April 2024, cybersecurity round-up

April 29, 2024 | Cybersecurity
Chloe Schofield

Written by
Chloe Schofield

As we head further into 2024, the cyberthreat landscape continues to evolve, presenting challenges for organisations across all industries worldwide. From operational disruptions to data breaches, businesses are grappling with relentless cyberattacks and trying to stay a step ahead.

Here's a look at the latest cybersecurity attacks this year.

Lights out in Leicester

Leicester's central management system suffered a sophisticated breach this month, resulting in streetlights remaining on day and night. The cyberattack has left officials scrambling to regain control.

Concerned residents first noticed the irregularity of the streetlights, raising the alarm and sparking unease among locals.

Streetlights remaining on may sound insignificant, but the disruption does pose safety concerns and has implications for the city's energy consumption and environmental impact.

With the shutdown of IT systems hindering remote diagnostics and repairs, Leicester City Council faces mounting pressure to speed up the restoration of essential services. City officials have assured locals that the problem will be resolved by the first week of May. However, concerns remain among locals regarding the prolonged impact of the cyberattack on essential services and infrastructure.

This incident highlights the need for robust cybersecurity measures to safeguard critical infrastructure for councils and other essential services.

Carpetright cyberattack

Flooring retailer Carpetright has found itself in the path of criminals this month, suffering a debilitating cyberattack. The attack on the company's IT infrastructure disrupted online and in-store ordering systems for nearly a week.

Hackers targeted Carpetright's head office, deploying malware to infiltrate systems and disrupt operations across the company's 400 stores and websites.

These types of attacks in the retail industry go beyond just operational disruptions. They cast a shadow of uncertainty over customer data security and brand reputation. Carpetright has supposedly reassured stakeholders that no sensitive employee or customer information was compromised, but the incident serves as a reminder of the significant impact cyberattacks can have.

Carpetright now faces pressure to strengthen its defences and prioritise investments in its security infrastructure.

Volkswagen cyber intrusion

Volkswagen, the automotive giant, has found itself caught up in a cybersecurity crisis following a cyberattack supposedly originating from China. The breach, which targeted sensitive data related to the company's electric vehicle initiatives, poses significant strategic and economic implications for the organisation.

The stolen data is said to contain confidential EV technologies and production strategies, which threaten Volkswagen's competitive edge in the expanding EV market. Around 19,000 documents were said to have been taken in the attack, but Volkswagen has managed to recover some of the stolen files.

As investigations into the cyber intrusion step up, speculation mounts about the identity and motives of the perpetrators behind the attack. The incident shows the vulnerability of major corporations and underscores the critical need for vigilance in safeguarding intellectual property.

Thwarted cyberattack over Easter

Thanks to a Microsoft developer, a potentially catastrophic cyberattack was narrowly missed over the Easter bank holiday weekend.

The attack targeted a widely used critical piece of open-source software. The meticulously planned attack aimed to insert a backdoor into Linux distributions. Fortunately, the backdoor was discovered before being implemented in production versions, avoiding what cybersecurity experts described as a catastrophic attack.

The supply chain attack involved slowly pushing updates to a compression zip tool shipped with Linux distributions, which created a backdoor to millions of computers.

This incident highlights the vulnerability of volunteer work to maintain critical digital infrastructure. However, it also highlights the benefits of open-source collaboration, as the attack was uncovered through the collective efforts of the cybersecurity community.

This incident demonstrates the importance of proactive threat detection and collaborative cybersecurity efforts.

Cybersecurity with Brigantia

Regardless of size or structure, businesses continually face the threat of cybercrime. Recent breaches and attacks are bold reminders of the more comprehensive impact attacks can have on the broader community. Robust defences are essential for all businesses to adopt modern cybersecurity strategies and implement robust measures.

At Brigantia, we work with top-tier vendors to deliver the latest technology and solutions to the MSP community. Contact our team if you're an MSP looking for cybersecurity solutions to enhance your offering.

Recommended reading

How Brigantia, Sendmarc and Air IT teamed up to tackle DMARC compliance

Leading MSP Air IT has announced a new partnership with Brigantia and Sendmarc to boost customers’ email ...

August 2024, cybersecurity round-up

It may be the summer holidays for many, but not in the world of cybercrime. August has been a busy month of ...

MFA bypass attacks are on the up: what can be done?

As I write this blog on an early morning train to London, it has given me time to reflect on the last few ...