Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      Know Your Breach: Comcast

      The Target: Comcast is an American mass media, telecommunications, and entertainment multinational company, and the fourth-largest telecom firm in the world by revenue, after AT&T, Verizon, and China Mobile.

      The Take: The threat actors stole personal and financial information between February 14 and February 26, including the names, addresses, Social Security numbers, dates of birth, and Comcast account numbers of affected current and former customers.

      The Vector: The breach occurred in February 2024, when attackers hacked into the systems of Financial Business and Consumer Solutions (FBCS), a debt collector Comcast had stopped using two years earlier.

      This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

      Read more...

      EU Agrees On New Rules For Online Fraud Protection

      2025-11-27

      Yahoo News/Reuters: EU member states and the European Parliament have ​agreed on new rules to force banks ‌and other payment service providers to better protect their customers ‌against online fraud, hidden fees and data leaks, the Parliament said.

      Read more...

      Account Takeover Fraud Caused $262 Million in Losses in 2025: FBI

      2025-11-26

      SecurityWeek: The threat actors were seen impersonating financial institutions to steal money or information from individuals, businesses, and organizations of different sizes, as over 5,100 complaints received by the agency show.

      Read more...

      Proof Over Promises: Why Cybersecurity Must Become Verifiable

      2025-11-26

      Forbes: For too long, the cybersecurity industry has relied on hope and hype when it should be focused on demonstrable effectiveness. Massive investments in cybersecurity haven’t translated into confidence for executives, boards or insurers—and CISOs are stuck in the middle.

      Read more...

      Alliances Between Ransomware Groups Tied to Recent Surge in Cybercrime

      2025-11-26

      CSO Online: A seasonal surge in malicious activity combined with alliances between ransomware groups led to a 41% increase in attacks between September and October. Cybercriminal group Qilin continues to be the most active ransomware paddlers, responsible for 170 of 594 attacks (29%) in October, NCC Group reports.

      Read more...

      Opti Raises $20 Million for Identity Security Platform

      2025-11-26

      SecurityWeek: Founded in 2023 by veteran cybersecurity experts, Opti has built an AI-native identity and access management (IAM) platform. The company’s solution is powered by a context-aware engine that continuously monitors access and risks across identities and applications, enabling security teams to define, govern, and protect identities.

      Read more...

      SEC Orders Portland-Based Hybrid Firm To Pay $325K Over Cybersecurity Lapses

      2025-11-25

      Investment News: The Securities and Exchange Commission has levied a $325,000 penalty against M Holdings Securities for failing to maintain adequate cybersecurity safeguards across its nationwide network of member firms, marking the latest enforcement action targeting inadequate information security practices in the wealth management industry.

      Read more...

      US Banks Scramble to Assess Data Theft After Hackers Breach Financial Tech Firm

      2025-11-24

      TechCrunch: Several U.S. banking giants and mortgage lenders are reportedly scrambling to assess how much of their customers’ data was stolen during a cyberattack on a New York financial technology company earlier this month.

      Read more...

      Know Your Breach: Checkout

      The Target: Checkout operates checkout.com and is a global payment processing firm that provides a unified payments API, hosted payment portals, mobile SDK, and plugins to use on existing platforms.

      The Take: Checkout says the threat actor, known as ShinyHunters, gained access to a third-party legacy system that had not been properly decommissioned, which held merchant data from 2020 and earlier, including internal operational documents and onboarding materials

      The Vector: Upon investigation, Checkout determined that this data was obtained by the threat actor gaining unauthorized access to a legacy third-party cloud file storage system, used in 2020 and prior years.

      This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

      Read more...

      SEC Drops Civil Fraud Case Against SolarWinds

      2025-11-20

      Yahoo Finance: The Securities and Exchange Commission said it was dropping a landmark civil fraud case against SolarWinds and Tim Brown, the company’s chief information security officer. 

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates