Data Breach News, Healthcare
December 07, 2023
1397 views 2 mins 0

Nine Prime Healthcare hospitals affected by MOVEit breach

CBIZ KA is a third-party vendor for Prime Healthcare that was affected by the MOVEit breach. They have issued the following notice: CBIZ KA, a third-party vendor for Prime Healthcare (Prime), discovered a security incident involving CBIZ’s use of MOVEit Transfer software, which has recently reported a security vulnerability. Prime takes the responsibility of safeguarding […]

Data Breach News, Malware Ransomware, News
November 10, 2023
660 views 52 secs 0

Basically all of Maine had data stolen by a ransomware gang

Engadget reports: The state agencies of Maine had fallen victim to cybercriminals who exploited a vulnerability in the MOVEit file transfer tool, making them the latest addition to the growing list of entities affected by the massive hack involving the software. In a notice the government has published about the cybersecurity incident, it said the event impacted […]

Data Breach News, Finance
October 09, 2023
799 views 2 secs 0

Flagstar Bank third-party breach affects more than 800,000 customers

Bleeping Computer reports Flagstar Bank in Michigan is notifying 837,390 customers whose personal information, including Social Security numbers, was acquired by the Clop hacking gang in May. The breach was not of Flagstar’s systems but at FISERV, a vendor they use for payment processing and mobile banking services. FISERV was one of thousands of entities […]

Data Breach News, Education Sector
September 26, 2023
729 views 25 secs 0

MOVEit fallout continues: National Student Clearinghouse discloses for 900 schools affected

The figures for the MOVEit data breach continue to rise to alarming heights. The Record reports: The National Student Clearinghouse (NSC) reported that nearly 900 colleges and universities across the U.S. had data stolen during attacks by a Russia-based ransomware gang exploiting the popular MOVEit file-sharing tool. The nonprofit manages educational reporting, data exchange, verification, […]

Data Breach News
September 18, 2023
883 views 48 secs 0

Victims of MOVEit breach continue to emerge

One of the biggest breaches of 2023 involves the 0-day attack by Clop threat actors on file transfer software called MOVEit by Progress Software. The attack was launched in May and June. It affected more than 1,100 entities and more than 56 million people according to statistics compiled by Emsisoft. One of the most recent […]

Data Breach News, News
September 11, 2023
1711 views 16 secs 0

Dissecting the MOVEit breach: Lessons learned from the ransomware attack

The MOVEit data breach, discussed in an earlier post, continues to make headlines. As SDX reports: Orchestrated by ransomware gang CL0P exploiting a zero-day vulnerability, it is now considered one of the largest hacks of 2023 — and potentially in recent history. To date, it is known to have impacted more than 1,150 organizations and nearly 56 million individuals, […]

Data Breach News
August 31, 2023
815 views 1 sec 0

MOVEit Was a SQL Injection Accident Waiting to Happen

Omkhar Arasaratnam writes that the same type of attack that took advantage of poor security in 1998 is still taking advantage of poor security in 2023. He writes: SQL injection — among the lowest hanging of security fruit — is still included in the Open Worldwide Application Security Project (OWASP) Top 10 list of security […]

News, New Threats
August 27, 2023
6990 views 7 mins 0

Etiology of a Breach

Most data breaches involve some level of victim human error, which theoretically employee training can address.  Human error can take the form of clicking on a link, where the email address of the sender is unknown to the person clicking on the link.  Malware then enters the scene.  Another common human error scenario involves phishing […]