Category: Cyber-Crime
Coast Guard data breach delays pay for more than 1,100 service members
The Coast Guard is in the midst of investigating a data breach within its personnel and payroll system that delayed bi-weekly pay for 1,135 service members. The Coast Guard said it temporarily shut down its Direct Access (DA) system as it investigates the breach. News articles won’t speculate, but supposedly enlisted users on certain online forums have said that hackers entered the DA system and changed the direct deposit data of the affected users. Coast Guard members take to social…
A secretive Silicon Valley tech giant set up shop in Canada. But what does it do? (CBC 2017)
This piece was first published by CBC in 2017. It’s one of the most valuable and secretive technology companies in Silicon Valley: Palantir Technologies, a developer of data mining software used by spies, banks and some of the biggest companies in the world. The company was co-founded in 2004 by billionaire Peter Thiel — previously the co-founder of PayPal — and now an adviser to U.S. President Donald Trump. Financial institutions are said to use Palantir’s software to detect fraud and cyberattacks, while pharmaceutical…
How A ‘Deviant’ Philosopher Built Palantir, A CIA-Funded Data-Mining Juggernaut (Forbes 2013)
Since rumors began to spread that a startup called Palantir helped to kill Osama bin Laden, Alex Karp hasn’t had much time to himself. On one sun-baked July morning in Silicon Valley Palantir’s lean 45-year-old chief executive, with a top-heavy mop of frazzled hair, hikes the grassy hills around Stanford University’s massive satellite antennae known as the Dish, a favorite meditative pastime. But his solitude is disturbed somewhat by “Mike,” an ex-Marine–silent, 6 foot 1, 270 pounds of mostly pectoral…
Julian Assange will be freed but must claim guilt: What it means for journalism
Wikileaks founder, publisher, journalist and DiEM25 founding member, Julian Assange, will reportedly enter into a plea deal with the United States prosecutors and be sentenced with time served.
Four FIN9 hackers indicted for cyberattacks causing $71M in losses
Four Vietnamese nationals linked to the international cybercrime group FIN9 have been indicted for their involvement in a series of computer intrusions that caused over $71 million in losses to companies in the U.S. The defendants, identified as Ta Van Tai, Nguyen Viet Quoc, Nguyen Trang Xuyen, and Nguyen Van Truong, carried out their cybercrimes from May 2018 until October 2021, stealing both data and funds directly from U.S. organizations. “The FIN9 defendants were prolific international hackers who, for years, allegedly…
Canada’s anti-money laundering agency offline after cyberattack
The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) has announced that a “cyber incident” forced it to take its corporate systems offline as a precaution. FINTRAC is a government agency in Canada that operates as the country’s financial intelligence unit. It is engaged in money laundering investigations, tracking millions of suspicious transactions annually and making thousands of disclosures about illegal money flows to the police. The agency has published a short press statement on its website stating that…
Foreign Affairs: Spying From Space
In 2023, the Department of Defense announced an ambitious plan to launch 1,000 satellites over the next decade. Over the same period, the National Reconnaissance Office, which runs the country’s spy satellites, plans to quadruple the size of its fleet of a couple dozen satellites. The U.S. government can expand its fleet this quickly because satellites have become much cheaper to manufacture and easier to launch into space. Many of these new satellites are intended for surveillance, and…
FTC orders Blackbaud to boost security after massive data breach
Blackbaud has settled with the Federal Trade Commission after being charged with poor security and reckless data retention practices, leading to a May 2020 ransomware attack and a data breach affecting millions of people. Blackbaud is a U.S.-based company listed on NASDAQ with operations in multiple countries and a provider of cloud-based donor data management software catering to nonprofit organizations, like charities, education organizations, and healthcare agencies. The FTC’s complaint alleges that the company “failed to monitor attempts by hackers…
23andMe says hackers accessed ‘significant number’ of files about users’ ancestry
Genetic testing company 23andMe announced on Friday that hackers accessed around 14,000 customer accounts in the company’s recent data breach. In a new filing with the U.S. Securities and Exchange Commission published Friday, the company said that, based on its investigation into the incident, it had determined that hackers had accessed 0.1% of its customer base. According to the company’s most recent annual earnings report, 23andMe has “more than 14 million customers worldwide,” which means 0.1% is around 14,000. But the company…
Norton Healthcare discloses data breach following May ransomware attack
Kentucky health system Norton Healthcare has confirmed that a ransomware attack in May exposed personal information belonging to patients, employees, and dependents. Norton Healthcare serves adult and pediatric patients in more than 40 clinics and hospitals across Greater Louisville, Southern Indiana, and the Commonwealth of Kentucky. With over 20,000 employees, more than 1,750 employed medical providers, and over 3,000 total providers on its medical staff, Norton Healthcare is Louisville’s second-largest employer, with more than 140 locations throughout Greater Louisville and…
23andMe updates user agreement to prevent data breach lawsuits
As Genetic testing provider 23andMe faces multiple lawsuits for an October credential stuffing attack that led to the theft of customer data, the company has modified its Terms of Use to make it harder to sue the company. In October, a threat actor attempted to sell 23andMe customer data and, after failing to do so, leaked the data for 1 million Ashkenazi Jews and 4.1 million people living in the United Kingdom. Threat actor leaking 23andMe data Source: BleepingComputer 23andMe told BleepingComputer that…
Hackers breach US water facility via exposed Unitronics PLCs
CISA (Cybersecurity & Infrastructure Security Agency) is warning that threat actors breached a U.S. water facility by hacking into Unitronics programmable logic controllers (PLCs) exposed online. PLCs are crucial control and management devices in industrial settings, and hackers compromising them could have severe repercussions, such as water supply contamination through manipulating the device to alter chemical dosing. Other risks include service disruption leading to a halt in water supply and physical damage to the infrastructure by overloading pumps or opening and…
US seizes Sinbad crypto mixer used by North Korean Lazarus hackers
The U.S. Department of the Treasury has sanctioned the Sinbad cryptocurrency mixing service for its use as a money-laundering tool by the North Korean Lazarus hacking group. A cryptocurrency mixer is a server that allows people to deposit crypto, which is mixed among many different wallet addresses to help prevent it from being accurately traced. The mixing service takes a commission from the crypto deposited, and after it is “mixed,” it will send it to another wallet address owned by…
Healthcare giant Henry Schein hit twice by BlackCat ransomware
American healthcare company Henry Schein has reported a second cyberattack this month by the BlackCat/ALPHV ransomware gang, who also breached their network in October. Henry Schein is a Fortune 500 healthcare products and services provider with operations and affiliates in 32 countries and a revenue of over $12 billion reported in 2022. It first disclosed on October 15 that it had to take some systems offline to contain another cyberattack that impacted its business one day before. More than a month…
Welltok data breach exposes data of 8.5 million US patients
Healthcare SaaS provider Welltok is warning that a data breach exposed the personal data of nearly 8.5 million patients in the U.S. after a file transfer program used by the company was hacked in a data theft attack. Welltok works with health service providers across the U.S., maintaining online wellness programs, holding databases with personal patient data, generating predictive analytics, and supporting healthcare needs like medication adherence and pandemic response. Earlier this year, the Clop ransomware gang exploited a zero-day vulnerability in…
Hacktivists breach U.S. nuclear research lab, steal employee data
The Idaho National Laboratory (INL) confirms they suffered a cyberattack after ‘SiegedSec’ hacktivists leaked stolen human resources data online. INL is a nuclear research center run by the U.S. Department of Energy that employs 5,700 specialists in atomic energy, integrated energy, and national security. The INL complex extends over an 890-square-mile (2,310 km2) area, encompassing 50 experimental nuclear reactors, including the first ones in history to produce usable amounts of electricity and the first power plant designed for nuclear submarines….