cybersecurity

DOJ confirms arrested US Army soldier is linked to AT&T and Verizon hacks

U.S. prosecutors have formally linked the arrest of a serving U.S. Army soldier in December to a massive theft of U.S. phone records from AT&T and Verizon last year. Authorities arrested Cameron John Wagenius, a U.S. Army communications specialist, in Texas on December 20 following a brief two-page grand jury indictment accusing the U.S. serviceperson […]

DOJ confirms arrested US Army soldier is linked to AT&T and Verizon hacks Read More »

How victims of PowerSchool’s data breach helped each other investigate ‘massive’ hack

On January 7, at 11:10 p.m. in Dubai, Romy Backus received an email from education technology giant PowerSchool notifying her that the school she works at was one of the victims of a data breach that the company discovered on December 28. PowerSchool said hackers had accessed a cloud system that housed a trove of

How victims of PowerSchool’s data breach helped each other investigate ‘massive’ hack Read More »

Treasury sanctions Salt Typhoon hacking group behind breaches of major US telecom firms

The U.S. government has announced sanctions against a Chinese organization with links to Salt Typhoon, the hacking group responsible for the largest telecoms hack in U.S. history.  The Treasury Department’s Office of Foreign Assets Control (OFAC) announced on Friday that it had sanctioned a China-based cybersecurity company, known as Sichuan Juxinhe Network Technology, which it

Treasury sanctions Salt Typhoon hacking group behind breaches of major US telecom firms Read More »

Malware stole internal PowerSchool passwords from engineer’s hacked computer

A cyberattack and data breach at U.S. edtech giant PowerSchool that was discovered December 28 threatens to expose the private data of tens of millions of school children and teachers.  PowerSchool told customers the breach was linked to the compromise of a subcontractor’s account. TechCrunch learned this week of a separate security incident, involving a

Malware stole internal PowerSchool passwords from engineer’s hacked computer Read More »

Clop ransomware gang names dozens of victims hit by Cleo mass-hack, but several firms dispute breaches

The prolific Clop ransomware gang has named dozens of corporate victims it claims to have hacked in recent weeks after exploiting a vulnerability ​​in several enterprise popular file transfer products developed by U.S. software company Cleo.  In a post on its dark web leak site, seen by TechCrunch, the Russia-linked Clop gang listed 59 organizations

Clop ransomware gang names dozens of victims hit by Cleo mass-hack, but several firms dispute breaches Read More »

Governments call for spyware regulations in UN Security Council meeting

On Tuesday, the United Nations Security Council held a meeting to discuss the dangers of commercial spyware, which marks the first time this type of software — also known as government or mercenary spyware — has been discussed at the Security Council.  The goal of the meeting, according to the U.S. Mission to the UN,

Governments call for spyware regulations in UN Security Council meeting Read More »

PowerSchool data breach victims say hackers stole ‘all’ historical student and teacher data

U.S. school districts affected by the recent cyberattack on edtech giant PowerSchool have told TechCrunch that hackers accessed “all” of their historical student and teacher data stored in their student information systems.  PowerSchool, whose school records software is used to support more than 50 million students across the United States, was hit by an intrusion

PowerSchool data breach victims say hackers stole ‘all’ historical student and teacher data Read More »

UnitedHealth hid its Change Healthcare data breach notice for months

Change Healthcare, the UnitedHealth-owned healthtech company that lost more than 100 million people’s sensitive health data in a ransomware attack last year, said on Tuesday that the company has “substantially” completed notifying affected individuals about the massive data breach. The February 2024 ransomware attack on Change Healthcare, one of the biggest processors of patient billing

UnitedHealth hid its Change Healthcare data breach notice for months Read More »

Hackers are exploiting a new Fortinet firewall bug to breach company networks

Security researchers say malicious hackers have been exploiting a newly discovered vulnerability in Fortinet firewalls to break into corporate and enterprise networks. In an advisory published Tuesday, security product maker Fortinet confirmed that a critical-rated vulnerability in its FortiGate firewalls, tracked as CVE-2024-55591, is “being exploited in the wild.”  Fortinet made patches available, but security

Hackers are exploiting a new Fortinet firewall bug to breach company networks Read More »

UK plans to ban public sector organizations from paying ransomware hackers

U.K. public sector and critical infrastructure organizations could be banned from making ransom payments under new proposals from the U.K. government.  The U.K.’s Home Office launched a consultation on Tuesday that proposes a “targeted ban” on ransomware payments. Under the proposal, public sector bodies — including local councils, schools, and NHS trusts — would be

UK plans to ban public sector organizations from paying ransomware hackers Read More »