MoviePass Operators Settle Data Security Allegations

MoviePass Operators Settle Data Security Allegations

The operators of subscription service MoviePass have agreed to settle Federal Trade Commission allegations of fraud and data security failures. 

It is alleged that MoviePass used an elaborate three-prong approach to prevent and discourage subscribers from using its $9.95 “one movie a day” monthly subscription service as advertised.

First, according to the FTC complaint, the company blocked as many as 75,000 subscribers from accessing content by purposefully invalidating their passwords. 

The FTC said: “MoviePass’s operators invalidated subscriber passwords while falsely claiming to have detected ‘suspicious activity or potential fraud’ on the accounts. MoviePass’s operators did this even though some of its own executives raised questions about the scheme.”

Their next alleged tactic was to create a time-sensitive ticket verification program that discouraged thousands of subscribers from using the service. 

“This program required subscribers to take and submit pictures of their physical movie ticket stubs for approval through the MoviePass app within a certain timeframe,” said the FTC.

“Subscribers who failed to submit their tickets could not view future movies and could have their subscriptions canceled if they failed to verify their tickets more than once.”

Finally, MoviePass’s operators allegedly set “trip wires” to block set groups of subscribers from using the service after they collectively hit certain thresholds based on their monthly cost to the company. The FTC alleges that this tactic was used against subscribers who typically watched three or more movies per month.

The operators of the now defunct app were further accused of storing the personal information it collected from subscribers in plain text and allowing unrestricted access to customers’ names, email addresses, birth dates, credit card numbers, and geolocation information.

In August 2019, MoviePass confirmed that it suffered a data breach that may have exposed customer credit card numbers.

MoviePass Inc., which was founded in 2011 and headquartered in New York City,  shuttered its mobile ticketing service in 2019. In January 2020, its parent company Helios and Matheson Analytics, Inc., filed for bankruptcy

Under the proposed settlement, MoviePass, Helios, former MoviePass CEO Mitchell Lowe, and former Helios CEO Theodore Farnsworth will be barred from misrepresenting their business and data security practices.

The order also states that any businesses controlled by MoviePass, Helios, or Lowe must implement comprehensive information security programs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber-attack on NYC Law Department

Cyber-attack on NYC Law Department

An intrusion into the IT system of the New York City Law Department is being co-investigated by the New York Police Department and the FBI’s Cyber Task Force.

The hack was first reported by The Daily News, which learned that sensitive information belonging to more than a thousand department employees may have been exposed in the security incident.

After discovering the intrusion, the city restricted admission to the system, preventing government lawyers from accessing documents. 

On June 7, the city government confirmed that it was examining “unauthorized access within the NYC Law Department’s IT environment.”

In a statement released Monday, Laura Feyer, a spokesperson for Mayor Bill de Blasio, told The Daily News that “the City’s Cyber Command” had “promptly launched an investigation into the matter.”

Feyer added: “As the investigation remains ongoing, the City has taken additional steps to maintain security, including limiting access to the Law Department’s network at this time.”

The New York City Law Department is staffed by approximately 1,000 lawyers and 890 support professionals. 

Mayor de Blasio said last night that investigators were yet to find any evidence that data belonging to the Law Department had been “compromised” in the attack.

“We’re still tracking down exactly who was behind it,” he told NY1. “So far, we believe the defenses have held.”

News of the intrusion came to light on Monday morning when The Daily News discovered that a city lawyer had cited technical problems when a filing a request to extend a case due to be heard in Manhattan federal court by one week. 

“The Law Department has been experiencing a connectivity issue since yesterday, and, as a result, no one is currently able to log on to the Law Department’s computer system,” city attorney Katherine Weall wrote to Judge P. Kevin Castel.

“I am therefore unable to access and file the answer I have drafted in this case, which is due today,” she added.

Nicholas Paolucci, a Law Department spokesperson, said the agency was taking steps “to ensure there was minimal impact to cases.”

The incident comes just days after Metropolitan Transportation Authority officials revealed that at least three of the agency’s 18 database systems had been accessed by hackers.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Illinois County Stricken with Grief

Illinois County Stricken with Grief

A new organized cybercrime group claims to have stolen sensitive data belonging to a county in Illinois. 

St. Clair County disabled its website on June 2 out of “an abundance of caution” after suffering a cyber-attack. Ransomware gang Grief has claimed responsibility for the digital assault.  

Because of the incident, several county services were rendered unavailable from May 28, including access to court records and payment for ticket fees. 

The county jail’s network was also impacted, with one woman telling 5 On Your Side that her partner was held past his release date because of the cyber-attack.

“I keep being told that the jail is on lockdown because there has been a system failure since last Saturday, and I want to know what’s going on,” said the anonymous woman. “Nobody can get released. Nobody can post bond. They can’t check out any information.” 

County Information Technology Director Jeff Sandusky said: “Beginning around May 28, St. Clair County became aware of a cybersecurity incident involving our computer systems.

“We immediately responded to secure our systems and commence an investigation into the nature and scope of the incident.” 

The county notified appropriate law enforcement authorities of the incident and said it has been “working diligently with industry-leading third-party cybersecurity specialists to investigate the source of this disruption and confirm the impact on our systems.”

Sandusky added that the county has dedicated substantial resources to gauging the attack’s full scope and will provide relevant updates as the findings emerge. 

The county’s website via www.co.st-clair.il.us was restored by June 4, but some services remain unavailable.

Grief is an emerging ransomware group, which claims to have swiped data from at least five entities, including Mobile County, Alabama, and HDHC Home Decor. 

Screenshots of the group’s website in the TOR network show the group claims to have purloined 2.5 gigabytes of data from St. Clair. Internal company documents and personal and customer information are among the allegedly stolen data.

Grief emerged at around the same time as another new ransomware gang, Prometheus, which claims to have ties to REvil. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#Infosec21: Cybersecurity to Become a “Matter of Life and Death”

#Infosec21: Cybersecurity to Become a “Matter of Life and Death”

The internet is both “the best and worst innovation of our time,” and as reliance on it grows, our ability to secure it could become a matter of life and death. This is according to Mikko Hypponen, researcher at F-Secure, speaking during the keynote session on Day 1 of the Infosecurity Europe virtual conference.

Hypponen firstly outlined how threat actors have changed significantly since he started working in the industry in 1991. Back then, “viruses and other kinds of malware we were finding were all written by teenage boys,” just for fun. At that point he could never have envisioned today’s scenario, in which the main threat actors are highly sophisticated organized crime groups and governments.

This change has been brought about by the internet revolution, according to Hypponen. He noted that the “first wave” of this is now over, in which all computers are online, and we are currently in the midst of the second, in which “everything else” becomes connected. These include smart devices and even more significantly, devices that don’t even require an internet connection, such as kitchen radios. This will be purely for the purpose of manufacturers to obtain diagnostics information.

Hypponen believes that as this process carries on, and more areas become interconnected, the internet will become as essential to society as electricity is today. “When technology is useful enough, we can’t live without it,” he commented. Currently, he observed that internet outages are an inconvenience but generally, not a matter of life and death. However, Hypponen expects it will reach this status within the next 20-30 years. “If your network cuts out it is going to be just as bad as getting your power cut,” he said, adding that in fact one day “when we have an internet outage, it’s going to cut power.”

“If your network cuts out it is going to be just as bad as getting your power cut”

In this landscape, the challenge for the cybersecurity industry “is to make sure the connectivity stays online regardless of the attacks that might be launched against it.” This is going to be very difficult – Hypponen highlighted how the internet has become a major vehicle for cybercrime and other malicious activities in recent years. Preventing these is to some extent a thankless task for cybersecurity professionals, with no credit given for stopping attacks, while failure to prevent incidents is highly visible.

Hypponen went to describe the changing threat landscape since the start of the COVID-19 pandemic. Many organizations that have shifted to remote working are now far more vulnerable to being breached, largely because a substantial number of corporate file servers have moved from internal networks to the public internet and are “only protected by usernames and passwords.”

Another trend he observed is that there has been a sharp rise in attacks on healthcare organizations over the past 15 months, including hospitals, clinics and research facilities. Previously, Hypponen didn’t see these types of bodies as prime targets for cyber-criminals, as they were not particularly lucrative compared to other sectors such as finance. This appears to be changing, with institutions like hospitals viewed by many threat actors as more likely to pay ransoms when their systems are encrypted or medical data stolen.

The last year or so has also seen the rise of double extortion ransomware attacks, also known as ransomware 2.0, where in addition to locking systems, malicious actors steal data and threaten to release it if a fee is not paid. This tactic has proved very successful, according to Hypponen, who gave the example of the Maze ransomware gang, which reportedly retired from operating in October 2020 as a result of the financial gain they have made from their attacks. He commented: “This is exactly what we don’t want to happen – we don’t want high tech lowlifes to be successful,” and encourage more people to go down this pathway.

Another area discussed in Hypponen’s address was supply chain attacks, which he said was particularly favored by nation-state actors, “looking for very specific victims” for espionage purposes. Unlike cyber-criminals, these actors will not deviate from their target if it becomes difficult to get into a system, and will therefore look for alternative routes, as demonstrated by the recent SolarWinds incident.

The root cause of these kinds of attack vectors “is always either a technical problem or a human problem,” noted Hypponen. While technical problems, such as unpatched servers, can be solved, albeit with difficulty, human error, like falling for phishing scams, is another matter. He stated: “There’s no patch for human brains.”

In the view of Hypponen, the solution is to become less reliant on humans in cybersecurity in general. For example, in the future, he believes machine learning will be used to write code, removing the need for human programmers. “When we have advanced, powerful systems writing all the code around us, there will be less Bucks, which means there will be less vulnerabilities,” he outlined.

On flip side, one day we could see machine learning be used by malicious actors to write malware. However, Hypponen noted that there is research being undertaken today looking at how this potential threat can be mitigated.

Concluding, Hypponen said that his 30-year career in cyber had demonstrated to him “how hard it is to forecast the future.” He added that we are living in an age of technological revolution and these advances are both the best and worst thing to happen in our lifetime.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Large Parts of Internet Offline Following Cloud Provider Issue

Large Parts of Internet Offline Following Cloud Provider Issue

Large parts of the internet were temporarily offline today, including Amazon, Reddit and Twitch, it has been reported. Other significant organizations whose websites were affected by the incident included media outlets the Financial Times, The Guardian and New York Times and the UK’s Gov.uk. When users attempted to enter these websites, they were met with messages like “Error 503 Service Unavailable” and “connection failure.”

Experts have traced the issue to a Fastly content delivery network (CDN) failure, which underpins many major websites. Fastly is a cloud computing services provider that runs an “edge cloud” designed to speed up loading times for websites, protect them from denial-of-service attacks and help them deal with bursts of traffic.

The Guardian reported that the outage started at around 11 am BST, lasting for approximately 30 minutes.

While the failure brought some websites down entirely, specific sections of other services were also damaged. These include the servers on Twitter that host the social network’s emojis.

The affected websites now appear to back online, and at around 12.10 BST, Fastly tweeted: “We identified a service configuration that triggered disruptions across our POPs globally and have disabled that configuration. Our global network is coming back online.” The company has also provided continuous updates about the issue on its service status pages.

Security experts were quick to express their concerns about the failure in Fastly’s system, as it highlights the reliance many organizations have on CDN infrastructure for the running of their websites and may provide opportunities for cyber-criminals to strike. Michael Barragry, operations lead and security consultant at edgescan commented: “CDNs have become ubiquitous in today’s web. Although they are primarily used to ensure smooth delivery of resources so that websites can perform optimally, they also often supply additional security features such as WAF-like traffic filtering and DDoS protection.

“The exact nature of this “issue” is unclear, but given how vast the impact appears to be, it looks to have transcended any failover or redundancies that were in place. This outage could also represent a window of opportunity for further attacks – especially against those sites which have an over-dependence upon CDN infrastructure for their security. Additional independent security layers should be used where appropriate to ensure that no single point of failure is present.”

Sergio Loureiro, cloud security director at Outpost24, said: “We have yet to gain insights into what exactly lead to this global outage. Based on the Fastly status pages, all their content delivery systems are affected by this issue. This global outage that affects many high-profile companies does highlight the dependency we have on cloud services and their availability. This directly impacts many businesses, including for example Reddit who’s entire business is based around their website.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Evil Corp Rebrands Ransomware to Escape Sanctions

Evil Corp Rebrands Ransomware to Escape Sanctions

Threat actors behind a notorious Russian cybercrime group appear to have rebranded their ransomware once again in a bid to escape US sanctions prohibiting victims from paying them.

Experts took to Twitter to point out that a leak site previously run by the Babuk group, which famously attacked Washington DC’s Metropolitan Police Department (MPD), had rebranded to “PayloadBin.” The Babuk group claimed that it was shutting down its affiliate model for encrypting victims and moving to a new model back in April.

A ‘new’ ransomware variant with the same name has also been doing the rounds of late, but according to CTO of Emsisoft, Fabian Wosar, it’s nothing more than a copycat effort by Evil Corp.

“Looks like EvilCorp is trying to pass off as Babuk this time. As Babuk releases their PayloadBin leak portal, EvilCorp rebrands WastedLocker once again as PayloadBin in an attempt to trick victims into violating OFAC regulations,” he said.

If that’s correct, it would appear to be the latest in a long line of rebranding by the group from its original BitPaymer effort in a bid to circumvent US sanctions.

Michael Gillespie, the creator of the ID Ransomware service, explained that aside from WastedLocker, the group has used “Hades” and “Phoenix” as new names for the same malware.

Wosar said it was easy to identify the same underlying code in all of those ‘variants.’

“EvilCorp malware sticks out like a sore thumb simply because of the obfuscator they use,” he tweeted. “But the cryptographic scheme is identical, encrypted file format is identical, MO is identical, configuration format is identical, the list goes on and on.”

The group was placed on the US Treasury’s Office of Foreign Assets Control (OFAC) sanctions list in December 2019 after being accused of using the Dridex banking Trojan to steal over $100 million globally.

That meant corporate victims were effectively prohibited from paying the group a ransom or risk themselves being accused of breaking sanctions.

Mitch Mellard, a threat intelligence analyst at Talion, argued that rebranding could be widespread in the underground economy.

“I feel that this situation is somewhat of an indictment of ransomware insurance as a whole. We have reached the point where instead of blanket condemnation of paying ransoms across the board, two lists of criminals have been created,” he added.

“The first list is comprised of actors who have achieved such renown that paying them is actually treated as … paying criminals. The second list is, by nature of its contents, also entirely criminals, but those who it is somehow acceptable to reward monetarily for their illegal activities.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

French Antitrust Regulator Slaps $268 Million Fine on Google

French Antitrust Regulator Slaps $268 Million Fine on Google

The French antitrust regulator has fined Google €220 million ($268 million) for abusing its dominant position in the online advertising market.

The fine, which Google has not disputed, was levied because the tech giant favored its own Google Ad Manager technologies.

This put competitors — such as publishers News Corp, Le Figaro group and the Rossel La Voix group, who brought the initial complaint — at a disadvantage, according to the Autorité de la concurrence.

The proprietary technologies in question were the DFP ad server — which allows site and app publishers to sell their advertising space — and the SSP AdX sales platform — which enables publishers to sell impressions to advertisers.

Autorité de la concurrence president, Isabelle de Silva, argued that this investigation was the first to look into the algorithmic processes by which online display advertising works.

“The particularly rapid investigation revealed processes by which Google, building on its considerable dominance in ad servers for websites and applications, outperformed its competitors on both ad servers and SSP platforms,” she added.

“These very serious practices penalized competition in the emerging online advertising market, and allowed Google not only to maintain but also to increase its dominant position. This sanction and these commitments will make it possible to re-establish a level playing field for all players, and the ability for publishers to make the most of their advertising space.”

Google France legal director, Maria Gomri, said the firm had “agreed on a set of commitments to make it easier for publishers to make use of data and use our tools with other ad technologies.”

These will be tested and developed over the coming months, with some changes set to be rolled out globally, she added.

Google has been on the receiving end of multiple fines in Europe over recent years, most notably a $1.7 billion antitrust penalty from the European Commission in 2019 — again for abusing its dominant position in the online advertising market.

The tech behemoth was also one of the first to receive a major GDPR fine, when the French regulator CNIL imposed a €50 million penalty for failing to notify users about how their data is used.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

DoJ Seizes Millions in Ransom Paid by Colonial Pipeline to Darkside Hackers

DoJ Seizes Millions in Ransom Paid by Colonial Pipeline to Darkside Hackers

The US authorities have scored a rare win in the fight against ransomware after claiming to have seized the majority of the funds paid to Russian ransomware hackers by Colonial Pipeline.

The Department of Justice (DoJ) announced on Monday that it had been able to track and access 63.7 out of the 75 Bitcoins paid by the East Coast fuel transportation company to the DarkSide gang. That amounts to roughly $2.3 million of the $4.4 million reportedly paid to the extorters.

The news is a coup for the newly launched DoJ Ransomware and Digital Extortion Task Force, which coordinated the operation.

Law enforcers were apparently able to review the public Bitcoin ledger and track the transfers to a specific address, for which the FBI had a private key, enabling it to access and seize the funds.

Deputy attorney general, Lisa Monaco, argued that “following the money” is still one of the most powerful tools investigators have in tracking down and disrupting cybercrime.

“Ransom payments are the fuel that propels the digital extortion engine, and today’s announcement demonstrates that the United States will use all available tools to make these attacks more costly and less profitable for criminal enterprises,” she added.

“We will continue to target the entire ransomware ecosystem to disrupt and deter these attacks. Today’s announcements also demonstrate the value of early notification to law enforcement; we thank Colonial Pipeline for quickly notifying the FBI when they learned that they were targeted by DarkSide.”

Experts welcomed the news.

“It has become clear that we need to use several tools to stem the tide of this serious problem, and even law enforcement agencies need to broaden their approach beyond building cases against criminals who may be beyond the grasp of the law,” argued John Hultquist, VP of analysis at Mandiant Threat Intelligence.

“In addition to the immediate benefits of this approach, a stronger focus on disruption may disincentivize this behavior, which is growing in a vicious cycle.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk