---
title: "Hyundai Europe Cyberattack, US Offers Bounty, Google’s Redesigned Interfaces, Cybersecurity News  [February 05, 2024] | DuoCircle"
description: "Hyundai Europe Cyberattack, US Offers Bounty, Google’s Redesigned Interfaces, Cybersecurity News [February 05."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2024/"
---

Quick Answer

Week 7, 2024 cyber news: Black Basta ransomware hits Hyundai Motor Europe, exfiltrating 3 TB across legal, sales, HR, accounting, and IT folders; US State Department offers up to $10M for information on Hive ransomware leadership after the FBI seized servers and distributed 1,300 decryption keys; Google previews refreshed Material Design sign-in pages including Gmail; Dutch MIVD discloses Coathanger RAT planted by Chinese actors on FortiGate appliances via CVE-2022-42475 (persists across reboots); US imposes visa restrictions on individuals tied to commercial spyware vendors including Intellexa SA, Intellexa Limited, and Cytrox.

Hyundai Europe Cyberattack, US Offers Bounty, Google’s Redesigned Interfaces, Cybersecurity News \[February 05, 2024\]

Your browser does not support the audio element.

[ Download episode](https://media.mailhop.org/duocircle/images/2024/02/Hyundai-Europe-Cyberattack-US-Offers-Bounty-Goog.mp3) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2024%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Hyundai%20Europe%20Cyberattack%2C%20US%20Offers%20Bounty%2C%20Google%E2%80%99s%20Redesigned%20Interfaces%2C%20Cybersecurity%20News%20%20%5BFebruary%2005%2C%202024%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2024%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2024%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2024%2F&title=Hyundai%20Europe%20Cyberattack%2C%20US%20Offers%20Bounty%2C%20Google%E2%80%99s%20Redesigned%20Interfaces%2C%20Cybersecurity%20News%20%20%5BFebruary%2005%2C%202024%5D "Share on Reddit") [ ](mailto:?subject=Hyundai%20Europe%20Cyberattack%2C%20US%20Offers%20Bounty%2C%20Google%E2%80%99s%20Redesigned%20Interfaces%2C%20Cybersecurity%20News%20%20%5BFebruary%2005%2C%202024%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2024%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2024/02/spf-flattening.jpg) 

From ransomware attacks on Hyundai Motor Europe to the US cracking down on spyware and **denying visas**, it’s been a busy week in tech news. Here we are with the latest scoops in [cybersecurity](/), sharing details of the above, along with the Chinese cyber attack on Dutch military networks, the US offering rewards for information on the Hive ransomware gang, and Google teasing a new sign-in page. Let’s get into them.

## Hyundai Motor Europe Targeted in Black Basta Ransomware Incident

Hyundai Motor Europe was the victim of a Black Basta ransomware attack where the [threat actors](https://www.darkreading.com/ics-ot-security/super-bowl-lviii-vast-attack-surface-threat-actors) made away with **3 TB of corporate data**.

Hyundai Motors began **experiencing** **IT issues** in early January, which were due to unauthorized third-party access in their networks. The [organization](https://www.bleepingcomputer.com/news/security/hyundai-motor-europe-hit-by-black-basta-ransomware-attack/?&web%5Fview=true) did not share any details of the attack at that time but did say that trust and security were fundamental to their business. It was discovered later when threat actors shared the news that they claimed to have stolen 3 TB of data from Hyundai Europe.

[![phishing prevention](https://media.mailhop.org/duocircle/images/2024/02/spf-record-6492.jpg)](https://media.mailhop.org/duocircle/images/2024/02/spf-record-6492.jpg)

_The sample shared by the threat actors had folder names related to many departments, legal, sales, HR, accounting, management, and IT._ The ransomware gang behind the attack, Black Basta, launched its operation in April 2022 with [double-extortion attacks](https://www.techtarget.com/searchsecurity/definition/double-extortion-ransomware#:~:text=Double%20extortion%20ransomware%20is%20a,the%20victim's%20data%20as%20well.). It’s considered an offshoot of the Conti ransomware operations and has been behind attacks against the Toronto library, Capita, Sobeys, Knauf, Yellow Pages Canada, and many more. The pressing demand for [phishing prevention](/content/phishing-prevention) solutions in businesses is evident from this news.

Hyundai suffered another attack a while back when [the X (Twitter) account of Hyundai MEA was hacked](https://thecyberexpress.com/netgear-and-hyundai-mea-twitter-account-hacked/) to promote **crypto wallet drainer sites**.

## US Pledges $10 Million Reward for Information on Hive Ransomware Leaders

The US State Department is offering rewards of up to $10 million to anyone who can **share information** that helps them locate, identify, or arrest members of the [Hive ransomware gang](https://www.bbc.com/news/technology-64418723).

The FBI highlighted how the threat actor group has extorted over $100 million from over 1300 organizations. The State Department is offering rewards for information that can help link Hive and other ransomware threat groups **with foreign nations**. Since 1986, the [TOCRP (Transnational Organized Crime Rewards Program)](https://www.state.gov/transnational-organized-crime-rewards-program-2/#:~:text=Since%202013%2C%20the%20Transnational%20Organized,lives%20and%20U.S.%20national%20security.) has paid $135 million to people who have helped law enforcement bag threat actors.

This new offer came after the operation where the **FBI seized Tor websites** operated by Hive ransomware. It was a joint operation where the FBI infiltrated Hive servers and monitored the gang’s activity for 6 months, [extracting and distributing 1300 decryption keys to the gang’s victims](https://www.bbc.com/news/technology-64418723). The FBI also discovered communication records, [malware file hashes](https://www.malwarepatrol.net/malware-hashes-and-hash-functions/), and information on nearly 250 affiliates of the gang.

The **State Department** will also offer $5 million for information about individuals who are conspiring to participate in or join the Hive ransomware gang.

## Google Reveals Upcoming Refreshed Design for Sign-In Interfaces, Gmail Included

Google is about to change sign-in pages for the better with a **modern makeover**.

If you visit the login screen of any Google service, you’ll see a pop-up that hints at a new sign-in screen. The [message](https://www.bleepingcomputer.com/news/google/google-teases-a-new-modern-look-for-sign-in-pages-including-gmail/) reads, “A new look is coming soon. Google is improving its sign-in page with a more modern look and feel.” Google has been releasing many Material Design updates recently, the last one being [the new style icons that the Chrome browser got in November](https://tech.hindustantimes.com/tech/news/google-chrome-begins-rolling-out-material-you-redesign-to-users-know-what-is-changing-71699683547350.html). These new icons are distinct and **boost legibility**. The new update is expected to continue the minimalistic approach followed by Google’s Material Design principles and will likely create a better and more user-friendly approach during the login process.

Google has **always prioritized security,** and the new update will still come with top-of-the-line security. What look the update will bring to the [Google Suite](/email-hosting/g-suite-measures-enterprise/) remains to be seen.

## Dutch Military Network Compromised by Chinese Cybercriminals Using Malware

A **Chinese cyber-espionage group** got into the Dutch Ministry of Defence and deployed [malware](/data-privacy/new-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users/) on many devices.

[![malware trends](https://media.mailhop.org/duocircle/images/2024/02/spf-validator-1.jpg)](https://media.mailhop.org/duocircle/images/2024/02/spf-validator-1.jpg)

The MIVD (Military Intelligence and Security Service) of the Netherlands shared the news of the attack and also outlined that the [threat actors made attempts to backdoor the hacked systems](https://gbhackers.com/apt-hackers-using-falsefont-backdoor/), but the damage of the **breach was limited** as the network was segmented. The network had 50 users who carried out R&D of unclassified projects and were notified.

The malware strain used was Coathanger, a RAT (Remote Access Trojan) that infects FortiGate network security appliances. Coathanger is a persistent threat that recovers after the system reboots as well. _Even fully patched FortiGate devices were breached, which shows how serious the threat is._ The Chinese hackers use the malware exploiting the CVE-2022-42475 **FortiOS SSL-VPN vulnerability** to compromise firewalls. The same vulnerability has also been used in [zero-day attacks](/cloud-email/protecting-email-in-the-cloud-challenges-and-solutions/) against many government organizations before.

This is the first time that the MIVD has [shared](https://www.ncsc.nl/documenten/publicaties/2024/februari/6/mivd-aivd-advisory-coathanger-tlp-clear) a **technical report** for the public that outlines the working methods. The significance of this news underscores the immediate requirement for businesses to invest in [Advanced Threat Defense](/advanced-threat-defense).

## US Implements Visa Restrictions for Individuals Associated with Commercial Spyware

Anthony J. Blinken, the Secretary of State, made a new announcement about a visa restriction policy that will allow the State Department to **ban people** linked to [commercial spyware](https://blog.talosintelligence.com/what-is-commercial-spyware/) from entering the US.

The new policy will restrict entry of such individuals instead of arbitrary detentions or forced disappearances that were employed before. The Biden Administration also issued an [Executive Order](https://web.archive.org/web/20250120155519/https://www.whitehouse.gov/briefing-room/presidential-actions/2023/03/27/executive-order-on-prohibition-on-use-by-the-united-states-government-of-commercial-spyware-that-poses-risks-to-national-security/) that prohibits the US government from using **mercenary tools** for surveillance that may pose risks to foreign policies or national security. From now on, the US can deny visas to individuals linked to spyware in 3 areas:

- If they use it **directly to target activists**, journalists, or other vulnerable groups.
- If they help develop, sell, or profit from organizations behind the spyware, especially if it’s being sold to countries with a **history of human rights abuses**.
- If they are **close family members** of individuals who fall into the first two categories.

The US State Department also thinks organizations like Intellexa SA from Greece, Intellexa Limited from Ireland, Cytrox Holdings Zrt from Hungary, and Cytrox AD from North Macedonia made spyware that’s being **used around the world** to bully opponents, silence critics, and [spy on journalists](https://www.mediadefence.org/news/spyware-against-journalists/).

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2024%2F) [ ](https://twitter.com/intent/tweet?text=Hyundai%20Europe%20Cyberattack%2C%20US%20Offers%20Bounty%2C%20Google%E2%80%99s%20Redesigned%20Interfaces%2C%20Cybersecurity%20News%20%20%5BFebruary%2005%2C%202024%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2024%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2024%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Hyundai Europe Cyberattack, US Offers Bounty, Google’s Redesigned Interfaces, Cybersecurity News  [February 05, 2024]","description":"Hyundai Europe Cyberattack, US Offers Bounty, Google’s Redesigned Interfaces, Cybersecurity News [February 05.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2024/","datePublished":"2024-02-12T15:27:11.000Z","dateModified":"2025-04-28T11:30:12.000Z","dateCreated":"2024-02-12T15:27:11.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2024/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1043,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/02/spf-flattening.jpg","caption":"cybersecurity","width":900,"height":507},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Hyundai Europe Cyberattack, US Offers Bounty, Google’s Redesigned Interfaces, Cybersecurity News  [February 05, 2024]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2024/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Hyundai Europe Cyberattack, US Offers Bounty, Google’s Redesigned Interfaces, Cybersecurity News  [February 05, 2024]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2024/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Hyundai Europe Cyberattack, US Offers Bounty, Google’s Redesigned Interfaces, Cybersecurity News  [February 05, 2024]","description":"Hyundai Europe Cyberattack, US Offers Bounty, Google’s Redesigned Interfaces, Cybersecurity News [February 05.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2024/","datePublished":"2024-02-12T15:27:11.000Z","dateModified":"2025-04-28T11:30:12.000Z","dateCreated":"2024-02-12T15:27:11.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2024/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1043,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/02/spf-flattening.jpg","caption":"cybersecurity","width":900,"height":507},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
