Cloud & IT Staffing Solutions in Chicago, Boston, Dallas
1

CyberSecurity

Cybersecurity Roundup for June–July 2024: It’s Time to Check Your Passwords

Tech Hiring Company Chicago - Peterson Technology Partners
Tech Hiring Company Chicago - Peterson Technology Partners

DATE POSTED

July 30, 2024

Table of Contents

WRITTEN BY

Doug McCord
Doug McCord
Doug McCord has a diverse educational and professional background, with degrees in Computer Science from Oregon State and Cinema-Television from the University of Southern California. He has a passion for learning, writing, and sharing what he can with others.

It’s the end of July 2024. Do you know where your passwords are?

On July 4, a plaintext file containing nearly 10 billion passwords was released.

Known as rockyou2024, it is one of the largest password leaks ever recorded.

The file combines data from several sources. It also expands on earlier password collections, including rockyou2021, which contained 8.4 billion passwords.

Some of the leaked passwords may be old.

However, the exposure still creates major security risks.

Attackers can use these passwords for:

  • Unauthorized login attempts
  • Financial fraud
  • Identity theft
  • Future data breaches

Rising Cyberattacks Across Industries

Combined with data from other major breaches, such as the Mother of All Breaches (MOAB), these password collections become powerful tools for attackers.

Hackers can use them for brute-force attacks.

They test large numbers of usernames and passwords until they find a combination that works.

Credential stuffing attacks can cause serious problems for both businesses and individuals.

The Snowflake breach is one example.

One of the simplest ways to reduce this risk is to avoid reusing passwords across multiple accounts.

In this cybersecurity roundup for June and July 2024, we explore several major events.

These include:

  • The ongoing Snowflake fallout
  • The Synnovis cyberattack
  • Disney’s Slack-related security incident
  • Increased cyber activity linked to Russia
  • The growing number of insider-related security events

Before updating your passwords, learn more about current cybersecurity trends and NIST’s updated password recommendations for 2024.

The Snowflake Data Breach 

A breach of this scale deserves special attention.

Cloud data platform Snowflake has been at the center of cybersecurity discussions for all the wrong reasons this summer.

The incident affected several organizations.

Reports indicated that impacted customers included:

  • Ticketmaster
  • Santander
  • Advance Auto Parts
  • LendingTree
  • QuoteWizard

AT&T also faced a major impact.

Reports stated that nearly all customer call and text records from a six-month period were exposed.

According to cybersecurity firm Mandiant, the attacks began with stolen customer credentials.

Attackers used these credentials to access and extract database information.

Mandiant found that the credentials were likely stolen through infostealer malware.

In some cases, contractors may have exposed company systems without realizing it.

This may have happened when company devices were used for personal activities such as:

  • Gaming
  • Downloading pirated software
  • Installing unsafe files

These activities can introduce malware that steals sensitive information.

The incident highlights the importance of strong security controls.

Multi-factor authentication (MFA) is especially important.

Similar to other major cyber incidents, the lack of MFA and outdated credentials increased the risk of unauthorized access.

Mandiant noted several common weaknesses in affected environments:

  • MFA was not required
  • Credentials had not been changed for years
  • Network allow lists were not used
  • Access was not limited to trusted locations

From Russia with Malice 

Cyberattacks against healthcare organizations can be especially damaging.

They can directly affect patient care and public safety.

Unfortunately, attacks against the healthcare sector continued to rise in 2024.

Healthcare providers remain common targets because they often have:

  • Complex networks
  • Large amounts of sensitive data
  • Many connected systems
  • Critical services that cannot easily go offline

Diagnostic services provider Synnovis became one of the latest organizations hit by a major ransomware attack.

In June, Russian ransomware group Qilin leaked Synnovis data.

The exposed information included patient records and medical test results.

The attack disrupted hospital and healthcare services across England.

Its impact included:

  • Canceled appointments
  • Delayed medical procedures
  • Shortages of universal donor blood
  • Postponed kidney transplants
  • Delayed cancer care

Russia continues to be a major source of cybercrime activity.

According to TRM Labs, Russian ransomware groups generated more than $500 million in proceeds over the past year.

Groups included:

  • LockBit
  • Black Basta
  • ALPHV/BlackCat
  • Cl0p
  • PLAY
  • Akira

Russian dark web activity also remains a major concern.

According to BleepingComputer, the three largest Russian dark web markets processed about $1.4 billion in transactions in 2023.

By comparison, Western markets processed about $100 million.

Additional cybersecurity developments from June and July include:

  • In June, the U.S. Commerce Department announced restrictions on domestic sales of Russian cybersecurity and antivirus provider Kaspersky.
  • Kaspersky later announced layoffs affecting its U.S. workforce.
  • In July, AI-powered Russian disinformation networks reportedly pushed a false news story from unverified websites into trending social media topics.
  • The same story later appeared as a top Google search result within 24 hours.
  • Researchers uncovered Russian-linked attacks targeting U.S. water infrastructure.
  • Dragos reported malware attacks on industrial control systems in Ukraine.
  • Those attacks disrupted heating services for hundreds of apartments during extreme cold.
  • Disney experienced a major Slack data breach in July.
  • Attackers reportedly accessed more than 1 terabyte of internal communications.
  • The incident has been linked to several possible causes, including insider security risks.

Spotlight on Password Security 2024… 

We started this roundup with the rockyou2024 password leak.

That makes the timing of NIST’s updated Digital Identity Guidelines especially important.

Released in late July 2024, the guidelines include updated recommendations for password security and digital identity protection.

NIST recommends several key security practices.

Organizations should:

  • Require multi-factor authentication (MFA)
  • Create strong passwords
  • Use password managers
  • Change default credentials
  • Keep antivirus software updated
  • Apply security patches
  • Train employees to identify phishing
  • Provide regular cybersecurity training

The updated password guidance also highlights several important practices:

  • Use long, complex passwords: NIST recommends passwords with at least 12 characters. Longer and randomly generated passwords offer stronger protection. Passwords should avoid easy-to-guess details such as names or company information.
  • Use a password manager: Password managers can create and store unique passwords. They also help prevent password reuse.
  • Avoid password reuse and hints: Every account should have a unique password. Security hints should also be avoided because they can make passwords easier to discover.
  • Avoid unnecessary password changes: Frequent password changes can sometimes reduce security. Users may create weaker or more predictable passwords. Strong, unique passwords and password managers are usually a better approach.

As we close this edition of our cybersecurity roundup, another area deserves attention.

That is the growing role of insiders in cybersecurity incidents.

Cybercrime often brings to mind outside attackers using advanced methods.

However, many incidents begin with actions inside an organization.

Most insider-related incidents are not intentional attacks.

They often result from mistakes such as:

  • Sending sensitive information to the wrong person
  • Clicking malicious links
  • Falling for phishing attempts
  • Downloading unsafe files
  • Using work devices for risky personal activities

These actions may seem simple.

However, they remain some of the hardest security risks for organizations to control.

Phishing attacks are also becoming more advanced.

Attackers now use methods such as:

  • Fake customer support chats
  • Impersonation of internal IT teams
  • Social engineering
  • Malware hidden in common downloads

The Disney Slack breach has been linked to several possible causes.

Attackers first claimed that an employee intentionally leaked internal data.

Later reports suggested another type of insider risk may have been involved.

Malware may have been hidden inside a game modification downloaded on the same device used to access Disney’s Slack environment.

In this case, an insider-related event may have helped attackers access more than one tebibyte of internal Disney data.

The incident shows why organizations must pay close attention to:

  • Employee devices
  • Personal downloads
  • Access controls
  • Security awareness
  • Cybersecurity training

Insider Threats and Malware Statistics

Conclusion 

That concludes our coverage of the top cyber attacks and news from June and July 2024.

Subscribe to The PTP Report or check it out on our website for continued coverage of the latest cybersecurity threats.

[And for help with your own cybersecurity needs, contact PTP for onsite or remote consultants.]

You can also catch up on our prior bi-monthly roundups here:

References 

RockYou2024: 10 billion passwords leaked in the largest compilation of all time, Cybernews

The Snowflake Attack May Be Turning Into One of the Largest Data Breaches Ever, Wired

Nearly all AT&T subscribers’ call records stolen in Snowflake cloud hack, Ars Technica

Toll of Snowflake Hack Widens With Theft of AT&T Text, Calling Data, Bloomberg

UK’s NHS says hackers have published data stolen in ransomware attack, Reuters

NHS cyber attack delayed my baby son’s life-saving kidney transplant, The i

Breast cancer patient reveals how Russian hackers forced her to delay surgery, The Telegraph

Russian ransomware gangs account for 69% of all ransom proceeds, BleepingComputer

Kaspersky to shut down US operations, lay off employees after US government ban, TechCrunch

How Disinformation From a Russian AI Spam Farm Ended up on Top of Google Search Results, Wired

Russia-linked hackers cut heat to 600 Ukrainian apartment buildings in the dead of winter, researchers say, Engadget

7 password rules to live by in 2024, according to security experts, ZDNet

Disney investigating massive leak of internal messages, BBC

A furry hacktivist group has breached Disney, leaked 1.1TiB of data, and says it’s because Club Penguin shut down, PC Gamer

WRITTEN BY

Doug McCord
Doug McCord
Doug McCord has a diverse educational and professional background, with degrees in Computer Science from Oregon State and Cinema-Television from the University of Southern California. He has a passion for learning, writing, and sharing what he can with others.

PREVIOUS POST

Spotlight on Innovation: Innovators Shaping 2024 and Beyond

NEXT POST

Adobe Experience Manager for Enhanced Digital Experiences

IT Staffing Firm - PTP