Dagenham Duo Jailed for Hacking Bank Accounts

Dagenham Duo Jailed for Hacking Bank Accounts

Two Dagenham residents have been put behind bars after compromising more than 700 bank accounts and cell phone accounts to commit fraud in a six-year crime spree.

Nigerian-born Oluwaseun Ajayi, aged 39, and 49-year-old Inga Irbe hacked into bank accounts then applied for loans, credit cards, and additional bank accounts in the names of their victims. 

An investigation by the Metropolitan Police’s Central Specialist Crime—Cyber Crime Unit revealed that the duo also committed multiple incidences of phone upgrade fraud by gaining unauthorized access to strangers’ cell phone accounts and ordering £12,000 worth of new devices. 

Police searches of the address shared by Irbe and Ajayi resulted in the seizure of numerous items, including multiple cell phones, SIM Cards, iPads, and a laptop. Correspondence and bank cards in other people’s names were also confiscated, along with £1,200 cash in £50 notes.

The pair, who both reside at Orchard Road, Dagenham, and who may be romantically involved, were found guilty of two counts of conspiracy to defraud and two counts of conspiracy to commit fraud by false representation between February 1, 2012, and May 14, 2018. Ajayi was further found guilty of failing to comply with a Section 49 RIPA notice to disclose his phone’s PIN number to police.

The guilty verdicts were reached by a jury at Croydon Crown Court on November 27. In the same court, on Friday, January 10, Ajayi was sentenced to five years and six months in prison, while Irbe was handed a community order of 12 months and ordered to complete 170 hours of unpaid work.

Detective Inspector Gary Myers said: “Ajayi and Irbe committed these offences in a manner that showed a lot of pre-planning and deception.

“However, they were not able to deceive officers, who carried out a thorough investigation which has brought these two criminals to justice.

“While cybercrime can often be complex and investigations take months, Met officers will not relent in pursuing those that hide behind their keyboards to steal other people’s money and make their lives a misery.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hidden Hotel Room Cameras Spark Investigation

Hidden Hotel Room Cameras Spark Investigation

An investigation has been launched by the Wisconsin Department of Justice and local police after hidden cameras were found in a downtown Minneapolis, Minnesota, hotel room.

The creepy discovery was made by a group of high school students who were staying at the Hyatt Regency Minneapolis hotel on 7th Street while on an overnight field trip with their school’s business club. The trip took place over the first weekend of December last year. 

Police confirmed that students found multiple cameras in the room but have not disclosed exactly how many devices were involved in the incident. 

After East High School DECA students informed the school of the discovery, the Madison school district placed an unidentified staff member who had accompanied the students on the field trip on an administrative leave as a precautionary measure. 

DECA is an international organization that aims to educate youngsters about jobs in marketing, finance, and hospitality. The organization runs events and competitions to encourage student interest in the business world. 

The Wisconsin Department of Justice (DoJ) agents and Minneapolis police are investigating the incident, along with previous trips run by East DECA. 

In an email sent to students’ parents on December 16, interim principal of East High School Brendan Kearney wrote: “We are sorry to have to contact you in this way and can only imagine what you must be feeling. 

“We want you to know that East and (the Madison school district) will do whatever we can to protect and support both our current and former students.”

Included in Kearney’s missive was a message from DoJ agent Jesse Crowe, which confirmed that the agency’s Division of Criminal Investigation was leading an investigation into any events that occurred prior to the business club’s December trip, including anything that occurred outside the state.

According to CBSN Minnesota, a search warrant was served on a home in Cottage Grove, Wisconsin, on December 12 in connection with the incident, but no arrests were made. Police later asked a judge to seal the contents of the warrant.

Former DECA trip participants have been provided with an email address to which they were invited to submit any relevant information regarding former events and excursions. 

The Madison school district intends to carry out its own investigation into the incident after the investigation by law enforcement concludes.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Announces AI Warship Contracts

UK Announces AI Warship Contracts

Britain’s Ministry of Defense today announced contracts to create “revolutionary” warships that use artificial intelligence (AI) to make quicker decisions.

The Defense and Security Accelerator (DASA), part of the Ministry of Defense (MoD), said that an initial funding wave of £4m had been allocated to the project.

“The funding aims to revolutionize the way warships make decisions and process thousands of strands of intelligence and data by using Artificial Intelligence,” said DASA.

The contracts are part of DASA’s Intelligent Ship—The Next Generation competition, which seeks to uncover inventive approaches for Human–AI and AI–AI teaming across a variety of defense platforms, such as warships, aircraft, and land vehicles. 

The competition was set up to source tech-based solutions that will prove effective in 2040 and beyond, with the possibility to completely change the way warships are built and how they operate. 

DASA, on behalf of the Defense Science and Technology Laboratory (Dstl), is looking at how future defense platforms can be designed and optimized to exploit current and future advances in automation, autonomy, machine learning, and artificial intelligence. 

Nine projects will share an initial £1m to develop technology and innovative solutions capable of overcoming the increasing information overload faced by Royal Navy crews. 

“Crews are already facing information overload with thousands of sources of data, intelligence, and information. By harnessing automation, autonomy, machine learning and artificial intelligence with the real-life skill and experience of our men and women, we can revolutionize the way future fleets are put together and operate to keep the UK safe,” said Julia Tagg, technical lead from Dstl.

Despite being titled Intelligent Ship, a warship is just the prototype demonstrator for this competition. Effective technological solutions born from the project could be rolled out to the British Army and also the Royal Air Force.

“The astonishing pace at which global threats are evolving requires new approaches and fresh-thinking to the way we develop our ideas and technology. The funding will research pioneering projects into how A.I and automation can support our armed forces in their essential day-to-day work,” said Defense Minister James Heappey.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Consultancies Leak Data on Thousands of Workers

UK Consultancies Leak Data on Thousands of Workers

Thousands of UK business professionals have had their personal details exposed online via a leaky Amazon Web Services bucket, after researchers discovered files belonging to multiple consulting firms.

The misconfigured S3 resource is thought to have been left publicly viewable with no authentication by a London-based company known as CHS Consulting, according to vpnMentor.

However, as the firm has no website the researchers have been unable to confirm ownership of the database, labelled “CHS.”

What they do know is that it contained files from the HR departments of multiple UK consulting firms including Eximius Consultants, Dynamic Partners and IQ Consulting. Most of the data is from 2014-15 although records go back to 2011.

It included passport scans, tax documents, criminal record information and background checks, HMRC-related paperwork, emails and private messages as well as a range of PII including names, email and home addresses, dates of birth and phone numbers.

“Had criminal hackers discovered this database, it would have been a goldmine for illicit activities and fraud, with potentially devastating results for those exposed,” argued vpnMentor.

“If you’re a UK-based consultant or consulting firm and are concerned about this breach, contact the CERT-UK to understand what steps are being taken to keep your data safe and ensure it has not been leaked.”

The researchers contacted the CERT-UK on December 10, a day after discovering the leak, and followed up with AWS a week later. The cloud giant took action a day later on December 19 to secure the database.

This is just the latest of several incidents in which large cloud databases containing highly sensitive personal information have been discovered by the research team.

Other companies found wanting include LightInTheBox, Yves Rocher and Autoclerk. In one incident, the names, phone numbers and financial information of approximately 20 million Ecuadoreans, virtually the entire population, were exposed online.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Mobile Apps Sharing Personal Data Illegally, Consumer Group Claims

Mobile Apps Sharing Personal Data Illegally, Consumer Group Claims

Several mobile apps such as Grindr, OKCupid and Tinder have been found to be leaking personal information to advertising tech companies in possible violation of European data privacy laws, an investigation by a Norwegian consumer group has discovered.

As stated in the Out of Control report, the Norwegian Consumer Council, a government-funded non-profit group, commissioned cybersecurity company Mnemonic to study 10 Android mobile apps. It said it found “serious privacy infringements” in its analysis of how online ad companies track and profile smartphone users, with the apps sending user data to at least 135 different third party services involved in advertising or behavioral profiling.

“As it stands, the situation is completely out of control, harming consumers, societies, and businesses,” the report said. Most of the adtech companies that Mnemonic observed receiving personal data have a “questionable legal basis” for harvesting and using consumer data, the report continued.

“If these companies do not have a legally valid basis for processing personal data, the backbone of much of the adtech system may be systemically in breach of the GDPR.”

The Norwegian Consumer Council therefore urged data protection authorities to enforce the GDPR, and for advertisers and publishers to look toward alternative digital advertising methods that respect fundamental rights.

“The digital marketing and adtech industry has to make comprehensive changes in order to comply with European regulation, and to ensure that they respect consumers’ fundamental rights and freedoms.”

Jake Moore, cybersecurity specialist at ESET, said: “When you join a high profile site such as Grindr, you expect to have your data protected and dealt with sensitively. Sadly, data on people is a lucrative currency, and so it can be tempting to share when given the opportunity. I always recommend that people limit the amount of personal data shared on these sites due to the possibility that the data could be targeted with a cyber-attack.”

James McQuiggan, security awareness advocate at KnowBe4, added that it is difficult in today’s society with social media apps for people to actually read the privacy or end user agreements and to understand what is happening with their name, address, pictures, contacts and GPS location once the data is entered into or collected by an app.

“On a lot of social media apps that are not charging users for their service, the users are undoubtedly the product,” he said. “Their information is collected and sold off to third party organizations for revenue for the social media app. Only in recent years are governments finally taking actions such as the GDPR in the UK and recently, the California Consumer Protection Act (CCPA).”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Russian Phishers Hit Firm at Center of Trump Impeachment

Russian Phishers Hit Firm at Center of Trump Impeachment

An infamous Kremlin-backed hacking group has launched a coordinated phishing campaign aimed at Ukrainian firm Burisma Holdings, in what looks like an attempt to find internal information which could benefit Donald Trump.

Security vendor Area 1 claimed the attacks were carried out by the GRU-linked Fancy Bear (APT28) group responsible for stealing and releasing emails from the Democratic National Committee (DNC) which many believe gave Trump an advantage ahead of the 2016 Presidential election.

It’s no coincidence that the son of current Democratic Presidential hopeful Joe Biden sat on the board of Burisma Holdings. It was Trump’s decision to improperly pressure the Ukrainian President to investigate dealings at the firm that led to his impeachment by the House on charges of abuse of power and obstruction of Congress.

“Our report is not noteworthy because we identify the GRU launching a phishing campaign, nor is the targeting of a Ukrainian company particularly novel. It is significant because Burisma Holdings is publically entangled in US foreign and domestic politics,” noted the report.

“The timing of the GRU’s campaign in relation to the 2020 US elections raises the specter that this is an early warning of what we have anticipated since the successful cyber-attacks undertaken during the 2016 US elections.”

Specifically, the group used a lookalike domain to spoof the legitimate Burisma Holdings webmail login portal to access employee accounts. With this access they could read sensitive corporate emails and use accounts to launch further attacks.

To increase the chances of success, the attackers focused on subsidiaries of the company such as KUB-Gas and CUB Energy, and set up email sender authentication records using SPF and DKIM, Area 1 said.

The attacks are thought to have been successful in tricking some Burisma employees to part with their logins.

Rosa Smothers, senior VP of cyber operations at KnowBe4, explained that phishing is the “go-to methodology” for Russian intelligence services seeking to infiltrate target networks.

“Like any fairly sophisticated and organised hacking campaign, they also ran multiple domains that were just similar enough to legitimate Burisma domains that they went unnoticed by users,” she added.

“At the end of the day, the story here is one of ongoing and escalating social engineering efforts by the Russians against their targets of interest — which is why we should expect and plan for such activities during our upcoming election cycle.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Patches Serious Crypto Flaw Found by NSA

Microsoft Patches Serious Crypto Flaw Found by NSA

Microsoft has kicked off the new decade with fixes for half a century of vulnerabilities, including one discovered by the NSA that could allow hackers to spoof digital certificates to bypass security measures.

This month’s Patch Tuesday focused around the CVE-2020-0601 flaw, which security experts praised the NSA for disclosing responsibly rather than trying to weaponize in attacks.

Affecting Windows 10 and Windows Server 2016 and 2019, the bug exists in the way the CryptoAPI DLL validates Elliptic Curve Cryptography (ECC) certificates.

“An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source,” warned Microsoft. “The user would have no way of knowing the file was malicious, because the digital signature would appear to be from a trusted provider.”

If successful, an attacker could then conduct man-in-the-middle attacks and decrypt confidential information, or run malware even in environments using app whitelisting.

“Every Windows device relies on trust established by TLS and code signing certificates, which act as machine identities. If you break these identities, you won’t be able to tell the difference between malware and Microsoft software,” argued Kevin Bocek, VP of security strategy and threat intelligence at Venafi.

Todd Schell, senior product manager at Ivanti, urged admins to prioritize fixing the problem.

“The vulnerability is only rated as important, but there have been many examples of CVEs that were only rated as important being exploited in the wild,” he said. “Due to the nature of this vulnerability we would urge companies to treat this as a top priority this month and remediate quickly.”

A second flaw in Windows’ cryptographic services is rated with a lower CVSS score, but should also be prioritized, Schell claimed.

CVE-2020-0620 could allow attackers to overwrite or modify a protected file and elevate their privileges accordingly, although it first requires them to execute on a targeted system.

“Gaining execute rights on a system is a pretty low bar for most threat actors. Again, our guidance is to treat this as a priority 1 and address it in a timely manner,” said Schell.

This is the last Patch Tuesday that will include fixes for Windows 7 and Server 2008 systems, unless organizations have paid for extended support. If they have not, they will need to upgrade, or invest in virtual patching capabilities to mitigate the increased risk of attack.

“This will increase the risk assumed by those organizations that continue to run Windows 7 or 2008 and we expect attackers will begin actively looking for those operating systems as a ‘soft spot’ for a compromise,” warned Trustwave threat intelligence manager, Karl Sigler.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk