News: 1658869484

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Culture shock: Ransomware gang sacks arts orgs' email lists

(2022/07/26)


A ransomware gang has not only taken down WordFly, a mailing list provider for top arts organizations among others, but also siphoned data belonging to the US-based Smithsonian, Canada's Toronto Symphony Orchestra, and the Courtauld Institute of Art in London.

As of right now, WordFly's main website is unavailable, and has been offline for the past two weeks. "Please plan accordingly if you need to send email before Aug. 1," the firm [1]advised on a separate site. WordFly is one of those companies that takes care of sending out mass emails, typically marketing messages, to customers who sign up for said bumf.

In an update about the ongoing outage, WordFly exec Kirk Bentley said the outfit's engineering team discovered a network disruption on July 10. "The incident was propagated by a bad actor who conducted a ransomware attack on WordFly, resulting in the encryption of the WordFly application," he [2]wrote in a support note.

[3]

During said attack, miscreants stole customers' email addresses and "other data" used by those organizations to communicate with their fans via WordFly. "At this time, we believe that the exported data was not sensitive in nature and largely consisted of names and email addresses," Bentley added.

[4]

[5]

The security update said the criminals deleted the data on July 15 — if you're inclined to believe someone who just stole and encrypted your customers' information — and Bentley noted that there's "no evidence" that the information was publicly leaked or "has been, or will be misused."

Again, may we suggest a very large grain of salt.

[6]

The digital marketing firm also hired outside forensics experts and cybersecurity professionals to assist, and said as of now the "situation has been contained," while the investigation is ongoing. No word as to when WordFly will be back online, however.

[7]Ransomware less popular this year, but malware up: SonicWall cyber threat report

[8]LockBit ransomware gang claims it ransacked Italy's tax agency

[9]Twitter launches probe after miscreants claims to have swiped 5.4m users' details

[10]Cyber-mercenaries for hire represent shifting criminal business model

Meanwhile, major arts and cultural organizations including Australia's Sydney Dance Company have since posted their own [11]updates about the ransomware attack.

The Courtauld [12]assured its fans that "visitors' financial data (including credit card details) were not compromised."

The Smithsonian, which runs 21 museums and the US National Zoo, and claims to be the world's largest museum, education and research complex, [13]noted that some of its data, specifically its subscribers' email addresses and names, was stolen in the cyberattack.

However, it reiterated that WordFly believes "the information has been deleted and there will be no further misuse of this information."

[14]

"We want to reassure you that we use this service to facilitate email communication and we do not store any information in the system that is financial or sensitive that could have been exposed by this incident," the museum operator said, adding that it will continue to monitor the situation. "If we learn any additional information about the information that was exported or have any reason to believe the data has not been deleted by the attackers, we will update this notice."

In a similar alert, the Toronto Symphony Orchestra [15]warned that personal information including names, email addresses, TSO patron ID and information about TSO accounts (such as donor level and demographic info collected via surveys) may have been compromised.

In the meantime, as WordFly's email service remains down, the orchestra has "temporarily partnered" with Mailchimp to send its communications to patrons. ®

Get our [16]Tech Resources



[1] https://updates.wordflystatus.com/

[2] https://support.wordfly.com/hc/en-us/articles/7890420089620-Information-about-a-Recent-Security-Incidente

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YuBkB-wircalyJv0kTm1KwAAAEQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YuBkB-wircalyJv0kTm1KwAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YuBkB-wircalyJv0kTm1KwAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YuBkB-wircalyJv0kTm1KwAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/07/26/sonicwall_threat_report/

[8] https://www.theregister.com/2022/07/26/lockbit-italy-ransomware-attack/

[9] https://www.theregister.com/2022/07/25/twitter_investigates_data_breach/

[10] https://www.theregister.com/2022/07/25/aig-unique-cybercrime-business/

[11] https://www.sydneydancecompany.com/email-provider-update/

[12] https://courtauld.ac.uk/news-blogs/2022/wordfly-incident-and-response/

[13] https://nationalzoo.si.edu/news/smithsonian-statement-wordfly-data-security-incident

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YuBkB-wircalyJv0kTm1KwAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://www.tso.ca/wordfly-incident/

[16] https://whitepapers.theregister.com/



Naïve art?

innominatus

Hmmm - surely only arts people could say "the exported data was not sensitive in nature and largely consisted of names and email addresses" and believe it.

Perhaps some high profile arts patrons will be receiving phishing emails very shortly?

The Blue Screen Of Advocacy

The Federal Bureau of Investigation & Privacy Violations has issued a
national advisory warning computer stores to be on the lookout for the
"Bluescreen Bandits". These extreme Linux zealots go from store to store
and from computer to computer typing in "C:\CON\CON" and causing the demo
machines to crash and display the Blue Screen Of Death.

Efforts to apprehend the bandits have so far been unsuccessful. The
outlaws were caught on tape at a CompUSSR location in Southern California,
but in an ironic twist, the surveillance system bluescreened just before
the penguinistas came into clear view.

"We don't have many clues. It's not clear whether a small group is behind
the bluescreen vandalism, or whether hundreds or even thousands of geek
zealots are involved," said the manager of a Capacitor City store.

The manager has good reason to be upset. The bluescreen raid was the top
story in the local newspaper and quickly became a hot topic of discussion.
As a result, the local school board halted its controversial plans to
migrate their computers from Macs to PCs.