Consumers Warned of Surging Delivery Text Scams Ahead of Christmas

Consumers Warned of Surging Delivery Text Scams Ahead of Christmas

Consumers have been warned to stay vigilant of delivery scam texts while online shopping for Christmas and during the Boxing Day sales.

UK Finance cited new data from cybersecurity firm Proofpoint showing that delivery ‘smishing’ scams are surging amid the busiest shopping period of the year. This showed that over half (55.94%) of all reported smishing text messages impersonated parcel and package delivery companies so far in Q4 2021. This compares to just 16.37% of smishing attempts in Q4 2020, more than tripling the proportion year-on-year.

Proofpoint also observed a significant drop-off in other types of smishing scams in Q4 2021 compared to Q4 2020. For example, text scams impersonating financial bodies and banks made up 11.73% of smishing attacks in 2021, compared to 44.57% in 2020.

The data comes from the NCSC’s 7726 text message system, operated by Proofpoint. This system enables customers to report suspicious texts.

Typically, delivery smishing scams start with the fraudster sending a fake text message informing the recipient that the courier has been unable to make a delivery and requesting a fee or additional details to rearrange. The consumer will be given a link to a fraudulent website impersonating the package delivery company, in which they are prompted to provide personal and financial details.

This type of scam has become increasingly prominent following the enormous growth in online shopping during COVID-19. Earlier this year, Proofpoint revealed that over two-thirds (67.4%) of all UK texts were reported as spam to the NCSC’s 7726 text messaging system in the 30 days to mid-July 2021.

A recent investigation by Which? demonstrated a particularly sophisticated smishing scam involving a highly convincing DPD copycat website.

Katy Worobec, managing director of economic crime at UK Finance, commented: “Scrooge-like criminals are using the festive season to try to trick people out of their cash. Whether you’re shopping online or waiting for deliveries over the festive period, it’s important to be on the lookout for scams.

“Don’t let fraudsters steal your Christmas – always follow the advice of the Take Five to Stop Fraud campaign and stop and think before parting with your information or money.”

Commenting, Steve Bradford, senior vice president EMEA at SailPoint, said: “The sharp rise in text message scams – or smishing, which has increased tenfold compared to last year, should be a stark warning to the public. With parcel delivery scam texts expected to spike this Christmas, it’s clear cyber-criminals are using every opportunity available to target victims using new methods.

“This comes as more businesses use SMS to engage with customers, to accommodate the digital-first mindset that now characterizes many consumers. But this also opens the doors to threat actors able to masquerade as popular websites or customer service support.

“Consumers must be extra vigilant and refrain from clicking any links in text messages that they’re unsure about. It’s also crucial they are keeping their data, identities and banking information safe – for example, by not taking pictures of their credit card and financial information, since photos often get stored in the cloud, which risks potential exposure to malicious actors.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Alibaba Suffers Government Crackdown Over Log4j

Alibaba Suffers Government Crackdown Over Log4j

Chinese tech giant Alibaba has reportedly been shunned by China’s top tech regulator for failing to report the infamous Log4j vulnerability quickly enough.

Local media claimed that the firm’s Alibaba Cloud business, which has a large team of security researchers, failed to report the issue to the Ministry of Industry and Information Technology (MIIT).

According to news site Protocol, a Chinese regulation dubbed Provisions on Security Loopholes of Network Products was in force as of September. It mandates vulnerabilities be reported immediately to the manufacturer and within two days to the Chinese authorities.

As a result, Alibaba Cloud has reportedly been suspended from MIIT’s threat information sharing platform for six months.

Alibaba Cloud researcher Chen Zhaojun is credited by Apache with finding the first bug in the popular logging utility, dubbed “Log4Shell.”

It was given a CVSS score of 10.0, with commentators describing it as a “worst-case scenario” because the utility is near-ubiquitous in enterprises, can be hard to find, and the bug is relatively easy to exploit.

Chen reportedly notified Apache on November 24, but MIIT only became aware of it on December 9.

Research from several years ago claimed that China’s National Vulnerability Database (CNNVD) is faster at updating with the latest CVEs than the US equivalent (NVD).

However, the researchers later found that this was down to government manipulation.

On further investigation, they found that the Chinese authorities tried to backdate original publication dates for vulnerabilities to disguise their own work to exploit these bugs in state-backed attacks.

Recorded Future argued that the CNNVD is essentially a “shell” for the government’s fearsome Ministry of State Security (MSS), a prodigious hacker of foreign entities.

“This systemic retroactive alteration of original publication dates by CNNVD is an attempt to hide the evidence of this process, obfuscate which vulnerabilities the MSS may be utilizing, and limit the methods researchers can use to anticipate Chinese APT behavior,” the firm said at the time.

“There is no other logical explanation as to why only the initial publication dates for outlier CVEs would have been altered.”

The latest action against Alibaba could also be viewed as part of a recent Communist Party crackdown on big tech, which has cost investors trillions.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

CISA Releases Free Scanner to Spot Log4j Exposure

CISA Releases Free Scanner to Spot Log4j Exposure

The US government’s top security agency has published a new scanning tool to help organizations find unpatched Log4j instances in their IT environment.

The Cybersecurity and Infrastructure Security Agency (CISA) posted the Log4j Scanner to GitHub yesterday. It claimed it’s a “project derived from other members of the open-source community” and designed to help find vulnerable web services impacted by the two flaws in the popular logging tool.

“This repository provides a scanning solution for the log4j remote code execution vulnerabilities (CVE-2021-44228 & CVE-2021-45046),” CISA said. “The information and code in this repository is provided ‘as is’ and was assembled with the help of the open-source community and updated by CISA through collaboration with the broader cybersecurity community.”

Cybersecurity firm FullHunt was name-checked in the release.

Log4j was patched earlier this month but exploits appeared soon after. The initial CVE-2021-44228 bug, dubbed “Log4Shell” was given a CVSS score of 10.0.

It’s deemed particularly dangerous as Log4j is found in numerous third-party software from iCloud to Minecraft. In some cases, it can be exploited relatively easily to achieve RCE for ransomware, cryptojacking, data theft, and more. All Log4j instances may be difficult to find given the complex Java dependencies operating in many enterprise environments.

As a result, some experts have said the threat could persist for years.

A second denial of service flaw (CVE-2021-45046) was found days later, although it has a lower CVSS score of 7.5.

CISA said the scanning tool would only help security teams “look for a limited set of currently known vulnerabilities in assets owned by their organization.” It warned that there may be “as yet unknown” ways for threat actors to leverage the vulnerabilities and said it is continuing to monitor community chatter to ensure its advice is current.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Up to 120,000 Cops May Have Legal Claim Over 2019 Breach

Up to 120,000 Cops May Have Legal Claim Over 2019 Breach

Lawyers are seeking a “group litigation order” against the Police Federation (PFEW) over a 2019 ransomware breach which they say may have impacted 120,000 officers.

Keller Lenkner UK said it served notice this week to the staff association for police constables, sergeants, inspectors and chief inspectors in England and Wales. It intends to seek the order from the High Court in early 2022.

As reported by Infosecurity at the time, the PFEW’s IT systems were first hit on March 9 2019, and then again ten days later.

It claimed that several databases and systems at its Surrey headquarters had been affected.

“Back-up data has been deleted and has been encrypted and became inaccessible. Email services were disabled and files were inaccessible,” an FAQ statement noted.

Although the attack was halted before it could spread to any regional branches across the country, Keller Lenkner claims that the federation did not have adequate data security processes.

This may have led to personal and financial data theft from members. The law firm is also alleging that the PFEW didn’t inform members until a fortnight after the breach, despite GDPR obligations to the contrary.

Group litigation orders are the UK’s equivalent of a US class action suit. However, unlike class actions, where affected parties are included in the suit unless they opt-out, the UK version requires potential litigants to opt-in proactively.

Therefore, each case will be judged on its own merits, but Keller Lenkner said it is looking into pursuing action around financial loss, distress, and loss of privacy for the breach victims.

It claimed that breached information included names, email addresses, national insurance (NI) numbers, ranks and serving forces of up to 120,000 officers, and names, addresses and email addresses of guests who visited the PFEW’s conference Leatherhead.

Also compromised were names, addresses, NI numbers and bank details of members who requested the federation’s assistance for “any investigation, inquiry or complaint.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Cyber-Attack on Belgium’s Military

Cyber-Attack on Belgium’s Military

Threat actors have exploited a vulnerability in Log4j software to wage a cyber-attack on Belgium’s Defense Ministry.

The attack began on December 16 and was confirmed by Belgium’s Ministry of Defense on Monday. 

Speaking to the AFP in Brussels on Tuesday, Belgian military spokesman Commander Olivier Séverin said that the incident had caused damage to services that were connected to the internet, paralyzing part of the ministry’s activities. 

He added that five days after the attack began, analysis of the incident was still being carried out and the process of restoring disrupted services remained ongoing.

Séverin did not shed any light on who may have been responsible for the cyber-attack. 

A spokesperson for Belgian Defense Minister Ludivine Dedonder said that “the ministry’s teams have been working hard in past days to secure its networks” and that the Belgian government will continue to invest in cybersecurity defenses.

Log4j is a Java-based logging library that tracks system processes. Security teams around the world have been working to secure their systems after multiple vulnerabilities were discovered in Log4j earlier this month.

Mike Saxton, chief technologist at Booz Allen and director of Federal Threat Hunt and Digital Forensics and Incident Response (DFIR) urged organizations to act now to mitigate the Log4j vulnerability. 

“Most immediately, organizations must establish and see through a plan that begins with the following: 1) Implementing sensor blocks; 2) Disabling Log4J; 3) Identifying and patching vulnerable versions; 4) Disabling JNDI lookups; 5) Disabling remote codebases; 6) Performing scan with updated vulnerability management templates; 7) Performing searches and analysis of all security logs for evidence of enumeration or compromise; 8) Consolidating, communicating, and disseminating updated threat intel associated with Log4j; 9) Tracking all remediation and mitigation efforts and tasks; 10) Continuing to apply up-to-date blocking measures; 11) Monitoring LDAP traffic; and 12) Moving vulnerable systems behind additional firewalls,” said Saxton. 

He added: “This list may seem overwhelming, but it should be viewed as a template rather than a checklist that organizations can follow.”

In the long term, Saxton advised organizations to move to a persistent threat hunt model and to work under the assumption that their vulnerable assets will be breached. 

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Cybercrime Cops Arrest NHS Workers

Cybercrime Cops Arrest NHS Workers

Cybercrime officers in the United Kingdom have arrested two individuals employed by the National Health Service (NHS) in connection with an investigation into suspected fake COVID-19 vaccination records.

The Metropolitan Police’s Cyber Crime Unit launched an investigation after suspicious vaccination records were flagged within the NHS Trust’s online electronic health records system. 

On December 14, a 36-year-old man from Ilford, East London, was arrested on suspicion of unauthorized computer access and conspiracy to commit fraud by misrepresentation. Police said that the man has since been released from custody but remains under investigation.

On Wednesday, cybercrime officers investigating the alleged records forgery made a second arrest. Suspect number two is a 28-year-old woman from Redbridge, East London.

The unnamed woman was arrested on suspicion of conspiracy to commit offenses under section 2 of the Computer Misuse Act, fraud by false representation, and money laundering. 

The investigation team have seized two laptops and two cell phones belonging to the female suspect, who is now in police custody. 

Police said that both suspects are employed by the same National Health Service Trust.

These latest two arrests by the Metropolitan Police follow other arrests made in Ilford last week in connection with the suspected forgery of vaccination records. 

Detective Inspector Alex Flanagan, from the Cyber Crime Unit, said: “Following arrests last week regarding two separate investigations into fake vaccine records, we have identified a fourth person suspected to be involved. 

“Misuse of IT systems is extremely serious; we will be analyzing all devices seized and are working closely with our partners.”

Flanagan said that the alleged cyber-criminal activity at the NHS trust did not involve an incursion by an external threat actor but appeared instead to be the result of an insider threat.

“I want to stress that no systems were hacked into from outside of NHS networks,” he said. 

Flanagan went on to ask the British public not to keep their suspicions to themselves in cases of suspected inoculation fraud.

“If anyone has information regarding fraudulent COVID-19 vaccination records then it is important you report what you know to Action Fraud,” he said.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains