Kylie Jenner’s Makeup Company Warns of Data Breach

Kylie Jenner’s Makeup Company Warns of Data Breach

Kylie Jenner’s makeup company has warned customers that their information may have been compromised in a recently detected security incident at a Canadian e-commerce merchant. 

Earlier this month, Shopify reported the theft, by members of its own support team, of transactional records belonging to up to 200 of the company’s merchants. The incident, which is now under investigation by the FBI, involved two Shopify employees who no longer have access to the company’s network.

Clients of Kylie Cosmetics have now been notified that their personal data may be among the information swiped by the two employees, whom Shopify has branded as “rogue.” 

Information impacted by the security incident included basic contact details such as email, name, and address, as well as order details, like products and services purchased. 

An email sent by the 23-year-old billionaire’s beauty business to its customers stated: “Your trust is so important to us and we wanted to let you know we’re working diligently with Shopify to get additional information about this incident and their investigation and response to this matter.”

An assurance given by Shopify to its merchants regarding future insider threats was passed on to Jenner’s clientele. 

“Shopify has assured us that they have implemented additional controls designed to help prevent this type of incident from recurring in the future,” the cosmetics company told its customers.

Jenner launched the company three years ago, and it has flourished on the back of popular products like Kylie’s “Lip Kit,” which consists of a matching liquid lipstick and lip liner. Last year, Jenner sold most of her shares in the company for $600m. 

Shopify was founded in 2006 and is used by over a million merchants around the world, including Tesla and Victoria Beckham.

“Insider threat is a very real issue that gets little attention,” commented Lamar Bailey, senior director of security research at Tripwire.

“Support engineers are often an entry level job, so it is easier for someone to infiltrate the organization at this level. 

“A bad actor looking to gain company data can easily use a fake identity to secure a job and then use this position as a launching point for gathering data to sell on the black market. It is imperative that organizations have security controls in place,” Bailey said. “A stance of least privilege for everyone is the best policy.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

One in Three Not Worried About Cybersecurity Despite Rise in Threats

One in Three Not Worried About Cybersecurity Despite Rise in Threats

Around one in three (31%) people in the UK are not actively concerned about cybersecurity, according to a study by ESET.

In a survey of 2000 UK citizens, which looked at their cybersecurity habits, more than half (57%) do not believe they’ve been hacked and 46% claimed they have never noticed or fallen for an online scam or hack.

However, this is unlikely to reflect reality, with over a quarter (26%) of respondents admitting that they do not know the signs of a successful or attempted hack.

The research was conducted in order to grow awareness of the growing threats of scams to both individuals and businesses. Numerous reports have found that the number of scams have risen this year, largely linked to the health, economic and social effects of COVID-19. For instance, at the start of the crisis, there was a 667% increase in phishing emails recorded while it was revealed last month that the UK’s HMRC is currently investigating more than 10,000 email, SMS, social media and phone scams exploiting the pandemic.

Jake Moore, cybersecurity expert at ESET UK, commented: “Scams are growing in frequency and it is becoming much harder to spot a phishing email. Possible signs you may have been hacked are more difficult to recognize, too, as criminals become more sophisticated in their art of deception. While some may not be concerned about their cybersecurity, this European Cybersecurity Month, we urge individuals to stay alert as they may be even more vulnerable in this current climate and must take extra precautions.

“Recent research from The Myers-Briggs Company showed that 47% of respondents are concerned about their ability to manage stress during the crisis – and, when people are facing financial and health stressors, they may be even less likely to pick up on signs of a hack. Remember to stay vigilant with emails, search directly for legitimate websites rather than clicking through from the email itself, always check before handing over any information – especially when it involves personal or financial data – and regularly change your passwords or use a robust password manager.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Click & Collect Fraud Up by 55% Following Shift to Online Shopping

Click & Collect Fraud Up by 55% Following Shift to Online Shopping

Buy online, pick-up in store fraud rose by 55% in the first half of 2020, according to the latest edition of the Forter Fraud Attack Index, published today. The study demonstrates that e-commerce is increasingly being targeted by fraudsters following the huge shift to online shopping since the start of the COVID-19 pandemic.

There has been a substantial increase in the number of new customer accounts, now representing 30% of all transactions – which is around five-times higher than pre-COVID levels. Forter said this phenomenon is posing cybersecurity issues for online traders, as it is more difficult for legacy fraud systems to identify legitimate new users from fraudsters due to lack of data. This growth in new users is also likely to lead to high false decline rates, which are five- to seven-times higher in new users compared to returning users.

The report also noted that the dramatic increase in legitimate online transactions has meant that the proportion of fraud attacks has actually decreased, and this could be giving retailers a false sense of security, as the number of fraud cases have gone up in real terms.

Another finding was that fraud attacks targeting digital currency gift cards increased by five-times the normal rate. Additionally, attacks on downloads of apps and music were three-times higher than usual, while for consoles, the volume of fraud attacks were twice as high.

Despite transaction volumes for the entire travel sector falling by 97% during the peak of the early COVID-19 outbreak, the study revealed that hotel fraud attacks rose 139% and airline fraud attacks increased 144% compared to the first half of 2019.

Forter also stated that despite there being a 5% decrease in account takeover (ATO) this will rise substantially in the coming months as fraudsters are currently harvesting data to use, possibly during the holiday season. It added that losses from ATO are expected to reach 25.6bn for the whole of 2020.

Speaking to Infosecurity, Michael Reitblat, CEO of Forter, commented: “As COVID-19 conditions began, some merchants were better prepared than others to scale their digital channels. However, with a quick shift to digital and a prioritization of business solvency, security measures and fraud prevention may have come as an afterthought for some.

“Based on our experience, the most successful merchants have been able to quickly adapt their digital channels alongside their fraud prevention and security precautions. Over the past few months, some of our merchants in industries like apparel and food and beverage have seen online demand increase between 300% and 400% per day. By automating their fraud prevention and making decisions on transactions in real time they’ve been able to seamlessly support this new demand while simultaneously protecting their business and without adding friction to their customers’ experience.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Former Amazon Employee Charged with $1.4m Insider Trading Scheme

Former Amazon Employee Charged with $1.4m Insider Trading Scheme

A former Amazon finance manager and two family members have been charged with insider trading, after the former allegedly misused tax details she was privy to as part of her job.

The Securities and Exchange Commission (SEC) levied the charges on Monday, clarifying that they related to Amazon earnings announcements between January 2016 and July 2018.

As a senior manager in Amazon’s tax department, Laksha Bohra prepared and reviewed calculations used to finalize details presented in the firm’s quarterly and annual earnings, according to the regulator.

It is alleged that, from January 2016 to July 2018, Bohra tipped off her husband Viky Bohra with confidential information on Amazon earnings. He is then said to have traded on this information with his father Gotham, using 11 accounts managed by various members of the family.

The SEC also alleged that Laksha Bohra ignored quarterly reminders from Amazon that sharing non-public information or recommending the purchase or sale of Amazon securities is illegal.

The family is alleged to have made $1.4m from its insider dealings.

“We allege that the Bohras repeatedly and systematically used Amazon’s confidential information for their own gain,” said Erin Schneider, director of the SEC’s San Francisco Regional Office. “Employees with access to confidential, potentially market-moving corporate information may not use that information to enrich themselves, their friends, or their families.”

According to the regulator, the three have agreed to pay back the $1.4m, plus $118,406 in “total prejudgment interest,” and total penalties of over $1.1m.

Incidents of this sort are still not uncommon, and are often perpetrated by those who already receive generous salaries from their employer.

In October 2018, a former Equifax software manager was sentenced to eight months home confinement after pleading guilty to insider trading, while in December last year it was the turn of a former IT administrator at Palo Alto Networks, who is said to have made $7m in a three-year conspiracy.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Amazon Trials Palm Scanner for Contactless Payments

Amazon Trials Palm Scanner for Contactless Payments

Amazon has unveiled a new biometric scanner it hopes will streamline contactless payment security and physical access for consumers and businesses.

Currently being trialled in a couple of Amazon Go stores in Seattle, the Amazon One scans the user’s palm as it is held above the device and identifies its unique vein patterns in order to match it with the correct pre-stored biometric details.

To register, users will first need to input their credit card in order to link it with their biometric palm image.

“We’ll start in select Amazon Go stores, where Amazon One will be added to the store’s entry gate as a convenient choice for customers to use to enter the store to shop,” the e-commerce giant wrote.

“In most retail environments, Amazon One could become an alternate payment or loyalty card option with a device at the checkout counter next to a traditional point of sale system. Or, for entering a location like a stadium or badging into work, Amazon One could be part of an existing entry point to make accessing the location quicker and easier.”

However, security and privacy experts were not convinced. Kaspersky Lab principal security researcher, David Emm, argued that because Amazon One combines identification, authentication and authorization, the biometric and payment data stored by the firm will need to be very secure.

“Where identification and authentication are separate, for example where a biometric is used to identify you and a PIN is used to verify that identity, anyone stealing the biometric data wouldn’t have a complete set of information or enough to steal people’s money. But in the case of Amazon One, they would have everything they need,” he said.

“Much safer to keep the two things separate — biometric data to identify you and something else (such as a PIN) for authentication.”

Meanwhile, Big Brother Watch director, Silkie Carlo, decried Amazon’s efforts “to fill the market with invasive, dystopian technologies that solve non-existent problems.”

A recent report from UK Finance said fraudsters are increasingly eschewing face-to-face transactions in favor of more online activity, as a result of the pandemic. Losses to contactless fraud fell 20% year-on-year in 1H 2020 to £8.2 million, it claimed.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware: from Entry to Ransom in Under 45 Minutes

Ransomware: from Entry to Ransom in Under 45 Minutes

Ransomware gangs are performing wide-ranging internet scans to find vulnerable systems and then accelerating attacks to just minutes to capitalize on COVID-19, Microsoft has warned.

Corporate VP of customer security and trust, Tom Burt, revealed the findings in a blog post introducing the firm’s Digital Defense Report yesterday.

He claimed that threat actors have “rapidly increased sophistication” over the past year, with ransomware the number one reason for Microsoft incident response between October 2019 and July 2020.

“Attackers have exploited the COVID-19 crisis to reduce their dwell time within a victim’s system — compromising, exfiltrating data and, in some cases, ransoming quickly — apparently believing that there would be an increased willingness to pay as a result of the outbreak. In some instances, cyber-criminals went from initial entry to ransoming the entire network in under 45 minutes,” Burt explained.

“At the same time, we also see that human-operated ransomware gangs are performing massive, wide-ranging sweeps of the internet, searching for vulnerable entry points, as they ‘bank’ access – waiting for a time that is advantageous to their purpose.”

Attackers have also become more sophisticated in performing reconnaissance on high-value targets, so that they appear to know when certain factors like holidays will reduce the victim organization’s chances of patching, or otherwise hardening their networks.

They’re also aware of how billing cycles operate in certain industries, and thus when specific targets may be more willing to pay, Burt claimed.

In total, Microsoft blocked over 13 billion malicious and suspicious emails in 2019, over one billion of which contained phishing URLs. Phishing now comprises over 70% of attacks, although the volume of COVID-related threats has dropped significantly from a peak in March, it said.

This isn’t the only threat to home workers: Microsoft said it also saw an increase in brute force attacks on enterprise accounts in the first half of the year, and urged widespread use of multi-factor authentication (MFA).

Burt said nation state actors have also been changing their tactics of late, shifting targets to healthcare providers and vaccine researchers, public policy think tanks and NGOs. Although each group has their preferred techniques, reconnaissance, credential harvesting, malware and virtual private network (VPN) exploits were most common over the past year, said Burt.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk