Monday, March 2, 2020


United States - TV Eyes

Exploit: RansomwareTV Eyes: Media monitoring service
extreme gauge

Risk to Small Business: 2.222 = Severe: An unidentified ransomware strain has disabled the network’s core servers and engineering workstations. As a result, clients have been unable to access any information, which could have broad and long-lasting financial consequences for the media monitoring company. TV Eyes has declined to pay the ransom. Still, brand erosion and opportunity costs will make this an expensive attack at a critical time for the company, whose services are widely used by news outlets and PR agencies to access media content for reporting purposes.
correct severe gauge

Individual Risk: 2.875 = Moderate: At this time, no personal information was compromised in the breach. However, some PR professionals and media members had expressed fears that their data was compromised before hackers encrypted their files. Those impacted by the breach should update their account credentials while being especially critical of digital communications.
Customers Impacted: Unknown
How it Could Affect Your Customers’ Business: In addition to academic and government institutions, cybercriminals are increasingly targeting businesses that store customer data. Many are now willing to compromise customer data if ransom demands aren’t met, a new reality that significantly increases the potential damage of a ransomware attack. Since ransomware attacks always require a vulnerability to gain network access, companies should regularly assess their defensive postures to ensure that they are prepared for this nefarious attack methodology.

ID Agent to the Rescue: Helping your SMB customers understand the importance of security is no easy task. With Goal Assist™, we offer hands-on assistance with your direct sales interactions, setting you up for the win by providing the resources necessary to make a case for Dark Web monitoring. Learn more here:

United States - Electronic Warfare Associates (EWA)

Exploit: Ransomware
Electronic Warfare Associates (EWA): Electronic product and services company

Risk to Small Business: 2.111 = Severe: Cybercriminals encrypted the company’s web servers, leaving customer-facing signs of a cyberattack even several days after the event. In response, the company took down the affected servers, and it’s unclear how much of the company’s internal IT is impacted by the attack. More than a week after the attack was discovered by security researchers, EWA still hasn’t issued a statement to the public. This lack of transparency could complicate their recovery process, which already promises to be an arduous journey due to the complicated nature of their business.
Individual Risk: No personal information was compromised in the breach.
Customers Impacted: Unknown
How it Could Affect Your Customers’ Business: Ransomware attacks often come with cascading consequences that impact every part of a business. Not only does this attack vector come with high up-front expenses, but the reputational damage and opportunity cost can be even more damaging. Every company should assess its threat landscape to ensure that it can adequately defend against a devastating ransomware attack.

ID Agent to the Rescue: WIth BullPhish ID™, MSPs can provide a more complete picture of a company’s security posture and potential risk, transforming the weakest links of an organization into their strongest points of protection. Find out how you can get started with us here:

United States - Fondren Orthopedic Group

Exploit: Malware attack
Fondren Orthopedic Group: Orthopedic healthcare services provider
extreme gauge

Risk to Small Business: 1.555 = Severe: A malware attack destroyed a number of the medical provider’s patient records. The incident was first discovered in November 2019, but IT administrators only recently identified the permanent damage to their digital records. As a result, patients have to complete new patient information forms that include detailed medical histories. Given the sensitive and incredibly important nature of this information, this attack could negatively impact patient care, and it will undoubtedly invite regulatory oversight.

Individual Risk: 2.285 = Severe: Fondren Orthopedic Group noted that there is no evidence of patient information being compromised. However, the lost data includes patients’ names, addresses, phone numbers, treatment data, and healthcare information. It stands to reason that if hackers can erase patient data, then they can also use it for other nefarious purposes. Those impacted by the breach should carefully monitor their online accounts for unusual or suspicious activity, and they should scrutinize digital communications because compromised data is often redeployed in spear phishing attacks.
Customers Impacted: 30,049
How it Could Affect Your Customers’ Business: After this devastating malware attack, Fondren Orthopedic Group announced an update to their cybersecurity practices, a move that is too little, too late for the thousands of patients impacted by the breach. There are many steps companies can take to mitigate the risk of a data breach, but those steps need to be taken before an incident occurs. Otherwise, these measures serve as vanity metrics as opposed to a defensive strategy.

ID Agent to the Rescue: We go into the Dark Web to keep you out of it. Dark Web IDTM is the leading Dark Web monitoring platform in the Channel. The award-winning platform combines human and sophisticated Dark Web intelligence with search capabilities to identify, analyze and proactively monitor an organization’s compromised or stolen employee and customer data. Schedule a demo today:

Canada - Confederation College

Exploit: Malware attackConfederation College: Provincially funded college of arts and technology

Risk to Small Business: 2.222 = Severe: A malware attack disabled the college’s IT services, rendering many digital accounts unusable. Fortunately, Confederation College doesn’t believe that any personal information was compromised in the breach, but they will face blowback from their student body that entrusts their personal information to the school.
correct severe gauge

Individual Risk: 2.555 = Moderate: At this time, no personal information was compromised in the breach. However, the college encourages anyone with a school email address to reset their account password and the passwords for any other accounts that may also use these credentials.
Customers Impacted: Unknown
How it Could Affect Your Customers’ Business: Even when login credentials are compromised in a data breach, businesses can still protect their accounts with simple security features like two-factor authentication. This service requires users to confirm their identity on a separate device before allowing account access, so cybercriminals deploying stolen credentials for brute force attacks are unable to find their way on to your organization’s network. As more and more information makes its way online, two-factor authentication is an obvious tool that every organization should implement.

ID Agent to the Rescue: With AuthAnvilTM , you can protect your employees’ password integrity. We offer integrated multi-factor authentication, single sign-on, and identity management solutions to protect your credentials and your data. Find out more at:

United Kingdom - Tissue Regenix

Exploit: Malware attack
Tissue Regenix: Medical technology company

Risk to Small Business: 1.888 = Severe: A malware attack forced Tissue Regenix to take its systems offline, which negatively impacted its short-term production capacity. Tissue Regenix hired cybersecurity experts to eradicate the malware, but the immediate financial repercussions were immense. The company’s shares dropped by 22% after the announcement. Researchers believe that the malware entered their network through a third-party, highlighting the importance of a 360-degree defensive posture that accounts for all possible risks.
Individual Risk: No personal information was compromised in the breach,
Customers Impacted: Unknown
How it Could Affect Your Customers’ Business: There are many ways that a data breach can impact a company’s financial outlook. In this case, the impact was immediate and intense. For businesses grappling with the cost of data security measures, this episode is a reminder that the cost of inaction can far exceed those of an effective cybersecurity strategy.

ID Agent to the Rescue: With Compliance ManagerTM, any company can automate data privacy standards and documentation responsibilities, making compliance a simple, intuitive process for everyone. Click the link to get started today:

United Kingdom - Dundee College

Exploit: Ransomware
Dundee College: Academic and research institution

Risk to Small Business: 1.666 = Severe: A ransomware attack disabled Dundee College’s entire IT infrastructure, canceling classes and requiring thousands of students to reset their account credentials. Currently, the outage has lasted more than a week, and it includes access to student records, educational material, and online learning portals. The event takes place at a critical time for the school, as they are conducting interviews for future students. In addition, the incredible recovery cost and reputational damage will facilitate a serious blowback to the college’s financial viability.
extreme gauge

Individual Risk: 2 = Severe: At this time, it’s unclear if personal data was compromised in the ransomware attack. However, Dundee College requires all students to reset their passwords before accessing their school accounts.
Customers Impacted: 5,000
How it Could Affect Your Customers’ BusinessRansomware attacks come with a litany of consequences, ranging from reputational damage to regulatory penalties and lost business. At the same time, cybercriminals are increasingly taking their attacks a step further by stealing company data before they encrypt it, increasing the impetus for companies to develop a comprehensive response strategy. Identifying compromised data and its whereabouts on the Dark Web or hacker forums is an excellent place to start.

ID Agent to the RescueDark Web ID monitors the Dark Web to find out if your employee or customer data has been compromised. We work with MSSPs to strengthen their security suite by offering industry-leading detection. Discover more at:

Australia - Metrix Consulting

Exploit: Phishing scam
Metrix Consulting: Strategic insight consultancy

extreme gauge

Risk to Small Business: 2.222 = Severe: A Metrix Consulting employee fell for a phishing scam that compromised the personal data for visitors of the Perth Mint. The data was provided by visitors who completed a survey that was stored on Metrix Consulting’s servers. This is the second data breach at Perth Mint in the past two years, and it could have significant implications for Matrix Consulting, as they may have a difficult time maintaining contracts if they can’t protect their customers’ data.
extreme gauge

Individual Risk: 2.285 = Severe: The personal data included visitors’ names, email addresses, home addresses, and telephone numbers. This information can be used in everything from identity fraud to spear phishing campaigns, so those impacted by the breach should carefully monitor their online accounts for suspicious activity. In addition, The Perth Mint is providing identity monitoring services to all victims and enrolling in this program can help provide long-term identity protection.
Customers Impacted: 1,480
How it Could Affect Your Customers’ BusinessCompanies that can’t or won’t protect their customers’ data face a serious competitive disadvantage in today’s breach-fatigued environment. As we often report here, many companies terminate contracts with businesses that fail to secure their information, making data security a bottom-line issue for any organization collecting and storing personal data.

ID Agent to the Rescue: BullPhish ID simulates phishing attacks and conducts security awareness training campaigns to educate your employees, making them the best defense against cybercrime. Click the link to get started:

Australia - Yarra Tram

Exploit: Accidental data exposure
Yarra Tram: Melbourne-based tram network

correct severe gauge

Risk to Small Business: 2.555 = Moderate: A Yarra Tram officer email to 91 commuters rejected their compensation requests, but the employee failed to conceal the email addresses, exposing them to the other recipients. Embarrassingly, in a follow-up email that attempted to recall the initial message, the sender once again failed to conceal recipient names. Victims took to social media, complaining about the error. Despite being entirely avoidable, this unforced error will result in a reputational black eye for the company, which will have to work with its customer base to restore trust after this incident.
correct severe gauge

Individual Risk: 2.714 = Moderate: Recipients’ email addresses were exposed in the message. While this information doesn’t pose a significant threat to data security, it could be used to send phishing emails, and users should carefully evaluate any unusual incoming messages.
Customers Impacted: 91
How it Could Affect Your Customers’ BusinessCompanies face cybersecurity threats from every direction, making internal, unforced errors especially egregious. Often, accidental data sharing is the result of a careless approach to data privacy. Therefore, every organization has an obligation to train their employees in the importance of data security and implement defensive best practices to reduce the risk of an embarrassing and costly data breach.

ID Agent to the Rescue: It’s critical that your SMB customers understand the importance of cybersecurity. Goal Assist is an expansion of our White Glove Support that includes hands-on assistance with your direct sales interactions. Let us help to ensure you are getting the most from your Partnership selling Dark Web ID. ID Agent’s Partner Success Team will set you up for the win! Learn more here:

Risk Levels:1 - 1.5 = Extreme Risk1.51 - 2.49 = Severe Risk2.5 - 3 = Moderate Risk*The risk score is calculated using a formula that considers a wide range of factors related to the assessed breach.

Bit by bit helps client networks run smooth and secure.. visit our website at 877.860.5831

No comments:

Post a Comment