Passports Now Most Attacked Form of ID

Passports Now Most Attacked Form of ID

A new report on identity fraud has found that passports are now the most frequently attacked form of identity document.

Onfido‘s 2022 Identity Fraud Report revealed that over the past year, passports overtook national identity cards as fraudsters’ favorite ID to forge. 

“This points to a shift in fraudsters’ methods as they choose to target the one-sided passport page, rather than a two-sided ID card, and target the most high-assurance document in the hope that a passport’s reputation will help the fake go undetected,” said Onfido researchers.

Document fraud specialists at Onfido process millions of identity documents every year, helping clients detect fraud across 2,500 document types issued by 195 countries. The company’s report is based on analysis of data collected from October 1, 2020, to October 1, 2021.

Other key findings shared in the report are that fraudsters typically prefer to create a fake document from scratch rather than doctor a genuine ID.

“Over 90% of ID fraud in the past year involved counterfeit documents using a complete reproduction of an original document, instead of adapting an existing ID,” said Onfido. 

Modern identity documents feature multiple security features that make modifications easily detectable, but fraudsters are raising their game and creating increasingly sophisticated forgeries.

Over the past year, 47% of all identity document fraud was classed as “medium” sophisticated fraud, which is a 57% increase compared with the previous year. 

Losses from identity theft also grew significantly, ballooning by 42% to reach $712bn in 2020. 

Identity fraud is yet to return to its pre-pandemic level. In 2020, there was a 41% increase in ID fraud, with the average ID fraud rate reaching 5.8%. Over the past year, the average fraud rate was recorded at 5.9%.

“Fraudulent documents open up avenues for serious organized crime, including money laundering and terrorist financing. Consequently, failure to identify fraudulent documents in both real-world and online scenarios poses a threat to the global economy, countries, and their citizens,” commented INTERPOL. 

“Increasingly, we have to adapt to the digital use of identity documents, as well as physical. Businesses and governments alike are facing challenges when identifying fraud in this environment.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Software Vulnerabilities Up by 20% in 2021

Software Vulnerabilities Up by 20% in 2021

Software vulnerabilities increased by 20% in 2021 compared with 2020, according to a new report by HackerOne.

The bug bounty platform said its hackers had uncovered over 66,000 valid vulnerabilities this year, while hacker-powered pentests detected a 264% rise in reported vulnerabilities in 2021 compared to 2020. Additionally, there was a 47% increase in vulnerabilities detected by Vulnerability Disclosure Programs.

The surge in vulnerabilities has partly been driven by the increase in organizations adopting hacker-powered security testing programs, according to the report. For example, there was a 62% increase in financial services programs and an 89% rise in government programs, including a bug bounty challenge by the UK’s Ministry of Defence.

HackerOne said another factor is the expansion of attack surfaces brought about by digital transformation and cloud migration during the pandemic.

The most commonly discovered bug was cross site scripting, as it was in 2020. However, there were significant increases in reports of information disclosure (58%) and business logic errors (67%). Of all the vulnerabilities reported, 26% were considered critical, 36% medium severity, and 34% low severity.

Encouragingly, the median time to resolution fell by 19%, from 33 days in 2020 to 26.7 days in 2021 across all industries. Retail and e-commerce even saw time-to-remediation drop by more than 50% in this period.

The report also found that the median price of a critical bug rose by 20%, from $2500 in 2020 to $3000 in 2021. Additionally, the average bounty price for a critical bug rose by 13% and by 30% for a high severity rated bug this year.

Chris Evans, CISO and chief hacking officer at HackerOne, commented: “Even the most conservative organizations are recognizing the power of the outsider point of view.

“We’ve continued to see high growth in the financial services sector, for example. Measuring and quantifying risk is their business, and they’re seeing that both risk and business outcome is better if they embrace hackers. Across the board, we’re seeing customers using vulnerability report data to inform their software development lifecycles. Organizations are catching issues earlier, and remediating them, at greatly reduced cost by focusing on improvements to developer education, source code integrations, and development frameworks.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Dramatic Fall in .UK Domain Suspensions

Dramatic Fall in .UK Domain Suspensions

There was a dramatic fall in the number of .uk domain names suspended for criminal activity in the year up to October 31 2021, new figures from Nominet have shown.

Nominet, the organization responsible for the management and security of the .uk internet infrastructure, revealed that 3434 .uk domain names were suspended over this period. This was a massive reduction compared to the previous 12 months, when 22,158 .uk domain names were suspended.

This fall is “entirely” due to the reduction in counterfeit sites using .uk, as reported by the Police Intellectual Property Crime Unit (PIPCU). Nominet said these figures show its efforts to tackle fraud and cybercrime in collaboration with law enforcement are working, meaning online criminals no longer see this domain “as a viable option.”

The suspension of domains follows notifications from the police or other law enforcement agencies that they are being used for criminal activity. Additionally, Nominet places domains on hold at registration if its Domain Watch initiative suspects it is involved in criminal activity such as phishing.

The report showed that Nominet received a total of 539 separate requests by law enforcement in the 12 months to October 31 2021. The reporting agencies that sent the highest number of requests were the PIPCU (2487), the National Fraud Intelligence Bureau (841) and the Financial Conduct Authority (75). Of these requests, only 18 didn’t result in a suspension, a fall from 47 in the previous year. Reasons for the requests not resulting in suspension include the domain already being suspended in a parallel process, the domain already being transferred on a court order or the registrant modifying the website to become compliant following notification.

The number of suspensions reversed in the 12 months to October 31 2021 was 25, which compares to 15 during the previous year. Nominet added that there were no suspension requests from the Internet Watch Foundation on Child Sexual Abuse Images (CSAM) on .uk domains in the most recent period.

Nick Wenban-Smith, general counsel and head of stakeholder relations at Nominet, commented: “We have seen an increase in some reporting agencies this year, particularly around online fraud and financial crime. However, the overall number of .uk domains associated with criminality is still lower than previous years, which is a positive outcome for all users.

“The trend is largely due to a very large reduction in suspensions related to intellectual property crime. This is a testament to the success of a joint initiative – Operation Ashiko in collaboration with PIPCU and Nominet – working to reduce the amount of counterfeit sites following a full mapped assessment on the DNS of websites selling and distributing counterfeit goods. For obvious reasons we won’t go into detail of the project, but it has delivered a positive outcome as online criminals are no longer seeing .uk as a viable option.”

DS Sophina Deed, of the City of London Police’s Cyber Prevention & Disruption Team of the National Fraud Intelligence Bureau, said: “Our focus is to disrupt criminals using technology as a facilitator for fraud, we focus on preventing and disrupting their activity enabling us to prevent people and business’s being victims of this type of crime, which can have devastating consequences. On behalf of our team, I’d like to thank Nominet for our continued positive partnership in this area enabling us all to continue our united fight against this type of criminality in the .UK arena.”   

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Google Files Lawsuit Against Blockchain Botnet Operators

Google Files Lawsuit Against Blockchain Botnet Operators

Google has filed what it claims to be the first ever lawsuit against a blockchain-based botnet, in a bid to ramp-up the pressure on its likely Russian administrators.

Glupteba is comprised of around one million compromised Windows PCs around the world, with thousands of new machines sometimes added in a day, the tech giant said in a blog post. It’s used to steal victims’ credentials and data, mine for cryptocurrency and use proxies to hide the location of attacks.

The Glupteba malware is said to distributed through pay per install (PPI) networks and via traffic purchased from traffic distribution systems (TDS).

In a separate blog, Google explained how it had taken action to disrupt the botnet’s command-and-control infrastructure.

However, the threat actors’ use of blockchain complicates matters, as the decentralized nature of the technology allows them to recover more quickly from shutdowns and disruptions, Google said.

That’s why it has also taken to the courts, whilst working on ways to improve the fight against blockchain-based botnets.

“Due to Glupteba’s sophisticated architecture and the recent actions that its organizers have taken to maintain the botnet, scale its operations, and conduct widespread criminal activity, we have also decided to take legal action against its operators, which we believe will make it harder for them to take advantage of unsuspecting users,” wrote VP of security Royal Hansen, and general counsel, Halimah DeLaine Prado.

“Our litigation was filed against the operators of the botnet, who we believe are based in Russia. We filed the action in the Southern District of New York for computer fraud and abuse, trademark infringement, and other claims. We also filed a temporary restraining order to bolster our technical disruption effort. If successful, this action will create real legal liability for the operators.”

If the botnet herders are indeed based in Russia, it remains to be seen how effective legal action is.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

French Transport Giant Exposes 57,000 Employees and Source Code

French Transport Giant Exposes 57,000 Employees and Source Code

A state-owned French transportation giant has inadvertently exposed nearly 60,000 employees to identity fraud after leaking their personal information via an unsecured HTTP server, according to researchers.

A team at vpnMentor found the server on October 13, and deduced from the file names that the culprit was Régie Autonome des Transports Parisiens (RATP), which runs public transport across the French capital and beyond.

The organization apparently never replied to the team, but the French CERT was more responsive and shut the privacy snafu down “shortly after.”

The server was left “open and accessible to anyone with basic web browsing skills,” according to vpnMentor.

The team wrote that it contained an SQL database backup dating back to 2018 with over three million records. This featured the details of 57,000 RATP employees — including senior executives and the cybersecurity team.

Among the data were full names, email addresses, logins for their RATP employee accounts and MD5-hashed passwords.

“In theory, hackers could still crack some of the passwords by converting billions of plaintext passwords into MD5 hashes and seeing if any match with those stored on RATP’s server,” vpnMentor argued. “This wouldn’t take very long, as a basic modern commercial laptop is powerful enough to convert tens of billions of MD5 hashes per second.”

With the stolen information, threat actors could have targeted employees with phishing emails designed to elicit more sensitive data, and launched follow-on fraud attempts.

However, potentially even more serious was a separate folder containing source code related to RATP’s employee benefits web portal. Within the code were API keys that enabled access to the sensitive info about the website’s backend, the team wrote.

This included RATP’s GitHub account, which could be highly valuable to threat actors. Depending on the permissions granted by the keys, it could allow hackers to create or delete projects, deploy ransomware and embed malicious backdoors into RATP’s apps, websites, and network, the report noted.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Hotel Guests Locked Out of Rooms After Ransomware Attack

Hotel Guests Locked Out of Rooms After Ransomware Attack

A popular Scandinavian hotel chain has warned that a recent ransomware attack may have led to the theft of personal information related to bookings, while current guests are struggling with longer waiting times at check-in.

Nordic Choice runs around 200 locations across the region, with brands such as Comfort, Clarion and Quality.

It claimed to have been hit last Thursday with a ransomware attack which impacted “the hotel systems that handle reservations, check-in, check-out and creation of new room keys.”

One guest took to social media to explain that hotel staff were forced to personally escort guests upstairs to their rooms because key cards were out-of-action.

A press release dated Monday failed to mention the problem with room keys but revealed that the Conti variant was to blame. Conti has been responsible for large-scale attacks on Ireland’s Health Service Executive (HSE) and an outrageous $40m ransom demand aimed at Broward County Public Schools in the US.

Nordic Choice claimed to have put in place “replacement solutions” at most of its hotels to maintain operations following the incident, and has informed the relevant Norwegian authorities. However, current, former and future guests were warned about potential data theft.

“Our investigations do not currently give any indication that data has been leaked, but we can’t guarantee that is the case. Therefore, the incident entails a risk that information about the guests’ bookings may be lost,” the release stated.

“This information consists of name, email address, telephone number, date of the visit and any information the guest may have provided in connection with their visit. We do not know for sure yet, but since we see that there may be a risk that such information is leaked, we choose to inform about it now, so that our guests can be extra alert to any suspicious text messages, phone calls or emails.”

The hotel chain said it had not sought to engage with its attackers, nor had they contacted the firm at the time of writing.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains