The Week in Cyber Security and Data Privacy: 25 – 31 March 2024

37,376,751 known records breached in 2,109 newly disclosed incidents

Welcome to this week’s global round-up of the biggest and most interesting news stories.

At the end of each month, these incidents – and any others that we find – will be used to inform our monthly analysis of data breaches and cyber attacks.


Publicly disclosed data breaches and cyber attacks: in the spotlight

Researchers find thousands of publicly exposed – and compromised – Ray servers

The Oligo Security research team have discovered an attack campaign targeting a critical vulnerability in Ray – an AI framework developed and maintained by Anyscale – for the past seven months.

This vulnerability is one of five disclosed to Anyscale in late 2023. The company addressed four of the vulnerabilities, but this one – CVE-2023-48022 – remains disputed and therefore unpatched. As such, many teams and tools aren’t aware of, or concerned about, it.

However, Oligo’s researchers discovered this vulnerability has already been exploited in the wild, meaning that “thousands of publicly exposed Ray servers all over the world were already compromised as a result of this new vulnerability, dubbed ShadowRay”.

According to Anyscale’s website, some of the organisations using Ray include OpenAI, Uber, AWS (Amazon Web Services), Cohere, Ant Group, Instacart and Samsara.

According to Oligo’s research team, the vulnerability “allows attackers to take over the companies’ computing power and leak sensitive data”.

Data breached: unknown.

More than 19 million users’ data breached in info stealer malware campaign

What is apparently the “largest infostealer malware campaign targeting gamers/cheaters in history” has affected millions of gamers, including around 14,000,000 Discord users and 3,662,647 Battle.net (from Blizzard Entertainment) users.

Other affected domains include Activision, elitepvpers, UnKnoWnCheaTs, Phantom Overlap, ACDiamond, ArtificialAiming, two EngineOwning domains, iNIUARIA Cheats and GameSense.

Note that, although most affected domains are cheating forums, the malware itself wasn’t in cheat software.

Data breached: 19,126,976 users’ data.

Change Healthcare acknowledges data stolen in February’s cyber attack

Change Healthcare (of UnitedHealth Group) confirmed a cyber attack in February. It’s now publicly acknowledged that data was stolen during that attack, and is now analysing the types of data – including personal, financial and health information – compromised.

The ransomware group ALPHV/BlackCat claimed to have exfiltrated 6 TB of data from Change Healthcare. If true, this is a relatively small amount in the context of the organisation apparently processing 15 billion transactions annually.

Data breached: 6 TB.


Publicly disclosed data breaches and cyber attacks: full list

This week, we found 37,376,751 records known to be compromised, and 2,109 organisations suffering a newly disclosed incident. “Thousands” of them – which we’ve logged as 2,000 – are attributed to the publicly exposed Ray servers, as discussed above.

2,092 of organisations disclosing a new incident this week are known to have had data exfiltrated, exposed or otherwise breached. Only 1 definitely hasn’t had data breached.

We also found 14 organisations providing a significant update on a previously disclosed incident.

Organisation(s)SectorLocationData breached?Known data breached
Discord
Source 1; source 2
(New)
SoftwareUSAYes14,000,000
Change Healthcare
Source 1; source 2
(Update)
HealthcareUSAYes6 TB
Battle.net (Blizzard Entertainment)
Source
(New)
LeisureUSAYes3,662,647
NHS Dumfries & Galloway
Source 1; source 2
(Update)
HealthcareUKYes3 TB
Harvard Pilgrim Health Care
Source 1; source 2
(Update)
HealthcareUSAYes2,860,795
NADRA
Source
(New)
IT services PakistanYes2,700,000
Sysmex Corporation
Source
(New)
ManufacturingJapanYes1,164,827
Juniper Education
Source
(New)
SoftwareUKYes864,603
Ejercito del Perú
Source 1; source 2
(New)
DefencePeruYes763.8 GB
Atraf
Source 1; source 2
(Update)
SoftwareIsraelYes669,672
Qosina
Source
(New)
ManufacturingUSAYes638 GB
EMSA (Emergency Medical Services Authority)
Source 1; source 2; source 3
(Update)
HealthcareUSAYes611,743
Accor
Source
(New)
HospitalityFranceYes596,000
UnKnoWnCheaTs
Source
(New)
Non-profitUnknownYes572,831
Activision
Source
(New)
LeisureUSAYes561,183
Big Issue
Source 1; source 2
(New)
MediaUKYes550 GB
Chattanooga Heart Institute
Source 1; source 2
(Update)
HealthcareUSAYes547,434
Houser LLP
Source 1; source 2
(Update)
LegalUSAYes364,312
FICO
Source
(New)
SoftwareUSAYes170,000
Rent Go
Source
(new)
TransportTurkeyYes>161,000
Scullion Law
Source
(New)
LegalUKYes155 GB
Elitepvpers
Source
(New)
LeisureMexicoYes117,366
EngineOwning (two domains)
Source
(New)
LeisureUAEYes85,360
BLOG (website for cheaters)
Source
(New)
LeisureUnknownYes67,152
Select Education Group, LLC
Source
(New)
EducationUSAYes>67,000
Contender Boats, Inc
Source
(New)
ManufacturingUSAYes65 GB
Bayer Heritage Federal Credit Union
Source 1; source 2
(Update)
FinanceUSAYes61,165
LC Waikiki
Source
(New)
RetailEgyptYes60,000
Ezras Choilim Health Center
Source 1; source 2
(New)
HealthcareUSAYes59,861
ECB (England & Wales Cricket Board)
Source 1; source 2
(Update)
LeisureUKYes43,299
Prudential Insurance Company of America
Source
(New)
InsuranceUSAYes36,545
Pembina County Memorial Hospital
Source
(New)
HealthcareUSAYes23,451
ArtificialAiming
Source
(New)
LeisureUnknownYes21,564
GameSense
Source
(New)
LeisureUnknownYes18,465
iNIURIA Cheats (DigitalWorks GmbH)
Source
(New)
LeisureGermanyYes14,181
Ethos
Source
(New)
Non-profitUSAYes13,418
Pomona Valley Hospital Medical Center
Source 1; source 2
(New)
HealthcareUSAYes13,345
Rancho Medical Family Group
Source 1; source 2; source 3
(Update)
HealthcareUSAYes10,480
Gunster Yoakley and Stewart PA
Source 1; source 2
(New)
LegalUSAYes9,550
Multiple government entities and private energy companies in India
Source
(New)
Public and energyIndiaYes8.81 GB
Wyndemere Senior Living
Source
(New)
HealthcareUSAYes6,846
Donald W. Wyatt Detention Facility
Source 1; source 2
(Update)
PublicUSAYes5,760
Northern Virginia Oral, Maxillofacial & Implant Surgery
Source
(New)
HealthcareUSAYes5,568
ACDiamond
Source
(New)
LeisureUAEYes3,818
Shivaji College
Source
(New)
EducationIndiaYes3,651
Sanford, Pierson, Thone & Strean, PLC
Source
(New)
LegalUSAYes3,100
Battle Mountain General Hospital
Source 1; source 2
(New)
HealthcareUSAYes3,000
Western New York Independent Living
Source 1; source 2
(New)
HealthcareUSAYes2,886
Barings (via Infosys McCamish Systems)
Source
(New)
FinanceUSAYes2,671
Kids Care Dental & Orthodontics
Source 1; source 2; source 3
(Update)
HealthcareUSAYes2,260
BodyHealth, LLC
Source
(New)
HealthcareUSAYes2,222
Sierra Lobo, Inc.
Source
(New)
ManufacturingUSAYes1,991
GH America
Source
(New)
Non-profitUSAYes1,802
Reyes Automotive Group
Source 1; source 2
(New)
ManufacturingUSAYes1,660
Bronson Healthcare
Source 1; source 2
(New)
HealthcareUSAYes1,597
Phantom Overlay
Source
(New)
LeisureUnknownYes1,365
Permian Resources
Source 1; source 2
(New)
EnergyUSAYes1,351
RN (website for cheaters)
Source
(New)
LeisureUnknownYes1,044
Cherry Health
Source 1; source 2
(New)
HealthcareUSAYes500
Cornerstone Healthcare Group Management Services LLC
Source 1; source 2
(New)
HealthcareUSAYes500
Southwest Binding & Laminating
Source 1; source 2
(Update)
Professional servicesUSAYes341
Southern Nevada Health District
Source
(New)
PublicUSAYes300
Saco River Medical Group, PC
Source
(New)
HealthcareUSAYes64
July Business Services
Source
(New)
FinanceUSAYes59
Coeur d’Alene, City of
Source
(New)
PublicUSAYes57
Regency Media
Source
(New)
LeisureAustraliaYesUnknown
The Star Entertainment Group
Source
(New)
LeisureAustraliaYesUnknown
Summer Fresh Salads Inc.
Source
(New)
ManufacturingCanadaYesUnknown
BSR Infratech India Ltd.
Source
(New)
ConstructionIndiaYesUnknown
CurioInvest
Source
(New)
CryptoLiechtensteinYesUnknown
DEBATE
Source
(New)
MediaMexicoYesUnknown
Europol
Source
(New)
LegalNetherlandsYesUnknown
Poh Heng Jewellery Pte Ltd
Source
(New)
RetailSingaporeYesUnknown
Nampak
Source
(New)
ManufacturingSouth AfricaYesUnknown
Ayuntamiento de Torre Pacheco
Source
(New)
PublicSpainYesUnknown
Cressex Community School
Source
(New)
EducationUKYesUnknown
Delta Pipeline, Inc.
Source 1; source 2
(New)
ConstructionUSAYesUnknown
OWASP® Foundation
Source
(New)
Cyber securityUSAYesUnknown
Baylor College of Medicine
Source
(New)
EducationUSAYesUnknown
Burnham Wood Charter Schools
Source
(New)
EducationUSAYesUnknown
Florida Memorial University
Source
(New)
EducationUSAYesUnknown
Groton Public Schools
Source 1; source 2
(Update)
EducationUSAYesUnknown
Tech-Quip Inc
Source
(New)
EnergyUSAYesUnknown
Orange County’s Credit Union
Source 1; source 2
(New)
FinanceUSAYesUnknown
Performance Health Technology
Source 1; source 2
(New)
HealthcareUSAYesUnknown
Trustpoint Rehabilitation Hospital of Lubbock
Source
(New)
HealthcareUSAYesUnknown
Alamo Insurance Group, Inc.
Source 1; source 2
(New)
InsuranceUSAYesUnknown
LoDan Electronics, Inc.
Source
(New)
ManufacturingUSAYesUnknown
Affinity Health Services
Source 1; source 2
(New)
Professional servicesUSAYesUnknown
KTUA Landscape Architecture and Planning
Source 1; source 2
(New)
Professional servicesUSAYesUnknown
Township of Haverford
Source
(New)
PublicUSAYesUnknown
White Oak Partners
Source
(New)
Real estateUSAYesUnknown
Pennsylvania Southeast Conference U C C
Source
(New)
ReligiousUSAYesUnknown
Hot Topic
Source 1; source 2
(New)
RetailUSAYesUnknown
Timberland
Source
(New)
RetailUSAYesUnknown
Anyscale and thousands of organisations using Ray
Source
(New)
Software and otherUSA and otherYesUnknown
Top.gg Discord bot community
Source
(New)
SoftwareUSAYesUnknown
VNDIRECT Securities Corporation
Source
(New)
FinanceVietnamYesUnknown
Munchables
Source
(New)
CryptoUnknownYesUnknown
Prisma Finance
Source
(New)
CryptoUnknownYesUnknown
University of Winnipeg
Source
(New)
EducationCanadaUnknownUnknown
St Paul’s Co-educational College
Source
(New)
EducationHong KongUnknownUnknown
Operational Research Society of India
Source
(New)
EducationIndiaUnknownUnknown
New Zealand Parliamentary Service and  Parliamentary Counsel Office
Source 1; source 2
(New)
PublicNew ZealandUnknownUnknown
Statistični urad Republike Slovenije
Source
(New)
PublicSloveniaUnknownUnknown
Website of President Nataša Pirc Musar
Source
(New)
PublicSloveniaUnknownUnknown
The University of Manchester
Source
(New)
EducationUKUnknownUnknown
University of Wolverhampton
Source
(New)
EducationUKUnknownUnknown
Clinical School Computing Service
Source
(New)
IT servicesUKUnknownUnknown
Communication Workers Union
Source
(New)
Professional servicesUKUnknownUnknown
YASNO
Source
(New)
EnergyUkraineUnknownUnknown
Traverse City Area Public Schools
Source
(New)
EducationUSAUnknownUnknown
City of St. Cloud, FL
Source
(New)
PublicUSAUnknownUnknown
Gilmer County Government
Source
(New)
PublicUSAUnknownUnknown
An ASEAN-affiliated entity
Source
(New)
PublicUnknown (likely Cambodia, Laos or Singapore)UnknownUnknown
Philippine Coast Guard Auxiliary
Source
(New)
Non-profitPhilippinesNo0

Note 1: ‘New’/‘Update’ in the first column refers to whether this breach was first publicly disclosed this week, or whether a significant update was released this week. The updated data point is italicised in the table.

Note 2: For incidents where we only know the file size of the data breached, we use the formula 1 MB = 1 record. Given that we can’t know the exact numbers, as it depends on the types of records included (e.g. pictures and medical histories are considerably larger files than just names and addresses), we err on the side of caution by using this formula. We believe that this underestimates the records breached in most cases, but it is more accurate than not providing a number at all. To learn more about our research methodology, click here.


AI

UK Artificial Intelligence (Regulation) Bill progresses to Lords committee stage

The House of Lords read the UK Artificial Intelligence (Regulation) Bill for a second time on 22 March, and have progressed the Bill to the committee stage. This blog explains in more detail how a bill becomes law.

Researchers reveal new quantum AI model that allegedly identifies 100% of attacks

Multiverse Computing and CounterCraft have revealed a new quantum AI model: the MPS (Matrix Product State) model. It’s been trained on data sets from real network traffic and system logs, and “significantly improves” attack detection compared to traditional methods, supposedly identifying 100% of cyber attacks.

US OMB issues first government-wide policy to mitigate risks and harness benefits of AI

Vice President Harris announced that the White House OMB (Office of Management and Budget) is issuing its first government-wide policy to mitigate the risks, and harness the benefits, of AI. This delivers on a key element of President Biden’s Executive Order on safely developing and using AI.

The OMB’s new policy is aimed at federal agencies, and looks to “strengthen AI safety and security, protect Americans’ privacy, advance equity and civil rights, stand up for consumers and workers, promote innovation and competition, advance American leadership around the world, and more”.


Enforcement

Sellafield to be prosecuted for alleged IT security offences between 2019 and 2023

The UK’s nuclear safety regulator – the ONR (Office for Nuclear Regulation) – has notified the nuclear site Sellafield that it’ll face prosecution under the Nuclear Industries Security Regulations 2003 for alleged IT security offences between 2019 and 2023.

Sellafield was reportedly hacked by cyber groups “closely linked to Russia and China”.

European Commission started investigation into Meta’s “pay or consent model”

The European Commission has opened proceedings again Meta’s “pay or consent model” – alongside Alphabet’s rules on steering in Google Play and self-preference on Google search, and Apple’s rules on steering in the App Store – under the DMA (Digital Markets Act).

The Commission is “concerned” that the “binary choice” of Meta’s model “may not provide a real alternative in case users do not consent, thereby not achieving the objective of preventing the accumulation of personal data by gatekeepers”.

EU and South Korea reaffirm partnership on cyber security, AI and other areas

In a second digital partnership council, the EU and South Korea reaffirmed their commitment to cooperating in “key digital technologies”, including cyber security, AI, quantum technology, platforms, semiconductors, 5G and beyond, and “defined other areas of cooperation such as network connectivity”.

Med-Data settles data breach lawsuit for $7 million

The Texas-based revenue cycle management company Med-Data has agreed to a $7 million (about £5.6 million) settlement to resolve a breach from 2018–2019, involving the health data of around 136,000 people.


Recently published reports


Other news

At least 17,000 Microsoft Exchange servers in Germany critically exposed

The BSI (Bundesamt für Sicherheit in der Informationstechnik; the German Federal Office for Information Security) warned that at least 37% of Microsoft Exchange servers in Germany (so at least 17,000) are vulnerable to at least one critical security vulnerability.

US DoD established new office: the Office of the Assistant Secretary of Defense for Cyber Policy

The US Department of Defense established a new office – the OASD(CP), or Office of the Assistant Secretary of Defense for Cyber Policy – on 20 March.

The ASD(CP) – Assistant Secretary of Defense for Cyber Policy – is responsible for “all matters related to cyber-related activities that support or enable DoD missions in, through, and from cyberspace”.

Proposed amendment to the US Cyber Incident Reporting for Critical Infrastructure Act of 2022

The US Department of Homeland Security has filed a draft to amend the CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act of 2022). The amendment requires CISA (Cybersecurity and Infrastructure Security Agency) to “promulgate regulations implementing the statute’s covered cyber incident and ransom payment reporting requirements for covered entities”.

The proposed rule is currently unpublished – the scheduled publication date is 4 April. CISA invites comments on the proposal until 60 days after publication.


Key dates

31 March 2024 – PCI DSS v4.0 transitioning deadline 

Version 3.2.1 of the PCI DSS (Payment Card Industry Data Security Standard) was retired on 31 March and replaced by version 4.0 of the Standard.

30 April 2024 – ISO/IEC 27001:2013 certification unavailable

Certification bodies must stop offering (re)certification to ISO 27001:2013 by 30 April. The new iteration of the Standard, ISO 27001:2022, isn’t significantly different from ISO 27001:2013, but there are some notable changes. Learn more about complying with ISO 27001:2022.


That’s it for this week’s round-up. We hope you found it useful.

We’ll be back next week with the biggest and most interesting news stories, all rounded up in one place.

In the meantime, if you missed it, check out last week’s round-up. Alternatively, you can view our full archive.


Security Spotlight

To get news of the latest data breaches and cyber attacks straight to your inbox, subscribe to our weekly newsletter: the Security Spotlight.

Every Wednesday, you’ll get a 4-minute email with:

  • Industry news, including this weekly round-up;
  • Our latest research and statistics;
  • Interviews with our experts, sharing their insights and expertise;
  • Free useful resources; and
  • Upcoming webinars.