Hack Notice

Hack Notice: Thai securities trading firm goes offline after cyberattack

Thai securities trading firm goes offline after cyberattack

Source
https://www.databreaches.net/thai-securities-trading-firm-goes-offline-after-cyberattack/
Description
It seems that yet another group of threat actors are trying the double-extortion method, replete with trying to receive media coverage. “ALTDOS,” as they call themselves, contacted a number of news outlets in Thailand and online news sites to announce that they had attacked CGSEC on december 4. “A large Thailand readiness public listed troupe dealing with securities trading has been hacked with its sensitive financial + customer database stolen and files encrypted last friday (4th December 2020),” the hackers wrote, adding, “CGS deals with securities and financial trading services, however their servers are poorly protected.” Allegedly, as a result of the firm’s lack of acknowledgement of their emails and demands, the attackers decided to dump some data. As proof of their claims, the attackers posted on popular file-sharing sites some of the data they claim to have exfiltrated. looking at the fields for the different tables, there appears to be a lot of unencrypted personal and financial info of customers and employees. The web site of country group Securities, the victim company, was online last night when DataBreaches.net reached out to them for comment on the claimed attack, but does not appear to live online this morning. On their LinkedIn page, the firm describes themselves as: Through the provision of comprehensive research information, reliable sound advice, and exemplary client service, country group Securities is emerging as a prominent figure in the thai equity market. The institutional equity team, comprising of a diverse and experienced group of professionals, is dedicated to providing its clientele with excellent service and expertise. With a focus on the client, the institutional equity team is segregated into ii divisions; domestic and international, affording each node individual service and concentrated expert advice. in communications with DataBreaches.net, a representative for the hacker(s) says that their group’s targets are mainly in the finance or gambling industry. When asked what type of ransomware they were favoring, they responded: During the event of ransomware attacks, there are many cases in which data or files are rendered corrupted even after decryption. Hence, we do not favor the usage of ransomware and we usually do not employ ransomware techniques on targets. Our methodology is to prison-breaking into systems, rip the data and backup copies of their databases locally with AES-256 encryption. Commenting specifically on this victim, they wrote: It did surprised us that a listed securities trading companionship actually left their data unencrypted and their systems did not detect our access from a lean of suspicious black-listed IP addresses. We did prepared systems for heavy decryption jobs but apparently there wasn’t a demand for it….. There are many red flags about how this troupe protects its servers and its sensitive data. For example, the login credentials of its employee workstations are left unencrypted in single of the databases. A ransomware based group would have infected all of their workstations. The attackers inform DataBreaches.net that on December 5, the attackers emailed the directors of CSG and demanded 170 BTC from the firm (more than $3 million USD at today’s rates). We received no replies or negotiations till date and CGS has blocked our emails from their post servers. Obviously, we did expected a negotiation from their management, given the magnitude of the nag – especially the fact that all of their financial records and client’s sensitive information are already stolen. However, CGS management thinks they could cover up the hack and donjon things under wrap by ignoring our emails. The fact is we are allay able to bust into the systems after 6th December 2020. As noted above, since last night, the firm has reportedly taken their servers offline. If a response is received from them, this will be updated.

About HackNotice and Thai securities trading firm goes offline after cyberattack

HackNotice is a service that notices trends and patterns in publically available data so as to identify possible data breaches, leaks, hacks, and other data incidents on behalf of our clients. HackNotice monitors data streams related to breaches, leaks, and hacks and Thai securities trading firm goes offline after cyberattack was reported by one of those streams. HackNotice may also have the breach date, hack date, the hacker responsible, the hacked industry, the hacked location, and any other parts of the hack, breach, or leak that HackNotice can report on for the consumers of our product.

If you are a user of Thai securities trading firm goes offline after cyberattack their products, services, websites, or applications and you were a client of HackNotice, monitoring for Thai securities trading firm goes offline after cyberattack you may have been alerted to this report about Thai securities trading firm goes offline after cyberattack . HackNotice is a service that provides data, information, and monitoring that helps our clients recover from and remediate data breaches, hacks, and leaks of their personal information. HackNotice provides a service that helps our clients know what to do about a hack, breach, or leak of their information.

If Thai securities trading firm goes offline after cyberattack had a breach of consumer data or a data leak, then there may be additional actions that our clients should accept to protect their digital identity. data breaches, hacks, and leaks often lead to and cause identity theft, account have overs, ransomware, spyware, extortion, and malware. account takeovers are often caused by credential reuse, watchword reuse, easily guessed passwords, and are facilitated by the sharing of billions of credentials and other customer information through data leaks, as the direct resultant of data breaches and hacks.

HackNotice monitors trends in publically available data that indicates tens of thousands of data breaches each year, along with billions of records from data leaks each year. On behalf of our clients, HackNotice works to monitor for hacks that direct to lower client security and digital identities that have been exposed and should be considered vulnerable to attack. HackNotice works with clients to identify the extent that digital identities hold been exposed and provides remediation suggestions for how to handle each type of exposure.

HackNotice monitors the hacker community, which is a network of individuals that part data breaches, hacks, leaks, malware, spyware, ransomware, and many other tools that are often used for financial fraud, account take overs, and further breaches and hacks. HackNotice monitors the hacker community specifically for breaches, hacks, and data leaks that hurt consumers. HackNotice applies industry specific knowledge and advanced security practices to monitor for trends that indicate breaches, hacks, and exposed digital identities.

HackNotice also enables clients to apportion hack notices with their friend, family, and collogues to help increment awareness around alleged hacks, breaches, or data leaks. HackNotice works to provide clients with sharable reports to assist increase the surety of our clients personal network. The security of the people that our clients interact with directly impacts the raze of surety of our clients. Increased exposure to accounts that experience been taken over by hackers leads to further account take overs through phishing, malware, and other attach techniques.

If you found this nag notice to be helpful, then you may live interested in reading some additional hack notices such as:

I), trade secrets of corporations or intellectual property. Most data breaches involve overexposed anational governments to careless disposal of used computer equipment or data storehouse media and unhaccustomary for the offending party to attempt to mitigate indemnification by providing to the victim's subscr

Defacement http://quantrac.hatinh.gov.vn/zeb.gif

Defacement https://bibliotecaep.mil.pe/CR4P5.html

Defacement http://lalitpur.dolrm.gov.np/Ju.php