News: 1686637692

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK telco watchdog Ofcom, Minnesota Dept of Ed named as latest MOVEit victims

(2023/06/13)


Two more organizations hit in the mass exploitation of the MOVEit file-transfer tool have been named – the Minnesota Department of Education in the US, and the UK's telco regulator Ofcom – just days after security researchers discovered additional flaws in Progress Software's buggy suite.

Ofcom disclosed this week it is among the businesses and public bodies that have had their internal data [1]stolen by crooks exploiting a MOVEit flaw. Russia's Clop ransomware crew has since [2]claimed it has been going around abusing the vulnerability in MOVEit deployments to steal documents and demanding payment not to leak the info.

"A limited amount of information about certain companies we regulate – some of it confidential – along with personal data of 412 Ofcom employees, was downloaded during the attack," Ofcom revealed in a [3]statement yesterday.

[4]

The watchdog said it took "immediate action" to remediate the issue and beef up its security.

[5]

[6]

"We also swiftly alerted all affected Ofcom-regulated companies, and we continue to offer support and assistance to our colleagues," the regulator added. "No Ofcom systems were compromised during the attack."

An Ofcom spokesperson declined to answer any additional questions about the attack – including what specific data was stolen, who is responsible for the attack, and whether the intrusion occurred in an Ofcom-run MOVEit instance, or at a third party (such as payroll and human resources services provider [7]Zellis ).

This is what transparency looks like

Minnesota's Department of Education (MDE), meanwhile, provided substantially more detail about what happened during the theft of its data.

The state agency said Progress Software alerted it to the security vulnerability on May 31, and on the same day "an outside entity" accessed 24 MDE files on a MOVEit server.

[8]

MDE's [9]data breach advisory , posted on Friday, said the compromised files included "data transferred to MDE from the Minnesota Department of Human Services (DHS) to meet state and federal reporting requirements, as well as files from two school districts (Minneapolis and Perham), and Hennepin Technical College."

Information therein contained about "95,000 names of students placed in foster care throughout the state, 124 students in the Perham School District who qualified for Pandemic Electronic Benefits Transfer (P-EBT), 29 students who were taking PSEO classes at Hennepin Technical College in Minneapolis, and five students who took a particular Minneapolis Public Schools bus route."

The foster care students' files included their names, dates of birth, and county of placement.

[10]

Additionally, the P-EBT and PSEO files contained student names, dates of birth, some home addresses and parents' or guardians' names. PSEO participants' data also included their high school and college transcript information, and last four digits of the student's social security number.

The files related to the Minneapolis Public Schools bus route only included the five kids' names.

MDE: 'No financial info stolen' – so that's all right then

"No financial information was included in any of the files in this data breach," the department's advisory added. "MDE is currently working to notify those individuals whose data was accessed. To date there have been no ransom demands nor is MDE aware that the data has been shared or posted online."

The miscreants didn't upload any malware to MDE's systems during the breach, so it's thought. And upon discovering the intrusion the state notified the FBI, Minnesota Bureau of Criminal Apprehension, and Office of the Legislative Auditor about the situation.

"Though no financial information was accessed, MDE recommends individuals who may have been impacted take precautionary measures to protect themselves, such as accessing and monitoring your personal credit reports," the advisory continued.

While the Minnesota students' information hasn't been posted on Clop's leak site, nor has the gang demanded any ransom from the state agency. MDE director of communications Kevin Burns told The Register that the department believes the attack exploited the initial MOVEit vulnerability, [11]CVE-2023-34362 , which Progress patched on May 31.

"We have not been contacted by the folks who did this, but our assumption is this was part of the larger global occurrences that happened in and around that same day," Burns said.

The list of victims will likely get longer, as on Friday security researchers uncovered [12]more MOVEit vulnerabilities .

[13]Hold it – more vulnerabilities found in MOVEit file transfer software

[14]Clop ransomware crew sets June extortion deadline for MOVEit victims

[15]Microsoft stole our stolen dark web data, says security outfit

[16]Lantum S3 bucket leak is prescription for chaos for thousands of UK doctors

Progress [17]said that discovery was made by cyber security firm Huntress, which it had engaged to conduct a detailed review of its code. As of Monday at least one of these has a CVE number: [18]CVE-2023-35036 .

"An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content," according to the MITRE description of the [19]new CVE .

Progress has since patched CVE-2023-35036.

While the investigation into both – and possibly additional MOVEit vulnerabilities – remains ongoing, Progress said it has not seen any indication that the new bugs have been found and exploited by criminals.

Also on Friday, risk analysis firm Kroll said Clop likely knew about the bug as far back as 2021. ®

Get our [20]Tech Resources



[1] https://www.theregister.com/2023/06/01/moveit_transfer_zero_day/

[2] https://www.theregister.com/2023/06/07/clop_crew_sets_extortion_deadline/

[3] https://www.ofcom.org.uk/news-centre/2023/ofcom-statement-on-moveit-cyber-attack

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZIg@Pmz8aihX5Y3vemSaVgAAAAc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZIg@Pmz8aihX5Y3vemSaVgAAAAc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZIg@Pmz8aihX5Y3vemSaVgAAAAc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/06/05/british_airways_boots_moveit/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZIg@Pmz8aihX5Y3vemSaVgAAAAc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://content.govdelivery.com/accounts/MNMDE/bulletins/35f2559

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZIg@Pmz8aihX5Y3vemSaVgAAAAc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://nvd.nist.gov/vuln/detail/CVE-2023-34362

[12] https://www.theregister.com/2023/06/12/security_in_brief/

[13] https://www.theregister.com/2023/06/12/security_in_brief/

[14] https://www.theregister.com/2023/06/07/clop_crew_sets_extortion_deadline/

[15] https://www.theregister.com/2023/06/12/microsoft_hold_security_lawsuit/

[16] https://www.theregister.com/2023/06/12/lantum_s3_bucket_leak/

[17] https://www.progress.com/security/moveit-transfer-and-moveit-cloud-vulnerability

[18] https://www.cve.org/CVERecord?id=CVE-2023-35036

[19] https://www.cve.org/CVERecord?id=CVE-2023-35036

[20] https://whitepapers.theregister.com/



Korev

Information therein contained about "95,000 names of students placed in foster care throughout the state, 124 students in the Perham School District who qualified for Pandemic Electronic Benefits Transfer (P-EBT), 29 students who were taking PSEO classes at Hennepin Technical College in Minneapolis, and five students who took a particular Minneapolis Public Schools bus route."

Why on all earth were these data just left lying around on a server? And also, there is no mention of encryption...

Andy The Hat

"MOVEit is a file transfer tool used by enterprises, as well as small and medium-sized businesses (SMB), to share sensitive data, such as personally identifiable information, banking data, health information, and similar, in a secure manner. That helps businesses prevent incidents that can lead to identity theft, wire fraud, and more."

By definition, organisations using this tool expect this information to be end-to-end secure and the data is supposedly encrypted en-route. No "lying around on a server" is suggested.

ChoHag

If you hear about a car accident, you will likely feel sympathy for all involved. When you learn that some of those weren't wearing seat belts or were drinking it colours your feelings somewhat.

That is how I feel about the breeches like this. What kind of bloody-minded incompetence, from engineering to management to board and beyond, allowed that to happen, and to happen so disastrously? Except for the final outcome it makes Boeing's culture look positively mature.

"Do not operate this equipment while under the influence of incompetence or hubris"

Kevin McMurtrie

If only there was some kind of [1]list that helped organizations research the most common security coding mistakes.

[1] https://owasp.org/www-project-top-ten/

Will OFCOM fine OFCOM?

Panicnow

Or will they go after MOVEiT?

There will be a great precedent set, either way.

If you drink, don't park. Accidents make people.