December 15, 2020

The Role of Admin Credentials in the SolarWinds Attack

I wanted to share my thoughts on the SolarWinds attack that has been used to target government agencies as well as other private/public companies. FireEye has an excellent write-up ( Highly Evasive Attacker Leverages SolarWinds Supply Chain to CompromiseMultiple Global Victims With SUNBURST Backdoor ) and I encourage everyone to read it to familiarize yourself with the exploit and attack paths. […]
October 10, 2020

Increasing Ransomware in COVID: Responding to Double Extortion

Hosted by Nihon Cyber Defence With the concept of “Thinking Cybersecurity in the UK in the Context of Japanese Organisations,” the NCD Insight online seminar series delivers the latest security trends and knowledge for global organisations. The seminar will hold monthly for six months. Cyber actors break into the corporate network, steal sensitive information, and 1) encrypt files, demand ransoms […]
July 6, 2020

Capcom hit by Ragnar Locker ransomware with 1TB of data stolen

On 2nd of November, Japanese game developer Capcom experienced a ransomware attack where the company had to shut down portions of their corporate network to prevent the spread of the attack and threat actors claim to have stolen 1TB of sensitive data from their corporate networks in the US, Japan, and Canada. At the time of compromise, Capcom displayed notices […]
March 20, 2020

UK Fintech Firm Finastra announces they were attacked by ransomware.

On the 20th of March 2020, Finastra, a leading financial technology provider from the UK, announced that it had to take several servers offline in response to a security breach they had discovered earlier that day. The announce come out after sources at two different U.S. financial institutions had forwarded a notice, they received from Finastra to cybersecurity writer Brian […]
March 3, 2020

Legal service provider Epiq Global among the Ransomware attack victims

On February 29th, 2021, Epiq Global, a highly recognized provider of legal services, experienced a ransomware attack by the Ryuk ransomware. Epiq Global’s initial response to the detection of the attack was to take all their systems offline to contain the ransomware. Later that day, news came out that some of Epiq Global’s computers and systems were running older versions […]