Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Kelly Benefits

    The Target: Kelly Benefits is a provider of benefits consulting, enrollment technology, payroll administration, HRIS, compliance support, and carrier management.

    The Take: The data breach notice sent to impacted individuals informs recipients of the specific data types impacted by the breach, which vary per person. However, the general notice published on the site says that the compromised info may contain full names, Social Security number, tax ID number, date of birth, medical information, health insurance information, and financial account information.

    The Vector: The Maryland-based health and life insurance agency has issued an update on a security incident it suffered last year between December 12-17, when unauthorized actors breached its IT systems and stole files. On April 9, 2025, the company stated that the incident impacted 32,234 individuals. The figure was revised multiple times until the final tally shared with authorities in the U.S. counted 553,660 individuals.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    FBI Cyber Guidance To Lawmakers Falls Short, US Senator Says

    2025-07-02

    Cybersecurity Dive: As commercial spyware proliferates and hackers linked to U.S. adversaries step up their attempts to breach high-profile American targets, one U.S. senator says the FBI isn’t doing enough to help lawmakers protect themselves.

    Read more...

    India’s Max Financial Says Hacker Accessed Customer Data From Its Insurance Unit

    2025-07-02

    TechCrunch: Max Financial Services said its insurance subsidiary Axis Max Life Insurance received communication from an anonymous sender about unauthorized access to its customer data.

    Read more...

    Most Enterprises Can’t Secure AI, Accenture Says

    2025-07-01

    CIO Dive: CIOs are under pressure to move AI projects along faster and demonstrate the corresponding value, but a need for speed doesn’t always translate to sustainable momentum. 

    Read more...

    DOJ Charges 4 North Koreans in $1 Million Crypto Theft From Blockchain Startup

    2025-07-01

    Cointelegraph: Four North Korean nationals were charged in the state of Georgia with wire fraud and money laundering after posing as remote IT workers at US and Serbian blockchain companies and stealing almost $1 million in crypto, prosecutors said.

    Read more...

    Ransomware Reshaped How Cyber Insurers Perform Security Assessments

    2025-07-01

    Dark Reading: The ransomware scourge has forced cyber insurers to re-examine how they use security assessments. While the threat has been around for years, it's only fairly recently that cybercriminals realized how profitable ransomware attacks could be. 

    Read more...

    Global Cybersecurity Market to Worth Over US$ 723.8 Billion By 2033

    2025-06-30

    GlobeNewswire: The global cybersecurity market was valued at US$ 233.4 billion in 2024 and is expected to reach US$ 723.8 billion by 2033, growing at a CAGR of 13.40% during the forecast period.

    Read more...

    Danish Pensions Industry Outlines Proposals to Strengthen Cyber Security

    2025-06-30

    European Pensions: The Danish insurance and pension industries have outlined eight concrete proposals to strengthen cybersecurity, given the country's particular vulnerabilities in this area, according to Insurance and Pension Denmark (I&P Denmark).

    Read more...

    Know Your Breach: McLaren Health Care

    The Target: McLaren is a nonprofit health system in the U.S. with $6.6 billion in annual revenue, operating a network that spans 14 Michigan hospitals (2,624 beds).

    The Take: The McLaren data breach notification sample submitted to U.S. authorities confirms that full names were exposed, redacting other data types that were exposed. Therefore, the full extent of the data breach remains unclear.

    The Vector: In the notice sent to impacted individuals, McLaren Health Care admits that the incident concerned a ransomware attack, though the INC ransomware gang, believed to be responsible for the attack, is still not mentioned.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    More Than Half of Cybersecurity Professionals Told to Conceal Breaches, Survey Claims

    2025-06-25

    Tech Monitor: More than half of cybersecurity professionals globally, at 57.6%, have been pressured to keep security breaches undisclosed, according to a survey by Bitdefender.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates