The Rising Threat – Examining the Largest Cyber Attacks in the Past Two Months

Sep 2, 2020 | Cyber Security, IT News

As we’ve mentioned in several prior articles and social media posts, malware, ransomware and data breaches have seen a significant increase this past year. The majority of it can be directly attributed to the COVID-19 pandemic, and it’s only getting worse.

Several incidents have occurred in just the past month or two alone, and today we’re going to outline a few and explain what happened, what caused them and how they possibly could have been prevented.

The Carnival Ransomware Attack

On Aug. 15, Carnival Corporation — the $20.8 billion corporation best known for its cruises — suffered a ransomware attack. The attacker accessed and encrypted a portion of one cruise liner brand’s information technology systems and exfiltrated sensitive customer information for extortion purposes.

What makes this even more serious is that this came only months after the company announced a similar incident in March. Its Princess and Holland Cruise Line operations experienced a malicious data breach thanks to a phishing campaign. Worse, however, was the fact that the attack itself actually took place in 2019.

But perhaps the worst part of all is that a cyber intelligence company says that it saw evidence of a network compromise and malware infection at Carnival, spanning from Feb. 2 through June 6, 2020. When they attempted to alert Carnival, they never received a response back.

The Canon USA Ransomware Attack

On Aug. 5, 2020, Bleeping Computer broke the story that Canon suffered a ransomware attack by a cybercrime group known as Maze. It had a major impact on numerous services, including Canon’s email, Microsoft Teams, USA website and other internal applications. As part of the attack, Maze claimed to have stolen 10 terabytes of data. After Canon refused to negotiate, the ransomware operators stated that they were publishing 5% of the total data stolen from Canon during the attack on Maze’s data leak website.

Maze operators use a form of ransomware that typically targets enterprise companies. The group’s malware encrypts networks, and a ransom note is then displayed. Unfortunately, simply restoring from a backup isn’t enough. Since it’s both an encryption attack as well as a data leak threat, the damage is already done once the data is out there for anyone to see.

The Twitter Hack

The Rising Threat - Examining the Largest Cyber Attacks in the Past Two MonthsEarlier in July, an attacker successfully manipulated a small number of Twitter employees and used their credentials to access Twitter’s internal systems, including getting through two-factor protections. This resulted in 130 high-profile accounts being compromised — 45 of which allowed the attacker to log into the account, reset their password and send out public tweets while pretending to be the real account owner.

This type of attack is what’s known as a social engineering scheme — where an attacker uses the art of manipulating people so they give up confidential information such as passwords, bank information or access to “secret question” answers through personal details.

Attacks like these three are only the tip of the iceberg. So much has happened this past year that is currently being reported, and we alert everyone about them daily on our social media feed as they occur. One can only wonder how much more is going unreported.

So, how do you protect yourself from similar attacks? Make secure offsite backups. Have up-to-date security solutions, ensuring that your computers are protected with the latest patches against newly discovered vulnerabilities. Use hard-to-crack, unique passwords to protect sensitive data and accounts, and enable multi-factor authentication. You should encrypt your sensitive data wherever possible. And you need to educate and inform staff about risks and the methods used by cybercriminals to electronically infiltrate organizations.

And be sure to follow us on Facebook, Twitter and Instagram for all the latest cybersecurity news and important directives from government agencies.

Since 1995, Manassas Park, VA-based V2 Systems has employed local systems administrators, network engineers, security consultants, help desk technicians and partnering companies to meet a wide range of clients’ IT needs, from research, to implementation, to maintenance. Concentrate on your VISION…We’ll handle the TECHNOLOGY!

More From V2 Systems

Downtime Is a Cybersecurity Problem, Not Just an IT Problem

Downtime can affect payroll, customer service, compliance, productivity, revenue, and reputation. For small businesses and government contractors, outages are no longer just technical issues. This blog explains why downtime should be treated as a cybersecurity and business resilience problem, and how organizations can better prepare for disruptions.

Zero Trust Without the Buzzwords: What It Actually Looks Like in Practice

Zero Trust is often discussed as a complex cybersecurity strategy, but at its core, it is about verifying access, limiting unnecessary permissions, and reducing risk. This blog explains what Zero Trust actually looks like in practice for small businesses and government contractors — without the buzzwords, hype, or confusion.

Access Creep Is a Business Risk: How Over-Permissioned Users Create Exposure

Access creep happens when users accumulate permissions over time and keep access they no longer need. For small businesses and government contractors, this creates unnecessary cybersecurity, compliance, and operational risk. This blog explains how over-permissioned users increase exposure and what organizations can do to strengthen access controls, reduce privilege misuse, and improve audit readiness.

Why Identity-Based Attacks Dominate Cybersecurity in 2026

Identity has become the new cybersecurity perimeter. In 2026, attackers are increasingly using stolen credentials, MFA fatigue tactics, and identity misuse to gain access to business systems. This blog explains why identity-based attacks are dominating the threat landscape and what small businesses and government contractors can do to strengthen access controls, improve MFA, and reduce exposure.

The Audit Readiness Problem Government Contractors Can’t Afford to Ignore

Many government contractors are not failing audits because they lack tools. They are failing because documentation is incomplete, evidence is disorganized, and readiness starts too late. This blog explains the most common gaps and how to fix them before an audit begins.

Free
Small Business Cybersecurity Checklist

cybersecurity checklist graphic