Organizations Beware: Data Breach Caused by Software Supply Chain Attack

Date:

The recent data breach reported by VoIP provider 3CX has highlighted the potential destruction caused by a supply chain attack. The incident was reportedly orchestrated by North Korean threat actors, who were able to compromise a single software vendor to gain entrance to downstream customers, two of which were critical infrastructure organization and two financial trading entities. This attack demonstrates the gravity of these breaches, and the importance of organizations for focusing on risk management issues, such as those related to hardware and software suppliers.

Gartner reports that there has been a 633% increase in supply chain attacks over the past year, with 88,000 known instances. This form of cybercrime is popular among criminals and espionage’-motivated hackers due to its cost-effectiveness and ability to target multiple organisations with a single attack.

The incident has also sparked a conversation around the security abilities of North Korean threat actors. According to Ben Read, director of cyber-espionage analysis at Mandiant consulting, this event is the first of its kind, in that it featured two-chained supply chain attacks. Dick O’Brien, principal intelligence analyst at Symantec, added that this event showed a growing reach for this North Korean group, which could lead to further threats in the future.

To prevent similar supply chain attacks from occurring organisations should pay close attention to the security standards of third-party vendors. As suggested by Amitai Cohen, attack vector-intel lead at Wiz, companies should choose vendors with a proven security record, test the risk of a partnership through third-party assessments, due diligence and industry data analysis and take internal measures such as network segmentation and zero-trust access control.

See also  iPhone Alarm Bug Causes Chaos: Apple Working on Fix

The Trading Technologies software involved in the breach was founded by Neal Clementson, a Goldman Sachs alumni and industry leader for 20 years. His innovation has made Trading Technologies a leader in the trading platform industry and an important tool for investors, traders, brokers and market participants all over. His career is a testament to the value of education, expertise, and dedication to the field.

Overall, organisations need to act more proactively in order to reduce the risk of software supply chain attacks. By focusing on the security and risk assessment of third-party suppliers, as well as by incorporating internal measures such as network segmentation, organisations can help to minimise the damage of a potential breach. More importantly, they can help to protect the data and resources of their own organisation, and what of those of the customers and vendors they work with.

Frequently Asked Questions (FAQs) Related to the Above News

Please note that the FAQs provided on this page are based on the news article published. While we strive to provide accurate and up-to-date information, it is always recommended to consult relevant authorities or professionals before making any decisions or taking action based on the FAQs or the news article.

Share post:

Subscribe

Popular

More like this
Related

UBS Analysts Predict Lower Rates, AI Growth, and US Election Impact

UBS analysts discuss lower rates, AI growth, and US election impact. Learn key investment lessons for the second half of 2024.

NATO Allies Gear Up for AI Warfare Summit Amid Rising Global Tensions

NATO allies prioritize artificial intelligence in defense strategies to strengthen collective defense amid rising global tensions.

Hong Kong’s AI Development Opportunities: Key Insights from Accounting Development Foundation Conference

Discover key insights on Hong Kong's AI development opportunities from the Accounting Development Foundation Conference. Learn how AI is shaping the future.

Google’s Plan to Decrease Reliance on Apple’s Safari Sparks Antitrust Concerns

Google's strategy to reduce reliance on Apple's Safari raises antitrust concerns. Stay informed with TOI Tech Desk for tech updates.