Skip to content

Qualys Data Breach

Article by Tsaaro

7 min read

Cybersecurity firm Qualys is the latest victim of a cyber attack, the company was likely hacked by threat actors that exploited a zero-day vulnerability in their Accellion FTA server. A set of cybercriminals belonging to the Clop Ransomware group claimed responsibility for a breach of Qualys, a major cloud computing security vendor. As proof of the access to data, an extortion site maintained by hackers on the dark web has leaked documents claiming to contain information on Qualys customers of about 19,000 clients, including major financial firms like Capital One and Experian.

Technical Details

The wave of attacks began in mid-December 2020, threat actors exploited multiple zero-day vulnerabilities in the Accellion File Transfer Appliance (FTA) software to deploy a shell dubbed DEWMODE on the target networks.

The attackers exfiltrated sensitive data from the target systems and then published it on the CLOP ransomware gang’s leak site. It has been estimated that the group has targeted approximately 100 companies across the world between December and January. Further, Qualys CISO Ben Carr added that the incident hadn’t affected Qualys production environments, codebase or customer data hosted on the Qualys Cloud Platform.

FireEye pointed out that despite FIN11 hackers publishing data from Accellion FTA customers on the Clop ransomware leak site, they did not encrypt systems on the compromised networks. In response to the wave of attacks, the vendor has released multiple security patches to address the vulnerabilities exploited by the hackers and the company is also going to retire legacy FTA server software by April 30, 2021.

Mitigation Strategy

An organization should always be well prepared for the forthcoming incidents that may approach possessing harmful instincts such as cyber-attacks. To tackle those attacks at the initial level, following are certain points that needs to be followed by any organization so as to reduce the risk of loss from the occurrence of any undesirable event.

1. Users should follow the best practices to defend against the malware and create an effective backup strategy by following the 3-2-1 rule:
–   Adopt strong passwords throughout the network.
–   Consider network segmentation to separate important processes and systems from the wider access network.
–   Increase awareness of how ransomware spreads, i.e., through spammed emails and attachments.
–   Monitor and audit network traffic for any suspicious behaviors or anomalies

2. Deploy IAM, limit privileged users, and implement MFA.

3. Install an antivirus solution, schedule signature updates, and monitor the antivirus status on all equipment.

4. If noticed any kind of activity (new process initiated, any files have been deleted automatic), take an appropriate action.

5. Keep your operating system and software up to date with the latest patches. Vulnerable applications and operating systems are the target of most attacks. Ensuring      these are patched with the latest updates greatly reduces the number of exploitable entry points available to an attacker. Use application whitelisting to help prevent malicious software and unapproved programs from running. Application whitelisting is one of the best security strategies as it allows only specified programs to run, while blocking all others, including malicious software.

Preventive Measures

An organization’s ability to rapidly respond to and recover from an incident begins with the development of an incident response capability. An organization’s response capability should focus on being prepared to handle the most common attack vectors (e.g., spearphishing, malicious web content, credential theft).
In general, organizations should prepare for those attacks for a longer run by keeping the following key pointers in consideration:

– Block the IOCs.
– Enable E-mail filtering for .exe attachment files.
– Set remote access restrictions.
– Configure PowerShell to execute only signed scripts.
– Configure Windows to show file extensions and keep the macros disabled.
– To ensure that recovery from a ransomware or sabotage attack is possible, all data must be regularly backed up and a good backup strategy adopted.
– Implement endpoint security with active monitoring.
– Encrypt all sensitive organizational information.
– Upgrade your systems with the latest security patches.

Conclusion

Ransomware has been around for a few years now and we are starting to see instances of this type of malware that break the mold and forge a new direction. Clop differs from other ransomware in many significant ways — from its capabilities to the heart of the ransomware attack itself, gaining entry.

It will be interesting to see if other ransomware begins to use exploit kits as infection vectors like Clop or if this practice remains the exception to the rule. The Financial Services Information Sharing and Analysis Center (FS-ISAC), a clearinghouse for financial threat information whose members include big banks, encourages all financial institutions to follow published procedures to assess and maintain the security of their systems and to continually monitor for signs of any anomalous activity.

598 thoughts on “Qualys Data Breach”

  1. Insightful read! I found your perspective very engaging. For more detailed information, visit: READ MORE. Eager to see what others have to say!

  2. medication from mexico pharmacy [url=https://mexicanpharmeasy.com/#]MexicanPharmEasy[/url] reputable mexican pharmacies online

  3. real viagra without a doctor prescription usa [url=https://canadianpharm1st.com/#]canadianpharm1st[/url] viagra without doctor prescription amazon

  4. buying prescription drugs in mexico [url=https://mexicanpharmeasy.com/#]mexican pharm easy[/url] pharmacies in mexico that ship to usa

  5. cvs prescription prices without insurance [url=https://canadianpharm1st.com/#]canadian pharm[/url] herbal ed remedies

  6. buying prescription drugs in mexico online [url=https://mexicanpharmeasy.com/#]MexicanPharmEasy[/url] mexican pharmaceuticals online

  7. online shopping pharmacy india [url=https://indianpharmstar.com/#]IndianPharmStar.com[/url] india pharmacy mail order

  8. mexico pharmacies prescription drugs [url=https://mexicanpharmeasy.com/#]mexican pharm easy[/url] reputable mexican pharmacies online

  9. zestril 5 mg india [url=https://lisinoprilus.com/#]zestril tablet[/url] order lisinopril online united states

  10. buy rybelsus online [url=https://semaglutidetablets.store/#]semaglutide tablets price[/url] semaglutide tablets store

  11. пин ап казино [url=https://pinup2025.com/#]пин ап казино официальный сайт[/url] пин ап казино официальный сайт

  12. welches online casino [url=https://casinositeleri2025.pro/#]yasal oyun siteleri[/url] ilk giriЕџte bonus veren bahis siteleri

  13. Г§evrim ЕџartsД±z deneme bonusu veren siteler 2025 [url=https://casinositeleri2025.pro/#]bonusu veren siteler[/url] betganyon

  14. пин ап казино официальный сайт [url=https://pinup2025.com/#]пин ап[/url] пинап казино

  15. en kazancl? slot oyunlar? [url=https://slottr.top/#]az parayla cok kazandiran slot oyunlar?[/url] en kazancl? slot oyunlar?

  16. en cok kazand?ran slot oyunlar? [url=https://slottr.top/#]slot oyunlar?[/url] az parayla cok kazandiran slot oyunlar?

  17. best pharmacy online [url=https://canadianpharmi.com/#]Cheapest drug prices Canada[/url] how to get prescription drugs without doctor

  18. brand prednisone [url=https://prednibest.com/#]prednisone 20mg online[/url] can you buy prednisone without a prescription

  19. amoxicillin 500mg capsule buy online [url=https://amoxstar.com/#]AmoxStar[/url] amoxicillin 500mg without prescription

  20. buy ciprofloxacin over the counter [url=https://cipharmdelivery.com/#]CiPharmDelivery[/url] where can i buy cipro online

  21. can i get cheap clomid without prescription [url=https://clomidonpharm.com/#]clomidonpharm[/url] can you get generic clomid without insurance

  22. order clomid without rx [url=https://clomidonpharm.com/#]cost of cheap clomid[/url] can i get cheap clomid now

  23. amoxicillin 825 mg [url=https://amoxstar.com/#]over the counter amoxicillin canada[/url] amoxicillin generic brand

  24. can you buy generic clomid without insurance [url=https://clomidonpharm.com/#]where can i get clomid prices[/url] how to buy clomid no prescription

  25. пин ап казино официальный сайт [url=https://gramster.ru/#]Gramster[/url] пин ап казино

  26. пин ап казино официальный сайт [url=https://gramster.ru/#]gramster.ru[/url] pinup 2025

  27. mexican drugstore online [url=https://mexicanpharmacy.store/#]mexican pharmaceuticals online[/url] medication from mexico pharmacy

  28. pharmacy website india [url=https://indianpharmacy.win/#]indian pharmacy online[/url] reputable indian online pharmacy

  29. buying prescription drugs in mexico online [url=https://mexicanpharmacy.store/#]pharmacies in mexico that ship to usa[/url] mexican border pharmacies shipping to usa

  30. india pharmacy [url=https://indianpharmacy.win/#]reputable indian pharmacies[/url] online shopping pharmacy india

  31. india pharmacy mail order [url=https://indianpharmacy.win/#]india online pharmacy[/url] mail order pharmacy india

  32. mexican mail order pharmacies [url=https://mexicanpharmacy.store/#]mexican pharmaceuticals online[/url] п»їbest mexican online pharmacies

  33. online canadian pharmacy [url=https://canadianpharmacy.win/#]best online canadian pharmacy[/url] legit canadian pharmacy

  34. п»їbest mexican online pharmacies [url=https://mexicanpharmacy.store/#]mexico pharmacies prescription drugs[/url] medicine in mexico pharmacies

  35. Cialis without a doctor prescription [url=https://maxpillsformen.com/#]Tadalafil Tablet[/url] п»їcialis generic

  36. Cialis without a doctor prescription [url=https://maxpillsformen.com/#]Max Pills For Men[/url] Cialis without a doctor prescription

  37. Cheap Sildenafil 100mg [url=https://fastpillsformen.com/#]FastPillsForMen.com[/url] viagra without prescription

  38. sildenafil 50 mg price [url=https://fastpillsformen.com/#]FastPillsForMen.com[/url] Viagra generic over the counter

  39. slot oyunlar? [url=https://slotsiteleri25.com/#]az parayla cok kazandiran slot oyunlar?[/url] guvenilir slot siteleri

  40. yeni deneme bonusu veren siteler [url=https://denemebonusuverensiteler25.com/#]deneme bonusu veren siteler[/url] deneme bonusu veren siteler yeni

  41. en cok kazand?ran slot oyunlar? [url=https://slotsiteleri25.com/#]slot oyunlar?[/url] en cok kazand?ran slot oyunlar?

  42. deneme bonusu veren yeni siteler [url=https://denemebonusuverensiteler25.com/#]deneme bonusu veren siteler[/url] yeni deneme bonusu veren siteler

  43. casino bahis siteleri [url=https://casinositeleri25.com/#]en guvenilir casino siteleri[/url] en guvenilir casino siteleri

  44. farmacia online piГ№ conveniente [url=http://farmabrufen.com/#]Ibuprofene 600 prezzo senza ricetta[/url] farmacie online autorizzate elenco

  45. Farmacia online miglior prezzo [url=https://farmabrufen.shop/#]BRUFEN 600 acquisto online[/url] п»їFarmacia online migliore

  46. viagra generico in farmacia costo [url=http://farmasilditaly.com/#]acquisto viagra[/url] viagra online in 2 giorni

  47. п»їFarmacia online migliore [url=https://farmaprodotti.com/#]Farma Prodotti[/url] farmaci senza ricetta elenco

  48. farmacie online affidabili [url=https://farmatadalitaly.shop/#]Tadalafil generico migliore[/url] Farmacia online miglior prezzo

  49. taya365 com login [url=http://taya365.art/#]taya365[/url] Live music events often accompany gaming nights.

  50. taya365 com login [url=https://taya365.art/#]taya365 login[/url] The casino scene is constantly evolving.

  51. taya365 com login [url=http://taya365.art/#]taya365 com login[/url] Slot machines feature various exciting themes.

  52. phmacao com login [url=http://phmacao.life/#]phmacao.life[/url] The Philippines has several world-class integrated resorts.

  53. phmacao club [url=http://phmacao.life/#]phmacao casino[/url] Many casinos host charity events and fundraisers.

Leave a Reply

Your email address will not be published. Required fields are marked *

Tsaaro Consulting

“It was invigorating to have a new competitor… DeepSeek’s model is impressive, particularly around what they’re able to deliver for …

Tsaaro Consulting

Introduction The Digital Personal Data Protection Act 2023 (DPDP Act) provides that consent is a prerequisite to process the personal …

Tsaaro Consulting

The Digital Personal Data Protection (DPDP) Act, 2023, introduces an overall approach to the protection of the digital personal data …

Tsaaro Consulting

Today, personal data has become one of the most valuable resources, powering industries and shaping digital economies. However, the misuse …

Tsaaro Consulting

Introduction: Data protection laws worldwide empower individuals, referred to as ‘Data Subjects’ under the GDPR or ‘Data Principals’ under India’s …

Recent Comments

SHARE THIS POST

Would you like to read regular updates from Tsaaro.
Subscribe to our newsletter

Our Latest Blogs

Read what the latest hapennings in the cyber world are and learn what the
experts have to say about them

Call Our Experts:

+91 95577 22103

small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png

We’d love to help your organization achieve your Data Protection goals!

Schedule a complimentary consultation with our Team of Experts.