It is 2024, and cyber criminals are still working overtime to break the security defenses of organizations and individuals to gain money and for other selfish reasons. Just like in previous months, there have been several hacks in March that have affected various organizations and their beneficiaries.
In one of our recent articles, we discussed the major hacks that happened in February 2024. In today’s article, we will explore some of the major hacks that occurred in March to help your organization stay prepared ahead of time. We will also discuss how the affected parties could have fought against these attacks to reduce and even mitigate the damage caused.
Major Hacks in March 2024
Ransomware Group Scams its Partner Out of a Share of $22 Million by Faking an FBI
In a complex and audacious scheme, a Russian hacker group known as AlphV executed a ransomware attack on Optum, a major healthcare management system in the US. The attack crippled critical healthcare operations, including patient accounts, payment processing, and insurance claims. Subsequently, Optum allegedly paid a hefty ransom of $22 million to AlphV to remove the ransomware and purportedly delete stolen data.
However, it later emerged that AlphV had not deleted the data as promised but instead attempted to deceive both Optum and law enforcement agencies by faking an FBI takedown. Despite the apparent seizure notice displayed on AlphV’s dark website, independent investigations revealed that the group was engaging in an exit scam, absconding with the ransom payment and leaving its affiliates in the lurch.
Prevention Measures
- Conduct regular security audits to identify and fix vulnerabilities.
- Provide employee training on cybersecurity practices, including recognizing phishing attempts.
- Implement robust data backup and recovery procedures to restore systems without paying ransom in the event of an attack.
- Establish enhanced verification processes to avoid falling for fraudulent schemes.
- Create closer collaboration with law enforcement agencies for quicker detection and response.
$8.5M Worth of Crypto Assets Stolen
Malicious actors targeted one of WooPPV2’s contract on the Arbitrum chain, exploiting a flaw in the price calculation mechanism to execute a price manipulation attack. By flash-loaning USDC.e and Woo tokens, the attacker manipulated prices and executed successive token swaps to siphon off $8.5 million worth of crypto assets.
The attacker initially received funding from a user on the Ethereum network and has since begun maliciously transferring the stolen funds to various accounts and bridging them to other chains. This move is to make it harder to track the whereabouts of these funds.
Prevention Measures
- Perform thorough smart contract audits to identify and rectify vulnerabilities.
- Implement real-time monitoring of transactions to detect suspicious activities. This would have made it harder for the hacker to transfer large volumes of tokens without being detected.
- Enhance token security measures, such as multi-signature wallets or using hardware wallets that are much harder to break into since they are always online.
- Crypto platforms should implement user verification protocols like Know Your Customer (KYC) to mitigate risks. With KYC, it is much easier to track malicious.
Data Breach Affects 235,000 Individuals Across Various Entities
Yakima Valley Radiology, along with Employee Benefits Corporation of America, Benefit Design Group, and Lena Pope Home, suffered data breaches affecting a total of 235,249 individuals. Yakima Valley Radiology detected unauthorized access to a limited amount of patient data, including names and Social Security numbers, originating from a compromised email account.
Affected individuals have been notified and offered complimentary credit monitoring services. Meanwhile, Employee Benefits Corporation of America and Benefit Design Group confirmed breaches affecting 38,912 employees. The compromised information that these companies reported includes user’s names, driver’s license numbers, Social Security numbers, and financial account details. The breaches, dating back to 2022, were detected following notifications from the Department of Homeland Security, prompting investigations and remedial actions.
Prevention Measures
- Enforce multi-factor authentication and email security measures.
- Provide regular security training for employees to minimize human error.
- Deploy robust endpoint security solutions to prevent unauthorized access to sensitive data.
Fidelity Investments Life Insurance Company Notifying 28,000 People of Data Breach
Fidelity Investments Life Insurance Company has alerted approximately 28,000 individuals to a data breach resulting from a cyberattack on third-party services provider Infosys McCamish System (IMS). The breach, which was due to a cyberattack on IMS systems in October 2023, led to unauthorized access to sensitive data.
The data that was accessed includes names, dates of birth, state of residence, Social Security numbers, bank account and routing numbers, and credit card numbers. Although Fidelity is unable to ascertain definitively which personal information was accessed, it has taken proactive steps to notify and offer affected individuals two years of complimentary credit monitoring services.
Prevention Measures
- Implement robust vendor risk management processes.
- Utilize data encryption for both in transit and at rest.
- Enforce stringent access controls, such as role-based access control.
Intense Cyberattacks Target the French Government
On Monday the 17th of March, the French government announced that it had been subjected to a series of intense cyberattacks targeting multiple government ministries. These attacks, characterized by their unprecedented intensity, prompted the activation of a special crisis center to restore online services.
While the government did not provide specific details regarding the nature or extent of the attacks, a group known as Anonymous Sudan, perceived as pro-Russia by cybersecurity experts, claimed responsibility for the incidents. The attacks believed to be denial-of-service attacks, aimed to overwhelm government websites and disrupt online services.
Prevention Measures
- Deploy robust DDoS mitigation solutions. The good news is that most cloud providers offer these services in their service offerings. Users just need to figure out the best service options to give them the most protection against DDoS attacks.
- Implement network segmentation and deploy firewalls.
- Develop comprehensive incident response plans for rapid detection and remediation.
UnitedHealth Group Recovers from Significant Cyberattack
UnitedHealth Group, a leading healthcare provider in the United States, is recovering from a massive cyberattack that was executed by the hacking group ALPHV. The attack, disclosed on February 21st, targeted UnitedHealth Group subsidiary Change Healthcare, severely impacting its operations. Change Healthcare, responsible for processing billions of healthcare transactions annually, experienced disruptions to pharmacy, medical claims, and payment systems.
This attack inflicted significant consequences on hospitals and communities, prompting UnitedHealth Group to allocate over $2 billion to assist affected healthcare providers. The Department of Health and Human Services Office of Civil Rights has initiated an investigation into the breach to ascertain the extent of protected health information compromised and ensure compliance with HIPAA regulations.
Prevention Measures
- Ensure timely patch management to address known vulnerabilities.
- Implement network segmentation and access controls.
- Provide employee awareness training on recognizing suspicious emails and attachments.
Key Takeaways
- The major cyberattacks in March 2024 mainly targeted healthcare, finance, government agencies, and crypto platforms.
- Ransomware attacks remain a major threat, with AlphV being responsible for a number of these attacks
- Data breaches exposed millions, highlighting the need for strong email security and employee training.
- Cryptocurrency platforms need thorough smart contract audits, real-time transaction monitoring, and more robust account security measures.
- Organizations can combat cyberattacks by, conducting regular security audits, implementing data backups and recovery procedures, training employees on cybersecurity best practices, enforcing multi-factor authentication and email security, utilizing data encryption and access controls, and partnering with law enforcement, and managing vendor risks.
If you would love to further elevate the security of your organization to avoid being the next victim of these attacks, our team of experts at Wizard Cyber is ready to be your partner. Contact our support team for more information on how to get started.


