notifies – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Tue, 18 Mar 2025 19:59:22 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 notifies – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Western Alliance Bank notifies 21,899 customers of data breach https://earlybirdsinvest.com/western-alliance-bank-notifies-21899-customers-of-data-breach/ https://earlybirdsinvest.com/western-alliance-bank-notifies-21899-customers-of-data-breach/#respond Tue, 18 Mar 2025 19:59:22 +0000 https://earlybirdsinvest.com/western-alliance-bank-notifies-21899-customers-of-data-breach/

Data breach

Arizona-based Western Alliance Bank is notifying nearly 22,000 customers their personal information was stolen in October after a third-party vendor’s secure file transfer software was breached.

Western Alliance is a wholly owned subsidiary of Western Alliance Bancorporation, a leading U.S. banking company with over $80 billion in assets.

The bank first revealed in a February SEC filing that the attackers exploited a zero-day vulnerability in the third-party software (disclosed by the vendor on October 27, 2024) to hack a limited number of Western Alliance systems and exfiltrate files stored on the compromised devices.

Western Alliance found that customer data was exfiltrated from its network only after discovering that the attackers leaked some files stolen from its systems.

In breach notification letters sent to 21,899 affected customers and filed with the Office of Maine’s Attorney General, the company said it has since “determined that the unauthorized actor acquired certain files from the systems from October 12, 2024, to October 24, 2024.”

An analysis of the stolen files concluded on February 21, 2025, and found they contained customer personal information, including your name and Social Security number, as well as their dates of birth, financial account numbers, driver’s license numbers, tax identification numbers, and/or passport information if it was provided to Western Alliance.

“We have no evidence to believe that your personal information has been misused for the purpose of committing fraud or identity theft,” Western Alliance added, saying it’s also offering those affected one year of free membership for Experian IdentityWorks Credit 3B identity protection services.

“While we have no evidence that your personal information has been misused as a result of this incident, we encourage you to take advantage of the complimentary credit monitoring included in this letter.”

A Western Alliance spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today.

Breach claimed by Clop ransomware

While the secure file transfer software compromised in the breach was not named in the breach notification letters or the February SEC filing, the bank is one of 58 companies the Clop ransomware gang added to its leak site in January.

The cybercrime group was behind a series of attacks exploiting a pre-auth zero-day vulnerability (CVE-2024-50623) in Cleo LexiCom, VLTransfer, and Harmony software patched in October, when the company warned customers to upgrade immediately.

In December, Cleo released security updates for a second zero-day (tracked as CVE-2024-55956) that the Clop threat actors exploited to deploy a JAVA backdoor dubbed “Malichus” to steal data, execute commands, and gain further access to the victims’ networks.

“This vulnerability has been leveraged to install malicious backdoor code on certain Cleo Harmony, VLTrader, and LexiCom instances in the form of a malicious Freemarker template containing server-side JavaScript,” Cleo explained in a private advisory.

While it’s currently unknown how many companies were breached in these attacks, Cleo claims its software is used by over 4,000 organizations worldwide.

Clop was previously linked to several other data theft campaigns in recent years, targeting zero-day flaws in MOVEit Transfer, GoAnywhere MFT, and Accellion FTA.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/western-alliance-bank-notifies-21899-customers-of-data-breach/feed/ 0 25893
HPE notifies employees of data breach after Russian Office 365 hack https://earlybirdsinvest.com/hpe-notifies-employees-of-data-breach-after-russian-office-365-hack/ https://earlybirdsinvest.com/hpe-notifies-employees-of-data-breach-after-russian-office-365-hack/#respond Sat, 08 Feb 2025 12:37:18 +0000 https://earlybirdsinvest.com/hpe-notifies-employees-of-data-breach-after-russian-office-365-hack/

Hewlett Packard Enterprise (HPE)

Hewlett Packard Enterprise (HPE) is notifying employees whose data was stolen from the company’s Office 365 email environment by Russian state-sponsored hackers in a May 2023 cyberattack.

According to filings with Attorney General offices in New Hampshire and Massachusets, HPE started sending the breach notification letters last month to at least 16 people who had their driver’s licenses, credit card numbers, and Social Security numbers stolen.

“HPE’s forensic investigation determined that certain individuals’ personal information may have been subject to unauthorized access,” the company says in the letters. “On January 29, 2025, HPE began providing notice of this event to impacted individuals, in accordance with applicable law.”

When asked to share the number of employees affected by this data breach, an HPE spokesperson said it was “a limited group of HPE team member mailboxes that were accessed, and only the information contained in those mailboxes was involved.”

The group behind the attack, Cozy Bear (also known as Midnight Blizzard, APT29, and Nobelium), is believed to be part of Russia’s Foreign Intelligence Service (SVR) and has also been linked to other high-profile breaches, including the infamous 2020 SolarWinds supply chain attack.

The HPE breach incident was first disclosed in an SEC filing on January 29, 2024, when the company said it was notified on December 12 that suspected Russian hackers breached its cloud-based Office 365 email environment in May 2023 using a compromised account.

“We determined that this nation-state actor accessed and exfiltrated data beginning in May 2023 from a small percentage of HPE mailboxes belonging to individuals in our cybersecurity, go-to-market, business segments, and other functions. We believe the nation-state actor is Midnight Blizzard, also known as Cozy Bear,” HPE told BleeingComputer at the time.

“The accessed data is limited to information contained in the users’ mailboxes. We continue to investigate and will make appropriate notifications as required.”

Sharepoint server breached by the same hackers

In the SEC filing, HPE added that the Office 365 incident was likely related to another May 2023 breach, when threat actors accessed the company’s SharePoint server and stole files.

Days before HPE’s disclosure, Microsoft also warned that Cozy Bear hackers stole data from corporate email accounts and source code repositories. They first breached Microsoft’s network in November 2024 in a password spray attack to access a legacy non-production test tenant account.

HPE was previously breached in 2018 when Chinese malicious actors hacked into its network and used that access to breach its customers’ devices.

In 2021, it also disclosed that the data repos for its Aruba Central network monitoring platform had been compromised, allowing a threat actor to access information about monitored devices and their locations.

More recently, in February 2024 and January 2025, the company started investigating other potential security breaches after a threat actor using the IntelBroker handle claimed to have stolen HPE credentials, source code, and other sensitive information.

]]>
https://earlybirdsinvest.com/hpe-notifies-employees-of-data-breach-after-russian-office-365-hack/feed/ 0 18206