“Unusually Unhinged” Cyber-stalker Jailed for 10 Years

“Unusually Unhinged” Cyber-stalker Jailed for 10 Years

The United States has imprisoned a man who continued to cyber-stalk his ex-wife and kids after they moved states and changed their names to evade him.

The determined Oscar Adrian Marquez tracked his former wife, Jennifer Lorraine, and two daughters from New Mexico to Oregon, harassing them even after they purchased guns and took out a protection order against him.

Following a three-day trial in November 2020, 47-year-old Marquez was convicted of stalking, cyberstalking, and three counts of interstate violation of a protective order.

During his trial, the jury were played a song recorded by Marquez. The ditty—named “I only need one bullet”—detailed how one bullet would be sufficient “to settle the score” with the person who “took my kids, my money, my life, when you walked out that door.”

On the stand at trial, Marquez suggested that the bullet he was singing about would be used against himself. 

The Marquez’ marriage broke down in 2014 after what his wife described as years of physical and emotional abuse. That summer, Marquez kidnapped his children in the middle of the night. After being missing for a week, they were found in El Paso.

Lorraine reported his abuse and the kidnapping to the FBI, but that didn’t stop Marquez from threatening to kill his ex-wife and her family and threatening them via voicemail and social media.

In 2017, Lorraine moved her family to Portland, Oregon, where she contacted the Oregon Crime Victims Law Center to keep their home address confidential and registered her protective order in the state’s courts. 

Lorraine then bought mace, a Taser, guns, and a guard dog and installed an alarm and camera system in her home together with a silent 911 button.

Marquez left a note at Lorraine’s mother’s house, stating that he was going to find her daughter. On July 16, 2019, he posted his ex-wife’s new name and home address in Portland on social media.

Thirteen days later, Marquez was arrested as he drove past his ex-wife’s new residence for a third time. 

US District Judge Michael Mosman described Marquez as “unusually unhinged” and “unusually” obsessed with his victims before sentencing him on May 3 to ten years in prison.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CaptureRx Data Breach Impacts Healthcare Providers

CaptureRx Data Breach Impacts Healthcare Providers

At least three American healthcare providers have suffered a data breach after a cyber-attack on an administrative services company in Texas.

CaptureRx, which is based in San Antonio, fell victim to a ransomware attack on February 6. On February 19, an investigation into the attack determined that certain files had been accessed without authorization.

During the attack, cyber-criminals exfiltrated files containing the personal health information (PHI) of more than 24,000 individuals.

CaptureRx serves the Mohawk Valley Health System affiliate Faxton St. Luke’s Healthcare in New York, Thrifty Drug Stores (Thrifty White), and Gifford Health Care of Randolph, Vermont, among others.

A review of the attack, completed on March 19, determined that the security breach impacted 17,655 patients of Faxton St. Luke’s Healthcare and a further 6,777 patients at Gifford Health Care. The number of Thrifty Drug Store patients affected by the attack has not yet been determined. 

HIPAA Journal reports that CaptureRx is currently unclear how many of its healthcare provider clients have been affected by the attack. Nor has the company finished its final tally of how many individuals had their PHI exposed because of the incident.

Data exposed and stolen by the ransomware attackers included names, dates of birth, prescription information, and, for a limited number of patients, medical record numbers.

Affected healthcare provider clients were notified of the incident by CaptureRx between March 30 and April 7. 

WKTV reports that 100 patients of Faxton St. Luke’s Healthcare were not notified of the data breach because CaptureRx was unable to verify a valid mailing address for them.

The company said no evidence has been found to suggest that the data stolen in the attack has been misused. Impacted individuals have been advised to closely monitor their bank accounts for any incidences of fraudulent activity.  

“Data privacy and security are among CaptureRx’s highest priorities, and there are extensive measures in place to protect information in CaptureRx’s care,” stated Capture Rx.

“As part of CaptureRx’s ongoing commitment to the security of information, all policies and procedures are being reviewed and enhanced and additional workforce training is being conducted to reduce the likelihood of a similar event in the future.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

DOD Expands Hacker Program

DOD Expands Hacker Program

The United States Department of Defense (DOD) has expanded its ethical hacking program to include more targets.

DoD officials announced yesterday that the Department’s Vulnerability Disclosure Program will be broadened to include all publicly accessible DOD information systems.

Bug hunters were first invited to engage with the DOD in 2016 when the initiative ‘Hack the Pentagon’ was launched. Through this initiative, the Defense Digital Service set up a bug bounty program to reward ethical hackers for identifying flaws in the Department’s digital defenses.

Director of the Defense Digital Service Brett Goldstein said that before the initiative was introduced, ethical hackers who discovered a vulnerability had no way of communicating their findings to the DOD.

“Because of this, many vulnerabilities went unreported,” said Goldstein.

He added: “The DOD Vulnerability Policy launched in 2016 because we demonstrated the efficacy of working with the hacker community and even hiring hackers to find and fix vulnerabilities in systems.”

When the vulnerability hunting policy was first established, it was limited to DOD public-facing applications and websites. 

Goldstein said that the newly announced expansion will allow for research and reporting of vulnerabilities detected in all DOD publicly accessible networks, Internet of Things, industrial control systems, frequency-based communication, and more.

“This expansion is a testament to transforming the government’s approach to security and leapfrogging the current state of technology within DOD,” said the director.

The expanded Vulnerability Disclosure program will continue to be overseen by the DOD’s Cyber Crime Center. Growing it to catch more vulnerabilities and improve cybersecurity was an obvious and sensible progression, according to program director Kristopher Johnson.

He said: “The department has always maintained the perspective that DOD websites were only the beginning as they account for a fraction of our overall attack surface,” he said.

Ethical hackers have submitted more than 29,000 vulnerability reports through the Vulnerability Disclosure Program since it was launched. Johnson said that over 70% of those reported weaknesses proved to be valid.

The program director said that he expects the number of disclosures reported by the security researcher community to increase significantly with the expansion of the program, which was last extended in 2018.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Financial Services Experience 125% Rise in Exposure to Mobile Phishing

Financial Services Experience 125% Rise in Exposure to Mobile Phishing

Financial services and insurance organizations experienced a 125% rise in exposure to mobile phishing attacks in 2020 compared to 2019, according to Lookout’s Financial Services Threat Report.

The cloud security firm also found that malware and app risk exposure went up by more than 400% on average per quarter last year among the industry’s employees and customers. This was despite a 50% growth in mobile device management deployment during this period.

This surge in exposure to risk has come as cyber-criminals have deliberately ramped up their targeting of phones, tablets, and Chromebooks to try to exploit vulnerabilities. Lookout noted that even a single successful phishing or mobile ransomware attack can enable access to highly sensitive data in this industry, including proprietary market research, client financials, and investment strategies.

Another finding from the study, which looked at telemetry data from nearly 200 million mobile devices and 140 million apps, was that almost 50% of phishing attempts attempted to steal corporate login credentials.

Particularly concerning was that close to 20% of mobile banking customers had a trojanized app on their device when trying to sign in to their account.

Additionally, Lookout revealed the extent to which delays in downloading the latest software updates for mobiles exposes users to significant cyber-risks. More than a fifth (21%) of iOS and around a third (32%) of Android devices were exposed to more than 390 iOS and 1060 Android vulnerabilities, respectively, due to running iOS 13 or earlier and Android 10 or earlier.

Gert-Jan Schenk, chief revenue officer, Lookout, commented: “These findings demonstrate that regardless of whether a device is managed or unmanaged, attackers have equal success in deploying phishing campaigns.

“In addition, phishing can be particularly difficult to detect on a mobile device. We inherently trust these devices, which makes us vulnerable to social engineering attacks. Protecting modern endpoints requires a different approach—one that is built from the ground up for mobile and can continuously secure an organizations’ data from endpoint to the cloud.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Financial Firms Report Puzzling 30% Drop in Breaches as Incidents Rise

Financial Firms Report Puzzling 30% Drop in Breaches as Incidents Rise

Data breach incidents reported to the UK’s financial regulator dropped by nearly a third from 2019 to 2020, although experts claim this is far from an accurate picture of the current threat landscape.

Governance and risk firm Kroll requested Freedom of Information (FoI) data from the Financial Conduct Authority (FCA) to better understand the level of cyber-breach activity in the sector.

However, the data received, a 30% year-on-year drop in reported breaches to just 76 in 2020, was at odds with its own figures. These showed a 56% average increase in incidents over the same time period across all sectors — with the financial services sector slightly higher still.

Given the pandemic has provided even more opportunities for threat actors to target organizations distracted by remote working, the figures are doubly puzzling.

Kroll argued that the disparity could be explained by more organizations pulling back, after an initial period of over-reporting following the introduction of the GDPR.

In many cases, legal counsel is recommending firms not to notify if they think reporting thresholds around whether data subjects were “harmed” are not met, it said.

“The GDPR is still a relatively new and complex piece of legislation and we certainly saw businesses being hyper-vigilant when it came to reporting to the ICO and the FCA in its initial stages of implementation,” explained Keily Blair, head of Orrick, Herrington & Sutcliffe’s UK Cyber, Privacy and Data Innovation team.

“The drop in the FCA numbers likely reflects that organizations are becoming more adept at assessing whether an incident truly meets the necessary thresholds to trigger a report to the FCA.”

She argued that the FCA’s official figures are likely to represent the tip of the iceberg in terms of security breaches at financial services firms.

“The worry is that by seeing these figures, without the benefit of knowing what is happening below the surface, organizations may misinterpret the true nature and extent of the cybersecurity threat leading to complacency and greater risk,” she warned.

Across Europe and across all sectors, year-on-year breach notifications increased by 19% in 2020, according to DLA Piper.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Researcher Claims Peloton APIs Exposed All Users Data

Researcher Claims Peloton APIs Exposed All Users Data

A security researcher has discovered several issues with the software used by exercise equipment maker Peloton, which may have leaked sensitive customer information to unauthenticated users.

Pen Test Partners explained in a new blog post that the problem could be traced back to unauthenticated API endpoints, which could have allowed hackers to interrogate  information on all users.

Among the potentially exposed data was user and instructor IDs, group membership, location, workout stats, gender and age, and whether users are in the studio or not.

“The mobile, web application and back-end APIs had several endpoints that revealed users’ information to both authenticated and unauthenticated users,” the security consultancy said.

“A full investigation should be conducted by Peloton to improve their security, especially now that famous individuals are openly using this service.”

The security flaws were so bad that it leaked information even for users in privacy mode, Pen Test Partners claimed.

Peloton has become hugely popular during the pandemic as a way for locked-down consumers to keep fit at home. The firm claims to have over three million subscribers, including famous users such as US President Biden, who probably don’t want their workout stats and location made public.

Unfortunately, Peloton initially appeared to make a few mistakes in its handling of the responsible disclosure.

According to Pen Test Partners: “it acknowledged the disclosure, then ignored me and silently ‘fixed’ one of the issues. The ‘fix’ didn’t fix the vulnerability.”

The security firm was forced to reach out to a journalist months after its initial disclosure to try and start a constructive dialog.

“Shortly after contact was made with the press office at Peloton we had contact direct from Peloton’s CISO, who was new in post. The vulnerabilities were largely fixed within seven days,” it concluded.

“It’s a shame that our disclosure wasn’t responded to in a timely manner and also a shame that we had to involve a journalist in order to get listened to.”

Jason Kent, hacker in residence at Cequence Security, argued that 2021 could be the year of the API attack unless organizations find and properly secure all of their API endpoints.

“The leaky Peloton API is just the latest example of how hard it can be for API developers to get authentication just right. In needing to build an API that allows some users to share information and build community, while respecting those who want privacy by ensuring the data is secure, they have risked all user data,” he added.

“The information might not show in the application itself, but developers and security teams need to also confirm that the APIs themselves conform to the security measures in place.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Half of UK Manufacturers Suffered a Cyber-Attack Last Year

Half of UK Manufacturers Suffered a Cyber-Attack Last Year

Half of British manufacturers and even more in the automotive sector suffered a successful cyber-attack last year, but cost remains a major barrier to improvements, according to an industry body.

Make UK, which represents the sector, claimed that the 47% figure overall rose to 62% for carmakers.

Although security has become a bigger priority for 50% of its members since the start of the pandemic, and 61% now have a board director responsible for cyber, 59% cited cost as the biggest barrier to building enhanced cyber protections.

As with organizations in many sectors, the move to mass remote working during the pandemic exposed many manufacturers to an increase in online threats. Make UK claimed the shift to remote production and remote monitoring of equipment, with staff working from home “on hastily supplied laptops” provided new opportunities for hackers to strike.

Manufacturing was the third most frequently targeted sector for ransomware last year globally, according to Trend Micro.

In the UK, 63% experienced losses of up to £5000 and nearly a quarter (22%) lost between £5000 and £25,000.

On the positive front, things slowly seem to be improving in the sector. Over two-fifths (43%) of respondents to the Make UK poll said they’ve been asked by a customer to demonstrate or guarantee the robustness of their cyber processes. Plus, one fifth claimed to have asked customers or suppliers to prove similar.

However, 44% still don’t offer staff cybersecurity awareness training and 47% don’t have a formalized incident response plan in place, the report found.

The cyber-threat to manufacturers is undoubtedly growing, warned Make UK CEO, Stephen Phipson.

“No business can afford to ignore this issue and while the increased awareness across the sector is encouraging, there is still much to be done with too many businesses still burying their heads in the sand,” he argued.

“This is a strategic threat; failing to get this right as a nation could cost the UK economy billions of pounds and put thousands of jobs at risk. Every business is vulnerable and every business needs to take the necessary steps to protect themselves properly.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk