InTegriLogic Blog
The Week in Breach News: 06/19/24 – 06/25/24
This week: Take a look at the cyberattack that has crippled thousands of car dealers around the world and a big data leak for Accenture.
CDK Global
https://www.washingtonpost.com/business/2024/06/21/car-dealers-cyberattack-cdk-global
Exploit: Ransomware
CDK Global: Technology Service Provider
Risk to Business: 1.201 = Extreme
Thousands of car dealers are facing disruptions due to two cyberattacks on CDK Global, an industry software provider. The BlackSuit ransomware group claimed responsibility. The attack led to ongoing outages in sales, financing and payroll systems, forcing some dealers to revert to manual operations. The first attack occurred last Tuesday evening, prompting CDK to shut down systems as a precaution on Wednesday. Although some systems were restored by Wednesday afternoon, a second incident occurred that evening, continuing to affect many dealers by Friday. Experts suggest CDK may have prematurely restored systems without fully resolving the issue, which could take weeks to fix.
How It Could Affect Your Business: Bad actors have been increasing the pressure on businesses by hitting key points in the supply chain to create urgency that brings payment.
The Federal Reserve of the United States
https://hackread.com/lockbit-ransomware-us-federal-reserve-data-ransom/
Exploit: Hacking
The Federal Reserve of the United States: Government Agency
Risk to Business: 1.856 = Severe
The LockBit ransomware group claims that it has stolen 33 TB of data from the U.S. Federal Reserve for ransom. The group says they breached the Federal Reserve Board (Federalreserve.gov). In a statement on its new dark web leak site, LockBit says they have “33 terabytes of juicy banking information” containing “American banking secrets.” The group also infers that they are negotiating with the U.S. government for payment, an unlikely circumstance.
How It Could Affect Your Business: The banking and financial services sector is one of the top three sectors for hackers to attack.
Disability Rights Wisconsin (DRW)
https://wtmj.com/news/2024/06/23/data-breach-puts-medicaid-members-information-at-risk-according-to-wisconsin-dhs/
Exploit: Hacking
Disability Rights Wisconsin (DRW): Non-Profit
Risk to Business: 1.721 = Severe
The Wisconsin Department of Health Services reported a cyber incident at Disability Rights Wisconsin (DRW) that may have exposed the private health information of nearly 19,150 Medicaid members. The breach was detected through unusual activity on a DRW email account. DRW is notifying affected individuals by mail and offering one year of free credit monitoring along with access to a dedicated call center.
How It Could Affect Your Business: It’s critical that every organization conduct regular security awareness training to mitigate its risk of trouble from threats that can lead to a data breach.
Financial Business and Consumer Solutions (FBCS)
https://www.foxnews.com/tech/massive-data-breach-exposes-over-3-million-americans-personal-information-cybercriminals
Exploit: Hacking
Financial Business and Consumer Solutions (FBCS): Debt Collector
Risk to Business: 1.803 = Severe
Financial Business and Consumer Solutions (FBCS) experienced a data breach affecting approximately 3 million Americans. The breach occurred in February 2024. FBCS says that it notified affected individuals in late April but only filed the result of their investigation until now. The leaked data may include names, addresses, birthdates, Social Security numbers, driver’s licenses, state ID data and medical information.
How It Could Affect Your Business: Cybercriminals can make a hefty profit from stolen personal and financial data that facilitates identity theft.
Newberg-Dundee School District
https://www.yamhilladvocate.com/2024/06/newberg-dundee-school-district-target-of-ransomware-cyber-attack/
Exploit: Ransomware
Newberg-Dundee School District: Government Agency
Risk to Business: 1.312 = Extreme
On June 12, 2024, the Newberg-Dundee School District in Oregon announced via district-wide email a suspected ransomware attack on their computer network. A separate email informed the community that the district’s phones and computer network were down. It was unclear at press time if any data had been stolen.
How it Could Affect Your Business: Schools are a top target for ransomware and cybercriminals may expect less security staffing in the off season.
Canada – The Toronto District School Board (TDSB)
https://therecord.media/toronto-school-board-ransomware-attack
Exploit: Hacking
The Toronto District School Board (TDSB): Government Agency
Risk to Business: 1.896 = Severe
Hackers targeted a technology testing environment of the Toronto District School Board (TDSB) to deploy ransomware on the main network. The board discovered unauthorized activity in a system used for testing programs. This environment is separate from official networks. The cybersecurity team promptly secured data and protected critical systems. Due to the ongoing investigation, officials can’t provide more details but will notify victims if personal information was accessed.
How it Could Affect Your Business: Every network that an organization maintains needs to be ready for cybercriminal incursions.
Ireland – Accenture
https://www.cyberdaily.au/security/10722-alleged-accenture-it-data-posted-on-breach-forums
Exploit: Hacking
Accenture: Staffing Firm
Risk to Business: 1.866 = Severe
A hacker named 888 recently leaked a file with the contact and personal details of 32,828 individuals, allegedly current and former Accenture employees. The data, including full names and email addresses, was posted on Breach Forums on June 19, 2024. Initially, Accenture denied the breach, later admitting only three people were affected before the full extent of the breach became apparent.
How it Could Affect Your Business: Staffing firms can be a goldmine for bad actors because they hold large amounts of personal and financial data gathered from job seekers.
The Philippines – Jollibee Foods Corp.
https://business.inquirer.net/464875/jollibee-probes-reported-data-breach-in-its-delivery-system
Exploit: Hacking
Jollibee Foods Corp.: Fast Food Chain
Risk to Business: 2.602 = Moderate
Fast-food giant Jollibee Foods Corp. is investigating an alleged data breach in its delivery service system. The company confirmed that its e-commerce platforms were unaffected and are still operational. A threat actor named “Sp1d3r” claims to have obtained the personal data of 32 million Jollibee customers, including names, addresses, phone numbers, email addresses, order histories, service details and sales records.
How it Could Affect Your Business: Any organization can be a target of cybercrime, especially ransomware, in today’s volatile threat landscape.