Data Breach at New England’s Largest Energy Provider

Data Breach at New England’s Largest Energy Provider

A misconfiguration error has exposed personal data belonging to customers of New England’s largest energy provider.

On March 16, Eversource discovered that one of its cloud data storage folders had erroneously been set to open access rather than to restricted access. 

The company serves more than 3.6 million electric and natural gas customers in Connecticut, Massachusetts, and New Hampshire.

An investigation into the data breach launched by Eversource’s security team found that the unsecured folder contained personal data belonging to customers residing in eastern Massachusetts. 

Information exposed in the incident included names, addresses, phone numbers, Social Security numbers, billing addresses, and Eversource account numbers and service addresses. 

The folder was secured on the same day that the error was detected, and the company’s security team do not believe that the personal information it contains was accessed, stolen, or misused by any unauthorized third parties. 

Cybersecurity company CyberScout is handling customer service related to the breach on behalf of Eversource.  A “frequently asked questions” document created by CyberScout states that the data breach impacted about 11,000 customers. 

The document states that the exposed files were created in August 2019, making the data breach a prolonged incident lasting a year and seven months. It also reveals that the information was stored in an unencrypted format. 

One Eversource customer who received written notification from the company that their data had been impacted by the breach shared their displeasure on Reddit.

“I’m definitely not happy with Eversource right now, and I imagine a lot of people are going to be getting these letters over the next few days if they haven’t already,” they said.

“Organizations need to have security processes and procedures in place when utilizing cloud and on-site servers when exposed to the internet,” commented James McQuiggan, security awareness advocate at KnowBe4.

“When organizations start to use any cloud service, it needs to be locked down and restricted access provided to only necessary and authorized users. Infosec and IT departments want to ensure they collaborate with all departments that require an offsite server for development and verify the system is not openly available to the internet,” he added.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

TikTok Sued Over Use of Minors’ Data

TikTok Sued Over Use of Minors’ Data

Video-sharing social networking service TikTok is being sued for billions of dollars over its alleged mishandling of children’s data. 

TikTok, which is owned by Chinese company ByteDance, has more than 800 million users worldwide. Internal company data from July 2020 reported by the New York Times showed 18 million TikTok users were aged 14 years or younger.

The claim against the company has been filed by Anne Longfield, children’s commissioner for England, on behalf of the millions of minors in the UK and the EU who have used TikTok since May 25, 2018, whether they have a TikTok account or not. 

In the legal challenge, TikTok is accused of harvesting children’s personal information without sufficient notice, transparency, or the consent required under British and European Union law. 

Children’s data that the company allegedly mishandles includes biometric information, location data, videos, and phone numbers. 

If the claim is successful, minor users could each receive thousands of pounds. Children who used TikTok but who do not wish to be included in the suit can opt out of being represented. 

Longfield told the BBC that TikTok’s data collection practices were “shadowy” and “excessive” compared to those of other social media companies.

“TikTok is a hugely popular social media platform that has helped children keep in touch with their friends during an incredibly difficult year. However, behind the fun songs, dance challenges and lip-sync trends lies something far more sinister,” said Longfield.

According to the children’s commissioner, TikTok is “a data collection service that is thinly veiled as a social network” and has “deliberately and successfully deceived parents.”

Tom Southwell, partner at law firm Scott and Scott, which filed the claim against TikTok, said the social media company’s data collection policies were in “severe breach of UK and EU data protection law.”

TikTok said the case brought against it by Longfield is baseless. In a statement shared by the BBC, the company said: “Privacy and safety are top priorities for TikTok and we have robust policies, processes and technologies in place to help protect all users, and our teenage users in particular. We believe the claims lack merit and intend to vigorously defend the action.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Rapid7 Acquires Open Source Monitoring Platform Velociraptor

Rapid7 Acquires Open Source Monitoring Platform Velociraptor

Rapid7 has announced the acquisition of open source software technology and community Velociraptor.

The move will enable Rapid7 to enhance its incident response capabilities by leveraging Velociraptor’s open source platform, which is used for endpoint monitoring, digital forensics and incident response.

Velociraptor was developed to help digital forensics and incident response (DFIR) professionals to discover and monitor malicious activities. The platform’s community style also allows DFIR pros to share their insights with one another. It’s also unique in allowing custom detections, collections and analyses capabilities to be written in queries, rather than code. This enables the queries to be shared easily, helping teams hunt for threats quickly.

In making the purchase, Rapid7 emphasized its support for open-source software. Richard Perkett, senior vice president of detection and response at Rapid7, commented: “Rapid7 has a long track record of supporting open-source projects that began when we acquired Metasploit in 2009 and that commitment and support continues today.

“We strongly believe that partnership with the open source community is one of the most important ways to move the security industry forward and make the digital world a safer place for everyone. We look forward to bringing our expertise in growing and nurturing open-source communities to Velociraptor, while also enhancing our monitoring, digital forensics, and incident response capabilities for customers.”

Velociraptor founder, Mike Cohen, who will also join Rapid7, said: “This is an exciting time for Velociraptor and the DFIR community. Velociraptor will greatly benefit from the investment, experience, and resources Rapid7 can bring to this community and I look forward to leading Velociraptor through this next phase of its evolution.”

The deal is the latest in a number of recent acquisitions by Rapid7 at it looks to expand its security and analytics capabilities. Earlier this year it announced the purchase of Kubernetes security provider Alcide.IO, and last year acquired cloud security company DivvyCloud.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Government Pressing Ahead with New IoT Law Amid Pandemic Smart Device Surge

UK Government Pressing Ahead with New IoT Law Amid Pandemic Smart Device Surge

The UK government is pushing forward with legislation that imposes new security obligations on the manufacturers of Internet of Things (IoT) devices, the Department of Digital, Media and Sport (DCMS) has announced today.

The announcement has come amid growing use of IoT devices, with the UK government highlighting figures from the end of last year showing that almost half (49%) of UK residents have purchased at least one smart device since the start of the COVID-19 pandemic. There have been numerous security concerns with these devices in recent years, which need to be addressed to keep consumers and businesses safe.

Smartphones will now be in scope of the secure by design legislation, with the government pointing to recent research by Which? that found that although a third of people kept their last phone for four years, while some brands only offer security updates for a little over two years.

Among the provisions of the law, makers of smart devices such as phones, speakers and doorbells will be required to inform customers how long a product will be guaranteed to receive security software updates. Manufacturers will also be banned from using universal default passwords that are easily guessable like ‘password’ or ‘admin’ in a device’s factory settings.

Additionally, they will be obliged to provide a public point of contact to make it easier for anyone to report a vulnerability.

The laws were initially proposed at the start of last year, which built on a non-binding code of practice introduced in 2018.

The government added it will introduce the legislation as soon as parliamentary time allows.

Digital Infrastructure Minister Matt Warman said: “Our phones and smart devices can be a gold mine for hackers looking to steal data, yet a great number still run older software with holes in their security systems.

“We are changing the law to ensure shoppers know how long products are supported with vital security updates before they buy and are making devices harder to break into by banning easily guessable default passwords.

“The reforms, backed by tech associations around the world, will torpedo the efforts of online criminals and boost our mission to build back safer from the pandemic.”

Yesterday, the open industry alliance, FIDO, announced the development of a new standard to help onboard IoT devices quickly and securely.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Codecov Supply Chain Attack May Hit Thousands: Report

Codecov Supply Chain Attack May Hit Thousands: Report

Experts have urged organizations to reassess cyber-risk in their supply chains as it emerged that hundreds of customers of a software auditing company had their networks accessed illegally.

Originally thought only to have affected the supplier, San Francisco-based Codecov, the incident is now believed to have been a deliberate supply chain attack likened in sophistication to the SolarWinds operation.

Investigators told Reuters that the attack had already led to hundreds of customers’ networks being accessed. Codecov’s customer-base of around 29,000 includes many big tech brands such as IBM, Google, GoDaddy and HP, as well as publishers (The Washington Post), consumer goods firms (Procter & Gamble) and many more.

The firm delivers tools enabling developers to gain visibility into how much source code executes during testing (code coverage), to help them produce more reliable and secure products.

However, an error in one of the firm’s Docker images allowed a threat actor to steal credentials and modify a critical Bash Uploader script used by customers.

Although the incident was discovered on April 1, Codecov said that “periodic, unauthorized alterations of our Bash Uploader script by a third party” had been occurring from January 31 onwards.

The firm said this gave attackers access to any credentials tokens or keys stored in customers’ continuous integration (CI) environments, and in turn any services, datastores and app code accessed via these credentials.

An investigator told Reuters that, by targeting tech companies, attackers could have used this technique to access thousands of restricted networks.

Calvin Gan, senior manager at F-Secure’s Tactical Defense Unit, urged organizations to treat third-party vendors like Codecov as part of their organization when performing security audits, and to do these audits regularly — ensuring all configurations are verified.

“Always understand and weigh the risk involved when using any third-party service such as Codecov. While the service offered is a valuable one, it is also good to review or limit what is being sent over to these services, especially if it contains credentials or sensitive information,” he added.

“This is not easy, especially if the service is a trusted one by the company. But weighing the risk involved and having a backup/response plan early enough would come in handy when breaches such as this are discovered.”

Stuart Reed, UK Director at Orange Cyberdefenseargued that the security industry should focus less on the details and more on understanding the bigger picture.

“We need to recognize that the security landscape is deeply fluid and dynamic, reshaping itself rapidly and continuously, and position ourselves to perceive and respond to it appropriately. We should not be distracted by the identity of the attacker, or the speculation about state-backed adversaries,” he said.

“Ransomware attacks, botnets, crypto-miners and the like, all follow the same ‘opportunistic’ philosophy in which no target is too small or insignificant. This is why it’s crucial for a new way of thinking, moving away from naïve rules-based security practices towards an agile, intelligence-based approach.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk