#RSAC: Solving the Ransomware Scourge Requires a Coordinated Effort

#RSAC: Solving the Ransomware Scourge Requires a Coordinated Effort

The scourge that is ransomware has had a devastating impact on the lives of ordinary people around the world, but it doesn’t have to be that way, according to a panel of experts speaking at the 2021 RSA Conference on May 18.

Ransomware is not a new problem in 2021, and it certainly is not one that appears to be diminishing by any measure; rather, it’s growing. Jen Miller-Osborn, deputy director of threat intelligence for Unit 42 at Palo Alto Networks, commented that, according to her firm’s research, from 2019 to 2020 the average ransom payment nearly tripled, from $115,123 to $312,493. In that same period the highest ransom payment doubled from $5m to $10m.

“They’re just gaining more and more money, and when that happens ransomware becomes more and more popular in the criminal sector,”  Miller-Osborn said.

The Evolution of Ransomware

Michael Daniel, president and CEO at the Cyber Threat Alliance, explained that over the course of the last decade, ransomware has changed.

“If you look back to, say, 2013, ransomware was typically targeted at an individual’s computer, and the average ransom was like 100 or 150 bucks, so it was a fairly minimal affair,” Daniel said.

In contrast, in 2021 Daniel noted that the average ransom is more than $300,000, and it’s not just individuals being targeted—it’s things like schools systems, hospitals and the energy grid.

As the cost and scale of ransomware attacks have grown, so too has the complexity of trying to limit the risk and the ability to shut down attackers. Among the challenges is that the impact of ransomware isn’t limited to any one industry or even any one agency within the US government.

Phil Reiner, chief executive officer, Institute for Security and Technology and Ransomware Task Force, explained that one of the primary reasons why the Ransomware Task Force existed was to help deal with the fast-moving threat landscape.

“It takes senior-level, top-down interest in a problem like this to really get after it with the resources that are required, and the prioritization of the issue needs to be raised in order to actually do something differently,” Reiner said. “It’s not business as usual. This is not just a normal cybersecurity threat—it’s a plague.”

These threat actors, they feel like they can operate this way because they’ve got safe haven.Phil Reiner

It Is Time for a Comprehensive Approach to End Ransomware

The panelists all agreed that reducing the growth of ransomware will require a coordinated and comprehensive effort across public and private sectors around the world.

“You’re not going to solve ransomware with some little silver bullet that just fixes the crypto payments processing problem, you’re not going to solve it by just sending Cyber Command after somebody sitting perhaps in Eastern Europe,” Reiner said. “These actions all have to happen at the same time if you’re really going to effect significant change and shift the trajectory.”

Daniel emphasized that disrupting the cryptocurrency element of ransomware will be a critical part of a comprehensive effort. He noted that it is clear that one of the big enablers for ransomware is the growth of cryptocurrencies.

“Cryptocurrency enables payments to occur in a way that the normal financial system can’t track or block,” Daniel said. “So clearly you’re going to have to address that part of the ecosystem, which has nothing to do with cybersecurity directly. “

Increasing Pressure with Law Enforcement Actions

As ransomware attackers can be anywhere in the world, Reiner said that there are different tactics, including economic sanctions, that can and should be used globally to apply pressure to de-incentivize attacks.

“These threat actors, they feel like they can operate this way because they’ve got safe haven,” Reiner said.

Daniel suggested that for the federal government, there is a need to increase capabilities across multiple agencies and not just those where the focus is on security. For example, he noted that the Department of Health and Human Services (HHS), the Department of Energy and others need to work with organizations within their respective sectors to make them more resilient to ransomware incidents.

Miller-Osborn advocated for more law enforcement actions to help deter would-be ransomware actors. In her view, many ransomware attackers haven’t been too concerned about consequences or the risk of ending up in jail. If there is a coordinated response, where ransomware infrastructure, network and payment operations are all taken down and people are arrested, convicted and get jail time, she expects that behavior will change

“Cybercrimes are never going to go away,” Miller-Osborn said. “But the more people we can discourage from doing these kinds of activities,  the safer everyone’s going to be as a whole.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#RSAC: Does the US Need a National Breach Reporting Law?

#RSAC: Does the US Need a National Breach Reporting Law?

When a security breach occurs in the US today there is no single authority or national breach reporting law that needs to be adhered to, but that could change in the near future, according to a panel of experts speaking at the 2021 RSA Conference on May 18.

Luke Dembosky, partner at law firm Debevoise & Plimpton LLP, commented that the current state of breach reporting in the US is a patchwork of laws and policies that vary by jurisdiction. He noted that each individual state sets the rules that determine whether an organization has to report to state authorities, as well as impacted individuals, in the event of a data breach.

“It’s very challenging for companies that do business across state lines, often to figure out what are all the various potential breach notification obligations,” Dembosky said.

The (Solar)Wind Pushing the National Data Breach Reporting Law Forward

Adam Hickey, deputy assistant attorney general, National Security Division at the US Department of Justice, commented that there have been a number of high-profile breaches in recent years that have impacted critical infrastructure across multiple sectors. Without a single reporting framework, the federal government doesn’t always get all the data and insight it needs.

“We are challenged getting a handle on the visibility of what’s happening,” Hickey said.

Among the recent high-profile data breach incidents discussed during the panel was the SolarWinds data breach. Tonya Ugoretz, deputy assistant director at the FBI, commented that a lot of times when there is a push for legislation to close a particular gap, like with the national data breach reporting law, that groundswell is prompted by something that didn’t happen, someone who didn’t take an action.  That’s not what happened in the SolarWinds incident.

Ugoretz said that in the SolarWinds incident, it was reported quickly by security vendor FireEye, which itself was a victim of a breach.

“They [FireEye] did the right thing,” Ugoretz said. “Almost immediately upon noticing that they were the victim of this very sophisticated intrusion, they reached out to the government.”

Part of the way you demonstrate you are taking something seriously and doing everything you can as a business is saying, I’m working with law enforcement to address it.Adam Hickey

She added that this type of quick notification doesn’t always happen and the fact that it did may well have helped to prevent even more data loss, which was a theme that Hickey echoed. Hickey said that thanks to FireEye raising its hand and saying, “This is happening on my network,” the federal government was able to move quickly to investigate and help limit risk.

Why a National Data Breach Reporting Law Is Needed

Hickey emphasized that a national data breach reporting law is needed to help provide visibility to law enforcement and push out information to enable potential victims to be protected.

As a general rule, Hickey noted, companies are more willing to contact the government and work with law enforcement now than they were ever before, for several reasons.

“In the past, having a data breach used to be kind of a scarlet letter, and there was a shame factor, so you kind of didn’t want it to get out,” Hickey said. “Now there’s sort of a sad understanding that this is a part of the mortality of computer networks.”

With the realization that data breaches happen, Hickey said, organizations’ attention has turned not just to defense, but also to resilience and reputation.

“Part of the way you demonstrate you are taking something seriously and doing everything you can as a business is saying, I’m working with law enforcement to address it,” Hickey commented.

What the National Breach Reporting Law Should Look Like

A key objective for a potential national breach reporting law that all the panelists agreed upon was the idea that it should make reporting a breach easier, not harder, than the current patchwork model.

Ugoretz emphasized that a having a national standard for breach reporting will give companies less to figure out, which is important especially at the moment that they’re suffering from an intrusion. She wants to see a law that is clear and concise and that helps victims and law enforcement to figure out what happened and prevent further exposure.

“We think of each of these intrusions, as if it were a murder conducted by a serial killer where whoever is behind it will strike again and they’re leaving clues, at each crime scene,” Ugoretz said. “This reporting law will help us pick up those clues and share it with others before they then become subsequent victims.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#RSAC: Anne Neuberger Sets Out Biden Administration’s Plan to Modernize US Cyber-defenses

#RSAC: Anne Neuberger Sets Out Biden Administration’s Plan to Modernize US Cyber-defenses

The new US administration’s approach to modernizing the nation’s cybersecurity defenses was laid out by Anne Neuberger, deputy assistant to the president and deputy national security advisor for cyber and emerging technology, National Security Council, during a keynote session on day two of the virtual RSA Conference 2021.

Neuberger began by describing the increasingly dangerous cyber-threat landscape, noting that President Joe Biden’s administration has already had to deal with two large-scale incidents during its first 100 days in office—the SolarWinds and Microsoft Exchange attacks.

“Governments and companies are under constant, sophisticated and malicious attack from nation-state adversaries and criminals,” she outlined, adding that “today, more than ever, cybersecurity is a national security imperative.”

In this environment, Neuberger stated, it is time to shift the mindset from incident response to prevention. “I’ve observed that as a community we’ve accepted that we’ll move from one incident response to the next,” she said. “While we must acknowledge that breaches will happen and prepare for them, we simply cannot let waiting for the next shoe to drop to be the status quo under which we operate.”

With this principle in mind, Neuberger set out three areas the current US federal government is focusing on to enhance the nation’s cybersecurity:

1. Modernize Cyber-defenses

Neuberger stated how the SolarWinds attacks demonstrated that “some of the most basic cybersecurity measures were not systemically rolled out across federal agencies.” These include multi-factor authentication, encryption and endpoint detection.

As well as mandating these basic security hygiene measures in government, Neuberger said the administration is also introducing ways of ensuring the software security it purchases from vendors is up to scratch. She explained that the products the government buys “often include defects and vulnerabilities.” This is being accepted by developers, either because they expect to be able to patch later or they decide to ignore them if they deem the defects to not be sufficiently serious, according to Neuberger.

“That’s not acceptable—it’s knowingly introducing unknown and potentially grave risks that adversaries and criminals then exploit,” she stated.

To tackle this issue, Neuberger revealed it is a priority of the government to ensure the software it buys is built securely from the start, “by potentially requiring federal vendors to build software in a secure development environment.” She added that this approach should have the knock-on effect of enhancing the software security brought by organizations outside of government, such as schools and small businesses.

Another vital step in this area is to gain visibility into what software is developed securely and what isn’t, as it is currently impossible for customers to make this assessment. Neuberger explained: “Today we place our trust in vendors but we largely do it blindly, because we don’t have a way to measure that trust.”

Today we place our trust in vendors but we largely do it blindly, because we don’t have a way to measure that trustAnne Neuberger

She additionally highlighted that the administration is currently working on a pilot program to protect the technology relied upon in critical national infrastructure. This initiative “will facilitate private-sector efforts to install new technologies that provide timely visibility, detection, response and blocking capabilities.” Neuberger noted this is “the first step in a series of efforts we’ll be working on to ensure we can trust the systems underpinning our critical infrastructure.”

2. Return to a More Active Role on Cyber Internationally

Neuberger also emphasized the need for the US to strengthen its global partnerships “to counter adversaries that leverage technology to undermine national and global security.” She highlighted a number of initiatives in this area, including the Quadrilateral Security Dialogue (QUAD), which aim to “counter cyber-threats and hold malicious actors accountable.”

She revealed that one of the administration’s first global cybersecurity initiatives will be a “cooperative effort to counter ransomware,” with this vector becoming increasingly prevalent. She noted: “This represents a national security threat for countries around the world because it can disrupt schools and hospitals and governments’ and companies’ abilities to deliver services. And because of the huge financial cost.”

Neuberger added that it is particularly concerning that ransomware actors are often able to strike by targeting known weaknesses, such as endpoint and software vulnerabilities.

Additionally, the increasing sophistication of ransomware groups, in terms of both their techniques, like the use of fileless malware, and their operational models, including the growth of double-extortion schemes, cannot be ignored. Neuberger commented: “International cooperation to address ransomware is critically important because transnational criminals are most often the perpetrators of these crimes and they often leverage global infrastructure and money laundering networks to do it.”

3. Prepare America’s Future Cybersecurity Posture

As well as focusing on securing today’s technology and infrastructure, Neuberger said another priority of the Biden administration is “to invest in and facilitate the innovation of tomorrow.” As such, the government’s American Jobs Plan has a proposal to invest $180bn in R&D emerging technologies. This covers areas like AI, quantum computing and micro-electronics.

This investment is vital for enhancing the US’s cyber-defenses, according to Neuberger. In particular, she highlighted the future importance of quantum computing in this regard. While this technology “promises to revolutionize certain unsolvable computing problems,” it will also “fundamentally disrupt cybersecurity and the technology platforms on which it’s built.”

This is because quantum computing offers malicious actors new vectors to compromise IT systems, with potentially “devastating” impacts on certain encryption methods, such as isometric encryption, which is “the foundation of our economic and national security communications.”

As such, the American Jobs Plan “reflects a commitment to accelerate US leadership in quantum computing and quantum information science more broadly,” which will help “protect the country from the adversarial use of these technologies.”

Neuberger concluded her talk by saying: “Bolstering the nation’s cybersecurity, safeguarding our critical infrastructure and renewing America’s advantages broadly are fundamental to the Biden administration’s commitment to our national security strategy.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#RSAC: McAfee CTO Calls for Risk Decisions Based on Science Not Headlines

#RSAC: McAfee CTO Calls for Risk Decisions Based on Science Not Headlines

McAfee senior vice president and CTO, Steve Grobman, took to the virtual stage at RSA Conference on May 18 with a call to action: reconsider the perception of risk by looking at data, not headlines

Grobman claimed that often the information security industry falls into the trap of perceiving risk based on how threats are portrayed in the media.

“A scientific approach is needed to measure risk and help counteract bias,” he said. Groban used the example of a micromart as a way of doing this. A micromart is a unit of risk defined as one-in-a-million chance of death. “We can use micromort to challenge our intuition on what is actually risky and what isn’t,” he said.

“Many of our perceptions about risk in cyber are miscalibrated… We need to use science based on data to counteract the influence of social and traditional media and raw emotions,” Grobman warned.

“Organizations worry about all sorts of threats. Mass malware we see every hour. Spear-phishing attacks on critical employees we see every day. And the rare national state-directed attacks that have the potential to be devastating.  

“One observation is that the frequency of an event is inversely proportionate to its impact.”

The impact of a cyber-event, said Grobman, “has multiple levels of nuance. We need to consider the impact to an organization independently from the global impact.”

He gave the examples of WannaCry  and NotPetya, which had catastrophic effects and a global impact on numerous organizations around the world, as they spread fast and were highly disruptive. He also gave the example of other attacks that had a huge impact but only on a solo organization.

“We need to examine the different aspects of the damage that emanates from certain attacks, for example, indirect costs, such as regaining environmental integrity, which can be immense.”

“We need to understand the risk/reward benefits when we choose to engage in high-risk areas,” he continued.

Impact, Scale, Frequency

Grobman suggests a risk model that takes all factors into consideration. “Consider impact, scale and frequency. These are the three vectors that matter,” he explained. “This model is all about risk. Risk is the potential for negative outcome, whereas an event is a historical record of what has occurred. Past events don’t predict future outcomes.”

Many of our perceptions about risk in cyber are miscalibrated… We need to use science based on data to counteract the influence of social and traditional media and raw emotionsSteve Grobman

However, Grobman advised, “they can provide data to scientifically access the likelihood of future scenarios” in order to understand how to prepare defenses.

McAfee did some research into how what we should worry about aligns with what we do worry about. “We analyzed traditional and social media along with the web activity of McAfee data related to threats. We found that many of the high-profile single organization targeted attacks saw a lot of attention.

“Whereas some campaigns such as trickbot get little media coverage, but organizations need to pay greater attention to them. They act as the catalyst for secondary, high impact attack scenarios.”

Media coverage can inform us about emerging global cyber events, said Grobman, “but we need a more science-based approach. We need to comprehensively evaluate the events that impact organizations.”

In addition, Grobman advises that good cyber-hygiene and good user education to prevent everyday threats, are incredibly important. “We need a combination of technology and cyber-operators to defeat the adversary, because no technology on its own can outsmart or outplay an advanced attacker.”

In conclusion, Gobman said it is critical that “the investments we do make have the strongest benefits compared to the risks they are mitigating.

“My call to action for you is this: let’s make the best cyber-defense decisions possible. Yes, watch the news and monitor your Twitter feed, but be hyper-conscious to counter-balance natural instinct reactions driven by media and hype and ensure that every trade-off and decision you make to defend your organization is based on data and objectivity.”  

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Q1 2021 Sees 2.9 Million DDoS Attacks Launched

Q1 2021 Sees 2.9 Million DDoS Attacks Launched

Approximately 2.9 million Distributed Denial of Service (DDoS) attacks were launched in the first quarter of 2021, according to research from NETSCOUT’s ATLAS Security Engineering & Response Team (ASERT).

The estimated figure represents a 31% increase compared to the same period in 2020. All three months of the year’s first quarter saw more than 900,000 DDoS attacks, which researchers said exceeded the existing baseline of 800,000 per month.

“The first two months of the year are usually the slowest months in the DDoS attack calendar,” wrote researchers. 

“This year, we saw 972,000 attacks in January, which eclipses the record set last May for the largest number of attacks yet seen in one month.” 

ASERT has warned that last year’s record-breaking volume of DDoS attacks could be exceeded in 2021.

“If this activity holds, we are on a trajectory that blows right by the unprecedented 10-million-attack threshold recorded in 2020,” wrote researchers.  

Comparing the first quarters of this year and 2020, researchers noted no significant increase in the size of the attacks launched. During both periods, attackers opted to deploy fast attacks that victims would find difficult to mitigate. 

The length of the attacks and the throughput both increased year-on-year. Many attacks (42%) lasted between five and ten minutes, while assaults lasting fewer than five minutes dropped from 24% to 19%.

“Adversaries ratcheted up throughput considerably, as the max throughput recorded increased 71% compared with Q1 2020,” noted researchers.

Analyzing which industries attackers chose to hit, researchers observed that healthcare, education and online services were prime targets. 

Healthcare organizations suffered about 7,000 attacks in Q3 2020, 10,000 attacks in Q4, and 8,400 attacks in Q1 of 2021. The figure for the first quarter of 2021 represents a 53% increase year over year.

In education, attacks rose by 41% over the past three quarters, with 32,000 attacks in Q3 2020, 39,000 in Q4 and 45,000 in the first quarter of this year. 

This latest research supports conclusions noted in NETSCOUT’s semi-annual Threat Intelligence Report, which predicted DDoS attacks would continue to hit record numbers this year while becoming increasingly complex in scope.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Oregonian Indicted Over International Streaming Fraud

Oregonian Indicted Over International Streaming Fraud

An Oregon man has been indicted on suspicion of carrying out a million-dollar streaming service fraud scheme. 

Samuel Joyner allegedly conspired with an accomplice based in Australia to steal and resell customer account credentials for popular internet streaming services, including Netflix, HBO Max and Spotify Premium.

On May 12, a federal grand jury in Portland returned an indictment charging 30-year-old Beaverton resident Joyner with conspiracy to commit computer and access device fraud, trafficking and use of unauthorized access devices, and possession of fifteen or more unauthorized access devices.

According to the indictment, between February 2018 and March 2019, Joyner teamed up with 23-year-old Sydney resident Evan McMahon to create and operate an online subscription service called AccountBot. 

AccountBot sold account credentials to access streaming services at a heavily discounted rate, rating from $1.79 to $24.99 depending on the service and the duration of access. 

It is alleged that Joyner and McMahon used credential stuffing attacks to obtain usernames and passwords for the services, which they then sold via AccountBot in exchange for cryptocurrency or fiat. 

By March 2019, AccountBot had more than 52,000 different registered customers and over 217,000 unique sets of stolen account credentials.

The indictment alleges that the men were equal partners in the illicit business but had different roles. Drafting computer code for AccountBot’s website and managing customer payments was allegedly McMahon’s responsibility, while Joyner is accused of stealing most of the user credentials and running AccountBot’s customer service.

McMahon pleaded guilty and was sentenced in April to serve two years and two months on an intensive corrections order.

Australian Federal Police cybercrime operations case officer Joanna Kondos said: “Following a referral of information from our FBI law enforcement partners, the Australian Federal Police arrested, charged, and secured a conviction against a Sydney man, and we also seized more than a million dollars’ worth of cryptocurrency assets which were the proceeds of his crime.”

Joyner, who reportedly went by numerous online aliases, including “FamousCracker,” was arrested on Wednesday by the FBI. He pleaded not guilty and was released pending a five-day jury trial scheduled to begin on July 13, 2021.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

IBM to Acquire Waeg

IBM to Acquire Waeg

American multinational technology company IBM today announced plans to acquire Waeg, a leading Salesforce Platinum Consulting Partner based in Brussels.

By acquiring Waeg, IBM hopes to extend the range of Salesforce services it can offer and progress its hybrid cloud and AI strategy. 

IBM said the deal would “build on its continued investment in Salesforce consulting services to meet the rising client demand for experience-led business transformation and new customer engagement strategies backed by data, AI, and machine learning.”

This news follows IBM’s acquisition of leading US Salesforce consultancy 7Summits in January 2021.

Waeg was established in 2014 and employs 130 people in offices in Belgium, Denmark, France, Ireland, Netherlands, Poland, and Portugal. It provides a full complement of Salesforce consulting services, including business-to-business commerce, digital strategy advisory, marketing automation and customer experience design, implementation, and managed services. 

The company works with organizations across a range of industries, but its expertise is most highly concentrated in manufacturing, healthcare, and life sciences. 

Waeg holds expert distinctions in Salesforce’s Navigator program in Manufacturing, Pardot, and Salesforce B2B Commerce and holds over 400 Salesforce certifications.

“Salesforce continues to play a critical role in companies’ digital transformations as they adapt to the conditions created by the pandemic,” said Mark Foster, senior vice president, IBM Services and Global Business Services.  

“Trust is the new currency of customer and employment engagement, and every touchpoint is an opportunity to personalize the relationship.”

Foster added that Waeg’s Salesforce expertise would help IBM customers move with the times. 

He said: “Waeg’s strength in Salesforce consulting services will be key to creating intelligent workflows that allow our clients to keep pace with changing customer and employee needs and expectations.”

Foster’s expectations are in alliance with Waeg’s mission as described by the company’s co-founder and managing partner Chris Timmerman.

Timmerman said: “Waeg’s growth was built on the simple notion of helping our clients successfully navigate constantly changing customer demands. Now, as we join forces with IBM, we are excited to leverage our collective Salesforce capabilities to accelerate that growth across Europe.”

The transaction is subject to customary closing conditions. It is expected to close this quarter.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Consumers Warned About Surge in Meal Kit Delivery Scams

Consumers Warned About Surge in Meal Kit Delivery Scams

Consumers have been warned to be vigilant about a surge in meal kit delivery scams, following rising demand for these DIY recipe kits during the COVID-19 lockdown.

Cybersecurity firm Tessian revealed it had uncovered a number of SMS scams impersonating well-known meal kit delivery companies, including Gousto and HelloFresh.

These scams come in a number of forms. In one example, several phishing campaigns are impersonating Gousto and asking recipients to rate their delivery to enter a prize draw. The link in the message takes them to a fake website, designed to steal personal and financial information or harvest important credentials.

There is also significant variation in the sophistication of these scam messages, with a particularly easy one to spot stating: “Your Gousto box is now delivered. Enjoy the reoipej! Rate delivesy and enter wrize diaw at ‘URL’.”

Tessian added that thousands of these SMS and WhatsApp messages are typically sent out at the same time.

Gousto has also warned its customers about the scams, posting on its Twitter account: “We are aware that these emails/texts are in circulation unfortunately, and we would advise against opening them. Our Info Tech team are looking into this suspicious activity.”

Commenting on the findings, Tim Sadler, CEO and co-founder of Tessian, said: “Throughout the pandemic, we’ve seen cyber-criminals jump on trending topics and impersonate well-known brands, with increasing sophistication. Often, scammers will register new web domains to set up convincing-looking fake websites, luring their victims to these pages using phishing scams, and then harvest valuable information.

“These scams are getting harder and harder to spot, with the perpetrators regularly coming up with new tactics to convince users to follow their link and input their confidential data. A general rule of thumb is that, if you’re ever not sure if something is a scam, then assume it is. You can always verify a message’s legitimacy with the company directly.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Families of Missing Persons Receive Fake Ransom Demands

Families of Missing Persons Receive Fake Ransom Demands

The FBI has warned families of missing persons to be on their guard for extortion demands from cyber-criminals claiming to have abducted their loved ones.

The scammers typically scour social media posts to gather information about missing persons and their families. They’ll carry out open source research to find out more about the individual in order to make their claims more realistic.

The fraudsters will then contact those family members online or call/message them using third-party apps to disguise their phone number. Usually they’ll request between $5000 and $10,000 in ransom, the FBI claimed.

“Generally, offenders do not offer proof of life. However, in one instance, an accomplice made telephone calls to family members claiming to be the missing person. Offenders often claim the missing person is ill or injured, adding to the urgency of the situation and putting additional pressure on family members to pay the ransom,” the FBI warned.

“Since the onset of COVID-19 nationwide stay-at-home orders, law enforcement has received several reports of scammers targeting families who have posted on social media about their missing family member.”

The FBI claimed in its recent Public Service Announcement that such scams had increased over the past three years, with COVID-19 offering extortionists more opportunities to strike the vulnerable.

The Feds urged anyone who has been targeted in this way to contact their local law enforcement agency or FBI field office, file an online complaint with the Internet Crime Complaint Center and be sure to keep all records of communication with the individuals concerned.

There were nearly 77,000 cases of extortion recorded by the FBI last year, putting the category third top in terms of frequency, according to its Internet Crime Report 2020. Nearly $71 million was lost to such incidents over the period.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NCSC Renews Bid to Improve Diversity and Inclusion in Cyber

NCSC Renews Bid to Improve Diversity and Inclusion in Cyber

The National Cyber Security Centre (NCSC) is launching a second annual survey in a bid to drive greater diversity in the cybersecurity sector.

Developed in partnership with KPMG UK, the 2021 Diversity and Inclusion Survey for the UK Cyber Workforce aims to improve understanding of disability and neurodiversity in the workforce to better spot where improvements are needed.

According to the results of the inaugural report, Decrypting Diversity 2020, there’s still a long way to go in the sector.

It revealed that one in five respondents do not feel they can be themselves at work, while 41% of black cybersecurity professionals felt they’d experienced discrimination because of their ethnicity over the previous year. A further 14% of respondents said they’d experienced barriers to career progression as a result of diversity and inclusion issues.

Part of the problem seems to be transparency: nearly three-quarters (74%) of negative incidents as a result of diversity and inclusion are not reported.

New benchmarks in this year’s study will capture key data on disability, neurodiversity, location of workplace, employer size and seniority.

The hope is that with this extra information, improvements can be made to encourage a wider range of individuals to choose a career within the sector — one experiencing major skills shortages. Currently, there’s a global shortfall of over three million professionals.

The NCSC said cybersecurity leaders need to be more accountable for diversity and inclusion among their workforce and the industry as a whole needs to absorb best practice more effectively from within and outside the sector.

“Our second Decrypting Diversity survey will help us build on the collective understanding of where the sector is falling short, allowing us to break down barriers to ensure that there are opportunities for all,” said NCSC CEO, Lindy Cameron.

“We know that a welcoming community and greater diversity leads to more innovation and better outcomes for the UK, and the NCSC is committed to helping transform the cybersecurity sector into an exemplar of best practice.”

Those wishing to participate can access the survey here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk