---
title: "Kansas Cyberattack Investigation, Lab Data Breach, Defender Bounty Program, Cybersecurity News  [November 20, 2023] | DuoCircle"
description: "The week was full of thrilling and chilling cybersecurity news and updates."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-47-of-2023/"
---

Quick Answer

Four items shaped the week of November 20, 2023\. The Kansas judicial branch confirmed that the October cyberattack which took its court network offline involved data theft and a ransom demand by an unnamed group, with personal information of court users exposed. Idaho National Laboratory, a US nuclear research facility, disclosed that the SiegedSec hacktivist group breached an HR system and leaked employee data including names, addresses, and Social Security numbers. Microsoft launched the Defender Bounty Program, offering rewards up to $20,000 for vulnerabilities in Microsoft Defender products. A Discord-based phishing wave followed the takeover of Bloomberg Crypto's account on X, where attackers promoted a fake airdrop link that drained victim wallets after wallet-connect approvals.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-47-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Kansas%20Cyberattack%20Investigation%2C%20Lab%20Data%20Breach%2C%20Defender%20Bounty%20Program%2C%20Cybersecurity%20News%20%20%5BNovember%2020%2C%202023%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-47-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-47-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-47-of-2023%2F&title=Kansas%20Cyberattack%20Investigation%2C%20Lab%20Data%20Breach%2C%20Defender%20Bounty%20Program%2C%20Cybersecurity%20News%20%20%5BNovember%2020%2C%202023%5D "Share on Reddit") [ ](mailto:?subject=Kansas%20Cyberattack%20Investigation%2C%20Lab%20Data%20Breach%2C%20Defender%20Bounty%20Program%2C%20Cybersecurity%20News%20%20%5BNovember%2020%2C%202023%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-47-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/11/what-is-dkim-selector.jpg) 

The week was full of **thrilling and chilling** cybersecurity news and updates. From ransomware hitting Kansas Courts to Bloomberg Crypto phishing campaign, here’s the scoop on the latest in [cybersecurity](/) this week.

## Kansas Courts Verify Data Theft and Ransom Demand Following Cyberattack

The Judicial Branch of Kansas [shared](https://web.archive.org/web/20240222071534/https://www.kscourts.org/Newsroom/News-Releases/News/2023-News-Releases/November-2023/Kansas-Supreme-Court-releases-statement-on-October) an update on the **cybersecurity attack** that the organization suffered last month.

Kansas Courts confirmed that the threat actors made away with sensitive files containing confidential information. The security incident took place in mid-October 2023, when multiple systems of the organization were impacted, including its **eFiling system** used for submission of documents, electronic payments, and case management systems.

The system has not changed, but many of the portals remain offline. The Kansas Judicial Branch newsroom posted an update explaining that the impact on said systems is temporary and also **confirmed news** of a [data breach](https://edition.cnn.com/2023/03/08/politics/data-breach-us-lawmakers/index.html).

The report outlined that the stolen information included files from the Office of Judicial Administration and district court case records, among other data. The attack exhibits core elements of [ransomware](/data-privacy/8-most-nefarious-ransomware-attacks-from-2017-to-mid-2023/) since the system **outage was caused by file encryptions**. However, the authorities have not specified it directly in the press release.

No ransomware gangs have taken responsibility for the attack as of now. _Kansas Courts eFiling, Order Portal, District Court Public Access, Case Inquiry System, eCourt Case Management, Attorney Registration, online marriage license application, and central payment center **remain offline**._

## U.S. Nuclear Research Lab Breached by Hacktivists, Employee Data Stolen

The Idaho National Laboratory (INL) confirmed that the organization was the victim of a [cyberattack](/phishing-protection/protecting-retail-businesses-from-cyber-attacks/). The [news](https://www.eastidahonews.com/2023/11/idaho-national-laboratory-experiences-massive-data-breach-employee-information-leaked-online/) came after hacktivists “SiegedSec” **leaked stolen H.R. data online**.

**INL** falls under the U.S. Department of Energy and employs nearly 5,700 specialists in nuclear and integrated energy. The INL focuses on research and development of [next-generation nuclear plants](https://en.wikipedia.org/wiki/Next%5FGeneration%5FNuclear%5FPlant), water reactors, advanced vehicles, bioenergy, robotics, and similar studies.

[The hacktivist gang SiegedSec](https://www.msspalert.com/news/siegedsec-hacktivists-claim-to-have-stolen-3000-nato-files-in-second-attack) later shared that they had gained access to INL data. They highlighted that said data also contained information of “hundreds of thousands” of citizens and users. _Just like the previous NATO and Atlassian breaches, the threat actors **leaked the stolen data** on hacker forums without any ransom demands._

Furthermore, they [posted proof of the breach via screenshots](https://www.cyberdaily.au/security/9832-medusa-ransomware-gang-claims-data-breach-of-toyota-financial-services-in-germany) on their **Telegram channel**. INL has not made any public statements, but a spokesperson confirmed the news to media outlets, sharing that law enforcement agencies are involved.

The full names, birth dates, emails, phone numbers, Social Security Numbers (SSNs), employment, and [residential information of thousands have been leaked](https://www.popsci.com/technology/us-patent-office-data-leak/).

[![cyberattack](https://media.mailhop.org/duocircle/images/2023/11/spf-record-7481.jpg)](https://media.mailhop.org/duocircle/images/2023/11/spf-record-7481.jpg)

## Microsoft’s New Defender Bounty Program, Offering $20,000 in Rewards

Microsoft has [launched](https://msrc.microsoft.com/blog/2023/11/introducing-the-microsoft-defender-bounty-program/) a new **bug bounty initiative** for its Defender platform.

_People who identify and report new flaws can receive rewards ranging from $500 to $20,000._ You should know that these rewards may exceed $20,000\. The final amount will be determined by Microsoft based on factors like the **flaw’s severity, impact, and the quality** of the submission.

As of now, the Microsoft Defender Bounty Program will only focus on [Defender for Endpoint Application Programming Interfaces (APIs)](https://arnav.au/2023/05/25/microsoft-defender-for-apis-in-defender-for-cloud/) but will expand to other products with time. The bounties will be awarded for **initial submissions** if multiple individuals file multiple bug reports on the same issue.

Microsoft has paid nearly $58.9 million in [bug bounty programs](/bug-bounty-program) to 1147 security experts around the world who reported 446 vulnerabilities. The organization also announced an AI bounty program last month that focuses on its **AI-driven Bing search** and offers rewards of up to $15000\. 

## Discord Phishing Attacks as a Result of Bloomberg Crypto X Account Mishap

Bloomberg’s Official Crypto Twitter account was used earlier this week to post a [phishing link redirecting victims](https://latesthackingnews.com/2023/10/07/evilproxy-phishing-targets-microsoft-365-accounts-via-indeed-com-redirects/) to a website that **stole Discord credentials**.

ZachXBT, a crypto fraud investigator, [spotted](https://twitter.com/zachxbt/status/1725632760012828897) the [phishing attack](/email-security/the-threat-of-phishing-email-attack-is-serious/) and shared all the details. The link was to a Telegram channel with over 14,000 members that pushed all visitors to a **fake Bloomberg Discord server** that showed 33,968 members. Bloomberg had a Telegram channel, @BloombergNewsCrypto, which was updated to @BloombergCrypto in [October 2023](https://twitter.com/crypto/status/1708923011795988495).

However, a scam artist was able to **seize the old username** during the transition and use it as a part of an elaborate [phishing campaign](https://www.scmagazine.com/news/credential-phishing-campaign-using-linkedin-smart-links-resurfaces). Once a victim clicked on the link, they were redirected to a fake Discord server where a bot prompted them to use **AltDentifier**, which is a genuine Discord bot, for verification.

[![cryptoscam](https://media.mailhop.org/duocircle/images/2023/11/email-migration-service-1.jpg)](https://media.mailhop.org/duocircle/images/2023/11/email-migration-service-1.jpg)

However, it presented a [link to a deceptive page to an altered domain](https://www.usatoday.com/story/news/factcheck/2021/04/30/fact-check-hackers-use-similar-looking-characters-phishing-schemes/4891437001/) “altidentifiers{.}com” instead of the authentic “altidentifier.com.” The users were given **30 minutes to visit this link** and complete the verification process, where they were required to verify with Discord.

Upon verification, the users were allowed to participate in the server, but their Discord **credentials were stolen**. Bloomberg has not shared any official statement regarding the incident that took place.

This incident underlines the significance of **staying informed** about the latest approaches to phishing and underscores the crucial role of [phishing awareness training](/phishing-awareness-training). The training also includes the key aspect of [phishing protection](/email/phishing-protection) which is essential to defend against these [security threats](https://www.crn.com/news/security/10-emerging-cybersecurity-threats-and-hacker-tactics-in-2023/1).

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-47-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=Kansas%20Cyberattack%20Investigation%2C%20Lab%20Data%20Breach%2C%20Defender%20Bounty%20Program%2C%20Cybersecurity%20News%20%20%5BNovember%2020%2C%202023%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-47-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-47-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Kansas Cyberattack Investigation, Lab Data Breach, Defender Bounty Program, Cybersecurity News  [November 20, 2023]","description":"The week was full of thrilling and chilling cybersecurity news and updates.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-47-of-2023/","datePublished":"2023-11-27T15:57:30.000Z","dateModified":"2025-05-15T11:18:30.000Z","dateCreated":"2023-11-27T15:57:30.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-47-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":833,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/11/what-is-dkim-selector.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Kansas Cyberattack Investigation, Lab Data Breach, Defender Bounty Program, Cybersecurity News  [November 20, 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-47-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Kansas Cyberattack Investigation, Lab Data Breach, Defender Bounty Program, Cybersecurity News  [November 20, 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-47-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Kansas Cyberattack Investigation, Lab Data Breach, Defender Bounty Program, Cybersecurity News  [November 20, 2023]","description":"The week was full of thrilling and chilling cybersecurity news and updates.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-47-of-2023/","datePublished":"2023-11-27T15:57:30.000Z","dateModified":"2025-05-15T11:18:30.000Z","dateCreated":"2023-11-27T15:57:30.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-47-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":833,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/11/what-is-dkim-selector.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
