InTegriLogic Blog
The Week in Breach News: 07/31/24 – 08/06/24
This week: Ransomware disrupts the blood supply in Florida and another cyberattack on a major mine.
OneBlood
https://floridapolitics.com/archives/687948-oneblood-says-systems-are-rebooting-after-cyberattack/
Exploit: Ransomware
OneBlood: Non-Profit
Risk to Business: 2.356 = Extreme
A July 17 ransomware attack on OneBlood, a nonprofit serving hospitals in Florida, has disrupted its ability to ship blood products. The organization has implemented manual processes, which are slower and affect inventory availability. Over 250 hospitals were asked to activate their critical blood shortage protocols while OneBlood works to resolve the issue. State officials are pointing the finger at Russia, but that has not been confirmed.
How It Could Affect Your Business: Attacks that interrupt the medical supply chain have the potential for catastrophic consequences.
City of Columbus, Ohio
https://www.nbc4i.com/news/local-news/columbus/ransomware-group-claims-columbus-attack-selling-6-terabytes-of-passwords-and-more/
Exploit: Ransomware
The City of Columbus, Ohio: Municipal Government
Risk to Business: 1.356 = Severe
Rhysida has announced that it stole 6.5 terabytes of sensitive data from City of Columbus servers following a ransomware attack on July 18. The attack led to the shutdown of multiple online city services and compromised the personal information of many police officers, including their bank accounts. Notably, no data was encrypted. The stolen information includes internal logins, city databases, a full dump of servers with emergency services applications, and access to city video cameras. Rhysida has demanded a $1.9 million ransom. The incident is under investigation by cybersecurity experts, the U.S. Federal Bureau of Investigation (FBI) and the U.S. Department of Homeland Security.
How It Could Affect Your Business: Beyond snarling services, attacks against municipal governments also have the potential to expose highly sensitive data.
Jerico Pictures Inc.
https://securityaffairs.com/166539/data-breach/personal-data-3-billion-people-data-breach.html
Exploit: Hacking
Jerico Pictures Inc.: Background Check Data Company
Risk to Business: 1.721 = Severe
Jerico Pictures Inc., operating as the background-checking data company National Public Data, exposed the personal information of nearly 3 billion individuals in an April breach. The threat actor known as USDoD announced the sale of this data, including full names, Social Security numbers, and addresses, on a dark web forum for $3.5 million. National Public Data collects such information by scraping non-public sources.
How It Could Affect Your Business: data repositories like this one are treasure troves for bad actors, supplying them with many types of saleable data in a one-stop-shop.
Mexico – Fresnillo PLC
https://cybersecuritynews.com/fresnillo-plc-suffer/
Exploit: Hacking
Fresnillo PLC: Silver Producer
Risk to Business: 2.632 = Moderate
Fresnillo PLC, the world’s leading silver producer, has reported a significant cybersecurity incident involving unauthorized access to IT systems and data. The company has activated response protocols and assures stakeholders that operations continue normally with no reported financial or operational impact. The incident is still under investigation.
How It Could Affect Your Business: It’s critical for companies to put themselves in the best possible position for a fast, smooth incident response.
UK – Sable International
https://therecord.media/hackers-email-victims-customers-data-breach
Exploit: Hacking
Sable International: Immigration Services
Risk to Business: 1.612 = Severe
Sable International, with offices in the UK, Australia, and South Africa, has been targeted by a sophisticated cyberattack that forced the company to shut down its servers, website, and transactional portals. The BianLian ransomware gang has claimed responsibility and is pressuring the firm by emailing demands its customers who had data stolen. As of Friday afternoon, the company’s website remains offline.
How it Could Affect Your Business: Bad actors are always on the hunt for the slightest opening in a company’s armor that they can exploit to strike.
Zimbabwe – ZB Financial Holdings
https://www.techzim.co.zw/2024/08/zb-financial-holdings-hacked-for-ransom-customer-operations-data-leaked-to-the-internet/
Exploit: Ransomware
ZB Financial Holdings: Financial Services
Risk to Business: 1.896 = Severe
ZB Financial Holdings, a major Zimbabwean financial institution, suffered a ransomware attack in July, resulting in the leak of data to the internet after the company refused to pay the ransom. The leaked data includes customer and employee information, account applications, and files dating back to 2017. The attack may be connected to a notice ZB issued on July 16 about system instability.
How it Could Affect Your Business: The financial services industry has been high on cybercriminals’ hit lists, consistently remaining in the top five most attacked industries.
India – C-Edge Technologies
https://www.reuters.com/technology/cybersecurity/ransomware-attack-forces-hundreds-small-indian-banks-offline-sources-say-2024-07-31/
Exploit: Ransomware
C-Edge Technologies: Financial Services
Risk to Business: 1.661 = Severe
C-Edge Technologies: Financial Services C-Edge Technologies, a tech service provider for banks, suffered a ransomware attack, leading to its temporary isolation from the NPCI’s retail payment systems. This disruption caused nearly 300 small Indian banks to shut down temporarily. The issue, reported on July 29, impacted cooperative and regional rural banks, affecting about 0.5% of the country’s payment systems. The connection with C-Edge was restored on August 1.
How it Could Affect Your Business: A successful cyberattack on a key service provider can have a disastrous impact on the businesses it supplies too.
Australia – McDowall Affleck
https://thecyberexpress.com/mcdowall-affleck-cyberattack/
Exploit: Hacking
McDowall Affleck: Engineering Firm
Risk to Business: 2.236 = Moderate
McDowall Affleck, an Australian engineering firm specializing in designing storage tanks and pipelines, has reported a cyber incident after the RansomHub ransomware group claimed responsibility. RansomHub alleges to have accessed 470 GB of internal data, including critical documents, insurance records, and personal information. The company has notified the Australian Cyber Security Centre and regional police and is cooperating with authorities.
How it Could Affect Your Business: Information about infrastructure components stolen from companies that supply, manufacture or service it can help bad actors attack critical infrastructure targets.