Student Arrested Over Cyber-attacks on Indiana Schools

Student Arrested Over Cyber-attacks on Indiana Schools

A 13-year-old boy has been arrested in the United States after allegedly hacking into an Indiana school district’s computer system. 

The unnamed teen was arrested after repeated cyber-attacks were launched against Valparaiso Community Schools. 

School officials reported regular assaults on the district’s e-learning systems that disrupted instruction by causing students to become disconnected from their virtual classrooms. 

The alleged hacker is a student at Benjamin Franklin Middle School, a highly rated public school with 820 students and a student-teacher ratio of 18 to 1. 

Police confirmed on September 18 that they had taken the boy into custody on September 17 after school officials discovered he had illegally entered the Valparaiso Community School computer system.

Valparaiso police captain Joe Hall said that the boy is believed to be behind a series of cyber-attacks that have struck schools in the district since the pandemic triggered a shift to online learning. 

The defendant was transported to the Porter County Juvenile Detention Center, where he was charged under a new law with committing an offense against computer users. The law, Indiana Code 35-32-1-8, is a level 6 felony.

Interim School Superintendent Michael Berta said no evidence had been found to suggest that the boy had been working with any accomplices when he allegedly carried out the cybercrimes. 

Berta said by disrupting the e-learning programs introduced in an effort to slow the spread of COVID-19, whoever was responsible had made an already challenging situation even more difficult. 

He added that since the boy’s arrest, the disruptions to e-learning had ceased. 

“This has been a very frustrating situation,” he told The Times. “We’re looking forward to moving on.”

Parents were notified by Valparaiso administrators that the school district was working with law enforcement to identify the criminal(s) behind the attacks, which they described as “purposeful and malicious criminal acts.”

After hiring experts to combat the cyber-attacks, the district is now investigating ways in which its cyber-defenses can be strengthened against future assaults. 

Nearly a quarter of the district’s students are currently engaging in Valparaiso Community Schools’ remote learning option.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Elderly People in the UK Lost Over £4m to Cybercrime Last Year

Elderly People in the UK Lost Over £4m to Cybercrime Last Year

Cyber-criminals stole more than £4m from elderly people in the UK in the financial year 2018-19, data received by the charity Age UK has revealed.

A freedom of information (FOI) request submitted by the charity to the UK’s national fraud reporting center, Action Fraud, showed that the police received 4173 reports of cybercrime from people aged 55+ from April 2018 to March 2019. Of those that became victims, a total loss of just over £4m was recorded. Those in this age group represented 19% of the overall number of reported cybercrime victims in this period.

Prominent examples of cybercrime included phishing, investment fraud, identity theft, fraudulent adverts and blackmail.

Worryingly, the FOI request also revealed that elderly people have been heavily targeted by COVID-19 related fraud in recent months. Of the 3162 instances of COVID-related fraud and cybercrime reported to Action Fraud between March 23 and July 31 2020, 701 involved a victim aged 55+; total losses for these elderly victims amounted to £2.4m in the four months.

The most common forms of COVID-related scams included purchases of fake PPE equipment and phishing texts and emails purporting to be from government and health bodies.

Age UK said cyber-criminals have taken advantage of the increasing number of elderly people relying on the internet for everyday services such as shopping as well as to stay in contact with friends and family during lockdown, in many cases for the first time.

Caroline Abrahams, charity director at Age UK, commented: “During lockdown, the majority of us relied on the internet to stay connected and we know that some older people were also encouraged to go online for the first time. That is  hopefully something they have enjoyed and benefited from and will want to continue now lockdown is being eased. However, unfortunately we also know that cyber-criminals were very active in exploiting the situation, seeking to con older people out of their hard-earned cash.

“Online crime is often highly sophisticated and tough to spot so anyone can be taken in, but if you are new to the internet and learned to use it in a rush, with little support, you are potentially more vulnerable to being caught out.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Facebook Takes Down More Beijing-Backed Fake Accounts

Facebook Takes Down More Beijing-Backed Fake Accounts

Facebook has been forced to remove over 150 fake accounts tied to Beijing’s efforts to influence public opinion in south-east Asia.

The social media giant describes influence operations like this as “coordinated inauthentic behavior” (CIB), as those behind them use fake profiles to “mislead people about who they are and what they are doing.”

In total, Facebook removed 155 accounts, 11 Pages, nine Groups and six Instagram accounts for violating its policy against CIB on behalf of a government or foreign entity

Although those coordinating the campaign used VPNs and other techniques to try and stay hidden, they were traced back to the Fujian province of China. They sought both to amplify their own content and like and comment on the posts of others, particularly about naval activity in the geopolitical flashpoint of the South China Sea.

“In south-east Asia where this network focused most of its activity, they posted in Chinese, Filipino and English about global news and current events including Beijing’s interests in the South China Sea; Hong Kong; content supportive of President Rodrigo Duterte and Sarah Duterte’s potential run in the 2022 Presidential election; criticism of Rappler, an independent news organization in the Philippines; issues relevant to the overseas Filipino workers; and praise and some criticism of China,” noted head of security policy, Nathaniel Gleicher.

“In the US, where this network focused the least and gained almost no following, they posted content both in support of and against presidential candidates Pete Buttigieg, Joe Biden and Donald Trump.”

He claimed that over 133,000 accounts followed the fake Pages and over 66,000 people joined at least one of the Groups, with 150 accounts following the fake Instagram profiles.

This is the second time China has been implicated in CIB: a year ago a small network of fake accounts was revealed to be trying to influence public opinion on the Hong Kong protests.

The Chinese government has also been blamed for orchestrating similar campaigns on Twitter.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#COVID19 Pushes More Fraud Online

#COVID19 Pushes More Fraud Online

Fraudsters are increasingly moving online to cash-in on the COVID-19 pandemic, although overall unauthorized fraud losses dropped in the first half of 2020, according to UK Finance.

The banking industry body’s 2020 Half Year Fraud Update revealed some promising headline findings.

Unauthorized fraud losses were down 8% year-on-year to £374.3m, while authorized push payment (APP) losses remained static at around £208m, although the number of APP cases jumped 15% over the period.

However, the bigger picture is that cyber-criminals are turning away from traditional methods of fraud such as contactless (down 20%) and cheque (down 78%) due to the reduced number of face-to-face transactions during the pandemic.

As a result, more fraud is migrating online in phishing emails and texts and unsolicited scam phone calls designed to harvest personal and financial details. These social engineering efforts may include impersonation of government officials, banking staff, airlines and travel agencies, and IT and software providers, UK Finance said.

The bad news is that the impact of these changes in fraud patterns is yet to be fully revealed, as the stolen data in many cases has yet to be used in follow-on fraud.

Elsewhere, UK Finance claimed that e-commerce fraud in the first half of the year, at £183m, was largely the same as in 1H 2019. However, remote banking fraud losses soared 21% to reach £80m, while the number of cases jumped 59% year-on-year to nearly 30,000.

UK Finance said it has also seen a rise in investment scams, with FCA-regulated firms often spoofed in advertising on search engines and social media sites. There’s also been a spike in purchase scams, including sale of counterfeit or non-existent PPE and home testing kits.

UK Finance managing director of economic crime, Katy Worobec, urged the public to stop and think before responding to unsolicited messages or calls.

“Criminals have ruthlessly adapted to this pandemic with scams exploiting the rise in people working from home and spending time online. These range from investment scams promoted on social media and search engines to the use of phishing emails and fake websites to harvest people’s data,” she added.

“The banking industry is working hard to protect customers from this threat, with almost £7 in £10 of fraud prevented in the first half of this year, but we need the public to remain vigilant against scams and remember that criminals are experts at exploiting events like COVID-19 to impersonate trusted organizations.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Zerologon Windows Server Flaw Used in Active Attacks

Zerologon Windows Server Flaw Used in Active Attacks

Microsoft has warned that a critical vulnerability it patched in August is now being actively exploited in the wild, enabling attackers to remotely control a target organization’s Windows domain.

Also known as “Zerologon,” CVE-2020-1472 is a critical elevation of privilege bug affecting Windows 2008 and more recent versions. It exists when an attacker uses the Netlogon Remote Protocol to establish a vulnerable secure channel connection to a domain controller, according to Microsoft.

According to the US Cybersecurity and Infrastructure Security Agency (CISA) it could allow an unauthenticated attacker with network access to a domain controller to completely compromise all Active Directory identity services — and with them the entire network.

In a sign of the criticality of the bug, CISA issued an emergency directive a week ago ordering all federal civilian agencies to patch the flaw by end-of-play last Monday. It poses an “unacceptable risk” to government IT systems, it said in the alert.

Although at the time, only proof-of-concept exploits were circulating, the vulnerability is now being actively used in attacks, Microsoft warned yesterday.

“Microsoft is actively tracking threat actor activity using exploits for the CVE-2020-1472 Netlogon EoP vulnerability, dubbed Zerologon. We have observed attacks where public exploits have been incorporated into attacker playbooks,” it tweeted.

“We will continue to monitor developments and update the threat analytics report with latest info. We strongly recommend customers to immediately apply security updates for CVE-2020-1472. Microsoft 365 customers can use threat and vulnerability management data to see patching status.”

Although many organizations may have delayed patching due to concerns over disruption to legacy apps, Axonius CEO, Dean Sysman, argued that many may not even know they’re running exposed systems.

“Despite having many tools that provide data on assets and networks, these solutions and the data they provide are often siloed, outdated and lack actionable context,” he added.

“Security teams find it nearly impossible to maintain a comprehensive asset inventory and know whether those assets are properly secured. Without this visibility, organizations are at risk — even in the case of known vulnerabilities.”

Scott Caveza, Tenable research engineering manager, urged system administrators to take immediate action.

“Given the flaw is easily exploitable and would allow an attacker to completely take over a Windows domain, it should come as no surprise that we’re seeing attacks in the wild,” he said.

“Administrators should prioritize patching this flaw as soon as possible. Based on the rapid speed of exploitation already, we anticipate this flaw will be a popular choice amongst attackers and integrated into malicious campaigns.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Report Outlines Importance of Providing Engaging User Awareness Training

Report Outlines Importance of Providing Engaging User Awareness Training

The way cybersecurity awareness training is conducted in organizations has a huge bearing on employees’ subsequent security outlook and behaviors, according to a new report from Osterman Research.

The researchers discovered that users who found security training “very interesting” were over 13-times more likely to make “fundamental changes” to how they think about security compared to those who considered the training “boring.”

The survey of 1000 US everyday employees, IT managers and decision makers also found that the quantity of security awareness training given makes a major difference, with the ability of staff to spot and deal with security threats such as phishing and business email compromise improving as more training is provided.

Encouragingly, it appears as though organizations are set to place much greater emphasis on security awareness training going forward, with around 45% of employees surveyed expecting to spend 15 minutes or more per month in training by mid-2021, a substantial rise from 26% in 2020. In addition, this type of training was regarded as just as important as technology in dealing with security threats by respondents.

Despite this, the authors said that although organizations generally want to establish a strong cybersecurity culture, IT, security and business leaders are not effectively conveying that idea to a large proportion of their employees, with senior IT and business management much more enthusiastic about security awareness training than non-management employees.

Overall, the report noted that “security and IT leaders, their staff members, and business leaders are largely onboard with the idea that developing a strong cybersecurity culture is important; everyday employees, however, are much less convinced about the importance of doing so, indicating that the goal of developing a robust security culture has not yet been achieved in most organizations.”

Lisa Plaggemier, chief strategist at MediaPRO, which co-sponsored the research, added: “Security awareness training doesn’t do anyone any good if they sleep through it. You can deliver the best security advice in the world, but if no one is listening, you might as well be talking to a brick wall.

“Good security awareness training should get and keep your attention. That’s what it means to be engaging.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk