InTegriLogic Blog
The Week in Breach News: 06/12/24 – 06/18/24
This week: A hack at a pathology lab causes a massive snarl for the UK’s National Health Service and the Snowflake cloud data platform saga continues.
Keytronic
https://www.bleepingcomputer.com/news/security/keytronic-confirms-data-breach-after-ransomware-gang-leaks-stolen-files
Exploit: Ransomware
Keytronic: Technology Manufacturer
Risk to Business: 2.201 = Severe
PCBA manufacturing giant Keytronic reported a data breach by the Black Basta ransomware gang, which leaked 530GB of stolen data. Initially an OEM for keyboards and mice, Keytronic disclosed in SEC filings that a May 6 cyberattack disrupted operations, causing a two-week shutdown in the U.S. and Mexico. The attack also compromised unspecified personal information. Keytronic confirmed the incident will significantly impact its financial performance in the fourth quarter ending June 29, 2024, though normal operations have now resumed.
How It Could Affect Your Business: Bad actors have been increasing the pressure on businesses by hitting key points in the supply chain to create urgency that brings payment.
Truist
https://www.americanbanker.com/news/truist-suffers-data-breach-hackers-claim-it-affects-65-000-employees
Exploit: Hacking
Truist: Bank
Risk to Business: 1.856 = Severe
Truist Bank, a major U.S. commercial bank, has confirmed a data breach resulting from an October 2023 cyberattack. A threat actor known as Sp1d3r is selling stolen data allegedly containing information of 65,000 employees, bank transactions, client details like names and account numbers, as well as source code for Truist’s automated phone system, for $1 million on a hacking forum. Truist’s investigation revealed that an unauthorized party accessed a small number of employee accounts on October 27, 2023, enabling them to access client information. The bank did not provide further details on the extent of the breach.
How It Could Affect Your Business: The banking and financial services sector is one of the top three sectors for hackers to attack.
Tile
https://www.spiceworks.com/it-security/data-security/news/tile-hit-massive-data-breach-customer-data-compromised/amp
Exploit: ransomware
Tile: Technology Company
Risk to Business: 1.721 = Moderate
Tile, the Bluetooth tracking device company owned by Life360, has suffered a major data breach in which hackers stole sensitive customer data like names, physical and email addresses and phone numbers. The hackers also accessed law enforcement tools used for location requests, suggesting potential hacktivism motives. They have demanded a ransom for the safe return of the data through an email to Life360. However, Tile has reassured customers that financial information and individual device locations were not compromised in the hack.
How It Could Affect Your Business: It’s critical that every organization conduct regular phishing simulations to mitigate its risk of trouble from threats like ransomware.
The City of Cleveland, Ohio
https://www.cleveland.com/metro/2024/06/cleveland-city-hall-confirms-it-was-hit-with-ransomware-attack.html
Exploit: Ransomware
The City of Cleveland, Ohio: Municipal Government
Risk to Business: 1.803 = Severe
Cleveland city officials have confirmed that the city’s government systems were hit by a ransomware attack, leading to the closure of City Hall for most of the week. The attack, discovered on Sunday, has disrupted various services, including the processing of building permits and vital records. While employees have returned to work, City Hall will remain closed to the public on Monday as efforts continue to restore and recover the computer systems. The duration of the closure is currently unknown as officials work to resolve the issues caused by the ransomware attack.
How It Could Affect Your Business: Local and municipal governments are prime targets for cyberattacks that can bring big bills in their wake.
USA – Snowflake
https://thehackernews.com/2024/06/snowflake-breach-exposes-165-customers.html
Exploit: Credential Compromise
Snowflake: Cloud Data Platform
Risk to Business: 1.312 = Extreme
Snowflake, a cloud data platform, has finally acknowledged that up to 165 of its customers may have had their information potentially exposed as part of a data theft and extortion campaign. Initially, the embattled company claimed only a limited number of customers were impacted, and an executive even claimed that those customers’ own weak security practices were to blame. However, Snowflake has since partnered with Mandiant to investigate the incident. Mandiant is tracking the problem as UNC5537, calling the perpetrator a financially motivated threat actor. The situation remains evolving, with the company reassessing the scope of the breach as the investigation progresses.
How it Could Affect Your Business: It’s better for companies to own up to a cybersecurity problem than to try to play the blame game.
UK- Synnovis
https://www.digitalhealth.net/2024/06/synnovis-ceo-confirms-ransomware-attack-at-london-hospitals/
Exploit: Ransomware
Synnovis: Pathology Services
Risk to Business: 1.376 = Extreme
A cyberattack on Synnovis, a pathology services provider for the UK’s NHS, disrupted over 800 surgeries and 700 outpatient appointments. Synnovis, a partnership between Guy’s and St Thomas’ NHS FT, King’s College Hospitals NHS FT and SYNLAB, confirmed the attack on June 3, 2024. The incident mainly affected patients at Guy’s, St Thomas’, King’s College Hospitals, and GP services in Bexley, Greenwich, Lewisham, Bromley, Southwark and Lambeth. NHS officials assured that emergency care remains available and advised patients to attend appointments unless informed otherwise, warning that recovery may take several weeks.
How it Could Affect Your Business: This is a chilling example of how a cyberattack at a key point in the supply chain can cripple a sector fast.
Russia – Verny
https://therecord.media/cyberattack-disrupts-supermarket-operations-russia
Exploit: Hacking
Verny: Retail Chain
Risk to Business: 1.866 = Severe
Major Russian discount retail chain Verny, with over 1,000 stores across the country, suffered a disruptive cyberattack over the weekend. The attack crippled the company’s operations for several days, forcing its stores to accept only cash payments, as indicated by printed signs on their doors. The company’s general director suspects the attack was an extortion attempt, although no specific ransom demand was mentioned. The unknown attackers disabled Verny’s website and mobile app, preventing the supermarkets from processing bank card payments or handling online orders and deliveries.
How it Could Affect Your Business: Cybercriminals know that attacks on retailers can be very profitable because they need to reopen fast to keep customers happy.
Australia – Victoria Racing Club
https://www.cyberdaily.au/security/10705-exclusive-medusa-ransomware-gang-demands-us-700-000-payment-from-victoria-racing-club
Exploit: Ransomware
Victoria Racing Club: Thoroughbred Racing Club
Risk to Business: 2.602 = Moderate
The Victorian Racing Club (VRC) has confirmed being the victim of a cyberattack by the Medusa ransomware operation, which claims to have obtained over 100 gigabytes of the club’s data. The Medusa gang is demanding a ransom of $700,000 to delete the data. The leaked data includes information related to gaming machines, financial details, customer invoices, marketing details, personal information of VRC members such as names, email addresses, and mobile phone numbers. The VRC has informed the Australian Cyber Security Centre about the attack and stated that operations will continue as normal.
How it Could Affect Your Business: No organization is too small to be a target of cybercrime, especially ransomware, in today’s volatile threat landscape.