January 5 2021 — On behalf of President Trump, the National Security Council staff has stood up a task force construct known as the Cyber Unified Coordination Group (UCG), composed of the FBI, CISA, and ODNI with support from NSA, to coordinate the investigation and remediation of this significant cyber incident involving federal government networks….
Category: Commentaries and Analyses
“Without Undue Delay, Part 1:” Update on earlier ransomware cases
In November, DataBreaches.net published a commentary arguing that patients need to be notified sooner of ransomware dumps even if HIPAA would seem to allow up to 60 days. As a companion to that piece, this site looked at 30 claimed ransomware attacks on U.S. healthcare entities that had been revealed on dedicated leak sites by…
Attacks targeting healthcare organizations spike globally as COVID-19 cases rise again– Researchers
Check Point writes: At the end of October 2020, we reported that hospitals and healthcare organizations had been targeted by a rising wave of ransomware attacks, with the majority of attacks using the infamous Ryuk ransomware. This followed a Joint Cybersecurity Advisory issued by the CISA, FBI and HHS, which warned of an increased and imminent cybercrime threat to US hospitals…
Apex Laboratory confirms ransomware attack; only recently discovered data theft
DataBreaches.net recently reported that Apex Laboratory Inc. had apparently been attacked by DoppelPaymer ransomware threat actors. Apex was added to their leak site on December 15. As proof of claims, the threat actors uploaded approximately 10,000 files containing protected health information of patients (PHI) and personally identifiable information of employees (PII). The 10,000 estimate is…
Bittrex To Delist Privacy Coins Monero, ZCash and Dash in Two Weeks
Decrypt.co reports: Crypto exchange Bittrex today announced that it will delist privacy coins Monero (XMR), ZCash and Dash on Friday, January 15, at 23:00 UTC. The Bermuda-registered exchange did not provide a reason for the delistings, but all three are privacy coins—a class of cryptocurrencies that offer untraceable transactions. Monero is private by default, and…
ROMWE’s press release reflects an abundance of …. something, but not caution.
This week, I drafted a commentary mocking ROMWE’s for claiming that they were notifying their consumers about a breach out of “an abundance of caution.” Then I decided to try to be nice, and I trashed it. Yesterday, Marco de Felice wrote a piece about the breach that shows that it was even worse than…