Police Set for Record Haul in Anti-Card Fraud Operation

Police Set for Record Haul in Anti-Card Fraud Operation

A cross-border anti-fraud initiative is set to save European cardholders tens of millions in cybercrime losses, according to experts who took part.

Carding Action 2021 was led by Italian police with support from the UK, leading card schemes and Europol.

It targeted the underground sites on which fraudsters and cyber-criminals trade stole card data.

According to Europol, the three-month operation has already led to the identification of 12 vendors selling card details on such sites, and total losses prevented of €14m ($16m).

However, only 50,000 stolen cards have so far been analyzed. According to participating cybersecurity vendor Group-IB, that represents only a quarter of the total. It said that the figure for losses prevented is worked out by multiplying average card spend by the number of compromised cards found.

That means the operation is set to clear the €40m (£45m) saved from last year’s Carding Action initiative.

Group-IB said its threat intelligence team was tasked with finding and analyzing newly compromised payment records from sources such as botnet and JS-sniffer infrastructure, as well as underground card shops and marketplaces regularly monitored by the vendor.

“Group-IB continues to hold true to its major principle of zero tolerance for cybercrime,” said Nicholas Palmer, head of global business at Group-IB. “Public-private partnerships and joint initiatives like Carding Action continue to play a key role in our strategy to disrupt cybercrime activities globally.”

The news comes as Europol also announced the results of another successful initiative: “Operation In Our Sites,” which ran from May to November 2021.

The anti-counterfeit operation led to 12 arrests, the takedown of nearly 500,000 websites, and the seizure of €2.6m ($3m) of fake goods.

“The sale of counterfeit goods and pirated materials is becoming an increasingly serious problem for law enforcement authorities for a number of reasons,” warned Europol.

“The internet allows criminals to remain anonymous due to the borderless nature of international e-commerce. It has never been easier to offer counterfeit goods or pirated content online as consumers have access to a greater variety of illicit products but are unaware of the potential risks.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

How Decryption of Network Traffic Can Improve Security

Most industry analyst firms conclude that between 80-90 percent of network traffic is encrypted today. Jeff Costlow, CISO at ExtraHop, explains why this might not be a good thing.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Intel is Maintaining Legacy Technology for Security Research

Interesting:

Intel’s issue reflects a wider concern: Legacy technology can introduce cybersecurity weaknesses. Tech makers constantly improve their products to take advantage of speed and power increases, but customers don’t always upgrade at the same pace. This creates a long tail of old products that remain in widespread use, vulnerable to attacks.

Intel’s answer to this conundrum was to create a warehouse and laboratory in Costa Rica, where the company already had a research-and-development lab, to store the breadth of its technology and make the devices available for remote testing. After planning began in mid-2018, the Long-Term Retention Lab was up and running in the second half of 2019.

The warehouse stores around 3,000 pieces of hardware and software, going back about a decade. Intel plans to expand next year, nearly doubling the space to 27,000 square feet from 14,000, allowing the facility to house 6,000 pieces of computer equipment.

Intel engineers can request a specific machine in a configuration of their choice. It is then assembled by a technician and accessible through cloud services. The lab runs 24 hours a day, seven days a week, typically with about 25 engineers working any given shift.

Slashdot thread.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Fighting Supply Chain Threats Is Complicated

Relying on the kindness of strangers is not an ideal strategy for CISOs and CIOs. And yet that is the precise position where most find themselves today while trying to battle cybersecurity issues across their supply chain. While these supply chains have plenty of their own challenges, such as global disruptions of distribution, our recent research shows that it’s the cybersecurity problems that will long survive for the long term.

It’s not as though enterprises rely on their partners any more today than they did ten years ago. Their needs have not changed and are unlikely to change, except those rare instances where an enterprise will choose to manufacture their own supplies rather than rely on partners. Consider, for example, Costco creating its own gigantic chicken farm. Other than outlier examples like this, partner reliance is relatively stable.

What is changing with the supply chain is how much system access is being granted to these partners. They are getting access they didn’t always get and are getting far deeper access as well. As technology has advanced to allow such access, enterprises have accepted.

Given the wide range of partners–suppliers, distributors, contractors, outsourced sales, cloud platforms, geographical specialists, and sometimes your own largest customers–the cybersecurity complexities are growing by orders of magnitude. In addition, the more integrations that enterprises accept, the higher the level that their risk is. To be more precise, the risk doesn’t necessarily grow with the number of partners as much as the risk grows with the number of partners whose cybersecurity environments are less secure than the enterprise’s own environment.

To even begin to craft a cybersecurity strategy to manage partners and a global supply chain, the enterprise CISO needs to have a candid understanding of what their partners’ security level truly is. That is tricky, given that many of those partners themselves do not have a good sense of how secure or insecure they are.

One suggestion is to revise contracts to make it a requirement for all partners to maintain a security level equal to the enterprise customer. The contract must not only specify penalties for non-compliance–and those penalties must be sufficiently costly that it makes no sense for a partner to take that chance–but it must specify means to determine and re-verify that security level. Surprise inspections and the sharing of extensive log files would be a start.

Otherwise, even the strictest security environment such as Zero Trust may be unable to plug supply chain holes due to sloppier partner security practices. Let’s say that a large enterprise retailer is working with a large consumer goods manufacturer as a partner. A good environment will start with strict authentication, making sure that the user from the partner is really that authorized user. The enterprise environment must also watch the user throughout the session to make sure the user doesn’t do anything suspicious. But if the partner has been breached, malware could sneak in through the secure tunnel and, if it’s not caught by the enterprise, there’s a problem and now they can be breached.

This is not hypothetical. Since the beginning of the pandemic, our research found that a vast majority of global enterprises (81 percent) said that they are seeing far more attacks since the beginning of COVID-19.

Almost every business is dependent on the supply chain, making it a prime target for cybercriminals looking to cause disruption and breach wider networks. As the holiday season approaches, we are already seeing a spike in consumer and business activity across the supply chain, making it a prime target for cybercriminals looking to target essential and lucrative services.

Attackers are going to continue to leverage the global supply chain as an initial entry vector, accessing the network through a trusted connection, system, or user. The fact that these attacks exploit trusted channels makes them very difficult to prevent or detect. As organisations continue their digital transformation, including ever-more cloud services, managed services and endpoint modernization, the risks of supply chain threats will increase as its prevalence as a vector does so.

 

The post Fighting Supply Chain Threats Is Complicated appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Data Breach at Panasonic

Data Breach at Panasonic

The Panasonic Corporation has disclosed a data security incident in which an undisclosed amount of data was compromised.

In a statement issued Friday, the major Japanese multinational conglomerate announced that an unauthorized third party had gained access to its network on November 11. 

An internal investigation was launched that determined that the intruder had accessed some data stored on a file server. Panasonic did not say how much data was compromised in the incident or whether any sensitive information was accessed. 

The company said that a “specialist third-party organization” is currently undertaking a second investigation into the incident. This probe is expected to discover the precise quantity and nature of the information accessed by the intruder. 

Panasonic has not shared any information regarding how the unauthorized access was detected. However, the company did state that it “immediately reported the incident to the relevant authorities and implemented security countermeasures, including steps to prevent external access to the network.”

Japanese news outlets Mainichi and NHK reported that the data breach went on for four months, from June 22 to November 3.  NHK claimed that sensitive data, including information on the company’s partners, personal details pertaining to customers and employees and technical files from Panasonic’s operations in Japan, was accessed in the intrusion.

John Bambenek, the principal threat hunter at Netenrich, told Infosecurity Magazine that the reported delay in detection “demonstrates that companies are continuing to lag behind attackers.”

Jake Williams, co-founder and CTO at BreachQuest, said that NHK’s data breach coverage raised several “red flags.” 

“NHK reported that internal network monitoring was the source of the incident detection, seemingly implying that the depth of intrusion is more than a misconfigured external server. Taken at face value, this means that Panasonic likely has some work ahead to threat hunt in its network before fully understanding the scope of the compromise,” said Williams. 

“This stands in stark contrast to cases where a simple misconfiguration on a server allow a threat actor access to excessive data. Those cases at least have localized impact because there is no threat of threat actor lateral movement deeper into the network.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains