Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    China Fines Didi $1.2 Billion for Violating Cybersecurity and Data Laws

    2022-07-21

    CNN: China’s cyberspace regulator fined Didi Global just over 8 billion yuan ($1.2 billion) for violating cybersecurity and data laws, putting an end to a yearlong investigation into the ride-hailing giant.

    Read more...

    EIS Fund Custodian Suffers Data Breach After Cyber-attack

    2022-07-20

    Portfolio Adviser: Hackers have infiltrated a London-based fund administrator and custodian’s IT system, potentially putting customers’ personal data at risk. Mainspring notified clients earlier this week it had suffered a data breach, following a targeted ransomware attack on the morning of 12 July.

    Read more...

    ACCC, ASIC Trials Website Takedowns for Phishing, Crypto Scams

    2022-07-20

    IT News: Australia’s competition watchdog has partnered with the corporate regulator to trial automated takedowns of websites hosting phishing and other scams.

    Read more...

    Atlantic Street Capital Acquires Assets of CyberGuard Compliance

    2022-07-19

    Private Equity Wire: Atlantic Street Capital (ASC), a private equity firm that invests in lower middle market companies, has acquired assets from CyberGuard Compliance, a licensed CPA firm with exclusive specialisation in IT compliance and cybersecurity audit and assessment services, and Elite Consulting Solutions, a provider of IT compliance and cybersecurity consulting and remediation services, collectively known as “CyberGuard”.

    Read more...

    FBI Issues Public Warning Over Fake Crypto Apps

    2022-07-19

    Coin Telegraph: The United States Federal Bureau of Investigation (FBI) has issued a public warning about fraudulent cryptocurrency applications, which have swindled U.S. investors out of an estimated $42.7 million so far. 

    Read more...

    Biden Administration Pushes to Close the Growing Cybersecurity Workforce Gap

    2022-07-19

    CNN: The Biden administration is pushing to fill hundreds of thousands of cybersecurity jobs in the United States as part of a bid to close a talent shortage US officials describe as both a national security challenge and an economic opportunity.

    Read more...

    Know Your Breach: Axie Infinity

    The Target: Axie Infinity, a Decentralized Finance company that runs a “play to earn” game video game.

    The Take: $625 million worth of crypto currency.

    The Vector: The hackers used social engineering and phishing to craft a highly targeted fake job offer email and embedded a malicious program instead a PDF attachment. The Axie Infinity employee believed this was legitimate and opened the PDF attachment, and during the fake recruiting process, also gave away critical personal information which was then used to gain access to the firm’s systems to steal the funds.

    This breach highlights the ongoing and ever-present need for employee training to protect a firm against social engineering attacks. By using the exposed credentials, the attackers were able to act with all the same permissions as the affected employee and pivot into other systems. The human component of cybersecurity is a very real and important piece of the overall picture of cybersecurity posture.

    Read more...

    Cyber Security and Ransomware in Financial Markets

    2022-07

    Bank of Canada: Financial markets face the constant threat of cyber attacks. We develop a principal-agent model of cyber-attacking with fee-paying clients who delegate security decisions to financial platforms. We derive testable implications about clients’ vulnerability to cyber attacks and about the fees charged. We characterize which cyber attacks actors choose.

    Read more...

    DHS Review Board Says it Could Take Years to Fix Government Software Vulnerability

    2022-07-14

    The Hill: The analysis states that a security engineer from the Alibaba Cloud Security team in China first reported the vulnerability to the Apache Software Foundation, a nonprofit organization that provides support for Log4j, the software. 

    Read more...

    $8 Million Stolen in Large-scale Uniswap Airdrop Phishing Attack

    2022-07-13

    Bleeping Computer: Uniswap, a popular decentralized cryptocurrency exchange, lost close to $8 million worth of Ethereum in a sophisticated phishing attack. While the protocol hasn't been compromised by exploiting a vulnerability as initially suspected, the cyberattack has impacted many investors in digital assets.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates