Google Receives Geofence Warrants

Sometimes it’s hard to tell the corporate surveillance operations from the government ones:

Google reportedly has a database called Sensorvault in which it stores location data for millions of devices going back almost a decade.

The article is about geofence warrants, where the police go to companies like Google and ask for information about every device in a particular geographic area at a particular time. In 2013, we learned from Edward Snowden that the NSA does this worldwide. Its program is called CO-TRAVELLER. The NSA claims it stopped doing that in 2014 — probably just stopped doing it in the US — but why should it bother when the government can just get the data from Google.

Both the New York Times and EFF have written about Sensorvault.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Wawa Breach May Have Compromised More Than 30 Million Payment Cards

In late December 2019, fuel and convenience store chain Wawa Inc. said a nine-month-long breach of its payment card processing systems may have led to the theft of card data from customers who visited any of its 850 locations nationwide. Now, fraud experts say the first batch of card data stolen from Wawa customers is being sold at one of the underground’s most popular crime shops, which claims to have 30 million records to peddle from a new nationwide breach.

On the evening of Monday, Jan. 27, a popular fraud bazaar known as Joker’s Stash began selling card data from “a new huge nationwide breach” that purportedly includes more than 30 million card accounts issued by thousands of financial institutions across 40+ U.S. states.

The fraud bazaar Joker’s Stash on Monday began selling some 30 million stolen payment card accounts that experts say have been tied back to a breach at Wawa in 2019.

Two sources that work closely with financial institutions nationwide tell KrebsOnSecurity the new batch of cards that went on sale Monday evening — dubbed “BIGBADABOOM-III” by Joker’s Stash — map squarely back to cardholder purchases at Wawa.

On Dec. 19, 2019, Wawa sent a notice to customers saying the company had discovered card-stealing malware installed on in-store payment processing systems and fuel dispensers at potentially all Wawa locations.

Pennsylvania-based Wawa says it discovered the intrusion on Dec. 10 and contained the breach by Dec. 12, but that the malware was thought to have been installed more than nine months earlier, around March 4. The exposed information includes debit and credit card numbers, expiration dates, and cardholder names. Wawa said the breach did not expose personal identification numbers (PINs) or CVV records (the three-digit security code printed on the back of a payment card).

A spokesperson for Wawa confirmed that the company today became aware of reports of criminal attempts to sell some customer payment card information potentially involved in the data security incident announced by Wawa on December 19, 2019.

“We have alerted our payment card processor, payment card brands, and card issuers to heighten fraud monitoring activities to help further protect any customer information,” Wawa said in a statement released to KrebsOnSecurity. “We continue to work closely with federal law enforcement in connection with their ongoing investigation to determine the scope of the disclosure of Wawa-specific customer payment card data.”

“We continue to encourage our customers to remain vigilant in reviewing charges on their payment card statements and to promptly report any unauthorized use to the bank or financial institution that issued their payment card by calling the number on the back of the card,” the statement continues. “Under federal law and card company rules, customers who notify their payment card issuer in a timely manner of fraudulent charges will not be responsible for those charges. In the unlikely event any individual customer who has promptly notified their card issuer of fraudulent charges related to this incident is not reimbursed, Wawa will work with them to reimburse them for those charges.”

Gemini Advisory, a New York-based fraud intelligence company, said the biggest concentrations of stolen cards for sale in the BIGBADABOOM-III batch map back to Wawa customer card use in Florida and Pennsylvania, the two most populous states where Wawa operates. Wawa also has locations in Delaware, Maryland, Virginia and the District of Columbia.

According to Gemini, Joker’s Stash has so far released only a small portion of the claimed 30 million. However, this is not an uncommon practice: Releasing too many stolen cards for sale at once tends to have the effect of depressing the overall price of stolen cards across the underground market.

“Based on Gemini’s analysis, the initial set of bases linked to “BIGBADABOOM-III” consisted of nearly 100,000 records,” Gemini observed. “While the majority of those records were from US banks and were linked to US-based cardholders, some records also linked to cardholders from Latin America, Europe, and several Asian countries. Non-US-based cardholders likely fell victim to this breach when traveling to the United States and utilizing Wawa gas stations during the period of exposure.”

Gemini’s director of research Stas Alforov stressed that some of the 30 million cards advertised for sale as part of this BIGBADABOOM batch may in fact be sourced from breaches at other retailers, something Joker’s Stash has been known to do in previous large batches.

Gemini monitors multiple carding sites like Joker’s Stash. The company found the median price of U.S.-issued records in the new Joker’s Stash batch is currently $17, with some of the international records priced as high as $210 per card.

“Apart from banks with a nationwide presence, only financial institutions along the East Coast had significant exposure,” Gemini concluded.

Representatives from MasterCard did not respond to requests for comment. Visa declined to comment for this story, but pointed to a series of alerts it issued in November and December 2019 about cybercrime groups increasingly targeting fuel dispenser merchants.

A number of recent high-profile nationwide card breaches at main street merchants have been linked to large numbers of cards for sale at Joker’s Stash, including breaches at supermarket chain Hy-Vee, restaurant chains Sonic, Buca di Beppo, Krystal, Moe’s, McAlister’s Deli, and Schlotzsky’s, retailers like Bebe Stores, and hospitality brands such as Hilton Hotels.

Most card breaches at restaurants and other brick-and-mortar stores occur when cybercriminals manage to remotely install malicious software on the retailer’s card-processing systems. This type of point-of-sale malware is capable of copying data stored on a credit or debit card’s magnetic stripe when those cards are swiped at compromised payment terminals, and that data can then be used to create counterfeit copies of the cards.

The United States is the last of the G20 nations to make the shift to more secure chip-based cards, which are far more expensive and difficult for criminals to counterfeit. Unfortunately, many merchants have not yet shifted to using chip-based card readers and still swipe their customers’ cards.

According to stats released in November by Visa, more than 3.7 million merchant locations are now accepting chip cards. Visa says for merchants who have completed the chip upgrade, counterfeit fraud dollars dropped 81 percent in June 2019 compared to September 2015. This may help explain why card thieves increasingly are shifting their attention to compromising e-commerce merchants, a trend seen in virtually every country that has already made the switch to chip-based cards.

Many filling stations are upgrading their pumps to include more cyber and physical security — such as end-to-end encryption of card data, custom locks and security cameras. In addition, newer pumps can accommodate more secure chip-based payment cards that are already in use and in some cases mandated by other G20 nations.

But these upgrades are disruptive and expensive, and many fuel station owners are putting them off until it is absolutely necessary. Prior to late 2016, fuel station owners in the United States had until October 1, 2017 to install chip-capable readers at their pumps. Station owners that didn’t have chip-ready readers in place by then would have been on the hook to absorb 100 percent of the costs of fraud associated with transactions in which the customer presented a chip-based card yet was not asked or able to dip the chip.

Yet in December 2016, Visa — by far the largest credit card network in the United States — delayed the requirements, saying fuel station owners would be given until October 1, 2020 to meet the liability shift deadline.

Either way, Wawa could be facing steep fines for failing to protect customer card data traversing its internal payment card networks. In addition, at least one class action lawsuit has already been filed against the company.

Finally, it’s important to note that even if all 30 million of the cards that Joker’s Stash is selling as part of this batch do in fact map back to Wawa locations, it’s highly unlikely that more than a small percentage of these cards will actually be purchased and used by fraudsters. In the 2013 megabreach at Target Corp., for example, fraudsters stole roughly 40 million cards but only ended up selling between one to three million of those cards.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Rolls Out New Bill to Reform NSA Surveillance

US Rolls Out New Bill to Reform NSA Surveillance

US senators have proposed a bill that would drastically reform the surveillance practices of the National Security Agency (NSA) and increase oversight of government surveillance.

Titled The Safeguarding Americans’ Private Records Act, the bill was introduced on Thursday by Senators Ron Wyden, Zoe Lofgren, Pramila Jayapal, Warren Davidson, and Steve Daines. 

According to a statement on Wyden’s website, the changes proposed in the bill will “protect Americans’ rights against unnecessary government surveillance.” 

The bill comes ahead of the March 15 expiration of Section 215 of the Patriot Act, which the National Security Agency “used to create a secret mass surveillance program that swept up millions of Americans’ phone calls.” The phone record program was terminated last year.

The bill prohibits the “warrantless collection of cell site location and GPS information as well as browsing history and internet search history and ensures that the government cannot conduct collection for intelligence purposes that would violate the Fourth Amendment in the criminal context.”

Furthermore, the bill aims to establish the Foreign Intelligence Surveillance Act (FISA) process as the only process by which the government is allowed to carry out surveillance. By doing this, the bill intends to close what it describes as “secret law” loopholes that have allowed the US government to clandestinely conduct surveillance outside the FISA process in the past

Other reforms proposed by the bill are the increase of congressional oversight of government surveillance activities with the addition of new public reporting requirements regarding Americans whose information has been collected under Sections 215 and 702 of the Patriot Act. 

Commenting on the new bill, Jack Mannino, CEO at Virginia-based application security provider nVisium, said: “These are important steps towards protecting the civil liberties and Fourth Amendment rights of citizens. Intelligence agencies do important work, and it’s necessary for them to be able to do their jobs, while preserving legal and moral boundaries. States, such as California, have passed legislation to protect internet privacy, and other states are quickly moving in the same direction. Overreaching surveillance erodes trust in the systems we use and our expectation of privacy.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Major Canadian Military Contractor Compromised in Ransomware Attack

Major Canadian Military Contractor Compromised in Ransomware Attack

A Canadian construction company that won military and government contracts worth millions of dollars has suffered a ransomware attack. 

General contractor Bird Construction, which is based in Toronto, was allegedly targeted by cyber-threat group MAZE in December 2019. MAZE claims to have stolen 60 GB of data from the company, which landed 48 contracts worth $406m with Canada’s Department of National Defense between 2006 and 2015.

In an email to the Canadian Broadcasting Corporation (CBC), a Bird Construction company spokesperson wrote: “Bird Construction responded to a cyber incident that resulted in the encryption of company files. Bird continued to function with no business impact, and we worked with leading cyber security experts to restore access to the affected files.”

MAZE’s modus operandi is to demand a ransom from its victim to secure the return of data that the group has stolen and encrypted. Victims are warned that failure to pay up will result in the data’s publication. If a victim refuses to pay, MAZE’s next move is typically to publish a small quantity of the data it claims to have stolen to show it means business.

According to Emsisoft threat analyst Brett Callow, MAZE has now published data it claims to have stolen from Bird Construction. The published files contain employees’ personal data and information relating to Canadian company Suncor Energy, with which Bird Construction has worked on multiple projects. 

Callow told Infosecurity Magazine: “Maze actually published some of Bird’s data. The files included documents relating to Suncor and records for a couple of Bird employees which included their names, home addresses, phone numbers, banking info, social insurance numbers, tax forms, health numbers, drug and alcohol test results—everything that a criminal would need to steal their identity. And all that info was posted on the clear web where anybody could’ve accessed it.” 

The published data, which Infosecurity Magazine has viewed, consisted of two large PDF files, each relating to a separate Bird Construction employee, plus documents detailing vehicle entry authorization and alcohol and drug testing procedures at Suncor.

Callow added: “The big question is: what else did MAZE get and did any of the data relate to Bird’s government and military contracts?” 

Bird Construction has not said whether a ransom was paid to its cyber-attackers. Callow advised any company that gets hit by ransomware not to pay up.

He said: “There is no way for a company to know that the data will be deleted after a ransom has been paid. In fact, it probably will not be deleted. Why would a criminal enterprise delete data that they may be able to use or monetize at a later date?”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Space Industry to Launch Cybersecurity Portal

US Space Industry to Launch Cybersecurity Portal

Spring 2020 will see the launch of a new US cybersecurity resource designed to protect the space industry. 

Space News reported last Thursday that the Space Information Sharing and Analysis Center, or Space ISAC, is currently in the process of setting up an unclassified portal where companies can share and analyze information on cybersecurity threats. The portal will go live in the tail end of spring. 

The activation of the portal will mark the official start of operations for Space ISAC, which was formally established in April 2019 as a nonprofit organization during a classified session at the 35th Space Symposium in Colorado Springs, Colorado. 

The need to establish a Space ISAC to secure commercial, government, and military space communications from cyber-attacks on global space assets was recognized by the Science & Technology Partnership Forum in 2017. The Forum shared its vision for the organization’s conception in April 2018 at the 34th Space Symposium.

Space ISAC was founded initially by Kratos Defense & Security Solutions. Ten other companies have since joined as founding members, though some wish to keep their connection with the organization under wraps. Firms that have made their membership of Space ISAC public include Booz Allen Hamilton, SES, Parsons Corp, Lockheed Martin, and MITRE, which all joined as founding members.

The senior vice president of Kratos and chairman of the board for Space ISAC, Frank Backes, said that once the new portal is in operation, Space ISAC will work to recruit and vet potential members. The organization is hoping to sign up as many as 200 member companies from the civil, commercial, and national security space sectors.

Annual membership fees will be $10,000 for silver membership, $25,000 for gold, and $50,000 for platinum; however, the organization will consider offering lower rates to small enterprises and startups.

Along with the portal, Backes said that Space ISAC intends to set up a “space systems vulnerability laboratory” for NCC analysts and ISAC members at the National Cybersecurity Center (NCC) in Colorado Springs. 

Space ISAC plans to hold its first ever summit meeting at the NCC’s Cyber Symposium in Denver on June 15 and 16 of this year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Royal Yachting Association Resets Passwords After Breach

Royal Yachting Association Resets Passwords After Breach

The Royal Yachting Association (RYA) is forcing a password reset for all online users after warning some that their data may have been compromised by a third party.

The UK’s national body for all things nautical appears to have moved quickly in response to the discovery.

“We have recently become aware that an unauthorized party accessed and may have acquired a database created in 2015 containing personal data associated with a number of RYA user accounts. The affected information included email addresses and RYA website passwords which were encrypted and therefore not visible,” it explained.

“The affected information included name, email and hashed passwords — the majority held with the salted hash function, which is used to secure passwords. The affected data did not include any financial or payment information and in this stage in our investigation there is no evidence that this data has been misused — it was legacy test data and it appears that the unauthorized party who gained access to a hosted server subsequently deleted that database.”

Despite passwords being salted and hashed, the RYA is taking no chances and will require all web users to choose a new credential. It is also urging members to be on the lookout for potential phishing scams attempting to capitalize on the breach notification.

“Please note that any email from the RYA about this issue (subject: Important notification regarding RYA Account Security) does not contain attachments and does not request your personal data,” it clarified.

“If you receive an email about this issue which suggests you download an attachment, or asks you for information, the email was not sent by RYA and may be an attempt to steal your personal data.”

Several yachters took to an industry forum warning of such an attempt, until they were reassured that the breach notification email was genuine. Some expressed surprise at receiving the email as they aren’t RYA members, although their email address may have found its way onto the “test” database another way.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Chrome and Firefox Clamp Down on Suspicious Behavior

Chrome and Firefox Clamp Down on Suspicious Behavior

Both Chrome and Firefox administrators have had to take action recently to halt the spread of malware via extensions and add-ons.

Google developer advocate Simeon Vincent explained over the weekend that the Chrome Web Store team detected an increase in fraudulent activity earlier in the month attempting to exploit users of the popular browser.

“Due to the scale of this abuse, we have temporarily disabled publishing paid items. This is a temporary measure meant to stem this influx as we look for long-term solutions to address the broader pattern of abuse,” he continued.

“If you have paid extensions, subscriptions, or in app-purchases and have received a rejection for ‘Spam and Placement in the Store’ this month, this is most likely the cause.

Extension developers will not be allowed to update their offerings while these temporary measures last. Those who want to publish an item that has been rejected are urged to reply to the rejection email and request an appeal.

“You may be asked to republish your item, at which point the review should proceed normally. You must repeat this process for each new version while this measure is in place,” said Vincent.

Unfortunately for developers, there’s no immediate end in sight for these temporary measures.

“We are working to resolve this as quickly as possible, but we do not have a resolution timeline at the moment. Apologies for the inconvenience,” concluded Vincent.

The news comes as rival browser Firefox experiences its own security issues. Mozilla administrators have begun removing scores of dodgy add-ons from the Mozilla Add-on (AMO) portal, and disabling any found in existing browser deployments.

Many of those marked for attention are thought to have been executing code from remote servers, installing malware, deliberately hiding code or eavesdropping on user searches.

Over 120 banned add-ons appear to have been published by a single developer, 2Ring, and were removed for executing remote code — which is illegal according to Mozilla’s add-on rule book.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Citrix Flaw Exploited by Ransomware Attackers

Citrix Flaw Exploited by Ransomware Attackers

Reports have emerged of multiple attempts to exploit a Citrix vulnerability, delivering ransomware to enterprise victims including a German car manufacturer.

Citrix began patching the CVE-2019-19781 bug in its Application Delivery Controller (ADC) and Citrix Gateway products last week. If successfully exploited, it could allow an unauthenticated attacker to perform arbitrary code execution.

At the time, FireEye warned that attackers were exploiting the flaw to deploy a backdoor, named “NotRobin,” in order to maintain access to exposed systems.

In an update, the security vendor claimed on Friday that it had detected efforts to deploy coin miners and ransomware via exploits for the vulnerability.

It traced attacks on dozens of FireEye customers back to ransomware named “Ragnarok,” which appears to have been created in mid-January. The ransom note demands 1 Bitcoin ($8600) to decrypt one infected machine or five ($43,002) for all.

“FireEye continues to observe multiple actors who are currently seeking to take advantage of CVE-2019-19781. This post outlines one threat actor who is using multiple exploits to take advantage of vulnerable internal systems and move laterally inside the organization,” it concluded.

“Based on our initial observations, the ultimate intent may have been the deployment of ransomware, using the Gateway as a central pivot point.”

As FireEye mentioned, there appear to be multiple groups looking to exploit the Citrix flaw in ransomware attacks.

Researchers took to Twitter to reveal efforts by attackers using the Sodinokibi variant, also known as REvil. Victims include German car parts manufacturer Gedia Automotive Group.

“I examined the files #REvil posted from Gedia after they refused to pay the #ransomware. The interesting thing I discovered is that they obviously hacked Gedia via the #Citrix exploit,” explained @underthebreach. “My bet is that all recent targets were accessed via this exploit.”

The news comes after white hats pointed to a critical unpatched flaw in Pulse Secure VPN products as being behind the Travelex ransomware outage.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk