zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - June 16, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - June 16, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • London Hospitals Cyber Incident Causes Severe O Positive and O Negative Blood Shortage
  • ZeroFox Intelligence Flash Report - Threat Actor Linked to ShinyHunters Advertises Extortionate Data Breach
  • City of Cleveland Shuts Down IT Systems After Cyberattack

London Hospitals Cyber Incident Causes Severe O Positive and O Negative Blood Shortage

Source: https://www.nhsbt.nhs.uk/news/o-positive-and-o-negative-donors-asked-to-urgently-book-appointments-to-give-blood-following-london-hospitals-it-incident/

What happened: England's NHS Blood and Transplant (NHSBT) has urgently called for O positive and O negative blood donors to book appointments and donate following last week’s cyberattack on pathology provider Synnovis. Many non-urgent procedures have been canceled or redirected.

Why it matters: The attack disrupted services at multiple hospitals in London, making it difficult to quickly match blood donor and recipient types. This raises the risk of transfusion mismatches, which could lead to life-threatening complications. The London hospital incident is part of a series of ransomware attacks on healthcare organizations this year, which have compromised patient services and exposed sensitive data. The much-publicized and disruptive impact of attacking healthcare services makes these organizations lucrative targets for extortion, potentially endangering patient lives.

ZeroFox Intelligence Flash Report - Threat Actor Linked to ShinyHunters Advertises Extortionate Data Breach

Source: https://www.zerofox.com/advisories/23723/

What happened: On June 11, 2024, untested threat actor “sp1d3r'' advertised the sale of a notably-large leaked data set in the Russian-speaking dark web forum xss. The breach allegedly contains 65,000 records of data stolen from a U.S.-based financial organization that purportedly include both personal financial information (PFI) and personally identifiable information (PII).

Why it matters: The owner of this stolen data is likely a victim of the ongoing fallout of the alleged breach of cloud-based service provider Snowflake. Since the alleged breach on May 23, 2024, several of Snowflake’s assumed customers’ data have been advertised on deep and dark web (DDW) forums. Sp1d3r is almost certainly synonymous with, or heavily associated with, threat actor “ShinyHunters”, who is very likely responsible for recent attacks against Snowflake customers. In the coming weeks, it is very likely that additional Snowflake customers will be implicated in data breaches, with the stolen information being advertised for sale in DDW forums.

City of Cleveland Shuts Down IT Systems After Cyberattack

Source: https://www.bleepingcomputer.com/news/security/city-of-cleveland-shuts-down-it-systems-after-cyberattack/

What happened: The City of Cleveland took its citizen-facing services, like public offices and City Hall, down after a cyberattack. Ongoing investigations reveal the incident has not impacted any essential services like healthcare and utility.

Why it matters: Investigations are still underway to determine the type of cyberattack. No threat actor has claimed the attack and neither has any ransom been demanded, at the time of writing. However, the City of Cleveland has a population of two million and is considered to be a significant economic center in Ohio. Forcing the city to take some of its services offline could mean backlogs and delays which could cause financial losses.

Tags: DIB, tlp:green