Data Breach at WorkForce West Virginia

Data Breach at WorkForce West Virginia

Personal information belonging to job seekers residing in the Mountain State may have been exposed during a security incident at WorkForce West Virginia.

The breach was confirmed yesterday by West Virginia governor Jim Justice, who addressed the incident during a press conference held earlier today. 

WorkForce has begun sending notification letters to individuals whose personal data was compromised. The letters state that WorkForce learned on April 13 that an unauthorized individual had accessed a job-seekers database.

The unknown cyber-criminal may have gained access to the database via the Mid-Atlantic Career Consortium Employment Services database, or MACC website. West Virginians use the MACC to register for job services before applying for unemployment benefits.

“Upon discovery, immediate steps were taken to secure the network, and WorkForce immediately began an investigation,” states the letter.

“An experienced computer forensic firm was hired to help determine what happened and what information may have been accessed,” it continues.

MACC remained offline for 45 days while investigators probed the incident. In May, they concluded that job seekers’ personal information could have been exposed. 

Data compromised in the incident may have included names, addresses, phone numbers, dates of birth and Social Security numbers.

“The security incident was investigated,” said WorkForce. “The risk was assessed, and the agency engaged a professional third-party forensic firm to manage ongoing risk mitigation.”

While sensitive data may have been accessed, WorkForce said that no files were downloaded, exfiltrated or altered. The agency has made improvements to its cybersecurity that include switching to a different software in the hope of preventing any similar incidents from occurring. 

“Mitigating any potential risk for constituents continues to be our top priority,” said WorkForce West Virginia commissioner Scott Adkins.

“Constituents should follow the guidance provided in the letter they received from WorkForce if they have any questions.”

The agency is offering those impacted by the data breach a year’s worth of credit report monitoring and $1m in fraud loss reimbursement, fraud consultation and identity theft restoration.

WorkForce did not state how many West Virginians may have been impacted by the incident.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Linguist Jailed for Sharing US Defense Secrets

Linguist Jailed for Sharing US Defense Secrets

A linguist employed by the US Department of Defense has been sent to prison for more than two decades for leaking the identities of American spies to a lover with ties to a foreign terrorist organization.

Mariam Taha Thompson was charged in March 2020 with sharing highly sensitive classified national defense information with a Lebanese national connected to Hizballah. 

A year later, the 62-year-old former resident of Rochester, Minnesota, pleaded guilty to placing American spies and US military personnel in grave danger by collecting and transmitting data. 

Thompson began communicating with her unindicted co-conspirator in 2017 via video chats and voice messages when she was working as contract linguist at an overseas US military facility. The pair stayed in touch and Thompson developed romantic feelings for her co-conspirator.

In January 2020, the co-conspirator asked the smitten Thompson for information on the “human assets” who had helped bring about the death in 2019 of Iranian Revolutionary Guard Corps Quds Force commander Qasem Suleimani. 

Thompson admitted knowing that her love interest intended to pass the information to Lebanese Hezbollah, and that it would be given to an unnamed high-ranking military commander.

Using her top secret government security clearance, Thompson began accessing dozens of files concerning human intelligence sources. Information accessed by the linguist included true names, personal identification data, background information and photographs of the human assets, as well as operational cables detailing information the assets provided to the US government. 

Thompson used a variety of techniques to pass this information on to her co-conspirator, including handwritten notes. 

By the time she was arrested by the FBI in February 2020, Thompson had provided her co-conspirator with the identities of at least eight clandestine human assets; at least 10 US targets; and multiple tactics, techniques and procedures. 

On Wednesday, Thompson was sentenced to 23 years in prison. 

“The defendant’s decision to aid a foreign terrorist organization was a betrayal that endangered the lives of the very American men and women on the battlefield who had served beside her for more than a decade,” said Acting US Attorney Channing Phillips for the District of Columbia. 

“Let today’s sentence serve notice that there are serious consequences for anyone who betrays this country by compromising national defense information.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Google Pushes Back Cookie Removal Plans to 2023

Google Pushes Back Cookie Removal Plans to 2023

Google Chrome users will have to wait until at least 2023 before third party cookies are blocked as part of the browser’s Privacy Sandbox initiative.

Google had first disclosed its plans to block third party cookies, which advertisers and marketers use to track users, in August 2019. In January 2020, Google provided more details on the Privacy Sandbox effort with the company stating that it intended to have the cookie blocking technology in place within two years. Now it looks like the timeline for implementation will take a bit longer due to the complexity of the challenge.

“The Privacy Sandbox initiative aims to create web technologies that both protect people’s privacy online and give companies and developers the tools to build thriving digital businesses to keep the web open and accessible to everyone, now, and for the future,” Vinay Goel, privacy engineering director for Google Chrome wrote in a blog post.

Addressing Regulatory Concerns in the UK

The United Kingdom’s Competition and Markets Authority (CMA) has been investigating Google’s Privacy Sandbox initiative since January of this year, when it launched a formal investigation.

As part of the investigation, Google has made a series of commitments to CMA and the industry at large about the Privacy Initiative process. A key commitment is that the effort will not provide any data advantage for Google’s own advertising products.

“The CMA is concerned that Google’s Proposals, if implemented without the regulatory scrutiny and oversight provided for by the Proposed Commitments, would be likely amount to an abuse of a dominant position in the market for the supply of web browsers in the UK,” the CMA stated.

Building Consensus for Cookie Removal

The effort to remove third-party cookies has involved multiple proposals for potential replacements for third-party cookies that provide more privacy assurance for web browser users. According to Goel, over 30 different proposals have been made, four of which are currently in some form of usability trial.

One of the technologies that Google is proposing to replace third-party cookies is FLoC (Federated Learning of Cohorts), which privacy experts have widely criticized as failing to protect user privacy. The basic idea behind FLoC is that groups of users can be clustered together by interests, hiding individual users and providing a way for advertisers to reach an appropriate audience.

Google is now expecting that it will enter into what it refers to as Stage 1 in late 2022, providing APIs for third-party cookie replacement in Chrome. Stage 2 of the cookie removal process is now expected to begin in 2023, with Chrome removing support for third-party cookies.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Attacks Decline as Gangs Focus on Lucrative Targets

Ransomware Attacks Decline as Gangs Focus on Lucrative Targets

Ransomware attacks fell by 50% in Q1 2021 as threat actors shifted from using mass spread campaigns to focusing on fewer, larger targets with unique samples, according to the McAfee Threats Report: June 2021.

The researchers noted that the traditional approach of using one form of ransomware to infect and extort payments from many victims is becoming less prominent, mainly because the targeted systems can recognize and block such attempts over time. Instead, they see a trend towards fewer, customized Ransomware-as-a-Service (RaaS) campaigns tailored to larger, more lucrative organizations.

As a result of this shift, the analysis found that the number of prominent ransomware family types declined from 19 in January 2021 to nine in March 2021. The most detected ransomware group in Q1 2021 was REvil, followed by RansomeXX, Ryuk, NetWalker, Thanos, MountLocker, WastedLocker, Conti, Maze and Babuk strains.

Raj Samani, McAfee fellow and chief scientist, explained: “Criminals will always evolve their techniques to combine whatever tools enable them to best maximize their monetary gains with the minimum of complication and risk. We first saw them use ransomware to extract small payments from millions of individual victims. Today, we see RaaS supporting many players in these illicit schemes holding organizations hostage and extorting massive sums for the criminals.”

Numerous high-profile ransomware incidents have taken place this year; these include the attacks on the US East Coast fuel pipeline operator Colonial Pipeline and meat processor JBS, both of which led to substantial payments being paid.

Another important finding from the report was that there was a 117% rise in the spread of cryptocurrency-generating coin mining malware, which McAfee said is as a result of a spike in 64-bit CoinMiner applications. Unlike ransomware, in which victims’ systems are locked up and held hostage until a cryptocurrency payment is made, Coin Miner malware infects organizations’ systems and then silently produces cryptocurrency using those systems’ computing capacity. This tactic means criminals do not need to interact with the victim, who may be completely unaware they are under attack.

Samani added: “The takeaway from the ransomware and coin miner trends shouldn’t be that we need to restrict or even outlaw the use of cryptocurrencies. If we have learned anything from the history of cybercrime, criminals counter defenders’ efforts by simply improving their tools and techniques, sidestepping government restrictions, and always being steps ahead of defenders in doing so. If there are efforts to restrict cryptocurrencies, perpetrators will develop new methods to monetize their crimes, and they only need to be a couple steps ahead of governments to continue to profit.”

In total, McAfee detected an average of 688 new malware threats per minute in Q1 of 2021, representing an increase of 40 threats per minute compared to Q4 of 2020.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransom Leak Sites Reveal 422% Annual Increase in Victims

Ransom Leak Sites Reveal 422% Annual Increase in Victims

Over three-quarters of consumers and cybersecurity professionals want to see ransom payments made illegal, as new figures showed a triple-digit year-on-year increase in victim organizations.

Mandiant claimed to have detected a 422% increase in victim organizations announced by ransomware groups on their leak sites between Q1 2020 and the first quarter of 2021.

That amounted to over 600 European organizations, with those in manufacturing, legal and professional services and retail most affected.

The new figures come as research from Talion revealed that 78% of UK consumers and 79% of security professionals believe payments to these groups should be banned by law.

It’s an increasingly controversial area, with many commentators blaming cyber-insurance policies for effectively bankrolling threat groups and encouraging more malicious actors to join the fast-growing ransomware cybercrime industry.

It recently emerged that corporate victims that pay up may even be able to deduct these sums from their US tax bills, providing another incentive to hand over money to cybercrime groups.

However, there have also been signs that things are shifting the other way: in France, AXA recently said that it would not be reimbursing policyholders for ransom payments.

The research was released to publicize a new #RansomAware initiative backed by the Research Institute for Sociotechnical Cyber Security (RISCS), which aims to encourage organizations to speak up about attacks.

Former National Cyber Security Centre (NCSC) CEO, Ciaran Martin, now professor at the Blavatnik School of Government, welcomed the initiative.

“We need to look at all the different reasons why ransomware is causing so much harm,” he said.

“That includes tackling the tough questions like the flows of money, including looking seriously at payment bans. But we need to provide more support for victims too, and help them protect themselves in the first place.”     

The Talion study also revealed that 81% of security professionals believe information sharing between victim organizations is key to building better defenses against ransomware.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Nuisance Call Company Fined £130,000 After Eight-Month Blitz

Nuisance Call Company Fined £130,000 After Eight-Month Blitz

A home improvement company has been fined £130,000 by the UK’s data privacy watchdog for inundating consumers with nearly a million nuisance calls.

ColourCoat Ltd of St Leonards on Sea in East Sussex provides insulation and wall and roof coatings, as well as roof repairs and cleaning, according to its website.

However, the firm is said to have made over 900,000 nuisance marketing calls to recipients in just over eight months.

After scores of complaints to the Information Commissioner’s Office (ICO), the regulator launched an investigation, finding that many of the recipients had signed up to the UK’s “Do Not Call” register, known as the Telephone Preference Service (TPS).

According to the ICO, the firm repeatedly called people who had asked not to be called again and withheld its phone numbers to prevent being contacted. It also used false company names on these calls, such as “Homes Advice Bureau,” and “EcoSolve UK,” the regulator claimed.

Along with the fine, the firm was hit with an enforcement notice demanding it stops all illegal activity or faces court action.

ICO investigations manager, Natasha Longson, said ColourCoat had no regard for the law or the individuals it inundated with nuisance calls.

“Businesses employing these tactics are very likely to come to our attention. The catalog of contraventions we uncovered, as well as the manner in which calls were made in this case, resulted in a fine and a legal notice to stop,” she added.

“Some of the complainants described the calls received as ‘rude,’ ‘aggressive’ and ‘abusive,’ and made one complainant feel ‘threatened.’ People also reported that the calls made them feel ‘annoyed’ or ‘anxious’.”

The firm was fined not under the GDPR but the UK’s Privacy and Electronic Communications Regulations (PECR), which governs privacy rights regarding marketing calls, emails and texts.

Unlike the better-known data protection law, the PECR only grants the ICO fining powers of up to £500,000.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber-Attacks Are Primary Funding Source for North Korea

Cyber-Attacks Are Primary Funding Source for North Korea

Cybercrime is now the primary means by which the North Korean state is funded, according to researchers at Venafi.

The security vendor’s threat intelligence specialist, Yana Blachman, and her team analyzed publicly available information on state-sponsored attacks directed by the hermit kingdom over the past four years.

They concluded that the Asian dictatorship now monetizes cyber-attacks to circumvent economic sanctions and keep the Kim Jong-un regime alive.

However, global democracies must take more assertive action to mitigate the cyber-threat from North Korea or risk the funding model being exported to Myanmar, Belarus and other countries shunned by the international community, Blachman warned.

“North Korean attacks are often much more brazen and reckless than those sponsored by other states, because they are not afraid of getting caught — this makes them particularly dangerous. It gives the cyber-criminals it sponsors free reign to engage in highly destructive, global attacks, such as the 2017 WannaCry attacks, affecting more than 200,000 users across at least 150 countries,” she argued.

“Worse still, North Korea is setting an example for other rogue states to follow. Belarus and even Myanmar can now see that cybercrime offers them a way of countering the worst effects of sanctions, while making themselves more of a threat to the wider community.”

Blachman, who started her professional career working in signals intelligence for the Israel Defense Forces’ Unit 8200, said North Korea’s Lazarus, APT38 and other groups are coordinated through the military’s Reconnaissance General Bureau (RGB).

These groups have been responsible for some major money-making raids over recent years, including the notorious $81 million cyber-heist at Bangladesh Bank in 2016 and a theft of $32 million in crypto-funds at South Korean exchange Bithumb two years later.

In 2019, the United Nations issued a report claiming that the Kim regime had managed to generate as much as $2 billion from attacks on banks and cryptocurrency exchanges, in part to raise money for its nuclear weapons program.

Blachman published a blog today explaining more.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk