Running head: WEEK 1 WRITTEN ASSIGNMENT 1
WEEK 1 WRITTEN ASSIGNMENT 4
Week 1 Written Assignment
Name of the Student
Name of College/University
Week 1 Written Assignment
A "denial of service attack" that targeted HSBC caused a shutdown of personal banking website and mobile application leaving thousands of its customers without access to banking services. The bank officials said that thousands of retail customers could not access mobile and online banking services for several hours (Dunkley, 2016). The bank and customers of the bank were the main victims in this attack. The attacker was not known in this case, but some extremist groups are known to be trying to demonstrate their abilities by bringing down various websites. The attack did not access customers’ personal information, but it denied them banking services for several hours, which was one of the motivations of the attacker. The victims in this case were the bank, its customers, and any other persons that relied on the customers for payment.
References
Dunkley, E. (2016). HSBC cyber attack brings Internet banking to its knees. Retrieved from http://www.cnbc.com/2016/01/29/hsbc-cyber-attack-brings-internet-banking-down.html
On May 26, 2015, Medical Informatics Engineering discovered a data security compromise that affected many of its clients. The security breach resulted in access to some personal information of clients, including some protected health information of those clients as it enabled the attacker to gain access to electronic health record of the organization. However, only some patients’ information were affected, and the company was prompt to notify all those whose personal information were compromised (Medical Informatics Engineering, 2015). The company’s monitoring systems were able to detect the unauthorized access in proper time to prevent further access to clients’ personal and sensitive information. The attacker was not identified, but his/her motive was to gain access to clients’ personal information with the intention of using it for personal selfish gain. The attacker gained personal information such as names, date of birth, email address, mailing address, telephone number, spousal information, usernames, hashed password, security questions and answers, Social Security number, health insurance policy information, disability code, lab results, medical conditions, and diagnoses. The attack affected the organization, its clients, and other entities associated with the organization.
References
Medical Informatics Engineering. (2015). Medical Informatics Engineering updates notice to individuals of a data security compromise. Retrieved from https://www.mieweb.com/notice/
U.S. authorities and security agencies have identified seven Iranian computer experts as being involved in cyber attacks targeting U.S. banks and a dam in New York. The FBI provided mug shots of the attackers and announced that it would press charges against them. The seven attackers worked for some private security firms that worked for the Iranian government. The attackers targeted forty-six leading financial organizations and the aim was to cause a denial of service (DDoS) attack, which essentially involves clogging of servers by flooding them with data (Winter & Connor, 2016). The attackers also targeted a dam in New York, in which they gained access into its control system. The aim was to compromise public health and safety of American citizens; however the dam was not connected to a computer system. The attacks by the cybercriminals affected the banks, the clients of the banks, and many other people (and entities) associated with the banks from all around the world.
References
Winter, T., & Connor, T. (2016). Iranians charged with cyber attacks on U.S. Banks, dam. Retrieved from http://www.nbcnews.com/news/us-news/iranians-charged-hacking-attacks-u-s-banks-dam-n544801
Between April and July 2014, cybercriminals attacked information systems of Community Health Systems (CHS), managing to have access to information relating to 4.5 million patients. The company believed that the attack originated from China. The organization and Mandiant (its forensic expert), considered that the attacker must have used highly advanced technology and malware to gain access to its information systems (Munro , 2014). The attackers managed to steal clients’ personal information such as patient names, birth dates, addresses, social security and telephone numbers. The victims in this attack included the hospital, its patients, and several other institution affiliated with the hospital. The attacker aimed to gain unauthorized access to clients’ personal information with the aim of misappropriating it for personal selfish gain.
References
Munro , D. (2014). Cyber attack nets 4.5 million records from large hospital system. Retrieved from http://www.forbes.com/sites/danmunro/2014/08/18/cyber-attack-nets-4-5-million-records-from-large-hospital-system/#7af95a0418bc