HHS Issues Warning Issued About LokiBot Malware
The Health Sector Cybersecurity Coordination Center (hC3) has published an Analyst Note about LokiBot – one of the most prevalent and persistent malware families. LokiBot, aka Loki PWS, has been used in attacks on a variety of industry sectors over the past 8 years, including critical infrastructure organizations; however, there has been a notable increase in the use of the malware since July 2020 The malware is used in attacks on Windows and Android devices and steals usernames, passwords, and other credentials from more than 100 different clients, along with cryptocurrency wallets and payment card information. The malware can take screenshots, log keystrokes, and steal cookies and system data, allowing multi-factor authentication to be bypassed. The malware also creates a backdoor in infected systems that allows attackers to deliver other malicious payloads such as ransomware. LokiBot was first offered for sale in 2015 for $540 and proved popular due to its relatively low price. The malware is now better at evading security solutions, has more extensive capabilities, and...
Indiana Attorney General Sues CarePointe Over 2021 Ransomware Attack
The Indiana Attorney General, Todd Rokita, has filed a lawsuit against CarePointe over its June 2021 ransomware attack and the theft of files containing the protected health information (PHI) of 48,742 individuals, including 45,002 Indiana residents. CarePointe’s investigation confirmed that an unauthorized third party gained access to its network, exfiltrated files containing sensitive data on or around June 25, 2021, and then used ransomware to encrypt files. The data stolen in the attack included names, addresses, dates of birth, Social Security numbers, medical insurance information, and health information. CarePointe explained in its Notice of Privacy Practices that it is committed to safeguarding patient information and is required by the HIPAA Privacy Rule to safeguard patient data. Patients were required to acknowledge that they had read and understood its Notice of Privacy Practices, despite its claims, CarePointe is alleged to have failed to implement appropriate security policies, conduct appropriate risk analyses, and did not promptly address known security risks in a...
FBI Sounds Alarm About Dual Ransomware Attacks and Data Wiping Tactics
The tactics, techniques, and procedures (TTPs) used by ransomware gangs often evolve, and with increasing numbers of victims refusing to pay ransoms, ransomware groups have started adopting more aggressive tactics. Two concerning new ransomware trends have been identified by the Federal Bureau of Investigation (FBI) – Ransomware groups are conducting dual attacks on victims using multiple ransomware variants and have been observed employing data destruction tactics using custom wiper tools when victims refuse to engage and discuss ransom payments. The FBI has previously warned that paying the ransom following a ransomware attack provides no guarantee that files can be recovered and victims that pay may be subject to further extortion demands. The latest warning concerns dual ransomware attacks, where two attacks are conducted using different ransomware variants in close proximity against the same target. This tactic was first observed by the FBI in July 2023 with the attacks involving various combinations of ransomware variants from the AvosLocker, Diamond, Hive, Karakurt, LockBit,...
What Does the Acronym OSHA Stand For?
The acronym OSHA stands for the Occupational Safety and Health Administration – an agency within the Department of Labor that was created in 1971 following the passage of the Occupation Safety and Health Act (referred to as the OSH Act to avoid confusion about what the acronym OSHA stands for). The agency is responsible for: Reducing the human and economic cost of workplace accidents. Developing workplace safety and health standards in the United States. Providing technical and compliance assistance, education, and training. Establishing recordkeeping requirements for workplace injuries and illnesses. Establishing workplace safety and health rights for employees. Enforcing standards through inspections, citations, and/or penalties. Working in partnership with states that operate their own safety and health programs. Prior to the creation of OSHA, the task of workplace safety and health was the responsibility of the Bureau of Labor Standards. However, as the economy expanded during the 1960s, workplace injury rates started to increase. Congress believed a new agency was necessary to...
Bienville Orthopaedic Specialists Sued Over March 2023 Data Breach
Bienville Orthopaedic Specialists in Gautier, Mississippi, is being sued by a patient whose protected health information was stolen in a February 2023 cyberattack. Bienville Orthopaedic Specialists identified unauthorized activity within its IT systems on March 5, 2023. The forensic investigation confirmed an unauthorized individual had access to its computer systems between February 3, 2023, and March 5, 2023, and exfiltrated sensitive data including names, Social Security numbers, medical information, health insurance information, usernames and passwords, financial account information, and driver’s license numbers. Complimentary credit monitoring and identity protection services were offered to the affected individuals. The lawsuit was filed by attorney Justin G. Witkin from the law firm Justin G. Witkin in the US District Court for the Southern District of Mississippi on behalf of Bienville patient Robert Harris. The lawsuit alleges Bienville failed to implement reasonable and appropriate security measures to ensure the privacy of its patients, did not follow industry standards...



