NY Makes Falsifying Vaccination Cards a Crime

NY Makes Falsifying Vaccination Cards a Crime

The state of New York has passed a law that makes it a crime to falsify information on a COVID-19 vaccination card.

New York governor Kathy Hochul signed new legislation on Wednesday that makes falsifying information on a COVID-19 vaccination card a Class D felony comparable under the New York Penal Law to promoting a sexual performance by a child, first degree sexual abuse, second degree assault, and second-degree vehicular manslaughter. 

The legislation, dubbed the “Truth in Vaccination” law, has also created a new Class E felony of computer tampering in the third degree “for intentional entering, alteration or destruction of ‘computer material’ regarding COVID-19 vaccine provisions.”

Other crimes recognized as Class E felonies under the New York Penal Law include criminally negligent homicide, weapons possession on school grounds, and third-degree rape.

Sentencing for Class D felonies ranges from no prison time (with probation) to a maximum of seven years in prison. A New Yorker convicted of a Class E felony could receive a maximum prison sentence of four years.

The maximum fine that can be imposed for a Class D or Class E felony in New York is $5,000 or double the amount of money that a defendant gained by committing their crime. 

Hochul said that the legislation represented “a major step forward in the State’s efforts to increase vaccination rates.”

“We need to make sure we learn the lessons of the pandemic so we don’t make the same mistakes twice,” Governor Hochul said. “These new laws will help us improve our response to the pandemic now, crack down on fraudulent use of vaccination records, and help us better understand the areas of improvement we need to make to our healthcare system so we can be even more prepared down the road.”

Hochul also signed legislation to give schools more access to New York’s statewide Immunization Database. 

Assembly member Jeffrey Dinowitz said: “This new law will undoubtedly help prosecutors and other law enforcement hold people accountable for the damage they are doing to public health by undermining the efficacy of vaccination requirements in workplaces, businesses, restaurants, and more.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Hellmann Warns Customers They Could Face Malicious Communications Following Attack

Hellmann Warns Customers They Could Face Malicious Communications Following Attack

German logistics provider Hellmann Worldwide Logistics has warned customers social engineering attacks could target them after being hit by a ransomware attack earlier this month.

In an update on the incident, which forced the company to take its IT systems temporarily offline on December 9, Hellmann confirmed that the attackers extracted data. While it is still investigating what type of data was stolen, the firm warned its partners and customers to beware of fraudulent emails and calls “in particular regarding payment transfers, changing bank details or the like.”

While reassuring customers that email and phone communication with Hellmann staff remains safe, they should take steps to ensure any contact from someone purporting to be from the firm is genuine.

Hellmann stated: “As reported, the forensic investigation has confirmed that data was extracted from our servers before our systems were temporarily taken offline as a precautionary measure on December 9. We are currently investigating what type of data was extracted. Should we receive indications that third parties are affected, we will inform them proactively. We are in regular contact with relevant government authorities.”

The company also confirmed its sales team continues to be reachable 24/7, and customers with any questions about the incident can email Crisis-faq@hellmann.com.

Hellmann was founded a century and a half ago and has 489 offices across 174 countries. The company handles approximately 16 million shipments per year, and in 2020, it reported revenues of $2.8bn.

In its original statement regarding the attack, the company said: “We can currently not rule out that there have been data leakages or unauthorized use of data.”

Social engineering attacks, such as phishing, are more likely to succeed if the attackers can tailor their communications to individuals, as they look more plausible. They are often able to do this through accessing personal information like names, email addresses and date of birth through data breaches.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Former Uber CSO Faces New Charge for 2016 Breach

Former Uber CSO Faces New Charge for 2016 Breach

A federal grand jury has charged Uber’s former chief security officer (CSO) with three counts of wire fraud for reportedly failing to inform several hundred thousand Uber drivers that their driver’s licenses had been exposed during a 2016 breach.

The superseding charges made to Joe Sullivan, 52, who served as Uber’s CSO from April 2015 through November 2017, followed original charges in August 2020 of obstruction of justice and concealing a felony. If convicted of those charges, Sullivan faces up to eight years in prison and a $500,000 fine.

Prosecutors claim that Sullivan should have reported the 2016 breach to authorities, a breach that exposed the personal information of 57 million riders, including some 600,000 drivers.

In 2018, Uber paid a $148m settlement to the 50 states and the District of Columbia. Notwithstanding, the separate criminal charges against Sullivan progressed. Sullivan faces up to eight years in prison and a $500,000 fine if convicted of the 2020 charges. 

A court date for Sullivan, who now serves as Cloudflare’s CSO, has not been set.

“Institutions that store personal information of others must comply with the law,” said Stephanie M. Hinds, the acting U.S. Attorney for the Northern District of California, where Sullivan formerly served as a federal prosecutor.

“When hacks like this occur, state law requires notice to victims,” Hinds said. “Federal law also requires truthful answers to official government inquiries. The indictment alleges that Sullivan failed to do either.

“We allege Sullivan falsified documents to avoid the obligation to notify victims and hid the severity of a serious data breach from the FTC, all to enrich his company.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Unique Cyber-Attacks Fall for First Time Since 2018

Unique Cyber-Attacks Fall for First Time Since 2018

Unique cyber-attacks declined for the first time in nearly three years in Q3 2021, according to new data from Positive Technologies.

The researchers observed a 4.8% decline in unique attacks in Q3 compared to the previous quarter, the first time they have recorded a reduction since the end of 2018. They said that this trend was primarily by a decline in ransomware attacks and the fact that a number of large cybercrime gangs have seen their activities curtailed by law enforcement. This includes successful actions against the notorious REvil ransomware group, which US authorities forced offline in October.

Positive Technologies recorded 45 ransomware attacks in September, representing a 63% reduction compared to the peak number of attacks in April (120).

The decline in ransomware helped explain why attacks aimed at compromising corporate computers, servers and network equipment fell from 87% to 75% quarter-on-quarter, according to the authors.

The report also noted a rebranding of a number of existing ransomware gangs in Q3. For example, some of these threat actors are rethinking their preference for ransomware-as-a-service (RaaS) due to concerns about relying on third parties.

Ekaterina Kilyusheva, head of research and analytics at Positive Technologies, commented: “In Q2, we predicted that one of the possible scenarios of ransomware transformation would be that groups abandon the RaaS model in its current form. It is much safer for ransomware operators to hire people who will deliver malware and search for vulnerabilities as permanent ‘employees.’ It will be safer for both parties, as more organized and efficient all-in-one forms of cooperation can be created. In Q3, we saw the first steps in this direction. An additional boost for this transformation is the development of the market of initial access.”

While the overall malware attacks fell by 22% over this period, the analysis revealed a significant increase in the use of remote access Trojans, driven by attackers’ growing desire to access data. In regard to attacks against organizations, the share of remote access Trojans increased from 17% to 36%. Against individuals, it made up over half of all used malware.

Another notable trend outlined in the study was that the share of attacks conducted by APT groups rose to 5% in Q3. The researchers believe this is due to a large number of phishing and intelligence campaigns against employees of government agencies, industrial enterprises and media workers.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

What’s the Difference Between Identity Fraud and Identity Theft?

What’s the difference between identity fraud and identity theft? Well, it’s subtle, so much so that it’s easy to use them nearly interchangeably. While both can take a bite out of your wallet, they are different—and knowing the differences can help you know understand what’s at stake. 

Let’s start with an overview and a few examples of each. 

Identity fraud is … 

  • When someone steals or misuses your personal information to exploit an account or accounts you already have.  
  • Examples:  
  • A criminal gets a hold of your debit card information from a data breach and makes purchases with it against your bank account. 
  • A criminal gains access to one of your accounts via a phishing attack and misuse the funds or otherwise misuses the access associated with that account. 

Identity theft is … 

  • When someone uses your personal information to open and abuse new accounts or services in your name—or possibly to impersonate you in other ways. 
  • Examples: 
    • A criminal uses your personal information to open a new line of credit at a retailer under your name and then makes purchases against the line of credit.  
    • A criminal uses your Social Security Number to create a driver’s license with their likeness but your name and personal information. 

So there’s that subtle difference we mentioned. Identity fraud involves misuse of an existing account. Identity theft means the theft of your personal information, which is then used to impersonate you in some way, such as opening new accounts in your name. 

Above and beyond those definitions and examples, a couple of real-life examples put the differences in perspective as well. 

Identity fraud in the news 

As for identity fraud, individual cases of fraud don’t always make the headlines, but that’s not to say you won’t hear about it a couple of different ways.  

The first way may be news stories about data breaches, where hackers gain things like names, emails, and payment information from companies or organizations. (ChipotleRobinHood, and T-Mobile being recent examples.) That info can then end up in the hands of a fraudster, who then accesses those accounts to drain funds or make purchases.  

On a smaller scale, you may know someone who has had to get a new credit or debit card because theirs was compromised, perhaps by a breach or by mistakenly making a payment through an insecure website or by visiting a phony login page as part of a phishing attack. These can lead to fraud as well. 

Identity theft in the news 

Identity theft took on new forms during the pandemic, such as was the case of a Rhode Island man charged with nearly half a million dollars in a pandemic unemployment fraud case. Authorities allege that the man-made 85 unemployment claims in 2020 using the identities of several other people.  

Similarly, a Massachusetts man was sentenced for filing fraudulent claims for relief funds, as well as open store credit accounts using fake identities. Court proceedings alleged that the personal information used to commit this fraud came from several sources, including information stolen from a realty company that collected that information from potential renters.  

Identity theft can stem from the workplace as well, such as the sentencing of a Maryland man who used stolen lists of personal information from his former employer. From there, he was found guilty of garnering more than a million dollars in funds from food assistance programs and fraudulent car loans.  

Identity theft can run far deeper than these examples. Because it effectively allows someone else to pose as you, an identity thief can do more than drain your accounts. They can also claim health insurance benefits, file taxes in your name, or possibly purchase the property. Further, an identity thief can potentially get a job, driver’s license, or other forms of ID in your name, which could ruin your credit history, reputation, or even create a police record in your name.  

So while both identity fraud and identity theft are certainly something you want to prevent, identity theft holds the potential to affect far-reaching aspects of your life—which marks a distinct difference between the two. 

Spotting identity fraud and theft (and preventing it too) 

It usually starts with someone saying anything from, “That’s strange …” to “Oh, no!” There’ll be a strange charge on your credit card bill, a piece of mail from a bill collector, or a statement from an account you never opened—just to name a few things. 

With that, I have a few recent blogs that help you spot all kinds of identity crime, along with advice to help keep it from happening to you in the first place: 

Keep a sharp eye out 

While there are differences between identity fraud and identity theft, they do share a couple of things in common: you can take steps to prevent them, and you can take steps to limit their impact should you find yourself faced with one or the other.  

The articles called out above will give you the details, yet staying safe begins with vigilance. Check on your accounts and credit reports regularly and really scrutinize what’s happening in them. Consider covering yourself with an —and act on anything that looks strange or outright fishy by reporting it to the company or institution in question.  

The post What’s the Difference Between Identity Fraud and Identity Theft? appeared first on McAfee Blogs.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Russian Hacker’s $1.7M Restitution Order Overturned

Russian Hacker’s $1.7M Restitution Order Overturned

A Russian cyber-criminal who hacked into three tech companies and stole more than 100 million user credentials will not have to pay restitution to his corporate victims.

Yevgeniy Aleksandrovich Nikulin was found guilty in July 2020 of causing data breaches at LinkedIn, Dropbox, and the now defunct social media platform Automatic in 2012. 

Speaking during the closing arguments of Nikulin’s trial, Assistant United States Attorney Katherine Wawrzyniak told the jury: “The data from one intrusion facilitated the next.”

Nikulin gained access to LinkedIn’s data by hacking into the personal computer of LinkedIn engineer Nick Berry, then installing malware that gave him access to Berry’s virtual private network (VPN) and the login credentials used by Berry to work remotely.

Nikulin used Berry’s credentials to access LinkedIn’s internal database and steal user credentials, which he then sold to associates. Some of the stolen data was used by Nikulin to infiltrate the work account of Dropbox employee Tom Wiegand and gain access to a shared employee Dropbox account.

Next, Nikulin used credentials stolen from Dropbox to compromise the work account of Formspring employee John Sanders and exfiltrate millions of hashed user passwords. 

Nikulin was sentenced to serve 88 months in federal prison by US District Judge William Alsup. Nikulin was further ordered to pay LinkedIn half the $2m restitution that the company had requested.

Alsup also ordered Nikulin to pay restitution of $514,000 to Dropbox, $20,000 to Formspring, and $200,000 to WordPress parent company Automatic.

On Wednesday, the Ninth Circuit overturned the restitution award. A three-judge panel found insufficient evidence to justify the compensation payment of $1.7m.

The order issued by the panel stated: “Although trial testimony and logs submitted at trial showed the extent of the victims’ responses to the computer intrusions, that evidence did not provide a basis for determining the costs incurred by the victims in mounting those responses.”

Letters submitted to the court by the victim companies were deemed by the judges not to satisfy government requirements to provide a complete accounting of the losses to each victim to the extent practicable.

However, the panel did uphold the prison sentence of more than seven years handed to Nikulin by Alsup.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Army Recruiter Cyber-Stalked by Wannabe Soldier

Army Recruiter Cyber-Stalked by Wannabe Soldier

A man from Virginia has admitted cyber-stalking a United States Army recruiter for two years. 

Braxton Louis Danley, a 26-year-old resident of Luray, began harassing the female victim after failing to pass the army’s entrance exam.

Prosecutors said Danley’s first contact with the victim occurred in February 2018 when he sent her an email asking for information on joining the US Army. 

A month later, Danley met the recruiter in person when he visited her recruiting station in Harrisonburg, Virginia. It was on this occasion that Danley took and failed the entrance exam.

The wannabe soldier was told by the victim and by other army recruiters that he should keep studying and retake the exam at a future date. 

Prosecutors said that after receiving this advice, Danley began repeatedly making calls to the army-issued cellphone belonging to the victim, whose identity was not disclosed in court filings.

During the calls, Danley kept asking the victim when he could retake the exam.

Prosecutors said: “Each time, Danley was asked if he had studied for the test – which he admitted that he had not – and was advised that he would only be permitted to retake the test after he had studied.”

In May 2018, after two months of phone calls, Danley started to send the victim abusive emails and text messages and to express his anger over the phone. In one email he wrote: “I remember every thing you [expletive] done to me so time to settle the score.”

Danley then took to posting abusive and physically threatening messages on social media to the victim and two other army recruiters. 

In response to Danley’s campaign of harassment, the victim took out a restraining order against him. When he violated that order, Danley was sentenced to a year in prison. 

Within a few months of his release in June 2019, Danley started harassing the victim again via Facebook. In August 2020, a grand jury indicted Danley on one count of cyber-stalking and three counts of interstate threats.

On December 20, Danley pleaded guilty to cyber-stalking. He is due to be sentenced on February 1 and faces a maximum sentence of five years in prison.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Texas Convicts BEC Scammer

Texas Convicts BEC Scammer

A Texas resident has been convicted of stealing hundreds of thousands of dollars from a school district in Idaho through a business email compromise (BEC) scam.

Teton School District 401, which serves 1,800 students in seven schools in Teton County, fell victim to the cybercrime three years ago. 

In 2018, the district’s business manager, Carl Church, unknowingly made an electronic payment to a fraudulent bank account accessed through his district email account. 

Church transferred $784,833.71 in the belief that he was paying Headwaters Construction Company, a general contractor based in Victor, Idaho, which had been hired by the district to build new schools. 

In January 2019, after news of the cybercrime became public, Church resigned from his position. Speaking at the time, Teton County Deputy Andrew Sewell emphasized that Church was not suspected of any wrongdoing.

Sewell said the BEC cyber-attack “was a believable scam that he [Church] fell victim to.”

The incident was investigated by the Federal Bureau of Investigation. Over half the stolen funds were eventually recovered, and the state insurance carrier ICRMP paid the remaining balance. 

Houston resident Julius Joachim Ohumole, who moved to the United States from his native Nigeria, was charged over the cybercrime on November 8, 2019, and later taken into custody. 

On December 31, 2019, the US Attorney’s Office for the Southern District of Texas announced that 37-year-old Ohumole had been charged with one count of conspiracy, four counts of bank fraud, and two counts of aggravated identify theft.

Teton Valley News reported Wednesday that Ohumole has now been convicted and is due to be sentenced in February 2022. 

Superintendent Monte Woolstenhulme shared news of the conviction at a meeting of the school board on December 13. Woolstenhulme informed the trustees that he had been notified of the conviction by the US Department of Justice in Texas.

Each count of conspiracy and bank fraud carries a possible sentence of up to 30 years in federal prison and a maximum fine of $1m. The aggravated identify theft charge carries a maximum sentence of up to two years in prison.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains