White House Asked to Increase Crypto Regulation

White House Asked to Increase Crypto Regulation

A task force organized by the Institute for Security and Technology has urged the White House to tackle the rise in ransomware attacks and make it harder for cybercrimes to be committed.

Law enforcement agencies, cybersecurity experts, and governments came together to make a series of recommendations to the Biden administration that aim to disrupt the illegal activities of threat actors.   

report submitted by the task force contained 48 recommendations, including advice to step up the regulation of cryptocurrencies and to root out safe havens sheltering ransomware attackers from capture and prosecution. 

The task force noted in the report that the volume of cyber-attacks has increased by four times year on year and that cybercrime is now a $350m criminal industry. 

The report is based on consultations carried out with researchers at Chainalysis Inc, cybersecurity experts at Palo Alto Networks Inc, and law enforcement agencies in Canada, the United Kingdom, and the United States. 

Among the recommendations contained within the report are five priorities described as “foundational and urgent.” These include using the long arm of the law and diplomatic channels to dissuade countries from offering cyber-criminals a safe haven in which to operate.

“Most ransomware criminals are based in nation-states that are unwilling or unable to prosecute this cyber crime, and because ransoms are paid through cryptocurrency, they are difficult to trace,” states the report. “This global challenge demands an ‘all hands on deck’ approach, with support from the highest levels of government.”

In the report, the task force notes that cyber-criminals favor cryptocurrencies when extorting payments from their victims as they are largely unregulated and transactions can be difficult to track. 

The task force called for governments to step up cryptocurrency regulation and make it a requirement for crypto exchanges and trading desks to enforce basic “know your customer,” anti-money laundering, and financial terrorism laws.

Chainalysis director of market development Don Spies said: “Believe these recommendations can go a long way to combating a problem that’s out of control.”

The report comes a week after the United States Justice Department created its own independent task force specifically to tackle ransomware.  

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Accenture to Acquire Openminded

Accenture to Acquire Openminded

Accenture has entered into an agreement to acquire 12-year-old French cybersecurity services company Openminded

The Irish multinational consulting and processing services company said that the acquisition would strengthen its security presence and capabilities in France and stimulate Accenture’s growth in Europe.

Openminded is a provider of advisory, cyber-defense, cloud & infrastructure security, and managed security services. The company was founded in 2008 and now has over 100 internal staff working in four business units. 

In 2020, Openminded’s turnover was €19m. According to its website, the company has 120 active customers in the public and private sectors and 40 editor partners.

Customers of Openminded include Chanel, BNP Paribas, Sarnoff, Etam, La Banque Postal, Banque De France, Thales, AXA, and Accor Hotels. 

Kelly Bissell, global leader of Accenture Security’s worldwide workforce of nearly 7,000 professionals, said that the resilience of today’s organizations was dependent on their approach to cybersecurity.

“With cyberattacks becoming more complex, constant and costly every day, companies must fully embed cybersecurity into the different layers of their organizations to ensure resilience,” said Bissell.

He added that the planned purchase of Openminded would help to protect the digital estates of Accenture’s clients going forward. 

“The acquisition of Openminded supports our commitment to leveraging technology and human ingenuity to help clients be confident and secure in the face of constant change,” said Bissell.

“We look forward to welcoming Openminded’s team to Accenture and helping clients defend against cyber threats more effectively across their entire ecosystem—now and in the future.”

Hervé Rousseau, Openminded’s founder and CEO, said his company aimed to build a synergy with Accenture that would support the delivery of services worldwide. 

“Joining forces with Accenture is a great opportunity for our teams and our clients,” said Rousseau. “The alliance of our talent and capabilities perfectly leverages our expertise and would allow us to deliver on a global scale. 

“Today, the fight against cyberattacks requires the implementation of the most advanced technologies, as well as the human resources to make them efficient. This is the synergy we are going to build and put at the service of our clients.”

Financial terms of the deal have not been disclosed.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Boston Nanny Arrested After Cyber-Tip

Boston Nanny Arrested After Cyber-Tip

Law enforcement have arrested a nanny based in Boston on suspicion of sharing child sexual abuse material (CSAM) over the messaging app Kik.

An investigation was launched into 36-year-old Roxbury resident Stephanie Lak by the Boston Police Department Crimes Against Children Unit following the submission of a cyber-tip to the National Center for Missing and Exploited Children (NCMEC) on March 2. 

Kik’s operator, MediaLab, notified NCMEC of an IP address that had been used to send at least eight files containing images of children aged five or younger being sexually abused. 

Police traced the address back to Lak and obtained a search warrant for her home, which was executed on April 15. A laptop and three cellphones were seized by police as evidence from a boarding house on Woodville Street.

Lak was held on $5,000 bail after being arraigned on Wednesday on charges of possessing and distributing CSAM and was instructed by a judge to stay away from children. 

District attorney Rachel Rollins said Lak had confessed to sharing more than 100 files depicting the sexual abuse of minors via Kik under the user name ‘sallydally69.’

Lak has worked in the childcare industry as a nanny and as a babysitter. Prosecutors said that she was active on the childcare services website Sittercity as recently as March 19. 

Describing the threat Lak allegedly poses to children, prosecutor Nicole Poitier told the judge: “It’s clear she has access to children. She has a long history of being a nanny and a babysitter on that site as well as potential other sites and she has a sexual interest in children.”

In a statement, Sittercity said they had run four background checks on Lak before allowing her to advertise childcare services on their platform and none of them had found evidence of criminal activity. Lak’s Sittercity account was removed when the site’s operators learned of the police’s investigation into her digital communications. 

Law enforcement are asking people who have had contact with Lak and think they may be able to identify alleged victims in this case to email lakinvestigation@fbi.gov

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Northern Ireland Government Announces Partnership to Offer Cyber Career Opportunities

Northern Ireland Government Announces Partnership to Offer Cyber Career Opportunities

The Northern Ireland government has announced a partnership with Immersive Labs and Capita, in which cybersecurity career opportunities will be provided to 16–25-year-olds living in the region.

The pilot initiative will offer free access to an enterprise-grade cyber-skills development platform for those who may not otherwise have access to relevant education courses. Initially, the aim is to upskill 1,000 individuals, who will subsequently have job opportunities in large organizations as incident responders, security architects, and security and vulnerability analysts.

The training will take place via the Immersive Labs gamified online platform, which is used by security teams to enhance skills in areas like software development and incident response. Those youngsters selected for the program will be dropped into browser-based labs portraying a range of cyber-threat scenarios. This will help them develop skills in a range of areas, including understanding how attackers operate and Base64 encoding.

The collaboration is designed to boost employment opportunities in Northern Ireland, a country in the UK, as well as to help address the worrying cyber-skills gap. Last month, a UK government-sponsored report found that half of UK businesses reported cyber-skills gaps in 2020, while the Learning & Work Institute recently warned that the UK is heading toward a “catastrophic” digital skills shortage.

Commenting on the announcement, Northern Ireland economy minister Diane Dodds outlined: “Northern Ireland has a growing international reputation in cybersecurity and the industry has seen significant growth in recent years. Capita have teamed up with Immersive Labs to deliver this online skills development and access to job vacancies. We have been working closely with industry to promote the myriad of varied and rewarding careers within the cybersecurity area and we will ensure candidates who successfully complete training can apply for the relevant vacancies advertised on the platform.”

James Hadley, CEO of Immersive Labs, said: “It’s great to see the Northern Ireland Government taking such a proactive role in addressing the need for cyber-skills, as well as opening up careers to as broad a range of people as possible. Large organizations are not just held back by a shortage of cyber talent, but also a lack of diverse approaches to problems which benefit from a wide range of opinions and backgrounds.”

Recruitment for the scheme will begin in June, and will be open to 16–25-year-olds resident in Northern Ireland who have essential skills or GCSEs in math and English.

Earlier this year, Queen’s University Belfast, Northern Ireland, was recognized for its cybersecurity education program and work promoting cyber-skills in its local community.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Emotet Group Harvested Over 4.3 Million Victim Emails

Emotet Group Harvested Over 4.3 Million Victim Emails

The threat actors behind the notorious Emotet botnet managed to collect over four million victim email addresses over the past few years, it has emerged.

The news came from Troy Hunt, Microsoft regional director and founder of breach notification site HaveIBeenPwned.

The FBI recently reached out to Hunt to ask if the site could be used as an intermediary to help those concerned they may have been affected to check their emails against the trove.

“In all, 4,324,770 email addresses were provided which span a wide range of countries and domains,” Hunt explained in a new blog post.

“The addresses are actually sourced from two separate corpuses of data obtained by the agencies during the takedown: email credentials stored by Emotet for sending spam via victims’ mail providers; and web credentials harvested from browsers that stored them to expedite subsequent logins.”

Hunt advised any individual who finds their email was in possession of Emotet to ensure their anti-malware is up-to-date, and to change their email account password as well as any passwords and security questions for accounts that might have been stored in their inbox or browser.

“For administrators with affected users, refer to the YARA rules released by DFN Cert, which include rules published by the German BKA,” he added.

Other best practice security tips also apply, including the use of two-factor authentication where possible, and strong unique passwords stored in a password manager, as well as prompt patching of all OS and software.

Emotet was finally disrupted back in January after action from the FBI and European police. Last Sunday law enforcers delivered an update to the botnet designed to erase the malware from all infected machines globally.

However, with some of the group still at large, experts believe it’s only a matter of time before they come back with an improved version of the malware.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cancer Patients Diverted After Cyber-Attack on MedTech Firm

Cancer Patients Diverted After Cyber-Attack on MedTech Firm

Scores of US hospitals are thought to have been affected after a security breach at a specialist provider of equipment for cancer treatments last week.

Swedish oncology and radiology system provider Elekta explained in a company update this week that a “data security incident” had affected its first-generation cloud-based storage system.

“Immediately upon learning of this incident, Elekta partnered with leading cyber experts and law enforcement to launch an investigation to understand what happened, mitigate any possible harm, and offer our customers a reliable solution that delivers on our commitment to ensure that cancer patients have access to precise and personalized radiotherapy treatments,” the statement continued.

“We recognize the impact this might have on customers and their patients and are working tirelessly to enable customers to continue providing secure patient care.”

It said only a subset of US customers were affected and that they had been fully briefed about the situation.

However, reports suggest it was a ransomware attack that forced the firm to take its cloud storage system offline, in order to contain the breach.

HIPAA Journal claimed that one customer, Connecticut-based Yale New Haven Health, was forced to take its radiation equipment offline for over a week, with cancer patients transferred to other providers.

Other Elekta customers were luckier. Lifespan, which runs the Lifespan Cancer Institute and Rhode Island Hospital, reportedly claimed the incident only affected one afternoon of appointments.

A separate report claimed 42 hospitals and clinics were affected by the breach.

Saryu Nayyar, CEO of Gurucul, argued that organizations are only as secure as the weakest link in their supply chain.

“Malicious actors will look for any way in and will always take the easiest path. The best defense is a proactive offense,” she added.

“If your third-party vendors can’t maintain adequate security protocols then you will have to put in place proactive measures such as behavior-based security analytics, which can detect these sorts of unknown threats in real-time. Saving lives is of utmost priority.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

First Horizon Bank Customers Have Account Funds Drained

First Horizon Bank Customers Have Account Funds Drained

A leading US bank has revealed a data breach in which over 100 online customers had their funds accessed by an unauthorized intruder.

First Horizon Bank claimed in a filing with the Securities and Exchange Commission (SEC) yesterday that less than $1 million was stolen in total from those accounts.

The attack itself seems to have relied on stolen or brute forced customer credentials, plus the exploitation of a vulnerability inside the financial services company.

“Based on its ongoing investigation, the company determined that an unauthorized party had obtained login credentials from an unknown source and attempted access to customer accounts,” the SEC filing explained.

“Using the credentials and exploiting a vulnerability in third-party security software, the unauthorized party gained unauthorized access to under 200 online customer bank accounts, had access to personal information in those accounts, and fraudulently obtained an aggregate of less than $1 million from some of those accounts.”

First Horizon, formerly known as First Tennessee Bank, said it had remediated the bug in question, reset the affected customer passwords and reimbursed those impacted by the breach.

“Based on its ongoing assessment of the incident to date, the company does not believe that this event will have a material adverse effect on its business, results of operations or financial condition,” it concluded.

Given the bank’s profits exceeded $500 million last financial year, the raid would indeed not seem to have made a serious impact on its bottom line.

However, experts argued that the incident should serve as a warning for IT security teams that layered defenses are essential today.

“Training users on security, such as recognizing phishing and fake websites, is a start, but not enough,” said Timothy Chiu, VP at K2 Cyber Security.

“Organizations also need network, system and application security to protect their assets.  Application security adds the final layer, protecting applications that may have unknown or unpatched vulnerabilities.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk