Government

Industry

Costa Rica Declares National Emergency in Response to Ransomware Attack

April 11, 2022

For the last two months (April/May 2022) Costa Rica has been under siege. Two major ransomware attacks have crippled many of the country’s essential services, plunging the government into chaos as it scrambles to respond. Officials say that international trade ground to a halt as the ransomware took hold and more than 30,000 medical appointments have been rescheduled, while tax payments have also been disrupted. Millions have been lost due to the attacks, and staff at affected organizations have turned to pen and paper to get things done.

Impact: 8 Major Gov. Agencies and services shutdown (30+ hit in total). National State of Emergency declared by President. Can’t collect taxes, delays processing imports/exports, 10k+ public employees can’t be paid. Medical attention and surgeries delayed or halted due to attack on Public Health (CCSS), container freight shipments slowed to a trickle at the port of Limón

Conti claimed responsibility for the first attack against Costa Rica’s government and is believed to have some links to the ransomware-as-a-service operation HIVE, which was responsible for the second attack impacting the health care system.

read more

City of Shanghai Health App Hack Affects over 48.5 Million Mandatory Users.

August 1, 2022

A hacker has claimed to have obtained the personal information of 48.5 million users of a COVID health code mobile app run by the city of Shanghai, the second claim of a breach of the Chinese financial hub’s data in just over a month.The hacker with the username as “XJP” posted an offer to sell the data for $4,000 on the hacker forum Breach Forums on Wednesday. The hacker provided a sample of the data including the phone numbers, names and Chinese identification numbers and health code status of 47 people.

The app collects travel data to give people a red, yellow or green rating indicating the likelihood of having the virus and users have to show the code to enter public venues. All residents and visitors have to use it.

read more

City of Lafayette, CO Opts to Pay Ransom of $45,000

July 27, 2020

Lafayette, Colorado fell victim to ransomware on July 27, which encrypted the city’s computer networks and caused disruptions to phone services, email and online-payment and reservation systems. It’s thought that the unidentified ransomware entered the city’s network via a phishing or brute force attack. Lafayette opted to pay the cyber criminals perceiving it to be the quickest and most cost effective way to restore municipal services to residents.

Other cities across the US have paid hundreds of thousands of dollars to criminals in exchange for returning the network.

read more

Magecart attacks Plague the Already Troubled Payment Platform Click2Gov

April 10, 2020

A new wave of data breaches in eight U.S. city governments is the work of online scammers using malicious code against the troubled online payments platform Click2Gov, according to research published Friday by the cybersecurity firm TrendMicro. The attacks involved Magecart-style attacks, in which lines of JavaScript code are injected into e-commerce platforms to rip off financial and personally identifiable information, like credit card numbers, names, addresses and other credentials. Click2Gov has for several years posed data-security problems for as many as 6,000 local governments across the United States who use Click2Gov. But according to TrendMicro, there’s no evidence directly linking the recent Magecart-style attacks to incidents in 2018 and 2019. Still, five of the eight cities analyzed had been victims of previous Click2Gov breaches.

Magecart attacks have plagued corporate websites, including big-name targets like British Airways, Ticketmaster and more than 2 million other websites, according to research published last October.

read more

Town of Erie, CO Loses over $1M in Business Email Compromise Scam.

November 13, 2019

A hacked email account scammed the Town of Erie to wire $1 million to a falsified contractor’s account. The FBI is still investigating the case. These comments were offered on the matter: on November 13, 2019, the Erie Police Department opened an investigation into a cyber intrusion which had affected the Town of Erie. The Erie Police Department contacted the FBI Denver Division and requested assistance with the investigation. There is a Canadian Internet Service Provider (ISP) the unknown suspect used. The Internet Provider (IP) Address of the unknown suspect who completed the electronic ACH Enrollment form is in Canada. This Internet Provider (IP) in Canada will not cooperate with this investigation. The FBI continues to look into this aspect of the case.

read more

SamSam Ransomware Takes Down Colorado DOT

February 21, 2018

The Colorado Department of Transportation (CDOT) was hit by a SamSam ransomware attack that penetrated a temporary system being tested without full security. Once inside, bad actors used it to access CDOT, ultimately affecting roughly half its computing environment, around 400 servers, all databases and applications and around 1,300 workstations. The agency was back to 80 percent functionality six weeks after the ransomware attack, at an estimated cost of up to $1.5 million. The state’s new backup system prevented data loss, but personal data on employees’ computers may not be recovered.

read more

Ransomware Attack Shuts Down City of Atlanta, GA,

March 22, 2018

On March 22, 2018, Atlanta’s connected systems city-wide were hit with a ransomware message locking their respective files and demanding an approximately $50,000 payment in bitcoin (the price has fluctuated since). The ransomware is believed to be from the group known as SamSam, which has been operating and executing similar attacks since at least 2015. Atlanta residents were unable to do simple city system-dependent tasks like paying parking tickets or utility bills. City employees didn’t get the all-clear to turn on their computers until five days later and many city systems still have not recovered. The cyberattack took more than one-third of Atlanta’s 424 software programs offline or partially offline. The first month of recovery cost almost $3 million.

read more

Exponential Rise in IRS-Themed SMS Phishing Attacks in U.S.

September 28, 2022

The Internal Revenue Service (IRS) warned Americans of an exponential rise in IRS-themed text message phishing attacks trying to steal their financial and personal information in the last few weeks. “In recent months, the IRS has reported multiple large-scale smishing (MMS/SMS/text scams) campaigns targeting taxpayers, that have delivered thousands – and even hundreds of thousands – of IRS-themed messages in hours or a few days, far exceeding previous levels of activity.”

The Federal Communications Commission (FCC) issued a similar warning in July 2022. According to the U.S. communications watchdog’s Robocall Response Team, these phishing messages (or robotexts as the FCC calls them) will hit billions of phones every month.

read more

$600K demanded in Dominican Agrarian Institute Quantum Ransomware Attack,

August 18, 2022

The Dominican Republic’s Instituto Agrario Dominicano has suffered a Quantum ransomware attack. The attack encrypted multiple services and workstations throughout the government agency. The Instituto Agrario Dominicano (IAD) is part of the Ministry of Agriculture and is responsible for executing Agrarian Reform programs in the country. “They ask for more than $600K. We were affected by four physical servers and eight virtual servers; virtually all servers,” IAD Director of Technology Walixson Amaury Nuñez told local media. The National Cybersecurity Center (CNCS) says that the IP addresses of the attackers were from the U.S. and Russia.

Quantum is becoming a major player among enterprise-targeting ransomware operations, linked to an attack on PFC that impacted over 650 healthcare orgs

read more