United Airlines to Pay $49m to Settle False Data Claim

United Airlines to Pay $49m to Settle False Data Claim

United Airlines Inc. has agreed to pay $49m to resolve criminal charges and civil claims that it was defrauding the United States Postal Service.

The world’s third largest airline entered into International Commercial Air (ICAIR) contracts to transport mail internationally on behalf of the postal service. Under the contracts, United was entitled to full payment only if accurate barcode scans were provided for deliveries and mail was delivered in a timely manner. 

Between 2012 and 2015, United engaged in a scheme to defraud USPS by submitting false delivery-scan data that made it appear as though mail was being delivered to meet the full payment requirements of the contract. However, the airline submitted automated scan data that was not tethered to the actual delivery of the mail but was based merely on aspirational delivery times. 

Through this data automation scheme, United secured millions of dollars in payments from the USPS that the airline was not entitled to under the terms of the ICAIR contracts.

In addition to submitting false data, United admitted concealing problems related to scanning and mail movements that would have landed the airline with financial penalties had they come to light.

“Certain individuals at United worked to conceal United’s automation efforts from the USPS, as they knew that the data being transmitted was fabricated,” said the Department of Justice. 

“These individuals further knew that the transmission of false data violated the terms of the ICAIR contracts.”

Attempts by United employees to hide the automation practices included revising the falsified delivery times to make the automated scans appear less suspicious.

On February 26 United entered into a non-prosecution agreement (NPA) with the Criminal Division’s Fraud Section and agreed to pay $17,271,415 in criminal penalties and disgorgement to resolve a criminal investigation into the fraud scheme. 

The airline also agreed to pay $32,186,687 as part of a False Claims Act settlement with the Civil Division’s Commercial Litigation Branch.

Acting Assistant Attorney General Nicholas McQuaid of the Justice Department’s Criminal Division said that “companies that defraud the government—no matter the context, contract, or federal program—will be held accountable.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Florida Police Arrest 12 Alleged Online Predators

Florida Police Arrest 12 Alleged Online Predators

Law enforcement officers in Florida’s Marion County have arrested a dozen men in a sting operation to catch sexual predators who use the internet to target children.

According to the Marion County Sheriff’s Office, the 12 defendants were caught chatting online with users who they believed to be children. In reality, the suspects were talking with undercover detectives.

The men arrested in the operation are 18-year-old Allen Vasquez of Jacksonville, Donald Dziadyk, Brayant McCullough, 21-year-old Robin Strickland of Gainesville, Ryan Boyette, 51-year-old Lonny Blankenship of Lake City, Robert Salch, 31-year-old Robert Hilse, Jason Sciongay, 31-year-old Dunte Campbell of Jacksonville, Koree Lee, and Jorge Cruz Ordonez. 

Four of the men are accused of sending sexually explicit images during the online conversations. Of the 12, eight men allegedly made arrangements to meet and have sex with the child who they believed they were talking to online. 

All eight of the men traveled to a location in Marion County, allegedly believing that they were about to engage in sex with a minor. However, upon arriving at the agreed upon meeting point, each suspect was greeted by law enforcement officers and placed under arrest.

Marion County Sheriff Billy Woods asked parents to make it their business to know what their children get up to when they are online. 

“My message to parents, I want to make something clear: You need to be fully aware of where your children are talking online. Be aware of their social media,” said Woods, “because all of these individuals, for some of them, this might be their first offense, but I promise you it’s not their first time.”

He also issued a warning to those who would use the internet as a tool to sexually exploit children. 

“To the would-be, vile individuals that are doing this and are seeking children in Marion County, be assured that I will find you, I will put handcuffs on you, and I will put you in my jail,” said Woods. 

“My deputies will spend hours upon hours hunting you down. Now, my job is bringing people to justice, but if it was my choice, I’d bury you under the jail, if I could. Don’t come to Marion County.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Facebook Photo-tagging Lawsuit Settled for $650m

Facebook Photo-tagging Lawsuit Settled for $650m

Facebook is to pay $650m to users in Illinois who accused the company of using their biometric data without first obtaining their consent. 

Nearly 1.6 million users in the Prairie State joined a class-action lawsuit filed against Facebook in April 2015 in Cook County Circuit Court on behalf of plaintiff Carlo Licata. 

The lawsuit alleged that the social media giant had violated an Illinois privacy law by using facial-recognition technology to scan photos uploaded by users and by digitally storing data regarding individuals’ faces without users’ permission.

In Illinois, the Biometric Information Privacy Act allows consumers to sue companies that harvest data such as faces and fingerprints or identify users without first obtaining permission. 

After moving to Chicago federal court, the suit was then moved to California federal court, where it attained class-action status.

The settlement class included approximately 6.9 million Facebook users whose face templates were created and stored by the social media company after June 7, 2011. To qualify, users had to have lived in the state for a minimum of six months over the past nine years.

The 1.6 million claim forms filed by the deadline represented only about 22% of eligible Facebook users in Illinois. 

The substantial settlement was approved Friday, February 26, by a California federal judge, James Donato, who described it as “a major win for consumers in the hotly contested area of digital privacy.”

Donato wrote that the deal “will put at least $345 into the hands of every class member interested in being compensated” and ordered Facebook to get the cash into the pockets of affected users “as expeditiously as possible.”

Providing no appeal is lodged against the ruling, impacted Illinois residents could get a check in the mail within the next two months, according to Chicago attorney Jay Edelson, who filed the initial lawsuit against Facebook nearly six years ago.

“It’s a big deal,” Edelson said. “It sends a pretty clear message that in Illinois, biometric privacy rights are here to stay.”

In a statement, Facebook said: “We are pleased to have reached a settlement so we can move past this matter, which is in the best interest of our community and our shareholders.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Half of Orgs Concerned Remote Working Puts Them at Greater Risk of Cyber-Attacks

Half of Orgs Concerned Remote Working Puts Them at Greater Risk of Cyber-Attacks

Half of organizations are concerned that the shift to remote work is putting them a greater risk of cyber-attacks, according to a new study by LogMeIn in collaboration with IDG.

A survey of UK CIOs, CTOs and IT decision makers revealed that insecure practices are regularly taking place among remote workers, providing more opportunities for cyber-criminals to strike.

A large majority (80%) of organizations admitted that a portion of their workforce use personal computers to work from home, while two in five said that over 50% of their staff rely on at-home Wi-Fi networks to operate.

The respondents also highlighted that among the most pressing challenges in supporting remote working were effective IT/helpdesk support, cybersecurity management and providing secure access to data.

As a result, of the CIOs, CTOs and IT decision makers surveyed in the UK, a third (33%) listed addressing security gaps as one of their top motives for consolidating remote work tools and solutions. Other motives included scalability, costs and performance issues, with hybrid working looking set to become increasingly prevalent post-COVID.

Over half of respondents stated that workforce productivity is significantly dependent on remote technology and 41% expect to increase their investment in remote work tools and solutions this year.

Dave Campbell, head of remote solutions group, LogMeIn, commented: “This survey shows companies are clearly re-evaluating their remote work tools and will need to make changes this year, so are finding that it is vital to consider the ways the tools will impact their employees and help desk staff. This means IT leaders need to place greater emphasis on tools that will minimize disruptions in employees’ day-to-day work to maintain productivity and ensure that employees feel supported, while still ensuring they don’t fall short in terms of infrastructure, IT and data security in 2021.”

Today, research from Tanium showed that 70% of organizations are facing new security challenges due to the COVID-19 pandemic.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

70% of Orgs Facing New Security Challenges Due to #COVID19 Pandemic

70% of Orgs Facing New Security Challenges Due to #COVID19 Pandemic

New research from endpoint management and security provider Tanium has discovered that seven out of 10 organizations have reported facing new security challenges due to the COVID-19 pandemic.

The firm’s report, IT Leads the Way: How the Pandemic Empowered IT, outlines the impact of remote working upon organizations and their strategies for adapting to it.

Some 88% of the 500 UK and US IT decision makers surveyed stated that, before the pandemic hit, they felt some level of confidence in their ability to fully and securely support remote work. However, when social distancing restrictions forced many offices to close and quickly instigate mass remote working, only 39% organizations found it easy to actually shift employees.

Highlighting the security challenges that have arisen as a result, those polled cited upticks in risky behavior from remote working employees including the storing of sensitive data (41%), clicking on phishing emails (38%) and inappropriate admin access (37%). What’s more, 30% said they had observed their end users failing to update software.

The report pointed to the sharp increase in the use of shadow IT/unsanctioned apps, chat or conference apps and third party file sharing as having a direct impact on organizational security challenges brought about by increased remote working.

Regarding actions taken by organizations to help address new, COVID-19 induced security risks, investments in data and information security (63%), threat detection (60%), security/compliance software and services (59%) and device management (50%) were cited. Furthermore, compared to their plans before the pandemic, 38% of businesses accelerated investments in technology that supports a zero trust architecture, with 55% and 51% accelerating investment in identity and access management and secure adaptive access, respectively.

Perhaps most intriguingly though, Tanium’s report discovered that only 33% of respondents considered improving cybersecurity as one of their top three IT initiatives for 2021, raising potential concerns regarding cybersecurity prioritization this year.

“Our distributed workforce means the end of the network perimeter as we know it and the rise of the endpoint,” said Chris Hodson, global CISO of Tanium, “but managing and securing endpoints requires visibility and control. You can’t secure what you can’t see. As the research reveals, it is critical that IT teams continue to invest in solutions that break down data silos and enable automation to ensure manageability, security and insight for their endpoints.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Go Malware Detections Increase 2000%

Go Malware Detections Increase 2000%

New malware written in the Go programming language has spiked by 2000% over the past four years, as nation state and cybercrime threat actors switch from older ecosystems, according to a new report.

Israeli security firm Intezer made the claims in a new report late last week, Year of the Gopher: 2020 Go Malware Round-Up.

It revealed that although the language, sometimes referred to as Golang, was first used for malware around nine years back, it took until 2019 for it to become popular among cyber-criminals.

However, since then it has emerged as an increasingly common choice, primarily as it works across Windows, Linux and Mac operating systems and is relatively challenging for researchers to reverse engineer.

Intezer also praised its “very well-written networking stack that is easy to work with.”

In a blog, the vendor explained that Go was used by Russian state-backed actors to target Eastern European countries with a variant of the Zebrocy malware last year. Kremlin hackers have also used the language to develop the WellMess malware which targeted COVID-19 vaccine researchers in the UK, Canada and US.

Chinese state attackers used Go malware in loaders and recent attacks against Tibetans, Intezer claimed.

On the cybercrime front, the vendor pointed to botnets (IPStorm) used to launch DDoS and mine illegally for cryptocurrency, as well as ransomware variants (Nefilim, EKANS) all written in Go.

Specialized runtime protection tools will be needed to tackle the growing threat from Go malware, Intezer concluded.

“We have seen threat actors targeting multiple operating systems with malware from the same Go codebase. Traditional anti-virus programs have had a hard time identifying Go malware due to many factors,” it continued.

“A detection method based on code reuse has shown to be effective, especially when it comes to detecting when malware families are targeting new platforms. It’s also likely that attacks from Go malware against cloud environments will increase as more valuable assets are moved to the cloud.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Self-Assessment Tool Aims to Enhance Small Biz Security

Self-Assessment Tool Aims to Enhance Small Biz Security

Sole traders and micro-businesses now have some extra cybersecurity support after the UK authorities launched a new online self-assessment tool.

The free service is being provided by the GCHQ-backed National Cyber Security Center to the country’s smallest businesses who, like most others, have been working remotely during the pandemic.

It’s a group the government believes is particularly at risk as they may typically lack the resources of even SMBs to devote to enhanced cyber-protection.

This can put them at risk of attacks designed to steal sensitive information, deploy ransomware, mine for cryptocurrency, perpetrate fraud and much more.

According to the government’s most recent figures, almost half (46%) of small and micro-businesses last year said they had been the victim of a breach or cyber-attack in the previous 12 months. The proportion of micro-businesses saying cybersecurity is a high priority has risen by 15 percentage points since 2016 (from 63% to 78%).

The new online assessment tool, launched as part of the government’s Cyber Aware campaign, asks participants a string of questions about their security posture. This idea is to find out whether the individual is following security best practice regarding backups, automated patching, up-to-date anti-virus, password management and use of multi-factor authentication (MFA).

Depending on their answers, the tool will conclude by offering advice and links to help the micro-business owner or sole trader enhance their security.

NCSC deputy director for economy and society, Sarah Lyons, urged micro-business owners to take a few minutes out of their day to take the self-assessment test.

“Small businesses are the lifeblood of this country, but we know they can be a target for cyber-criminals, particularly as they move more operations online,” she added.

“Our free Cyber Action Plan is here to help, offering bespoke, actionable information linked to the Cyber Aware behaviors.”

The tool will be advertised on TV and radio from March 5.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Berlin Resident Jailed for NHS Bomb Threats

Berlin Resident Jailed for NHS Bomb Threats

An Italian national has been sentenced to three years behind bars after threatening to blow up NHS hospitals, MPs and Black Lives Matters protesters over the past year.

Berlin resident Emil Apreda, 33, was identified by the UK’s National Crime Agency (NCA) after emailing a series of threats to the Health Service last year, starting with a £10m Bitcoin extortion demand.

Apreda is said to have done so from his Berlin apartment, using anonymization techniques such as use of a Tor browser, to stay hidden. He claimed in the notes he was a member of far right organization Combat18.

Although the emails were written in English, investigators used behavioral, linguistic and other cutting-edge techniques to determine that the perpetrator was probably a fluent German speaker.

With the help of German law enforcement they traced the emails to an address in the Steglitz district of Berlin where the local state police or Landeskriminalamt (LKA) put Apreda under surveillance.

He is said to have sent 18 emails in all, threatening not only hospitals but also lawmakers and rights protesters in the UK.

“The threat made during the extortion demand significantly added to the pressures on the NHS during the COVID pandemic and meant senior leaders and emergency response staff were called on to direct the NHS aspects of the response to this threat,” said an NHS spokesperson.

“The threat and demand was made at a time that hospitals were at their most vulnerable, and could have resulted in significant loss of life.”

Firearms officers finally used explosives to force open the door to Apreda’s apartment and arrest him in June last year. Officers continued to monitor communications until they were sure he was acting alone.

Apreda was convicted of attempted extortion in the District Criminal Court in Berlin, and sentenced to three years in jail.

Nigel Leary, deputy director of the NCA’s National Cyber Crime Unit, thanked the German authorities for their help in bringing Apreda to justice.

“Protecting the NHS and the public was an absolute priority throughout this investigation and we used all the tools at our disposal to ensure he was identified and brought to justice,” he said.

“Apreda carried out his crimes against the UK hidden behind a computer screen in Germany. Cybercrime knows no borders and so our work with international partners is key to tackling it.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk