Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    OCC Designates Points of Contact for Computer Security Incident Notifications

    2022-03-29

    ABA Banking Journal: With a joint agency final rule requiring banks to notify their primary regulatory within 36 hours of becoming aware of computer security incidents that are considered “notification incidents” taking effect on May 1, the OCC issued a bulletin reminding banks of their notification responsibilities and specifying points of contact.

    Read more...

    Hackers Steal Over $600 Million from Video Game Axie Infinity's Ronin Network

    2022-03-29

    CNN: The latest crypto hack has targeted a gaming-focused blockchain network that supports the popular video game Axie Infinity. Hackers made off with about $625 million worth of Ethereum and USDC, two cryptocurrencies, in one of the largest crypto hacks of all time.

    Read more...

    Know Your Breach: Doctors Me

    The Target: Doctors Me, a private self-assessment health service company located in Japan.

    The Take: Exposure of 300,000 records of nearly 12,000 customers. The exposed information was a collection of symptom photos, in many cases, exposing the customer’s faces.

    The Vector: A misconfigured Amazon S3 storage server was left open online, meaning anyone with internet access could have viewed and downloaded the data. 

    While the photos were uploaded anonymously, attackers can cross reference these pictures with other social media sties and craft extremely effective spear-phishing campaigns, as well engage in fraud and blackmail. This breach is another critical reminder of the importance of airtight credential management at all points of access for firms. Ensuring two-factor and comprehensive user authentication is paramount for a robust cybersecurity posture.

    Read more...

    Biden’s Russia Cyber Warning Befuddles Ill-Prepared Businesses

    2022-03-24

    Yahoo Finance: A day after U.S. President Joe Biden issued a stark warning that a Russian cyberattack “is coming,” members of his administration hosted a three-hour call with about 13,000 people representing businesses, public agencies and other organizations to discuss the potential threat.

    Read more...

    London Cops Nab Seven Teens in Connection with Lapsus$ Hacks

    2022-03-24

    PYMNTS: Seven teenagers were arrested by London police on Thursday (March 24) in connection with the recent hacking spree by the Lapsus$ cyber-crime gang that infiltrated Microsoft and Okta this week and recently, Samsung, Ubisoft and Nvidia. 

    Read more...

    One in Five Businesses Have Paid or Would Pay a Ransom for Their Data, Finds Thales

    2022-03-23

    Business Wire: New research from Thales has found that malware, ransomware and phishing continues to plague global organisations. In fact, one in five (21%) have experienced a ransomware attack in the last year; with 43% of those experiencing a significant impact on operations.

    Read more...

    Financial Sector and Cloud Security Providers Complete Initiative to Enhance Cybersecurity

    2022-03-23

    Business Wire: The Cyber Risk Institute (CRI), the Cloud Security Alliance (CSA), and the Bank Policy Institute-BITS announced today the release of a cloud extension for the CRI Profile version 1.2. The “Cloud Profile” represents the collaboration of over 50 financial institutions and major cloud service providers (CSPs) to extend the CRI Profile, which is a widely accepted cybersecurity compliance framework for the financial sector.

    Read more... 

    How to Reassure Clients About Cybersecurity

    2022-03-22

    Investment Executive: According to Edelman’s 2021 Trust Barometer, two thirds of Canadians said they were worried about cyberattacks — more than those who were worried about contracting Covid-19. With the Canadian government now warning businesses about Russian cyberattacks, those concerns can only increase.

    Read more...

    EU proposes Cybersecurity Rules for EU Bodies Amid Cyberattack Worries

    2022-03-22

    Yahoo News: EU countries should put in place a framework to manage cybersecurity risks at EU institutions, the European Commission said on Tuesday, amid concerns about rising cyberattacks that could disrupt key activities and steal sensitive information.

    Read more...

    Know Your Breach: Melijoe

    The Target: Melijoe.com a high-end e-commerce fashion retailer of luxury children’s clothing.

    The Take: Exposure of 2 million records totalling 200GB of Personally Identifiable Information including: email addresses, names, gender, dates of birth, marketing and preferences data. 

    The Vector: A misconfigured Amazon S3 storage bucket was left open and unsecured, meaning anyone with an internet connection could have accessed and viewed the data.

    This breach highlights the critical importance of employing robust practices of credential management, user authentication and validation. An unprotected point of entry on a key piece of equipment like a storage server can lead to a breach with a cascading effect on data security. The detailed personal information contained exposes users to targeted phishing attacks and fraud.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates