industryThe Ransomware Era (2020-Present) Daily Briefing

    Cybersecurity Daily Briefing - September 25, 2023

    Monday, September 25, 2023

    Lead Story: Monti Ransomware Attack on Auckland University

    On September 25, 2023, the Monti ransomware gang launched a significant cyber-attack against the Auckland University of Technology in New Zealand. The attackers have threatened to release 60GB of stolen data unless a ransom is paid by October 9, 2023. This incident underscores the growing threat posed by ransomware groups, particularly in the education sector, which often lacks the resources to fend off sophisticated attacks effectively. The implications of the breach could be far-reaching, potentially compromising sensitive student and staff data, research projects, and institutional integrity. Check Point Research

    Secondary Item 1: Retool Data Breach

    Retool, a software company, has disclosed a data breach affecting 27 of its clients due to an SMS-based social engineering attack. This breach has resulted in approximately $15 million being stolen in cryptocurrency for at least one affected client. The incident highlights the critical importance of maintaining robust multi-factor authentication protocols to mitigate such risks. Check Point Research

    Secondary Item 2: International Criminal Court Cyber Attack

    The International Criminal Court (ICC) confirmed it was the target of a cyber-attack that impacted its information systems. While the specifics of the stolen information and the responsible threat actor remain undisclosed, this incident raises serious concerns regarding the security of sensitive international legal data. Check Point Research

    Secondary Item 3: Greater Manchester Police Data Breach

    A ransomware attack on a third-party supplier has led to the exfiltration of personal data belonging to approximately 20,000 officers within the Greater Manchester Police. Fortunately, no financial data appears to have been compromised, but the breach raises alarms about the vulnerabilities in supply chain security and the protective measures in place for law enforcement data. Check Point Research

    Analyst Perspective

    The incidents reported on September 25, 2023, demonstrate a concerning trend in cybersecurity where ransomware attacks and data breaches are increasingly targeting critical institutions. The attacks on the Auckland University of Technology and the Greater Manchester Police highlight the vulnerabilities in the education and law enforcement sectors, while the Retool breach illustrates the risks associated with social engineering. As threat actors continue to evolve their tactics, organizations must enhance their security protocols and invest in employee training to mitigate these risks effectively.

    Sources

    ransomware data breach cyber attack Monti Retool