"Your Information Technology Leader"

Client Portal Payment Portal

Blog

InTegriLogic Blog

InTegriLogic has been serving the Tucson area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

The Week in Breach News: 09/27/23 – 10/03/23

Breach-5

This week: Ransomware leads to trouble for Johnson Controls and the U.S. Department of Homeland Security and ransomware takes down a German motel chain.

 

Progressive Leasing

https://therecord.media/product-leasing-giant-progressive-ransomware

Exploit: Ransomware

Progressive Leasing: Product Leasing Company

 

Risk to Business: 1.803 = Severe

Progressive Leasing announced that it was the victim of a cyberattack last week that took down the company’s systems. The company told the U.S. Securities and Exchange Commission that bad actors stole data including customers’ personally identifiable information including social security numbers. Progressive said that it has engaged a third-party firm to investigate the incident.

How It Could Affect Your Business: Leasing companies can hold a wide variety of valuable personal and financial data from their customers.


 

McLaren Health Care

https://www.bankinfosecurity.com/ohio-community-college-data-theft-breach-affects-nearly-300k-a-23132

Exploit: Ransomware

McLaren Health Care: Health System

 

Risk to Business: 1.603 = Severe

The ALPHV/BlackCat ransomware gang has added McLaren Health Care in Michigan to its list of victims on its dark web leak site. The group claims to have 6TB of data impacting 2.5 million patients. As part of this attack, McLaren was forced to shut down IT systems temporarily at 14 of its facilities. Hospitals in four states were forced to cancel appointments, divert ambulances and use paper records. The incident remains under investigation.

How It Could Affect Your Business: The healthcare sector has been a top target for cybercriminals conducting ransomware attacks.


 

BORN Ontario

https://therecord.media/pittsburg-kansas-government-cyberattack

Exploit: Hacking

The Town of Pittsburg, KS: Municipality

 

Risk to Business: 1.873 = Moderate

A cyberattack has left a small city in Kansas without government email, phone and online payment systems. Officials in Pittsburg, KS, population 20,000, said that the cyberattack was discovered over the weekend. They were quick to reassure citizens that the city’s emergency services and 911 capabilities were not impacted. City officials said that their IT personnel reacted quickly and took proactive measures to protect city data and network systems. The incident remains under investigation.

How It Could Affect Your Business: Governments of every size need to be prepared for ransomware attacks because they’re favored targets for bad actors.


 

Canadian Flair Airlines

https://securityaffairs.com/151512/data-breach/canadian-flair-airlines-data-leak.html

Exploit: Misconfiguration

Canadian Flair Airlines: Airline

 

Risk to Business: 1.710 = Severe

Canadian Flair Airlines has suffered a data breach caused by misconfiguration. The company left credentials to sensitive databases and email addresses open for at least seven months on the flyflair.com website. The public .env files revealed the MySQL database credentials and location for the local database, the MySQL database credentials and location for the remote, internet-connected database, the SMTP configuration, including credentials and secret tokens and a Laravel App key. Other stolen data may include a database of customer records that includes a customer’s first and last name, email address, phone number, flight details (destinations, dates, flight numbers, etc.) and other personal information. 

How It Could Affect Your Business: Employee mistakes are gateways for expensive diasters like a data breach or regulatory trouble.


 

Germany – Motel One 

https://securityaffairs.com/151732/cyber-crime/alphv-ransomware-motel-one.html

Exploit: Ransomware

Motel One: Motel Chain

cybersecurity news represented by agauge showing severe risk

 

Risk to Business: 1.673 = Severe

German motel chain Motel One had suffered a ransomware attack. The chain was added to the dark web leak site of ALPHV/BlackCat. The group claims to have stolen 24,449,137 files amounting to approximately 6 TB of data. The stolen data includes booking confirmations for the past three years as well as customer records including customers’ names, addresses, dates of reservation, payment methods and contact information. 

How it Could Affect Your Business: Ransomware risk has been steadily rising for businesses in every sector, and all companies should be working to mitigate it.


 

Ireland – Johnson Controls International

https://www.databreaches.net/building-automation-giant-johnson-controls-hit-by-ransomware-attack/

Exploit: Ransomware

Johnson Controls International: Security Equipment Company

cybersecurity news represented by agauge showing severe risk

 

Risk to Business: 1.612 = Severe

A newer ransomware group called Dark Angels is claiming responsibility for a ransomware attack that shut down some of Johnson Controls’ offices. Several subsidiaries of the company in Asia and other areas experienced IT outages as officials took systems offline in response to the attack. The gang has asked for $51 million in ransom. CNN reported that they obtained an internal memo from the U.S. Department of Homeland Security raising alarm about the incident and warning that the attack on Johnson Controls may have “compromised sensitive physical security information such as DHS floor plans.” The gang claims to have snatched 27 TB of data. 

How it Could Affect Your Business: Companies that contract for government agencies often have sensitive information that requires powerful protection


 

Switzerland – European Telecommunications Standards Institute (ETSI): Regulator 

https://therecord.media/etsi-telecommunications-standards-body-hack-database-stolen

Exploit: Hacking

European Telecommunications Standards Institute (ETSI): Regulator

cybersecurity news represented by a gauge indicating moderate risk

 

Risk to Business: 2.802 = Moderate

The European Telecommunications Standards Institute (ETSI) announced last week that it had been the victim of a cyberattack that led to a data breach. ETSI said that bad actors stole a database identifying its users. The non-profit said that bad actors were able to take advantage of an unnamed exploit to grab the data. The company said that the problem has since been corrected. ETSI has more than 900 member organizations from over 60 countries.

How it Could Affect Your Business: Companies need to be careful to watch out for vulnerabilities and exploits that bad actors could use to penetrate systems


 

Switzerland – The World Baseball Softball Confederation (WBSC)

https://securityaffairs.com/151666/data-breach/misconfigured-wbsc-server-leaks-thousands-of-passports.html

Exploit: Misconfiguration

The World Baseball Softball Confederation (WBSC): Sports Governing Body

cybersecurity news represented by agauge showing severe risk

 

Risk to Business: 1.716 = Severe

 A misconfigured server is the culprit in a data breach at The World Baseball Softball Confederation (WBSC). On June 5th, security researchers discovered a misconfigured Amazon Web Services (AWS) bucket belonging to WBSC that contained nearly 48,000 files. Some of those files contained copies of 4,600 peoples’ national passports. The WBSC, headquartered in Switzerland, was established in 2013 and currently has 141 countries as members located in Asia, Africa, the Americas, Europe and Oceania.

How it Could Affect Your Business: When employees are trained in proper security procedures they take security more seriously and avoid mistakes.


 

The Week in Breach News: 10/04/23 – 10/10/23
The Week in Breach News: 09/20/23 – 09/26/23

Customer Login

News & Updates

InTegriLogic is proud to announce the launch of our new website at www.integrilogic.com. The goal of the new website is to make it easier for our existing clients to submit and manage support requests, and provide more information about our services for ...

Contact us

Learn more about what InTegriLogic can do for your business.

InTegriLogic
1931 W Grant Road suite 310
Tucson, Arizona 85745

Copyright InTegriLogic. All Rights Reserved.