There have already been several major hacks in 2024, costing victims millions of dollars to overcome and resulting in several other indirect negative consequences. Most of these attacks involved data breaches, ransomware, and crypto-related fraud. As the trend has been in previous years, attackers mainly target organizations in sensitive industries such as health, finance, and government institutions.
We always share a monthly round-up of the major hacks to help you learn how these attacks affect businesses and the prevention measures you can use to prepare for similar attacks. Today, we will walk you through the major hacks in April 2024 and how victims could have effectively dealt with them. So, without wasting any more of your time, let’s get started right away!
1. Roku Cyberattack
In the Roku cyberattack that happened on 12th April, hackers used the credential stuffing method to gain access to the streaming service and payment methods. This attack affected over 576,000 users of the platform. This breach resulted in unauthorized purchases of streaming services and Roku devices, with about 400 cases involving partial credit card numbers.
Fortunately, no sensitive information like full credit card numbers and addresses was obtained by the hackers. In response, Roku promptly reset passwords for the affected accounts and issued refunds or reversed charges for the impacted users.
Preventions Measures
This attack could have been prevented using these measures:
- Implementing stronger password policies
- Emphasizing the use of two-factor authentication
- Migrating to passkeys in the future
- Constantly monitoring for suspicious activity
2. Change Healthcare Cyberattack
Change Healthcare, a medical firm and subsidiary of UnitedHealth Group was a victim of a ransomware attack in February. However, Change Healthcare publicly revealed the details of this attack in April. In this attack, the hackers, identified as the AlphV (also known as BlackCat) ransomware group, gained access to sensitive medical data, prompting Change Healthcare to pay a ransom of $22 million.
Despite initial denials, the company later confirmed the payment. The breach potentially exposed patient data, including protected health information (PHI) and personally identifiable information (PII). Despite the ransom payment to BlackCat, there are 22 screenshots of data posted on the dark web and a second ransomware group, RansomHub, claiming to possess stolen data and threatening to sell it.
This conflict between hackers may lead to further data leaks, despite the ransom payment. The attack has caused widespread disruption to medical practices and hospitals, affecting hundreds, and resulted in significant financial losses for Change Healthcare. Experts estimated this attack to have cost Change Healthcare over $1 billion.
Prevention Measures
Change Healthcare could have implemented these prevention measures:
- Regular security audits
- Regular data backup for sensitive user information
- Employee training on security best practices
- Not paying the ransom regardless of the promises made by attackers.
3. Coordinated Attacks on Docker Hub
A JFrog research team discovered millions of malicious repositories on Docker Hub, a popular container registry platform. The team identified three large-scale malware campaigns that planted “imageless” repositories with malicious metadata, impacting over 20% of public repositories (almost three million). These repositories contained documentation pages with links to phishing websites or malware but did not contain container images.
The campaigns, named “Website SEO”, “Downloader”, “eBook Phishing”, and “Other suspicious”, showed anomalies in publication patterns, with spikes in repository creation and deviations from normal usage. JFrog and Docker are collaborating on mitigation and cleanup efforts to address this widespread issue.
Prevention Measures
Docker Hub could have prevented this attack using these measures:
- Implementing stricter verification processes for repository creators
- Monitoring for anomalies in repository activity
- Enforcing secure coding practices
- Regularly scanning for malware
4. Hedgey Finance Crypto Theft
Hedgey Finance, a cryptocurrency platform also suffered a significant theft of approximately $44.5 million worth of digital assets. A malicious attacker exploited the “createLockedCampaign” function using flash-loaned funds. This attack targeted Ethereum’s layer-2 network Arbitrum and Binance Smart Chain. The attack occurred in two stages: an initial theft of $1.9 million, followed by a larger theft of $42.8 million on the Arbitrum chain.
Cyvers, a blockchain security firm, detected the attack but was unable to reach Hedgey Finance’s team in time. Hedgey Finance announced an ongoing investigation and advised users to cancel active claims. The attack resulted in a 10% drop in the value of the BONUS token, and the attacker began shifting stolen assets, including 200,000 BONUS tokens valued at $110,000 to the Bybit exchange.
Prevention Measures
Hedgey Finance could have dealt with this attack using the following measures:
- Implementing robust smart contract auditing and testing
- More cautious validation of user inputs and transactions
- Educating users on secure practices
- Regularly monitoring the platform to detect suspicious activities early enough
5. Frontier Communications Cyberattack
Frontier Communications, a Texas-based telecommunications company, detected unauthorized access to its IT systems on April 14. The attack resulted in the shutdown of certain systems, causing operational disruption, and the accessing of personally identifiable information. The company has implemented containment measures, hired cybersecurity experts to assist, and notified law enforcement agencies.
While the investigation is ongoing, Frontier Communications does not believe the incident will materially impact its financial condition or its operations. This attack is part of a larger trend, as dozens of telecommunications companies have been targeted in recent months, highlighting the need for enhanced cybersecurity measures.
Prevention Measures
Frontier Communications could have dealt with this attack by using these measures:
- Regular security assessments and audits
- Employee training on security best practices
- Implementing robust access controls
6. Ransomware Attack on the UN Development Programme
The United Nations Development Programme (UNDP) faced a ransomware attack on a locally hosted server, resulting in data exfiltration. The 8Base ransomware gang claimed responsibility for the attack, which compromised human resources and procurement information. The UNDP confirmed the attack and emphasized that no ransom would be paid. This incident is part of a growing trend of escalating cyberattacks on humanitarian organizations worldwide.
Previous attacks have targeted the World Council of Churches, Amnesty International, and the International Committee for the Red Cross, highlighting the vulnerability of these organizations to cyber threats. The UNDP’s response to the attack sets an important precedent for not giving in to ransom demands, which can often escalate the problem and encourage further attacks.
Prevention Measures
UNDP could have prevented the impact of this attack using these measures:
- Implementing robust backup systems for their sensitive data
- Employee training on security best practices
- Implementing robust access controls for their servers
7. London Drugs Cybersecurity Incident
London Drugs, a Canadian pharmacy and retail chain, temporarily closed all its stores over the last weekend due to a cybersecurity incident. The company is investigating to determine the extent of the data compromise and will notify individuals if their personal information is impacted.
Third-party cybersecurity experts are working with London Drugs to restore operations. The incident has resulted in the indefinite closure of over 80 drug stores, with phone lines temporarily shut down. However, pharmacy staff are available for urgent needs.
Prevention Measures
The details of this attack have not been revealed yet, so we cannot suggest the possible measures that could have been implemented to prevent it.
8. LockBit Ransomware Attack on DC City Agency
The DC Department of Insurance, Securities, and Banking (DISB) was targeted by the LockBit ransomware gang, resulting in the theft of 800GB of data. After negotiations failed, the attackers leaked 1GB of the stolen data. The data was stolen from a third-party technology provider, Tyler Technologies. DISB confirmed the incident and directed inquiries to Tyler Technologies’ statement.
Tyler Technologies is investigating the incident, working with law enforcement and a cybersecurity firm, but it is unclear if other clients were affected. This attack likely resulted in the theft of personal information, with the identification process ongoing. This incident is not isolated, as similar incidents have occurred in DC, including attacks on the healthcare exchange platform and the Board of Elections.
LockBit has continued to successfully attack organizations despite an international law enforcement takedown. Some of their recent victims include a pharmaceutical development company and a South African company.
Prevention Measures
Measures to prevent such attacks from happening include:
- Regularly updating and patching software
- Implementing robust backup systems for sensitive information
- Employee training on security best practices
Final Thoughts
April 2024 saw a worrying surge in major cyberattacks across various industries. As you might have guessed, health and finance were among the most affected sectors once again. These attacks, ranging from data breaches and ransomware to crypto theft, demonstrate the need for implementing robust cybersecurity measures. The victims of these attacks suffered significant financial losses and operational disruptions.
This article presented several potential preventative measures that could have mitigated the impact of these attacks. Most of these attacks could have been prevented by implementing standard practices such as stronger password policies, employee security training, regular security audits, and robust data backups.
One positive note from these attacks was UNDP refusing to pay the ransom demanded by the attackers. Organizations should always desist from paying ransoms because it usually doesn’t guarantee data recovery and encourages future attacks.


