Phishing Most Frequently Reported Cybercrime in US

Phishing Most Frequently Reported Cybercrime in US

Phishing and social media/email hacks are the most frequently reported cybercrimes in the United States and the United Kingdom, respectively, according to new research by cybersecurity company Clario and British cross-party think-tank Demos.

The finding was included in “The Great Cyber Surrender” report, created from the results of a survey of 2,000 people in the UK and the US about cybercrime and its impact.

Other insights provided by the report are that while one in three Brits is worried about phishing scams, this particular cybercrime is only a concern for one in five Americans. Ransomware is a worry for a third of Brits and Americans, while a fifth of UK and US residents worry about their financial data being stolen.

One in five people surveyed had been a victim of a cybercrime, with this fate befalling one in five Americans and one in ten Brits. 

Victims of cybercrime rate stress (reported by 75%) and anxiety (reported by 70%) as the most common psychological impacts. Other mental repercussions include fear (52%), shame (51%), anger (48%), and isolation (43%).

More than half (57%) of Brits don’t find reporting cybercrime to their government helpful, and just 21% say the legal system does a good job of protecting them from online fraud. 

More than half (55%) of Americans feel their legal system is doing a good job of protecting them from online fraud; however, 37% say reporting cybercrime to their government is not helpful. 

“Despite cybercrime being a widely spread issue, most people do not know how to protect their digital identities which eventually has a massive impact on their real lives,” said Scarlet Jeffers, VP of experience at Clario. 

“Clearly, both the US and UK governments aren’t doing enough to implement policies that protect consumers, and people have lost faith in these institutions to protect them.”

Researchers noted certain differences in attitude toward security among age groups. 

“A false sense of security was more apparent among Gen Z-ers, (18- to 25-year-olds), with 50% feeling they aren’t important enough or vulnerable enough to be targeted by hackers.

“In comparison, those aged 65+ were far less likely to have this attitude, with just 15% agreeing with the statement ‘I’m not vulnerable enough’ and 22% agreeing with ‘I’m not important enough’ to be targeted by hackers,” noted researchers.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Nigerians Arrested Over International BEC Scam

Nigerians Arrested Over International BEC Scam

Alleged members of a Nigerian cybercrime gang that compromised 500,000 companies and government organizations in more than 150 countries have been arrested.

The arrests were made in Lagos as part of the year-long, INTERPOL-led Operation Falcon targeting cyber-criminals who use business email compromise (BEC) scams to steal money. 

Singapore-based cybersecurity company Group-IB, which has been tracking the gang they dubbed TMT since 2019, supported the operation. The company’s APAC Cyber Investigations Team, with the help of CERT-GIB teams, identified a trio of Nigerian nationals as gang members.

A Nigerian cybercrime police unit subsequently arrested three suspects, referred to as 32-year-old OC, 34-year-old IO, and 35-year-old OI. 

Police said data discovered on the devices of the arrested trio confirms their involvement in the criminal BEC scheme and includes stolen data from at least 50,000 targeted victims.

“The analysis of their operations revealed that the gang focuses on mass email phishing campaigns distributing popular malware strains under the guise of purchasing orders, product inquiries, and even COVID-19 aid impersonating legitimate companies,” said a Group-IB spokesperson.

The attackers use Gammadyne Mailer and Turbo-Mailer to send out phishing emails in English, Russian, and Spanish, and MailChimp to track whether a recipient has opened the malicious message.

The goal of their attacks was to steal authentication data from browsers, email, and FTP clients, possibly to sell to the highest dark net bidder.

INTERPOL said: “The suspects are alleged to have developed phishing links, domains, and mass mailing campaigns in which they impersonated representatives of organizations.  

“They then used these campaigns to disseminate 26 malware programmes, spyware and remote access tools, including AgentTesla, Loki, Azorult, Spartan and the nanocore and Remcos Remote Access Trojans.” 

The gang used these programs to infiltrate and monitor the systems of victim organizations and individuals, then launched scams and syphoned funds. 

Vesta Matveeva, head of the Cyber Investigations Team at Group-IB APAC, highlighted the importance of cooperation in catching cyber-criminals. 

“This cross-border operation once again demonstrated that only effective collaboration between private sector cybersecurity companies and international law enforcement can bring evildoers to justice,” said Matveeva.

“It allows us to overcome regulatory differences across countries that impede threat intelligence data exchange.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Medical Officer Speaks Out Against Cyber-Bullying

Medical Officer Speaks Out Against Cyber-Bullying

A Canadian doctor who is being bullied online over his handling of the coronavirus pandemic has called for people to treat each other with kindness and respect.

The receipt of online threats has been an issue for the medical officer of health for the Windsor-Essex County Health Unit, Dr. Wajid Ahmed, and his colleagues since the start of the coronavirus outbreak. However, the problem has worsened in recent months.

Speaking out to mark Bullying Awareness Week, Ahmed said: “We have received many threatening letters to the health unit and also emails, which is, again, all understandable. People are frustrated, people are upset.

“The message we want to share is it’s not okay to bully anyone.” 

Ahmed took up the position of medical officer in January 2019. He told CBC that since the novel coronavirus outbreak, he and Theresa Marentette, the health unit’s chief nursing officer, have been “living and breathing . . . I want to call it a nightmare, not a dream, of COVID pandemic.” 

Married father of three sons Ahmed revealed that his children had been upset after reading cruel comments posted about their father online. However, the doctor from Pakistan who carved out a career for himself in Canada turned the negativity into a teaching moment.

“I use that as an opportunity to teach them. What people do, it is beyond our control or anyone’s control, you cannot control behavior,” said Ahmed.

“The only thing we can change is the perspective of society, is to learn to be kind, is to learn to be okay to have your own opinion . . . but you having an opinion does not mean you can start challenging anyone and everyone about whatever they believe in and intimidate them in such a way.”

Ahmed said that fear of being cyber-bullied was putting some people off seeking medical assistance for COVID-19.

“There can be online gossip related to potential cases, threats around disclosing information around close contacts and even threats made to [the] victim for being ill,” said the doctor.

Ahmed said such behavior may cause people to hide their symptoms or avoid getting tested “out of fear of what may be said to them because of their diagnosis.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#DTX Cybersecurity Mini Summit: Awareness Key to Securing a Remote Workforce

#DTX Cybersecurity Mini Summit: Awareness Key to Securing a Remote Workforce

A greater focus on employee training is the foundation to organizations tackling a fast-changing cyber-threat landscape, according to Rayad Jawaheer, sales engineer at Bitdefender, speaking during the DTX Cyber Security Mini Summit.

The shift to remote working since the start of the COVID-19 pandemic has meant staff, and consequently their organizations, are at heightened risk of attack. This is primarily due to operating across potentially unsecured networks and devices, as well as having limited access to IT teams.

Although security technologies and good procedures have an important role in combatting the rise in attacks on remote workers that have been observed this year, they will only be effective if they are operated by an engaged and knowledgeable workforce. “Having policies and supporting them with tools can get you so far, but educating and training users on the best practices will help explain and outline why they need to follow the policy and use the tools,” said Jawaheer.

He added: “Essentially you want your employees to care about cybersecurity, not only at home, but for business use as well.”

He noted that although most organizations have some form of security awareness training for their employees, it is often irregular “and the content can become very quickly outdated.” He therefore recommended monthly training sessions to keep staff fully educated on the evolving threat landscape “and more importantly [on] what their responsibilities are when it comes to your company’s information security program.”

This includes engendering a similarly cautious attitude while working from home as they do in the office.

As well as training, another crucial aspect of securing a remote workforce is having the right technological tools in place. Jawaheer noted: “Having a policy in place lets your employees know what they need to do and how to do it, but providing the right tools also reduces the risks of working remotely.”

The tools required can vary according to the type and size of the company. However, common examples include VPNs to ensure network traffic is encrypted regardless of whether staff are on a public or private network, building encryption into security systems to make sure it is harder for data to be pulled from a device if they are lost or stolen and password managers to allow staff to generate secure logins as well as reducing the risk of the same password being used across multiple services.

While such steps can be taken to mitigate the risk of security incidents taking place, there is still every chance of breaches and other situations occurring, and organizations must be ready to respond. This involves taking a more proactive approach to discovering issues early on, according to Jawaheer. In particular, organizations should embrace analytics to alert them early on to possible threats and quicken their response time.

He added: “Essentially, if you take a more proactive approach to alerting, this in turn will strengthen your overall security posture across your network.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#DTX Cybersecurity Mini Summit: How to Apply Individualized Zero-Trust Architecture

#DTX Cybersecurity Mini Summit: How to Apply Individualized Zero-Trust Architecture

Organizations need to work out how to apply the principle of zero-trust security to meet their specific requirements, according to a panel speaking at the DTX Cyber Security Mini Summit.

The concept of zero-trust has come into much sharper focus as a result of the shift to remote working during COVID-19, with the traditional approach of having a secure outer perimeter now largely redundant. Thomas Fischer, principal security consultant at FVT SecOps Consulting, noted: “This global pandemic has been a wake-up call for a lot of organizations on how they handle the ability to use systems away from the traditional model of the castle and moat structure – nobody is now stuck to a fixed terminal in a building.”

This has in turn meant that to some extent, organizations have lost control and visibility of their assets, and most crucially of all in the view of Fischer, of their data. “The critical asset is the data – it could be credit card information, intellectual property or source code – any of those things that actually makes your business run,” he said.

Organizational strategies for gaining control over access to data in this new environment is therefore crucial, and has generally centerd around the concept of zero-trust. Moderating the panel, Richard Archdeacon, advisory CISO at Duo Security, defined this as “looking at how you can be as confident as possible in identifying the access and reducing the perimeter down to that point of access so we know who you are, where you are and what you’re going to be doing.”

While there is growing understanding of this general principle, the panel acknowledged that there will be different interpretations as to how it will manifest within individual organizations. Alex Morgan, customer support engineer at Duo Security, explained: “Most organizations will have a slightly different view of what zero-trust is or at least what it will mean to them in terms of how they would actually look at implementing it.”

Carefully planning the practical application of zero-trust architecture should therefore be the priority for organizations right now. This strategy needs to start with an “inside out view” according to Archdeacon. “What’s the data, how important is it, what are the risks and threats? Then put the controls around that before looking outwards towards the access,” he outlined.

Similarly, Fischer said that organizations have to define their boundary in a different way – not by an application or technology stack, but “around the data.” He added that boundaries could be very different depending on the type of business; for instance, in financial institutions, there is likely to be a number of boundaries, with only certain types of users allowed to access each one.

A major aspect that also needs to be considered now is the growing use of third parties which handle organizations’ data, such as contractors, and in particular the way they access this information. “It’s no longer just users that need to access the information,” observed Fischer.

In the view of Morgan, good internal communication is the key to gaining these insights and delivering an effective zero-trust model. “That’s not necessarily just communication with end users, it’s between the security department and the different parts of the organization. Understanding how different parts of the business work and what their drivers are for getting their work done will really affect the success of implementing a lot of those security controls,” he explained.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Home Depot Settles with US States Over 2014 Data Breach

Home Depot Settles with US States Over 2014 Data Breach

Home Depot has reached a $17.5m settlement with 46 US states and Washington, D.C. regarding its 2014 data breach.

In the breach, the payment card data of 40 million customers was accessed by attackers between April 10 and September 13. That breach, which was uncovered by Brian Krebs, was reportedly the largest retail card breach on record at the time, estimated to have impacted around 56 million individuals.

Later, staff criticized the company’s attitude to security, and it was revealed that attackers used the username and password of a third-party vendor to enter the perimeter of the Home Depot network. They later deployed custom-built malware to access customers’ information.

It was also revealed that at least 52 million people had their email addresses exposed, partially overlapping those whose payment card data was compromised.

According to Reuters, Home Depot did not admit liability in agreeing to the settlement, but will comply with the following specific information security provisions: 

  • Employing a duly qualified CISO reporting to both the senior or C-level executives and board of directors regarding Home Depot’s security posture and security risks
  • Providing resources necessary to fully implement the company’s information security program
  • Providing appropriate security awareness and privacy training to all personnel who have access to the company’s network or responsibility for US consumers’ personal information 
  • Employing specific security safeguards with respect to logging and monitoring, access controls, password management, two-factor authentication, file integrity monitoring, firewalls, encryption, risk assessments, penetration testing, intrusion detection and vendor account management
  • Consistent with previous state data breach settlements, the company will undergo a post-settlement information security assessment which, in part, will evaluate its implementation of the agreed upon information security program 

In a statement, Home Depot said security is a top priority and that it has since 2014 “invested heavily to further secure our systems. We’re glad to put this matter behind us.”

Companies that collect sensitive personal information from customers “have an obligation to protect that information from unlawful use or disclosure,” Connecticut attorney general William Tong said in a statement. “Home Depot failed to take those precautions.”

Michigan attorney general Dana Nessel added: “I am pleased with this settlement as it sets procedures in place that The Home Depot must follow to further protect consumers’ interests and provide them peace of mind as they shop.” 

Jake Moore, cybersecurity specialist at ESET, said: “Punishing huge companies must set a precedent but we don’t want to see any company forced out of business for a mistake which may have been out of their control.

“Data breaches happen in a variety of ways and many could have been avoided with best practice, simulation attacks and better staff training. However, many are simply unavoidable and bad luck which do not require much more punishment other than the negative publicity they will no doubt attract. Maybe if the fines were reduced if companies were more open about how they were breached, we may see a change in how they [breaches] are reported and penalized.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

LOQBOX Appoints Tim Porter as New Chief Risk Officer

LOQBOX Appoints Tim Porter as New Chief Risk Officer

Credit building company LOQBOX has announced the appointment of Tim Porter as its new chief risk officer (CRO).

Porter brings more than 30 years of experience in international banking, finance and consultancy to the role having previously held positions at Royal Bank of Scotland, Impact Plus and Standard Chartered Bank. He is also a fellow of the International Compliance Association and holds the ICA’s professional postgraduate diploma in governance, risk and compliance, and a diploma in financial crime prevention.

As LOQBOX’s new CRO, Porter – who has been working alongside the firm as a consultant since 2017 – will be responsible for all aspects of risk and compliance across the enterprise.

Porter said: “After working alongside LOQBOX for several years as a consultant, I am thrilled to join this team. Having watched their journey with interest over the last couple of years, it is certainly a great time to join the company and to be able to work with an engaged and positive team through the next phase. This is a very exciting opportunity for me.”

LOQBOX co-founder and Co-CEO, Gregor Mowat, added: “We are delighted to have Tim join us at such an exciting time in LOQBOX’s evolution. We are growing at pace and are extremely pleased to be adding talent to our senior team. Tim’s broad and global experience will really help us to keep on the right path towards a successful future.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Peatix Braces Users for Follow-On Attacks After Breach

Peatix Braces Users for Follow-On Attacks After Breach

Events and ticketing app Peatix has warned users of follow-on cyber-attacks after admitting it suffered a data breach earlier this month.

The firm claimed to have been informed by a third party on November 9 that account information had been “improperly accessed and obtained.

“It has been confirmed that information, including names, email addresses, salted and hashed version of passwords, nicknames, preferred languages, and countries and time zones where the accounts were created, about some of our users was involved,” it noted.

Fortunately, because the company does not store passwords in plain text or full credit card details, the fallout from the breach should be fairly contained.

However, it is still requesting users to reset their passwords, and warned of potential follow-on credential stuffing and password spraying attacks, which suggests that its encryption may be crackable.

“If your information was obtained by bad actors, they could use it to contact you (e.g. by sending you emails) or to attempt to gather personal information from you by deception (known as phishing attacks),” the notice continued. “They may claim to be Peatix or send emails appearing to be from Peatix.”

Paul Bischoff, privacy advocate at Comparitech.com, argued that the level of risk exposure for affected customers will depend on details that haven’t yet been divulged by the company.

“Peatix has not stated what algorithm is used to hash and salt the passwords in the database, which would give us a better indication as to whether users’ passwords are at risk,” he explained.

“I’ve seen plenty of breaches of passwords that were hashed with deprecated algorithms such as SHA1 or MD5 that can be cracked with little effort, so it would be good to know what algorithm was used to encrypt those passwords.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Fines Less of a Concern than Reputational Damage for Public Sector Security

Fines Less of a Concern than Reputational Damage for Public Sector Security

In a survey of 250 UK public sector professionals working in cybersecurity, risk and data protection by Zivver, 52% of all respondents cited reputational damage as their biggest challenge in relation to outbound secure communications. This was followed by preventing data leaks (50%) and employee awareness on security (49%). Meanwhile, fines were deemed a lesser concern at 19%.

Speaking to Infosecurity, Rick Goud, CIO and co-founder of Zivver, said while the fines issued to BA and Ticketmaster put the topic more top of mind, “I don’t think the fear of fines is what will drive change.”

He added: “In the Netherlands, for example, the country with the highest adoption of email data protection solutions, fines hardly exist. Adoption will increase with higher awareness, which is enforced by media attention, public interest, independent research and awareness campaigns. So I see fines as a way to increase awareness, not increase fear.”

Regarding COVID-19’s impact on the security of outbound communications in public sector organizations, around one in three of all respondents said the pandemic brings additional vulnerabilities requiring ongoing security changes. Further reflecting the high levels of uncertainty, especially by those at the top, 43% of IT leaders in local government said their organization was less secure as a result of COVID-19.

In terms of data leak frequency, 82% of respondents said their organization had experienced at least one data leak in the past 12 months, while 73% stated they had suffered three or more.

Asked how much he thought this was due to greater remote working and the likelihood of security mistakes being made as a result, Goud said: “Stakeholders report an increase of data leaks since having a remote workforce, which is a logical consequence of two things. Firstly, any change will lead to people making more mistakes, because change is one of the most difficult things for people, inevitably resulting in errors. Secondly, additional data leaks will occur because, with a remote workforce, people have to increasingly rely on ways of communicating that were not built for security, like email and popular (free) SAAS-tools for sharing files, sending out questionnaires, etc.

“The latter, especially, is a problem that organizations increasingly recognize and are looking to fix by putting solutions in place that enhance and secure digital communication, knowing that the old way of working will not fully return.”

Goud claimed the findings of this survey indicate an urgent need for public sector organizations to review and update current security practices, requiring technology that is simple to introduce and use to avoid disruption to employees’ productivity.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FBI in Threat Warning After Surge in Spoofed Domains

FBI in Threat Warning After Surge in Spoofed Domains

The FBI is warning internet users to be on high alert for website and email domains masquerading as those of the crime-fighting agency.

The Bureau claimed in a Public Service Announcement that it has detected multiple threat actors registering fake domains mimicking legitimate FBI ones, which could be the precursor to a new campaign.

Cyber-criminals typically register domains that look identical to those of their victims, but which contain very small differences, such as an alternative TLD after the dot, or a slightly different spelling. Internationalized Domain Names (IDNs) also offer opportunities to use Cyrillic and other letters that look very similar to Roman alphabet characters.

Internet users could visit such sites of their own accord or be prompted to do so via phishing emails which also use spoofed domains to appear more trustworthy.

“Spoofed domains and email accounts are leveraged by foreign actors and cyber-criminals and can easily be mistaken for legitimate websites or emails,” the noticed warned.

“Adversaries can use spoofed domains and email accounts to disseminate false information; gather valid usernames, passwords, and email addresses; collect personally identifiable information and spread malware, leading to further compromises and potential financial losses.”

The Feds urged members of the public to ensure web and email addresses are correctly spelled, and that operating systems, computer software and anti-malware tools are all up-to-date.

It recommended users to disable Macros, and to never open unsolicited emails or attachments, or provide personal information to the sender.

Multi-factor authentication for log-ins and domain whitelisting were also recommended.

Tim Helming, security evangelist at DomainTools, argued that part of being security aware is becoming familiar with common abuse patterns.

“In this case, many of the illegitimate domains use various other words in conjunction with ‘fbi,’ which is a common practice by malicious actors. However, since legitimate organizations do own variations on their own domain names, internet users also need to consider the context of any link they are presented with,” he added.

“For example, if a link referring to the FBI (or other government agency) arrives as an unsolicited text message, there is a high likelihood of fraud. When in doubt, users should type the simplest version of the domain name (such as fbi.gov) into the browser, and navigate around the site to find the content they seek.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk