Finance
New Grandoreiro Banking Malware Variants Emerge with Advanced Tactics to Evade Detection
Who:
- Threat Actor: Operators of the Grandoreiro banking malware, a Brazilian banking trojan.
- Target: Banking customers, particularly in Mexico, Latin America (LATAM), and Europe.
What:
- Malware Evolution: New variants of Grandoreiro have adopted advanced tactics like domain generation algorithms (DGA), encryption, mouse tracking, and CAPTCHA barriers to evade detection.
Fidelity says data breach exposed personal data of 77,000 customers
Who:
- Affected users: 77,099 Fidelity customers.
- Company: Fidelity Investments, a global asset management firm.
- Perpetrator: An unnamed third party.
What:
Prudential Financial now says 2.5 million impacted by data breach
Who:
- Prudential Financial, a global financial services company.
- Over 2.5 million individuals whose personal information was compromised.
What:
- Prudential Financial experienced a data breach on February 4, 2024, detected the following day.
Bay Area Credit Union Struggles to Recover After Ransomware Attack
Who:
- Patelco Credit Union, a Bay Area financial institution with $9 billion in assets and 450,000 members nationwide.
What:
- On June 29, Patelco Credit Union was hit by a ransomware attack that forced it to shut down several key banking systems.
- The attack has left tens of thousands of customers without access to their accounts and core electronic transactions such as direct deposits, transfers, balance inquiries, and payments.
First American December data breach impacts 44,000 people
First American Financial Corporation, the second-largest title insurance company in the U.S., with over 21,000 employees and annual revenue of $6 billion.
What: A cyberattack in December impacted 44,000 individuals by accessing sensitive personal information. The breach follows a settlement with New York State for a 2019 data exposure incident.
Impact: The attack led to unauthorized access to personal data of 44,000 people, prompting First American to offer credit monitoring and identity protection services to those affected. This incident underscores ongoing cybersecurity challenges in the financial services sector, particularly for firms handling large volumes of sensitive information.
Read the full article HERE
Fidelity data breach affects 28,000+ customers
Who: Fidelity Investments Life Insurance Co. disclosed that over 28,000 of its customers may have had their personal information compromised.
What: The data breach, discovered in October 2023, occurred due to an unauthorized third party gaining access to customer information held by third-party services provider Infosys McCamish Systems (IMS).
Impact: Affected customers' personal data, including names, Social Security numbers, state of residence, bank account and routing numbers, and birthdates, may have been exposed. Fidelity emphasized its commitment to the security of personal information and is providing free credit monitoring and identity restoration services for 24 months. This breach adds to a series of recent cybersecurity incidents affecting various companies, highlighting the ongoing challenges of safeguarding sensitive information.
Read the full article HERE
American Express credit cards exposed in third-party data breach
Who: American Express customers are affected by the data breach. The incident resulted from a hack at a third-party merchant processor, not a breach at American Express directly.
What: Customer credit cards were exposed in a data breach at a third-party service provider engaged by multiple merchants. The breach led to unauthorized access to the account information of some American Express Card Members, including account numbers, names, and card expiration data.
Impact: The breach raises concerns about the security of third-party service providers in the payment processing chain. While American Express asserts that its systems were not compromised, the incident highlights the risks associated with the broader payment ecosystem. The number of affected customers, the identity of the breached merchant processor, and the timeline of the attack remain unclear. American Express advises affected customers to review account statements, enable fraud alerts, and consider requesting new card numbers to mitigate potential.