shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Ellington Management Group

    The Target: Investment management firm Ellington Management Group L.L.C.

    The Take: Ellington determined that the following general categories of information may have been involved in the incident but are not relevant to every individual impacted: name, date of birth, Social Security number, medical information, and driver’s license number. In only three instances, non-Ellington financial account information may have been impacted.

    The Vector: Ellington’s investigation determined that between July 18, 2023 and August 8, 2023, an unauthorized actor had access to a single Ellington email account for the demonstrated purpose of sending phishing emails. Ellington analyzed the email account and did not find any evidence of any data being downloaded, emails being forwarded, or the account being synced to other systems.

    As phishing actors continue to explore every potential abuse opportunity on legitimate service providers, novel security gaps constantly threaten to expose users to severe risks. It is essential not to rely solely on email protection solutions, and also scrutinize every email that lands on your inbox, look for inconsistencies, and double-check all claims made in those messages.

    Read more...

    How US SEC Legal Actions Put CISOs At Risk And What To Do About It

    2023-11-16

    CSO: With the US Securities and Exchange Commission (SEC) having taken legal action against CISOs at both SolarWinds and Uber, security executives feel the pressure to be absolutely precise when writing up security incidents that the company has decided are material. 

    Read more...

    How To Strengthen Your Business's Cybersecurity Practices

    2023-11-15

    Forbes: Most of you have heard a lot in the past month about cybersecurity, hacking attacks and many words that are strange to us, like man in the middle ("MITM") phishing, spoofing, LifeLock, blueprinting, fingerprinting, crypto locker, VPN and so on, in the news and from media ads.

    Read more...

    Barclays Flags Treasuries Central Clearing Cybersecurity Risks After ICBC Hack

    2023-11-15

    Yahoo Finance: A key reform proposed by the U.S. Securities and Exchange Commission to boost the use of central clearing for U.S. Treasuries could leave the market more exposed to cybersecurity risks, Barclays said, referring to the cyber hack of Industrial and Commercial Bank of China's U.S. broker-dealer.

    Read more...

    Vulcan Cyber, Which Scans Software For Security Vulnerabilities, Lands $55 Million Cash Infusion

    2023-11-15

    TechCrunch: Vulcan Cyber, a company developing software to help enterprises detect vulnerabilities in their software stack, announced that it raised $55 million in equity financing led by Maor Investments and Ten Eleven Ventures with participation from Dawn Capital and Wipro Ventures.

    Read more...

    Cybersecurity Spending Surges Amid AI Threat Concerns

    2023-11-15

    Investing.com: OpenText, a global leader in information management, released its annual Cybersecurity Global Ransomware Survey, revealing significant trends in cybersecurity among small and medium-sized businesses (SMBs) and enterprises.

    Read more...

    Esma Makes Cyber-Risk Its Top Priority

    2023-11-13

    FundsTech: Europe’s main securities regulator has elevated cyber risk and digital resilience to the top of its supervisory authorities for the coming year.

    Read more...

    More Than Half of ASIC Regulated Organizations Can’t Protect Confidential Information

    2023-11-12

    CSO: A cybersecurity self-assessment of 697 Australian organizations revealed 58% have limited or no capability to protect confidential information adequately.

    Read more...

    Know Your Breach: Hilb Group

    The Target: Hilb Group, a business that handles property, casualty, and employee benefits insurance and advisory services at more than 130 locations across 22 US states.

    The Take: People's first and last names and sensitive financial data and credentials. Specifically, Financial Account Number or Credit/Debit Card Number (in combination with security code, access code, password or PIN for the account).

    The Vector: Hilb says it discovered "suspicious activity" related to employee email accounts around January 10. After doing some digging, and bringing on a third-party incident response firm, the insurance brokerage determined someone broke into those inboxes between December 1, 2022 and January 12, 2023.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    OpenAI Suggests Cyber-Attackers Behind Persistent ChatGPT Outage

    2023-11-09

    BNN Bloomberg: OpenAI is grappling with “abnormal traffic” that suggests hackers are trying to swamp its services, revealing for the first time the potential cause of outages that’ve plagued ChatGPT this week.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates