Don’t Let Tax Fraud Ruin Your IRS Refund

Don’t Let Tax Fraud Ruin Your IRS Refund

Here’s how to lock down your data this tax season

Tax season is always a high time for scams that put our money and information at risk. But this year securing your data may be more important than ever, due to a spike in unemployment fraud.

Millions of Americans have lost their jobs over the course of the pandemic, and states have seen a surge in unemployment applications, including fake claims using stolen information. In California, authorities report that between $10 billion and $30 billion was recently paid in fraudulent unemployment claims, while in New York authorities identified $5.5 billion in fake jobless claims since March of 2020.

ictims don’t even know that their information was used for a fraudulent claim until they receive an unemployment letter from their state, or a tax form from the IRS. Whether you’re concerned about your personal data, or just want to safely file your IRS return and hopefully get a tax refund, let’s take some steps to protect your private information for this tax season, and beyond.

The first thing to know is that there are a that we see evolving each year – according to the IRS, Criminal Investigation identified $2.3 billion in tax fraud schemes just last year. So, it’s always a good idea to take caution and be skeptical whenever you see something that seems too good to be true, like a free tax filing service you’ve never heard of before.

But recently, with so many people out of work, bad actors have decided to focus their attention on filing fraudulent jobless claims using stolen information from people who were actually employed.

Think You May Be a Victim of Tax Fraud?

If you’ve received a notice about unemployment benefits that you never applied for, contact your state unemployment agency and submit a claim. Then follow up with the Federal Trade Commission since they can help you by placing a fraud alert on your credit. This lets lenders know that you may be a victim of fraud, prompting them to take extra steps to verify your identity. The good news is that in the U.S. you only have to notify one of the three national credit bureaus and they will transmit your request to the other two.

My colleague Judy has shared some easy ways you can check your credit report and even freeze your credit in a blog post here. Starting 2021, you can also register for a six-digit Identity Protection PIN (IP PIN) with the IRS to add another layer of verification to protect yourself from tax-related identity theft.

How to Keep Your Private Information Safe This Tax Season and Year-Round

Of course, tax season isn’t the only time your data can fall into the wrong hands. Keep your personal information safe by adopting these best practices and robust tools.

• Use comprehensive security software—For protection against the growing range of threats, choose holistic security software that goes beyond traditional antivirus products, by protecting your identity and privacy wherever and however you connect.

  • Search and surf safely—Whether you are looking for tax information, or ways to file your return online, be careful where you click. A tool like McAfee® WebAdvisor included in McAfee Total Protection can help you avoid dangerous websites and risky links by warning you about them in the search results, before you click.
  • Double down on password protection—Besides online scams, data breaches are another main way that the bad guys get their hands on your personal information. That’s why you need unique and strong passwords for each of your sensitive accounts. This way, if your password is obtained through a data breach, it cannot be used to gain entry to your other accounts. The easiest way to do this is to employ a password manager, like the one included in McAfee Total Protection, which can create and remember complicated passwords for you, and save them across all of your devices.
  • Protect your privacy—Take the stress out of monitoring your data by using a tech tool like our new privacy and identity protection app, available in the U.S. It can alert you if your personal information has been shared on the dark web, where cybercriminals buy and sell information. We’ll help you immediately change the passwords on compromised accounts. It also includes a virtual private network, which allows you to safely and easily connect to the internet, shielding your private information from prying eyes.

Stay Updated

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home  on Twitter, subscribe to our email, listen to our podcast Hackable?, and ‘Like’ us on Facebook.

 

 

The post Don’t Let Tax Fraud Ruin Your IRS Refund appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Let’s Commit To Protect Our Privacy This Year

Let’s Commit To Protect Our Privacy This Year

How our new identity & privacy app can help

By this point in the year you may have already broken some of your New Year’s resolutions, but here’s one to keep: better protecting your online privacy.

After all, we are likely to continue to spend more time online in 2021, whether it be for working, learning, or shopping. This makes taking some preventative steps to shield our identity information more important than ever.

That’s why McAfee has been working on a new identity and privacy app for safeguarding your personal information, and we’d love for you to try it if you’re in the U.S.

Here’s a little bit about our approach. We looked at some of the key areas where users’ private information can be vulnerable, and designed a tool that offers easy-to-use, proactive protection for Windows, Android, and iOS devices, with consistent, familiar experiences regardless of the platform.

Safely Connect Through a VPN

We know, for instance, that users are vulnerable when using unsecured networks, like public Wi-Fi. This is where a cybercriminal can potentially capture your login credentials and other personal information as it flows over the network, from your laptop to your bank’s website, for example.

So, we made sure to include a Virtual Private Network (VPN) to keep your information protected from prying eyes. It does this easily, and even automatically, by detecting when you’re on a public network and prompting you to turn on your VPN. The VPN then scrambles, or encrypts, your data as it flows over the network. Unlike some VPNs that require advanced settings to shield your data, our app offers seamless security.

Dark Web Monitoring

Another area of high risk that we want to address is data breaches. Whether one of your personal accounts is hacked–or worse–another website somehow gets ahold of your data and subsequently gets breached, your data may end up on the dark web. This is where cybercriminals buy and sell information.

To detect these dangerous leaks, we included dark web monitoring, which alerts you if your login credentials have been exposed. It can even provide you with a link to the site that uses those credentials when the information is available. This allows you to swiftly reset your passwords, mitigating the risk.

Given that we saw a spike in corporate data breaches in 2020, where 58% of victims had their personal data compromised, I believe this kind of always-on monitoring of your private information is key.

Ease of Use

Most importantly, we wanted to make this personal protection app easy to use and available across all your compatible devices. So, whether you’re out with just your phone, or home working at your PC, you have access to your protection, and can even pick up where you left off on a different device.

I know that organizing my digital life gives me one less thing to worry about, and I hope it’s the same for you. Give the app a try, and please let us know what you think since we are always open to your feedback.

Here’s to a happy and secure year!

Stay Updated

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home  on Twitter, subscribe to our email, listen to our podcast Hackable?, and ‘Like’ us on Facebook.

The post Let’s Commit To Protect Our Privacy This Year appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Who loves tax season besides accountants? Hackers

Who loves tax season besides accountants? Hackers

 It’s tax time in the United States, and even if you’re pretty sure you did everything right, you’re worried. Did I file correctly? Did I claim the right deductions? Will I get audited? Unfortunately, tax season brings out scammers eager to take advantage of your anxiety.

The tax scam landscape

First, know that you’re probably doing a good job with your taxes. Less than 2% of returns get audited and most discrepancies or adjustments can get handled easily if you address them promptly.

Still, wariness of the IRS and intricate tax laws makes for ripe pickings when it comes to hackers, who prey on people’s fear of audits and penalties. Common scams include fake emails, phone calls from crooks posing as IRS agents, and even robocalls that threaten jail time. With the information they get from you, hackers can take things a step further by stealing your identity and filing tax claims in your name.

As if we didn’t have enough to worry about at tax time.

The good news is that you have plenty of ways to protect yourself from hackers. Check out these tips to stay safe this tax season.

The IRS Dirty Dozen: 12 tax-season scams

Straight from the authority itself, the IRS has published its top 12 tax season scams with new warnings brought on by the events of 2020.

For example, new to this year are scams associated with stimulus checks sent out by the government. The IRS says they have seen “… a tremendous increase in phishing schemes utilizing emails, letters, texts and links. These phishing schemes are using keywords such as “coronavirus,” “COVID-19” and “Stimulus” in various ways.”

This is very important: The IRS does not use email. If you get an email from someone saying they are the IRS and they want to talk with you about a problem, it is a scam.

Here’s what the IRS has to say:

The IRS will never initiate contact with taxpayers via email about a tax bill, refund, or Economic Impact Payments. Don’t click on links claiming to be from the IRS. Be wary of emails and websites − they may be nothing more than scams to steal personal information.

Social media attacks also made the IRS Dirty Dozen. In a social media attack, scammers harvest information from social media profiles. Hackers use the information to gain access to your online accounts in social media and beyond, like your bank account. Make it hard for them. Make your social media profiles private so that only friends and family can see them. Also consider so you can be safer from these kinds of crimes.

Get an email or call from the IRS? Here’s how to know if it was legit.

When a hacker poses as an IRS agent, they try to get personal information from you, like your social security number. They might demand payment, sometimes under the threat of penalties or even jail time. These strong-arm tactics are a dead giveaway that the email or phone call is fake.

What will the IRS do? Usually, the IRS will first mail a bill to any taxpayer who owes taxes. IRS collection employees might call on the phone or make an unannounced visit to your home or business. If they require a payment, the payment will always be to the U.S. Treasury. Read about other ways to know what the IRS won’t do when they contact you.

And remember: the IRS does not use email to contact you about tax problems.

File A.S.A.P. and check your credit report

A good defense is a good offense. File early. Protect yourself by filing your claim before they have a chance to file one as you. You don’t want to be one of those identity theft victims who finds out you’ve been scammed when you file your taxes only to get a notice in the mail saying your tax claim has already been filed.

Here’s other tool that can help you fight identity theft. And get this: it’s not only helpful, it’s free.  Through the Federal Trade Commission, you are entitled to a free copy of your credit report from each of the three major credit reporting companies once every 12 months. In this report, you can find inaccuracies in your credit or evidence of all-out identity theft.

Keep in mind that you get one report from each of the reporting companies each year. That works out to three reports total in one year. Consider this: if you request one report from one credit reporting company every four months, you can spread you free credit report coverage across the whole year.

Security software can help you protect your digital wellness

The idea is that, just like with your physical wellness, there are lots of steps you can take to protect your digital wellness. We’ve covered some of those steps in this blog. Consider one more: protect your digital life with a holistic security solution like McAfee Total Protection so you can enjoy life online knowing your precious data is protected. Tax time or otherwise, security software is always a smart move.

Stay Updated 

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home  on Twitter, subscribe to our email, listen to our podcast Hackable?, and ‘Like’ us on Facebook.

 

The post Who loves tax season besides accountants? Hackers appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

How to Spot, and Prevent, the Tax Scams That Target Elders

How to Spot, and Prevent, the Tax Scams That Target Elders

Elder scams cost seniors in the U.S. some $3 billion annually. And tax season adds a healthy sum to that appalling figure.

What makes seniors such a prime target for tax scams? The Federal Bureau of Investigation (FBI) states several factors. For one, elders are typically trusting and polite. Additionally, many own their own home, have some manner of savings, and enjoy the benefits of good credit—all of which make for an ideal victim profile.

Also according to the FBI, elders may be less able or willing to report being scammed because they may not know the exact way in which they were scammed, or they may feel a sense of shame over it, or even some combination of the two. Moreover, being scammed may instill fear that family members will lose confidence in their ability to look after their own affairs.

If there’s one thing that we can do for our elders, it’s help them raise their critical hackles so they can spot these scams and stop them in their tracks, particularly around tax time. With that, let’s see how crooks target elders, what those scams look and feel like, along with the things we can do to keep ourselves and our loved ones from getting stung.

The IRS imposter scam

The phone rings, and an assertive voice admonishes an elder for non-payment of taxes. The readout on the caller ID shows “Internal Revenue Service” or “IRS,” the person cites an IRS badge number, and the victim is told to pay now via a wire transfer or prepaid gift card. The caller even knows the last four digits of their Social Security Number (SSN). This is a scam.

The caller, and the claim of non-payment, are 100 percent bogus. Even with those last four digits of the SSN attempting to add credibility, it’s still bogus. (Chances are, those last four digits were compromised elsewhere and ended up in the hands of the thieves by way of the black market or dark web so that they could use them in scams just like these.)

Some IRS imposter scams take it a step further. Fraudsters will threaten victims with arrest, deportation, or other legal action, like a lien on funds or the suspension of a driver’s license. They’ll make repeated calls as well, sometimes with additional imposters posing as law enforcement as a means of intimidating elders into payment.

The IRS will never threaten you or someone you know in such a way.

In fact, the IRS will never call you to demand payment. Nor will the IRS ever ask you to wire funds or pay with a gift card or prepaid debit card. And if the IRS claims you do owe funds, you will be notified of your rights as a taxpayer and be given the opportunity to make an appeal. If there’s any question about making payments to the IRS, the IRS has specific guidelines as to how to make a payment properly and safely on their official website.

It’s also helpful to know what the IRS will do in the event you owe taxes. In fact, they have an entire page that spells out how to know it’s really the IRS calling or knocking at your door. It’s a quick read and a worthwhile one at that.

In all, the IRS will contact you by mail or in person. Should you get one of these calls, hang up. Then, report it. I’ll include a list of ways you can file a report at the end of the article.

Tax scams and robocalls

Whether it’s a disembodied voice generated by a computer or a scripted message that’s been recorded by a person, robocalls provide scammers with another favorite avenue of attack. The approach is often quite like the phone scam outlined above, albeit less personalized because the attack is a canned robocall. However, robocalls allow crooks to cast a much larger net in the hopes of illegally wresting money away from victims. In effect, they can spam hundreds or thousands of people with one message in the hopes of landing a bite.

While perhaps not as personalized as other imposter scams, they can still create that innate sense of unease of being contacted by the IRS and harangue a victim into dialing a phony call center where they are further pressured into paying by wire or with a prepaid card, just like in other imposter scams. As above, your course of action here is to simply hang up and report it.

IRS email scams and phishing attacks

Here’s another popular attack. An elder gets an unsolicited email from what appears to be the IRS, yet isn’t. The phony email asks them to update or verify their personal or financial information for a payment or refund. The email may also contain an attachment which they are instructed to click and open. Again, all of these are scams.

Going back to what we talked about earlier, that’s not how the IRS will contact you. These are phishing attacks aimed at grifting prized personal and financial information that scammers can use to commit acts of theft or embezzlement. In the case of the attachment, it very well may contain malware that can do further harm to their device, finances, or personal information.

If you receive one of these emails, don’t open it. And certainly don’t open any attachments—which holds true for any unsolicited email you receive with an attachment.

Preventing tax scams from happening

Beyond simply knowing how to spot a possible attack, you can do several things to prevent one from happening in the first place.

Physical security

First let’s start with some good, old-fashioned physical security. You may also want to look into purchasing a locking mailbox. Mail and porch theft are still prevalent, and it’s not uncommon for thieves to harvest personal and financial information by simply lifting it from your mailbox.

Another cornerstone of physical security is shredding paper correspondence that contains personal or financial information, such as bills, medical documents, bank statements and so forth. I suggest investing a few dollars on an actual paper shredder, which are typically inexpensive if you look for a home model. If you have sensitive paper documents in bulk, such as old tax records that you no longer need to save, consider calling upon a professional service that can drive up to your home and do that high volume of shredding for you.

Likewise, consider the physical security of your digital devices. Make sure you lock your smartphones, tablets, and computers with a PIN or password. Losing a device is a terrible strain enough, let alone knowing that the personal and financial information on them could end up in the hands of a crook. Also see if tracking is available on your device. That way, enabling device tracking can help you locate a lost or stolen item.

Digital security

There are plenty of things you can do to protect yourself on the digital front too. Step one is installing comprehensive security software on your devices. This will safeguard you in several ways, such as email filters that will protect you from phishing attacks, features that will warn you of sketchy links and downloads, plus further protection for your identity and privacy—in addition to overall protection from viruses, malware, and other cyberattacks.

Additional features in comprehensive security software that can protect you from tax scams include:

  • File encryption, which renders your most sensitive files into digital gibberish without the encryption key to translate them back.
  • A digital file shredder that permanently deletes old files from your computer (simply dropping them into the desktop trashcan doesn’t do that—those files can be easily recovered).
  • Identity theft protection, which monitors the dark web for your personal info that might have been leaked online and immediately alerts you if you might be at risk of fraud.

And here’s one item that certainly bears mentioning: dispose of your old technology securely. What’s on that old hard drive of yours? That old computer may contain loads of precious personal and financial info on it. Look into the e-waste disposal options in your community. There are services that will dispose of and recycle old technology while doing it in a secure manner so the data and info on your device doesn’t see the light of day again.

Spot a tax scam? Report it.

As said earlier, don’t let a bad deed go unreported. The IRS offers the following avenues of communication to report scams.

  • Contact the Treasury Inspector General for Tax Administration to report a phone scam. Use their “IRS Impersonation Scam Reporting” web page. You can also call 800-366-4484.
  • Report phone scams to the Federal Trade Commission. Use the “FTC Complaint Assistant” on FTC.gov. Please add “IRS Telephone Scam” in the notes.
  • Report an unsolicited email claiming to be from the IRS, or an IRS-related component like the Electronic Federal Tax Payment System, to the IRS at phishing@irs.gov.

Stay safe this tax season!

In all, learning to recognize the scams that crooks aim at elders and putting some strong security measures in place can help prevent these crimes from happening to you or a loved one. Take a moment to act. It’s vital, because your personal information has a hefty price tag associated with it—both at tax time and any time.

Stay Updated 

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home  on Twitter, subscribe to our email, listen to our podcast Hackable?, and ‘Like’ us on Facebook.

 

The post How to Spot, and Prevent, the Tax Scams That Target Elders appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Satanic Temple Loses Cyber-squatting Lawsuit

Satanic Temple Loses Cyber-squatting Lawsuit

A federal judge in Washington state has dismissed a cyber-squatting claim brought by the Washington Chapter of The Satanic Temple.

The United Federation of Churches LLC, doing business as The Satanic Temple, filed a lawsuit against a group of former Temple members who it claimed erased the contents of the Temple’s social media accounts and replaced it with content that was critical of the organization.

In 2014, the Washington Chapter created a business page on Facebook to disseminate information about The Satanic Temple. The page currently has over 17,000 followers. Another Facebook page associated with the Temple and named TST WA allies, has about 500 followers. 

The Temple alleged that in March 2020, former church members David Johnson and Mickey Meeham hacked into the Facebook pages and exceeded their authorization by removing all Temple-approved administrators from the account except the other defendants named in the suit.

Meeham was accused of changing the name of the TST WA allies page to “Evergreen Memes for Queer Satanic Friends” and uploading a post stating that the page was “no longer affiliated with The Satanic Temple.” 

Suggestions that the Washington Chapter had supported “ableism, misogyny, and racism,” transphobia, and police brutality were allegedly added to the page by Meeham.

The Temple claimed that days after Meeham’s alleged actions, Johnson logged into the chapter’s primary Facebook page, modified the contents, removed Temple-approved administrators, and posted false claims about the church. 

Johnson allegedly accused the leadership of the Temple of being “cozy with the alt-right,” and “insufficiently leftist.” He was further accused of changing the Temple’s profile description in their Twitter account and “following a number of extremist groups to create a false impression of affiliation between The Satanic Temple and extremism.”

Defendant Leah Fishbaugh was accused of changing the password, recovery email, and phone number associated with the Temple’s Google accounts. 

The Temple has since recovered access to its Twitter and Google accounts but was unable to recover access to the Facebook pages. 

Judge Richard A. Jones dismissed the Temple’s lawsuit on February 26, after concluding that “post-domain paths” or “vanity URLs” aren’t considered “domain names” under the Anti-Cybersquatting Consumer Protection Act.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Medal of Honor Holders’ Identities Stolen

Medal of Honor Holders’ Identities Stolen

A threat actor stole the identities of recipients of the US Congressional Medal of Honor and used their personal data to purchase goods from American military exchanges. 

According to a Secret Service search warrant application obtained by The Daily Beast, the identities of a third of the living holders of the US government’s highest and most prestigious military decoration were stolen in the attack.

In the affidavit, Special Agent Matthew O’Neill writes the United States Secret Service “is currently investigating a matter in which the personally identifiable information (PII) of 22 of 75 living Congressional Medal of Honor recipients was used to create fraudulent lines of credit at the Army and Air Force Exchange Service (AAFES) in order to purchase items utilizing the newly created fraudulent lines of credit, all in violation of 18 U.S.C. § 1029 (access device fraud).”

AAFES is an agency of the US Department of Defense. It was founded in 1895 to provide quality merchandise and services to authorized customers at uniform low prices and to generate earnings to supplement funds for US Army and Air Force morale, welfare, and recreation programs.

Items purchased by the threat actor using the stolen identities included luxury watches and tens of thousands of dollars’ worth of Apple products. The fraudulently obtained goods were shipped to various commercial reshipping companies, including UNEOL Post, a commercial reshipper based in New Hampshire.

At least 5 reshippers received the purchases, all of which were eventually shipped to various addresses in Russia. In addition to using companies, the threat actor exploited individuals recruited through online ads.

“An individual re-shipper named Kiril Motorin, located in Gaithersburg, MD, advised that he became a re-shipper after responding to an employment advertisement on a website used by Russians living in the Washington, DC, area,” wrote O’Neill. 

“Motorin provided me e-mails, sent to him from maksim.zna@gmail.com, which provided Motorin instructions such as where to send the merchandise and on how Motorin would be paid for re-shipping the merchandise.”

According to investigators, the threat actor netted $54,530.92 through approximately 50 separate fraudulent transactions. 

The individuals whose personal information was stolen are not named in the affidavit, which was unsealed in December 2020.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Gamer Sues Microsoft Over Cyberbullying

Gamer Sues Microsoft Over Cyberbullying

A video-game maker is suing Microsoft for allegedly failing to protect him from being harassed and cyber-stalked by players of the video-game series Halo

Russian-born Ezra Romanov, who moved to the United States in 2007 and now resides in New Egypt, New Jersey, describes himself as a prominent member of the Halo gaming community. 

In 1998, Romanov, together with his friend Sacha Shibinov, founded an online community that drew together players of the first-person shooter game Unreal.

Originally known as Triple X, the group adopted the name Fist of the Unicorns (FOTUS) in 2012. FOTUS currently has over 43,000 subscribers to its YouTube channel, over 30,000 followers on Twitter, and more than 23,000 members in its private Facebook group, Halo Infinite.

Halo is an American military science fiction franchise managed and developed by 343 Industries and published by Xbox Game Studios, which acts as a division of Microsoft.

According to the complaint, Romanov has been organizing offline and online events designed to bring fans of the game together since 2013. Despite the events being put on to foster a sense of camaraderie among players, the FOTUS founder said he has been targeted with hate mail, and that disturbing letters and packages were sent to his home address.

The gamer also claims to have been the target of unsubstantiated accusations of lewd and illicit behavior.

Romanov has accused Microsoft of breaching its duty by allowing his personal information to be accessed by the malicious actors who have harassed and cyber-stalked him. 

The suit claims that Romanov reported the incidents to Microsoft and was told that an investigation would be carried out. However, Romanov claims that the company has taken no action, despite having the power to ban users who engage in such harassment under its terms of service.

It is further alleged that Microsoft refused to cooperate with police investigations into the alleged harassment of Romanov.

Romanov, who is represented by Alexander Schactel of Jersey City, has brought claims for negligence, breach of contract, and negligent and intentional infliction of emotional distress. He sued in Ocean County Superior Court on October 21, 2020. The suit was moved to federal court on February 25 on behalf of Microsoft.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Quarter of Healthcare Apps Contain High Severity Bugs

Quarter of Healthcare Apps Contain High Severity Bugs

A quarter (25%) of healthcare apps contain high severity flaws, but healthcare organizations (HCOs) are relatively quick to fix them, according to new data from Veracode.

The security vendor broke out sector-specific data collected for its State of Software Security report and claimed that three-quarters (75%) of healthcare applications contained some kind of vulnerability.

This is about on par with the cross-sector average, which stands at 76%.

The sector fixes 70% of the flaws it finds, which puts it behind several other verticals in terms of total volume addressed. However, those it does tackle are fixed faster than any other industry on average except for retail.

Veracode claimed that this is because apps in healthcare are often smaller in size, relatively new and have a lower density of bugs than software in verticals like tech, financial services, manufacturing and government.

HCOs do a better job than most at handling CRLF injection and cryptography-related bugs, which are both important to helping protect personally identifiable information (PII).

However, the sector is still not scanning apps for issues regularly enough and is the least likely of any vertical to scan for flaws in open source components. These are a major source of cyber risk: a Sonatype study last year found that a fifth (21%) of reported breaches over the previous 12 months were linked to the use of these third-party components.

Veracode argued that a failure to scan frequently for flaws means many are going unfixed and could therefore be exploited in future attacks.

This is bad news considering data breaches in healthcare cost more than any other sector. They are estimated at over $7.1 million per incident, according to IBM.

“Hospitals and healthcare systems are considered soft targets by cyber-criminals because they often don’t have the budget or personnel to protect from attacks,” said Chris Wysopal, co-founder and chief technology officer at Veracode.

“The threat is obviously greater due to the lifesaving work in this industry. Healthcare companies need to double down on securing their code.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Kaspersky to Co-Chair Working Group of the Paris Call

Kaspersky to Co-Chair Working Group of the Paris Call

Kaspersky has announced it is partnering with Cigref to co-chair the Working Group 6 (WGF) as part of the Paris Call for Trust and Security in Cyberspace initiative. The group is tasked with developing proposals for solutions to strengthen security in technologies and ICT supply chains.

The Paris Call for Trust and Security in Cyberspace was launched by French President Emmanuel Macron back in 2018, earning the backing of over 50 countries. It aims to promote collective action between public, private and civil organizations to enhance security in numerous areas of cyberspace, including prevention against and resilience to malicious online activity, protecting the accessibility and integrity of the internet and cooperating in order to prevent interference in electoral processes.

As part of the Paris Call, the Ministry of Europe and Foreign Affairs created six working groups to find solutions to enhance security in the global cyberspace. One of these, WG6, is expected to propose concrete tools to help supporters of the Paris Call to enable them to improve their cybersecurity.

With expert support from the research center, GEODE, which focuses on geopolitics in the datasphere, WG6 aims to grow trust and security in technologies and ICT supply chains. A particular emphasis will be placed on collaboration between different actors, users, suppliers and public institutions that operate in this space.

The group will begin by outlining existing global initiatives on product security and hold stakeholders accountable for their delivery. It will also identify gaps and implementation challenges in these initiatives and offer conclusions and review by the Paris Call community.

Commenting on the announcement, Eugene Kaspersky, CEO of Kaspersky, said: “We support the Paris Call, the key multi-stakeholder initiative for the stability in cyberspace. In line with our Global Transparency Initiative (GTI), endorsing the principle 6 on lifecycle security, we will dedicate our efforts, together with industry, technical community, academia and civil society, to the development of concrete tools for enhancing security and resilience of cyberspace.”

Henri Verdier, ambassador for the digital affairs, France, stated: “The Ministry of Europe and Foreign Affairs is pleased to be able to count on Cigref and Kaspersky to steer the work of this working group in collaboration with the supporters of the Paris Call. We believe that joint efforts of industry’s actors would help us to enhance state of global cybersecurity.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Universal Health Services Estimates $67 Million in Ransomware Losses

Universal Health Services Estimates $67 Million in Ransomware Losses

A ransomware attack on Universal Health Services (UHS) last autumn cost the company an estimated $67 million in downtime and related expenses, it has revealed.

The Fortune 500 healthcare organization has tens of thousands of employees in the US and UK and annual revenues exceeding $10 billion.

However, it fell victim to a Ryuk attack at the end of September 2020 which forced the firm to pull the plug on key systems in the US.

“While our information technology applications were offline, patient care was delivered safely and effectively at our facilities across the country utilizing established back-up processes, including offline documentation methods,” it explained in a new financial filing.

“Our information technology applications were substantially restored at our acute care and behavioral health hospitals at various times in October 2020, on a rolling/staggered basis, and our facilities generally resumed standard operating procedures at that time.”

However, during this downtime some acute care and other patient services including ambulance traffic had to be diverted to facilities run by competitors, which cost UHS dear.

“We also incurred significant incremental labor expense, both internal and external, to restore information technology operations as expeditiously as possible,” it added. “Additionally, certain administrative functions such as coding and billing were delayed into December 2020, which had a negative impact on our operating cash flows during the fourth quarter of 2020.”

As a result, UHS estimates an “unfavorable pre-tax impact” of around $67 million for 2020, with $12 million experienced in the third quarter and $55 million in the final three months of the year.

“The substantial majority of the unfavorable impact was attributable to our acute care services and consisted primarily of lost operating income resulting from the related decrease in patient activity as well as increased revenue reserves recorded in connection with the associated billing delays,” the firm noted.

“Also included were certain labor expenses, professional fees and other operating expenses incurred as a direct result of this incident and the related disruption to our operations.”

The good news for UHS is that it expects the majority of these losses to be reimbursed by its insurer.

The news highlights the potentially severe financial cost of ransomware, and the reason why many organizations continue to choose to pay-up rather than suffer downtime, lost revenue and additional IT overtime expense — even though experts and law enforcers usually advise them not to.

Other ransomware victims to have suffered major losses include Cognizant ($70m), Sopra Steria ($60m) and Norsk Hydro ($41m).

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk