Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: US Cellular

    The Target: United States Cellular Corporation, a wireless carrier. 

    The Take: Personally Identifiable information including: names, addresses, PIN codes, phone numbers, information on wireless usage and billing statements.

    The Vector: The threat actors contacted employees of U.S Cellular and tricked them into downloading and installing malicious software and as the employees were logged on with legitimate credentials, the dangerous software was able to be installed. This malware let the attackers further access customer accounts remotely to port the victim’s phone numbers to a different carrier.

    This breach highlights the ongoing and ever-present threat that social engineering poses to firms. Regular training and policy review can help firms ensure their employees are employing a slow and measured approach whenever access, or installation of software, is made – especially when the request is initiated from outside the firm.

    Read more...

    Crypto Scammers Took A Record $14 Billion In 2021

    2022-01-06

    CNBC: Scammers took home a record $14 billion in cryptocurrency in 2021, thanks in large part to the rise of decentralized finance (DeFi) platforms, according to new data from blockchain analytics firm Chainalysis.

    Read more...

    Cybersecurity Training Isn't Working. And Hacking Attacks Are Only Getting Worse

    2022-01-06

    ZDNet: The threat of cyberattacks is growing and much more needs to be done to educate businesses and users about risks in order to prevent widespread damage and disruption as a result of cyber incidents.  

    Read more...

    Livingbridge Invests In Cyber Security Services Provider Quorum Cyber

    2022-01-05

    Private Equity Wire: Livingbridge’s investment includes growth capital to enable Quorum Cyber to capitalise on strong macro tailwinds in the cyber security sector and execute its ambitious growth plans through increased investment in its solutions as well as sales and marketing functions.

    Read more...

    NY AG Notifies 17 Companies of Breaches, Says 1.1 Million Accounts Compromised In Attacks

    2022-01-05

    ZDNet: Seventeen companies have been informed of cyberattacks that compromised user information by New York Attorney General Letitia James following an investigation into credential stuffing. More than 1 million customer accounts were compromised due to the attacks, which James said were previously undetected. 

    Read more...

    China exempts Hong Kong listings from finalised cybersecurity review rules for offshore IPOs, analysts say

    2022-01-04

    South China Morning Post: China’s regulators will exempt Hong Kong from the rigid cybersecurity review process for all initial public offerings (IPOs) in foreign markets by companies with the personal data of at least 1 million customers, according to analysts’ reading of the finalised regulations published.

    Read more...

    Morgan Stanley Files $60 Million Proposed Settlement of Data Breach Claims

    2022-01-03

    Insurance Journal: Morgan Stanley has filed for court approval of a $60 million settlement of a class action stemming from two data breaches in July 2020 that the complaint alleges compromised the information of 15 million of the investment bank’s customers.

    Read more...

    Bridging the “Front and Back of the House”: A lesson in risk management

    2022-01-06

    Help Net Security: Between cloud proliferation, new tech infrastructure and tools and an increasingly distributed workforce, organizations are struggling to implement proper risk management practices

    Read more...

    Know Your Breach: Cox Communications

    The Target: Cox Communications, a U.S based digital cable provider and telecommunicating company.

    The Take: Breach of employee accounts, leading to further exposure of Personally Identifiable Information including: name, address, telephone, Cox account number, username, PIN code, account security question and answer. 

    The Vector: The threat actor impersonated a Cox Support Agent and gained access to a different employee’s credentials, which allowed them to view the sensitive data. 

    This breach highlights the ongoing and persistent threat of social engineering. Regular awareness testing and training, along with tone-from-the-top messaging to emphasize the importance of critical thinking and caution are crucial to protecting sensitive information assets.

    Read more...

    Dovell Bonnett Talks About Enterprise Password Security Solutions

    2021-12-29

    Yahoo Finance: Dovell Bonnett talks with Mission Matters about the growing importance of efficient frontend cybersecurity and how Access Smart can help businesses achieve secure networks and data by removing their weakest link – Employee-Managed Passwords.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates