Back To Resource Center

Published: April 7, 2023

Security 3-2-1 Week of 4/7/23

By Annie articles

3 Interesting Articles

Novel social engineering attacks soar 135% amid uptake of generative AI
IT Pro: There’s been a 135% increase in novel social engineering attack emails since January 2023. Researchers from Darktrace say that corresponding with the widespread adoption of ChatGPT, email attacks targeted thousands of its customers in January and February. These attacks use “sophisticated linguistic techniques” that make it harder for humans to detect malicious emails.The current pattern indicates that the use of generative AI tools, like ChatGPT, is enabling bad actors to create advanced and precise attacks rapidly and on a large scale. It has become insufficient for humans to solely rely on their intuition and training to prevent hackers from causing damage. It may be imperative for organizations to equip themselves with AI that possesses a deeper understanding of their systems than the hackers themselves.

Justice Dept. Seizes Over $112M in Funds Linked to Cryptocurrency Investment Schemes, With Over Half Seized in Los Angeles Case
Department of Justice: The Department of Justice announced that it has seized six cryptocurrency accounts worth more than $112 million, all linked to pig butchering scams. One single crypto account in California accounted for $66.4 million, accumulated from 10 victims. These schemes represent $2.57 billion in losses just in 2022, a 183% increase since 2021. The scam works by buttering up people (hence the term, pig butchering) for weeks or even months to gain the victim’s trust. Once trust is built, fraudsters eventually convince the victims to make investments in fake cryptocurrency trading platforms. While the victim appears to make gains in their portfolio, in reality the money goes directly to the virtual pockets of the scammers. The good news is that the money most recently seized will be returned to the victims.

Western Digital says hackers stole data in ‘network security’ breach
Tech Crunch: Business operations for data storage giant Western Digital, the company behind data storage brands such as SanDisk, WD and WD_Black, have been disrupted due to a systems breach on March 26. The company stated that hackers gained access to a number of its internal systems and suggests that it may be linked to ransomware. Their service status website confirms that the hack took down its My Cloud network-attached storage (NAS) service which allows customers to access their files from the internet.The company is working to restore infrastructure and services and the incident does not seem to be connected to a major ransomware group.

2 Stats You Should Know

57% of companies don’t back up all of their SaaS data. (source)

81% of Americans feel that they have little or no control over the data that is collected about them by companies. (source)

1 More Thing

If you missed our Privacy in 2023 webinar with Dr. Maxine Henry, CEO at Cyvient and a leading privacy expert, check out the recording. Thank you to our attendees for the great conversation and here’s the video for those who couldn’t join!

Our large and diverse network of experts is here to help...

Charles M.

Principal

Charlies is a 14 year cyber security expert. He started his career in the U.S. armed forces and then transitioned into commercial roles. A security engineer by training, he's well-versed in tool deployment and administration.

Ellen K.

GRC Expert

Ellen bring a decade of GRC expertise to the TalPoint community. She's knowledgeable on a variety of frameworks and employs a methodical approach to compliance. She's available for needs assessments, gap assessments, internal audits, and for certain frameworks running independent 3rd party audits.

Zachary C.

Founder and CRO

Zachary bring a 20+ year career in risk management to the TalPoint community. He's worked across healthcare, finance, and supply chain manufacturing. His broad experience offers both a holistic view of risk as well as a common sense approach to risk management.