Tag Archive for: extent

Extent Of Ransomware Hack Of Attorney General Remains Uncertain


CHICAGO — Illinois Attorney General Kwame Raoul’s admitted for the first time this week that his office — which often advises people on ways to protect themselves from identity theft and fraud — had suffered a ransomware attack earlier this month, exposing the personal data of an as-yet-unknown number of residents.



Kwame Raoul wearing a suit and tie: Illinois Attorney General Kwame Raoul said his office was working closely with federal law enforcement and technology experts to figure out how it was sacked and "what we can do to ensure that such a compromise does not happen again."


© AP Photo/Seth Perlman, File
Illinois Attorney General Kwame Raoul said his office was working closely with federal law enforcement and technology experts to figure out how it was sacked and “what we can do to ensure that such a compromise does not happen again.”

Three days after the April 10 discovery of the hack, Raoul issued a statement saying his office’s networks had been compromised to an unknown extent.

Loading...

Load Error

On April 21, several gigabytes of files apparently taken from the attorney general’s office were uploaded to a dark web website called Dopple Leaks, which contains “private data of the companies which were hacked by DoppelPaymer,” a ransomware gang.

“This companies decided to keep the leakage secret. And now their time to pay is over,” the website says. It claims about 200 gigabytes of “confidential information will be progressively uploaded.”

On Thursday, Raoul’s office issued a public notification of the hack, which described the breach as a “ransomware attack that has compromised the office’s network.”

State law requires businesses and institutions to notify residents when their information has been compromised by a data breach, so the attorney general’s office posted a public notice saying officials were unaware what was stolen.

But it noted the hacked material could include the names, addresses, social security numbers, account numbers, health insurance, tax, medical, driver’s license and “other such information as necessary,” according to the notice.

“While we do not yet know with certainty what was compromised in the ransomware attack, we are working closely with federal law enforcement authorities and outside technology experts to determine what information was exposed, how this happened, and what we can do to ensure that such a compromise does not happen again,” Raoul said in the…

Source…

FireEye Cyber Attack Shows the Extent and the Very Real Threat of Cyber Warfare


FireEye, a $3.5 billion cyber security giant, has disclosed that it was recently targeted with a massive, specialised and highly sophisticated cyber attack. The attack is said to have been specifically tailored to breach FireEye’s own defences, and included highly sophisticated techniques that FireEye claims had so far not been seen before in the usual swarm of cyber attacks that occur every day. Given that FireEye is one of the world’s biggest cyber security firms, that inference is cause for concern.

ALSO READ | Covid-19 Vaccine Research in India, Abroad Bombarded by North Korean, Russian Hackers

What the hack took

Compounding on the threat, FireEye CEO Kevin Mandia further states that after studying the hack’s forensics, the company has concluded that this activity was enforced by a nation state-backed hackers, who were very specific, highly advanced and purpose-driven in their attack. “The attackers tailored their world-class capabilities specifically to target and attack FireEye. They are highly trained in operational security and executed with discipline and focus. They operated clandestinely, using methods that counter security tools and forensic examination. They used a novel combination of techniques not witnessed by us or our partners in the past,” Mandia adds.

The hack targeted the FireEye Red Team hacking tools, which are typically used in conjunction with a honey pot to assess evolving and zero-day security threats. Such tools are often designed to soak-test enterprise security, and given FireEye’s extensive clientele, raised cause for significant concern. On this note, Mandia adds, “we are proactively releasing methods and means to detect the use of our stolen Red Team tools.

“We are not sure if the attacker intends to use our Red Team tools or to publicly disclose them. Nevertheless, out of an abundance of caution, we have developed more than 300 countermeasures for our customers, and the community at large, to use in order to minimize the potential impact of the theft of these tools. We have seen no evidence to date that any attacker has used the stolen Red Team tools. We, as well as others in the security community, will continue to monitor for any…

Source…

China blasts CIA after WikiLeaks reveals extent of agency’s hacking abilities – Washington Times


Washington Times

China blasts CIA after WikiLeaks reveals extent of agency's hacking abilities
Washington Times
Cybersecurity proved to a contentious issue under former President Barack Obama's administration with respect to his relationship with China. The Justice Department charged five members of the Chinese military with cyber espionage in 2014, and Chinese …

and more »

Espionage China – read more

Computer Security Expert: We May Still Not Know The Full Extent Of The Recent … – WXXI News


WXXI News

Computer Security Expert: We May Still Not Know The Full Extent Of The Recent
WXXI News
We may still not know the extent of how many people potentially were affected by the cyber attack that hit Excellus BlueCross BlueShield and its affiliated companies. That's the feeling of a computer security expert at the University at Buffalo, Arun
Excellus records hacked; 10.5 million records affectedRochester Democrat and Chronicle

all 159 news articles »

“computer security” – read more