Despite immediate action to thwart unauthorized access and enforce security measures, ADT had some encrypted employee data stolen as a result of the incident, said the firm in a filing with the Securities and Exchange Commission.
Attackers were able to exfiltrate individuals' names, Social Security numbers, and other personal details as a result of the incident but there has been no evidence suggesting the misuse of impacted data, said UMG in a filing with the Office of the Maine Attorney General.
After being assured it was not affected by the incident in March, Comcast was notified by FBCS two months later stating the opposite, with the breach compromising information belonging to 273,703 customers of the cable TV company.
While most of the impacted individuals had their names, birthdates, home addresses, medical details, driver's licenses or state IDs, and health insurance information compromised, a few others also had their Social Security numbers, financial information, and passport details potentially stolen as a result of the intrusion.
Misconfigurations leaked the full names, emails, personal and work phone numbers, and financial application usernames belonging to clients of Dominican Republic's Asociacion La Nacional de Ahorros y Prestamos, Mexico's Caja Mitras and Caja Buenos Aires, Bolivia's La Cooperativa de Ahorro y Credito Abierta "San Martín de Porres," Costa Rica's Credecoop, Ecuador's Coac Puellaro, and El Salvador's AMC.
Attacks by CeranaKeeper involved the deployment of the Mustang Panda-linked TONESHELL backdoor, a credential dumping tool, and a legitimate Avast driver before proceeding with the delivery of the WavyExfiller Python uploader for data gathering, the DropboxFlop payload, the Microsoft OneDrive REST API-exploiting OneDoor backdoor, and the BingoShell Python backdoor.
Confidential trading data exfiltrated from the U.S. companies' systems had been leveraged by Westbrook to amass $3.75 million in illicit profits from trades before over a dozen earnings announcements.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.