Cathy Bussewitz of AP reports: The operator of the nation’s largest fuel pipeline confirmed it paid $4.4 million to a gang of hackers who broke into its computer systems. Colonial Pipeline said Wednesday that after it learned of the May 7 ransomware attack, the company took its pipeline system offline and needed to do everything…
Category: Commentaries and Analyses
Despite an alert from NYS DFS, some insurance companies with “instant quote” portals were victimized
On February 16, the NYS Department of Financial Services issued a cybersecurity fraud alert involving public-facing web sites where consumers could request “instant quotes” for car insurance or other products. The alert warned insurers that private information used to prefill requests was being stolen and misused for pandemic unemployment benefits fraud. At the time, they…
NY: Filters Fast Settles Charges Stemming from Failure to Patch Critical Vulnerability Exploited in 2019 Data Breach
In 2019, Filters Fast experienced a data breach when a threat actor exploited a plugin vulnerability in vBulletin. Using SQL injection, the attacker was able to obtain consumers’ cardholder names, billing addresses, expiration dates, validation codes, and primary account numbers for purchases made between June, 2019 and July, 2020. Filters Fast did not detect any…
Update to Sincera Reproductive Medicine (formerly known as Abington Reproductive Medicine) ransomware incident
On November 8, 2020, in a report called “Without Undue Delay,” DataBreaches.net noted that Maze threat actors had a listing on their dedicated leak site for “Abington Reproductive Medicine.” The proof of claim that they posted, though, was not from Abington Reproductive, leaving us confused as to whether Abington Reproductive had really been a victim…
Apex America hit by Sodinokibi ransomware
Apex America describes itself as a leading Digital Customer Experience services company in Latin America that partners with more than 50 global brands. It has operational centers in 14 locations in Latin America. That’s how they describes themselves. The threat actors known as REvil (Sodinokibi) describe them as targets who have so far refused to pay…
Russian-language hacking forum bans ransomware-related ads
XSS forum, one of the two most popular Russian-language forums with sites on clearnet and Tor, has announced that it is now banning ransomware-related ads. No more ransom! Friends, on our forum lockers (Ransomware) and everything connected with them are prohibited . Namely: Ransomware affiliate programs; Ransomware rental; sale of lockers (ransomware software); All topics matching this rule will be…