Software

Industry

Data Leak at Alexion Pharmaceuticals after Vendor’s Systems Compromised

May 14, 2024

On May 14, 2024, Alexion Pharmaceuticals (“Alexion”) filed a notice of data breach with the Attorney General of Vermont after discovering that a vendor used by the company experienced a data security incident.

In this notice, Cisiv explains that the incident resulted in an unauthorized party being able to access consumers’ sensitive information, which includes their name, address, email address, and phone number, as well as information regarding surveys taken regarding Alexion’s products.

read more

AI Platform for Learning and Work Automation Loses $250K in Cyber Incident

November 18, 2024

iLearningEngines, Inc. lost $250,000 in a cybersecurity incident after an attacker gained access to files on its network and misdirected a wire payment. The company has not recovered the wire payment.

Maryland-based iLearningEngines has developed a platform that uses AI to deliver personalized and automated learning, as well as work automation capabilities that organizations can use to custom-design workflows and optimize processes.

read more

TEAM Software Suffers Cyberattack

July 25, 2024

Workforce management software provider, TEAM Software, suffered a cyberattack where threat actors made off with personal information of its victims.
On July 26, Holmdel, New Jersey-based TEAM Software detected unusual activity on platforms and quickly launched an investigation, with the assistance of third-party cybersecurity and forensics specialists to determine the nature and scope of the event.
The investigation found an unauthorized actor gained access to certain TEAM Software systems and that information contained in those systems ended up potentially accessed or taken by the unauthorized actor between July 25 and July 26. The company recorded 99,525 victims in the attack

read more

Cyberattack at PSI Systems, a German Industrial Software Co.

February 15, 2024

PSI Software SE, a German software developer for complex production and logistics processes, has confirmed that the cyber incident it disclosed last week is a ransomware attack that impacted its internal infrastructure. The IT systems and the extent of the impacts are currently being checked.

The company operates at a global level with a staff of more than 2,000 and specializes in software solutions for major energy suppliers.

read more

Microsoft Azure Outage Amplified by Fumbled DDoS Defense Strategy Implementation

July 30, 2024

Microsoft confirmed today that a nine-hour outage on Tuesday, which took down and disrupted multiple Microsoft 365 and Azure services worldwide, was triggered by a distributed denial-of-service (DDoS) attack. The company has yet to link it to a specific threat actor. “While the initial trigger event was a Distributed Denial-of-Service (DDoS) attack… initial investigations suggest that an error in the implementation of our defenses amplified the impact of the attack rather than mitigating it,” said an update on the website of the Microsoft Azure cloud computing platform.

It comes less than two weeks after a major global outage left around 8.5 million computers using Microsoft systems inaccessible, impacting healthcare and travel, after a flawed software update by cybersecurity firm CrowdStrike.

read more

Malware Cloaked as Fixes and Updates Exploit Global Crowdstrike Outage

July 30, 2024

Threat actors are exploiting the massive business disruption from CrowdStrike’s glitchy update on Friday to target companies with data wipers and remote access tools. As businesses are looking for assistance to fix affected Windows hosts, researchers and government agencies have spotted an increase in phishing emails trying to take advantage of the situation. CrowdStrike says it “is actively assisting customers” impacted by the recent content update that crashed millions of Windows hosts worldwide. The company advises customers to verify that they communicate with legitimate representatives through official channels since “adversaries and bad actors will try to exploit events like this.”

The CrowdStrike crash was caused by human error.

read more

BlackSuit Ransomware Attack at CDK Global Causes Widespread Disruption

June 19, 2024

On June 19 CDK Global, a major car dealership software company suffered a cyberattack prompting the company to take all systems offline “out of an abundance of caution.” Reuters reported CDK took down its dealer management system at more than 15,000 retail locations.

The outage has impacted about half of Volkswagen dealers and around 60% of Audi’s dealers and several card retailers also flagged disruptions. Dealers moved back to traditional pen and paper format to conduct operations. As a result new car sales for June are projected to fall.

The hacker group was identified as BlackSuit. As of Wednesday, July 3, the company is still working to get all impacted dealers back online. The date all dealerships using CDK are expected to be back online following the attack is July 4.

COST: A study from the Anderson Economic Group (AEG) estimated losses of over $1 billion for auto dealerships during the outage. The ransomware group reportedly received $25million. CDK agreed to pay $100Million in class action settlement

read more

Radiant Logistics Isolates Canadian Operations after Cyberattack

March 14, 2024

Radiant Logistics, an international freight technology company said it has cut off a portion of its business in Canada after a cyberattack. The Company proactively took measures to isolate its Canadian operations from the rest of its network. The incident has caused service delays for customers in Canada.

Despite the shutdown, the filing says the incident is not “reasonably likely to materially impact the Company’s financial conditions.” No ransomware gang has taken credit for the incident.

read more

Switserland: Federal Passwords and Classified Information Stolen

May 23, 2023

On May 23, the Play ransomware group claimed it attacked Xplain – a Swiss IT firm providing services to several federal agencies in the country. The ransomware group leaked the files it stole from the company on June 1, which it claimed included 907 GB of financial and other data.

In March, 2024 SWI news reports that federal passwords and classified information were stolen in the >2023 cyberattack

read more

Hackers Exploits Critical Security Hole in Atlassian Software

October 31, 2023

Software company Atlassian is now saying that a recently disclosed issue is being exploited by hackers using the Cerber ransomware — a ransomware brand thought to be long-defunct. Atlassian CISO Bala Sathiamurthy warned the public on November 3 about the bug, which he said could lead to “significant data loss if exploited.” The company escalated this on November 6, 2023 following evidence of malicious activity, including ransomware attacks.”

The Cerber ransomware operation was active between 2016 and 2019. Several ransomware experts said they had not seen the Cerber ransomware used in years.

read more