How China Uses Stolen US Personnel Data

Interesting analysis of China’s efforts to identify US spies:

By about 2010, two former CIA officials recalled, the Chinese security services had instituted a sophisticated travel intelligence program, developing databases that tracked flights and passenger lists for espionage purposes. “We looked at it very carefully,” said the former senior CIA official. China’s spies “were actively using that for counterintelligence and offensive intelligence. The capability was there and was being utilized.” China had also stepped up its hacking efforts targeting biometric and passenger data from transit hubs…

To be sure, China had stolen plenty of data before discovering how deeply infiltrated it was by U.S. intelligence agencies. However, the shake-up between 2010 and 2012 gave Beijing an impetus not only to go after bigger, riskier targets, but also to put together the infrastructure needed to process the purloined information. It was around this time, said a former senior NSA official, that Chinese intelligence agencies transitioned from merely being able to steal large datasets en masse to actually rapidly sifting through information from within them for use….

For U.S. intelligence personnel, these new capabilities made China’s successful hack of the U.S. Office of Personnel Management (OPM) that much more chilling. During the OPM breach, Chinese hackers stole detailed, often highly sensitive personnel data from 21.5 million current and former U.S. officials, their spouses, and job applicants, including health, residency, employment, fingerprint, and financial data. In some cases, details from background investigations tied to the granting of security clearances — investigations that can delve deeply into individuals’ mental health records, their sexual histories and proclivities, and whether a person’s relatives abroad may be subject to government blackmail — were stolen as well….

When paired with travel details and other purloined data, information from the OPM breach likely provided Chinese intelligence potent clues about unusual behavior patterns, biographical information, or career milestones that marked individuals as likely U.S. spies, officials say. Now, these officials feared, China could search for when suspected U.S. spies were in certain locations — and potentially also meeting secretly with their Chinese sources. China “collects bulk personal data to help it track dissidents or other perceived enemies of China around the world,” Evanina, the top U.S. counterintelligence official, said.

[..]

But after the OPM breach, anomalies began to multiply. In 2012, senior U.S. spy hunters began to puzzle over some “head-scratchers”: In a few cases, spouses of U.S. officials whose sensitive work should have been difficult to discern were being approached by Chinese and Russian intelligence operatives abroad, according to the former counterintelligence executive. In one case, Chinese operatives tried to harass and entrap a U.S. official’s wife while she accompanied her children on a school field trip to China. “The MO is that, usually at the end of the trip, the lightbulb goes on [and the foreign intelligence service identifies potential persons of interest]. But these were from day one, from the airport onward,” the former official said.

Worries about what the Chinese now knew precipitated an intelligence community-wide damage assessment surrounding the OPM and other hacks, recalled Douglas Wise, a former senior CIA official who served deputy director of the Defense Intelligence Agency from 2014 to 2016. Some worried that China might have purposefully secretly altered data in individuals’ OPM files to later use as leverage in recruitment attempts. Officials also believed that the Chinese might sift through the OPM data to try and craft the most ideal profiles for Chinese intelligence assets seeking to infiltrate the U.S. government­ — since they now had granular knowledge of what the U.S. government looked for, and what it didn’t, while considering applicants for sensitive positions. U.S. intelligence agencies altered their screening procedures to anticipate new, more finely tuned Chinese attempts at human spying, Wise said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Teen Accused of Deadly Cyber-stalking Campaign

US Teen Accused of Deadly Cyber-stalking Campaign

A man from New York City has been charged with waging a grim cyber-stalking campaign against a female college student. 

Desmond Babloo Singh allegedly created over 100 accounts on social media platforms and email services and used them to harass a former classmate of his sister for whom he claimed to have developed romantic feelings. 

Nineteen-year-old Singh professed his love to the unnamed victim via an Instagram story in February 2020. When she didn’t return his affections, Singh allegedly accessed several of the victim’s electronic accounts without authorization, changing her passwords to lock her out of the accounts.

Singh then allegedly posted offensive images and statements to the victim’s accounts without authorization. Among the sentiments allegedly shared by Singh were racial slurs and express and implied threats of sexual violence, bodily injury, and death. 

The New Yorker is further accused of stealing images stored privately in the victim’s Snapchat account then posting them on social media and sending them to the victim and her family members via text message.

According to the affidavit filed in support of the criminal complaint against Singh, the teen then solicited others to rape, murder, and decapitate the victim in exchange for Bitcoin. He is further accused of causing the police to show up at the victim’s residence in Baltimore County, Maryland, by emailing a hoax bomb threat in a “swatting” attack. 

Singh’s alleged cyber-stalking campaign went on from around April 18, 2020, to November 24. According to the affidavit, Singh also “doxed” the victim, publicly posting her personal information on several occasions, and encouraged others to harass her. 

The victim’s family and an ex-boyfriend whom the Department of Justice believe Singh viewed as a romantic rival were allegedly also targeted. The affidavit states that Singh doxed the victim’s family members and sent her ex harassing messages, and also posted messages attacking him online. 

The complaint against Singh was filed on December 14 and unsealed yesterday. Singh is accused of the federal charges of cyber-stalking, causing intentional damage to a protected computer, aggravated identity theft, e-mailing a hoax bomb threat, and murder for hire. 

If convicted on all counts, Singh could be sentenced to a maximum of 32 years in prison.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Lazarus Attacks Vaccine Research

Lazarus Attacks Vaccine Research

The infamous advanced persistent threat group (APT) Lazarus is behind two recent cyber-attacks that targeted two separate entities related to COVID-19 research.

In one attack, a Ministry of Health body was hit with malware. The other incident involved the use of a different kind of malware against a pharmaceutical company that is developing a vaccine for the novel coronavirus. The company is authorized to produce and distribute the vaccine.

The attacks, which both occurred in the fall of 2020, were identified by researchers at Kaspersky. Despite the use of different tactics, techniques, and procedures (TTPs) in each assault, the researchers have now assessed “with high confidence” that both malicious activities can be attributed to the Lazarus group.

“Both attacks leveraged different malware clusters that do not overlap much,” wrote researchers. “However, we can confirm that both of them are connected to the Lazarus group, and we also found overlaps in the post-exploitation process.”

Researchers found that on October 27, two Windows servers belonging to the Ministry of Health entity were compromised with sophisticated malware known to Kaspersky as “wAgent.” Closer analysis found that the malware used against the public health office had the same infection scheme as Lazarus’ previous attacks on cryptocurrency businesses.

The attack on the pharmaceutical company took place on September 25. Researchers found that the threat actor deployed Bookcode malware in a supply-chain attack through a South Korean software company. This particular type of malware has been previously reported by security vendor ESET to be connected to Lazarus.

Bookcode and wAgent malware have similar functionalities, with both boasting a full-featured backdoor. After deploying the final payload, the malware operator can take control of the victim’s machine.

“These two incidents reveal Lazarus group’s interest in intelligence related to COVID-19,” said Seongsu Park, security expert at Kaspersky. “While the group is mostly known for its financial activities, it is a good reminder that it can go after strategic research as well.” 

Park went on to issue a grave warning to all organizations striving to put an end to the long-running global health pandemic. 

“We believe that all entities currently involved in activities such as vaccine research or crisis handling should be on high alert for cyber-attacks,” said Park.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber-Attack on European Court of Human Rights

Cyber-Attack on European Court of Human Rights

The European Court of Human Rights has fallen victim to a cyber-attack after publishing a ruling regarding the fate of an incarcerated Turkish political leader. 

According to Bloomberg, hackers struck at the Court’s website on Tuesday, knocking it offline for approximately 16 hours. The website has now been restored, and the order is one again accessible to the public.

The attack came shortly after the Court published a grand chamber ruling on December 22 demanding that Turkey release the former leader of the pro-Kurdish Peoples’ Democratic Party (HDP), Selahattin Demirtaş, immediately. 

Demirtaş was locked up after helping the HDP win enough seats to end the parliamentary majority of Recep Tayyip Erdoğan’s Justice and Development Party (AKP) in the 2015 general election.  

He was indicted on offenses related to terrorism and jailed in 2016 after parliamentary immunity for politicians was revoked in Turkey. If convicted of the more than 100 charges that he faces, Demirtaş could receive a sentence of 142 years in prison. 

The Court found that the detention of 47-year-old Demirtaş, which has lasted more than four years, goes against “the very core of the concept of a democratic society.”

A panel of 17 judges said that by locking up the politician, Turkey was sending “a dangerous message to the entire population” that pluralism and free political debate will be stifled.

Hacking collective Anka Neferler Timi (The Turkish Hacker Team) appear to have claimed responsibility for the cyber-attack. The group posted on Twitter that they had brought the website down and asked the Court to apologize for the ruling they issued regarding Demirtaş.

The Twitter account used by Anka Neferler Timi was only created earlier this month and has fewer than 100 followers. 

Today, the Court released the following statement: “Following the delivery of the Selahattin Demirtas v. Turkey (no. 2) judgment on 22 December, the website of the European Court of Human Rights was the subject of a large-scale cyberattack which has made it temporarily inaccessible. The Court strongly deplores this serious incident. The competent services are currently making every effort to remedy the situation as soon as possible.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Semperis Appoints Igor Baikalov as Chief Scientist

Semperis Appoints Igor Baikalov as Chief Scientist

Semperis has announced the appointment of Igor Baikalov as its chief scientist to lead the enterprise identity protection company’s research division.

In his new role, Baikalov is tasked with developing identity-centric models of cyber-attacks as well as enhancing the cyber-resiliency of hybrid identity stores through the application of identity analytics and machine learning.

He joins Semperis following over 30 years’ experience working in data analysis and enterprise application development, covering areas such as insider threats and risk monitoring.

Baikalov’s most recent position was chief scientist at security firm Securonix, where he led the development of behavioral models of cyber-attacks and automated large-scale detection of cyber-threats.

He has also previously worked for the Bank of America in the role of senior vice president, global information security, where he was charged with developing security intelligence and risk analytics solutions. In his time at this institution, he helped create solutions for predictive analytics, risk-based governance and proactive data protection.

Mickey Bresman, CEO of Semperis commented: “As Semperis continues to deliver on our promise to provide customers with cutting-edge identity protection technology, Igor will play a major role in our efforts.

“A pioneer in the world of data analytics and threat intelligence, Igor is well versed on the challenges facing large IT and security teams. He brings years of proven leadership and first-hand experience developing enterprise security intelligence and risk analytics solutions. We’re happy to welcome Igor to the team, as we constantly evolve the toolsets that enterprises need to achieve identity-centric security and cyber resilience for hybrid identity environments.”

Baikalov added: “I’m eager to join the Semperis team during a period of remarkable growth for the company and amid surging demand in the market for identity management security and resilience solutions.

“In the modern highly-mobile digital world with disappearing security perimeters, identity is key to protecting the enterprise, and it’s also the focal point for attackers. Identity analytics and machine learning will further enhance the Semperis cyber-resiliency platform by facilitating identity hygiene, uncovering risky exposure, isolating attack paths, and automating system response to protect hybrid identity stores.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber Insurance Market Expected to Surge in 2021

Cyber Insurance Market Expected to Surge in 2021

The global cyber insurance market is projected to grow by 21% next year, reaching $9.5bn in value, according to new data by insurance firm Finaria.it.

This is as a result of greater recognition of the increasing cyber-threat landscape, exacerbated by the shift to remote working this year. Finaria added that the cyber insurance market is expected to reach $20.4bn by 2025, as more organizations look to protect themselves from malicious actors.

In its analysis, the company cited data showing that almost one-quarter of all cyber insurance claims between 2013 and 2019 were in the healthcare sector, an industry particularly heavily targeted by attackers this year amid the COVID-19 pandemic. Healthcare was followed by IT and telecommunications, insurance, retail and wholesale and manufacturing as the sectors with the most claims.

Almost three-quarters of claims in this period involved an insurance clause related to breach incident response and crisis management. In second place was data privacy breaches, with cyber-extortion in third.

In the first half of 2020, ransomware attacks were found to be the biggest cause of cyber insurance claims in North America.

Data from the Ponemon institute’s Cost of a Data Breach Report earlier this year was also highlighted, which showed that healthcare has the most expensive data breach costs, at $7.13m per incident, with energy in second at $6.39m per breach. This is followed by financial services ($5.85m), pharma ($5.06m) and technology ($5.04m).

Finaria.it commented: “Over the years, cyber-attacks and data breaches became one of the biggest risks in the business sector, compromising sensitive data, and causing a massive financial hit to companies and organizations worldwide. As data applications and technology in the business sector increase, organizations are becoming more vulnerable to these attacks and more aware of the need for insurance coverage for cyber-risks.

“If a costly data breach occurs, the company may not have enough resources to resolve these issues and cover the losses. Cybersecurity insurance can provide support to businesses, so cyber-attacks do not cripple their business.”

Earlier this year, a study found that more than 80% of UK businesses still don’t have cyber-related insurance, while another revealed that under 13% of SMEs in the UK have cyber insurance.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Leaky Server Exposes 12 Million Medical Records to Meow Attacker

Leaky Server Exposes 12 Million Medical Records to Meow Attacker

A healthcare technology company leaked 12 million records on patients including highly sensitive diagnoses, before the exposed cloud server was struck by the infamous “meow” attacker, researchers have revealed.

A team at SafetyDetectives led by Anurag Sen discovered the leaky Elasticsearch server in late October after a routine IP address scan, although it’s unknown how long the data was exposed for before that.

It was traced back to Vietnamese tech firm Innovative Solution for Healthcare (iSofH), which provides software for electronic health records and hospital management to 18 medical facilities, including eight top-tier clinics.

As the server was left publicly exposed without encryption or password protection, the researchers were able to view a 4GB database of 12 million records, affecting roughly 80,000 patients and healthcare staff.

The data is a treasure trove for fraudsters, containing full names and dates of birth, postal and email addresses, phone numbers, passport details, credit card numbers, medical records and recent test results and diagnoses.

It also included the personal information of some children.

Three days after the discovery, the database was attacked by the meow bot which deleted an unspecified number of indexes.

After reaching out to iSofH and the Vietnamese CERT in mid-November to no avail, the researchers were finally able to contact the latter in early December, although the organization apparently hasn’t been persuaded to take the incident seriously.

That’s despite the potential for follow-on blackmail and fraud attacks using the leaked data.

“The server contained incredibly detailed patient information and logs, as well as personal information regarding company staff and even partial information about the doctors who work at the various hospitals iSofH operates. If such information was to fall into the hands of criminals, this would present an acute security risk to doctors, company staff and patients simultaneously,” SafetyDetectives argued.

“More broadly, revealing full names, addresses and emails can be harnessed by nefarious users to inflict severe financial and reputational harm upon victims in the form of identity theft and financial fraud. The availability of credit card information further exacerbates the potential danger posed to victims, leaving them susceptible to credit card fraud and other financial crimes.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Web Page Layout Can Trick Users into Divulging More Info

Web Page Layout Can Trick Users into Divulging More Info

Computer users can be manipulated into divulging more information than they would normally simply by the layout of webpages, new research has revealed.

A team at Israel’s Ben-Gurion University of the Negev (BGU) presented its study, Online Disclosure Depends on How You Ask for Information, at the International Conference on Information Systems last week.

They examined the behavior of 2504 users who were asked to provide their country, full name, phone number, and email address as part of the sign-up process for Tel Aviv-based digital bank, Rewire.

Successful tactics included asking for relatively non-sensitive info first and then gradually scaling up the requests to more private details. Similarly, by placing information requests on separate but consecutive web pages, the researchers were also able to elicit more personal data from the participants.

The research garnered impressive results.

“We found that both manipulations independently increased the likelihood of sign-up and conversion,” said Lior Fink, head of the BGU Behavioral Information Technologies (BIT) Lab and a member of the Department of Industrial Management and Engineering.

“The ascending privacy intrusion manipulation increased sign-up by 35% and the multiple-page manipulation increased sign-up by 55%.”

Lead researcher Naama Ilany-Tzur added that regulators and members of the public should be made aware of such tactics, as they may help social engineering attackers to bypass users’ natural caution when divulging personal details online.

However, on a less security-centric note, the BGU student also heralded the research as an important discovery for marketers trying to find the optimal way to capture as much data on individuals as possible.

Ideally, the findings of research like this would be built into security awareness training courses. However, research released this week revealed that just 8% of UK firms carry out regular training in the first place.

The iomart study found that a quarter (28%) of employers offer no cybersecurity training for remote workers, while a further 42% do but only to select employees. Yet even the majority of those that get training are given a short briefing rather than the regular sessions that are required to keep up-to-date with evolving threats.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US: Buying Chinese Tech is a “Grave Threat” to Your Data Security

US: Buying Chinese Tech is a “Grave Threat” to Your Data Security

The US government has urged domestic businesses not to invest in Chinese IT kit or data services over fears companies there will be coerced by the Communist Party into enabling cyber-espionage.

The business advisory from the Department of Homeland Security (DHS) clarified what many have known for some time: that the People’s Republic of China (PRC) is on a mission to become self-sufficient in technology and a global tech superpower over the coming decades.

A key part of this strategy is to steal intellectual property from foreign firms and governments. The same tactic is used to enhance the PRC’s military capabilities, the advisory noted.

Local Chinese firms are compelled to covertly assist intelligence officers according to the requirements of the 2017 National Intelligence Law (aka the Cybersecurity Law), and an updated version in 2020 which is designed “to force foreign markets to remain open to Chinese data services providers.”

A third law from 2020 requires foreign commercial crypto firms to provide encryption keys to the PRC government.

Together, these make Chinese tech firms a bad bet for US businesses, because they mean the state can force local providers to send customer data and encryption keys to Beijing, and install backdoors in equipment, the advisory argued.

“The PRC’s data collection actions result in numerous risks to US businesses and customers, including: the theft of trade secrets, of intellectual property, and of other confidential business information; violations of US export control laws; violations of US privacy laws; breaches of contractual provisions and terms of service; security and privacy risks to customers and employees; risk of PRC surveillance and tracking of regime critics; and reputational harm to US businesses,” it said.

The warning extends to fitness trackers, mobile applications and even foreign data centers built with Chinese equipment, among other things.

It can be seen in the context of a bipartisan crackdown on perceived abuses by China that have been ongoing for years, as the Asian giant seeks to grow its economic, technological and military strength.

Most recently, legislation has passed the Senate designed to prevent Chinese firms listed on US stock exchanges from escaping regulatory scrutiny, as they have for over a decade, and — just this week — to punish foreign firms looking to steal American IP.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk