Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: MIDC

    The Target: MIDC, Maharashtra Industrial Development Corporation

    The Take: $68,000.00

    The Vector: A threat actor gained access to the firm’s CEO’s email account. With the compromised credentials, the attacker sent requests for fund transfers to an external account, to which the employees followed through.

    This breach is a stark reminder of not only the importance of credential hygiene and authentication, as well as reminders about access and how attackers will be able to act with all the powers the breached accounts give them, but also for social engineering. These types of attacks exploit our innate desire to do tasks quickly without stopping to consider the nature of the request. At all times, requests for information or monetary payments should be approached with caution and deliberate, thoughtful action.

    Read more...

    Cybersecurity Worries Draw C-Level Attention in Asia

    2022-08-31

    Business Wire: Enterprises in Singapore and Malaysia have grown so concerned about the dangers of cyberattacks that they are changing the way they make security-related decisions and procure cybersecurity services, according to a new research report published today by Information Services Group (ISG) (Nasdaq: III), a leading global technology research and advisory firm.

    Read more...

    Cybersecurity Ranked Most Serious Enterprise Risk in 2022

    2022-08-31

    Security Magazine: Uncertainty has become a business standard in 2022, with enterprise leaders feeling cautiously optimistic about their ability to navigate future economic, social and geopolitical uncertainty.

    Read more...

    UK Imposes Tough New Cybersecurity Rules for Telecom Providers

    2022-08-31

    Info Security: A new security framework for the UK’s telecommunications industry is set to come into effect in October, making the UK’s telecoms security regulations among the strongest in the world.

    Read more...

    Ellington Management Group, LLC Announces Data Breach Related to Compromised Employee Email Accounts

    2022-08-31

    JDSupra: On August 29, 2022, Ellington Management Group, LLC reported a data breach with the Montana Attorney General after the company learned that an unauthorized party had gained access to two employee email accounts.

    Read more...

    Remote Work Drives Cybersecurity Changes at Nervous Companies

    2022-08-30

    Commercial Observer: We’ve all done it. You leave your computer with a stranger’s promise to “keep an eye on it” in a café. Your kid messes around on your laptop in your home office. You scroll through Facebook during a tedious Zoom meeting. What’s the harm?

    Read more...

    Chinese Hackers Target Australian Govt with ScanBox Malware

    2022-08-30

    Bleeping Computer: China-based threat actors have been targeting Australian government agencies and wind turbine fleets in the South China Sea by directing select individuals to a fake impersonating an Australian news media outlet.

    Read more...

    How the Newly Imposed SEC Cybersecurity Rules Impact Private Funds and Investors

    2022-08-29

    Forbes: Most forward-thinking corporations understand the benefits of taking a proactive approach to cybersecurity. If investments haven’t been made from the desire to protect customer and client data, it is seemingly being invested in by organizations that do understand the potential negative impacts on brand and reputation should they not take it seriously.

    Read more...

    Know Your Breach: WSI

    The Target: Workforce Safety & Insurance, North Dakota’s division of workplace safety and worker compensation.

    The Take: Exposure of 182 records of Personally Identifiable Information including: emails between claimants and WSI, voice-mails containing information about said claims, and emails between WSI and their business partners.

    The Vector: The attacker penetrated Klaviyo’s internal systems by tricking an employee to give up their company credentials through a phishing attack, allowing the threat actor to access systems with all the privileges of the stolen login.

    This breach highlights critical need for employee training to protect a firm against phishing attacks. By using the exposed credentials, the attackers were able to act with all the same permissions as the affected employee. The human component of cybersecurity is a very real and important piece of the overall picture of cybersecurity posture. Furthermore, the sensitive information breached can lead to highly targeted spear-phishing attacks as it lends credence.

    Read more...

    LDC Sells its Stake in Nottingham-based Managed IT and Cyber Services Firm Littlefish to Bowmark Capital

    2022-08-25

    Business Live: Mid-market private equity firm LDC has sold its minority stake in Nottingham-based managed IT and cyber services provider Littlefish to Bowmark Capital following a three-year partnership.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates