Technology

Industry

Schneider Electric Sustainability Business Hit by Cactus Ransomware Gang

January 17, 2024

Schneider Electric confirmed a ransomware attack that affected its Sustainability Business division. The attack disrupted some of Schneider Electric’s EcoStruxure Resource Advisor cloud platform. The Cactus ransomware gang claims they stole 1.5TB of data. 25MB of allegedly stolen were also leaked on the operation’s dark web leak site today as proof of the threat actor’s claims. It is not known if Schneider Electric will be paying a ransom demand.

At a recent PASA Connect roundtable event, three of the 13 Chief Product Officers in attendance confirmed minor issues related to the incident.

read more

TSMC Hit by WannaCry Variant

August 3, 2018

The cyber attack on iPhone supplier TSMC was apparently caused by a WannaCry variant, the company has revealed. The severity of the attack caused the company to shut down some of its factories while the issue was fixed, which meant some plants were out of action for days. Although the problem has mostly been rectified now, it says it’s still expecting shipments to be delayed for some time.

The virus was injected into TSMC’s systems when a supplier reportedly installed infected software onto some of its machines, without running an antivirus scan. The infection then spread to other locations within the company’s network in Tainan, Hsinchu and Taichung, which caused the majority of its facilities to close down temporarily.

The attack may have cost the iPhone component manufacturer up to 3% of revenues and could cost Apple over $255M

read more

Cyberattack at Israeli Tower Semiconductor Manufacturer

September 6, 2020

Cyberattack at Tower Semiconductor forced certain operations to a complete halt. Company authorities said that specific measures were taken to prevent the spread of the cyberattack, however, there was no immediate factual assessment report available that would state the real effect of the damages done.

read more

Contractor inserts Cyber “Time Bomb Attack” in Firmware of Orqa Drone Goggle

May 6, 2023

A contractor named Swarg maliciously planted a time-bomb in the firmware of Orqa’s FPV.One V1 first person view (FPV) drone goggles, causing product failures. The malicious code was designed to brick devices after a timestamp is reached. Later, Swarg posted a paid and unauthorized binary firmware fix online as a “license extension and renewal” that would unbrick devices. Orqa’s stated this is effectively a case of a ransomware attack by a malcious insider deploying a wiper payload. Analysis shows that both Orqa and Swarg have done business together and operate from the same location, suggesting they share offices.

read more

Ricardo Defense Suffers Cyberattack

October 16, 2023

Multi-industry technology provider, Troy, Michigan-based Ricardo Defense Inc., suffered a cyberattack this past October where personally identified information ended up stolen.
“On October 23, 2023, Ricardo discovered suspicious activity on its network,” the company said in a notice. “Ricardo immediately took steps to secure its systems and initiated an investigation into the nature and scope of the event with the assistance of third-party forensic specialists.
“The investigation determined that Ricardo’s network was subject to unauthorized access between October 16, 2023 and October 23, 2023, and that certain files were acquired by an unknown actor while on the network,” the statement said.

read more

Framework Laptop Maker Suffers Cyberattack

January 9, 2024

San Francisco, California-based Framework, the repairable laptop maker, said hackers phished a worker Tuesday at its accounting service provider and were able to purloin customer data.
Framework sent an email to affected customers explaining what happened during the incident at San Mateo, California-based Keating Consulting, its primary external accounting partner. In the attack, an accountant fell victim to a social engineering attack that resulted in thieves stealing customers’ personal information related to outstanding balances.
The letter from Framework to its customers said:
“Keating Consulting, Framework’s primary external accounting partner, brought to our attention at 8:13am PST on January 11th, 2024, that one of their accountants fell victim to a phishing email that utilized social engineering tactics to obtain customer PII (Personal Identifiable Information) associated with outstanding balances for Framework purchases.”

read more

Employee of Taiwanese D-Link Falls for Phishing Leading to Data Breach

October 10, 2023

D-Link Corporation, a Taiwanese networking equipment, confirmed a data breach linked to information stolen from its network and put up for sale on BreachForums earlier this month.
The intrusion vector was likely an employee who unintentionally fell victim to phishing. The attacker claims to have stolen source code for D-Link’s D-View network management software, along with millions of entries containing personal information of customers and employees, including details on the company’s CEO.

read more

BlackCat Allegedly Attacked Drone Systems Partner of NASA, Airbus

November 1, 2023

Unmanned drone systems maker, Autonomous Flight Technologies (AFT), has allegedly fallen victim to a cyberattack orchestrated by the notorious BlackCat ransomware group. The attackers claimed the Autonomous Flight Technologies data breach and purportedly sold exfiltrated data to an undisclosed foreign entity.

AFT, recognized for its cutting-edge unmanned drone technology, boasts prominent partnerships with industry giants such as Airbus, NASA, NBC, and Northrop Grumman. As the Autonomous Flight Technologies data breach remains unconfirmed, the industry awaits an official response from AFT while grappling with the broader implications of cybersecurity vulnerabilities in the rapidly advancing field of unmanned autonomous systems.

read more

Cyberattack Disrupts Systems at Infosys McCamish Systems

November 3, 2023

Infosys McCamish Systems, a subsidiary of India-based IT services giant Infosys Ltd. (NYSE: INFY), experienced a cyberattack. The company reported the incident in a regulatory filing on 3 November.

“Infosys McCamish Systems (IMS), a subsidiary of Infosys BPM Limited (a wholly owned subsidiary of Infosys Limited), has become aware of a cybersecurity event resulting in non-availability of certain applications and systems in IMS,” according to the filing.

“Data protection and cybersecurity are of utmost importance to us,” the statement continued. “We are working with a leading cybersecurity products provider to resolve this at the earliest and have also launched an independent investigation with them to identify potential impact on systems and data.”

read more

Wuhan Earthquake Monitoring Center Suspects Cyberattack comes from US.

July 26, 2023

Wuhan Earthquake Monitoring Center suffered a cyberattack. The Wuhan public security bureau Jianghan sub-bureau confirmed the discovery of a Trojan horse program originating from abroad at the Wuhan Earthquake Monitoring Center. According to the public security bureau, this Trojan horse program can illegally control and steal seismic intensity data collected by the front-end stations. This act poses a serious threat to national security. The center has immediately sealed off the equipment that was affected and reported the attack to the public security authorities, in order to investigate the case and handle the hacker organization and criminals according to law, said the statement.

read more