Cloud & IT Staffing Solutions in Chicago, Boston, Dallas
1

CyberSecurity

Cybersecurity Roundup for June–July 2024: It’s Time to Check Your Passwords

Tech Hiring Company Chicago - Peterson Technology Partners
Tech Hiring Company Chicago - Peterson Technology Partners

DATE POSTED

July 30, 2024

Table of Contents

WRITTEN BY

Doug McCord
Doug McCord
Doug McCord has a diverse educational and professional background, with degrees in Computer Science from Oregon State and Cinema-Television from the University of Southern California. He has a passion for learning, writing, and sharing what he can with others.

It’s the end of July 2024,  do you know where your passwords are?

On July 4, a plaintext file containing nearly 10 billion passwords was released, making it one of the largest password leaks ever recorded. Known as rockyou2024, the file combines data from multiple sources and expands on previous password collections, including rockyou2021, which contained 8.4 billion passwords, along with older data breaches.

Although many of the leaked passwords may be outdated, the exposure still creates significant security risks. The release could contribute to future data breaches, financial fraud, and identity theft as attackers use the information for unauthorized access attempts.

Rising Cyberattacks Across Industries

Combined with data from other major breaches, such as the Mother of All Breaches (MOAB), password leak collections give attackers valuable resources for launching brute-force attacks. Hackers use these files to test large numbers of username and password combinations until they discover credentials that provide access.

Credential stuffing attacks can create serious consequences for both businesses and individuals, as seen in incidents like the Snowflake breach. One of the simplest ways to reduce this risk is to avoid reusing passwords across multiple accounts.

In this cybersecurity roundup for June and July 2024, we explore the ongoing Snowflake fallout, the Synnovis cyberattack, and Disney’s Slack-related security incident. We also examine increased cyber activity linked to Russia and the growing number of security events caused by insider threats.

Before updating your passwords, learn more about the latest cybersecurity trends and NIST’s updated password creation and protection recommendations for 2024.

The Snowflake Data Breach 

A breach of this scale deserves special attention, and cloud data platform Snowflake has been at the center of cybersecurity discussions for all the wrong reasons this summer.

The incident has affected numerous organizations, with reports indicating that companies such as Ticketmaster, Santander, Advance Auto Parts, LendingTree, and QuoteWizard were among the impacted customers. AT&T also faced a major impact, with reports stating that nearly all customer call and text records from a six-month period were exposed.

According to cybersecurity firm Mandiant’s investigation, the attacks began with compromised customer credentials that allowed attackers to access and extract database information.

Mandiant found that the stolen credentials were likely obtained through infostealer malware. In some cases, contractors may have unknowingly exposed systems by using company devices for personal activities, including gaming or downloading pirated software, which introduced malware capable of stealing sensitive information.

The incident highlights the importance of implementing strong security measures, especially multi-factor authentication (MFA). Similar to other major cyber incidents, the lack of MFA and outdated credentials increased the risk of unauthorized access.

Mandiant noted that affected customer environments often lacked MFA requirements, had credentials that had not been updated for years, and did not use network allow lists to restrict access to trusted locations.

From Russia with Malice 

Cyberattacks targeting healthcare organizations are among the most damaging forms of cybercrime, as they can directly impact patient care and public safety. Unfortunately, 2024 has continued to see a steady rise in attacks against the healthcare sector.

Healthcare providers remain frequent targets due to their complex networks, large amounts of sensitive data, and interconnected systems. Diagnostic services provider Synnovis became the latest organization impacted by a major ransomware attack.

In June, Russian ransomware group Qilin leaked Synnovis data, including patient information and medical test results. The attack disrupted hospital and healthcare services across England, creating widespread operational challenges. The impact included canceled appointments, delayed medical procedures, shortages of universal donor blood supplies, and postponed critical treatments, including kidney transplants and cancer care.

Russia continues to be a major source of cybercrime activity. According to TRM Labs, Russian ransomware groups accounted for a significant share of global crypto ransomware revenue over the past year, generating more than $500 million in proceeds for groups such as LockBit, Black Basta, ALPHV/BlackCat, Cl0p, PLAY, and Akira.

Russian dark web activity also remains a major concern, accounting for a large portion of global illicit service and marketplace activity. According to BleepingComputer, the three largest Russian dark web markets processed approximately $1.4 billion in transactions in 2023, compared with about $100 million across Western markets.

Additional cybersecurity developments from June and July include:

  • In June, the U.S. Commerce Department announced restrictions on domestic sales of Russian cybersecurity and antivirus provider Kaspersky. The company later announced layoffs affecting its U.S. workforce.
  • In July, AI-powered Russian disinformation networks reportedly spread a false news story from unverified websites to trending social media topics and eventually to a top Google search result within 24 hours.
  • Researchers uncovered Russian-linked attacks targeting U.S. water infrastructure, while Dragos reported malware incidents affecting industrial control systems (ICS) in Ukraine that disrupted heating services for hundreds of apartments during extreme cold conditions.
  • Disney experienced a major Slack data breach in July, with attackers reportedly accessing more than 1 terabyte of internal communications. The incident has been linked to multiple potential causes, including insider security risks.

Spotlight on Password Security 2024… 

We started this roundup with the rockyou2024 password leak, making the timing of NIST’s updated Digital Identity Guidelines especially relevant. Released in late July 2024, the guidelines provide updated recommendations for improving password security and protecting digital identities.

NIST’s cybersecurity recommendations include several best practices that organizations should prioritize, such as requiring multi-factor authentication (MFA), creating strong passwords, using password managers, changing default credentials, keeping antivirus software updated, applying security patches, educating employees about phishing, and providing regular cybersecurity training.

The updated password management guidance also highlights several important practices:

  • Use long, complex passwords: NIST recommends using passwords with at least 12 characters, with longer and randomly generated passwords providing stronger protection. Passwords should include a mix of uppercase and lowercase letters, numbers, and special characters while avoiding easily guessed information such as names or company details.
  • Use a password manager: Password managers are becoming essential for creating and storing unique passwords. They help prevent password reuse and generate strong credentials that are difficult for attackers to guess.
  • Avoid password reuse and hints: Each account should have a unique password, and security hints should be avoided because they can make passwords easier to discover.
  • Avoid unnecessary password changes: Contrary to older security practices, frequently changing passwords can sometimes reduce security by encouraging users to create weaker or predictable passwords. Instead, organizations should rely on strong, unique passwords and password managers to maintain account security.

As we close this edition of our cybersecurity roundup, another important area deserves attention: the growing role of insiders in cybersecurity incidents and data breaches.

Insider Threats and Malware Statistics

While cybercrime often brings to mind external attackers using advanced techniques to break through security systems, many cybersecurity incidents are actually caused by insider actions.

Most insider-related incidents are not intentional attacks. Instead, they often result from human mistakes, such as sending sensitive information to the wrong recipient, clicking malicious links, or falling victim to phishing attempts. Although these incidents may seem simple, they remain one of the most challenging security risks for organizations to address.

Phishing attacks continue to become more sophisticated, with attackers using tactics such as fake customer support chats and impersonating internal IT teams to gain employee trust.

The Disney Slack breach has been linked to multiple possible causes, with attackers initially claiming that an employee intentionally leaked internal data. However, later reports suggested another type of insider risk may have been involved: malware hidden in a game modification downloaded on the same device used to access Disney’s Slack environment.

In this case, an insider-related security event may have enabled attackers to access more than one tebibyte of Disney’s internal data. The incident highlights how employee devices, personal downloads, and security awareness can play a critical role in protecting organizations from modern cyber threats.

Conclusion 

That concludes our coverage of the top cyber attacks and news from June and July 2024. Subscribe to The PTP Report or check it out on our website for continued coverage of all the latest cybersecurity threats.  

[And for help with your own cybersecurity needs, contact PTP for onsite or remote consultants.] 

You can also catch up on our prior bi-monthly roundups here: 

References 

RockYou2024: 10 billion passwords leaked in the largest compilation of all time, Cybernews 

The Snowflake Attack May Be Turning Into One of the Largest Data Breaches Ever, Wired 

Nearly all AT&T subscribers’ call records stolen in Snowflake cloud hack, Ars Technica 

Toll of Snowflake Hack Widens With Theft of AT&T Text, Calling Data, Bloomberg 

UK’s NHS says hackers have published data stolen in ransomware attack, Reuters 

NHS cyber attack delayed my baby son’s life-saving kidney transplant, The i 

Breast cancer patient reveals how Russian hackers forced her to delay surgery, The Telegraph 

Russian ransomware gangs account for 69% of all ransom proceeds, BleepingComputer 

Kaspersky to shut down US operations, lay off employees after US government ban, TechCrunch 

How Disinformation From a Russian AI Spam Farm Ended up on Top of Google Search Results, Wired 

Russia-linked hackers cut heat to 600 Ukrainian apartment buildings in the dead of winter, researchers say, Engadget 

7 password rules to live by in 2024, according to security experts, ZDNet 

Disney investigating massive leak of internal messages, BBC 

A furry hacktivist group has breached Disney, leaked 1.1TiB of data, and says it’s because Club Penguin shut down, PC Gamer 

WRITTEN BY

Doug McCord
Doug McCord
Doug McCord has a diverse educational and professional background, with degrees in Computer Science from Oregon State and Cinema-Television from the University of Southern California. He has a passion for learning, writing, and sharing what he can with others.

PREVIOUS POST

Spotlight on Innovation: Innovators Shaping 2024 and Beyond

NEXT POST

Adobe Experience Manager for Enhanced Digital Experiences

IT Staffing Firm - PTP