Skip to main content
Category

Cyber Attacks

Dept. of Homeland Security Highly Recommends Better Cyber Practices

Evolve MGA Cyber Insurance

Despite Donald Trump’s push to increase cyber security initiatives (May of 2017), as well as the abundance of cyber security resources and tools on the market today, the department of Commerce and Homeland Security reported that a large majority of businesses are not utilizing effective tools to address botnets and other automatic, distributed threats. According to the Botnet report by both departments, cyber security tools are routinely applied in select market sectors but are not part of common practices for product development in many other sectors for a variety of reasons, including lack of awareness, cost avoidance, insufficient technical expertise and lack of market incentives.

Due to this concern the departments have created action plans to assist with adapting to current security protocols in order to avoid and mitigate automated cyber attacks. The Departments of Commerce and Homeland Security also recommend creating partnerships that correlate with overall security, infrastructure, and operational technology services with the goal of increasing awareness amongst all levels of employees across all industries.

A cyber insurance policy from Evolve MGA not only protects your business from cyber risks, but it also provides your clients or business to partner with some of the best security tools on the market. To learn more about how our preferred vendors and how they can assist employees with the skills needed to detect a potential cyber attack, check out our Risk Management page.

It’s important to note the consistency of cyber risks and threats surrounding lack of employee awareness, regardless of industry. All businesses are utilizing internet connections, accessing data, transacting payments, and distributing customer information, but not every business is protected against modern day exposures.

Evolve MGA offers cyber liability insurance that covers policyholders in the event their cloud data is hacked. If you’re interested in protecting your business with cyber coverage, head over to our free cyber quote page.

If you’d like to read more about the security protocols that the Departments of Commerce and Homeland Security are recommending, click here.

 

 

 

FBI Warns Hidden Cobra Is Targeting Organizations Across the Globe

hidden cobra

The FBI have issued warnings surrounding two North Korean backed, malicious malware, that are targeting media organizations, aerospace, financial and critical infrastructure sectors around the globe. Known as Hidden Cobra, the malware has links to popular cyber attacks that have occurred in past years. Some of those attacks are WannaCry, which shut down hospitals and businesses around the world, Sony Pictures hack, which occurred in 2014, as well as the Swift banking attack in 2016. 


Hidden Cobra is using a Remote Access Trojan (RAT) in order to attack their victims. The RAT is a two-stage malware that establishes peer-to-peer communications and manages botnets designed to enable other malicious operations, according to the US-Cert.  
 Using remote command by the Hidden Cobra “team”, the malware infects systems by utilizing another deliverable malware file, which tricks users into visiting compromised websites or downloading malicious attachments.

Avoiding these attacks can be done by providing staff with security tools & training. To learn more about best security standards and tools, head over to our Risk Management page! Evolve MGA offers cyber liability insurance that covers policyholders in the event their cloud data is hacked, lost, or stolen. 

If you’re interested in reading more about the Hidden Cobra malware, click here.

Mental Healthcare Practice Hit With Cyber Attack & Quickly Paid Ransom

mental healthcare practice

A mental healthcare practice was hit with a ransomware attack and they quickly decided to pay the ransom to ensure their data does not get exposed or deleted. The practice disclosed that on March 31st, their computers containing patient data had been accessed remotely and encrypted by attackers.

According to reports, the mental healthcare practice’s office manager, decided to pay an undisclosed ransom after determining it would take longer and potentially be more difficult to attempt to restore its systems without obtaining a decryption key from the hackers. The computers that were exposed contained names, addresses, birthdates, Social Security numbers, treatment records and insurance data.

Had the practice not of paid the ransom, there’s a high probability that the data would have been sold on the dark web.  Had the patient data been exposed, the mental healthcare practice would have been forced to purchase credit monitoring services for patients, forensic security consultants, PR consultants, and data breach attorneys, all billing at an hourly rate.

Evolve MGA offers cyber insurance that covers policyholders in the event their cloud data is hacked, lost, or stolen. Interested in equipping your business with cyber coverage? Get a free cyber quote today.

If you’d like to read more, click here.

LifeBridge Health Hacked & 539,000 Patients Health Records Exposed

LifeBridge Health

LifeBridge Health was hit with a malware cyber attack back in 2016 and it took 18 months to discover the vulnerability. Roughly 539,000 patients were exposed in this cyber attack that targeted the server containing patient electronic health records.

Although LifeBridge Health understands that the information of their patients presents a huge vulnerability, they do not believe it was misused in any way. However, they are offering one free year of credit monitoring and identity protection to ensure patients are protected. According to LifeBridge Health the information potentially accessed may include patients’ names, addresses, dates of birth, diagnoses, medications, clinical and treatment information, insurance information, and in some instances Social Security numbers.

In addition to purchasing credit monitoring services for patients, LifeBridge Health most likely hired forensic security consultants, PR consultants, and data breach attorneys, all billing at an hourly rate.

Evolve MGA offers cyber liability insurance that covers policyholders in the event their cloud data is hacked, lost, or stolen. If you’re interested in equipping your business with cyber coverage, head over to our website for a free cyber quote!

If you’d like to read more about the vulnerabilities surround the healthcare industry, click here.

Corporation Service Company’s Data Breach Is Directly Affecting California Clients

Evolve MGA Cyber Insurance

The Delaware Corporation Service Company (CSC), which provides business, legal, tax, and digital brand services to companies around the world, experienced a data breach this week, directly affecting clients in California. Often times, digital brands establish LLC’s in the state of Delaware due to the favorable business climate they offer corporations. CSC works as a one stop shop for most brands as they perform services such as: keeping your business in compliance, streamlining operations, and protecting and promoting your brand online. However, cybercriminals were able to expose their client’s personal identifiable information due to a breach in the company’s network.

According to reports, the Corporation Service Company sent notice to the California District Attorney acknowledging the 5,678 clients that were affected by the cyber attack. The clients were made aware that not only was there an unauthorized hacker within the company’s network between the months of November through April, but the cyber criminal exposed clients’ names, social security numbers, and payment card information.

It comes at no surprise that CSC hired post breach experts in order to mitigate the damages of this breach. Based on the reports, Corporation Service Company hired two cyber security firms, PR consultants, data breach attorneys, all billing at an hourly rate. Depending on their findings, notification and credit monitoring costs could follow. Additionally, the company is implementing enhanced security measures (two-factor authentication, additional firewalls, enforcing 16-character passwords for all employees, etc.) in order to prove they are taking this breach seriously.

Evolve MGA offers cyber liability insurance that covers policyholders in the event their cloud data is hacked, lost, or stolen. If you’re interested in equipping your business with cyber coverage, head over to our website for a free cyber quote!

If you’d like to read more about Corporation Service Company’s data breach, click here.

LocationSmart Leaked Real-Time Locations Of Cell Phones To Anyone

Evolve | LocationSmart Leaked

LocationSmart, a service that identifies real-time locations of AT&T, Sprint, and Verizon smart phones up to a hundred yards in proximity, has been exposed by security researchers due to a free trial exploitation.

In order to gain access to the free trial demo, a prospective user would enter their name, email address, and phone number. LocationSmart would then message the user asking for permission to locate their mobile device, utilizing the closest cellular network tower.

It was then that Security researcher, Robert Xiao figured out that practically anyone with web development experience could expose the LocationSmart demo site in order to gain access to mobile phone locations without having to supply a password or login credentials.

Fortunately for LocationSmart, Krebs and Robert Xiao of Carnegie Mellon University were able to address this vulnerability before their users could be exploited by cybercriminals (or so we know). Equipping a Cyber Insurance policy would protect SmartLocation or any business in the event they would have been hacked.

Evolve MGA offers cyber liability insurance that covers policyholders in the event their cloud data is hacked. If you’re interested in protecting your business with cyber coverage, head over to our website for a free cyber quote!

If you’d like to read more about LocationSmart, click here.

Mexico’s Central Bank Lost $15 Million Due To Fake Money Orders

Evolve MGA Cyber Insurance

Mexico’s central bank initially reported real-time processing issues a couple of weeks ago when they noticed cyber threat activity surrounding their encrypted network that allows for real-time payments to be transferred between private accounts. Reports indicate that operational incidents reflect the workings of hackers attempting to intercept these real-time payments. Although they were initially able to protect their customers and banks by transitioning to their contingency protocol, recent reports indicate that the hackers were able to steal over $15 million from dozens of different bank branches.

According to the central bank, the cyber criminals stole $15 million by creating fake money orders and phony accounts in order to withdraw the funds. The hackers sent hundreds of money orders in order to steal hundreds of thousands of pesos, then quickly had their boots on the ground to withdraw the money before the banks were able to stop the attack. The bank is working to mitigate this cyber threat, but assures that customers were not affected in this cyber attack.

It’s important to note the consistency of cyber risks and threats surrounding network exposures, regardless of industry. All businesses are utilizing internet connections, accessing data, transacting payments, and distributing customer information, but not every business is protected against modern day exposures. 

Evolve MGA offers cyber security insurance that covers policyholders in the event their cloud data is hacked, lost, or stolen, as well as cyber risk resources to protect employees from falling victim to a hacker’s attempt to accessing your system. Our cyber insurance specialists are here to equip your business or clients with a free cyber quote and cyber insurance policy to provide the best possible cyber coverage.

If you’d like to read more about Mexico’s central bank cyber attack, click here.

Chili’s Baby Back Ribs With A Side of Data Breach

Evolve MGA Cyber Insurance

Utilized at many, if not all modern restaurants, point of sale (POS) systems are becoming increasingly more at risk of being hacked by cyber criminals due to the volume of customers they can expose, as well as the lucrative information that is attached to their payment cards. Often times, this information is collected and then sold on the Dark Web.

According to Chili’s parent company, Brinker International, the data breach, which was discovered on May 11th, could have affected the company and its customers over the course of March and April, which puts many customers at risk of being exposed.

Although Brinker believes that they caught the cyber attack early, they have not provided an approximate amount of customers who are at risk, but are providing 12 months of credit monitoring to all who were affected. If Brinker had a cyber insurance policy in place, not only would they be covered from this breach, but the cost for providing credit monitoring to all affected customers would be waived.

Evolve MGA offers cyber liability insurance that covers policyholders in the event their cloud data is hacked, lost, or stolen. If you’re interested in equipping your business with cyber coverage, head over to our website for a free cyber quote!

Nuance Communications Hit With 2nd Data Breach In The Past Year!

nuance communications

Speech recognition software company, Nuance Communications was hit with a data breach that has exposed over 45,000 individual records. Since the cyber attack, Nuance has contacted all of the affected patients, shut down their site in order to investigate the security breach, and transitioned patients over to their eScription transcription platform in order to convert dictation by clinicians into documents.

To add to this devastating discovery, Nuance Communications was also severely affected in 2017 when they were hit by NotPetya Malware, which cost the company $92 million!

Nuance Communications did not have a Cyber Insurance Policy in place and as a result, they estimated to have lost approximately $68 million in revenues in 2017, primarily from their healthcare segment, due to business interruption and credit monitoring payments for affected customers. Additionally, they also experienced a loss of $24 million in 2017 as a result of remediation and restoration efforts, according to Nuance.

Evolve MGA offers cyber liability insurance that covers policyholders in the event their cloud data is hacked, lost, or stolen. If you’re interested in equipping your business with cyber coverage, head over to our website for a free cyber quote!

If you’d like to read more about this data breach, click here.

Two-Factor Authentication Is Not A Standalone Best Security Practice

Evolve MGA Cyber Insurance

Two-factor authentication was a method created to confirm the identity of an individual utilizing multiple factors that the user has and knows in order to access an account securely. Although this security protocol has been deemed to be a significant step in securing accounts, hacking professional, Kevin Mitnick, has proven that hackers can spoof the security and send a user to a fake login page and steal the credentials and session cookie.

Utilizing a false domain to lure users in, the hacker can capture the login credentials and authentication code, which they would pass onto the actual site and login indefinitely. Intended to be an extra layer of security to rely on in order to protect your organization, Mitnick has shown that two-factor authentication cannot be a standalone solution to security. With a cyber insurance policy in place, policyholders are protected in the event their cloud data is hacked.

As Stu Sjouwerman of KnowBe4 notes, “anti-phishing education is deeply important and that a hack like this is impossible to complete if the victim is savvy about security and the dangers of clicking links that come into your email box.”

Head over to our Risk Management page to learn more about the best security tools on the market.

If you’d like to read more about two-factor authentication, click here.