Booking.com Fined $558,000 for Late Breach Notification

Booking.com Fined $558,000 for Late Breach Notification

A major hotel bookings site has been fined €475,000 after failing to report a serious data breach within the time period mandated by the General Data Protection Regulation (GDPR).

Booking.com suffered the breach back in 2018 when telephone scammers targeted 40 employees at various hotels in the United Arab Emirates (UAE).

After obtaining their login credentials to a Booking.com system, they were able to access the personal details of over 4100 customers who had booked a hotel room in the UAE via the site. Credit card details on 283 customers were also exposed, and in 97 cases the security (CVV) code was compromised.

“Booking.com customers ran the risk of being robbed here. Even if the criminals did not steal credit card details, but only someone’s name, contact details and information about his or her hotel booking, the scammers used that data for phishing,” explained Monique Verdier, VP of the Dutch Data Protection Authority (AP).

“By pretending to belong to the hotel by phone or email, they tried to take money from people. This can be very credible if such a scammer knows exactly when you have booked which room, and asks if you want to pay for those nights. The damage can then be considerable.”

Although the breach does not appear to have been Booking.com’s fault, its response was found wanting.

The travel giant, which is headquartered in the Netherlands, was notified of the incident on January 13 2019, but didn’t report it to AP until February 7 — 22 days later. The GDPR mandates strict rules to report within 72 hours.

Verdier argued that this was a serious violation of the trust that millions of customers place in the platform to keep their details safe. Online firms’ obligations don’t just extend to best practice cybersecurity controls, she claimed, but also to reacting quickly if and when things do go wrong.

“A data breach can unfortunately happen anywhere, even if you have taken good precautions, but to prevent damage to your customers and the repetition of such a data breach, you have to report this in time,” Verdier said.

“That speed is very important: in the first place for the victims of a leak. After such a report, the AP can, among other things, order a company to immediately warn affected customers — to prevent criminals from having weeks to continue trying to defraud customers, for example.”

Booking.com will not contest the fine, according to AP.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

North Korean Hackers Expand Targeting of Security Community

North Korean Hackers Expand Targeting of Security Community

A North Korean espionage campaign targeting security researchers has taken another turn with the creation of a new fake company, website and social media accounts to lure victims, according to Google.

The tech giant’s Threat Analysis Group (TAG) first discovered the campaign back in January. At the time, the threat group launched a research blog which it posted links to via fake social media profiles on LinkedIn, Twitter and Keybase.

It then approached researchers in the cybersecurity community, asking if they wanted to collaborate on projects. They would either be sent backdoor malware or pointed to a blog site seeded with malware.

However, in mid-March, TAG analysts observed the group had launched a fake security company, ‘SecuriElite,’ with its own website.

“The new website claims the company is an offensive security company located in Turkey that offers pen-tests, software security assessments and exploits. Like previous websites we’ve seen set up by this actor, this website has a link to their PGP public key at the bottom of the page,” explained TAG’s Adam Weidemann.

“In January, targeted researchers reported that the PGP key hosted on the attacker’s blog acted as the lure to visit the site where a browser exploit was waiting to be triggered.”

Alongside the website, the North Korean group has created some more fake social media profiles related to both security researchers and non-existent recruiters for AV companies. One is misspelled “Trend Macro” rather than the legitimate firm Trend Micro.

Although the fake security company site as yet is not serving up malware to those who visit it, the group itself means business, Google warned.

“Following our January blog post, security researchers successfully identified these actors using an Internet Explorer zero-day. Based on their activity, we continue to believe that these actors are dangerous, and likely have more zero-days,” Weidemann concluded.

“We encourage anyone who discovers a Chrome vulnerability to report that activity through the Chrome Vulnerabilities Rewards Program submission process.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Half of Global Retailers See Account Takeovers Surge

Half of Global Retailers See Account Takeovers Surge

Most global retailers are predicting an increase in fraud budgets next year, with nearly half seeing an increase in attacks, according to new data from Ravelin.

The fraud prevention software vendor polled over 1000 merchants globally to understand their current challenges.

It revealed that 45% are seeing an increase in account takeover (ATO) attacks. These efforts aim to hijack consumer accounts to tap them for any stored personal information which could be monetized on the dark web. Attackers may also try to use stored cards to purchase goods fraudulently, or to sell access to the accounts on underground sites.

Ravelin claimed that ATO attacks are on the rise due to shoppers’ password reuse across multiple sites. When one is breached, fraudsters can use these in credential stuffing operations to try them across multiple other sites.

An Akamai study from October 2020 claimed that over 60% of credential stuffing attacks detected over the previous two years were targeted at retail, hospitality and travel businesses, with the lion’s share (90%+) affecting retailers.

Nearly 40% of fashion and FMCG retailers claimed online payment fraud is now their biggest fraud risk, the Ravelin report also found.

So-called refund abuse, or “friendly fraud,” where consumers wrongly claim they never received a product they ordered online, has increased for half of respondents. This could be attributed to the pandemic; first-party fraud like this often spikes during periods of financial crisis, where money is tight and usually law-abiding individuals are tempted to lie.

The surging fraud levels are at least being met with a firm response, as 76% of retailers predicted their organization would increase fraud budgets in the next 12 months, and 20% said the increase would be “significant.”

Ravelin CIO Mairtin O’Riada argued that the pandemic has created “a veritable petri dish” to grow fraud volumes.

“Retailers are scrambling to drive ecommerce and are handling extremely high volumes of transactions online, while also trying to fulfil a growing number of online deliveries. At the same time, honest consumers and avid fraudsters are feeling the pinch of a shrunken economy — many have lost their jobs and money is tight,” he added.

“Trying to detect fraud manually under these conditions is a difficult and expensive undertaking.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#LORCALive: Cybersecurity to Play a Key Role in Supporting Growing Space Sector

#LORCALive: Cybersecurity to Play a Key Role in Supporting Growing Space Sector

The burgeoning commercial space industry needs support from the cybersecurity sector to ensure it can be trusted and resilient, according to Rob Meyerson, founder and CEO at Delalune Space, speaking during the LORCA Live online event.

Meyerson is formerly of NASA in a highly technical role and Blue Origin, where he worked alongside Jeff Bezos to create new business lines in areas such as human space flights. He is now focused on investing in new businesses looking to operate in the space sector, and this includes cybersecurity.

Meyerson outlined how we are already very reliant on space for the running of a number of important services. These includes communication, navigation and timing, weather monitoring and the Internet of Things (IoT). “You can think of these space systems as utilities as part of our critical infrastructure,” he explained.

Additionally, we have now reached a point where it’s possible for space to become a more commercial domain, with businesses able to build on top of infrastructure already developed. This has meant things like the cost of launch and satellites have fallen, offering great opportunities. Meyerson noted: “If you have a great idea you can build a space business, but you don’t necessarily have to invest in building the rocket or satellite.”

Meyerson believes we will soon see products being manufactured in space to improve life on earth, such as pharmaceuticals and 3D bio-printing and in the future, potentially “things being made in space, primarily for space.”

Ensuring this environment is secure is going to become a major frontier for the cybersecurity industry. “You can easily see how important it is for these systems to be trusted,” Meyerson commented, adding that “just like it’s critical here on earth to support healthcare, the financial sector and all the other important sectors that we have, our space sector needs that support of the cybersecurity industry.”

He also observed that different countries view the use of space through different lenses; for example, the US mainly looks at it for exploration and knowledge, whereas in China, it is seen as an opportunity for economic benefit. In this environment, it is likely we will see nation state cyber-attacks targeting the space sector. Meyerson said: “That differing view leads to conflict and we are going to have to find ways to protect these assets.”

In many respects, securing space assets will be no different to that of other areas of the economy, and the “fundamental tools to protect those are very similar,” explained Meyerson. He added: “These assets up in space are being controlled with humans and computers – command and control, data are uplinked and downlinked through networks at ground stations that are distributed around the world. So, the security of these ground systems is critical.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk