MesaZona > Table of Contents : Here's The Menu. Enjoy

Tuesday, August 16, 2022

SECURITY NEWS: Bleeping computer

 Just three and then some . . . 

Hackers attack UK water supplier but extort wrong company

OkBy 
Bill Toulas 

South Staffordshire Water, a company supplying 330 million liters of drinking water to 1.6 consumers daily, has issued a statement confirming IT disruption from a cyberattack.

As the announcement explains, the safety and water distribution systems are still operational, so the disruption of the IT systems doesn’t impact the supply of safe water to its customers or those of its subsidiaries, Cambridge Water and South Staffs Water.

“This is thanks to the robust systems and controls over water supply and quality we have in place at all times, as well as the quick work of our teams to respond to this incident and implement the additional measures we have put in place on a precautionary basis,” explains the statement published on the company’s site.

Also, South Staffordshire Water reassures its customers that all service teams are operating as usual, so there’s no risk of extended outages due to the cyberattack.

Clop misidentifies victim?

Meanwhile, the Clop ransomware gang claimed Thames Water as their victim via an announcement on their onion site today, alleging to have accessed SCADA systems they could manipulate to cause harm to 15 million customers.

Thames Water is UK's largest water supplier and wastewater treatment provider, serving Greater London and areas surrounding river Thames.

The hackers allege to have informed Thames Water of its network security inadequacies and claim that they acted responsibly by not encrypting their data and only exfiltrating 5TB from the compromised systems.

Part of Clop's claims in the extortion site
Part of Clop's claims in the gang's data leak extortion site

However, following a supposed collapse in the negotiations of the ransom payment, the actors published the first sample of stolen data that includes passports, screenshots from water treatment SCADA systems, driver’s licenses, and more.

Thames Water has officially disputed these claims via a statement today, saying that reports of Clop having breached its network are "cyber-hoax" and that its operations are at full capacity.

One key detail in the case is that among the published evidence, Clop presents a spreadsheet with usernames and passwords, which features South Staff Water and South Staffordshire email addresses.

Published evidence pointing to South Staffordshire Water
Published evidence pointing to SSW

Additionally, BleepingComputer observed, one of the leaked documents sent to the targeted firm is explicitly addressed to South Staffordshire PLC.

As such, it’s very likely that Clop misidentified their victim or that they are attempting to extort a much larger company using false evidence.

This attack comes during dire drought times for UK consumers, with eight areas in the country imposing water ration policies and hosepipe bans.

Cybercriminals don’t pick their targets randomly, as hitting water suppliers during harsh drought periods could apply insurmountable pressure to pay the demanded ransom.

For this to happen, though, Clop has to redirect its threats to the correct entity, but considering the publicity the matter has taken, it’s probably too late for that.

 
  • August 16, 2022
  •  
  • 05:05 AM
  •  
  • 0

✓ 1  

SECURITY, GAMING

CS:GO trading site hacked to steal $6 million worth of skins

CS.MONEY, one of the largest platforms for trading CS:GO skins, has taken its website offline after a cyberattack allowed hackers to loot 20,000 items worth approximately $6,000,000.

  • BILL TOULAS
  •  
  • AUGUST 16, 2022
  •  
  • 09:59 AM
  •  
  • Comment 1

✓ 2 

  • DDoS Denial of Service
     
    SECURITY

    Malicious PyPi packages aim DDoS attacks at Counter-Strike servers

    A dozen malicious Python packages were uploaded to the PyPi repository this weekend in a typosquatting attack that performs DDoS attacks on a Counter-Strike 1.6 server.

    • BILL TOULAS
    •  
    • AUGUST 15, 2022
    •  
    • 06:03 PM
    •  
    • Comment 0
  • Signal
     
    SECURITY

    Twilio hack exposed Signal phone numbers of 1,900 users

    Phone numbers of close to 1,900 Signal users were exposed in the data breach Twilio cloud communications company suffered at the beginning of the month.

    • IONUT ILASCU
    •  
    • AUGUST 15, 2022
    •  
    • 05:46 PM
    •  
    • Comment 0
  • Microsoft
     
    SECURITY, MICROSOFT

    Microsoft disrupts Russian hackers' operation on NATO targets

    The Microsoft Threat Intelligence Center (MSTIC) has disrupted a hacking and social engineering operation linked to a Russian threat actor tracked as SEABORGIUM that targets propland organizations in NATO countries.

    • LAWRENCE ABRAMS
    •  
    • AUGUST 15, 2022
    •  
    • 02:22 PM
    •  
    • Comment 0
  • Ukraine Phishing
     
    SECURITY

    Russian hackers target Ukraine with default Word template hijacker

    Threat analysts monitoring cyberattacks on Ukraine report that the operations of the notoriousOk

✓ 3 

  • Call center phone
     
    SECURITY

    Callback phishing attacks see massive 625% growth since Q1 2021

    Phishing is constantly evolving to bypass user training and email protections, and as threat actors adopt new tactics with better success ratios, quarterly stats reflect interesting threat trends on multiple fronts.

    • BILL TOULAS
    •  
    • AUGUST 15, 2022
    •  
    • 10:32 AM
    •  
    • Comment 0


on August 16, 2022
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
View mobile version
Subscribe to: Post Comments (Atom)

Popular Posts

  • City Council Meeting - 5/19/2025
  • Chief of War — Official Teaser | Apple TV+
  • World Defense News
    Flash News: Ukraine Intercepts Russian Kh-59 Cruise Missile Using US VAMPIRE Air Defense System Mounted on Boat. Ukrainian forces have made ...

About Me

My photo
Tim Mello
Education and work in most major East Coast cities like Washington D.C. [Georgetown University], Philadelphia [Temple University], Boston and New York City for 20+ years - all with robust, dynamic, and diverse populations. Here in Mesa by choice with the challenges of living in a "downtown" area motivated to regenerate its city center for residents and visitors.
View my complete profile
  • Jun (303)
  • May (381)
  • Apr (505)
  • Mar (545)
  • Feb (387)
  • Jan (391)
  • Dec (430)
  • Nov (409)
  • Oct (586)
  • Sep (414)
  • Aug (504)
  • Jul (512)
  • Jun (467)
  • May (576)
  • Apr (604)
  • Mar (549)
  • Feb (603)
  • Jan (625)
  • Dec (625)
  • Nov (633)
  • Oct (622)
  • Sep (733)
  • Aug (695)
  • Jul (716)
  • Jun (606)
  • May (638)
  • Apr (462)
  • Mar (198)
  • Feb (99)
  • Jan (107)
  • Dec (148)
  • Nov (171)
  • Oct (156)
  • Sep (168)
  • Aug (211)
  • Jul (188)
  • Jun (218)
  • May (168)
  • Apr (267)
  • Mar (224)
  • Feb (316)
  • Jan (179)
  • Dec (275)
  • Nov (316)
  • Oct (313)
  • Sep (405)
  • Aug (406)
  • Jul (398)
  • Jun (305)
  • May (222)
  • Apr (170)
  • Mar (231)
  • Feb (178)
  • Jan (171)
  • Dec (293)
  • Nov (340)
  • Oct (227)
  • Sep (247)
  • Aug (151)
  • Jul (80)
  • Jun (121)
  • May (146)
  • Apr (142)
  • Mar (198)
  • Feb (188)
  • Jan (265)
  • Dec (137)
  • Nov (102)
  • Oct (161)
  • Sep (117)
  • Aug (55)
  • Jul (121)
  • Jun (74)
  • May (107)
  • Apr (129)
  • Mar (117)
  • Feb (105)
  • Jan (145)
  • Dec (125)
  • Nov (106)
  • Oct (118)
  • Sep (143)
  • Aug (89)
  • Jul (82)
  • Jun (124)
  • May (121)
  • Apr (66)
  • Mar (98)
  • Feb (98)
  • Jan (132)
  • Dec (120)
  • Nov (154)
  • Oct (96)
  • Sep (123)
  • Aug (128)
  • Jul (119)
  • Jun (168)
  • May (192)
  • Apr (149)
  • Mar (129)
  • Feb (122)
  • Jan (157)
  • Dec (100)
  • Nov (109)
  • Oct (98)
  • Sep (102)
  • Aug (95)
  • Jul (70)
  • Jun (121)
  • May (123)
  • Apr (62)
  • Mar (55)
  • Feb (72)
  • Jan (74)
  • Dec (80)
  • Nov (55)
  • Oct (45)
  • Sep (26)
  • Aug (24)
  • Jul (20)
  • Jun (41)
  • May (24)
  • Apr (13)
  • Mar (8)
  • Feb (2)

Report Abuse

Total Pageviews

Search This Blog

  • Home

LIVE: Putin takes questions from international journalists

Awesome Inc. theme. Powered by Blogger.