social engineering3 articles
Clover Health Investments Hit by Social Engineering Attack, Patient Data Exposed
Clover Health Investments disclosed a data breach discovered on July 4, resulting from a social engineering attack that compromised three non-managerial employee accounts with access to personal and protected health information. The company activated its response plan, engaged third-party cybersecurity experts, and believes the attackers have been evicted, though the full scope of the breach remains undetermined. No threat actor or ransomware group has claimed responsibility for the incident.
AdaptHealth Blames Social Engineering After Patient Data Walks Out the Door
Medical equipment provider AdaptHealth suffered a cyberattack in which criminals used social engineering to compromise a third-party contractor and gain access to the company's cloud systems. Attackers stole sensitive patient data, including personally identifiable information, protected health information, and a password file linked to insurance billing, though Social Security numbers and payment details are believed to be unaffected. AdaptHealth disclosed the breach to the SEC on June 27, deeming it material due to the potential volume of data at risk, while investigations into the full scope of the incident are ongoing.
Fake IT Support Calls Are How This Gang Walks Into Law Firms and Walks Out With Everything
The Silent Ransom Group (also tracked as UNC3753/Luna Moth) is actively targeting U.S. law firms and professional services organisations using social engineering tactics, including fake IT support phone calls that trick employees into installing remote access tools, enabling data theft within hours. Once inside a network, attackers steal sensitive legal and financial documents before sending highly aggressive ransom demands — sometimes within 30 minutes of exiting the victim's environment — threatening to notify clients and regulators if payment is not made. Cybersecurity firm Mandiant and the FBI recommend organisations counter these attacks by enforcing strict IT verification procedures, limiting remote access tools, implementing multi-factor authentication, and training staff to recognise voice phishing attempts.