Borrower sues Gold Star Mortgage a day after ransomware gang claims data theft | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The cybercriminal group BrainCipher has claimed responsibility for the attack, according to the filing. The suit says BrainCipher claims to have pulled more than 10,300 documents from Gold Star’s IT network.

The borrower behind the suit says she was a former Gold Star customer who handed over her personal information as a condition of receiving a loan. Since the breach, she alleges she has experienced “a sharp uptick in suspicious spam emails and calls” and received alerts that her data “was discovered on the Dark Web,” according to the filing. She says she now checks her financial and credit statements multiple times a week.

The lawsuit describes a lender that collected highly sensitive financial data from borrowers but allegedly fell short on the security infrastructure to protect it. The filing alleges Gold Star did not use phishing-resistant multi-factor authentication, did not encrypt stored data, did not maintain adequate monitoring or alert systems, and did not properly train employees on cybersecurity. The suit goes further, alleging the lender kept borrower data long after the customer relationship ended – and left it sitting on its network “in a condition vulnerable to cyberattacks.”

Gold Star knew – or should have known – its systems would be attractive targets for cybercriminals, the suit alleges, given the volume and sensitivity of borrower data it held. The filing says the lender “failed to recognize the Data Breach until cybercriminals had already accessed” borrower information, meaning it “had no effective means in place to ensure that cyberattacks were detected and prevented.”

The filing points to a stack of federal cybersecurity benchmarks it says Gold Star failed to meet: FTC guidelines on data protection, the NIST Cybersecurity Framework, the Center for Internet Security’s Critical Security Controls, and CISA recommendations for defending against intrusions.

——————————————————–


Click Here For The Original Source.

.........................