InTegriLogic Blog
The Week in Breach News: 04/10/24 – 04/16/24
This week: A second helping of cyber trouble for Change Healthcare and Roku and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) speaks about the hacking at Sisense
Change Healthcare
https://www.itpro.com/security/ransomware/change-healthcare-hit-with-second-ransomware-attack-of-2024
Exploit: Ransomware
Change Healthcare: Technology Provider
Risk to Business: 1.741 = Extreme
On the heels of its massive cyber disaster a few weeks ago, Change Healthcare has fallen victim to a ransomware attack yet again. A threat actor new to the scene calling themselves RansomHub claims to have snatched 4TB of sensitive data from the organization’s network. The bad actors claim to have obtained a variety of data including the personal identifying information (PII) of active US service members and other patients, medical records, insurance records, payment information and over 3,000 source code files for Change Healthcare technology.
How It Could Affect Your Business: Getting hit by another major cyberattack so soon after the last one is a disaster for a company whose reputation is already tarnished
Roku
https://techcrunch.com/2024/04/12/roku-second-user-accounts-hacked/
Exploit: Credential Stuffing
Roku: Streaming Service
Risk to Business: 1.856 = Extreme
Roku is cleaning up after its second credential stuffing attack in as many months. The company said about 576,000 customers were impacted. Roku said that the attackers likely did not steal any customer information. However, malicious hackers made fraudulent purchases of Roku hardware and streaming subscriptions using the payment data stored in about 400 users’ accounts. Those charges have been refunded. Roku said it discovered this incident while investigating a credential stuffing attack we covered two weeks ago. when 15,000 Roku users had their accounts compromised.
How It Could Affect Your Business: Credential stuffing isn’t hard for bad actors to pull off with the huge pools of exposed passwords for sale on the dark web.
Wells Fargo
https://cybernews.com/news/wells-fargo-suffers-data-breach/
Exploit: Insider Threat
Wells Fargo: Bank
Risk to Business: 1.721 = Severe
Banking giant Wells Fargo has sent a data breach notice to some customers. In the letter, the bank said that an employee violated company policy by sending information to his personal account. Wells Fargo told customers that their personal information and mortgage account numbers were exposed in the incident. It is not known how many customers were impacted.
How It Could Affect Your Business: Employees mishandling data, whether accidental or intentional, can cause major problems that lead to big bills quickly
Sisense
https://techcrunch.com/2024/04/11/cisa-government-sisense-reset-credentials-cyberattack/
Exploit: Hacking
Sisense: Analytics Platform Developer
Risk to Business: 1.803 = Severe
In a rare move, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a short statement noting that it is investigating a data breach from a cyberattack on analytics technology company Sisense. The company counts major organizations including infrastructure operators among its clients. CISA warned customers to reset their passwords immediately. The purloined data included millions of access tokens, email account passwords and SSL certificates among other data. Sisense confirmed that bad actors accessed a restricted server. The incident is under investigation.
How It Could Affect Your Business: A data breach from a company that handles sensitive infrastructure data is a danger to the public.
The Heritage Foundation
https://techcrunch.com/2024/04/12/heritage-foundation-cyberattack/
Exploit: Hacking
The Heritage Foundation: Think Tank
Risk to Business: 1.712 = Severe
Conservative think tank the Heritage Foundation admitted that they fell victim to a cyberattack last week. A spokesperson from the group said that they suspect they’ve fallen victim to nation-state hackers, although there is no solid evidence that is the case. The group was not forthcoming about any stolen data.
How it Could Affect Your Business: Politically prominent organizations are prime targets for both general hackers and nation-state cybercriminals
New Mexico Highlands University (NMHU)
https://www.aol.com/nmhu-nears-week-canceled-classes-030200860.html
Exploit: Hacking
New Mexico Highlands University (NMHU): Institution of Higher Learning
Risk to Business: 2.376 = Severe
Classes have been canceled for a week as the result of a ransomware attack on New Mexico Highlands University (NMHU). School officials said that its Information Technology Services department identified a technology issue on April 3, 2024. NMHU said that the impacted system was the college’s internal portal for staff, students and faculty. The incident is still under investigation.
How it Could Affect Your Business: Cyberattacks on business service providers can open the organizations they serve up to data security and cybersecurity trouble.
UK – EBlock
https://cybernews.com/news/eblock-hit-by-cyberattack/
Exploit: Hacking
EBlock: Auto Retailer
Risk to Business: 1.866 = Moderate
Toronto-based online auto retailer EBlock has fallen victim to a data breach. The company disclosed that an unauthorized party had accessed specific areas of the legacy ABS Auto Auctions infrastructure. The personal information of its clients was stolen including dates of birth, Social Security numbers, driver’s licenses, bank account numbers and bank routing numbers.
How it Could Affect Your Business: A data breach is an expensive proposition for any business from the first stage of the investigation to the final stage of remediation.
France – The City of Saint-Nazaire
https://therecord.media/france-cyberattack-loire-municipalities
Exploit: Ransomware
The City of Saint-Nazaire: Municipal Government
Risk to Business: 2.602 = Moderate
The City of Saint-Nazaire, France is among five cities in the Loire Valley region that experienced a cyberattack last week that knocked out city systems and services. French officials are describing this as a “large-scale cyberattack”. The cities impacted are Saint-Nazaire, Montoir-de-Bretagne, Donges, La Chapelle-des-marais and Pornichet. In Saint-Nazaire, the attack that occurred last Tuesday night left city employees with no access to their workspaces, files or business software. No word on what, if any, data was stolen or a timeline on restoring impacted systems.
How it Could Affect Your Business: Municipal governments around the world have been plagued by hackers deploying ransomware to interrupt city services.