Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      Australian Banks Targeted by DDoS Extortionists

      2020-02-25

      ZDNet: A threat group has been emailing victims with threats to carry out distributed denial of service (DDoS) attacks unless the organizations pay hefty ransom fees in the Monero (XMR) cryptocurrency.

      Read more...

      Know Your Breach: Crown Bank

      The target: Crown Bank, a New Jersey based financial institution.

      The take: $2 million USD

      The attack vector: Cyber criminals impersonated the wife of the CEO using a fake email address and tricked the bank’s employees to transfer funds multiple times. Using fraudulently created signatures of the CEO’s wife attached to PDF files, the attackers convinced bank staff that the requests, and their urgency, were legitimate.

      Failure to implement and follow internal validation procedures can have serious consequences, and where an attacker discovers and exploits a weakness, they are likely to attack again until they are discovered. Furthermore, failure to enforce a firm’s security and cash transfer control procedures can invalidate an attempt to recoup damages via an insurance claim.

      Read more...

      Are Your Clients Safe? Cybersecurity Expert Warns Wealth Managers Over Hacking Risks

      2020-02-20

      City Wire: Financial firms and their employees could be doing much more to protect their assets and those of their clients as cybercrime will become one of the biggest risks they face over the next decade, according to cybersecurity expert and former FBI agent Scott Augenbaum.

      *Note full article may require free sign-up registration.

      Read more...

      Georgia, Backed by U.S. and Britain, Blames Russia for 'Paralyzing' Cyber Attack

      2020-02-20

      Reuters: Britain and the United States joined Georgia on Thursday in blaming Russia for a large-scale cyber attack last year that knocked thousands of Georgian websites offline and disrupted national television broadcasts.

      Read more...

      MGM Hack Exposes Personal Data of 10.6 Million Guests

      2020-02-20

      BBC: The data exposed included names, address, and passport numbers for former guests. MGM said it was "confident" no financial information had been exposed. The resort chain said it was unable to say exactly how many people were impacted because information that was exposed might be duplicated.

      Read more...

      Cybersecurity Strategies for the Adviser Industry

      2020-02-20

      Plan Adviser: Retirement plan advisers not only have rigorous cybersecurity responsibilities of their own—they also need to proactively help their plan sponsor clients establish airtight cybersecurity firewalls and procedures, industry experts say.

      Read more...

      ForgePoint Capital Raises $450M for its Second Cybersecurity Investment Fund

      2020-02-19

      Silicon Angle: The venture capital firm has been a prolific investor in cybersecurity startups. Investments included access control startup Remediant Inc. in August, app security startup NowSecure in June and IoT security provider Mocana Corp. in March. Fund II focus areas include cyber intelligence, privacy, security services and infrastructure protection.

      Read more...

      Dell Sells RSA to Consortium Led by Symphony Technology Group for Over $2B

      2020-02-18

      Tech Crunch: Dell Technologies announced that it was selling legacy security firm RSA for $2.075 billion to a consortium of investors led by Symphony Technology Group. Other investors include Ontario Teachers’ Pension Plan Board and AlpInvest Partners.

      Read more...

      Cybersecurity and Cannabis ETFs Launched by Former LGIM Team

      2020-02-18

      CityWireSelector: An ETF specialist boutique launched by four former Legal & General Investment Management (LGIM) employees has unveiled two thematic ETFs as it seeks to capitalise on future trends.

      Read more...

      Know Your Breach: United Nations

      The target: The United Nations

      The take: 400GB of data including: internal documents and emails, human resource records, database access, commercial information, and Active Directory access.

      The attack vector: The threat actors used compromised 42 servers in total when they were able to exploit a known remote code vulnerability in Microsoft Sharepoint. This let the attackers move freely within all of the IT systems. A patch was released a few months prior to the breach, but the U.N’s IT department failed to deploy the patch when it was released, leaving a significant timeframe in which their systems were vulnerable.

      This breach highlights the critical importance of maintaining an inventory of internal systems and software, and ensuring those systems are kept up-to-date. Security vulnerabilities can be exploited as soon as they’re identified, underlining the importance of adhering to a regular and frequent patching schedule.

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates