In this weekly blog, we’ll compile the top cyber news you need to know from the week before and provide an easy breakdown so you can get the news you need and skip the fluff you don’t.
UK’s National Health Service Issues Urgent Request for O+ and O- Blood Types Following Cyber Attack
The United Kingdom’s National Health Service is recovering from a ransomware attack on June 3rd. Hackers targeted a key pathology service provider, creating major diagnostic gaps. London hospitals serve roughly two million people, prompting them to cancel all cancer surgeries, blood transfusions, and even organ transplants. As matching patients’ blood type at the same frequency as usual isn’t possible, stock of O positive and O negative blood are low. This is prompting the nation-wide request for 0 blood type donors to donate blood across the nation.
What You Need to Know:
According to the FBI’s 2023 Internet Crime Report released in March of this year, the healthcare sector experienced more critical infrastructure attacks than any other sector in 2023. Ransomware attacks led the charge, with an 130% increase.
Implications:
Cyberattacks aren’t just targeting “the big guys.” Rural health clinics top targets for cyberattacks, as they are often the only healthcare options for miles in the communities they serve. This pressure means they are more likely to pay if hit by ransomware attacks. Microsoft announced on Monday, June 10th the launch of a new cybersecurity program to support hospitals for the more than 60 million Americans living in rural areas.
New York Times Source Code and Data Stolen
Threat actors used an exposed internal GitHub token to hijack 273 GB worth of data. The 4chan forum, where the code was leaked on Thursday, June 6, claimed it contained “basically all source code belonging to The New York Times Company, 270GB.” The post included a claimed 3.6 million total files distributed in 6,223 folders, including IT documentation, infrastructure tools, and source code. NYT states “The underlying event related to yesterday’s posting occurred in January 2024 when a credential to a cloud-based third-party code platform was inadvertently made available…There is no indication of unauthorized access to Times-owned systems nor impact to our operations related to this event. Our security measures include continuous monitoring for anomalous activity.”
What You Need to Know:
The breach occurred due to the compromise of third-party, cloud-based code platform’s credentials. Read: the cloud-based storage provider got breached.
Implications:
It’s not new news that many large companies utilize third-party vendors for cloud storage, much like Amazon Web Services provides cloud services for over 7,500 federal government agencies. What agencies need to be vigilant of, however, is that the providers they are working with are focused on security as well as storage.
Hacker Sp1d3r Claims Compromised Data from 190 Million People in Snowflake/LendingTree Breach
Threat actor Sp1d3r is allegedly selling the data belonging to Quote Wizard, a subsidiary of Lending Tree, for a cool $2,000,000. The breach is said to contain the data for more than 190 million people, including 3 billion track pixel data containing email, PII, and IP for online tracking. This also potentially includes driving records, personal background information about their insurance quotes, and more. The breach also snagged data for Advance Auto Parts, pulled from the same Snowflake cloud storage environment.
What You Need to Know:
Cloud storage can be a very secure place for your storage needs, as long as adequate security protocols as are in place. When you use a third-party cloud storage vendor, the vendor, not you, is responsible for keeping that data safe. That means the vendor you trust must protect your data like their own – because legally, it is.
Implications:
Your cloud vendor needs to:
- Use strong passwords
- Use multi-factor authentication
- Regularly backup your data
- Monitor access controls and remove unnecessary privileges
Notice I didn’t include encryption on the list. Encryption of cloud storage is the provider’s duty only if the cloud storage is actively managed. If it is self-managed, we as an MSSP can manage the security of your storage for you. If you’re interested in pursuing secured, monitored cloud storage for your business, let’s talk. Schedule a conversation with one of our solutions engineers here.
Genetic Testing Firm 23andMe Under Investigation for October 2023 Breach
Genetic testing giant 23andMe is back in hot water. Data watchdogs and regulators in the UK and Canada announced they will proceed with investigating the company over a data breach in October of 2023. The breach was one of the largest for this niche, compromising data for nearly seven million people. This includes complete family trees, birth years, and geographic locations. In an eyebrow-raising comment, 23andMe stated, “We intended to cooperate with these regulators’ reasonable requests” (emphasis added). Like the healthcare sector at large, the burden of responsibility for health-related business is growing. According to the UK Information Commissioner’s Office, the data stored by 23andME “can reveal information about an individual and their family members, including their health, ethnicity, and biological relationships,” meaning it is “essential” for the public to be able to trust the service.
What You Need to Know:
The threat actors used password stuffing on 14,000 accounts, using email and password details previously exposed in other hacks.
Implications:
The investigation is examining the size of the hack, potential harm to users, if adequate safeguards were in place to prevent the breach, the report of the breach, and whether the firm followed the correct reporting processes for the UK and Canada. The legal burden of responsibility is adequate safeguards. This means in compliance with national standards and best practices.