US and Australia Enter CLOUD Act Agreement

US and Australia Enter CLOUD Act Agreement

The United States has entered into an agreement with Australia to share electronic data so as to facilitate the investigation of serious crimes. 

Crimes that fall under the category of serious include terrorism, ransomware attacks, and the sexual abuse of children. 

The landmark agreement was authorized by the Clarifying Lawful Overseas Use of Data (CLOUD) Act, a bill passed by Congress in 2018. 

In a statement released Wednesday, the Department of Justice Office of Public Affairs said that the agreement will offer strong protection for the rule of law, privacy, and civil liberties while helping police to obtain the data they need faster and more efficiently. 

“The CLOUD Act Agreement will help ensure Australian and US law enforcement agencies are able to timely access electronic data to prevent, detect, investigate, and prosecute serious crime, including child sexual abuse, ransomware attacks, terrorism, and the sabotage of critical infrastructure over the internet,” said the office. 

With the new data-sharing agreement in place, authorities in each country will be able to obtain “certain electronic data” more efficiently from communications service providers operating in the other’s jurisdiction. 

“This agreement paves the way for more efficient cross-border transfers of data between the United States and Australia so that our governments can more effectively counter serious crime, including terrorism, while adhering to the privacy and civil liberties values that we both share,” said United States Attorney General Merrick Garland.

Garland and the Australian minister for home affairs, Karen Andrews, said the agreement would enhance cooperation between each country’s law enforcement agencies and help keep communities in both countries safe without infringing upon the values, principles, and sovereignty of either country.

“As we saw in Operation Ironside – known in the United States as Operation Trojan Shield – the Australian Federal Police and the FBI are already capable of smashing serious organized crime networks using sophisticated digital techniques,” said Andrews. 

She added: “By strengthening both nations’ ability to fight crime, and giving our law enforcement agencies more efficient access to evidence, we’re ensuring the safety, security, and prosperity of our citizens.”

The CLOUD Act Agreement will now undergo Parliamentary and Congressional review processes in both countries.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

France Orders Clearview AI to Delete Data

France Orders Clearview AI to Delete Data

France’s data protection regulator has ordered American facial recognition software firm Clearview AI to stop illegally processing images.

In a statement released today, the CNIL said that Clearview’s facial recognition software relies on a database of photographs that was built by extracting photographs and videos that are publicly available on the internet. 

The data protection authority commanded Clearview to desist from extracting such images from people on French territory and to delete the data it had gathered in this manner within two months. 

The CNIL launched an investigation into Clearview AI in the spring of 2020 after the authority received complaints from individuals about the company’s data practices. 

Investigators found that Clearview AI “does not respond effectively to requests for access and erasure. It provides partial responses or does not respond at all to requests.”

The association Privacy International also warned the CNIL about Clearview’s data practices in May 2021.

“These complaints revealed the difficulties encountered by the complainants in exercising their rights with Clearview AI,” said the authority. 

CNIL’s probe found that Clearview AI had breached the General Data Protection Regulation (GDPR) in force in the European Union in two different ways.

The first violation committed by Clearview AI was the unlawful processing of personal data in breach of Article 6 of the GDPR. CNIL determined that Clearview AI was guilty of this transgression “because the collection and use of biometric data are carried out without a legal basis.”

CNIL found that in an “intrusive and massive” process, Clearview AI extracted people’s images from the internet for use by its facial recognition software without first obtaining their consent to do so. 

“These people, whose photographs or videos are accessible on various websites, including social media, do not reasonably expect their images to be processed by the company to supply a facial recognition system that could be used by States for law enforcement purposes,” stated the CNIL.

Clearview’s second strike was its “failure to take into account the rights of individuals in an effective and satisfactory way, in particular requests for access to their data” in contravention of Articles 12, 15, and 17 of the GDPR.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

60% of UK Workers Have Been Victim of a Cyber-Attack, Yet Awareness Remains Low

60% of UK Workers Have Been Victim of a Cyber-Attack, Yet Awareness Remains Low

There is a “dangerous” lack of awareness among UK workers towards cybersecurity, leaving businesses at risk of attacks, according to a new study by Armis. This is despite 60% of workers admitting they have fallen victim to a cyber-attack.

The nationwide survey of 2000 UK employees found that only around a quarter (27%) are aware of the associated cyber risks, while one in 10 (11%) don’t worry about them at all.

Even more worryingly, just one in five people said they paid for online security, putting businesses at high risk of attacks amid the shift to remote working during COVID-19.

The most prevalent types of attacks experienced by workers or their organizations were phishing (27%), data breaches (23%) and malware (20%).

The study also revealed growing concerns about the scale of the cyber-threats facing the UK. A large-scale cyber-attack was ranked as the fourth biggest future concern (21%) among the respondents, equal to the UK going to war. Two-fifths (40%) said they would like to see a minister for cybersecurity installed to ensure the issue is focused on more at a government level.

Russian-backed cyber-criminals were considered to be the biggest threat to the UK’s cybersecurity (20%) by the respondents, followed by financially motivated cyber-criminals (17%) and Chinese-backed cyber-criminals (16%).

Conor Coughlan, CAO and General Manager for EMEA at Armis, outlined: “It’s clear that cybersecurity awareness and training must be made a priority within the UK government.

“This is an issue that must be addressed from the top down. Moving forward, more emphasis should be placed on security awareness training as well as technology controls that give organizations a full picture of risk exposure. Organizations need to understand the importance of investing in the right security to protect themselves and their customers and to avoid experiencing any downtime.”

Reacting to the findings, Javvad Malik, lead security awareness advocate at KnowBe4, said the study demonstrated the need for organizations to create a strong cybersecurity culture among their workforces. “The results of this survey demonstrate why it’s important for organizations to not just push out security awareness messages, but why it’s vital they foster a culture of security throughout so that everyone is aware of the importance their role plays in securing the organization.

“While technical controls and security teams have a large part to play in securing an organization, the impact of an individual’s actions and the role they have to play in securing the organization needs to be emphasized repeatedly.

“Just as engineers build safe roads and bridges, and car manufacturers build safe vehicles, we still need road signs, markings and good driving to create a safe road network for everyone. We need people to play their part in keeping their organizations safe.”

Jamie Akhtar, CEO and co-founder of CyberSmart, concurred, stating: “Unfortunately, while Armis’ findings are deeply worrying, they aren’t surprising. We’ve long had a dangerous lack of cybersecurity awareness in the UK. However, this isn’t the fault of individual employees or even small businesses themselves. For too long, practicing good cyber hygiene has been viewed as a specialist skill that the average employee or small business owner couldn’t possibly do themselves. But the only way to improve cybersecurity across society is to empower everyone to take responsibility for their own safety. And we need to give small businesses and their employees the knowledge, skills and tools to do it. This will require a combination of standards, state intervention, education and easily accessible tools.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Online Shoppers Could Face Eight Million Credential Stuffing Attacks Per Day Over Christmas

Online Shoppers Could Face Eight Million Credential Stuffing Attacks Per Day Over Christmas

Online shoppers in the UK will be hit by up to eight million credential stuffing attacks per day in the Christmas period, according to a new analysis by Arkose Labs.

The worrying prediction was made following a massive spike in this attack vector, largely due to the shift to online shopping during COVID-19. Arkose researchers observed more than two billion credential stuffing from October 2020 to September 2021, representing a 98% increase on the previous year. Astonishingly, they found this activity made up 5% of all online traffic in the first half of 2021.

According to the analysts, credential stuffing rose by 56% during last year’s Christmas and New Year shopping period. This enabled them to calculate that consumers will face up to eight million attacks every day in the same period this year.

Credential stuffing is where fraudsters attempt to gain unauthorized access to consumers’ financial and personal accounts by automating known stolen username and password combinations across multiple sites. Once inside, the attackers can monetize the account in numerous ways. These include draining compromised accounts of funds, stealing and reselling personal data, selling lists of known verified username and password combinations and using the compromised accounts to launder money gained from other illegal enterprises. The success of this tactic has been exacerbated by common password reuse among online users.

The study found that sectors most often targeted by credential stuffing attacks were gaming, digital and social media and financial services. In fact, nearly 50% of all attacks targeting the gaming industry were credential stuffing.

Interestingly, the UK was identified as one of the top three regions to launch the most credential stuffing attacks on the rest of the world, alongside Asia and North America.

Kevin Gosschalk, CEO at Arkose Labs, commented: “The global e-commerce landscape is more connected than ever before, and personal information has become the currency of fraudsters. Credential stuffing is prolific. It’s become an enormous concern to online businesses and is fast overtaking other well-known attack tactics, such as ransomware, as THE cyber-attack to watch out for.

“Fraudsters are compelled to this type of cybercrime as the low barrier to entry makes it easy to deploy, and online criminals can generate profits with just one successful compromised account. Their volumetric approach can come on abruptly, quickly overloading businesses’ servers and putting customers at risk.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

All Change at the Top as New Ransomware Groups Emerge

All Change at the Top as New Ransomware Groups Emerge

The Ransomware as a Service (RaaS) landscape underwent another major shift in the third quarter as new variants emerged to become the dominant players in the ecosystem, according to Intel 471.

In a new update, the threat intelligence company explained that 60% of the attacks it tracked during the period were tied back to four variants: LockBit 2.0, Conti, BlackMatter and Hive.

Of these, LockBit 2.0 was the most prolific, accounting for a third (33%) of observed attacks, followed by Conti (15%), BlackMatter (7%) and Hive (6%).

“Be it due to law enforcement, infighting amongst groups or people abandoning variants altogether, the RaaS groups dominating the ecosystem at this point in time are completely different than just a few months ago,” said Intel 471.

“Yet, even with the shift in variants, ransomware incidents as a whole are still on the rise. From July to September 2021, Intel 471 observed 612 ransomware attacks that can be attributed to 35 different ransomware variants. Among those attacks, several lesser-known variants have supplanted prominent ones that rose in notoriety over the first half of 2021.”

LockBit 2.0’s rise has been particularly notable, as it was only discovered in June 2021 following the disappearance of LockBit late last year. Its most famous scalp so far has been Accenture, which it bombarded with a DDoS attack as well as leaking data in a bid to force a $50m ransom payment.

Conti has been beset by in-fighting which may have led to a 64% drop in the number of recorded attacks using the variant between Q2 and Q3 2021.

“In August, an actor leaked training documents and exposed some infrastructure that revealed two other actors’ roles in running the variant, allegedly due to the operators not paying network access brokers their cut of ransom payments,” said Intel 471.

“The initial actor and one of the doxxed actors were booted from the forum after being tied to ransomware operations.”

While the four mentioned variants are on the rise, Clop and REvil have fallen away after significant law enforcement disruption.

However, the message to defenders is that the threat will persist as long as victims continue to pay up and hostile nations shelter attackers. That makes proactive threat defense a must.

This week, news emerged that the new Log4j vulnerability is already being exploited in ransomware attacks, offering a dangerous new vector for threat actors.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Regulator: Venues Must Protect User Privacy During #COVID19 Checks

Regulator: Venues Must Protect User Privacy During #COVID19 Checks

The UK’s privacy watchdog has released new advice for venue owners and large event organizers on ensuring COVID-19 checks comply with data protection and digital privacy laws.

This week, the government avoided a humiliating defeat in the Commons after nearly 100 of its party’s own MPs voted against introducing new COVID passes for certain high-risk venues like nightclubs and large outdoor events with thousands of people.

However, the new rules passed, which means COVID-19 status checks must be carried out on entry at relevant locations.

The Information Commissioner’s Office (ICO) warned that event organizers and venue owners must be “clear open and honest” about what they’re doing by sharing their privacy notices online and in venues.

It added that they should check whether local rules mandate full digital scans of COVID passes or simply a visual check. Staff should answer any questions on this and treat any information gathered confidentially. Venues should not make their own lists featuring the COVID status of customers.

The ICO has a handy web page on the privacy implications of COVID pass checks. The GDPR only kicks in if organizers physically scan pass QR codes – deemed “processing” under the strict European data protection law.

Health information like this is classed as “special category data” under the law and mirrored in the UK Data Protection Act 2018. That means it requires more protection since it’s deemed more sensitive.

To ensure they follow the critical GDPR principle of data minimization, venue owners and event organizers in the UK must also ensure any use of the data they collect is “fair, relevant and necessary for a specific purpose,” the ICO warned.

That means anything that isn’t needed should be deleted periodically to ensure it does not become a target for threat actors.

Privacy advocates have in the past raised severe concerns about the Scottish government’s Check-In Scotland app and the NHS Track and Trace app

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Experts: All Breach Victims Should Freeze Credit

Experts: All Breach Victims Should Freeze Credit

Only 3% of victims have frozen their credit after receiving a breach notice, despite it being the most effective way to prevent fraudsters from opening new accounts in their name, according to new research.

Suspecting consumers aren’t making the most of the facility, the Identity Theft Resource Center (ITRC) polled over 1000 US consumers on the topic.

Less than a third had frozen their credit at one time for any reason, dropping into the low single digits for breach victims. Yet over three-quarters claimed to be familiar with the process.

Despite broad awareness of credit freezing, consumers are often misinformed about the details. The ITRC claimed 11% incorrectly believe it will impact their credit score or require payment to freeze or thaw, and have therefore never done so.

Most respondents said they didn’t think they needed to.

Freezing credit prevents lenders from obtaining a credit report about an individual, meaning they can’t open any new lines of credit, nor can fraudsters use their stolen identity information. It can be done free of charge in just minutes and is widely regarded as more useful than the credit monitoring checks often offered to customers by breached organizations.

The ITRC called for changes to the law so that all breach notifications include an explicit recommendation for the victim to freeze their credit and info stating that credit monitoring alone is not sufficient to prevent new accounts from being fraudulently created.

It also called on businesses, victim advocates and government representatives to collaborate on a new awareness-raising campaign, emphasizing the importance of freezing the credit of children’s accounts when their data has been stolen.

One-third of respondents to the poll said they didn’t think it was necessary to freeze their children’s credit to prevent identity misuse.

Finally, the ITRC wants the credit reporting industry to streamline freeze requests, so individuals do not need to lodge requests with each individual agency, as they have to at present.

“The vast majority of people know what a credit freeze is but do not take advantage of this valuable resource,” argued ITRC CEO, Eva Velasquez.

“A credit freeze is generally considered the most effective tool to prevent new accounts from being opened in your name. This research shows that there needs to be improved awareness and utilization of credit freezes, particularly for children.”

This year is on track to be a record-breaker regarding the number of publicly disclosed breaches in the US.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Virginia Reeling from Ransomware

Virginia Reeling from Ransomware

Virginia is fighting cyber-fires on two fronts after ransomware attacks affected its state legislature and an agency within its executive branch. 

In an attack that struck on the evening of December 12, critical IT systems under the Division of Legislative Automated Systems (DLAS) were rendered inaccessible.

The attack was focused on certain internal servers, impacting the General Assembly voicemail server and the General Assembly’s Legislative Information System (LIS) portal, which allows lawmakers to draft bills and track legislation.

Most of the websites for Virginia’s legislative agencies and commissions, including the Division of Legislative Services and the Division of Capitol Police, were later forced offline by the attack.

A spokesperson for state governor Ralph Northam confirmed on Monday that ransomware was to blame. 

In an email sent out to members, Virginia House of Delegates deputy clerk Sharon Crouch Steidel wrote that neither the House systems nor the General Assembly website had been affected.

DLAS director Dave Burhop said on Monday that while a ransom note had not yet been sent, Virginia was considering alternatives to paying a ransom, including restoring their system using backups. However, Burhop added that the backups might also have been compromised in the attack. 

By Tuesday, the ransomware attack had spread to other agencies, the Joint Legislative Audit and Review Commission’s website, and the Virginia Law Portal, an online database containing Virginia’s constitution and state code.

The attack came weeks before the legislature was due to convene its biennial 60-day session to ratify a new budget for the next two years.

Another ransomware attack, which struck the global network of digital cloud-based human resources management company Ultimate Kronos Group, is adding to Virginia’s cyber-misery. 

Yesterday, the state’s Department of Behavioral Health and Developmental Services said that the strike against Kronos had “paralyzed” its IT system for managing employee payroll and timesheets.

“At this time, we do not know if this is related to the ransomware attack over the weekend on Virginia’s legislative agencies,” said Lauren Cunningham, a spokesperson for the state agency.

She added this assurance: “What we do know is staff will be paid their normal compensation and on time.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

FBI Recovers Oregonians’ Stolen Data

FBI Recovers Oregonians’ Stolen Data

Patient data stolen from an Oregon healthcare provider during a cyber-attack has been recovered by the Federal Bureau of Investigation (FBI). 

The personal health information (PHI) of approximately 750,000 patients of Oregon Anesthesiology Group (OAG) was compromised in the summer. 

Cyber-criminals gained access to the group’s IT system on July 11 and deployed ransomware that encrypted the contents of certain files. As a result of the attack, staff at the healthcare provider could not access patients’ data or the group’s servers.

OAG hired a digital forensics firm to investigate the attack. The cybersecurity experts determined that the attackers had accessed data belonging to 522 current and former employees, as well as sensitive information belonging to patients.

Areas of the network impacted by the attack contained files in which names, addresses, dates of service, diagnosis and procedure codes and descriptions, medical record numbers, insurance provider names and insurance ID numbers were stored. 

Employee data that could have been compromised included names, addresses, Social Security numbers, and additional information declared in W-2 tax forms. 

Following the attack, the group restored its systems from off-site backups and rebuilt its IT infrastructure from the ground up. In the fall, the FBI contacted the healthcare provider, with OAG sharing information on how the cybercrime was executed. 

“On October 21, the FBI notified OAG that it had seized an account belonging to HelloKitty, a Ukrainian hacking group, which contained OAG patient and employee files,” stated the group in a data breach notice issued earlier this month. 

“The FBI believes HelloKitty exploited a vulnerability in our third-party firewall, enabling the hackers to gain entry to the network.”

A cyber forensics report obtained by OAG in late November stated that the cyber-criminals used their access to the healthcare provider’s IT system to data-mine the administrator’s credentials and access OAG’s encrypted data.

Since the attack, OAG has replaced its third-party firewall and expanded multi-factor authentication. The group has also engaged a third-party vendor to provide around-the-clock real-time security monitoring with live response, advice on security system architecture, and additional compartmentalization of sensitive data.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains