Facebook Removes 16k Groups for Trading Fake Reviews

Facebook Removes 16k Groups for Trading Fake Reviews

Social media giant Facebook has removed thousands of groups from its platforms over the trading of fake and misleading reviews.

The cull occurred after two separate interventions by Britain’s competition watchdog, the Competition and Markets Authority (CMA).

In January 2020, Facebook committed to improving its identification, investigation, and removal of groups and other pages where misleading and fake reviews were being traded, and to preventing their return. Four months later, Facebook gave a similar pledge in relation to its Instagram.com business.

During a follow-up investigation, evidence was found that fake reviews were still being traded on both platforms, prompting the CMA to intervene for a second time.

The CMA said on Friday that Facebook had taken down a further 16,000 groups that were dealing in fake and misleading reviews. The company has also changed the way it identifies, removes, and blocks from its platforms paid content that could mislead Facebook and Instagram users. 

“We have engaged extensively with the CMA to address this issue,” said a spokesperson for Facebook. 

“Fraudulent and deceptive activity is not allowed on our platforms, including offering or trading fake reviews.”

Facebook has committed to suspending or banning users who repeatedly create Facebook groups and Instagram profiles that promote, encourage, or facilitate fake and misleading reviews. New automated processes will be introduced to improve the detection and removal of this content. 

Changes will be made to Facebook’s search tools to make it harder for people to find fake and misleading review groups and profiles on Facebook and Instagram.

“The pandemic has meant that more and more people are buying online, and millions of us read reviews to enable us to make informed choices when we shop around. That’s why fake and misleading reviews are so damaging,” said CMA chief executive Andrea Coscelli.

Facebook’s sluggish response to the problem of fake reviews does not sit well with Coscelli.

They said: “Facebook has a duty to do all it can to stop the trading of such content on its platforms. After we intervened again, the company made significant changes—but it is disappointing it has taken them over a year to fix these issues.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Jails Cyber-stalker Who Targeted Attack Survivor

US Jails Cyber-stalker Who Targeted Attack Survivor

The United States has imprisoned the cyberstalker of a woman who, as a child, survived a violent assault that claimed the life of her friend. 

According to court records, the victim was in a Texas bedroom with another girl in December 1999 when an assailant entered and slit both the little girls’ throats. The perpetrator was later caught and convicted of the crime.

Alvin Willie George of Cross City, who has no connection to the surviving victim, admitted harassing her and her sisters online 17 years after the horrific attack unfolded. 

For several months, starting in or around November 2016, 25-year-old George sent photos from the 1999 crime scene to the surviving victim and her sisters, all of whom live in Idaho. 

“George did not know the surviving victim or her sisters, rather he researched the 1999 murder on the internet and used various Facebook accounts he created to send harassing and intimidating messages to these women, as well as threatening to rape and kill them,” said the US attorney’s office for the district of Idaho. 

The case was investigated by the Federal Bureau of Investigation and the Boise Police Department and on December 11, 2019, a federal grand jury in Boise indicted George.

In January 2021, George pleaded guilty to two counts of cyberstalking. On April 8, he was sentenced to 51 months in federal prison followed by three years of supervised release.

George was also ordered to pay $525.31 in restitution to one of the victims by US District Judge B. Lynn Winmill.

In Idaho, the crime of cyberstalking is punishable by up to five years in prison, a maximum fine of $250,000, and a supervised release period of up to three years, per charge.

According to a September 2020 Pew Research Center survey of US adults, 41% Americans have experienced some form of online harassment.

In 2014, 15% of Americans had been targeted with more severe forms of harassment, encompassing physical threats, stalking, sexual harassment, and sustained harassment. In 2020, that figure increased to 25%. 

Pew’s latest survey found that 75% of online abuse victims—equaling 31% of Americans overall—reported that their most recent experience was on social media.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

LifeLabs Launches Vulnerability Disclosure Program

LifeLabs Launches Vulnerability Disclosure Program

Canada’s leading provider of laboratory diagnostic information and digital health connectivity systems today announced the launch of a new Vulnerability Disclosure Program (VDP).

LifeLabs Medical Laboratory started the VDP program with the intention of strengthening cybercrime detection technology across its online tools, apps, and solutions.

“Our goal is to continue to innovate and lead the health care industry in cybersecurity, offering the best protection and customer experience when accessing digital health records,” said LifeLabs CISO Mike Melo.

Crowdsourced cybersecurity platform Bugcrowd is working with LifeLabs to deliver the program and streamline the process of accepting, triaging, and remediating vulnerabilities and issues as they are spotted by cybersecurity researchers.

“Implementing a Vulnerability Disclosure Program is a key piece in our commitment to becoming a global leader in protecting our customers’ health care data and accelerating our plan to achieve ISO 270001 certification—an industry gold standard in information security,” said Charles Brown, president and CEO, LifeLabs. 

“By actively staying ahead of threats, the VDP will further enhance our security-first mentality and vulnerability management.”

The outbreak of COVID-19 has made cybersecurity even more crucial than before by increasing the adoption of virtual and digital health care options. 

“VDP programs are a critical component of any organization’s security program, but they are especially important for health care organizations amid the rapidly evolving security threat landscape brought on by the pandemic,” said Ashish Gupta, CEO, Bugcrowd. 

“Our VDP solution gives these companies peace of mind by providing a proactive approach to security with end-to-end management for vulnerability submission, validation, and remediation advice.”

But cybersecurity was a challenge for LifeLabs before the pandemic hit. In December 2019, LifeLabs paid an undisclosed sum to secure data belonging to millions of its customers that was compromised during a cyber-attack. 

The data breach, which could have impacted 15 million LifeLabs customers, occurred on October 28, 2019. In January 2020, a class-action lawsuit was filed against the company over the data breach.

The plaintiffs claimed that LifeLabs stored customers’ personal information on unsecured networks or servers, failed to implement “any, or adequate, cyber-security measures,” didn’t encrypt data, and neglected to hire or train any personnel responsible for network security management.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NCSC: Large Number of Brits Are Using Easily Guessable Passwords

NCSC: Large Number of Brits Are Using Easily Guessable Passwords

A substantial proportion of Brits choose passwords that are easy for cyber-criminals to predict, leaving them vulnerable to hacking.

This is according to an independent survey carried out on behalf of the UK’s National Cyber Security Centre (NCSC). This found that when protecting their online accounts, people regularly use predictable passwords. These include pet names (15%), family members’ names (14%), a significant date (13%) and a favorite sports team (6%).

Additionally, 6% of respondents admitted using ‘password’ as all or part of their password, which means millions of accounts could be easily breached by trial and error methods of common codes.

Weak password security has become an even greater issue in the past year as a result of the shift to online services during the COVID-19 crisis. The survey revealed that 27% of people have at least four new password-protected accounts compared to this time last year.

In response to the findings, the NCSC has advised people to make passwords with three random words to ensure they are difficult to hack.

Nicola Hudson, NCSC director for policy and communications said: “We may be a nation of animal lovers, but using your pet’s name as a password could make you an easy target for callous cyber-criminals.

“I would urge everybody to visit cyberaware.gov.uk and follow our guidance on setting secure passwords which recommends using passwords made up of three random words.

“You can even use our Cyber Action Plan tool to generate tailored, free of charge advice to improve your security against online attacks.”

Commenting, Colin Truran, senior risk, compliance and governance advisor at Quest said: “The recent study from the NCSC highlights just how imperative it is we talk about the problem of password reuse and opting for easy to remember terms such as a pets’ name. Many of us recognize this problem, but as human beings we will continue to opt for easy passwords – it’s a habit of convenience.

“Even the growing trend of forcing users to update their passwords regularly is not helping as the majority of people are just numbering their passwords, or cycling through a handful of regulars. With data breaches hitting the news on an almost weekly basis, and ‘credential stuffing’ techniques being used to great effectiveness against organizations, this does very little to impede a cyber-criminal.” 

Ian Pitt, CIO at LogMeIn added: “Online security risks have risen substantially over the past year, but employing basic password security practices will go a long way in keeping users secure. This means using long, randomly generated passwords that are unique to every single account and contain lower and uppercase letters, digits and symbols. Simple solutions like password managers, also kill two birds with one stone as they can be used to both generate and store unique passwords for every log-in.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Learning from Recent Insider Data Breaches

Learning from Recent Insider Data Breaches

The security lessons organizations can take from insider attack trends were discussed by Neil Daswani, Co-Founder and Co-Director, Stanford Advanced Cybersecurity Program, during a RSAC 365 webcast.

Daswani, author of the recently published book Big Breaches: Cybersecurity Lessons for Everyone, began by outlining trends there have been in regard to the volume of insider data breaches. From the period 2005-2009, the average number per year was under 25, but this figure subsequently surged during 2010-2014, close to 100 per year. This was largely swelled by the Edward Snowden National Security Agency (NSA) leaks of 2013. Surprisingly, the number dropped significantly in the following years, and incredibly there were no reported insider data breaches in 2019. However, Daswani added that “if something is too good to be true it usually is, because in 2020 we saw insider data breaches picking up again.”

Daswani also highlighted significant variation in the prevalence of insider data breaches among different industries. By far the most affected is the healthcare industry, and as a result “if you work for one of these organizations, you should probably pay more attention to insider attacks than peers at other types of organizations.” The next most impacted was the financial sector, followed by retail and merchant and government and military.

Daswani then went on to analyse how insider data attacks occur, looking firstly at the most famous example of its kind – the Snowden leaks in 2013. It appears that the problem emanated from the fact Snowden was provided with widespread access to highly sensitive data; given contractor access, SSH keys, digital certificates and a smart card. This enabled him to build a “crawler” within government systems and download over one million files. “It was interesting that one system administrator had so many credentials,” commented Daswani.

Another issue was the inability of the NSA to detect the huge amount of encrypted flows of traffic within their networks. “There was a lack of monitoring, a lack of anomaly detection that probably allowed this attack to succeed,” stated Daswani.

Over the past year, since the start of the COVID-19 pandemic, the indications are that insider attacks have become easier to conduct. Daswani quoted figures from Code 42 that employees are more likely to leak files than they were pre-COVID.

The main reason for this has been the shift to home working, according to Daswani, meaning that “CISOs and their teams didn’t have as much visibility into all the traffic.” In addition, organizations were unable to impose security measures on staff who are exposed to high levels of sensitive data. For example, customer service agents would normally have to abide by certain physical countermeasures in the workplace, such as no cell phone and paper/pens, “so they can’t write down things and can only interact with customers using virtual desktop interfaces.” These types of policies are impossible to enforce remotely.

With home working having been in place for over a year for many organizations, it is Daswani’s hope that “companies that have lost visibility will take steps to get back visibility even when people work remotely.”

Daswani also spoke about several recent high profile insider attacks, taking place at Twitter, Tesla and Shopify. From these, a number of lessons can be taken. While traditional approaches to security are focused on prevention and are binary, this model is insufficient for insider attacks, in which perpetrators are already in your systems.

Preventative steps can be put in place for insider threats, mainly centered around psychological profiling of employees to uncover high risk personality traits, and developing usage-based security and user behavior analytics around these insights. This should feed into high-level monitoring and detection capabilities. Daswani said: “You’ve got to have a model that is primarily detection-oriented and is probabilistic.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#COVID19 Fraud Surge Threatens to Overwhelm Banks

#COVID19 Fraud Surge Threatens to Overwhelm Banks

Surging levels of fraud and financial crime during the pandemic threaten to overwhelm banking teams working from home with disjointed internal systems, according to new research from FICO.

The predictive analytics company commissioned Omdia to poll 110 senior executives supporting financial crime-fighting efforts in banks across the US, UK, Brazil, Germany, the Nordics and Canada.

In the UK, the vast majority (79%) of respondents cited remote working as having a “high” or “major” impact on the effectiveness of their financial crime prevention efforts.

A lack of cloud-based capabilities for home working, low levels of automation, inflexible systems and low levels of integration all compounded the challenges of maintaining productivity levels across the distributed workforce, the report found.

The integration piece appears to be key: half (49%) of UK respondents cited as a major challenge having multiple software systems for fraud management and financial crime compliance.

Toby Carlin, senior director for fraud consulting at FICO, explained that even though 80% of the functions shared between fraud prevention software and anti-money laundering (AML) software are the same, these systems and the teams that operate them are nearly always separate.

Nearly two-thirds (64%) of UK respondents said these teams don’t report to the same person at the bank.

“Just as the pandemic put huge stresses on the healthcare system, it put huge stresses on fraud and financial crime management teams,” explained Carlin.

“Teams that collaborate in person and work with large software systems that have restricted access found that working from home hurt their productivity. This was compounded as the volume of fraud attacks rose.”

As a result, 69% of global financial institutions surveyed for the report now have plans to integrate functions or share resources between AML compliance and fraud. Half (50%) said they will do so within three years.

The findings chime somewhat with a BAE Systems Applied Intelligence report out last year that revealed frustration among banks’ AML staff about outdated technology and a lack of resources.

It also claimed that most customers now expect their banks to do more to stop money laundering and related offenses.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hackers Hacked as Underground Carding Site is Breached

Hackers Hacked as Underground Carding Site is Breached

Thousands of cyber-criminals have had their personal data leaked online after a popular carding forum was hacked, according to Group-IB.

The Singapore-based security firm said it discovered that data belonging to users of the Swarmshop site was leaked to another underground forum on March 17.

“The database was posted on a different underground forum and contained 12,344 records of the card shop admins, sellers and buyers including their nicknames, hashed passwords, contact details, history of activity and current balance,” explained Group-IB.

“In addition to user data, the database exposed all compromised data traded on the website, including 623,036 payment card records issued by the banks from the US, Canada, the UK, China, Singapore, France, Brazil, Saudi Arabia, Mexico; 498 sets of online banking account credentials; and 69,592 sets of US Social Security Numbers and Canadian Social Insurance Numbers.”

With over 12,000 users and more than 600,000 payment card records up for sale, Swarmshop is a mid-sized site for buyers and sellers of stolen card data.

This is the second time in just over a year that it has been the subject of a successful cyber-attack.

In January 2020, the site’s records were leaked on another underground site by what Group-IB claimed was likely to be a vengeful user.

It’s unclear whether the two incidents were connected in some way . In total, four site admins, 90 sellers, and 12,250 buyers had their details exposed in the most recent attack.

Dmitry Volkov, Group-IB CTO, argued that such incidents are rare and on this occasion, revenge was probably once again the motive.

“This is a major reputation hit for the card shop as all the sellers lost their goods and personal data. The shop is unlikely to restore its status,” he claimed.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Firms Suffer Record Number of Cyber-Attacks in Q1

UK Firms Suffer Record Number of Cyber-Attacks in Q1

There was no let up for UK businesses in the first three months of 2021, with commercial organizations suffering an 11% year-on-year increase in cyber-attacks during the period, according to Beaming.

The business ISP compiled the stats from analysis of traffic flowing to thousands of its corporate customers nationwide.

It claimed UK firms were hit by over 172,000 attacks each on average during the first quarter, the equivalent of 1912 per day and one intrusion attempt every 45 seconds. This compares to 1725 attacks per day in the first quarter of 2020.

Beaming claimed that Q1 2021 saw the highest level of malicious online activity seen at the start of a year since it began recording such data in 2016.

It’s likely that most of these attempts were automated commodity attacks that organizations with decent cybersecurity could repel fairly easily.

However, Beaming managing director, Sonia Blizzard, warned that attacks could still expose some organizations that have not found secure ways to enable remote working for staff.

“The mass move to home and hybrid working means that company data and IT systems are now being accessed via a wide range of personal equipment on unmanaged domestic internet connections,” she said.

“Each offers a potential point of failure for hackers to gain access to company systems over the public internet, and hackers are doubling down to take advantage of vulnerabilities created by this fundamentally less secure way of working.”

Remotely controlled IoT applications and file-sharing services were the top targets for attackers, attracting 175 and 100 attacks per day respectively between January and March.

The most popular countries of origin for IP addresses used in attacks were China (14%), the US (11%) and India (6%).

“The number of cyber-attacks launched against UK businesses surged as the country went into COVID lockdown last year and has remained at exceptionally high levels ever since,” said Blizzard.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk