April 24, 2023
CyberSec Roundup
A synopsis of the Latest Cybersecurity News
American Bar Association’s Old Site Hacked
The American Bar Association has disclosed that their old website was compromised last week by threat actors who used weak/default passwords for older accounts. Credentials for nearly 1.5 million accounts were stolen from the old site, but no personal or corporate information was taken. That could change if members used the same password on the new ABA site as they did on the old ABA site, so those members are advised to change their password if that is the case.
Canada’s Yellow Pages Breached
Canada’s Yellow Pages Group was compromised by the Black Basta ransomware group in March. The hackers stole business documents relating to employees and some customers, which they are already attempting to sell on the dark web.
Capita Confirms Breach
The consulting, transformation, and digital services business based out of London confirmed that they were the victims of a cyber-attack that caused major disruption to its internal Microsoft Office 365 applications. Some customer, supplier, and employee data were stolen during the attack, which may be attributed again to Black Basta as Capita is also listed on their data leak site.
By: David Pinder
IT & Cybersecurity Consultant
Certified Ethical Hacker (Master) | CCSK | AZ-500