US Imprisons “Sadistic” Sextortionist

US Imprisons “Sadistic” Sextortionist

A man from California has been sent to prison for cyberstalking two people and threatening to murder them unless they performed sex acts on him.

US Judge Dolly Gee described the actions of Covina resident Carl De Vera Bennington as “sadistic” and “cruel” before handing him a custodial sentence.

One of the victims of 34-year-old Bennington was just a teenager when he began targeting her. The cyberstalking took place over a period of several years, with Bennington repeatedly sending unsolicited messages.

When one victim tried to end the abuse by blocking Bennington from her social media accounts, the determined cyberstalker created new accounts via which he carried on abusing her. 

Between June and November 2019, Bennington bombarded the victim with sexually explicit images and insulting messages. San Gabriel Valley resident Bennington also demanded that the victim engage in sexual acts with him. 

When the victim refused to comply with his demands, Bennington threatened to sexually assault her. She demanded that he stop his harassment of her. He responded by threatening to kill the victim and her family.

The second victim deactivated her social media accounts in 2017 after Bennington repeatedly sent her messages in which he solicited sex from her. When she reactivated her social media accounts in August 2019, Bennington sent her numerous messages in which he threatened to kill her if she didn’t respond to his sexual demands. 

According to an affidavit filed with a criminal complaint in the case against Bennington, the cyberstalker never met either of his victims in person. 

The Department of Justice said: “Bennington frequently promoted incel (involuntarily celibate) ideology, which involves individuals who are unable to find a willing sex partner and promotes the view that women oppress men and have too much freedom to choose their own sexual partners.” 

In December 2020, Bennington pleaded guilty via videoconference to two counts of cyberstalking. Despite his mental health issues, on April 14 Bennington was sentenced to 18 months behind bars. 

According to the sentencing memo, a custodial term was warranted because of Bennington’s long pattern of cyberstalking activity and “his deep-seated and violent ideology regarding women.” 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Sanctions Escalate US–Russia Tensions

Sanctions Escalate US–Russia Tensions

Relations between the United States and Russia have soured following the imposition of new sanctions by the Biden administration on America’s former Cold War enemy.

The measures were introduced today in retaliation for cyber-attacks and election interference that the United States says were carried out by Russia. President Joe Biden announced the sanctions earlier today in one of the more than 50 executive orders he has signed during his first four months in power. 

In the order, Biden said that “specified harmful foreign activities” of the Russian government “constitute an unusual and extraordinary threat to the national security, foreign policy, and economy of the United States.”

Among the harmful activities listed in the order were “efforts to undermine the conduct of free and fair democratic elections and democratic institutions in the United States and its allies and partners” and engaging in and facilitating “malicious cyber-enabled activities against the United States and its allies and partners.”

The United States says Moscow interfered in the 2020 presidential election and that Russian intelligence officials were behind last year’s Microsoft hack in which attackers exploited SolarWinds’ Orion business software to gain access to nine federal agencies and around 100 American companies.

Sources quoted by Bloomberg say that 32 individuals and entities and six Russian companies that support the Russian government’s hacking operation will be sanctioned. US financial institutions will be barred from participating in certain transactions with the Russian central bank from June 14. 

In addition to the sanctions, the White House said that it will expel 10 Russian diplomats who are currently residing in Washington, DC, including “representatives of Russian intelligence services.” 

Responding to the imposition of the sanctions, Russian government official Dmitry Polyanskiy posted the following message on social media: “Well, actions speak stronger than words! If that’s true and US continues to promote its baseless accusations, it will get adequate response and deprive the world of maybe the last opportunity to avoid Great Powers’ confrontation instead of solving acute problems. Not our choice!” 

Biden’s actions echo the decision by the Obama administration in 2016 to expel 35 Russian diplomats from the US and impose sanctions on Russia in retaliation for election hacking.  

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Arrest Made Over California City Data Breach

Arrest Made Over California City Data Breach

Almost every member of a California city’s finance department has been placed on leave and one has been placed under arrest following a probe into a data breach. 

The city of Huntington Park launched an investigation after becoming aware of a “large-scale security breach of electronic financial records at Huntington Park City Hall” that was “intercepted and contained” by staff in the city’s information technology department. 

Personal information belonging to Huntington Park city residents is not believed to have been compromised in the data breach, according to city officials. However, the city did say that the investigation into what records were accessed or exposed remains ongoing. 

As reported by the Los Angeles Times, a statement issued by the city on April 14 said that the data breach had triggered a criminal investigation by the Huntington Park Police Department (HPPD). 

On April 8, HPPD arrested a 48-year-old city employee and charged them with carrying out a felony offense in connection with the data breach. 

Los Cerritos reports that the city’s budget analyst, Teresa Garcia, was arrested and booked into Los Angeles County Jail at 8:30pm on April 8 on suspicion of identity theft and unauthorized computer access. 

Garcia, who has worked for the department for over a decade, is due to appear before Downey Municipal Court on August 9. 

On Monday, five other finance department employees were escorted from City Hall by police and placed on leave, leading to the closure of the department on Monday and Tuesday. 

City Mayor Graciela Ortiz confirmed that an arrest had been made and said that the data breach had impacted confidential information belonging to an employee. 

“As an elected official, I do not handle personnel matters, that is the role of the City Administrators,” said Ortiz. “However, I can tell you that a serious data breach of confidential data, that includes employee’s identity information, was performed by an employee in the City’s finance department and was discovered by the city’s police department, and the investigation and case was turned over to an independent agency, the Los Angeles County Sheriff’s Department, which resulted in the arrest of the employee.”

She added: “Finance staff was placed on temporary paid administrative leave to maximize the integrity of the on-going Sheriff investigation.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Uni of Hertfordshire Suffers Cyber-Attack That Takes Down its Entire IT Network

Uni of Hertfordshire Suffers Cyber-Attack That Takes Down its Entire IT Network

The University of Hertfordshire in the UK has been hit by a cyber-attack that has taken down its entire IT network as well as blocking access to its cloud-based services.

The higher education institution revealed the attack occurred late on Wednesday 14 April in a statement posted on its website earlier today. As a result, all its online classes scheduled today (15 April) have been cancelled.

The statement read: “Shortly before 22:00 last night, the University experienced a cyber-attack which has impacted all of our systems, including those in the Cloud such as Canvas, MS Teams and Zoom. Please be reassured that our IT colleagues are working hard to rectify the situation as soon as possible.

“However, as a result, all online teaching will be cancelled today (Thursday 15 April), and we understand that this may impact students being able to submit assignments. We want to reassure our students that no-one will be disadvantaged as a consequence of this.

“Any in-person, on-campus teaching may still continue today, if computer access is not required, but students will have no onsite or remote access to computer facilities in the LRC’s, labs or the University Wi-Fi.

“We apologise for the inconvenience this situation has caused and will continue to keep you updated. You can check the status of all our systems by visiting https://status.herts.ac.uk/.”

Currently, there are no further details about the nature of the attack, although there has been a sharp rise in ransomware attacks targeting higher education institutions in the last year, partly as a result of additional vulnerabilities brought about by the shift to online learning during COVID-19. Last year in the UK, Newcastle and Northumbria Universities experienced ransomware incidents, causing significant disruption.

Commenting, Jérôme Robert, director at Alsid, explained that there are a range of reasons why universities are forming tempting targets for cyber-criminals.

“Universities are becoming increasingly aware that they are prime targets for cyber-attacks and ransomware. Although universities’ pockets are not as deep as big enterprises, there are numerous characteristics which make them susceptible to attacks of this nature,” he said.

“The sheer size of the student and faculty at a University – in Hertfordshire’s case nearly 28,000 people – makes it incredibly difficult to secure and manage the IT estate. Think of the huge volume of new joiners and leavers each year at universities: IT teams somehow have to manage that process of creating, deleting and managing all those accounts. It’s a never-ending operation to keep all of that neat and tidy, and any oversights such as old accounts not being closed down present risk. On top of this, higher education is currently at heightened risk because of the increase of network activity and general complexity of enabling hybrid learning.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Europe’s Data Protection Guardians Green Light EU-UK Data Flows

Europe’s Data Protection Guardians Green Light EU-UK Data Flows

The UK’s quest for unhindered data flows to and from the EU took another important step forward yesterday after the European Data Protection Board (EDPB) approved the Commission’s draft adequacy decisions.

Adequacy decisions are the process by which the European Union decides whether countries outside the bloc offer an adequate level of protection for the data of EU citizens. They are critical to granting seamless data flows between the EU and so-called “third countries”  like the UK post-Brexit.

After the European Commission issued two draft adequacy decisions in February 2021 approving the UK’s data protection regime, the EDPB has now recommended their acceptance. The board is an independent European body set up to ensure consistent application of the GDPR.

“The EDPB says that there are key areas of ‘strong alignment’ between the EU and the UK data protection frameworks including on: grounds for lawful and fair processing for legitimate purposes; purpose limitation; data quality and proportionality; data retention, security and confidentiality; transparency; special categories of data; and on automated decision making and profiling,” explained compliance experts Cordery.

“But it is not an unqualified blessing. The EDPB highlights a number of areas requiring further assessment and monitoring including: the UK exception for immigration data; onward transfers; and the role and powers of the security services.”

The latter could be a particular sticking point, given the outsized powers for mass surveillance the UK’s Investigatory Powers Act grants to its intelligence services. It was a similar issue which led to the collapse of the Safe Harbor and Privacy Shield data sharing agreements between the EU and US.

In a similar manner, privacy groups may well challenge any official EU decision in the courts, as happened with the now famous Schrems cases.

That’s why Cordery is advising its clients to ensure they make alternative arrangements in case the adequacy decisions aren’t confirmed, or as insurance against any successful future challenge.

This includes things like updating privacy policies, mapping data flows in and out of the UK, putting agreements in place to protect data transfers, doing due diligence on suppliers, and even data localization in the long-term.

The UK’s temporary data deal with the EU will expire at the end of this month unless renewed. It desperately needs an adequacy decision given the size of its digital economy. The UK’s e-commerce market is the largest in the region, for example.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Man Gets 10 Years for Multimillion-Dollar Medicare Fraud Scheme

Man Gets 10 Years for Multimillion-Dollar Medicare Fraud Scheme

A Florida man has been sentenced to a decade behind bars after investigators discovered $3.3 million in fraudulent Medicare claims for genetic cancer testing that patients didn’t need.

Ivan Andre Scott, 36, of Kissimmee, was convicted by a federal jury in January on one count of conspiracy to commit health care fraud, three counts of health care fraud, one count of conspiracy to pay and receive unlawful healthcare kickbacks, and three counts of receiving unlawful kickbacks.

He is said to have targeted Medicare patients via his Scott Global telemarketing company, cold-calling and persuading them they were eligible to receive cancer screening genetic (CGx) tests, which usually cost an estimated $6000 each.

He is then said to have paid bribes to telemedicine companies to have doctors authorize the tests, despite never having seen the patients or treated them for cancer-like symptoms.

Scott was then able to sell the doctors’ orders for these tests to laboratories, which paid him kickbacks in return. Scott submitted invoices to the labs for hourly marketing services rather than per referral, to conceal what was going on.

The labs are said to have submitted over $3.3 million in claims to Medicare for these tests, of which the government health insurance program paid out over $1.3 million. Scott received $194,000 for his role in the scheme.

“Fraudsters who steal from taxpayer-funded federal health care programs and engage in predatory telemarketing calls are a threat to our country’s healthcare system and its most vulnerable beneficiaries,” said special agent in charge Omar Pérez Aybar of the US Health and Human Services, Office of Inspector General.

“Our agents will continue to aggressively investigate health care fraud and hold criminals responsible for their actions.”

Healthcare fraud is big business in the US and has been growing during the pandemic, with a surge in telemedicine appointments providing cover for dishonest doctors, telemarketers, labs and other stakeholders.

Operation Double Helix, under which this case was investigated, has already resulted in charges against dozens of individuals associated with telemedicine companies and cancer genetic testing laboratories.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Global Attacker Dwell Time Drops to Just 24 Days

Global Attacker Dwell Time Drops to Just 24 Days

Organizations are spotting attackers inside their networks faster than ever before, although the figure for “dwell time” may have been influenced by a surge in ransomware attacks, according to Mandiant.

The FireEye-owned forensic specialist’s M-Trends 2021 report was compiled from investigations of targeted attack activity between October 1, 2019 and September 30, 2020.

It revealed that 59% of organizations detected attackers within their own environments over the period, a 12-percentage point increase on the previous year.

The speed at which they did so also increased: dwell time for attackers inside corporate networks fell below a month for the first time in the report’s history, with the median global figure now at 24 days.

This is in stark contrast to the 416 days it took firms when the report was first published in 2011. It’s also more than twice as fast as the previous year (56 days), and shows that detection and response is moving in the right direction.

For incidents notified to firms externally, the figure was slightly higher (73 days) and for internally detected attacks it was lower (12 days).

In the Americas, dwell time dropped from 60 days in 2019 to just 17 days last year, while in APAC (76 days) and EMEA (66 days) the figure increased slightly.

However, a major contributing factor to the global reduction in dwell time may be the proliferation of ransomware attacks, which usually take place over a shorter time frame than traditional cyber-espionage or data theft operations.

“A major factor contributing to the increased proportion of incidents with dwell times of 30 days or fewer is the continued surge in the proportion of investigations that involved ransomware, which rose to 25% in 2020 from 14% in 2019,” the report noted.

“Of these ransomware intrusions, 78% had dwell times of 30 days or fewer compared to 44% of non-ransomware intrusions.”

Mandiant explained that ransomware actors are using an increasingly wide range of tactics to force payment from their victims. These include data theft and exposure on “name and shame” websites, harassment of employees and business partners, persuading journalists to write stories about affected companies and even launching denial of service attacks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CISOs Must Focus on People and Technologies Amid Rising Attacks

CISOs Must Focus on People and Technologies Amid Rising Attacks

Strategies CISOs need to put in place to deal with a rising volume of attacks were discussed by a panel of security leaders during a webinar. Set up by cybersecurity firm F-Secure, the session was built upon the latest findings from its CISOs’ New Dawn report, which surveyed 28 senior information security leaders across the US, UK and Europe about how their roles have changed as a result of the COVID-19 pandemic.

The discussion began by highlighting the how cyber-criminals have ramped up the targeting of employees since the shift to remote working during COVID-19. Indeed, the report found employees were the most popular attack vector in the past year. Marc Ashworth, CISO at First Bank, explained that a lot of these attacks were based around phishing, and therefore investing in email security and stepping up training exercises for staff is critical. At First Bank, he said controls have been introduced recently “to help signify an external email versus an internal email,” alongside other help for staff in detecting potentially malicious messages.

Michael Greaves, security advisor, managed detection and response at F-Secure noted, while these kinds of preventive steps are important, even with the best will in the world, organizations have to accept there is a high likelihood of mistakes being made when it comes to phishing. “Things are going to get past those controls and you want to have something in place to stop the consequences of that leading to a mass incident across your environment,” he outlined.

Focusing on staff and the security culture within an organization is the most important aspect, according to Chani Simms, SHe CISO founder & CEO. “Often I see the problem lies with people, right from the leadership level to employee level where there’s a lack of awareness,” she noted. To address this, awareness training has to be conducted regularly to engender the right security culture. “You can’t just have one security awareness session a year and then think your security is going to be better,” she stated.

The technological investments to protect organizations in the current threat environment were also highlighted by the panel. Sims emphasized the importance of opting for a secure by design strategy, which means when building an IT infrastructure, “you have to think of security in every layer.” She added: “if you don’t build your IT infrastructures securely, problems can happen.” It is also about creating platforms that ensure when a breach occurs, there are other controls that stop it getting worse.

In the view of Erka Koivunen, CISO at F-Secure, managed detection and response (MDR) technology is a vital component of security by design. “It nicely completes the security control framework because it provides me with visibility to those dark spots,” he said, adding it enables the “same visibility a potential attacker has to my estate.”

Ultimately, when deciding upon the right security technologies to invest in, Ashworth emphasized the importance of CISOs assessing a range of factors relating to the individual circumstances of their organization. “It’s about measuring the risk and the cost benefit,” establishing “where are those gaps that you might have in your organization that can cause the risk and weighing that from a budget standpoint to determine where you need to allocate those limited funds,” he explained.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New Jersey School Districts Investigate Cyber-Attacks

New Jersey School Districts Investigate Cyber-Attacks

Cyber-attackers are believed to be targeting school districts in the New Jersey county of Somerset.

Security incidents that occurred in the county over the past week caused day-long school closures at two educational establishments. Schools in Bernards were closed on April 7 and Hillsborough schools were shuttered on April 12 following suspected cyber-attacks. 

Computer systems and staff voicemail at Hillsborough remained down on Tuesday. However, students and staff have been able to access lessons virtually. 

“Our technology team continues to work methodically with cybersecurity experts and law enforcement to establish a timetable for the completion of the restoration of the operation of our systems,” Hillsborough superintendent of schools Lisa Antunes told parents in an email dated April 13.

She added: “This is an overwhelmingly complicated task with many moving parts.” 

While the investigation into the incident is ongoing, the superintendent was unwilling to give away many details. 

“We are very limited in sharing the many factors that affect information we can provide to staff and families,” said Antunes. “A timetable for the completion of the restoration of the operations of our systems cannot be provided at this time.”

She added that the decision to close the school on Monday had been taken on the advice of the FBI and law enforcement “in an effort to minimize damage to the organization,” opening up the possibility that the district has been hit by ransomware. 

“Several hours ago, our technology department was alerted to a possible cyber-attack,” wrote Antunes in a message posted to the school’s Messenger page. 

“Law enforcement, including the FBI, recommended shutting our systems down so that we may be able to ascertain the depth of the attack.”

Bernards schools superintendent Nick Markarian told parents that the security incident affecting the district was “server focused.” He said that individual Chromebooks, laptops, smartphones, and other devices connected to the district’s network had not been compromised. 

Markarian added that “additional protections will be added to all district issued devices in the coming days to monitor their health in new ways” as a precaution. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Aviation Industry Lacks Cohesive Cybersecurity Approach

Aviation Industry Lacks Cohesive Cybersecurity Approach

A new study published today by the World Economic Forum (WEF) has identified the need for cybersecurity practices within the aviation sector to be unified. 

The study—Pathways to a Cyber Resilient Aviation Industry—describes how airlines, airports, and aircraft manufacturers currently take different approaches to countering cyber-risks. It includes a warning that rising levels of interdependency within the industry “can lead to systemic risks and cascading effects.”

To guard against these risks, the WEF connected with leaders from 50 organizations, including ACI, EASA, IATA, and Eurocontrol, to determine how the aviation sector can prepare against future security incidents and cyber-attacks. 

The coalition urged the global adoption of nine principles it came up with to unify security requirements across the industry.

On an international level, the coalition would like to see regulations aligned globally and the development of international information-sharing standards. It also called for the creation of an impartial assessment and benchmarking framework and a baseline of cyber-resilience across the supply and value chain.

Nationally, the group want re-skilling to be enabled and more-open communication regarding aviation incidents to be rewarded.

Organizational priorities expounded upon by the coalition were the integration of cyber-resilience in business resilience practices, the improvement of collaboration, and the need to ensure risk assessment and prioritization around cybersecurity.

“The aviation industry has developed a strong track record of safety, resilience and security practices for physical threats and must integrate cyber risks into this culture of safety and resilience,” said Georges De Moura, head of industry solutions, Center for Cybersecurity, World Economic Forum. 

“A common understanding and approach to existing and emerging threats will enable industry and government actors to embrace a risk-informed cybersecurity approach to ensure a secure and resilient aviation ecosystem.”

Chris Verdonck, partner at Deloitte, Belgium, said that creating trust between cross-sector organizations and national and supranational authorities, as well as adopting a collaborative cyber-resilience stance, would be a “logical yet challenging next step” for the aviation industry.

He added: “However, if the effort is not collective, cyber risks will persist for all. Further solidifying an extensive and inclusive community and developing and implementing a security baseline is key to adapt to the current digital reality.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk