The week in breach news

Supply chain attacks dominate this week’s cybersecurity headlines, with ecommerce platform BigCommerce confirming a breach that compromised multiple merchant storefronts and customer engagement platform Brevo falling victim to an attack that injected malicious code into more than 100,000 websites. Meanwhile, U.S. law firm Greenberg Traurig, Japan’s Government Solution Service and Germany’s Ludwig Maximilian University of Munich all found themselves dealing with the fallout of cyberattacks that put sensitive personal data at risk.

The week in breach news

North America

BigCommerce

Industry: TechnologyExploit: Supply Chain Attack

Ecommerce platform BigCommerce confirmed a supply-chain breach involving compromised credentials from third-party app Ribon, affecting multiple merchant customers.

BigCommerce is a cloud-based SaaS ecommerce platform that businesses use to build and operate online stores without needing to develop their own commerce infrastructure. The company confirmed the credential compromise on September 17, stating that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by Be A Part Of, a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts.

The UK-based online spirits vendor Master of Malt is among the BigCommerce customers that received breach notifications, with the retailer confirming that attackers accessed shopper information, including full names, email addresses, phone numbers and shipping postal addresses.

Source

How it could affect your business

Supply chain attacks are growing in both frequency and sophistication, with attackers increasingly targeting third-party apps and integrations as a way into larger platforms and their customers. A single compromised vendor can create a ripple effect that reaches hundreds or thousands of businesses downstream, as this incident demonstrates. Businesses should regularly audit the third-party tools and integrations connected to their platforms, ensure vendors meet their security standards and monitor for any unusual activity that could signal a compromise further up the supply chain.

Europe

Brevo

Industry: TechnologyExploit: Supply Chain Attack

Customer engagement platform Brevo fell victim to a supply chain attack that resulted in malicious code being injected into more than 100,000 websites.

On September 10, a threat actor exploited a vulnerability in Brevo's handling of SAML SSO to access 138 accounts, including one belonging to cryptocurrency storage provider Trezor. The attackers sent phishing emails from six of the compromised accounts and exported contacts from 43 others. After Brevo closed the unauthorized access, the attackers returned on September 14, using a compromised long-lived Cloudflare API key to deploy a worker that injected malicious scripts into brevo.com, sibforms.com and three JavaScript files embedded by Brevo's customers across their websites.

According to reports, the malicious code was served for roughly four hours, with more than 100,000 websites likely impacted during that window.

Source

How it could affect your business

Any website using Brevo should be reviewed immediately for signs of compromise. Administrators should check for unauthorized plugin installations, unexpected script changes and any other indicators of tampering that may have occurred during the affected window. Site visitors who may have been served the fake verification pages should scan their machines for malware as a precaution.

United States

Greenberg Traurig

Industry: LegalExploit: Hacking

U.S. law firm Greenberg Traurig has been sued in federal court in Manhattan following its disclosure of a data breach that exposed sensitive personal information belonging to a number of its clients.

Earlier in August, Greenberg Traurig confirmed that an unauthorized actor had accessed a limited number of documents and posted them on the dark web, with affected clients notified shortly after. The firm stated that its systems were not compromised or breached and that it has continued to operate without disruption. The information involved in the breach included names, contact information, dates of birth and Social Security numbers.

The incident adds to a growing list of U.S. law firms targeted by cybercriminals in recent months. Prominent firms, including Quinn Emanuel, McDermott, Herbert Smith Freehills Kramer, Goodwin Procter, and WilmerHale, have all reported breaches recently.

Source

How it could affect your business

A data breach does not end when the attacker leaves, as this lawsuit makes clear. Stolen data posted to the dark web can circulate long before affected individuals or organizations realize the full extent of the damage, opening the door to legal action, regulatory penalties and reputational harm. Dark web monitoring gives businesses an early warning when sensitive data surfaces online, and a well-prepared incident response plan that covers legal and compliance obligations can make the difference between a manageable situation and a costly, drawn-out fallout.

Asia & Pacific

Government Solution Service (GSS)

Industry: Government & Public SectorExploit: Hacking

Japan's digital agency disclosed a data breach affecting the personal information of approximately 240,000 individuals.

In late June, hackers accessed files from Japan's Government Solution Service (GSS) using a maintenance and operations employee's account. A subsequent investigation determined in July that a vulnerability in a VPN product had been exploited to gain access. The attackers compromised over 246,000 records containing names, addresses, email addresses and phone numbers belonging to users, public officials, administrative staff and businesses and individuals working with GSS.

The agency did not name the exploited VPN product but confirmed that the targeted vulnerability had already been publicly disclosed before the attack was detected. The agency said it would strengthen its vulnerability management practices in response.

Source

How it could affect your business

VPNs have become an increasingly attractive target for cybercriminals, offering a direct path into an organization's network when left unpatched or poorly configured. As this incident shows, a single exploited vulnerability can be enough to compromise tens of thousands of records. Businesses should ensure that VPN products and other remote access tools are kept up to date, regularly audited for known vulnerabilities and monitored closely for unusual access patterns that could signal an intrusion before it escalates.

Europe

LMU Munich

Industry: EducationExploit: Hacking

Germany's Ludwig Maximilian University of Munich (LMU Munich) is investigating a cyberattack in which an unknown hacker accessed a system containing sensitive student information.

LMU Munich, one of Germany's largest universities with more than 52,000 students, announced on September 19 that an attacker had accessed enrollment data stored on one of its IT systems. The university said there is no evidence that the affected data was altered or deleted and no indication so far that the stolen information has been published or misused.

The potentially affected records include students' names, dates of birth, contact details, email addresses, bank account information and details about their courses of study and previous educational qualifications.

Source

How it could affect your business

Universities hold large volumes of personal, financial and academic information, making them a high-value target with a broad attack surface. The combination of names, bank account details and contact information exposed in this breach gives attackers plenty of material to craft highly convincing phishing campaigns targeting affected students. Institutions and individuals alike should ensure users are trained to recognize suspicious communications and verify the source of any unexpected messages before taking action.

Like what you're reading?

Subscribe now to get security news and information in your inbox every week

Upcoming Webinars

Join other IT professionals to connect, learn and level up. Get insights into the latest cybersecurity trends and technologies.

Security Quarterly Product Innovation Update Asia Pacific

Security Quarterly Product Innovation Update Asia Pacific

View event
Smarter MSP growth: Real stories, real results

Smarter MSP growth: Real stories, real results

View event
Kaseya Connect Local ∷ Cleveland

Kaseya Connect Local ∷ Cleveland

View event