A cyberattack targeting News Corp journalists represents the latest stern reminder that MSSPs and MSPs need to audit and safeguard customers' cloud and SaaS services.In the News Corp incident, hackers had access to the media company's systems since at least February 2020 -- including emails, Google Docs and drafts of articles, The Wall Street Journal reported.Plus, a Cyber Insurance Warning: In the same filing, News Corp warned that cyber risk insurance has also become more difficult and expensive to obtain, and the Company cannot be certain that its current level of insurance or the breadth of its terms and conditions will continue to be available on economically reasonable terms.
News Corp Cyberattack Disclosure: SEC Filing
A News Corp SEC filing on February 4 shared some general information about the breach. Among the takeaways from the filing:- News Corp relies on third-party providers for certain technology and “cloud-based” systems and services that support a variety of business operations.
- In January 2022, the Company discovered that one of these systems was the target of persistent cyberattack activity.
- Together with an outside cybersecurity firm, the Company is conducting an investigation into the circumstances of the activity to determine its nature, scope, duration and impacts.
- The Company’s preliminary analysis indicates that foreign government involvement may be associated with this activity, and that data was taken.
- Based on its investigation to date, the Company believes the activity is contained.
- At this time, the Company is unable to estimate the expenses it will incur in connection with its investigation and remediation efforts.