InTegriLogic Blog
The Week in Breach News: 09/04/24 – 09/10/24
This week: Another organization falls to the MOVEit exploit and business email compromise (BEC) snags a regional government.
Centers for Medicare & Medicaid Services
https://www.newsweek.com/medicare-data-breach-wisconsin-1950454
Exploit: Zero Day exploit
Centers for Medicare & Medicaid Services: Healthcare
Between May 27 and May 31, 2023, a data breach occurred when unauthorized third parties exploited a vulnerability in the MOVEit service, compromising beneficiaries’ personal information, according to the Centers for Medicare & Medicaid Services (CMS). MOVEit’s developer, Progress Software, disclosed the breach on May 31, but the Wisconsin Physicians Service Insurance, a CMS contractor, recently discovered that files containing Medicare claims data and personal information had been affected. CMS and WPS are notifying 946,801 individuals whose data may have been exposed, outlining steps to take in response.
How It Could Affect Your Business: Zero Day exploits like MOVEit will continue to be a growing problem for organizations in every sector and can often be addressed through regular patching.
Avis
https://izoologic.com/region/north-america/car-rental-avis-confirms-data-breach-exposing-customer-data
Exploit: Hacking
Avis: Travel & Tourism
New Jersey-based rental car giant Avis has reported a data breach affecting 299,006 individuals. In this breach, bad actors accessed sensitive customer information such as names, addresses, emails, phone numbers, birth dates, credit card details and driver’s license numbers. A filing with Maine’s attorney general disclosed the breach. Texas is the most affected state, accounting for 34,592 individuals. Avis also owns the Budget car rental and Zipcar car-sharing brands.
How It Could Affect Your Business: A data breach can impact a company’s reputation and make consumers hesitant to do business with that company again.
Rite Aid
https://www.supermarketnews.com/grocery-technology/rite-aid-recovering-from-security-breach
Exploit: Credential Compromise
Rite Aid: Healthcare
Drugstore chain Rite Aid has disclosed that it experienced a data breach on June 6, 2024. Bad actors successfully compromised an employee’s credentials and gained access to sensitive business data. The breach exposed customer addresses, dates of birth and ID numbers from purchases between June 6, 2017, and July 30, 2018. Social Security numbers and healthcare information were not affected.
How It Could Affect Your Business: Even old data that is stolen in a data breach can be used for nefarious purposes by bad actors.
St. Charles Parish, LA
https://www.nola.com/news/crime_police/cyber-scheme-hacker-st-charles-government-fbi/article_6563c322-6cb2-11ef-808e-0f3a6ad0054e.html
Exploit: Business Email Compromise
St. Charles Parish, LA: Government
Officials in St. Charles Parish, Louisiana, recently discovered a cyberattack involving a vendor whose email system was compromised. This allowed a threat actor to alter the vendor’s banking details, leading to a $1 million invoice payment being redirected to the fraudulent new account. An investigation by local and federal law enforcement is underway following the vendor’s inquiry about the payment.
How It Could Affect Your Business: Security awareness training is an inexpensive and effective way to prevent employees from falling into cybercriminal traps like this BEC incident.
Planned Parenthood of Montana
https://www.techtarget.com/healthtechsecurity/news/366609974/RansomHub-claims-Planned-Parenthood-cyberattack
Exploit: Ransomware
Planned Parenthood of Montana: Healthcare
Planned Parenthood of Montana confirmed a cyberattack that began on Aug. 28, 2024. The cybercrime group RansomHub has claimed responsibility. In a post on the group’s dark web leak site, the gang claimed to have stolen 93 gigabytes of data. The healthcare organization said that it was able to quickly institute its incident response plan and minimize damage.
How it Could Affect Your Business: The exposure of sensitive medical data like this could be traumatic and harmful for the clinic’s clients.
Highline Public Schools
https://www.geekwire.com/2024/school-district-south-of-seattle-cancels-classes-monday-due-to-cyberattack
Exploit: Hacking
Highline Public Schools: Education
Highline Public Schools, a district south of Seattle with 17,500 students, canceled classes for Monday due to a cyberattack. The district detected unauthorized activity on its systems and is working with partners to restore them. The closure affects all school activities, athletics, and meetings. The attack has disrupted communications, transportation and attendance records, but no personal information theft has been detected.
How it Could Affect Your Business: The education sector has been a top target for ransomware gangs because schools can’t afford delays, making them likely to pay up.
U.K. – Tewkesbury Borough Council
https://therecord.media/tewkesbury-borough-council-near-gchq-cyberattack
Exploit: Hacking
Tewkesbury Borough Council: Government
Tewkesbury Borough Council in Gloucestershire, England, has warned residents of a cyberattack and is assuming its systems have been compromised. The council has shut down its systems as part of the response, leading to service disruptions and busy phone lines. The specifics of the attack and whether personal information was affected are still unclear. Residents have been asked not to contact the council except in an emergency.
How it Could Affect Your Business: Bad actors are a menace to governments and government agencies of every size.
Guam – Guam Seventh-Day Adventist Clinic
https://www.guampdn.com/news/guam-seventh-day-adventist-clinic-reports-data-security-breach/article_8332937a-6d97-11ef-9694-1729f6ff8fb9.html
Exploit: Hacking
Guam Seventh-Day Adventist Clinic: Healthcare
Guam Seventh-Day Adventist Clinic has experienced a data breach. The healthcare provider said that unauthorized persons gained access to a few employee email accounts occurred between Jan. 23 and Feb. 3, 2023. An investigation revealed that personal and protected health information, including names, contact details, financial information and medical records, was exposed. Not all types of data were affected for every individual.
How it Could Affect Your Business: a mixed bag of medical records and financial information can be a profitable haul for bad actors.