A recent survey indicates that over 2,200 cybersecurity incidents are occurring every day, which equates to about attacks every 39 seconds. In 2024, February has not been an exception to these attacks. Today’s hack round-up will delve into the major attacks that occurred this month and suggest solutions for how they could be prevented. Let’s dive in immediately!
$26M Bitcoin Exploit on Decentralized Crypto Exchange FixedFloat
FixedFloat, a decentralized crypto exchange is one of the recent victims of an exploit resulting in the theft of at least $26 million worth of Bitcoin and Ether. Users began reporting frozen transactions and missing funds on the exchange’s page starting from February 17th. On February 18th, over 400 Bitcoins worth nearly $5 million were already drained from user accounts. The exchange team confirmed the hack and initiated an investigation, although the specific method of attack remains unclear.
Prevention Suggestions
To prevent such exploits in the future:
- FixedFloat could make it mandatory for all users to use multi-factor authentication to add an extra layer of security to these accounts.
- They should also put in place systems that monitor for abnormal behavior and notify the platform’s security teams in real time.
Radiology Services at 100 Healthcare Facilities in Minnesota Disrupted by Cyber Attack
Consulting Radiologists, Ltd., a reputable provider of off-site radiology services relied upon by more than 100 healthcare facilities in Minnesota, was recently a victim of a debilitating cyberattack. This attack began on February 11th targeting the company’s core infrastructure. The attacks compromised its phone systems, rendering them inaccessible, which disrupted the delivery of crucial medical interpretations to hospitals and health systems statewide. Despite efforts to rectify the issue, as of February 16th, the company’s communication channels remained compromised.
Prevention Suggestions
To prevent future breaches and uphold the integrity of its services, Consulting Radiologists, Ltd. should consider implementing this security best practices:
- Implementing strict access controls and user permissions to limit the scope of potential attacks
- Establishing resilient backup and recovery protocols to mitigate the impact of system disruptions.
- Investing in continuous security assessments and collaborating with industry peers to share threat intelligence data.
Services in 18 Hospitals in Romania Disrupted by Ransomware Attack
A ransomware attack targeted the Hospital Information System (HIS) healthcare management system, causing severe disruption to medical services across 18 hospitals in Romania. The attack rendered the HIS system non-functional, preventing hospital staff from accessing essential files and databases.
This consequently led to delays in patient care and forced patients to endure lengthy waits in emergency rooms. The Romanian Ministry of Health promptly identified and listed the affected medical facilities to alert users heading there. The National Cyber Security Directorate (NCSD) initiated an investigation to determine the extent of the breach and identify the perpetrators.
Prevention Suggestions
To mitigate the risk of future ransomware attacks, healthcare facilities in Romania should prioritize cybersecurity measures including the following:
- Regular system updates and patching of all software to avoid zero-day exploits
- Robust network segmentation to contain potential infections
- Implementing effective backup and recovery strategies to restore operations in the event of an attack.
- Conducting comprehensive employee training programs to raise awareness about phishing scams and other common attack vectors can empower staff to recognize and report suspicious activities.
California State Worker Union Targeted SSNs Data Breach
California’s largest state employee union, representing nearly 96,000 workers, experienced a significant data breach resulting from a ransomware attack. The breach, which occurred last month, compromised sensitive information including Social Security numbers, home addresses, and birth dates of union members.
Although the union initially reported a “network disruption” on January 20th, it wasn’t until February 5th that an open letter on Facebook confirmed the breach. However, details regarding the extent of the data compromised and the specific individuals affected remain unclear. The incident is being treated as a criminal cyber act, with law enforcement agencies actively involved in the investigation.
Prevention Suggestions
To safeguard against similar breaches in the future, the California State Worker Union should prioritize enhancing its cybersecurity posture in the following ways:
- Implementing robust threat detection mechanisms, such as intrusion detection systems and real-time monitoring tools. This allows for swift identification and response to unauthorized access attempts.
- Implementing encryption protocols to protect sensitive data
- Adopting a proactive approach to cybersecurity hygiene, including regular vulnerability assessments and employee awareness training,
- Encouraging collaboration with industry partners and law enforcement agencies can facilitate the exchange of threat intelligence and enhance the union’s ability to preemptively defend against cyber threats.
Millions of Health Data at Risk as French Healthcare Giant Got Hacked,
Viamedis, a prominent third-party insurance payment provider in France is another victim of recent cybercrimes. This company serves approximately 84 healthcare providers and 20 million insured individuals. The attack on Viamedis compromised sensitive data belonging to various stakeholders, including customers’ social security numbers, dates of birth, marital status, health insurance company names, and information accessible to third-party payment providers.
While Viamedis disclosed the data breach on February 2nd, details regarding the exact number of individuals impacted remain undisclosed. The severity of the breach demonstrates the urgent need for enhanced cybersecurity measures within the healthcare sector.
Prevention Suggestion
To prevent similar breaches in the future, Viamedis and other insurance companies should consider implementing the following practices
- Implementing robust encryption protocols to protect sensitive data
- Adopting stringent access controls to limit unauthorized access
- Conducting regular security audits to identify and address potential vulnerabilities.
- Prioritizing employee training programs to educate staff on cybersecurity best practices and raising awareness about emerging threats
- Collaboration with industry regulators and cybersecurity experts can also provide valuable insights and guidance on boosting the security posture of insurance companies.
Hackers Steal $112 Million of XRP Ripple Cryptocurrency
On January 30th, hackers executed a sophisticated cyber heist, resulting in the theft of approximately $112 million worth of XRP cryptocurrency from a crypto wallet. Chris Larsen, co-founder and executive chairman of Ripple, confirmed the theft on January 31st, revealing that his personal XRP accounts were among those compromised.
Larsen promptly notified exchanges to freeze the affected addresses and engaged law enforcement agencies to address the breach. This incident marks the largest cryptocurrency theft of 2024 thus far and ranks as the twentieth-largest cryptocurrency theft in recorded history.
Prevention Suggestions
To safeguard against future cryptocurrency thefts, individuals and organizations in the crypto space should implement the following practices:
- Users should prioritize using hardware wallets and other secure offline storage solutions to store digital assets securely.
- Enabling multi-factor authentication can also add an extra layer to user accounts
- Regularly updating software and firmware can help mitigate the risk of unauthorized access to cryptocurrency wallets.
- Maintaining a high level of vigilance against phishing attacks and suspicious activities can help to quickly detect and prevent cyber heists targeting digital assets.
Parts of Pennsylvania Courts’ Website Down Due to DDoS Attack
A distributed denial of service (DDoS) attack targeted the Pennsylvania Courts’ website on February 4th, rendering certain web services inaccessible. Chief Justice of Pennsylvania, Debra Todd, confirmed that the cyberattack disrupted court information technology services.
This attack prompted collaboration with law enforcement agencies including the Cybersecurity and Infrastructure Security Agency (CISA), the U.S. Department of Homeland Security, and the FBI to investigate the incident. The affected court web services include PACFile, online docket sheets, PAePay, and the Guardianship Tracking System.
Prevention Suggestions
To enhance resilience against future DDoS attacks, Pennsylvania Courts and other related organizations should implement the following practices:
- Create a robust network infrastructure capable of mitigating large-scale traffic influxes and deploying dedicated DDoS mitigation solutions to detect and thwart malicious traffic in real time.
- Conducting regular security assessments and implementing incident response plans can facilitate swift and coordinated responses to cyber incidents.
- Ongoing collaboration with cybersecurity experts and sharing threat intelligence within the judicial community can enhance the cybersecurity posture of legal institutions.


