Five regional hospitals in Ontario, Canada, rescheduled appointments and diverted non-emergency patients after a cyber attack disrupted a shared service provider.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The cybersecurity workforce continues to grow, but not nearly fast enough to keep pace with demand. This is just one of several factors contributing to what the new ISC2 report calls a "perfect storm" of instability in the field.
Seiko has confirmed that the July 2023 data breach resulted from a ransomware attack and leaked personal information. BlackCat/ALPHV ransomware gang, took responsibility for the attack and claimed to have exfiltrated 2 TB of data.
With projections of closing out at $1 to $2 trillion by the end of the present decade and making up about a third of total regional GDP, ASEAN's rapid digital economy growth is poised to put it at the center of global conversations about cyber rights and regulations in the very near future.
Octo Tempest has gradually stepped up from data theft, to data extortion, and now to ransomware as of this summer (becoming an affiliate of the ALPHV/BlackCat group). The cybercriminals are entirely financially motivated and nearly always leads with either a phishing email/message or a social engineering call. It also looks to execute SIM swap attacks.
Casio has confirmed a data breach on its ClassPad education platform that impacted over 100,000 customers, including learning institutions in Japan and 148 other countries.
IT environments are simply too complex and too dynamic for self-attestation, based on manual processes, to ever work. Without continuous monitoring to accurately assess compliance to cyber insurance requirements, organizations remain at risk.
Leading insurer Lloyd's of London has issued a dire warning about a potential cyber attack scenario on one of the world's major payments systems, estimating that the global cost would total about $3.5 trillion and that much of the recovery cost would not be covered by insurance policies.
A hacker who leaked one million genetic profiles from 23andMe in early October has returned with an even larger trove, this time dumping a little over four million files and including the DNA Relatives feature that allows for connections between relations to be made.
The FBI warns that cybercriminals are targeting plastic surgery offices and stealing sensitive information, including medical records, in a multi-stage cyber extortion campaign.










