Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      Know Your Breach: Kaiser Permanente

      The Target: Kaiser Permanente, a U.S based health plan and health-care provider.

      The Take: Personally Identifiable health Information on 69,000 individuals, including: first and last name, medical record number, dates of service, laboratory test results. 

      The Vector: A threat actor gained access to compromised employee email account and acting with all the same permissions as the breached credentials, downloaded and stole the information.

      This breach is a stark reminder of the importance of robust employee credential authentication and password hygiene. Performing regular monitoring on account behaviour is critical to ensure access is kept within the firm. Additionally, locking down appropriate permissions, admin access, and ensuring users only need the tools they need to do their jobs, and no more, will reduce the risk of these attacks.

      Read more...

      Cybersecurity M&A Roundup: 45 Deals Announced in June 2022

      2022-07-07

      Security Week: A SecurityWeek study showed that more than 430 cybersecurity mergers and acquisitions were announced in 2021. SecurityWeek will soon also publish an M&A analysis for the first half of 2022.

      Read more...

      China’s Cabinet Urges Greater Cybersecurity After Mass Data Leak

      2022-07-07

      BNN Bloomberg: China’s cabinet stressed the need to bolster information security, following a huge leak of personal data that could be the largest cyber-attack in the country’s history. 

      Read more...

      Hotel Giant Marriott Confirms Yet Another Data Breach

      2022-07-06

      Tech Crunch: Hotel group Marriott International has confirmed another data breach, with hackers claiming to have stolen 20 gigabytes of sensitive data, including guests’ credit card information.

      Read more...

      Greenwich-based Information Technology Company is Acquired

      2022-07-06

      The Middletown Press: Officials with a Foxborough, Mass.-based cybersecurity firm announced their company has acquired Edge Technology Group of Greenwich, which is an information technology company serving financial firms.

      Read more...

      The Cyber-Asset Management Playbook for Supply Chain Modernization

      2022-07-06

      Dark Reading: The recent upheaval in the supply chain is unprecedented, thanks to ongoing disruptions tied to the pandemic, financial and trade sanctions stemming from Russia's war in Ukraine, cyberattacks targeting the supply chain, and other factors.

      Read more...

      US Department of Defense Invites Hackers to Help Harden its Security Systems

      2022-07-06

      Tech Radar: The Chief Digital and Artificial Intelligence Office (CDAO), the Directorate for Digital Services and the Department of Defense Cyber Crime Center (DC3) jointly launched “Hack US”, a bounty-hunting program aimed at identifying high-severity flaws in government systems.

      Read more...

      Ignoring Cybersecurity Can Sour M&A Deals

      2022-07-05

      Forbes: When a private equity firm had acquired a midsized manufacturer late last year, little did they know that someone else had set on the same target as well. Just two months after it was purchased, a cybercriminal organization launched a crippling ransomware attack that locked up the manufacturer’s systems.

      Read more...

      Know Your Breach: Halfords

      The Target: Halfords, a U.K-based automobile maintenance service.

      The Take: Exposure of Personally Identifiable Information of current and past customers including: telephone number, car details, and physical address location.

      The Vector: The firm’s automated confirmation email which contained a URL link for order tracking with ID in the address. By incrementing the ID number, different orders belonging to other customers were able to be freely accessed and seen.

      The breach is critical reminder of the importance of credential management and authentication around points of access which expose customer data. The information stored in customer record scenarios is especially sensitive as the exposed details can greatly aid malicious actors in crafting highly targeted and effective spear-phishing campaigns. All points of access to sensitive data should be appropriately locked down, minimizing unnecessary and dangerous exposure of customer information.

      Read more...

      OpenSea Reports Email Data Breach

      2022-06-30

      CoinDesk: Watch out for phishing emails, says OpenSea, after staff at the world’s largest NFT marketplace discovered that an employee of Customer.io, a platform for managing email newsletters and campaigns, leaked the list of OpenSea customers’ emails to an outside party.

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates