Over Half of SMEs Have Experienced a Cybersecurity Breach

Over Half of SMEs Have Experienced a Cybersecurity Breach

Over half (51%) of SME businesses and self-employed workers in the UK have experienced a cybersecurity breach, according to a new study by insurance firm Markel Direct.

The findings were taken from a survey of 1000 SME firms and self-employed individuals in the UK, underlining fears that these organizations are at particularly high risk of cyber-attacks due to lack of resources and cybersecurity expertise. This issue has been exacerbated by the digital shift during COVID-19.

The most common attack methods faced by these organizations were malware/virus related (24%), data breaches (16%) and phishing attacks (15%). More than two-thirds (68%) of respondents said the cost of breaches they experienced was up to £5000.

The study also analyzed the extent of cybersecurity measures that are in place for SMEs and the self-employed. Nearly nine in 10 (88%) respondents said they had at least one form of cybersecurity, such as antivirus software, firewalls or multifactor authentication, and 70% said they were fairly confident or extremely confident in their cybersecurity arrangements.

Of these organizations and individuals, 53% had antivirus/malware software in place, and 48% had invested in firewalls and secure networks. In addition, nearly a third (31%) revealed they conducted risk assessments and internal/external audits on a monthly basis.

Worryingly, 11% of respondents said they would not spend any money on cybersecurity measures, viewing them as “unnecessary costs.”

Rob Rees, director of direct and partnerships from Markel Direct, commented: “Cyber-attacks on the largest corporations are often headline news, especially in consideration of some of the major breaches that have happened over the last few years to well-known businesses and local authorities. However, SMEs and the self-employed are also at risk, and the consequences can be devastating to smaller businesses that may not be able to recover from the financial impact of a cyber-breach or losing the trust of their customers.

“Cyber-criminals often target the self-employed and SMEs, as they lack the resources that large businesses have to invest in cybersecurity. SMEs and the self-employed who become targets of a cyber-attack can end up facing financial and operational consequences, of which some may never recover from.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

US Issues Warning Over Commercial Spyware

US Issues Warning Over Commercial Spyware

US government security experts have issued new guidance for possible targets of commercial spyware on protecting themselves from unwarranted surveillance.

“Some governments are using commercial surveillance software to target dissidents, journalists & others around the globe who they perceive as critics,” warned the US National Counterintelligence and Security Center (NCSC) in a Twitter post.

“Commercial surveillance tools are also being used in ways that pose a serious counterintelligence and security risk to US personnel and systems.”

The notice explained that the spyware is being deployed to target mobile and other internet-connected devices using Wi-Fi and cellular data connections.

“In some cases, malign actors can infect a targeted device with no action from the device owner. In others, they can use an infected link to gain access to a device,” it said.

Issued jointly by the NCSC and State Department, the guidance document warned that spyware could monitor phone calls, device locations and virtually any content on a device, including text messages, files, chats, messaging app content, contacts and browsing history.

Among the advice for potential targets was to update software regularly, never click on links in unsolicited messages, encrypt and password-protect devices and regularly restart devices to help remove malware implants.

The note also urged individuals to only use trusted VPNs, disable geolocation features and cover the camera.

The guidance comes just weeks after it was revealed that nine State Department staffers had their iPhones remotely hacked by spyware from controversial surveillance firm NSO Group.

The notorious Pegasus malware was used to snoop on the employees, who were either based in Uganda or working on projects concerning the African country.

The Biden administration is cracking down on the activities of commercial spyware providers.

In November, the Treasury put NSO Group on its Entity List – an export blocklist that will make it harder for the firm to get hold of American components or work with US partners.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

FlexBooker Reveals Major Customer Data Breach

FlexBooker Reveals Major Customer Data Breach

An online booking software provider has released details of a cloud breach over the festive period, resulting in the theft of millions of customers’ personal details.

FlexBooker offers appointment scheduling software for organizations in healthcare, finance and other sectors to accept bookings on their website.

However, late last week, breach notification site HaveIBeenPwned revealed that 3.7 million customer accounts had been compromised in December. It noted that most (69%) of the info was already in its database, presumably due to previous breaches and details reshared across multiple sites.

FlexBooker released a notice soon after, admitting that its cloud systems were targeted.

“On December 23, 2021, starting at 4:05 PM EST our account on Amazon’s AWS servers was compromised, resulting in our temporary inability to service customer accounts, and preventing customers from accessing their data,” it said.

“As part of the incident, our system data storage was also accessed and downloaded. In response to the outage, we worked closely with Amazon to restore a backup, and were able to restore operations within 12 hours.”

It’s unclear how the attackers were able to compromise the FlexBooker account and whether human error such as cloud misconfiguration had anything to do with it.

According to FlexBooker, the stolen information included customers’ full names, email addresses and phone numbers. It claimed that no payment card details were compromised, although according to HaveIBeenPwned, “partial credit card data” was taken.

Customer passwords were encrypted, and the encryption key was not accessed or downloaded, FlexBooker added.

It urged victims of the breach to review accounts for any suspicious activity, obtain a credit report, and consider placing a fraud alert on the report, as well as seeking a credit freeze.

Only 3% of breach victims place a credit freeze on their accounts despite it being a far more effective fraud mitigation strategy than credit monitoring.

It prevents lenders from obtaining a credit report about an individual, meaning they can’t open any new lines of credit, nor can fraudsters use stolen identity information.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Finalsite: All School Sites Now Restored After Ransomware Attack

Finalsite: All School Sites Now Restored After Ransomware Attack

A school IT supplier hit by ransomware last week has claimed that all of its customers’ websites have now been restored, although many will still be suffering some kind of disruption.

Finalsite claims to serve over 8000 schools worldwide, offering content management, communications, mobile and enrolment software.

After discovering ransomware on some systems on January 4, it was claimed that thousands of schools were affected – not only by the downing of websites but also critical messaging services designed to notify communities about weather-related closures or changing COVID-19 protocols.

In an update on Sunday, the firm claimed that it had restored front-end access to 99.9% of customer websites and that all sites now had admin access.

However, there were several caveats.

“We are still working to restore some assets from File Manager and Media Manager, which may affect the display of pages that rely on items like photos or videos loaded from these locations,” Finalsite noted.

“We have identified a segment of data integrations that require the restoration of mapping files, which we will restore and provide an update upon completion.”

It also explained that its legacy bulk email notification tool, eNotify, was still experiencing problems, although its replacement, the Messages module, is back up and running.

There’s still no word from the company as to whether it was forced to engage with its extorters to accelerate the process of restoration and recovery or if any sensitive data may have been taken. The majority of ransomware attacks now feature a data exfiltration and “double extortion” element, according to experts.

The nature of the provider hit by this attack could hint at a growing trend for ransomware in 2022, as threat actors target upstream supply chain firms more frequently to cause maximum damage and increase their chances of a big pay-out

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

500M Avira Antivirus Users Introduced to Cryptomining

Many readers were surprised to learn recently that the popular Norton 360 antivirus suite now ships with a program which lets customers make money mining virtual currency. But Norton 360 isn’t alone in this dubious endeavor: Avira antivirus — which has built a base of 500 million users worldwide largely by making the product free — was recently bought by the same company that owns Norton 360 and is introducing its customers to a service called Avira Crypto.

Avira Crypto

Founded in 2006, Avira Operations GmbH & Co. KG is a German multinational software company best known for their Avira Free Security (a.k.a. Avira Free Antivirus). In January 2021, Avira was acquired by Tempe, Ariz.-based NortonLifeLock Inc., the same company that now owns Norton 360.

In 2017, the identity theft protection company LifeLock was acquired by Symantec Corp., which was renamed to NortonLifeLock in 2019. LifeLock is now included in the Norton 360 service; Avira offers users a similar service called Breach Monitor.

Like Norton 360, Avira comes with a cryptominer already installed, but customers have to opt in to using the service that powers it. Avira’s FAQ on its cryptomining service is somewhat sparse. For example, it doesn’t specify how much NortonLifeLock gets out of the deal (NortonLifeLock keeps 15 percent of any cryptocurrency mined by Norton Crypto).

“Avira Crypto allows you to use your computer’s idle time to mine the cryptocurrency Ethereum (ETH),” the FAQ explains. “Since cryptomining requires a high level of processing power, it is not suitable for users with an average computer. Even with compatible hardware, mining cryptocurrencies on your own can be less rewarding. Your best option is to join a mining pool that shares their computer power to improve their chance of mining cryptocurrency. The rewards are then distributed evenly to all members in the pool.”

NortonLifeLock hasn’t yet responded to requests for comment, so it’s unclear whether Avira uses the same cryptomining code as Norton Crypto. But there are clues that suggest that’s the case. NortonLifeLock announced Avira Crypto in late October 2021, but multiple other antivirus products have flagged Avira’s installer as malicious or unsafe for including a cryptominer as far back as Sept. 9, 2021.

Avira was detected as potentially unsafe for including a cryptominer back in Sept. 2021. Image: Virustotal.com.

The above screenshot was taken on Virustotal.com, a service owned by Google that scans submitted files against dozens of antivirus products. The detection report pictured was found by searching Virustotal for “ANvOptimusEnablementCuda,” a function included in the Norton Crypto mining component “Ncrypt.exe.”

Some longtime Norton customers took to NortonLifeLock’s online forum to express horror at the prospect of their antivirus product installing coin-mining software, regardless of whether the mining service was turned off by default.

“Norton should be DETECTING and killing off crypto mining hijacking, not installing their own,” reads a Dec. 28 thread on Norton’s forum titled “Absolutely furious.”

Others have charged that the crypto offering will end up costing customers more in electricity bills than they can ever hope to gain from letting their antivirus mine ETH. What’s more, there are hefty fees involved in moving any ETH mined by Norton or Avira Crypto to an account that the user can cash out, and many users apparently don’t understand they can’t cash out until they at least earn enough ETH to cover the fees.

In August 2021, NortonLifeLock said it had reached an agreement to acquire Avast, another longtime free antivirus product that also claims to have around 500 million users. It remains to be seen whether Avast Crypto will be the next brilliant offering from NortonLifeLock.

As mentioned in this week’s story on Norton Crypto, I get that participation in these cryptomining schemes is voluntary, but much of that ultimately hinges on how these crypto programs are pitched and whether users really understand what they’re doing when they enable them. But what bugs me most is they will be introducing hundreds of millions of perhaps less savvy Internet users to the world of cryptocurrency, which comes with its own set of unique security and privacy challenges that require users to “level up” their personal security practices in fairly significant ways.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Cyber-Attack on New Mexico County

Cyber-Attack on New Mexico County

A cyber-attack has forced the government of New Mexico’s most populous county to close most of its county buildings to the public.

Bernalillo County had to take some of its IT systems offline on Wednesday after becoming the target of a digital assault that county officials suspect was a ransomware attack. 

In a statement released Wednesday, the county said that all public safety departments, such as emergency 911 communications, the Sheriff’s Office, and Fire and Rescue, were operating as normal “using back-up contingencies.”

However, the incident caused the county’s Metropolitan Detention Center to cancel inmate visits Wednesday.

“Bernalillo County has discovered what is believed to be a ransomware attack on county systems,” stated the county. 

“The county has taken affected systems offline and has severed network connections.”

Vendors for the county’s IT systems have been notified of the attack. The county said that its cybersecurity and IT suppliers are “working to solve the issue and restore the system functions.”

While the disruption of the attack continues, the county said its employees would do their best to fulfill their duties by working remotely.

A county statement read: “Most county buildings are closed to the public; however, county employees are remote working and will assist the public as much as possible, given the circumstances.”

The county did not share any information as to how or by whom the attack was orchestrated. Nor has the county stated if any data has been compromised or if it has received a ransom demand. 

Bernalillo County spokesperson Tia Bland said: “Just know the county is working with a good team of people, long hours, the right people are at the table trying to figure this thing out.”

KOAT Action News reported that the attack on Bernalillo County is causing disruption to the local real estate industry. With key county IT systems offline, realtors are unable to access information such as taxes and deeds that is needed to complete property sales.

“It’s having a ripple effect on the real estate market in general,” said Damon Maddox, the president of the New Mexico Association of Realtors.

“It’s difficult for us to do our job if we can’t access the county website to get that public information.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains