Merck Wins Insurance Lawsuit re NotPetya Attack

The insurance company Ace American has to pay for the losses:

On 6th December 2021, the New Jersey Superior Court granted partial summary judgment (attached) in favour of Merck and International Indemnity, declaring that the War or Hostile Acts exclusion was inapplicable to the dispute.

Merck suffered US$1.4 billion in business interruption losses from the Notpetya cyber attack of 2017 which were claimed against “all risks” property re/insurance policies providing coverage for losses resulting from destruction or corruption of computer data and software.

The parties disputed whether the Notpetya malware which affected Merck’s computers in 2017 was an instrument of the Russian government, so that the War or Hostile Acts exclusion would apply to the loss.

The Court noted that Merck was a sophisticated and knowledgeable party, but there was no indication that the exclusion had been negotiated since it was in standard language. The Court, therefore, applied, under New Jersey law, the doctrine of construction of insurance contracts that gives prevalence to the reasonable expectations of the insured, even in exceptional circumstances when the literal meaning of the policy is plain.

Merck argued that the attack was not “an official state action,” which I’m surprised wasn’t successfully disputed.

Slashdot thread.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Scary Fraud Ensues When ID Theft & Usury Collide

What’s worse than finding out that identity thieves took out a 546 percent interest payday loan in your name? How about a 900 percent interest loan? Or how about not learning of the fraudulent loan until it gets handed off to collection agents? One reader’s nightmare experience spotlights what can happen when ID thieves and hackers start targeting online payday lenders.

The reader who shared this story (and copious documentation to go with it) asked to have his real name omitted to avoid encouraging further attacks against his identity. So we’ll just call him “Jim.” Last May, someone applied for some type of loan in Jim’s name. The request was likely sent to an online portal that takes the borrower’s loan application details and shares them with multiple prospective lenders, because Jim said over the next few days he received dozens of emails and calls from lenders wanting to approve him for a loan.

Many of these lenders were eager to give Jim money because they were charging exorbitant 500-900 percent interest rates for their loans. But Jim has long had a security freeze on his credit file with the three major consumer credit reporting bureaus, and none of the lenders seemed willing to proceed without at least a peek at his credit history.

Among the companies that checked to see if Jim still wanted that loan he never applied for last May was Mountain Summit Financial (MSF), a lending institution owned by a Native American tribe in California called the Habematelol Pomo of Upper Lake.

Jim told MSF and others who called or emailed that identity thieves had applied for the funds using his name and information; that he would never take out a payday loan; and would they please remove his information from their database? Jim says MSF assured him it would, and the loan was never issued.

Jim spent months sorting out that mess with MSF and other potential lenders, but after a while the inquiries died down. Then on Nov. 27 — Thanksgiving Day weekend — Jim got a series of rapid-fire emails from MSF saying they’ve received his loan application, that they’d approved it, and that the funds requested were now available at the bank account specified in his MSF profile.

Curiously, the fraudsters had taken out a loan in Jim’s name with MSF using his real email address — the same email address the fraudsters had used to impersonate him to MSF back in May 2021. Although he didn’t technically have an account with MSF, their authentication system is based on email addresses, so Jim requested that a password reset link be sent to his email address. That worked, and once inside the account Jim could see more about the loan details:

The terms of the unauthorized loan in Jim’s name from MSF.

Take a look at that 546.56 percent interest rate and finance charges listed in this $1,000 loan. If you pay this loan off in a year at the suggested bi-weekly payment amounts, you will have paid $3,903.57 for that $1,000.

Jim contacted MSF as soon as they opened the following week and found out the money had already been dispersed to a Bank of America account Jim didn’t recognize. MSF had Jim fill out an affidavit claiming the loan was the result of identity theft, which necessitated filing a report with the local police and a number of other steps. Jim said numerous calls to Bank of America’s fraud team went nowhere because they refused to discuss an account that was not in his name.

Jim said MSF ultimately agreed that the loan wasn’t legitimate, but they couldn’t or wouldn’t tell him how his information got pushed through to a loan — even though MSF was never able to pull his credit file.

Then in mid-January, Jim heard from MSF via snail mail that they’d discovered a data breach.

“We believe the outsider may have had an opportunity to access the accounts of certain customers, including your account, at which point they would be able to view personal information pertaining to that customer and potentially obtain an unauthorized loan using the customer’s credentials,” MSF said.

MSF said the personal information involved in this incident may have included name, date of birth, government-issued identification numbers (e.g., SSN or DLN), bank account number and routing number, home address, email address, phone number and other general loan information.

A portion of the Jan. 14, 2022 breach notification letter from tribal lender Mountain Summit Financial.

Nevermind that his information was only in MSF’s system because of an earlier attempt by ID thieves: The intruders were able to update his existing (never-deleted) record with new banking information and then push the application through MSF’s systems.

“MSF was the target of a suspected third-party attack,” the company said, noting that it was working with the FBI, the California Sheriff’s Office, and the Tribal Commission for Lake County, Calif.  “Ultimately, MSF confirmed that these trends were part of an attack that originated outside of the company.”

MSF has not responded to questions about the aforementioned third party or parties that may be involved. But it is possible that other tribal lenders could have been affected: Jim said that not long after the phony MSF payday loan was pushed through, he received at least three inquiries in rapid succession from other lenders who were all of a sudden interested in offering him a loan.

In a statement sent to KrebsOnSecurity, MSF said it was “the victim of a malicious attack that originated outside of the company, by unknown perpetrators.”

“As soon as the issue was uncovered, the company initiated cybersecurity incident response measures to protect and secure its information; and notified law enforcement and regulators,” MSF wrote. “Additionally, the company has notified individuals whose personal identifiable information may have been impacted by this crime and is actively working with law enforcement in its investigation. As this is an ongoing criminal investigation, we can make no additional comment at this time.”

According to the Native American Financial Services Association (NAFSA), a trade group in Washington, D.C. representing tribal lenders, the short-term installment loan products offered by NAFSA members are not payday loans but rather “installment loans” — which are amortized, have a definite loan term, and require payments that go toward not just interest, but that also pay down the loan principal.

NAFSA did not respond to multiple requests for comment.

Nearly all U.S. states have usury laws that limit the amount of interest a company can charge on a loan, but those limits traditionally haven’t applied to tribal lenders.

Leslie Bailey is a staff attorney at Public Justice, a nonprofit legal advocacy organization in Oakland, Calif. Bailey says an increasing number of online payday lenders have sought affiliations with Native American tribes in an effort to take advantage of the tribes’ special legal status as sovereign nations.

“The reason is clear: Genuine tribal businesses are entitled to ‘tribal immunity,’ meaning they can’t be sued,” Bailey wrote in a blog post. “If a payday lender can shield itself with tribal immunity, it can keep making loans with illegally-high interest rates without being held accountable for breaking state usury laws.”

Bailey said in one common type of arrangement, the lender provides the necessary capital, expertise, staff, technology, and corporate structure to run the lending business and keeps most of the profits. In exchange for a small percent of the revenue (usually 1-2%), the tribe agrees to help draw up paperwork designating the tribe as the owner and operator of the lending business.

“Then, if the lender is sued in court by a state agency or a group of cheated borrowers, the lender relies on this paperwork to claim it is entitled to immunity as if it were itself a tribe,” Bailey wrote. “This type of arrangement — sometimes called ‘rent-a-tribe’ — worked well for lenders for a while, because many courts took the corporate documents at face value rather than peering behind the curtain at who’s really getting the money and how the business is actually run. But if recent events are any indication, legal landscape is shifting towards increased accountability and transparency.”

In 2017, the Consumer Financial Protection Bureau sued four tribal online payday lenders in federal court — including Mountain Summit Financial — for allegedly deceiving consumers and collecting debt that was not legally owed in many states. All four companies are owned by the Habematolel Pomo of Upper Lake.

The CFPB later dropped that inquiry. But a class action lawsuit (PDF) against those same four lenders is proceeding in Virginia, where a group of plaintiffs have alleged the defendants violated the Racketeer Influenced and Corrupt Organizations Act (RICO) and Virginia usury laws by charging interest rates between 544 and 920 percent.

According to Buckley LLP, a financial services law firm based in Washington, D.C., a district court dismissed the RICO claims but denied the defense’s motion to compel arbitration and dismiss the case, ruling that the arbitration provision was unenforceable as a prospective waiver of the borrowers’ federal rights and that the defendants could not claim tribal sovereign immunity. The district court also “held the loan agreements’ choice of tribal law unenforceable as a violation of Virginia’s strong public policy against unregulated lending of usurious loans.”

Buckley notes that on Nov. 16, 2021, the U.S. Court of Appeals for the Fourth Circuit upheld the district court ruling, concluding that the arbitration clauses in the loan agreements “impermissibly force borrowers to waive their federal substantive rights under federal consumer protection laws, and contained an unenforceable tribal choice-of-law provision because Virginia law caps general interest rates at 12 percent.”

Jim said he learned of the Thanksgiving weekend MSF loan only because the hackers apparently figured it was easier to push through loans using existing MSF customer account information than it was to alter anything in the records other than the bank account for receiving the funds.

But had the hackers changed the email address, Jim might have first found out about the loan when the collection agencies came calling. And by then, his exorbitant loan would be in default and racking up some wicked late charges.

Jim says he’s still hopping mad at MSF, and these days he’s just waiting for the other shoe to drop.

“They issued this loan in my name without verification and without even checking my credit at all, even though they were already on notice that they shouldn’t have been dealing with me from the May incident,” Jim said. “I still feel like I’m going to get that call at some point from a collection agency asking why I haven’t been making payments on some installment loan I never asked for.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

IRS to Require New ID Verification

IRS to Require New ID Verification

American taxpayers will soon be required to sign up with an identity verification company to access their Internal Revenue Service (IRS) accounts online.

Currently, those with an online account at IRS.gov online can log in using only their email address and password. Staring this summer, those accounts will cease to function, and users will have to verify their identity by creating an account with online identity verification service, ID.me.

Based in McLean, Virginia, ID.me requires applicants to prove who they are by uploading a photo of an identity document such as a driver’s license, state ID or passport and taking a selfie with a smartphone or a computer with a webcam.

While Americans will not need to make an ID.me account to file a tax return, they will need to register with the new security system to access the Child Tax Credit portal, view previous years’ transcripts, get an identity protection PIN, see records of previous payments and view the online payment agreement.

“The IRS emphasizes taxpayers can pay or file their taxes without submitting a selfie or other information to a third-party identity verification company. Tax payments can be made from a bank account, by credit card or by other means without the use of facial recognition technology or registering for an account,” said an IRS spokesperson.

The IRS has received criticism for requiring taxpayers to allow their biometric data to be collected to access their own tax data. 

Jackie Singh, director of technology and operations at the Surveillance Technology Oversight Project, predicted that the new security requirement “will only lead to further ruin for Americans when their data is inevitably breached.”

The IRS said the new process would help to ensure that taxpayer information is provided only to the person who has a legal right to the data.

“Identity verification is critical to protect taxpayers and their information. The IRS has been working hard to make improvements in this area, and this new verification process is designed to make IRS online applications as secure as possible for people,” said IRS commissioner Chuck Rettig.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

SBA Announces $3m Cybersecurity Program

SBA Announces $3m Cybersecurity Program

The United States Small Business Administration (SBA) has launched a program to help the country’s emerging small businesses to improve their cybersecurity infrastructure. 

SBA administrator Isabella Casillas Guzman, who heads the SBA, announced the new Cybersecurity for Small Business Pilot Program on Friday. The SBA will award $3m in grants to help entrepreneurs defend against cyber-threats through the program. 

“Throughout the COVID-19 pandemic, small businesses have adopted technology at high rates to survive, operate and grow their businesses,” said Guzman. 

She added: “As a result, cybersecurity has become increasingly important as now, more than ever before, small business owners face cyber-risks and challenges that could disrupt their operations and competitive advantages.”

As part of the pilot program, through the Office of Entrepreneurial Development, state governments can compete for funding that would provide emerging small firms in multiple industries with training, counseling, remediation and other tailored cybersecurity services.

Applications will be accepted from January 26 2022 through March 3 2022, and grantees will be awarded up to $1m to assist small businesses.

“The bottom line is we must do more to help small businesses combat cybersecurity threats, which continue to increase, evolve and inhibit,” said SBA associate administrator for the Office of Entrepreneurial Development Mark Madrid. 

“This pilot program will empower state governments to expand existing services, innovate, adapt to current environments, develop new resources and scale solutions to assist more small businesses.”

The grant recipients are required to explore, offer or expand services to specific “entrepreneurial audiences,” including veterans, minorities, women, disaster-affected businesses, urban entrepreneurs and rural entrepreneurs. 

Guzman said the number of small businesses in America is growing, and new ways were needed to secure them against cyber-threats.

“As we seek to build a stronger and more inclusive entrepreneurial ecosystem, we must innovate and provide resources to meet the evolving needs of the growing number of small businesses,” she said.

“With this new funding opportunity, the SBA intends on leveraging the strengths across our state governments, territories, and tribal governments to provide services to help small businesses get cyber ready and, in the process, fortify our nation’s supply chains.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

NSF Awards $29m to Cybersecurity Scholarships

NSF Awards $29m to Cybersecurity Scholarships

The United States National Science Foundation (NSF) is awarding universities more than $29m to fund hundreds of new cybersecurity scholarships.

The foundation is making the award to support the urgent need for more cybersecurity professionals in the United States. 

“As cyber-threats continue to evolve in complexity, so must our approaches to cybersecurity education and our workforce,” said NSF director Sethuraman Panchanathan.

They added: “The cybersecurity talent shortage remains a critical issue in the United States, with businesses and government agencies alike struggling to fill critical cybersecurity positions.”

NSF will distribute the money to eight universities over the next five years as part of its CyberCorps Scholarship for Service program, which has already funded projects at 82 universities in 37 states, the District of Columbia and Puerto Rico.

Students must agree to work in a government cybersecurity role following graduation to be accepted onto the scholarship program.

Training provided through the scholarships will address topics including autonomous systems and artificial intelligence, next-generation cybersecurity engineering and aviation and aerospace cybersecurity.

“To address the demand for dedicated cybersecurity professionals, particularly in government agencies, the US National Science Foundation is investing in eight new CyberCorps Scholarship for Service grants,” said the NSF in a statement released Friday.

“This investment will increase the volume and strength of the nation’s cybersecurity workforce by providing full scholarships and stipends to students who agree to work in cybersecurity jobs for federal, state, local or tribal governments after graduation.”

The eight universities set to receive NSF funding in 2022 are Oakland University, Fordham University, Indiana University – Purdue University Indianapolis, State University of New York at Binghamton, Georgia State University, University of Memphis, University of Nevada, Reno and the Embry-Riddle Aeronautical University.

Every university’s scholarship program includes an effort to promote the recruitment and retention of students from historically underrepresented groups in cybersecurity careers, including minorities, women, first-generation students, low-income students, students with disabilities and veterans.

Panchanathan said: “These new CyberCorps Scholarship for Service projects engage diverse student populations and provide innovative and high-quality educational experiences that will ensure our nation is prepared to meet future cyber-threats with a well-trained workforce.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Two in Five IT Security Managers Considering Quitting Their Jobs

Two in Five IT Security Managers Considering Quitting Their Jobs

Two in five (41%) IT security managers in the UK are considering quitting their jobs in the next six months, largely due to growing stress levels, according to a new study by ThreatConnect.

The researchers said the findings highlight the scale of the so-called “great resignation” impacting the cybersecurity industry, exacerbating the sector’s skills shortage.

The survey of 503 senior managers responsible for technology decisions at their organization or IT security found an average security staff turnover rate of 20% in the UK. Around three-quarters (74%) of respondents reported this rate as rising in the past year. Adding to the problem, just under a third (31%) said they experienced difficulties recruiting people with the skills and talent required for cybersecurity.

In a particularly concerning finding, less than a quarter (23%) of security leaders surveyed would recommend a career in cybersecurity, while two in five (42%) said they are unlikely to do so.

Stress and workload appeared to be the principal causes of these issues. Over a third (37%) of all respondents reported feeling highly stressed about work, and more than half (53%) experienced increased stress levels over the past six months. The respondents revealed that long hours and heavy workloads had manifested in headaches (44%), a drop in work performance (43%) and sleeping difficulties and fatigue (37%).

The biggest reasons given by all respondents for quitting their jobs were lack of opportunities to work from home (31%), high-stress levels (26%) and the attraction of a better salary elsewhere (25%). For security managers specifically, excessive workload was the most common factor (31%) cited.

In another worrying finding, around a third (32%) of all respondents did not agree that their company can keep up with the volume and sophistication of cyber-threats.

Adam Vincent, co-founder and CEO at ThreatConnect, commented: “Now more than ever, IT security teams are being expected to do more with less.

“High employee turnover and stressed IT professionals can negatively impact an organization’s performance both in the short term and in the long term. The growing volume and sophistication of threats makes it critical that organizations manage workload feasibility and give teams the support they need.” 

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

US Data Breaches Surge 68% to All-Time High

US Data Breaches Surge 68% to All-Time High

The volume of publicly reported data compromises in the US soared 68% year-on-year to a record high of 1862, according to new data from the Identity Theft Resource Center (ITRC).

The non-profit said the figure was 23% higher than the previous record, set in 2017.

The number of victims was down 5%, continuing a recent trend as threat actors focus their efforts on collecting specific data types rather than acquiring mass troves of data indiscriminately.

Ransomware continues to be a significant driver of the overall upward trend for breaches: data compromises related to these attacks have doubled in each of the past two years. Ransomware is on course to surpass phishing as the number one cause of breaches in 2022, the ITRC claimed.

Although the report covers leaked and breached data, compromises stemming from cyber-attacks were by far the most significant cause. In fact, there were more of these incidents in 2021 (1603) than there were data compromises in 2020 (1108).

The manufacturing and utilities sector reported the largest percentage increase in data compromises, up 217% over 2020. Every sector saw a rise in incidents bar the military vertical, where there were no publicly reported breaches.

Reporting is also becoming more opaque: the number of data breach notices that did not reveal the root cause of a compromise (607) grew by over 190% year-on-year in 2021.

The only positive from the report was that the number of data events involving sensitive information like Social Security numbers increased only slightly year-on-year. It nudged up from 80% to 83% over the period but is still well below the record high of 95% in 2017.

ITRC president and CEO Eva Velasquez argued that 2021 had seen a shift in the identity crime space.

“Too many people found themselves in between criminals and organizations that hold consumer information. We may look back at 2021 as the year when we moved from the era of identity theft to identity fraud,” she said.

“The number of breaches in 2021 was alarming. Many of the cyber-attacks committed were highly sophisticated and complex, requiring aggressive defenses to prevent them. If those defenses failed, too often we saw an inadequate level of transparency for consumers to protect themselves from identity fraud.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

US Adds 17 Exploited Bugs to “Must Patch” List

US Adds 17 Exploited Bugs to “Must Patch” List

A US government’s security agency has added 17 vulnerabilities currently being actively exploited in the wild to a database of bugs that federal agencies must fix.

The Known Exploited Vulnerabilities Catalog was launched in November last year as part of Binding Operational Directive (BOD) 22-01, designed to make civilian federal government agencies more cyber-resilient.

An initial list of just over 300 CVEs, some of which dated as far back as 2010, has been steadily added to since. The latest update includes vulnerabilities that could be exploited for various ends, including denial of service, privilege escalation, authentication bypass and information disclosure.

Attackers are using them to steal information and credentials, execute malware, access networks and more.

Among the most interesting are CVE-2021-32648, which came to light last week and is an improper authentication flaw in the October CMS. It was exploited in a wide-ranging campaign to hijack and deface Ukrainian government websites.

Another is CVE-2021-35247, listed as an improper input validation vulnerability in SolarWinds Serv-U file servers.

Microsoft researchers discovered it being exploited in Log4j attacks in an attempt to compromise Windows domain controllers. Such attacks failed because Windows domain controllers aren’t vulnerable to Log4Shell.

However, it must be patched by February 4, according to the order from the Cybersecurity and Infrastructure Security Agency (CISA).

There’s an even tighter time frame for CVE-2021-32648 and eight other CVEs listed: these must be fixed by February 1. The remaining seven bugs must be patched by July, according to the update.

While the BOD to patch any vulnerabilities added to the database is only mandatory for civilian federal agencies, the government wants other organizations to follow the same rules.

“While this directive applies to federal civilian agencies, we know that organizations across the country, including critical infrastructure entities, are targeted using these same vulnerabilities,” it said back in November.

“It is therefore critical that every organization adopt this directive and prioritize mitigation of vulnerabilities listed in CISA’s public catalog.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

UK’s Privacy Tsar Mounts Fierce Defense of End-to-End Encryption

UK’s Privacy Tsar Mounts Fierce Defense of End-to-End Encryption

The UK’s privacy watchdog has defended end-to-end encryption (E2EE) following a government campaign lobbying for a halt to further roll-outs by the likes of Meta.

The publicly funded “No Place to Hide” campaign, backed by several children’s charities, is calling for social media companies to stop implementing E2EE until they can prove children’s safety will not be put at risk as a result.

Meta’s delayed roll-out of the security and privacy-enhancing technology is now slated for 2023 for Messenger and Instagram. Its messaging platform WhatsApp already uses E2EE.

The arguments against the tech are that it blindfolds police and provides a safe haven for pedophiles to groom victims and share sex abuse material.

However, the Information Commissioner’s Office (ICO) has argued that multiple techniques and innovative approaches already exist which can help investigators – and that E2EE plays a vital role in protecting children and wider society.

“The discussion on end-to-end encryption use is too unbalanced to make a wise and informed choice. There is too much focus on the costs without also weighing up the significant benefits,” argued the ICO’s executive director for technology and innovation, Stephen Bonner.

“E2EE serves an important role both in safeguarding our privacy and online safety. It strengthens children’s online safety by not allowing criminals and abusers to send them harmful content or access their pictures or location. It is also crucial for businesses, enabling them to share information securely and fosters consumer confidence in digital services.”

Accessing encrypted content is not the only way police can catch offenders, Bonner added.

“Law enforcers have other methods such as listening to reports of those targeted, infiltrating the groups planning these offenses, using evidence from convicted abusers and their systems to identify other offenders,” he argued.

“We are also seeing a range of other techniques and innovations available that can be used without accessing content to help stop abuse or catch those trying to harm. As an example, platforms are listening to teenagers’ reports and limiting search results for anyone attempting unwanted contact.”

The government should be doubling down on support for these approaches and finding new ones, Bonner concluded.

Instead, the government is using taxpayer money to fund its E2EE campaign with help from advertising giant M&C Saatchi.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains