McMenamins Reports Data Breach

McMenamins Reports Data Breach

A cyber-attack on American hospitality chain McMenamins may have exposed data belonging to its current and former employees. 

The business, which owns and operates brewpubs, breweries, music venues, historic hotels, and theater pubs in Oregon and Washington, issued a data breach notice after suffering a ransomware attack.

Suspicious activity was identified in the company’s computer network on December 12. 

“As soon as we realized what was happening, we blocked access to our systems to contain the attack that day,” states McMenamins in a data breach notice updated on December 30. 

“It appears that cybercriminals gained access to company systems beginning on December 7 and through the launch of the ransomware attack on December 12.”

The company went on to say that the installation of malicious software on its computer systems prevented staff from accessing company files and data. 

An investigation into the security incident has determined that the perpetrators “stole certain business records,” including payroll data and human resources files, “for at least some individuals” who worked for McMenamins between January 1, 1998, and June 30, 2010. 

McMenamins said: “We have not been able to recover these files or contact information for these previous employees. Out of abundance of caution and for the purposes of providing this notice and credit monitoring support, we are assuming that all previous employees during this time period were potentially affected.”

The unidentified ransomware gang behind the attack also stole human resources files containing the personal data of individuals employed by McMenamins between July 1, 2010, and December 12, 2021.

The affected files potentially contained employees’ names, addresses, telephone numbers, email addresses, dates of birth, race, ethnicity, gender, disability status, medical notes, performance and disciplinary notes, Social Security numbers, health insurance plan elections, income amounts, and retirement contribution amounts. 

McMenamins said it is working with the Federal Bureau of Investigation and an “experienced cybersecurity investigation firm” to gauge the full extent of the attack, restore its systems, and improve its security. 

Identity theft and credit monitoring and protection services are being provided free of charge to all current and previous employees of McMenamins who worked for the company between January 1, 1998, and December 12, 2021.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Kansas Gets 17 Critical Cybersecurity Recommendations

Kansas Gets 17 Critical Cybersecurity Recommendations

A task force formed to assess gaps and possibilities in the cybersecurity posture of Kansas has made 41 key recommendations.

Seventeen of the recommendations included in the Cybersecurity Task Force’s final report have been identified as “critical priorities.”

The task force was set up in August 2021 and issued an interim report in October. This was followed by a final report that was released in December. 

“Important to us was to provide the governor with actionable recommendations that can increase the cybersecurity posture of Kansas and grow its cybersecurity workforce,” said the task force’s co-chairs, Mike Mayta and Jeff Maxon. “After meeting with stakeholders, we feel confident in the potential that Kansas possesses.”

Topping the list of critical recommendations is the need to identify both a short-term cybersecurity governance model to continue the work of the task force and a long-term sustainable cybersecurity governance model to support a whole-of-state approach.

The task force found Kansas needs to perform state assessments of current computer science and cybersecurity workforce development and education capabilities in and available to Kansas, as well as of the state’s cybersecurity capabilities. 

Kansas was also advised to create a cyber-incident and disruption response plan and to ensure there are mechanisms in place to test it annually with partners throughout the state. The task force recommended that an advisory body be formed from appropriate agencies and stakeholders to develop such a plan. 

Another critical recommendation was to create a cybersecurity position “such as a Cyber Navigator or Cyber Liaison” in state government to “focus on communicating, coordinating, and collaborating with public and private cybersecurity partners.” 

To ensure the state has access to the best cybersecurity talent, the task force advised Kansas to partner with higher education institutions to develop a talent pipeline through work-based learning opportunities. The state was also advised to identify salary differences between public and private cybersecurity jobs “and see if and where the public sector can raise wages to be more competitive.”

Kansas governor Laura Kelly said: “These cybersecurity recommendations put Kansas on a path to be proactive in securing our data while also growing our workforce.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Morgan Stanley Agrees to Data Breach Settlement

Morgan Stanley Agrees to Data Breach Settlement

American multinational investment bank and financial services company Morgan Stanley has agreed to pay $60m to settle a legal claim over data security.

A class-action lawsuit was filed against the company in July 2020 over two security breaches that compromised the personal data of approximately 15 million of its customers.

The suit alleges that Morgan Stanley failed to safeguard the personally identifiable information (PII) of its current and former clients. According to the plaintiffs, data center equipment decommissioned by Morgan Stanley in 2016 and 2019 was not wiped clean properly.

The plaintiffs allege that a software flaw meant that sensitive data stored on the old servers and other technology was visible in an unencrypted format to whoever purchased the decommissioned equipment. 

It is further alleged that some of the equipment went missing after it was decommissioned.

An investigation into the security incident was launched by the Office of the Comptroller of the Currency (OCC) after a vendor contacted Morgan Stanley in 2017 to inform the company that data belonging to its clients was accessible via the old technology. 

In July 2020, Morgan Stanley began notifying current and former clients who had been impacted by the data security incident. 

Three months later, the OCC issued Morgan Stanley with a consent order for the assessment of a $60m civil penalty.

The OCC found Morgan Stanley “failed to effectively assess or address risks associated with decommissioning its hardware; failed to adequately assess the risk of subcontracting the decommissioning work, including exercising adequate due diligence in selecting a vendor and monitoring its performance; and failed to maintain appropriate inventory of customer data stored on the decommissioned hardware devices” in connection with decommissioning two Wealth Management business data centers located in the US in 2016.

“In 2019, the banks experienced similar vendor management control deficiencies in connection with decommissioning other network devices that also stored customer data,” stated the OCC.

The $60m data breach settlement now awaits the approval of a federal judge in Manhattan.

In a statement issued Monday, Morgan Stanley said: “We have previously notified all potentially impacted clients regarding these matters, which occurred several years ago, and are pleased to be resolving this related litigation.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Aqua Security Appoints Paul Calatayud as CISO

Aqua Security Appoints Paul Calatayud as CISO

Aqua Security has announced the appointment of Paul Calatayud as its chief information security officer (CISO).

The Israeli cloud security firm has tasked Calatayud with developing its security program and support strategies to advance innovation in its cloud-native products. This includes advancing key certifications, such as FedRAMP.

Prior to joining Aqua, Paul Calatayud (pictured) was chief security officer at Palo Alto Networks for over four years
Prior to joining Aqua, Paul Calatayud (pictured) was chief security officer at Palo Alto Networks for over four years

Calatayud is a well-recognized figure in the world of cybersecurity, enjoying a distinguished career in the sector spanning more than two decades. Prior to Aqua, he was chief security officer at Palo Alto Networks for over four years. Before then, he held various security, privacy and risk roles at companies like SANS, FireMon and Code42.

Explaining the appointment, Dror Davidoff, co-founder and CEO of Aqua Security, said: “Security is at the core of what we do, and our ability to secure our own systems is as important as our ability to help our customers secure theirs.

“Paul understands the necessity to be both a manager of our risk and security posture as well as an educator and advisor to our customers. His knowledge and experience will be crucial as we continue to build our security team and scale the business.”  

Calatayud commented: “Aqua is the only pure-play provider of cloud-native security solutions, and I am eager to join the industry leader at this critical moment for the future of cybersecurity. In my role as CISO, I will focus on ensuring the integrity and security of Aqua’s solutions, so we can maintain the highest level of trust with our customers as they navigate their cloud transformations.”

This week, Palo Alto Networks announced the appointment of Helmut Reisinger as its CEO across the EMEA and LATAM regions.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Palo Alto Networks Appoints CEO for EMEA and LATAM Regions

Palo Alto Networks Appoints CEO for EMEA and LATAM Regions

Cybersecurity firm Palo Alto Networks has announced the appointment of Helmut Reisinger to CEO for its operations across the EMEA and LATAM regions.

Reisinger will join Palo Alto’s leadership team and is tasked with accelerating the company’s global growth strategy. He will work closely with Palo Alto Networks’ president BJ Jenkins to achieve this aim.

Reisinger comes with a wealth of experience in business leadership. Most recently, he was CEO of Orange Business Services, leading a global organization of around 28,000 employees. In this role, he spearheaded the digital transformation of enterprise customers worldwide. Previously, Reisinger has held leadership positions at Avaya Inc., NextiraOne Germany and Alcatel Austria.

He also holds a Ph.D. from Vienna University for Economics and Business (WU) and speaks English, French, German and Spanish.

Nikesh Arora, CEO and chairman of Palo Alto Networks, commented: “Helmut is a visionary executive who I’ve known as both a global business leader and close partner to our company.

“Given the recent rapid growth of the worldwide cybersecurity market, we see significant opportunities to accelerate our international business. Working together with BJ, Helmut’s relentless focus on the customer and understanding of the international business ecosystem will help us drive our robust EMEA business to future growth while developing our growing Latin American business.”

Reisinger said: “I am excited to join Palo Alto Networks’ extraordinary leadership team at what is a critical time for the cybersecurity industry. As a long-time partner, I’ve had the privilege of seeing first-hand how Palo Alto Networks’ continuous innovation is answering organizations’ cybersecurity needs with its unique end-to-end, cloud and platform-based approach. As demand to protect corporate and essential data escalates amid a growing threat landscape, there’s no company better positioned to address these challenges around the globe.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Info-Stealing Malware Hits 100+ Countries

Info-Stealing Malware Hits 100+ Countries

Researchers warn of a new malware campaign that has already stolen passwords and user information from over 2000 victims in 111 countries worldwide.

ZLoader is a known banking Trojan that uses web injection to steal cookies, passwords, and sensitive information. It has also been linked to the delivery of the infamous Conti and Ryuk ransomware variants.

In the past, ZLoader has been delivered via both traditional phishing email campaigns and abuse of online advertising platforms, where attackers purchase ads pointing to legitimate-looking websites hosting the malware.

The new campaign, attributed to cybercrime group Malsmoke, begins with the installation of a legitimate remote management program from Atera pretending to be a Java installation, according to Check Point.

This provides the attacker full access to the targeted system, enabling them to upload and download files and run additional scripts. One of these scripts purportedly runs “mshta.exe” with the file “appContast.dll” as the parameter.

Although appContast.dll is signed by Microsoft, the attackers found a way to exploit the firm’s digital signature verification method to add extra information to the file. This info downloads and runs the final Zloader payload, according to Check Point.

Malware researcher, Kobi Eisenkraft, explained that the Check Point team first spotted the campaign in November.

“People need to know that they can’t immediately trust a file’s digital signature. What we found was a new ZLoader campaign exploiting Microsoft’s digital signature verification to steal the sensitive information of users,” he added.

“All in all, it seems like the ZLoader campaign authors put great effort into defense evasion and are still updating their methods on a weekly basis. I strongly urge users to apply Microsoft’s update for strict Authenticode verification. It is not applied by default.”

Users were also urged not to install programs from unknown sources and not to click on links or open attachments in unsolicited messages.

It’s unknown exactly how this campaign is being disseminated, but the largest group of victims are located in the US (40%), followed by Canada (14%) and India (6%)

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

UK’s Information Commissioner Starts New Role Amid Major Changes

UK’s Information Commissioner Starts New Role Amid Major Changes

The UK’s new data protection tsar began his role this week at the start of what promises to be a momentous period of change for the Information Commissioner’s Office (ICO).

Former New Zealand privacy commissioner John Edwards will follow Elizabeth Denham into an increasingly important role as head of the UK’s privacy watchdog.

The ICO is the independent regulator for data protection and information rights laws, including the Data Protection Act 2018, the General Data Protection Regulation (GDPR), the Freedom of Information Act and the Privacy and Electronic Communications Regulations 2003, which govern nuisance marketing.

Edwards joins the ICO ahead of a promised government “overhaul,” which will see its governance model changed to mirror those of other regulators such as the Competition and Markets Authority (CMA), Financial Conduct Authority (FCA) and Ofcom. That means the creation of an independent board and chief executive position.

He will also oversee what could be significant reforms to the country’s data protection laws which some fear may cause it to diverge too far from the GDPR, imperiling cross-border data flows to the EU.

The government wants to make it easier to strike data adequacy partnerships with other non-EU countries worldwide and sees a new, more flexible regime as key to this – one “based on common sense, not box-ticking.”

Other significant jobs on Edwards’ to-do list will be the introduction of the controversial Online Safety Bill, which promises a much more substantial role for Ofcom in holding tech companies to account for the content disseminated over their platforms.

He will also be tasked with ensuring responsible use of health data in the fight against the COVID-19 pandemic and the simplification of data use by scientists and researchers to help drive innovation without infringing on privacy rights.

“Privacy is a right not a privilege. In a world where our personal data can drive everything from the healthcare we receive to the job opportunities we see, we all deserve to have our data treated with respect,” Edwards said in a statement.

“The ICO has an international reputation for forward thinking and clear assessment of the practicalities of the law, which I will continue to promote. I know too of the active data protection community in the UK – I look forward to hearing the experiences of businesses, the public sector, civil society and the privacy community.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

FTC: Patch Log4j Now or Risk Major Fines

FTC: Patch Log4j Now or Risk Major Fines

The Federal Trade Commission (FTC) has urged US organizations to patch the recently discovered Log4Shell vulnerability or risk facing punitive action from the agency.

The consumer protection agency said that the original CVE-2021-44228 bug found in the Java logging utility late last year is being widely exploited in the wild and poses “a severe risk to millions of consumer products,” including enterprise software and web applications.

“When vulnerabilities are discovered and exploited, it risks a loss or breach of personal information, financial loss and other irreversible harms,” it continued.

“The duty to take reasonable steps to mitigate known software vulnerabilities implicates laws including, among others, the Federal Trade Commission Act and the Gramm Leach Bliley Act. It is critical that companies and their vendors relying on Log4j act now, in order to reduce the likelihood of harm to consumers, and to avoid FTC legal action.”

The FTC highlighted the case of Equifax, one of the big three credit agencies, which failed to patch a known Apache Struts flaw back in 2017, leading to the compromise of sensitive info on 147 million consumers. The firm subsequently agreed to pay $700m to settle with the agency and individual states.

“The FTC intends to use its full legal authority to pursue companies that fail to take reasonable steps to protect consumer data from exposure as a result of Log4j, or similar known vulnerabilities in the future,” it said.

Although Log4Shell was the first and most dangerous bug found in Log4j recently, it was followed by several more disclosures, including CVE-2021-45046, a denial of service (DoS) vulnerability subsequently found to enable information leakage and remote code execution in some environments.

This was followed in late December by DoS bug CVE-2021-45105 and arbitrary code execution flaw CVE-2021-44832.

Microsoft warned on Monday that “exploitation attempts and testing have remained high during the last weeks of December,” with commodity attackers and nation-state actors alike looking to cash in.

“At this juncture, customers should assume broad availability of exploit code and scanning capabilities to be a real and present danger to their environments,” it added.

“Due to the many software and services that are impacted and given the pace of updates, this is expected to have a long tail for remediation, requiring ongoing, sustainable vigilance.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains