#RSAC: The Lasting Impact of the COVID Pandemic on Privacy

#RSAC: The Lasting Impact of the COVID Pandemic on Privacy

The pandemic has forever changed people’s relationship with technology, and with it their expectations of user privacy, according to a pair of privacy experts speaking at the 2021 RSA Conference on May 19.

Julie Brill, chief privacy officer at Microsoft, noted that during the pandemic increasing numbers of people came to realize that they can work from home, learn from home, and socialize and still be deeply productive. With that increased reliance on technology has come growing awareness and concern about the privacy implications of different technologies and online services.

“People are saying more and more that they’re concerned about how their data is being used and that they want more privacy,” Brill said. “They want companies to do more, and they want governments to do more, to ensure that their data is well protected.”

While access to online services has been a way of life during the pandemic, Brill emphasized that the pandemic should not be the reason why people are being asked to give up their privacy. In her view, it should be the case that companies that are providing online tools to schools, community groups and other end users need to be thinking about ensuring they are providing trusted technology.

In the absence of a comprehensive privacy law, which is still the state of affairs in the US, Brill said that it’s critical that groups and individuals can trust the technologies they are using to go about daily life.

People’s relationship to who they are and how they want to be portrayed has often been framed in the context of control, empowerment and engagement.Julie Brill

Defining Privacy Harm

A key challenge with privacy is precisely determining how it is violated in the eyes of the law, in terms of harm that can occur that is quantifiable, according to Danielle Citron, Jefferson Scholars Foundation Schenck Distinguished Professor in Law at the  University of Virginia.

Citron observed that existing privacy laws in the US are not well suited to the problems of the 21st century. She noted that privacy laws that exist were made in an era when there was mass media publishing stories about people and advertisers using someone’s face without permission.

“Now so many of our 21st-century problems are about the collection, the use and the sale of information,” Citron said. “Tort law and civil claims haven’t quite caught up, and courts really insist upon really tangible harms that are financial and physical.”

The Promise of Privacy Laws

In Brill’s view, emerging standards and privacy laws such as the European Union’s GDPR are positive steps.

While there isn’t yet a national data privacy rule in the US, there are currently multiple rules in different states, including California and Virginia, with more to come in the months ahead. Brill said that she sees a lot of hopes and aspirations for privacy laws for a few reasons.

Brill commented that privacy laws are about choosing when the individual wants to engage and having the ability to choose how their personal data is used. In her strong view, privacy is a fundamental right and foundational to other basic human rights.

“People’s relationship to who they are and how they want to be portrayed has often been framed in the context of control, empowerment and engagement,” Brill said. “And when you really think about it, that’s what privacy laws are about.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#RSAC: SolarWinds CEO Provides New Details into Attack and Response

#RSAC: SolarWinds CEO Provides New Details into Attack and Response

New details into the notorious SolarWinds nation-state attack and its fallout were provided by Sudhakar Ramakrishna, CEO of SolarWinds, during a keynote session on Day 3 of the virtual RSA Conference 2021, which was hosted by Laura Koetzle, VP and group director at Forrester.

This included the revelation that the attackers may have accessed the system as early as January 2019, and an expression of remorse for comments made during his congressional appearance about the attack in February 2021.

Starting the session, Ramakrishna explained that he was first informed of the attacks while sitting down to his birthday dinner on December 12, 2020, after receiving a phone call from the company’s legal officer. Ramakrishna was at the time still waiting to take up the position of CEO at SolarWinds on January 4, 2021.

Koetzle asked Ramakrishna whether he ever considered backing out of taking the role as more details about the scale of the incident emerged in the following days. While a number of friends had advised him to do so, Ramakrishna said that “he decided to persevere with this opportunity” after speaking to the SolarWinds chairman, Bill Bock. He was given continuity and support from the previous CEO, Kevin Thompson, as he began the role in January, which helped him enact a fast response to the event.

With SolarWinds believing as many as 18,000 of its customers had been affected by the breach, as that was the number that had downloaded the malicious update, Ramakrishna explained that in the immediate aftermath, the SolarWinds security team looked to contact everyone possible to try to address their concerns and questions.

He was also asked about how SolarWinds is supporting its customers now. Ramakrishna explained it was a step-by-step approach. “What started out as a reactive measure turned into learning about and addressing issues, and at the foundation of what we’re trying to do is transparency,” he said, adding that the company had worked with its global partners to develop the Orion Assistant Program. This offers extra support to those customers that do not have the resources to upgrade or rebuild, and “in many cases [involved] working side by side with them as they completed their upgrades.”

“The foundation of what we’re trying to do is transparency”

Ramakrishna noted that his previous experience in dealing with security incidents as CEO at Pulse Secure has helped him deal with the fallout of the SolarWinds attacks. In these prior incidents, the response “was rooted in being transparent, being communicative and updating everybody on progress, even at times when you do not have all the details in place.”

The discussion then moved on to the details that have subsequently been discovered about the attack. When asked exactly how the attackers were able to stay undetected for such a long period of time, Ramakrishna emphasized the sophisticated nature of the perpetrators. “The tradecraft that the attackers used was extremely sophisticated where they did everything possible to hide in plain sight,” he explained, adding that “they were able to cover their tracks at every step of the way. Given the resources of a nation-state, it was very difficult for one company . . . to uncover.”

Interestingly, Ramakrishna said that SolarWinds has since “stumbled across” some old configurations of code, which enabled it to figure out what the attackers did. After assessing “hundreds of terabytes of data and thousands of virtual build systems,” it was discovered “that the attackers may have been in the environment as early as January 2019,” which is much earlier than initially thought. “They were doing very early reconnaissance activities in January 2019, which explains what they were able to do in September/October 2019,” he added.

When reflecting on his, and SolarWinds’, response to the attacks, Ramakrishna expressed regret for comments he made during his testimony to Congress in February 2021, which concerned the exposure of a weak FTP password by an intern at the company back in 2017. He outlined: “I have long held a belief system and an attitude that you never flog failures – you want your employees, including interns, to make mistakes and learn from those mistakes . . . so what happened at the congressional hearing where we attributed it to an intern was not appropriate and is not what we are about.”

Finally, Ramakrishna revealed that another way the company’s response could have been improved was to have coordinated a better media response, stating it was not prepared for being thrust into the limelight in the way it was. “I wish we had more resources, more proactive outreach. We’ve learned from that and we continue to grow our communications team,” he outlined.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UHS Data Breach Lawsuit Proceeds

UHS Data Breach Lawsuit Proceeds

A lawsuit filed against an American healthcare provider over a 2020 data breach has been allowed to proceed, but only for one patient. 

The patient, Stephen Motkowicz, claims that his surgery was canceled as a result of a ransomware attack and subsequent data breach at Universal Health Services (UHS). 

UHS employs around 90,000 people at the approximately 400 care centers and hospitals it operates in the United Kingdom, Puerto Rico, and the United States.

Sensitive data belonging to UHS was exfiltrated in September last year when the company was targeted by the Ryuk ransomware gang. 

All UHS sites in Puerto Rico and the US were affected by the cyber-attack, which caused the company’s IT systems to go offline for a month. Some scheduled appointments were postponed as a result. 

The Fortune 500 healthcare organization said in March that the attack had cost it an estimated $67m  in downtime and related expenses.

The law firm Morgan & Morgan filed a lawsuit in the US District Court, Eastern District of Pennsylvania against UHS on behalf of three patients who accused the healthcare company of negligence, breach of implied contract, breach of fiduciary duty, and breach of confidence. 

Claims made by two of the plaintiffs who said that the data breach had made them vulnerable to fraud and identity theft were dismissed by US District Judge Gerald McHugh as too speculative in an opinion filed Monday. 

However, McHugh adjudged that Motkowicz had sufficient grievance to proceed. When Motkowicz’s surgery was canceled because of the attack, he was forced to take additional time off work. This caused him to lose his health insurance through his employer, with the result that he had to purchase an insurance policy at a higher price.

Referring to the two claimants whose claims he dismissed, McHugh said: “A court is still left to speculate . . . whether the hackers acquired plaintiffs’ (private health information) in a form that would allow them to make unauthorized transactions in their names, as well as whether plaintiffs are also intended targets of the hackers’ future criminal acts.”

Of Motkowicz, McHugh said: “Plaintiff’s injury is not speculative, as his financial expenditures allegedly occurred in response to the data breach and the corresponding cancellation of his surgery.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Splunk to Acquire TruSTAR

Splunk to Acquire TruSTAR

California tech company Splunk has announced its intentions to acquire San Francisco–based cloud-native security firm TruSTAR.

The Data-to-Everything Platform providers shared news of their proposed acquisition on Tuesday. The terms of the deal have not been disclosed.

TruSTAR was founded in 2016 by Patrick Coughlin and Paul Kurtz on the mission to make threat detection and response simpler and more efficient. The company has more than 50 clients, including BNP Paribas, LogMeIn and Rackspace. 

“They share our passion for the value of data and the power of turning data into doing,” said Splunk’s senior vice president, cloud and chief product officer, Sendur Sellakumar.

“I’ve been very impressed with the growth not only of their solution but of their business.”

Sellakumar went on to identify three core principles that Splunk and TruSTAR share. The first of these was the view that organizations “need a unified, data-centric view across their cloud environments, paired with the right analytics at the right time, for intelligent detection and response.”

According to Sellakumar, both companies also hold the notion that the most effective way to accelerate efficiencies in the SOC is “to prioritize data with a focus on automation, improving your MTTD and MTTR outcomes.”

The third principle to which TruSTAR and Splunk adhere is that “managing and integrating internal and external sources of intelligence accelerates outcomes across the security operations lifecycle, delivering customers critical and timely value,” said Sellakumar.

TruSTAR is known for its Intelligence Platform, through which its customers can operationalize all sources of security intelligence across their teams, tools and partners.

Should the acquisition go ahead as planned, TruSTAR’s capabilities will be added to the Splunk Data-to-Everything Platform, allowing customers to autonomously improve their detection and response workflows with information from third-party threat intelligence sources as well as from their internal historical intelligence.

“We founded TruSTAR to help security teams unlock the signal in their data to accelerate automation and power seamless intelligence sharing while preserving privacy in the cloud,” said TruSTAR CEO Coughlin.

“We’re thrilled to join Splunk. Combining TruSTAR with Splunk’s leading enterprise data platform will bring security and IT teams to a new level of integration, automation and resilience.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

DarkSide Gang Retires on $90m

DarkSide Gang Retires on $90m

The ransomware gang DarkSide extorted more than $90m in Bitcoin before allegedly disbanding its illegal operation, according to new research.

Analysts at London-based blockchain analytics firm Elliptic said in a report published Tuesday that they had discovered a now empty digital wallet that had contained the proceeds of ransomware attacks engineered by the cyber-criminal gang.

“In total, just over $90m in Bitcoin ransom payments were made to DarkSide, originating from 47 distinct wallets,” wrote Elliptic’s co-founder and chief scientist, Dr. Tom Robinson.  

“According to DarkTracer, 99 organizations have been infected with the DarkSide malware – suggesting that approximately 47% of victims paid a ransom, and that the average payment was $1.9m.”

DarkSide has appeared in the news numerous times for its cyber-attacks, but the gang achieved real infamy earlier this month when it crippled America’s Colonial Pipeline with ransomware. From this exploit, which triggered panic buying and fuel shortages along the East Coast, the gang reportedly netted $5m.

Elliptic researchers report that DarkSide’s virtual wallet received a ransom payment of 75 Bitcoin from Colonial Pipeline. 

The gang shut down its site on the dark web on May 13. Researchers at cybercrime intelligence provider Intel 471 reported that DarkSide had told its hacking partners who use the gang’s “ransomware-as-a-service” tools to launch cyber-attacks that sales of its software and released services have ceased.

Before closing its digital doors, DarkSide appeared to be on track to achieve its most profitable month of the last three quarters. 

Elliptic researchers found that since October 2020, February had seen the gang collect its biggest Bitcoin haul of more than $20m. May’s earnings were close to $15m before DarkSide went dark.

Researchers noted that money extorted by the gang was divided up between those that had developed the ransomware (developers) and those who successfully deployed it (affiliates).

“In the case of DarkSide, the developer reportedly takes 25% for ransoms less than $500,000, but this decreases to 10% for ransoms greater than $5m,” they wrote. 

“This split of the ransom payment is very clear to see on the blockchain, with the different shares going to separate Bitcoin wallets controlled by the affiliate and developer.”

Elliptic said that the DarkSide developer received a total of $15.5m in Bitcoin.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#DTX: Security Pros Must Focus on Human Behaviors to Address Cyber-challenges

#DTX: Security Pros Must Focus on Human Behaviors to Address Cyber-challenges

The cybersecurity industry should be placing more consideration on human behaviors to effectively tackle cyber-risks, according to a panel of experts speaking during the DTX: NOW virtual conference.

Lisa Forte, partner at Red Goat Cyber Security, who moderated the session, emphasized that human behaviors simply cannot be ignored when it comes to cybersecurity, noting that people “interact with our technology on a daily basis – whether that’s our staff who are responsible for looking after the data, or whether that’s clients creating unique usernames and passwords on our applications in order to access their own data, the human element comes into all of it.”

The panel first discussed approaches that security teams should use to help prevent people from falling foul of social engineering scams and cyber-attacks. Javvad Malik, security awareness advocate at KnowBe4, believes the starting point is to make people more aware of the threats that are out there. “Giving things a label and a name helps normalize it so people don’t feel like they’re the only ones getting caught out by a particular scam,” he said.

Additionally, this normalization needs to extend to when people are caught out by scams, thereby creating an environment in which there is no shame in admitting to being duped and that encourages frequent reporting of scams to law enforcement, according to Malik.

To help citizens truly understand cyber-risks, Holly Grace Williams, founder at Akimbo Core, said we need to focus on ensuring it is easy for people to do so. This includes the way awareness training is treated in organizations. “Very often I see security awareness programs delivered by companies where either the company doesn’t care about the content of the training and it’s simply a tickbox, or that the content is just on the face of it ineffective,” she noted.

John Graham-Cumming, chief technology officer at Cloudflare, added that digital companies should also be putting more effort into effectively forcing customers to adopt better security behaviors, such as strong passwords and two-factor authentication. He gave the example of systems that are emerging that tell users they are “using a password that has previously been hacked so don’t use that password,” he commented, adding that those outside the security industry “just need help to get into the right spot.”

The panel went on to highlight new ways security teams can bring about positive security behavioral change in people. Malik highlighted the importance of effective marketing to normalize certain behaviors. For example, he believes cybersecurity could learn from the “designated driver” terminology used to stop drunk driving, which was pushed heavily by behavioral scientists onto Hollywood. As this term got written into sitcoms, the concept quickly became normalized, and led to behavior change. “If we approach security from that perspective, we can get better behaviors,” he stated.

Removing the fear of punishment from employees caught out by social engineering attacks such as phishing is another crucial step organizations need to take. Williams noted that, sadly, it is still often the case that single employee mistakes are blamed by organizations for security breaches, which occurred in the wake of the Equinox and SolarWinds attacks. “If your entire organization can fail because one staff member chose a bad password, or clicked a link in an email, there are fundamentally bigger problems to your organization,” she pointed out.

As well as not laying blame for errors, developing the right security culture among all employees in an organization is crucial to preventing tactics such as phishing from being successful. This requires a good relationship being “built in” between security teams and other members of staff, according to Malik. “If the only interaction you have with your security team is when an incident occurs, or when they send a simulated phish out to you and say ‘we caught you out,’ regardless of how good it is, you’re just going to think ‘who are these people and why are they trying to trick me?’” he outlined.

Graham-Cumming agreed, stating that security personnel have to develop a good “bedside manner” in addition to having technical expertise. He said it’s vital to have a relationship with general staff “not just when things have gone bad,” which includes encouraging people to report any concerns they have, even if they turn out not to be security related. “It’s really about openness and honesty and treating people well so they respect what your job is and they feel like you’re somebody they can trust,” he explained.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Regulator Fines QR Code Provider Which Spammed Customers

Regulator Fines QR Code Provider Which Spammed Customers

The UK privacy regulator has fined a QR code provider that abused its access to personal data to spam individuals with direct marketing at the height of the pandemic.

The Information Commissioner’s Office (ICO) explained in a notice yesterday that it fined St Albans firm Tested.me £8000 after it send the marketing email without gaining adequate valid consent from data subjects.

The firm provided clients with contact tracing services by enabling them to offer customers a QR code to scan when arriving at their premises.

However, it used this data to send nearly 84,000 nuisance emails at the height of the COVID-19 pandemic between September and November 2020, the ICO said.

The ICO has also been running checks on other QR code providers to ensure they’re handling people’s data in accordance with the GDPR and its UK equivalent, the Data Protection Act 2018.

It said the checks revealed that most companies understood the laws and the importance of processing personal data fairly and securely.

The regulator’s guidance for firms as the economy starts to reopen following extensive lockdowns, is to make privacy policies clear and simple, follow data protection by design guidance and not to keep any personal data collected for more than 21 days.

Personal data collected for contact tracing is also not to be used for marketing or any other purposes, it said.

QR codes are increasingly used not only to check-in to locations using the NHS Test and Trace app, but by hospitality venues keen to offer customers a hands-free menu experience.

However, the technology doesn’t just represent a privacy risk. Security experts have warned that QR codes could be hijacked by threat actors to download malware and other threats to users’ devices.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

RDP Hijacked for Lateral Movement in 69% of Attacks

RDP Hijacked for Lateral Movement in 69% of Attacks

Some 90% of cyber-attacks investigated by a leading security vendor last year involved abuse of the Remote Desktop Protocol (RDP), and ransomware featured in 81%.

The figures come from a new Active Adversary Playbook 2021 compiled by Sophos from the experiences of its frontline threat hunters and incident responders.

It revealed that, while RDP is often used to gain initial access into victim organizations, especially during ransomware attacks, it was also hijacked by attackers in 69% of incidents for lateral movement.

Techniques such as using VPNs and multi-factor authentication (MFA), which focus on preventing unauthorized external access to RDP, won’t work if the attacker is already in the network, Sophos warned.

In fact, it seems as if attackers are increasingly capable of slipping past perimeter defenses to infiltrate networks. The average dwell time for cases investigated by Sophos was 11 days. Considering many of these were ransomware attacks which typically require less time, 264 hours is more than enough for threat actors to do their worst.

“With adversaries spending a median of 11 days in the network, implementing their attack while blending in with routine IT activity, it is critical that defenders understand the warning signs to look out for and investigate,” argued Sophos senior security advisor, John Shier.

“One of the biggest red flags, for instance, is when a legitimate tool or activity is detected in a unexpected place. Most of all, defenders should remember that technology can do a great deal but, in today’s threat landscape, may not be enough by itself. Human experience and the ability to respond are a vital part of any security solution.”

According to ESET, RDP attacks increased by a staggering 768% between Q1 and Q4 2020 as cyber-criminals focused on exploiting a tool used increasingly by remote workers to access their corporate desktops.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Recruiter’s Cloud Snafu Exposes 20,000 CVs and ID Documents

Recruiter’s Cloud Snafu Exposes 20,000 CVs and ID Documents

Tens of thousands of jobseekers have had their personal information exposed by a misconfigured cloud account, according to researchers.

A team at Website Planet discovered the AWS S3 bucket left unprotected and unsecured by FastTrack Reflex Recruitment, now TeamBMS.

The firm apparently specializes in recruitment for the building management systems sector, for projects including skyscrapers 22 Bishopsgate and The Shard, Wembley Stadium and the Olympic Stadium, Heathrow Terminal 5 and Crossrail stations.

The 5GB trove contained 21,000 files including CVs featuring personal information such as email addresses, full names, mobile phone numbers, home addresses and social network URLs. Other details included dates of birth, passport numbers and applicant photos, according to Website Planet.

The research team believes that TeamBMS’s IT service provider may have been to blame for the privacy snafu.

If found by threat actors, the data could have been used to commit follow-on identity theft and fraud, and craft phishing attacks designed to steal more personal details or deploy malware.

Website Planet also claimed that the information contained in the bucket could have been used for corporate espionage or to target victims’ homes for burglary.

The research team discovered the leak on December 29 last year, and reached out several times to TeamBMS’s parent company TeamResourcing as well as to the UK CERT. The bucket was finally secured on March 23.

Not only those impacted by the leak but the company itself should be on guard for any suspicious activity going forward, Website Planet claimed.

“FastTrack, and anyone else implicated in this breach, should be vigilant when receiving calls from parties claiming to be clients or associates. In which case, businesses must implement strategies to confidently identify these individuals,” it said.

“It’s crucial that FastTrack, as well as any businesses at-risk of this exposure, implements stringent security measures when storing customer data. Businesses should hire a cybersecurity professional, to be sure that customer data is adequately protected.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk