Communications

Industry

Australian Infrastructure Services Provider Takes Down Systems

July 8, 2023

The Australian infrastructure services provider Ventia says a cyberattack on the weekend of July 8 and 9 is contained. The attack on the Sydney-headquartered essential infrastructure services provider caused it to take key systems offline. However, in a July 12 statement, Ventia says its key internal systems have been safely re-enabled and external-facing networks are systematically being restored. Ventia is giving little away about the nature of the cyberattack, but the company’s decision to shut down its systems is a characteristic response to a ransomware-style attack.

An APAC Analyst Technical Director at DarkTrace says some of Ventia’s systems were offline for at least three days and switching off services would significantly impact customers. “Ventia are an important pillar in the management of critical infrastructure. They operate sites across Australia and New Zealand on behalf of defence, electricity, gas, and water companies,”

read more

Italtel Cyberattack Claimed by Medusa

September 25, 2023

On Monday 25 September, the Italian company Italtel was the victim of a cyber attack. The cyber attack impacted Italtel’s IT infrastructure, limiting access and use of some company systems. The situation continues to evolve. The Italtel affair adds to the many IT incidents involving large Italian companies.
Italtel has already started communicating with its customers and suppliers about the cyber attack. Any subsequent interactions will be managed by the competent figures within the company.

The Medusa ransomware criminal gang claims the ransomware attack, Italtel has as of today not confirmed the attack. Italtel’s target markets are Telco & Media, Industry & Manufacturing, Energy & Transportation, Banking & Insurance, Healthcare and Public Administration.

read more

Satellite Communications System Serving the Russian military Knocked Offline

June 30, 2023

A group of previously unknown hackers has claimed responsibility for a cyberattack on the Russian satellite communications provider Dozor-Teleport, which is used by energy companies and the country’s defense and security services.

Doug Madory, the head of internet analysis at the network monitoring company Kentik confirmed to Record Future News that Dozor-Teleport has been disconnected from the internet and is currently unreachable. Dozor’s parent company, Amtel Svyaz, also suffered a significant outage late on Wednesday, according to Madory.

The hackers claim that they damaged some of the satellite terminals and leaked and destroyed confidential information stored on the company’s servers. The group posted 700 files, including documents and images, to a leak site, as well as some to their newly created Telegram channel.

The group claims to be affiliated with the notorious Wagner Grouphackers. There was no mention of the hack on the official Telegram channel of the Wagner Group and several experts expressed skepticism that the group was involved.

Dozor did not respond to inquiries about the attack.

read more

Cyberattack Causes Widespread Operational Disruption at Rheinische Post Mediagruppe

June 16, 2023

The “Rheinische Post Mediengruppe” has to shut down some systems because of a cyberattack. The operation of the news portals is only possible to a limited extent. Emergency editions of the affected newspapers were published on Monday. Unfortunately, the printed and digital editions cannot be offered in the usual structure, stated the “Rheinische Post”.

Individual technical systems had to be switched off and the connection to the Internet had to be cut, according to the “Rheinische Post”. The “Aachener Zeitung”, which belongs to the media group, addressed the readers on the first page and wrote of an emergency edition “that does not fully correspond to what you are used to from us”. The Bonn “General-Anzeiger” reacted with an edition that appeared “not in the usual scope and in the usual timeliness”.

read more

Lumen Hit By Separate Ransomware, Malware Attacks

March 27, 2023

Multibillion-dollar telecommunications firm Lumen Technologies told regulators Monday that it had discovered two cybersecurity incidents, including a ransomware attack that crippled some of its systems, that degraded services for some of its enterprise customers.

Lumen said that it caught the ransomware attack when a “malicious intruder” inserted malware “into a limited number of the Company’s servers that support a segmented hosting service.” The company did not immediately respond to questions about the type of ransomware involved, the scope of the attack, or whether they have attributed it to a specific group. The company said that the incident “is currently degrading the operations of a small number of the Company’s enterprise customers.”

Additionally, the company said that it discovered a separate incident involving an intruder accessing and installing malware on “internal information technology systems,” allowing the cybercriminal to steal “a relatively limited amount of data.”

read more

Swiss, German-Language Newspaper NZZ Shut Down Production

March 24, 2023

The “Neue Zürcher Zeitung” continues to struggle with problems two weeks after a cyberattack on its computers. The publisher shut down central systems for newspaper production and had to pre-produce the Saturday edition on Thursday of last week. The company announced on Saturday that this “exceptional situation” was also associated with a reduction in scope.

Due to the cyberattack, some systems and services are still not available. NZZ’s IT team is working with external specialists on corrective measures, it said. Newspapers from CH-Media-Verlag, which obtains IT services from NZZ, also appeared on a reduced basis over the weekend.

A ransomware attack on the infrastructure of NZZ’s parent, NZZ Mediengruppe in Zürich, became known two weeks ago. 500GB data stolen from this was later published on the dark web.

Additional impact at three media companies:
On May 3, CH Media confirmed that data had been published, saying, “initial analyses show that the data is from our delivery organisations”.
The Blick Group is affected as a company that belongs to CH Media is responsible for the postal delivery of the Blick newspapers, and is directly affected by the cyber attack.
Customer data from Tamedia newspapers is also said to be affected

read more

Accellion-related Data Breach Reported by Singtel

February 11, 2021

Singtel, the largest mobile carrier in Singapore, announced that they suffered a data breach caused by the Accellion FTA service’s vulnerability.

“A third-party file sharing system provided by Accellion called FTA has been illegally accessed through a zero-day vulnerability or previously unknown vulnerability. Singtel uses this system to share information internally as well as with external stakeholders and organisations,” Singtel announced in a security incident notification.

The telecommunications company has not disclosed what data has been accessed in the attack and states that they are currently investigating who was impacted.

read more

Philadelphia Inquirer Unable to Print Sunday Paper

May 11, 2023

The Philadelphia Inquirer was hit with a cyberattack that resulted in significant disruptions to its operations. It was unable to print its Sunday paper on May 14, and it had to scramble to restore several systems. The paper closed its office through Tuesday and the newspaper is working with “third-party forensic specialists from Kroll to restore systems and fully investigate the matter,” according to the emailed statement.

With the timing of the attack right before the city’s mayoral primary election, political motivation is a possibility. The Philadelphia Inquirer has not made any ransom demands public, nor is it clear if the information of employees or customers has been compromised, according to The Philadelphia Inquirer coverage.

read more

T-Mobile Data Breach Hits 37 Million

November 25, 2022

U.S. wireless carrier T-Mobile said an unidentified malicious intruder breached its network in late November and stole data on 37 million customers, including addresses, phone numbers and dates of birth.

T-Mobile said in a filing with the U.S. Securities and Exchange Commission that the breach was discovered Jan. 5. It said the data exposed to theft — based on its investigation to date — did not include passwords or PINs, bank account or credit card information, Social Security numbers or other government IDs.

“Our investigation is still ongoing, but the malicious activity appears to be fully contained at this time,” T-Mobile said, with no evidence the intruder was able to breach the company’s network. It said the data was first accessed on or around Nov. 25.

T-Mobile, based in Bellevue, Washington, became one of the country’s largest cellphone service carriers in 2020 after buying rival Sprint. It reported having more than 102 million customers after the merger.

read more

T-Mobile Hit Again

February 24, 2023

While it may seem like a small attack, T-Mobile disclosed its second data breach this year after the company found attackers accessed personal information of over 800 customers in late February.
The first breach, which the company discovered in early January, hit 37 million customers. This attack affected 836 customers, according to a notification to the Maine Attorney General’s office.
The breach occurred between Feb. 24 and March 30, according to the notification. The Bellvue, Washington-based T-Mobile said it discovered the issue March 27. The information the attackers acquired entailed name and driver’s license number or non-driver identification card number.

read more