Cyberattacks: Page 24


  • Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol. 3d rendering.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Johns Hopkins hit with class action suit following MOVEit data breach

    The suit alleges that the health system failed to implement safeguards to secure patients’ health information and provided insufficient details about the stolen data.

    By Sydney Halleman • July 12, 2023
  • Telecom network above a city
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Threat group testing more sophisticated DDoS hacks, authorities warn

    Hacktivists behind the attacks on Microsoft OneDrive and Azure are claiming recent test disruptions at Stripe, Reddit and EFTPS.  

    By July 10, 2023
  • Trendline

    Top 5 stories from Cybersecurity Dive

    tk

    By Cybersecurity Dive staff
  • Illustrated man with fishing hook stealing key
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Hackers using TrueBot malware for phishing attacks in US, Canada, officials warn

    Threat actors have been leveraging a known vulnerability in Netwrix Auditor to exfiltrate data from targeted entities since May.

    By July 7, 2023
  • Petro-Canada has more than 1,500 retail locations across the nation of Canada.
    Image attribution tooltip
    Courtesy of Suncor
    Image attribution tooltip

    Suncor Energy confirms hackers breached Petro-Canada gas stations’ customer rewards data

    The company, the largest integrated energy firm in Canada, said field operations were not impacted.

    By July 6, 2023
  • Rendered image depicting global networks.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    MOVEit vulnerability snags almost 200 victims, more expected

    The education sector has been hit particularly hard as many widely used vendors in the space confirm impacts linked to the mass exploited vulnerability.

    By July 5, 2023
  • Petro-Canada has more than 1,500 retail locations across the nation of Canada.
    Image attribution tooltip
    Courtesy of Suncor
    Image attribution tooltip

    Petro-Canada reports service restoration after suspected Suncor breach

    The gas station chain restored card payments, but hasn’t shared specific details about the disruption. The industry has been under threat from state-linked actors. 

    By June 29, 2023
  • Petro-Canada has more than 1,500 retail locations across the nation of Canada.
    Image attribution tooltip
    Courtesy of Suncor
    Image attribution tooltip

    Suncor Energy continues probe of cyber incident disrupting gas station payments

    The incident came just days after authorities warned of possible attacks against the Canadian oil and gas sector.

    By June 28, 2023
  • American Airlines and Southwest Airlines jets on the runway at Los Angeles International Airport.
    Image attribution tooltip
    David McNew/Getty via Getty Images
    Image attribution tooltip

    Cyberattack exposes data on nearly 9K American and Southwest Airlines pilot applicants

    Two of the world’s largest airlines no longer use recruitment portal Pilot Credentials after a cyberattack at the end of April.

    By June 27, 2023
  • Smiling businesswoman in headphones taking notes, working with laptop and talking smartphone, blue glowing information protection icons. Padlock, cloud and digital interface. Cyber security concept - stock photo
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    MOVEit vulnerability ensnares more victims

    Some organizations have been impacted due to their direct use of MOVEit while others have been exposed by third-party vendors.

    By June 27, 2023
  • An illustration of a stock market graph and bar chart price display.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Cybercriminals target high-profit companies: AEI

    Investors in recent years have responded faster to news about a cyberattack, the study, which encompasses more than two decades of cyber events, found.

    By Jim Tyson • June 26, 2023
  • PwC logo outside of London, England
    Image attribution tooltip
    Jack Taylor via Getty Images
    Image attribution tooltip

    Big names disclose MOVEit-related breaches, including PwC, EY and Genworth Financial

    More than 100 organizations have been hit as part of the MOVEit attack campaign, including PBI Research Services, which exposed millions of customer data files to theft. 

    By June 23, 2023
  • Dole, produce
    Image attribution tooltip
    Retrieved from Dole.
    Image attribution tooltip

    Dole says February ransomware attack breached data of almost 3,900 US workers

    The fresh produce giant disclosed the data security impact in a filing with the Maine Attorney General.

    By June 22, 2023
  • A stack of snack food packages from Mondelez International, including Wheat Thins, Oreos, Ritz and Sour Patch kids.
    Image attribution tooltip
    Courtesy of Mondelē​​z International
    Image attribution tooltip

    Mondelēz retirement data breached after hacker targets law firm Bryan Cave

    The company said a third-party actor stole sensitive customer data from the firm, impacting more than 51,000 current and former MondelÄ“z employees. 

    By June 21, 2023
  • Gavel sitting on paper saying class action suit
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Progress Software faces federal class action lawsuits as MOVEit breach exposure widens

    Louisiana residents allege their personal financial information was put at risk after the state's motor vehicles department had data exposed in the MOVEit data breach. 

    By June 21, 2023
  • An aerial view of Washington, D.C. that includes the Washington Monument.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    US puts $10M bounty on Clop as federal agencies confirm data compromises

    Additional private sector companies have disclosed attacks after multiple vulnerabilities were found in MOVEit Transfer software.

    By June 20, 2023
  • A signage of Microsoft is seen on March 13, 2020 in New York City.
    Image attribution tooltip
    Jeenah Moon via Getty Images
    Image attribution tooltip

    Microsoft confirms DDoS attacks caused Azure, OneDrive outages

    The DDoS attacks, targeting layer 7, were designed to overwhelm application server infrastructure and are considered especially complex to detect. 

    By Updated June 20, 2023
  • The U.S. Capitol Building at night with lightning in the background.
    Image attribution tooltip
    Naomi Eide/Cybersecurity Dive
    Image attribution tooltip

    Another MOVEit vulnerability found, as state and federal agencies reveal breaches

    The third vulnerability since Progress Software first disclosed a MOVEit Transfer zero day arrived just as CISA officials said a “small number” of federal agencies were impacted. 

    By Naomi Eide • June 16, 2023
  • The red lock and its structure explode in a digital computer setting.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Clop names a dozen MOVEit victims, but holds back details

    As its deadline expired, the ransomware group released the first batch of victim organizations, most of which were U.S.-based, ReliaQuest found.

    By Naomi Eide • June 15, 2023
  • Ransomware virus has encrypted data. Attacker is offering key to unlock encrypted data for money.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    MOVEit customers on high alert as Clop’s deadline expires

    As more compromised organizations come forward, one risk analysis firm is pushing the timeline for the vulnerability back years.

    By June 14, 2023
  • Military Surveillance Officer Working on a City Tracking Operation in a Central Office Hub for Cyber Control and Monitoring for Managing National Security, Technology and Army Communications.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Fortinet urges firmware upgrades after critical vulnerability at risk of malicious attacks

    The warning comes just weeks after the company was linked to the Volt Typhoon campaign against U.S. critical infrastructure targets.

    By June 13, 2023
  • A photo illustration of LastPass logos on a hard drive disk held in someone's hand.
    Image attribution tooltip
    Leon Neal via Getty Images
    Image attribution tooltip

    LastPass CEO reflects on lessons learned, regrets and moving forward from a cyberattack

    Karim Toubba is ready to talk nearly a year after LastPass suffered a cyberattack that became one of the biggest security blunders of 2022.

    By June 13, 2023
  • A logo sits illuminated outside the Microsoft pavilion on the opening day of the World Mobile Congress at the Fira Gran Via Complex on February 22, 2016 in Barcelona, Spain.
    Image attribution tooltip
    David Ramos via Getty Images
    Image attribution tooltip

    Microsoft investigating threat actor claims following multiple outages in 365, OneDrive

    A hacktivist group known as Anonymous Sudan has claimed to be involved in DDoS attacks.

    By June 9, 2023
  • a swarm of barracudas
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Barracuda urges customers to replace compromised ESG appliances immediately

    The retirement of all compromised ESG appliances is akin to an admission the company could not remove threat actor access and recover the devices for customers.

    By June 9, 2023
  • exclamation point depicted hovering above network infrastructure
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Clop claims hundreds of MOVEit vulnerability victims

    The prolific threat actor is responsible for two of the three high-profile, actively exploited vulnerabilities in file-transfer services so far this year.

    By June 8, 2023
  • City skyline from above over highways.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Dallas in the homestretch of ransomware attack recovery

    Security operations and tools are also getting a refresh as city officials rebuild impacted systems and make upgrades across multiple departments.

    By June 7, 2023