Technology

Industry

Akira Ransomware Attacks Cisco VPN Network in Attempt to Breach Corporate Networks

August 22, 2023

Bleepingcomputer reports there’s mounting evidence that Akira ransomware targets Cisco VPN (virtual private network) products as an attack vector to breach corporate networks, steal, and eventually encrypt data. Reportedly, Akira has been using compromised Cisco VPN accounts to breach corporate networks without needing to drop additional backdoors or set up persistence mechanisms that could give them away.

Cisco VPN solutions are widely adopted across many industries to provide secure, encrypted data transmission between users and corporate networks, typically used by remotely working employees.

read more

Italtel Cyberattack Claimed by Medusa

September 25, 2023

On Monday 25 September, the Italian company Italtel was the victim of a cyber attack. The cyber attack impacted Italtel’s IT infrastructure, limiting access and use of some company systems. The situation continues to evolve. The Italtel affair adds to the many IT incidents involving large Italian companies.
Italtel has already started communicating with its customers and suppliers about the cyber attack. Any subsequent interactions will be managed by the competent figures within the company.

The Medusa ransomware criminal gang claims the ransomware attack, Italtel has as of today not confirmed the attack. Italtel’s target markets are Telco & Media, Industry & Manufacturing, Energy & Transportation, Banking & Insurance, Healthcare and Public Administration.

read more

Confusion About $70M Ransom Demand: Kinmax or TSMC ?

June 29, 2023

“In the morning of June 29, 2023, the Company discovered that our internal specific testing environment was attacked, and some information was leaked,” reads the Kinmax statement.
“The leaked content mainly consisted of system installation preparation that the Company provided to our customers as default configurations.”

The Lockbit ransomware group claimed to have hacked chipmaker giant TSMC. TSMC stated its supplier Kinmax was attacked. Kinmax is not the corporate giant that TSMC is, so LockBit’s demands for a $70 million ransom payment will likely be ignored.

While there appears to be a mixup as to who was compromised in this attack, the $70 million ransom demand is one of the largest seen to date.

read more

Lockbit Demands $70M of TSMC Chipmaking Giant

June 28, 2023

Chipmaking giant TSMC denied being hacked after the LockBit ransomware gang demanded $70 million not to release stolen data.

On Wednesday, a threat actor known as Bassterlord, who is affiliated with LockBit, began to live tweet what appeared to be a ransomware attack on TSMC, sharing screenshots with information related to the company. While this Twitter thread has since been deleted, the LockBit ransomware gang created a new entry for TSMC yesterday on their data leak site, demanding $70 million or they would leak stolen data, including credentials for their systems.

A TSMC spokesperson told BleepingComputer that they were not breached, but rather the systems of one of their IT hardware suppliers, Kinmax Technology, were hacked. “Upon review, this incident has not affected TSMC’s business operations, nor did it compromise any TSMC’s customer information.”

Apart from validating that its systems had not been impacted in any way, TSMC states that it also stopped working with the breached supplier until the situation cleared up.

read more

Hackers Stole Source Code from Taiwanese PC Parts Maker MSI

April 5, 2023

Taiwanese PC parts maker MSI (Micro-Star International) was listed on the extortion portal of a new ransomware gang known as “Money Message”. The threat actors claimed to have stolen 1.5TB of data from MSI’s systems. The stolen data includes source code and databases. The group demanded a ransom payment of $4,000,000.

read more

Schneider Hit In MOVEit Transfer Zero Day

May 30, 2023

Schneider Electric suffered cyberattack from the Clop ransomware group

“On May 30th, 2023, Schneider Electric became aware of vulnerabilities impacting Progress MOVEit Transfer software.” the company said in a statement. “Subsequently, on June 26th, 2023, Schneider Electric was made aware of a claim mentioning that we have been the victim of a cyberattack relative to MOVEit vulnerabilities,” the company said. “Our cybersecurity team is currently investigating this claim as well.”

No further information was released at this time.

read more

Siemens Energy AG Confirms Ransomware Attack

June 27, 2023

Cl0p ransomware group claimed the cyber attack on Siemens Energy and four other organizations including Schneider Electric and the University of California Los Angeles.

Siemens Energy spokesperson, Claudia Nehring, stated, “Regarding the global data security incident, Siemens Energy is among the targets. Based on the current analysis, no critical data has been compromised and our operations have not been affected. We took immediate action when we learned about the incident.”

Siemens Energy in-house ProductCERT team has not released any statements or updates regarding the alleged cyber attack. The team is responsible for handling all security-related matters pertaining to their products, solutions, and services.

Cl0p listed Siemens Energy on their data leak site. The group has been wreaking havoc on various organizations in recent weeks.

read more

Maritime Tech Giant Voyager Worldwide Takes Systems Offline

December 1, 2022

Singapore-based maritime technology solutions provider Voyager Worldwide was reported to have been hit by a cyber attack at the beginning of December. From December 2nd all systems were taken offline at the navigation services and solutions provider. The company has more than 1,000 shipping companies as customers around the world.

“As this is an ongoing investigation, and our priority is keeping the impact of the incident contained, the time frame for recovery could shift,” Voyager stated on its site.

read more

Data Breach at Acer

February 15, 2023

Computer behemoth, Acer, suffered a data breach in mid-February after attackers were able to get into a server hosting private documents used by repair technicians.
That being said, the Taiwan-based computer firm said so far there are no indications the hack had an impact on stealing customer data.
The company’s confirmation of the breach comes after the attacker began selling on a popular hacking forum what they claim is 160GB of data stolen from Acer in mid-February, according to a report with BleepingComputer. The attacker said the stolen data contains technical manuals, software tools, backend infrastructure details, product model documentation for phones, tablets, and laptops, BIOS images, ROM files, ISO files, and replacement digital product keys (RDPK).

read more

MKS Suspends Operations to Contain Ransomware Attack

February 3, 2023

MKS Instruments Inc is investigating a ransomware attack and is temporarily suspending operations at some of its facilities. “The incident has affected certain business systems, including production-related systems, and as part of the containment effort, the company has elected to temporarily suspend operations at certain of its facilities”, Kathleen F Burke, senior vice president, general counsel and secretary at MKS Instruments, said in the SEC filing.

The ransomware incident was reported just a day after national cybersecurity agencies and security experts around the world warned about a global ransomware attack that hit thousands of servers running on VMware ESxi.

Applied Materials, Samsung Electronics Co., Taiwan Semiconductor Manufacturing Co. , Intel Corp. and ASML Holding NV are among MKS Instrument’s customers. Applied Materials reported they will take a $250M hit to sales this quarter, thanks to a cyberattack at one of its (unidentified) suppliers.

read more