According to a press release, Personal Touch, a home health company located on Long Island, has reached a settlement with New York Attorney General Letitia James for $350,000 for a data breach that occurred in January of 2021 when a Personal Touch employee “opened a malware-infected file attached to a phishing email that allowed
phishing
AI Phishing Attacks Illustrate the Importance of Employee Awareness
Retool, a software development firm offering modular code for customizable enterprise software, recently notified 27 customers that a threat actor had accessed their accounts. The attacker was able to navigate through multiple layers of security controls after taking advantage of an employee through an SMS-based phishing attack. The attacker then used this access to target…
CISA Issues Three Advisories for Industrial Control Systems
On May 16, 2023, the Cybersecurity & Infrastructure Security Agency (CISA) released three advisories applicable to Industrial Control Systems (ICS). The Alerts cover vulnerabilities of Snap One OvrC Cloud, Rockwell ArmorStart, and Rockwell Automation Factory Talk Vantagepoint.
The Snap One vulnerabilities, if exploited, “could allow an attacker to impersonate and claim devices, execute arbitrary…
Threat Groups Using Translation Tools in Phishing Attacks
It used to be that one of the sure ways to identify a phishing email was to notice grammatical errors or broken English in the text of the communication. Thanks to new translation tools like Google Translate, which are available worldwide, threat actors can translate a phishing email into any language, so it sounds authentic…
Beware of Luna Moth Callback Phishing Scam
Palo Alto’s Unit 42 recently issued a threat assessment alert outlining a new, unique phishing scam that has been successful. The scam is believed to have been carried out by the Luna Moth/Silent Ransom Group and is targeting businesses in the legal and retail sectors. Unit 42 predicts that the scam is “expanding in scope.”…
Acronis Reports Ransomware Damages Will Exceed $30B by 2023
In its Mid-Year Cyberthreat Report published on August 24, 2022, cybersecurity firm Acronis reports that ransomware continues to plague businesses and governmental agencies, primarily through phishing campaigns.
According to the report over 600 malicious email campaigns were launched in the first half of 2022, with the goal of stealing credentials to launch ransomware attacks. Other…
Privacy Tip #336 – Facebook Accounts Stolen Through Phishing Schemes Using Messenger Chatbots
Trustwave has reported a new scheme in which threat actors are using the popular Facebook Messenger platform to steal Facebook login credentials.
According to the report, the threat actors are using a phishing email to Facebook users that employs Meta’s Messenger chatbot feature. The message states that the user’s page will be terminated because the…
“Well frens, it happened to me;” Actor’s Stolen NFTs Highlight Uncertainties for NFT Artwork
Actor and comedian Seth Green, best known for creating Robot Chicken and portraying Dr. Evil’s son in the Austin Powers franchise, announced on Twitter last month that phishers stole his four “Bored Ape” NFTs. Let’s break down that mouthful: NFTs are a blockchain technology that creates indisputable ownership records that the art world has embraced…
Privacy Tip #332 – Chatbots Used to Steal Credentials
I am not a huge fan of using chatbots, as I never end up getting my questions fully answered. I get the efficiency of using a chatbot for simple questions, but my questions are usually not so easily resolved, so I end up completely frustrated with the process and trying to find a human being…
Mailchimp Suffers a Data Breach
This week we learned that the email and social media marketing company Mailchimp suffered a data breach that allowed an intruder to view 319 Mailchimp accounts. According to multiple sources, audience data were accessed from 102 of those accounts.
It was reported that the threat actor was able to breach Mailchimp’s systems through social engineering…