US Retailer Kroger Admits Accellion Breach

US Retailer Kroger Admits Accellion Breach

US retail giant Kroger has become the latest big-name brand to admit it suffered a data breach via legacy file transfer software.

The supermarket chain, America’s largest by revenue, posted the notice late last week.

It revealed that some of the firm’s customers and employees may have had their data compromised by a malicious third party who exploited a vulnerability in Accellion’s FTA platform.

“After being informed of the incident, Kroger discontinued the use of Accellion’s services, reported the incident to federal law enforcement and initiated its own forensic investigation to review the potential scope and impact of the incident,” the company said.

“Kroger’s own IT systems have not been affected by this incident. No grocery store data or systems, credit or debit card (including digital wallet) information, or customer account passwords were impacted. However, Kroger believes certain associate HR data, certain pharmacy records and certain money services records have been affected.”

Kroger said it was in the process of notifying those affected, claiming that there hasn’t been any indication of fraud or data misuse so far.

The retailer is the latest in a string of organizations to admit they were compromised via the legacy FTA product. Others include Singtel and the New Zealand Central Bank.

It’s unclear whether Kroger’s attackers exploited a vulnerability patched by Accellion over the Christmas period or one discovered by the vendor in January.

The statement would seem to indicate the latter, as Accellion informed Singtel on the same day (January 23) in an advisory for a new bug that the December 27 patch hadn’t fixed. The telecoms giant said it had likely been attacked on January 20.

Back in December, Kroger was one of the 30 top US retailers found to have connections to a vulnerable third-party asset.

Cincinnati-headquartered Kroger operates nearly 3000 stores across the US, and has over 400,000 employees.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Concern as Attacker “Breakout” Time Halves in 2020

Concern as Attacker “Breakout” Time Halves in 2020

The average time it took for attackers to move from initial infection to lateral movement and beyond halved lasted year, in a sign that organizations are failing in detection and response, according to CrowdStrike.

The security vendor’s 2021 CrowdStrike Global Threat Report is compiled from its threat intelligence, managed threat hunting and cloud graph database technology which processes four trillion global events per week.

It revealed that the vast majority (79%) of “hands-on” attacks spotted last year were financially motivated cybercrime, with supply chain attacks, data extortion and ransomware all featuring strongly. It pointed to 18 “big game” ransomware groups that infected 104 healthcare organizations in 2020.

However, of particular concern was how threat actors appear to be accelerating attacks once they’ve made an initial intrusion into a victim’s network. The average “breakout” time dropped from around nine hours in 2019 to just four hours and 28 minutes.

CrowdStrike SVP of services, Tom Etheridge, told Infosecurity that the aim should be for defenders to hit the “1-10-60” rule, whereby intrusions are detected within a minute, investigated in 10 and adversaries eliminated within 60 minutes.

“The prevalence and availability of malware supporting various stages of the attack cycle, and the reliance on legacy signature-based AV technology and overtaxed security practitioners, have fostered an environment where adversaries can move through a victim’s environment from initial point of entry (typically a phish) to being able to target and encrypt critical infrastructure before defenders are able to implement the controls necessary to stop the breach,” he warned.

Despite the majority of attacks last year coming from e-crime, CrowdStrike also warned of escalating threat activity from nation states in 2021, especially North Korea and China.

Beijing-backed attackers will be targeting key western verticals to support the government’s 14th Five-Year Plan and COVID-19 vaccine efforts, including academia, healthcare, technology, manufacturing and aerospace, the vendor claimed.

In North Korea, meanwhile, the ravages of COVID-19 and a national food shortage will force the government to ramp-up campaigns designed to generate more funds for the hermit kingdom.

“The DPRK economy has continued to contract as a result of COVID-19, so currency generation schemes are likely to continue at pace and even expand,” CrowdStrike SVP of intelligence, Adam Meyers, told Infosecurity.

“They have also continued to move towards economic espionage, particularly around industries called out in the National Economic Development Strategy (NEDS), including energy, agriculture, mining, heavy machinery and land reclamation.”

The report can be found here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CIS Offers Free DNS Security Tool for US Hospitals

CIS Offers Free DNS Security Tool for US Hospitals

A leading internet non-profit is offering US hospitals a free DNS security tool designed to help protect them from ransomware and other threats.

The Center for Internet Security (CIS) announced on Friday that its Malicious Domain Blocking and Reporting Service (MDBR) would be made available at no cost to all non-public hospitals.

The MDBR works by monitoring and blocking any outbound DNS traffic headed for suspicious domains.

“Once an organization points its domain name system (DNS) requests to Akamai’s DNS server IP addresses (primary and secondary), every DNS lookup will be compared against a list of known and suspected malicious domains,” CIS claimed.

“Attempts to access known malicious domains such as those associated with malware, phishing and ransomware, among other threats, will be blocked and logged. Accepted and blocked DNS request logs will be stored for a period of 30 days.”

CIS will provide weekly reports for users of the service to show accepted and blocked requests, and said it will also help with remediation where needed. However, users will not be able to log-in to the Akamai portal and download logs directly as these will come at a cost.

As for that list of known bad domains, CIS said Akamai maintains it with the latter’s own and third-party threat intelligence feeds, as well as publicly available information including WHOIS and domain registration details.

“All of this data is analyzed using proprietary algorithms that can quickly identify malicious domains contained in this large volume of data,” CIS continued.

“Additionally, the Akamai threat research team further analyzes the data sets, as there are certain types of threats that an automated machine learning process will not easily detect.”

CIS claimed that switching on the service would take a matter of minutes for participating hospitals. They would be well minded to sign-up given the increase in threat activity launched against the sector during 2020.

Healthcare data breaches increased 55% year-on-year in 2020, impacting over 26 million patients, according to Bitglass. Sophisticated customized ransomware attacks have been particularly mercenary given the work hospitals are doing on the frontline fight against COVID-19.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

GPS Vulnerabilities

Really good op-ed in the New York Times about how vulnerable the GPS system is to interference, spoofing, and jamming — and potential alternatives.

The 2018 National Defense Authorization Act included funding for the Departments of Defense, Homeland Security and Transportation to jointly conduct demonstrations of various alternatives to GPS, which were concluded last March. Eleven potential systems were tested, including eLoran, a low-frequency, high-power timing and navigation system transmitted from terrestrial towers at Coast Guard facilities throughout the United States.

“China, Russia, Iran, South Korea and Saudi Arabia all have eLoran systems because they don’t want to be as vulnerable as we are to disruptions of signals from space,” said Dana Goward, the president of the Resilient Navigation and Timing Foundation, a nonprofit that advocates for the implementation of an eLoran backup for GPS.

Also under consideration by federal authorities are timing systems delivered via fiber optic network and satellite systems in a lower orbit than GPS, which therefore have a stronger signal, making them harder to hack. A report on the technologies was submitted to Congress last week.

GPS is a piece of our critical infrastructure that is essential to a lot of the rest of our critical infrastructure. It needs to be more secure.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Arrests Six Alleged Cyber-Scam Money Launderers

US Arrests Six Alleged Cyber-Scam Money Launderers

The United States has arrested six alleged members of an international fraud and money-laundering ring that deployed spoofing, catfishing, and COVID-19 relief scams to con victims out of $55m.

The defendants are accused of creating fake identities to trick companies, the Small Business Administration (SBA), and old folks searching for romance online into wiring funds to bank accounts controlled by a criminal enterprise.

Thirty-five-year-old Farouk Appiedu was arrested on October 18 in Queens, New York. His alleged co-conspirator 24-year-old Sadick Edusei Kissi was arrested on February 5 in Fargo, North Dakota. The four remaining defendants—Celvin Freeman, 37, Faisal Ali, 34, Fred Asante, 35, and Lord Aning, 28—were all arrested on February 17; Freeman and Ali in New Jersey, and Asante and Aning in Alexandria, Virginia. 

From 2013 to 2020, the defendants were allegedly members of a criminal enterprise based in Ghana that unloaded a series of business email compromise (BEC) scams, COVID-19 fraud, and romance scams on companies and individuals in the US. 

Money fraudulently obtained via these schemes was sent to Ghana though the purchase of luxury cars and food products that were subsequently shipped overseas.

One ruse involved assuming fake identities to contact senior singles via email, text messaging, or online dating websites. Victims were led to believe they were in a genuine romantic relationship before being hit up for financial help. 

Collectively, the defendants allegedly controlled more than 45 bank accounts containing over $55m. 

“A vast majority of the deposits consisted of large wire transfers and check or cash deposits from various US-based individuals and entities that were victims of fraud schemes of the enterprise,” said the Department of Justice. 

“The fraud schemes alleged that these defendants facilitated were lucrative, diverse, and most of all, callous. As alleged, they engaged in email spoofing, duping elderly online daters into wiring them money, and applying for government-funded Coronavirus relief funds earmarked for the benefit of small businesses affected by the pandemic,” said Manhattan US Attorney Audrey Strauss.

“Thanks to the determination of the IRS and FBI, these defendants face serious prison time, and their next online profiles could potentially appear in a place where they’ll be unable to catfish anymore—the website for the Bureau of Prisons.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk