Category: Cyber-Crime

Toronto Public Library outages caused by Black Basta ransomware attack

The Toronto Public Library is experiencing ongoing technical outages due to a Black Basta ransomware attack. The Toronto Public Library (TPL) is Canada’s largest public library system, giving access to 12 million books through 100 branch libraries across the city. The library system has 1,200,000 registered members and operates on a budget that surpasses $200M. Earlier this week, TPL warned…

Unprecedented Cyber Breach via MOVEit Software Rattles Multiple Sectors

In a devastating cyberattack that unfolded over three days in May 2023, numerous victims fell prey to a large-scale intrusion. The attackers exploited a vulnerability in MOVEit, a managed file transfer software, sending shockwaves across various sectors. Government agencies, airlines, educational institutions, financial organizations, and healthcare providers found themselves in the crosshairs of this breach. The attackers absconded with sensitive…

Russian Hackers Accessed 632,000 Emails From Pentagon, Other Agencies: Report

Hackers have accessed approximately 632,000 emails from the Department of Defense and other federal agencies this year, the US Office of Personnel Management (OPM) confirmed. The report detailed a large-scale cyberattack in May 2023 in which emails from US government offices, private sectors, airlines, and academic entities were accessed by a suspected Russian group called “CL0P.” Alongside electronic personal data,…

Cyberattacks Slam Israel After Hamas Surprise Assault

Israel has incurred several cyberattacks following the large-scale surprise attack by Palestinian militant group Hamas. Among the recorded incidents was an attack on the country’s services and government information website, resulting in the portal’s connectivity failure. It was claimed by hacktivists called Killnet, a pro-Russian cyber group that gained notoriety after Moscow’s 2022 invasion of Ukraine. “Israeli government, you are…

MGM didn’t pay up after hackers broke into its system and stole customer data

The Wall Street Journal wrote on Thursday that MGM Resorts International didn’t pay the ransomware attackers who broke into its systems last month, forcing the company to shut down systems at several of its hotels and casinos. The hack kept many waiting to check into their rooms, including FTC chair Lina Kahn, who was in Las Vegas, Nevada to attend…

Genetics firm 23andMe says user data stolen in credential stuffing attack

23andMe has confirmed to BleepingComputer that it is aware of user data from its platform circulating on hacker forums and attributes the leak to a credential-stuffing attack. 23andMe is a U.S. biotechnology and genomics firm offering genetic testing services to customers who send a saliva sample to its labs and get back an ancestry and genetic predispositions report. Recently, a threat…

Israeli President Targeted by Cyber Attack

The Telegram channel of Israeli President Isaac Herzog was briefly hacked before being “very swiftly” restored, his spokesman said on Thursday. The breach on Wednesday evening was thought to be “criminal in nature,” the spokesman said, suggesting it was not linked to a foreign power or tied to the Israeli-Palestinian conflict. “Initial checks show no concern that information was obtained,”…

Warning: 100,000 industrial control systems exposed online

About 100,000 industrial control systems (ICS) were found on the public web, exposed to attackers probing them for vulnerabilities and at risk of unauthorized access. Among them are power grids, traffic light systems, security and water systems. Exposed ICSs include units (sensors, actuators, switches, building management systems, and automatic tank gauges) for critical infrastructure systems. Cybersecurity company BitSight alerted of the…

The Group Claiming To Have Hacked Sony Is Using GDPR As A Weapon For Demanding Ransoms

Unintended Consequences We’ve spilled a great deal of ink discussing the GDPR and its failures and unintended consequences. The European data privacy law that was ostensibly built to protect the data of private citizens, but which was also expected to result in heavy fines for primarily American internet companies, has mostly failed to do either. While the larger American internet…

Microsoft breach led to theft of 60,000 US State Dept emails

Chinese hackers reportedly stole tens of thousands of emails from U.S. State Department accounts after breaching Microsoft’s cloud-based Exchange email platform in May. During a recent Senate staff briefing, U.S. State Department officials disclosed that the attackers stole at least 60,000 emails from Outlook accounts belonging to State Department officials stationed in East Asia, the Pacific, and Europe, as Reuters first…

Air Canada discloses data breach of employee and ‘certain records’

Air Canada, the flag carrier and the largest airline of Canada, disclosed a cyber security incident this week in which hackers “briefly” obtained limited access to its internal systems. According to the airline, the incident resulted in the theft of a limited amount of personal information of some of its employees and “certain records.” Customer data was not affected. Hackers “briefly”…

Airbus Hacker Threatens to Sell US, Europe Military Intel on Dark Web

The hacker behind the recent attack on Airbus has warned that he will sell US and European military intelligence on the dark web. Known by the moniker “USDoD,” the hacker said he recently managed to enter the company’s website by exploiting employee access from Turkish Airlines. He also immediately posted the stolen data on a hacker forum. In a lengthy…

US Homeland Security Reveals Guide to Enhance Cyber Incident Reporting

The US Department of Homeland Security (DHS) has introduced new recommendations to streamline the reporting of cyber incidents across the Department of Defense and 32 other federal agencies. The guide is expected to further protect the country’s vital infrastructure, reduce the burden on cybersecurity partners, and decrease the downtime of associated operations in each sector covered. The recommendations will also…

TransUnion denies it was hacked, links leaked data to 3rd party

Credit reporting firm TransUnion has denied claims of a security breach after a threat actor known as USDoD leaked data allegedly stolen from the company’s network. The Chicago-based company’s over 10,000 employees provide their services to millions of consumers and more than 65,000 businesses from 30 countries. “Immediately upon discovering these assertions, we partnered with outside cybersecurity and forensic experts…

War crimes tribunal ICC says it has been hacked

The International Criminal Court (ICC) said on Tuesday its computer system had been hacked, a breach at one of the world’s most high-profile international institutions and one that handles highly sensitive information about war crimes. The ICC said it had detected unusual activity on its computer network at the end of last week, prompting a response that was still ongoing….

Microsoft leaks 38TB of private data via unsecured Azure storage

The Microsoft AI research division accidentally leaked dozens of terabytes of sensitive data starting in July 2020 while contributing open-source AI learning models to a public GitHub repository. Almost three years later, this was discovered by cloud security firm Wiz whose security researchers found that a Microsoft employee inadvertently shared the URL for a misconfigured Azure Blob storage bucket containing the…