IT Services Giant Conduent Suffers Ransomware Attack, Data Breach, Customer data found over Dark Web

Continue reading
Conduent has admitted that a ransomware attack happened to its European operations, but according to the $4.4 billion by revenue IT giant most, most of the system was restored within eight hours.
The majority of Fortune 100 companies and over 500 governments use Conduent's services for HR, payments, and other infrastructures. The firm was reportedly hit on Friday, May 29.
“Conduent’s European operations experienced a service interruption on Friday, May 29, 2020. Our system identified ransomware, which was then addressed by our cybersecurity protocols.
“This interruption began at 12.45 AM CET on May 29th with systems mostly back in production again by 10.00 AM CET that morning, and all systems have since then been restored,” said spokesman Sean Collins.
Although Conduent has not named the ransomware-type or intrusion vector, the maze ransomware group has posted stolen Conduent data to its Dark Web Page.
An arbitrary code in Citrix VPN appliance, CVE-2019-1981, has been widely exploited in the wild by ransomware gangs. This unpatched Citrix VPN was running for "at least" eight weeks and was being used by over 67,000 users employed by Conduent globally, according to the security researchers at Bad Packets.
Bad Packets found, in early January, nearly 10,000 vulnerable hosts running this unpatched VPN in the US itself and over 2,000 in the UK, which was later updated by Citrix on January 24.
1) Military, federal, state, and city government agencies
2) Public universities and schools
3) Hospitals and healthcare providers
4) Electric utilities and cooperatives
5) Major financial and banking institutions
6) Numerous Fortune 500 companies
According to a March 2020 McAfee analysis, the malware used by Maze is a binary file of 32bits, most of the time packed as a DLL or an EXE file. The ransomware was also noted that it could terminate debugging tools used to analyze its behavior, including x32dbg, IDA debugger, and more, to avoid dynamic analysis and security tools.
Instead of "Spray and pray" Cybercriminals have now largely moved to more targeted intrusions styles. Hackers now exploit weak credentials, unpatched software, or phishing techniques to gather data and use it to blackmail their victims before actually triggering the malware that locks down end-points.
Companies have been constantly advised by law enforcement to improve basic cyber hygiene and regularly update their software to avoid such attacks.

Estée Lauder reveals a data breach caused by an Oracle E-Business Suite flaw, exposing sensitive data and prompting security response measures.