic can do for your business.

InTegriLogic
1931 W Grant Road suite 310
Tucson, Arizona 85745

Copyright InTegriLogic. All Rights Reserved.