Cyberattack on Clorox Underlines the Critical Importance of Cybersecurity

several bottles of clorox on a shelf

Attention shoppers: The next time you search the grocery aisles for Clorox cleaning supplies, especially with flu season around the corner, you may find shelves emptier than expected. The reason? A recent cyberattack on Clorox.

This isn’t a tale of pandemic-induced shortages but a stark reminder of the risks unprepared companies face from cyber threats. On Aug. 11, Clorox discovered unauthorized activity on its IT systems. This cyber breach hit their infrastructure and forced them into manually processing orders, affecting product availability.

MGM Resorts, too, recently felt the brunt of a cyberattack, demonstrating that no company, big or small, is immune to these threats.

These incidents emphasize a few crucial points:

  1. The Risks of Unpreparedness: Not having robust cybersecurity measures can lead to significant disruptions, potentially leading to financial losses and loss of customer trust. Clorox, a household name, saw its operations grind nearly to a halt. It underscores that cyber threats are not just IT issues but business risks.
  2. Cyber Security Insurance: With hackers becoming more sophisticated, cyber insurance isn’t just a want; it’s a need. It can be the buffer your company needs to mitigate the fallout from a breach, covering everything from notification costs to potential legal claims.
  3. The Need for 24/7/365 Monitoring: This is where Managed Service Providers (MSPs) like WheelHouse IT come into the picture. We monitor your systems, ensuring any suspicious activities are caught early, minimizing potential damage.

Clorox’s woes might be making headlines now, but remember: any company, regardless of size, is vulnerable. With flu season on the horizon and consumer concerns rising, businesses can’t afford disruptions, especially self-inflicted ones from inadequate cybersecurity measures.

Don’t wait for a crisis to happen. Protect your company with the right tools, expertise, and insurance. Call WheelHouse IT to speak with an advisor today.

Intrusion Unveiled MGM Resorts Ransomware Saga and the Low-Hanging Fruit Conundrum

the las vegas sign is lit up at night

On September 8, 2023, MGM Resorts International, a colossal casino and hospitality sector force, was trapped in a relentless ransomware assault orchestrated by the notorious hacking conglomerate Scattered Spider.

This audacious breach sent shockwaves through MGM’s intricate web of systems and operations, casting a shroud of disruption that persisted for several harrowing days. The fallout rippled across MGM’s digital domain, wreaking havoc upon its website, mobile application, reservation infrastructure, and even the venerable slot machines gracing its casinos sprawled nationwide.

Scattered Spider, a nefarious organization with an unsettling penchant for manipulating human psychology, employed crafty social engineering strategies to infiltrate MGM’s corporate infrastructure. In a sinister twist, the hackers homed in on an unsuspecting employee prowling the professional network terrain of LinkedIn. This seemingly innocuous low-hanging fruit served as the conduit for their entry.

With this foothold, they brazenly dialed MGM’s help desk, leveraging this employee’s identity to gain unauthorized entry into the company’s sacred digital systems. Once inside, the nefarious hackers traversed the digital labyrinth, securing access to MGM’s most critical systems.

What Does this MGM Breach Mean?

This breach begs a troubling question: What treasures did these cyber hackers obtain from MGM’s digital databases during their malevolent raid? Scattered Spider, renowned for its audacious ransom demands, could hold stolen data as collateral, threatening data leaks as a grim ultimatum should MGM refuse to meet their unreasonable demands.

As the world speculates on MGM’s response to this digital siege, the company remains tight-lipped regarding whether a ransom was paid to Scattered Spider. Instead, they affirm their cooperation with law enforcement agencies in a relentless pursuit of justice and vow to fortify their cybersecurity efforts to foresee such insults in the future.

This MGM breach serves as a stark warning, highlighting the increasing menace of ransomware that casts its shadow indiscriminately upon businesses of all kinds. The evolving sophistication and frequency of ransomware incursions render it an ever more formidable adversary, necessitating vigilant safeguarding measures.

For businesses striving to armor themselves against this growing peril, consider the following strategies:

Educate employees

Illuminate your workforce on the dangerous art of social engineering and arm them with the knowledge to repel such tactics.

Fortify security controls

Implement robust defenses like multi-factor authentication and stringent access controls to ensure formidable digital security.

Data fortification

Regularly shuttle your data to secure repositories, erecting a protective defense against data loss.

Incident response

Prepare a meticulously detailed response plan should the dark threat of ransomware cast its shadow upon your enterprise.

The MGM breach also underscores the paramount importance of data privacy. Businesses must remain unwavering in their commitment to safeguarding their data, providing a resilient shield against the ever-looming specter of cyber attacks.

Now, let’s delve into the timeline of events that unfolded for MGM

 

Friday 9/8 – Saturday 9/9

During this critical timeframe, the threat actor executed a series of audacious maneuvers that led to their initial breach of MGM Resorts. Their tactics involved cunning social engineering tactics that successfully manipulated the IT help desk into unwittingly resetting a user account—a classic example of exploiting low-hanging fruit for nefarious purposes.

Furthermore, the adversary escalated their intrusion by securing privileges and granting domain controller access. They astutely exfiltrated credentials, subsequently employing their dark art to crack them. Adding to their arsenal, they claimed to have intercepted passwords during the synchronization process between Okta and, presumably, Active Directory.

In a disturbingly pivotal development, the threat actor acquired Okta super user access and Azure Global Admin privileges. This conquest provided them with near-complete control over the expansive digital terrain.

The precise extent of data obtained during these incursions remains uncertain, but the threat actor’s insidious presence was firmly established.

Regrettably, MGM Resorts’ initial attempts at containment proved futile during this phase.

Sunday 9/10

MGM Resorts initiated additional containment measures on this fateful day, desperately striving to expel the audacious adversary from their digital domain. However, these valiant efforts were met with stubborn resistance as the attacker tenaciously clung to their internal foothold.

Monday 9/11

The threat actor escalated their campaign of digital terror, purportedly encrypting over 100 ESXi hypervisors. It is crucial to note that these hypervisors are the bedrock upon which virtual machines are hosted, amplifying the impact across many servers. The attacker exploited vulnerabilities that often lurk in the periphery—a grim reminder of how the low-hanging fruit can serve as a conduit for a massive company attack.

In an ominous gesture, the threat actor provided a link, presumably giving access to a sample of the stolen data. Thus, heightening concerns about the gravity of the situation.

Tuesday 9/12 – Wednesday 9/13

In concert with external experts, MGM Resorts persisted in tireless efforts to contain and neutralize the threat. These pivotal days were marked by intensive incident response and recovery operations, aiming to reclaim control over their besieged digital infrastructure.

Simultaneously, the threat actor continued their vigilance, monitoring the negotiation portal for any signs of interaction. Their evident frustration at the lack of engagement hinted at their evil intentions.

Thursday 9/14

Undeterred and fearless, the threat actor seized the digital podium to present a staggering 1,101-word statement. In this message, they asserted their enduring control over the environment and made chilling threats of further attacks unless MGM Resorts initiated contact.

Aftermath of MGM Breach

Our collective hearts go out to the steadfast MGM team grappling with this relentless adversary throughout this complicated ordeal.

In the shadow of this evolving crisis, it becomes abundantly clear that managing an active attacker situation is a formidable challenge, defying simplistic solutions. Further, the threat actor’s sophistication far surpasses conventional ransomware groups, rendering the MGM team’s task extremely challenging.

For those of us observing and learning from this unfolding drama, it is paramount to recognize the underlying value of this information. Understanding the insidious techniques employed by such groups empowers us to fortify our security programs, evolving them to then counter these evolving threats.

Acknowledging that an impervious security program remains an idealistic notion is imperative. In the face of a determined adversary, a breach remains a possibility regardless of the defenses in place.

In the aftermath of the MGM Resorts International cyber breach by Scattered Spider, a notorious hacking group, our cybersecurity-focused IT company offers assistance to businesses facing similar threats. WheelHouse IT can educate your workforce on cyber threats, fortify security controls, safeguard your data, create incident response plans, and ensure data privacy. The MGM breach serves as a stark reminder of the need for robust cybersecurity.

Contact us to tailor our services to your organization’s needs and strengthen your digital defenses against evolving cyber threats. Don’t wait; secure your digital assets now to prevent future breaches.

The Top Cybersecurity Threats Facing South Florida Businesses In 2023

a person sitting at a desk in front of two computer monitors

Cybersecurity threats pose a serious risk to businesses in South Florida. In 2023, these threats are expected to be more advanced and sophisticated. Business owners need to understand the various cyber threats that could affect their operations and know how to mitigate them effectively. This article will discuss the top cybersecurity threats facing South Florida businesses in 2023 and provide recommendations on measures they can take to reduce their exposure.

The rapid development of technology has made it easier for attackers to exploit network vulnerabilities. There is an increased demand from malicious actors such as hackers and organized crime groups who seek to gain access to confidential information or disrupt services via digital means. As a result, companies must stay ahead of the latest trends and develop comprehensive strategies for protecting their data against potential intrusions.

In addition, several other risks related to human error need consideration when evaluating the threat landscape. For example, employees may fail to follow security protocols or accidentally share sensitive information with unauthorized individuals; this increases the chances of a breach, which can have devastating consequences for any organization. Businesses should have robust policies that outline acceptable use practices and appropriately address employee negligence.

Overview Of Cybersecurity Threats In 2023

As the digital world continues to expand, so do cybersecurity threats. South Florida businesses are particularly vulnerable due to their large population and increased tourism industry. Cybersecurity threats in 2023 for these businesses include ransomware attacks, phishing scams, and malware attacks.

Ransomware is malicious software designed to block access to data or systems until a ransom is paid. This attack has increased since 2019, with hackers targeting small to medium-sized companies often lacking proper security measures. Phishing scams involve emails from cybercriminals that appear legitimate but contain malicious links or attachments that can lead to stolen data or compromised accounts if opened. Malware attacks also occur when malicious code infiltrates a computer system without authorization, allowing attackers to gain control over computers and confidential information. These attacks have become increasingly sophisticated as cyber criminals use advanced techniques such as artificial intelligence (AI) and machine learning (ML). As a result, organizations in South Florida need to be aware of current trends to protect themselves against these threats adequately.

Ransomware: A Growing Risk For Businesses

As cyber threats become more sophisticated, businesses in South Florida are beginning to face a growing risk from ransomware. Ransomware is malicious software that holds data or systems hostage until the user pays a ransom. This attack can quickly cripple an organization’s operations and cause significant financial loss. Understanding how ransomware works and what organizations can do to protect themselves is critical for any business in South Florida in 2023.

Ransomware attacks typically involve social engineering tactics such as phishing emails or exploiting unpatched vulnerabilities on networks or applications. These attacks often operate with insider threats, zero-day exploits, or even brute force attacks, where hackers use automated tools to guess passwords repeatedly until they gain access to a system. Once inside the network, attackers encrypt valuable data and demand payment for unlocking the files. In some cases, the attacker may threaten further damage if their demands are unmet within a specific timeframe.

For businesses in South Florida looking to reduce their chances of falling victim to this kind of attack, there are several steps they can take:

  • Developing robust cybersecurity policies and procedures
  • Implementing strong authentication protocols
  • Keeping all devices up-to-date with the latest security patches
  • Educating employees about cybersecurity best practices

By taking these precautions, companies can ensure their data remains safe from malicious actors seeking to exploit them through ransomware attacks.

Phishing Scams And Social Engineering Attacks

Phishing scams and social engineering attacks are two of the most prominent cybersecurity threats facing South Florida businesses in 2023. They involve cybercriminals sending emails to unsuspecting victims that appear to be from a legitimate source, such as a bank or government agency, to obtain sensitive information like passwords or credit card numbers. Cybercriminals often use phishing to access an organization’s network and commit fraud or theft. Social engineering attacks involve gaining access to confidential data by manipulating victims into divulging personal details through maliciously crafted emails or phone calls. These cyberattacks can have severe consequences for organizations if not detected and addressed quickly. Organizations must ensure their systems are secure, regularly train employees on online security best practices, and implement strategies for detecting and responding to potential cyber threats before they become significant issues.

The Dangers Of Malware Attacks

Malware attacks will be a significant threat to South Florida businesses in 2023. Malware, short for malicious software, is defined as any computer program that could be detrimental to the network or stored data. Attackers can use it to gain access to confidential information and disrupt operations. Examples of malware include viruses, worms, spyware, Trojans, and ransomware.

The consequences of malware attacks can vary depending on the type of attack and its severity; however, common risks include system downtime, financial losses due to theft or corruption of data, reputational damage, and legal liability. Businesses should protect themselves from such threats through preventive measures like antivirus solutions and employee training on cybersecurity best practices. Additionally, they need incident response plans to react quickly if a breach occurs.

Insider Threats To Consider

While malware attacks will severely threaten South Florida businesses in 2023, the risks posed by malicious insiders should not be ignored. Insider threats come from current or former employees, contractors, and third-party vendors who access an organization’s internal networks and systems. Such threats can range from careless mistakes that compromise data security to intentional sabotage.

The following list outlines four potential insider threats facing organizations in South Florida:

  1. Unintentional misuse – Employees may unintentionally click on malicious links or download malicious files due to a lack of awareness about cyber security protocols.
  2. Malicious intent – Current and former employees with privileged access may attempt to steal confidential data for financial gain or other reasons.
  3. Human error – Staff members could mistakenly share sensitive information with unauthorized personnel through email attachments or verbal communication.
  4. Insufficient IT controls – Organizations may lack sufficient policies and procedures related to user account management and access control, making it easier for malicious actors to exploit system vulnerabilities.

Insider threats must be taken seriously since they can cause significant damage if left unchecked. Companies must develop robust strategies around user education, monitoring tools, incident response plans, and risk assessment processes to protect their businesses against such risks.

Understanding Zero-Day Exploits

Zero-day exploits are a primary cyber security concern. They refer to vulnerabilities in computer systems, applications, or software that the manufacturer or vendor has not yet detected. Thus, they can be exploited by attackers before they can be patched. Zero days also affect mobile devices through mobile apps and desktop computers. In addition, zero-day attacks often leverage existing malware, such as Trojans and other malicious code, to access a system. As these threats remain primarily undetected, it is difficult for businesses to defend against them effectively.

One way to reduce risk from zero-day exploits is to use application allow listing technology that only allows approved programs and applications to run on the company’s IT infrastructure. Additionally, organizations should regularly patch their systems with the latest security updates vendors release. However, this may still leave some unknown vulnerabilities open for attack if not done in time.

Organizations should additionally consider implementing multi-factor authentication processes. Therefore, users will require multiple forms of identification when attempting to access sensitive data or networks. Finally, companies must ensure their staff is educated on best practices related to cybersecurity. Thus can identify suspicious activity quickly and mitigate any potential risks associated with zero-day threats.

Don’t Face The Threat Alone

As a managed IT services provider based in South Florida, WheelHouse IT recognizes the critical need for businesses to safeguard their networks and data against cyber threats in 2023. It is no longer a question of if companies will face such threats but when. To protect against these threats, businesses must take proactive steps. This includes encrypting sensitive information, training employees on cybersecurity awareness, and staying up-to-date on emerging trends.

WheelHouse IT understands that implementing a comprehensive security plan may be challenging for small-to-medium enterprises. This could be due to budget constraints or a lack of technical expertise. However, it is still possible to enhance security levels through basic practices such as patch management and user access control. Moreover, partnering with experienced IT professionals may be an alternative to costly in-house solutions when more complex solutions are needed.

In a ransomware attack, businesses should have an action plan ready. That is why WheelHouse IT emphasizes the importance of establishing preventive measures. As threats evolve, today’s best practices may be insufficient tomorrow. Thus, businesses in South Florida must remain vigilant and proactive in their approach to cybersecurity.

By evaluating existing procedures and policies carefully and adopting new, innovative technologies, businesses in South Florida can protect their assets and keep them secure for years to come. With WheelHouse IT as a trusted partner, companies have the resources necessary to maintain a safe and secure operating environment.

Email Encryption for HIPAA Compliance

a person sitting on a couch using a laptop computer

Email encryption is a method that converts data that is readable into something that is not readable in the hope of preserving the privacy of the data. If used in conjunction with HIPAA security measures, email encryption could assist in protecting the privacy and security of PHI (Protected Health Information). This article will explain how to utilize email encryption to achieve HIPAA compliance by covering its fundamentals. We’ll also provide a list of HIPAA-compliant email providers to compare. 

Email Encryption to Achieve HIPAA Compliance

Here are some ways that you can utilize encryption in the email to ensure HIPAA compliance:

  • Use popular and HIPAA-compliant email services that secure messages in transit and at rest.
  • Ensure that you secure the message using high-level encryption techniques, such as obtaining HIPAA certification.
  • Limit access to the individuals who can receive and send emails that contain PHI.
  • Limit access to audit logs to stop unauthorized access to PHI.
  • Allow two-factor authentication to provide more security.
  • Inform staff about HIPAA compliance guidelines and procedures, email compliance, and email rules, such as encryption for emails and secure web and online forms.

Following HIPAA guidelines regarding email compliance and rules and these additional steps will ensure PHI transmitted via email stays private and secure. HIPAA-compliant secure email services provide the required tools and features to ensure your PHI is protected and kept safe when sent via email.

The HIPAA Compliance Checklist

HIPAA compliance requires companies to follow the best practices in managing PHI. The HIPAA Compliance Checklist can help ensure that all HIPAA obligations are met and that PHI is secured. 

Here’s a list of technical safeguards for HIPAA Compliance: 

  1. Implement physical, administrative, and technological safeguards to safeguard the privacy and security of PHI.
  2. Create HIPAA guidelines and procedures to ensure conformity with HIPAA regulations regarding email communications.
  3. Train staff on HIPAA policies, procedures, and security guidelines.
  4. Use access control measures to restrict who has access to PHI.
  5. Secure email encryption is recommended for all email accounts that contain PHI.
  6. Check systems for any unauthorized access to or use of PHI.
  7. Set up audit controls to track and record HIPAA-related activity.
  8. Update regularly HIPAA policies, procedures, guidelines, and security.
  9. Ensure HIPAA Compliance is maintained by conducting periodic audits and risk assessments.
  10. Create an email notification for breach of procedure system to notify via email reports of any unauthorized access to or disclosure of PHI.

What are the HIPAA-compliant email providers?

HIPAA-compliant email service providers include those that satisfy the specifications of HIPAA to protect the privacy and security of PHI. These providers offer security features (email encryption software) like encryption in transit, in-the-middle users’ authentication, granular audit trails, and access control to safeguard against unauthorized access.

There are several HIPAA-compliant email service providers available, including: 

  • Microsoft Office 365 HIPAA/HITECH-compliant plans
  • Google G Suite HIPAA or Google Workspace/HITECH-compliant plans
  • Proof point HIPAA Compliant Email Services and Encryption
  • Six HIPAA Compliant Email Services and File Encryption
  • Iron Core HIPAA Compliant Email Service and File Encryption

With these HIPAA-compliant email and email archiving service providers, you can be sure that all personal health information is secure and encrypted when sent via email. You can sign-up for a 30-day free trial with these popular email applications before choosing which email platform suits you best.

Having HIPAA-Compliant Secure Email Providers Is Only A Part Of HIPAA Compliance

 HIPAA-compliant email service is only one aspect of HIPAA compliance. HIPAA stipulates that all PHI is kept safe and protected throughout the day. Alongside HIPAA-compliant secure email services, companies must also have guidelines and policies that ensure the privacy and security of email content, especially that of PHI. This includes access control, user authentication, data backup, and disaster recovery procedures. HIPAA also requires companies to perform regular HIPAA risk assessments to determine any vulnerabilities that could be present within their systems.

What is PHI? And why is it essential to secure it?

PHI refers to any protected health information that could be used to identify the patient. Additionally, HIPAA stipulates that all PHI must be secured and private, and encryption of emails is among the most efficient methods to ensure this.

Utilizing HIPAA-compliant email services and encryption techniques, you can ensure your personal information is safe in transit and storage. This ensures the fullest extent of HIPAA compliance standards is met and PHI is kept secure and private.

How does PHI get encrypted during the entire process?

HIPAA-compliant email services use different encryption methods to add an extra layer of security to ensure the privacy and security of PHI.It is used during transit (i.e., while data moves between computers) and at rest (i.e. when saved on different storage devices).

Encryption In Transit

The process of encryption in transit can be described as the act of encryption data as it is moved from one system to the next. This ensures that any PHI sent from one email address to other email recipients remains safe while traveling across networks. HIPAA-compliant secure email services use encryption methods, such as TLS (Transport Layer Security) and SSL (Secure Socket Layer), to safeguard PHI during transport.

Encryption At Rest

“Encryption at rest” refers to the process stored on storage devices or email archives, such as computers. HIPAA-compliant secure email services use various encryption methods like AES 256-Bit Encryption (Advanced Security Standard for Encryption) and PGP (Pretty Good Privacy) to safeguard the privacy of PHI while it is in storage or email archiving.

Who is covered by HIPAA?

Per HIPAA, “Covered Entities” must comply with HIPAA compliance requirements for handling PHI and observing transmission security. The covered entities include:

  • Healthcare Industry and Healthcare Organizations
  • Healthcare professionals (e.g., hospitals and physicians)
  • Health plans (e.g., insurance companies as well as HMOs)
  • Associate business (e.g., suppliers who provide solutions to entities covered)
  • Any company that handles PHI is a Covered Entity and must comply with HIPAA regulations.

This means using HIPAA-compliant secure email services for all addresses communicating PHI. It also includes implementing encryption techniques to ensure the privacy and security of all PHI.

How can an entity violate HIPAA?

HIPAA considers any unauthorized access to or disclosure of PHI a violation. HIPAA-compliant secure email services are designed to prevent such breaches by encrypting data during transit and storage.

Examples of HIPAA violations are: 

  • Sending unencrypted emails containing PHI
  • Use of unencrypted email addresses in transmitting PHI
  • People store unencrypted PHI on storage devices such as computers or devices
  • Unauthorized use of secure email addresses and access to PHI

The consequences of these violations could be penalties, fines, and even criminal charges for both organizations and individuals. When you utilize HIPAA-compliant secure email services, you can ensure your private information is kept secure and protected throughout the day.

Penalties For HIPAA Non-Compliance

The penalties for violating HIPAA could be very extreme. HIPAA violations could result in criminal and civil penalties, including as high as $1.5 million in fines for each instance. Additionally, HIPAA regulations may oblige organizations to offer breach notification services for affected patients, which could be costly and long-winded.

IT Support’s Role In HIPAA Compliance

IT support plays a crucial role in ensuring HIPAA compliance by implementing HIPAA-compliant email services, encryption techniques, and additional security methods following the business associate agreement. Professionals assist businesses in adhering to HIPAA standards to protect the security of PHI.

Additionally, they can offer guidelines on using HIPAA-compliant secure email services to secure emails containing PHI and guarantee HIPAA compliance. Including IT support is essential for HIPAA compliance.

WheelHouse IT provides HIPAA-compliant email solutions to help companies achieve HIPAA regulations and safeguard their personal information. We provide various solutions, such as email encryption access control, encryption, and loss prevention for data to ensure that PHI remains safe and secure throughout the day in compliance with the business associate agreement. 

WheelHouse IT As Your Partner In HIPAA Compliance

WheelHouse IT provides HIPAA-compliant email services and encryption solutions to businesses that require a safe method of sending, receiving, and saving PHI while respecting the business associate agreement. We employ the most recent encryption techniques, including TLS and SSL for emails in transit, AES 256-bit encryption, and PGP for data at rest. Additionally, we ensure HIPAA conformity requirements are met by taking extra steps.

The services we offer include the following:

  • HIPAA-compliant email encryption
  • Controlling access and authentication
  • Data loss prevention
  • Secure storage of PHI under the business associate agreement
  • Support and maintenance of HIPAA compliance 

We also provide consulting and training services that help businesses understand HIPAA regulations, use HIPAA-compliant email services, and ensure HIPAA compliance.

Contact us for more details about HIPAA-compliant email solutions from WheelHouse IT. We can help you attain HIPAA compliance and also ensure the privacy and security that you have of your PHI.

We look forward to working with you throughout the HIPAA conformance journey!