Business

Industry

Sault Tribe Cyberattack Forces System Shutdowns

February 9, 2025

In February 2025, the Sault Ste. Marie Tribe of Chippewa Indians in Michigan was hit by a major ransomware cyberattack that forced the shutdown of computer and phone systems across tribal government offices, health centers, businesses and all five of its Kewadin Casinos beginning February 9, 2025. Tribal leaders immediately took systems offline, engaged cybersecurity experts, and refused to pay the hackers’ ransom demand, opting instead to restore operations and strengthen IT defenses. The phased reopening of the casinos began on February 26, 2025, and most services were restored in the following weeks, though some health and administrative functions continued under limited capacity during forensic review.

read more

Tungsten Automation Hit In Cyberattack

May 27, 2025

Irvine, California-based Tungsten Automation Corporation, formerly known as Kofax Inc. before its name change, suffered a cyberattack where personally identifiable information ended up stolen from victims.
“On May 27, 2025, Tungsten Automation discovered suspicious activity occurring on its internal IT networks,” the company said in a letter to victims. “Tungsten Automation immediately began an investigation, engaged third-party cybersecurity experts, and notified law enforcement.”
The company said its investigation found an unauthorized party accessed Tungsten’s internal IT network and obtained certain files in May.

read more

TN Security, Benefits Provider Hit in Cyberattack

March 30, 2025

Memphis, Tennessee-based Coalesce, LLC dba Benefitelect (BEI), a full-service employee benefits administration platform and cybersecurity provider, suffered a cyberattack in March and is now informing victims of the attack.
“On April 2, 2025, BEI was alerted to suspicious activity on its systems,” the company said in a notice to victims. “After becoming aware of this activity, we quickly took steps to secure the system and launched an investigation with the assistance of a third-party specialist to determine the nature and scope of the activity.”
The investigation found certain files ended up accessed and/or exfiltrated without authorization between March 30 and March 31.

read more

Data Breach at Colorado-based Trinity Petroleum Management

October 14, 2024

Denver, Colorado-based Trinity Petroleum Management, LLC suffered a cyberattack after discovering an unauthorized party was able to access information that had been provided to the company.
Trinity Petroleum said the incident resulted in an unauthorized party being able to access consumers’ personally identifiable information, which includes first and last names, addresses, and Social Security numbers. The incident affected 46,659 victims, the company said in an advisory.

read more

Over 46 Japanese Businesses, incl Banks and Government Agencies,Targeted by Cyberattacks

January 9, 2025

At least 46 Japanese entities, including banks and government agencies, were targeted by cyberattacks utilizing the same malware, causing temporary service suspensions. According to Trend Micro Inc., Japan Airlines Co., NTT Docomo Inc. and major banks were among the victims of distributed denial-of-service, or DDoS, attacks in which networks are overwhelmed by data from multiple sources over a short period, causing temporary service suspensions. The Japan Weather Association said on Thursday it was hit by a cyberattack that rendered its information website inaccessible for over nine hours from around 7 a.m. A similar cyberattack on Sunday that affected both the web and app versions of the weather site took over 7 hours to resolve.

“We can’t rule out the possibility that multiple groups conducted attacks at the same time,” a Trend Micro official said. The hackers were able to simultaneously control devices including cameras and home appliances connected to the internet to carry out the attacks, the security firm said.

read more

Widespread Issues Reported after Cyberattack on US Business Services Giant and Government Contractor Conduent

January 22, 2025

American business services giant and government contractor Conduent confirmed that a recent outage resulted from what it described as a “cybersecurity incident. One week ago, the govtech giant also said it “supports approximately 100 million U.S. residents across various government health programs.”

The outage affected customers’ operations across multiple U.S. states, impacting organizations such as the Wisconsin Department of Children and Families, Oklahoma Human Services, and others. This caused widespread issues for those relying on the affected organizations to make payments via electronic transfer or EBT cards.

“We experienced a service interruption that affected the Wisconsin Support Collections Trust Fund’s ability to process payments,” Conduent told BleepingComputer on Tuesday, two days after restoring systems and bringing services back online for Wisconsin’s Department of Children and Families.

“The Conduent technology team worked to resolve the issue. We sincerely regret the inconvenience this incident may have caused.”

read more

National Outage at Omni Hotels after Cyberattack

March 29, 2024

Omni Hotels & Resorts has been experiencing a chain-wide outage that brought down its IT systems on Friday, impacting reservation, hotel room door lock, and point-of-sale (POS) systems.

The official website was down on Friday, and an alert was added after it came back online over the weekend, warning customers, “Dear valued guest, we are currently experiencing technical difficulties, please try back at a later time.”

According to some Omni Hotels employees, the IT team is now manually restoring affected servers from scratch, with staff being informed that systems will be available again on Thursday.

Omni Hotels & Resorts was the recent target of a ransomware attack by the Daixin Team ransomware group. The incident led to disruptions across Omni Hotels & Resorts, and the Daixin Team and claimed the theft of information pertaining to visitors from 2017 onwards.

“The attack is already pretty significant; however, considering the ransom amount has been dropped and the systems have been restored, it is likely that Omni Group has a good backup of information. Financial information is probably protected through encrypted to PCI requirements.

“This is a new target vertical for the Daixin ransomware group. In the past, they have mainly gone after healthcare providers.

read more

Data Breach at Australian Ticketek

June 1, 2024

Ticketek has been hit by a “cyber incident” with personal information of Australian customers stolen from a third-party global cloud-based platform. The incident affected many Australians but appears restricted to the release of names, dates of birth and email addresses.

read more

Class-action Lawsuit Follows Cyberattack at Findlay Automotive

June 10, 2024

Findlay Automotive shared that a June 10 cybersecurity issue impacted its sales and service departments. Since June 10, Findlay Automotive hasn’t shared much information on the nature of the ransomware attack or the impact on its customers. The company said vehicle sales couldn’t be finalized, service appointments couldn’t be scheduled online and only cash payments could be accepted. The company didn’t answer questions on when its systems got back to normal or how it was able to return to normal.

In the wake of the cyberattack, the company was hit with two class-action lawsuits last month that allege Findlay Automotive didn’t properly protect customers’ sensitive financial and personal information.

It is unknown at this time if this attack was part of the widespread CDK attack reported a month later.

read more