The Week in Breach News: 1/15/25 – 1/21/25
This week: Employee actions cause major trouble for several businesses, Russia-Ukraine nation-state hacking continues, New Brunswick unwillingly participates in Dry January and how to reduce IT team burnout with automation.
Read this week’s new featured blog: From Stress to Success: Reducing Burnout in IT Security Teams
Texas Health and Human Services
Exploit: Malicious Insider
Industry: Government
The Texas Health and Human Services Commission (HHSC) disclosed on Friday that 61,000 individuals may have had their personal data improperly accessed by agency employees. Information involved includes Social Security numbers, full names, home addresses and Medicaid and Medicare Identification Numbers. HHSC terminated the employees responsible and referred the case to the agency’s Office of Inspector General for potential criminal charges. Recipients of the Supplemental Nutrition Assistance Program (SNAP) are advised to monitor Lone Star Card transactions for fraudulent activity. Affected individuals should review their accounts closely and report any suspicious charges immediately.
How It Could Affect Your Customers’ Business: Organizations must implement strict access controls and continuous monitoring to prevent insider threats and unauthorized access to sensitive data.
Kaseya to the Rescue: No company is safe from malicious insider risk. Learn about how to identify malicious insiders and mitigate your risk of trouble in our eBook. GET YOUR FREE EBOOK>>
Chemeketa Community College
https://www.salemreporter.com/2025/01/17/chemeketa-employees-hit-by-retirement-plan-data-breach/
Exploit: Hacking
Industry: Education
Bank of America filed a data breach notice with the Attorney General of Massachusetts after discovering unauthorized access to a third-party vendor’s systems on October 1, 2024. The breach exposed sensitive information about certain loan customers. The potentially exposed data includes names, addresses, passport numbers, phone numbers, Social Security numbers and loan numbers. BofA has since sent notification letters to affected customers, detailing the breach and its impact.
How It Could Affect Your Customers’ Business: Vetting and monitoring third-party vendors is crucial for protecting sensitive data, especially when it involves employee benefits and financial information.
Kaseya to the Rescue: Learn to mitigate a company’s risk of damage from often email-based cyberattacks like ransomware in A Comprehensive Guide to Email-based Cyberattacks. GET THE GUIDE>>
Otelier
Exploit: Malware
Industry: Technology (Software)
Hotel management platform Otelier has experienced a data breach. Threat actors claim that they accessed its Amazon S3 cloud storage to steal nearly 8 terabytes of data regarding major hotel brands like Marriott, Hilton and Hyatt. The breach began in July 2024 and continued through October 2024. The sensitive documents reportedly snatched include personal information, reservations, nightly reports, shift audits and accounting data. The attackers said that they gained access to Otelier’s Atlassian server through stolen employee credentials harvested via malware. Otelier, formerly MyDigitalOffice, serves over 10,000 hotels worldwide.
How It Could Affect Your Customers’ Business: Organizations must prioritize securing employee credentials, and security awareness training is an essential part of that effort.
Kaseya to the Rescue: Our infographic walks you through exactly how security awareness training prevents phishing from hooking unsuspecting employees. DOWNLOAD IT>>
Indiana University Health
https://www.healthcarefinancenews.com/news/iu-health-says-data-compromised-cyberattack
Exploit: Credential Compromise
Industry: Healthcare
Indiana University Health (IU Health) has confirmed that unusual activity linked to a team member’s email account resulted in unauthorized access to sensitive information, including a limited number of Social Security numbers. The breach, discovered on November 8, revealed that the account was accessed between August 27 and October 2, 2024. Exposed data may include addresses, ages, medical record numbers, diagnoses, and other limited treatment details. IU Health has since secured its systems and is notifying affected individuals. The organization began notifying affected individuals on January 2 and is providing dedicated call center support to answer any questions.
How It Could Affect Your Customers’ Business: Organizations must ensure that their third-party partners meet high cybersecurity standards and regularly audit their practices.
Kaseya to the Rescue: Leveraging innovative tools like an AI-enhanced, automated phishing threat detection solution can prevent malware disasters. See why in this infographic. DOWNLOAD IT>>
Willow Pays
Exploit: Human Error
Industry: Banking & Finance
Technische Universiteit Eindhoven (TU/e) took its internal network offline on Sunday following a cyberattack, disrupting access to essential services like email, Wi-Fi, Canvas, and Teams for students and staff. As a result, no educational activities are taking place, including planned makeup sessions and exam preparations. The university’s ICT experts are investigating the attack’s scope and expect the network to be restored by Tuesday. Despite the disruption, TU/e’s buildings and campus remain open.
How it Could Affect Your Customers’ Business: Today’s reliance on technology for education underscores the importance of raising awareness about cybersecurity risks among students, faculty, and staff to help prevent such incidents.
Kaseya to the Rescue: Watch this webinar to explore K365 User, our latest innovation to empower small and midsize businesses to maximize security while boosting productivity. LEARN MORE>>
Uncover today’s worst phishing threats and see smart strategies to keep businesses out of trouble. GET EBOOK>>
New Brunswick Liquor
https://globalnews.ca/news/10957499/nb-liquor-cyber-attack/
Exploit: Hacking
Industry: Government
New Brunswick Liquor (NB Liquor) stores are still working to restore their point-of-sale systems one week after a suspected cyberattack disrupted operations. The Crown corporation initially shut down all stores last Wednesday to protect customers and reopened the following day, but transactions remain limited to cash. Early last week, NB Liquor announced it still could not yet accept debit, credit or gift cards and expected system recovery to extend into the week. Cannabis NB stores have been similarly affected. Alcohol NB Liquor (ANBL) is the provincial Crown corporation that governs the purchase, importation, distribution and retail sale of all alcoholic beverages and cannabis in the province.
How it Could Affect Your Customers’ Business: Organizations must also have contingency plans in place for system recovery to help reduce operational disruptions and customer frustration.
Kaseya to the Rescue: Learn about five ways that businesses may be in danger of trouble from the dark web in an infographic that’s also perfect for sharing on social media! DOWNLOAD IT>>
Feeling overwhelmed by your task list? Discover four strategies for reducing your workload! GET INFOGRAPHIC>>
Russia – Roseltorg
https://therecord.media/russian-platform-for-state-procurement-hit-cyberattack
Exploit: Hacking (Nation-State)
Industry: Government
Roseltorg, Russia’s primary electronic trading platform for government and corporate procurement, confirmed a cyberattack on its systems after initially attributing outages to “maintenance work.” The attack, claimed by the pro-Ukraine hacker group Yellow Drift, reportedly resulted in the deletion of 550 terabytes of data, including emails and backups. While Roseltorg stated that its data and infrastructure have been restored, its website remains offline and trading systems are yet to resume full operations. The breach has disrupted clients, including government agencies and suppliers, raising concerns about financial losses and delays in procurement processes. Yellow Drift shared screenshots of the compromised infrastructure as proof of the attack.
How it Could Affect Your Customers’ Business: Advanced Persistent Threat (APT) groups frequently carry out highly targeted attacks designed to cause strategic disruption of their adversary’s infrastructure.
Kaseya to the Rescue: Explore the biggest challenges professionals contended with in 2024 and the impact of AI on cybersecurity in the Kaseya Cybersecurity Survey 2024. GET THE REPORT>>
Take a deep dive into why an AI-powered anti-phishing solution is a smart financial choice. GET EBOOK>>
Read this week’s feature story: What’s for Sale on the Dark Web (and How AI Is Changing the Marketplace)
Take a deep dive into the dark web economy as we explore the prices of services and commodities on the dark web as well as a look at how artificial intelligence (AI) has impacted that market. READ THE BLOG>>
Learn how to identify and mitigate malicious and accidental insider threats before there’s trouble! GET EBOOK>>
New integration: BullPhish ID and Graphus targets across multiple domains
When integrating a BullPhish ID organization with Graphus, all targets, regardless of their domain, are now included in the integration. Previously, targets could only belong to a single domain for the integration to work. Now, as long as all targets are protected by Graphus, they can belong to different domains or subdomains. Learn more in the BullPhish ID Release Notes. SEE MORE>>
Learn more about growing supply chain risk for businesses and how to mitigate it in a fresh eBook. DOWNLOAD IT>>
Make 4 smart moves to reduce your IT team’s cybersecurity workload
Help your IT team work smarter, not harder while keeping your security top-notch. Grab our infographic 4 Smart Moves to Reduce Your IT Cybersecurity Workload now to see how easy it can be to start making smart moves to bolster your IT team’s efficiency and reduce their stress today.
Did you miss…our eBook State of the Dark Web 2025? GET THE EBOOK>>
Learn how to spot today’s most dangerous cyberattack & get defensive tips in Phishing 101 GET EBOOK>>
April 28 – May 1 Kaseya Connect Global REGISTER NOW>>
June 17 – 19 Kaseya DattoCon Europe REGISTER NOW>>
October 6 – 8 Kaseya DattoCon REGISTER NOW>>
Do you have comments? Requests? News tips? Complaints (or compliments)? We love to hear from our readers! Send a message to the editor.
Partners: Feel free to reuse this content. When you get a chance, email [email protected] to let us know how our content works for you!
Read our case studies and see how MSPs and businesses have benefitted from using our solutions. READ NOW>