Cyber-attack Exposes Eye Clinic Patient Data

Cyber-attack Exposes Eye Clinic Patient Data

A cyber-attack on an eye clinic with locations across Iowa may have exposed the records of hundreds of thousands of patients. 

On Tuesday, Wolfe Eye Clinic announced that it had suffered a digital assault in February of this year. During the attack, an unauthorized third party gained access to the clinic’s computer network. 

According to the clinic, the perpetrators behind the cyber-attack may have compromised the records of roughly half a million past and present patients. 

Wolfe Eye Clinic stated that the breach occurred on February 8. The clinic hired an independent IT firm to probe the security incident, but it wasn’t until months later that the scale of the breach was realized.

“Upon detecting this incident, we moved quickly to secure our network environment and launched a thorough investigation,” stated Wolfe Eye Clinic.

“The investigation was performed with the help of independent IT security and forensic investigators to determine the scope and extent of the potential unauthorized access to our systems and any sensitive information,” the clinic continued. 

“Given the complexity and scale of the cyber-attack detected, the full scope of information potentially impacted was not fully realized until May 28, 2021.”

The firm completed its investigation on June 8. After examining the digital forensic evidence, it found that patient data exposed in the attack may have included patient names, mailing addresses, dates of birth, Social Security numbers, and protected medical/health information.

Wolfe Eye Clinic is in the process of contacting all patients that may have been impacted by the data breach with a mailed breach notification. Affected patients are being offered a complementary year of identity monitoring services. 

The clinic said that it is “taking steps to prevent a similar event from occurring in the future by implementing additional safeguards and enhanced security measures to better protect the privacy and security of information in our systems.”

Wolfe Eye Clinic, which was founded by Dr. Otis Wolfe, first opened its doors in 1919. The business, which today serves more than 700,000 patients, started with one clinic in Marshalltown, Iowa. It now includes 11 main clinics, 9 family vision centers, a surgical center and more than 25 outreach locations across the state.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Employee Privacy Gap Discovered

Employee Privacy Gap Discovered

Two thirds of organizations are not effective at protecting the privacy of their employees, according to new research conducted by the Ponemon Institute.

While gathering information for DTEX Systems’ inaugural State of Workforce Privacy & Risk Report, the Institute discovered a significant workforce privacy gap. 

The report, created with sponsorship from cyber-intelligence company DTEX, surveyed a global pool of 1,249 IT and IT security practitioners. Participants were questioned about their organizations’ approach to securing sensitive information and reducing workforce risks. 

Findings revealed that 63% of respondents believe it is important or very important to protect employees’ privacy in the workforce. However, only slightly more than a third (34%) of organizations are effective or very effective in doing so.

Researchers also found that most organizations struggle to balance respecting workforce privacy against a perceived need to monitor employee engagement and internal risk. 

Sixty-four percent of survey respondents said that tracking employee activity and performance without damaging their morale or diminishing their trust in the organization was a difficult task. 

More than half (53%) of companies believe their employees expect their personal behaviors and activities to remain private. However, fewer than half (47%) of companies anonymize the data they collect on their employees for the purposes of monitoring for security risk and operational performance.

Fewer than half (49%) of companies were transparent about what information about their employees was being collected onsite and remotely. 

The shift to remote work was seen as a reason to keep an even closer eye on the workforce. However, only 35% of organizations enable their employees to express any concerns about the protection of their privacy in remote locations.

A key takeaway from this research is that workforce privacy “must be a top priority, not simply just a feel-good goal,” said DTEX Systems chief customer officer, Rajan Koo. 

“The workforce is a source of incredible intelligence, yet organizations continue to fall into a ‘big brother’ surveillance approach that erodes trust and transparency. Draconian tech solutions in the marketplace are only worsening this problem. The findings of this report make it clear – a reckoning is coming.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Gaming Industry Experiences 340% Spike in Web App Attacks

Gaming Industry Experiences 340% Spike in Web App Attacks

Web application attacks targeting the video game industry grew by a higher rate than any other sector during the COVID-19 pandemic, according to a new report by Akamai.

The Gaming in a Pandemic found that attacks of this nature surged by 340% in 2020 compared to 2019, totaling more than 240 million attempts against the video game industry.

The most prominent web application attack vector was SQL injection, making up 59% of all attacks against the gaming sector. This method targets the login credentials and personal information of players. This was followed by local file inclusion, which comprised 24% of all attacks;. This method focuses on sensitive details within apps and services that can further compromise game servers and accounts. Other prominent vectors in this category were cross-site scripting and remote file inclusion, accounting for 8% and 7% of attacks detected by Akamai, respectively.

The video game industry also experienced a 224% increase in credential stuffing attacks in 2020 compared to 2019, a total of nearly 11 billion. Akamai observed that these attacks took place at a large, steady rate throughout last year, with millions of attacks registered each day and two days seeing spikes of more than 100 million. It added that credential stuffing became so common that bulk lists of stolen usernames and passwords were available for as little as $5 on illicit websites.

Surprisingly, there was a 20% reduction in DDoS attacks targeting the gaming industry.

Another key finding from the report was that cyber-criminals consistently targeted mobile games incorporating in-app purchases. These are in-game purchases of virtual items like skins, character enhancements and additional levels.

Steve Ragan, Akamai security researcher and author of the report, commented: “We’re observing a remarkable persistence in video game industry defenses being tested on a daily – and often hourly – basis by criminals probing for vulnerabilities through which to breach servers and expose information. We’re also seeing numerous group chats forming on popular social networks that are dedicated to sharing attack techniques and best practices.”

There have been several high-profile hacks on video game companies over the past year. Earlier this month, gaming giant EA suffered a major data breach in which 780GB of data, including source code for games, was stolen and advertised for sale on the dark web.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

EU Proposes Joint Cyber Unit Amid Rising Attacks

EU Proposes Joint Cyber Unit Amid Rising Attacks

The European Union (EU) has proposed creating a Joint Cyber Unit to improve the ability to respond to rising cyber-attacks on member states.

The ambition is for the unit to enable a coordinated EU response to large-scale cyber incidents and crises by pooling together nation-state resources and improving knowledge sharing among the relevant bodies.

To implement this vision, the EU Commission has proposed developing a physical and a virtual platform for the unit. The physical platform will provide “a physical space where cybersecurity experts can, in case of need, come together to conduct joint operations, share knowledge and work together.” The virtual platform will be used “for collaboration and secure information sharing, leveraging the wealth of information gathered through monitoring and detection capabilities.”

With the creation and maintenance of secure communication channels and improved detection capabilities, the platforms will be primarily funded through the EU’s Digital Europe Programme.

The commission has suggested that the Joint Cyber Unit is built in four stages, with a completion date of June 2023.

  1. Assess (by December 31 2021) – to establish how the unit will be organized and understand EU operational capabilities.
  2. Prepare (by June 30 2022) – Roll out joint preparedness activities alongside national incident and crisis response plans, with a view to outline the roles and responsibilities of participants in the unit.
  3. Operationalize the Joint Cyber Unit by mobilizing EU rapid reaction teams (by December 31 2022)
  4. Involve private sector partners (by June 2023) – in particular, increasing information sharing with users and providers of cybersecurity solutions and services.

The main parties involved in the unit fall under four categories: Resilience, Law enforcement, Diplomacy and Defense.

The proposal has come amid a growing number of serious cyber incidents, which are impacting critical services in the EU and other parts of the world. Recent examples include a ransomware attack on Ireland’s health service and the theft of official COVID-19 vaccine data from the European Medicines Agency.

Security experts have been quick to welcome the proposal but cautioned that it requires the cooperation of member states in areas such as intelligence sharing to work effectively. Matt Lock, technical director at Varonis, commented: “Any new initiative to tackle cybercrime is to be welcomed, so the launch of the Joint Cyber Unit is good news and shows the EU is taking the problem seriously. 

“However, organizations should not think that they can take their eyes off the road. Once a ransomware attack or another breach has taken place, it’s often too late – the damage has already been done. 

“Organizations need to take responsibility for their own cybersecurity and securely lock down their data to avoid falling victim to hackers. 

“It’s important also to note that the EU views this reactive force as a ‘recommendation’ to governments and institutions. The launch of this initiative should therefore be a message to every business, both large and small. Prepare for the worst and raise your defenses, because cyber-criminals won’t be giving up.”

Steve Forbes, government cybersecurity expert at Nominet, said: “The new effort includes rapid response teams ready to be deployed in the instance of an attack, as well as a game-changing platform for collaboration across the EU, including intelligence, resources and expertise. This is exactly what’s needed to stem the tide against attacks that are only becoming more brazen and sophisticated.

“Until now, it has been reported that countries were hesitant to give away any control of their national security, and that is completely understandable when you consider that cyber is increasingly being seen alongside traditional methods of defence such as the army, navy and air force. There is a middle ground, however, where countries can benefit from centralized intelligence, overarching strategies and broad-reaching tactics. With similar threats faced across the EU – particularly against critical infrastructure – often with the same adversaries, pulling together will allow the bloc to make step changes in its cyber defense.

“The new cyber unit will set a powerful precedent for international collaboration as central to our future global cyber defense.”

Today, the EU has also published a progress report on its EU Security Union Strategy, which emphasizes combatting cybercrime and other malicious activity online.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Banks Drive £77 Million Reduction in European Fraud Losses

UK Banks Drive £77 Million Reduction in European Fraud Losses

UK banks led the way in Europe last year with fraud protection efforts, driving an overall drop in associated losses of £77 million (€90 million) year-on-year, according to new data from FICO.

The predictive analytics firm claimed that British financial institutions cut fraud losses by an impressive £46 million (€69 million) in 2020, the equivalent of a 7% reduction on 2019 figures.

They were joined by their counterparts in Denmark, who managed to drive down fraud by €20 million (£17 million).

However, this is largely where the good news ends for Europe, as only three more out of the 18 countries studied managed to achieve a reduction and none on the same scale as the UK and Denmark. FICO claimed that without the “focus, robustness, resilience and adaptability” of UK banks, European fraud losses would have increased over the period by around £8 million (€10 million).

In France (€6 million), Poland (€5 million) and Germany (€3 million), fraudsters all increased their takings.

Norway saw the biggest year-on-year rise (172%) from €8 million to €22 million, driven by prolific phishing and smishing campaigns designed to trick users into divulging their log-ins.

According to banking industry association UK Finance, financial institutions prevented £1.6 billion in unauthorized fraud by implementing real-time transaction analysis and other technologies.

Other steps included improved collaboration and intelligence sharing between law enforcement, government and industry, and the roll-out of the Banking Protocol, which allows bank branch staff to alert the police when they think a customer is being scammed.

UK Finance also pointed to collaborative industry efforts to block scam text messages and number spoofing, as well as an account name-checking service known as “Confirmation of Payee” designed to prevent authorized push payment scams.

The new figures are at odds with many predictions that cited COVID-19 as providing fraudsters with new opportunities to scam consumers and their banks.

However, a respected think tank earlier this year branded escalating fraud a national security risk, requiring a “major systemic shift” in government strategy. A separate paper from the same organization warned of “silent stealing” tactics in which fraudsters target large numbers of consumers for very small amounts they may not notice.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Nearly 10% of SMB Defense Contractors Show Evidence of Compromise

Nearly 10% of SMB Defense Contractors Show Evidence of Compromise

More than half of SMB contractors in the US defense supply chain are critically vulnerable to ransomware attacks, a new report has claimed.

Cybersecurity vendor BlueVoyant chose to analyze a representative sample of 300 smaller contractors from a defense industrial base (DIB) estimated to have anywhere from 100,000-300,000 suppliers.

The resulting Defense Industry Supply Chain & Security 2021 review uncovered concerning signs of weaknesses in this complex ecosystem of contractors — potentially putting national security at risk.

It found that over half of the companies studied had unsecured ports vulnerable to ransomware attacks. In contrast, 48% had vulnerable ports and other weaknesses, including unsecured data storage ports, out-of-date software and operating systems, and other vulnerabilities rated severe by NIST.

Unpatched flaws were particularly concerning: more than six months after critical F5 and Microsoft Exchange vulnerabilities were published, nine companies were yet to fix them.

A fifth (20%) of SMB contractors were found to have multiple vulnerabilities and evidence of targeting, while 7% also featured evidence of compromise.

In total, BlueVoyant found evidence of over 1300 email security issues, more than 400 vulnerabilities, and 344 indications that suggest “company resources are involved in anomalous or criminal activity.”

Perhaps unsurprisingly, over a quarter (28%) of appraised contractors showed evidence indicating they would fail to meet the most basic tier-1 requirement for the Cybersecurity Maturity Model Certification (CMMC). This is a critical compliance standard designed to improve security best practices among US defense contractors.

Austin Berglas, global head of professional services at BlueVoyant, argued that as primary contractors improve cybersecurity, threat actors have pivoted towards SMBs in the same supply chain. He highlighted manufacturers and R&D firms as particularly exposed to the risk of attack.

“For an industry with such an expansive, interconnected digital ecosystem, supply chain security should be a fundamental consideration. Prime contractors are under enormous pressure to reduce the attack surface of the entire supply chain but are partly blind to the vulnerabilities that exist,” he added.

“For smaller companies, identifying ongoing risks and understanding overall supply chain health is a daunting but vital process, and more attention and resources should be dedicated to combating the growing threat.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Councils Reported Over 700 Data Breaches in 2020

Councils Reported Over 700 Data Breaches in 2020

Hundreds of councils across the UK suffered data breaches last year, according to new Freedom of Information (FOI) research from Redscan.

The managed security services provider used official FOI responses from over 60% of the country’s 398 local authorities to compile its new report, Disjointed and under-resourced: Cyber security across UK councils.

Extrapolating these results, Redscan estimated that there were over 700 breaches reported to data protection regulator the Information Commissioner’s Office (ICO) last year. The average number reported by county councils (4.6) was more than double that of the total figure (1.8).

The report also noted that those reporting the most breaches tended to be the largest councils.

On the face of it, things are improving: the 2020 figure for breached councils (704) was around 10% lower than 2019 estimates (786).

However, the threat to local government is still high, Redscan warned.

Some ten councils confirmed they had been victims of ransomware or had experienced breaches that disrupted their operations last year. One reported 29 breaches to the ICO in just a single year.

Although not broken down by breach type, many of the incidents organizations report to the ICO stem from employee negligence, such as emailing information to the wrong recipient or failing to BCC users.

That’s why the report called out staff training as a key area of scrutiny.

Around 40% of local authorities spent no money on this crucial area in 2020, while nearly half (45%) were found to employ no staff with recognized security qualifications.

An estimated £1.5 million was spent in total among UK councils on security awareness training, which amounts to just £1.58 per employee, Redscan claimed.

The firm’s CTO, Mark Nicholls, argued that there’s plenty of room for improvement for local authorities.

“Every council has thousands of citizens depending on its services daily. Going offline due to a cyber-attack can deny people access to these critical services,” he added.

“To minimize the impact of data breaches, it is important that councils are constantly prepared to prevent, detect and respond to attacks. While our findings show that councils are taking some steps to achieve this, approaches vary widely and, in many cases, are not enough.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk