Uncomplicated Cyber Insurance Program Launched

Uncomplicated Cyber Insurance Program Launched

Cowbell Cyber has announced the launch of a cyber insurance program designed to deliver coverage to address the diversity of incidents under the ‘cyber’ category.

Named Prime 250, Cowbell Cyber said this is intended to deliver “on the need for clarity, simplicity, speed and flexibility” in the space, especially as research has shown that “not understanding coverage” (63%) and “cost” (46%) remain obstacles to the adoption of cyber insurance. 

“For years, policyholders have raised concerns about the complexity and opacity of cyber insurance. Meanwhile, cyber-incidents are becoming more frequent and diverse,” said Trent Cooksley, co-founder and COO at Cowbell Cyber. “We have created Prime 250 with the explicit intent to make cyber insurance easy and bring clarity to coverages and policy terms so that every business can benefit from the financial protection delivered by cyber insurance.”

In an email to Infosecurity, Caroline Thompson, head of underwriting at Cowbell Cyber, said the intention was to simplify the application process, so it is now 100% online and only requires the company name and its domain name. She said: ”All quotes issued by Cowbell are bindable; this eliminates any delay. We see businesses in need of a Certificate of Insurance (COI) for contractual reasons. We can deliver policy and COI in minutes. Nobody else can do this in the market.

“There are side cases that might be automatically referred to our underwriting team, this is all online, triggered automatically with all information required to make a timely decision. This is what we call Prime 250, a Cyber Insurance 2.0 solution.”

In particular, Prime 250’s 25 cyber-specific coverages are organized to mirror the way businesses experience cyber-incidents: first party loss, first party expense and liability. Policyholders receive value from day one of their policy, with access to Cowbell Factors for risk rating and industry peer benchmarking, while Cowbell offers recommendations to remediate identified risk exposures.

Thompson said the intention was to close the gap “on immediate issues related to cyber being bundled with other commercial insurance policies such as a Property & Casualty policy or Business Owner Policy as an add-on (endorsement).”

“Most importantly, we are proud to bring transparency to policyholders,” she added. “With Cowbell Factors and Cowbell Insights, users get a view into their cyber-risk exposure and how to improve their security posture as they get a cyber insurance quote so they can understand how the quote and the policy are built. This provides value on day one and every day after.”

 


Join our panel discussion on cyber insurance, as part of the Online Summit, taking place 12pm EDT/5pm BST. Register here.


Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Six Indicted for Bribing Amazon Workers in $100m Scheme

Six Indicted for Bribing Amazon Workers in $100m Scheme

Six individuals have been indicted on conspiracy charges after they allegedly bribed Amazon workers to gain an unfair competitive advantage on Amazon Marketplace estimated to be worth $100m.

The alleged co-conspirators are Ephraim Rosenberg, 45, of Brooklyn, New York; Joseph Nilson, 31, and Kristen Leccese, 32, of New York; Hadis Nuhanovic, 30, of Acworth, Georgia; Rohit Kadimisetty, 27, of Northridge, California; and Nishad Kunju, 31, of Hyderabad, India.

They’ve been charged with conspiracy to use a communication facility to commit commercial bribery, conspiracy to access a protected computer without authorization, conspiracy to commit wire fraud and wire fraud.

Acting as consultants to third-party sellers on the marketplace, they are accused of bribing Amazon staff and contractors to the tune of over $100,000.

In return, the employees reinstated products and merchant accounts blocked by Amazon — including items flagged for violating IP laws, products removed after customer complaints and accounts suspended after manipulating product reviews.

The insiders are also alleged to have suspended competitor accounts, shared intelligence on these businesses and provided info on Amazon algorithms which allowed the six to flood competitor items with negative reviews.

The bribed employees are also said to have provided access to “Amazon’s highly confidential standard operating procedures and algorithms,” and circumvented internal controls to increase storage limits in warehouses, allow sales of restricted products and provide inside info on the most successful ad campaigns and profitable product listings.

As well as providing consultancy services to third-party sellers, Nilson, Leccese and Nuhanovic are also said to have operated and sold through their own accounts on Amazon Marketplace. Kunju was initially bribed as a seller-support worker before becoming an external consultant who recruited and bribed former colleagues, it is alleged.

“As the world moves increasingly to online commerce, we must ensure that the marketplace is not corrupted with unfair advantages obtained by bribes and kick‑backs,” said US attorney Brian Moran. “The ultimate victim from this criminal conduct is the buying public who get inferior or even dangerous goods that should have been removed from the marketplace. I commend the investigators and cybersecurity experts who have worked to identify and indict those engaged in these illegal scheme.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Activision Denies Hacking Claims Over Leaked Accounts

Activision Denies Hacking Claims Over Leaked Accounts

Around half a million Activision account details have been breached, after an apparent credential stuffing attack.

According to a series of user reports on social media, detailed by Dexerto, attackers leaked the user credentials and locked users out of their accounts too.

Activision, whose games include Call of Duty, the Tony Hawk skateboarding series and Crash Bandicoot, do not have two-factor authentication offered on accounts, and users encouraged each other to change passwords. In a statement, Activision said “reports suggesting Activision Call of Duty accounts have been compromised are not accurate.” It recommended players “take precaution to protect their Activision accounts, as well as any online accounts, at all times.”

A support blog featured advice on basic cybersecurity steps, such as using strong passwords and password re-use.

Martin Jartelius, chief security officer at Outpost24 said while this is much lower than the 77 million accounts exposed in the Playstation Network breach of 2011, this is still a substantial breach. “In parts the cleanup will be a large undertaking for Activision, we can only hope backups allow restoring original contact data, resetting access and managing the users who still cannot regain access which should be a smaller group,” he said. 

Boris Cipot, senior security engineer at Synopsys, said: “Gaming is not simply entertainment for children, it is a thriving industry with highly sophisticated technology. For example, games now offer highly advanced simulators whereby individuals can embody a soldier, fighter pilot or even a football player. With the support of Virtual Reality technology, these games can become even more realistic.

“Moreover, we are witnessing a rise in E-sports, where tournaments and winners amass large pots of money. As there is a lot of money involved, it is normal for cyber-criminals to target known game brands to access user accounts.“

He suspected that the access is used for financial gain, rather than for account access, as “many accounts have a collection of virtual goods which can be acquired by gamers for real money.” Cipot said cyber-criminals could gain profits just by selling one or many accounts which hold valuable virtual goods. “In gaming, the real money lies in selling virtual goods,” he said.

Dean Ferrando, lead systems engineer (EMEA) at Tripwire, recommended those within the gaming industry to take this opportunity to review their own security controls to ensure they are adequately deployed. “A security team should be able to easily assess how many of what kind of assets are on the network, how securely they are configured, and what the vulnerability posture of those assets are,” he said. “All organizations should use this as a wakeup call to ensure that security is not just a check box for compliance. Organizations like Activision want to provide a safe and secure space for gamers and not a game over experience.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Just 13% of SMEs Have Cyber Insurance

Just 13% of SMEs Have Cyber Insurance

Less than 13% of small and medium-sized businesses (SMBs) have cyber-insurance, potentially leaving large numbers exposed to the serious financial impact of online attacks, according to GlobalData.

The data analytics and consulting firm claimed in its 2020 UK SME Insurance Survey that the mid-market represents a potentially lucrative one for insurers, given the relatively small number currently covered for cyber-related losses.

GlobalData senior analyst, Daniel Pearce, argued that the need for specialized insurance coverage was even greater as distributed working has expanded the corporate attack surface and created security gaps which attackers are keen to exploit.

“The pandemic has increased businesses’ reliance on technology in order to operate during lockdowns, while social distancing guidelines continue to promote home working. With this growing dependence on technology comes an increase in cyber-risk,” he added.

“Given this, the need for cyber-insurance has arguably never been higher. Traditionally, cyber-insurance has seen greater levels of uptake and interest among mid-market and larger corporations, but the pandemic has accelerated the need for smaller business to purchase cover as well.”

Healthcare has been one of the sectors hardest hit by cyber-attacks, especially ransomware, over recent months. In fact, a German patient died recently after an attack forced her to be transferred to a different hospital, delaying treatment by an hour.

Accordingly, in the health and social work sector, cyber-insurance coverage is almost double the average, at 26%.

The findings chime with a poll of UK businesses by insurer Gallagher earlier this year which found that 82% did not have any specialized coverage for cyber-related incidents. Crucially, nearly half (46%) of respondents from mid-sized firms said they thought that cyber-attacks are “mainly an issue for bigger organizations.”

Yet despite the eye-catching headlines of major security incidents at large multi-nationals that cost millions of dollars to fix, a large number of attacks seek out the lower hanging fruit of smaller businesses.

Ransomware was the number one cause of insurance claims in North America in the first half of 2020, according to Coalition.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FinCEN Leak Exposes $2tn of Money Laundering Activity

FinCEN Leak Exposes $2tn of Money Laundering Activity

Global financial institutions have largely failed over recent years to prevent mass money laundering linked to Russian oligarchs, mobsters and Conservative Party donors, according to a new trove of leaked documents.

Over 2000 suspicious activity reports (SARs) filed with the US government’s Financial Crimes Enforcement Network (FinCEN) between 2000 and 2017 were leaked to various publications, in an apparent whistleblowing effort designed to highlight the scale of criminal activity in this area.

SARs are filed by banks and others when illegal activity such as money laundering is suspected. Although this doesn’t require the lender to stop doing business with their clients, banks need to know who their account holders are and to stop any activity that may break international money laundering laws.

However, the sheer scale of the sums involved seem to highlight a major problem area for global financial institutions: the SARs from this leak relate to around $2 trillion in transactions, but are just a small portion of the total reports filed during the 17-year period.

In fact, part of the challenge for the industry is that the scale of the money laundering challenge is still little understood. Accurate statistics are hard to come by, although the UN estimates it could be worth as much as 5% of global GDP ($7 trillion). In the EU, only an estimated 1% of illegal proceeds are seized by authorities.

Among the shady dealings uncovered in the FinCEN leak are evidence that an ally of Russian President Vladimir Putin had ties to a major Conservative Party donor, while other oligarchs avoided Western sanctions by buying art works in London, according to the BBC. Former Trump campaign manager, Paul Manafort, is also named in a SAR.

HSBC, Barclays Bank, JP Morgan, Standard Chartered and Deutsche Bank were all named as helping to move dirty money around the world.

The UK has been named a “higher risk jurisdiction” by FinCEN because of the large number of firms based in the country (3000+) that are named in the leaks.

The leak itself appears to have come from FinCEN given the SARs were originally issued by multiple different lenders. As such, the incident can be filed along with other major whistleblowing discoveries such as the Panama Papers and the Paradise Papers.

FinCEN reacted angrily to the incident, claiming to have referred it to the Department of Justice and the Treasury’s Office of Inspector General.

“As FinCEN has stated previously, the unauthorized disclosure of SARs is a crime that can impact the national security of the United States, compromise law enforcement investigations, and threaten the safety and security of the institutions and individuals who file such reports,” it said in a brief statement.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Online Retailers Urged to Take Action on Platform Security

Online Retailers Urged to Take Action on Platform Security

Online retailers, particularly those still using the Magento 1 e-commerce platform, need to take action fast to update their security posture, according to Sonassi, which hosts Magento.

Magento 1 officially reached its end-of-life at the end of June and is therefore no longer supported by security patches.

Last week it was revealed that around 2000 e-commerce stores running the Magento 1 software were targeted by Magecart attacks over the previous weekend in the largest recorded campaign of its kind. It is estimated that tens of thousands of customers unwittingly had their payment details stolen as a result of the attacks.

Sansec’s Threat Research Team, which revealed the attacks, suggested that attackers may have found a new way to compromise their servers — potentially exploiting a zero-day in Magento 1 that was advertised online. It warned that if this is the case, 95,000 stores could also be exposed to the exploit, as they are running Magento 1.

James Allen-Lewis, development director at Sonassi, commented: “Unfortunately, this incident should not come as a surprise. As far back as last year, warnings had been issued about the likelihood of attacks on Magento 1 stores, and as the deadline to end-of-life grew closer, these warnings have gotten louder. While cyber-threats do exist on Magento 2, those remaining on Magento 1 are no longer supported with security patches, and therefore a prime target for hackers.”

Allen-Lewis added that due to the accelerated shift to e-commerce during the COVID-19 pandemic, it is more important than ever that retailers secure their digital shopping sites. The prospect of a second wave of the virus and localized lockdowns are likely to boost demand on this channel even further.

Allen-Lewis said: “It’s critical retailers deploy basic cybersecurity best practices. Simple things such as regular updates to your passwords and multi-factor authentication are often overlooked. Additionally, retailers should be locking down the administrator interface by IP address. This simple change makes it much harder for hackers to get near this critical part of the store.

“Many attacks involve files being added or changed on a website. It is vital you monitor your log for any suspicious file activity. Furthermore, run regular audits on admin accounts and keep admin access to a minimum. You should always know who has access to your website.

“Finally, ensure you scan your website regularly for indicators of compromise. This will give you a much stronger insight into the security posture of your business.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk