Ie: Authorities investigating ransomware attack on charity that works with vulnerable children

The Journal reports: A police investigation has been launched after a charity that works with vulnerable children suffered a data breach in a ransomware attack. Extern, a cross-border social justice charity with offices in Belfast and Co Kildare, has c… Continue reading Ie: Authorities investigating ransomware attack on charity that works with vulnerable children

‘Large-scale cyberattack’ hits five French municipalities, impact may last ‘months’

Alexander Martin reports: Five municipalities near the river Loire on the west coast of France have been hit by a “large-scale cyberattack” on their shared computer servers, leaving staff without the ability to access documents or get on with their wor… Continue reading ‘Large-scale cyberattack’ hits five French municipalities, impact may last ‘months’

Small physician groups particularly vulnerable after Change Healthcare cyberattack; some consider bankruptcy

Marty Stempniak reports that physician practices are struggling from the financial impact of the Change Healthcare cyberattack in February. Smaller physician practices may be particularly hard-hit, with some considering closing, according to new data f… Continue reading Small physician groups particularly vulnerable after Change Healthcare cyberattack; some consider bankruptcy

The AI Gold Rush: ChatGPT and OpenAI targeted in AI-themed investment scams

Investment scams and AI – a match made in heaven?  

Online investment scams are a big money spinner for criminals, accounting for $4.6B of losses in the US. With the explosion of interest in artificial intelligence (AI) following the release of OpenAI’s ChatGPT in late 2022, it was perhaps inevitable that criminals would look to jump on the bandwagon to promote a new generation of bogus investment products that claim to “harnesses the power of AI.”  

Netcraft has uncovered a range of malicious sites using ChatGPT and OpenAI-themed content to attract would-be investors looking to take advantage of the rise of generative AI. Many tout the use of “advanced trading technology,” promising outlandish returns, and feature bogus success stories. Once lured in, would-be investors are tricked into making payments that inevitably never result in the promised returns.  

In this blog, we’ll walk through some of the examples we’ve found. 

“ChatGPT platform” with fake Sam Altman and Elon Musk videos 

One such investment scam campaign blatantly impersonates ChatGPT, claiming to be powered by the popular generative AI platform, allowing it to “imitate the thinking of analysts.” Seeking to establish credibility, this scam claims more than 1 million registered users and $68 million invested each month. Particularly implausible, given the domain name had been registered eight days prior. 

Figure 1 Fake investment platform masquerading as ChatGPT – hxxps://lifecovewe[.]world. 

The site also includes a poorly crafted video that attempts to fool the visitor into thinking it is a genuine endorsement from Sam Altman (the CEO of OpenAI). It espouses the increasing power of machine learning, with the tool being able to “analyze the market situation and correlate data in real-time”. With rapid progress being made with deepfakes, it is only a matter of time before videos created by criminals …

Continue reading The AI Gold Rush: ChatGPT and OpenAI targeted in AI-themed investment scams

On Q Financial announces data breach, law firm feeding frenzy follows

On April 2, Arizona-based On Q Financial notified the Maine Attorney General’s Office of a breach the mortgage lender experienced. Within days, law firms announced investigations into the breach and sought potential class action members. Was ther… Continue reading On Q Financial announces data breach, law firm feeding frenzy follows

HC3: Sector Alert: Social Engineering Attacks Targeting IT Help Desks in the Health Sector

April 3, 2024 TLP:CLEAR Report: 202404031000 Executive Summary HC3 has recently observed threat actors employing advanced social engineering tactics to target IT help desks in the health sector and gain initial access to target organizations. In genera… Continue reading HC3: Sector Alert: Social Engineering Attacks Targeting IT Help Desks in the Health Sector

Proporsed Rule: Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements

A quick note that the official draft of CIRCA is now published: A Proposed Rule by the Homeland Security Department on 04/04/2024 All information is linked from https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-fo… Continue reading Proporsed Rule: Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements

City of Hope updates a breach disclosure, reports 827,149 patients affected in ransomware attack last year

City of Hope updated its breach disclosure. DataBreaches can now reveal some previously undisclosed details about the 2023 incident. In December 2023, City of Hope, a cancer treatment center in Duarte, California, notified HHS that it had experienced a… Continue reading City of Hope updates a breach disclosure, reports 827,149 patients affected in ransomware attack last year