fbpx
Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Penetration Testing

          Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

VC giant Sequoia Capital Discloses Data Breach After Failed BEC Attack

VC giant Sequoia Capital Discloses Data Breach After Failed BEC Attack

American VC firm Sequoia Capital has disclosed a data breach following what looks like a failed business email compromise (BEC) attack from January.

Since its founding in 1972, the venture capital (VC) firm Sequoia has invested in a long list of high-profile companies (e.g., Apple, NVIDIA, Google, Oracle, Yahoo, LinkedIn, YouTube, Paypal, Electronic Arts, and Cisco).

The VC giant also backed many start-ups, including Airbnb, Dropbox, FireEye, Palo Alto Networks, Stripe, Square, and WhatsApp.

In total, the companies Sequoia has backed and invested in over the years now have an “aggregate, public market value of over $3.3 trillion.”

Two months ago, the FBI warned US companies about scammers actively abusing email auto-forwarding rules to increase the BEC attacks’ success rate.

BEC fraudsters use a combination of social engineering, phishing, and hacking to compromise business email accounts with the end goal of redirecting payments to bank accounts under their control.

Also Read: How to Send Mass Email Without Showing Addresses: 2 Great Workarounds

Attackers gained access to employee’s mailbox

“On or about January 20, 2021, we learned that an unauthorized third party had gained remote access to the business email mailbox of one Sequoia employee, with the apparent aim of conducting a wired version scam,” Sequoia Capital explained in a notice of data breach sent to affected individuals.

While the attackers were able to breach the employee’s email inbox, they didn’t gain access to other resources or assets on the company’s network.

“Our investigation has found no evidence of compromise beyond this single mailbox,” Sequoia said.

Even though a single mailbox was impacted in the incident, the VC firm acknowledged that it might have allowed the threat actors to exfiltrate impacted individuals’ personal information.

“The unauthorized access to the mailbox might have allowed the third party to acquire a copy of files including certain individuals’ personal information,” Sequoia added.

“As part of our investigation, we have analyzed the contents of the affected email mailbox and determined that it contained your personal information and that the unauthorized third party might have accessed or acquired a copy of it.”

Measures taken after the attack

After detecting the attack, Sequoia Capital hired external security experts to investigate the incident and secure its systems.

Sequoia said that it found no evidence that exfiltrated data was being sold or traded by cybercriminals on the dark web.

The company also informed relevant law enforcement authorities of the attack and has taken a series of measures to similar incidents in the future as it has:

  • Identified and remediated the configuration that permitted the initial access;
  • Deployed additional prevention and detection technology at multiple layers to improve visibility into anomalous user activity and malicious email content;
  • Reviewed the methods we use to store and share sensitive information inside and outside the company, including email message forwarding rules; and
  • Refreshed our security training with additional emphasis on phishing awareness and proper data handling.

Sequoia offers impacted individuals 24 months of free credit monitoring and identity theft protection through Experian.

Axios reported over the weekend about the VC firm informing investors that it was hacked and that their information might have been compromised as part of a data breach.

Also Read: How a Smart Contract Audit Works and Why it is Important

“We regret that this incident has occurred and have notified affected individuals,” a Sequoia Capital spokesperson said. “We have made considerable investments in security and will continue to do so as we work to address constantly evolving cyber threats.”

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us