Other

Industry

Serious IT Breach at Wisag, German Aviation Services

January 27, 2022

Wisag, a German aviation services provider suffered a serious IT breach on Jan. 27. Operational business continued, but the processes were severely disrupted for about a week. Wages for 55,000 employees were paid late. Wisag board member Michael Wisser publicly insisted at the time that he would not allow himself to be blackmailed by criminals.

It’s not clear if it’s linked to the Mabanaft breach.

read more

Wisag Group Hacked Again a Year Later

February 9, 2023

Almost exactly a year after the first attack, the service group Wisag fell victim to hackers again. On Tuesday morning, the IT department found “irregularities” on the servers, said a spokeswoman for the Frankfurt-based company. As a result, all systems and applications were immediately taken off the network.

“At the current time, it is not apparent that customer or internal data has leaked,” it continues. “We are optimistic that we can safely put all systems back into operation as soon as possible.”

read more

Attack Disables Irrigation Systems and Disrupts Water Treatment Processes

April 9, 2023

Water controllers for irrigating fields in the Jordan Valley were damaged, as were control systems for the Galil Sewage Corporation. Several water monitors – which monitor irrigation systems and wastewater treatment systems – were left dysfunctional on Sunday after a cyber attack targeted the monitoring systems. Specifically, water controllers for irrigating fields in the Jordan Valley were damaged, as were control systems for the Galil Sewage Corporation.

The management for both major systems was pushing all of Sunday morning to work through the issue and bring the systems back into full operation. Farmers in the region were warned several days prior about suspicions over a planned cyber attack. Some of them, as a result of the warning, disconnected the remote control option for their irrigation systems and switched them to manual operation, instead, to prevent any harm from the attack. Indeed, those who left their systems on remote control were the ones impacted by the attack.

The attack is thought to be part of an annual “hacktivist” campaign that takes place every April, and this year’s attempt at least managed to cause a nuisance for some farms in the Jordan Valley. The cyber attack is part of an annual campaign called “OpIsrael,” which strikes in April with DDoS attacks and breach attempts on targets in the country.

Each year of the cyber attack campaign seems to bring new targets of opportunity. This year the threat actors put a special focus on irrigation systems. The Galil Sewage Corporation was one of the targeted wastewater processors that was breached, and the company reports that the cyber attack blocked several controllers for about a day and disrupted some treatment processes.

read more

Ransomware Attack at NCR

April 13, 2023

NCR is suffering an outage on its Aloha point of sale (PoS) platform after being hit by an ransomware attack claimed by the BlackCat/ALPHV gang.
NCR provides digital banking, PoS point of sale system, and payment processing solutions for restaurants, businesses, and retailers
On Friday, NCR released a statement saying: “On April 13, NCR determined that a single data center outage that is impacting some functionality for a subset of its commerce customers was caused by a cyber ransomware incident. Upon such determination, NCR immediately started contacting customers, enacted its cybersecurity protocol and engaged outside experts to contain the incident and begin the recovery process. The investigation into the incident includes NCR experts, external forensic cybersecurity experts and federal law enforcement.

read more

Business Operations Continue Manually After Cyberattack at Textile Logistics Company

December 6, 2022

On December 6th there was a successful cyber attack on the systems of the well-known textile logistics company Meyer & Meyer. The company can still be reached, but various processes had to be converted to manual work. The extent of the damage caused by the cyber attack is currently being checked and the system has started to be restored. “We reacted quickly and decisively to the targeted attack,” says Björn Plantholt, who is responsible for corporate communications at Meyer & Meyer. The company was able to maintain part of the business operations after the cyber attack, despite the systems being shut down, by switching to manual processes.

read more

ALMA Observatory Shutdown Impacts Scientist Worldwide.

October 29, 2022

The Atacama Large Millimeter Array (ALMA) Observatory in Chile has suspended all astronomical observation operations and taken its public website offline following a cyberattack on Saturday, October 29, 2022. Email services at the observatory are currently limited, and IT specialists are working toward restoring the affected systems.

The observatory is used by scientists of the National Science Foundation, the European Southern Observatory, the National Astronomical Observatory of Japan, and other groups from around the world, so any halt in its operations impacts multiple science teams and ongoing projects.

read more

Cyberattack at Intercontinental Hotel Group (IHG) disrupts Franchisees, Customers and Supply Chains

September 6, 2022

Leading hospitality company InterContinental Hotels Group says its IT systems have been disrupted after its network was breached. Customers reported widespread problems with booking and check-in. “Booking channels and other applications have been significantly disrupted since yesterday,” IHG said in an official notice lodged with the London Stock Exchange.

The attack disrupted business at franchisees during September, leaving a trail of angry customers, lost income and a class-action lawsuit. The hack on the hotel group highlights the potential ripple effects for franchisees, customers and supply chains, reports the WSJ.

The hotel chain giant was also the target of a three-month security breach in 2017—between September 29 to December 29—when more than 1,200 InterContinental franchised hotels in the United States were impacted. An IHG spokesperson denied commenting when contacted by BleepingComputer earlier today, saying that “outside of the statement, we don’t have any more that we can say at the moment.”

read more

Italian Waste Management Service IT Systems Down after Ransomware Attack

September 28, 2022

Redhotcyber.com (RHC) reported that a second computer attack against Alia Servizi Ambientali SpA was intercepted 6 months after the first. Alia issued a statement on their website stating they temporarily took IT systems offline and reported “from the checks carried out, the company confirms that there have been no intrusions and/or compromise of functions or data.”

Reportedly, the €400,000 ransom demanded was not paid. Systems operational 2 days later.

read more

Marriott Data Hack Compromised 5.2M Guest Records

January 15, 2020

Marriott International announced that approximately 5.2 million guests could be affected by a recent data breach. Upon discovery, the company disabled the compromised login credentials, immediately began an investigation, implemented heightened monitoring, and arranged resources to inform and assist guests. Marriott also notified relevant authorities and is supporting their investigations.

read more

Marriott System Breach Undetected for 4 Years (2014 to 2018)

May 31, 2014

The first part of the cyber-attack happened in 2014, affecting the Starwood Hotels group, which was acquired by Marriott two years later. But until 2018, when the problem was first noticed, the attacker continued to have access to all affected systems. On that basis, the ICO said Marriott had failed to protect personal data as required by the General Data Protection Regulation (GDPR)

Information Commissioner’s Office (ICO) dined Marriott hotel 18.4 Million pounds for the data breach.

read more