Showing posts with label insurance. Show all posts
Showing posts with label insurance. Show all posts

Tuesday, June 29, 2021

That was an expensive click

 

Everyone needs or is required to have insurance. This may take the form of auto, health, dental, short- or long-term disability care, or any of the other types of insurance. It seems as though if there is a need, you can find insurance for it. One of the largest commercial insurance carriers in the US is CAN. While being one of the largest insurance carriers in the nation certainly is a success to be applauded, this also has the tendency to put a target on you. After all, when a company is this huge, there is a literal mountain of data to target, and the company certainly has deep pockets to pay a ransom, if they so choose.

Recently CNA had the pleasure of working through an incident much like this. Ironically, CNA sells cyber insurance. In this case, the attackers were able to compromise CNA’s system. Post-breach, they were able to encrypt over 15K of the company’s devices using Phoenix Crypto Locker, a variant of Hades. This variant is engineered to encrypt the files on the compromised machines and demand a ransom for the decrypt key. The group, Evil Corp, was paid the ransom by CNA.

For everyone and organizations that believe “This can’t happen to me!”, yes it can. If CNA who has a vast number of resources and even sells the insurance for this type of incident can be successfully attacked, you certainly can also.

Tuesday, June 1, 2021

Ransomware around the world

 

Everyone needs insurance. This takes various forms, from life, health, disability, and other forms. One firm in this industry is AXA S.A. This is a global firm with vast reach. A huge company of this size certainly has ample data to target. A portion of the network had been attacked with ransomware.

One May 9, 2021 AXA S.A. announced the company policy was not to pay the ransom when there would be a successful ransomware attack. At that point, the company may have created a bit more attention than intended for itself. The company, interestingly enough, was a victim of ransomware right after this. The target was one of its Asia Assistance Divisions. In this case, the division’s information technology services were adversely impacted for Thailand, Malaysia, Hong Kong, and the Philippines and their data accessed. Allegedly, the Avaddon ransomware group was responsible for the successful attack. During the attack, apparently 3TB of data were exfiltrated. This included ID cards, passport, copies, customer claims, reserved agreements, denied reimbursements, payments to customers, contract and reports, customer IDs, bank account scanned papers, hospital and doctor reserved material (private investigation for fraud, and customer medical reports, including HIV, hepatitis, STD, and other illness reports).

Sometimes it is better to just remain in obscurity.