About Members News Events Trainings Career Catalog Log In Join TR

CYBER CASES THAT HAPPENED IN 2022

CYBER CASES THAT HAPPENED IN 2022

In the report published by Virustotal, which produces security solutions, of Ransomware (Ransomware) attacks, which increased by 19% compared to 2021, it was stated that 93% were made on devices with Windows operating system. It should not be forgotten that the attacks mostly occur due to reasons such as incorrect system configuration, targeted phishing, lack of vulnerability management and Stealer Malware.

On March 20, 2022, Microsoft was targeted by the threat actor group called Lapsus$. The group posted a screenshot on Telegram stating that they had hacked Microsoft and captured data for Cortana, Bing, and several other products in the process. By March 22, Microsoft announced that it had quickly stopped the attack attempt and only one account had been compromised. Microsoft also stated that no customer data was stolen. The Lapsus$ group has previously targeted Nvidia, Samsung and many other companies.

The security company Kaspersky, which provides security solutions, was added to the list of unreliable IT companies by the US Federal Communications Commission (FCC) and the Department of Homeland Security (DHS) on March 25, 2022.

The data breach incident at Nelnet Servicing, which provides student loan services in June 2022, caused the confidential information of more than 2.5 million users to be leaked. It was determined that student loan account registration information, including name, surname, home and email addresses, phone numbers and social security numbers, was accessible by an unidentified third party due to a security vulnerability in its system.

On July 27, 2022, on the darkweb forum called BreachForums, a user named "devil" published data containing details of 5.4 million Twitter users. While it is thought that the relevant leak was achieved by exploiting the vulnerability reported to Twitter on January 1, 2022, Twitter confirmed the relevant vulnerability on August 5, 2022.

On September 15, after a contractor's device was infected with malware, user information was sold on the darkweb and from there, Uber's internal servers were accessed. The attacker then moved laterally, obtained other Uber user information, and sent a message to a company-wide Slack channel, reconfiguring the DNS settings to display a graphical image to employees via some internal sites.

In October 2022, Binance lost $ 570 million worth of BNB Tokens due to attackers using the vulnerability in the BSC Token Hub, which includes the BNB chain supported by the cryptocurrency platform Binance.

On November 16, phone numbers of 487 million WhatsApp users were put up for sale on the forum site called BreachForums. It was observed that the sharing, which included data of many users from 84 different countries, did not contain any personal data other than phone numbers.

The company named LastPass, which provides services as a password safe on many platforms and has been mentioned many times in 2022, suffered a data breach and all information about its customers was seized by the attackers in December 2022.

In the forum called "BidenCash", which is an illegal platform where stolen credit card information is also included, 1.2 million credit cards with expiration dates of 2023 and 2026 were published free of charge. Leaks are increasing day by day due to the use of credit cards in insecure environments and users not paying attention to system security.

A critical vulnerability called Rolling Pwn, which allows the locking system and vehicle remote control in Honda vehicles, was found.

A security vulnerability was found in MiCODUS MV720 GPS devices used in more than 1.5 million vehicles that can remotely manage the vehicle.

Google broke the record by blocking the largest HTTPS DDoS attack ever made, with 46 million requests per second.

Yandex Taxi was hacked and all taxis in Moscow were directed to the same point, causing a huge traffic jam.

Source codes of Intel's 12th generation processor Alper Lake have been leaked.

It was determined that 34 different Russian hacker groups stole more than 50 million passwords with malicious software.

The FBI seized 48 domain names as a result of its operation on platforms offering DDoS services for hire.

A critical security vulnerability has been found in the Java Web Framework called Spring, which is widely used around the world, allowing remote code execution on the system.


Source: GAİS Security and cyrops

Gallery

CYBER CASES THAT HAPPENED IN 2022 - 1