Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Zacks Investment Research Data Breach Affects 820,000 Clients

    2023-01-25

    Bleeping Computer: Zacks discovered the at the end of last year that some customer records had been accessed without authorization. An internal investigation into the incident determined that a threat actor gained access to the network somewhere between November 2021 and August 2022.

    Read more...

    German Cybersecurity Officials Looking Into 'Attacks' On Websites

    2023-01-25

    Sky News: The attacks - known as distributed denial-of-service (DDoS) - work by directing high volumes of internet traffic towards targeted servers in a bid by so-called hacktivists to knock them offline.

    Read more...

    North Korea-linked Hackers Behind $100 Million Crypto Heist, FBI Says

    2023-01-24

    CNBC: North Korean-linked actors were behind the theft of $100 million through the hack of a crypto product last year, the Federal Bureau of Investigation said.

    Read more...

    LastPass Owner GoTo Says Hackers Stole Customers’ Backups

    2023-01-24

    TechCrunch: LastPass’ parent company GoTo — formerly LogMeIn — has confirmed that cybercriminals stole customers’ encrypted backups during a recent breach of its systems.

    Read more...

    Abacus Group Expands PE Cybersecurity Offering

    2023-01-23

    Private Equity Wire: Abacus Group, a provider of hosted IT services and solutions to alternative investment firms, has acquired two boutique cybersecurity consulting companies, Gotham Security and its parent company, GoVanguard, which will now be known as Gotham Security, and will operate as an independent subsidiary of Abacus Group. 

    Read more...

    Cybersecurity Worries Around Hybrid Working Drop, but Many IT Leaders Still Concerned Over Cyber-Skills Gap

    2023-01-23

    DarkReading: Leading global intelligence and cyber security consultancy S-RM has today revealed in its Cyber Security Insights Report that there has been a drop in concern around the cyber security threats posed by hybrid working. However, a significant proportion (35%) of IT leaders say they are concerned over a cyber skills gap among employees. 

    Read more...

    Know Your Breach: Myrocket

    The Target: Myrocket, a Human Resources recruitment company based in India.

    The Take: Exposure of 200,000 employees and 9 million candidate records of Personally Identifiable Information including: names, taxpayer information, personal identification numbers, emails, phone numbers, bank details, dates of birth, salaries, payslips, employees roles, and more.

    The Vector: A misconfigured data server was left open and unsecured, meaning anyone with an internet connection could have viewed and downloaded the data.

    This breach is critical reminder that authentication controls are an important piece in an overall robust cybersecurity posture. This data is perfect for constructing highly effecting spear-phishing campaigns. Multi-factor authentication and password length and complexity rules on server access are effective strategies to mitigate these kinds of breaches to protect a firm’s data.

    Read more...

    Fewer Companies Are Paying Ransoms to Hackers, Researchers Say

    2023-01-19

    BNN Bloomberg: In findings published, the blockchain forensics firm estimated that ransom payments — which are almost always paid in cryptocurrency — fell to $456.8 million in 2022 from $765.6 million in 2021, a 40% drop.

    Read more...

    PayPal Accounts Breached in Large-scale Credential Stuffing Attack

    2023-01-19

    Bleeping Computer: PayPal is sending out data breach notifications to thousands of users who had their accounts accessed through credential stuffing attacks that exposed some personal data. Credential stuffing are attacks where hackers attempt to access an account by trying out username and password pairs sourced from data leaks on various websites.

    Read more...

    Cole-Frieman & Mallon Launches First Cybersecurity Law Practice for Asset Managers With Eye to SEC’s Proposed Rules

    2023-01-18

    BusinessWire: With the Securities & Exchange Commission proposing tighter cybersecurity requirements for hedge funds and other asset managers, Cole-Frieman & Mallon LLP, one of the nation’s leading boutique law firms serving the investment management industry, has launched a first-of-its-kind cybersecurity law practice.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates