shutterstock_490960141-1

Industry News: ESG5

    Delta Launches $500 Million Lawsuit Against CrowdStrike

    2024-10-28

    Dark Reading: Delta Air Lines is suing CrowdStrike to recover the $500 million in revenue it lost due to the CrowdStrike outage earlier this year, which led to an assortment of issues and disrupted businesses, airlines, healthcare providers, and more.

    Read more...

    Cyber Startup Armis Security Raises $200 Million At $4.2 Billion Valuation

    2024-10-28

    Crunchbase: Cybersecurity firm Armis Security closed a $200 million Series D led by Alkeon Capital and General Catalyst. The round boosts the company’s valuation nearly 25% to $4.2 billion. The San Francisco-based startup last raised  a $300 million private equity round in 2021 led by One Equity Partners at a $3.4 billion valuation.

    Read more...

    Know Your Breach: Transak

    The Target: One of the largest cryptocurrency infrastructure providers, Transak serves nearly six million users across 160 countries and 46 U.S. states.

    The Take: Names, birthdays, passports, driver’s license information and user selfies were leaked in the breach.

    The Vector: A “sophisticated phishing attack” granted the attacker access to an unnamed know-your-customer vendor Transak uses for document scanning and verification.

    As phishing actors continue to explore every potential abuse opportunity on legitimate service providers, novel security gaps constantly threaten to expose users to severe risks. It is essential not to rely solely on email protection solutions, and also scrutinize every email that lands on your inbox, look for inconsistencies, and double-check all claims made in those messages.

    Read more...

    CISA Proposes New Security Requirements for Businesses Exposed to Cyber Espionage

    2024-10-23

    CSO Online: The US Cybersecurity Infrastructure Security Agency (CISA) has proposed a set of security requirements to be fulfilled by organizations running sensitive business transactions with states posing national security and foreign policy threats to the US.

    Read more...

    Sophos Buys Secureworks for $859 Million to Beef Up Cybersecurity Portfolio

    2024-10-22

    MSN: Thoma Bravo-backed cybersecurity firm Sophos said it would acquire Secureworks from Dell Technologies for $859 million in cash to strengthen its product lineup for enterprise customers.

    Read more...

    Cybersecurity Firm Socket Raises $40 Million With Backing From Bret Taylor, Jerry Yang

    2024-10-22

    Yahoo Finance: Cybersecurity services provider Socket said it has raised $40 million in a mid-stage round from a host of existing and new investors, including OpenAI Chairman Bret Taylor, Yahoo Co-Founder Jerry Yang and Shopify CEO Tobias Lutke.

    Read more...

    SEC Accuses Four Firms of Downplaying SolarWinds-Related Hacks

    2024-10-22

    BNN Bloomberg: Four hacked companies will pay a total of almost $7 million to settle US Securities and Exchange Commission allegations that they downplayed the significance of the cyberattacks, the latest fallout from the massive SolarWinds Corp. breach.

    Read more...

    Cybersecurity in Healthcare: How Hackers Get in and How Organizations Can Protect Themselves

    2024-10-21

    Yahoo Finance: As technology advances at a rapid pace, even the most sophisticated organizations struggle to keep up — especially when it comes to cybersecurity. 

    Read more...

    Know Your Breach: MoneyGram

    The Target: U.S. money transfer giant MoneyGram.

    The Take: The stolen customer data includes names, phone numbers, postal and email addresses, dates of birth, and national identification numbers. The data also includes a “limited number” of Social Security numbers and government identification documents, such as driver’s licenses and other documents that contain personal information, like utility bills and bank account numbers.

    The Vector: BleepingComputer first reported that MoneyGram was breached through a social engineering attack on its IT help desk where threat actors impersonated an employee. Once they gained access to the network, the threat actors initially targeted the Windows active directory services to steal employee information.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    Fidelity Says Data Breach Exposed Personal Data of 77,000 Customers

    2024-10-10

    TechCrunch: Fidelity Investments, one of the world’s largest asset managers, has confirmed that over 77,000 customers had personal information compromised during an August data breach, including Social Security numbers and driver’s licenses.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates