HACKINTOSH.ORG | Macintosh discussion forums

Macintosh News => Apple News => Topic started by: HCK on October 13, 2023, 04:05:05 pm



Title: SEC investigating MOVEit hack that exposed data of at least 64 million people
Post by: HCK on October 13, 2023, 04:05:05 pm
SEC investigating MOVEit hack that exposed data of at least 64 million people

<p>Progress Software disclosed that it has received a <a data-i13n="cpos:1;pos:1" href="https://www.sec.gov/Archives/edgar/data/876167/000087616723000190/prgs-20230831.htm">subpoena[/url] from the SEC to share information relating to the vulnerability in its file transfer software, <a data-i13n="cpos:2;pos:1" href="https://www.progress.com/moveit">MOVEit[/url], which became the subject of a massive exploit beginning last May. According to the filing, the investigation is presently a "fact-finding inquiry," and there's no indication at this time that Progress has "violated federal securities laws." The company intends to cooperate with the SEC.</p>
<p>One <a data-i13n="elm:affiliate_link;sellerN:;elmt:;cpos:3;pos:1" href="https://shopping.yahoo.com/rdlw?siteId=us-engadget&amp;pageId=1p-autolink&amp;featureId=text-link&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3d3dy5lbXNpc29mdC5jb20vZW4vYmxvZy80NDEyMy91bnBhY2tpbmctdGhlLW1vdmVpdC1icmVhY2gtc3RhdGlzdGljcy1hbmQtYW5hbHlzaXMvIiwiY29udGVudFV1aWQiOiJmMTk2YmJhMC1lMGQ2LTQ4NDYtYjg0Ni1kMDVmYjc0MzgyZWYifQ&amp;signature=AQAAATxBxKmh_3GBUPiBhf04yhPvzHEWHjt6uEur1kU4j3yk&amp;gcReferrer=https%3A%2F%2Fwww.emsisoft.com%2Fen%2Fblog%2F44123%2Funpacking-the-moveit-breach-statistics-and-analysis%2F" class="rapid-with-clickid" data-original-link="https://www.emsisoft.com/en/blog/44123/unpacking-the-moveit-breach-statistics-and-analysis/">report[/url] by cybersecurity software company Emsisoft&nbsp;estimates that the MOVEit breach exposed the information of at least 64 million individuals through 2,547 affiliated organizations. Among the organizations impacted by the zero-day vulnerability are the Louisiana Office of Motor Vehicles and the Colorado Department of Health Care Policy and Financing. <a data-i13n="cpos:4;pos:1" href="https://www.engadget.com/sony-confirms-data-breach-affecting-nearly-7000-employees-075945888.html">Sony confirmed[/url] its employee data was compromised in the exploit earlier this month. And Michigan-based financial services provider, Flagstar Bank, sent its customers <a data-i13n="cpos:5;pos:1" href="https://s3.documentcloud.org/documents/24017531/flagstar-consumer-notification-template.pdf">a notice[/url] that said records had been stolen (they'll now receive free identity monitoring services for two years.)</p>
<span id="end-legacy-contents"></span><p>The culprits of the attack — the CL0P ransomware gang — "helped pioneer the practice of double-extortion," according to <a data-i13n="cpos:6;pos:1" href="https://www.reuters.com/technology/who-is-behind-sweeping-moveit-hack-2023-06-27/">Reuters[/url]. In this sort of scheme, the ransomers both encrypt the target's data and threaten to leak said data (unless they're paid.) The group have since made <a data-i13n="cpos:7;pos:1" href="https://www.bleepingcomputer.com/news/security/clop-now-leaks-data-stolen-in-moveit-attacks-on-clearweb-sites/">clearweb sites[/url] to leak some of the data they've exfiltrated in the MOVEit hack, from companies like Kirkland and TD Ameritrade. The FBI have since <a data-i13n="cpos:8;pos:1" href="https://twitter.com/RFJ_USA/status/1669740545403437056">offered[/url] up to $10 million to anyone with information that could link CL0P to any particular foreign government.</p>
<p>The true cost (both to victims and Progress Software) remain unknown at this time. But some of the affected customers have begun seeking restitution for the breach. Progress disclosed in the same regulatory filing that it is a party to 58 class action lawsuits at this time. Many of those may be consolidated as they progress, but they still present the possibility of enormous civil penalties.</p>This article originally appeared on Engadget at https://www.engadget.com/sec-investigating-moveit-hack-that-exposed-data-of-at-least-64-million-people-163057853.html?src=rss

Source: SEC investigating MOVEit hack that exposed data of at least 64 million people (https://www.engadget.com/sec-investigating-moveit-hack-that-exposed-data-of-at-least-64-million-people-163057853.html?src=rss)