Fintech Startup Offers $500 for Payroll Passwords

How much is your payroll data worth? Probably a lot more than you think. One financial startup that’s targeting the gig worker market is offering up to $500 to anyone willing to hand over the payroll account username and password given to them by their employer, plus a regular payment for each month afterwards in which those credentials still work.

This ad, from workplaceunited[.]com, promised up to $500 for people who provided their payroll passwords, plus $25 a month for each month those credentials kept working.

New York-based Argyle.com says it’s building a platform where people who work multiple jobs and/or side hustles can improve their credit and employment options by pooling all of their gig work data in one place.

“Consumers’ access to financial security and upward mobility is dependent on their access to and control over their own employment records and how easily they can share those records with financial institutions,” Argyle explained in a May 3 blog post. “We enable access to a dataset that, for too long, has gone unstandardized, unregulated, and controlled by corporations instead of consumers, contributing to system-wide inequalities.”

Argyle’s app flow. Image: Argyle.com.

In that sense, Argyle is making a play for a discrete chunk of a much larger employment data market dominated by the major credit bureaus, which have been hoovering up and selling access to employment data for years.

The 800-lb. gorilla there is Equifax, whose The Work Number product has for years purchased employment data flows from some of the world’s largest companies (employees consent to this sharing as part of their employment contract, and The Work Number makes it fairly easy for anyone to learn how much you earn).

The Work Number is designed to provide automated employment and income verification for prospective employers, and tens of thousands of companies report employee salary data to it. It also allows anyone whose employer uses the service to provide proof of their income when purchasing a home or applying for a loan.

On its blog, Argyle imagines a world in which companies choose to integrate its application platform interface (API) and share their employee payroll data. At the same time, the company appears to be part of an effort in which non-salaried workers are prompted to repay their erstwhile employers’ trust by selling payroll credentials.

If Argyle is worried these two goals might somehow conflict, that is not obvious by looking at some of its direct-to-consumer efforts.

The website pictured below prompts visitors to “connect payroll,” and those who proceed agree to have their payroll data shared with a company called Earnin, a mobile payday loan app that lets users get an advance on their upcoming paycheck.

Clicking “Connect Payroll” brings up a list of payroll login pages for brand name companies, including Walmart, Starbucks, Amazon, Uber, Chipotle, etc., with a search feature that reveals login pages for everyone from the Federal Bureau of Investigation (FBI) to the Federal Reserve and Federal Trade Commission (FTC).

The default Argyle list of payroll login pages for major companies.

Here’s what comes up when you search by “Department of” at this site:

Drilling down into individual companies listed here produces a username and password form that in some cases is modified to request an employee identifier other than a username, such as a employee ID, associate or partner number instead. Here’s the login page for Starbucks employees:

The site pictured above actively checks if any submitted credentials are working, by submitting them directly to the employer in question. This Argyle status page indicates the system’s “data connection status” to countless employers.

Some of you may be thinking, “How many of us actually know or have our payroll passwords?” According to Argyle, plenty of people do.

“At Argyle, we are intimately familiar with how likely someone is to know the password for their employment account or payroll system, because we’ve seen hundreds of thousands of users successfully (and unsuccessfully) provide their credentials,” Argyle’s Billy Mardsen wrote on Apr. 1. “We closely monitor their success rate—what we call conversion—because it drives the performance of the products and applications that our clients build on top of Argyle.”

Argyle’s “conversion” numbers by employer. Image: Argyle.com

UNCOMMON GROUNDS

KrebsOnSecurity first heard about this company via Twitter from security researcher Kevin Beaumont, who pointed to a nest of domains associated with Argyle’s API — nearly all of which are offline now. At the time, Beaumont and others digging into this suspected the sites were part of an elaborate phishing scam.

These sites, which seemed to be grouped around a recent recruitment effort variously called “Workers United,” “UniteAtWork,” “WageCompete” and “CommonGrounds,” indicate that Argyle’s platform has been pivotal in a slew of campaigns paying employees at specific companies up to $100 for their payroll account passwords. Here’s one seeking T-Mobile employees:

A promotion offering T-Mobile employees $100 to give up their T-Mobile payroll account passwords.

Another recent promotion targeted employees at J.P. Morgan Chase, the largest financial institution in the United States:

Argyle declined multiple interview requests for this story, so it’s not clear how much of a role — if any — the company may have played in these various sites. But code prebuilds and instructions published in the company’s name on Github strongly suggest Argyle was instrumental in the WageCompete initiative.

Also, this page over at Scopeinc.com says the WageCompete program is provided by Argyle Expert Services.

Here’s a graphical look at the various websites mentioned here and their ties to Argyle’s API (click to enlarge):

The network of sites paying people for payroll passwords and their connections to Argyle’s API. Click to enlarge. Image: Virustotal

One of the sites in that graphic above that’s connected to Argyle’s API — workerresearchalliances[.]com — is currently live and includes the same verbiage about participants getting paid for their payroll credentials. The terms and conditions of the “WorkersApp beta program” were set by a company called Workers Research Alliances LLC, incorporated in February. The address for Workers Research Alliances is just a few blocks from Argyle’s office in New York City.

‘WE DO THINGS OTHERS DARE NOT DO’

Steve Friedl, an IT consultant in the payroll service bureau industry, said it appears Argyle has been paying people to help them refine their API and data scraping technology.

“They are not paying this money just to be able to sell people services, they are doing so to maintain their screen-scraping software API,” Friedl said. “This is essentially paying employees to help Argyle hack their payroll provider.”

Last fall Argyle announced it had landed a $20 million investment from Bain Capital, among others. The company’s co-founder, Shmulik Fishman, is described as a “disruptor” who says he wants to make credit scores obsolete.

“We’re fearless,” Fishman told Authority Magazine. “We do things other people dare not do.”

That much is clear. Hey, I can get behind almost anything that disintermediates the creaky old credit bureaus in a straightforward and consumer-friendly way. And the last time I checked, it’s not against the law to give someone your password, or to induce someone to do so willingly in exchange for something else (unless maybe you work for a federal agency).

But I wonder how many of the companies listed on all these payroll connect sites will respond to knowing their brands and logos are associated with a site that asks their employees to give away passwords.

KrebsOnSecurity contacted multiple high-level sources at major companies whose login pages are shown in these payroll connect programs running on Argyle’s platform. None of those sources were authorized to talk to the media, but all seemed fairly horrified at what they were seeing, and each said their employer’s legal departments were launching their own investigations.

Beaumont said he’s worried that in some companies, an employee’s payroll credentials may work to gain access to other parts of the organization — meaning some employees may be giving away more than they realize.

“My concern is some companies use single sign-on for payroll,” Beaumont said. “That’s a lot of access for a data harvesting company.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Three Marylanders Indicted Over BEC Scam

Three Marylanders Indicted Over BEC Scam

Three Maryland residents are suspected of being involved in dating and business email compromise (BEC) scams that defrauded victims out of more than $2.3m.

An indictment returned in March by a federal grand jury and unsealed yesterday charges 37-year-old Baltimore resident Noel Chimezuru Agoha, 34-year-old Sessieu Ange Oulai of Parkville, and 32-year-old Essex resident Kelechi Arthur Ntibunka with conspiracy to commit wire fraud, conspiracy to commit money laundering, and aggravated identity theft.

Court documents allege that from August 2016 to December 2018, the three defendants conspired with others to execute a BEC scam in which Agoha, Oulai, and Ntibunka sent deceptive emails and made fraudulent phone calls to victim businesses. 

In the communications, the defendants allegedly tried to induce money from their victims by posing as clients or representatives of companies with whom the victims had ongoing business.  

“The parties being impersonated were also victimized by the BEC scam because the object of the fraud was to intercept payments intended for these parties and/or to deprive these parties of money to which they were entitled,” stated the Department of Justice. 

Bank accounts known as drop accounts were allegedly opened by Agoha, Oulai, and Ntibunka and their co-conspirators to receive money sent by the victims and monitored by the defendants. Details of deposits, transfers, and balances were allegedly relayed to their conspirators by the defendants over text messages.

The indictment alleges that the defendants and their co-conspirators received, or attempted to receive, more than $1.1m in proceeds from BEC scams.

Agoha is further accused of conspiring with others to run an online dating scam from May 2016 to July 2018. Victims were tricked into believing that they were in a real romantic relationship by scammers who then claimed they were in financial hardship and asked for money. 

Through this ruse, Agoha and their co-conspirators allegedly accrued more than $1.2m. 

Agoha and Ntibunka were arrested on May 5 and taken before US Magistrate Judge Beth Gesner, who ordered that they be detained pending a hearing scheduled for May 12. Oulai was already in custody over unrelated state charges when the indictment was unsealed. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Three Marylanders Indicted Over BEC Scam

Three Marylanders Indicted Over BEC Scam

Three Maryland residents are suspected of being involved in dating and business email compromise (BEC) scams that defrauded victims out of more than $2.3m.

An indictment returned in March by a federal grand jury and unsealed yesterday charges 37-year-old Baltimore resident Noel Chimezuru Agoha, 34-year-old Sessieu Ange Oulai of Parkville, and 32-year-old Essex resident Kelechi Arthur Ntibunka with conspiracy to commit wire fraud, conspiracy to commit money laundering, and aggravated identity theft.

Court documents allege that from August 2016 to December 2018, the three defendants conspired with others to execute a BEC scam in which Agoha, Oulai, and Ntibunka sent deceptive emails and made fraudulent phone calls to victim businesses. 

In the communications, the defendants allegedly tried to induce money from their victims by posing as clients or representatives of companies with whom the victims had ongoing business.  

“The parties being impersonated were also victimized by the BEC scam because the object of the fraud was to intercept payments intended for these parties and/or to deprive these parties of money to which they were entitled,” stated the Department of Justice. 

Bank accounts known as drop accounts were allegedly opened by Agoha, Oulai, and Ntibunka and their co-conspirators to receive money sent by the victims and monitored by the defendants. Details of deposits, transfers, and balances were allegedly relayed to their conspirators by the defendants over text messages.

The indictment alleges that the defendants and their co-conspirators received, or attempted to receive, more than $1.1m in proceeds from BEC scams.

Agoha is further accused of conspiring with others to run an online dating scam from May 2016 to July 2018. Victims were tricked into believing that they were in a real romantic relationship by scammers who then claimed they were in financial hardship and asked for money. 

Through this ruse, Agoha and their co-conspirators allegedly accrued more than $1.2m. 

Agoha and Ntibunka were arrested on May 5 and taken before US Magistrate Judge Beth Gesner, who ordered that they be detained pending a hearing scheduled for May 12. Oulai was already in custody over unrelated state charges when the indictment was unsealed. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Lawsuit Filed Over Contact Tracing Data Breach

Lawsuit Filed Over Contact Tracing Data Breach

A federal lawsuit has been filed against Pennsylvania and a vendor contracted by the state’s Department of Health (DOH) over a data breach that exposed the personal health information (PHI) of thousands of Pennsylvanians.

The DOH hired Atlanta-based company Insight Global in 2020 “to provide contact tracing and other similar services” following the outbreak of COVID-19. The Department later said that employees of the company caused a data breach by creating “unauthorized documents outside of the secure data systems created by the Commonwealth.”

Information exposed in the data breach included names, phone numbers, and medical information belonging to 72,000 individuals.

The data breach was first reported by WPXI TV show Target 11 on April 30 after the show’s team learned of the incident via a whistleblower. The show’s investigator Rick Earle today reported that a lawsuit has been filed over the breach.

Insight Global and the Pennsylvania Department of Health are named as defendants in the suit, which claims that data breach victims now face an increased risk of identity theft.

The plaintiffs allege that the data breach was a “direct result of Defendants’ failure to implement adequate and reasonable cybersecurity procedures and protocols.”

In the suit, Insight Global is accused of maintaining “unsecure spreadsheets, databases and or documents containing the PHI (public health information).”

In a statement by the company sent to Earle, Insight Global claimed to be unaware of any litigation regarding the data breach.

“Insight Global has not been served with the lawsuit and will need time to analyze any allegations, but can say that we are working closely with the Pennsylvania Department of Health to identify any individuals whose information may have been affected and have taken steps to secure and prevent any further access to, or disclosure of, information,” stated the company.

The DOH has stated that it will not be renewing its contract with Insight Global after it expires on July 31. State representatives meeting in Harrisburg on Monday reportedly called for the contract to be terminated immediately and for an investigation into the breach to be launched by a state House Oversight Committee.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Lawsuit Filed Over Contact Tracing Data Breach

Lawsuit Filed Over Contact Tracing Data Breach

A federal lawsuit has been filed against Pennsylvania and a vendor contracted by the state’s Department of Health (DOH) over a data breach that exposed the personal health information (PHI) of thousands of Pennsylvanians.

The DOH hired Atlanta-based company Insight Global in 2020 “to provide contact tracing and other similar services” following the outbreak of COVID-19. The Department later said that employees of the company caused a data breach by creating “unauthorized documents outside of the secure data systems created by the Commonwealth.”

Information exposed in the data breach included names, phone numbers, and medical information belonging to 72,000 individuals.

The data breach was first reported by WPXI TV show Target 11 on April 30 after the show’s team learned of the incident via a whistleblower. The show’s investigator Rick Earle today reported that a lawsuit has been filed over the breach.

Insight Global and the Pennsylvania Department of Health are named as defendants in the suit, which claims that data breach victims now face an increased risk of identity theft.

The plaintiffs allege that the data breach was a “direct result of Defendants’ failure to implement adequate and reasonable cybersecurity procedures and protocols.”

In the suit, Insight Global is accused of maintaining “unsecure spreadsheets, databases and or documents containing the PHI (public health information).”

In a statement by the company sent to Earle, Insight Global claimed to be unaware of any litigation regarding the data breach.

“Insight Global has not been served with the lawsuit and will need time to analyze any allegations, but can say that we are working closely with the Pennsylvania Department of Health to identify any individuals whose information may have been affected and have taken steps to secure and prevent any further access to, or disclosure of, information,” stated the company.

The DOH has stated that it will not be renewing its contract with Insight Global after it expires on July 31. State representatives meeting in Harrisburg on Monday reportedly called for the contract to be terminated immediately and for an investigation into the breach to be launched by a state House Oversight Committee.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Bot Attacks a Top Cybersecurity Concern

Bot Attacks a Top Cybersecurity Concern

Mitigating bot attacks is a major concern for security leaders, according to new research published yesterday by cybersecurity company Human (formerly White Ops).

The “2021 Bot Management Trends” report, which is based on a survey conducted by Enterprise Strategy Group (ESG), exposed worries regarding a string of threats posed by bots.  

In the first quarter of 2021, ESG asked 425 cybersecurity and IT decision makers with application security knowledge and responsibilities for their organizations about their perceptions of and responses to bot attacks.

Leaders expressed concerns that bots could cause site slowdowns by overwhelming traffic, new account fraud, credential cracking/brute force attacks, account takeover, content manipulation, sensitive content scraping, and inventory exhaustion and cart abandonment.

Among the report’s key findings are that nearly half of respondents believed their organization would be susceptible to a sophisticated bot attack. 

Most of those surveyed (90%) said that they viewed bot management as a top-five cybersecurity priority. This finding aligns with security leaders’ view of how sophisticated bots are, as 86% of respondents said they believed most bots are capable of circumventing simple bot mitigation features.

“This research demonstrates how crucial a robust bot mitigation platform is to a strong cybersecurity posture,” said Tamer Hassan, co-founder and CEO of HUMAN. 

“Sophisticated bots can have immense detrimental effects to customer experience, and the time it takes to rebuild trust with customers is time that today’s organizations don’t have.”

The impact of bot attacks upon those surveyed was significant, with 37% of respondents confirming that they had been victimized by sophisticated bots in the past twelve months. Another 30% believed they had suffered a bot attack but were unable to confirm it.

Senior analyst at ESG, John Grady, said bot attacks were on the rise. 

“As organizations have shifted to more online-focused business operations, a trend further accelerated by the pandemic, attackers have doubled down on their efforts and increased the frequency of bot-driven fraud and logic abuse,” said Grady. 

“This new research explores how application security leaders perceive the threat of bot attacks and what their plans are for combatting them.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Bot Attacks a Top Cybersecurity Concern

Bot Attacks a Top Cybersecurity Concern

Mitigating bot attacks is a major concern for security leaders, according to new research published yesterday by cybersecurity company Human (formerly White Ops).

The “2021 Bot Management Trends” report, which is based on a survey conducted by Enterprise Strategy Group (ESG), exposed worries regarding a string of threats posed by bots.  

In the first quarter of 2021, ESG asked 425 cybersecurity and IT decision makers with application security knowledge and responsibilities for their organizations about their perceptions of and responses to bot attacks.

Leaders expressed concerns that bots could cause site slowdowns by overwhelming traffic, new account fraud, credential cracking/brute force attacks, account takeover, content manipulation, sensitive content scraping, and inventory exhaustion and cart abandonment.

Among the report’s key findings are that nearly half of respondents believed their organization would be susceptible to a sophisticated bot attack. 

Most of those surveyed (90%) said that they viewed bot management as a top-five cybersecurity priority. This finding aligns with security leaders’ view of how sophisticated bots are, as 86% of respondents said they believed most bots are capable of circumventing simple bot mitigation features.

“This research demonstrates how crucial a robust bot mitigation platform is to a strong cybersecurity posture,” said Tamer Hassan, co-founder and CEO of HUMAN. 

“Sophisticated bots can have immense detrimental effects to customer experience, and the time it takes to rebuild trust with customers is time that today’s organizations don’t have.”

The impact of bot attacks upon those surveyed was significant, with 37% of respondents confirming that they had been victimized by sophisticated bots in the past twelve months. Another 30% believed they had suffered a bot attack but were unable to confirm it.

Senior analyst at ESG, John Grady, said bot attacks were on the rise. 

“As organizations have shifted to more online-focused business operations, a trend further accelerated by the pandemic, attackers have doubled down on their efforts and increased the frequency of bot-driven fraud and logic abuse,” said Grady. 

“This new research explores how application security leaders perceive the threat of bot attacks and what their plans are for combatting them.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NCSC Sets Out Security Principles for Smart Cities

NCSC Sets Out Security Principles for Smart Cities

The UK’s National Cyber Security Centre (NCSC) has published a set of security principles to underpin the development of so-called smart cities.

Titled Connected Places Cyber Security Principles, the guidance aims to help local authorities in the UK embrace the benefits of connected places, while at the same time ensure they are resilient to cyber-attacks.

The smart city concept involves the use of connected technology, such as IoT devices, to collect data and enhance services within a built environment. Examples of smart city technologies include the use of parking sensors to provide real-time data on space availability and sensors to monitor pollution levels.

Despite these benefits, security experts believe smart cities will be heavily targeted by cyber-criminals via methods such as ransomware as a result of the critical public functions they will perform and the numerous security vulnerabilities that are associated with IoT devices.

The guidance outlines the high-level security requirements and principles that should be considered and implemented in the development of smart city technology. These include advising local authorities to think about the cybersecurity governance and skills they will need and the role of third-party suppliers in the process. The NCSC also sets out how connected environments can be designed in a way that is resilient and scalable, and able to protect data.

Dr. Ian Levy, technical director at the NCSC, stated: “Local authorities are using sensors and intelligent systems to improve our lives and make our cities more efficient and environmentally friendly.

“While these benefits should be embraced, it’s important to take steps now to reduce the risk of cyber-attacks and their potentially serious impact on these interconnected networks. I urge every individual and organisation establishing a connected place in the UK to consult our newly published cybersecurity principles.

“It’s our collective responsibility to ensure that our cities of the future are safe and resilient.”

Commenting, Mark Jackson, national cybersecurity advisor, Cisco UK and Ireland, outlined how the publication is part of a broad strategy to enhance the security of IoT technology in general: “Cities and metropolitan districts across the UK are at the point of turning their smart city strategies into actionable plans—with many having already conducted proof of concepts or successful trials. The complexity of the smart cities marketplace, with multiple device manufacturers and IT providers in play, could quite easily present cybersecurity issues that undermine these efforts. The NCSC’s principles are one of the most sophisticated pieces of government-led guidance published in Europe to date.

“The guidance set out for connected places generally aligns to cybersecurity best practice for enterprise environments, but also accounts for the challenges of connecting up different systems within our national critical infrastructure. With the DCMS also planning to implement legislation around smart device security, this is indicative of a broader government strategy to level up IoT security across the board.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NCSC Sets Out Security Principles for Smart Cities

NCSC Sets Out Security Principles for Smart Cities

The UK’s National Cyber Security Centre (NCSC) has published a set of security principles to underpin the development of so-called smart cities.

Titled Connected Places Cyber Security Principles, the guidance aims to help local authorities in the UK embrace the benefits of connected places, while at the same time ensure they are resilient to cyber-attacks.

The smart city concept involves the use of connected technology, such as IoT devices, to collect data and enhance services within a built environment. Examples of smart city technologies include the use of parking sensors to provide real-time data on space availability and sensors to monitor pollution levels.

Despite these benefits, security experts believe smart cities will be heavily targeted by cyber-criminals via methods such as ransomware as a result of the critical public functions they will perform and the numerous security vulnerabilities that are associated with IoT devices.

The guidance outlines the high-level security requirements and principles that should be considered and implemented in the development of smart city technology. These include advising local authorities to think about the cybersecurity governance and skills they will need and the role of third-party suppliers in the process. The NCSC also sets out how connected environments can be designed in a way that is resilient and scalable, and able to protect data.

Dr. Ian Levy, technical director at the NCSC, stated: “Local authorities are using sensors and intelligent systems to improve our lives and make our cities more efficient and environmentally friendly.

“While these benefits should be embraced, it’s important to take steps now to reduce the risk of cyber-attacks and their potentially serious impact on these interconnected networks. I urge every individual and organisation establishing a connected place in the UK to consult our newly published cybersecurity principles.

“It’s our collective responsibility to ensure that our cities of the future are safe and resilient.”

Commenting, Mark Jackson, national cybersecurity advisor, Cisco UK and Ireland, outlined how the publication is part of a broad strategy to enhance the security of IoT technology in general: “Cities and metropolitan districts across the UK are at the point of turning their smart city strategies into actionable plans—with many having already conducted proof of concepts or successful trials. The complexity of the smart cities marketplace, with multiple device manufacturers and IT providers in play, could quite easily present cybersecurity issues that undermine these efforts. The NCSC’s principles are one of the most sophisticated pieces of government-led guidance published in Europe to date.

“The guidance set out for connected places generally aligns to cybersecurity best practice for enterprise environments, but also accounts for the challenges of connecting up different systems within our national critical infrastructure. With the DCMS also planning to implement legislation around smart device security, this is indicative of a broader government strategy to level up IoT security across the board.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk