Top US hedge funds targeted by major vishing campaign


Some of the biggest US hedge funds and law firms have been targeted by a highly sophisticated data breach and extortion campaign, conducted by a group of criminals previously known as BlackFile, experts have warned.

BlackFile (or Redact, as the group is now calling itself) has a relatively simple modus operandi, also used by ShinyHunters – they call their targets on the phone (usually employees with access to SaaS systems), identify as IT staff, and direct victims to convincing, lookalike login pages designed to steal their credentials and authentication tokens.

Once they gain access to victims’ accounts, the attackers access enterprise SaaS environments (for example, Microsoft 365 and Okta) and use automated tools to exfiltrate sensitive data. In the last step, they notify the victims and threaten to leak the data on the dark web unless a ransom is paid.

Read more…
Source:  Tech Radar News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • FBI worked with Ukraine intelligence agency to remove social media accounts

    July 10, 2023

    The FBI colluded with a Ukrainian intelligence agency in an effort to disrupt Russian disinformation campaigns by flagging social media accounts in a failed effort that ensnared a verified Russian-language U.S. State Department account and others, the House Judiciary Committee said in a report released Monday. The report said the FBI partnered with the SBU, one ...

  • Florida patients among 11 million affected by HCA Healthcare data breach

    July 10, 2023

    Data on roughly 11 million HCA Healthcare patients in 20 states including Florida, was stolen and recently posted on an online forum, the hospital chain reported on Sunday. According to the company, an unauthorized party gained access to 27 million rows of data stored at an external location that is used to to automate company email ...

  • Charges filed in cyber attack on East Bay water treatment plant

    July 6, 2023

    A 53-year-old Tracy man is facing federal criminal charges in connection with an alleged attack on the computer systems of a Discovery Bay water treatment plant more than two years ago, according to the U.S. Attorney’s Office. Rambler Gallo was a full-time employee of a private Massachusetts-based company that contracted with Discovery Bay to operate the ...

  • CISA and Partners Release Joint Cybersecurity Advisory on Newly Identified Truebot Malware Variants

    July 6, 2023

    Today, the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigations (FBI), the Multi-State Information Sharing and Analysis Center (MS-ISAC), and the Canadian Centre for Cyber Security (CCCS) released a joint Cybersecurity Advisory (CSA), Increased Truebot Activity Infects U.S. and Canada Based Networks, to help organizations detect and protect against newly identified Truebot malware ...

  • CISA: DoS and DDoS Attacks against Multiple Sectors

    June 30, 2023

    CISA is aware of open-source reporting of targeted denial-of-service (DoS) and distributed denial-of-service (DDoS) attacks against multiple organizations in multiple sectors. These attacks can cost an organization time and money and may impose reputational costs while resources and services are inaccessible. If you think you or your business is experiencing a DoS or DDoS attack, it ...

  • 2023 CWE Top 25 Most Dangerous Software Weaknesses

    June 29, 2023

    The Homeland Security Systems Engineering and Development Institute, sponsored by the Department of Homeland Security and operated by MITRE, has released the 2023 Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Weaknesses. The CWE Top 25 is calculated by analyzing public vulnerability data in the National Vulnerability Data (NVD) for root cause mappings to ...