InTegriLogic Blog
The Week in Breach News: 04/17/24 – 04/23/24
This week: A data breach rocks a troubled Australian music festival and nation-state hackers hit security experts The MITRE Corporation.
Frontier Communications
https://www.pcmag.com/news/cyberattack-at-frontier-communications-causes-service-disruptions
Exploit: Hacking
Frontier Communications: Telecom
Risk to Business: 1.741 = Extreme
Frontier Communications has told the U.S. Securities and Exchange Commission that it experienced a cyberattack on April 14, 2024. The telecom giant said that it discovered an intrusion on that date and took measures to contain it including shutting down some systems. The shutdown led to a service interruption for some customers. Frontier also said that some customers’ information was snatched by the attackers but has not yet offered specifics. The company said that it was restoring systems as quickly as possible, and the incident is under investigation.
How It Could Affect Your Business: A cyberattack that causes a service outage like customers losing access to the internet could push customers to another provider.
The MITRE Corporation
https://www.bleepingcomputer.com/news/security/mitre-says-state-hackers-breached-its-network-via-ivanti-zero-days/
Exploit: Zero Day (Nation-State)
The MITRE Corporation: Non-Profit
Risk to Business: 1.856 = Extreme
The MITRE Corporation said that suspicious activity was detected on one of its networks, causing it to shut down its Networked Experimentation, Research and Virtualization Environment (NERVE), an unclassified collaborative network used for research and development. The organization stated that a threat actor exploited two Ivanti Connect Secure zero-day vulnerabilities to target Mitre’s Virtual Private Networks, then slipped into the organization’s VMware infrastructure using a compromised administrator account. MITRE points to unnamed nation-state threat actors as the culprit.
How It Could Affect Your Business: As business cybersecurity tightens, Cybercriminals are making the most of zero day vulnerabilities
Solano County Library Services (California)
https://www.dailyrepublic.com/townnews/museums/county-maintains-silence-about-cyberattack-possible-threats/article_2777ddb6-fce4-11ee-9dae-4349f40237bb.html
Exploit: Ransomware
Solano County Library Services: Public Library System
Risk to Business: 1.721 = Severe
Solano County, California’s Library Services system has been hit with a ransomware attack. The cyberattack occurred April 5, 2024, and affected facilities in the Solano Partner Libraries and St. Helena network, or SPLASH. The unnamed threat actors purportedly demanded $100,000 or they would release data stolen in the attack. Officials did not offer a timeline for restoration of networks or services. The incident remains under investigation.
How It Could Affect Your Business: People rely on libraries for a variety of important life functions like applying for jobs or government assistance.
Home Depot
https://www.cpomagazine.com/cyber-security/a-home-depot-third-party-data-breach-leaks-the-personal-information-of-10000-employees/
Exploit: Supply Chain Data Breach
Home Depot: Home Improvement Retailer
Risk to Business: 1.803 = Severe
Notorious threat actor IntelBroker claims that it stole data belonging to 10,000 Home Depot employees. Home Depot confirmed the data breach, pointing the finger at an unnamed third-party Software-as-a-Service (SaaS) vendor. Home Depot said the vendor inadvertently made some Home Depot associates’ names, work email addresses and User IDs public during the testing of their systems. Home Depot is still investigating the incident.
How It Could Affect Your Business: Businesses should discuss their service providers’ cybersecurity plans to protect their data when making a deal.
Denmark – The United Nations Development Programme (UNDP)
https://www.cyberdaily.au/security/10456-un-agency-ransomware-attack-claimed-by-8base
Exploit: Ransomware
The United Nations Development Programme (UNDP): International Development Agency
Risk to Business: 1.712 = Severe
The United Nations Development Programme (UNDP) has disclosed that it has become the victim of a ransomware attack. The 8Base ransomware group has claimed responsibility. UNDP said that the attack took out the network in its Copenhagen offices. The agency believes that the attackers stole an assortment of data including human resources and procurement information. On its dark website, 8Base claims to have obtained accounting documents, personal data, employment contracts, confidentiality agreements, personal files, certificates, invoices, receipts, a “huge amount of confidential information” and more.
How it Could Affect Your Business: Politically prominent organizations are prime targets for both general hackers and nation-state cybercriminals.
Switzerland – Octapharma Plasma
https://www.hipaajournal.com/octapharma-ransomware-attack/
Exploit: Ransomware
Octapharma Plasma: Plasma Bank
Risk to Business: 2.376 = Severe
Swiss pharmaceutical company Octoplasma pharma has experienced a cyberattack that impacted technology systems, leading to the temporary closure of 190 plasma donation centers in 35 U.S. states. The company said that it first identified suspicious activity in its network on April 17, 2024. Experts suspect that the fledgling ransomware gang BlackSuit is responsible for the attack. No information was offered about stolen data or a ransom demand.
How it Could Affect Your Business: Cyberattacks on healthcare sector targets aren’t just limited to hospitals, service providers and medical suppliers are also at risk.
France – Hospital Simone Veil in Cannes (CHC-SV)
https://securityaffairs.com/162057/hacking/french-hospital-cyber-attack.html
Exploit: Hacking
Hospital Simone Veil in Cannes (CHC-SV): Medical Center
Risk to Business: 1.866 = Moderate
French medical center Hospital Simone Veil in Cannes (CHC-SV) was hit by a cyberattack last week that impacted medical procedures. The system outages forced personnel to return to pen and paper. The hospital’s website directs patients to reschedule non-urgent consultations. The hospital’s phone systems were unaffected. The incident is under investigation by ANSSI, Cert Santé, Orange CyberDéfense and GHT06.
How it Could Affect Your Business: A cyberattack that shuts down or limits operations at a medical center is a danger to the public.
Australia – Pandemonium Rocks
https://tonedeaf.thebrag.com/massive-data-breach-as-pandemonium-rocks-exposes-hundreds-of-bank-accounts/
Exploit: Misconfiguration
Pandemonium Rocks: Music Festival
Risk to Business: 2.602 = Moderate
The troubled Pandemonium Rocks music festival has taken another massive blow after a major data breach. First, seven of the 10 acts scheduled to perform canceled their appearances. That led to a rush for refunds from angry ticketholders. Organizers said that a clerical error in the refund forms it used left the Administrator tab open. That gave bad actors a window on April 14, 2024, between 5.47 pm and 7.20 pm, to steal ticketholders’ personal data including bank details, email addresses and phone numbers.
How it Could Affect Your Business: Customers are likely to be very upset about having their personal information exposed when trying to get their money refunded.