DataBreach

The Fallout from Cl0p’s Attack is Growing

The fallout from ransomware gang Cl0p’s massive, worldwide attack continues to grow. Police departments, state and federal agencies, and numerous companies are among the known victims. Recap Cl0p stole data from hundreds of organizations by exploiting a vulnerability in popular file transfer software MOVEit at the end of May. The cybercriminals then told organizations to

The Fallout from Cl0p’s Attack is Growing Read More »

Cl0p Starts Naming Victims

Yesterday, ransomware gang Cl0p began listing organizations affected by its exploit of file transfer software MOVEit. The gang used the exploit to steal data from potentially hundreds of companies around the world at the end of May. The gang had previously instructed affected companies to begin negotiations by June 14th to avoid being named and

Cl0p Starts Naming Victims Read More »

Two States Fall Victim to Ransomware Attack

On Friday, the State of Illinois and the Minnesota Department of Education both revealed they were victims of the Cl0p ransomware gang. Cl0p exploited a vulnerability in file transfer software MOVEit at the end of May, breaching up to hundreds of organizations worldwide. Minnesota Department of Education The Minnesota Department of Education (MDE) reported that

Two States Fall Victim to Ransomware Attack Read More »

Cl0p Tells Companies to Begin Negotiations

Ransomware gang Cl0p has exploited a vulnerability in file transfer software MOVEit to compromise companies around the world. Security researcher Kevin Beaumont estimates “there are over one hundred” organizations affected by the attack, with British Airways, the BBC and Boots already confirmed as victims. Cl0p posted a message to companies who use MOVEit on their

Cl0p Tells Companies to Begin Negotiations Read More »

Negotiating with Ransomware Gangs

Valéry Marchive, a cybersecurity journalist, has published chat logs of negotiations between ransomware gangs and their victims. The goal, he explained in a Twitter thread, is to provide a resource for ransomware victims and researchers, since “What happens during #ransomware negotiations is rarely widely shared.” Background to the chats The chats take place after companies

Negotiating with Ransomware Gangs Read More »

A key on a phishing hook, laying on a keyboard.

Two-Factor Authentication Bypassed in Reddit Breach

Online discussion forum Reddit reported on Thursday that its systems had been breached following a sophisticated phishing attack. In the breach notification, Reddit CTO Christopher Slowe, aka KeyserSosa, explained that the hacker “sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of [Reddit’s] intranet gateway, in an attempt to steal credentials

Two-Factor Authentication Bypassed in Reddit Breach Read More »

A hooded man sits in front of a laptop. Between him and the laptop is an unlocked lock and the word "data" is printed repeatedly throughout the air.

What You Should Do After T-Mobile’s Most Recent Data Breach

T-Mobile has yet again suffered a data breach, this time affecting 37 million customers. The company reported in a press release that criminals pilfered customer names, addresses, email addresses, dates of birth and account numbers by abusing a piece of software called an API that allows computer programs to talk to each other.  T-Mobile emphasized

What You Should Do After T-Mobile’s Most Recent Data Breach Read More »