Credential Stuffers Scaled The North Face to Access Accounts

Credential Stuffers Scaled The North Face to Access Accounts

Outdoor clothing giant The North Face has notified customers that it has been hit by a credential stuffing attack which may have given third parties access to their personal information.

In a data breach notice filed with the Californian Office of the Attorney General (OAG), the San Francisco-headquartered firm claimed that the brute force attack had been launched against its site on October 8-9.

A credential stuffing attack occurs when cyber-criminals use automated software to try previously breached log-ins across a large range of sites: they’ll be able to access accounts where the individual has reused their password.

Fortunately, The North Face uses tokenization to obfuscate customer card details, but customers’ personal information  may have been accessed in the incident.

“Based on our investigation, we believe that the attacker obtained your email address and password from another source and may have accessed the information stored on your account at thenorthface.com, including products you have purchased on our website, products you have saved to your ‘favorites,’ your billing address, your shipping address(es), your VIPeak customer loyalty point total, your email preferences, your first and last name, your birthday (if you saved it to your account), and your telephone number (if you saved it to your account),” the noticed read.

As a precaution, the firm deleted all payment card tokens on the site, limited logins from suspicious sources and disabled all passwords from accounts compromised in the attack. Affected customers will need to create new passwords and re-enter payment card details, it said.

“We strongly encourage you not to use the same password for your account at thenorthface.com that you use on other websites, because if one of those other websites is breached, your email address and password could be used to access your account at thenorthface.com,” the notice continued.

“In addition, we recommend avoiding using easy-to-guess passwords. You should also be on alert for schemes, known as phishing attacks, where malicious actors may pretend to represent The North Face or other organizations, and you should not provide your personal information in response to any electronic communications regarding a cybersecurity incident.”

Retail accounted for over 90% of the 64 billion credential stuffing attempts detected by Akamai over the period July 1 2018 to June 30 2020.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CISA’s Krebs Set to be Fired in Blow for Security Community

CISA’s Krebs Set to be Fired in Blow for Security Community

The head of the US Cybersecurity and Infrastructure Security Agency (CISA) expects to become the latest high-profile public servant fired by outgoing President Donald Trump, according to reports.

Christopher Krebs is a widely respected figure with support from both sides of the political divide, who has served as the Department of Homeland Security (DHS) agency’s first head since 2018.

However, three sources familiar with the matter told Reuters that he has already informed associates he expects to be fired. His assistant director, Bryan Ware, has already been asked to leave his position and handed his resignation in yesterday, according to reports.

There are suggestions that the Trump administration is displeased at CISA’s Rumor Control service, which was set-up to debunk mis- and disinformation about the integrity of the election result. Many of the rumors the site has dismissed are being actively peddled by Trump and his allies in the Republican party.

“Under Chris Krebs’ leadership, CISA has been a trusted source of election security information. If Donald Trump fires him, it will suggest Trump is preparing to spread lies about the election from a government agency,” warned Democrat senator, Ron Wyden.

Mark Warner, another Democrat senator, praised Krebs for his role in protecting the country’s elections from misinformation.  

“He is one of the few people in this administration respected by everyone on both sides of the aisle. There is no possible justification to remove him from office. None,” he tweeted.

The news comes on the back of multiple sackings by Trump of high-profile officials, including defense secretary Mark Esper. CIA director, Gina Haspel’s fate is also said to be in the balance. The unprecedented moves will make an orderly transition to the next administration that much harder.

Chloé Messdaghi, VP of strategy at Point3 Security, also had nothing but praise for Krebs.

“It is up to CISA to help America understand cybersecurity threats and misinformation. Christopher Krebs is utterly non-partisan and he deserves his CISA post in every way,” she argued.

“He has earned the nation’s trust and faith, and worked tirelessly to help secure the current election cycle. We owe him an enormous debt of gratitude.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Fraudulent Transactions a Bigger Worry for Online Retailers During #COVID19

Fraudulent Transactions a Bigger Worry for Online Retailers During #COVID19

Increased risk of fraudulent payment transactions has been one of the biggest concerns of online retailers this year, according to new research from payments platform Paysafe.

In the survey, which asked 1100 small and medium-sized businesses (SMBs) with an online presence about the effect of COVID-19 on their operations, 60% of online retailers said they feel consumers are more worried than ever about becoming a victim of fraud as a result of the crisis. More than three-quarters (76%) had noticed their customers had changed the way they are making payments, with 40% citing searching for a more secure payment as the reason for this.

In addition, Paysafe found that security remained the primary payment concern among SMBs for the third year running. Nearly half (45%) of respondents said it was in the top three most important factors to consider when evaluating a payments provider, ranking higher than reliability (36%), cost (34%) and ease of integration (22%).

Despite this, the majority (58%) admitted they had faced difficulties in achieving the right balance between improving security processes and creating a quick and simple customer journey. However, there appears to be a greater tolerance among consumers for more stringent security to be put in place, with Paysafe highlighting its research from April in which 51% of consumers said they would accept any security measure if it kept their data secure, however poor it made the user experience.

Danny Chazonoff, chief operating officer at Paysafe, commented: “Protecting ourselves from fraud has long been reported as a concern among businesses and consumers, but our research shows that security has become more of a priority than ever, and there are a few reasons for this. The economic impact of COVID-19 has led to a natural desire from both consumers and businesses to protect their finances. Coupled with that, we know that criminal activity such as fraud historically rises during national and global crises, and this pandemic has been no exception.”

There has been a huge shift to digital shopping during the pandemic, with many consumers forced to purchase items online for the first time due to lockdown restrictions. This has opened up new opportunities for fraudsters, particularly exploiting those unused to using the internet. For instance, the charity Age UK found that elderly people in the UK were scammed out of £2.4m in the period from March 23 to July 31 this year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ethical Hacker’s Comic Dream Gets Backing

Ethical Hacker’s Comic Dream Gets Backing

A Texas security professional’s dream of creating a comic book publishing company dedicated to titles about hacking is edging closer to reality.

Robert Willis started a campaign on Kickstarter to self-finance and create a new publishing company named Paraneon. The company will specialize in cyber-punk and sci-fi comics that are written by hackers and for hackers to inspire young people to pursue STEM careers. 

“Superheroes dominate the comic books, which I think is great, but I want to see more hacker and tech going on in this series,” said Willis. 

“I really want to inspire kids the same way I was inspired when I was younger.”

With just over two days to go to reach its modest $2,000 total, Willis’ idea has already received $6,324 in support from 100 backers. In return for funding the project, backers choose to receive the first titles to be published under Paraneon, collected together in a graphic novel called Initiating . . . Paraneon.

Those who pledge $200 or more to support the creation of the first three titles can opt to be drawn into one of the hacking comic titles, The Hive Network

“You will be drawn without clothing in a tank, but none of your goodies will be shown,” said Willis. 

The setting for the books—the Paraneon Universe—comprises technocentric cities, underground worker colonies, and apocalyptic “drylands.” In this reality, pollution and global warming have caused all factories and production to be moved to Mars, where more androids dwell than do humans.

“The initial books lay out the world, which is very technocentric,” Willis told Bleeding Cool. “The stories introduce characters and the scenery. Future books will expand on hacking scenarios from real-world hackers like myself.”

InfoSec professional and ethical hacker Willis, who wrote all of the titles himself, has hired artists all over the world to bring his vision of Paraneon to life. 

“I really want to raise money right now so I can bring in known people from the comic book industry,” said Willis, “known writers and known illustrators.”

If the project proves to be successful, Willis plans to use live action and animation to bring the Paraneon Universe to life in the future.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber-Mercenaries Sell Espionage Campaigns

Cyber-Mercenaries Sell Espionage Campaigns

Ransomware-as-a-Service (RaaS), dedicated phishing campaigns, and digital espionage can be bought on the cyber-criminal underground, according to new research by BlackBerry.

In a report published today, BlackBerry‘s Research and Intelligence team reveals the illegal activities of a cyber-espionage campaign they have been tracking for six months. 

The campaign, dubbed CostaRicto by researchers, is seemingly operated by a group of APT mercenaries called “hackers-for-hire” who operate bespoke malware tooling and complex VPN proxy and SSH tunneling capabilities.

Key findings of the report are that CostaRicto targets can be found the world over: in Europe, the Americas, Asia, Australia, and Africa. However, the majority of targets are concentrated in South Asia, particularly in India, Bangladesh, and Singapore.

Researchers say this data could suggest that the threat actor behind the campaign is based in that region but selling their illegal services on an international black market to the highest bidders. 

The command-and-control (C2) servers utilized by CostaRicto are managed via Tor and/or through a layer of proxies. The attacker practices “better-than-average operation security,” creating a complex network of SSH tunnels established in the victim’s environment. 

A strain of malware that hasn’t been seen before is used to create a backdoor in the victim’s network. Researchers described the malware as “a custom-built tool with a suggestive project name, well-structured code, and detailed versioning system.” 

Whoever created the backdoor project named it Sombra, a reference to a character in the video game Overwatch who specializes in intelligence assessment and espionage and is known for their hacking abilities. 

The malware appears to have been rolled out in October 2019, but version numbers suggest that the project is still in the debug testing phase. Researchers found indications that the operation may have been around even longer.

“The timestamps of payload stagers go back to 2017, which might suggest the operation itself has been going on for a while, but used to deliver a different payload,” said researchers.

An IP address to which the backdoor domains were registered overlaps with a pre-existing phishing campaign attributed to APT28. However, researchers believe it most unlikely that a direct link exists between CostaRicto and that particular advanced persistent threat group.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Most Americans Reuse Passwords for Work Devices

Most Americans Reuse Passwords for Work Devices

New research into the security behavior of employees in the United States has found that most Americans reuse passwords on work devices. 

A September 2020 survey of 500 full-time US employees by portfolio website Visual Objects found that 63% increased their vulnerability to cyber-attacks by recycling the same passwords for multiple accounts on work devices.

The majority of those surveyed (63%) said that they weren’t concerned about where they stored their personal data and were comfortable keeping it on their work devices. 

This could be because they see cybersecurity as something that their employer should take care of. Almost all (91%) said that they feel companies are more responsible for cybersecurity efforts than employees are. 

A Visual Objects spokesperson commented: “Most companies sent office devices home with employees during COVID-19, allowing workers to intermix work and personal data. Employees risk introducing malware onto work devices when using them for personal activities.”

The findings revealed a link between the age of the workers and their attitude to cybersecurity. While only 2% of baby boomers said that they always reuse work-related passwords, 13% of millennials confessed to always using duplicate passwords. 

More survey respondents in the baby boomer age group (27%) said that they were not concerned with where they stored their personal data than in any other age group. Only 17% of millennials felt very unconcerned about storing personal data on work devices.  

Christine Sabino, a senior associate at data breach claims company Hayes Connor, said that millennials have a natural inclination to keep personal and work information separate.

“[Millennials] have more technological devices, like a personal laptop, tablet, mobile phone, and games console,” Sabino said. “They are less likely to require the use of their work laptop for these [personal] activities.”

More than three-quarters of US workers (76%) said that they felt at least somewhat accountable for ensuring cybersecurity measures were followed at their company. 

“Employees have a responsibility to ensure guidelines and processes are followed,” commented Cyphere‘s Harman Singh. 

“Employees must take small actions that have a bigger impact on improving culture, such as appropriately reacting to suspicious emails, calls, or information online.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Recommendations Accepted in Boost for EU Data Transfers

Recommendations Accepted in Boost for EU Data Transfers

The European Data Protection Board (EDPB) has adopted recommendations on measures around transfer tools which aim to assist controllers and processors acting as data exporters.

During its 41st plenary session, the EDPB adopted recommendations which will essentially ensure a level of protection for data being transferred outside of Europe.

In doing so, the EDPB is seeking a consistent application of the GDPR and the court’s ruling across the EEA. 

EDPB chair Andrea Jelinek said: “The EDPB is acutely aware of the impact of the Schrems II ruling on thousands of EU businesses and the important responsibility it places on data exporters.

“The EDPB hopes that these recommendations can help data exporters with identifying and implementing effective supplementary measures where they are needed. Our goal is to enable lawful transfers of personal data to third countries while guaranteeing that the data transferred is afforded a level of protection essentially equivalent to that guaranteed within the EEA.”

Following the July determination that Privacy Shield was unlawful, this is one step closer to data transfers being compliant once again.

The recommendations contain a roadmap of the steps data exporters must take to find out if they need to put in place supplementary measures to be able to transfer data outside the EEA in accordance with EU law, and help them identify those that could be effective.

The EDPB said that “data exporters are responsible for making the concrete assessment in the context of the transfer, the third country law and the transfer tool they are relying on,” and “must proceed with due diligence and document their process thoroughly, as they will be held accountable to the decisions they take on that basis, in line with the GDPR principle of accountability.”

Jelinek said: “The implications of the Schrems II judgment extends to all transfers to third countries. Therefore, there are no quick fixes, nor a one-size-fits-all solution for all transfers, as this would be ignoring the wide diversity of situations data exporters face.

“Data exporters will need to evaluate their data processing operations and transfers and take effective measures bearing in mind the legal order of the third countries to which they transfer or intend to transfer data.”

Cordery partner Jonathan Armstrong told Infosecurity that this appears to be draft guidance, which may be welcomed “but as we know, the courts don’t have to follow guidance and we’ve seen in the past how they often don’t.”

He added: “There’s no 100% safe way of doing data transfers even if you follow guidance from the EDPB – companies will still have to do their own risk assessment which is effectively double due-diligence – (a) who am I transferring data to (and are they safe) and (b) where is the data going (and is that country safe or can I strap on additional measures to make it safe).”

Commenting, William Long, global co-leader of Sidley’s privacy and cybersecurity practice, and leader of the EU Data Protection practice, said the recommendations are welcome in this respect; however, they will need to be carefully reviewed by international companies to determine the kind of data transfer assessment they will need to carry out.

“In particular, the six steps require data mapping, identifying the GDPR data transfer mechanism, such as Standard Contractual Clauses (SCCs), and an assessment of the laws in the country outside of the EEA where the data is being transferred to (e.g. the US),” he said.

“Where the assessment reveals that the third country legislation impinges on the effectiveness of the data transfer mechanism (e.g. SCCs) then the recommendations set out a non-exhaustive list of supplementary measures to bring the level of protection of the data transferred to an EU standard of essential equivalence. The measures include a number of technical measures focusing on state-of the-art encryption and pseudonymization, so information security professionals may need to be closely involved in these assessments.”

Long said despite the recommendations being made, a further significant step forward would be for the European Commission and the US government to promptly negotiate a successor to the EU-US Privacy Shield program that directly addresses the CJEU’s concerns in Schrems II.

The six recommendations, as featured by Hogan Lovells, are as follows:

  • Step One: Identify international data transfers
  • Step Two: Identify data transfer mechanisms
  • Step Three: Assess the law in the third country
  • Step Four: Adopt supplementary measures
  • Step Five: Adopt necessary procedural steps
  • Step Six: Re-evaluate at appropriate intervals

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk