QAnon/8Chan Sites Briefly Knocked Offline

A phone call to an Internet provider in Oregon on Sunday evening was all it took to briefly sideline multiple websites related to 8chan/8kun — a controversial online image board linked to several mass shootings — and QAnon, the far-right conspiracy theory which holds that a cabal of Satanic pedophiles is running a global child sex-trafficking ring and plotting against President Donald Trump. Following a brief disruption, the sites have come back online with the help of an Internet company based in St. Petersburg, Russia.

The IP address range in the upper-right portion of this map of QAnon and 8kun-related sites — 203.28.246.0/24 — is assigned to VanwaTech and briefly went offline this evening. Source: twitter.com/Redrum_of_Crows.

A large number of 8kun and QAnon-related sites (see map above) are connected to the Web via a single Internet provider in Vancouver, Wash. called VanwaTech (a.k.a. “OrcaTech“). Previous appeals to VanwaTech to disconnect these sites have fallen on deaf ears, as the company’s owner Nick Lim reportedly has been working with 8kun’s administrators to keep the sites online in the name of protecting free speech.

But VanwaTech also had a single point of failure on its end: The swath of Internet addresses serving the various 8kun/QAnon sites were being protected from otherwise crippling and incessant distributed-denial-of-service (DDoS) attacks by Hillsboro, Ore. based CNServers LLC.

On Sunday evening, security researcher Ron Guilmette placed a phone call to CNServers’ owner, who professed to be shocked by revelations that his company was helping QAnon and 8kun keep the lights on.

Within minutes of that call, CNServers told its customer — Spartan Host Ltd., which is registered in Belfast, Northern Ireland — that it would no longer be providing DDoS protection for the set of 254 Internet addresses that Spartan Host was routing on behalf of VanwaTech.

Contacted by KrebsOnSecurity, the person who answered the phone at CNServers asked not to be named in this story for fear of possible reprisals from the 8kun/QAnon crowd. But they confirmed that CNServers had indeed terminated its service with Spartan Host. That person added they weren’t a fan of either 8kun or QAnon, and said they would not self-describe as a Trump supporter.

CNServers said that shortly after it withdrew its DDoS protection services, Spartan Host changed its settings so that VanwaTech’s Internet addresses were protected from attacks by ddos-guard[.]net, a company based in St. Petersburg, Russia.

Spartan Host’s founder, 25-year-old Ryan McCully, confirmed CNServers’ report. McCully declined to say for how long VanwaTech had been a customer, or whether Spartan Host had experienced any attacks as a result of CNServers’ action.

McCully said while he personally doesn’t subscribe to the beliefs espoused by QAnon or 8kun, he intends to keep VanwaTech as a customer going forward.

“We follow the ‘law of the land’ when deciding what we allow to be hosted with us, with some exceptions to things that may cause resource issues etc.,” McCully said in a conversation over instant message. “Just because we host something, it doesn’t say anything about we do and don’t support, our opinions don’t come into hosted content decisions.”

But according to Guilmette, Spartan Host’s relationship with VanwaTech wasn’t widely known previously because Spartan Host had set up what’s known as a “private peering” agreement with VanwaTech. That is to say, the two companies had a confidential business arrangement by which their mutual connections were not explicitly stated or obvious to other Internet providers on the global Internet.

Guilmette said private peering relationships often play a significant role in a good deal of behind-the-scenes-mischief when the parties involved do not want anyone else to know about their relationship.

“These arrangements are business agreements that are confidential between two parties, and no one knows about them, unless you start asking questions,” Guilmette said. “It certainly appears that a private peering arrangement was used in this instance in order to hide the direct involvement of Spartan Host in providing connectivity to VanwaTech and thus to 8kun. Perhaps Mr. McCully was not eager to have his involvement known.”

8chan, which rebranded last year as 8kun, has been linked to white supremacism, neo-Nazism, antisemitism, multiple mass shootings, and is known for hosting child pornography. After three mass shootings in 2019 revealed the perpetrators had spread their manifestos on 8chan and even streamed their killings live there, 8chan was ostracized by one Internet provider after another.

The FBI last year identified QAnon as a potential domestic terror threat, noting that some of its followers have been linked to violent incidents motivated by fringe beliefs.

Further reading:

What Is QAnon?

QAnon: A Timeline of Violent Linked to the Conspiracy Theory

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

DDoS Attacks Disrupt Massachusetts Schools

DDoS Attacks Disrupt Massachusetts Schools

Students learning remotely in Massachusetts have had their lessons disrupted by distributed-denial-of-service, or DDoS, attacks.

Sandwich Public Schools suffered a week of connection issues after what was first identified as a firewall failure occurred on October 8. A new firewall put in place to resolve the issue subsequently crashed, prompting the technology department to source a firewall from a different vendor. 

After further connectivity issues were experienced with the schools’ OpenCape Network despite the new firewall, the source of the problem was determined to be a DDoS attack. 

Superintendent Pamela Gould said the district has reported the attack to Sandwich police as well as to the FBI’s Cyber Crime Unit.

“This is not a capacity issue for the district,” wrote Gould in an email to parents. “This is something that is happening to us.”

Repeated internet outages have also been occurring this month at Tyngsboro’s high school and middle school, interrupting the district’s best efforts to deliver education remotely to their students.

Superintendent Dr. Michael Flanagan said the Tyngsboro district’s IT professionals and cybersecurity provider have determined that the outages were not caused by an internal hardware issue or an issue with the district’s internet provider, but instead were the result of a DDoS cyberattack, apparently from a device being brought into the Norris Road campus each morning,

“We are frustrated and disappointed that this outage has disrupted what has been a very successful and positive start to our school year here in Tyngsboro,” Flanagan said in a news release. 

“We have all pulled together and worked so hard to create a positive learning environment in spite of the challenges and disruptions of the COVID pandemic.”

Tyngsboro’s outage is currently under investigation by state education officials, an IT solutions company, and local police. It is not yet clear whether lessons were sabotaged deliberately or via a device that had been compromised unbeknownst to its owner.

“While we are confident that we will soon rectify this situation, I am upset for the difficulty and disruption this has caused our students, families, and staff,” said Flanagan.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Iran Reports Two Major Cyber-Attacks

Iran Reports Two Major Cyber-Attacks

Iran has reported falling victim to two large-scale cyber-attacks, one of which was leveled at the country’s government institutions.

The Iranian government’s Information Technology Organization on Thursday reported that two institutions had been compromised by attackers. No party has claimed responsibility for the attack, and Iranian government officials have not stated whether the attack was domestic or foreign.

The target of earlier attacks carried out on Monday and Tuesday has not yet been named. 

According to The Jerusalem Post, the Iranian government made an announcement concerning the attacks after news of the incidents began spreading on social media. 

An Iranian news agency reported on Friday that the cyber-attacks had impacted the electronic infrastructure of the country’s ports. According to US-funded Radio Farda, unconfirmed reports in Iranian media named the country’s banking system and Ports and Maritime Organization as among the targets. 

Quasi-official news agency Tasnim reported a spokesperson for the country’s Ports and Maritime Organization as stating: “Sworn enemies have been trying for some time to carry out cyberattacks.”

The statement went on to say that action had been taken to block further attacks and prevent any disruption of the “organization’s missions.”

Abolghasem Sadeghi, from the government’s Information Technology Organization, commented on the attacks on state TV on Thursday. Sadeghi said that the incidents had prompted several government bodies to temporarily shut down internet services as a precautionary measure. 

He described the attacks as “important and on a large scale,” and said that an investigation into them had been launched. 

A previous attack carried out on Iran’s Bandar Abbas port in May 2020 was blamed on Israel. The attack was supposedly a retaliation for an attack carried out against six Israel Water Authority facilities in April 2020.

Iran reported three cyber-attacks within a week in December last year, one of which the country said was sponsored by a foreign state. The country’s telecommunications minister said at the time that a cybersecurity project known as the “Dejfa fortress” had repelled a cyber-onslaught involving the “well-known APT27” threat group that has been linked to Chinese-speaking hackers.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Senator Questions US Healthcare Giant Over Cyber-Attack

Senator Questions US Healthcare Giant Over Cyber-Attack

A major healthcare provider whose systems were knocked offline for three weeks by a ransomware attack has been asked by a US senator to answer questions about its cybersecurity practices. 

Universal Health Services announced on Monday that all 400 of its health system sites were back online after being hit by a cyber-attack in the early hours of September 27. 

UHS initially reported the attack as an “Information Technology security incident,” but staff who took screenshots of the attack confirmed that ransomware was responsible for the disruption. 

As a result of the incident, UHS disconnected all systems and shut down the network to prevent further propagation. While some hospitals diverted ambulances and some lab test results were delayed, the company said that “patient care was delivered safely and effectively at our facilities across the country using established back-up processes, including offline documentation methods.” 

Following the attack, former technology entrepreneur and vice chairman of the Senate Intelligence Committee, Senator Mark Warner, has written to UHS to express concerns regarding their cybersecurity measures.

Warner told the Fortune 500 company that with annual revenue of more than $11bn, it should have a cybersecurity posture “sufficiently mature and robust to prevent major interruptions to health care operations.”

In his letter dated October 9, the senator questioned UHS over its vulnerability management process, third-party risk management, protection of clinical medical devices, and ability to isolate networks to prevent lateral movement by attackers.

Warner also asked UHS to state whether it had paid a ransom to its attackers and to confirm whether any patient medical records, HIPAA-protected data, or healthcare information has been affected or suffered a denial of access as a result of the attack. 

On October 12, UHS stated: “Throughout the IT remediation work we have had no indication that any patient or employee data was accessed, copied or misused.”

UHS, which is headquartered in King of Prussia, Pennsylvania, operates facilities in Puerto Rico, the United Kingdom, and the United States. In a statement released on September 29, the company said that its UK operations were not impacted by the attack. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

BA GDPR Data Breach Fine Lowered to £20m Due to COVID-19

BA GDPR Data Breach Fine Lowered to £20m Due to COVID-19

The fine against British Airways for GDPR failings has been reduced to £20m from the original £183m intent to fine issued last July.

An ICO investigation found the airline was processing a significant amount of personal data without adequate security measures in place, leading to a cyber-attack during 2018, which it did not detect for more than two months. It said the amount to be fined (£20m) was considered with both representation from BA and the economic impact of COVID-19 on the business.

The ICO also said, as the breach happened in June 2018, before the UK left the EU, the ICO investigated on behalf of all EU authorities as lead supervisory authority under the GDPR. The penalty and action have been approved by the other EU DPAs through the GDPR’s cooperation process.

According to the penalty notice, a proposed penalty of £183.39m was issued on July 4 2019 with a extension till March 21 2020 agreed in December. On April 3 2020, the ICO wrote to BA requesting information regarding the impact of COVID-19 on its financial position, and having considered BA’s representations, both BA and the ICO “agreed to a series of further extensions of the statutory deadline to 30 September.

Rachel Aldighieri, managing director of the Data & Marketing Association (DMA), said: “Brexit and coronavirus have put businesses under immense financial strain and a fine of this magnitude will get the attention of board members of organizations across the UK. They will certainly not want to risk receiving similar disciplinary action from the ICO.

“This is the largest fine issued by the ICO to date under the new GDPR laws, highlighting the importance all businesses should place on the security of customers’ data and the need to build in safeguards to protect it.”

In the attack, an attacker is believed to have potentially accessed the personal data of approximately 429,612 customers and staff. This included names, addresses, payment card numbers and CVV numbers of 244,000 BA customers. Other details thought to have been accessed include the combined card and CVV numbers of 77,000 customers and card numbers only for 108,000 customers.

Usernames and passwords of BA employee and administrator accounts as well as usernames and PINs of up to 612 BA Executive Club accounts were also potentially accessed.

The ICO said that since the attack BA has made considerable improvements to its IT security. Information Commissioner Elizabeth Denham said: “People entrusted their personal details to BA and BA failed to take adequate measures to keep those details secure.

“Their failure to act was unacceptable and affected hundreds of thousands of people, which may have caused some anxiety and distress as a result. That’s why we have issued BA with a £20m fine – our biggest to date.”

Piers Wilson, head of product management at Huntsman Security, said: “Whether this was a result of clever bargaining by BA, the investigation process uncovering mitigating factors, an acknowledgement of the ravages of COVID-19 on the airline industry or the ICO deliberately setting a high initial target with a more realistic goal in mind, it could give the message that fines will not be as severe as businesses and some in the security and privacy industry expect.”

Vanessa Barnett, commercial and IP partner at Keystone Law, added: “In the grand scheme of things, it’s important that the punishment fits the wrongdoing: whilst the GDPR certainly has teeth and can really bite quite hard, it’s great to see the ICO continuing with its attitude of proportionality that existed pre-GDPR. Don’t forget that before GDPR the statutory limit was £500,000.

“£500,000 to £20m is a big jump and will still very much focus the (compliance) minds! The ICO may have felt some moral pressure not to whack BA even more in the midst of a global pandemic which is affecting it hugely and luckily, its enforcement framework allows that.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Election Security and Confidence Can Be Enabled Through Public-Private Partnerships

Election Security and Confidence Can Be Enabled Through Public-Private Partnerships

The security of democracy can be better protected if there is trust from the public and improved collaboration between public/private sectors and governments.

Speaking on a virtual roundtable, Shawn Henry, Crowdstrike CISO and president of Crowdstrike Services, said this is a political and cybersecurity issue. Henry began by claiming that foreign interference in an election is the “ultimate hack, not just of democracy, but of peoples beliefs, what they think and why they think it.” This leads to questions about whether the election is secure and valid, and whether casted votes do count, calling it “a national security issue.”

William Evanina, director of the National Counterintelligence and Security Center (NCSC), said foreign interference is not new, but in the past year it has travelled across to the US and “we’ve seen our adversaries amplify and accentuate over social media.” He also said too many western governments do not understand what disinformation looks and feels like, so the opportunities presented by social media present a vulnerability.

Commenting, Sir Rob Wainwright, senior partner at Deloitte, said disinformation is “a problem around the world” as social media has the opportunity to “spread false narratives, but there is a side to this that is even more dangerous and insidious.” Wainwright also cited cyber-attacks as part of a campaign of disinformation, as this “is about more than just spreading propaganda.”

Wainwright explained the complexity and cycle of the threat between 2016 and 2020 elections and said “we need to up our game as a result.” Evanina said time had been spent over the past few years driving partnerships with government agencies and industry “so the local CISO understands the intent and the adversary, and how they can be compromised.”

Asked by Henry what role a collaboration between public and private sector can play in this situation, Wainwright said there is a role in society to get this right, particularly for social media, and those companies are working more intensively than four years ago. “The big point is that this is not about what role governments can play on one side and private sector companies on the other, it is very much about the collaboration and getting that public-private partnership in the right space so it is all hands on deck in a uniform way,” he added.

Wainwright said the collective responsibility should be about getting the hygiene right, about common standards across the election infrastructure, as well as knowing where the threats are coming from and what the intelligence looks like.

Evanina agreed that public-private partnerships has never been more important. “We have to be willing and able to partner, and that partnership starts not only with intelligence sharing, but we have to find a happy medium where we can provide due diligence on sharing information at the same time, some privacy protections and privacy sanctions after a company is victimized,” he said. “Being a victim is not something that can carry penalties, we have to find a happy medium.”

Wainwright concluded by citing the importance of this issue, particularly in embedding confidence in the public, saying regardless of if you work for a social media company, in intelligence or in government “you need to see everything through that lens to get it right and prioritize it in a collective and successful way.”

Evanina said as a democracy, we need to provide free and open elections, so the public has confidence in the voting systems. “If we cannot ensure that, we have a lot more problems than we think we do.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Dickey’s PoS Breach Could Hit Three Million Cards

Dickey’s PoS Breach Could Hit Three Million Cards

Another popular US restaurant franchise appears to have been on the receiving end of a major point of sale (PoS) data breach, with dark web traders claiming to have three million cards to sell.

Threat intelligence firm Gemini Advisory analyzed data uploaded to infamous carding forum Joker’s Stash and revealed that Dickey’s Barbecue Pit is the affected restaurant chain.

It said that customers in around a third of locations, 156 of 469, across 30 states may have had their cards compromised between July 2019 and August 2020.

“Dickey’s operates on a franchise model, which often allows each location to dictate the type of PoS device and processors that they utilize,” said the vendor.

“However, given the widespread nature of the breach, the exposure may be linked to a breach of the single central processor, which was leveraged by over a quarter of all Dickey’s locations.”

The dark web seller advertising the cards, BlazingSun, has not uploaded the entire stash yet, and will likely continue to add compromised data over the next few months, Gemini Advisory said.

“Gemini sources have also determined that the payment transactions were processed via the outdated magstripe method, which is prone to malware attacks,” it concluded. “It remains unclear if the affected restaurants were using outdated terminals or if the EMV terminals were misconfigured; either of these possibilities may hold serious liability for Dickey’s.”

After the shift to EMV, merchants which continue to process magstripe could face legal action and fines if breached. The practice is far more common in the US, which made the switch to more secure cards relatively late compared to much of Western Europe, which is why PoS breaches like this still occur.

Other big names compromised in this way over the past year include convenience store chain Wawa, Planet Hollywood parent company Earl Enterprises and Rutter’s, another convenience store brand.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Nearly 800,000 SonicWall VPNs Need Critical Flaw Patching

Nearly 800,000 SonicWall VPNs Need Critical Flaw Patching

Nearly 800,000 VPNs around the world need urgent patching after a vendor issued a security update for a critical flaw this week.

Researchers from Tripwire found the stack-based buffer overflow vulnerability in SonicWall’s Network Security Appliance (NSA), or more specifically, its underlying SonicOS software.

According to Tripwire security researcher Craig Young, who discovered the bug, the problem exists in the HTTP/HTTPS service used for product management and SSL VPN remote access. It can apparently be triggered by an unauthenticated HTTP request involving a custom protocol handler.

“An unskilled attacker can use this flaw to cause a persistent denial of service condition,” Young continued.

“Tripwire VERT has also confirmed the ability to divert execution flow through stack corruption indicating that a code execution exploit is likely feasible. This flaw exists pre-authentication and within a component (SSLVPN) which is typically exposed to the public internet.”

With over 795,000 SonicWall devices exposed according to a Shodan search made by Tripwire on Wednesday, the bug could be exploited to cause widespread damage.

According to SonicWall, the vulnerability has a CVSS score of 9.4, perhaps a reflection of the fact it could lead not only to denial of service but also arbitrary remote code execution.

The affected versions are: SonicOS 6.5.4.7-79n and earlier, SonicOS 6.5.1.11-4n and earlier, SonicOS 6.0.5.3-93o and earlier, SonicOSv 6.5.4.4-44v-21-794 and earlier and SonicOS 7.0.0.0-1.

The vendor released patches on Monday.

VPN systems are increasingly being targeted by attackers looking to find a way into corporate systems, given the large numbers of remote workers currently reliant on them.

In April it was confirmed that cyber-criminals were exploiting known bugs in Citrix and Pulse Secure VPNs to deploy ransomware in hospitals, while just this week it emerged that other attackers were chaining VPN exploits with Zerologon to compromise Active Directory (AD) identity services.

SonicWall sent Infosecurity a statement to confirm it takes every vulnerability disclosure seriously.

“Immediately upon discovery, SonicWall researchers conducted extensive testing and code review to confirm the third-party research. This analysis led to the discovery of additional unique vulnerabilities to virtual and hardware appliances requiring CVE listings based on CVSS,” it explained.

“The PSIRT team worked to duplicate the issues and develop, test and release patches for the affected products. At this time, SonicWall is not aware of a vulnerability that has been exploited or that any customer has been impacted.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

VoIP Firm Broadvoice Leaks 350 Million Customer Records

VoIP Firm Broadvoice Leaks 350 Million Customer Records

A US-based VoiP provider has been found leaking over 350 million customer records, after a configuration error left several online databases exposed.

Researcher Bob Diachenko found the unprotected Elasticsearch database clusters belonging to Broadvoice on October 1.

The trove of 10 databases included one containing more than 275 million records. It featured full caller name, identification number, phone number, state and city.

Perhaps more dangerous from a privacy perspective was another collection of over two million records that included names, phone numbers and, for 200,000 records, call transcripts.

According to Comparitech, which worked with Diachenko on the case, some of these transcripts themselves contained sensitive details such as voicemails left at medical clinics and financial services firms.

Comparitech claimed most of the data belongs to Broadvoice XBP customers.

“The leaked database represents a wealth of information that could help facilitate targeted phishing attacks. In the hands of fraudsters, it would offer a ripe opportunity to dupe Broadvoice clients and their customers out of additional information and possibly into handing over money,” Comparitech argued.

“For example, criminals could pose as Broadvoice or one of its clients to convince customers to provide things like account login credentials or financial information.”

Some exposed data, such as insurance policy numbers and financial loan details, could even be used to attempt identity fraud without the need for further phishing, it added.

However, Broadvoice reacted relatively quickly to the notification on October 1, fixing the privacy snafu by October 4.

The firm’s CEO, Jim Murphy, claimed the data had been “inadvertently” stored in an unsecured database on September 28, and said that law enforcement has been informed and an investigation has been launched.

“At this point, we have no reason to believe that there has been any misuse of the data,” he continued.

“We are currently engaging a third-party forensics firm to analyze this data and will provide more information and updates to our customers and partners. We cannot speculate further about this issue at this time. We sincerely regret any inconvenience this may cause.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk