Cyber Criminals Targeting Websites to Steal Private Consumer Information and Use for Benefits Fraud Regulated Entities Are Advised to Review Security Controls for Public-Facing Websites The New York State Department of Financial Services (“DFS”) today issued a cybersecurity fraud alert (“Alert”) to all of its regulated entities. The Alert describes a widespread cybercrime campaign to steal consumers’ nonpublic information (“NPI”) from…
Category: U.S.
Jones Day disputes claimed breach; points to hacked vendor; hacker points back to them (UPDATE2)
Although Jones Day failed to respond to multiple inquiries sent to it by this site about a ransomware attack claimed by CLOP threat actors*, the giant law firm apparently responded to inquiries by the Wall Street Journal. Their statement, however, omits important information and has been disputed by the threat actors. WSJ reports, in part:…
Could an ex-employee be planting ransomware on your firm’s network?
We’ve all seen too many instances where vengeful former employees have tried to sabotage their former employer’s network. Even when their employers remember to revoke access for the individual, they often find other ways in — like using a former colleague’s credentials or having previously created another user on the system with credentials. But would…
Preliminary settlement approved in 21st Century Oncology 2015 breach case
Long-time readers may remember that 21st Century Oncology had a slew of serious problems going back to 2013 including a rogue employee-related breach that they were alerted to by law enforcement, and litigation under the False Claims Act that resulted in them paying $34.7 million for billing for medically unnecessary tests. But of note, in…
Threat actors claim to have stolen Jones Day files; law firm remains quiet
Over on AdvIntel, Tyler Combs has a post about threat actors attacking law firms. Many of us are already aware of a number of law firms who have been attacked and who have had their firm’s files dumped publicly when they refused to pay ransom demands, but if the biggest law firms fall prey, what…
NC: Central Piedmont Community College impacted by ransomware attack
Central Piedmont Community College experienced a ransomware attack that they first disclosed on February 10. Here is their most recent update: Central Piedmont Community College has experienced a ransomware attack, which was discovered Wednesday evening, Feb. 10. The college’s Information Technology Services (ITS) staff worked tirelessly through the night to take the college’s critical systems…