Yazılar

Qantas reveals cyber breach exposed personal data of over 5 million customers

Australia’s Qantas Airways confirmed on Wednesday that a major cyberattack compromised the personal data of approximately 5.7 million customers, marking one of the country’s largest data breaches in recent years. Initially, Qantas reported 6 million records affected but later removed duplicates.

More than one million customers had sensitive details like phone numbers, birth dates, or home addresses accessed. An additional four million customers’ data was limited to names and email addresses.

The airline said there is currently no evidence that the stolen data has been publicly released, and it is actively monitoring the situation to protect affected customers.

“Since the incident, we have implemented several new cybersecurity measures to better safeguard our customers’ data and are thoroughly reviewing the breach,” Qantas Group CEO Vanessa Hudson stated.

This breach follows a wave of high-profile cyberattacks in Australia, including those against telecom giant Optus and health insurer Medibank in 2022, which spurred the introduction of mandatory cyber resilience regulations.

US SEC and SolarWinds Reach Preliminary Settlement in Cyberattack Lawsuit

The U.S. Securities and Exchange Commission (SEC) has reached a deal in principle with SolarWinds Corp and its chief information security officer, Timothy Brown, to settle litigation related to a Russia-linked cyberattack on the software company. The agreement was revealed in a court filing on Wednesday.

SolarWinds, the SEC, and Brown jointly requested a federal judge to pause court proceedings while they finalize the settlement paperwork, which the judge approved. The case centers around the “Sunburst” cyberattack, which lasted two years and targeted SolarWinds, based in Austin, Texas.

The SEC accused the company and its security officer of defrauding investors by hiding security vulnerabilities. However, much of the SEC’s case was dismissed last year by U.S. District Judge Paul Engelmayer, who criticized the claims as relying on hindsight and speculation.

Both the SEC and SolarWinds declined to comment on the settlement details beyond public filings. SolarWinds expressed satisfaction with the potential resolution and a desire to focus on its business operations moving forward.

The parties plan to file the final settlement documents or a joint status report by September 12.

Cyberattack on Brazil Tech Provider Disrupts Reserve Accounts of Several Financial Institutions

Brazil’s central bank revealed on Wednesday that C&M Software, a technology services provider catering to financial institutions without their own connectivity infrastructure, suffered a cyberattack targeting its systems. In response, the central bank ordered C&M to suspend access to the infrastructure it manages for these institutions.

Kamal Zogheib, C&M Software’s commercial director, confirmed the company was a direct victim of the attack, which involved fraudulent use of client credentials to try to access its services. Despite the breach, C&M said its critical systems remain intact and fully operational, with all security protocols activated. The company is working closely with the central bank and Sao Paulo state police as investigations continue.

Brazilian financial institution BMP and five other banks reported unauthorized access to their reserve accounts during the Monday attack. These reserve accounts, held directly at the central bank, are used solely for interbank settlements and are separate from client accounts, which were unaffected. BMP stated it has taken appropriate operational and legal measures and holds sufficient collateral to cover any impacted amounts, ensuring no disruption to its operations or partners.

An anonymous official indicated C&M services about two dozen smaller financial institutions, and the financial impact of the attack does not reach billions of reais. Another source confirmed no losses were sustained by clients.

The central bank refers to these affected entities as “financial institutions lacking their own connectivity infrastructure,” including many digital payment providers that have grown rapidly in Brazil. The Pix instant payment system, operated by the central bank since late 2020, has become the country’s most popular payment method, driving competition and innovation in the sector.