---
title: "Cyber Security News Update, Week 44 of 2020 | DuoCircle"
description: "While on the one hand, the advent of newer technologies is a boon for us all; on the other, it also gives cyber adversaries the upper hand many times."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2020/"
---

Quick Answer

Week 44 of 2020 covered six items. The Mount Locker ransomware crew leaked 18 GB of data stolen from Swedish security firm Gunnebo AB, including bank vault and ATM blueprints. US health insurer Aetna agreed to pay $1 million to settle HIPAA violations tied to a 2017 mailing that exposed HIV status to roughly 12,000 members through a windowed envelope. Researchers at CyberNews uncovered 39 fake PayPal-UPS phishing sites built on a single shared template to harvest payment and identity details from delivery-related lures. The Russian-linked Turla APT was observed using new ComRAT and Crutch backdoors to exfiltrate documents from undisclosed European government networks. Canadian Home Depot customers reported a flood of order-confirmation notifications tied to a misconfiguration that broadcast purchase data more widely than intended. Researchers also disclosed a remote-control flaw in Hormann garage door and gate openers that could let attackers operate them from outside the network.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2020%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2044%20of%202020&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2020%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2020%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2020%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2044%20of%202020 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2044%20of%202020&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2020%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2020/11/spf-record-2738.jpg) 

While on the one hand, the advent of newer technologies is a boon for us all; on the other, it also gives cyber adversaries the upper hand many times, as they also get to improve their skill sets to launch all sorts of cyberattacks worldwide, which is why it is crucial to stay abreast of the **latest cyber updates** such as given below, which can help professionals and regular consumers of technology alike mitigate these cyber threats in the future.

## Mount Locker Group Leaks 18Gb Worth Gunnebo AB Information

In August 2020, the servers of Sweden’s leading cybersecurity company, [Gunnebo AB](https://www.hackread.com/mount-locker-ransomware-group-gunnebo-ab-data/?web%5Fview=true), were compromised. _Hackers released information regarding the firm on the dark web_. Nearly **38,000 files** were also uploaded to public servers. The Mount Locker group, who were responsible for the cyberattack, demanded bitcoins as a ransom to not release the stolen data, but the company decided to report the incident to Swedish Security Service.

The stolen data includes details such as bank vault drawings, ATM security functions, monitoring, and alarming systems, and the worst confidential drawings from the Swedish Tax agency were also compromised.

## Aetna Agrees On A Settlement After A Data Breach, Which Violates HIPAA Rules

[![Aetna Life Insurance company](https://media.mailhop.org/duocircle/images/2020/11/check-DMARC-record-3578.jpg)](https://media.mailhop.org/duocircle/images/2020/11/check-DMARC-record-3578.jpg)

[Aetna Life Insurance company](https://portswigger.net/daily-swig/aetna-agrees-million-dollar-settlement-after-healthcare-data-breaches-violate-hipaa-rules?&web%5Fview=true) in the US _agreed to pay $ 1 million to the US Department of Health and Human Services for its 2017 data breach_ of nearly 5002 individual data, which consists of name, insurance-related data, and PHI (Protected Health Information). Furthermore, approximately **11,000 people were affected** due to the second breach in July 2017, which compromised medical details, and in September 2017, nearly 1,600 user details were further compromised.

In addition to human errors, the company failed to periodically evaluate PHI, which made the cyber intrusion easier for malicious actors. Moreover, the business could not implement the necessary technical, administrative, and physical cybersecurity measures to ensure PHI privacy.

## Cybernews Uncovered 39 Scam Sites Related To Paypal-UPS Scam

On April 1, 2020, Isabelle Taylor fell victim to an e-commerce-based nutrition company gardenoflifego.com _which sold products at a huge discount but provided its user fake or already delivered product tracking identifiers and stole money from their PayPal account_. Despite complaining to PayPal about the same, there were no actions taken against the entity, nor were there any refunds.

[![email security services](https://media.mailhop.org/duocircle/images/2020/11/DMARC-generator-8563.jpg)](https://media.mailhop.org/duocircle/images/2020/11/DMARC-generator-8563.jpg)

When [CyberNews](https://cybernews.com/security/paypal-ups-scam-retiree-wins-back-money-uncovers-scam-network/?web%5Fview=true) contacted PayPal regarding the same, the victim got a goodwill refund, 37 similar scam websites linked to the domain from which Garden of Life operated were also discovered. Even though the website has now been removed, _CyberNews further found 17 other sites linked to a scam_ email id [support@vitmaincheapest.com](mailto:support@vitmaincheapest.com) and other [email security services](/), and altogether, **39 websites were uncovered**.

## Russian Based APT Turla Hacked Into Undisclosed European Governmental Systems

According to the [Accenture Cyber Threat Intelligence](https://securityaffairs.co/wordpress/110127/apt/turla-target-eu-gov-org.html?web%5Fview=true) or ACTI, APT Turla, a notorious Russian-based hacker group, compromised European Governmental systems using RPC (Remote Procedure Call) based backdoors and RAT (Remote Administration Trojans). The Turla APT group has been active since 2007\. It is notorious for attacking diplomats, private businesses, and governmental institutions in the Middle East, North and South America, Soviet unions, Europe, and Asia. The group has previously attacked Swiss defense wing RUAG, US Central Command, and the US Department of State as well.

_ACTI has identified that Turla has used Command and Control (C&C) executions for each cyberattack_ and also that the group relied on bot-compromised web servers. Moreover, Turla APT has used a Carbon installer with **encrypted configuration files**, two communication modules, and a Carbon Orchestrator.

## Canadian Home Depot users Receive Hundreds of Suspicious Notifications

On October 28, 2020, [Home Depot customers](https://www.bleepingcomputer.com/news/security/home-depot-blunder-emails-customer-order-info-to-strangers/?&web%5Fview=true) in Canada started receiving hundreds of order related and shipment related emails from the company. The order details specified in the emails were not linked to the receiver. _Customers have received hundreds of such emails containing order details_, customer names, addresses, partial card information, order numbers, and order items.

The emails contained orders from October 24th and 25th for in-store pickups, and these emails were generated as remainders for pickups. Since each email can have up to **544 email accounts** in the _to_ address, various users received the same email at an instant. Also, the reply to the section contained multiple emails along with the Home Depot email ID and thus flooded users’ mailboxes.

## Researchers Found Vulnerability In Hormann Devices

_Researchers of an Austria based cybersecurity firm SEC Consult found nearly **15 vulnerabilities** in gateway device and mobile application of_ _Hormann_, a German company that manufactures industrial and home doors. The vulnerabilities, especially poor communication protocols and _less secure encryption techniques_, can be exploited remotely using a local network or through the internet and can even break **email security**.

The remote malicious actors use client certificates and private keys to tamper with the door opening hardware utilizing the internet and use the key to connect with the vendor’s server. They can then upload scripts into the server, which will further switch the target node’s identity with the attacker’s system due to Hormann devices’ failure to ensure the validity of certificates.

And that’s the week that was.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2020%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2044%20of%202020&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2020%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2020%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Spam](https://media.mailhop.org/duocircle/images/2016/05/spf-permerror-3256.jpg)  April Spam Filtering Uptime Report News ](/blog/announcements/april-spam-filtering-uptime-report/)
- [ ![Spam Filtering](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-7226.jpg)  Changes to Spam Filtering Technology News ](/blog/announcements/changes-to-spam-filtering-technology/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2020/01/spf-permerror-7312.jpg)  Cyber Security News Update, Week 1 of 2020 News ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 1m  April Spam Filtering Uptime Report  May 4, 2016 ](/blog/announcements/april-spam-filtering-uptime-report/)[  News 2m  Changes to Spam Filtering Technology  Feb 8, 2023 ](/blog/announcements/changes-to-spam-filtering-technology/)[  News 4m  Cyber Security News Update, Week 1 of 2020  Jan 3, 2020 ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 44 of 2020","description":"While on the one hand, the advent of newer technologies is a boon for us all; on the other, it also gives cyber adversaries the upper hand many times.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2020/","datePublished":"2020-11-02T17:56:13.000Z","dateModified":"2025-05-27T11:10:15.000Z","dateCreated":"2020-11-02T17:56:13.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2020/"},"articleSection":"announcements","keywords":"","wordCount":841,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2020/11/spf-record-2738.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 44 of 2020","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2020/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 44 of 2020","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2020/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 44 of 2020","description":"While on the one hand, the advent of newer technologies is a boon for us all; on the other, it also gives cyber adversaries the upper hand many times.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2020/","datePublished":"2020-11-02T17:56:13.000Z","dateModified":"2025-05-27T11:10:15.000Z","dateCreated":"2020-11-02T17:56:13.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2020/"},"articleSection":"announcements","keywords":"","wordCount":841,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2020/11/spf-record-2738.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
