BEC Attack on Monongalia Health System

BEC Attack on Monongalia Health System

A three-hospital health system in West Virginia has become the victim of a business email compromise (BEC) scam that began with a phishing attack. 

Monongalia Health System, Inc. (MHS) had no idea that its cybersecurity defenses had been penetrated until a vendor reported not receiving a payment from the healthcare provider on July 28, 2021. 

An investigation was launched, which determined that threat actors had compromised several email accounts belonging to MHS employees between May 10, 2021, and August 15, 2021, gaining unauthorized access to emails and attachments. 

Threat actors used one account belonging to an MHS contractor to impersonate Monongalia Health System and attempt to fraudulently obtain funds by wire transfer. 

Monongalia Health System, whose affiliated hospitals are Monongalia County General Hospital Company, Preston Memorial Hospital, and Stonewall Jackson Memorial Hospital Company, issued a data security notice Tuesday.

In the notice, MHS said that while the threat actors had not accessed the healthcare provider’s electronic health records system, some patient and employee data that was stored in the compromised email accounts had been breached.

This information included names, Medicare health insurance claim numbers (which could contain Social Security numbers), addresses, dates of birth, patient account numbers, health insurance plan member ID numbers, medical record numbers, dates of service, provider names, claims information, medical and clinical treatment information, and/or status as a current or former MHS patient.

MHS has begun mailing notice letters to patients whose information may have been involved in the security incident. 

“From a technology perspective, implementing verification of domains and senders’ email addresses, while not widely used, is a quick fix to authenticate domains and emails to reduce the risk of an attack by a ‘doppelganger domain,’” commented KnowBe4‘s security awareness advocate, James McQuiggan. 

He added: “For the human element, a robust security awareness program educates employees to be aware of the red flags, spot fake emails, check the email address, and verify the user by explicitly asking yourself if you were expecting the email.”

MHS said that it “is continuing to review and enhance its existing security protocols and practices, including the implementation of multi-factor authentication for remote access to its email system.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Russian Cyber Exec Extradited After Alleged Trading Conspiracy

Russian Cyber Exec Extradited After Alleged Trading Conspiracy

A Russian cybersecurity executive has been extradited to the US for his alleged role in a conspiracy to steal sensitive non-public information to make illegal trades.

Vladislav Klyushin, 41, of Moscow, was arrested in Sion, Switzerland in March and arrived in the US last weekend. He’s charged with conspiring to obtain unauthorized access to computers, and to commit wire fraud and securities fraud, and with obtaining unauthorized access to computers, wire fraud and securities fraud.

His alleged co-conspirators, Ivan Ermakov, 35, and Nikolai Rumiantcev, 33, both of Moscow, and Mikhail Vladimirovich Irzak, 43, and Igor Sergeevich Sladkov, 42, both of St. Petersburg, are still at large.

As deputy general director, Klyushin worked alongside Ermakov and Rumiantcev at Moscow-based pen testing and APT emulation firm M-13.

Between January 2018 and September 2020, Klyushin, Ermakov, Irzak, Sladkov and Rumiantcev are alleged to have made tens of millions of dollars from illegal trading based on material non-public information about corporate earnings, in advance of financial results being published.

They are said to have obtained this information by hacking the networks of two US filing agents used by companies to make quarterly and annual SEC filings.

According to court documents, they first harvested employee log-ins at these two companies using proxy networks outside of Russia to disguise their location. This enabled them to gain access to the filing companies’ networks and download sensitive info on hundreds of NASDAQ and NYSE-listed firms.

It allowed them to purchase securities on companies about to disclose positive financials and sell short on those who were due to post negative results.

To further hide their identities, the quartet are said to have registered email addresses and subscribed to payment systems in others’ names. Trading was distributed across accounts in European, US and Russian banks.

M-13 names the Russian government and President’s administration among its clients. Another tie with the Kremlin is Ermakov, who is apparently a former officer in the Russian Main Intelligence Directorate (GRU), charged in 2018 for hacking and disinformation efforts linked to the 2016 US election.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Ubisoft Reveals Player Data Breach Came from User Error

Ubisoft Reveals Player Data Breach Came from User Error

Ubisoft has admitted that data on some players may have been taken after a breach of its IT systems stemming from human error.

The French gaming giant explained in a brief post that the misconfiguration of its IT infrastructure was quickly identified, but not before unauthorized individuals were able to access and perform a “possible copy” of the information.

Data stolen related to players of the wildly popular Just Dance game.

“The data in question was limited to ‘technical identifiers’ which include GamerTags, profile IDs, and Device IDs as well as Just Dance videos that were recorded and uploaded to be shared publicly with the in-game community and/or on your social media profiles,” the firm explained.

“Our investigation has not shown that any Ubisoft account information has been compromised as a result of this incident.”

Ubisoft claimed all affected players would be contacted via email shortly and would be able to follow up with any queries by getting in touch with the firm’s support team.

“We have taken all the proactive measures necessary to secure our infrastructure from future incidents,” it said.

This isn’t the first time Ubisoft’s security has been found wanting.

Back in 2013, it revealed that threat actors were able to access customer names, email addresses and encrypted passwords from an account database.

More recently, it suffered a ransomware attack after the Egregor gang claimed to have been able to access employee and developer data and personal info, as well as game source code.

However, Ubisoft isn’t the only gaming firm to have been targeted of late. Electronic Arts (EA) was hit back in June 2021 when attackers advertised 780GB of stolen data for sale, including source code from popular titles like FIFA 21 and the underlying Battlefield engine, which powers many of its games.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

US Returns $150m to Sony After Employee BEC Attack

US Returns $150m to Sony After Employee BEC Attack

The US government has handed back over $150m to Sony that one of its employees allegedly embezzled.

It filed a civil forfeiture complaint in the Southern District of California to protect Sony’s interest in the funds allegedly stolen by Rei Ishii, an employee of Sony Life Insurance Company.

Although Sony had a double authentication process set up for international money transfers, requiring both Ishii and his supervisor to sign them off, the former is said to have instructed the company’s bank to change the contact email address for his boss.

That enabled him to initiate and sign-off money transfers to an account under his control totaling $154m, which he later converted into Bitcoin, according to court documents.

Ishii is even said to have emailed several executives, including his supervisor with a ransom note claiming that the money would be returned if they paid a fee. The end goal appears to have been to dissuade them from filing criminal charges.

However, the FBI – working alongside the National Police Agency, the Tokyo Metropolitan Police Department, Tokyo District Public Prosecutors Office, and the Japan Prosecutors Unit on Emerging Crimes (JPEC) – obtained the private key to this Bitcoin address.

“The FBI was able to recover these stolen funds for two very important reasons. First, Sony and Citibank immediately contacted and cooperated with law enforcement as soon as the theft was detected, and the FBI worked in partnership with both to locate the funds,” explained FBI special agent in charge, Suzanne Turner.

“Second, the FBI’s footprint internationally through our Legal Attaché offices and the pre-existing relationships we have established in foreign countries – in this instance with Japan – enabled law enforcement to coordinate and identify the subject. The FBI’s technical expertise was able to trace the money to the subject’s crypto wallet and seize those funds.”

Ishii has been charged in Japan.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains