Influencers Offered Money to Vilify Vaccine

Influencers Offered Money to Vilify Vaccine

A public relations agency in the UK has allegedly offered social media influencers money to portray the Covid-19 vaccine created by Pfizer-BioNTech as highly dangerous. 

Fazze allegedly offered to pay French and German bloggers, influencers and YouTubers to tell their followers that the vaccine had caused hundreds of deaths. 

Over 285 million doses of COVID-19 vaccines were administered in the United States from December 14, 2020, through May 24, 2021. During this time, the CDC’s Vaccine Adverse Event Reporting System (VAERS) received 4,863 reports of death (0.0017%) among people who received a COVID-19 vaccine.

On its website, Fazze describes itself as a “marketplace that connects bloggers and advertisers.” The Guardian reports that Fazze claimed to be headquartered at 5 Percy Street in London but is not registered at this address. 

It is alleged that Fazze contacted several French health and science YouTubers last week, asking them to share the false claim that the Pfizer vaccine is three times more deadly than the COVID-19 vaccine developed by AstraZeneca.

The influencers were instructed to present the lie as their own independent view. They were also told to publish links on Instagram, TikTok or YouTube to reports in French newspaper Le Monde, on Reddit and on the Ethical Hacker website that Fazze said contained data substantiating this claim. 

The Reddit and Ethical Hacker articles have been removed from the sites, and the piece in Le Monde contains no information about mortality rates associated with either vaccine. 

It is alleged that Fazze told the influencers to tell their followers that the dangers of the Pfizer vaccine were being ignored by mainstream media, and to question the wisdom of governments who purchased it. 

Mirko Drotschmann, a German YouTuber and podcaster with 1.5 million subscribers, and Léo Grasset, a French science YouTuber with nearly 1.2 million subscribers, both said that they had been approached and asked to disparage the vaccine. 

Both influencers shared screenshots of emails they had received. The missive sent to Drotschmann states: “I am engaged in an information campaign regarding the Covid-19 vaccine. The data leak showed a significant number of deaths after the Pfizer vaccination. We would like to invite you to share this information link…”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber-criminal Gang Targets Texas Unemployment System

Cyber-criminal Gang Targets Texas Unemployment System

A gang of Nigerian cyber-criminals has shared a step-by-step guide detailing how to commit unemployment identity fraud in the Lone Star State, according to CBS News

Organized cybercrime group Scattered Canary is already suspected of making millions defrauding the states of Hawaii, Florida, Massachusetts, North Carolina, Oklahoma, Rhode Island, Washington and Wyoming.

Now the gang has allegedly circulated a 13-page tutorial explaining how to successfully defraud the Texas Workforce Commission website. 

Evidence shared with the news channel’s CBS 11 I-Team appears to show this highly detailed guide being shared online in a closed group chat that took place between multiple gang members.

With the help of an insider, private cybersecurity firm Agari managed to obtain a copy of the document from a WhatsApp group chat. 

Former FBI agent Crane Hassold, who is now employed as Agari’s director of threat research, said: “For these cyber-criminals it’s all about information flow.” 

“The tutorial shows how to apply for unemployment benefits and even introduces some of the red flags if you enter things a certain way.”

Texas has lost more than $893m to fraudulent unemployment benefits since the start of the global COVID-19 pandemic. The Texas Workforce Commission said it has been targeted by scammers from all over the world.

Hassold said Scattered Canary are exploiting a feature in Gmail to speed up their fraudulent activity.

Because Google ignores periods in Gmail addresses, slight variations of a single email address can be used to file multiple fraudulent claims without raising the suspicion of state unemployment systems. 

For example, three claims filed using the addresses john.doe@gmail.com, j.ohndoe@gmail.com,” and “j.o.h.n.d.o.e@gmail.com” appear to belong to three separate individuals but are all attached to the same email account.

“Essentially it allows their communication flow to be much more efficient,” said Hassold.

“Instead of having to go to dozens of different email accounts to look at what’s going on, it’s all coming to one centralized location.”

Scattered Canary is suspected of funneling the money it nets through fraudulent claims offshore by using it to purchase prepaid Green Dot cards. The cards are registered using the same identities stolen when committing the unemployment fraud.

Before the cards are delivered via the mail, the gang goes online and drains the money from the account.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

22 Americans Indicted Over Card-Skimming Scam

22 Americans Indicted Over Card-Skimming Scam

Nearly two dozen Americans have been indicted in connection with a card-cloning scam that targeted a national retail chain headquartered in Chicago, Illinois. 

In 2016 and 2017, a malicious software program was installed on multiple computers belonging to the unnamed retailer, which sold clothing, electronics, toys, furniture and home decor. 

This malware allowed a co-conspirator to capture the data of more than three million credit cards, debit cards and gift cards that were used in-store at 400 of the retailer’s branches. 

Data stolen using the card-skimming software was then sold by the co-conspirator to another individual for $4m in Bitcoin. The money was transferred over the course of approximately 66 transactions.

This next link in the criminal chain offered the stolen information for sale on two different websites to over 3,000 users. 

An indictment unsealed May 25 in the Northern District of Illinois accuses 22 individuals from nine different states of purchasing that data. Most of the defendants are in their late 20s or early 30s and reside in California or New York state. 

It is alleged that the defendants used the data they purchased to buy items at businesses across America, including gas stations, hotels and restaurants. The illegal activity allegedly occurred between August 2016 and July 2020. At least 80 people living in Illinois were victimized as a result.

All but two of the defendants named in the indictment were arrested this month and have entered the federal court system. The defendants who remain at large are believed to have moved overseas. 

The Department of Justice said that the investigation into the card-skimming scam remains ongoing.

Typically, the defendants are accused of purchasing the payment card data of between 1,000 and 2,000 skimmed cards. However, one defendant, 35-year-old Barry Shi of Rosemead, California, allegedly bought the data of at least 18,742 payment cards, including at least 13,249 that were used at the Chicago retailer’s stores, in exchange for around $507,273 in Bitcoin. 

Wire fraud is punishable by up to 20 years in federal prison, while aggravated identity theft carries a mandatory, consecutive prison sentence of two years.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NHS to Share Patient Data with Third Parties, Fueling Privacy and Security Fears

NHS to Share Patient Data with Third Parties, Fueling Privacy and Security Fears

NHS patient data in England will be shared with third parties for research and planning purposes, fueling concerns about privacy and security, it has been reported today.

The Financial Times revealed that NHS Digital, which runs the health service’s IT systems, will create a database containing the medical records of around 55 million patients in England who are registered with a GP clinic. This includes sensitive data on mental and sexual health, criminal records and abuse.

This information will subsequently be made available to academic and commercial third parties involved in research and planning, although no details on the types of organizations that will have access have been provided.

The initiative follows suggestions that the UK’s response to the COVID-19 pandemic was hampered by lack of data sharing and access, including in a report published this year by the House of Commons Science and Technology Committee.

Patients will need to fill in a form and take it to their GP to opt out of the scheme by June 23, otherwise their historical records will become a permanent and irreversible part of the new data set. Any patients who opt out after this date will prevent any future data becoming part of the new system.

The idea for a database of this kind was first set out by UK Health Secretary Matt Hancock in April, and explained in blogs on the NHS website. This emphasized that patients will not be directly identified in the data set.

The plans have received significant criticism from privacy campaigners. The Financial Times cited a letter from Foxglove, a campaign group for digital rights, to the Department of Health and Social Care, questioning the legality of the proposals under current data protection legislation. Rosa Curling, a solicitor at the organization who penned the letter, wrote that “very few members of the public will be aware that the new processing is imminent, directly affecting their personal medical data.”

Cybersecurity experts have also warned that the database will be a tempting target for cyber-criminals. George Papamargaritis, MSS director at Obrela Security Industries, commented: “It is not surprising that the NHS is facing backlash in response to this move. Sharing medical data with third parties is very risky as there is no way to be sure they will have the proper security tools in place to keep the data safe. While it looks like the NHS has plans to anonymize patient data, this is not a 100% guarantee of security protection.”

David Sygula, senior cybersecurity analyst at CybelAngel, said: “This move from the NHS provides some strong benefits from an academic research standpoint. An initiative like this could have been useful in better controlling the magnitude of the pandemic, and all research work that goes with it. 

“However, data collection on this scale is creating a new set of risks for individuals, where their Personal Health Information (PHI) is exposed to third-party data breaches. The extent of the unsecured database problem is growing. It’s not simply an NHS issue, but the NHS’ third, fourth or further removed parties too, and how they will ensure the data is securely handled by all suppliers involved. These security policies and processes absolutely need to be planned well in advance and details shared with both third parties and individuals. 

“Several mechanisms must be put in place, starting with the anonymization of data, as data leaks will inevitably happen. Security researchers, attackers, and rogue states have all put in place processes to identify unsecured databases and will rapidly find leaked information. That’s the default assumption we should start with. It’s about making sure patients are not personally exposed in case of a breach, while setting up the appropriate monitoring tools to look for exposed data among the supply chain.”

NHS England previously tried to store all GP patient information in a central database back in 2013 in a project called Care.data, which was subsequently abandoned in 2016 due to privacy concerns.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Police Suffered Thousands of Data Breaches in 2020

UK Police Suffered Thousands of Data Breaches in 2020

There were over 2300 data breach incidents reported by just 22 of the UK’s police forces in 2020, according to new Freedom of Information data.

VPNoverview requested information from the UK’s 45 police forces and received responses from 31.

All told, the results revealed a national average of 299 data breaches per police station over the period dating from 2016 to the first four months of 2021.

This included a combination of human error — for example, staff emailing sensitive information to the wrong recipient — and malicious third-party attacks.

There was no breakdown in the report indicating which accounted for the majority of cases. However, separate FoI data from 23 forces obtained in 2019 revealed that 237 officers and staff members were disciplined, six resigned during investigations and 11 were sacked for computer misuse offenses over the previous two years.

Many of these involved accessing police databases unlawfully to search for individuals.

The VPNoverview study did reveal the best and worst offenders of the past four years. Lancashire Constabulary topped the list of forces suffering most incidents over the period (1300), followed by nearby Cheshire Constabulary (1193), Sussex Police force (980) and the Police Service of Northern Ireland (928).

Five forces reported fewer than 10 incidents from 2016-21 while London’s Metropolitan Police and Dorset Police claimed to have suffered no breaches in over four years.

Sussex Police has already recorded 62 data breach incidents so far in 2021, followed by West Midlands Police (37), North Wales (24) and Wiltshire Constabulary (12).

A Big Brother Watch study from 2016 found that UK police suffered more than 2300 breach incidents over the previous four years as a result of insiders abusing their position.

A year previously, South Wales Police was fined £160,000 after it misplaced unencrypted DVDs containing a highly sensitive video recording of an interview with a sex abuse victim.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Bose Reveals Ransomware Attack Impacting Staff

Bose Reveals Ransomware Attack Impacting Staff

Bose has told regulators that a sophisticated ransomware attack back in March led to unauthorized access of personal information on current and former employees.

The US audio tech giant told the New Hampshire Office of the Attorney General that it first detected the ransomware back on March 7 2021. However, nearly two months later, on April 29, it found that human resources files were accessed.

“The personal information contained in these files include name, Social Security Number, and compensation-related information,” it continued.

“The forensics evidence at our disposal demonstrates that the threat actor interacted with a limited set of folders within these files. However, we do not have evidence to confirm that the data contained in these files was successfully exfiltrated, but we are also unable to confirm that it was not.”

The firm said it had engaged third-party experts to scour the dark web for this data, to check if it is being actively used by cyber-criminals, and is also working with the FBI.

“Bose has not received any indication through May 19, 2021 its monitoring activities or from impacted employees that the data discussed herein has been unlawfully disseminated, sold, or otherwise disclosed,” it added.

Only a small number of staff were affected and the firm is not thought to have paid the ransom.

However, it disclosed to the regulator a long list of remedial actions taken by its security team to mitigate the risk of a worse attack in the future.

This included: enhanced anti-malware, logging and monitoring; blocking of malicious IPs linked to the threat actor; changing passwords for all end users; and changing access keys for all service accounts.

Robert Golloday, EMEA and APAC director at Illusive, praised Bose for its transparency.

“Kudos for not paying a ransom and for having the appropriate backups in place. With that said, the time to put in controls for early detection and prevention of lateral movement is before these attacks occur, not after,” he added.

“It’s another unfortunate example of an ever-widening criminal enterprise.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Europe’s Top Human Rights Court Rules UK Mass Surveillance Illegal

Europe’s Top Human Rights Court Rules UK Mass Surveillance Illegal

Privacy groups are celebrating after winning an eight-year battle to prove the UK government’s mass surveillance regime violated human rights.

A ruling by the top court of the European Court of Human Rights yesterday noted that the regime first exposed by Edward Snowden in 2013 violated rights to privacy and freedom of expression.

Three main issues were highlighted by the judges: that bulk interception was authorized by the secretary of state and not an independent party; categories of search terms related to the type of comms to be extracted weren’t included in the warrant application; and that identifiers linked to individuals were not subject to prior authorization.

However, the European court fell short of ruling that bulk interception of communications is illegal in and of itself, claiming instead that stronger safeguards should have been put in place.

The judgement by the Grand Chamber goes further than the European Court of Human Rights’ 2018 ruling, by adding a new requirement of prior independent or judicial authorization for bulk interception of communications, Privacy International argued.

“Today the court reiterated that intelligence agencies cannot act on their own, in secret and in the absence of authorization and supervision by independent authorities,” noted the group’s acting legal director, Ilia Siatista.

“They must be accountable because their capabilities to access personal data about each and every one of us — even if we’re not suspected of any wrongdoing – pose serious risks in a democratic society.”

The case combined three separate challenges from 16 groups and individuals and challenged three different UK surveillance programs: the bulk interception of communications; intelligence sharing; and obtaining communications data from service providers.

The groups argued that the metadata collected by UK digital spy agency GCHQ could reveal intimate secrets of individuals’ personal lives, including where they go, who they contact and which internet sites they visit and when.

The UK government has said its new regime, brought in with the controversial 2016 Investigatory Powers Act or “Snooper’s Charter,” has added safeguards to the process.

However, according to reports, the European judgement will now pave the way for a legal challenge to the law to proceed through the UK courts.

This could have implications for the UK’s much-needed data adequacy decision from the EU. The European Parliament last week sent back the Commission’s draft decision on data protection, asking for better protection for EU citizens from UK mass surveillance.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk