Government

Industry

Ransomware Attack impacts City of Oakland, State of Emergency Activated

February 8, 2023

Oakland has declared a local state of emergency because of the impact of a ransomware attack. The state of emergency was declared to allow the City of Oakland to expedite orders, materials and equipment procurement, and activate emergency workers when needed. The ransomware attack impacted non-emergency services only, but many systems taken down immediately to contain the threat, are still offline a week later.

read more

Attempted Cyberattacks at Nuclear Research Laboratories in US in Summer ’22.

June 21, 2022

A Russian hacking team known as Cold River targeted three nuclear research laboratories in the United States this past summer, according to internet records reviewed by Reuters and five cyber security experts.
Between August and September Cold River targeted the Brookhaven (BNL), Argonne (ANL) and Lawrence Livermore National Laboratories (LLNL), according to internet records that showed the hackers creating fake login pages for each institution and emailing nuclear scientists in a bid to make them reveal their passwords.

Reuters was unable to determine why the labs were targeted or if any attempted intrusion was successful. A BNL spokesperson declined to comment. LLNL did not respond to a request for comment. An ANL spokesperson referred questions to the U.S. Department of Energy, which declined to comment.

read more

Vice Society Claims it Stole Leaked Data from San Francisco’s Bay Area Rapid Transit – BART

January 6, 2023

Vice Society, a prolific ransomware group, leaked data it claims to have stolen from San Francisco’s Bay Area Rapid Transit. BART’s spokesperson Alicia Trost: “We are investigating the data that has been posted.” “To be clear, no BART services or internal business systems have been impacted. As with other government agencies, we are taking all necessary precautions to respond.” Trost did not say whether ransomware was involved nor when the incident occurred.

Transit sector remains highly vulnerable. “They have the worst security by far generally. It’s run on tax money and it’s run as a bureaucracy, and their mission is to deliver transit,” which means they often don’t spend enough on cybersecurity or properly assess the risk, according to Chester Wisniewski, principal research scientist at Sophos.

read more

Ransomware Attack Paralyses Greek Postal Services

March 20, 2022

Ransomware hit ELTA encrypting its systems and halting operations in a major service disruption. “Threat actors exploited an unpatched vulnerability to drop malware that allowed access to one workstation using an HTTPS reverse shell.” To stop the spread, they shut down all data centres. Online parcel tracking and labelling is also down for customers. Full service was restored by April 6th.

Impact: Ransomware halted all mail, financial transactions and bill payments thru the national carrier

read more

Complete State Postal System Outage in Bulgaria

April 16, 2022

A major Russian-originated ransomware attack occurred on the Bulgarian State Post Office system. Six hours passed between the beginning of their attack and the moment when the servers were turned off and the system’s connection to the Internet was cut off. During this time, hackers had access to the entire database and were able to encrypt or even delete archives Hackers moved laterally into all IT and OT systems affecting all 26 services offered.

Besides affecting systems for payment and transfer of money, pensions, etc, the sending and receiving of post, domestic and international was interrupted for weeks. After a time, post could be received but only if the recipient did not owe amounts at time of delivery.

read more

Canada Post Customers Affected by Ransomware Attack at Supplier

May 26, 2021

Canada Post disclosed that a third-party supplier named Commport Communications suffered a ransomware attack where threat actors accessed data stored in their systems. This accessed data includes shipping manifest data for large parcel business customers, including sender and receiver contact information, names, and mailing addresses.

In total, the breach affected 44 Canada Post commercial customers and 950,000 receiving customers.

read more

Cyberattack Paralyzes Operations at Suffolk County Offices in NY

September 8, 2022

Since September 8, Suffolk County has been trying to recover from a cyberattack by a ransomware group known as “ALPHV” or “BlackCat.” The attack disabled the county’s 911 system as well as other services. The county reverted to older methods for handling essential county operations, dispatching, and paying bills. Real estate industry was most impacted by the cyberattack. Access was cut off to key records required in property sales transactions.

read more

Cybersecurity Attack at City of Dunedin, Pinellas County, Florida

October 5, 2022

Florida officials at City of Dunedin, in Pinellas county, discovered a cybersecurity attack on Wednesday October 5. The city is investigating. Dunedin says its Water and Wastewater Treatment Facilities, city phones and social media networks are all secure. As reported by MSN,
these operations are not available: city email, online payments for permits, utility billing, Parks & Recreation programs, inspection scheduling, and Marina fees.

read more

City of Tucson Discloses Data Breach Exposing 123K Individuals

May 17, 2022

The City of Tucson, Arizona, disclosed a data breach affecting the personal information of more than 123,000 individuals. The threat actors had access to the network between May 17 and May 31. They potentially accessed or stolen documents containing the information of 123,513 individuals.

“On May 29, 2022, the City learned of suspicious activity involving a user’s network account credential,” the data breach notification reads. “On August 4, 2022, the City learned that certain files may have been copied and taken from the City’s network.” The City began notifying potentially impacted individuals on September 23. The he attacker potentially accessed files included certain individuals’ name, Social Security number, driver’s license or state identification number, and passport number.

read more

Second Largest US Public School District in CA Hit by Ransomware Attack

September 5, 2022

A cyberattack prompted an unprecedented shutdown of The Los Angeles Unified School District, the second largest in the nation. The attack sounded alarms across the country, from urgent talks with the White House and the National Security Council after the first signs of so-called ransomware were discovered late Saturday night to mandated password changes for 540,000 students and 70,000 district employees. On September 30, the Los Angeles Unified School District said that cybercriminals who targeted it with a ransomware attack plan to release some of the hacked data online. LAUSD has not disclosed the ransom demanded by the criminal organization.

UPDATE: 500GB of data that was stolen during a cyberattack against the Los Angeles Unified School District (LAUSD) has been made public by hackers, media reports said on October 4.

read more