---
title: "Canadian Device Restrictions, US Targets Ryuk, FBI: Casinos Targeted, Cybersecurity News [November 06, 2023] | DuoCircle"
description: "The week has been full of cybersecurity news that continues to shake the cyber world as usual."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-45-of-2023/"
---

Quick Answer

Four items shaped the week of November 6, 2023\. Canada banned WeChat and Kaspersky products from federal government devices, citing unacceptable levels of risk to privacy and security following a review by the Chief Information Officer of Canada. The US Treasury sanctioned a Russian national accused of laundering hundreds of millions of dollars in ransomware proceeds, including payments to the Ryuk crew. The FBI alerted the casino industry that ransomware operators including Scattered Spider were breaching gaming companies through their third-party gaming partners and IT support staff. McLaren Health Care confirmed that an August ransomware attack exposed personal and medical data of approximately 2.2 million patients across its Michigan hospital network.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Canadian%20Device%20Restrictions%2C%20US%20Targets%20Ryuk%2C%20FBI%3A%20Casinos%20Targeted%2C%20Cybersecurity%20News%20%5BNovember%2006%2C%202023%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2023%2F&title=Canadian%20Device%20Restrictions%2C%20US%20Targets%20Ryuk%2C%20FBI%3A%20Casinos%20Targeted%2C%20Cybersecurity%20News%20%5BNovember%2006%2C%202023%5D "Share on Reddit") [ ](mailto:?subject=Canadian%20Device%20Restrictions%2C%20US%20Targets%20Ryuk%2C%20FBI%3A%20Casinos%20Targeted%2C%20Cybersecurity%20News%20%5BNovember%2006%2C%202023%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/11/dmarc-report-service.jpg) 

The week has been full of cybersecurity news that continues to shake the cyber world as usual. Here’s our latest [cybersecurity](/) news piece sharing the **latest developments** to help you keep a step ahead of threat actors.

## Canada Says No to WeChat and Kaspersky on Government Devices

Canada has [banned](https://www.canada.ca/en/treasury-board-secretariat/news/2023/10/minister-anand-announces-a-ban-on-the-use-of-wechat-and-kaspersky-suite-of-applications-on-government-mobile-devices.html) the use of Kaspersky security products and Tencent’s WeChat app on **mobile devices** that are used by its government.

The country has taken this step as the officials believe that these applications **share sensitive information** with Russia and China. Smartphones and tablets are routinely moved in and out of workspaces. This poses a challenge for the effective monitoring of [covert data siphoning](https://www.dailymail.co.uk/news/article-12421565/Joe-Rogan-warns-China-infiltrating-universities-siphon-data-information-students-caught-happens.html).

> The President of the Treasury Board, Anita Anand, spoke about the ban as well. She explained, “The Chief Information Officer of Canada determined that WeChat and Kaspersky suite of applications present an unacceptable level of **risk to privacy and security**.”

The ban took effect on 30 October 2023, requiring the removal of this software from government-issued mobile devices by that date. The government has also put extra [phishing protection](/email/phishing-protection) measures in place. _The measures will block the download of these applications to **prevent reinstallation** on the devices._

Kaspersky broke the silence, outlining that Canada’s decision lacks consultation on alleged security concerns. Furthermore, the organization says that the decision focuses more on **geopolitical considerations** and not on a proper technical evaluation.

## U.S. Puts the Squeeze on Russian Linked to Money Laundering for Ryuk Ransomware

Ekaterina Zhdanova, a Russian national, has been **officially sanctioned** by the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC).

[![Ransomware](https://media.mailhop.org/duocircle/images/2023/11/dmarc-report-1-1.jpg)](https://media.mailhop.org/duocircle/images/2023/11/dmarc-report-1-1.jpg)

This was a response to Zhdanova’s involvement in [laundering millions in cryptocurrency](https://cybersecuritynews.com/cryptocurrency-mixin-network/) for various people, including actors linked to ransomware activities. Zhdanova used her expertise in cryptocurrency and [blockchain networks](/email-security/tradertraitor-targeted-attack-on-blockchain-organizations/) to navigate through platforms like **Garante**. Chainalysis shared a [report](https://www.chainalysis.com/blog/ofac-russia-crypto-money-laundering-sanctions-2023/) shedding light on Zhdanova’s public businesses, which are potentially connected to her money laundering schemes.

Both OFAC and Chainalysis emphasize her utilization of a global network of money launderers to complicate her financial activities. The reported activities of Zhdanova extend to her alleged involvement in laundering over $2.3 million in ransom payments for an affiliate of the [Ryuk ransomware operation](https://thehackernews.com/2023/02/russian-hacker-pleads-guilty-to-money.html). The Ryuk gang was active from 2018 to 2021 and targeted various sectors.

_Authorities have also verified cases where Zhdanova arranged for **Russian clients** to obtain UAE tax residency, I.D. cards, and bank accounts._ As a result, all U.S.-based assets belonging to Ekaterina Zhdanova will be frozen, and U.S. persons and entities will be prohibited from engaging in any transactions with her.

## FBI Reveals: Ransomware Crews Target Casinos Through Third-Party Gaming Partners

The Federal Bureau of Investigation (FBI) shared an [advisory](https://www.ic3.gov/Media/News/2023/231108.pdf) highlighting the escalating threat of [ransomware actors](https://thehackernews.com/2023/11/new-ransomware-group-emerges-with-hives.html) **targeting casino servers**.

The FBI has outlined that these threat actors employ legitimate system management tools. They use the tools to escalate their permissions on the network, posing a significant risk. The FBI shared that third-party vendors and services are a prevalent attack vector in these cases. The agency pointed out new trends in which ransomware actors exploit [vulnerabilities](/phishing-protection/microsoft-uncovers-high-severity-android-vulnerabilities/) in **vendor-controlled remote access** to casino servers.

Since the beginning of 2022, the FBI has observed ransomware attacks specifically targeting small and tribal casinos, encrypting servers, and compromising Personally Identifiable Information (PII) of both employees and patrons. The ransomware gang behind these attacks is **Luna Moth/SRG**. The threat actor gang [focuses on data extortion](https://www.crn.com/news/security/as-ransomware-gangs-shift-to-data-extortion-some-adopt-a-new-tactic-customer-service-) without encrypting the files. Previous reports have highlighted **fake subscription renewal** lures associated with their [email phishing](/phishing-protection/how-to-prevent-phishing-and-spoofing/) tactics.

The FBI recommends maintaining encrypted and immutable **offline backups** for the organizational data infrastructure, implementing [policies for remote access](https://www.linkedin.com/advice/0/what-best-policies-remote-access-troubleshooting#:~:text=Before%20you%20initiate%20a%20remote,protect%20their%20data%20and%20privacy.), and allowing only known and trusted applications to stay safe.

## McLaren Health Care Reveals Data Breach Affecting 2.2 Million Individuals

[![data breach](https://media.mailhop.org/duocircle/images/2023/11/hosted-email-server-5963.jpg)](https://media.mailhop.org/duocircle/images/2023/11/hosted-email-server-5963.jpg)

McLaren Health Care (McLaren) has revealed a [significant data breach](https://www.entrepreneur.com/business-news/maine-hacked-in-data-breach-13-million-residents-at-risk/465304) that occurred between late July and August this year, impacting almost 2.2 million individuals.

_The breach was detected on 22 August 2023 and prompted McLaren to launch investigations with the assistance of external cybersecurity experts._ The findings indicated that unauthorized access had been ongoing since 28 July 2023\. The **compromised data** includes a range of [sensitive information](https://www.infosecurity-magazine.com/news/manchester-police-data-breached/), including full names, Social Security numbers (SSN), health insurance details, dates of birth, billing or claims information, diagnoses, physician details, medical record numbers, Medicare/Medicaid information, prescription/medication specifics, and diagnostic results and treatment information.

McLaren has already begun notifying affected individuals via email. The notification includes detailed instructions on enrolling in **identity protection services** for a year, emphasizing the importance of utilizing [advanced threat defense](/advanced-threat-defense) to safeguard personal information.

While there is currently no evidence of misuse, McLaren advises that affected individuals should exercise caution with [unsolicited communications](https://backendnews.net/pldt-smart-warn-against-fake-bank-e-wallet-advisories/) and **maintain a close eye** on their bank account activity.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=Canadian%20Device%20Restrictions%2C%20US%20Targets%20Ryuk%2C%20FBI%3A%20Casinos%20Targeted%2C%20Cybersecurity%20News%20%5BNovember%2006%2C%202023%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-45-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Canadian Device Restrictions, US Targets Ryuk, FBI: Casinos Targeted, Cybersecurity News [November 06, 2023]","description":"The week has been full of cybersecurity news that continues to shake the cyber world as usual.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-45-of-2023/","datePublished":"2023-11-14T15:43:00.000Z","dateModified":"2025-05-14T15:17:45.000Z","dateCreated":"2023-11-14T15:43:00.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-45-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":789,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/11/dmarc-report-service.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Canadian Device Restrictions, US Targets Ryuk, FBI: Casinos Targeted, Cybersecurity News [November 06, 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-45-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Canadian Device Restrictions, US Targets Ryuk, FBI: Casinos Targeted, Cybersecurity News [November 06, 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-45-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Canadian Device Restrictions, US Targets Ryuk, FBI: Casinos Targeted, Cybersecurity News [November 06, 2023]","description":"The week has been full of cybersecurity news that continues to shake the cyber world as usual.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-45-of-2023/","datePublished":"2023-11-14T15:43:00.000Z","dateModified":"2025-05-14T15:17:45.000Z","dateCreated":"2023-11-14T15:43:00.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-45-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":789,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/11/dmarc-report-service.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
