ICO Slaps £250,000 Fine on Another Nuisance Call Company

ICO Slaps £250,000 Fine on Another Nuisance Call Company

The Information Commissioner’s Office (ICO) has fined yet another company for making nuisance calls, as doubts grow over the regulator’s ability to actually collect the money owed to it.

Over a six-month period from the beginning of 2019, Bury-based Reliance Advisory Limited (RAL) made over 15 million calls to individuals who had not requested them. They included mis-sold PPI and other claims management issues.

Scores of victims complained to the ICO, many of them having been called several times a day by the company. Some noted that RAL staff were rude and aggressive on the phone.

Unsolicited calls for marketing purposes have been banned for over two years under the Privacy and Electronic Communications Regulations 2003. However, RAL told the ICO it was unaware of its legal responsibilities.

As a result of this, and its inability to provide evidence of consent for the majority of calls it made, the firm was fined £250,000.

Andy Curry, head of investigations at the ICO, encouraged members of the public to report nuisance calls like these, as well as unsolicited texts and emails, to the regulator.

“Nuisance calls continue to be a matter of great distress, annoyance and significant concern for the public and we will continue to find and take action against the worst offenders,” he said.

“The law exists for a reason, and that is to protect people from this high degree of intrusion into their private lives. Businesses must respect the law and the onus is on them to be aware of their responsibilities. Pleading ignorance of the rules, as was put forward in this case, will never be a valid argument.”

However, as reported by Infosecurity yesterday, there are increasing concerns that the ICO is failing to hold such companies to account. A Freedom of Information (FOI) request revealed that since 2015, £6.6m, or over 39% of total fines, are still outstanding.

Of the 21 fines handed out between Jan 2019 and August 2020, only nine have been paid, meaning that 68% of their monetary value remains outstanding. Just 13% of fines related to nuisance calls have been collected.

Experts argue that it’s still too easy for company directors to find ways to avoid paying, such as by declaring bankruptcy.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Number of “Breached” Records Hits 36 Billion in 2020

Number of “Breached” Records Hits 36 Billion in 2020

The number of publicly reported data breaches fell in the third quarter of 2020, but billions more records were exposed globally to bring the total this year to 36 billion, according to Risk Based Security.

The security vendor’s 2020 Q3 Data Breach QuickView Report was compiled from human and automated analysis of publicly available reports, FOI requests and news reports.

It claimed 2020 was already the worst year ever recorded, even before the extra 8.3 billion records that were exposed in Q3. However, these figures include not only stolen data but also cloud-based misconfigurations that may imperil information but not result in a malicious actor getting hold of it.

The number of data breach reports in the first three quarters of the year dropped 51% year-on-year to 2953.

The vendor’s executive vice-president, Inga Goddijn, argued that this could be explained by the rise in ransomware attacks. Although these accounted for 21% of reported breaches in the first three quarters, it may be that many more are not being recorded.

“While many of these attacks are now clearly breach events, the nature of the data compromised can give some victim organizations a reprieve from reporting the incident to regulators and the public,” she argued.

“After all, while the compromised data may be sensitive to the target organization, unless it contains a sufficient amount of personal data to trigger a notification obligation, the event can go unreported.”

Elsewhere in the report, healthcare was the sector most affected by breach incidents, accounting for 11.5% of events.

Interestingly, two breaches in Q3 exposed over one billion records each and four breaches exposed over 100 million records. So these six breaches cumulatively accounted for around eight billion exposed records, or over 22% of the total.

The findings chime somewhat with those of the Identity Theft Resource Center, which records publicly reported breaches in the US. It said recently that the volume of those incidents is on track for its lowest figure since 2015.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Scammers Spoof MAGA Hat Vendors to Steal $2.3m from Republicans

Scammers Spoof MAGA Hat Vendors to Steal $2.3m from Republicans

The Wisconsin Republican Party (WisGOP) has been left red-faced after a suspected Business Email Compromise (BEC) attack stole millions of dollars intended to support Donald Trump’s re-election bid.

The party issued a statement on Thursday revealing that it discovered a phishing attack a week previously, on October 22, and promptly notified the FBI.

According to the statement, attackers had forged invoices and sent them to the party under the names of legitimate WisGOP vendors.

This sounds like a classic BEC attack, in which cyber-criminals hijack a target’s inbox via phishing to monitor emails sent back and forth with vendors. They’re then able to spoof those vendors, sending invoices to the targeted organization with their own bank details at the bottom.

“Cyber-criminals, using a sophisticated phishing attack, stole funds intended for the re-election of President Trump, altered invoices and committed wire fraud. These criminals exhibited a level of familiarity with state party operations at the end of the campaign to commit this crime,” said state party chairman, Andrew Hitt.

“While a large sum of money was stolen, our operation is running at full capacity with all the resources deployed to ensure President Donald Trump carries Wisconsin on November 3.”

The attack has extra significance given that Wisconsin is a key swing state which Trump won by only around 20,000 votes last time, so every last penny will be needed as both parties step up their campaigning.

According to reports, the vendors in question sold the party pro-Trump hats and other items to be handed out at rallies, as well as direct mail services.

DomainTools senior security advisor, Chad Anderson, explained that BEC is on the rise.

“Cyber-criminals appear to be discovering the reality that as opposed to engaging with ‘wide-net’ phishing campaigns, they can save time and energy in researching one individual within a business and sending them a targeted email,” he continued.

“Sites such as LinkedIn make this incredibly easy to achieve, allowing a threat actor to research members of staff in an organization with a few clicks. In order to avoid the exponential growth of these scams continuing, businesses need to engage in robust training and awareness campaigns with staff, as well as investing in an email filtering system which is regularly audited and updated.”

BEC was responsible for over half of all cybercrime losses reported to the FBI last year, standing at nearly $1.8bn.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

BEC Attacks Targeting Energy and Infrastructure Rise by 93%

BEC Attacks Targeting Energy and Infrastructure Rise by 93%

Business email compromise attacks (BEC) have continued to grow in Q3 of 2020, rising by 15% overall compared to Q2, according to Abnormal Security’s Quarterly BEC Report.

The average weekly volume of BEC attacks increased quarter-by-quarter in six out of eight industries, with the biggest rise observed in the energy/infrastructure sector, at 93%. The industries which had the highest number of weekly BEC attacks were retail/consumer goods and manufacturing and technology, which were tied for the volume of campaigns received per 1000 emails.

Cyber-criminals had a particularly strong focus on BEC campaigns that had a goal of invoice and payment fraud in this period, with a 155% increase from Q2 to Q3 recorded. A corresponding decline in social engineering BEC attacks aiming to impersonate internal employees and VIPs or external partners was also seen.

In regard to the types of employees targeted, Abnormal Security reported that attacks on C-suite executives stayed flat compared to Q2, while campaigns targeting employees in finance departments fell by 53%. However, email attacks to group mailboxes surged by 212%, denoting a shift in tactics.

Credential-phishing COVID-19 related attacks declined 82% quarter-by-quarter, although invoice and payment fraud that leveraged the fear, uncertainty and doubt of the pandemic increased by 81%.

Evan Reiser, CEO of Abnormal Security, commented: “As the industry’s only measure of BEC attack volume by industry, our quarterly BEC research is important for CISOs to prepare and stay ahead of attackers. Not only are BEC campaigns continuing to increase overall, they are rising in 75% of industries that we track. Since these attacks are targeted and sophisticated, these increases could indicate an ability for threat actors to scale that may overwhelm some businesses.”

In the report Abnormal Security added: “It’s important to note that the highest rates of invoice and payment fraud BEC attacks targeting employees in finance observed thus far by Abnormal occurred during Q4 2019. This may indicate a seasonality to these types of attacks. If this is the case, we should see a significant spike in such attacks in Q4 of this year.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US: Collaboration Needed to Combat Online Child Exploitation

US: Collaboration Needed to Combat Online Child Exploitation

United States Assistant Attorney General Beth Williams has called for people to come together to protect children from being exploited. 

Speaking yesterday at a Columbia Law School virtual event, Williams said: “Addressing the problem of online child exploitation requires that all of civil society work collaboratively—including law enforcement, non-governmental organizations, private industry, and individual citizens.”

Williams warned that abuse carried out in one sphere may result in further abuse occurring in another. 

“Exploitation and abuse that begins online in the virtual world often leads to abuse in the real world. In an all-too-common scenario, a predator can use social media to make contact with a child, spend time grooming her to build trust, and then attempt to meet in person to engage in abuse,” said Williams.

She added that sextortion cases, in which predators use social media and other platforms to coerce victims into sharing explicit images of themselves, and then blackmail the victims into paying money, producing more explicit content, or engaging in sexual acts, are on the rise and “occurring in our communities throughout the country on a daily basis.”

Last year, the National Center for Missing & Exploited Children (NCMEC) received 16.9 million reports of suspected abuse that included over 69 million photos, videos, and other files related to child sexual exploitation, said Williams. 

She added that by causing children to become familiar with webcams and spend more time online, often unsupervised, COVID-19 “is making an ongoing crisis worse.”

“We are fortunate to have advanced technology that provides us the means to stay connected,” said Williams. “However, that same technology also provides predators with pathways into our homes that can be used to target children for sexual exploitation.”

Williams then spoke in opposition to the deployment of end-to-end encryption technology in everyday consumer devices and software, arguing that it will make child exploitation harder to detect and report.

“This has real-life consequences,” said Williams. “Law enforcement will be less able to act in thousands of cases where they might have otherwise been able to stop the spread of child sexual abuse material, arrest a predator, or rescue a child from abuse.”        

The NCMEC has received over 65 million cyber-tips relating to online child exploitation. The organization estimates that more than half of its CyberTipline reports will vanish with end-to-end encryption.  

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Triple Data Breach Earns Insurer $1m Fine

Triple Data Breach Earns Insurer $1m Fine

An American insurance company has been fined $1m over three data breaches that occurred over a six-month period in 2017.

Aetna agreed to the fine and to the adoption of a corrective action plan to settle potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules. The payment will go to the Office for Civil Rights (OCR) at the US Department of Health and Human Services (HHS).

On April 27, 2017, Aetna discovered that two web services used to display plan-related documents to health plan members had allowed documents to be accessible without login credentials. As a result of this breach, the sensitive data of 5,002 individuals was exposed.

Protected health information (PHI) disclosed in the incident included names, insurance identification numbers, claim payment amounts, procedure service codes, and dates of service.

Aetna experienced a second data breach on July 28, 2017, when benefit notices mailed out to members in window envelopes displayed the words “HIV medication” next to the member’s name and address. A breach report submitted to OCR in August stated that 11,887 individuals were affected by this disclosure.

The third 2017 breach that hit Aetna happened on September 25, when a research study mailing sent to members displayed the name and logo of the atrial fibrillation (irregular heartbeat) research study in which they were participating on the envelope. Aetna reported in November 2017 that 1,600 individuals were affected by this breach.

OCR’s investigation into the breaches found that in addition to the impermissible disclosures, Aetna “failed to perform periodic technical and nontechnical evaluations of operational changes affecting the security of their electronic PHI.”

“Unfortunately, on numerous occasions where it would have cost the organization several thousands of dollars for technology or training, the decision was made not to purchase the product or service,” James McQuiggan, security awareness advocate at KnowBe4, told Infosecurity Magazine.

“These decisions come back around later after a data breach that costs millions in lost productivity, revenue, and fines. Organizations need to have a robust security awareness training program to help employees make smarter security decisions to protect an organization from various attacks.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Taiwanese Company Admits Stealing US Trade Secrets

Taiwanese Company Admits Stealing US Trade Secrets

A company in Taiwan has been fined $60m after pleading guilty to stealing trade secrets from an American semiconductor company.

United Microelectronics Corporation (UMC), a semiconductor foundry based in Hsinchu that turned 40 this year, admitted to swiping secrets from Micron Technology, a leading producer of computer memory and computer data storage that is headquartered in Boise, Idaho.

UMC was indicted by a United States federal grand jury in September 2018 for conspiracy to steal, convey, and possess trade secrets stolen from Micron for the benefit of the Fujian Jinhua Integrated Circuit Company. 

Fujian, a state-owned enterprise of the People’s Republic of China, was also indicted on the same charges, along with three individuals UMC says it hired from Micron’s Taiwan subsidiary. The company denies any wrongdoing.

Yesterday the United States Justice Department announced that UMC had admitted stealing the secrets and had agreed to cooperate with the US government in the investigation and prosecution of its Chinese co-defendant.

In a statement released on October 28, the Department of Justice said: “As a result of today’s guilty plea, and in accordance with an accompanying plea agreement, UMC, whose American Depository Receipts are publicly traded on the New York Stock Exchange, will pay the fine—the second largest ever in a criminal trade secret prosecution, be subject to a three-year term of probation, and cooperate with the United States.”

Under the plea agreement, UMC pleaded guilty to one count of criminal trade secret theft. Other criminal charges and a parallel civil suit by the United States against the Taiwanese company will be dismissed. 

The criminal prosecution of Fujian and the three individual defendants will continue, with a trial US Attorney David Anderson deemed likely to occur next year.

Continuing also is a civil action that seeks to prohibit Fujian from the further transfer of stolen trade secrets and from the export to the United States of products manufactured by the PRC-owned company using trade secrets stolen from Micron.

“UMC stole the trade secrets of an American leader in computer memory to enable China to achieve a strategic priority: self-sufficiency in computer memory production without spending its own time or money to earn it,” said Deputy Attorney General Jeffrey Rosen.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Education Sector Facing Disproportionate Level of Spear-Phishing Attacks

Education Sector Facing Disproportionate Level of Spear-Phishing Attacks

Educational institutions are being disproportionately targeted by spear-phishing attacks, according to a new study by Barracuda Networks.

The security firm’s latest Threat Spotlight analysis found that in the period from June to September 2020, over 1000 schools, colleges and universities faced more than 3.5 million spear-phishing attacks.

More than a quarter of these were business email compromise (BEC) attacks, a method which is over twice as likely to be used against educational institutions compared with an average organization across all sectors.

More than four in 10 (41%) of all attacks targeting education were spear-phishing, according to the analysis, with 28% scamming attempts and 3% related to extortion.

Spear-phishing attacks dropped off in July and August when schools were closed, and were at their highest in June and September: 11% and 13% higher than average, respectively.

Cyber-criminals increasingly used the topic of COVID-19 as a lure for these phishing attacks, with subject headings including ‘COVID19 NEW UPDATES’; ‘Covid-19 Update Follow Up Right Now’; ‘COVID-19 SCHOOL MEETING’ and ‘Re: Stay Safe’.

Barracuda also highlighted examples the potentially devastating costs of these types of attacks, including the Manor Independent School District in Texas reporting that a seemingly normal school-vendor transaction resulted in a loss of $2.3 million.

Michael Flouton, VP email protection for Barracuda Networks, commented: “Cyber-attackers have come to understand that education institutions don’t often have the same level of security sophistication as in other organizations, and therefore, they will send carefully crafted email messages designed to trick unknowing and untrained victims into leaking personal or confidential information, such as login credentials, student records, or payment information.

“In light of COVID-19 and the transition to remote learning environments, the quantity of data stored on school and university servers has surged, and thus, so too has the quantity of cyber-attacks facing them.

“Therefore, schools and universities must combat this threat by investing in email security that leverages artificial intelligence to help identify unusual senders, intercept suspicious requests and block spear-phishing attacks. Additionally, account takeover protection, security awareness education for staff and students, and a reconstruction of internal policies, are all imperative to preventing human error from leading to costly mistakes in the future.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Employee Awareness Recognized as Biggest Lockdown Security Failing

Employee Awareness Recognized as Biggest Lockdown Security Failing

Employee awareness is seen as the biggest area of weakness for firms’ cybersecurity strategies over the past few months of mass remote working during COVID-19, according to a new study.

Secure storage firm Apricorn received over 23,500 responses from a poll of its Twitter followers in October exploring business preparedness during the pandemic.

Over 30% said that employee education was the area most in need of improvement at their organization. Home workers may be more distracted than they would otherwise be in the office, IT support feels more remote and devices or PCs may be less well secured, presenting increased cyber-risk to organizations.

New Mimecast research out this week revealed that nearly half (45%) of remote workers open emails they consider to be suspicious while 73% use their corporate devices for personal matters, potentially exposing it to cyber-threats.

“IT and security teams had to scramble to respond to this crisis and in doing so, left a lot of companies wide open to breach. Nine months into employees working remotely, some know already that they have been attacked. Others think they may have been but can’t be sure,” argued Apricorn’s EMEA managing director, Jon Fielding.

“In the same way that we had to learn how to protect ourselves from illness and modify our behavior, we had to also learn how to protect our data outside of the firewall and more importantly, to remain vigilant about it.”  

However, improving staff security awareness and education may not be that easy.

Trend Micro research from earlier this year revealed that remote workers continue with their bad habits whilst claiming that: they feel more conscious of their organization’s cybersecurity policies (72% ) since lockdown began; they take IT instructions seriously now (85%); and that cybersecurity is partly their responsibility (81%).

According to Apricorn, 40% of employees felt that they were not fully prepared to work at home securely and productively, with 18% claiming they lacked the right technology and 16% saying they were not sure how to. A fifth (20%) said they were still not able to work remotely. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk