InTegriLogic Blog
The Week in Breach News: 08/07/24 – 08/13/24
This week: A big breach at ADT and attacks on mining companies continue.
ADT
https://securityaffairs.com/166857/cyber-crime/adt-disclosed-a-data-breach.html
Exploit: Hacking
ADT: Security Company
ADT has disclosed a data breach resulting from a cyberattack, where threat actors accessed certain databases containing customer order information. However, ADT’s investigation indicates that customers’ home security systems and financial data, such as credit card or banking information, were not compromised. The company does not anticipate significant operational or financial impacts. The threat actor claims that over 30,800 records, including customer emails, addresses, user IDs and purchase details, were exposed in the breach.
How It Could Affect Your Business: This may not sound like a big deal, but any intrusion at a company like ADT that handles controls for physical security is concerning.
McLaren Health Care
https://www.freep.com/story/news/health/2024/08/11/mclaren-health-care-cyberattack-details-nessel/74744141007/
Exploit: Ransomware
McLaren Health Care: Health System
McLaren Health Care confirmed that the disruption to its IT and phone systems was due to a cyberattack. The healthcare provider said its IT team is working with external cybersecurity experts to assess the attack and reduce its impact. It’s unclear if any patient or employee data was compromised. Despite the disruption, most facilities remain operational, including emergency departments and most surgeries. Some non-emergency appointments are being rescheduled as a precaution. The attack affected all 13 Michigan hospitals and the health system’s network across Michigan, Indiana and Ohio.
How It Could Affect Your Business: Beyond snarling services, attacks against medical centers can be dangerous for the local community.
First Commonwealth Federal Credit Union
https://www.cybersecuritydive.com/press-release/20240808-first-commonwealth-fcu-data-breach-investigation-1/
Exploit: Hacking
First Commonwealth Federal Credit Union: Financial Services
First Commonwealth FCU notified individuals of a data breach via mailed letters on August 2, 2024. The breach was discovered after investigating suspicious activity on its network starting June 27, 2024. The investigation revealed that hackers had compromised a significant amount of personal information, including names, Social Security numbers, and account details.
How It Could Affect Your Business: Banks and other entities in the financial services sector are to targets for cybercriminals hunting for saleable data.
CSC ServiceWorks
https://techcrunch.com/2024/08/10/csc-serviceworks-reveals-2023-data-breach-affecting-thousands-of-people/
Exploit: Hacking
CSC ServiceWorks: Laundry Machine Manager
CSC ServiceWorks recently disclosed that tens of thousands of individuals had their personal information stolen in a cyberattack that occurred in 2023. The New York-based company, which provides over a million internet-connected laundry machines to residential buildings, hotels and university campuses across North America and Europe, confirmed in a data breach notification filed late on Friday that the breach affected at least 35,340 people, including more than 100 in Maine. CSC employs over 3,200 team members, according to its website.
How It Could Affect Your Business: Every company is at risk for cyber trouble no matter the size or the industry so every company needs to be ready for it.
Sumter County Sheriff (FL)
https://www.scmagazine.com/news/rhysida-ransomware-hits-sumter-county-sheriff-in-latest-ci-attack
Exploit: Ransomware
Sumter County Sheriff: Law Enforcement
The Sumter County Sheriff’s Office in Florida has been targeted by the Rhysida ransomware group, which has threatened to release stolen data including ID scans and fingerprints. The Sheriff’s Office disclosed the attack on Tuesday, stating that while law enforcement operations will not be affected, access to some records may be limited during the investigation. The Rhysida group posted the breach on its leak site Friday, with a seven-day countdown for bidding on the stolen data, starting at 7 bitcoin (approximately $423,000).
How it Could Affect Your Business: Hitting a law enforcement agency is a great way for cybercriminals to get their hands on highly sensitive data that can be used to blackmail victims.
UK – Mobile Guardian
https://www.csoonline.com/article/3481871/over-13000-phones-wiped-clean-as-cyberattack-cripples-mobile-guardian.html
Exploit: Hacking
Mobile Guardian: Mobile Device Management
A cyberattack on UK-based Mobile Guardian, a mobile device management firm, has caused widespread disruption to schools and businesses across North America, Europe, and Singapore. The attack resulted in data loss and the remote wiping of iOS and ChromeOS devices for thousands of users. Mobile Guardian confirmed the incident, which occurred on August 4th, affected users globally. In Singapore, the education sector was hit hard, with around 13,000 students from 26 secondary schools having their iPads and Chromebooks rendered inoperable.
How it Could Affect Your Business: The education sector encompasses more than just schools, and it has has been high on cybercriminals’ hit lists, coming in at #1 for ransomware attacks.
Switzerland – Schlatter Industries
https://www.reuters.com/technology/cybersecurity/swiss-based-schlatter-says-it-network-affected-by-cyber-attack-2024-08-12
Exploit: Ransomware
Schlatter Industries: Manufacturing
Schlatter Industries, a Switzerland-based manufacturer, reported a ransomware attack had hit its network last Friday. The attack took out the company’s email system. The company is investigating whether data was stolen while working to restore system functionality. Schlatter Industries did not share the ransom demand. Schlatter Industries specializes in resistance welding technology and manufacturing weaving machines for specialized purposes.
How it Could Affect Your Business: A successful cyberattack on a key manufacturer can have a disastrous impact on the businesses it supplies.
Australia – Evolution Mining
https://www.reuters.com/technology/australian-gold-miner-evolution-flags-ransomware-attack-2024-08-12/
Exploit: Ransomware
Evolution Mining: Mine Operator
Australian gold miner Evolution Mining reported a cyberattack last week, joining a wave of similar incidents. The company has notified the Australian Cyber Security Centre and stated that the attack is not expected to impact operations. Evolution worked with external cyber forensics experts to investigate the incident, which was discovered on August 8. The company believes the attack is now contained but did not disclose details about the ransomware or any potential extortion payment.
How it Could Affect Your Business: This is the latest in a series of attacks on gold and silver mining companies around the world that has been going on for several months.