Amazon: We Blocked 10 Billion Bad Listings in 2020

Amazon: We Blocked 10 Billion Bad Listings in 2020

Amazon claims to have blocked billions of “bad” listings before they went live on its e-commerce platform last year in a bid to prevent rampant counterfeiting on the site.

The internet shopping giant’s first Brand Protection Report contained plenty of facts and figures to back its stated efforts to drive “counterfeits to zero.”

Alongside the 10 billion suspected bad listings that were blocked, the firm’s VP of worldwide customer trust and partner support, Dharmesh Mehta, claimed that Amazon prevented over six million attempts to create new selling accounts during 2020. The latter figure is up from the 2.5 million reported in 2019.

These efforts have been driven largely by machine learning analytics combined with human expertise, although they go hand-in-hand with criminal prosecution guided by a new Counterfeit Crimes Unit, and tools like Brand Registry, Transparency, and Project Zero, which participating vendors can use.

Although the e-commerce giant claimed that fewer than 0.01% products sold on the platform received a counterfeit-related complaint from a customer, the problem is a serious one. Only 6% of attempted new seller account registrations passed Amazon’s verifications processes.

What’s more, the company claimed to have seized and destroyed more than two million products sent to its fulfilment centers but detected at the last minute as being counterfeit.

Amazon said it has invested over $700 million in 2020 and employed more than 10,000 people to fight fraud and abuse on the platform.

Counterfeit items aren’t the only challenge facing Amazon. The new report comes just days after news emerged of a mass scheme to pay consumers for fake reviews.

A misconfigured China-based Elasticsearch server revealed details of communications between vendors and consumers to coordinate fake five-star reviews, in return for keeping the reviewed products free-of-charge.

E-commerce fraud is expected to surge by 18% from 2020 to top $20 billion globally by the end of this year as scammers continue to target shoppers driven online by the pandemic.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

AXA to Stop Reimbursing Ransom Payments

AXA to Stop Reimbursing Ransom Payments

A major global insurer has said it will stop reimbursing French clients who fall victim to ransomware, for any costs they incur paying their extorters.

AXA said it had taken the decision after listening to the concerns of French officials and cybersecurity experts last month, according to AP.

Ransom and associated downtime costs for French corporate victims stood at over $5.5 billion last year, off the back of over 4400 attacks, according to one estimate. That makes the country the second most frequently targeted by ransomware globally, although it still lies some way behind the US in first place.

The new AXA rules will apparently not affect existing policies and will only apply to ransom payments, not reimbursements for the cost of responding to and recovering from attacks.

However, the move could be followed by other insurers, given the increasingly large pay-outs many are being forced to issue. Cyber-insurance provider Coalition last year estimated that ransomware accounted for over two-fifths (41%) of claims in North America in the first half of 2020.

The practice of reimbursing corporate policyholders to pay-off their extorters has also come in for criticism by lawmakers and police, who see it as perpetuating the problem. As long as policies continue to pay-out, victims will be happy to pay-up and cyber-criminals will continue to target them.

Another train of thought has it that the insurance industry can use its influence to improve baseline corporate security and therefore make life tougher for the threat actors, by writing rules into policies that stipulate payments will only be made if the customer has followed strict security best practices.

ImmuniWeb CEO, Ilia Kolochenko, argued that if AXA’s decision is limited to France, it’s unlikely to have a material impact on the global ransomware business.

“On one side, this decision will likely hinder flourishing ransomware business and indirectly incentivize would-be victims to implement better cybersecurity and enhance their cyber resilience,” he added.

“On the other, the categorical ban will unfairly discriminate against enterprises who adequately care about their cyber-defense but nonetheless fall victim to sophisticated attacks, perhaps because of their careless suppliers.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Japanese Manufacturer Yamabiko Targeted by Babuk Ransomware

Japanese Manufacturer Yamabiko Targeted by Babuk Ransomware

A ransomware group that claimed to be retiring after an audacious attack on Washington DC’s police department appears to be back in action after reportedly targeting a Japanese firm.

Yamabiko, a Tokyo-headquartered manufacturer of power tools and agricultural and industrial machinery, was apparently added to the data leak site used by the Babuk group.

Although official confirmation is still pending from the firm itself, reports suggest the Russian-speaking threat actors have already released some of the data on their naming-and-shaming site.

This includes personally identifiable information (PII) on employees, product schematics, financial data and more, according to TechNadu.

The group reportedly claimed to have a total of 0.5TB of data in its possession.

With annual revenue exceeding $1 billion, Yamabiko is a prime candidate for targeting by “hands-on-keyboard” ransomware attacks which often use “living-off-the-land” techniques and legitimate tools like Cobalt Strike to move laterally inside networks and exfiltrate data.

Confusingly, the Babuk group intimated last month that its attack on the Washington DC police department, in which it threatened to release stolen data on officers and informants, would be its last. However, it subsequently deleted an online note which claimed that it would be open sourcing its code for Ransomware as a Service (RaaS) actors to use.

Saumitra Das, CTO of Blue Hexagon, said Babuk has in the past been linked to attacks that exploit VPN vulnerabilities to gain a foothold inside victim networks.

“Due to the deluge of new CVEs this year, attackers have now started attacking company infrastructure as an entry rather than the usual first vectors of phishing users, finding leaked credentials or open RDP,” he added.

“Such infection methods circumvent prevention-based perimeter defense like firewalls and necessitate the use of network detection and response to find attack traces that signature-based technologies miss. “

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk