News: 1709666892

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Fidelity customers' financial info feared stolen in suspected ransomware attack

(2024/03/05)


Criminals have probably stolen nearly 30,000 Fidelity Investments Life Insurance customers' personal and financial information — including bank account and routing numbers, credit card numbers and security or access codes — after breaking into Infosys' IT systems in the fall.

According to Fidelity, in [1]documents filed with the Maine attorney general's office, miscreants "likely acquired" information about 28,268 people's life insurance policies after infiltrating Infosys.

"At this point, [Infosys] are unable to determine with certainty what personal information was accessed as a result of this incident," the insurer noted in a letter

[2]PDF

sent to customers. However, the US-headquartered firm says it "believes" the data included: names, Social Security numbers, states of residence, bank accounts and routing numbers, or credit/debit card numbers in combination with access code, password, and PIN for the account, and dates of birth.

[3]

In other words: Potentially everything needed to drain a ton of people's bank accounts, pull off any number of identity theft-related scams — or at least go on a massive online shopping spree.

[4]Infosys subsidiary named as source of Bank of America data leak

[5]Ransomware ban backers insist thugs must be cut off from payday

[6]Change Healthcare attack latest: ALPHV bags $22M in Bitcoin amid affiliate drama

[7]The federal bureau of trolling hits LockBit, but the joke's on us

LockBit [8]claimed to be behind the Infosys intrusion in November, shortly after the Indian tech services titan disclosed the "cybersecurity incident" affecting its US subsidiary, Infosys McCamish Systems aka IMS. It reported that the intrusion shuttered some of its applications and IT systems

[9]PDF

.

This was before law enforcement [10]shut down at least [11]some of LockBit's infrastructure in December, although that's [12]never a guarantee that the gang will slink off into obscurity — as we're already seen.

[13]

[14]

And if the Fidelity security breach sounds familiar, it's because [15]Infosys was also at the heart of a Bank of America leak disclosed last month. Back then [16]BofA told 57,028 of its customers that crooks may have swiped from Infosys names, addresses, business email addresses, dates of birth, Social Security number, and "other account information."

As of now, in addition to disrupting both financial firms' IT services, it appears that criminals swiped more than 85,000 individuals' sensitive details.

[17]

Fidelity did not immediately respond to The Register 's inquiries.

We've asked Infosys for more information about the break in — including how the criminals gained access and how much data they stole — and will update this story if and when we get a response.

The incident, according to letters sent to BofA and Fidelity customers, happened between October 20 and November 2, and disrupted Infosys-provided services to both financial institutions.

[18]

"Since learning of this event, we have been engaged with IMS to understand IMS's actions to investigate and contain the event, implement remedial measures, and safely restore its services," Fidelity assured its customers. "In addition, we remain engaged with IMS as they continue their investigation of this incident and its impact on the data they maintain." ®

Get our [19]Tech Resources



[1] https://apps.web.maine.gov/online/aeviewer/ME/40/0c98c6d7-c7b3-4bbf-a7fa-8005c61168d6.shtml

[2] https://regmedia.co.uk/2024/03/05/fidelity_life_insurance_data_breach_notification.pdf

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZeekFk-sXZ8HhC9tuKDsdwAAAYM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.theregister.com/2024/02/13/infosys_bank_of_america_leak/

[5] https://www.theregister.com/2024/03/04/experts_echo_calls_for_ransomware/

[6] https://www.theregister.com/2024/03/04/alphv_ransom_payment/

[7] https://www.theregister.com/2024/03/04/opinion/

[8] https://twitter.com/DarkWebInformer/status/1720868655037120602

[9] https://www.sec.gov/Archives/edgar/data/1067491/000106749123000059/exv99w01.htm

[10] https://www.theregister.com/2024/03/04/opinion/

[11] https://www.theregister.com/2024/02/26/lockbit_back_in_action/

[12] https://www.theregister.com/2024/03/04/in_brief/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZeekFk-sXZ8HhC9tuKDsdwAAAYM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZeekFk-sXZ8HhC9tuKDsdwAAAYM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://www.theregister.com/2024/02/13/infosys_uk_government_contracts/

[16] https://www.theregister.com/2024/02/13/infosys_bank_of_america_leak/

[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZeekFk-sXZ8HhC9tuKDsdwAAAYM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZeekFk-sXZ8HhC9tuKDsdwAAAYM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[19] https://whitepapers.theregister.com/



Blames Infosys, hah!!!

A random security guy

You outsourced to an offshore company without tough security guardrails i.e. based on the commercial costs which did not include cybersecurity requirements.

You get what you pay for.

Re: Blames Infosys, hah!!!

Anonymous Coward

Quite. Seems like the headlines should be more like "Infosys at fault for yet another security incident, customer data stolen".

Also seems like "do you use Infosys?" should be among the first questions in any security auditor list. With an immediate mark-down if answered in the affirmative. Sorry, no insurance coverage for you.

Infosys (et al) supposedly have such awful reputations in the IT industry, customers should already know better than to employ them. And yet it keeps happening, presumably because Infosys has bottom-dollar fees to go along with their cut-rate consultants.

Creating some impact to that financial bottom line motivation is likely the only way to start turning things around. Public/PR news and headlines, high insurance premiums, direct penalties to the executives making these business decisions, etc.

Re: Blames Infosys, hah!!!

Doctor Syntax

"nfosys (et al) supposedly have such awful reputations in the IT industry, customers should already know better than to employ them."

It's not likely to be a decision made at IT department pay grades.

Anonymous Coward

Having worked in the bowels of Fidelity in the UK, "ransomware" is probably the least embarrasing explanation...

Distrust all those who love you extremely upon a very slight acquaintance
and without any visible reason.
-- Lord Chesterfield