Cox Media Group Validates Ransomware Attack that Pulled Down its Broadcasts

Date:

Share post:

On June 3, 2021, American media company Cox Media Group (CMG) experienced a cyberattack in which the malicious threat actor encrypted the network servers and forced the systems to go offline.

In the initial investigation, the company did not mention the nature of the attack; however, in a notification letter released on October 8, CMG acknowledged the breach as a ransomware attack. The company also stated that it did not pay ransom to the threat actors.

Over 800 individuals were believed to have been impacted. Personal information exposed in the breach included names, addresses, Social Security numbers, financial account numbers, health insurance information, health insurance policy numbers, medical condition information, medical diagnosis information, and online user credentials. The attack also resulted in disruption of the streaming of its live TV and radio broadcasts streams. As a security measure, the company took down the systems to mitigate the further spread of the threat.

Improved Security

Post attack, the company took measures to improve its security posture by adopting multi-factor authentication, enterprise-wide password reset, and implementation of endpoint detection solutions.

Ransomware Attacks   

In its Ransomware Index Update Q2 2021, Cyber Security Works states that six vulnerabilities have become associated with seven ransomware strains; among them are the infamous Darkside, Conti, FiveHands, and the newly christened, Qlocker.

With this update, the total number of vulnerabilities associated with ransomware has increased to 266. It also noticed a 1.5% increase in the number of actively exploited vulnerabilities that are trending currently, reiterating that a risk-based approach for the remediation of vulnerabilities is the need of the hour.

One of the most compelling observations during the quarter was the exploitation of zero-day vulnerabilities even before vendors published their discovery or released patches.

We have witnessed dangerously disruptive ransomware attacks in 2021. The ransomware attacks on Colonial Pipeline, JBS USA Holdings, Kaseya, and Accenture — the most recent victim of LockBit — are proof that the lack of cyber hygiene is rampant. These attacks highlight the need for the continual assessment of vulnerabilities and the prioritization of remediation.

See also: Conti Ransomware Attacks on Rise – CISA, FBI, NSA Issue Joint Alert

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

5th Edition MENA CYBER SECURITY CONFERENCE – RIYADH EDITION

Name: 5th Edition MENA CYBER SECURITY CONFERENCE - RIYADH EDITION Website: https://mena-cybersecurity.com/riyadh/ Date: September 8th, 2026 Location: Crowne Plaza Riyadh Palace,...

Cyber Security Expo

Name: Cyber Security EXPO Website: https://www.cybersecurityexpo.co.uk/cheltenham Date: September 10, 2026 Location: Cheltenham Racecourse, United Kingdom The Cyber Security EXPO is the only...

6th Edition MENA CISO SUMMIT – Dubai Edition

Name: 6th Edition MENA CISO Summit – Dubai Edition Website: https://mena-cybersecurity.com/ciso-dubai/ Date: September 30, 2026 Location: Millennium Airport Hotel, Dubai,...

Build the Pipeline, Not the Headcount

There's a principle in Taoist philosophy called wu wei, often translated as "effortless action" or "non-doing." It doesn't...