zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 31, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 31, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • “Tech Support” Scammers Charged with Conspiracy to Commit Money Laundering
  • Modified HIPAA Rules to Better Strengthen User Data
  • Hackers Release Rhode Island Residents’ Data Onto the Dark Web

“Tech Support” Scammers Charged with Conspiracy to Commit Money Laundering

Source: https://www.justice.gov/usao-az/pr/participants-tech-support-scheme-charged-conspiracy-launder-fraudulent-proceeds

What happened: A U.S. federal grand jury has returned an elder fraud indictment against two individuals for Conspiracy to Commit Money Laundering and charged one of them with Conspiracy to Commit Wire Fraud. The indictment alleges that the two individuals and others conspired to launder fraudulent proceeds derived from schemes targeting elderly victims around the United States, including Arizona.

Why it matters: The individuals lured victims with a pop-up on their computer claiming their devices were hacked, directing them to tech support agents or "government representatives" who were part of the scheme. The agents convinced the victims that their accounts were compromised and instructed them to withdraw money, buy gold, or purchase gift cards. Such scams tend to create a sense of panic in targeted victims and take advantage of their trust in customer support networks for monetary gain.

Modified HIPAA Rules to Better Strengthen User Data

Source: https://thehackernews.com/2024/12/new-hipaa-rules-mandate-72-hour-data.html

What happened: The Office for Civil Rights (OCR) in the U.S. Department of Health and Human Services (HHS) issued a Notice of Proposed Rulemaking (NPRM) to modify the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule to strengthen electronically protected health information (ePHI). The Security Rule aims to establish national standards for the protection of individuals’ data by covered entities and their business associates, improving healthcare cybersecurity.

Why it matters: The NPRM aims to strengthen the Security Rule by requiring all implementation specifications to be mandatory, standardizing compliance timeframes, and mandating detailed documentation and risk assessments. Key proposals include developing an annual technology asset inventory, encrypting ePHI, implementing multi-factor authentication, conducting regular vulnerability scans and penetration tests, and ensuring network segmentation. The rule also emphasizes contingency planning, compliance audits, and business associate accountability, including written certifications of compliance and timely notifications for security incidents.

Hackers Release Rhode Island Residents’ Data Onto the Dark Web

Source: https://www.necn.com/news/local/hackers-have-released-ri-residents-info-to-dark-web-governor-says/3426047/

What happened: Threat actors have breached the State of Rhode Island's RIBridges system—which delivers health and human service benefits—and leaked data of approximately 650,000 residents on the dark web.

Why it matters: At the time of reporting, IT teams are investigating the attack and have yet to confirm the scope of the data in the leaked files. Meanwhile, the leaked data is likely to expose the impacted residents, also involved in programs like Medicaid and SNAP, to identity theft and fraud. With such sensitive personal information at risk, including financial details, authorities have advised residents to freeze their credit, monitor reports, and use multi-factor authentication.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user: Threat actor "888" claimed to have leaked a database associated with FoodMap, a Vietnam-based marketplace, on the predominantly English-language dark web forum BreachForums. The compromised data includes customer ID, name, phone number, email address, province/city, district, ward, gender, and date of creation, resulting in the exposure of 58,948 users.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-13030: A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. This issue affects a function of the component Web Management Interface. The manipulation leads to improper access controls. The attack may be initiated remotely.

Affected products: D-Link DIR-823G 1.0.2B05_20181207

Tags: DIB, tlp:green