Ransomware Resurgence: 5 Lessons from Healthcare’s Cyber Frontlines

Healthcare leaders are facing a mounting security crisis: More than two-thirds of healthcare organizations experienced ransomware attacks in 2024. Five of the top 10 ransomware attacks last year involved healthcare, and recovery costs averaged more than $2.5 million per incident. 

This resurgence of ransomware attacks on the industry is partly thanks to the spread of ransomware-as-a-service (RaaS), eliminating the need for advanced technical expertise to carry out attacks. Healthcare continues to be an attractive target due to its critical nature: when patient lives are at stake, health systems are more likely to pay the ransom to restore operations as quickly as possible.

Cybercriminals value patient data, such as medical histories, Social Security numbers, insurance details, and financial records. Often sold on the dark web, this data is more valuable than standard credit card information because of its usefulness in a wide range of fraudulent activities, such as identity theft, insurance fraud, and even blackmail.

While the increasing digitization of healthcare supports obvious benefits like efficiency and improved care, it unfortunately also creates more opportunities for cybercriminals. Many organizations still use legacy systems with significant security risks. Connected devices such as MRI machines, ventilators, and heart monitors often lack standard security controls or have critical software vulnerabilities that make them attractive entry points. Third-party vendors offering services related to billing, data storage, or other operations may also have cybersecurity gaps that ransomware attackers can exploit to gain access to healthcare systems.

Beyond the cost and the threat to data, ransomware attacks severely compromise healthcare systems’ ability to treat patients. Downtime and loss of access to critical information have profound and far-reaching effects on patient care and safety. The impact of a ransomware attack can include:

  • Delayed or canceled treatments. When systems are unavailable, hospitals may struggle to access patient records, schedule procedures, or conduct diagnostic tests, leading to delays in urgent care. An attack on Lurie Children’s Hospital in Chicago affected a wide range of operations, from prescription refills to scheduling, causing significant backlogs.
  • Diverted emergency services. Manchester Memorial Hospital in Connecticut was forced to send emergency care patients to other hospitals for more than two weeks after an attack rendered its systems inoperable.
  • Ripple effects across the healthcare ecosystem. The impact of ransomware extends beyond the affected facility to nearby hospitals and providers, overwhelming resources and negatively affecting patient care. One study found stroke code activations doubled, cardiac arrests increased by 81%, and EMS arrivals increased by 35.2% at nearby hospitals after a ransomware attack.
  • Financial impacts. An outage caused by ransomware at Change Healthcare, which provides revenue and payment cycle management services, prevented healthcare organizations from receiving insurance reimbursements. Unable to pay for operational expenses, many smaller practices faced potential closure — affecting not only the healthcare professionals and staff, but their patients and communities as well.

Given these devastating outcomes, you would think healthcare systems would waste no time bolstering their defenses. Yet the industry still lags behind others when it comes to implementing robust cybersecurity measures that can proactively fend off attacks or mitigate damage from ransomware. More than half of healthcare organizations report allocating less than 10% of their IT budget to cybersecurity.

Bolstering healthcare cybersecurity for evolving threats

 It’s time for healthcare leaders to start treating ransomware like what it is: a threat to patient safety and public health. Here are five strategic recommendations for proactively strengthening organizational resilience, securing data, and reducing disruptions caused by ransomware attacks.

  1. Undertake regular risk assessments. Organizations should conduct comprehensive investigations at least annually to identify and address weaknesses in their technology infrastructure and procedures. These should include penetration testing and other real-world exercises to uncover opportunities that automated tools might miss. 
  2. Strengthen defenses. Advanced cybersecurity tools and services can identify ransomware attacks via real-time monitoring and AI-based intelligence, which can quickly recognize unusual activities or behaviors. They can also automatically take action to contain or address threats, preventing significant damage before IT teams can step in.
  3. Train staff. Some of the most common entry points in security incidents are employees, who are targeted via phishing attempts or ploys to gain access to their credentials. In a fast-paced, high-pressure environment like a hospital, workers are even more vulnerable to phishing. Regular cybersecurity training helps them recognize up-to-date social engineering tactics and reinforces security awareness as a part of their job.
  4. Ensure backups are secure. Your system could be hit with ransomware at any time, so take steps to back up systems and data. 95% of healthcare organizations hit by ransomware in 2023 said that the attackers also attempted to compromise their backups, so follow the 3-2-1 rule: keep at least three copies of data on two types of media, with one copy stored offsite or in a secure cloud environment. Offline or air-gapped backups ensure there is always a clean copy for recovery. It’s also essential to regularly test backups and restoration processes to ensure data hasn’t been compromised, minimize downtime, and facilitate rapid recovery in a crisis.
  5. Implement access controls. Limiting remote access to systems, unless multi-factor authentication (MFA) is in place, helps prevent incursions from unauthorized users. Role-based access controls (RBAC) ensure users can only access systems and functions that are necessary for their job functions, so even if ransomware attackers gain access with employee credentials, the damage they can do is limited. Overall, healthcare organizations should implement a zero trust approach that continuously verifies all requests.

The ever-increasing sophistication of ransomware groups, and their relentless focus on exploiting vulnerabilities in healthcare systems, adds to the urgency of this issue. In the interconnected environment of modern healthcare, a single cyber incident can cascade to affect not just one healthcare system but organizations in an entire region.

Cybersecurity has become as critical to patient outcomes as medical equipment. Investing in solutions that proactively defend healthcare networks from intrusion, minimize potential damage, and ensure clean backups for operational continuity can help ensure healthcare organizations stay online and functional even in the face of accelerating cyber threats.

__

Tamra Durfee, vCISO, Fortified Health Security, is an experienced CISO with over 25 years in information security, compliance, regulatory risk, strategy, innovation, and technology transformation. For the past 8 years, she has specialized in healthcare cybersecurity and building risk-based medical device information security programs. She is a presenter at HIMSS, CHIME, CHA, and a healthcare security contributor to Healthcare IT News. Tamra holds certifications as a Certified Healthcare CIO (CHCIO), Certified Digital Healthcare Executive (CDH-E), GIAC Security Leadership Certification, Certified Professional in Healthcare Information Management Systems (CPHIMS), and IBM Certified Solutions Architect. 

The post Ransomware Resurgence: 5 Lessons from Healthcare’s Cyber Frontlines first appeared on Cybersecurity Insiders.

The post Ransomware Resurgence: 5 Lessons from Healthcare’s Cyber Frontlines appeared first on Cybersecurity Insiders.

from Cybersecurity Insiders https://ift.tt/ezsBrYC
via IFTTT

Your Apps Are Leaking: Understanding and Preventing Mobile Data Exposure

In our hyperconnected world, mobile devices are no longer a convenience but central to how businesses operate and communicate. As organizations increasingly embrace mobility and bring-your-own-device (BYOD) policies, a hidden risk is quietly growing within the apps we rely on every day: mobile data leaks.

While many assume that breaches occur from malicious hacking attempts, a far more overlooked threat is the unintentional exposure of sensitive data due to misconfigured cloud services or weak cryptographic practices. This is not a hypothetical concern. In 2024 alone, over 1.7 billion individuals were impacted by personal data compromises, marking a 312% increase from the previous year. The financial toll? An estimated $280 billion.

Zimperium’s zLabs research team analyzed over 54,000 work-related mobile apps used by enterprise device fleets. Their findings reveal a disturbing reality that cloud misconfigurations and cryptographic flaws are widespread and, more importantly, preventable.

What Is a Mobile Data Leak?

A data leak occurs when sensitive information becomes unintentionally accessible to unauthorized individuals, often due to poor design, misconfiguration, or oversight in app development. Data breaches usually stem from deliberate, external attacks, and one of the main vehicles for these types of threats is attackers exploiting vulnerabilities that produce data leaks. 

Mobile apps that store data in the cloud or perform cryptographic operations are particularly opportunistic for such leaks. With mobile devices acting as both personal and business tools, the line between consumer and corporate data is increasingly blurred. This makes the implications of a mobile data leak even more severe, especially when it comes to personally identifiable information (PII), financial data, intellectual property, and corporate credentials.

Cloud Misconfigurations: Convenience With a Cost

Cloud services are widely adopted in mobile app development for their scalability and ease of use, but this convenience comes with a cost. Of the apps analyzed, 62% leveraged some form of cloud integration. Alarmingly, dozens of these were found to use cloud storage services without proper protection.

For example, over 100 Android apps were discovered with unprotected or misconfigured cloud storage. In several cases, entire file directories were accessible without authentication, some even ranked among the top 1,000 most downloaded apps. This means a malicious actor wouldn’t need sophisticated tools or insider knowledge, just a web browser and patience, to access sensitive enterprise data.

Additionally, 10 apps had exposed hardcoded AWS credentials, effectively handing attackers the keys to access or even manipulate data. These types of exposures not only compromise confidentiality but could also enable attackers to delete or encrypt data for ransom, simulating the impact of a ransomware attack without deploying malware.

Even major corporations are not immune. A recent case involving one of the world’s largest automotive manufacturers saw over 260,000 customer records exposed due to a simple cloud misconfiguration. It is evident that mobile security must be embedded from the ground up, not implemented after the fact.

Cryptography: A False Sense of Security (if done wrong)

Encryption is often viewed as a silver bullet for data protection, but not all encryption is implemented equal. zLabs’ research revealed that 88% of all analyzed apps, and nearly half of the top 100, use cryptographic methods that fail to meet industry best practices.

Common pitfalls include:

  • Hardcoded cryptographic keys
  • Outdated algorithms like MD2
  • Predictable random number generators
  • Reuse of the same encryption keys across multiple operations

These flaws could render encryption useless because if attackers can guess, retrieve, or reverse-engineer cryptographic keys, the data becomes exposed regardless of how well it is stored or transmitted. In some cases, cryptographic weaknesses open the door to deeper attacks on enterprise infrastructure, such as man in the middle attacks.

The Organizational Cost

The repercussions of mobile data leaks extend far beyond technical headaches as enterprises can face legal liability, reputational damage, and significant financial loss. Regulatory frameworks like GDPR, HIPAA, and others demand stringent data protection measures, and failing to comply can lead to detrimental penalties.The average cost of a data breach has risen to nearly $5 million per incident, with cloud misconfigurations and compromised credentials ranking among the most frequent root causes. These issues are not just IT problems, they are inherent business risks.

What Can Organizations Do?

Mobile data security begins with visibility, so it’s critical that organizations first understand the behavior of the apps operating within their environments. While they may not control third-party code, they can certainly control which apps are allowed on employee devices and under what conditions.

A proactive strategy includes cloud security checks to identify misconfigured or public-facing cloud storage, monitor for exposed credentials and API keys, and assess the security of integrated cloud services. This helps reduce the risk of unauthorized data access or leaks through cloud platforms.

Implementing cryptographic best practices is also essential. Organizations should validate that apps use modern, strong encryption algorithms and ensure proper key management by avoiding hardcoded keys. Additionally, it’s important to watch for weak or predictable random number generation that could compromise security.

Finally, third-party component vetting plays a crucial role. This involves evaluating the security of embedded SDKs and libraries, as well as tracking and responding to known vulnerabilities in third-party code. By staying vigilant and selective with the software components used, organizations can strengthen their mobile security posture.

Ultimately, security teams must adopt a mindset of continuous monitoring and risk assessment. Mobile threat defense solutions and app vetting tools are essential for ensuring that employees’ devices don’t become backdoors into enterprise systems.

Mobile devices and apps are here to stay since they are powerful, portable, and indispensable to modern business. But with their ubiquity comes responsibility as data doesn’t leak on its own with poor security practices letting it slip through the cracks. As organizations embrace the flexibility of mobile work, they must also adopt rigorous standards for app security.

 

The post Your Apps Are Leaking: Understanding and Preventing Mobile Data Exposure first appeared on Cybersecurity Insiders.

The post Your Apps Are Leaking: Understanding and Preventing Mobile Data Exposure appeared first on Cybersecurity Insiders.

from Cybersecurity Insiders https://ift.tt/QbxRUCD
via IFTTT

CISO Global Shifts to SaaS Cybersecurity Platform

Leading cybersecurity provider CISO Global (NASDAQ: CISO) is entering a new phase of growth, pivoting toward high-margin, recurring-revenue software offerings that complement its managed and professional services. According to a recent Zacks report, the company has launched multiple proprietary software platforms, including its AI-driven Argo Security Management platform, and expects significant revenue growth driven by recurring software sales. After restructuring its go-to-market strategy and consolidating 20+ acquisitions, CISO Global projects improved margins and a more scalable revenue model in 2025.

Strategic Pivot: From Services to Software-Led Security

At the core of CISO Global’s recent announcements is a fundamental business model shift. For years, the company grew rapidly through more than 25 acquisitions, assembling a diversified portfolio of managed services, incident response, and consulting capabilities. But services alone are notoriously hard to scale. The move to develop proprietary platforms like Argo signals a deliberate step toward SaaS-driven margins and recurring revenue stability.

Argo, CISO’s flagship security management platform, appears to be central to this transition. It leverages AI to streamline threat detection and response workflows, likely integrating telemetry from customers’ existing security stacks. While details are limited, the platform’s focus on centralized visibility and orchestration suggests it may function similarly to extended detection and response (XDR) models—but tailored for mid-market clients without large SecOps teams.

Notably, CISO Global reported $57.4 million in revenue in 2023, with over 50% tied to managed and recurring offerings. This is important. The company isn’t just launching software; it’s converting existing service relationships into subscription-based platform engagements. That gives it a built-in upsell path, reducing customer acquisition costs and deepening account stickiness—both critical for margin expansion.

The report also signals a clear shift in leadership focus. CEO David Jemmett has stepped into a new role as Chief Strategy Officer, making room for new executives better suited to scale this next chapter. Strategic realignments like this often hint at a company preparing to be measured not just on top-line growth, but on operational metrics like gross margin, customer retention, and ARR growth rate.

Zooming Out: Industry Trends and Competitive Pressure

CISO Global’s evolution is part of a larger movement across the cybersecurity landscape: MSSPs and consulting-heavy vendors are increasingly building or acquiring software IP to escape the margin squeeze of labor-intensive services. We’ve seen this before—Palo Alto Networks transitioned from appliances to cloud-delivered security, and Mandiant (pre- and post-Google) has flirted with similar hybrid models mixing IR with platform technology.

The recurring revenue model CISO is targeting is more than just a financial goal—it’s a response to customer demand. In the wake of SaaS sprawl, security leaders are looking for fewer vendors who can offer toolchain consolidation, streamlined dashboards, and built-in threat intelligence. Platforms like Argo potentially offer mid-sized enterprises a way to get “just enough” of an XDR/SIEM/SOAR experience without hiring a squad of engineers to manage it.

The timing is also aligned with significant external pressures. The SEC’s cybersecurity disclosure rules, effective as of late 2023, are pushing boards and executives to demand more continuous, auditable visibility into their risk posture. That visibility can’t be delivered through consulting alone—it needs centralized, always-on platforms. Regulatory scrutiny has effectively created a commercial tailwind for vendors with dashboardable, metrics-driven solutions.

Also worth noting: CISO Global’s increased investment in recurring software comes at a time when investor expectations are shifting. The report highlights that gross margins on software sales can reach 70–80%, compared to services margins that often cap out around 30–40%. As cybersecurity valuations compress across public markets, investors are rewarding companies that prioritize durable, high-margin revenue streams over raw top-line growth.

A Strategic Move with Tactical Consequences

For cybersecurity leaders watching this space, the lesson isn’t just about following CISO Global’s trajectory—it’s about understanding the broader shift in what buyers are asking for and what vendors are trying to become. As more providers launch hybrid models—bundling consulting with proprietary platforms—CISOs need to sharpen their scrutiny. Are you buying expert hands, or just renting access to another dashboard?

Security buyers should also ask tough questions about integration, data portability, and lock-in. A platform like Argo may offer real value in visibility and orchestration, but only if it plays well with your existing stack and doesn’t become another silo. And for vendors, the takeaway is clear: if you’re services-heavy today, the pressure is on to deliver software that not only generates revenue, but demonstrably reduces customer risk.

The post CISO Global Shifts to SaaS Cybersecurity Platform first appeared on Cybersecurity Insiders.

The post CISO Global Shifts to SaaS Cybersecurity Platform appeared first on Cybersecurity Insiders.

from Cybersecurity Insiders https://ift.tt/2g35Urk
via IFTTT

PowerSchool customers hit by downstream extortion threats

Five months after education software vendor PowerSchool paid an unnamed threat actor a ransom in exchange for the deletion of sensitive stolen data, some of the company’s customers are now receiving extortion demands. 

A threat actor, who may or not be the same criminal group behind the attack, has contacted four school district customers of PowerSchool in the past few days, CyberScoop has learned, threatening to leak data if they don’t pay. 

The downstream extortion attacks highlight the ongoing risk organizations confront when a vendor is hit by a cyberattack, exposing not just their data but also that of others in their supply chain. The follow-on extortion attempts also underscore that paying ransoms for data does not guarantee stolen data won’t be leaked.

“PowerSchool is aware that a threat actor has reached out to multiple school district customers in an attempt to extort them using data from the previously reported December 2024 incident,” a company spokesperson said Wednesday in a statement. “We do not believe this is a new incident, as samples of the data match the data previously stolen in December.”

The company did not say how much it paid in ransom. “We made the decision to pay a ransom because we believe it to be in the best interest of our customers and the students and communities we serve,” the spokesperson said. 

“We thought it was the best option for preventing the data from being made public, and we felt it was our duty to take that action,” the spokesperson added. “As is always the case with these situations, there was a risk that the bad actors would not delete the data they stole, despite assurances and evidence that were provided to us.”

PowerSchool provides a suite of cloud-based software — including a student information system — to K-12 schools and districts, supporting more than 60 million students and 18,000 customers in over 90 countries. The company says its customers include more than 90 of the 100 largest school districts in the United States. 

The company identified suspicious activity in the PowerSchool Student Information System on Dec. 28 of last year. CrowdStrike, which already provided endpoint detection-and-response software and a threat-hunting service to PowerSchool, began an investigation into the circumstances behind the attack the following day.

The unnamed attacker gained access to PowerSchool’s system with a compromised credential for a support user in the company’s PowerSource support portal. The level of access granted to a support technician includes “sufficient permissions to gain access to customer SIS database instances for maintenance purposes,” CrowdStrike said in an investigation report it released in late February. 

The threat stole data from the “teachers” and “students” tables of the PowerSchool SIS instances for certain PowerSchool customers between Dec. 19 and Dec. 23, according to CrowdStrike’s report. The incident response firm said it found no evidence of system-layer access or malware, and nothing to indicate PowerSchool customer IT environments outside of PowerSource and PowerSchool SIS were compromised or at risk of intrusion due to the attack.

CrowdStrike found evidence of earlier unauthorized activity in the PowerSchool environment associated with the compromised support credentials between Aug. 16 and Sept. 17, but it couldn’t attribute this activity to the threat actor responsible for the malicious activity in December 2024.

The last evidence of threat actor activity occurred Dec. 28, when the attacker “used the compromised support credentials to log in to the maintenance interface of PowerSource to interact with PowerSchool SIS,” CrowdStrike said in the report.

PowerSchool customers have contacted the company to inform it of the recent extortion demands and threats. 

“We have reported this matter to law enforcement both in the United States and in Canada, and are working closely with our customers to support them,” the company spokesperson said. “We sincerely regret these developments — it pains us that our customers are being threatened and re-victimized by bad actors.”

The post PowerSchool customers hit by downstream extortion threats appeared first on CyberScoop.

from CyberScoop https://ift.tt/Y1S0HTP
via IFTTT

Pakistani Firm Shipped Fentanyl Analogs, Scams to US

A Texas firm recently charged with conspiring to distribute synthetic opioids in the United States is at the center of a vast network of companies in the U.S. and Pakistan whose employees are accused of using online ads to scam westerners seeking help with trademarks, book writing, mobile app development and logo designs, a new investigation reveals.

In an indictment (PDF) unsealed last month, the U.S. Department of Justice said Dallas-based eWorldTrade “operated an online business-to-business marketplace that facilitated the distribution of synthetic opioids such as isotonitazene and carfentanyl, both significantly more potent than fentanyl.”

Launched in 2017, eWorldTrade[.]com now features a seizure notice from the DOJ. eWorldTrade operated as a wholesale seller of consumer goods, including clothes, machinery, chemicals, automobiles and appliances. The DOJ’s indictment includes no additional details about eWorldTrade’s business, origins or other activity, and at first glance the website might appear to be a legitimate e-commerce platform that also just happened to sell some restricted chemicals

A screenshot of the eWorldTrade homepage on March 25, 2025. Image: archive.org.

However, an investigation into the company’s founders reveals they are connected to a sprawling network of websites that have a history of extortionate scams involving trademark registration, book publishing, exam preparation, and the design of logos, mobile applications and websites.

Records from the U.S. Patent and Trademark Office (USPTO) show the eWorldTrade mark is owned by an Azneem Bilwani in Karachi (this name also is in the registration records for the now-seized eWorldTrade domain). Mr. Bilwani is perhaps better known as the director of the Pakistan-based IT provider Abtach Ltd., which has been singled out by the USPTO and Google for operating trademark registration scams (the main offices for eWorldtrade and Abtach share the same address in Pakistan).

In November 2021, the USPTO accused Abtach of perpetrating “an egregious scheme to deceive and defraud applicants for federal trademark registrations by improperly altering official USPTO correspondence, overcharging application filing fees, misappropriating the USPTO’s trademarks, and impersonating the USPTO.”

Abtach offered trademark registration at suspiciously low prices compared to legitimate costs of over USD $1,500, and claimed they could register a trademark in 24 hours. Abtach reportedly rebranded to Intersys Limited after the USPTO banned Abtach from filing any more trademark applications.

In a note published to its LinkedIn profile, Intersys Ltd. asserted last year that certain scam firms in Karachi were impersonating the company.

FROM AXACT TO ABTACH

Many of Abtach’s employees are former associates of a similar company in Pakistan called Axact that was shut down by Pakistani authorities for fraud in 2015. Axact met its demise not long after The New York Times ran a front-page story about the company’s most lucrative scam business: Hundreds of sites peddling fake college degrees and diplomas.

People who purchased fake certifications were subsequently blackmailed by Axact employees posing as government officials, who would demand additional payments under threats of prosecution or imprisonment for having bought fraudulent “unauthorized” academic degrees. This practice created a continuous cycle of extortion, internally referred to as “upselling.”

“Axact took money from at least 215,000 people in 197 countries — one-third of them from the United States,” The Times reported. “Sales agents wielded threats and false promises and impersonated government officials, earning the company at least $89 million in its final year of operation.”

Dozens of top Axact employees were arrested, jailed, held for months, tried and sentenced to seven years for various fraud violations. But a 2019 research brief on Axact’s diploma mills found none of those convicted had started their prison sentence, and that several had fled Pakistan and never returned.

“In October 2016, a Pakistan district judge acquitted 24 Axact officials at trial due to ‘not enough evidence’ and then later admitted he had accepted a bribe (of $35,209) from Axact,” reads a history (PDF) published by the American Association of Collegiate Registrars and Admissions Officers.

In 2021, Pakistan’s Federal Investigation Agency (FIA) charged Bilwani and nearly four dozen others — many of them Abtach employees — with running an elaborate trademark scam. The authorities called it “the biggest money laundering case in the history of Pakistan,” and named a number of businesses based in Texas that allegedly helped move the proceeds of cybercrime.

A page from the March 2021 FIA report alleging that Digitonics Labs and Abtach employees conspired to extort and defraud consumers.

The FIA said the defendants operated a large number of websites offering low-cost trademark services to customers, before then “ignoring them after getting the funds and later demanding more funds from clients/victims in the name of up-sale (extortion).” The Pakistani law enforcement agency said that about 75 percent of customers received fake or fabricated trademarks as a result of the scams.

The FIA found Abtach operates in conjunction with a Karachi firm called Digitonics Labs, which earned a monthly revenue of around $2.5 million through the “extortion of international clients in the name of up-selling, the sale of fake/fabricated USPTO certificates, and the maintaining of phishing websites.”

According the Pakistani authorities, the accused also ran countless scams involving ebook publication and logo creation, wherein customers are subjected to advance-fee fraud and extortion — with the scammers demanding more money for supposed “copyright release” and threatening to release the trademark.

Also charged by the FIA was Junaid Mansoor, the owner of Digitonics Labs in Karachi. Mansoor’s U.K.-registered company Maple Solutions Direct Limited has run at least 700 ads for logo design websites since 2015, the Google Ads Transparency page reports. The company has approximately 88 ads running on Google as of today. 

Junaid Mansoor. Source: youtube/@Olevels․com School.

Mr. Mansoor is actively involved with and promoting a Quran study business called quranmasteronline[.]com, which was founded by Junaid’s brother Qasim Mansoor (Qasim is also named in the FIA criminal investigation). The Google ads promoting quranmasteronline[.]com were paid for by the same account advertising a number of scam websites selling logo and web design services. 

Junaid Mansoor did not respond to requests for comment. An address in Teaneck, New Jersey where Mr. Mansoor previously lived is listed as an official address of exporthub[.]com, a Pakistan-based e-commerce website that appears remarkably similar to eWorldTrade (Exporthub says its offices are in Texas). Interestingly, a search in Google for this domain shows ExportHub currently features multiple listings for fentanyl citrate from suppliers in China and elsewhere.

The CEO of Digitonics Labs is Muhammad Burhan Mirza, a former Axact official who was arrested by the FIA as part of its money laundering and trademark fraud investigation in 2021. In 2023, prosecutors in Pakistan charged Mirza, Mansoor and 14 other Digitonics employees with fraud, impersonating government officials, phishing, cheating and extortion. Mirza’s LinkedIn profile says he currently runs an educational technology/life coach enterprise called TheCoach360, which purports to help young kids “achieve financial independence.”

Reached via LinkedIn, Mr. Mirza denied having anything to do with eWorldTrade or any of its sister companies in Texas.

“Moreover, I have no knowledge as to the companies you have mentioned,” said Mr. Mirza, who did not respond to follow-up questions.

The current disposition of the FIA’s fraud case against the defendants is unclear. The investigation was marred early on by allegations of corruption and bribery. In 2021, Pakistani authorities alleged Bilwani paid a six-figure bribe to FIA investigators. Meanwhile, attorneys for Mr. Bilwani have argued that although their client did pay a bribe, the payment was solicited by government officials. Mr. Bilwani did not respond to requests for comment.

THE TEXAS NEXUS

KrebsOnSecurity has learned that the people and entities at the center of the FIA investigations have built a significant presence in the United States, with a strong concentration in Texas. The Texas businesses promote websites that sell logo and web design, ghostwriting, and academic cheating services. Many of these entities have recently been sued for fraud and breach of contract by angry former customers, who claimed the companies relentlessly upsold them while failing to produce the work as promised.

For example, the FIA complaints named Retrocube LLC and 360 Digital Marketing LLC, two entities that share a street address with eWorldTrade: 1910 Pacific Avenue, Suite 8025, Dallas, Texas. Also incorporated at that Pacific Avenue address is abtach[.]ae, a web design and marketing firm based in Dubai; and intersyslimited[.]com, the new name of Abtach after they were banned by the USPTO. Other businesses registered at this address market services for logo design, mobile app development, and ghostwriting.

A list published in 2021 by Pakistan’s FIA of different front companies allegedly involved in scamming people who are looking for help with trademarks, ghostwriting, logos and web design.

360 Digital Marketing’s website 360digimarketing[.]com is owned by an Abtach front company called Abtech LTD. Meanwhile, business records show 360 Digi Marketing LTD is a U.K. company whose officers include former Abtach director Bilwani; Muhammad Saad Iqbal, formerly Abtach, now CEO of Intersys Ltd; Niaz Ahmed, a former Abtach associate; and Muhammad Salman Yousuf, formerly a vice president at Axact, Abtach, and Digitonics Labs.

Google’s Ads Transparency Center finds 360 Digital Marketing LLC ran at least 500 ads promoting various websites selling ghostwriting services . Another entity tied to Junaid Mansoor — a company called Octa Group Technologies AU — has run approximately 300 Google ads for book publishing services, promoting confusingly named websites like amazonlistinghub[.]com and barnesnoblepublishing[.]co.

360 Digital Marketing LLC ran approximately 500 ads for scam ghostwriting sites.

Rameez Moiz is a Texas resident and former Abtach product manager who has represented 360 Digital Marketing LLC and RetroCube. Moiz told KrebsOnSecurity he stopped working for 360 Digital Marketing in the summer of 2023. Mr. Moiz did not respond to follow-up questions, but an Upwork profile for him states that as of April 2025 he is employed by Dallas-based Vertical Minds LLC.

In April 2025, California resident Melinda Will sued the Texas firm Majestic Ghostwriting — which is doing business as ghostwritingsquad[.]com —  alleging they scammed her out of $100,000 after she hired them to help write her book. Google’s ad transparency page shows Moiz’s employer Vertical Minds LLC paid to run approximately 55 ads for ghostwritingsquad[.]com and related sites.

Google’s ad transparency listing for ghostwriting ads paid for by Vertical Minds LLC.

VICTIMS SPEAK OUT

Ms. Will’s lawsuit is just one of more than two-dozen complaints over the past four years wherein plaintiffs sued one of this group’s web design, wiki editing or ghostwriting services. In 2021, a New Jersey man sued Octagroup Technologies, alleging they ripped him off when he paid a total of more than $26,000 for the design and marketing of a web-based mapping service.

The plaintiff in that case did not respond to requests for comment, but his complaint alleges Octagroup and a myriad other companies it contracted with produced minimal work product despite subjecting him to relentless upselling. That case was decided in favor of the plaintiff because the defendants never contested the matter in court.

In 2023, 360 Digital Marketing LLC and Retrocube LLC were sued by a woman who said they scammed her out of $40,000 over a book she wanted help writing. That lawsuit helpfully showed an image of the office front door at 1910 Pacific Ave Suite 8025, which featured the logos of 360 Digital Marketing, Retrocube, and eWorldTrade.

The front door at 1910 Pacific Avenue, Suite 8025, Dallas, Texas.

The lawsuit was filed pro se by Leigh Riley, a 64-year-old career IT professional who paid 360 Digital Marketing to have a company called Talented Ghostwriter co-author and promote a series of books she’d outlined on spirituality and healing.

“The main reason I hired them was because I didn’t understand what I call the formula for writing a book, and I know there’s a lot of marketing that goes into publishing,” Riley explained in an interview. “I know nothing about that stuff, and these guys were convincing that they could handle all aspects of it. Until I discovered they couldn’t write a damn sentence in English properly.”

Riley’s well-documented lawsuit (not linked here because it features a great deal of personal information) includes screenshots of conversations with the ghostwriting team, which was constantly assigning her to new writers and editors, and ghosting her on scheduled conference calls about progress on the project. Riley said she ended up writing most of the book herself because the work they produced was unusable.

“Finally after months of promising the books were printed and on their way, they show up at my doorstep with the wrong title on the book,” Riley said. When she demanded her money back, she said the people helping her with the website to promote the book locked her out of the site.

A conversation snippet from Leigh Riley’s lawsuit against Talented Ghostwriter, aka 360 Digital Marketing LLC. “Other companies once they have you money they don’t even respond or do anything,” the ghostwriting team manager explained.

Riley decided to sue, naming 360 Digital Marketing LLC and Retrocube LLC, among others.  The companies offered to settle the matter for $20,000, which she accepted. “I didn’t have money to hire a lawyer, and I figured it was time to cut my losses,” she said.

Riley said she could have saved herself a great deal of headache by doing some basic research on Talented Ghostwriter, whose website claims the company is based in Los Angeles. According to the California Secretary of State, however, there is no registered entity by that name. Rather, the address claimed by talentedghostwriter[.]com is a vacant office building with a “space available” sign in the window.

California resident Walter Horsting discovered something similar when he sued 360 Digital Marketing in small claims court last year, after hiring a company called Vox Ghostwriting to help write, edit and promote a spy novel he’d been working on. Horsting said he paid Vox $3,300 to ghostwrite a 280-page book, and was upsold an Amazon marketing and publishing package for $7,500.

In an interview, Horsting said the prose that Vox Ghostwriting produced was “juvenile at best,” forcing him to rewrite and edit the work himself, and to partner with a graphical artist to produce illustrations. Horsting said that when it came time to begin marketing the novel, Vox Ghostwriting tried to further upsell him on marketing packages, while dodging scheduled meetings with no follow-up.

“They have a money back guarantee, and when they wouldn’t refund my money I said I’m taking you to court,” Horsting recounted. “I tried to serve them in Los Angeles but found no such office exists. I talked to a salon next door and they said someone else had recently shown up desperately looking for where the ghostwriting company went, and it appears there are a trail of corpses on this. I finally tracked down where they are in Texas.”

It was the same office that Ms. Riley served her lawsuit against. Horsting said he has a court hearing scheduled later this month, but he’s under no illusions that winning the case means he’ll be able to collect.

“At this point, I’m doing it out of pride more than actually expecting anything to come to good fortune for me,” he said.

The following mind map was helpful in piecing together key events, individuals and connections mentioned above. It’s important to note that this graphic only scratches the surface of the operations tied to this group. For example, in Case 2 we can see mention of academic cheating services, wherein people can be hired to take online proctored exams on one’s behalf. Those who hire these services soon find themselves subject to impersonation and blackmail attempts for larger and larger sums of money, with the threat of publicly exposing their unethical academic cheating activity.

A “mind map” illustrating the connections between and among entities referenced in this story. Click to enlarge.

GOOGLE RESPONDS

KrebsOnSecurity reviewed the Google Ad Transparency links for nearly 500 different websites tied to this network of ghostwriting, logo, app and web development businesses. Those website names were then fed into spyfu.com, a competitive intelligence company that tracks the reach and performance of advertising keywords. Spyfu estimates that between April 2023 and April 2025, those websites spent more than $10 million on Google ads.

Reached for comment, Google said in a written statement that it is constantly policing its ad network for bad actors, pointing to an ads safety report (PDF) showing Google blocked or removed 5.1 billion bad ads last year — including more than 500 million ads related to trademarks.

“Our policy against Enabling Dishonest Behavior prohibits products or services that help users mislead others, including ads for paper-writing or exam-taking services,” the statement reads. “When we identify ads or advertisers that violate our policies, we take action, including by suspending advertiser accounts, disapproving ads, and restricting ads to specific domains when appropriate.”

Google did not respond to specific questions about the advertising entities mentioned in this story, saying only that “we are actively investigating this matter and addressing any policy violations, including suspending advertiser accounts when appropriate.”

From reviewing the ad accounts that have been promoting these scam websites, it appears Google has very recently acted to remove a large number of the offending ads. Prior to my notifying Google about the extent of this ad network on April 28, the Google Ad Transparency network listed over 500 ads for 360 Digital Marketing; as of this publication, that number had dwindled to 10.

On April 30, Google announced that starting this month its ads transparency page will display the payment profile name as the payer name for verified advertisers, if that name differs from their verified advertiser name. Searchengineland.com writes the changes are aimed at increasing accountability in digital advertising.

This spreadsheet lists the domain names, advertiser names, and Google Ad Transparency links for more than 350 entities offering ghostwriting, publishing, web design and academic cheating services.

KrebsOnSecurity would like to thank the anonymous security researcher NatInfoSec for their assistance in this investigation.

For further reading on Abtach and its myriad companies in all of the above-mentioned verticals (ghostwriting, logo design, etc.), see this Wikiwand entry.

from Krebs on Security https://ift.tt/pf2HWQv
via IFTTT

CrowdStrike cuts 5% of workforce after revenue jumped 29% last year

CrowdStrike is cutting 5% of its workforce, about 500 positions, telling its staff that it’s shifting resources and realigning its operating model for growth in new market segments, according to a Wednesday filing with the Securities and Exchange Commission.

The company is slashing headcount following a year of significant growth in a strong market. CrowdStrike’s revenue jumped 29% year-over-year to $3.95 billion in fiscal year 2025, which ended Jan. 31. Yet, the company also reported a net loss of $19.3 million in FY25 after reporting net income of $89.3 million the previous year.

CrowdStrike’s growing use of artificial intelligence for internal operations was a factor behind the decision to cut staff in certain roles, according to CEO George Kurtz. “AI flattens our hiring curve, and helps us innovate from idea to product faster,” he said in a letter to employees. “It streamlines go-to-market, improves customer outcomes, and drives efficiencies across both the front and back office. AI is a force multiplier throughout the business.”

The company plans to continue hiring customer-facing and product engineering roles, but layoffs in other areas of the business suggests AI’s ability to automate some tasks and boost productivity has made some roles redundant.

Industry analysts question the extent to which CrowdStrike needed to or chose to point to AI as a factor leading to layoffs.

“We have to be careful that AI isn’t being used as an excuse for some area of the business that is underperforming,” said Neil MacDonald, a vice president and analyst at Gartner. 

“AI tools are used to make a given employee more productive, therefore you don’t need as many people,” MacDonald said. “But if you’re growing, what it means is you don’t have to hire as many [people], but it doesn’t necessarily mean you have to lay people off.”

CrowdStrike is the second-largest provider of endpoint protection, a market segment that drives the bulk of its revenue. Its market share in that segment grew from 20.3% in 2023 to 21.3% in 2024, according to Gartner.

Jeff Pollard, VP and principal analyst at Forrester, said Kurtz’s mention of AI likely came from some AI-related efficiency gains, but noted there’s also an industrywide trend at play. 

“Some amount of AI-washing is now prevalent in every one of these announcements and this is no exception,” he said. “In much the same way that ‘we take privacy and security very seriously’ can be found in every breach disclosure, so too can ‘AI productivity’ in workforce reduction announcements.”

Unfortunately, Pollard said, CrowdStrike’s “obligatory mention of AI” will be widely emulated by other cybersecurity vendors. 

Business leaders across multiple industries say they are looking to use AI to cut their workforce by at least 10% and up to 30%, including customer service, creative and administrative roles, according to Zeus Kerravala, principal analyst at ZK Research. 

“The layoffs are part of a broader set of efficiencies and I’m fully expecting to see more. This was only 5% and I think it’s more indicative of the state of AI rather than the state of cyber,” Kerravala said. 

“The layoffs should be viewed more as the evolution of AI and the changing nature of cyber rather than issues at CrowdStrike,” he added.

Kurtz said the decision to cut staff was predicated and driven by other factors as well. This includes, he said, a push to consolidate more customers on CrowdStrike’s Falcon platform, and multibillion-dollar opportunities in new market segments, such as tools for next generation security information and event management, identity, cloud and exposure management.

The company’s goals beyond its core business in endpoint protection pose an important question in the face of these layoffs, according to MacDonald. 

CrowdStrike is growing, gaining market share in cloud protection and SIEM last year, he said, but the company is still a relatively small player in those areas, and perhaps it’s not growing as quickly as it hoped in newer market segments.

“The cyber industry is changing with platforms starting to take hold over point products,” Kerravala said. “CrowdStrike will likely have to cut heads as they bring in talent around how to build and monetize platforms.”

The layoffs also come nearly 10 months after a faulty CrowdStrike Falcon security software update caused millions of Microsoft Windows systems to malfunction. That mistake caused major issues for businesses worldwide, and company executives have repeatedly said they need to regain the trust of customers.

CrowdStrike expects to incur up to $53 million in charges related to the layoffs, including severance payments, benefits and stock-based compensation.

“I know this is difficult news and it affects all of us. These decisions were made with care and guided by a clear view of where we need to go,” Kurtz said.

“As we evolve, we are laser-focused on transforming cybersecurity,” he said. “We stop breaches. This mission defines our purpose, unites our team and keeps us focused on what matters most: protecting our customers.”

The post CrowdStrike cuts 5% of workforce after revenue jumped 29% last year appeared first on CyberScoop.

from CyberScoop https://ift.tt/ZqsJOF5
via IFTTT

In the works – AWS South America (Chile) Region

Today, Amazon Web Services (AWS) announced plans to launch a new AWS Region in Chile by the end of 2026. The AWS South America (Chile) Region will consist of three Availability Zones at launch, bringing AWS infrastructure and services closer to customers in Chile. This new Region joins the AWS South America (São Paulo) and AWS Mexico (Central) Regions as our third AWS Region in Latin America. Each Availability Zone is separated by a meaningful distance to support applications that need low latency while significantly reducing the risk of a single event impacting availability.

Skyline of Santiago de Chile with modern office buildings in the financial district in Las Condes

The new AWS Region will bring advanced cloud technologies, including artificial intelligence (AI) and machine learning (ML), closer to customers in Latin America. Through high-bandwidth, low-latency network connections over dedicated, fully redundant fiber, the Region will support applications requiring synchronous replication while giving you the flexibility to run workloads and store data locally to meet data residency requirements.

AWS in Chile
In 2017, AWS established an office in Santiago de Chile to support local customers and partners. Today, there are business development teams, solutions architects, partner managers, professional services consultants, support staff, and personnel in various other roles working in the Santiago office.

As part of our ongoing commitment to Chile, AWS has invested in several infrastructure offerings throughout the country. In 2019, AWS launched an Amazon CloudFront edge location in Chile. This provides a highly secure and programmable content delivery network that accelerates the delivery of data, videos, applications, and APIs to users worldwide with low latency and high transfer speeds.

AWS strengthened its presence in 2021 with two significant additions. First, an AWS Ground Station antenna location in Punta Arenas, offering a fully managed service for satellite communications, data processing, and global satellite operations scaling. Second, AWS Outposts in Chile, bringing fully managed AWS infrastructure and services to virtually any on-premises or edge location for a consistent hybrid experience.

In 2023, AWS further enhanced its infrastructure with two key developments, an AWS Direct Connect location in Chile that lets you create private connectivity between AWS and your data center, office, or colocation environment, and AWS Local Zones in Santiago, placing compute, storage, database, and other select services closer to large population centers and IT hubs. The AWS Local Zone in Santiago helps customers deliver applications requiring single-digit millisecond latency to end users.

The upcoming AWS South America (Chile) Region represents our continued commitment to fueling innovation in Chile. Beyond building infrastructure, AWS plays a crucial role in developing Chile’s digital workforce through comprehensive cloud education initiatives. Through AWS Academy, AWS Educate, and AWS Skill Builder, AWS provides essential cloud computing skills to diverse groups—from students and developers to business professionals and emerging IT leaders. Since 2017, AWS has trained more than two million people across Latin America on cloud skills, including more than 100,000 in Chile.

AWS customers in Chile
AWS customers in Chile have been increasingly moving their applications to AWS and running their technology infrastructure in AWS Regions around the world. With the addition of this new AWS Region, customers will be able to provide even lower latency to end users and use advanced technologies such as generative AI, Internet of Things (IoT), mobile services, banking industry, and more, to drive innovation. This Region will give AWS customers the ability to run their workloads and store their content in Chile.

Here are some examples of customers in Chile using AWS to drive innovation:

The Digital Government Secretariat (SGD) is the Chilean government institution responsible for proposing and coordinating the implementation of the Digital Government Strategy, providing an integrated government approach. SGD coordinates, advises, and provides cross-sector support in the strategic use of digital technologies, data, and public information to improve state administration and service delivery. To fulfill this mission, SGD relies on AWS to operate critical digital platforms including Clave Única (single sign-on), FirmaGob (digital signature), the State Electronic Services Integration Platform (PISEE), DocDigital, SIMPLE, and the Administrative Procedures and Services Catalog (CPAT), among others.

Transbank, Chile’s largest payment solutions ecosystem managing the largest percentage of national transactions, used AWS to significantly reduce time-to-market for new products. Moreover, Transbank implemented multiple AWS-powered solutions, enhancing team productivity and accelerating innovation. These initiatives showcase how financial technology companies can use AWS to drive innovation and operational efficiency. “The new AWS Region in Chile will be very important for us,” said Jorge Rodríguez M., Chief Architecture and Technology Officer (CA&TO) of Transbank. “It will further reduce latency, improve security and expand the possibilities for innovation, allowing us to serve our customers with new and better services and products.”

To learn more about AWS customers in Chile, visit AWS Customer Success Stories.

AWS sustainability efforts in Chile
AWS is committed to water stewardship in Chile through innovative conservation projects. In the Maipo Basin, which provides essential water for the Metropolitan Santiago and Valparaiso regions, AWS has partnered with local farmers and climate-tech company Kilimo to implement water-saving initiatives. The project involves converting 67 hectares of agricultural land from flood to drip irrigation, which will save approximately 200 million liters of water annually.

This water conservation effort supports AWS commitment to be water positive by 2030 and demonstrates our dedication to environmental sustainability in the communities where AWS operate. The project uses efficient drip irrigation systems that deliver water directly to plant root systems through a specialized pipe network, maximizing water efficiency for agricultural use. To learn more about this initiative, read our blog post AWS expands its water replenishment program to China and Chile—and adds projects in the US and Brazil.

AWS community in Chile
The AWS community in Chile is one of the most active in the region, comprising of AWS Community Builders, two AWS User Groups (AWS User Group Chile and AWS Girls Chile), and an AWS Cloud Club. These groups hold monthly events and have organized two AWS Community Days. At the first Community Day, held in 2023, we had the honor of having Jeff Barr as the keynote speaker.

Chile AWS Community Day 2023

Stay tuned
We’ll announce the opening of this and the other Regions in future blog posts, so be sure to stay tuned! To learn more, visit the AWS Region in Chile page.

Eli

Thanks to Leonardo Vilacha for the Chile AWS Community Day 2023 photo.


How is the News Blog doing? Take this 1 minute survey!

(This survey is hosted by an external company. AWS handles your information as described in the AWS Privacy Notice. AWS will own the data gathered via this survey and will not share the information collected with survey respondents.)

from AWS News Blog https://ift.tt/P7H05cR
via IFTTT

Top 10 Cloud Security Mitigation Tactics

As businesses continue to migrate operations and data to the cloud, securing cloud environments has become more critical than ever. Cloud security threats are dynamic and complex, making proactive mitigation tactics essential to protect sensitive data, ensure compliance, and maintain business continuity. Below are ten proven tactics organizations should employ to mitigate cyber threats existing in the cloud environments.

1. Implement Strong Identity and Access Management (IAM)

IAM is the first line of defense in cloud security. Use multi-factor authentication (MFA), enforce least privilege principles, and regularly audit user roles and permissions. Centralized IAM helps ensure that only the right individuals have access to the right resources.

2. Encrypt Data at Rest and in Transit

Data should always be encrypted—whether it’s being stored or transmitted. Use strong encryption protocols such as AES-256 and TLS 1.2/1.3. Ensure encryption keys are managed securely, preferably through hardware security modules (HSMs) or a key management service (KMS).

3. Conduct Regular Security Audits and Penetration Testing

Regular audits and penetration tests help identify vulnerabilities before attackers can exploit them. These assessments should include code reviews, infrastructure scans, and configuration checks across all cloud services.

4. Enable Continuous Monitoring and Logging

Monitoring tools should be in place to detect anomalies and potential breaches in real time. Services like AWS CloudTrail, Azure Monitor, or Google Cloud’s Operations Suite offer robust visibility into activities across your cloud infrastructure.

5. Harden Cloud Configurations

Misconfigured cloud resources are one of the most common causes of breaches. Use automated tools like AWS Config, Azure Security Center, or open-source solutions like ScoutSuite to continuously validate and harden your environment against insecure settings.

6. Apply the Principle of Least Privilege (PoLP)

Ensure users and applications have only the access they need. This minimizes the risk of lateral movement in case an account is compromised. Implement granular access controls and isolate critical workloads whenever possible.

7. Regularly Patch and Update Systems

Outdated software and unpatched vulnerabilities are easy targets for attackers. Automate patch management and ensure all components—from VMs to containers and third-party applications—are up to date.

8. Use Firewalls and Network Segmentation

Network security remains vital. Use cloud-native firewalls, security groups, and network access control lists (ACLs) to filter traffic. Segment networks by environment (e.g., dev, test, prod) and by application type to limit the blast radius of potential attacks.

9. Implement a Strong Incident Response Plan

Have a well-documented and tested incident response (IR) plan specific to cloud services. This plan should define roles, communication protocols, and procedures for identifying, containing, and recovering from a breach.

10. Educate and Train Your Workforce

Human error is a persistent risk. Regular training and awareness programs can prevent phishing, social engineering, and accidental misconfigurations. Include cloud security best practices in onboarding and ongoing education.

Conclusion

Cloud security is a shared responsibility between providers and customers. By applying these ten mitigation tactics, organizations can significantly reduce their exposure to threats and maintain a strong cloud security posture. As technology evolves, staying informed and agile is just as important as any tool or policy.

The post Top 10 Cloud Security Mitigation Tactics first appeared on Cybersecurity Insiders.

The post Top 10 Cloud Security Mitigation Tactics appeared first on Cybersecurity Insiders.

from Cybersecurity Insiders https://ift.tt/9osPMYC
via IFTTT