US Healthcare Provider Proposes $4.2m Data Breach Settlement

US Healthcare Provider Proposes $4.2m Data Breach Settlement

An American healthcare provider is proposing to resolve a lawsuit filed on behalf of victims of a 2019 data breach with a $4.2m settlement.

Kalispell Regional Healthcare, based in Montana, announced in October last year that a data breach had occurred. Approximately 130,000 patients had their personal health information (PHI) exposed as a result of a cyber-attack.

Criminals used what Kalispell chief executive officer and president Craig Lambrecht described as a “sophisticated phishing attack” to gain access to the email accounts of multiple employees on May 24, 2019. The breach wasn’t detected by the healthcare provider until August of that year. 

Patient data compromised in the breach included names, addresses, telephone numbers, dates of birth, medical record numbers, medical histories, Social Security numbers, and health insurance information.

Attackers stole an estimated 250 Social Security numbers from Kalispell Regional patients. After announcing the breach, the healthcare provider advised patients to review account statements, report suspicious activity to the authorities, and, if necessary, place security freezes on their credit files.

The lawsuit claimed that Kalispell failed to take appropriate measures to ensure the privacy of patient data and placed patients at financial risk by waiting until October to disclose the security incident. 

It further alleges that employees were not given adequate security awareness training and that Kalispell didn’t do enough to monitor its systems for suspicious activity. 

The class-action lawsuit was filed against Kalispell Regional in the Montana Eighth Judicial District Court in Cascade County on November 22, 2019. The case is scheduled to go before Judge Elizabeth Best for a final approval hearing on January 5.

Kalispell Regional denies any wrongdoing in the settlement document. The healthcare provider proposes establishing a $4.2m settlement fund that will be used to pay various relief benefits to victims of the data breach.

statement released by the healthcare provider on Friday reads: “The letter references a class action settlement that has been proposed in litigation relating to the cybersecurity event KRH experienced in October, 2019. Settlements are common with events such as these and we will work with the court through the settlement process.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

One Charged in Puppy Scam

One Charged in Puppy Scam

The United States Department of Justice has brought charges against the alleged operator of a puppy scam website that defrauded American consumers. 

A criminal complaint was unsealed on December 4 in federal court in Pittsburgh charging Desmond Fodje Bobga with conspiracy to commit wire fraud, wire fraud, forging a seal of the US Supreme Court, and aggravated identity theft.

According to the affidavit filed with the complaint, 27-year-old Cameroon native Bobga and his co-conspirators offered puppies and other animals for sale online. Victims were contacted by email and text message and conned into handing over money for pets that never arrived. 

Bobga and his co-conspirators allegedly told victims that their new pets would be delivered by a transportation company and provided them with fake tracking numbers. 

The scammers then posed as the transportation company, telling victims that their delivery had been delayed and that they would need to pay extra money to ensure the safe arrival of their pet.

Some victims were instructed to hand over additional money because their pet had supposedly been exposed to the coronavirus. 

“The perpetrators used false and fraudulent promises and documents regarding shipping fees and coronavirus exposure to extract successive payments from victims,” said the Department of Justice.

Among the fake documents were a “refundable crate and vaccine guarantee document” that purported to have been issued by the “Supreme Court of the United States of America” and bore the seal of the court, along with the signature of a Clerk of the Court.   

One victim, who resides in Cheswick, Pennsylvania, paid $1,500 for a Chihuahua named Bentley that never arrived.

A couple from Dallas, Texas, seeking to purchase a puppy named Snow White were conned out of $1,800 while another victim in Fruitland, Iowa, was tricked into handing over $1,840 for a miniature dachshund that was not delivered.

Another victim, located in New Brighton, Pennsylvania, lost a total of $9,100 while attempting to purchase a mini-dachshund for her mother. 

Bobga was arrested in Cluj, Romania, on December 3. If found guilty of all charges, he faces a maximum prison term of 27 years.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Orca Security Nets $55m Series B Funding

Orca Security Nets $55m Series B Funding

Cloud security provider Orca Security has announced a $55m Series B fund round led by ICONIQ Growth with participation from previous investors GGV Capital, YL Ventures and Silicon Valley CISO Investments.

The funding will see the firm expand its cloud security and compliance capabilities, with the aim of almost tripling its R&D team by the end of 2021.

The company also plans to open new sales offices in the UK and Australia to serve the European and APAC markets and boost its sales operations to meet global product and customer demand.

Avi Shua, CEO and co-founder of Orca Security, said: “Cloud security is fundamentally broken. Practitioners are forced to waste their time installing and maintaining security agents instead of managing actual security risks. Even after spending years plumbing agents in their environment, coverage is usually limited to less than 50%.

“The fact is, competing solutions view cloud resources as simple lists whereas bad actors see a graph with a clear path of attack. Orca Security changes that paradigm by visualizing cloud resources through the lens of an attacker.”

“We are very impressed with the depth, ease of deployment and effectiveness of Orca Security’s technology, and believe in its potential to solve the growing problem in cloud security,” added Matthew Jacobson, general partner at ICONIQ Growth. “We have been fortunate to partner with many high growth, high impact, emerging market leaders with an unmatched approach to solving customer needs and we have full confidence in Orca Security’s long-term opportunity as an important technology leader.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

One in Five Online Marketplace Listings Show Signs of Fraud

One in Five Online Marketplace Listings Show Signs of Fraud

Around one in five (19%) items listed on UK online marketplaces over Black Friday and Cyber Monday this year showed signs of being fraudulent or dangerous, according to an analysis by Besedo.

In total, the investigation of around 3000 public listings in the month of November found that 15% of items had indications of being scams. A particularly high proportion of consumer electronic products were observed to have these characteristics, with the researchers stating that 22% of PlayStation 5 listings were likely to be scams during the month, which rose to over a third over the Black Friday weekend. Interestingly, only 7% and 5% of competing gaming consoles Xbox Series X and Xbox Series S were likely to be scams, which may be a result of difficulties consumers have had in finding a PS5 available for sale.

Close to one in five (19%) of iPhone 12 products listed also showed signs of fraud.

Besedo also recorded that fashion products on online marketplaces are leaving shoppers at substantial risk of losing their money or receiving fake goods, with 15% of listings found to be counterfeit.

Another area of concern highlighted was the sale of pets on this platform, with close to a quarter (23%) of listings for puppies observed to be scams.

This year, the shift to e-commerce brought about by COVID-19 has increased the risk of consumer fraud, and Christmas shoppers have been urged to be extra vigilant when searching for bargains.

Petter Nylander, CEO of Besedo, commented: “This holiday season really is a one-two punch of risk for shoppers. Fewer gifts will be bought in physical retail stores, as we all work to limit the spread of the pandemic, leaving online retail as the main source for gift buying for many.

“At the same time, anticipated slow deliveries will give scammers more leeway to string along their targets, making it that much harder for victims to know that they’ve been caught out and take the appropriate action. We should all be taking additional care while buying presents this year, triple checking that prices are realistic, that the seller seems genuine and that the goods are what they say they are before pressing the buy button.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Most Victim Organizations Suffer Second Intrusion Within a Year

Most Victim Organizations Suffer Second Intrusion Within a Year

Security experts have warned victims of sophisticated cyber-attacks not to think of intrusions as a one-off event, as a majority of organizations end up getting hit again within the year.

CrowdStrike compiled an analysis of its own incident response and managed services engagements in 2020, to produce the CrowdStrike Services Cyber Front Lines Report.

It warned that in 68% of cases where an organization had experienced an intrusion, it is targeted again within 12 months. This makes the case for continuous monitoring and response, although too many organizations still believe they can get back to business-as-usual following an intrusion, the report argued.

Another oversight related to anti-malware and endpoint detection and response (EDR) tools, which CrowdStrike claimed were either not fully deployed, not supported on the operating system or improperly configured in 30% of cases.

This may have led to the fact that these tools failed to provide adequate defense against increasingly sophisticated eCrime tactics in 40% of cases.

“It emphasizes the need to not just buy a security product, but actually invest in ensuring comprehensive coverage in your environment and proper configuration, tuning and integrating it into your security operations program to mitigate even the most sophisticated attacks,” the report argued.

When it comes to financially motivated cybercrime, the vast majority of incidents tracked by the vendor (81%) related to ransomware. The remaining 19% were split between point-of-sale intrusions, e-commerce website attacks, business email compromise (BEC) and cryptocurrency mining.

However, although the attacks often garner most headlines, state-sponsored activity remained a serious threat across a wide range of sectors, according to the report.

CrowdStrike CSO and President, Shawn Henry, argued that remote work has helped to provide new attack surfaces and vectors for attackers to exploit in 2020.

“Holistic coordination and continued vigilance are key in detecting and stopping sophisticated intrusions; because of this, we’re seeing a necessary shift from one-off emergency engagements to continuous monitoring and response,” he added.

“This will better enable incident response teams to help customers drastically reduce the average time to detect, investigate and remediate from 162 hours to less than 60 minutes.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Former NCSC CEO Ciaran Martin Joins SBRC Board

Former NCSC CEO Ciaran Martin Joins SBRC Board

Former National Cyber Security Centre (NCSC) CEO Ciaran Martin has joined the board of the Scottish Business Resilience Centre (SBRC) to strengthen its strategic cyber-relationships across the UK.

Martin was the first CEO of the GCHQ spinout and held the position from 2017 until he stepped down earlier this year. He was replaced by Lindy Cameron, who took on the role in July.

SBRC is a non-profit organization which supports and helps protect Scottish businesses. Martin will work with SBRC CEO, Jude McCorry, and the wider organization to build its broader cyber-strategy and strengthen its affiliation with industry and government.

Jude McCorry, CEO of SBRC, said: “Businesses have never before experienced the strain that they currently face as a direct result of Brexit and COVID-19. Added to the fact that we have seen a noticeable a rise in cyber-attacks on businesses, if the extremely tough market conditions don’t negatively impact a business, a security breach might.

“The role of business resilience centers has never been more important. Ciaran’s experience with the NCSC, Cabinet Office and GCHQ will allow us to ensure that our own cyber-strategy is industry leading and reinforces Scotland as one of the world leaders in cybersecurity.”

Martin added: “The work that the SBRC does is unique; the collaboration and connection it has with its partners has helped to cement its position as one of the foremost business resilience organizations in Europe. I look forward to working with Jude and the team to support their vision and further enhance the organization’s cybersecurity expertise.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Thales and Google Cloud Partner for External Encryption Key Management

Thales and Google Cloud Partner for External Encryption Key Management

Thales has announced a collaboration with Google Cloud to allow users to securely migrate sensitive data between public cloud, hybrid and private IT infrastructures.

The joint innovation will allow the two companies to offer new capabilities which will enable security teams to own and control their encryption keys, and leverage Google Cloud technology for the external key management needed to control and secure data across hybrid cloud IT environments.

Addressing both private and public cloud environments, Thales and Google Cloud will provide a solution that manages, brokers and stores encryption keys completely controlled by the customer, effectively enabling companies to move data assets to the cloud with confidence.

Thales will also integrate its CipherTrust Key Broker service with the Google Cloud External Key Manager (EKM). By generating encryption keys using the CipherTrust Key Broker, organizations can verify the origin and quality of the keys they are providing to the cloud provider, while maintaining the original version of the key outside of the Google Cloud environment.

Users will hold their master keys in a Thales Luna Cloud HSM, which acts as the trust anchor for the CipherTrust Key Broker solution. “Our collaboration with Google Cloud truly embodies the technology leadership needed to place the control of data directly into the hands of our customers,” said Sebastien Cano, SVP for cloud protection and licensing at Thales.

“Companies no longer need to put their sensitive data in untrusted environments and relinquish control of their coveted encryption keys. It has become abundantly clear that an evolution in data protection is taking place at a global level as security professionals work together to build a shared responsibility security model between enterprise customers and providers. With this joint innovation effort, we’re supporting organizations as they move to the cloud with confidence.”

Sunil Potti, VP and GM of Google Cloud Security, said the relationship with Thales was created to further protect its customers’ most sensitive information, as companies deal with “an extremely fluid and dynamic business environment where even the best lines of defense are constantly being battle tested.

“Together with Thales, we acknowledge the current set of circumstances and remain vigilant to provide customers with the most advanced solutions that address today’s cybersecurity needs as well as those that are emerging on the horizon,” Potti said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NSA: Patch VMware Bug Now to Stop Russian Hackers

NSA: Patch VMware Bug Now to Stop Russian Hackers

The National Security Agency (NSA) has issued an alert warning that Russian state hackers are exploiting a VMware vulnerability to access sensitive data and maintain persistence in targeted systems.

The NSA urged network administrators at the US National Security System (NSS), Department of Defense (DoD) and Defense Industrial Base (DIB) to patch the bug as a priority.

VMware fixed CVE-2020-4006 on December 3. It’s a Command Injection Vulnerability that exists in VMware Access and VMware Identity Manager products.

“The exploitation via command injection led to installation of a web shell and follow-on malicious activity where credentials in the form of SAML authentication assertions were generated and sent to Microsoft Active Directory Federation Services (ADFS), which in turn granted the actors access to protected data,” the NSA explained in its advisory.

“It is critical when running products that perform authentication that the server and all the services that depend on it are properly configured for secure operation and integration. Otherwise, SAML assertions could be forged, granting access to numerous resources.”

The NSA recommended that any admins integrating authentication servers with ADFS follow Microsoft best practices such as MFA.

It said that password-based access to the web-based user interface of the device is required to exploit the bug, so using a strong and unique password would help to mitigate the risk, as would disconnecting the interface from the internet.

Daniel Trauner, director of security at Axonius, likened the vulnerability to one in a MobileIron MDM exploited recently as it enables compromise across a potentially large number of organizations.

“Bugs that affect central infrastructure like this, even slightly lower severity bugs that require prerequisites for authentication, are attractive and useful to adversaries because these systems are the central aggregation point for a significant portion of infrastructure. This makes pivoting easy,” he said.

“In addition to prioritizing patching and updating assets with known critical vulnerabilities, organizations need to make sure they are gathering detailed information about their assets —particularly those central to core infrastructure — and continually validate every asset’s adherence to their overall security policy.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

BTC-e Founder Gets Five Years for Money Laundering

BTC-e Founder Gets Five Years for Money Laundering

A Russian national has been sentenced to five years after being found guilty by a French court of large-scale money laundering, although charges relating to his alleged involvement in ransomware development were dropped.

Alexander Vinnik was extradited at the start of 2020 to France from Greece, where he had been since his arrest there in 2017.

The US authorities indicted him that year for laundering over $4bn in funds via his Bitcoin exchange, BTC-e. They alleged that his business had become heavily reliant on criminal customers, and received the proceeds from numerous identity theft campaigns, ransomware attacks, narcotics gangs and corrupt public officials.

These allegedly included money taken from now-defunct exchange Mt Gox, which spectacularly collapsed in 2014 after large sums were stolen from its customers.

Following his arrest, Vinnik became the subject of a three-way tussle for extradition between the Russian, French and American authorities.

Some $90m in assets were seized by New Zealand police in June this year, following a coordinated campaign with the US Internal Revenue Service.

Vinnik was handed a five-year sentence for money laundering by a judge in Paris yesterday, although prosecutors also wanted him charged with “extortion, conspiracy and harming automatic data-processing systems,” according to local reports.

He was accused of helping to develop the Locky ransomware, which the authorities said was responsible for extorting $157m out of French organizations.

Vinnik maintained his innocence throughout, claiming that he was merely a technical assistant working for BTC-e. He went on hunger strike in January to try to force an extradition to his home country.

His attorney, Frederic Belot, has reportedly claimed that the US authorities are still seeking to get their hands on Vinnik.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk