This week, Volkswagen AG’s U.S. entity and its Audi brand were hit with a class action for a data breach that allegedly compromised 3.3 million consumers’ personal information. In the U.S. District Court for the District of New Jersey, a California consumer filed a suit against the automakers on behalf of other current and prospective
hacked
CISA Releases “Bad Practices” with Hope of Decreasing Cyber Blunders
The federal Cybersecurity and Infrastructure Security Agency (CISA) released a few cybersecurity “bad practices” this week to assist in decreasing the volume of knowable and preventable cyber mistakes. These bad practices are aimed at educating critical infrastructure owners and operators, as well as the defense industry and the organizations that support the supply…
Privacy Tip #290 – 700 Million LinkedIn Users’ Data for Sale on Hacker Forum
Although a security researcher has confirmed that LinkedIn users’ data, including full names, gender, email addresses, telephone numbers, and industry information is for sale on RaidForums by a hacker self-dubbed “GOD User TomLiner,” LinkedIn has stated that it is not from a data breach of its networks. According to LinkedIn, “[O]ur initial analysis indicates that…
Phishing, Vishing, and Smishing—Your Employees Need to Know the Newest Schemes
New dictionary words have been formed to describe online scams. Phishing, one that everyone knows by now, is when a scammer uses a pretext in an email to get someone to click on a link or attachment in the email to deploy malicious malware and ransomware.
Social engineering is when criminals conduct online search of…
Prometheus Ransomware Targeting Manufacturing Sector
Since the Colonial Pipeline and JBS meat manufacturing security incidents, attention is finally being paid to the cybersecurity vulnerabilities of critical infrastructure in the U.S. and in particular, the potential effect on day to day life and national security if large and significant manufacturers’ production are disrupted. In the wake of these recent incidents in…
Colonial Pays Millions in Ransomware Attack on Pipeline
Colonial Pipeline paid hackers a ransom of $4.4 million in bitcoin soon after discovering a cybersecurity hack on its systems that began on May 6. The company’s acknowledgement comes after days of speculation about whether a ransom was paid to the hackers. The company’s CEO defended the “difficult” decision to pay the ransom, maintaining he…
Metropolitan Washington, D.C. Police Department Hit with Ransomware Attack
The Associated Press has reported that the Metropolitan Washington, D.C. police department has been the victim of a hacking incident for which the Russian-based ransomware group Babuk is claiming responsibility. According to the department, the FBI is investigating the incident.
It is reported that the department’s police operations were not affected. Babuk claims that it…
School Nutrition Vendor Sued for Compromise of 867,209 K-12 Student Records
PCS Revenue Control Systems, Inc. (PCS) was hit with a proposed class action lawsuit last week alleging that it discovered a data breach from a hacking attack in December 2019 but failed to notify the affected students until March of 2021.
According to the lawsuit, student information was collected by PCS’s predecessor, Advanced Business Technologies…
Ironic Justice: WeLeakInfo Users’ Information Compromised
In the category of “you can’t make this up but satisfyingly ironic,” it was recently reported that criminals who used the WeLeakInfo database to buy stolen credentials of individuals have had their own information compromised. It’s about time criminals get their just reward. Why would hackers treat other hackers any differently than the rest of…
Microsoft Releases Additional Resources for Exchange Flaws and CISA Issues Alert
As we alerted our readers last week, Microsoft announced that its Exchange email servers have been compromised, which is estimated to affect at least 30,000 companies based in the United States. It is reported that the hackers installed web shells (and sometimes multiple web shells) into Microsoft’s customers’ email servers, giving the hackers back doors…