Connect with us

Infosecurity

Are CEOs Judged Not to Have Ensured Necessary Cybersecurity? The New Reality

Published

on

Are CEOs Judged Not to Have Ensured Necessary Cybersecurity? The New Reality

When a major cyber-attack hits, the spotlight often falls on the chief executive. But a recent report from the UK’s Culture, Media and Sport Committee suggests that CEOs cybersecurity compensation could soon be directly tied to how well they protect their organisations. This is no longer just an IT issue—it’s a boardroom liability.

The investigation, triggered by the October 2015 cyber-attack on TalkTalk, has delivered two stark recommendations that every enterprise leader should understand. Whether you run a small business or a multinational, the message is clear: ignore cybersecurity at your peril.

Linking CEO Pay to Cybersecurity Performance

The committee’s report, published on 17 June, proposes a radical shift in executive accountability. It suggests that a portion of CEO compensation should be linked to effective cybersecurity. In the committee’s own words: “To ensure this issue [cybersecurity] receives sufficient CEO attention before a crisis strikes, a portion of CEO compensation should be linked to effective cybersecurity, in a way to be decided by the Board.”

This recommendation alone is a wake-up call for many leaders. Remuneration committees will now have to grapple with how to measure cybersecurity effectiveness. Lawyers, too, can expect a new stream of work as they help define what constitutes “effective” protection.

How Will Boards Measure Cybersecurity?

Implementing this will not be straightforward. Boards will need to establish clear metrics—perhaps based on incident response times, employee training completion rates, or vulnerability patching schedules. The key is to move beyond vague promises and create tangible targets that align with business risk.

GDPR and the Threat of Custodial Sentences

Even more alarming for executives is the second recommendation. The committee concurs with the Information Commissioner’s Office (ICO) that, while the EU General Data Protection Regulation (GDPR), effective from 2018, will sharpen focus on data protection, a full range of sanctions—including custodial sentences—would be beneficial.

This means that enterprise executives could not only lose money if they are judged not to have ensured the necessary cybersecurity, but they may also face imprisonment. The prospect of jail time for data breaches is a dramatic escalation that demands immediate attention.

The Growing Cyber-Crime Threat

Some may view these recommendations as extreme. However, the report highlights that cyber-crime is a mounting risk for businesses of all sizes. According to the Federation of Small Businesses (FSB), a third of their members have experienced cyber-crime. Meanwhile, a 2015 survey by PwC for the Department for Business, Innovation and Skills found that 90% of large organisations had suffered a security breach.

Executives constantly balance risk and reward. Many have previously assumed that cyber-attack risks are negligible, relegating cybersecurity to the bottom of the business agenda. The committee’s novel approach aims to change that calculus by tying personal financial and legal consequences to cybersecurity outcomes.

ICO’s Expanded Audit Powers

Another critical development is the call for the ICO to gain additional non-consensual audit powers, particularly in health, local government, and potentially other sectors. Currently, the ICO has limited ability to inspect systems without consent. If this changes, regulators could knock on your door to verify compliance with security standards.

Businesses already accept that HMRC may inspect accounts to ensure tax and VAT payments are correct. A similar regime for cybersecurity would mean keeping your digital house in order at all times. The committee’s report states: “At present, the ICO has limited powers of non-consensual audit… the ICO should have additional powers of non-consensual audit.”

What This Means for CEOs Today

The TalkTalk incident involved the theft of customer records, including bank account details. Tens of thousands of individuals had their personal information compromised. In response, diligent CEOs—mindful of their income and liberty—are now asking searching questions about IT security. They are also listening with renewed sympathy to their CIO’s pleas for increased cybersecurity budgets.

As a result, the message is clear: cybersecurity is no longer just a technical concern. It is a core governance issue that affects compensation, legal liability, and even personal freedom. CEOs who fail to act may find themselves judged not only by the market but also by the courts.

For more insights on how to protect your organisation, explore our guide on cybersecurity risk management strategies and GDPR compliance steps.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

Squatted Open VSX Extensions Slip Past the Registry and Drain CI Data

Published

on

fake Open VSX extensions

Malicious Packages Hit the Open VSX Registry

Counterfeit extensions that copied the names of legitimate developer tools were discovered on the Open VSX registry. Roughly a quarter of them were quietly harvesting the git and continuous integration identity of anyone who ran them.

Security firm Manifold Security published its findings on August 4. The team flagged 77 packages that appeared between July 26 and August 1. Each one republished the name and namespace of a real extension from an account that had zero ownership rights to it.

Every single package beaconed to one domain. That domain was registered just 11 days before the first malicious package surfaced.

What the Payload Actually Collected

Most of the packages were light on data. They sent little more than a hostname. But the squatted namespaces tell a story of their own. The list included AMD, LEGO Education, Hyperledger, Azure, Artsy, Salesforce OSS, a US federal agency, and marketplace.visualstudio — a name that impersonated the marketplace itself.

The other 19 packages carried a much heavier payload. Seconds after activation, they sent the hostname, the operating system username, editor details, and the machine ID. Then things got more serious.

The malicious code read the repository currently open in the editor. It pulled the git remote host and organization, the commit email domain, the branch, and the HEAD commit. It also grabbed continuous integration values, including the GitHub repository name, GitLab project path, and Codespace name.

“On a build runner or a cloud development environment, that is the full private repository name, not just the organization,” Manifold explained.

The Disclosure Was the Disguise

Here’s the twist. The listings actually disclosed what they were doing.

Each one carried a “Telemetry” section that enumerated most of those fields accurately. The disclosure also included assurances that no source code, credentials, or tokens were taken. Manifold checked those claims against the code and found they held up.

Almost all of them, anyway.

One listing stated that continuous integration data covered marker names only and never values. The code, however, sent both. The single most sensitive field in the payload was the one the disclosure explicitly said was not being sent.

These extensions had no other real function. A status bar item rendered a checkmark. One command displayed a message box. Then the beacon fired.

Built to Outlive the Takedown

The collector domain was registered through a registrar that redacts registrant details. The registration term was three years. The code treated any HTTP response as success — including an error — and retried across seven days, resuming on every editor restart.

If every endpoint failed, the beacon queried a DNS TXT record for a replacement collector address. That let the operator relocate infrastructure without shipping new packages.

The payload also reported whether the workspace’s own devcontainer or extensions configuration had pulled the extension in. That distinction matters: it separates installs a repository caused from installs a human chose.

Manifold argued this is critical because name resolution is increasingly automated. Agents and provisioning scripts install by name across two registries whose separate ownership rules make a squatted name indistinguishable from the real one.

How to Protect Yourself

Open VSX removed the packages on August 3, though the infrastructure remained live at the time of writing. If you’re worried about similar attacks, Manifold offered some practical advice:

  • Pin by publisher and version where registries are mirrored internally
  • Treat the unverified-publisher banner as a blocking condition in automated installs
  • Alert on editor processes contacting recently registered domains shortly after startup

This isn’t the first time extension name abuse has caused problems. Earlier research highlighted how malicious VS Code extensions exploit a name reuse loophole. The pattern keeps repeating because the registries haven’t closed the gap.

The takeaway is simple. If you’re running automated installs across a team, don’t trust names alone. Verify the publisher. Check the version. And treat any telemetry disclosure in a random extension as a red flag, not a comfort.

Continue Reading

Infosecurity

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches

Published

on

Snowflake hacks

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches

A Canadian national is facing decades in prison for his role in the hacking of data storage platform Snowflake. Connor Riley Moucka, 26, pleaded guilty to computer fraud, wire fraud, aggravated identity theft and a related conspiracy on Wednesday in a Washington state federal court. He will be sentenced on October 27 and faces up to 32 years behind bars.

Moucka and his co-conspirators used stolen login credentials to breach Snowflake and steal troves of information from at least 165 companies. The hackers walked away with billions of files from major corporations, including AT&T, Ticketmaster, Advance Auto Parts, one of the largest school districts in the U.S., Neiman Marcus, Santander, LendingTree and more.

The AT&T breach exposed logs of calls and texts belonging to more than 100 million customers. The Ticketmaster breach affected roughly 560 million users. Those numbers alone show the scale of what Moucka and his crew pulled off.

How the Snowflake hacks unfolded

Moucka, from Kitchener, Ontario, was arrested in November 2024 and extradited to the U.S. in July 2025. Prosecutors said the breaches happened between February and October 2024. During that window, the hackers stole banking records, financial information, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, Social Security numbers and more.

The stolen data wasn’t just for show. The hackers tried to extort victim companies by threatening to publish the information online. The crew collected about $2.5 million in ransom payments. Court documents show Moucka even extorted at least one victim a second time.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” prosecutors said.

That’s a chilling detail. It shows Moucka wasn’t just casting a wide net — he was targeting specific people with sensitive information.

Profit from stolen data

Beyond the ransom payments, Moucka earned another $495,000 by advertising some of the stolen data on cybercriminal forums like BreachForums and XSS.is. Court documents said victim companies suffered about $9.5 million in losses related to the breaches.

FBI Special Agent in Charge W. Mike Herrington didn’t hold back in his assessment of Moucka’s actions.

“Connor Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers,” Herrington said.

Snowflake’s response and the Mandiant investigation

After the breaches came to light, Snowflake hired Google’s Mandiant unit to investigate. Mandiant confirmed that Snowflake’s platform itself wasn’t compromised. The hackers, according to Mandiant, stole still-valid credentials dating back to 2020 and used those login details to access company accounts.

That’s a key point for anyone worried about cloud security. The breach wasn’t a flaw in Snowflake’s infrastructure — it was a credential problem. The hackers got their hands on old passwords that were still active, and that was enough.

The Turkey connection

Mandiant said at the time that the hackers behind the campaign are “based in North America, and collaborates with an additional member in Turkey.” At least one of the alleged Turkey-based hackers, John Erin Binns, was detained by Turkish authorities in 2024 after being indicted for his role in a previous hack of telecom T-Mobile.

Before his arrest, Moucka allegedly spoke to news outlet 404Media, telling them he expected to be arrested and had been destroying evidence in advance of his detainment. That detail paints a picture of someone who knew the net was closing in.

What this means for cybersecurity

The Snowflake hacks are a reminder that credential theft remains one of the most effective attack vectors. Companies can have the best security infrastructure in the world, but if old passwords are still floating around, they’re a liability.

For businesses, the takeaway is clear: regularly rotate credentials, enforce multi-factor authentication, and audit who has access to what. For individuals, the lesson is equally simple — if you’re reusing passwords across accounts, stop. The fallout from these breaches affects real people, not just corporations.

Moucka’s guilty plea is a significant step in holding cybercriminals accountable. But with 165 breaches and millions of victims, the damage is already done. Sentencing in October will determine how long he pays for it.

Continue Reading

Infosecurity

Ransomware Attacks Surge 19% in July After a Quieter Spring

Published

on

ransomware attacks surge

Ransomware Attacks Surge After a Spring Slowdown

Ransomware activity snapped back with a vengeance in July. New data from Comparitech shows a 19% jump in claimed attacks compared to June, making last month the second-busiest of 2026 so far.

The numbers are stark. Researchers tracked 799 claimed ransomware attacks in July — the third-highest monthly total in the past 17 months. That spike follows an unusually quiet stretch from April through June, when activity dipped noticeably.

Finance took the hardest hit, with attacks soaring 71% month-over-month. Technology wasn’t far behind at 62%, while healthcare (46%) and education (44%) also saw sharp increases. US-based organizations felt the pressure too, with attacks up 31% from June.

Major Incidents Show the Damage Ransomware Can Do

Two confirmed attacks stood out for their real-world consequences. US healthcare provider AnMad was forced to close facilities after a breach. In Romania, the government’s land registry agency suffered an attack that wiped an entire database, throwing the country’s real estate market into chaos.

Rebecca Moody, head of data research at Comparitech, put it bluntly: “These attacks highlight how ransomware groups hit organizations in various different ways – taking down key systems, stealing troves of data, and even deleting massive datasets.”

Her advice? Regular backups — and backups of those backups. “Never has it been more important for organisations to ensure they’re carrying out regular backups… so they can reset systems and restore data as quickly as possible if the worst does happen,” she said.

The Gentlemen and Qilin Continue Their Battle for Supremacy

Two ransomware strains continue to dominate the threat landscape. The Gentlemen and Qilin together accounted for 33% of all attacks in July — 135 and 125 claims, respectively.

That’s a continuation of a power struggle that’s been brewing for months. ReliaQuest analysis from earlier this year found The Gentlemen had overtaken Qilin as the most prolific threat actor between March and May 2026.

The gap between these two and everyone else is significant. DragonForce came in third with 41 attacks, followed by INC (36), CRPx0 (33), and SafePay (30).

What This Means for Security Teams

The July numbers are a reminder that ransomware isn’t going anywhere. The lull in spring was temporary — these groups adapt, regroup, and strike when defenses drop.

For organizations in finance, healthcare, and tech, the message is clear: ransomware protection strategies need constant updating. That means patching vulnerabilities, segmenting networks, and testing recovery plans before an incident, not after.

It also means paying attention to who’s actually attacking. The dominance of The Gentlemen and Qilin suggests a consolidation in the ransomware ecosystem — fewer, bigger players with more resources and better tactics.

How to Prepare for the Next Wave

Comparitech’s data points to a few practical steps every organization should take:

  • Maintain offline backups and test restoration procedures regularly
  • Monitor threat intelligence feeds for emerging ransomware groups
  • Implement strict access controls and multi-factor authentication
  • Develop and rehearse an incident response plan specific to ransomware
  • Consider cyber insurance that covers extortion payments and business interruption

The July surge is a warning shot. The spring lull lulled some into complacency — but the attackers never stopped. They were just waiting.

Continue Reading

Trending