A Fifth of Sunburst Backdoor Victims from Manufacturing Industry

A Fifth of Sunburst Backdoor Victims from Manufacturing Industry

Nearly a fifth of organizations hit by the Sunburst backdoor emanating from the SolarWinds supply chain attack are from the manufacturing sector, a new analysis from Kaspersky has revealed.

While researchers have already uncovered technical details of the Sunburst backdoor that was embedded in the SolarWinds incident late last year, information of the full impact of the attack is still being investigated. It has been officially confirmed that around 18,000 users may have installed backdoor versions of SolarWinds, potentially leaving them at risk of further attack, but Kaspersky sought to gain more information on the types of organizations affected.

To do so, Kaspersky ICS CERT researchers compiled a list of nearly 2000 readable and attributable domains from available decoded internal domain names obtained from DNS names generated by the Sunburst DomainName Generation Algorithm. This showed that around a third (32.4%) of all victims were industrial organizations, with manufacturing (18.11% of all victims) by far the most affected. This was followed by utilities (3.24%), construction (3.03%), transportation and logistics (2.97%) and oil and gas (1.35%).

The regions in which these industrial organizations were based were wide-ranging, including Benin, Canada, Chile, Djibouti, Indonesia, Iran, Malaysia, Mexico, the Netherlands, the Philippines, Portugal, Russia, Saudi Arabia, Taiwan, Uganda and the US.

Maria Garnaeva, senior security researcher at Kaspersky, commented: “The SolarWinds software is highly integrated into many systems around the globe in different industries and, as a result, the scale of the Sunburst attack is unparalleled – a lot of organizations that had been affected might have not been of interest to the attackers initially. While we do not have evidence of a second-stage attack among these victims, we should not rule out the possibility that it may come in the future. Therefore, it is crucial for organizations that may be victims of the attack to rule out the infection and make sure they have the right incident response procedures in place.”

The cybersecurity firm advised that possible victims of the SolarWinds compromise should check whether they have installed backdoored versions and look out for known indicators of compromise, as displayed in CISA’s Alert AA20-35A.

As the fallout of the high profile incident continues, earlier this week several more cybersecurity vendors revealed that they were attacked by the same threat actors that compromised SolarWinds.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#DataPrivacyDay: Organizations Must Increase Focus on Data Privacy in 2021

#DataPrivacyDay: Organizations Must Increase Focus on Data Privacy in 2021

Organizations must be far more focused on data privacy issues this year, according to a panel of experts speaking during the Spirion webinar Customer Data Privacy 2021: It’s No Longer Just Business, It’s Personal.

The panel began by setting out the trends that have pushed data privacy issues to the fore over recent years. These include the growth and fragmentation of data privacy legislation, both in the US and across the world, which has expanded consumer rights, the increased usage of the internet and social media and emergent technologies such as AI and facial recognition. “It’s an incredible time to be in privacy,” noted Jane Mailander, deputy general counsel, data, privacy and cybersecurity, Fannie Mae.

In this landscape, organizations must review their whole data collection process to ensure consumers “own” their privacy, according to Robert Eckman, CISO at Kent State University. “What rights are they giving that data subject as they are collecting it – are they informing them of its legitimate use?” he asked.

Jason Hodgert, product marketing manager, Spirion, agreed, stating that organizations must acknowledge that consumers own their own data, and they are merely “borrowing it,” which means taking extra care. “This requires a fundamental switch in how businesses treat the data they possess,” he commented.

Data privacy issues have also become more important in the context of the digital shift many businesses are undergoing as a result of the COVID-19 pandemic. These include the move to remote working and growing use of IoT devices. Rebecca Herold, CEO of The Privacy Professor, explained: “When we’re dealing with digital transformation, often privacy and data protection are just forgotten. You’re focused on the digital transformation that you’re dealing with and then dealing with security and privacy later – you can’t do that.” Instead, privacy and security has to be part of any transformation plan from the very beginning, throughout “the full lifecycle.”

Mailander outlined that in many ways the digital shift has provided the perfect opportunity for businesses to implement “privacy by design” when setting up new programs.

While protection of consumer data can sometimes be viewed as something of a burden, the panellists also highlighted how being strong in this area can be turned into a competitive advantage for businesses. Hodgert noted that people are more aware than ever before about the collection and use of their personal data and that it “has a value to the organization.” In an era where people increasingly only choose to invest in organizations they feel share their values, it is vital that there is greater transparency when it comes to data. Hodgert added: “People are going to be paying more attention to what’s being done with that data. It’s not enough that they know companies have it, they want to know who they are sharing it with and why.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

66% of Workers Risk Breaching GDPR by Printing Work-Related Docs at Home

66% of Workers Risk Breaching GDPR by Printing Work-Related Docs at Home

Two-thirds of remote workers risk potentially breaching GDPR guidelines by printing out work-related documents at home, according to a new study from Go Shred.

The confidential shredding and records management company discovered that 66% of home workers have printed work-related documents since they began working from home, averaging five documents every week. Such documents include meeting notes/agendas (42%), internal documents including procedure manuals (32%), contracts and commercial documents (30%) and receipts/expense forms (27%).

Furthermore, 20% of home workers admitted to printing confidential employee information including payroll, addresses and medical information, with 13% having printed CVs or application forms.

The issue is that, to comply with the GDPR, all companies that store or process personal information about EU citizens within EU states are required to have an effective, documented, auditable process in place for the collection, storage and destruction of personal information.

However, when asked whether they have disposed of any printed documents since working from home, 24% of respondents said they haven’t disposed of them yet as they plan to take them back to the office and a further 24% said they used a home shredding machine but disposed of the documents in their own waste. This method of disposal is not recommended due to personal waste bins not providing enough security for confidential waste and therefore still leaving employers open to a data breach and potential fines, Go Shred pointed out.

Most concerning of all, 8% of those polled said they have no plans to dispose of the work-related documents they have printed at home, with 7% saying they haven’t done so because they do not know how to.

Mike Cluskey, managing director at Go Shred, said: “Printing any documentation which includes personal information about employees or potential employees is a high risk activity as should this information get into the wrong hands, it could be used to impersonate someone.

“It’s quite shocking to see that so many home workers are printing items such as payroll and personal information like addresses. Even internal documents such as meeting notes and agendas can be risky, so extra precautions should be taken in order to dispose of these properly.”

It’s vital that business leaders review their current processes and educate their staff on the current guidelines, as working from home demands a different security standard than being in the office, especially with data security and disposing of confidential information, Cluskey added.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Apprenticeships Could Solve Cyber-Skills Crisis, Say Experts

Apprenticeships Could Solve Cyber-Skills Crisis, Say Experts

Offering apprenticeships could help to encourage more young people into the cybersecurity sector, alleviating skills shortages, according to a new poll run by Infosecurity Europe.

The region’s top cybersecurity event, held annually by Infosecurity publisher Reed Exhibitions, asked its Twitter followers for their thoughts on the ongoing skills crisis in the industry.

Some 43% argued that apprenticeships, in which trainees learn on-the-job whilst studying for a formal qualification, would be a good fit for a fast-moving, hands-on sector like cybersecurity, where degree courses can often be out-of-date by the time students have finished them.

Respondents also cited the need for a formal career path (27%), more role models and mentors (17%) and greater diversity (13%) as important in helping to reduce skills shortages.

The latest figures from (ISC)2 revealed that, although shortages fell for the first time globally last year, they still totalled more than three million.

The crisis has not been helped by COVID-19 which has forced 36% of respondents to the poll to institute a hiring freeze.

This chimes with a CrowdStrike survey released this week which revealed that 44% of UK organizations refused to take on any new security professionals last year. In fact, the UK had the lowest average of new cybersecurity hires of all countries surveyed, and respondents raised concerns that this could amplify the increased cyber-risks emanating from the pandemic.

Amar Singh, CEO of Cyber Management Alliance, backed the idea of apprenticeships to build up UK-wide capability.

“It’s a pipeline — you can’t simply pick someone up and say ‘You’re now infosec.’ That individual has to be trained and inspired from a young age,” he added. “If they’re not, by the time they’re 16 or 18 this becomes more difficult because they’re already established on another path.” 

Maxine Holt, senior research director at Omdia, has first-hand experience of this route into professional employment.

“After doing my BTEC in computer studies I got an apprenticeship, learning on the job while studying part-time for my degree,” she explained. “I also got to work in other parts of the business, which really helped me understand how they interacted with IT.” 

Infosecurity Europe will run from June 8-10 2021 at London’s Olympia.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Delivery Biz Exposes 400 Million Records in Privacy Snafu

Delivery Biz Exposes 400 Million Records in Privacy Snafu

A popular south Asian delivery company exposed 400 million records containing customers’ personal information after misconfiguring an Elasticsearch server, according to researchers.

A team from reviews site Safety Detectives found the 200GB trove during a simple IP address check on specific ports. It was left wide open with no password protection or encryption, meaning anyone with the server’s IP address could have accessed the database.

The team soon traced the leak back to Bykea, a Karachi-based vehicle-for-hire and delivery company that offers an extensive fleet of “motorbike taxis” which are bookable via smartphone app.

According to Safety Detectives, the firm exposed its entire production server, including customers’ full names, phones numbers and email addresses, and drivers’ full names, phone numbers, addresses, license numbers and ID card (CNIC) details.

Also featured in the trove were Bykea employees’ unencrypted passwords and logins.

Other information exposed in the privacy snafu included API logs, delivery and collection location info, vehicle info, GPS coordinates and user device information.

The firm secured the server within 24 hours of being notified, on November 24.

If cyber-criminals were able to get hold of the leaked information it would have armed them with a major haul for carrying out follow-on phishing, identity theft and fraud.

“Full names, residential address details, ID documents like CNIC, online login information and location data could potentially be exploited by nefarious users to target unsuspecting people that registered with the company,” said Safety Detectives.

“Car registration and vehicle data could potentially be used to conduct insurance fraud and other heinous crimes involving stolen identities.”

With employee logins, attackers could also have attempted ransomware and other attacks against Bykea itself.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Breach Volumes Fell 19% in 2020 as Ransomware Surges

US Breach Volumes Fell 19% in 2020 as Ransomware Surges

The number of publicly reported US data breaches and leaks last year dropped 19% as attackers continued to move away from mass theft of customer data to more lucrative tactics like ransomware, according to a leading non-profit.

The Identity Theft Resource Center (ITRC) compiled its annual report from company announcements, mainstream news reports, government agencies, recognized security firms and researchers, and other non-profits.

In total, it recorded 1108 incidents, down by nearly a fifth on 2019’s figures, while nearly 301 million individuals were affected, a drop of 66% on the previous year.

Breaking it down further, there were 1001 actual breaches and 107 data exposures, which often result from misconfiguration of cloud servers. More people were affected by the latter (156 million) than the former (145 million).

The ITRC claimed the stats show that cyber-criminals are gravitating to ransomware and targeted email compromises, using previously stolen log-ins and phishing tactics, and away from bulk theft of personal data.

“Ransomware and phishing require less effort, are largely automated, and generate pay-outs that are much higher than taking over the accounts of individuals,” it continued. “One ransomware attack can generate as much revenue in minutes as hundreds of individual identity theft attempts over months or years.”

In fact, the average ransomware payment was $233,000 in Q4 2020, up from just $10,000 in Q3 2018, according to Coveware.

Phishing can also help attackers reap massive Business Email Compromise (BEC) profits. Total losses for BEC in 2019 reached $1.8bn, or half of all cybercrime losses reported to the FBI.

In terms of actual compromises, the ITRC recorded 878 cyber-attacks, with the largest number (44%) going to phishing/smishing and BEC, followed by ransomware (18%).

However, in spite of these macro-trends, ITRC CEO Eva Velasquez warned that the breach problem is not going away, with hundreds of millions of consumers still being impacted. The headline 2020 numbers may also have been skewed by the increasing popularity of supply chain attacks, where only the initial breached company is counted but many more clients may be affected.

For example, the ransomware attack on Blackbaud last year affected over 475 of its corporate customers and led to the compromise of information on 11 million people.

“Cyber-criminals are simply shifting their tactics to find a new way to attack businesses and consumers,” argued Velasquez. “It is vitally important that we adapt our practices, and shift resources, to stay one step ahead of the threat actors.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk