KPMG: Consumers Vote to Ditch Breached Firms

KPMG: Consumers Vote to Ditch Breached Firms

Most consumers would take their business elsewhere if they discovered an organization had suffered a major cyber-attack or data breach, according to new data from KPMG.

The global consulting firm polled over 2000 Canadians in September to better understand the impact of security incidents and the risks for online firms that fail to adequately protect customer data.

As many as 90% of respondents said they would feel wary about sharing personal or financial information with a company that had suffered such an incident, and over two-thirds (67%) are more worried than ever about their data being breached.

The findings come at a time when consumers are spending more of their lives, and sharing more of their data, online.

Over half (54%) of respondents said they are shopping more online than they used to pre-COVID, rising to 64% for the 18-44 age group. The same number (54%) said they had received a lot more suspicious emails in the first half of 2020, and even more (84%) claimed they were being “extra careful” when shopping online for fear of their data being stolen.

Phishing (38%) and spear-phishing (13%) were revealed as the most common attacks likely to face Canadians, as they are consumers in other Western countries. Unfortunately for brands, they are likely to get the blame for successful attacks on consumers even though it is the email recipients themselves who make the mistake of clicking through.

Restoring consumer confidence will therefore require a focus on internal security, to mitigate the threat of data breaches, and closer engagement with customers to educate them about the threat from phishing and social engineering attempts to impersonate their brand.

KPMG urged organizations to identify and protect their “crown jewels,” build internal resilience through incident response, improve staff training and awareness, establish governance and accountability, and help managers better understand the business impact of security.

“While social distancing has made us much more reliant on all things digital, the surge in cyber-attacks and data breaches amid the COVID-19 pandemic is starting to undermine trust,” argued Hartaj Nijjar, KPMG partner. “The new reality in which we are living demands that every organization takes a much harder look at their cybersecurity strategy, systems and protocols.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Suspected Ransomware Takes Out Major US Healthcare Provider

Suspected Ransomware Takes Out Major US Healthcare Provider

There are major concerns for the health of patients across America and beyond after one of the nation’s largest hospital providers was struck by an apparent ransomware attack over the weekend.

Universal Health Services (UHS) claims to operate around 400 acute care hospitals, behavioral health facilities and ambulatory centers across the US, Puerto Rico and the UK.

It posted a brief statement on Monday morning Eastern Time admitting that its IT network across all UHS facilities is currently offline due to an “IT security issue.

“We implement extensive IT security protocols and are working diligently with our IT security partners to restore IT operations as quickly as possible,” it continued.

“In the meantime, our facilities are using their established backup processes including offline documentation methods. Patient care continues to be delivered safely and effectively.”

Given its reference to backup processes, the incident seems very much like a ransomware attack. It also fits the classic ransomware MO of attacking targets at the weekend when technical support may take longer to rally, and of targeting healthcare organizations that have much to lose from refusing to pay.

In fact, Microsoft revealed in April that ransomware gangs were deliberately targeting the healthcare sector during the COVID-19 crisis.

Reports on social media suggest that some patients are being redirected to other hospitals, as UHS continues to tackle the IT incident.

Fresh in the mind is an incident in Germany earlier this month when a patient died after delays to her treatment caused by a ransomware attack.

There will also be concerns about the security of patient data at UHS hospitals, given many ransomware gangs now also steal information in a bid to force payment.

However, UHS claimed: “No patient or employee data appears to have been accessed, copied or misused.”

There was a 20% increase in ransomware attacks in the first half of 2020, to top 121 million, according to SonicWall.

Daniel Norman, senior solutions analyst at the Information Security Forum, argued that the healthcare sector has an outdated approach to cybersecurity.

“With this industry adopting new and emerging technologies, the requirement to educate and train the entire workforce on a range of cyber-risks and threats is urgent. In addition, the safety and wellbeing of patients has historically been the top priority, so this mindset needs to translate into the security of systems and devices that will underpin the lives of many,” he added.

“Basic cyber-hygiene standards need to be met, covering patching and updates, network segmentation, network monitoring and hardening, especially for technologies such as AI, robotics and IoT devices. Privacy should also be a high priority for anyone handling sensitive information, considering the shift towards storing patient records online.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Nearly Half of Citizens Believe There is Online Censorship

Nearly Half of Citizens Believe There is Online Censorship

Nearly half (45%) of citizens across seven countries – the UK, US, Canada, Australia, Russia, Norway and Sweden – do not trust the integrity of information they find online, according to an analysis by TunnelBear. This includes 48% of respondents from the UK.

Amongst the survey of 5500 people aged 18-65 in these countries, there was also a strong suspicion that online censorship is taking place. Over two in five (44%) reported that either they have, or someone they know has, experienced internet censorship, with this figure rising to 58% in the UK.

In addition, more than two-thirds (69%) said they felt there could be censorship taking place within their country while over one-third (35%) believe a significant amount is censored in their country.

More than a third (39%) also commented that they believe political parties and governments are engaging in political censorship in order to avoid upheaval or embarrassment. This figure rose to 44% amongst US participants.

The lack of trust in online information is especially concerning given the growing reliance on this channel as a result of COVID-19 lockdown restrictions this year.

Justin Watts, head of engineering at TunnelBear, stated: “While consumers are increasingly aware of and wary about internet censorship in the UK and globally, they also need to understand how to combat such intrusions on their freedom.”

Speaking to Infosecurity, Watts added: “The tech industry has made some astounding strides in the development of internet services over the past few years. As online services and platforms continue to evolve and play a large role in people’s lives, so does the awareness about the effects of these technologies and the importance of an uncensored lens into our world.”

Commenting on the research, Raef Meeuwisse CISM, CISA, author of Cybersecurity for Beginners, said: “There is a predictable lifecycle to the emergence, use and then misuse of new types of electronic information. Whenever new types of digital information emerge that influence or control human decisions, they become high-value targets for subversion.

“Two of the most prominent examples of information misuse have been online product reviews besieged by fake reviews and how the term fake news – once used just to label news that was provably incorrect – is now regularly misapplied to discredit or question real news more often than it is to label genuine fake news.

“With more time being spent online and attention focused on particular subjects and platforms, I think it is inherently evident that there has been more censorship – which by definition is the suppression of speech and communication. As an example, in place of social proof or popularity, some search engines and social media platforms promote what they consider to be ‘authoritative sources’ and may suppress or remove other results. Is that good practice? It really depends on how reliable the censorship decisions are – but what has been evident in many cases is that the sources that have been marginalized turned out to be correct – and the supposedly authoritative sources have sometimes turned out to be the misinformation.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hacking a Coffee Maker

As expected, IoT devices are filled with vulnerabilities:

As a thought experiment, Martin Hron, a researcher at security company Avast, reverse engineered one of the older coffee makers to see what kinds of hacks he could do with it. After just a week of effort, the unqualified answer was: quite a lot. Specifically, he could trigger the coffee maker to turn on the burner, dispense water, spin the bean grinder, and display a ransom message, all while beeping repeatedly. Oh, and by the way, the only way to stop the chaos was to unplug the power cord.

[…]

In any event, Hron said the ransom attack is just the beginning of what an attacker could do. With more work, he believes, an attacker could program a coffee maker — ­and possibly other appliances made by Smarter — ­to attack the router, computers, or other devices connected to the same network. And the attacker could probably do it with no overt sign anything was amiss.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Who’s Behind Monday’s 14-State 911 Outage?

Emergency 911 systems were down for more than an hour on Monday in towns and cities across 14 U.S. states. The outages led many news outlets to speculate the problem was related to Microsoft‘s Azure web services platform, which also was struggling with a widespread outage at the time. However, multiple sources tell KrebsOnSecurity the 911 issues stemmed from some kind of technical snafu involving Intrado and Lumen, two companies that together handle 911 calls for a broad swath of the United States.

Image: West.com

On the afternoon of Monday, Sept. 28, several states including Arizona, California, Colorado, Delaware, Florida, Illinois, Indiana, Minnesota, Nevada, North Carolina, North Dakota, Ohio, Pennsylvania and Washington reported 911 outages in various cities and localities.

Multiple news reports suggested the outages might have been related to an ongoing service disruption at Microsoft. But a spokesperson for the software giant told KrebsOnSecurity, “we’ve seen no indication that the multi-state 911 outage was a result of yesterday’s Azure service disruption.”

Inquiries made with emergency dispatch centers at several of the towns and cities hit by the 911 outage pointed to a different source: Omaha, Neb.-based Intrado — until last year known as West Safety Communications — a provider of 911 and emergency communications infrastructure, systems and services to telecommunications companies and public safety agencies throughout the country.

Intrado did not respond to multiple requests for comment. But according to officials in Henderson County, NC, which experienced its own 911 failures yesterday, Intrado said the outage was the result of a problem with an unspecified service provider.

“On September 28, 2020, at 4:30pm MT, our 911 Service Provider observed conditions internal to their network that resulted in impacts to 911 call delivery,” reads a statement Intrado provided to county officials. “The impact was mitigated, and service was restored and confirmed to be functional by 5:47PM MT.  Our service provider is currently working to determine root cause.”

The service provider referenced in Intrado’s statement appears to be Lumen, a communications firm and 911 provider that until very recently was known as CenturyLink Inc. A look at the company’s status page indicates multiple Lumen systems experienced total or partial service disruptions on Monday, including its private and internal cloud networks and its control systems network.

Lumen’s status page indicates the company’s private and internal cloud and control system networks had outages or service disruptions on Monday.

In a statement provided to KrebsOnSecurity, Lumen blamed the issue on Intrado.

“At approximately 4:30 p.m. MT, some Lumen customers were affected by a vendor partner event that impacted 911 services in AZ, CO, NC, ND, MN, SD, and UT,” the statement reads. “Service was restored in less than an hour and all 911 traffic is routing properly at this time. The vendor partner is in the process of investigating the event.”

It may be no accident that both of these companies are now operating under new names, as this would hardly be the first time a problem between the two of them has disrupted 911 access for a large number of Americans.

In 2019, Intrado/West and CenturyLink agreed to pay $575,000 to settle an investigation by the Federal Communications Commission (FCC) into an Aug. 2018 outage that lasted 65 minutes. The FCC found that incident was the result of a West Safety technician bungling a configuration change to the company’s 911 routing network.

On April 6, 2014, some 11 million people across the United States were disconnected from 911 services for eight hours thanks to an “entirely preventable” software error tied to Intrado’s systems. The incident affected 81 call dispatch centers, rendering emergency services inoperable in all of Washington and parts of North Carolina, South Carolina, Pennsylvania, California, Minnesota and Florida.

According to a 2014 Washington Post story about a subsequent investigation and report released by the FCC, that issue involved a problem with the way Intrado’s automated system assigns a unique identifying code to each incoming call before passing it on to the appropriate “public safety answering point,” or PSAP.

“On April 9, the software responsible for assigning the codes maxed out at a pre-set limit,” The Post explained. “The counter literally stopped counting at 40 million calls. As a result, the routing system stopped accepting new calls, leading to a bottleneck and a series of cascading failures elsewhere in the 911 infrastructure.”

Compounding the length of the 2014 outage, the FCC found, was that the Intrado server responsible for categorizing and keeping track of service interruptions classified them as “low level” incidents that were never flagged for manual review by human beings.

The FCC ultimately fined Intrado and CenturyLink $17.4 million for the multi-state 2014 outage. An FCC spokesperson declined to comment on Monday’s outage, but said the agency was investigating the incident.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk