The week in breach news

Ransomware dominates the headlines this week, with Berlin’s city government, a U.S. federal agency and Manchester Airports Group all finding themselves in the crosshairs of different ransomware gangs. Meanwhile, a highly disruptive cyberattack brought Boston Scientific’s global operations to a standstill, and a breach at Canadian telecom provider Eastlink left 75,000 customers with their data potentially exposed.

The week in breach news

Europe

Berlin city government

Industry: Government & Public SectorExploit: Ransomware & Malware

The Berlin city government is being blackmailed by a ransomware group after hackers compromised the city’s systems and exfiltrated 5.79 TB of data.

The breach was discovered early in August after attackers gained access to city systems and exfiltrated a significant volume of information. Officials have not been able to confirm the content or scope of the affected data, as the investigation is still ongoing.

The Rhysida ransomware group has since claimed responsibility on its website, stating it took 5.79 TB of data from the city government administration. The group says the stolen data includes 46,500 contracts, emails, phone numbers, passwords and other classified information and is demanding 30 bitcoin, equivalent to approximately $2.5 million.

Source

How it could affect your business

Paying a ransom is never a guarantee that stolen data won’t still be leaked or sold. Cybercriminals have little incentive to keep their word once payment is made. Ransomware-resilient backups, a strong business continuity and disaster recovery (BCDR) strategy and proactive threat monitoring can make the difference between a manageable recovery and a costly standoff with attackers. Dark web monitoring can also provide early warning if stolen data surfaces before a formal demand is even made.

United States

ATF

Industry: Government & Public SectorExploit: Ransomware & Malware

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a data breach after a hacking group publicly claimed the attack last week.

The breach affected a stand-alone system separate from the bureau's main network, which contained information such as the targets of ATF investigations. The system was shut down quickly after the breach was discovered, and an investigation is currently underway. The incident has been formally classified as a "major incident," a legally defined designation that requires official notification to members of Congress.

The Qilin ransomware gang claimed responsibility on its leak site, though it has not provided any evidence to support the claim, such as a sample of the stolen data.

Source

How it could affect your business

Ransomware groups like Qilin operate on a ransomware-as-a-service model, leasing their tools to criminal affiliates in exchange for a cut of the profits. This approach is rapidly increasing both the frequency and scale of ransomware attacks, meaning more organizations are in the crosshairs than ever before. Raising user awareness is one of the most effective ways to reduce the risk, as cybercriminals often rely on phishing and social engineering to gain their initial foothold.

United Kingdom

Manchester Airports Group (MAG)

Industry: Aerospace & DefenseExploit: Ransomware & Malware

Manchester Airports Group (MAG), the largest airport group in the UK, disclosed a data breach on August 27 that could expose data belonging to 8.7 million customers.

MAG operates Manchester, London Stansted and East Midlands airports. The group confirmed that data was stolen from a third-party-hosted database, with the breach affecting car park, lounge and Fast Track bookings, as well as in-airport Wi-Fi sign-ups across all three airports. Compromised data includes email addresses, phone numbers, vehicle registrations and postcodes. MAG confirmed that no payment information was accessed and that passenger safety and aviation security were not affected.

MAG said it received a ransom demand from the attackers but has not shared further details on the threat actor or the specific demands. Meanwhile, the FulcrumSec extortion group reportedly claimed responsibility for the incident, stating it stole approximately 86 GB of data from MAG.

Source

How it could affect your business

Your attack surface extends beyond your own systems to every third-party vendor with access to your data. Attackers increasingly target suppliers and service providers as a way in, making third-party risk monitoring an essential part of any security strategy. Vetting vendors thoroughly, limiting the data they can access and ensuring they meet your security standards can significantly reduce the risk of a breach originating outside your walls.

North America

Boston Scientific

Industry: HealthcareExploit: Hacking

American medical technology giant Boston Scientific is still working to restore operations following a highly disruptive cyberattack it experienced on August 25.

Boston Scientific develops and manufactures devices and therapies used in cardiology, neurology and oncology. The cyberattack caused a network outage that disrupted the company’s global operations, including product manufacturing, customer order processing and shipping. Boston Scientific confirmed that its cloud-based systems and applications were not affected, with the breach appearing limited to some on-premises systems.

The company has not been able to provide a full restoration timeline. Meanwhile, the identity of the threat actor remains unclear, as no known cybercrime group has claimed responsibility for the attack.

Source

How it could affect your business

A cyberattack does not have to result in a data breach to cause serious damage. Operational disruptions can grind day-to-day business functions to a halt, costing organizations time, revenue and customer trust. Having a solid business continuity strategy in place, one that accounts for network outages and system failures, ensures your organization can keep critical functions running while recovery efforts are underway.

Like what you're reading?

Subscribe now to get security news and information in your inbox every week

Upcoming Webinars

Join other IT professionals to connect, learn and level up. Get insights into the latest cybersecurity trends and technologies.

recovery readiness for Microsoft environments: What IT teams need to check now

recovery readiness for Microsoft environments: What IT teams need to check now

View event
From Managed to Certified: Building a cybersecurity practice that proves itself

From Managed to Certified: Building a cybersecurity practice that proves itself

View event
Datto RMM quarterly product innovation update

Datto RMM quarterly product innovation update

View event