The Problem with Treating Data as a Commodity

Excellent Brookings paper: “Why data ownership is the wrong approach to protecting privacy.”

From the introduction:

Treating data like it is property fails to recognize either the value that varieties of personal information serve or the abiding interest that individuals have in their personal information even if they choose to “sell” it. Data is not a commodity. It is information. Any system of information rights­ — whether patents, copyrights, and other intellectual property, or privacy rights — ­presents some tension with strong interest in the free flow of information that is reflected by the First Amendment. Our personal information is in demand precisely because it has value to others and to society across a myriad of uses.

From the conclusion:

Privacy legislation should empower individuals through more layered and meaningful transparency and individual rights to know, correct, and delete personal information in databases held by others. But relying entirely on individual control will not do enough to change a system that is failing individuals, and trying to reinforce control with a property interest is likely to fail society as well. Rather than trying to resolve whether personal information belongs to individuals or to the companies that collect it, a baseline federal privacy law should directly protect the abiding interest that individuals have in that information and also enable the social benefits that flow from sharing information.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

6 Alabamans Charged in $7m Virtual Schools Fraud

6 Alabamans Charged in $7m Virtual Schools Fraud

Six school officials in Alabama have been indicted over a scheme to fraudulently obtain millions of dollars in state education funding by pretending to enroll private students into virtual schools.

Federal prosecutors say educators in Athens City Schools and Limestone County Schools stole the identities of hundreds of private students and falsified enrollment records to make it appear as though the children were full-time attendees of virtual schools throughout the state. 

By allegedly doctoring the records, the conspirators were able to obtain $7 million in state education funding for the 2016–17 and 2017–18 academic years. Private schools persuaded to take part in the conspiracy by sharing their students’ data were rewarded with laptops and access to online courses. 

An 80-page indictment unsealed on February 23 names 55-year-old Toney resident Thomas Michael Sisk, who was formerly the superintendent of the Limestone County School District; 56-year-old Gregory Earl Corkren of Tuscaloosa; 61-year-old David Webb Tutt of Uniontown, 57-year-old Athens resident and former Athens City School District employee Deborah Irby Holladay; her husband, Athens resident and former superintendent of the Athens City School District, 56-year-old William Holladay III; and former Athens district director of innovative programs and current executive director of planning for Athens City Schools, 45-year-old Athens resident William Richard Carter Jr. as defendants. 

To conceal the fraud, the defendants allegedly created fake report cards and submitted falsified course-completion reports to the state department of education. 

Federal officials said the investigation into the conspiracy began two years ago and involved more than 200 interviews statewide.

William Holladay stands accused of launching the scheme in 2015 by enrolling students from private schools in the district’s virtual school option Athens Renaissance. Holladay, who allegedly received cash payments for his part in the scheme, has been indicted on more than 100 counts of fraud. 

As of November 2017, more than 50 private school students from Abbeville Christian Academy were fraudulently enrolled in Conecuh County Schools and over 500 private school students were fraudulently enrolled in Athens Renaissance.

“The money Alabama sets aside for public education should be used for exactly that—educating the students of our public schools,” said US Attorney Louis Franklin.

“The defendants in this case prioritized their own profits over the education needs of our students.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Steris Touted as Latest Accellion Hack Victim

Steris Touted as Latest Accellion Hack Victim

Data belonging to a client of recently hacked California-based private cloud solutions company Accellion is being advertised for sale online by cyber-criminals.

On the website Clop Leaks, ransomware gang Clop are claiming to have in their possession an unspecified amount of information belonging to the Steris Corporation. Steris is an American Ireland-registered medical equipment company specializing in sterilization and surgical products for the US healthcare system. 

Documents that appear to have been stolen include a confidential report about a phenolic disinfectant comparison study dating from 2018 that bears the signatures of two Steris employees— technical services manager David Shields and quality assurance analyst Jennifer Shultz.  

Another document appears to contain the formula for CIP neutralizer, a highly confidential trade secret owned by Steris Corporation.

“Clop is known to use data stolen from one organization to attack (spear phish) others,” Emsisoft’s Brett Callow told Infosecurity Magazine.

“This is why, for example, there was a cluster of cases in Germany. So any organization that has had dealings with one of the compromised entities should be on high alert.”

Steris did not immediately respond to Infosecurity Magazine’s request for comment. Accellion customers have been suffering cyber-attacks since the end of 2020.

Other companies that Clop claim to have stolen data from include SingtelJones Day, Inrix, ExecuPharm, Planatol, Software AG, Fugro, Nova Biomedical, Amey Plc, Allstate Peterbilt, Danaher, and the CSA Group.

Asked what advice he would give to companies that discover their data is being hawked online, Callow said: “It really makes no sense for companies to pay to prevent the publication of their data. There have been multiple instances in which threat actors have published or otherwise misused information after their victims have paid the ransom. 

“In some cases, actors have even used the same data to attempt to extort companies a second time. And this is really not at all surprising. These groups are untrustworthy bad actors and it would be a mistake to assume that they will abide by their promises.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Iraqi MP Suffers Online Extortion

Iraqi MP Suffers Online Extortion

A senior Iraqi politician has become the victim of a prolonged international campaign of intimidation and online extortion.

In dual raids carried out on February 24, police in Australia and Canada arrested four individuals accused of targeting the politician and his family for over a year. 

While the identity of the victim has not been officially disclosed, Australian police described him as a “very senior politician” who has dual Australian and Iraqi citizenship and who “spends almost all of his time in Iraq.” 

An investigation was launched after a series of attacks on a residence in western Sydney and multiple online extortion attempts demanding $10m. Australian police were able to link the cybercrimes to social media accounts controlled by suspects located in Edmonton, Canada. 

The attacks on the Sydney home began in December 2019 when armed assailants broke in, stole money, and assaulted a 16-year-old boy. In the months that followed, a brick was thrown through the window and shots were fired at the house while two adults and three children were at home. 

In February 2021, the front porch of the house was set alight late at night and a threatening note left.

Australian police said: “Throughout this time, the family received various demands for money and threats to their welfare via social media and letters left at their home.”

Edmonton police arrested 33-year-old Ghazi Shanta and 32-year-old Diana Kadri and charged both individuals with extortion and conspiracy to commit extortion. 

Two men—Luminous Touto, 24, and Zigalo Sogora, 22—were arrested in Sydney after allegedly being hired by Shanta and Kadri to attack the MP and his family. 

“With the immediacy of today’s communication tools, it was critical for us to collaborate with Australian police to make simultaneous arrests on opposite sides of the planet,” said Phil Hawkins of the Edmonton force’s Cyber Crime Investigations Unit.

Australian media have reported the victim as Ahmed Al-Asadi—the spokesperson for the Fatah alliance in Iraq’s Parliament.

“The safest place for someone is their home, and for us it was the most dangerous place for a while,” Al-Asadi’s daughter Rusul Al-Asadi told ABC News.

“The attacks have really taken their toll on my mum. She is very stressed and is not her old, bubbly self.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Educational Adaptation Required to Close the Cyber-Skills Gap

Educational Adaptation Required to Close the Cyber-Skills Gap

Addressing the cyber-skills gap requires a variety of career pathways and greater collaboration between governments, academia and industry, according to experts speaking during a webinar entitled Closing The Cyber Skills Gap: Can We Make a Difference? This session involved security vendor Palo Alto Networks and academics, government members and security experts from Scotland, and took place during CyberScotland week.

First and foremost, a strong cybersecurity awareness and culture throughout society needs to be built. This includes making cybersecurity exciting and interesting to children even at primary school age, teaching them basic behaviors to stay safe using digital technology, and later on, engraining it into non-technical subjects at college. Anna Chung, threat intelligence analyst, Palo Alto Networks, who came into cybersecurity from a non-technical background herself, explained: “The best way is to teach the younger generations how to protect themselves, because cybersecurity is not just a profession or a career, it is a basic fundamental element of our current digital way of life.”

Callum Campbell, lecturer, Organization Glasgow Clyde College, said: “We have to start influencing children into the ideas and concepts of security,” adding that “it’s something that society as a whole has to make a paradigm shift on.”

Teaching children the importance of problem solving is particularly critical for developing the soft skills that are needed to pursue a later career in the area of cybersecurity, according to the speakers.

Denise Doyle, lecturer, City of Glasgow College, observed that one positive of the current COVID-19 crisis is that is has forced people to be more self-reliant. She noted that often “the basic problem solving skills are missing” among students, and actually “one good thing about COVID-19 and lockdown is they get forced to do more problem solving” in regard to independent research.

The panel went on to discuss the available higher educational route into a cybersecurity career, and agreed it is important to emphasize that there are multiple pathways available. In particular, Campbell outlined that for this type of industry, universities don’t always necessarily provide the hands-on practical experience that employers are looking for, and college courses such as HNDs can be better at offering this to students. “I think the practical application is paramount,” he stated.

To make the picture clearer for students and parents, Daniel Sellers, cyber-resilience learning and skills coordinator, Scottish Government, said that “we need to present very clear evidence of successful career outcomes for individuals who have gone through diverse pathways.”

Supporting this assessment, Laura McEwan, cyber-skills project manager, Skills Development Scotland, revealed that her organization had found that 70% of the industry are not overly concerned with the qualifications job applicants have. Instead, “what really matters is that the candidates can demonstrate good competencies and that they have the passion and dedication to do the role.”

It should also be remembered that cybersecurity is a rapidly-moving sector, and continuous learning is needed for people to keep up with developments. McEwan commented: “Many of these people will come in with a degree or HND but will still need to learn on the job as there will be software that organizations use that haven’t been presented to them while they were doing formal qualifications.”

In a relatively young industry, where the educational pathways are still in their early stages, it is therefore vital that government, academia and industry work more closely together to ensure courses are providing real-world knowledge for students. Sellers expressed a wish to see “academia and industry working together to ensure that the curricula are right, and are feeding specialists into the jobs market.”

Chair of the discussion, Greg Day, chief security officer EMEA, Palo Alto Networks, added that this kind of collaboration is something his company is keen on developing, for example, by sharing training content. He explained: “We develop training for two purposes; for our own employees and for all our customers, but we readily share both of those training curricula with academic institutions.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Nominet Announces Expansion of Initiative to Educate Online Users on Cybercrime

Nominet Announces Expansion of Initiative to Educate Online Users on Cybercrime

Nominet, the organization responsible for managing the .uk domain registry, has announced that three new agencies have joined its pilot initiative to direct users to law enforcement landing pages for domains suspended due to criminal activity.

The Medicines and Healthcare products Regulatory Agency (MHRA), the Financial Conduct Authority (FCA) and the National Crime Agency (NCA) will now join the effort to educate online users on protecting themselves from online scams and cybercrime. First introduced by Nominet in partnership with City of London’s Police Intellectual Property Crime Unit in November 2020, the pilot aims to ultimately improve transparency and public confidence in the safety of the internet.

The collaboration with the MHRA will enable web users to be directed information about how to purchase medicines online, with sales of fake treatments online becoming prevalent during the COVID-19 pandemic. This advice will highlight the health and financial dangers posed by the sales of counterfeit medicines online as well as showcase safe purchasing options.

Working with the FCA, users will also be redirected to pages that outline how to protect themselves from financial scams. The FCA estimates this move could potentially save the UK public millions of pounds.

In addition, the NCA will have the functionality to redirect web users to the UK’s national reporting center for fraud and internet crime to help bring more cyber-criminals to justice.

When the pilot initiative ends, Nominet will assess its impact and report on the next steps.

Eleanor Bradley, MD of registry and public benefit at Nominet, explained: “Our landing page initiative is just one example of how we go above and beyond to make .uk the safest place in the world to be online.

“In addition to clarifying why the domain has been suspended, these bespoke pages will direct the public to official government resources designed to help them buy medicines safely, avoid financial scams and report fraud.

“These pages are designed to give vital information and support to the UK public at a time when they need it most while still disrupting criminal activity.”

Improving awareness of the dangers posed by cyber-criminals has become increasingly important during the pandemic, which has seen a substantial rise in internet use as a result of ongoing social distancing restrictions. Earlier this month, banking giant Barclays revealed it saw a record number of scams reported in the UK last year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk