Summer Exit Planned for Head of UK’s National Cyber Security Centre

Summer Exit Planned for Head of UK’s National Cyber Security Centre

After six and half years in the job, Ciaran Martin is to relinquish his role as head of UK cybersecurity. 

The 45-year-old has announced plans to surrender his title of chief executive of the National Cyber Security Centre (NCSC) in the summer of 2020. 

Oxford University graduate Martin, who has dedicated his entire working life to the UK civil service, described his years with the NCSC as “the privilege of a lifetime.”

British government ministers established the NCSC four years ago on the recommendation of Martin, who was then appointed to lead it. 

Martin in a statement: “When we created the NCSC we set out to achieve something truly special, and I hope and believe we are leaving UK cyber security in much better shape.”

Martin, who was recently appointed a Companion of the Order of the Bath by Queen Elizabeth in the New Year’s Honor’s List, said that the time was ripe to bring a fresh perspective to the demanding role. However, he believes his successor will not be in for an easy ride. 

“Challenges around securing technology are only going to get ever more complex,” said Martin, “so it’s right that after six and a half years that someone else takes this world-class organization to the next level.”

Britain’s Government Communications Headquarters, commonly known as GCHQ, has said that a new NCSC chief executive will be appointed and in place by the end of the summer. 

Martin joined the board of GCHQ in December 2013 as head of cybersecurity. His recommendation to set up the NCSC as a division of GCHQ was made after the 2015 election. 

The NCSC now employs approximately 1,000 staff and operates from a head office in London’s Victoria area on an annual budget of £250m. The center offers practical cybersecurity advice for individuals and organizations via a website.

Since its inception, the NCSC has dealt with over 2,000 cybersecurity incidents targeting the UK. In the 12 months ending August 2019, the NCSC supported nearly 900 British organizations to recover from cyberattacks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Data Leak Forces Password Reset at Crypto Exchange Poloniex

Data Leak Forces Password Reset at Crypto Exchange Poloniex

A cryptocurrency exchange has been forced to reset customer passwords after a suspected data leak via social media, although its incident response efforts caused more confusion among some users.

US-based exchange Poloniex informed around 1% of its customer base that they had to reset their log-ins, following a tweet claiming to contain a list of leaked email/password combos.

However, customers took to Twitter warning that the email itself was a phishing scam, forcing the exchange to re-emphasize its legitimacy.

It followed-up with a blog post to clarify the situation.

“Our immediate priority was to ensure that our customers’ accounts were safe. As a result, we reset the passwords of potentially impacted customers, as users often reuse passwords or minor variants of the same password,” it explained.

“Our second priority was to determine the source of the leak and we can now confirm that neither this list, nor the information contained, originated from Poloniex. For those interested in our security protocols, we do not store passwords in plain text or a recoverable form, but rather we store them as salted bcrypt hashes.”

In fact, 90% of the compromised passwords on that list have already appeared on breach notification site HaveIBeenPwned?, it said.

“If you have a Poloniex account and did not receive an email from us related to this, you can be confident that your email address was not on the list,” the firm continued. “Less than 5% of the email addresses on the posted list were associated with Poloniex accounts.”

The incident highlights the increasing difficulty online firms are having to convince customers of the legitimacy of urgent communications, in light of a continued epidemic of phishing scams.

Following the collapse of UK travel agency Thomas Cook last year, UK banks were criticized for sending unsolicited text messages to affected customers containing clickable links.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Restaurant Chain Landry’s Hit by POS Malware

US Restaurant Chain Landry’s Hit by POS Malware

A major US hospitality chain has revealed that POS malware affecting scores of its restaurant brands may have led to customer card data theft over several months in 2019.

Landry’s claimed in an incident notice this week that 63 of its food and beverage and restaurant concepts — including Morton’s, Bubba Gump and Rainforest Café — had been affected.

Although the firm switched its POS card machines to an end-to-end encrypted system following a 2016 breach, order entry systems were left unprotected — and it is these that are thought to have been affected by the malware.

“Besides the encryption devices used to process payment cards, our restaurants and food and beverage outlets also have order entry systems with a card reader attached for waitstaff to enter kitchen and bar orders and to swipe Landry’s Select Club reward cards,” the note continued.

“In rare circumstances, it appears waitstaff may have mistakenly swiped payment cards on the order entry systems. The payment cards potentially involved in this incident are the cards mistakenly swiped on the order-entry systems. Landry’s Select Club rewards cards were not involved.”

Customers that visited between March 13 2019 and October 17 2019 may have been affected, although at “a small number of locations” hackers may have accessed cards as early as January 18 2019, it said.

“The malware searched for track data (which sometimes has the cardholder name in addition to card number, expiration date, and internal verification code) read from a payment card after it was swiped on the order-entry systems,” said Landry’s.

“In some instances, the malware only identified the part of the magnetic stripe that contained payment card information without the cardholder name.”

This data is usually sold on the dark web by hackers, where it is used to create counterfeit cards. Although the advent of EMV cards has largely eradicated this type of fraud across Europe, slow adoption in the US means POS malware attacks like this still happen from time to time.

Last year, restaurant chain Huddle House suffered just such an attack after a third party POS vendor was compromised.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Biz Wins Court Case Against Ransomware Data Thieves

US Biz Wins Court Case Against Ransomware Data Thieves

A US company targeted by ransomware has taken its fight to the Irish courts to have confidential data stolen by the same attackers removed from the web.

Southwire was struck by the Maze variant in December last year, with attackers demanding over $6m in ransom — not only for the decryption key, but also to regain company data that they exfiltrated.

However, the attackers reportedly grew frustrated with the firm’s refusal to pay up, and started publishing the data on a site called mazenews[dot]top.

That’s when the firm, which is one of America’s largest manufacturers of wire and cabling, enlisted its lawyers.

According to local reports, the company has secured an injunction in the Irish High Court against the registrants of the IP address linked to the “mazenews” site.

They’re said to work for a now-dissolved company called World Hosting Farm Limited (WHFL), with addresses in Cork and Dublin. The owner and director of the firm is Artur Grabowski of Stupsk, in Poland, according to the court documents.

Grabowski and the others named in connection with the IP address were all contacted by Southwire but failed to respond, hence the temporary injunction. It apparently requires the removal of all confidential information from the site and that no more material is published online.

Southwire is also said to have asked the judge to prevent media outlets from publishing its name in reporting of the court case, arguing that it would help the ransomware authors. However, Ms Justice Mary Rose Gearty refused.

Data theft is becoming increasingly common in ransomware attacks, raising the stakes for victim organizations.

Aside from Maze, strains such as Zeppelin, Snatch, Sodinokibi and Merry Christmas have all been observed exfiltrating sensitive data from targeted networks. The tactic is designed to force victim organizations to pay up to avoid their data being published, rather than simply ignore the ransom demands and restore from backup.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk