LockBit Ransomware Group Restores Servers Following Law Enforcement Takedown
Last week, 32 servers, the affiliate portal, and the data leak site used by the LockBit ransomware group were seized following an international law enforcement operation; however, the takedown appears to have been short-lived, as the LockBit dark leak data leak site has now been re-established. The LockBit group has also posted a lengthy explanation of what happened along with the group’s plans for future attacks. The post explains that the takedown will not affect operations and that LockBit attacks would continue, with more attacks conducted on the government sector. Operation Cronos was a collaboration between law enforcement agencies in the United States, United Kingdom, and Europe. In a series of announcements last week, details of the success of the operation were announced. LockBit source code, cryptocurrency wallets, and decryption keys were obtained, and a decryptor was released that would allow victims of LockBit attacks to recover their encrypted files. The UK’s National Crime Agency also threatened to reveal the identity of LockButSupp, the supposed leader of the...
Colorado Department of Health Care Policy & Financing: 4,662,668 Individuals Affected by MOVEit Hack
The Colorado Department of Health Care Policy & Financing has issued an updated breach notification to the Maine Attorney General confirming that the sensitive data of 4,662,668 individuals was compromised when the Clop hacking group exploited a vulnerability in Progress Software’s MOVEit Transfer solution in May 2023. MOVEit was used by its business associate, IBM, for file transfers. Progress Software issued a patch to fix the vulnerability on May 31, 2023; however, the flaw had already been exploited. The Colorado Department of Health Care Policy & Financing has been investigating the breach to determine what data was involved and has confirmed that the protected health information of Health First Colorado and CHP+ members was involved, as well as the data of applicants, providers, provider and member-affiliated individuals, and individuals who may provide additional coverage to Health First Colorado and CHP+ members. The compromised data included full names, Social Security numbers, and insurance policy identifiers. Previous notifications were issued by the Colorado...
Majority of Ransomware Victims That Pay a Ransom Suffer a Second Attack
Paying a ransom may allow encrypted files to be recovered and threat actors usually remove stolen data from data leak sites, but victims that pay are often attacked a second time. These may be attacks by the same threat actor or a different ransomware group. These double attacks are incredibly common. According to a recent study by the cybersecurity firm Cybereason, 56% of organizations surveyed have suffered more than one ransomware attack, and 78% of organizations that paid a ransom suffered a second ransomware attack. The second time around, 63% were asked to pay even more. Out of the 78% of organizations that suffered a second attack, 36% said the attack was conducted by the same threat actor and 42% were conducted by a different attacker. The survey confirmed the perils of paying a ransom. Only 47% of organizations that chose to pay the ransom were able to recover their files, with the remainder saying they were either unable to recover their data or that their data was corrupted. Many victims of ransomware attacks choose to pay a ransom to prevent the publication of the...
ConnectWise ScreenConnect Vulnerabilities Under Active Exploitation
Recently disclosed vulnerabilities in the remote desktop application ConnectWise ScreenConnect are being exploited to deliver a variety of different malicious payloads into business environments. The vulnerabilities were first disclosed by ConnectWise on February 13, 2024, and attacks exploiting the vulnerabilities started a day after the patches were released. One of the vulnerabilities, CVE-2024-1709, is an authentication bypass flaw with a maximum CVSS severity score of 10. The other, CVE-2024-1708, is a high-severity path traversal vulnerability with a CVSS severity score of 8.4. Due to the severity of the flaws and the high risk of exploitation, ConnectWise urged admins to update their on-premise servers to the fixed version immediately. Proof-of-concept (PoC) exploits were published soon after the disclosure and within 24 hours of the emergency patches being released, hackers started exploiting the flaws. According to Palo Alto Networks, there are around 18,000 IP addresses hosting ScreenConnect, although as of February 20, 2023, the ShadowServer Foundation reports that the...
The HHS OIG Safe Harbor Regulations
The HHS OIG Safe Harbor Regulations define the circumstances in which the offer, solicitation, payment, or receipt of remuneration in exchange for items or services billable to a Federal healthcare program is not regarded as a violation of the Anti-Kickback Statute. It is important for healthcare providers to be aware of these regulations in order to avoid inadvertent violations of anti-fraud laws. In 1972, Congress added an Anti-Kickback Statute to the Social Security Act §1128B which penalizes individuals found to have intentionally offered, solicited, or received anything of value in return for referrals for goods or services billable to a Federal Healthcare program. At the time, the broad nature of the Statute raised concerns that healthcare providers participating in beneficial commercial arrangements were technically covered by the statute and at risk of criminal prosecution. It was not until the passage of the Medicare and Medicaid Patient and Program Protection Act of 1987 that the law was changed to allow the HHS Office of Inspector General (OIG) to promulgate regulations...



