Claims Cybersecurity in September 2022

10/10/2022

Cybersecurity incidents happen every day. Sometimes it hits companies particularly hard, which can lead to major damage, outages and losses. Some of the damage cases from the month of September in 2022 are listed here and summarized for you.

Extortion after hacker attack on Caritas

In mid-September, Caritas in Munich and Freising was the victim of a cyber attack. The hackers penetrated the central IT infrastructure and were able to encrypt and additionally steal data. As a result, Caritas was blackmailed. The offer: after a ransom was handed over in the form of cryptocurrency, the data would be decrypted again. If the demand was not met, the data would be made public.

Instead of paying this ransom, Caritas decided to focus on building an alternative IT infrastructure, which was soon possible thanks to an extensive data backup. The demand of the hackers was not met, as there would be no guarantee that the cyber criminals would not reveal the sensitive data to the public after all.

An international group of cyber criminals, who are already responsible for many attacks on large companies and organizations, is said to be responsible for the hacker attack. In addition to demanding money, another goal of the attack is said to be to create a breach of trust between the people who are supported by Caritas and the people who support Caritas. Currently, external specialists and investigating authorities are working to clarify the attack. Despite the hampered communication caused by the hacker attack, the work with the people continues at full speed.

Source: After cyber attack: Caritas won't pay extortionists anything | BR24


18-year-old paralyzes internal systems of Uber after hacker attack

After a cyber attack on 15. September 2022, caused by an 18-year-old, mobility services provider Uber was forced to take all internal communications and technology systems offline. The hacker was able to gain full access to source codes, emails and other internal systems at Uber. The hacker posed as an information technology employee at the company, according to the New York Times. As a result, he was able to persuade an Uber employee to provide him with a password that allowed him to gain access to computer systems at the company. The 18-year-old hacker was able to announce the cyberattack through another employee's Slack account. In addition, he posted a revealing photo on an intranet page of the company.

Uber is, according to its own statements, in contact with law enforcement authorities and shared internally an email that the attack is still being investigated and it is not yet foreseeable when all tools can be fully used again. According to their own information, the hacker wanted to get better pay for the service provider's drivers. For the users and drivers of the provider, there were apparently no consequences, the operation continued throughout.

Source: Cyberattack: Hacker attack on Uber completely paralyzes systems (basicthinking.de)


Customer data stolen after cyber attack at Neobank Revolut

Unknown perpetrators were able to gain access to data of customers of Neobank Revolut through a hacker attack in a short time. More than 50,000 consumers are affected, but an extortion attempt had not occurred. In mid-September 2022, the access was noticed by Revolut and they were able to isolate the cyber attack within a few hours. The target of the hacker attack remains unclear. Further, the bank informed its customers that no card data, PINs or passwords were stolen, but they were able to partially capture card payment data, names, addresses, e-mail addresses and telephone numbers of customers.

Source: Hacker attack: Neobank falls victim to cyberattack | Law | 23.09.2022 | FONDS professionell

Your contact

Bianca Sum
Dr. Robert Couronné