Cyber-Attack Impacts Aussie Companies

Cyber-Attack Impacts Aussie Companies

A cyber-attack on Australian recruitment company Finite Group is impacting both companies and government agencies across the country.

Finite was compromised by threat actors in October in an incident that is still being investigated. During the attack, some of the company’s data was exfiltrated and later published online.

Information stolen in the attack includes the personal details of employment-seeking Australians who registered with the company. News source ABC viewed stolen data that contained individuals’ resumes, salary details, and details of checks that had been carried out to verify their employment references, criminal history, and visa information.

The cyber-criminals behind the attack threatened to release the data unless they received a ransom payment. 

Finite serves the recruitment needs of corporate clients and government agencies as well as those of individuals. Banks, businesses, and government agencies that have reportedly been impacted by the cyber-attack on Finite include Adairs, AMP, Westpac, Coles, ME Bank, Suez Australia, NBN Co., and the departments of defense, health, and home affairs.

Finite said that it will contact any individuals and stakeholders impacted by the incident to notify them that their data may have been compromised. 

The Conti ransomware gang has claimed responsibility for the attack on Finite. In a notice posted on its website, the cyber-criminal organization bragged that it had stolen more than 300 gigabytes of data from Finite. 

The stash allegedly included financial data, contracts, NDA forms, customer databases with phone numbers and addresses, contracts with employees, scans of passports, and mail correspondence. 

Conti was also responsible for a recent attack on the South Australian government’s payroll provider in which the personal information of public-sector workers in South Australia was compromised. 

The attack on Frontier Software exposed the names, dates of birth, tax file numbers, home addresses, bank account details, remuneration, and superannuation contributions of close to 80,000 workers.

Speaking last week, State Treasurer Rob Lucas said: “I am advised all public sector employees, except for Department of Education staff who are on a different payroll system, should assume that their personal information has been accessed during Frontier Software’s cyber-attack.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Tech Companies to Protect Data on Undersea Cable

Tech Companies to Protect Data on Undersea Cable

American companies Google and Meta have agreed to protect data traveling on an undersea fiber-optic cable system that will connect the United States, Taiwan, and the Philippines. 

On Friday, the Department of Justice announced that Google LLC and its subsidiary GU Holdings Inc., and Meta Platforms Inc. (formerly known as Facebook Inc.) and its subsidiary Edge Cable Holdings USA LLC have entered into national security agreements to safeguard data traveling on the Pacific Light Cable Network (PLCN) system.

The agreements were made with the Departments of Justice (DOJ), Defense (DOD), and Homeland Security (DHS) in their roles as members of Team Telecom (the Committee for the Assessment of Foreign Participation in the United States Telecommunications and Services Sector).

Under the agreements, Meta and Google will annually assess what risk exists to sensitive data moving through the PLCN system. Their risk assessments will also delve into what happens to data when it exits the cable.

The companies will also pursue ways to diversify the system’s interconnection points in other parts of Asia, including Thailand, Singapore, Vietnam, and Indonesia. 

Meta and Google have further agreed to restrict access to information and infrastructure by the Hong Kong–based owner of PLCN, Pacific Light Data Communications Co. Ltd (PLCD). 

PLCD applied for an FCC license but withdrew the application after Team Telecom, in June 2020, advised against accepting PLCD’s proposal to connect the PLCN to Hong Kong and to the portions of the PLCN owned by PLDC.

“These agreements enable Google and Meta to take advantage of critical, additional cable capacity while protecting US persons’ privacy and security through terms that reflect the current threat environment,” said Assistant Attorney General Matthew G. Olsen of the Justice Department’s National Security Division.

Olsen, who leads Team Telecom’s work for the Justice Department, added: “This resolution also demonstrates Team Telecom’s ability to resolve complex cases involving critical infrastructure in a timely matter, thanks to recent reforms of our structure and process.”

Under the agreement, Edge USA has the ability to interrupt traffic to and from the United States on the U.S.–Philippines segment within twenty-four hours of notice.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Ransomware Gang Publish Confidential Police Data on the Dark Web

Ransomware Gang Publish Confidential Police Data on the Dark Web

The Clop ransomware gang has published confidential data held by UK police on the dark web, according to reports over the weekend.

The Mail on Sunday reported that the notorious cybercrime group accessed the information following a successful phishing attack on IT services provider Dacoll in October 2021. This provided Clop with access to vast amounts of material, including data held on the police national computer (PNC), which Dacoll manages.

According to the Mail on Sunday, the attackers uploaded hundreds of files on the dark web after Dacoll refused to pay a ransom demand. Among the PNC files uploaded were close-up images of motorists taken from the UK’s National Automatic Number Plate Recognition (ANPR) system.

It is currently unclear whether Clop holds other information held by the UK Police that it could release in the future.

The report quoted a spokesman for the National Cyber Security Centre (NCSC), who stated: “We are aware of this incident and working with law enforcement partners to fully understand and mitigate any potential impact.”

Breaches of data held by law enforcement agencies are especially concerning, given their highly confidential nature, the potential to disrupt criminal investigations and even fears serious risks will be posed to victims and witnesses of crime should the information fall into the wrong hands. Earlier this year, an FoI request revealed there were more than 2300 data breach incidents reported by just 22 UK police forces in 2020.

Commenting on the story, Jake Moore, cybersecurity specialist at ESET, said: “You may be mistaken for thinking that sensitive data held by police is under very strong protection, but the truth is that even this level of security can still very easily be breached. The level of cybersecurity protection on offer remains as strong as the weakest link, which is often swung by the human factor. The release of personal information amplifies the attackers’ demands and highlights their anger at not having their demands listened to.  

“Like many persistent campaigns, Clop is very sophisticated and determined in their ways, making it very difficult to mitigate against. When very targeted attacks persist, it is very onerous to withstand, and therefore relying on current measures with a touch of good fortune is often the only answer. The release of this data could have very dangerous consequences for those affected and they should ideally be made aware to reduce any follow-on impact.”

The Clop group is believed to be responsible for a number of major ransomware attacks in recent years, including on oil giant ShellSwire Pacific Offshore and the University of California. In November, Interpol revealed it is still on the hunt for two suspected members of the Clop ransomware gang after making multiple arrests in the summer following a 30-month operation.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Ukrainian War Games Test Electricity Grid

Ukrainian War Games Test Electricity Grid

Hundreds of Ukrainian cyber experts have taken part in a large-scale incident response exercise against the country’s energy grid as geopolitical tensions with Russian continue to escalate.

President Putin on Friday issued a series of security demands, including that NATO limits deployments of troops and weapons to Ukraine’s eastern border with Russia and that the country commits to never joining the military alliance.

It warned of a military crisis in the region if its demands weren’t met. Russia has already massed 100,000 troops, alongside missiles and artillery, on its side of the border.

Many Ukrainians will be thinking back nervously to December 2015 and 2016 when Russian state-backed hackers disrupted the power grid, leaving hundreds of thousands in the dark and cold of winter for several hours.

That’s likely to have informed a recent exercise in which 250 participants and 49 teams competed to fend off an attack on a fictitious energy provider after it suffered major operational technology (OT) failures, according to reports.

The hours-long exercise, which featured private industry experts and participants from universities and other institutions, focused on three key elements: finding out what had happened, ejecting the intruders and remediating affected systems.

It was apparently run using the Sans Institute’s Grid NetWars suite, designed for OT professionals to pit their wits against fictional attackers in the electricity sector.

“Grid NetWars is a suite of hands-on, interactive learning scenarios that enable OT security professionals to develop, test and master the real-world, in-depth skills they need to defend real-time systems,” Sans says of the platform. “It is designed as a challenge competition and is split into separate levels to allow players to quickly move through earlier levels based on their expertise.”

According to Sans, participants move through four levels, conducting: incident response; environment discovery, mapping, and reconnaissance; identification of adversary actions; and eradicating adversary access and recovering/restoring systems

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Execs Get 16+ Years After SBA Fraud Scheme

Execs Get 16+ Years After SBA Fraud Scheme

Four Indianapolis executives have been sentenced to over 16 years behind bars for their part in a 13-year fraud scheme that targeted the US Small Business Administration (SBA).

The quartet worked for now-defunct lender Banc-Serv Partners, an outsourcing provider that assessed small businesses for their eligibility for loans, amongst other things.

However, the co-conspirators worked to trick the SBA into providing loans for clients they knew weren’t eligible, according to the Department of Justice (DoJ).

In a scheme that ran from 2004 to October 2017, they secured loans on behalf of various lenders, obtaining SBA guarantees by misrepresenting what the loans would be used for, hiding facts about some borrowers and even diverting denied loan applications into “expedited approval channels” at the SBA.

When the loans defaulted, the four execs submitted requests to the SBA to purchase the loans from investors and lenders, effectively shifting financial liability to the government agency.

Investigators and prosecutors argued the four had effectively robbed US small businesses which would otherwise have received loan support from the SBA.

“These sentences hold the defendants accountable for their egregious conduct to cheat a government-guaranteed loan program – by lying on loan documentation, concealing key information and asking the government to pay for defaulted loans,” said inspector general Jay Lerner of the Federal Deposit Insurance Corporation (FDIC).

“We remain committed to working with our law enforcement partners and investigating those who seek to exploit federal programs and undermine the integrity of our nation’s banks.”

The four executives are: former Banc-Serv president, founder and owner Kerri Agee; former COO Kelly Isley; former CMO Chad Griffin; and co-founder Matthew Smith, 53. A fifth co-conspirator, Nicole Smith, 44, of Indianapolis, is scheduled to be sentenced on January 7, 2022.

Agee was sentenced to 68 months, Isley got 57 months, Griffin was handed 28 months and Smith received 46 months.

Alongside their sentences, Agee and Isley were each ordered to pay $2.2m, Griffin was ordered to pay $685,000, and Matthew Smith was ordered to pay $1.7m

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

New Log4j Patch Released to Fix DoS Flaw

New Log4j Patch Released to Fix DoS Flaw

Apache has released a new patch for Log4j to mitigate a high severity vulnerability, as researchers separately found a new attack vector for the Log4Shell bug.

The open-source web server community had previously released a patch to fix the now-infamous CVE-2021-44228 flaw in the popular logging utility.

However, in an update, it admitted that this fix did not address a newly discovered issue in Log4j, which has been given a CVSS score of 7.5.

“Apache Log4j2 versions 2.0-alpha1 through 2.16.0 did not protect from uncontrolled recursion from self-referential lookups,” it explained.

“When the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, $${ctx:loginId}), attackers with control over Thread Context Map (MDC) input data can craft malicious input data that contains a recursive lookup, resulting in a StackOverflowError that will terminate the process. This is also known as a DoS (Denial of Service) attack.”

The news comes as researchers at Blumira made a discovery that effectively expands the attack surface for Log4Shell, by enabling Javascript WebSocket connections to trigger the remote code execution bug on unpatched Log4j instances.

It means that even services running as localhost that aren’t exposed to a network could be impacted.

“Previously, we understood that the impact of Log4j was limited to vulnerable servers. This newly discovered attack vector means that anyone with a vulnerable Log4j version on their machine or local private network can browse a website and potentially trigger the vulnerability,” said Blumira.

“The client itself generally has no direct control over these WebSocket connections, which can silently initiate when a webpage loads. WebSocket connections within the host can be difficult to gain deep visibility into, which increases the complexity of detection for this attack.”

The threat from Log4Shell is now so great that the US Cybersecurity and Infrastructure Security Agency (CISA) on Friday updated its patching deadline for federal agencies from December 24 to “immediately.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains