InTegriLogic Blog
The Week in Breach News: 02/21/24 – 02/27/24
This week: An insider snatches 79k email addresses from a UK council and Royal Canadian Mounted Police (RCMP) gets caught up in cyber trouble.
Change Healthcare
https://thecyberexpress.com/cyberattack-on-change-healthcare/
Exploit: Hacking
Change Healthcare: Healthcare Technology Provider
Risk to Business: 1.771 = Severe
Change Healthcare is admitting that it has experienced a successful cyberattack that has caused widespread disruptions to healthcare services and prescription processing across the U.S. The healthcare technology company is part of Optum and owned by UnitedHealth Group. The trouble began on February 21, when bad actors were able to exploit the ConnectWise vulnerability. More than 100 Change Healthcare applications across pharmacy, medical record, clinical, dental, patient engagement, and payment services are affected. Some reports are pointing to a state-sponsored threat actor as the culprit.
How It Could Affect Your Business: Software vulnerabilities are a fact of life and unfortunately a hazard that companies have to navigate carefully
Quik Pawn Shop
https://thecyberexpress.com/quik-pawn-shop-cyberattack/#google_vignette
Exploit: Ransomware
Quik Pawn Shop: Liquidator
Risk to Business: 2.691 = Moderate
The Akira ransomware gang has claimed a hit on Alabama-based pawn shop chain Quik Pawn Shop. The attack occurred on February 22. Akira said that they snatched 140 GB of files along with a database full of customer information. Stolen customer information includes millions of records containing sensitive details such as dates of birth, addresses, Social Security numbers and financial transaction histories. The incident is under investigation.
How It Could Affect Your Business: Data from a pawn shop can contain sensitive details that could be used in blackmail operations.
Medical Management Resource Group (MMRG)
https://www.bankinfosecurity.com/hack-at-services-firm-hits-24-million-eye-doctor-patients-a-24418
Exploit: Hacking
Medical Management Resource Group (MMRG): Professional Services Company
.
Risk to Business: 1.643 = Severe
An Arizona-based healthcare services firm is in the process of notifying nearly 2.4 million patients that their data may have been compromised in a November 2023 hacking incident. The incident involved data held by American Vision Partners, a brand of Medical Management Resource Group (MMRG) that services ophthalmology practices. The company said that it detected unauthorized activity on certain parts of its network in November 2023 and later determined that hackers had stolen sensitive data. The compromised information varies among patients but may include names, contact information, birthdates and medical information including services received, clinical records and medications. For some individuals, the hack also affected Social Security numbers and insurance information.
How It Could Affect Your Business: Business services companies can be juicy targets for cybercriminals because of the large amount of data they handle.
Royal Canadian Mounted Police (RCMP)
https://www.bleepingcomputer.com/news/security/rcmp-investigating-cyber-attack-as-its-website-remains-down/
Exploit: Hacking
Royal Canadian Mounted Police (RCMP): Law Enforcement Agency
Risk to Business: 1.462 = Extreme
The Royal Canadian Mounted Police (RCMP) has disclosed that a recent website outage was due to a cyber attack. The RCMP site was down as of early morning on February 26. Officials were quick to assure the public that RCMP is still operating normally and there is no impact on public safety. The federal body has started its criminal investigation into the matter as it works to determine the scope of the security breach.
How It Could Affect Your Business: Critical infrastructure has been under increasing pressure and that includes law enforcement agencies as well.
UK – Stratford-on-Avon District Council
https://www.infosecurity-magazine.com/news/insider-steals-80000-emails/
Exploit: Insider Threat
Warwick District Council: Regional Government Agency
Risk to Business: 2.702 = Moderate
A former council worker has admitted to making off with tens of thousands of residents’ emails from a Stratford-on-Avon District Council database in order to promote a business. The breach occurred in November 2023 when 79,000 email addresses were copied from a garden waste collection database. A Warwick District Council database was also nabbed. Officials say that the databases only contained email addresses. No bank details, names or addresses were exposed. The former employee has been cautioned by the police.
How it Could Affect Your Business: Many employees take information with them when they go including customer data and proprietary information.
Switzerland – Das Team Ag
https://thecyberexpress.com/das-team-ag-cyberattack/#google_vignette
Exploit: Ransomware
Das Team Ag: Job Placement Agency
Risk to Business: 1.836 = Severe
Major recruiter Das Team Ag has become a victim of the notorious Black Basta ransomware outfit. The company, which boasts 25 branches across Switzerland and the Principality of Liechtenstein, admitted that they have fallen victim to a ransomware attack after they appeared on Black Basta’s dark web leak site. The group did not post any evidence to back up its claim, nor did Das Team Ag specify what types of data have been stolen.
How it Could Affect Your Business: Ransomware has been a menace to the business and professional services industry as well as other players in the business supply chain.
Germany – PSI Software
https://www.cybersecuritydive.com/news/psi-software-ransomware/707940/
Exploit: Ransomware
PSI Software: Logistics Software Company
Risk to Business: 1.566 = Extreme
German critical infrastructure software and logistics platforms vendor PSI Software has been knocked out by a ransomware attack. The company, providers of software used to provision critical infrastructure, was forced to shut down all external connections and systems last week. The problem was first revealed unusual activity was spotted on PSI’s network on February 15. PSI said that it doesn’t see evidence that customer sites were hacked, and bad actors did not gain access to remote connections for the maintenance of customer systems.
How it Could Affect Your Business: Bad actors are leveraging the relationships between companies to conduct sophisticated cyberattacks.
Australia – Tangerine
https://www.healthcareinfosecurity.com/breach-at-aussie-telecom-tangerine-affects-232000-customers-a-24414
Exploit: Third-Party Risk
Tangerine: Telecom
Risk to Business: 1.802 = Severe
Officials at Tangerine say that the compromise of a contractor’s credentials is to blame for a cyberattack that has resulted in a data breach. The incident came to light last Tuesday. Approximately 232,000 customers have been affected. Exposed customer data includes names, birthdates, mobile numbers, email addresses, postal addresses and Tangerine account numbers. The telecom said that no credit or debit card numbers, driver’s license numbers, ID documentation details, banking details or passwords have been exposed as a result of this incident.
How it Could Affect Your Business: Third-party and supply chain risks are becoming an ever more complex web of threats for businesses.