CyberWire Daily: Black Basta Manhunt, UK Fraud Service, and CISA Nominee
N2K NetworksJanuary 21, 202624 min428 views
22 connectionsΒ·40 entities in this videoβBlack Basta Hackers Targeted
- πΊπ¦ Ukrainian and German authorities have identified two Ukrainian nationals suspected of working for the Russia-linked ransomware group Black Basta.
- π·πΊ The group's alleged Russian leader has been placed on an international wanted list, with Black Basta extorting hundreds of organizations worldwide since at least 2022, causing hundreds of millions in damage.
- π Investigators seized digital devices and cryptocurrency during searches, with analysis ongoing.
UK's New National Fraud Reporting Service
- π¬π§ British authorities have launched Report Fraud, a new national service to transform how victims of fraud and cyber crime report incidents and how police act on them.
- ποΈ This system replaces Action Fraud, which faced criticism for poor outcomes, and promises follow-up updates and real-time analytics for actionable intelligence.
- π Fraud accounts for roughly half of all recorded crime in the UK, costing the economy billions annually.
LinkedIn Phishing and Browser Extension Attacks
- π§ A phishing campaign is delivering malware through private messages on LinkedIn, abusing open-source tools to infect victims with a remote access Trojan (RAT).
- π― The operation targets high-value individuals, including executives, using industry-themed lures.
- π₯ A separate maladvertising campaign is distributing a fake ad blocker extension called Nex Shield, which deliberately crashes browsers to deliver malware via a new ClickFix variant dubbed Crash Fix.
Ingram Micro Data Breach and Access Broker Guilty Plea
- πΎ IT distributor Ingram Micro disclosed a ransomware-related data breach affecting over 42,000 individuals after detecting a cyber intrusion in early July of last year.
- π° A Jordanian national has pleaded guilty in US federal court to selling stolen access to corporate networks, admitting to selling unauthorized login credentials tied to at least 50 victim organizations.
Business Breakdown and CISA Nomination
- π° Over $350 million was raised across seven investments and five acquisitions in the cybersecurity sector.
- π’ CrowdStrike acquired SGNL for $740 million and Seraphic for $420 million to enhance its Falcon platform.
- ποΈ Tim Starks discusses the surprising renomination of Sean Plankey to lead CISA, noting that his nomination had been previously stalled by Senate Republicans over unrelated issues.
Funeral Industry Security Gaps
- π°π· In Korea, eight affiliates of the Kawan group are under government investigation following a ransomware attack, exposing significant security gaps in the funeral industry.
- π None of the country's top funeral service providers have obtained information security management system certification, operating in a regulatory gap despite handling sensitive data and significant prepaid funds.
- β οΈ Experts note that ransomware groups favor industries with steady cash flow, sensitive data, and thin defenses.
Knowledge graph40 entities Β· 22 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover Β· drag to explore
40 entities
Chapters10 moments
Key Moments
Transcript89 segments
Full Transcript
Topics15 themes
Whatβs Discussed
Black BastaRansomwareCybercrimeFraudCybersecurityReport FraudLinkedInPhishingRemote Access Trojan (RAT)MalwareIngram MicroData BreachCISASean PlankeyFuneral Industry Security
Smart Objects40 Β· 22 links
PeopleΒ· 8
EventsΒ· 4
MediaΒ· 1
ConceptsΒ· 4
CompaniesΒ· 16
ProductsΒ· 7