Back to top

Hacks, Attacks and Breaches: 07/01/2020 to 07/07/2020

Suzanne Gassman

Here’s the latest installment of the Hacks, Attacks and Breaches cybersecurity news update.

The Logically team provides top cyber security stories every week to keep you up to date on the latest news headlines on cybersecurity, hacking, computer security, ransomware and other cybersecurity threats.

United States – Department of Education

Exploit: Unsecured Database
United States Department of Education: Federal Government Agency 

Risk to Small Business: A large number of Americans may have had their personally identifiable data compromised by the United States Department of Education. According to reports, the agency left the Social Security numbers of tens of thousands of people seeking student debt relief unprotected and susceptible to a data breach for at least six months. While the information was stored securely enough to prevent an external breach, any users of the agency’s systems could freely access the information in a simple shared folder, including outside contractors.   

How it Could Affect Your Business: Failure to secure a customer’s information briefly is bad enough but allowing that information to stay unsecured for more than 6 months shows indicates an overall lack of concern regarding cybersecurity that may make future clients think twice about starting a business relationship.

United States – Healthcare Fiscal Management

Exploit: Ransomware
Healthcare Fiscal Management: Payment Solutions Provider 

Risk to Small Business: Maze ransomware has claimed another victim. Healthcare Fiscal Management in North Carolina was hit, exposing private data for thousands of patients of St. Mary’s Healthcare System in Georgia, including names, dates of birth, Social Security numbers, account numbers, medical record numbers, and dates of service. The company was able to restore data from backup storage the same day to a different hosting provider and a forensic investigation firm was brought on board to investigate the breach.

How it Could Affect Your Business: Ransomware is an ongoing threat to every business, and it’s primarily delivered via phishing. Failure to stop a ransomware attack can not only cost a fortune in recovery, it can also incur huge fines from regulators. Companies that deal with particularly sensitive data should have constantly updated training in place for every user to prevent phishing attacks from landing. 

United States – CNY Works

Exploit: Ransomware
CNY Works: Employment Assistance Non-Profit

Risk to Small Business: Job seekers who used CNY Works as part of their search were recently informed that their personal information may have been compromised in a data breach caused by ransomware in December 2019. The agency noted that it had only begun notifying potentially affected clients in June 2020 because it did not discover that any personal information was affected until May 2020. 

How it Could Affect Your Business: By taking so long to investigate the incident and warn potential victims, CNY Works has left them at risk for identity theft. Data that enables identity theft is a valuable commodity in Dark Web markets and travels quickly, enabling bad actors to open credit accounts with the stolen information.   

United States – V Shred

Exploit: Unsecured Database
V Shred: Fitness and Nutrition Brand 

Risk to Small Business: An unsecured Amazon S3 bucket is once again the cause of a data breach. This time, fitness and nutrition company V Shred failed to secure 606 GB of customer data that is now in the hands of cybercriminals. The huge haul of information includes the full name, age, gender, date of birth, spouse names, email address, phone numbers, home addresses, health conditions, citizenship status, Social Security number, social media accounts, username, and password for clients and fitness trainers throughout the US. It is also suspected that potentially revealing fitness journey “before” and “after” photos were included in the files. 

How it Could Affect Your Business: Failure to secure this database could be catastrophic for this company. It entered an agreement with trainers and clients when it collected such personal information, and it failed to keep up its end, creating distrust that will linger. This information has already been seen on the Dark Web and includes extremely sensitive data.