Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
MOVEit Moves  To Colorado--Millions Affected In Recent Attacks
Facebook   X   LinkedIn   Email

MOVEit Moves To Colorado--Millions Affected In Recent Attacks

September 10, 2023

The Colorado Department of Health Care Policy and Financing (HCPF) has reported a breach that compromised the data of more than 4 million individuals. The incident was attributed to IBM, a vendor for the state, which utilizes the MOVEit application for the transfer of HCPF data files.

Despite this breach, HCPF and the Colorado state government's infrastructure remain unaffected, as far as anyone knows at this point. However, unauthorized access was gained by an external entity to specific HCPF files on the application managed by IBM. The compromised files contained comprehensive personal data, encompassing full names, dates of birth, addresses, Social Security numbers, medical records, laboratory results, medication history, Medicare and Medicaid ID numbers, income information, and more.

Another organization impacted by this recent breach is Missouri’s Department of Social Services (DSS). It also uses IBM services. DSS has disclosed that exposed data might encompass an individual's name, department client identification number, birth date, and information concerning potential benefit eligibility status or coverage, along with medical claims data.

Adding insult to injury in Colorado, the Colorado Department of Higher Education divulged an incident involving a ransomware attack, resulting in the exfiltration of 16 years' worth of data from their systems. Likewise, Colorado State University was not immune, falling victim to a MOVEit-related breach that impacted tens of thousands of students and faculty.

An in other data breach news, PH Tech, a healthcare insurer data management service provider, revealed that the health information of 1.7 million Oregon residents was compromised due to MOVEit.

MOVEit obviously won’t stay out of the news, so it’s best to take action to mitigate compromise on your systems. Updating with the latest patches is primary, but it’s also recommended that you Disable all HTTP and HTTPs traffic to the MOVEit Transfer environment. The FBI’s Cybersecurity & Infrastructure Security Agency (CISA) has also listed several recommendations for prevention and mitigation as well. As always, instruct all users on identification of phishing and have a plan in place to react in case anyone falls victim to this or any phishing attack.

In a separate incident unrelated to MOVEit, HCA Healthcare experienced the most substantial data breach within the U.S. healthcare sector this year. That breach exposed the personal details, including names, addresses, and appointment specifics, of approximately 11.2 million individuals.


Do Zero-Day Vulnerabilities Really Get Exploited Or Are You Just Scaring Us?

Corporate Security

Do Zero-Day Vulnerabilities Really Get Exploited Or Are You Just Scaring Us?

Sometimes we hear about an exploit that could cause potential harm to an individual or company and push it aside and perhaps briefly wonder if it ever actually did cause harm. If you have been paying attention to the technology news at all in the past weeks, you will know that they do indeed get exploited. One group is really busy and has made headlines a few times lately. In fact, every day there is a new story about an organization that has been attacked using the MOVEit zero-day. But no doubt, the other vulnerabilities are being abused too. READ FULL STORY

Check Point Research Reveals Threats Making a Menace of Themselves in 2023

Your Security

Check Point Research Reveals Threats Making a Menace of Themselves in 2023

Have you heard enough of the Trojan Qbot? Well, that sneaky bot is not going away, nor is it sitting back and being quiet. In fact, per a report by Check Point Research, it’s been hanging around making a cybersecurity menace of itself all throughout the year, thus far. It’s not the only malicious news for the year either. The mobile Trojan SpinOk made its debut and that pesky MOVEit zero-day vulnerability has not moved an inch to stay out of the news. READ FULL STORY

Top Ransoware Groups Wreak Havoc Since 2020; Tips To Keep Ransomware At Bay

Scams & Phishing

Top Ransoware Groups Wreak Havoc Since 2020; Tips To Keep Ransomware At Bay

There are many ransomware groups lurking in the shadows these days. They may come out from time to time, hold a few businesses for ransom and then slink back into the abyss. Later, they may reappear and do it again. Some disappear but under a different name and others morph into a new group. One thing that stays consistent is that they are always there. Included here is some information on them and what you can do to combat their tactics. READ FULL STORY

You Better MOVEit To Protect Yourself Against Fraud If You Live In Louisiana

Identity Theft

You Better MOVEit To Protect Yourself Against Fraud If You Live In Louisiana

Officials from Louisiana have revealed that hackers are responsible for a massive cyber-attack targeting driver’s license and state ID holders in the state. This attack, thought to be an exploit of the MOVEit vulnerability, which also affected prominent entities like the U.S. Department of Energy, British Airways, and the BBC, exposed personally identifiable information (PII) of millions of residents. The hackers likely obtained access to further personal details that would enable them to commit fraud using them. READ FULL STORY

Multiple U.S. Government Agencies Targeted: Global Cyberattack Exploits Vulnerability

Your Security

Multiple U.S. Government Agencies Targeted: Global Cyberattack Exploits Vulnerability

According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA), several U.S. federal government agencies have fallen victim to a global cyberattack that exploits a vulnerability in commonly used software. CISA is working diligently to assess the extent of the impact and facilitate timely remediation measures. No specific agencies are being called out in this attack, but government officials have admitted there are a few in this attack involving MOVEit software. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...