Yazılar

Australia Regulator Sues FIIG Securities for Cybersecurity Failures

The Australian Securities and Investments Commission (ASIC) announced on Thursday that it is suing FIIG Securities, a fixed-income broker, accusing the company of failing to implement proper cybersecurity measures over a four-year period. These alleged failures allowed a hacker to infiltrate FIIG’s IT network, resulting in the theft of approximately 385 gigabytes of confidential data.

The breach, which occurred between May 19 and June 8, 2023, affected 18,000 clients, who were notified that their personal information may have been compromised. Some of the stolen client data was later found on the dark web.

ASIC’s lawsuit claims that from March 2019 to June 2023, FIIG failed to take necessary steps to ensure the security of its digital infrastructure. The regulator stated that the company lacked adequate cyber risk management systems, which directly contributed to the attack.

“Advancing digital safety and resilience is a strategic priority for ASIC, and we have been actively engaging with companies to support the continuous improvement of cyber and operational resilience practices,” said ASIC Chair Joe Longo.

During the period when the cybersecurity issues occurred, JPMorgan held assets for FIIG and its clients, ranging in value from A$2.89 billion ($1.83 billion) to A$3.7 billion. However, JPMorgan declined to comment on the matter when contacted by Reuters, and FIIG did not respond to requests for comment.

According to ASIC, the deficiencies alleged include FIIG’s failure to adequately update and patch its software, as well as its insufficient resources to protect against and prevent cyberattacks.

Sony Extends PlayStation Plus Membership After Global Outage

Sony has announced a five-day extension for all PlayStation Plus subscribers following a global outage that disrupted the PlayStation Network (PSN) for nearly 18 hours on Friday and Saturday. The company confirmed that network services had been fully restored by Saturday evening and expressed regret for the inconvenience caused to users.

The outage, which began late on Friday, prevented users from signing in, playing online games, or accessing the PlayStation Store. Sony did not specify the cause of the disruption in its update. At its peak, the outage affected nearly 8,000 users in the U.S. and over 7,300 in the UK, according to Downdetector.com, which tracks service interruptions.

This incident is the latest in a series of PSN outages, though Sony has faced more severe disruptions in the past. A cyberattack in 2014 forced the network offline for several days, and a significant data breach in 2011 compromised the personal information of millions of users, resulting in a month-long service shutdown and a regulatory investigation.

Despite the inconvenience, the extended PlayStation Plus membership is seen as a way to compensate users for the lost time. One user on X (formerly Twitter) humorously remarked that Sony had “saved millions of gamers’ Sunday” after the outage impacted their Saturday.

Chinese Hack of U.S. Treasury Targets Economic Sanctions Office

A cyberattack by Chinese government hackers successfully breached the U.S. Treasury’s office responsible for administering economic sanctions, the Washington Post reported on Wednesday. According to unnamed U.S. officials, the hackers infiltrated the Office of Foreign Assets Control (OFAC), the Office of Financial Research (OFR), and even targeted the office of U.S. Treasury Secretary Janet Yellen.

The Treasury Department had already disclosed the breach earlier this week in a letter to lawmakers, describing it as a “major incident” where unclassified documents were stolen. However, the department did not reveal the specific departments or individuals affected by the attack.

In response to the Washington Post‘s report, Liu Pengyu, a spokesperson for the Chinese Embassy in Washington, dismissed the U.S. claims as “irrational” and lacking factual basis, calling them “smear attacks” against China. The statement emphasized that China opposes all forms of cyberattacks but did not specifically address the report regarding the targeted offices.

The Treasury Department has not yet commented on the details revealed in the Washington Post report. According to the sources cited by the paper, Chinese government hackers were likely focused on gathering intelligence about Chinese entities that the U.S. might consider sanctioning in the future.

The Treasury’s earlier disclosure mentioned that the breach involved third-party cybersecurity service provider BeyondTrust. Chinese entities and individuals have been frequent targets of U.S. sanctions, which are a key component of Washington’s foreign policy towards Beijing. Last month, U.S. Treasury Secretary Janet Yellen confirmed that the U.S. would not rule out sanctions on Chinese banks in its efforts to curb Russia’s oil revenue and limit access to foreign supplies, in connection with the ongoing war in Ukraine.