NBA Warns Fans of Cyber Attack and Data Breach

“The data hacked was limited, and it is ample to do phishing attacks and other scams. The NBA urges its fans to stay cautious when they open doubtful emails that only appear to be from the association or its partners.”

Though the credentials of fans were not impacted by the attack, the hackers managed to steal some of their information. The National Basketball Association (NBA) has already hired a third-party cybersecurity service to investigate and resolve the issue.

Also Read, New US Cybersecurity Strategy Targets Cyber Attacks from China

However, the data hacked was limited, and it is ample to do phishing attacks and other scams. The NBA urges its fans to stay cautious when they open doubtful emails that only appear to be from the association or its partners.

To ensure that fans won’t get trapped in phishing attempts, the association clarified that it will never ask its fans for their usernames, account information, or passwords through their emails. Another indication that the email is true is if the email address ends in “@nba.com.”

Fans requested to ensure that if they do get an email with attachments that have suspicious links and take it to another website, they must verify it first before opening it since it could lead fans to a malicious website.

Previous NBA-Related Cyber Attacks

Back in April 2021, the NBA team Houston Rockets also faced a cyber attack, where the hackers tried to install malware on the computer systems of the franchise. However, the trials failed and threat actors did not breach their systems.

Houston Rockets hired cybersecurity experts to investigate the attack as they worked with the FBI (Federal Bureau of Investigation) as well. 

Tracey Hughes, Houston Rockets Spokesperson, said, “the organization detected suspicious activity on certain systems in its internal network.”

The malware did not impose any threat because of the cyber defenses that were already installed before the attack. The Houston Rockets mentioned that a few systems were impacted but it did not disturb their operations.

Reddit Claimed of Hacking says User Data is Safe

Synopsis

“Reddit explaining the nature of the phishing attack further mentioned that the attack was targeted at Reddit employees pressuring them into clicking on the link to a site that was similar to the internal gateway of Reddit. It seems some of the employees clicked on the link and enabled the hackers to enter the internal systems, thereby getting hold of the company data.”

Reddit, the California-based technology enabled community builder, has accepted that its site was hacked this week and claimed that the phishing attack was sophisticated targeting its employees.

Also Read, Cybersecurity Attacks: New Wave of Ransomware Target ESXi Hypervisors of VMware

The social media platform also mentioned this phishing attack happened on February 5 breaching the security systems of Reddit.

Having said that, the information technology company made sure that there was no exposure of the user database in the hack attempt but the hackers were able to access code, some internal documents, and some internal business systems.

Reddit explaining the nature of the phishing attack further mentioned that the attack was targeted at Reddit employees pressuring them into clicking on the link to a site that was similar to the internal gateway of Reddit.

It seems some of the employees clicked on the link and enabled the hackers to enter the internal systems, thereby getting hold of the company data. 

It once again persuades users that there has been no data loss or attack on the data of users. And in fact most of the data leaked comprises limited information about hundreds of company contacts and employees.

The company has tackled a complete analysis of the phishing attack after the employees notified them of possible intrusion from hackers.

The security team of Reddit managed to immediately close the breach and ascertain there was the least possible damage to its systems.

First of all, the attacker’s access to the systems was blocked and then initiated its enquiry into the incident mentioning the aforementioned details.

A group of Hackers stole police data on a billion Chinese citizens

In today’s world Hackers are the criminals everyone should be afraid of. Not only the normal citizens and netizens but Government authorities can also fall prey to them. Recently a group of Hackers claimed that they have stolen data on a billion Chinese citizens from a Shanghai police database. Not only this they are also attempting to sell the data. 23 terabytes of will cost just over $198,000. According to Bloomberg, “The person or group claiming the attack has offered to sell more than 23 terabytes of stolen data from the database, including names, addresses, birthplaces, national IDs, phone numbers and criminal case information, according to an anonymous post on an online cybercrime forum last week. The unidentified hacker was asking for 10 bitcoin, worth around $200,000.” They added, “Shanghai authorities have not publicly responded to the purported hack. Representatives for the city’s police and Cyberspace Administration of China, the country’s internet overseer, did not immediately respond to faxed requests for comment.”

 

The actual threat of Hackers

 

The real threat about this is that the data they have stolen includes old criminal cases which other than police are not expected to to have access of. Engadget says, “the hacker provided a sample of the data, which included crime reports dating as far back as 1995. Reporters confirmed the legitimacy of at least some of the data by calling people whose numbers were listed.” They added, “It’s not yet clear how the hacker infiltrated the police database, though there have been suggestions that they gained access via an Alibaba cloud computing company called Aliyun, which was said to host the database. Alibaba said it’s investigating the matter.

The true scope of the leak is unknown. However, cybersecurity experts have dubbed it the biggest cybersecurity breach in China’s history.”

It will be interesting to see how in future the respective authority handles and takes further steps to cop up with the matter.

Unemployment Benefits in some states are affected by a Cyberattack

Associated Press reported that a cyberattack on a third-party vendor has impacted employment services, including unemployment benefits, in several states. They said, “A cyberattack on a software company has disrupted unemployment benefits and job-seeking assistance for thousands of people in several states.

In Tennessee, the website for unemployment benefits remained down Thursday morning after the vendor, Geographic Solutions Inc., told the state Sunday that service would be interrupted. Some 12,000 Tennesseans rely on the unemployment program, and for now, they’re not getting their payments. The company said that it expects Tennessee’s system to be back online before July 4.”

Paul Toomey, the president of vendor Geographic Solutions, said in a statement on Wednesday, “We recently identified anomalous activity on our network, and immediately took [Tennessee’s] Jobs4TN system offline to halt the activity. With the help of third-party specialists, we are conducting a full investigation to determine the cause and scope of the incident,” He added, “Our current focus is working around the clock to bring Jobs4TN back online. We anticipate that this will occur prior to the July 4th holiday.”

 

The effect of the cyberattack on Unemployment Benefits

 

To what extent the attack has affected is not clear yet. Geographic Solutions who have clients in more than 35 states and territories is down now. Statescoop reported, “California’s Employment Development Department said in a release Wednesday that “dozens of states” are included in the outages. The overall scope of the attack is not immediately clear. Geographic Solutions did not immediately return a call for comment. Louisiana’s workforce commission posted on social media that its HiRE employment website is down and that the outages could affect up to 40 states.”

According to Engadget, “The situation could have a significant effect on those who depend on unemployment benefits and are having problems accessing them. Around 12,000 people rely on such benefits in Tennessee, but the AP reports that they are not receiving payments.”