"Investigations into the incident are continuing, however, the Company is confident that no customer systems data has been compromised," said Microlise in an incident update, which has noted "substantial progress" in thwarting the network threat.
Attackers behind the Singtel breach utilized a web shell, noted sources close to the matter. Such a webshell was previously reported by Lumen researchers to have been planted on an anonymous Singaporean entity to secure credentials that were later used to infiltrate four U.S.-based organizations and an India-based entity.
Investigation into the incident is already underway, according to Van Wagner, which has already offered a year's worth of complimentary theft protection services to impacted persons while emphasizing the implementation of additional security measures across its IT infrastructure to avoid future intrusions.
Attackers who infiltrated its systems from June 29 to July 18 were able to compromise some system files, which included individuals' names, financial details, and Social Security numbers, with the stolen data differing from person to person.
Infiltration of systems belonging to Mystic Valley, which caters to older adults and people with disabilities, have enabled the exfiltration of names, birthdates, Social Security numbers, payment card and financial account numbers, passport numbers, driver's license numbers, online passwords, medical details, and health insurance data.
After Quad7's successful exfiltration of targeted systems' passwords through a limited number of sign-in attempts meant to evade detection, Storm-0940 immediately utilized the stolen credentials to breach networks, conduct credential dumping, and deploy remote access trojans and proxy tools to ensure persistence as part of a possible cyberespionage attack.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.