
Industry News: ESG5

    Know Your Breach: U.S. Securities and Exchange Commission

    The target: The SEC's EDGAR filing system

    The take: Nonpublic 'test filings' containing earning results and other material data were obtained and used to make profitable securities trades before the information was publicized. Seven individuals and two organizations were recently charged by the SEC in connection with the hack and are reported to have profited to the tune of $4.1M from the scheme.

    The attack vector: An undisclosed software vulnerability reportedly allowed attackers to bypass the system's authentication controls.

    Find out more...

    Know Your Breach: Germany

    The target: The German Government. 

    The take: The personal data of hundreds of politicians in Germany were exposed. The hacked data includes contacts’ email addresses, private chats, mobile numbers, photographs and credit card details, which were all published on Twitter.

    The attack vector: The prime suspect in the case indicated that he had acted alone, and it is believed he would not have been able to obtain the personal data had it not been for his target's use of weak passwords on their personal accounts.

    Find out more...

    Know Your Breach: Starwood / Marriott

    The target: The reservation database for Marriott hotel chain’s recently acquired Starwood subsidiary was compromised from 2014 until September of 2018.

    The take: 170 million customers had only names, addresses & e-mail addresses stolen, while 327 million more lost some combination of name, home address, e-mail, date of birth, gender, and passport numbers. Marriott have confirmed that over 5 million unencrypted passport numbers were accessed by attackers.

    The attack vector: It is suspected that the merging of information systems after the Starwood acquisition created the vulnerabilities that were exploited by suspected state actors. Marriott hotels are often the preferred hotel of US government and military officials.

    Find out more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates