Connect with us

Published

on

Ransomware has long been plaguing American municipalities. It appeared to be another typical ransomware attack that impacted the city of Columbus, Ohio, this past July. The city’s response to the hack, however, was not, and it has cybersecurity and legal experts across the country questioning its motives.

Connor Goodwolf (legal name is David Leroy Ross) is an IT consultant who plumbs the dark web as part of his job. “I track dark web-type crimes, criminal organizations, and stuff like what the Telegram CEO has been arrested for,” Goodwolf said.

So when word got out that the city of Columbus, his hometown, had been breached, Goodwolf did what he does: he poked around online. It didn’t take him long to discover what the hackers had in their possession.

“It wasn’t the biggest, but it was one of the most impactful breaches I have seen,” Goodwolf said.

In some ways, he described it as a routine breach, with personal identifiable information, protected health information, Social Security numbers and driver’s license photos exposed. However, because multiple databases were breached, it was more encompassing than other attacks. According to Goodwolf, the hackers had breached multiple databases from the city, the police, and the prosecutor’s office. There were arrest records and sensitive information about minors and domestic violence victims. Some of the breached databases, he says, went back to 1999. 

Goodwolf found over three terabytes of data that took over 8 hours to download.

“The first thing I see is the prosecutor’s database, and I’m like ‘holy sh-t’ these are domestic violence victims. When it comes to domestic violence victims, we need to protect them the most because they have already been victimized once, and now they are again by having their information exposed,” he said.

Goodwolf’s first action was to contact the city to let them know how serious the breach was, because what he saw contradicted official statements. At a press conference on August 13,  Columbus Mayor Andrew Ginther said: “The personal data that the threat actor published to the dark web was either encrypted or corrupted, so the majority of the data came by the threat actor is unusable.”

But what Goodwolf was finding didn’t support that view. “I tried to reach out to the city multiple times to multiple departments and was blown off,” he said.

Google-owned Mandiant, as well as many other top cybersecurity firms, have been tracking a continued increase in ransomware attacks, both in prevalence and severity, and the rise of the Rhysida Group behind the Columbus hack, which has come into prominence within the last year.

The Rhysida Group claimed responsibility for the hack. While not much is known about the cyber gang, Goodwolf and other security experts say they appear to be state-sponsored and based in Eastern Europe, possibly linked to Russia. Goodwolf says these ransomware gangs are “professional operations” with a staff, paid vacation, and PR people.

“They have ramped up the attacks and targets since last autumn,” he said.

The U.S. government’s Cybersecurity and Infrastructure Security Agency issued a bulletin about Rhysida last November.

Goodwolf said that because no one from the city responded to him he went to the local media and shared data with journalists to get the word out about the seriousness of the breach. And that is when he heard from the city of Columbus, in the form of a lawsuit and a temporary restraining order preventing him from disseminating additional information. 

The city defended its response in a statement to CNBC:

“The City initially moved to obtain this order, which was granted by the Court, to prevent the dissemination of sensitive and confidential information, potentially including the identities of undercover police officers, that threatens public safety and criminal investigations.”

The city’s temporary 14-day restraining order against Goodwolf has since expired, and now it has a preliminary injunction and an agreement with Goodwolf not to release more data.

“It should be noted that the Court order does not prohibit the defendant from discussing the data breach or even describing what kind of data was exposed,” the city’s statement added. “It simply prohibits the individual from disseminating the stolen data posted on the dark web. The City remains engaged with federal authorities and cyber security experts to respond to this cyber intrusion.”

Meanwhile, the mayor did have to perform a mea culpa at a subsequent press conference, saying his initial statements were based on the information he had at the time. “It was the best information we had at the time. Clearly, we discovered that that was inaccurate information and I have to accept responsibility for that.”

Realizing the exposure to residents was greater than first thought, the city is offering two years of free credit monitoring from Experian. This includes anyone who has had contact with the city of Columbus via an arrest or other business. Columbus is also working with Legal Aid to see what additional protections are needed for domestic violence victims who may have been compromised or need help with civil protection orders.

To date, the city has not paid the hackers, who were demanding $2 million in ransom.   

‘He’s Not Edward Snowden’

Those who study cybersecurity law and work within the realm expressed surprise at Columbus filing a civil lawsuit against the researcher.

“Lawsuits against data security researchers are rare,” said Raymond Ku, professor of law at Case Western Reserve University. On the rare occasion they do happen, he said, it is usually when the researcher is alleged to have disclosed how a flaw was or can be exploited, which would then allow others to take advantage of the flaw as well.

“He wasn’t Edward Snowden,” said Kyle Hanslovan, CEO of cybersecurity company Huntress, who described himself as troubled by the city of Columbus’s response and what it could mean for future breaches. Snowden was a government contract employee who leaked classified information and faced criminal charges, but considered himself a whistleblower. Goodwolf, Hanslovan says, is a Good Samaritan who independently found the breached data.

“In this case, it appears we have just silenced someone who, as far as I can tell, appears to be a security researcher who did the bare minimum and confirmed the official statements made were not true. This can’t possibly be an appropriate use of the courts,” Hanslovan said, predicting the case will be quickly overturned.

Columbus City Attorney Zach Klein said during a September press conference that the case was “not about freedom of speech or whistleblowing. This is about downloading and disclosure of stolen criminal investigatory records.”

Hanslovan worries about the ripple effect where cybersecurity consultants and researchers are afraid to do their jobs for fear of being sued. “The bigger story here is are we seeing the emergence of a new playbook” for hacking response in which individuals are silenced, and that should not be welcomed, he said. “Silencing any opinion, even for 14 days, could be enough to prevent something credible from coming to light, and that terrifies me,” Hanslovan said. “That voice needs to be heard. As we see bigger cybersecurity incidents come up, I am worried that folks will be more concerned bringing them to light.”

Scott Dylan, founder of United Kingdom-based venture capital firm NexaTech Ventures, also thinks the actions of the city of Columbus could induce a chilling effect on the field of cybersecurity.

“As the field of cyberlaw continues to mature, this case is likely to be referenced in future discussions about the role of researchers in the aftermath of data breaches,” Dylan said.

He says legal frameworks must evolve to keep pace with the sophistication of both cyberattacks and the ethical dilemmas they generate, and the approach taken by Columbus is a mistake.

Meanwhile, the legal process will grind on for Goodwolf. Despite Columbus and Goodwolf reaching an agreement last week on the dissemination of information, the city is still suing him for damages in a civil suit that could reach $25,000 or higher. Goodwolf is representing himself in his talks with the city, though says that he has a lawyer on standby, if needed.

Some residents have filed a class-action lawsuit against the city. Goodwolf says that 55% of the information breached has been sold onto the dark web, while 45% is available for anyone with the skills to access it.

Dylan thinks the city is taking a big risk, even if its actions may be legally defensible, by creating the appearance of an attempt to silence discourse rather than encourage transparency. “It’s a strategy that could backfire, both in terms of public trust and future litigation,” he said.

“I am hoping the city realizes the mistake of filing a civil suit and the implications not just on security,” Goodwolf said, noting that Intel is building a $1 billion facility in a Columbus suburb. In recent years, the city has been positioning itself as a new tech hub in the Midwest, and attacking white hats and cybersecurity researchers, he said, could cause some in the tech sector to rethink it as a location.

Continue Reading

Technology

Anne Wojcicki has a new offer to take 23andMe private, this time for $74.7 million

Published

on

By

Anne Wojcicki has a new offer to take 23andMe private, this time for .7 million

Anne Wojcicki attends the WSJ Magazine Style & Tech Dinner in Atherton, California, on March 15, 2023.

Kelly Sullivan | Getty Images Entertainment | Getty Images

23andMe CEO Anne Wojcicki and New Mountain Capital have submitted a proposal to take the embattled genetic testing company private, according to a Friday filing with the U.S. Securities and Exchange Commission.

Wojcicki and New Mountain have offered to acquire all of 23andMe’s outstanding shares in cash for $2.53 per share, or an equity value of approximately $74.7 million. The company’s stock closed at $2.42 on Friday with a market cap of about $65 million.

The offer comes after a turbulent year for 23andMe, with the stock losing more than 80% of its value in 2024. In January, the company announced plans to explore strategic alternatives, which could include a sale of the company or its assets, a restructuring or a business combination. 

Read more CNBC tech news

23andMe has a special committee of independent directors in place to evaluate potential paths forward. The company appointed three new independent directors to its board in October after all seven of its previous directors abruptly resigned the prior month. The special committee has to approve Wojcicki and New Mountain’s proposal.

“We believe that our Proposal provides compelling value and immediate liquidity to the Company’s public stockholders,” Wojcicki and Matthew Holt, managing director and president of private equity at New Mountain, wrote in a letter to the special committee on Thursday.

Wojcicki previously submitted a proposal to take the company private for 40 cents per share in July, but it was rejected by the special committee, in part because the members said it lacked committed financing and did not provide a premium to the closing price at the time.

Wojcicki and New Mountain are willing to provide secured debt financing to fund 23andMe’s operations through the transaction’s closing, the filing said. New Mountain is based in New York and has $55 billion of assets under management, according to its website.

23andMe declined to comment.

WATCH: The rise and fall of 23andMe

The rise and fall of 23andMe

Continue Reading

Technology

Shares of Hims & Hers tumble 23% after FDA says semaglutide is no longer in shortage

Published

on

By

Shares of Hims & Hers tumble 23% after FDA says semaglutide is no longer in shortage

Hims & Hers

Shares of Hims & Hers Health tumbled more than 23% on Friday after the U.S. Food and Drug Administration announced that the shortage of semaglutide injection products has been resolved.

Semaglutide is the active ingredient in Novo Nordisk‘s blockbuster weight loss drug Wegovy and diabetes treatment Ozempic. Those medications are part of a class of drugs called GLP-1s, and demand for the treatments has exploded in recent years. As a result, digital health companies such as Hims & Hers have been prescribing compounded semaglutide as an alternative for patients who are navigating volatile supply hurdles and insurance obstacles.

Compounded drugs are custom-made alternatives to brand-name drugs designed to meet a specific patient’s needs, and compounders are allowed to produce them when brand-name treatments are in shortage. The FDA doesn’t review the safety and efficacy of compounded products.

Hims & Hers began offering compounded semaglutide to patients in May, and it owns compounding pharmacies that produce the medications.

Compounded medications are typically much cheaper than their branded counterparts. Hims & Hers sells compounded semaglutide for less than $200 per month, while Ozempic and Wegovy both cost around $1,000 per month without insurance.

Read more CNBC tech news

The FDA said Friday that it will start taking action against compounders for violations in the next 60 to 90 days, depending on the type of facility, in order to “avoid unnecessary disruption to patient treatment.”

“Now that the FDA has determined the drug shortage for semaglutide has been resolved, we will continue to offer access to personalized treatments as allowed by law to meet patient needs,” Hims & Hers CEO Andrew Dudum posted Friday on X. “We’re also closely monitoring potential future shortages, as Novo Nordisk stated two weeks ago that it would continue to have ‘capacity limitations’ and ‘expected continued periodic supply constraints and related drug shortage notifications.'”

Him & Hers’ weight loss offerings have been a massive hit with investors. Shares of the company climbed more than 200% last year, and the stock is already up more than 100% this year despite Friday’s move.

Even before it added compounded GLP-1s to its portfolio, the company said in its 2023 fourth-quarter earnings call that it expects its weight loss program to bring in more than $100 million in revenue by the end of 2025.

Despite the turbulent regulatory landscape, Hims & Hers has showed no signs of slowing down.

On Friday, the company announced it has acquired a U.S.-based peptide facility that will “further verticalize the company’s long-term ability to deliver personalized medications.” Hims & Hers will explore advances across metabolic optimization, recovery science, biological resistances, cognitive performance and preventative health through the acquisition, the company said.

That move comes just days after Hims & Hers also bought Trybe Labs, the New Jersey-based at-home lab testing facility. Trybe Labs will allow Hims & Hers to perform at-home blood draws and more comprehensive pretreatment testing.

Hims & Hers did not disclose the terms of either deal.

WATCH: Hims & Hers Super Bowl ad sparks controversy

Hims & Hers Super Bowl ad sparks controversy

Continue Reading

Technology

Tesla recalls more than 375,000 vehicles in U.S. due to failing power-assisted steering systems

Published

on

By

Tesla recalls more than 375,000 vehicles in U.S. due to failing power-assisted steering systems

Tesla models Y and 3 are displayed at a Tesla dealership in Corte Madera, California, on Dec. 20, 2024.

Justin Sullivan | Getty Images

Tesla is voluntarily recalling 376,241vehicles in the U.S. to correct an issue with failing power-assisted steering systems, according to records posted to the website of the U.S. National Highway Traffic Safety Administration.

In a safety recall report posted on the NHTSA website, Tesla said the recall includes Model 3 and Model Y vehicles that were manufactured for sale in the U.S. from Feb. 28, 2023, to October 11, 2023, and that were equipped with a certain older software release.

The records said printed circuit boards in the steering systems in affected vehicles could become overstressed, causing the power-assist steering to fail in some cases when a Tesla vehicle rolled to a stop and then accelerated.

When electronic power-assist steering systems fail in a Tesla, drivers need to exert more force to steer their cars, which can increase the risk of a collision.

Read more CNBC tech news

Tesla told the vehicle safety regulator that it was not aware of any crashes, injuries or deaths related to the power steering failures, and that it was offering an over-the-air software update as a remedy.

The recall follows an earlier related probe and voluntary recall in China concerning the same systems.

President Donald Trump has appointed Tesla CEO Elon Musk to lead a team that is slashing the federal government workforce, and in some cases, regulations and entire agencies. Those cuts already affected the NHTSA, an agency Musk has long seen as standing in the way of some of his ambitions at Tesla.

The regulator has been engaged in a yearslong investigation into safety defects in the systems that Tesla markets currently as its Autopilot and Full Self-Driving (Supervised) options. The features do not make Tesla cars into robotaxis. They require a human driver ready to steer or brake at any time.

The Washington Post reported on Thursday that Musk’s team has led mass firings at the NHTSA, reducing the agency’s workforce and capacity to investigate companies including Tesla by about 10%.

Tesla didn’t respond to a request for comment.

WATCH: Tesla stock hinges on new vehicles being introduced

Tesla stock hinges on new vehicles being introduced, says Canaccord's  George Gianarikas

Continue Reading

Trending