Police Warn of Physical IT Risk from Malicious Contractors

Police Warn of Physical IT Risk from Malicious Contractors

Organized crime groups are increasingly looking at ways to physically access IT infrastructure via insiders in contracting firms, police cyber-chiefs have warned.

Shelton Newsham, manager of the Yorkshire and Humber Regional Cyber Crime Team, reportedly told the SINET Global Cybersecurity Innovation Summit last week that gangs are placing their own people in cleaning companies, in order to target corporate networks.

“Exploitation of staff is a key area”, Newsham said, according to CBR.

“Organized crime groups are planting ‘sleepers’ in cleaning companies that a procurement team may look at bidding for. There’s no way of auditing their vetting. They’ll also using people in painting and decorating firms; anyone who has out-of-hours access to a building is fair game.”

Jake Moore, cybersecurity specialist at ESET, argued that both cyber and physical security are crucial to maximizing protection of corporate assets, but that it’s a difficult message to get through to the board, especially given the costs involved.

“The best way to realize a business’s own flaws is to conduct a basic penetration test that involves both physical and cyber-threat vectors, and this will easily highlight where those risks lie,” he added.

“It would be arrogant to think that your business does not have weaknesses, so it is best to test these out using red team professionals who will acknowledge any weak points that need addressing.”

The warnings from Yorkshire police echo those made at Infosecurity Europe last year, when Holly Grace Williams, technical director at Secarmaargued that physical intrusions too often go unreported by staff.

CISOs don’t just have to worry about cyber-criminal gangs exploiting physical access to target IT systems. Last year a former college student pleaded guilty to vandalizing computer equipment at his alma mater, the College of St. Rose in Albany, New York.

Vishwanath Akuthota used a “USB Killer” device he bought online to destroy IT kit with an electrical charge.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Twitter Fixes API Bug That Unmasked Users

Twitter Fixes API Bug That Unmasked Users

Twitter has been forced to take action after discovering malicious actors taking advantage of an API bug to unmask users on the site by getting hold of their phone numbers.

The social network discovered the issue on Christmas Eve last year after detecting a user employing a large network of fake accounts to exploit an API which matches usernames to phone numbers. It’s specifically intended for new users to find people they may already know on the site — as long as they have enabled the “let people who have your phone number find you on Twitter” function and have a phone number associated with their account.

“During our investigation, we discovered additional accounts that we believe may have been exploiting this same API endpoint beyond its intended use case,” Twitter continued.

“While we identified accounts located in a wide range of countries engaging in these behaviors, we observed a particularly high volume of requests coming from individual IP addresses located within Iran, Israel, and Malaysia. It is possible that some of these IP addresses may have ties to state-sponsored actors. We are disclosing this out of an abundance of caution and as a matter of principle.”

The bug may therefore have helped nation state intelligence services obtain the phone numbers of rights activists and others who use Twitter under pseudonyms. It would also have been useful to cyber-criminals for intelligence gathering on high value individuals, whose phone accounts may be useful to target in SIM swap operations.

Fortunately, the social site has now closed this vulnerability down.

“After our investigation, we immediately made a number of changes to this endpoint so that it could no longer return specific account names in response to queries. Additionally, we suspended any account we believe to have been exploiting this endpoint,” it confirmed.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Suffolk iCloud Voyeur Gets 32 Months Behind Bars

Suffolk iCloud Voyeur Gets 32 Months Behind Bars

A Suffolk man has been jailed for several years after hacking the iCloud accounts of several women and sharing their intimate pictures online.

Tony Spencer, 38, of Victoria Hill, Eye, was sentenced at Basildon Crown Court late last week after admitting his guilt in September 2019 to these cases and secretly filming women and children getting changed in a Norfolk leisure center.

He received a 32-month jail term for nine counts of voyeurism, five counts of taking indecent photographs of a child and 12 counts of Computer Misuse Act offences.

Spencer was caught after a woman came to Essex police reporting that her iCloud account had been hacked and explicit photos of herself posted online. That set in motion an investigation which revealed multiple suspects across the region were hacking hundreds of victims in a similar manner.

Several searches of Spencer’s home in 2017 by the Essex Cyber Crime Team revealed computers containing the images belonging to 12 victims and software he used to access the accounts, presumably either to brute force or phish their passwords.

Detective sergeant Ian Collins of the cybercrime unit said the case highlights why computer users should switch on two-factor authentication (2FA) to protect their accounts.

“Spencer went to extreme lengths to obtain images of young women and children without permission for his own and others’ sexual gratification. His secret lifestyle went hidden for many years until we received just a single report that revealed much, much more,” he explained.

“He used his specialist knowledge to hack his unsuspecting victims’ accounts and then accessed their most intimate photographs for his own sexual purpose and that of others. Spencer was not able to access any accounts secured with 2FA as he would have needed the mobile phone of the victims at the same time.”

Spencer has also been placed on the Sex Offenders’ Register for life and was given a Sexual Harm Prevention Order for 10 years. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk