StateScoop reports that threat actors associated with the Babuk malware claimed they have stolen more than 250 gigabytes of data from the Metropolitan Police Department in Washington, D.C., which appeared on a ransomware leak site on Monday.
The stolen data include arrest records, police reports, internal memos and documents which have been shared with other authorities, such as the FBI.
According to intelligence company Recorded Future’s Allan Liska, the attack was unlikely to be an intentional attack on the nation’s capital. The incident was possibly a crime of opportunity since the malware does not have a history of targeting organizations in the public sector like school districts and local governments, and uses phishing schemes and looks for vulnerabilities, such as open Remote Desktop Protocol ports, Liska added.
“They’re scanning for open RDP or something like that, and bam, they hit the police department,” said Liska.
Liska noted that Babuk has “improved a lot” and is “a lot more difficult to detect because it can look like the admin moving around the network.
Jill Aitoro is senior vice president of content strategy for CyberRisk Alliance. She has more than 20 years of experience editing and reporting on technology, business and policy. Prior to joining CRA, she worked at Sightline Media as editor of Defense News and executive editor of the Business-to-Government Group. She previously worked at Washington Business Journal and Nextgov, covering federal technology, contracting and policy, as well as CMP Media’s VARBusiness and CRN and Penton Media’s iSeries News.
OpenSea has confirmed being impacted by a third-party security breach, marking the third attack against the major non-fungible token marketplace following a third-party hack and phishing incident in June 2022 and February 2022, respectively, SiliconAngle reports.
Nansen impacted by third-party breach BleepingComputer reports that Ethereum blockchain analytics firm Nansen has disclosed that its third-party authentication provider was impacted by a data breach, which resulted in the compromise of data from 6.8% of its user base over a 48-hour period.