September 2024 brought rise to a number of serious data breaches, ransomware and cyber attacks. All of these have highlighted weaknesses in the software and cybersecurity infrastructures of several companies. All of the instances below reiterate the constant cybercrime threat that is looming every single day.
These events highlight yet again the extraordinary requirement for all industry sectors to adopt a “go beyond and twice as deep” approach to cybersecurity. Proactive identification of even the most sophisticated threats and a high-order, short-time response to breaches that occur anyway are essential. Every organization must engage its whole workforce, from the top down and across all sectors, in regular cybersecurity drills that prepare everyone for the bad day that just might come.
Massive Breach at MC2
In September 2024, MC2 Data experienced a massive breach that exposed the sensitive information of over 100 million Americans. This incident underscored the enormous weaknesses present in the services that background checks provide to the public. The exposed data amounted to 2.2 terabytes that were stored in an improperly secured database, which was then made readily accessible online. The kinds of data that were exposed are hard to fathom. They ranged from easy-to-get-at details, like names and email addresses, to hard-to-explain choices of what to store in an encrypted format, like “Password123” (with variations). As Cybernews reported, background-check services have long struggled with security, making personal data vulnerable to misuse. This incident underscores the importance of adhering to the Fair Credit Reporting Act (FCRA), which mandates that both background-check companies and the organizations using their services must ensure data is protected from unauthorized access.
Not only did this breach put individuals in the path of identity theft and the kinds of harmful activities that frequently accompany it, but it also raised serious questions about the security practices of organizations that manage huge quantities of sensitive data. MC2 Data, operating under various platforms including PrivateRecords.net and PeopleSearchUSA, did a very poor job of safeguarding information that was vital to keep private. All these entities must take reasonable steps to protect the data, and there must be no inadvertent sloppiness that allows someone who shouldn’t have access to it to get access to it.
Microchip Technology Ransomware Theft
Microchip Technology, a key semiconductor industry player, announced in September that it suffered a major cyber incident. The Play ransomware group led the attack, which resulted in the theft not only of employee data—sensitive personal information and IDs but also of a number of business and financial documents that were certainly not meant to be seen by the outside world.
The initial news of the cyberattack came to light in August, when Microchip Technology notified the US Securities and Exchange Commission (SEC) that it was experiencing server and business operation disruptions. However, the actual confirmation that a breach had occurred would not come until September 4, when the company filed a Form 8-K with the SEC. As of that time, it appeared that no data from customers or suppliers had been accessed by unauthorized parties.
The unfolding situation has led to PCMag’s Kate Irwin reporting that the Play ransomware group has been identified as a significant threat since at least 2022. This group has struck more than 300 organizations worldwide. The Play group’s MO is to steal data and then to encrypt it. They use direct communication with the victims to work through their demands.
The most recent brush that the semiconductor company Microchip had with the cybersecurity menace shows how crucial it is for businesses to take protective measures. Various authorities recommend using several key steps to protect not just sensitive data but also the many systems that hold that data. These include mandatory multi-factor authentication for any system that holds sensitive data, a swift response to any discovered vulnerability in a system, and, as always, making sure that any software in use is fully patched and up-to-date.
Microchip Technology’s trials and tribulations should make organizations everywhere take a long, hard look at their cybersecurity defenses and consider shoring them up.
Planned Parenthood:
Another prominent target of ransomware attacks was Planned Parenthood. Planned Parenthood confirmed a cyberattack that impacted its IT systems in late August 2024, prompting portions of its network to be taken offline as a security measure. The ransomware group RansomHub has claimed responsibility, threatening to leak 93GB of allegedly stolen data. This attack raises significant privacy concerns, particularly due to the sensitive nature of the healthcare services the organization provides. The investigation is ongoing, and no confirmed data theft has been reported yet.
Avis Budget Group Data Breach
A major cybersecurity incident hit Avis Budget Group in early August 2024. On September 5, 2024, the group began notifying customers. Hackers got into a third-party cloud application and used it to access highly sensitive personal data of around 300,000 of Avis’s customers. The incident started on August 3 and played out over several days until it was detected (and thankfully, stopped) on August 5. Hackers got into the system and took personal information that you would think was well-protected. They accessed names, addresses, dates of birth, driver’s license numbers, and a lot of key financial information—credit card numbers among them.
The attack on Avis is not an isolated instance; rather, it is part of a larger trend targeting the automotive and rental sectors. So what makes these two industries so attractive? Well, the simple answer is that Automotive and Rentals are both data-rich sectors operating with weak cybersecurity. Increasingly, rental car companies find themselves under direct threat from sophisticated bad actors.
Transportation Industry Under Siege
A well-coordinated and sophisticated phishing effort recently hit the transportation industry. This attack on companies across North America targeted logistics organizations with malicious tools, like Lumma Stealer and NetSupport malware. The threat actor’s goal was to obtain sensitive info and execute unauthorized access.
Tactics and Techniques
The attackers employed compromised email accounts from legitimate transportation and shipping companies, enabling them to seamlessly inject harmful content into existing email threads. Although the initial method of compromising these accounts remains unknown, at least 15 email accounts were reported as part of this campaign. From May to July 2024, the attackers primarily leveraged Lumma Stealer, StealC, and NetSupport.
Shifts in Strategy
Starting in August, a change in tactics was observed: new infrastructures and delivery techniques surfaced, introducing harmful payloads like DanaBot and Arechclient2. By distributing email attachments with internet shortcuts or URLs from Google Drive, recipients unknowingly fetched malware if they opened these links. This approach came alongside a technique called ClickFix, which deceived users into executing a Base64-encoded PowerShell script, spreading DanaBot malware.
From the outset, Proofpoint indicated what was happening: transportation and logistics companies were being targeted, and more than one prominent name in the business was among the victims. It was clear that threat actors masquerading as or in some way affiliated with these software companies (like Samsara and AMB Logistics) were trying to understand how the targeted organizations operated. This aspect of the operation suggests thorough research was conducted before launching attacks.
Antwan Banks, who directs enterprise security at NMFTA, drives home the need for vigilance: “It is a very real threat, and it could come from anywhere. You ought not to think of this as a one-off, that it won’t happen again.”
Healthcare Breach at Elitecare Hospital
In September 2024, Elitecare Emergency Hospital experienced a very significant cyberattack that was due to serious vulnerabilities in its healthcare IT system. This major breach had occurred because of an earlier and much larger breach at another healthcare company, linked to Elitecare by the notorious ransomware team ALPHV (or BlackCat). These cybercriminals managed to compromise Change Healthcare, a vital healthcare payment processing company, and used that victory to get at Elitecare in a way that made the hospital pay dearly. They got in without any Multi-Factor Authentication (MFA) being required for remote access to the servers that made up the hospital’s IT system—a serious oversight by the compromised hospital that isn’t even allowed under HIPAA.
Compromised sensitive patient data included health information, Social Security numbers, and insurance claims. The breach affected the operations of hospitals, medical offices, and pharmacies and clearly demonstrated the necessity of more robust security measures in the healthcare sector. Because the breach was partly the result of using outdated technology, the incident also served to emphasize the importance of compliance with necessary regulatory frameworks.
The assault had a severe effect on finances, with reports putting the total cost at up to $872 million. The discussions sparked by this breach centered on the need to make cybersecurity as ironclad as possible for healthcare providers. Making it as tough as possible to get at data requires a combination of technologies: end-to-end encryption, access controls, regular updates. Organizations have to work day in and day out on these problems to keep them from becoming even more serious than they already are.
Slim CD:
On September 6, 2024, Slim CD, a payment gateway provider, notified approximately 1.7 million individuals of a data breach that compromised their personal and credit card information. The breach, which occurred over ten months, was discovered on June 15, 2024, although attackers had access to Slim CD’s systems since August 2023. The compromised data includes names, addresses, credit card numbers, and expiration dates. Slim CD has reported the incident to law enforcement and regulators, including the Maine Attorney General’s Office, and has advised affected individuals to remain vigilant against identity theft. No identity theft protection services are being offered.
Basic Defenses Aren’t Enough Anymore
September 2024 brought forth some truly alarming cyberattacks across a range of industries. From healthcare to tech, no sector was left untouched, and each incident exposed just how vulnerable many companies still are when it comes to protecting their data. These breaches highlight a simple but crucial fact: basic cybersecurity just isn’t enough anymore. Businesses need to step up their game by focusing on proactive threat detection and responding fast when an attack happens.
The fallout from these attacks goes way beyond financial loss—it’s about the trust companies build with their customers and partners, which can take years to recover once damaged. The lesson is clear: everyone, from the C-suite to the frontline workers, needs to be involved in cybersecurity efforts. It’s not just an IT issue anymore; it’s a company-wide priority. The faster businesses embrace this reality, the better prepared they’ll be for whatever comes next in the constantly shifting cyber landscape.