logo

Enzo Biochem ordered to cough up $4.5 million over lousy security that led to ransomware disaster

ID: 458eda17-7f9d-5cb5-96a4-1f05e778f2e4

STIX ID: report--458eda17-7f9d-5cb5-96a4-1f05e778f2e4

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2024-08-14

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Enzo Biochem suffered a 2023 ransomware intrusion that compromised the personal and health data of over 2.4 million individuals; state investigations found shared and decade-old credentials used for initial access, no enforced MFA, unencrypted sensitive data on some servers and desktops, and manual-only network monitoring that delayed detection. The company was fined $4.5M by New York, New Jersey, and Connecticut and ordered to implement a 15-point security remediation plan (including EDR, 24/7 SOC, MFA enforcement, enterprise storage migration, and Zero Trust controls).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.