Last Updated on April 14, 2017
It’s time to publish the first timeline of March 2017, covering the main events between March 1st and March 15th.
Another month, another series of mega breaches… This fortnight has brought us a 52gb (33.6 million records) database belonging to Dun & Bradstreet, and 2.2 million records and 287,000 telephone numbers belonging to the users of the popular teen app Wishbone.
Other important events targeted GMO Payment Gateway Inc (700,000 records compromised from two client websites), and the Association of British Travel Agents (ABTA – data of 43,000 holidaymakers compromised).
In the meantime, the row between Turkey and The Netherlands extended into the Cyberspace: several Dutch webesites were taken down by DDoS attacks, and the compromising of the popular TwitterCounter app flooded the social network with hashtags like #NaziGermany and #NaziHolland.
The chronicles also report a new alleged attack by APT29 (AKA CozyBear), and yet another variant of the infamous Shamoon malware dubbed StoneDrill.
If you want to have an idea of how fragile our electronic identity is inside the cyberspace, have a look at the timelines of the main Cyber Attacks in 2011, 2012, 2013, 2014, 2015 and 2016 (regularly updated). You may also want to have a look at the Cyber Attack Statistics that are regularly published, and follow @paulsparrows on Twitter for the latest updates.
Additionally, feel free to submit remarkable incidents that in your opinion deserve to be included in the timelines (and charts), and if useful, you can access the timeline in Google Sheet format.
|1||01/03/2017||?||Single Individuals||Malware Must Die publishes the details of a massive credential harvesting campaign carried on via an SSH Direct TCP Forward attack orchestrated via an IoT botnet.||SSH Direct TCP Forward||Single Individuals||CC||>1|
|2||01/03/2017||?||Association of British Travel Agents (ABTA)||The UK's largest travel trade organisation, the Association of British Travel Agents (ABTA) experiences a cyberattack on its website that puts 43,000 holidaymakers and travel agents at risk of identity theft.||Unknown||Org: Travel||CC||UK|
|3||01/03/2017||?||Kennesaw State University||The FBI is investigating an alleged hack of Kennesaw State University server.||Unknown||Education||CC||US|
|4||02/03/2017||China?||Lotte Duty Free (lottedfs.com)||South Korea's Lotte Duty Free website (lottedfs.com) is taken down by a DDoS attack orchestrated from a Chinese IP.||DDoS||Industry: Retail||CC||KR|
|5||02/03/2017||?||Radio Station WZZY-FM||Radio station WZZY-FM falls victim to a prank when hackers access its computer systems and begin broadcasting fake news alerts of a zombie attack, along with a disease outbreak caused by the resulting carnage.||Unknown||Radio Station||CC||US|
|6||02/03/2017||?||Daytona State College||Daytona State College notifies staff of potential W-2 incident||Account Hijacking||Education||CC||US|
|7||03/03/2017||?||Pennsylvania Senate Democrats||The Pennsylvania Senate Democrats are hit by a ransomware attack that locks senators and employees out of their computer network||Malware||Government||CC||US|
|8||04/03/2017||?||Advertisement board in Mexico City||A digital advertisement board owned by Grupo Carteleras located on a busy road in Mexico City is hacked on Friday and features a pornographic video for a few minutes.||Unknown||Billboard||CC||MX|
|9||06/03/2017||Cozy Bear (APT29)?||Several US progressive groups||New reports reveal that Russian hackers are targeting U.S. progressive groups in a new wave of attacks. According to the report, at least a dozen groups have faced extortion attempts since the U.S. presidential election. The ransom demands are accompanied by samples of sensitive data in the hackers’ possession.||Targeted Attack||Org: Politics||CC||US|
|10||06/03/2017||?||Several organisations across Saudi Arabia and Europe||Kaspersky Lab reveals the details of a new wiper malware, dubbed StoneDrill, has been uncovered by security researchers, believed to be targeting more organisations across Saudi Arabia and Europe.||Targeted Attack||>1||CC||>1|
|11||06/03/2017||?||University of Idaho||University of Idaho notifies 257 employees after phishing incident.||Account Hijacking||Education||CC||US|
|12||07/03/2017||?||Verifone||Credit and debit card payments giant Verifone investigates a breach of its internal computer networks that appears to have impacted a number of companies running its point-of-sale solutions.||Malware||Industry: Banking and Finance||CC||US|
|13||08/03/2017||?||Government organizations in the Middle East||Malware researchers at Palo Alto Networks spot a new strain of ransomware, dubbed RanRan, that has been used in targeted attacks against government organizations in the Middle East.||Targeted Attack||Government||CC||>1|
|14||09/03/2017||?||GMO Payment Gateway Inc||GMO Payment Gateway confirms data leakage from two client websites, due to the Apache Struts vulnerability. The victims are the Tokyo Metropolitan Government, and the Japan Housing Finance Agency. The total leaked records are more than 700,000.||Apache Struts Vulnerability||Industry: Banking and Finance||CC||JP|
|15||09/03/2017||?||Queensland School Photography||Queensland School Photography emails students' parents to notify that payment card information has been compromised.||Malware||School photographic service provider||CC||AU|
|16||10/03/2017||?||Products from surveillance technology company AVTech||Trend Micro discovers a new family of Linux malware targeting products from surveillance technology company AVTech exploiting a CGI vulnerability that was disclosed in 2016.||CGI Vulnerability||Industry: Video Surveillance||CC||TW|
|17||11/03/2017||?||Several Dutch Websites||Turkish hacker groups target a large number of Dutch websites after the political fallout between the Netherlands and Turkey over the weekend.||DDoS/Defacement||>1||H||NL|
|18||11/03/2017||?||Single Individuals||Danish-speaking users were infected by malware spread through Dropbox.||Malware||Single Individuals||CC||DK|
|19||12/03/2017||Rekan Herror||fifthharmony.com||A Kurdish hacker going by the online handle of “Rekan Error” defaces the official website of Fifth Harmony, an American girl group formed on the second season of The X Factor US in July 2012 and posts messages against ISIS.||Defacement||Industry: Entertainment||H||US|
|20||13/03/2017||?||Welsh NHS||Details of thousands of medical staff of Welsh NHS are stolen from a private contractor's computer server (Landauer). The breach happened in October 2016 and the total number of affected staff is 4,766.||Unknown||Healthcare||CC||UK|
|21||13/03/2017||?||Single Individuals||Google declares to have identified and shut down a massive ad fraud Android botnet called Chamois, which may have infected multiple Android devices.||Mobile Malware||Single Individuals||CC||>1|
|22||14/03/2017||?||Statistics Canada (statcan.gc.ca)||The Canadian government confirms that the Statistics Canada website is hacked and taken offline for over two days. In the aftermath of the cyberattack parts of the Canada Revenue Agency's (CRA) site is also reportedly taken offline by authorities as a precaution.||Apache Struts Vulnerability||Government||CC||CA|
|23||14/03/2017||?||Several targets||Kaspersky Lab reveals the details of PetrWrap, a new Petya-based ransomware used in targeted attacks.||Malware||>1||CC||TR|
|24||14/03/2017||?||Magento installations||Sucuri reveals that Cybercriminals continue to target the Magento platform, abusing a payment module (Realex Payments Magento extension, SF9) to steal payment card data from online shops running on Magento e-commerce platform.||Malicious Function Injection||Industry: Software||CC||>1|
|25||14/03/2017||?||Mountain Home Water Department||The servers of Mountain Home Water Department fall victim of a ransomware attack.||Malware||Utility: Water||CC||US|
|26||15/03/2017||?||Dun & Bradstreet||A Dun & Bradstreet 52GB database containing about 33.6 million records with very specific details about each of the people involved from job title to email address is exposed.||Unknown||Industry: Business Services||CC||US|
|27||15/03/2017||?||Wishbone App||Hackers steal 2.2 million email addresses and 287,000 cellphone numbers from popular teen quiz App Wishbone users, many of whom are young women under the age of 18.||Unknown||Industry: Software||CC||US|
|28||15/03/2017||?||Single Individuals (via TwitterCounter)||A large number of Twitter accounts including verified big-name brands, from Justin Bieber to Forbes Magazine, are hacked to display Nazi symbols, a message written in Turkish and two hashtags that translate to "NaziGermany" and "NaziHolland." The issues appear to be linked to a service called Twitter Counter, an analytics company that was previously embroiled in a similar incident last year.||Account Hijacking||Single Individuals||H||>1|
|29||15/03/2017||?||Several business organizations in North America||Trend Micro reveals the details of MajikPOS, a new PoS malware, targeting business in North America and Canada.||PoS Malware||>1||CC||US CA|
|30||15/03/2017||Anonymous||boaec.com.br||The Anonymous deface the official website of Boa Esporte, a second division football club in the state of Minas Gerais, after the team hired goalkeeper Bruno Fernandes das Dores de Souza convicted for murdering his ex-girlfriend.||Defacement||Org: Sport||H||BR|