Cyberattacks


  • Binary code of ones and zeros
    Image attribution tooltip
    deberrar/Getty Images via Getty Images
    Image attribution tooltip

    BeyondTrust customers hit by wave of attacks linked to compromised API key

    The cybersecurity vendor said an attacker compromised its access-management tool and reset customer passwords.

    By Dec. 20, 2024
  • gavel and money
    Image attribution tooltip
    Avosb via Getty Images
    Image attribution tooltip

    Flagstar fined $3.5M for ‘misleading’ after 2021 cyberattack

    The bank “negligently made” materially misleading statements after a hack that resulted in the theft of 1.5 million customers’ personally identifiable information.

    By Gabrielle Saulsbery • Dec. 19, 2024
  • An abstract photo copy background in black and white. Explore the Trendline
    Image attribution tooltip
    BNMK0819 via Getty Images
    Image attribution tooltip
    Trendline

    Top 5 stories from Cybersecurity Dive

    A wave of rules, regulations and federal action is putting pressure on businesses to shore up security amid a backdrop of emboldened threat actors has a nice ring to it.

    By Cybersecurity Dive staff
  • Person waits to enter Apple Store in San Francisco.
    Image attribution tooltip
    Justin Sullivan/Getty Images via Getty Images
    Image attribution tooltip

    CISA mobile security advice gets personal in wake of telecom intrusions

    The agency’s recommendations are not for the technically inept. Yet the extraordinary measures, including the use of encrypted apps, are applicable to all audiences.

    By Dec. 19, 2024
  • A facade of the U.S. Environmental Protection Agency signage on the wall of its building
    Image attribution tooltip
    Joe Cicak via Getty Images
    Image attribution tooltip

    Pennsylvania representative pitches bill to double cyber assistance for local water systems

    The proposed legislation comes amid a surge in ransomware and state-linked attacks against U.S. water utilities.

    By Dec. 17, 2024
  • cybersecurity, matrix, abstract
    Image attribution tooltip
    iStock / Getty Images Plus via Getty Images
    Image attribution tooltip

    Cleo releases new patch as threat groups ramp up exploitation of critical CVE

    Researchers warned that companies primarily in the trucking, food, retail and shipping industries were under attack.

    By Dec. 12, 2024
  • An image of a barista wearing green putting a pink drink into a bag
    Image attribution tooltip
    Permission granted by Grubhub/Starbucks
    Image attribution tooltip

    Blue Yonder helps restore operations for majority of impacted customers

    Starbucks regained access to its employee scheduling platform, while authorities continue to probe claims by a threat group.

    By Dec. 12, 2024
  • An image of various doughnuts from Krispy Kreme behind a bakery counter.
    Image attribution tooltip
    Brandon Bell via Getty Images
    Image attribution tooltip

    Krispy Kreme online ordering disrupted by cyberattack

    Following an attack on a portion of its IT systems, the chain said it was working to restore online ordering. In-store operations were not impacted.

    By Julie Littman • Dec. 11, 2024
  • Photo illustration of a VF Corp. SEC filing.
    Image attribution tooltip

    Photo illustration: Industry Dive; US Securities and Exchange Commission

    Image attribution tooltip

    SEC cyber incident reporting rule generates 71 filings in 11 months

    Most companies that disclosed cyber incidents to the agency did not describe materiality or other useful information, a BreachRx report found.

    By Dec. 11, 2024
  • A black and gold United States Environmental Protection Agency sign next to double-glass doors.
    Image attribution tooltip
    Sara Samora/Cybersecurity Dive
    Image attribution tooltip

    US subsidiary of global water treatment firm probes November cyberattack after data encrypted

    Kurita America, a subsidiary of a Tokyo-based company, is the latest in a string of companies tied to the water industry targeted by hackers.

    By Dec. 10, 2024
  • Snowflake office building in San Mateo, CA.
    Image attribution tooltip
    Permission granted by Snowflake
    Image attribution tooltip

    Snowflake to phase out single-factor authentication by late 2025

    The security policy change starts one year after a wave of attacks targeted more than 100 Snowflake customer environments without MFA.

    By Dec. 10, 2024
  • Finance chiefs can achieve supply chain security, risk mitigation, and even happy customers by collaborating with their logistics and procurement teams.
    Image attribution tooltip
    Getty Images via Getty Images
    Image attribution tooltip

    Blue Yonder investigating data leak claim following ransomware attack

    The software supply chain company is widening its investigation after Termite ransomware leaked data it claims is linked to the attack.

    By Dec. 9, 2024
  • Federal Communications Commission Commissioner Brendan Carr
    Image attribution tooltip
    Kevin Dietsch / Getty Images via Getty Images
    Image attribution tooltip

    Trump’s pick to run FCC deeply concerned about Salt Typhoon

    The recently uncovered swarm of attacks on U.S. telecom companies, part of a China-sponsored campaign, made FCC Commissioner Brendan Carr want to smash his phone, he said.

    By Dec. 9, 2024
  • Federal Communications Commission Chair Jessica Rosenworcel
    Image attribution tooltip
    Chip Somodevilla/Getty Images via Getty Images
    Image attribution tooltip

    FCC proposes stronger telecom cyber rules as Salt Typhoon fallout continues

    The agency’s proposed rule changes come two months after a China-government sponsored espionage campaign first came to light.

    By Dec. 6, 2024
  • A worker scans produce at a Morrisons supermarket in 2017. The supermarket chain was impacted by a cyberattack against Blue Yonder in November 2024.
    Image attribution tooltip
    Christopher Furlong via Getty Images
    Image attribution tooltip

    Morrisons recovers warehouse systems following attack on Blue Yonder

    The U.K. supermarket chain was one of several high-profile customers impacted by a ransomware attack against the supply chain management software provider.

    By Dec. 6, 2024
  • T-Mobile storefront in Washington.
    Image attribution tooltip
    Anna Moneymaker/Getty Images via Getty Images
    Image attribution tooltip
    Q&A

    T-Mobile undeterred as telecom sector reels from attack campaign

    Cybersecurity Dive spoke with CSO Jeff Simon about how the carrier says it thwarted a threat group resembling Salt Typhoon despite its past security failures.

    By Dec. 5, 2024
  • Anne Neuberger, deputy national security advisor for cyber and emerging technology, speaks at the White House.
    Image attribution tooltip
    Drew Angerer via Getty Images
    Image attribution tooltip

    At least 8 US companies hit in telecom attack spree, officials say

    A deputy national security advisor warned that the China-affiliated Salt Typhoon attack spree potentially infiltrated more telecom companies and the threat group still has network access.

    By Dec. 4, 2024
  • An illustration of a large dollar coin with medical supplies flying in the foreground is positioned on an analysis tracking chart background.
    Image attribution tooltip

    Illustration: Xavier Lalanne-Tauzia for Industry Dive

    Image attribution tooltip

    Ascension reduces operating loss as it rebounds from cyberattack

    A sweeping cyberattack this spring took the provider’s electronic health record offline for weeks and led to significant losses.

    By Susanna Vogel • Dec. 4, 2024
  • Engineer repairs 5G cell tower.
    Image attribution tooltip
    Jinli Guo/Getty Images via Getty Images
    Image attribution tooltip

    Feds raise alarm on China-linked infiltration of telecom networks

    Salt Typhoon gained access to many telecom networks and stole large amounts of data, including audio and text of targeted people involved in government or politics.

    By Dec. 4, 2024
  • Abstract black and white monochrome art with surreal funnel.
    Image attribution tooltip
    Philipp Tur/Getty Images Plus via Getty Images
    Image attribution tooltip

    ENGlobal IT systems impacted by ransomware attack

    The attack marks at least the third disruptive cyberattack impacting energy sector providers based in Texas since August.

    By Dec. 3, 2024
  • Shoppers buy groceries at Morrison's in 2020 during the Covid-19 lockdown.
    Image attribution tooltip
    Hollie Adams via Getty Images
    Image attribution tooltip

    Blue Yonder moves closer to full recovery after November ransomware attack

    U.K. supermarket chain Morrisons says its operations are mostly restored, while Blue Yonder is working with other customers to recover operations.

    By Dec. 2, 2024
  • New York Attorney General Letitia James attends a press conference on July 31, 2023, in New York City.
    Image attribution tooltip
    Michael M. Santiago / Staff via Getty Images
    Image attribution tooltip

    New York fines Geico, Travelers $11.3M for pandemic-era breaches

    The auto insurance companies were penalized for a series of attacks that exposed the personal data of 120,000 people in late 2020 and early 2021.

    By Nov. 26, 2024
  • A Starbucks worker holds a beverage.
    Image attribution tooltip
    Courtesy of Starbucks
    Image attribution tooltip

    Starbucks confirms Blue Yonder attack impacted employee scheduling platform

    The company is reverting to manual operations to make sure workers are paid on time, a spokesperson said. 

    By Nov. 26, 2024
  • Las Vegas Boulevard aerial view
    Image attribution tooltip
    Robert Mora / Staff via Getty Images
    Image attribution tooltip

    Gambling tech vendor’s IT systems impacted by cyberattack

    International Game Technology, which makes slot machines and other gambling technology, said it took systems offline following a Nov. 17 cyberattack.

    By Nov. 25, 2024
  • A worker scans produce at a Morrisons supermarket in 2017. The supermarket chain was impacted by a cyberattack against Blue Yonder in November 2024.
    Image attribution tooltip
    Christopher Furlong via Getty Images
    Image attribution tooltip

    Ransomware hits supply chain software firm Blue Yonder ahead of Thanksgiving

    The attack against Blue Yonder led to issues for Morrisons, a U.K.-based grocery chain, in its warehouse management system for fresh food and produce.

    By Nov. 25, 2024
  • Programming scripts on laptop monitor, unauthorized remote hacking of server
    Image attribution tooltip
    Motortion via Getty Images
    Image attribution tooltip

    Palo Alto Networks pushes back as Shadowserver spots 2K of its firewalls exploited

    The security vendor maintains only a limited number of customers’ firewalls have been exploited by a zero-day it patched earlier this week.

    By Nov. 22, 2024