fbpx
Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Penetration Testing

          Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Data Breach Exposes 1.6 Million Washington Unemployment Claims

Data Breach Exposes 1.6 Million Washington Unemployment Claims

Washington’s State Auditor office has suffered a data breach that exposed the personal information in 1.6 million employment claims.

The Office of the Washington State Auditor (“SAO”) states that they suffered a data breach after a threat actor exploited a vulnerability in a secure file transfer service from Accellion.

“SAO is advised that an unauthorized person was able to exploit a software vulnerability in Accellion’s file transfer service and gain access to files that were being transferred using Accellion’s service. Accellion stated that they believe the unauthorized access occurred in late December of 2020.”

“Other customers of this Accellion service were similarly impacted. SAO is currently seeking a full understanding of the timeline of the incident and the status of Accellion’s investigation and the investigation by law enforcement. At this time, SAO does not have enough information to draw conclusions about the timing or full scope of what took place.”

Also Read: Data Centre Regulations Singapore: Does It Help To Progress?

“It was not until the week of January 25, 2021, that Accellion confirmed to SAO that SAO files were subject to this attack and provided the information needed for SAO to begin to identify which data files were impacted and individuals whose personal information is in those files,” SAO stated in a security breach notification posted to their website.

The exposed claims were in data files from the Employment Security Department (ESD) and contain sensitive personal information of Washington residents.

“These ESD data files contained unemployment compensation claim information including the person’s name, social security number and/or driver’s license or state identification number, bank account number and bank routing number, and place of employment,” the breach notification explains.

In addition to unemployment claims, the breach exposed files from some Washington local governments and other state agencies were also affected.

The SAO is still investigating what information is contained in these files.

Zero-day responsible for December attacks

Accellion is a provider of secure file transfer services that allow organizations to securely share sensitive documents with users outside their organization. This service is popular among banks, government agencies, and financial organizations that commonly share sensitive documents with external users.

Accellion stated that they became aware of an actively exploited zero-day vulnerability in their legacy FTA solution in mid-December, and a patch was deployed to all customers.

BleepingComputer later learned from one of Accellion’s customers that the modern secure file sharing service, Accellion KiteWorks, also received a security update in December 2020.

Unfortunately, numerous organizations were breached before they could deploy the patch for this vulnerability, including the Reserve Bank of New Zealand, the Australian Securities and Investments Commission (ASIC), and the Harvard Business School.

“In late December, Harvard Business School (HBS) was informed by one of its vendors of a vulnerability in the vendor’s software. HBS applied a patch supplied by the vendor to resolve the vulnerability. On December 29, 2020, the vendor notified HBS that it had identified unauthorized access to certain HBS files.”

“HBS immediately launched an investigation and determined that files containing personal information were downloaded by one or more unauthorized third parties between December 21 and December 23, 2020,” the Harvard Business School told BleepingComputer in a statement.

Sources in the cybersecurity industry have told BleepingComputer that Accellion’s software’s vulnerability also caused the Harvard Business School breach.

Also Read: What Is A Governance Framework? The Importance And How It Works

With Accellion being a popular service used by numerous organizations, we should expect to see a steady trickle of similar breaches revealed soon.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us