Kia Denies Ransomware Attack

Kia Denies Ransomware Attack

Kia Motors America has said a recent computer network outage problem was not caused by a ransomware attack.

IT outages began on Saturday, impacting both Kia and affiliated automaker Hyundai Motor America, both of which are owned by the South Korea–based Hyundai Motor Group. The issues experienced by Hyundai were not as severe as those impacting Kia. 

As a result of the network problems, dealers have been unable to order parts and vehicles. A smartphone app that Kia owners can use to start and warm up their vehicles remotely has also been impacted.

On February 15, a Twitter user claimed in a tweet that Kia’s entire United States operation had been impacted by a ransomware attack.

“I went to the Kia dealership in Arizona and signed a new lease, yet the manager told me your computers have been down for 3 days due to Ransomware and has affected Kia all over the USA. Can’t get my car for ???? Now what?” tweeted @amylee62.

In a statement released Thursday, Kia said: “We are aware of online speculation that Kia is subject to a ransomware attack. At this time, and based on the best and most current information, we can confirm that we have no evidence that Kia or any Kia data is subject to a ransomware attack.”

The car maker said that a recovery was under way, then went on to apologize to customers who weren’t able to warm up their cars at a time when much of America is experiencing severe winter weather.

“Kia Motors America, Inc. (Kia) has been experiencing an extended systems outage since Saturday but can confirm that the UVO app and owner’s portal are now operational,” said Kia.

“We anticipate remaining primary customer-facing affected systems will continue to come back online within the next 24–48 hours, with our most critical systems first in line. We apologize for the inconvenience to affected customers, especially those impacted by winter storms, who felt the outage of our remote start and heating feature most acutely. Kia is wholly focused on fully resolving this issue and would like to thank our customers for their continued patience.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Healthcare Data Breaches Halved in January

Healthcare Data Breaches Halved in January

The number of month-on-month healthcare data breaches of 500 or more records reported in the United States was halved in January, according to new research by the HIPAA Journal.

While December 2020 saw 62 such incidents recorded, only 32 were recorded in January 2021. The 32 breaches occurred across 18 states. Florida, where six of the breaches took place, was the worst affected state. 

The journal noted: “While this is well below the average number of data breaches reported each month over the past 12 months (38), it is still more than 1 data breach per day.”

Despite the massive decline in the number of breaches recorded in January, the total number of health records compromised in the first month of 2021—4,467,098—exceeded December’s total by more than 225,000. A major data breach at Florida Healthy Kids Corporation that impacted 3.5 million individuals was key in driving January’s figure past the four million mark.

The breach—one of the largest ever suffered by the US healthcare industry—occurred when cyber-attackers hit an IT company contracted to Florida Healthy Kids Corporation. The health plan had hired vendor Jelly Bean Communications Design to host its website and an app connected to insurance coverage. 

An investigation into the incident found that unauthorized individuals were able to access sensitive data by exploiting a vulnerability. A patch that fixed the flaw had been created seven years ago but had not been applied by the IT company.

Other notable data breaches reported in January include a ransomware attack on healthcare provider Hendrick Health that compromised 640,436 records and a phishing attack on Roper St Francis Healthcare in which 640,436 records were exposed.

Hacking and other IT incidents caused the majority of healthcare data breaches in January. No theft or improper disposal incidents were recorded in January; however, one incident that exposed 2,340 records involved the accidental loss of an unencrypted laptop on which the records were stored.

“January saw 20 hacking/IT incidents reported, which accounted for 62.5% of the month’s data breaches. The protected health information of 4,413,762 individuals was compromised or exposed in those breaches—98.8% of all breached records in January,” stated the HIPAA Journal.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Draft Adequacy Decision Paves the Way for EU-UK Data Flows to Continue Freely

Draft Adequacy Decision Paves the Way for EU-UK Data Flows to Continue Freely

The UK government has welcomed draft decisions by the European Commission to grant the UK adequacy status for data transfers, but has urged a quick completion of the approval process.

Published today, the draft decisions, which have followed months of discussions between the two parties, recognized the UK’s high data protection standards, paving the way for the free flow of data to continue from the EU to the UK. This relates to two areas, one under the General Data Protection Regulation (GDPR) and the other for the Law Enforcement Directive.

As part of the UK/EU Trade and Cooperation Agreement, signed at the end of last year just before the Brexit transition period expired, a bridging mechanism was agreed to allow personal data to flow between the two regions for a period of four months, potentially extending to six, while the EU considered whether or not to grant adequacy to the UK.

The Commission will now share the draft decisions with the European Data Protection Board for a ‘non-binding opinion’ before it is put forward to EU member states to formally approve.

Commenting on the decisions, Didier Reynders, Commissioner for Justice, at the European Commission said: A flow of secure data between the EU and the UK is crucial to maintain close trade ties and cooperate effectively in the fight against crime. Today we launch the process to achieve that. We have thoroughly checked the privacy system that applies in the UK after it has left the EU. Now European Data Protection Authorities will thoroughly examine the draft texts. EU citizens’ fundamental right to data protection must never be compromised when personal data travel across the Channel. The adequacy decisions, once adopted, would ensure just that.”

The UK government has requested that the EU formalises these adequacy decisions “swiftly,” to provide certainty for UK businesses and law enforcement agencies. It also emphasized the importance of maintaining seamless international data flows in an increasingly digitized and hyper-connected world.

Discussing the Commission’s announcement, the UK’s Secretary of State for Digital Oliver Dowden said: “I welcome the publication of these draft decisions which rightly reflect the UK’s commitment to high data protection standards and pave the way for their formal approval.

“Although the EU’s progress in this area has been slower than we would have wished, I am glad we have now reached this significant milestone following months of constructive talks in which we have set out our robust data protection framework.

“I now urge the EU to fulfil their commitment to complete the technical approval process promptly, so businesses and organizations on both sides can seize the clear benefits.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Kaspersky: Decline in DDoS Attacks Linked to Surge in Cryptocurrency Value

Kaspersky: Decline in DDoS Attacks Linked to Surge in Cryptocurrency Value

DDoS attacks fell by almost a third (31%) in Q4 of 2020 compared to Q3, according to new figures from Kaspersky.

The researchers believe this reduction is linked to the surge in cryptocurrency costs, with cyber-criminals increasingly turning their attention to cryptomining. Kaspersky statistics showed that while the number of cryptominers declined throughout 2019 and at the start of 2020, from August 2020, this form of malware has gone up slightly.

With cryptomining becoming more lucrative, it is likely many cyber-criminals re-profiled some botnets to enable C&C servers, typically used in DDoS attacks, to repurpose infected devices and use their computing power to mine cryptocurrencies instead.

Last month, Avira revealed it had detected a 53% rise in crypto-mining software in the final quarter of 2020, linked to the soar in Bitcoin value.

Despite this quarter-on-quarter decline in Q4 of 2020, DDoS attacks were still 10% higher compared to the same period in 2019. This is as a result of the ongoing surge in DDoS attacks in 2020, with cyber-villains exploiting the growing number of people and time spent online since the introduction of COVID-19 social distancing restrictions. Kaspersky noted that numerous educational institutions were targeted with this tactic in the final three months of 2020, including several schools in Massachusetts and Laurentian University in Canada.

Alexey Kiselev, business development manager on the Kaspersky DDoS Protection team commented: “The DDoS attack market is currently affected by two opposite trends. On the one hand, people still highly rely on stable work of online resources, which can make DDoS attacks a common choice for malefactors. However, with a spike in cryptocurrency prices, it may be more profitable for them to infect some devices with miners. As a result, we see that the total number of DDoS attacks in Q4 remained quite stable. And we can predict that this trend will continue in 2021.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Shift to Remote Work Necessitating Greater Innovation in Cybersecurity

Shift to Remote Work Necessitating Greater Innovation in Cybersecurity

Cybersecurity trends emerging from nearly a year of remote working were highlighted by a panel of experts during a RSAC 365 Innovation Showcase webinar.

Robert Ackerman JR, founder and managing director, Allegis Cyber, described how the “virtualization” of organizations’ perimeters has significantly expanded the attack surface for cyber-criminals. He believes COVID-19 lockdown measures have accelerated this new perimeter by five years in the space of one, and encouragingly, there has been “a lot of innovation in that area as people realize their definition of a secure perimeter changed radically because the definition of the perimeter changed radically.”

Ackerman added that the huge increase in cloud adoption over this period has changed the cybersecurity environment, creating “entirely new security black holes.” He said: “One of the things we’ve seen over the last year open up as an entirely new area of innovation in cybersecurity is how you get visibility into your workloads in that hybrid environment.”

Merging security controls with good user experience is also going to be critical to defending distributed workforces against cyber-threats going forward, according to Mark Kraynal, founding partner, aCrew Capital. He noted that if home working security measures cause friction for staff in fulfilling their jobs, then they will find ways to get round them, thereby putting organizations at high risk. “What people have found out is that when you push out your centralized security controls to a distributed workforce at home, it doesn’t work that well for the users,” he explained.

Real innovation will be required to achieve these dual goals, with Kraynal acknowledging that “user experience and security is inherently difficult.”

Another cybersecurity trend being observed is a renewed focus on SaaS security. Yoav Leitersdorf, managing partner, YL Ventures, believes that prior to the COVID-19 pandemic, this had been put to one side, “but now in 2020/21, its really coming back and there are lots of solutions making SaaS more secure given there’s so much work from home, which is essentially people on browsers using SaaS.”

Another area that is growing in importance is the role of developers in security, according to Leitersdorf. “I think we’ve all realised that if we let developers just develop code without thinking too much about security and leave security to production and DevOps, we’re all in trouble, and we’ve seen that very clearly in the SolarWinds attack,” he commented.

With so many aspects of cybersecurity requiring new ways of thinking and types of solutions in the current environment, Kraynal believes there needs to be a greater emphasis on improving productivity in the industry. “We have to stop thinking about the skills gap and think about it as a productivity gap,” he outlined. “In almost every area, there’s a way to be more productive – to be more developer-orientated so developers take the load on app security, to mitigate vulnerabilities better as opposed to just sorting them out and telling you which is the worst one and to go back to basics on hygiene – so I think there’s a lot of opportunity to make security teams across all personas in security more productive.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CrowdStrike Snaps Up London Start-Up Humio

CrowdStrike Snaps Up London Start-Up Humio

CrowdStrike has announced a $400 million deal to acquire British log management firm Humio in a bid to bolster its extended detection and response (XDR) capabilities.

The endpoint security and threat intelligence giant claimed it was “blown away” by the London-based firm’s high-performance cloud log management and observability technology. Its proven ability to deliver at scale makes it the perfect fit for the CrowdStrike Security Cloud, it added.

“By leveraging new ingest pipelines and cloud log management, we will continue to help developers, security analysts, and IT professionals gain complete observability to answer any question, explore threats and vulnerabilities, and gain valuable insights from all computer-generated data in real-time,” argued CrowdStrike CTO, Michael Sentonas.

“CrowdStrike and Humio share a vision that contextual data can help solve critical enterprise problems, across cybersecurity and beyond. After we close this transaction, our joint forces will deliver a combination of capabilities that are truly unmatched in the industry and I am very excited for what our combined future holds.”

Humio CEO and co-founder, Geeta Schmidt, said the CrowdStrike Security Cloud was the ideal platform to extend the company’s reach while empowering customers to make “data-rich decisions.”  

One such customer is New York City Cyber Command (NYC3), whose job it is to secure the city’s IT infrastructure.

“The success of our entire security strategy rests on having reliable, high-performance ingestion technology that enables us to combine disparate security data resources, including from more than 20 third-party tools, and extract actionable insights in a frictionless and efficient manner,” said Geoffrey Brown, head of NYC3.

“In evaluating world-class technologies, we chose Humio because of their market-leading technology and ability to execute at massive scale and analyze and action data with speed, accuracy, and context.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

SolarWinds Attackers Breached 100+ Private Firms

SolarWinds Attackers Breached 100+ Private Firms

Over 100 private sector firms were breached in the SolarWinds attack, the White House has revealed.

Anne Neuberger, deputy national security advisor for cyber and emerging technology, told the press yesterday that many of those affected were technology companies, “whose products could be used to launch additional intrusions.”

That’s certainly what appears to have happened with the targeting of firms like FireEye, Microsoft, Malwarebytes, Mimecast and Palo Alto Networks — although not all of these attacks were successful.

Neuberger also confirmed that nine government departments and agencies were affected, and that the attackers were likely Russian in origin.

Also yesterday, Microsoft revealed it had completed its investigation into the incident.

The tech giant claimed that the attackers had managed to access and download source code related to Azure, InTune and Exchange — but added that “only a few files” were viewed for most repositories.

“The search terms used by the actor indicate the expected focus on attempting to find secrets. Our development policy prohibits secrets in code and we run automated tools to verify compliance,” the firm continued.

“Because of the detected activity, we immediately initiated a verification process for current and historical branches of the repositories. We have confirmed that the repositories complied and did not contain any live, production credentials.”

Microsoft argued that the attack shows why a zero trust approach and protecting credentials are vital for organizations serious about minimizing cyber risk.

“The investigation found no indications that our systems at Microsoft were used to attack others,” it explained. “Because of our defense-in-depth protections, the actor was also not able to gain access to privileged credentials or leverage the SAML techniques against our corporate domains.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Internet Registry RIPE NCC Warns of Credential Stuffing Attack

Internet Registry RIPE NCC Warns of Credential Stuffing Attack

One of the world’s five internet registries yesterday warned users that it suffered a failed credential stuffing attack.

RIPE NCC is the regional internet registry (RIR) for Europe, West Asia and the former Soviet Union.

It claimed in an update yesterday that its single sign-on (SSO) service was affected by an attempt to crack open accounts, causing some downtime.

“We mitigated the attack, and we are now taking steps to ensure that our services are better protected against such threats in the future,” it noted.

“Our preliminary investigations do not indicate that any SSO accounts have been compromised. If we do find that an account has been affected in the course of our investigations, we will contact the account holder individually to inform them.”

The registry is asking all account holders to enable two-factor authentication if they’ve not already done so, and recommended the same for all internet accounts.

It remains to be seen what the attackers were after. Credential stuffing is an increasingly popular way for cyber-criminals to hijack the online accounts of internet users, but it tends to be focused on consumer-facing businesses.

A 2020 report from Akamai claimed that 60% of credential stuffing attacks detected over the previous two years were targeted at retail, travel and hospitality businesses, with the vast majority (90%+) of these related to retail brands.

As long as enterprise security is found wanting, such attackers will have a readymade supply of credentials to use in these automated raids.

A report from F5 earlier this month revealed that the number of attacks resulting in large-scale credential theft almost doubled over the past four years.

Although brands are often loathe to enforce 2FA for fear that it adds too much customer friction to the login process, organizations like RIPE NCC would benefit from enforcing it by default.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Capital Group Appoints Marta Zarraga as Global Chief Information Officer

Capital Group Appoints Marta Zarraga as Global Chief Information Officer

Investment firm Capital Group has appointed Marta Zarraga as its new global chief information officer. In the role, Zarraga will be responsible for overseeing the organization’s technology and cybersecurity.

She joins the company with 25 years of experience in the information security industry, including as global chief information officer at Aviva and chief information officer at Vodafone and British Telecom.

Capital Group explained that Zarraga was selected for her strong technical qualifications, holding a Master’s degree in computer engineering from Universidad de Deusto in Spain, as well as her experience driving business value through technology and ability to develop diverse and successful teams.

Commenting on her appointment, Zarraga said: “Technology is foundational to Capital Group’s business. As the company continues to focus on expanding and strengthening its services to investors, data and technology remain critical enablers.

“It is a phenomenal opportunity to join a company that is so committed to its mission of improving people’s lives and so committed to its associates, and I am excited to leverage new technologies to help achieve that mission.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk