IKEA Fined $1.2m for Spying on Employees

IKEA Fined $1.2m for Spying on Employees

Swedish furnishing conglomerate IKEA has been fined €1m ($1.2m) for illegally spying on its employees in France and storing their data.

The fine was ordered by a French court on Tuesday after a criminal probe launched in 2012 found that IKEA France had created an elaborate “spying system” to snoop on staff and on customers who had opened disputes.

IKEA, which has 29 stores in France, was found guilty of “receiving personal data by fraudulent means.” 

Prosecutors said IKEA France tapped police sources, engaged a private security company, and hired private detectives to illegally acquire confidential information on its workers and prospective employees. 

Data obtained by the company included membership of labor unions or works councils. Investigators were also asked to find out how an employee could afford a new BMW.

In 2012, satirical weekly newspaper Le Canard enchaine published email exchanges between IKEA and private investigators that showed that spying on staff had been de rigueur at the French subsidiary for years.

Prosecutors said that the espionage infrastructure established by the French subsidiary operated for at least a three-year period from 2009 to 2012. After accusing the company of “mass surveillance,” prosecutors sought a fine of €2m ($2.4m) against the company.

IKEA admitted to basic rights violations back in 2012, and released a statement declaring that “IKEA fully condemns the practices brought to light.”

Although the trial was centered on spying that occurred from 2009 to 2012, prosecutors say the snooping system was set up almost a decade earlier under a former head of IKEA France, Jean-Louis Baillot.

Baillot, who headed the company from 1996 to 2002, denies any wrongdoing and has declared himself “shocked” to be convicted for his role in the scandal. A French court handed Baillot a two-year suspended prison sentence and fined him €50,000 ($60,630) for storing personal data.

Jean-Francois Paris, IKEA’s former head of risk management and a central figure in the scandal, admitted to sending lists bearing the names of people “to be tested” to the security firm Eirpace. The testing was so prevalent that it generated annual bills of up to €600,000.

Paris was given a suspended 18-month prison term and fined €10,000. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NATO Warns it Will Consider a Military Response to Cyber-Attacks

NATO Warns it Will Consider a Military Response to Cyber-Attacks

NATO has warned it is prepared to treat cyber-attacks in the same way as an armed attack against any of its allies and issue a military response against the perpetrators.

In a communique issued by governments attending the meeting of the North Atlantic Council in Brussels yesterday, the military alliance revealed it had endorsed a Comprehensive Cyber Defence Policy, in which a decision will be taken to invoke Article 5 “on a case-by-case basis” following a cyber-attack. Under Article 5 of the NATO treaty, first signed in 1949, when any NATO ally is the victim of an armed attack, it will be considered an attack on all alliance members, who will theoretically take any actions necessary to defend that ally.

The announcement has come amid rising cyber-threats to the alliance, which NATO said are “complex, destructive, coercive, and becoming ever more frequent.” It highlighted recent ransomware and other types of cyber-attacks “targeting our critical infrastructure and democratic institutions, which might have systemic effects and cause significant harm.”

Examples of these kinds of incidents include the ransomware attack on Colonial Pipeline last month, which forced the US’ largest fuel pipeline offline, and the SolarWinds supply chain attacks at the end of 2020, both of which are purportedly conducted by Russian state-backed actors.

NATO has signalled it considers cyber as a legitimate military domain on a number of occasions in recent years, and the new policy clarifies this stance.

“Reaffirming NATO’s defensive mandate, the Alliance is determined to employ the full range of capabilities at all times to actively deter, defend against, and counter the full spectrum of cyber-threats, including those conducted as part of hybrid campaigns, in accordance with international law,” it added.

The communique also warned of the growing security challenge that China poses to the alliance through its “stated ambitions and assertive behavior,” which includes cyber-threats and disinformation campaigns.

Commenting on the communique, Erwan Keraudy, CEO of CybelAngel said, “Traditional forms of war, rules of engagement and conduct have existed in one form or another and have been with us for centuries. But there is no straightforward definition in the cyber world. The lines have been completely blurred. So, NATO re-affirming the rules and conventions governing cyberspace is a positive and proactive step forward in establishing a standard cyber framework.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Fake Online Reviews Linked to $152 Billion in Global Purchases

Fake Online Reviews Linked to $152 Billion in Global Purchases

Fake online reviews are responsible for an estimated $152 billion in purchases, according to a new study based on data shared by major e-commerce sites.

Customer acquisition security vendor CHEQ teamed up with the University of Baltimore to produce its Fake Online Reviews 2021 report — part of what it claims to be the “first-ever in-depth economic analysis of the full scale of internet harm.”

The report’s headline claim is based on an average rate for fake reviews of 4% across platforms including Amazon, TrustPilot, Yelp and Tripadvisor, and an estimated global e-commerce market size of nearly $4.3 trillion in 2020.

It breaks down to around $28 billion of consumer spending in the US influenced by fake reviews, $6.4 billion in Japan, $5 billion in the UK, $2.3 billion in Canada, and $900 million in Australia.

In the US, travel and fashion (both around $4 billion) are the sectors most affected in purely financial terms, followed by electronics ($3 billion), furniture and homeware ($2 billion) and entertainment ($1 billion).

The report reveals the sheer size of the underground trade in five-star reviews, which it claims are charged at anywhere between 25 cents to $100 per review. Reviewers may be encouraged to purchase an item for ‘review’, which they are then reimbursed for and allowed to keep, sometimes in addition to a commission.

This was the kind of scam uncovered by researchers recently when they discovered a misconfigured database containing the personal details of around 200,000 such reviewers.

However, the same kind of thing is increasingly done by ad fraud bots which are signed up via travel, e-commerce paid search and social campaigns, the report claimed.

Overall, the impact could be to diminish customer trust in online reviews, and therefore in e-commerce itself, and to unduly harm businesses whose rivals have posted fake negative reviews about them online.

“Given the size of the market, the ease of entry and the immediate economic benefits, bad actors remain highly incentivized to engage in fake reviews,” argued report co-author Roberto Cavazos at the University of Baltimore.

“This complex market is adversely influencing our purchases, causing significant economic detriment, creating real revenue losses for businesses, and severely diminishing trust in online purchasing.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Third of Staff Use Security Workarounds at Home

Third of Staff Use Security Workarounds at Home

Over a third (36%) of workers claim to have picked up bad security behaviors since working from home, potentially putting their employers at risk, according to a new study from Tessian.

The security vendor polled over 4,000 employees in the US and UK across various company sizes and industries, along with 200 IT professionals, to better understand back-to-work trends.

The resulting Back to Work: Security Behaviors Report revealed that many staff found security workarounds since working remotely, with younger respondents in the 16-24 age bracket (51%) and 25-34-year-olds (46%) most likely to have cut security corners. By contrast, just 19% of over-55s said they did.

Nearly a third (30%) also said they feel like they can get away with riskier behavior at home, with half (49%) claiming it’s because they think they aren’t being watched by IT.

Behaviors such as clicking on links in unsolicited messages, using personal devices and online accounts for work, and downloading unsanctioned apps to work devices can expose the organization to enhanced cyber-risk.

In fact, over a quarter of responding employees admitted making a mistake that has compromised company security. These incidents went unreported for fear of disciplinary action or having to take part in more security training, Tessian said.

The good news is that most (70%) IT professionals surveyed believe the return to the office will encourage employees to reengage with security and data protection policies.

However, there are still concerns: over half (54%) of IT leaders are worried that staff will bring infected devices back into the workplace, while 69% said ransomware would be a greater concern when new hybrid ways of working bed in.

Tessian CEO, Tim Sadler, agreed that the hybrid model would be challenging to secure.

“Employees are the gatekeepers to data and systems, but expecting them to be security experts and scaring them into compliance won’t work,” he argued.

“IT leaders need to prioritize building a security culture that empowers people to work securely and productively, and understand how to encourage long-lasting behavioral change over time if they’re going to thrive in this new way of working.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

No Two REvil Attacks Are the Same, Experts Warn

No Two REvil Attacks Are the Same, Experts Warn

According to a new report, no two criminal groups deploy the infamous REvil ransomware variant identically, adding to the challenge for those tasked with detecting and responding to such attacks.

The new study from Sophos details the activity of the affiliates who license the malware itself and handle the break-ins. This ransomware-as-a-service (RaaS) model now accounts for the majority of attacks in the wild.

Initial network access could come from brute-forcing internet-facing services like VPNs, RDP, VNC, and cloud-based management systems. Or it could come from phished or otherwise stolen credentials for legitimate accounts not protected by multi-factor authentication (MFA). Or in some cases, from “piggybacking” from other malware already present on the network.

Brute force password cracking attempts on RDP servers is common: Sophos revealed that one customer experienced 35,000 failed login attempts over a five-minute period, originating from 349 unique IP addresses around the world. 

Suppose they don’t have a functioning credential. In that case, the REvil affiliates are then likely to bide their time, monitoring the target network and/or using tools like Mimikatz to extract passwords for a domain administrator account.

The next stage involves preparing the victim network for a ransomware attack, which Sophos principal researcher, Andrew Brandt, calls “tilling the field.”

“The attackers need to establish a list of internal targets, give themselves domain admin privileges, and use those privileges to shut down or otherwise hobble anything that might impede their attack,” he explained.

“Windows Defender is usually the first to go, but often the attackers will spend some time trying to determine what endpoint protection tools are running on the computers, and may run one or more customized scripts that combine an attempt to kill any running protection process or services, and also to remove any persistence those processes or services might have.”

A tell-tale sign of malicious activity here is the presence of PowerShell scripts, batch files, or other “laying the groundwork” code used to disable protective features.

Next comes data exfiltration, a practice that should be detectable “but never happened in the cases we investigated,” according to Brandt.

REvil affiliate attackers typically spend a few days looking through file servers and bundling large numbers of docs into compressed files in a single location. It’s then usually uploaded to a cloud storage service over the course of a few hours or a day, with Mega.nz favored by most attackers.

There’s a wide variety of different ways to launch the ransomware payload itself, Sophos explained.

“They may push out copies to individual machines from a domain controller, or use administrative commands with WMIC or PsExec to run the malware directly from another server or workstation they control over the internal network of the target organization,” said Brandt.

Another option for REvil affiliates is to reboot a hijacked computer into Safe Mode, with the REvil malware adding itself to the shortlist of apps that can run in this mode.

“In others, we’ve observed the threat actor using WMI to create service entries on the machines they target for encryption,” said Brandt. “The entries contain a long, encoded command string that is impossible to decode unless you know the specific variables it was looking for.”

The sheer variety of REvil affiliate attacks, and by implication, those of other popular ransomware types, may appear challenging, but there are some helpful common best practices.

Sophos recommended MFA and strong passwords, Zero Trust and segmentation, prompt patching of all assets and the locking down of internet-facing services like RDP, among other steps.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk