T-Mobile has begun notifying 37 million prepaid and post subscribers whose personal information was accessed by unauthorized bad actors in an unsecured API data breach.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Software supply chain attacks are among the most destructive strategies used by cybercriminals today. 59% of companies that have suffered a supply chain attack reported significant operational disruption, according to BlackBerry research.
GoTo says that the stolen information varies by product, but encryption keys that were also taken in the hack will grant access to "a portion" of the encrypted backups that were stolen.
Nissan said a third-party data breach allowed hackers to access and exfiltrate customer information for software testing but stored on a misconfigured cloud service by a contracted software development firm.
The increasing spread of wiper malware is a stark reminder of the dangerous landscape organisations face when protecting their data. A solid, well-managed data backup and recovery plan is the key to ensuring data safety in the face of today’s growing array of threats.
2020 and 2021 were record years for ransomware payments at about $765 million. The take collected by ransomware operators is now down 40% to $457 million in 2022.
MFA can be circumvented by modern identity attack techniques. Thwarting cyber attackers starts by understanding the techniques they rely on to bypass MFA protected users, and responding with a holistic, well-rounded identity security strategy that can fill these gaps.
The FTX recovery team says that it has recovered about $5 billion at this point, but that a significant portion of the remaining shortfall is due to almost half a billion in stolen crypto.
The Mailchimp security breach appears to have lasted for less than a full day. The company says that client login information was not compromised, but customer support tools were used to send phishing emails.
There is a prevailing belief that employees were less safe from a cybersecurity standpoint at home rather than in their corporate workplace. In reality, while some cyber risk factors have changed, the risk is often reduced in a remote working scenario.










