"Your Information Technology Leader"

Client Portal Payment Portal

Blog

InTegriLogic Blog

InTegriLogic has been serving the Tucson area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

The Week in Breach News: 09/18/24 – 09/24/24

Breach-1

This week: Bad actors double-dip for data at Dell and cybercriminals brazenly try to fool Aramark employees with a fake payroll portal.

 

David’s Bridal

https://www.jdsupra.com/legalnews/david-s-bridal-data-breach-leaks-an-4083510/

Exploit: Hacking

Industry: Retailer

cybersecurity news represented by agauge showing severe risk

 

Leading wedding dress retailer David’s Bridal has notified customers that their data may have been exposed in a January 2024 incident. The company reported to the Attorney General of Maine that they detected unusual activity on January 21, 2024, prompting them to secure their system, launch an investigation and notify federal law enforcement. The investigation revealed that on January 20, certain files containing confidential consumer data, including names and Social Security numbers, were accessed without authorization. David’s Bridal sent out data breach letters to anyone who was affected by this data security incident. 

How It Could Affect Your Business: Retailers are excellent sources of data for bad actors because they often have both financial and personal data.


 

Access Sports Medicine & Orthopaedics 

https://www.seacoastonline.com/story/news/local/2024/09/19/access-sports-medicine-data-breach-what-clients-need-to-know/75289867007/

Exploit: Hacking

Industry: Healthcare 

cybersecurity news represented by agauge showing severe risk

 

New Hampshire-based Access Sports Medicine & Orthopaedics reported a data breach involving personal health information. The healthcare provider admitted that unauthorized actors accessed patient PHI and PII including names, birthdates, medical data, Social Security numbers, health insurance and limited financial details. Impacted individuals were notified by mail after the breach was discovered in July 2024.  

How It Could Affect Your Business: A data breach can negatively impact a medical clinic’s reputation just as much as it would negatively impact any other type of business.


 

Mt. Carmel Behavioral Healthcare 

https://www.jdsupra.com/legalnews/mt-carmel-behavioral-healthcare-3197242

Exploit: Hacking

Industry: Healthcare 

cybersecurity news represented by agauge showing severe risk

 

Mt. Carmel Behavioral Healthcare (MCBH) reported a data breach after an unauthorized party accessed an employee email account on June 12, 2024. The breach exposed sensitive consumer information, including names, Social Security numbers, birth dates, addresses and medical and health insurance details. MCBH secured the account, launched an investigation and notified affected individuals by mail between August 9 and August 30, 2024. 

How It Could Affect Your Business: Service providers who handle mental health need to be extra cautious about data security due to the sensitive nature of the data they hold.


 

Aramark

https://www.jdsupra.com/legalnews/aramark-provides-notice-of-mypay-data-9603792

Exploit: Phishing

Industry: Hospitality 

cybersecurity news represented by a gauge indicating moderate risk

 

Aramark, a top food service and facilities services provider, has disclosed that it has experienced a data breach. Aramark discovered that an unauthorized party created a fake website to steal employee login credentials and access the myPay site. The attacker aimed to change direct deposit details but also accessed other personal information, including names, addresses, Social Security numbers, and direct deposit details. 

How It Could Affect Your Business: Training employees to resist phishing is critical for preventing cyberattacks like credential compromise and BEC.


 

Fireworks Software

https://www.jdsupra.com/legalnews/fireworks-software-notifies-27k-5089264

Exploit: Hacking

Industry: Technology

cybersecurity news represented by agauge showing severe risk

 

On September 17, 2024, Fireworks Software reported a data breach after discovering unauthorized access to its network, affecting sensitive data from Rowan College at Burlington County. The breach occurred between June 23 and June 26, 2024. After securing its systems and investigating, Fireworks Software notified impacted individuals. The data breach letter that was uploaded to the Maine Attorney General’s site did not mention what type of information was compromised. 

How it Could Affect Your Business: Slipping in through a service provider or third party can be an easy way for bad actors to snatch data without attacking an organization.


 

Dell Technologies

https://hackread.com/dell-hit-by-second-security-breach-in-week/

Exploit: Hacking

Industry: Technology 

cybersecurity news gauge indicating extreme risk

 

Cybercriminals claim that Dell Technologies has experienced two related data breaches. One breach exposed over 10,000 employee records. Hackers claim to have obtained records that include an employee’s full name, ID number, active status, and internal employee ID information. The same hacker behind the original breach claims to have gone back for round two, this time snatching up data related to Jira files, database tables, and schema migrations, amounting to 3.5 GB of uncompressed data. The hackers claim to have gained access by compromising Dell’s Atlassian software suite.

How it Could Affect Your Business: Multiple data breaches within a short window of time aren’t a good look for any company.


 

UK – Compass Group  

https://www.cyberdaily.au/security/11128-exclusive-sydney-based-compass-group-confirms-medusa-ransomware-attack

Exploit: Ransomware

Industry: Hospitality

cybersecurity news represented by a gauge indicating moderate risk

 

Foodservice giant Compass Group confirmed a ransomware attack on its Compass Group Australia subsidiary. The Medusa gang claims to have stolen 785.5 GB of data. Medusa is demanding $2 million to delete or sell the data and has shared stolen documents. The documents may contain employee information including employee wage declarations, passports, driver’s licenses, and other internal files. The gang has threatened to publish the data in eight days if the ransom is not paid. 

How it Could Affect Your Business: Cybercriminals aren’t just looking for consumer data, they can profit off of employee data and company proprietary data too.


 

Australia – Total Tools

https://www.cyberdaily.au/security/11135-38-000-total-tools-shoppers-compromised-in-data-leak

Exploit: Ransomware

Industry: Retailer

cybersecurity news represented by a gauge indicating moderate risk

 

Total Tools has disclosed that it has experienced a data breach. Initial investigations by a third-party cyber forensics team suggest that the data of 38,000 customers was compromised. Data reportedly includes customers’ names, log-on details, email addresses and credit card information. The company said that its investigation into the nature and size of the incident is still ongoing. Total Tools said that it has also informed the Australian Cyber Security Centre and Office of the Australian Information Commissioner. 

How it Could Affect Your Business: Australian companies have had a particularly rough time with hackers in the past year.


 

Meet Kitboga: The Scam Baiter Fighting Cybercrime ...
The Importance of Project Management in Small Busi...

Customer Login

News & Updates

InTegriLogic is proud to announce the launch of our new website at www.integrilogic.com. The goal of the new website is to make it easier for our existing clients to submit and manage support requests, and provide more information about our services for ...

Contact us

Learn more about what InTegriLogic can do for your business.

InTegriLogic
1931 W Grant Road suite 310
Tucson, Arizona 85745

Copyright InTegriLogic. All Rights Reserved.