Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Russian Hacker Should Serve Over a Decade in Prison, U.S. Says

    2020-12-01

    BNN Bloomberg: A Russian who admitted carrying out one of the largest known cyberattacks against a U.S. bank is a “brazen and prolific” hacker who should serve as long as almost two decades in prison, U.S. prosecutors told a federal judge in advance of his sentencing.

    Read more...

    FINRA Alerts Firms to Phishing Email Using Invest-FINRA.org Domain Name

    2020-11-30

    FINRA: FINRA warns member firms of an ongoing phishing campaign that involves fraudulent emails that include the domain “@invest-finra.org”. FINRA recommends that anyone who clicked on any link or image in the email immediately notify the appropriate individuals in their firm of the incident.

    Read more...

    Cybersecurity, Pharma Coordination Are Big Post-Pandemic Structural Themes: LGIM

    2020-11-30

    Reuters: Cybersecurity could be one of the key post-pandemic investment themes in an equity-friendly world of low interest rates and vaccine-led recovery, LGIM CIO Sonja Laud said.

    Read more...

    Know Your Breach: Levitas

    The target: Levitas, an Australian based hedge fund manager.

    The take: $8 million

    The attack vector: The attack was initiated when one of the founders clicked on a fake Zoom meeting link. This gave the attackers the ability to inject their own malicious software to take control of the high level email account, and with these powerful credentials in hand, the attackers created fake invoices for a bogus company and then sent requests for payments to be made from the firm. Authorizations from the compromised email account were sent shortly after the requests, prompting the transference of funds to the unknown companies. The threat actors then withdrew the cash.

    This breach demonstrates the critical nature of verification processes, and the inherent power of high level credentials and their management. There were several flags raised along throughout the scheme and this attack shows just how important it is to review, verify, and certify transactional processes no matter to origin within a firm.

    Read more...

    Major Cyber Breach in Finance Inevitable: APRA

    2020-11-26

    Investor Daily: The prudential regulator has unveiled its cyber-security strategy for 2020-24, which seeks to lift security standards and introduce higher accountability where companies fail to meet their requirements. 

    Read more...

    Sophos Alerts Customers of Info Exposure After Security Breach

    2020-11-26

    Bleeping Computer: British cybersecurity and hardware company Sophos has emailed a small group of customers to alert them that their personal information was exposed following a security breach discovered.

    Read more...

    The Emerging Cybersecurity Headaches Awaiting Biden

    2020-11-25

    Axios: The incoming administration will face a slew of cybersecurity-related challenges, as Joe Biden takes office under a very different environment than existed when he was last in the White House as vice president.

    Read more...

    Why Data Protection And Cybersecurity Can't Be Separate Functions

    2020-11-25

    Forbes: Companies often separate cybersecurity and data protection by forming two independent teams and buying different software to address each of these issues apart. Maintaining and managing two teams, together with two software sets, involves high IT costs and administrative expenses.

    Read more...

    Banks See Billion-Dollar Cyber Costs Soaring Even Higher in 2021

    2020-11-24

    BNN Bloomberg: Big banks and other financial firms predict the cost of warding off cyber criminals will keep climbing in 2021 as they work to secure digital financial services popularized by the pandemic.

    Read more...

    Canadians May Overestimate Their Ability to Spot Phishing Scams

    2020-11-24

    CBA: Despite a growing understanding that cyber security is essential in a digital era, some Canadians still need help in getting the message that simple steps can make a big difference in protecting personal information from cyber criminals.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates