FBI, CISA, and NSA warn of hackers increasingly targeting MSPs – BleepingComputer

Posted: May 11, 2022 at 11:40 am

Members of the Five Eyes (FVEY) intelligence alliance today warned managed service providers (MSPs) and their customers that they're increasingly targeted by supply chain attacks.

Multiple cybersecurity and law enforcement agencies from FVEY countries (NCSC-UK, ACSC, CCCS, NCSC-NZ, CISA, NSA, and the FBI) shared guidance for MSPs to secure networks and sensitive data against these rising cyber threats.

"The UK, Australian, Canadian, New Zealand, and U.S. cybersecurity authorities expect malicious cyber actorsincluding state-sponsored advanced persistent threat (APT) groupsto step up their targeting of MSPs in their efforts to exploit provider-customer network trust relationships," the joint advisory reads.

"For example, threat actors successfully compromising an MSP could enable follow-on activitysuch as ransomware and cyber espionageagainst the MSP as well as across the MSP's customer base."

FVEY cybersecurity authorities have issued other advisories [1, 2, 3, 4] across the last several years with general guidance for MSPs and their customers.

However, today's advisory comes with specific measures on securing sensitive information and data via transparent discussions centered around re-evaluating security processes and contractual commitments to accommodate the customers' risk tolerance.

A quick rundown of the most critical tactical actions that MSPs and their customers can take includes:

"We know that MSPs that are vulnerable to exploitation significantly increases downstream risks to the businesses and organizations they support," CISA Director Jen Easterly said.

"Securing MSPs are critical to our collective cyber defense, and CISA and our interagency and international partners are committed to hardening their security and improving the resilience of our global supply chain."

One year ago, the UK government announced a call for advice on defending against software supply-chain attacks and ways to strengthen the cybersecurity defenses of IT Managed Service Providers (MSPs) across the country.

The move came after President Biden had issued an executive order to modernize the United States' defenses against cyberattacks following the SolarWinds supply chain attack and the DarkSide ransomware attack against Colonial Pipeline, the largest US fuel pipeline.

Visit link:
FBI, CISA, and NSA warn of hackers increasingly targeting MSPs - BleepingComputer

Related Posts