Convicted SIM Swapper Gets 3 Years in Jail

A 21-year-old Irishman who pleaded guilty to charges of helping to steal millions of dollars in cryptocurrencies from victims has been sentenced to just under three years in prison. The defendant is part of an alleged conspiracy involving at least eight others in the United States who stand accused of theft via SIM swapping, a crime that involves convincing mobile phone company employees to transfer ownership of the target’s phone number to a device the attackers control.

Conor Freeman of Dublin took part in the theft of more than two million dollars worth of cryptocurrency from different victims throughout 2018. Freeman was named as a member of a group of alleged SIM swappers called “The Community” charged last year with wire fraud in connection with SIM swapping attacks that netted in excess of $2.4 million.

Among the eight others accused are three former wireless phone company employees who allegedly helped the gang hijack mobile numbers tied to their targets. Prosecutors say the men would identify people likely to have significant cryptocurrency holdings, then pay their phone company cohorts to transfer the victim’s mobile service to a new SIM card — the smart chip in each phone that ties a customer’s device to their number.

A fraudulent SIM swap allows the bad guys to intercept a target’s incoming phone calls and text messages. This is dangerous because a great many sites and services still allow customers to reset their passwords simply by clicking on a link sent via SMS. From there, attackers can gain access to any accounts that allow password resets via SMS or automated calls, from email and social media profiles to virtual currency trading platforms.

Like other accused members of The Community, Freeman was an active member of OGUsers, a forum that caters to people selling access to hijacked social media and other online accounts. But unlike others in the group, Freeman used his real name (username: Conor), and disclosed his hometown and date of birth to others on the forum. At least twice in the past few years OGUsers was hacked, and its database of profiles and user messages posted online.

According to a report in The Irish Times, Freeman spent approximately €130,000, which he had converted into cash from the stolen cryptocurrency. Conor posted on OGUsers that he spent approximately $14,000 on a Rolex watch. The rest was handed over to the police in the form of an electronic wallet that held the equivalent of more than $2 million.

The Irish Times says the judge in the case insisted the three-year sentence was warranted in order to deter the defendant and to prevent others from following in his footsteps. The judge said stealing money of this order is serious because no one can know the effect it will have on the victim, noting that one victim’s life savings were taken and the proceeds of the sale of his house were stolen.

One way to protect your accounts against SIM swappers is to remove your phone number as a primary or secondary authentication mechanism wherever possible. Many online services require you to provide a phone number upon registering an account, but in many cases that number can be removed from your profile afterwards.

It’s also important for people to use something other than text messages for two-factor authentication on their email accounts when stronger authentication options are available. Consider instead using a mobile app like Authy, Duo, or Google Authenticator to generate the one-time code. Or better yet, a physical security key if that’s an option.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Oregon County Hit by Ransomware Attack

Oregon County Hit by Ransomware Attack

An Oregon county hit by wildfires and a fall surge in Covid-19 cases is now dealing with the fallout from a cyber-attack.

Jackson County’s website is currently down following a recent ransomware attack on the county’s web-hosting service provider, Managed.com. The company took down all its servers on Monday after reportedly becoming the latest target of REvil. 

status update issued by Managed.com on November 19 said: “On Nov. 16, the Managed.com environment was attacked by a coordinated ransomware campaign. To ensure the integrity of our customers’ data, the limited number of impacted sites were immediately taken offline. Upon further investigation and out of an abundance of caution, we took down our entire system to ensure further customer sites were not compromised. 

“Our Technology and Information Security teams are working diligently to eliminate the threat and restore our customers to full capacity. Our first priority is the safety and security of your data. We are working directly with law enforcement agencies to identify the entities involved in this attack. As more information is available, we will communicate directly with you.”

With Jackson County’s regular website, jacksoncountyor.org, still inoperable, the county has established an alternate page, jacksoncounty.org, to allow the public to access key links on property taxes, 2020 election results, marriage applications, and public virtual meetings of the county Board of Commissioners during the outage.

On November 17, the county tweeted: “The Managed.com outage is still affecting our main public website. Internal county systems and data are not affected. Key online services remain available at jacksoncounty.org. No ETA yet to restore full public website. Thanks for your patience.”

The attack on their service provider couldn’t have come at a worse time for Jackson County. In addition to dealing with a rise in the number of coronavirus cases, the county is also taking the lead on recovery efforts related to what has been one of the most destructive seasons in Oregon’s wildfire history. 

Earlier this week, Oregon announced free programs to clear hazardous fire-related debris from residential and business properties, then remove any remaining ash, rubble, burned vehicles, damaged trees, and debris.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hard Rock Stadium Ups Cybersecurity

Hard Rock Stadium Ups Cybersecurity

The critical infrastructure of a famous Florida sporting and entertainment venue is being protected by a brand-new cybersecurity solution.

Atos and Forescout Technologies today announced a jointly developed solution that allows Miami Gardens’ Hard Rock Stadium to offer fans, staff, and spectators a whole new level of cybersecurity.

The joint solution of Forescout’s cloud-based network segmentation solution eyeSegment and Atos’ managed security services used more than 20 real-time monitoring techniques to protect over 7,100 IT, Internet of Things (IoT), and operational technology (OT) devices, including point-of-sale terminals, scoreboards, televisions, visual broadcasting equipment, field microphones, and servers connecting to the network.

It was successfully implemented for the first time over a two-week period in February 2020 to secure and manage the venue’s critical infrastructure for Super Bowl LIV.

“The security of our fans and their physical and online environments is of the utmost importance to us. While more than 65,000 fans are excited for touchdowns, most are unaware thousands of technology devices in our stadium’s infrastructure must be protected from malicious intent by threat actors,” said Kim Rometo, vice president and chief information officer, Miami Dolphins and Hard Rock Stadium. 

“With Atos and Forescout we recognized an opportunity to secure Hard Rock Stadium in new and critical ways, effectively creating a defense strategy that protects our operational and informational technology.”

Deploying the new solution has allowed its creators to flag more than 600 security events and secure 400 new OT devices connected to the network for the venue’s halftime show. Furthermore, it has allowed over 1,200 point-of-sales devices to be monitored for malicious patterns.

“Stadiums present unique challenges for CIOs as they create strategies to secure their dynamic and highly connected infrastructure,” said Jon Connet, general manager of Network Segmentation at Forescout Technologies. 

“Working with Atos, we provide complete device visibility and network segmentation that together help reduce the attack surface and protect Hard Rock Stadium from today’s cybersecurity threats.”

Karan Chetal, vice president of strategic engagements at Atos, said venues like Hard Rock Stadium were at increasing risk from bad actors. 

She said: “Cyberattacks continue to get more aggressive and the sporting and entertainment industry is a major target for these malicious threats.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#DxPsummit: CISOs Discuss Ransomware Strategies for Recovery and Resistance

#DxPsummit: CISOs Discuss Ransomware Strategies for Recovery and Resistance

Speaking as part of Druva’s Cloud Data Protection Summit, panel moderator and Druva CISO Drew Daniels focused on the theme of cyber-resiliency, specifically on the subject of ransomware and what the role of data protection is in combatting the threat.

Asking the speakers for their perspectives on ransomware detection and recovery, Mike Towers, CISO at Takeda Pharmaceuticals, said he follows a six-point plan of:

  • Risk ranking to be in focus on what cannot go down
  • Have resiliency and test resources
  • Use modern endpoint security and make sure to log everything so you can identify patient zero
  • Maximize threat intelligence feeds
  • Make sure you have targeted visibility
  • Help others in your provider space

Dave Estlick, vice-president and CISO at Chipotle, said another element is how you bring the threat intelligence in and “make it real as a tool for your organization.” He said this can prepare the staff before ransomware hits their vertical, and if people have seen the issue and are trained, they are less likely to fall for the campaign.

Daniels said it is important to be prepared to fail, as actors will try to exploit companies, and it is worth preparing for this. Marshall O’Keefe, corporate technology leader at HED, was asked how data protection can aid ransomware recovery, and he said that there are different systems used for backing up to recover the environment and core systems.

Shaun Marion, CISO at Republic Services, explained that data protection is central, as the attacker is after data no matter whom they are. “I don’t have unlimited funds, so we have got to get hyper focused on how we use those funds and understand where the critical data is, and use the same controls,” he said.

“Some systems are so critical that downtime is unacceptable, and you apply different controls. So from a data protection point of view, if we’re talking about ransomware, it is the same thing – how do I protect that data, as once it is encrypted, do I care? Applying controls is key.”

Jason Lee, CISO at Zoom, said adding protections is vital, and during the pandemic, the CISO has had a larger role as the business needs to know where those assets are and what the backup strategy is. Daniels agreed, saying the CISO is the firefighter, and “often called into action when it is an emergency.”

Asked by Daniels how other ransomware incidents impact a strategy, Lee said he was definitely aware of other incidents, and the issue “is growing and growing and you need to have this challenge as part of your cyber-strategy.” He raised the issue of zero-trust, which should now include all users and endpoints, and not just the firewalls as part of the perimeter.

“Preparedness is key here, so make sure you’re educating your users, and one thing I find [beneficial] now is making sure users are diligent when working from home, as it is easy to let your guard down but phishing emails and ransomware are increasing.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Raytheon Employee Jailed for Exporting Missile Data to China

Raytheon Employee Jailed for Exporting Missile Data to China

A former Raytheon employee has been imprisoned in the United States for exporting sensitive military data from America to the People’s Republic of China. 

Chinese national Wei Sun was employed in Tucson, Arizona, as an electrical engineer with Raytheon Missiles and Defense for 10 years. In February 2020, the 49-year-old pled guilty to violating the Arms Export Control Act (AECA) by taking a company-issued laptop containing sensitive information to China during a vacation.  

Raytheon Missiles and Defense, one of four business segments of American multinational Raytheon Technologies, develops and produces missile systems for use by the United States military.

During his 10-year tenure with the company, naturalized United States citizen Sun had access to information directly related to defense-related technology. 

“Some of this defense technical information constituted what is defined as ‘defense articles,’ which are controlled and prohibited from export without a license under the AECA and the International Traffic in Arms Regulations (the ITAR),” said the US Department of Justice. 

Sun took a personal trip to the PRC in December 2018, returning to the United States in January 2019. On that winter holiday, Sun brought unclassified technical information in his computer, including data associated with an advanced missile guidance system that was controlled and regulated under the AECA and the ITAR. 

“Despite having been trained to handle these materials correctly, Sun knowingly transported the information to China without an export license in violation of the AECA and the ITAR,” said the DOJ. 

The assistant director of the FBI’s Counterintelligence Division, Alan Kohler, Jr., said Sun’s transportation of sensitive military data to China was no accident. 

“This isn’t about a laptop mistakenly taken on a trip, this was the illegal export of US missile technology to China,” said Kohler.

“The FBI will continue to partner with companies to protect their information and our national security while bringing criminals such as Wei Sun to justice.”

On November 18, District Court Judge Rosemary Marquez sentenced the former engineer to 38 months in prison.

“Sun was a highly skilled engineer entrusted with sensitive missile technology that he knew he could not legally transfer to hostile hands,” said Assistant Attorney General John Demers.

“Today’s sentence should stand as a warning to others who might be tempted similarly to put the nation’s security at risk.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

HMRC Records 73% Growth in Email Phishing Attacks During #COVID19

HMRC Records 73% Growth in Email Phishing Attacks During #COVID19

The UK’s HMRC detected a 73% rise in email phishing attacks in the six months that the COVID-19 pandemic struck the country, according to official data obtained following a FOI request by accountancy firm Lanop Outsourcing.

It revealed that from March to September 2020, there was an average of 45,046 email attacks per month in the UK. This compares to an average of 26,100 in the two months preceding the introduction of COVID-19 lockdown measures, in January and February. In total, HMRC revealed it had received 367,520 reports of phishing email attacks during 2020 up to September.

During the six months since the start of lockdown, September had the largest monthly quantity, at 57,801 cases, while August experienced the lowest, at 38,096.

Additionally, HMRC reported 199,621 cases of phone scams and 58,921 SMS referrals during this period. Interestingly, phone and text scams were at their lowest point in the first full month of lockdown, in April, with 425 and 2515 cases reported, respectively. This could be due to cyber-criminals focusing on email phishing attacks to take advantage of the shift to home working at this time.

Phone and SMS scams began to grow again when lockdown restrictions were first lifted in the UK in June, with phone scams steadily rising to reach a peak of 46,015 in September.

Steve Peake, UK systems engineer manager, Barracuda Networks, commented: “Interestingly, Barracuda’s own data recently unveiled a similar pattern of cyber-attacks facing regular businesses, with our researchers observing a 667% spike in spear-phishing attacks from February to March, as a direct result of coronavirus. Similarly, other sectors, such as education, have also observed an upward trend of COVID-19 related phishing attacks during our battle against the virus.

“As the pandemic continues, businesses must anticipate COVID-19 themed attacks to increase in quantity. It’s also worth noting that cyber-attacks and scams aren’t just contained to email messages, SMS-based phishing attacks, or ‘Smishing,’ and fraudulent phone calls also pose a serious threat to consumers, workers and the general public.”

Mohammad Sohaib, director at Lanop Outsourcing, added: “Cyber-criminals have not missed a trick when it comes to using the devastating coronavirus to lure unknowing victims into leaking their own private information, such as passwords and payment details, via a phishing scam.

“In one such example, scammers impersonated HMRC to trick business owners into believing that their VAT deferral application, a key government support initiative during the pandemic, had been rejected. They would then redirect victims to a website with official HMRC branding, before stealing credit card details.”

Last month it was revealed that HMRC recorded 521,582 malicious emails between June and September.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UN and Europol Warn of Growing AI Cyber-Threat

UN and Europol Warn of Growing AI Cyber-Threat

Cyber-criminals are just getting started with their malicious targeting and abuse of artificial intelligence (AI), according to a new report from Europol and the UN.

Compiled with help from Trend Micro, the Malicious Uses and Abuses of Artificial Intelligence report predicts AI will in the future be used as both attack vector and attack surface.

In effect, that means cyber-criminals are looking for ways to use AI tools in attacks, but also methods via which to compromise or sabotage existing AI systems, like those used in image and voice recognition and malware detection.

The report warned that, while deepfakes are the most talked about malicious use of AI, there are many other use cases which could be under development.

These include machine learning or AI systems designed to produce highly convincing and customized social engineering content at scale, or perhaps to automatically identify the high-value systems and data in a compromised network that should be exfiltrated.

AI-supported ransomware attacks might feature intelligent targeting and evasion, and self-propagation at high speed to cripple victim networks before they’ve had a chance to react, the report argued.

By finding blind spots in detection methods, such algorithms can also highlight where attackers can hide safe from discovery.

“AI promises the world greater efficiency, automation and autonomy. At a time where the public is getting increasingly concerned about the possible misuse of AI, we have to be transparent about the threats, but also look into the potential benefits from AI technology.” said Edvardas Šileris, head of Europol’s Cybercrime Center.

“This report will help us not only to anticipate possible malicious uses and abuses of AI, but also to prevent and mitigate those threats proactively. This is how we can unlock the potential AI holds and benefit from the positive use of AI systems.”

To that end, the paper highlights multiple areas where industry and law enforcement can come together to pre-empt the risks highlighted earlier. These include the development of AI as a crime-fighting tool and new ways to build resilience into existing AI systems to mitigate the threat of sabotage.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

MoD Receives Funding Boost and Confirms Increase in Cyber-Spending

MoD Receives Funding Boost and Confirms Increase in Cyber-Spending

The UK government has dedicated an extra £16.5bn to defense spending which will see a heavy investment in cybersecurity defense and offensive capabilities.

The Ministry of Defence has been given a four-year funding settlement, which includes a 10% increase in its annual £40bn budget – despite other government departments having a single-year settlement due to the COVID-19 impact.

According to BBC News, Prime Minister Boris Johnson said on Wednesday evening that he was making the announcement “in the teeth” of the pandemic because “the defense of the realm must come first.”

Speaking to BBC Radio 4’s The Today Show, defense minister Ben Wallace said there was a need to modernize and invest in defending new domains that pose a threat to our way of life. This includes cyber “as our adversaries are investing heavily and [they] are using what we would call the sub threshold to constantly attack us, and we need to make sure we defend against that.”

Also, £1.5bn of the budget will go on creating a national cyber-force and will provide the option “to launch offensive cyber-weapons against our adversaries, or against other areas that currently pose a threat.” Wallace said this would give the opportunity to attack a server being used by an attacker as an example, as some adversaries are foreign states.

“We have to be mindful that the power of cyber can cause real problems, so we need the ability to strike back if we need to,” he said. “We also need the ability to tackle the non-state threats.” He explained his will include taking down servers being used to host child abuse images.

Plans for the National Cyber Force were announced in 2018. It will bring together offensive operations, combine contractors, GCHQ spies and military personnel in a force of up to 2000 online experts, and will be operated by the MoD and GCHQ.

Commenting, Francis Gaffney, director of threat intelligence and response at Mimecast, said: “It is really positive to see the UK government acknowledging cybersecurity as a significant enough concern to continue with these large investments in its cyber-activity.

“At Mimecast, our latest threat report observed a total number of 163.92 million attacks in the last month, taking the total number of attacks in 2020 past the one billion mark. This is almost certainly a result of the pandemic and many UK organizations working remotely in such a volume for the first time, leaving many of them potentially more vulnerable to cyber-attacks.

“This initiative will also have a positive impact on the overall cyber-hygiene level of citizens and organizations of the UK, as it further elevates the cybersecurity threat and keeps it at the forefront of the thoughts of the British public. I definitely welcome the continued interest and funding of the UK’s cyber-defenses. Long may it continue.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Researcher Drops Gender Discrimination Lawsuit Against Microsoft

Researcher Drops Gender Discrimination Lawsuit Against Microsoft

Computer researcher Katie Moussouris has dropped her gender discrimination lawsuit against tech giant Microsoft.

Issued in 2015, the lawsuit claimed that Microsoft unfairly discriminated against Moussouris (who worked at the company between 2007 and 2016) and other female employees because of their gender. It claimed that female workers were passed over for promotions, while less qualified male colleagues were promoted.

“I have dropped my lawsuit because my funds are better put towards solutions that help to implement both real change and demonstrate strong commitment to pay equity in our lifetime for women around the world, leaving behind organizations like Microsoft that pantomime pay equity, while resisting any real commitment to change,” Moussouris wrote in a blog post published on November 18 2020.

Moussouris went on to explain that, in dropping her case, she did not sign a non-disclosure agreement or receive a payment of any type.

“I’m free to focus on pay inequity without any limitations, using both my voice and my hard-earned assets to put a spotlight on companies like Microsoft, who are on the wrong side of history. These companies will be remembered for their resistance to change as the rest of the modern world takes decisive action towards pay equity in our lifetime.”

She urged organizations to support the Pay Equity Now Pledge (which she founded), as well as to make real pay, bonus, hiring, assignment and promotion rate changes that truly put all genders on equal footing as human beings.

“The legal system failed me and many other women to help us hold Microsoft and other companies accountable for gender discrimination that manifested in pay inequity over many years. I refuse to stop fighting for pay equity for women and racial minorities, and I have found a way forward regardless of Microsoft’s resistance to positive change.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Publicly Available Exploit Code Gives Attackers 47-Day Head Start

Publicly Available Exploit Code Gives Attackers 47-Day Head Start

When exploit code is released into the wild, it gives attackers a 47-day head start on their targets, new research has warned.

Kenna Security teamed up with the Cyentia Institute to analyze 473 vulnerabilities from 2019 where there was some evidence of exploitation in the wild.

Over the succeeding 15 months, the team noted when a vulnerability was discovered, when a CVE was reserved, when a CVE was published, when a patch was released, when the bug was first detected by vulnerability scanners and when it was exploited in the wild.

It claimed that exploit code is released into the wild in around one in four (24%) cases and the majority (70%) of exploited CVEs are likely to have been predated by publicly available exploit code.

There is therefore strong evidence that “early disclosure of exploit code gives attackers a leg up,” argued Kenna Security CTO, Ed Bellis.

However, things are a little more complicated than that, he added.

“At the same time, when exploits are released before patches, it takes security teams more time to address the problem, even after the patch is released,” Bellis explained. “That’s an indication that exploit code availability is not the motivator that some would suggest it is.”

Early disclosure may also actually help the white hat community by providing the code from which IDS and IPS systems can derive signatures. It could also push software developers to produce patches more quickly, and organizations to patch once one becomes available.

The good news is that responsible disclosure processes appear to be working quite well. Around 60% of vulnerabilities have a patch before a CVE is officially published, rising to over 80% within just a few days following the publication of a CVE.

However, once again, this doesn’t tell the whole story.

“Just because a patch is released, it doesn’t mean it will get used. Companies have a backlog of open vulnerabilities,” explained Bellis.

“Conversely, just because an exploit is available, that doesn’t mean attackers will use it. So, there are periods of time when attackers are able to deploy more attacks than defenders can patch, and there are times when defenders have momentum.”

Unfortunately, at present, attackers have momentum 60% of the time, according to the research.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk