{"id":29865,"date":"2020-04-24T06:00:58","date_gmt":"2020-04-24T12:00:58","guid":{"rendered":"https://www.webroot.com/blog/?p=29865"},"modified":"2020-04-23T13:27:44","modified_gmt":"2020-04-23T19:27:44","slug":"cyber-news-rundown-ransomware-hits-la-suburbs","status":"publish","type":"post","link":"https://www.webroot.com/blog/2020\/04\/24\/cyber-news-rundown-ransomware-hits-la-suburbs\/","title":{"rendered":"Cyber News Rundown: Ransomware Hits LA Suburbs"},"content":{"rendered":"\n<h2>Los Angeles Suburb Hit with Ransomware<\/h2>\n\n\n\n<p>Last month, the City of Torrance, California fell victim to\na ransomware attack that shut down many of their internal systems and demanded\n100 Bitcoins to not publish the stolen data. Along with the roughly 200GB of\ndata it stole from the city, the <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/doppelpaymer-ransomware-hits-los-angeles-county-city-leaks-files\/\">DoppelPaymer<\/a>\nransomware also deleted all local backups and encrypted hundreds of\nworkstations. At this time, it\u2019s uncertain whether the City of Torrance has\nchosen to pay the ransom, as the malware authors seem to have diligently removed\nany means for the City to recuperate on their own.<\/p>\n\n\n\n<h2>Malicious Packages Hidden Within Popular File Repository<\/h2>\n\n\n\n<p>Over 700 malicious packages have been discovered within the <a href=\"https:\/\/arstechnica.com\/information-technology\/2020\/04\/725-bitcoin-stealing-apps-snuck-into-ruby-repository\/\">RubyGems<\/a>\nmain program and file repository. These originated from just two accounts and\nwere uploaded over a single week period in late February. Between them, the\nmany packages have a combined download number of over 100,000, most of which\nincluded a cryptocurrency script that could identify and intercept cryptocurrency\ntransactions being made on Windows\u00ae devices. While this isn\u2019t the first time malicious\nactors have used open source file repositories to distribute malicious payloads,\nthis infiltration of an official hub for such a long period of time speaks to\nthe lack of security within these types of systems. <\/p>\n\n\n\n<h2>Maze Ransomware Targets Cognizant ISP<\/h2>\n\n\n\n<p>Late last week, the <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/maze-wage-ransomware-attack-on\/\">Maze\nRansomware<\/a> group took aim at New Jersey-based internet service provider,\nCognizant, and took down a significant portion of their internal systems. The\nattack occurred just a day after the removal of a dark web post that offered access\nto an IT company\u2019s systems for $200,000. It had been listed for nearly a week.\nWhile Cognizant has already begun contacting its customers about the attack, the\ntrue extent of the damage remains unclear. <\/p>\n\n\n\n<h2>COVID-19 Scams Net $13 Million<\/h2>\n\n\n\n<p>The Federal Trade Commission recently released statistics on\nthe number of complaints they\u2019ve received specifically related to the COVID-19\npandemic: it\u2019s over 17,000 in just a three-month period. While this number is\nassuredly less than the actual number of <a href=\"https:\/\/www.helpnetsecurity.com\/2020\/04\/16\/covid-19-fraud-losses\/\">COVID-19\nrelated scams<\/a>, these reported complaints have resulted in a sum of over $13\nmillion in actual losses, ranging from fraudulent payments to travel\ncancellations and refunds. Additionally, the FTC was able to catalogue over\n1,200 COVID-19 related scam calls reported by people on the Do Not Call list.<\/p>\n\n\n\n<h2>Customer Data Stolen from Fitness App<\/h2>\n\n\n\n<p>A database belonging containing 40GB of personally\nidentifiable information on thousands of customers of the fitness app, <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/fitness-app-kinomap-leaks-42\/\">Kinomap<\/a>,\nwas found unsecured. Containing a total of 42 million records, the database remained\naccessible for nearly 2 weeks after the company was informed. It was only\nsecured at last after French data protection officials were notified. Kinomap\nAPI keys were also among the exposed data, which would have allowed malicious\nvisitors to hijack user accounts and steal any available data. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Los Angeles Suburb Hit with Ransomware Last month, the City of Torrance, California fell victim to a ransomware attack that shut down many of their internal systems and demanded 100 Bitcoins to not publish the stolen data. Along with the roughly 200GB of data it stole from the city, the DoppelPaymer ransomware also deleted all [&hellip;]<\/p>\n","protected":false},"author":47,"featured_media":29867,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[21944],"yst_prominent_words":[],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/29865"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/47"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=29865"}],"version-history":[{"count":1,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/29865\/revisions"}],"predecessor-version":[{"id":29869,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/29865\/revisions\/29869"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/29867"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=29865"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=29865"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=29865"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=29865"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}