Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: McLaren Health Care

    The Target: McLaren is a nonprofit health system in the U.S. with $6.6 billion in annual revenue, operating a network that spans 14 Michigan hospitals (2,624 beds).

    The Take: The McLaren data breach notification sample submitted to U.S. authorities confirms that full names were exposed, redacting other data types that were exposed. Therefore, the full extent of the data breach remains unclear.

    The Vector: In the notice sent to impacted individuals, McLaren Health Care admits that the incident concerned a ransomware attack, though the INC ransomware gang, believed to be responsible for the attack, is still not mentioned.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    More Than Half of Cybersecurity Professionals Told to Conceal Breaches, Survey Claims

    2025-06-25

    Tech Monitor: More than half of cybersecurity professionals globally, at 57.6%, have been pressured to keep security breaches undisclosed, according to a survey by Bitdefender.

    Read more...

    Judge Approves AT&T’s $177 Million Data Breach Settlement

    2025-06-25

    Cybersecurity Dive: The consolidated class action highlights a growing concern for business leaders: the steady escalation of cybersecurity threats and data breach costs.

    Read more...

    Securing SaaS In The Age Of AI: What CISOs Need To Know

    2025-06-25

    Forbes: AI is everywhere. It’s driving productivity, accelerating workflows and powering SaaS for every department. But while AI tools are making life easier for teams, they are also creating new opportunities for cybersecurity attacks.

    Read more...

    Cycurion Secures $8 Million In New Cybersecurity Contracts

    2025-06-25

    Investing.com: Cycurion, Inc., a cybersecurity firm with trailing twelve-month revenue of $17.4 million and current market capitalization of $12.5 million, has secured several new contracts totaling over $8 million with government and commercial clients, the company announced.

    Read more...

    Cyber Insurance Premiums Drop For First Time, Report Finds

    2025-06-24

    Cybersecurity Dive: Last year’s decrease in the premiums generated from cyber insurance represents the first such decline since the National Association of Insurance Commissioners began collecting data in 2015, according to AM Best’s report.

    Read more...

    UK Cybersecurity Startups Struggle for VC Funding Despite Surge of Threats

    2025-06-23

    Pitchbook: Even as the UK government scrambles to support the cybersecurity industry following a string of attacks, VC funding for UK cybersecurity startups is on track to hit its lowest level in a decade.

    Read more...

    US Braces for Cyberattacks After Bombing Iranian Nuclear Sites

    2025-06-23

    SecurityWeek: After the US bombed three key nuclear sites in Iran, the regime in Tehran vowed to retaliate. The Department of Homeland Security (DHS) issued a national terrorism advisory system bulletin, warning that the Iranian government has publicly condemned the United States’ involvement in the conflict and that retaliation could come in several forms.

    Read more...

    Know Your Breach: Scania

    The Target: Scania is a major Swedish manufacturer of heavy trucks, buses, and industrial and marine engines and is a member of the Volkswagen Group.

    The Take: Documents related to insurance claims were downloaded. Insurance claim documents are likely to contain personal and possibly sensitive financial or medical data, so the incident could have a significant impact on those affected. At this time, the number of exposed individuals remains undefined.

    The Vector: On the 28th and 29th of May, a perpetrator used credentials for a legitimate external user to gain access to a system used for insurance purposes; the current assumption is that the credentials used by the perpetrator were leaked by a password stealer malware.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    UBS and Pictet Report Data Leak After Cyber Attack On Provider, Client Data Unaffected

    2025-06-18

    Yahoo Finance: Swiss banks UBS and Pictet said they had suffered a data leak due to a cyber attack on a provider in Switzerland that did not compromise client information, although a report said thousands of UBS workers' data was affected.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates