Cyber Security Intelligence reports: Cyber security experts have recently revealed the top six government impersonation scams they have removed from the Internet in 2022 as they urged the public to remain vigilant to cyber crime in 2023. The scams unveiled by the National Cyber Security Centre (NCSC), part of GCHQ, included phishing emails and messages from cyber criminals…
Category: Phishing
WA: Therapist notifies clients after tricked by a hacker
Some breaches may be more embarrassing to admit to than others. Kudos to this therapist for forthrightly informing the Washington state attorney general what happened: I am writing to advise you of a computer data breach, which occurred from December 2 to December 4, 2022. I was contacted by a person representing himself as an…
Lawsuits come, lawsuits go (settle), Friday edition
Three more recent announcements of lawsuit settlements involving healthcare entities. Two of the following involve ransomware and Massachusetts entities; the third is a phishing attack on an Arkansas entity. North Shore Pain Management and Resolve I.T. North Shore Pain Management has set aside $200,000 to settle a class action lawsuit that claimed the company and…
Disneyland Malware Team: It’s a Puny World After All
Brian Krebs reports: A financial cybercrime group calling itself the Disneyland Team has been making liberal use of visually confusing phishing domains that spoof popular bank brands using Punycode, an Internet standard that allows web browsers to render domain names with non-Latin alphabets like Cyrillic. The Disneyland Team uses common misspellings for top bank brands in its domains….
A state-appointed receiver is investigating a phishing scam that drained $400K from Chester’s coffers
Vinny Vella reports: A phishing scam siphoned more than $400,000 from Chester in June, and the state-appointed receiver who is handling the beleaguered city’s finances wants to know why his office wasn’t notified until two weeks ago. In a memo sent to Mayor Thaddeus Kirkland and Chester’s city council on Monday, Michael T. Doweary said…
Robin Banks phishing service returns to steal banking accounts
Bill Toulas reports: The Robin Banks phishing-as-a-service (PhaaS) platform is back in action with infrastructure hosted by a Russian internet company that offers protection against distributed denial-of-service (DDoS) attacks. Robin Banks faced operational disruption in July 2022, when researchers at IronNet exposed the platform as a highly threatening phishing service targeting Citibank, Bank of America, Capital One, Wells…