Croatian hospital suffers network outage in ransomware attack

The University Hospital Centre in Zagreb, Croatia, was hit by a cyberattack on 27 June, claimed by the LockBit ransomware group. The attack crippled the hospital’s networks, forcing emergency patients to be redirected to other facilities. Despite the disruption, hospital officials assured that patient safety was never compromised. Over 100 experts worked tirelessly to restore the IT systems, bringing the hospital back online within 24 hours.

LockBit, a Russian-affiliated ransomware group, posted on its dark leak site that it had stolen a large cache of sensitive data from the hospital in Croatia, including medical records and employee information. The hospital has not confirmed the specifics of the stolen data but has involved the authorities, and a criminal investigation is underway. LockBit, operating since 2019, has been linked to over 1,400 attacks globally and continues to evade law enforcement despite setbacks like the FBI and Interpol’s Operation Cronos.

The attack on KBC Zagreb coincided with multiple cyberattacks on Croatian government agencies by another Russian-linked group, NoName057(16). Known for targeting the critical infrastructure of nations supporting Ukraine, NoName denied responsibility for the hospital attack, emphasising their principle of not targeting medical facilities. NoName has been responsible for numerous cyberattacks across Europe, affecting several countries’ banking systems and critical infrastructure.

Data breach at Evolve Bank and Trust compromises Wise customers’ personal information

Wise, a well-known money transfer and fintech company, stated that the personal data of some customers had been compromised in the recent Evolve Bank and Trust data breach. There is uncertainty about the extent of the breach and its impact on third-party companies, their customers, and users, as an increasing number of companies have come forward in recent days to disclose that they have been affected.

In an official statement, Wise states it had worked with Evolve from 2020 to 2023 and shared with the latter USD account details. This personal data included names, addresses, dates of birth, contact information, and Social Security numbers or Employer Identification Numbers. The statement suggests that due to the breach, there is a potential risk that customers’ personal information might be exposed. The extent of the impact on Wise customers remains undisclosed as the company continues its investigation. Yet the company assured that affected Wise customers would be notified via email. Despite the breach at Evolve, Wise assured that their systems remained integral and facilitated customers’ secure access to their accounts.  

Evolve highlighted its ongoing efforts to address the cybersecurity incident following the ransomware attack by the LockBit cybercrime group by noting there was limited data loss and minimal operational disruptions due to available backups. Evolve ensured that it would individually notify all persons affected by the breach. Affirm, EarnIn, Marqeta, Melio, and Mercury, among other Evolve partners, are investigating the impact on their customers.

Australian man charged for conducting ‘evil twin’ WiFi attacks at airports

Australia’s Federal Police (AFP) have pressed charges against an Australian man for allegedly carrying out an ‘evil twin’ WiFi attack on multiple domestic flights and airports in Perth, Melbourne, and Adelaide with the aim of stealing email and social media credentials from unsuspecting passengers. The investigation by the police in Australia was initiated following reports from airline staff in April 2024. This led to the seizure of the man’s devices at the airport and discovery of incriminating evidence on them.

In an evil twin WiFi attack, a deceptive wireless access point is set up with the same SSID (WiFi network name) as a legitimate network in the vicinity. For instance, many flights provide in-flight WiFi services that require passengers to connect to the airline’s WiFi network. In this attack, cybercriminals create a fake network with the same name, tricking users into connecting to it. Once connected users are directed to a counterfeit login page or captive portal asking them to enter their login credentials.

The Australian individual apprehended by the AFP reportedly used a portable device to establish free WiFi access points at various locations making users log in using their email or social media accounts. The stolen information could potentially be exploited to gain access to sensitive data, take over social media accounts, extort victims, or sell the data to other cybercriminals. The charges brought against the suspect include unauthorised impairment of electronic communication, possession of data with intent to commit a serious offence, unauthorised access or modification of restricted data, dishonestly obtaining or dealing in personal financial information, and possession of identification information with intent to commit an offence, each carrying significant prison sentences.

While coming across malicious WiFi access points in public spaces is rare, individuals should exercise caution when sharing login credentials on such networks. It is advisable to disable file sharing on untrusted WiFi networks and use a VPN to encrypt internet traffic and safeguard sensitive information. While ‘even twin’ attacks are known in the cybersecurity world, they are not usually encountered outside of controlled environments like hacker conferences or when used by GRU operatives. Apart from a 2018 GRU case, where hackers employed evil twin attacks to surveil the internet traffic of targets from a wide range of organisations, no other incidents of this type have been reported to date. 

Kadokawa faces major major ransomware attack

On 8 June, Kadokawa, a Japanese media conglomerate, reported a data security incident on its website, stating that multiple servers within the Kadokawa Group had become inaccessible. In response, the company promptly shut down the affected systems and investigated to determine the incident’s nature and scope.

The ongoing investigation revealed various services, including Niconico, Kadokawa’s official website, and the e-commerce site ‘ebten,’ were impacted. Kadokawa is also looking into potential information leaks resulting from the incident.

Subsequent updates from Kadokawa confirmed that the disruption was caused by a large-scale cyberattack involving ransomware. Emergency measures were taken, such as shutting down servers and forming a task force to assess the damage, identify the cause, and restore operations. The ransomware attack primarily targeted Niconico’s systems, Japan’s popular video-sharing service, as well as affected the company’s payment system, leading to payment delays for some business partners.

The BlackSuit ransomware group claimed responsibility for the attack on Kadokawa and listed the company as a victim on its data leak site. The group alleges to have stolen over 1.5TB of confidential data and threatened to publish it on 1 July unless ransom demands were met.

Kadokawa acknowledged the hacker group’s claims and stated that they are investigating the possibility of data leakage with external cybersecurity experts. The company reassured stakeholders that no credit card information of customers, including Niconico users, is stored in their systems, ensuring that such data remains secure. 

AI Innovation Challenge launched to combat cybercrime in the UK

The City of London Corporation, London and Partners and Microsoft have launched an AI Innovation Challenge, where participants will vie to spot and stop cybercriminals using fake identities and audio and visual deepfakes to commit fraud. With the increase of such events and the ubiquity of GenAI models, Nvidia, the multinational AI chip-maker, is increasingly becoming the modern-day Standard Oil. Nvidia’s chips can be found in just about all areas of economic activity, from education to medicine and in nearly all financial and professional services.

With its growing usage, its potential for fighting cybercrime increases, given its ability to analyse vast amounts of data rapidly, decipher patterns, and ultimately lead to higher fraud detection rates and greater trust in and securitise customer services. Banks in the United Kingdom lead the way in AI adoption, particularly as some 90 percent of them have already onboarded generative AI models to their asset portfolios.

Participants of the AI Innovation Challenge have until 26 July 2024 to register for the competition, which is scheduled for six weeks between September and November. The final event promises to be a display of fraud detection and other cybersecurity innovations developed during the course of the competition.

ChatGPT-4 demonstrates powerful cyberattack capabilities

A recent study has revealed that ChatGPT and similar large language models (LLMs) are highly effective in launching cyberattacks, raising significant concerns in the cybersecurity field.

Researchers Richard Fang, Rohan Bindu, Akul Gupta, and Daniel Kang tested ChatGPT-4 against 15 real-life ‘one-day’ vulnerabilities, finding that it could exploit these vulnerabilities 87% of the time. These vulnerabilities included websites issues, container management software, and Python packages, all sourced from the CVE database.

The study utilised a detailed prompt with 1,056 tokens and 91 lines of code, including debugging and logging statements. The research team noted that ChatGPT-4’s success stemmed from its ability to handle complex, multi-step vulnerabilities and execute various attack methods. However, without the CVE code, ChatGPT-4’s success rate plummeted to just 7%, highlighting a significant limitation.

The researchers concluded that while ChatGPT-4 currently stands out in its ability to exploit one-day vulnerabilities, the potential for LLMs to become more powerful and destructive is a major concern. They emphasised the importance of the cybersecurity community and LLM providers collaborating to integrate these technologies into defensive measures and carefully consider their deployment.

Report reveals cyber insurance premiums decline despite rising ransomware attacks

A report by Howden has stated that cyber insurance premiums are on a downward trend worldwide despite the rise in ransomware attacks as businesses are upping their capacity to mitigate losses from cybercrime. The surge in insurance premiums first arose during 2021 and 2022 because of COVID-19 pandemic and an increase in cyber incidents but has since declined in the following years. The cyber insurance market witnessed significant price reductions in 2023/24, attributed to advancements such as multifactor authentication that significantly enhanced data protection, decreasing insurance claims.

Sarah Neild, the head of UK cyber retail at Howden, highlighted the fundamental role of multifactor authentication in securing data, comparing it to a basic security measure akin to locking the door when leaving the house. Neild stressed the multifaceted nature of cybersecurity, underscoring the importance of increased investments in IT security, including employee training. 

Following Russia’s invasion of Ukraine in February 2022, global ransomware attacks saw a decline as hackers from these regions shifted their focus to military activities. However, recorded ransomware incidents surged by 18% in the first five months of 2024 compared to the previous year—ransomware functions by encrypting data where hackers typically offer victims a decryption key in exchange for cryptocurrency payments. While business interruption remains the primary cost after a cyberattack, businesses can mitigate these expenses by instituting improved backup systems such as cloud backup systems.

Although most of the cyber insurance business is concentrated in the United States, the report anticipates that the fastest-growing market will be Europe in the coming years due to lower current penetration levels. Finally, the report finds that smaller firms exhibit lower rates of cyber insurance adoption, which can partly be attributed to a need for more awareness regarding cyber risks.

OpenAI improves GPT-4 with CriticGPT

OpenAI has launched CriticGPT, a new model based on GPT-4, designed to identify and critique errors in ChatGPT’s outputs. The tool aims to enhance human trainers’ effectiveness by assisting them in providing feedback on the chatbot’s performance.

According to OpenAI, CriticGPT-assisted trainers have demonstrated a 60% improvement over those without assistance, particularly in reducing false outputs. However, challenges remain, especially in handling complex tasks and scattered errors.

Similar to ChatGPT’s training process, CriticGPT learns through human feedback, focusing on identifying intentionally inserted errors in ChatGPT’s code outputs. Evaluations showed that CriticGPT’s critiques were preferred over ChatGPT’s in 63% of cases involving naturally occurring bugs, highlighting its ability to minimize irrelevant feedback.

OpenAI plans to further develop CriticGPT’s capabilities, aiming to integrate advanced methods to improve human-generated feedback for GPT-4. The initiative underscores the ongoing role of human oversight in refining AI technologies despite their increasing automation capabilities.

Geisinger reveals data breach by ex-employee affecting million patients

Geisinger recently disclosed that on 29 November, a former Nuance Communications employee detected unauthorised patient data access just two days after the employee’s termination. Nuance Communications, a technology service provider owned by Microsoft, has access to Geisinger’s patient records as part of their IT services agreement.

Upon notification of the breach, Nuance promptly revoked the ex-employee’s access to Geisinger’s records and initiated an investigation to assess the incident’s extent. Subsequent findings revealed that the former employee had illicitly obtained information about over one million Geisinger patients. The compromised data included details such as names, dates of birth, addresses, medical record numbers, race, gender, phone numbers, and facility name abbreviations.

Geisinger clarified that sensitive information like claims or insurance details, credit card numbers, bank account information, and Social Security numbers remained secure and were not accessed by the ex-employee. Following a thorough investigation, the former Nuance employee was apprehended and is currently facing federal charges. Geisinger’s chief privacy officer, Jonathan Friesen, emphasised the organisation’s commitment to safeguarding patient privacy, stating, ‘Our patients’ and members’ privacy is a top priority, and we take protecting it very seriously.’ Friesen expressed gratitude for the swift resolution of the case while acknowledging the unfortunate breach.

The former Nuance employee, Max Vance, is now undergoing legal proceedings at the US Middle District Court in Williamsport. Geisinger has advised all impacted individuals to remain vigilant by monitoring their credit reports, account statements, and benefits for any unusual activity. In case of suspicion, affected individuals are urged to report such incidents to the relevant authorities, including law enforcement agencies and the state attorney general.

Evolve Bank and Trust falls victim to cyberattack affecting FinTech companies

Evolve Bank and Trust, a prominent financial institution favoured by fintech startups, disclosed on Wednesday that it was victim to a cyberattack and data breach that may have impacted its affiliated companies. According to the company’s statement, the incident involved the personal information and data of some Evolve retail bank customers.

The cybercriminals linked to the breach are believed to be the infamous ransomware gang LockBit, which purportedly shared data stolen from Evolve on its dark web leak site. Evolve’s website lists several companies as partners that rely on the bank to provide various financial and lending services. 

The spokesperson of one of the partner companies Affirm, posted on X that the company is investigating the incident and will directly communicate with affected consumers as more information becomes available. Affirm also notified its customers about the breach and assured them that it is safe to use their card and Money Accounts while the investigation continues.

Other partner companies also spoke up. EarnIn’s spokesperson, Stephanie Borman, mentioned that the company is closely monitoring the situation. Marqeta’s spokesperson, Kelly Kraft, acknowledged the breach and highlighted that Evolve supports a portion of their business. Melio’s co-founder and CEO, Matan Bar, confirmed awareness of the breach and assured customers that operations remain unaffected. Finally, Mercury, another partner of Evolve, disclosed that the breach impacted company records including account numbers, deposit balances, business owner names, and emails.

As more affected companies step forward, the full extent of the breach’s impact on Evolve’s customers and partners will likely become clearer. Evolve has recently made headlines for issues related to its fintech collaborations, with the Federal Reserve ordering the bank to enhance its risk management programs concerning fintech partnerships and anti-money laundering laws.