On Q Financial announces data breach, law firm feeding frenzy follows

On April 2, Arizona-based On Q Financial notified the Maine Attorney General’s Office of a breach the mortgage lender experienced. Within days, law firms announced investigations into the breach and sought potential class action members. Was ther… Continue reading On Q Financial announces data breach, law firm feeding frenzy follows

HC3: Sector Alert: Social Engineering Attacks Targeting IT Help Desks in the Health Sector

April 3, 2024 TLP:CLEAR Report: 202404031000 Executive Summary HC3 has recently observed threat actors employing advanced social engineering tactics to target IT help desks in the health sector and gain initial access to target organizations. In genera… Continue reading HC3: Sector Alert: Social Engineering Attacks Targeting IT Help Desks in the Health Sector

Proporsed Rule: Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements

A quick note that the official draft of CIRCA is now published: A Proposed Rule by the Homeland Security Department on 04/04/2024 All information is linked from https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-fo… Continue reading Proporsed Rule: Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements

City of Hope updates a breach disclosure, reports 827,149 patients affected in ransomware attack last year

City of Hope updated its breach disclosure. DataBreaches can now reveal some previously undisclosed details about the 2023 incident. In December 2023, City of Hope, a cancer treatment center in Duarte, California, notified HHS that it had experienced a… Continue reading City of Hope updates a breach disclosure, reports 827,149 patients affected in ransomware attack last year

Indiana-based Otolaryngology Associates, LLC notifies 316,802 patients about February cyberattack

Otolaryngology Associates, LLC (OA) has 13 locations throughout Indiana in Indianapolis, Greencastle, Greenfield, Kokomo, Noblesville, and Carmel. On April 1, the ENT (ears, nose, throat) practice notified the U.S. Department of Health and Human Servic… Continue reading Indiana-based Otolaryngology Associates, LLC notifies 316,802 patients about February cyberattack

No need to hack when it’s leaking, Wednesday edition: Eyecare Services Partners exposed more than 2 million patients’ SSN – researcher

EyeCare Services Partners  (ESP) is a private company with a network of ophthalmologic, optometric and ambulatory surgery centers. It is headquartered in Dallas, Texas. On February 9, an IT student who was searching the internet for exposed datasets no… Continue reading No need to hack when it’s leaking, Wednesday edition: Eyecare Services Partners exposed more than 2 million patients’ SSN – researcher

UN? FBI? World Bank? Deepfake police chief used for compensation scam video

Advance fee fraud campaigns are using generative AI in both text and video to speed up responses, evade filters, and make scams more convincing.

Large Language Models and other forms of Generative AI (GenAI) promise to make many people more productive, and cybercriminals are no exception. Fraudsters are using GenAI to enhance all kinds of scams, from consumer-focused bulk campaigns to highly targeted business email compromise attempts. High-profile cases have involved losses of tens of millions of dollars.

Over the last six months, Netcraft has noticed an increase in advance fee fraud emails with signs of ChatGPT-generated text, as well as a new pattern of deepfake videos designed to convince would-be victims and evade existing filters used to block scams, including examples impersonating the FBI, UN, and World Bank.

Advance fee fraud is a long-popular paradigm among scammers: they typically start with an unsolicited message indicating that the recipient is due money—for example, that a businessman has offered money to them or that they have won a competition such as an “internet lottery”—and that by paying a comparatively small fee, they will gain access to that fortune. However, the supposed fortune does not exist: once paid, the scammer will make off with the fee and either invent more roadblocks to continue extracting funds or move on to the next victim.

Another type of advance fee fraud we often see are compensation scams. Playing on the frequency of the previously mentioned lures, fraudsters claim that they can reunite the victim with their supposed funds. This is to further capitalize on people who had already fallen for other forms of scams, as the fraudster will themselves ask for a fee to be paid, with the fund never having existed.

“Sandra Steven” Deepfakes used to evade email filters

Netcraft recently received a …

Continue reading UN? FBI? World Bank? Deepfake police chief used for compensation scam video

Update: David Kee Crees, aka “DR32,” in U.S. custody, trial scheduled for August

In September 2022, DataBreaches reported that Australian national David Kee Crees was going to be extradited from Australia to the U.S. to stand trial on hacking charges. Crees, now 25, has used a number of aliases. DataBreaches had first known him bac… Continue reading Update: David Kee Crees, aka “DR32,” in U.S. custody, trial scheduled for August

Grassley, Wyden Probe Data Breach that Exposed 1.5 Million Organ Transplant Patients’ Sensitive Data

AJ Taylor reports: Sens. Chuck Grassley (R-Iowa) and Ron Wyden (D-Ore.) are holding the United Network for Organ Sharing (UNOS) accountable after a data breach allowed UNOS system users unauthorized access to over a million sensitive patient records. T… Continue reading Grassley, Wyden Probe Data Breach that Exposed 1.5 Million Organ Transplant Patients’ Sensitive Data