Yeah, you got it right from the title. We’ve already faced some major hacks in January 2024, just two weeks into the new year. Hackers don’t take breaks; they’re always working their socks off to find the next weak vulnerability they can leverage to get into the data and systems of organizations and individuals.
To prevent you or your organization from becoming the next victim, it’s crucial to be aware of common hacks and learn what you can do to avoid them. In today’s article, we’ll dive into some of the major hacks that have already happened in January 2024, covering how they happened and the best ways you can avoid falling victim to similar hacks. Let’s jump right in!
Major Hacks in January 2024 and How They Could Be Prevented
1. Victoria Court System Data Breach
In early January 2024, the court system in Victoria, Australia fell victim to one of the first data breaches in 2024. Unauthorized parties managed to gain access to recordings of various court hearings. Fortunately, the breach was somewhat contained, as confirmed by Victoria’s Chief Executive Louise Anderson.
According to her statement, the unauthorized access was limited to the recordings, and no other critical court systems or records, including employee or financial data, were compromised. Even though the breach is concerning, it appears that sensitive information beyond the court recordings was not accessed or tampered with by these hackers.
How this attack could be prevented
- Enhanced Access Controls: Implementing stricter access controls, ensuring that only authorized personnel can access sensitive information.
- Multi-factor authentication: Multi-factor authentication can add an extra layer of security, making it harder to compromise accounts.
- Regular Security Audits: Conducting regular security audits to identify vulnerabilities and weaknesses in the system can also help mitigate such attacks. This can help in detecting and addressing potential threats before they are exploited.
- Encryption of Sensitive Data: Encrypt all sensitive data, in this case, the recordings of court hearings. This makes it significantly harder for unauthorized parties to make sense of the information even if they gain access.
2. Suspected Chinese Hackers Breach US Research Organization
Another significant hack in January involved suspected Chinese hackers targeting a US research organization specializing in China and geopolitics. The attackers exploited two newly discovered software flaws to gain unauthorized access. The primary motive behind the breach was to get sensitive military or political information, specifically serving China’s intelligence interests. This incident is part of an ongoing pattern of cyber-espionage efforts executed by China against the US.
The leaked exploit code poses additional concerns, as it could potentially be used by less skilled hackers for wider attacks. The good news is that the software vendor, Ivanti, is actively working on a fix and advising customers to implement enhanced security measures to avoid being the next victim.
How this attack could be prevented
- Regular Software Updates: Keep software and systems up-to-date to patch any known vulnerabilities. Regularly check for updates and apply them promptly to minimize the risk of exploitation.
- Employee Training: Train employees on cybersecurity best practices, including recognizing phishing attempts and suspicious activities that could lead to exposing login credentials. Human error is often a factor in successful cyber-attacks.
- Collaboration with Cybersecurity Experts: Engage with cybersecurity experts to assess and strengthen the organization’s defenses. Continuous monitoring and threat intelligence can help detect and mitigate potential threats.
3. Orbit Chain Bridge Hacked for $80 Million
Orbit Chain, a South Korean cross-chain bridge project, suffered a significant loss of over $80 million in assets due to a preventable breach. The attacker exploited a security weakness by gaining access to 7 out of 10 multisig signers, effectively bypassing security measures meant to prevent unauthorized transactions. The stolen funds primarily comprised stablecoins such as $30 million USDT, $20 million USDC, and DAI, along with some Bitcoin and Ethereum.
The funds were moved through an intermediary address and a cryptocurrency mixer. In response, the project’s team is requesting exchanges to freeze assets and collaborate with law enforcement. Notably, this incident adds to a series of hacks involving Ozys-developed infrastructure, including KlaySwap and Belt Finance. The success of this attack also further emphasizes the importance of learning from past mistakes to enhance security in the decentralized finance (DeFi) space.
How this attack could be prevented
- Enhanced Network Security: Strengthen the security of internet service providers (ISPs) and critical infrastructure, implementing measures to prevent unauthorized access and data deletion.
- Enhanced Key Security: Crypto platforms that use the multisig signers system should ensure that each signer’s private key is stored securely using hardware wallets or secure hardware modules. The signers should also regularly update and review key storage protocols to minimize the risk of key compromise.
4. Ukrainian Hackers Hit Moscow ISP as Retaliation
A hacking group named “Blackjack,” associated with Ukraine’s main spy agency (SBU), targeted M9 Telecom, a Moscow-based internet and TV provider, as a retaliatory move against a Russian cyberattack on Ukrainian telecom giant Kyivstar. The impact was significant, with 20 terabytes of data deleted, causing disruptions in internet access for Moscow residents. The hackers claim this is a “warm-up” for a larger attack, signaling a potential escalation in cyber warfare between Ukraine and Russia. This incident further raises concerns about the ongoing digital security challenges between the two nations, and how that could impact the ongoing war.
How this attack could be prevented
- International Collaboration: International collaboration on cybersecurity can be crucial to preventing state-sponsored attacks.
5. Ivanti Connect Secure and Policy Secure Zero-Day Vulnerabilities Exploited
Suspected China-linked nation-state actors exploited two critical zero-day vulnerabilities (CVE-2023-46805 and CVE-2024-21887) in Ivanti Connect Secure and Policy Secure, affecting less than 10 customers. These vulnerabilities allowed attackers to bypass authentication and execute arbitrary commands on affected devices. Both vulnerabilities were actively exploited, and the cyber-espionage attacks are attributed to a group tracked by cybersecurity firm Volexity as UTA0178, believed to be linked to China.
Patches to address the vulnerabilities are expected to be released as soon as January 22, 2024. The vulnerabilities can be chained together for unauthenticated remote code execution, and attackers have been observed manipulating Ivanti’s internal integrity checker to cover their tracks. These incidents revealed attackers using these vulnerabilities for various malicious activities, including stealing configuration data, modifying files, downloading remote files, and establishing a reverse tunnel from the affected devices.
How this attack could be prevented
- Prompt Patching: Apply software patches promptly to address known vulnerabilities. Regularly check for updates from software vendors and prioritize security patches. Before the patches, users can use workarounds like the one provided by Ivanti to temporarily fix the vulnerability.
- User Awareness Training: Train users to recognize and report suspicious activities. A well-informed user base can act as an additional layer of defense against phishing attempts and social engineering.
- Continuous Monitoring: Implement continuous monitoring systems to detect and respond to anomalous activities promptly. This can help identify and mitigate threats before they cause significant damage.
Final thoughts
While we’ve just stepped into 2024, January has already served as a strong reminder of why vigilance in cyberspace is paramount. From court systems to research organizations, no one is immune to the ever-increasing cyberattacks. In this article, we explored the major attacks this year so far, including the vulnerabilities exploited. We also provided actionable steps that would have been taken by both individuals and institutions to avoid such attacks.
Such steps include enhanced access controls, employee training, prompt patching, continuous monitoring, verification protocols for reported attacks, and international cooperation. In the world of DeFi, robust multisig protocols and collaboration with cybersecurity experts are key.
Remember, cybersecurity is a shared responsibility that needs to involve all the stakeholders of your organization.


