UBS bank reports data leak after attack on its external supplier


Zurich-based banking giant UBS Group has confirmed that company information was stolen during a cyberattack on one of its external suppliers, though it assured that no client data was compromised.

The bank said the breach was part of a larger cyber incident affecting multiple companies, including former UBS affiliate Chain IQ and Swiss private bank Pictet. “A cyber-attack at an external supplier has led to information about UBS and several other companies being stolen,” UBS said in a statement. “No client data has been affected. As soon as UBS became aware of the incident, it took swift and decisive action to avoid any impact on its operations.”

Read more…
Source: CNN News


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Ransomware attack exposes data of 500,000 Chicago students

    May 21, 2022

    The Chicago Public Schools has suffered a massive data breach that exposed the data of almost 500,000 students and 60,000 employee after their vendor, Battelle for Kids, suffered a ransomware attack in December. Ohio-based Battelle for Kids is a not-for-profit educational organization that analyzes student data shared by public school systems to design instructional models and ...

  • Global food supply chain at risk from malicious hackers

    May 20, 2022

    Modern “smart” farm machinery is vulnerable to malicious hackers, leaving global supply chains exposed to risk, experts are warning. It is feared hackers could exploit flaws in agricultural hardware used to plant and harvest crops. Agricultural manufacturing giant John Deere says it is now working to fix any weak spots in its software. Read more… Source: BBC News  

  • Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices

    May 19, 2022

    In the last six months, we observed a 254% increase in activity from a Linux trojan called XorDdos. First discovered in 2014 by the research group MalwareMustDie, XorDdos was named after its denial-of-service-related activities on Linux endpoints and servers as well as its usage of XOR-based encryption for its communications. XorDdos depicts the trend of malware ...

  • Bruised but Not Broken: The Resurgence of the Emotet Botnet Malware

    May 19, 2022

    The Emotet botnet malware is well known in the cybersecurity industry for its success in using spam emails to compromise machines and then selling access to these machines as part of its infamous malware-as-a-service (MaaS) scheme. Operators behind notorious threats such as the Trickbot trojan and the Ryuk or Conti ransomware are among the malicious ...

  • Weaponization of Excel Add-Ins Part 2: Dridex Infection Chain Case Studies

    May 19, 2022

    In Part 1 of this two-part blog series, Unit 42 researchers discussed briefly how XLL files are exploited to deploy Agent Tesla. During December 2021, they continued to observe Dridex and Agent Tesla exploiting XLL in different ways for initial payload delivery. A more in-depth look at the Dridex infection chain follows. Threat actors behind Dridex ...

  • Hydra with Three Heads: BlackByte & The Future of Ransomware Subsidiary Groups

    May 18, 2022

    On February 13, 2022, a novel, lesser-known ransomware collective posted the alleged financial documents of the San Francisco 49ers football team on their underground site. The threat group, known as BlackByte, was widely credited with the orchestration of the attack—However, AdvIntel’s sensitive primary-source intelligence and factual data evidence (including IOCs) point to a different conclusion: ...