HomeSecuritySerco: Reveals data breach following attacks on MoveIT

Serco: Reveals data breach following attacks on MoveIT

Serco Inc, the US arm of multinational outsourcing company Serco Group, has disclosed a data breach in which hackers managed to extract the personal information of more than 10,000 people from a third-party vendor's MoveIT file transfer (MFT) management server.

See also: Clop ransomware group will earn $75-100 million through MOVEit attacks

Serco

In a breach notice filed with the Maine Attorney General's Office, Serco says the information was pulled from CBIZ's file transfer platform.

On 30 June 2023, Serco was informed that its third-party benefits management provider, CBIZ, had experienced a ransomware and data breach attack ,” the company explained

We were informed by CBIZ that the incident began in May 2023 and CBIZ took steps to mitigate the incident on June 5, 2023. To be clear, the breach of CBIZ's systems did not impact the security of Serco's systems.

Personal information compromised by the attack includes: name, U.S. Social Security Number, date of birth, home mailing address, email address, and selected health benefits for the current year.

Serco is currently working with CBIZ to investigate the breach and fully assess the scope of the incident. It is focusing on ensuring that the third-party supplier has taken security measures to prevent future incidents.

See also: MOVEit Transfer customers warned to patch new, critical flaw

According to CBIZ, a company active in the cybersecurity sector, it is also conducting detailed research on the issue.

MoveIT

Serco's client list includes an extensive list of US federal agencies, including the Departments of the Interior, Justice and Homeland Security, as well as the Intelligence Community and several branches of the US Armed Forces, including the Navy, Army, Marine Corps and Air Force.

Serco also operates as a contractor for state and local governments in the US and the Canadian government, while also providing services to high-profile commercial clients such as Pfizer, Capital One and Wells Fargo. The company employs over 50,000 people in 35 countries and has annual revenues exceeding $5.7 billion for the year 2022.

The Clop ransomware group has launched a large-scale data theft campaign, exploiting a zero-day in the secure file transfer platform MOVEit Transfer, since May 27. Although Coveware estimates that Clop's ransom demands may have many potential victims, it is predicted that few will give in and ultimately pay.

See also: MOVEit attacks: Siemens Energy confirmed data breach

The Clop ransomware group is one of the most active and successful groups in the cybersecurity space, attacking large companies and organizations. What makes Clop particularly dangerous is its double extortion tactic, where the malicious actors hold the victim's data hostage, threatening not only to keep it, but also to publish it if the required ransom.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS