Facebook, Instagram, TikTok and Twitter Target Resellers of Hacked Accounts

Facebook, Instagram, TikTok, and Twitter this week all took steps to crack down on users involved in trafficking hijacked user accounts across their platforms. The coordinated action seized hundreds of accounts the companies say have played a major role in facilitating the trade and often lucrative resale of compromised, highly sought-after usernames. Continue reading Facebook, Instagram, TikTok and Twitter Target Resellers of Hacked Accounts

PART I: Retrospective 2020: DDoS Was Back — Bigger and Badder Than Ever Before

Never before has the risk of a distributed denial-of-service (DDoS) attack been higher. In 2020, we saw record-breaking attacks, a DDoS extortion campaign impacting thousands of organizations globally, more emergency customer turnups, and more Akamai customers attacked than any year on record — and we’ve been successfully fighting DDoS attacks since 2003! We also saw a big increase in attacks targeting verticals that haven’t seen as much activity of late, with 7 of 11 of the industries we track seeing peak attack counts in 2020. Continue reading PART I: Retrospective 2020: DDoS Was Back — Bigger and Badder Than Ever Before

On the Evolution of Ransomware

Good article on the evolution of ransomware:

Though some researchers say that the scale and severity of ransomware attacks crossed a bright line in 2020, others describe this year as simply the next step in a gradual and, unfortunately, predictable devolution. After years spent honing their techniques, attackers are growing bolder. They’ve begun to incorporate other types of extortion like blackmail into their arsenals, by exfiltrating an organization’s data and then threatening to release it if the victim doesn’t pay an additional fee. Most significantly, ransomware attackers have transitioned from a model in which they hit lots of individuals and accumulated many small ransom payments to one where they carefully plan attacks against a …

Continue reading On the Evolution of Ransomware

Finnish Data Theft and Extortion

The Finnish psychotherapy clinic Vastaamo was the victim of a data breach and theft. The criminals tried extorting money from the clinic. When that failed, they started extorting money from the patients:

Neither the company nor Finnish investigators have released many details about the nature of the breach, but reports say the attackers initially sought a payment of about 450,000 euros to protect about 40,000 patient records. The company reportedly did not pay up. Given the scale of the attack and the sensitive nature of the stolen data, the case has become a national story in Finland. Globally, attacks on health care organizations have escalated as cybercriminals look for higher-value targets…

Continue reading Finnish Data Theft and Extortion

Pandemic, A Driving Force in 2021 Financial Crime

Ransomware gangs with zero-days and more players overall will characterize financially motivated cyberattacks next year. Continue reading Pandemic, A Driving Force in 2021 Financial Crime

Pay2Key Ransomware Joins the Threat Landscape

As we approach the end of a year that has been trying for so many reasons, yet another ransomware has been seen in the wild targeting corporations—in particular, Israeli companies. A report published by Check Point Software tells of the new ransomware… Continue reading Pay2Key Ransomware Joins the Threat Landscape

Don’t Let DDoS Extortionists Deliver a KO Punch

Since mid-August, a variety of threat actors (and copycats alike) have been targeting organizations across all industries globally, threatening impending DDoS attacks unless Bitcoin is paid out. It’s apparent, as the campaign rages on, that some busine… Continue reading Don’t Let DDoS Extortionists Deliver a KO Punch

Don’t Let DDoS Extortionists Deliver a KO Punch

Since mid-August, a variety of threat actors (and copycats alike) have been targeting organizations across all industries globally, threatening impending DDoS attacks unless Bitcoin is paid out. It’s apparent, as the campaign rages on, that some businesses must be paying the extortion demands, — incentivizing the criminal activity. Others are procuring emergency DDoS defenses in order to withstand bandwidth-busting attacks and keep internet-facing infrastructure protected. As highlighted in our last blog, we’ve been busy ramping customers on to our DDoS mitigation platforms for rapid protection before the threat actors strike again. And based on recent activity, they desire a rematch. Continue reading Don’t Let DDoS Extortionists Deliver a KO Punch

Why the extortion of Vastaamo matters far beyond Finland — and how cyber pros are responding

Even for veterans of cybercriminal investigations, the recent extortion of a psychotherapy practice in Finland has been unusual — and disturbing. Rather than sticking only to the common tactic of trying to shake down a breached organization, the attackers who stole tens of thousands of patient records from Vastaamo also demanded ransoms from individual people. In doing so, the thieves have been leveraging some of the most sensitive medical data imaginable, and making it difficult for victims to respond collectively. “Therapeutic notes are at a different level of privacy problems,” said Mikko Hypponen, chief research officer at Finnish cybersecurity company F-Secure. “I know of a handful of cases where patients were blackmailed for their health data, but those were much smaller breaches. There’s never been a crime in Finland with so many victims as in this one.” While the incident has rocked Finland, prompting an emergency government meeting and costing Vastaamo’s CEO his job, […]

The post Why the extortion of Vastaamo matters far beyond Finland — and how cyber pros are responding appeared first on CyberScoop.

Continue reading Why the extortion of Vastaamo matters far beyond Finland — and how cyber pros are responding

Data breach at Finnish psychotherapy center takes a darker turn with extortion attempts

The response to a data breach at a prominent Finnish psychotherapy practice intensified over the weekend after cybercriminals reportedly posted batches of patient information on the dark web and claimed that individual people could protect their data by directly paying a ransom. The breach at Vastaamo, which has locations throughout Finland, prompted an emergency meeting of the country’s Cabinet on Sunday. The company said the incident happened as early as November 2018. Local news reports say the attackers didn’t contact Vastaamo with any demands until September of this year. Neither the company nor Finnish investigators have released many details about the nature of the breach, but reports say the attackers initially sought a payment of about 450,000 euros to protect about 40,000 patient records. The company reportedly did not pay up. Given the scale of the attack and the sensitive nature of the stolen data, the case has become a […]

The post Data breach at Finnish psychotherapy center takes a darker turn with extortion attempts appeared first on CyberScoop.

Continue reading Data breach at Finnish psychotherapy center takes a darker turn with extortion attempts