US Bank Slammed for “Vague and Deceptive” Breach Disclosure

US Bank Slammed for “Vague and Deceptive” Breach Disclosure

American bank Fifth Third has come under fire for sending customers a cryptic breach disclosure letter judged to be “vague and deceptive” by a consumer group.  

Fifth Third wrote to customers after discovering that at least two of its employees had stolen customer information and provided it to a third party. Data exposed included names, Social Security numbers, addresses, phone numbers, dates of birth, mothers’ maiden names, driver’s license information, and account numbers.

The thefts began in the summer of 2018, and those responsible have since been terminated by the company. Although it hasn’t been confirmed that the employees who pulled this inside job later sold the stolen data on the dark web, it’s only logical to conclude that they stood to profit in some way from their high-risk actions. 

The bank, which is headquartered in Cincinnati, Ohio, at Fifth Third Center, has not specified how many customers were impacted by the incident or how many former employees were fired for passing out customers’ personal data.  

In a written statement, Fifth Third said: “We have notified the limited number of customers who may be impacted. We will provide identity theft monitoring to them at no cost.”

The head of the Consumer Federation of America slammed Fifth Third’s enigmatic letter to customers disclosing the data breach.

Jack Gillis, executive director of the Washington, DC–based non-profit consumer advocate, said: “Fifth Third is only telling half the story—it’s vague and deceptive to customers because it’s not just their Fifth Third accounts that will be impacted.” 

A breach notification letter sent to select consumers which reassured them that the bank had “not detected any fraudulent activity on your accounts” was criticized by Gillis as misleading. He pointed out that whoever had access to the stolen data could misuse it in ways that wouldn’t be detected by the bank.

The illicitly obtained personal data, which Gillis said could now be on sale on the dark web, could be purchased by criminals and used to set up credit accounts with banks other than Fifth Third. Such accounts could be used to run up fraudulent charges that wouldn’t be detected until they came on the radar of credit reporting agencies.  

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Great Britain at Odds over Police Use of Facial Recognition Technology

Great Britain at Odds over Police Use of Facial Recognition Technology

Great Britain’s three nations are not in agreement over the use of facial recognition technology by police forces.

The technology, which can be legally used by police in Wales, was officially introduced by England’s Metropolitan Police Service in East London yesterday, amid a peaceful protest by Big Brother Watch

Use of the technology by English police forces has not been debated in parliament or approved by elected officials. 

By contrast, Police Scotland announced yesterday that its plans to roll out facial recognition technology by 2026 have been put on hold pending a wider debate about the implications of its use. 

Their decision comes in the wake of a report published on Tuesday, February 11, by a Scottish government committee, which concluded that facial recognition technology is “currently not fit for use” by Police Scotland.

The Justice Sub-Committee on Policing informed Police Scotland that the force must demonstrate the legal basis for using the technology and its compliance with human rights and data protection legislation before they can start using it.

In a report that was part of the committee’s inquiry into the advancement of the technology, the committee wrote: “The use of live facial recognition technology would be a radical departure from Police Scotland’s fundamental principle of policing by consent.”

The committee warned that the facial recognition technology was “known to discriminate against females and those from black, Asian and ethnic minority communities.”

Committee convener John Finnie said: “It is clear that this technology is in no fit state to be rolled out or indeed to assist the police with their work.

“Current live facial recognition technology throws up far too many ‘false positives’ and contains inherent biases that are known to be discriminatory.”

Police Scotland Assistant Chief Constable Duncan Sloan said it would now conduct a public consultation on the live software and keep a “watching brief on the trialling of the technology in England and Wales.”

In September 2019, Cardiff’s high court ruled that police use of automatic facial recognition technology to search for people in crowds is lawful. The technology is currently being used by South Wales police.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#teissLondon2020: Supply Chain Challenge Can Be Contained

#teissLondon2020: Supply Chain Challenge Can Be Contained

Speaking on a panel at the TEISS conference in London on the theme of threats in the supply chain, chair Raef Meeuwisse asked where the supply chain sits in a company’s overall risk.

Mike Seeney, head of supply chain information risk at Pinsent Masons, said that it is typically very high, as it is common that you will be breached via social engineering or the supply chain. “In the last few years we have had advances in technology, and the best way is through people or the supply chain,” he said. “This is a dedicated function and you need to have recognition of that.”

Quentyn Taylor, director of information security at Canon EMEA, said that this is now part of infosecurity risk, and while the infosec team should own the risk, they may not rate it too highly. “We trust third parties as we buy from them, but we should consider the third parties of the third parties,” Taylor said.

Holly Grace Williams, technical director at Secarma, said that the conversation should be on where you draw the line, and who takes ownership of the risk, while Naina Bhattacharya, director of cybersecurity for EMEIA at EY, said that, 10 years ago, this sort of risk was being taken seriously by payment card companies as they saw fraud, but the introduction of consumer products and compliance frameworks has changed attitudes.

Asked by Meeuwisse about how far contracts can protect you, Taylor said that “virtually not at all” as contracts “can be a useful way to start a fire” as ultimately the company who offers a contract has not got your back.

In order to better protect yourself, Bhattacharya said that you should have a foundation in place, and she acknowledged that this “can be a big step forward” but a way for you take care of risk.

Focusing briefly on the theme of Huawei, Meeuwisse said that there is guidance offered from government, but acknowledged that global standards are needed.

Concluding, Bhattacharya said that supply chain has “been a problem for a while and will continue to be one” while Williams recommended reviewing what level of access you’re sharing, and Taylor suggested picking “a simple model and be prepared to change” to follow a way of working.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#teissLondon2020: Tech is Not Neutral and Needs Ethical Frameworks

#teissLondon2020: Tech is Not Neutral and Needs Ethical Frameworks

At The European Information Security Summit in London, Dr Stephanie Hare, author of the forthcoming book Technology Ethics, reflected on the need for ethical frameworks in technology.

Technology ethics engages with a problem that no one has solved to anyone’s satisfaction, Dr Hare said. That problem is how we create and use technologies so that they deliver maximum benefit and minimum harm.

Technology is not neutral, she added, and technology ethics surrounds all of us, so “there is no such thing as being ‘neutral’ on technology ethics.

“Every time you want to introduce something, the positive effects may have negative effects elsewhere – so how do you balance that out and think it through ahead of time?”

An ethical lens is therefore vital in the production and application of technology, and whilst Dr Hare admitted that technical ethics is not the answer to all problems, it is a tool that can help create better technologies, involves everyone and aligns technology/people with key values.

“I’m an optimist,” Dr Hare concluded. “I think we can do better and there are a lot of good opportunities for technology to be a better source for society. Right now, we have to move beyond a ‘Hippocratic Oath’ for tech. This group [security professionals] in particular has so much to contribute to the next generation of computer engineers and scientists, to people looking to make a buck in tech, and to law makers who, with the best will in the world, don’t have time to develop expertise [in tech ethics] and so need a roadmap.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Canadian Cabinet Ministers Get Hacking Hotline

Canadian Cabinet Ministers Get Hacking Hotline

An around-the-clock phone line to report suspected cyber-attacks has been created for federal cabinet ministers in Canada.

Newly released documents show that officials at the Canadian Centre for Cyber Security (CCS) set up the 24/7 telephone service last year to help ministers respond swiftly to possible security breaches and hacking incidents. 

The cyber-reporting hotline is operated by the CCS, a division of the Communications Security Establishment (CSE), which is the Government of Canada’s national cryptologic agency.

According to a confidential memo circulated to ministers, the hotline was set up to act as a “front-line response to address compromise and limit damage.” Ministers are advised to call it if they suspect that their ministerial, parliamentary, or personal email has been compromised or if their social media accounts are hacked. 

A copy of the memo was obtained by The Canadian Press via the Access to Information Act. However, due to the sensitivity of the topic, only parts of the circular were revealed to the media. 

The memo was part of a larger briefing package regarding ministerial security that was put together in August 2019. It was prepared by Prime Minister Justin Trudeau’s then national security and intelligence advisor Greta Bossenmaier for Privy Council clerk Ian Shugart. 

The CSE said the phone service was set up in advance of the October federal election and “is still operational today.” 

Shugart was advised in August that all cabinet members had registered for the hotline service, following online security guidance given to them at a CSE briefing in March.

The CSE would not reveal how many incidents had been reported by ministers since the hotline was made operational. 

“Due to operational security reasons, we are unable provide a specific breakdown of the incidents reported through the hotline, but we can confirm that the service was used effectively by ministers, as well as political parties throughout the 2019 general election,” the CSE said.

“As per Cyber Centre standard policy, we do not comment on specific meetings with individual political parties, candidates and their staff, nor do we comment on any specific incident.”

A round-the-clock phone line to report suspected cyber-attacks has been created for federal cabinet ministers in Canada.

Newly released documents show that officials at the Canadian Centre for Cyber Security (CCS) set up the 24/7 telephone service last year to help ministers respond swiftly to possible security breaches and hacking incidents. 

The cyber-reporting hotline is operated by the CCS, a division of the Communications Security Establishment (CSE) which is the Government of Canada’s national cryptologic agency.

According to a confidential memo circulated to ministers, the hotline was set up to act as a “front-line response to address compromise and limit damage.” Ministers are advised to call it if they suspect that their ministerial, parliamentary or personal email has been compromised or if their social media accounts are hacked. 

A copy of the memo was obtained by The Canadian Press via the Access to Information Act. However, due to the sensitivity of the topic, only parts of the circular were revealed to the media. 

The memo was part of a larger briefing package regarding ministerial security which was put together in August 2019. It was prepared by Prime Minister Justin Trudeau’s then national security and intelligence advisor Greta Bossenmaier for Privy Council clerk Ian Shugart. 

The CSE said the phone service was set up in advance of the October federal election and “is still operational today.” 

Shugart was advised in August that all cabinet members had registered for the hotline service, following online security guidance given to the at a CSE briefing in March.

The CSE would not reveal how many incidents had been reported by ministers since the hotline had been operational. 

“Due to operational security reasons, we are unable provide a specific breakdown of the incidents reported through the hotline, but we can confirm that the service was used effectively by ministers, as well as political parties throughout the 2019 general election,” the CSE said.

“As per Cyber Centre standard policy, we do not comment on specific meetings with individual political parties, candidates and their staff, nor do we comment on any specific incident.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#teissLondon2020: ICO Outlines Expectations for 2020 and Beyond

#teissLondon2020: ICO Outlines Expectations for 2020 and Beyond

Speaking at The European Information Security Summit in London, Stephen Eckersley, director of investigations at the Information Commissioner’s Office, outlined the privacy watchdog’s expectations for 2020 and beyond with particular focus on regulations and data protection.

“We are still coming to terms with our new [regulatory] powers,” Eckersley said, “and we are still learning how to apply them – there are a lot of them.”

The ICO expects to face increased expectations from the public, industry, other regulators, law enforcement agencies and governments with regards to being an effective and relevant regulator, he added.

The ICO is the lead supervisory authority on a number of current GDPR-related investigations, Eckersley explained, and will soon be submitting those cases to various EU counterparts, whilst the ICO will also be involved in post-Brexit negotiations relating to data protection.

“That will include the arrangements under cooperation and coordination – it’s too early to say what those arrangements are going to look like – however, from our perspective, securing arrangements that are very similar to the current ones under GDPR would be advantageous for the UK.”

In terms of the volume of data breach reports, the ICO does not expect to see a significant rise over this year and next year, Eckersley said, but the issue of privacy rights surrounding emerging technology will prove a significant challenge.

Lastly, the main challenge for the ICO will be “helping UK citizens stay safe, because personal data, as a commodity, is increasing in value. Organized crime groups are moving into cybercrime, as are state actors, because they recognize that personal data is of value and they can hold organizations to ransom.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#teissLondon2020: Security Requires Sound Storytelling, Says Thom Langford

#teissLondon2020: Security Requires Sound Storytelling, Says Thom Langford

At The European Information Security Summit in London, Thom Langford, founder of TL(2) Security, said that effective storytelling is important to security professionals if they want to evoke reactions, behaviors and actions from others.

“Stories are important to us as security professionals, because, to be blunt, we’re normally really bad at putting across information to people who are not security professionals.”

If we focused more on telling stories, Langford added, we would actually generate an experience.

“When people experience things, they create a visceral response in their bodies and they start to remember things.”

Langford cited an equation that security professional can adopt to better translate important security topics. The equation is: value (the knowledge you have and wish to impart) plus story (the best way of imparting the value) equals experience (the memorable thing that allows people to absorb the information you are sharing).

“Storytelling is as old as time,” Langford concluded, “and it doesn’t matter if it’s a short story or a longer story, what’s important is that people learn, understand and then are able to impart knowledge onto others.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#teissLondon2020: NCSC Shares Six Tips for Secure Password Management

#teissLondon2020: NCSC Shares Six Tips for Secure Password Management

Speaking at The European Information Security Summit in London, Helen L, technical director for sociotechnical security at the National Cyber Security Centre, discussed strategies for effective password management within the enterprise.

Helen L challenged common, traditional password management strategies, saying that “what looks good in theory and on paper, may not work in the real world.”

If a person who typically has around 50 different passwords across their work and home life conscientiously followed standard security advice, they would be expected to remember the equivalent of the order of nine shuffled decks of cards, she said.  

“I don’t think the average person using passwords would be able to do that,” she added, and traditional password security policies often lead to people using workarounds (such as reusing passwords, writing passwords down, sharing passwords, etc) that result in weaker security than to begin with.

Therefore, different approaches to password management are needed, Helen L said, highlighting six pieces of advice that the NCSC is promoting.

Tip one: Reduce your organization’s reliance on passwords

  • Passwords have been the default authentication method for too long and often used when another method is more suitable

Tip two: Implement technical solutions

  • Your system’s security should always rely on effective technical defenses rather than user behavior and so solutions should be used to remove the burden from users

Tip three: Protect all passwords

  • While all passwords should be protected, the accounts they protect are not all the same, so time and effort should be spent on accounts that contain extra privileged information

Tip four: Help users cope with password overload

  • Many of the issues around passwords are a consequence of burdens placed on users

Tip five: Help users generate better passwords

  • Too much emphasis has been placed on password generation as a defense mechanism, so provide users with support in password creation

Tip six: Key messages for training

  • Repeating the usual messages over and over again is not effective – instead, focus on the areas where users’ decisions have the most impact and make training useful and relevant

To conclude, Helen L said: “When you’re thinking about security in your organization, try to think of it from the perspective of the user.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FBI: BEC Losses Soared to $1.8 Billion in 2019

FBI: BEC Losses Soared to $1.8 Billion in 2019

Losses from business email compromise (BEC) attacks soared by hundreds of millions of dollars over the past year, to once again account for half of all cybercrime losses reported to the FBI.

BEC scammers made nearly $1.8 billion in 2019, over half the $3.5 billion total, according to the FBI’s 2019 Internet Crime Report. That’s up from around $1.3bn and a total of $2.7bn in 2018.

A recent evolution in BEC tactics has seen scammers impersonate regular employees rather than C-level execs.

“In this type of scheme, a company’s human resources or payroll department receives an email appearing to be from an employee requesting to update their direct deposit information for the current pay period,” the report explained. “The new direct deposit information generally routes to a pre-paid card account.”

The second biggest earning category of cyber-threat was romance scams, which netted over $475 million, followed by “spoofing” at $300m.

Ransomware was way down in the bottom half of the table with $9m in losses, up significantly from $3.6m in 2018. However, the usual caveats apply that this calculation doesn’t include “lost business, time, wages, files, or equipment, or any third party remediation services acquired by a victim.”

The FBI also admitted that many victims do not report ransomware losses to the Bureau.

When measured according to numbers of reported victims rather than financial losses, phishing (114,702) came top, followed by non-payment/non-delivery (61,8332), and extortion (43,101).

BEC was down in fifth place (23,775) with ransomware even further behind with just 2047 reported cases in 2019 — highlighting the scale of under-reporting.

The FBI also singled out tech support fraud as a growing problem, with some recent complaints involving criminals posing customer support for well-known travel companies, banks and even virtual currency exchanges.

“In 2019, the IC3 received 13,633 complaints related to tech support fraud from victims in 48 countries,” the report said. “The losses amounted to over $54 million, which represents a 40% increase in losses from 2018. The majority of victims reported to be over 60 years of age.”

Total reported cybercrime losses have tripled over the past five years, from just $1.1bn in 2015, amounting cumulatively to $10.2bn for the period.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Fixes 99 Problems This Patch Tuesday

Microsoft Fixes 99 Problems This Patch Tuesday

Microsoft has fixed almost a century of CVEs this month, although experts suggest the workload shouldn’t be too hard on admins.

The 99 vulnerabilities fixed this month feature 12 critical CVEs, including one zero-day, and another four that have been publicly disclosed and so will also need to be prioritized.

The zero-day being exploited in the wild is CVE-2020-0674, a remote code execution flaw in the way the scripting engine handles objects in memory in Internet Explorer. By hosting a specially crafted website designed to exploit the bug, a hacker could gain the same rights as the current user.

Other noteworthy critical bugs include CVE-2020-0729 a remote code execution vulnerability in the way Microsoft processes LNK files.

“Microsoft considers exploitation of the vulnerability unlikely, however, a similar vulnerability discovered last year, CVE-2019-1280, was being actively exploited by the Astaroth trojan as recently as September,” explained Recorded Future senior solutions architect, Allan Liska.

He also highlighted CVE-2020-0662, an RCE vulnerability that could allow any user with a domain account to execute arbitrary code on a victim’s machine at elevated privileges, using a specially crafted packet.

It affects the now-unsupported Windows 7 and Server 2008, as well as later versions.

Todd Schell, senior product manager at Ivanti, argued that despite the sizeable patch load, updating operating systems or browsers “can take the teeth out of the majority of risks this month.”

“The really good news in all of this is 99 CVEs really doesn’t mean a whole lot of extra work for admins this month,” he added.

“The normal updates still apply. OS, browsers, and Office will resolve most of your vulnerabilities from the Microsoft side. SQL and Exchange admins do get a bit of extra work this month as both of those products are included in the updates released.”

Meanwhile, Adobe resolved 17 CVEs for Adobe Reader and Acrobat (APSB20-05), including 12 critical ones, and one critical CVE for Flash Player (APSB20-06). 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk