Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: United Nations

    The target: The United Nations

    The take: 400GB of data including: internal documents and emails, human resource records, database access, commercial information, and Active Directory access.

    The attack vector: The threat actors used compromised 42 servers in total when they were able to exploit a known remote code vulnerability in Microsoft Sharepoint. This let the attackers move freely within all of the IT systems. A patch was released a few months prior to the breach, but the U.N’s IT department failed to deploy the patch when it was released, leaving a significant timeframe in which their systems were vulnerable.

    This breach highlights the critical importance of maintaining an inventory of internal systems and software, and ensuring those systems are kept up-to-date. Security vulnerabilities can be exploited as soon as they’re identified, underlining the importance of adhering to a regular and frequent patching schedule.

    Read more...

    Nedbank Says 1.7 Million of its Clients May Have Been Hit by a ‘Data Incident’

    2020-02-13

    Business Insider: A company that sends out SMSes and emails on Nedbank’s behalf may have been hit by a data breach. The “data security incident” may have released the names, ID numbers, telephone numbers, physical and/or email addresses of 1.7 million Nedbank clients.

    Read more...

    Puerto Rico Loses US$2.6 Million in Phishing Scam

    2020-02-13

    CTV: Puerto Rico's government has lost more than US$2.6 million after falling for an email phishing scam, according to a senior official.

    The finance director of the island's Industrial Development Company, Ruben Rivera, said in a complaint filed to police Wednesday that the agency sent the money to a fraudulent account.

    Read more...

    London Hedge Funds' Websites Cloned as Scammers Grow Bolder and More Ubiquitous

    2020-02-13

    Reuters: Some of London’s top hedge funds and asset managers are among those that have been targeted by rogue internet operators who clone their names and websites in an attempt to part unsuspecting investors from their cash.

    Read more...

    Leaked Report Describes Federal Parliament's Cyber Security as Having 'Low Level of Maturity'

    2020-02-13

    ABC: Federal Parliament failed to develop effective methods for preventing cyber intrusions and did not regularly update some sensitive information systems, according to a draft internal audit dated three months after a major cyber attack was uncovered.

    Read more...

    Personal Data of All 6.5 Million Israeli Voters Exposed by Security Flaw in App

    2020-02-11

    CNN: A security flaw in a mobile app used primarily by Prime Minister Benjamin Netanyahu's Likud party exposed the personal data of every eligible voter in Israel just three weeks before a national election.

    Read more...

    Equifax: US Charges Four Chinese Military Officers Over Huge Hack

    2020-02-11

    BBC: More than 147 million Americans were affected in 2017 when hackers stole sensitive personal data including names and addresses. Some UK and Canadian customers were also affected. China has denied the allegations and insisted it does not engage in cyber-theft.

    Read more...

    FBI: BEC Scams Accounted for Half of the Cyber-crime Losses in 2019

    2020-02-11

    ZDNet: The FBI received 467,361 internet and cyber-crime complaints in 2019, which the agency estimates have caused losses of more than $3.5 billion, the bureau wrote in its yearly internet crime report.

    Read more...

    Know Your Breach: Mitsubishi Electric

    The target: Mitsubishi Electric, an electronics company based in Japan.

    The take: Personal data of 8000 employees and trade secrets including technical, sales, and client information.

    The attack vector: A zero-day vulnerability (a newly discovered vulnerability for which no patch/mitigation has yet been published) in antivirus software used by Mitsubishi compromised accounts and internal systems. Attackers gained access to forty servers and one hundred and twenty computers inside the company.

    The unfortunate reality is that every company is potentially vulnerable, and this example only reinforces our position that cybersecurity is not a one-and-done, set-it-and-forget-it domain. While zero-day exploits are rare and extremely difficult to defend against, monitoring and assessment of redundant security measures and the defense-in-depth approach can limit the potential impact of a compromise of one layer of a firm’s defenses.

    Read more...

    IT boss Stole £500k from City Firm Before Splashing Out on Diamonds, Holidays and Cottage Conversion

    2020-02-06

    Evening Standard: Anthony Murrell, 44, siphoned off the money from Legal and General Investment Management over three years, buying non-existent computer cables and paying the money to a fake company in his wife’s name. 

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates