Showing posts with label dlp. Show all posts
Showing posts with label dlp. Show all posts

Wednesday, November 20, 2024

Data theft-It’s not just for medical facilities

 There’s been volumes written about data theft in medical facilities, methods, and effects. This is no

wonder given the mountain of data created daily from the patient care and operations. Another viable

target would be auto dealerships. This hold much the same data hospital would generally. When a

person purchases their vehicle, as a course of the process, they provide their name, address, data of

birth, SSN, financial information, and other data. The hospital or medical care facility collects much the

same, with additional data for the patient care.

In this case an automotive dealership was compromised. On or about May 27, 2023, the Jeff Wyler

Automotive Family an unauthorized party compromised their perimeter security and was able to access

the consumer information (e.g., name, date of birth, SSN, driver’s license or state ID #, medical

information, health insurance information, and financial information). This was detected on January 29,

2024.

The method of attack unfortunately was not detailed. Anytime this event occurs, there’s something to

learn and use to build up your defenses. This experience does highlight the need for regular

cybersecurity assessments. This, depending on the environment and budget, may consist of vulnerability

scans, per tests, and threat feeds for your equipment. This also includes working on the vulnerabilities to

remove these and secure your system.

Oil Pipeline Targeted

 Companies are targeted for attack for various reasons. One predominant reason continues to be

revenue. Without the possibility of a payout, there isn’t much reason for a group to spend the resources

to attack the target.

One set of high value targets are pipelines. A few years ago, there was an issue with a pipeline in the US

(i.e., Colonial Pipeline in 2021). Another pipeline has been compromised with the same form of attack,

but in Canada. In this case, the Alpha V group successfully compromised the Trans-Northern Pipeline’s

systems in three provinces and applied the standard ransomware. They were able to exfiltrate

approximately 190GB of data. The successful attack occurred in 2023.

Unlike the US attack, there were no unplanned interruption for the pipeline’s operations. Unfortunately,

not much has been published as to the attack method used, depth of network penetration, and type of

data. Portions of this information could be helpful as to how best to secure other’s networks. If any

nuances would occur with this attack.

We must continue to be ever vigilant. This includes having internal systems checked more than once

over time.