Hack Round-Up For April– Big Hacks That Happened In April 2024

There have already been several major hacks in 2024, costing victims millions of dollars to overcome and resulting in several other indirect negative consequences. Most of these attacks involved data breaches, ransomware, and crypto-related fraud. As the trend has been in previous years, attackers mainly target organizations in sensitive industries such as health, finance, and government institutions.

We always share a monthly round-up of the major hacks to help you learn how these attacks affect businesses and the prevention measures you can use to prepare for similar attacks. Today, we will walk you through the major hacks in April 2024 and how victims could have effectively dealt with them. So, without wasting any more of your time, let’s get started right away!

 

1. Roku Cyberattack

In the Roku cyberattack that happened on 12th April, hackers used the credential stuffing method to gain access to the streaming service and payment methods. This attack affected over 576,000 users of the platform. This breach resulted in unauthorized purchases of streaming services and Roku devices, with about 400 cases involving partial credit card numbers.

Fortunately, no sensitive information like full credit card numbers and addresses was obtained by the hackers. In response, Roku promptly reset passwords for the affected accounts and issued refunds or reversed charges for the impacted users.

Preventions Measures

This attack could have been prevented using these measures:

  • Implementing stronger password policies
  • Emphasizing the use of two-factor authentication
  • Migrating to passkeys in the future
  • Constantly monitoring for suspicious activity

 

2. Change Healthcare Cyberattack

Change Healthcare, a medical firm and subsidiary of UnitedHealth Group was a victim of a ransomware attack in February. However, Change Healthcare publicly revealed the details of this attack in April. In this attack, the hackers, identified as the AlphV (also known as BlackCat) ransomware group, gained access to sensitive medical data, prompting Change Healthcare to pay a ransom of $22 million.

Despite initial denials, the company later confirmed the payment. The breach potentially exposed patient data, including protected health information (PHI) and personally identifiable information (PII). Despite the ransom payment to BlackCat, there are 22 screenshots of data posted on the dark web and a second ransomware group, RansomHub, claiming to possess stolen data and threatening to sell it.

This conflict between hackers may lead to further data leaks, despite the ransom payment. The attack has caused widespread disruption to medical practices and hospitals, affecting hundreds, and resulted in significant financial losses for Change Healthcare. Experts estimated this attack to have cost Change Healthcare over $1 billion.

Prevention Measures

Change Healthcare could have implemented these prevention measures:

  • Regular security audits
  • Regular data backup for sensitive user information
  • Employee training on security best practices
  • Not paying the ransom regardless of the promises made by attackers.

 

3. Coordinated Attacks on Docker Hub

A JFrog research team discovered millions of malicious repositories on Docker Hub, a popular container registry platform. The team identified three large-scale malware campaigns that planted “imageless” repositories with malicious metadata, impacting over 20% of public repositories (almost three million). These repositories contained documentation pages with links to phishing websites or malware but did not contain container images.

The campaigns, named “Website SEO”, “Downloader”, “eBook Phishing”, and “Other suspicious”, showed anomalies in publication patterns, with spikes in repository creation and deviations from normal usage. JFrog and Docker are collaborating on mitigation and cleanup efforts to address this widespread issue.

Prevention Measures

Docker Hub could have prevented this attack using these measures:

  • Implementing stricter verification processes for repository creators
  • Monitoring for anomalies in repository activity
  • Enforcing secure coding practices
  • Regularly scanning for malware

 

4. Hedgey Finance Crypto Theft

Hedgey Finance, a cryptocurrency platform also suffered a significant theft of approximately $44.5 million worth of digital assets. A malicious attacker exploited the “createLockedCampaign” function using flash-loaned funds. This attack targeted Ethereum’s layer-2 network Arbitrum and Binance Smart Chain. The attack occurred in two stages: an initial theft of $1.9 million, followed by a larger theft of $42.8 million on the Arbitrum chain.

Cyvers, a blockchain security firm, detected the attack but was unable to reach Hedgey Finance’s team in time. Hedgey Finance announced an ongoing investigation and advised users to cancel active claims. The attack resulted in a 10% drop in the value of the BONUS token, and the attacker began shifting stolen assets, including 200,000 BONUS tokens valued at $110,000 to the Bybit exchange.

Prevention Measures

Hedgey Finance could have dealt with this attack using the following measures:

  • Implementing robust smart contract auditing and testing
  • More cautious validation of user inputs and transactions
  • Educating users on secure practices
  • Regularly monitoring the platform to detect suspicious activities early enough

 

5. Frontier Communications Cyberattack

Frontier Communications, a Texas-based telecommunications company, detected unauthorized access to its IT systems on April 14. The attack resulted in the shutdown of certain systems, causing operational disruption, and the accessing of personally identifiable information. The company has implemented containment measures, hired cybersecurity experts to assist, and notified law enforcement agencies.

While the investigation is ongoing, Frontier Communications does not believe the incident will materially impact its financial condition or its operations. This attack is part of a larger trend, as dozens of telecommunications companies have been targeted in recent months, highlighting the need for enhanced cybersecurity measures.

Prevention Measures

Frontier Communications could have dealt with this attack by using these measures:

  • Regular security assessments and audits
  • Employee training on security best practices
  • Implementing robust access controls

 

6. Ransomware Attack on the UN Development Programme

The United Nations Development Programme (UNDP) faced a ransomware attack on a locally hosted server, resulting in data exfiltration. The 8Base ransomware gang claimed responsibility for the attack, which compromised human resources and procurement information. The UNDP confirmed the attack and emphasized that no ransom would be paid. This incident is part of a growing trend of escalating cyberattacks on humanitarian organizations worldwide.

Previous attacks have targeted the World Council of Churches, Amnesty International, and the International Committee for the Red Cross, highlighting the vulnerability of these organizations to cyber threats. The UNDP’s response to the attack sets an important precedent for not giving in to ransom demands, which can often escalate the problem and encourage further attacks.

Prevention Measures

UNDP could have prevented the impact of this attack using these measures:

  • Implementing robust backup systems for their sensitive data
  • Employee training on security best practices
  • Implementing robust access controls for their servers

 

7. London Drugs Cybersecurity Incident

London Drugs, a Canadian pharmacy and retail chain, temporarily closed all its stores over the last weekend due to a cybersecurity incident. The company is investigating to determine the extent of the data compromise and will notify individuals if their personal information is impacted.

Third-party cybersecurity experts are working with London Drugs to restore operations. The incident has resulted in the indefinite closure of over 80 drug stores, with phone lines temporarily shut down. However, pharmacy staff are available for urgent needs.

Prevention Measures

The details of this attack have not been revealed yet, so we cannot suggest the possible measures that could have been implemented to prevent it.

 

8. LockBit Ransomware Attack on DC City Agency

The DC Department of Insurance, Securities, and Banking (DISB) was targeted by the LockBit ransomware gang, resulting in the theft of 800GB of data. After negotiations failed, the attackers leaked 1GB of the stolen data. The data was stolen from a third-party technology provider, Tyler Technologies. DISB confirmed the incident and directed inquiries to Tyler Technologies’ statement.

Tyler Technologies is investigating the incident, working with law enforcement and a cybersecurity firm, but it is unclear if other clients were affected. This attack likely resulted in the theft of personal information, with the identification process ongoing. This incident is not isolated, as similar incidents have occurred in DC, including attacks on the healthcare exchange platform and the Board of Elections.

LockBit has continued to successfully attack organizations despite an international law enforcement takedown. Some of their recent victims include a pharmaceutical development company and a South African company.

 

Prevention Measures

Measures to prevent such attacks from happening include:

  • Regularly updating and patching software
  • Implementing robust backup systems for sensitive information
  • Employee training on security best practices

Final Thoughts

April 2024 saw a worrying surge in major cyberattacks across various industries. As you might have guessed, health and finance were among the most affected sectors once again. These attacks, ranging from data breaches and ransomware to crypto theft, demonstrate the need for implementing robust cybersecurity measures. The victims of these attacks suffered significant financial losses and operational disruptions.

This article presented several potential preventative measures that could have mitigated the impact of these attacks. Most of these attacks could have been prevented by implementing standard practices such as stronger password policies, employee security training, regular security audits, and robust data backups.

One positive note from these attacks was UNDP refusing to pay the ransom demanded by the attackers. Organizations should always desist from paying ransoms because it usually doesn’t guarantee data recovery and encourages future attacks.

 

CYBERSECURITY READINESS

Strengthen Your Cyber Defences Today

As cyber threats grow more complex, proactive detection is no longer optional.

With Wizard Cyber’s Microsoft expertise, organizations can transform their security posture and gain real-time visibility across all endpoints.

Start your journey to smarter, faster cybersecurity today.

EXPLORE MORE

Related Blogs & Insights

Discover blogs that deepen your knowledge and accelerate your security strategy.

Abdallah Alhajeid

WordPress Developer

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation