ZeroFox Weekly Intelligence Brief – April 15, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – April 15, 2024
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on April 12, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
Social Engineering Attacks Targeting IT Help Desks in the Health Sector
What happened: Reports confirm that IT help desks in the health sector are the recent target of threat actors who seek to gain unauthorized access to organizations through advanced social engineering tactics. Threat actors first approach IT help desks with phone calls from the target organization’s local area codes, posing as employees in financial roles such as revenue cycle or administrator positions. To further strengthen their disguise, the threat actors mimic high-level personnel through domain spoofing, amplifying the risk. Claiming their phone is broken and they are unable to receive multi-factor authentication (MFA) tokens, the threat actors convince the help desk to enroll a new device in MFA, thus gaining access to corporate resources.
U.S. Government Consulting Firm Discloses Data Breach Exposing over 340,000 Social Security Numbers
What happened: Greylock McKinnon Associates (GMA), a consulting firm known for assisting businesses and government agencies such as the U.S. Department of Justice (DOJ) in litigation support, has disclosed a data breach exposing 341,650 Social Security numbers. GMA stated it suffered a cyberattack in May 2023, promptly initiating mitigation measures. It has also notified law enforcement and the DOJ. In its notification email to the victims, GMA mentioned that the breach does not affect their current Medicare benefits or coverage and that the victims are not “the subject of this investigation or the associated litigation matters.”
GHC-SCW Ransomware Attack Affects over 533,000 People
What happened: Group Health Cooperative of South Central Wisconsin (GHC-SCW) has disclosed that a ransomware gang breached its network access and stole data that included protected health information (PHI) of over 533,000 individuals. On March 11, ZeroFox observed an update on the Black Suit Ransomware leak site targeting GHC-SCW.
Tags: tlp:green