NCSC Issues Warning About Expected #BlackFriday Scams

NCSC Issues Warning About Expected #BlackFriday Scams

The National Cyber Security Centre (NCSC) has issued refreshed guidance for online shopping ahead of this week’s Black Friday.

The NCSC said that cyber-criminals are seeking to exploit an increased number of online shopping transactions in the run-up to Christmas and anticipated that consumers may slightly lower their guards during the rush to bag the best deals.

The advice includes:

  • Being selective about where you shop
  • Only providing necessary information
  • Using a secure protected payment
  • Keeping your accounts secure
  • Identifying suspicious emails, phone calls and text messages
  • What to do if things go wrong

As part of its ongoing work to protect the public from cyber-criminals, the NCSC’s takedown service, which is part of its Active Cyber Defence program, has removed 113,000 malicious URLs from fake online shops over the past 12 months. The NCSC is also supporting Action Fraud’s #FraudFreeXmas campaign following an increase of online fraud.

Sarah Lyons, NCSC deputy director for economy and society, said: “At this time of year our inboxes are filling up with promotional emails promising incredible deals, making it hard to tell real bargains from scams. We want online shoppers to feel confident they’re making the right choices and following our tips will reduce the risk of giving an early gift to cyber-criminals.

“If you spot a suspicious email, report it to us or if you think you’ve fallen victim to a scam, report the details to Action Fraud and contact your bank as soon as you can.”

According to a recent blog by Digital Shadows, risks to brand reputation accounted for 45% of the alerts it sent to retail clients, second only to data leakage risks. “As we have seen before, cyber-criminals love creating phishing pages and fake social media accounts to mislead users into exposing their login credentials, personally identifiable information (PII) or payment card data,” said Kacey Clark, security researcher at Digital Shadows.

For example, a threat actor may deploy a phishing campaign that targets a specific retailer’s customers. When customers receive emails that appear to be legitimate, they may be urged to click on malicious links or open malware-laced attachments, giving way to potential financial or credential compromise or malware propagation.”

Digital Shadows also said that roughly 30% of the retail risks identified throughout its recent reporting period involved the impersonation of domains, phishing sites and phishing attempts.

“As found in our previous research on the phishing ecosystem, out of over 100 advertisements for pre-built phishing pages and templates on cyber-criminal forums and marketplaces, 29% specifically targeted retail and e-commerce organizations,” Clark said.

“These were sold for an average of $20.43. In the same breath, we also found that the cheapest phishing page templates were for some of the biggest online brands, including retailers and social media sites, averaging between $2 and $3.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

MPs Bombarded by Nearly Three Million Monthly Email Attacks

MPs Bombarded by Nearly Three Million Monthly Email Attacks

UK Members of Parliament (MPs) have been targeted by a 60% year-on-year increase in cyber-attacks so far in 2020, according to new data from Parliament Street.

The think tank collected Freedom of Information (FOI) responses to reveal that over 22.3 million cyber-attacks were blocked by parliament from January 1 to August 31 2020.

That averages out at just under 2.8 million attacks per month, almost a million more than the 1.7 million monthly average detected last year, it said.

Parliament Street claimed that the increase could be explained by the pandemic, and attempts to hijack inboxes whilst MPs are working remotely and may be distracted.

Phishing attacks are still the easiest way to compromise an organization, argued Tessian CEO, Tim Sadler.

“Governments, therefore, need to protect their people from falling for phishing attacks, putting solutions in place to automatically detect threats and educating employees on threats like social engineering attacks,” he added.

“Failure to do so and the fallout could be disastrous, as cyber-criminals get their hands on sensitive data and gain illegal access to officials’ email accounts. Consider the damage that could be caused should a hacker successfully take over an MP’s email account.”

Yet despite the risks, parliament has proved pretty resilient to email attacks over recent years. There has been nothing to rival a 2017 incident where suspected Iranian state hackers brute forced a small number of accounts, and followed-up with a vishing campaign.  

Earlier this year, a parliamentary news alert sent to members of the House of Lords warned that the institution was under attack “every minute of every day.”

Over the summer, the role of director of security for parliament was advertised.

To put the FOI stats in perspective, Trend Micro blocked 27.8 billion cyber-threats in the first half of 2020, nearly 93% of which were email-borne.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Suspected in Man United Attack

Ransomware Suspected in Man United Attack

Security experts have suggested the cyber-attack that hit Manchester United late last week could be ransomware.

A brief statement issued on Friday evening confirmed that an incident had taken place, but added few details.

“The club has taken swift actions to contain the attack and is currently working with expert advisers to investigate the incident and minimize the ongoing IT disruption,” it noted.

“Although this is a sophisticated operation by organized cyber-criminals, the club has extensive protocols and procedures in place for such an event and had rehearsed for this risk. Our cyber-defenses identified the attack and shut down affected systems to contain the damage and protect data.”

The club added that its website and app remained unaffected by the attack and that it is “not currently aware” of any breach of personal data belonging to fans or customers.

“All critical systems required for matches to take place at Old Trafford remain secure and operational and tomorrow’s game against West Bromwich Albion will go ahead,” it added.

Jon Niccolls, EMEA & APAC incident response lead at Check Point, praised the club for responding swiftly to the attack.

“It isn’t clear what type of attack hit the club, but as its statement mentioned that it ‘shut down affected systems to contain the damage and protect data,’ this suggests ransomware, and possibly a double extortion attack where the attackers both steal data with the threat of leaking it, as well as encrypting it to disrupt operations,” he added.

“These are a fast-growing trend in 2020, and organizations such as football clubs are a prime target as their systems hold the details of hundreds of thousands of people including fans, employees, players as well as sensitive business and payment data.”

Sam Curry, chief security officer at Cybereason, said firms need to improve security hygiene and employee awareness to improve resilience against such attacks.

“Secondly, companies need to deploy around the clock threat hunting capabilities. They also need to deploy newer anti-ransomware software and advanced detection and response software (XDR) in order to be able to detect in real time when malicious behavior is occurring inside their network,” he added.

“Too often, cyber-criminals penetrate a network and then steal credentials and essentially impersonate employees that have been authorized, and unbeknownst to them, they are stealing proprietary data for weeks or months completely undetected.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk