HomeSecurityInsight Partners: Data breach following cyberattack

Insight Partners: Data breach following cyberattack

Investment firm Insight Partners confirmed that during the cyberattack that occurred in January 2025, a data breach also occurred, exposing sensitive information concerning staff members and specific external partners.

Insight Partners data breach cyberattack

On February 18, 2025, the company issued an official statement regarding a cybersecurity incident recorded on January 16 of the same year. As reported, the breach was achieved through a targeted and technically advanced social engineering attack, resulting in an attacker gaining access to internal information systems.

According to Insight Partners, this incident was isolated, limited in time to a single 24‑hour period and had no impact on the company's operations. ’ Nevertheless, the investigation of the case continues.

See also: Pearson: Cyberattack led to data breach

In a recent update, Insight Partners confirmed that there had been a data breach. Efforts are now focused on identifying the individuals affected.

The data exposed varies from case to case and may include varying information depending on the profile of the individual or investor.

The data that were exposed include:

  • Information about the funds
  • Details about the management company
  • Information about a company's Portfolio
  • Banking data
  • Tax information
  • Personal data of current and former employees
  • Details concerning Limited Partners

Those who have been confirmed as affected by the breach will be notified accordingly, with notifications being sent gradually, starting in the coming days.

In the meantime, individuals who may have been affected are urged to change their passwords for both personal and business accounts, as well as enable two-factor authentication (2FA) on all their financial accounts.

Additionally, they are advised to carefully monitor their financial statements and credit reports, as well as consider placing a fraud alert or freezing their credit cards.

See also: Ransomware groups abuse legitimate Kickidler software

Μέχρι στιγμής, η Insight Partners δεν έχει καταγραφεί σε ιστοσελίδες ransomware ή πύλες εκβιασμών, οπότε η ταυτότητα των υπευθύνων για την επίθεση παραμένει άγνωστη.

Insight Partners data breach cyberattack

To avoid cyberattacks and data breaches, such as the one at Insight Partners, a company can adopt several security measures and best practices:

1. Εκπαίδευση και ευαισθητοποίηση προσωπικού

  • Develop a security culture: Employee training is crucial. Employees need to understand the risks of social engineering (phishing, spear phishing, etc.) and how to recognize suspicious activity or emails.
  • Continuous training: Training initiatives should be ongoing and include the latest attack methods.

2. Implementation of strong access and authentication policies

  • Access rights management: The "least access" policy must be strictly enforced, meaning that each user only has the permissions they need to perform their job.
  • Two-factor authentication (2FA): Enable 2FA on all critical accounts, including email, corporate applications, and systems that handle sensitive data.
  • Restrict access to critical systems: Users with high privileges (administrators) should have strict controls and use accounts with limited privileges when full access is not required.

3. Upgrade and management of software and systems

  • Regularly upgrade software: Apply security updates to all systems and applications, as most attacks exploit known security vulnerabilities in outdated software.
  • Upgrade security systems and applications: Use the latest security software to protect computers and networks, such as antivirus, firewalls, and anti-malware tools.

4. Secure storage and encryption of data

  • Data encryption: Encryption of sensitive data both at rest (on disk) and during network transmission.
  • Securely store passwords: Avoid storing credentials in plain files or databases without encryption. Use password managersto securely store and use strong, unique passwords.

5. Enhancing the security of the cloud and third‑party suppliers

  • Extensive vetting of suppliers and partners: Suppliers and partners who have access to corporate data must adhere to strict security policies and be regularly inspected to ensure they meet security standards.
  • Cloud security: Using secure cloud storage solutions and limiting access to authorized individuals only.

See also: Hacker tried to breach Kraken platform via job application

Insight Partners: Data breach following cyberattack
Insight Partners: Data breach following cyberattack

6. Developing a comprehensive incident response plan

  • Cyberattack response plan: The company must have a prepared response plan in the event of a cyberattack, with defined steps for detecting, responding to, and recovering from the attack.
  • Testing and risk identification: Regular vulnerability testing and penetration tests to detect vulnerabilities before an attack.

7. Continuous monitoring and attack detection

  • Increased monitoring: Use of monitoring systems to constantly monitor network traffic and systems for suspicious activity.
  • Traffic and system log analysis: Analysis of data and logs to identify unusual behaviors or intrusion attempts.

8. Installation and maintenance of backups

  • Backups and isolated copies: Maintain secure backups that are not directly accessible over the network to ensure data recovery in the event of a ransomware attack.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS