Data Breach Impacts 1 in 4 Wyomingites

Data Breach Impacts 1 in 4 Wyomingites

Wyoming’s Department of Health (WDH) has announced the accidental exposure of personal health information belonging to more than a quarter of the state’s population on GitHub.com.

The data breach occurred when fifty-three files containing laboratory test results were “inappropriately handled” by an employee. 

News of the security incident was published on the department’s website yesterday along with a response plan.

WDH detected the breach on March 10. An investigation into the incident revealed that the health information of approximately 164,021 Wyoming residents and others could have been exposed as early as November 5, 2020.

Data in the leaked files included the results of tests for influenza and COVID-19 performed across the United States between January 2020 and March 2021. One file containing breath alcohol test results was also exposed. 

Along with the test results were patients’ names, ID numbers, addresses, dates of birth, and dates of when tests had been carried out.

“These files were mistakenly uploaded by a WDH Public Health Division workforce member to private and public online storage locations, known as repositories, on servers belonging to GitHub.com,” said WDH.

The department added that the information “was also unintentionally disclosed, meaning it was made available to individuals who were not authorized to receive it, on GitHub’s public site as early as January 8, 2021.”

WDH has begun the process of notifying impacted individuals but said that it did not have contact details for some of the victims of the breach. Those whom it does manage to reach will be offered a year of free identity theft protection. 

“While WDH staff intended to use this software service only for code storage and maintenance rather than to maintain files containing health information, a significant and very unfortunate error was made when the test result data was also uploaded to GitHub.com,” said WDH director Michael Ceballos.

He added: “We are taking this situation very seriously and extend a sincere apology to anyone affected. We are committed to being open about the situation and to offering our help.”

Jeri Hendricks, Office of Privacy, Security, and Contracts administrator with WDH, said that the files have been removed from GitHub and GitHub has destroyed any “dangling data” from its servers.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Alsid SAS Acquired by Tenable

Alsid SAS Acquired by Tenable

Tenable Holdings has completed its acquisition of Active Directory security startup Alsid SAS.

The deal, which was first announced in February, was officially closed on April 26 with a cash payment of $98m.

Alsid was founded in France in 2016 by Emmanuel Gras and Luc Delsalle, two former incident responders from the French National Cybersecurity Agency (ANSSI).

The newly acquired company is best known for its Software as a Service (SaaS) solution that allows organizations to monitor the security of Active Directory in real time. 

News of the completed acquisition was shared yesterday and coincided with the launch of new cybersecurity solution Tenable.ad. The product uses Alsid technology to defend against threats and maintain the security of Active Directory environments.

Developed as a SaaS solution, Tenable.ad allows users to detect and mend existing weaknesses in their digital estate. It can also detect ongoing attacks in real time without the need to deploy agents or use privileged accounts.

Tenable CEO and chairman Amit Yoran said that it is important to protect Active Directory as it is commonly targeted by threat actors who gain unauthorized access to a company’s computer network.

“Understanding your Active Directory security posture is a strategic and important complement to vulnerability management and is imperative to managing risk, especially in complex cloud and hybrid environments,” said Yoran.

He added: “We are delighted to welcome the Alsid team to Tenable and to offer Tenable.ad to our customers so we can help them focus on the security challenges that pose the greatest risk to their business.”

Emmanuel Gras, CEO and co-founder of Alsid, said that the acquisition put a stamp of approval on what his company has achieved so far. 

“While this milestone is important validation, we’re even more excited about the opportunities ahead of us as we integrate capabilities and expand into new markets globally,” said Gras.

Describing the relationship between the two newly joined companies, Gras said: “We share a singular vision to help our customers with a more holistic approach to foundational cybersecurity that includes powerfully effective solutions to prevent and detect Active Directory-focused attacks.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

G7 Nations Sign Declaration to Keep the Internet Safe and Open

G7 Nations Sign Declaration to Keep the Internet Safe and Open

G7 nations have signed a new declaration that promises to boost online safety worldwide in accordance with open democratic principles.

The joint ministerial declaration, signed by tech leaders from the UK, Canada, France, Germany, Italy, the US, and the EU, agreed on a range of principles to tackle cyber-risks. These emphasize that any action taken to tackle cybercrime must support democratic ideals and respect human rights and fundamental freedoms.

The announcement has come amid growing concerns about the influence of nations with illiberal values, such as China, in cyberspace, and the market power of big tech platforms, which potentially threatens competition and even free speech online.

The agreements relate to the following areas:

  • Internet safety principles, in which the G7 countries have committed to protecting human rights online and agreed that tech firms are responsible for their users’ safety
  • A framework for the use of electronic transferable records to make it easier for companies to use digital solutions for the shipment of goods and trade finance
  • Agreement that a more coordinated approach to regulation and promotion of competition is needed in digital markets
  • Cooperation between the G7 to develop best practices for the safe and free flow of data across priority areas, including transport and science and research
  • Working together on how democratic governments and stakeholders can support the creation of digital technical standards that enable a free, open, and secure internet

During the virtual meeting, hosted by UK digital secretary Oliver Dowden, the representatives of the G7 also discussed the need to enhance security and resilience in critical digital infrastructure, especially in telecommunications technologies such as 5G.

Dowden commented: “As a coalition of the world’s leading democracies and technological powers, we want to forge a compelling vision of how tech should support and enhance open and democratic societies in the digital age.

“Together we have agreed a number of priorities in areas ranging from internet safety to digital competition to make sure the digital revolution is a democratic one that enhances global prosperity for all.”

The agreements are part of the first of seven ministerial declarations expected to be signed this year by the G7 governments.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#GartnerIAM: Pandemic Disruption Necessitates a Transformation in Identity Access Management

#GartnerIAM: Pandemic Disruption Necessitates a Transformation in Identity Access Management

There needs to be a transformation in identity access management (IAM) as a result of digital acceleration during the COVID-19 pandemic, according to Tricia Phillips, sr director analyst, Gartner, speaking during the Gartner Identity & Access Management Summit – EMEA.

Phillips firstly highlighted how lockdown restrictions had disrupted our everyday lives, including the way we work, parent, bank and socialize. This distributed world has had a major impact on cybersecurity, where “control and access has had to be decentralized just to support the changing demands of the business.” She added: “Our IAM architecture was not designed for this level of decentralization, and that’s left gaps in our security.”

In many ways, the crisis rapidly accelerated digital transformation plans that were already in the pipeline for many businesses. “Crisis is the mother of transformation,” stated Phillips.

In her view, to adapt to the new environment, IAM must transform. “Not tweak, adjust or modify slightly, but change completely,” she clarified.  

Phillips noted that as a result of distributed workforces, cyber-criminals are increasingly using account compromise to attack organizations. “While they may have different strategies like exploiting supply chain vulnerabilities or using weak or unmanaged service credentials, they all have one thing in common – they use the compromise of user or machine identity to gain access and profit,” she outlined.

As a result, “it’s clear that the battle ground for cybersecurity starts and ends with identity.

As well as the development of new technologies, we also have to think radically differently about the make-up of security teams in order to reshape IAM, according to Phillips. “We have to change how we think about IAM, how we approach IAM and how we staff IAM roles,” she said.

Promoting diversity, such as neurodiversity, gender diversity and racial diversity is critical to ensure a broad range of experiences and thought processes are at play. Phillips explained that she has more than 20 years’ experience in the cybersecurity industry in a range of high profile positions, “but if I look at most cybersecurity job postings, I don’t meet the qualifications.” This is because her educational background is in English literature, rather than traditional STEM subjects. Yet, she noted “I have been successful in this industry largely because I come at security problems from a different perspective.”

The value in having people from diverse backgrounds is that they “will ask new questions, make new connections, and through the process, the entire team starts making new connections and asking new questions, and together the team is transformed and the outcomes are transformed,” commented Phillips.

She concluded: “There are identity technologies that will help you along your journey, but do not underestimate the importance of people, policies, processes and creativity, in meeting the challenges of the future.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Security Spending Doubles but Two-Fifths of Firms Suffer Breaches

Security Spending Doubles but Two-Fifths of Firms Suffer Breaches

Cybersecurity spending across the US and Europe has surged over the past year, but so too have security breaches, from 38% to 43% of businesses surveyed by Hiscox.

The insurer’s annual Hiscox Cyber Readiness report has become a useful gauge of how mature and effective organizations’ cybersecurity strategies are. This year the firm engaged Forrester Consulting to poll over 6000 such companies across the US, UK, Belgium, France, Germany, Spain, the Netherlands and Ireland.

It revealed that the average firm now spends more than a fifth (21%) of its IT budget on cybersecurity, an increase of 63% in a year, with mean spending per firm more than doubling in two years — from $1.45 million to $3.25 million.

However, this money isn’t necessarily improving outcomes, given that successful attacks are on the rise. Over a quarter (28%) of those targeted suffered five or more such attacks, with almost a fifth (17%) claiming the financial impact materially threatened the company’s future.

Ransomware had a major impact on organizations last year: 16% suffered attacks and over half (58%) paid up, rising to 71% in the US, according to the report.

Hiscox also appraises organizations by their “cyber readiness” across six key areas of people, process and technology.

It found there was much work still to do, with just a fifth (20%) named as “experts” and more than a quarter (27%) classed as “novices.”

Perhaps unsurprisingly, those deemed experts suffered fewer ransomware attacks, were less likely to pay up and recovered more quickly.

The US had the highest proportion of cyber “experts” (25%) and one of the lowest median costs of attacks. Although the UK ranked second, with 23% of firms named as experts, they were least likely to have had a cyber-attack (36%) and most likely to have defended it successfully, according to Hiscox.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Average Ransom Surges 43% After Accellion Attacks

Average Ransom Surges 43% After Accellion Attacks

The average payment to ransomware groups has surged by 43% over the past quarter, driven by the threat actors behind the Accellion attacks, according to Coveware.

The security vendor’s quarterly report for Q1 2021 revealed that the average ransom was $220,298 during the period, with data exfiltration now a major extortion tactic present in the vast majority (77%) of attacks, up 10% from the previous quarter.

Yet while most ransomware groups simply steal data for extra leverage, as proof an attack occurred and in some cases to create legal obligations for victim organizations, the Clop gang took a different approach in its targeting of Accellion, Coveware claimed.

The group has been linked to attacks on customers of the vendor’s legacy FTA product in December 2020 and January 2021 which resulted in the theft of valuable data. These attacks exploited multiple zero-day bugs in the product which Accellion since patched — but in some cases, fixes were applied or released too late to protect the victims.

Unlike most other ransomware attempts, this campaign focused solely on data theft, eschewing ransomware altogether, Coveware noted.

“This was a highly sophisticated and targeted exploitation of a single software appliance, only used by a handful of enterprises. The CloP group may have purchased the exploit used in the initial stages of the attack, so as to have exclusive use,” it explained.

“This behavior stands in stark contrast to how most unauthorized network access is brokered through the cyber extortion supply chain to any willing purchaser post exploitation.”

Although the group behind the attacks has never formally been named, FireEye produced an analysis in February which named financial cybercrime gang FIN11, which itself has numerous links with Clop including using the same attack infrastructure and data leak site.

“Unlike most exploits used by ransomware threat actors, unpatched Accellion FTA instances are rare (likely less than 100 total), especially when compared to vulnerable RDP instances which number hundreds of thousands globally,” Coveware said.

“Clop’s confidence that such a small number of targets would yield a positive financial return must have been high and, unfortunately, they were correct.”

However, in the end, the majority of the corporate victims targeted by Clop refused to pay and had their data exposed online by the group. The ransomware actors have apparently since returned to more traditional network access vectors (ie RDP) and encryption to make their money.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#COVID19 Rattles Banks and Insurers as Security Budgets Are Slashed

#COVID19 Rattles Banks and Insurers as Security Budgets Are Slashed

Financial institutions in the US and UK cut security budgets by a quarter last year and saw cybercrime and fraud activity rise by about the same amount during the pandemic, according to new research from BAE Systems Applied Intelligence.

The British cybersecurity and risk management firm engaged Atomik Research to poll nearly 1000 banks and insurers and 2000 consumers in the US and UK back in March, in order to better understand the impact of COVID-19 on the industry.

It found that three-quarters (74%) of responding organizations experienced a rise in cybercrime since the start of the pandemic, with botnet attacks (35%), ransomware (35%), phishing (35%), mobile malware (32%), COVID-related malware (30%) and insider threats (29%) particularly common.

Although there’s no direct link between the two, the research revealed that budgets were cut by around the same amount (26%) as cybercrime increased (29%).

With the pandemic and budget cuts also came a surge in financial losses from cybercrime, growing 56% over the past 12 months to reach $720,000 on average.

Two-thirds (42%) of responding organizations said they felt remote working made them less secure, while a similar number (44%) claimed it had made it harder to gain visibility into potential network blind spots.

“We’re noticing a clear collaboration emerging between different groups of criminals across the wider landscape of serious and organized crime. Fraudsters and cyber-criminals seek to exploit fear, uncertainty and change, and the pandemic has offered them new opportunities to probe for weaknesses they can monetize and new ways to disguise their activity” said BAE System Applied Intelligence head of cyber, Adrian Nish.

“Attackers are building increasingly advanced capabilities to target core banking systems and becoming more aggressive, harming victims’ ability to respond to attacks. Online criminals have reacted fast, adapting their approach to hunt out remote working security gaps and prey on the vulnerable.”

Despite the pressures COVID-19 has put on cyber and fraud teams inside banks and insurers, there are opportunities to differentiate by improving customer outreach, education and protection, the report found.

More than half (53%) of consumers surveyed argued that it is the job of the banks to protect them, versus 40% that said it was their own responsibility. The same number (53%) said banks or credit card providers could provide more guidance on how to stay safe from cybercrime.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk