Arrest Made Over Multi-million-dollar BEC Scam

Arrest Made Over Multi-million-dollar BEC Scam

Texas law enforcement officers have made an arrest in connection with a multi-million-dollar wire fraud and money laundering scheme involving Business Email Compromise (BEC).

Guillermo Perez was taken into custody Wednesday morning for allegedly defrauding businesses and individuals of more than $2m through cyber-scams and bank fraud schemes.

An indictment unsealed on June 9 accuses 26-year-old Houston resident Perez of participating in the illegal scam from at least October 2018 to October 2019.

Perez is accused of impersonating individuals and businesses over email in the course of otherwise ordinary financial transactions. While posing as someone else, Perez allegedly tricked victims into transferring funds into bank accounts controlled by him and his co-conspirators.

As part of the alleged scheme, Perez provided banks with false and misleading information regarding his and his co-conspirators’ affiliations, then tricked the banks into opening business bank accounts that were fraudulent.

Victims of the BEC scheme, who were unaware that they were acting on false and misleading misrepresentations made by Perez and his co-conspirators, wired more than $2.2m into the fraudulent bank accounts. 

It is alleged that Perez and his co-conspirators, knowing that the transferred cash represented fraud proceeds, moved it out of the fraudulent bank accounts in transactions designed to conceal and disguise its origins and ownership.

The arrest of Perez was announced yesterday by Audrey Strauss, the United States attorney for the Southern District of New York, and Peter C. Fitzhugh, the special agent-in-charge of Homeland Security Investigations (HSI) in New York.

He is charged with one count of conspiracy to commit wire fraud and bank fraud, which carries a maximum sentence of 30 years in prison. Perez is also charged with one count of conspiracy to commit money laundering, which carries a maximum sentence of 20 years in prison.

In a statement issued yesterday, the US Attorney’s Office wrote that Strauss praised the investigative work of HSI in the Perez case. 

The prosecution is being handled by the Money Laundering and Transnational Criminal Enterprises Unit. Assistant United States attorneys Emily Deininger and Tara La Morte are in charge of the prosecution.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Texas to Publish Data Breach Notifications

Texas to Publish Data Breach Notifications

Lawmakers in Texas have passed a bill requiring notices to be published online of any data breaches involving the personal information of 250 or more Lone Star State residents.

The unanimously passed House Bill 3746, which amends the Texas Business and Commerce Code §521.053, requires the Texas Attorney General’s Office to post the breach notifications to its public-facing website.

Notifications must be uploaded to the website within 30 days of receipt, and listings of organizations impacted by a data breach must remain in place for a period of 12 months.

A listing will only be removed if the individual or company does not suffer any further data breaches affecting 250 or more Texas residents during the year-long listing period. 

Under current Texas law, notifications that a security system has been breached must be sent to the state Attorney General within 60 days of detection. 

Included in the breach notice must be a detailed description of the scope of the breach, how it happened, and what sensitive information may have been compromised, exfiltrated, stolen or deleted in the security incident.

Though it may not be a final tally, another detail that must be included in the data breach notice is the number of individuals known to be impacted by the breach at the time it is reported to the State Attorney General. 

Breached individuals and organizations cannot simply report a data breach incident to the Attorney General’s Office and walk away. Their notice must include a description of what measures were taken to mitigate the breach and details of what future actions will be taken regarding the incident.

The Office must be informed as to whether law enforcement has been notified and is investigating the breach. It must also be instructed over how many Texas residents have been notified about the breach, by mail or another direct method of communication, at the time the incident is reported.

Before it becomes law, the bill must be signed by Texas governor Greg Abbott. Should it be graced with Abbott’s signature, the law will take effect from September 1, 2021.

By passing the new bill, the Texas Legislature has followed in the footsteps of California and Maine.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#Infosec21: Lack of Vision Explains Cyber Skills Shortage

#Infosec21: Lack of Vision Explains Cyber Skills Shortage

The cybersecurity skills gap is caused by a lack of vision in the industry rather than it being a pipeline problem, argued Wendy Nather, head of advisory CISOs at Cisco, during her keynote address on day three of the Infosecurity Europe virtual conference.

Nather, who was recently inducted into the Infosecurity Hall of Fame, believes it is a complete misnomer that there is a lack of talent available to fill the expanding number of security roles. Instead, it is down to the industry “to open our eyes and see what’s in front of us, namely that there are sources of great security talent everywhere.”

Nather then showed a collage of high profile security professionals representing a range of demographics, including those often not associated with technical IT skills, such as older people. She said this demonstrates that anyone from any walk of life has the potential to be successful in the sector.

She added that it is vital to recognize that there is a range of pathways into the security industry, and it is quite possible to move across from a completely different profession. “They just need to be able to innovate and then they can learn the technology,” outlined Nather. “People are capable of learning all sorts of things; you don’t have to go for the person who is exactly like the last person you had in this position.”

In fact, it is a great advantage to a security team to have personnel from different backgrounds and experiences. Nather gave the example of hiring a man called John Skaarup, an army veteran of 21 years, based on the mindset he demonstrated during her interview with him. Nather said that “he turned out to be one of the best security colleagues that I have ever had” and is now a cybersecurity officer, running the security operations center at the Texas Department of Transportation.

Nather then offered advice on how those involved in the hiring of security personnel can adapt their practices to open their doors to a much wider pool of talent. She observed that there are already highly knowledgeable people familiar with security but whose skills are not recognized for various reasons. These include the way they speak – if they do not use traditional security terminology. Nather commented: “Just because they don’t know the right lingo doesn’t mean they don’t know the concepts and that they can’t apply their skills.”

Nather also said that organizations need to be more careful about how they word their job descriptions, as they can often come across as overly restrictive to many good candidates. This includes postings asking for “ridiculous amounts of experience” in relatively new areas, like Kubernetes.

She added that this was a particular issue for candidates from underrepresented groups as they are “less likely to apply for positions where they fit the description 100%.” Therefore, asking for too many qualifications risks “cutting out the person who you need for your team.” To help prevent this situation from occurring, Nather believes that senior security personnel should be making this case loud and clear and “fight for latitude in hiring.”

In addition, a greater emphasis on soft skills should be made during the hiring stage, according to Nather. She argued that these types of attributes are just as valuable to an organization as the specific technical expertise, as the right people will be able to add these such skills to their repertoire in any case. For instance, she believes more value should be put on “tact, collaboration, the ability to explain things to anybody using very small words or the talent to be able to create something that people enjoy using.”

Concluding, Nather offered some takeaways for how the cybersecurity industry can grow the skills pipeline and diversify the people working within it. These include taking the initiative to discover and meet people from underrepresented groups rather than simply posting a job online. “To find the best people, you have to put in the work,” she explained.

Finally, Nather provided what she regarded to be the most crucial takeaway of the presentation, which is to recognize that “what I knew back then doesn’t matter now.” Simply put, the cybersecurity industry is evolving so quickly that the ability to adapt and learn new skills now is more important than past experiences in the field. She concluded: “What matters now is that we are all on the same starting line – we are all in the same race to learn. So look for the people you want to run with.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Schools Forced to Shut Following Critical Ransomware Attack

Schools Forced to Shut Following Critical Ransomware Attack

Two schools in the south of England have been forced to temporarily close their doors after a ransomware attack that encrypted and stole sensitive data.

The Skinners’ Kent Academy and Skinners’ Kent Primary School were attacked on June 2, according to a statement on the trust’s website which said it is currently working with third-party security experts, the police and the National Cyber Security Centre (NCSC).

It revealed that on-premise servers were targeted at the Tunbridge Well-based schools. As student and staff emergency contact details, medical records, timetables and registers were encrypted by the attackers, the decision was taken to close on Monday.

“Data stolen includes: a wealth of teaching resources, school trip information, policies, human resources files and a significant amount of staff data, some student data including medical information and data pertaining to our iPad scheme,” an FAQ statement noted.

“Data encrypted (and therefore not accessible to the school anymore) includes our management information system, which contains the bulk of contact details for parents. Therefore, it is the latter that we have had to ask parents to re-submit to the trust.”

Students and parents have been advised to change any passwords, and parents have been told to inform their bank that account information may have been taken.

“The details of bank accounts may have been accessed through details taken for the iPad scheme for example,” the trust said.

The news comes just days after the NCSC warned of a surge in ransomware attacks on the UK’s education sector.  It claimed that phishing, RDP hijacking, and targeting vulnerabilities in VPNs and other systems were the primary attack vectors.

“As a result of the pandemic, schools have shifted to remote and hybrid learning, leading to an increase in the types of devices accessing the school’s cloud-based servers to attend classes and complete schoolwork,” argued Lookout security engineer, Burak Agca.

“A lack of visibility and a high degree of fragmentation in operating system platforms and device types introduces several security gaps and risks which schools have been struggling to deal with.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

High Street Banks Exposing Customers to Phishing Attacks

High Street Banks Exposing Customers to Phishing Attacks

A consumer rights group is calling on all high street banks to improve their anti-phishing capabilities after spotting that a key protocol is sometimes not configured to offer maximum protection.  

Domain-based message authentication, reporting and conformance (DMARC) is a tried-and-tested way to help brands block phishing emails to customers.

It helps to verify that the domain of the sender hasn’t been impersonated, although it must be set to “p=reject” in order to prevent suspicious emails from being sent to customer inboxes.

Consumer group Which? asked tech firm 6point6 to audit some of the biggest names on the high street to check their DMARC policies.

At the time of the study, it found that Bank of Ireland and Lloyds Bank-owned Agricultural Mortgage Corporation had not introduced DMARC at all, although both have since taken action.

It also found that Nationwide, TSB and Virgin Money had not set DMARC to p=reject, although the latter two claimed they were planning to do so.

The Co-operative Bank, First Direct, Starling and Tesco Bank had DMARC in place for their primary domains but not their alternative domains, which phishers could theoretically abuse.

Starling and Tesco Bank have now taken action to close this security loophole, Which? claimed.

“It has never been harder for people to know whether they’re receiving genuine communications from their bank, or being tricked — so it is crucial that banks take every measure to protect their customers from these devastating scams,” said Which? Money editor, Jenny Ross.

“These include implementing email scam protections properly and no longer putting phone numbers and links in messages, to ensure customers feel safe and can bank with confidence.”

On the plus side, most UK banks have signed up to a “do not originate” (DNO) number scheme designed to clamp down on number spoofing, which scammers often use in vishing (phone-based phishing) attacks, Which? said.

Last year, a Proofpoint report found that only 13 out of the 64 accredited financial institutions it studied had implemented the strongest DMARC policy.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

JBS Admits Paying REvil Ransomware Group $11 Million

JBS Admits Paying REvil Ransomware Group $11 Million

A meat processing giant recently hit by ransomware has confirmed it paid its extorters $11 million, reigniting the debate over the ethics of doing so.

A statement published by Sao Paolo-headquartered JBS, whose US and Australia businesses were hit in the incident last week, claimed that at the time of payment, the “vast majority” of its facilities were operational.

“In consultation with internal IT professionals and third-party cybersecurity experts, the company made the decision to mitigate any unforeseen issues related to the attack and ensure no data was exfiltrated,” it added.

Usually, the attackers have already exfiltrated sensitive data in such attacks, and payment is made to prevent them from publishing it.

However, there’s no guarantee that the attackers will not try to monetize the data anyway.

Last November, a Coveware report claimed that data exfiltration is now a tactic in over half of ransomware attacks.

It warned that groups such as REvil (Sodinokibi), which was blamed for the JBS attack, sometimes still publish data after payment, and, in some cases, demand a second payment.

It’s unclear whether JBS paid the ransom with the expectation its insurance provider would cover it. The issue is increasingly controversial, with AXA recently stating that it would stop reimbursing clients in France for ransom payments.

“This was a very difficult decision to make for our company and for me personally,” said Andre Nogueira, CEO of JBS USA. “However, we felt this decision had to be made to prevent any potential risk for our customers.”

The firm’s statement goes on to boast a $200 million annual IT budget and state that its ability to bounce back quickly from the attack was due to “its cybersecurity protocols, redundant systems and encrypted backup servers.”

Edgard Capdevielle, CEO of Nozomi Networks, argued that enterprises must now be prepared for the inevitable ransomware attack.

“That’s why in addition to strengthening cybersecurity defenses, it’s equally important to invest in business resilience in the face of an attack,” he added.

“This post-breach mindset establishes a strong cybersecurity culture that asks the tough questions, anticipates worst-case scenarios and establishes a recovery and containment strategy aimed at maximizing your organization’s resiliency, long before an attack occurs.”

It’s generally advised that victims do not pay ransomware groups as it simply encourages more of the same malicious activity. However, when critical supply chains are involved, it’s not quite so simple.

“Naive statements like ‘never pay the ransom’ simply ignore the reality of the situation and do not have any chance in actually changing anything,” argued John Bambenek, Threat Intelligence Advisor at Netenrich.

“President Biden’s meeting with Vladimir Putin next week is critical in attempting to change the trajectory of this threat to bring the rogue state responsible for harboring this threat to heel.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk