Cloud Provider

Industry

Cyberattack Adds Complication to Daily Lives of French Farmers

December 15, 2024

The IT platform hosting Synel and all other animal notification modules in south-west France has been hit by a cyber-attack. Since December 15, approximately 30,000 farmers in 22 departments in the southwest have been affected by a cyberattack. The Synel herd management software used by cattle, sheep and goat farmers is unusable. They have returned to the age of paper declarations.

The Synel software usually ensures the identification of animals by declaring birth, death or sale. Any change affecting the herd must be scrupulously reported within seven days. In the event of failure to comply with these obligations, farmers are exposed to financial penalties during checks.

read more

Customers affected after Cyberattack at Swedish IT Company

February 6, 2024

IT provider Advania was hit by a cyber attack on Tuesday attack.
Around 60 of the company’s customers are affected, of which between 10 and 15 are healthcare centres. “We cannot read any medical records or take any samples and can only write paper prescriptions. We cannot receive any patients,” says Per Svensson, director of operations at Herkules care center in Borås, to Borås Tidning. Some health centers have closed completely on Wednesday, while others receive patients on drop-in and write with paper and pencil because they do not have access to the medical record system.

There is no indication that ransomware has been introduced into the system. There is currently no forecast for when the problem may be fixed.

read more

Numerous Customers Suffer from Ransomware Attack at Cloud Provider Tietoevry

January 20, 2024

Cloud hosting services provider Tietoevry announced that one of its datacenters in Sweden “was partially subject to a ransomware attack” this weekend, affecting numerous customers and forcing stores to close across the country.

According to the Finland-based technology company’s statement on Monday, the attackers used the Akira ransomware-as-a-service tools. The incident was limited to “one part of one of our Swedish datacenters” and is believed to have only impacted services to some of Tietoevry’s customers in Sweden. However, these customers include Primula, a widely used payroll and HR company in Sweden, including by the majority of the country’s universities and more than 30 government authorities. Staff at these organizations cannot submit personal leave or expenses requests.

Primula customers include the Swedish State Service Centre (SSC), which itself manages administrative services including payroll for nearly 170 government agencies. Swedish businesses currently reporting issues due to the incident include cinema chain Filmstaden and retailer Rusta. As a result of the ransomware attack, Granngården announced its grocery stores across the country would be closed on Monday.

On April 24, the company reports: With the exception of efforts continuing with few customers, all other impacted customer services were fully restored by mid-March.

read more

Dropbox Cybersecurity Incident Isolated to Dropbox Sign Infrastructure.

April 24, 2024

Dropbox said a cybersecurity incident “has not had, and we do not believe it is reasonably likely to have” a material impact on overall operations. The episode was isolated to Dropbox Sign infrastructure, and did not impact any other Dropbox products.

The cloud-storage company earlier reported unauthorized access to data such as email, user names, phone numbers and hashed passwords. The company said there was no evidence that intruders accessed account contents.

read more

Outage Affected All LucidLink Customers

April 29, 2024

LucidLink experienced a malicious attack resulting in an outage that affected all customers. Access was fully restored for everyone on May 1, 2024 at 12:06 UTC.

The company believes that, “the root cause of the event to be malicious exploitation of an internal server with access to the production environment. This server was utilized to gain elevated privilege and to execute a script that corrupted the disk attached to each metadata server.”

As LucidLink clients became disconnected, they contact the discovery service to determine the IP address of the metadata server they need to reconnect to. Having all of the company’s clients attempt to do this at once overloaded the discovery service, leading the company to initially suspect a DDoS attack.

read more

Malware Cloaked as Fixes and Updates Exploit Global Crowdstrike Outage

July 30, 2024

Threat actors are exploiting the massive business disruption from CrowdStrike’s glitchy update on Friday to target companies with data wipers and remote access tools. As businesses are looking for assistance to fix affected Windows hosts, researchers and government agencies have spotted an increase in phishing emails trying to take advantage of the situation. CrowdStrike says it “is actively assisting customers” impacted by the recent content update that crashed millions of Windows hosts worldwide. The company advises customers to verify that they communicate with legitimate representatives through official channels since “adversaries and bad actors will try to exploit events like this.”

The CrowdStrike crash was caused by human error.

read more

Cloud Provider Snowflake Suffers Snowballing Data Breach

April 14, 2024

The number of alleged hacks targeting the customers of cloud storage firm Snowflake appears to be snowballing into one of the biggest data breaches of all time. The earliest evidence of unauthorized access to Snowflake customer instances occurred on April 14, according to Mandiant’s June 10 threat intelligence report on the attacks.

Alleged affected customers are Ticketmaster (560 million records), Santander (30 million records), automotive giant Advance Auto Parts (380 million records/3TB),LendingTree and QuoteWizard (190 million records/2TB). Neither LendingTree nor Advance Auto Parts has filed breach notifications with the Securities and Exchange Commission at this time.

read more

Ransomware Attack on Thousands of VMware ESXi Servers

February 3, 2023

A vast ransomware infection campaign hits VMware ESXi servers around the world on February 3. The scale suggests an automated operation.

Admins, hosting providers, and the French Computer Emergency Response Team (CERT-FR) warn that attackers actively target VMware ESXi servers unpatched against a two-year-old remote code execution vulnerability to deploy a new ESXiArgs ransomware. Tracked as CVE-2021-21974, the security flaw is caused by a heap overflow issue in the OpenSLP service that can be exploited by unauthenticated threat actors in low-complexity attacks.

While the threat actors behind this attack claim to have stolen data, one victim reported in the BleepingComputer forums that it was not the case in their incident. Victims have also found ransom notes named “ransom.html” and “How to Restore Your Files.html” on locked systems. Others said that their notes are plaintext files.

read more

ALPHV/Blackcat Reportedly Demands ‘8 figure’ Ransom from Western Digital

March 26, 2023

On March 26 hackers breached Western Digital’s

Hackers breached data storage giant Western Digital internal network and stole company data. They claim to have stolen around 10 terabytes of data from the company, including reams of customer information. The extortionists are pushing the company to negotiate a ransom — of a “minimum 8 figures” — in exchange for not publishing the stolen data.

The ALPHV ransomware operation, aka BlackCat, has published screenshots of internal emails and video conferences stolen from Western Digital, indicating they likely had continued access to the company’s systems even as the company responded to the breach Western Digital declined to comment regarding the leaked screenshots and claims by the threat actors.

read more

German Cloud Service Provider Hacked

May 20, 2023

The hosted exchange of the German provider United Hoster suffered a ransomware attack on Saturday (May 20th). “As part of an internal investigation, it was determined that an attacker exploited an unknown vulnerability in Microsoft Exchange to gain access to the Exchange Server,” a company spokesman told heise online

United Hoster is building a new Microsoft Exchange environment into which customers will eventually be migrated so that they can receive the full range of functions again. The company does not provide information about the number of affected customers or mailboxes, as this is a business secret. It is also unclear when United Hoster expects to restore services in the new structure. The company spokesman did not specify which Exchange security gap the attackers were able to abuse.

read more