shutterstock_490960141-1

Industry News: ESG5

    SEC Accuses Four Firms of Downplaying SolarWinds-Related Hacks

    2024-10-22

    BNN Bloomberg: Four hacked companies will pay a total of almost $7 million to settle US Securities and Exchange Commission allegations that they downplayed the significance of the cyberattacks, the latest fallout from the massive SolarWinds Corp. breach.

    Read more...

    Cybersecurity in Healthcare: How Hackers Get in and How Organizations Can Protect Themselves

    2024-10-21

    Yahoo Finance: As technology advances at a rapid pace, even the most sophisticated organizations struggle to keep up — especially when it comes to cybersecurity. 

    Read more...

    Know Your Breach: MoneyGram

    The Target: U.S. money transfer giant MoneyGram.

    The Take: The stolen customer data includes names, phone numbers, postal and email addresses, dates of birth, and national identification numbers. The data also includes a “limited number” of Social Security numbers and government identification documents, such as driver’s licenses and other documents that contain personal information, like utility bills and bank account numbers.

    The Vector: BleepingComputer first reported that MoneyGram was breached through a social engineering attack on its IT help desk where threat actors impersonated an employee. Once they gained access to the network, the threat actors initially targeted the Windows active directory services to steal employee information.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    Fidelity Says Data Breach Exposed Personal Data of 77,000 Customers

    2024-10-10

    TechCrunch: Fidelity Investments, one of the world’s largest asset managers, has confirmed that over 77,000 customers had personal information compromised during an August data breach, including Social Security numbers and driver’s licenses.

    Read more...

    Man Pleads Guilty to Stealing $37 Million in Crypto From 571 Victims

    2024-10-06

    Bleeping Computer: A 21-year-old man from Indiana named Evan Frederick Light pleaded guilty to stealing $37,704,560 worth of cryptocurrency from 571 victims in a 2022 cyberattack.

    Read more...

    Know Your Breach: ScienceLogic

    The Target: ScienceLogic SL1 (formerly EM7) is an IT operations platform for monitoring, analyzing, and automating an organization's infrastructure, including cloud, networks, and applications.

    The Take: The hackers exploited the zero-day to gain access to web servers and steal limited customer monitoring data, including customer account names and numbers, customer usernames, Rackspace internally generated device IDs, device name and information, IP addresses, and AES256 encrypted Rackspace internal device agent credentials.

    The Vector: Threat actors exploited a zero-day vulnerability in a third-party tool used by the ScienceLogic SL1 platform.

    This breach is critical reminder that zero-day exploits do happen, and furthermore that patching software in a timely, effective manner is a key component of ensuring customer data is protected. Ensuring third-party vendors are deploying patches and fixes in accordance with a firm’s cybersecurity policy is an important step in an overall robust security posture.

    Read more...

    Darktrace Announces Formal Completion of its Acquisition by Thoma Bravo

    2024-10-01

    Dark Reading: Darktrace, a global leader in cybersecurity AI, has announced the completion of its acquisition by Thoma Bravo, a leading software investment firm, for $5.3bn. The recommended cash acquisition was announced on 26 April 2024 and the Scheme of Arrangement has now become effective. 

    Read more...

    Ransomware Attacks Surge Despite International Enforcement Effort

    2024-10-01

    Cybersecurity Dive: The number of ransomware attacks hitting U.S. and international organizations continues to climb, despite an extensive and growing effort to reduce the volume and impact of these attacks, U.S. cyber authorities said.

    Read more...

    Cybersecurity M&A Balloons as Breach Danger Builds

    2024-10-01

    Chief Investment Officer: Mergers and acquisitions are up this year for firms providing cybersecurity tools and services, amid heightened attacks by criminals and increased use of artificial intelligence to counter the bad guys.

    Read more...

    Cyber Attacks Causing Reputational Damages: CIRA

    2024-10-01

    BNN Bloomberg: As the number of cyber-attacks has risen in recent years, a new survey finds that the incidents are leading to reputational damages amongst impacted organizations. The Canadian Internet Registration Authority (CIRA) released the results of its latest annual Cyber Security Survey.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates