Cloud & IT Staffing Solutions in Chicago, Boston, Dallas
1

CyberSecurity

Cybersecurity Roundup January–March 2024: MOAB, UnitedHealth, AI, and More

Tech Hiring Company Chicago - Peterson Technology Partners
Tech Hiring Company Chicago - Peterson Technology Partners

DATE POSTED

March 26, 2024

Table of Contents

WRITTEN BY

Doug McCord
Doug McCord
Doug McCord has a diverse educational and professional background, with degrees in Computer Science from Oregon State and Cinema-Television from the University of Southern California. He has a passion for learning, writing, and sharing what he can with others.

In late January, a cybersecurity researcher, with help from Cybernews, made a stunning discovery. They found 12 terabytes of carefully collected stolen personal information in a database containing 26 billion records.

Dubbed MOAB, or the Mother of all Breaches, this international collection includes exposed and reindexed records. Some are duplicates, but many are believed to be new.

The database combines personal information from earlier breaches with records from a wide range of sources, including:

  • Chinese IM app Tencent QQ, with 1.4 billion records
  • Weibo, with 504 million records
  • MySpace, with 360 million records
  • X/Twitter, with 281 million records
  • LinkedIn, with 251 million records
  • Adobe, with 153 million records
  • Canva, with 143 million records

It also includes records from international governments, including the US, Brazil, Germany, and Turkey.    

Increasing cybersecurity breaches

MOAB is by far the largest discovery of its kind. It greatly exceeds previous leaks such as the 2021 Compilation of Many Breaches (COMB), which contained 3.2 billion records.

MOAB also makes it likely that 2024 will see an increase in credential stuffing attacks. In these attacks, usernames and passwords stolen from one website are tested across many others.

Protecting users from this type of attack may sound simple:

  • Change passwords regularly
  • Change passwords after a breach
  • Do not reuse passwords across websites

In practice, however, users may have hundreds of logins across many devices. Constant notifications about new data leaks can also make it difficult for both individuals and businesses to keep up.

This is why we’re launching a new edition of the PTP Report called the CyberSecurity Roundup. It will report on the major cybersecurity events of the month.

Like our Emerging AI report, it will be bi-monthly and cover events since the previous roundup.

We hope to keep you informed about key events. This can help you and your organization take a more proactive approach to protection against emerging cyberthreats.

[Check out our 2023 Cybersecurity roundup, which focuses on one key event for each month of the prior year.]  

January

The Trello Breach 

We open 2024 with a January attack involving the Atlassian product Trello. The incident resulted in information from 15 million users being traded on the dark web.

The exposed information included:

  • Usernames
  • Full names
  • Email addresses
  • Other account details

Trello stated that the incident did not involve a traditional breach of its databases. Instead, the information was reportedly collected by scraping publicly available API data.

Email addresses were not publicly available. However, the hacker reportedly used broad lists of email addresses already in their possession. They then queried the Trello API to find matching account information.

This incident shows how APIs can be exploited through brute-force attacks. The use of AI can make these attacks easier to carry out.

Indian Telecom 

A much larger database was also discovered in January. Cybersecurity firm CloudSEK found information connected to 750 million Indians, or about 85% of the country’s population.

The database was also traded on the dark web and included:

  • Names
  • Mobile phone numbers
  • Addresses
  • Aadhaar details
  • UIDAI numbers

The information covered customers from India’s major telecom providers. It led to internal investigations that were still ongoing.

The list was offered by multiple sources. One source claimed the information had been obtained through law enforcement channels.

Several breaches may have contributed data to this collection. One possible source was the October 2023 breach of the Indian Council of Medical Research (ICMR), which affected 815 million Indians.

[Check out IT and Telecommunication: Rethinking Transformation Strategies for insight from our CEO on the challenges the telco industry is facing as it works to stay abreast of technological innovations and demands.] 

MOAB 

January’s discovery of the Mother of All Breaches is similar to the Indian telecom breach. In both cases, it remains unclear when and how the records were obtained.

As discussed earlier, the MOAB dataset includes 26 billion carefully collected records from many websites. The database was discovered only after a firewall failure left the website containing it unsecured.

MOAB is more serious than the previous two January examples. It includes:

  • Passwords
  • Sensitive financial information
  • Medical records
  • Other personal data

Because the information is already collected in one place, it can serve as a form of big data for cybercriminals. Tools such as AI may make it easier to organize and use.

Many of the records are old. However, experts believe some are new. This may point to unknown security weaknesses that continue to exist across several sectors.

AI 

In late January, Anthropic AI became the latest major AI provider to experience a data leak.

However, the incident reportedly involved a more traditional cybersecurity failure. A contractor emailed private customer information to a third party.

Also in January, the National Institute of Standards and Technology (NIST) published a report on what it calls “adversarial machine learning.”

The report identified four major types of attacks that can manipulate the behavior of AI systems:

  • Evasion: These attacks change input sent to AI systems to influence their behavior. One example is changing recognizable road signs to confuse an autonomous vehicle.
  • Poisoning: This involves adding harmful or misleading data during the training phase. For example, repeated profanity may cause a chatbot to treat inappropriate language as acceptable.
  • Privacy: These attacks occur during deployment. Attackers ask many valid questions and study the responses to uncover sensitive information from the training data.
  • Abuse: This involves inserting false information into sources that an AI system may use. The system may then accept mistakes as facts or behave in unintended ways.

As first reported by Wired, researchers at Cornell University also found a concerning new cyberthreat in early 2024. It was an AI worm that targeted generative AI systems, including email platforms.

The attack was an example of evasion. It worked in a way similar to SQL injection, where harmful code is placed into text fields to trick a database into running unintended commands.

The researchers created what they called an “adversarial self-replicating prompt.” It tricked AI systems, including ChatGPT and Gemini, into calling additional prompts in their responses.

The researchers were also able to trigger this behavior using text hidden inside images.

 2024 cybersecurity events

  

International Subterfuge 

Cyberattacks are increasingly being used as weapons between nations. This creates a form of cyber cold warfare.

Several examples appeared in early 2024:

  • China Hacker Network: In January, the FBI reported that hackers working for the Chinese government were increasingly targeting US infrastructure. Targets included water treatment plants, oil and gas pipelines, and transportation hubs.
  • Also in January, the US and its allies disrupted a Chinese spying program operating on hundreds of compromised routers.
  • In early February, leaked documents showed that this Chinese government-funded network was also conducting large-scale attacks against other Asian nations, including Vietnam.
  • Microsoft and Hewlett Packard hacked by Russian Intelligence: New SEC rules require companies to report security intrusions more quickly, as discussed in this PTP Report article.
  • These rules may have influenced the January disclosures from Microsoft and HPE. Both companies reported that Russia’s intelligence service, through hackers known as Midnight Blizzard or Cozy Bear, had accessed their systems and exposed sensitive emails.
  • US cybersecurity agencies responded with recommendations. The National Security Agency advised customers to audit logs, limit user permissions, and review recent activity.

As of March 15, Microsoft had still not fully contained the breach. The incident was more serious than first believed and may have involved:

  • Source code
  • Cryptographic secrets
  • Authentication keys
  • Other sensitive information
  • Russian Center for Space Hyrdometerology Research Center hit by Ukraine: A late January attack targeted Planeta, a Russian organization that manages satellite data.
  • The attack destroyed 2 petabytes of data and 280 servers.
  • A Ukrainian group called the BO Team claimed responsibility.
  • The estimated damage to Russia was $10 million.

February 

Bank of America 

In early February, Bank of America disclosed a cybersecurity incident connected to an attack from late 2023.

The breach affected a third-party provider called Infosys McCamish Systems (IMS). A LockBit ransomware operation reportedly stole information belonging to around 57,000 customers.

The exposed data included:

  • Social Security numbers
  • Addresses
  • Other personal information

The delay in contacting affected customers was concerning. However, the bank offered free third-party identity protection services to those impacted.

The incident also caused an estimated $30 million in damages.

This case shows that cybersecurity risks extend beyond an organization’s own systems. Companies must also consider the security of partners and vendors across increasingly complex supply chains.

Zero Day, Month Two 

Only two months into the new year, major technology companies Apple and Google were already fixing zero-day flaws.

As discussed in this PTP roundup, zero-day flaws are vulnerabilities that are unknown to the company but already available to malicious actors. The company has zero days to prepare before addressing them.

Apple’s update to iOS 17.3 and related systems fixed WebKit issues that allowed malicious code to run.

Google’s January Android Security Bulletin also fixed several serious issues. One vulnerability could allow an attacker to gain higher system privileges without user interaction.

Keeping software updated is one of the most important steps users can take against cybercrime.

Security patches often include technical details about the vulnerability. Criminals may reverse-engineer these updates and target users who have not installed them quickly.

Healthcare 

Cyberattacks in the healthcare sector doubled in 2023. Around one in three Americans was affected by a healthcare-related data breach during that year.

The problem continued to grow in February 2024.

A ransomware attack targeted Change Healthcare, a UnitedHealth component. The attack was carried out by ALPHV/Blackcat, the group also linked to attacks on MGM and Caesars in the previous year.

The attack disrupted billing services. These systems remained unavailable into March and pushed some medical providers close to closure.

Healthcare organizations are frequent targets because the sector includes many connected practices of different sizes. This creates a large number of possible entry points.

Major international law enforcement operations had already attempted to disrupt ransomware groups such as LockBit and ALPHV. However, attacks continued.

Rick Pollack, president and CEO of the American Hospital Association, described the incident as “the most significant and consequential incident of its kind against the U.S. health care system in history.”

March  

American Express 

The UnitedHealth attack targeted a recently acquired component. American Express, like Bank of America, faced consequences from a breach involving a third-party provider.

The provider was used by American Express merchants.

Details were still being released. However, American Express informed customers in March that the breach exposed information belonging to current and former customers.

The exposed data may have included:

  • Customer names
  • Card account numbers
  • Expiration dates
  • Other account information

Even if American Express maintains strong internal security, it can still suffer serious consequences when a partner is compromised.

This reflects the growing risk of supply-chain vulnerabilities across industries.

Conclusion 

2024 may have been only three months old, but there was already too much cybercrime activity to cover fully. This is one reason cybersecurity professionals remain in high demand.

[For help with your cybersecurity, contact PTP to hire onsite or remote consultants!]

This article covers some of the most important cybersecurity events from January through March 2024.

Look for the next installment of this roundup in the final week of May.

WRITTEN BY

Doug McCord
Doug McCord
Doug McCord has a diverse educational and professional background, with degrees in Computer Science from Oregon State and Cinema-Television from the University of Southern California. He has a passion for learning, writing, and sharing what he can with others.

PREVIOUS POST

Spotlight on Innovation: Innovators Shaping 2024 and Beyond

NEXT POST

Adobe Experience Manager for Enhanced Digital Experiences

IT Staffing Firm - PTP