Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: RATP

    The Target: Régie Autonome des Transports Parisiens

    The Take: Exposure of 3 million records of Personally Identifiable Information belonging to 60,000 employees including: full names, email addresses, source code and APIs, logins for their RATP accounts, hashed passwords, and more critically, access to the firm’s Github account where attackers could access ongoing projects.

    The Vector: The data was left open and accessible to public on an unsecured SQL database backup server, allowing anyone with internet access to connect and view the sensitive information.

    It is critical to employ robust practices of credential management, user authentication and validation around all points of access. An unprotected point of entry on a key piece of equipment like a server can lead to a breach with a cascading effect on data exposure. This breach highlights the multiplicative effects of these cascading pivot attacks which is why it’s important to lock down every point of access in an IT system.

    Read more...

    Exclusive-IMF, 10 Countries Simulate Cyberattack On Global Financial System

    2021-12-09

    U.S. News: Israel led a 10-country simulation of a major cyberattack on the global financial system in an attempt to increase cooperation that could help to minimise any potential damage to financial markets and banks.

    Read more...

    Cybersecurity Can Pose A Risk In More Than One Way for Financial Advisors

    2021-12-08

    CNBC: Financial advisors may want to view cybersecurity as a critical issue on more than one level.

    Read more...

    Hummingbird Lands $30M to Bring Design Thinking to Anti-money Laundering Investigations

    2021-12-07

    Yahoo News: Hummingbird, which sells anti-money laundering software to banks and fintechs, announced today that it raised a $30 million Series B led by new investor Battery Ventures. Existing investors Flourish and Homebrew also participated in the round, alongside FinVC and Plaid co-founder William Hockey.

    Read more...

    Biden’s Cyber Leaders Go to Silicon Valley for More Help Fighting Hackers

    2021-12-07

    Politico: Senior Biden administration officials met in Silicon Valley on Monday with key technology and cybersecurity companies as part of a push for more help from the private sector in fending off increasingly aggressive hackers working for adversarial regimes and criminal gangs.

    Read more...

    The Cyberdemic Will Continue, According to the 2022 Experian Data Breach Industry Forecast

    2021-12-06

    Business Wire: In the Experian ninth annual Data Breach Industry Forecast, five predictions for 2022 underscore the ongoing impact of the pandemic on cybersecurity. Cybercriminals will continue to exploit vulnerabilities within remote working and the vaccine ecosystem, but also set their sights on new targets such as online gambling.

    Read more...

    U.S. Bank Regulator Urges Vigilance As Ransomware Attacks On the Rise

    2021-12-06

    U.S. News: A top U.S. banking regulator is cautioning firms to ensure they have robust policies to protect themselves from cyberattacks, saying it is seeing an uptick in ransomware attacks, it said in a report issued.

    Read more...

    BitMart Says It Will Compensate Victims of $196 Million Hack and Restore Trading

    2021-12-06

    CNBC: Crypto trading platform Bitmart says it will use its own money to reimburse victims of a large-scale security breach, in which hackers took as much as $196 million.

    Read more...

    Know Your Breach: Huntington Hospital

    The Target: Huntington Hospital, a New York based medical center.

    The Take: Exposure of 13,000 records of Personally Identifiable Information including: name, date-of-birth, phone number, addresses, internal account number, medical record number, diagnoses, and other treatment information.

    The Vector: An employee improperly accessed this information without clearance and was not prevented from viewing this data based upon their level of access and role within the firm, exposing the data.

    This breach highlights the important concept of Least-Privilege when it comes to system access and authorization. Employees should only have access to the minimum amount of information and privileges they need to do their role. Ensuring this process is applied at all levels of access across a firm is a key component to maintaining a robust Cybersecurity posture.

    Read more...

    Governor General's Office Says Internal Network Breached

    2021-12-02

    CTV News: The Office of the Secretary to Gov. Gen. Mary Simon says that there’s been an ‘unauthorized access to its internal network,’ with the scope of the breach still under investigation.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates