7 Common Digital Behaviors that Put Your Family’s Privacy at Risk

It would be impossible nowadays to separate our everyday lives from technology. We travel well-worn, comfortable paths online and engage in digital activities that work for us. But could those seemingly harmless habits be putting out the welcome to cyber criminals out to steal our data? 

It’s a given that our “digital-first mindset”  comes with inherent risks. With the work and learn from home shift looking more permanent and cybercrime on the rise, it’s imperative to adopt new mindsets and put new skills in motion. The first step with any change? Admitting your family may have a few bad habits to fix. Here are just a few to consider.  

7 Risky Digital Behaviors  

1. You share toooo much online. Too Much Information, yes, TMI. Oversharing personal information online is easy access for bad actors online. Those out to do harm online have made it their life’s work to piece together your personal details so they can steal your identity—or worse. Safe Family Tips: Encourage your family not to post private information such as their full name, family member names, city, address, school name, extracurricular activities, and pet names. Also, get in the habit of a) setting social media profiles to private, b) regularly scrubbing personal information on social profiles—this includes profile info, comments, and even captions that reveal too much c) regularly editing your friends lists to people you know and trust.  

2. You’ve gotten lazy about passwords. It’s tough to keep up with everything these days. We get it. However, passwords are essential. They protect your digital life—much like locks on doors protect your physical life. Safe Family Tips: Layer up your protection. Use multi-factor authentication to safeguard user authenticity and add a layer of security to protect personal data and all family devices. Consider adding comprehensive software that includes a password manager as well as virus and malware protection. This level of protection can add both power and peace of mind to your family’s online security strategy.   

3. You casually use public Wi-Fi. It’s easy to do. If you are working away from home or on a family trip, you may need to purchase something, meet a deadline, or send sensitive documents quickly. Public Wi-Fi is easy and fast, but it’s also loaded with security gaps that cybercriminals camp out on. Safe Family Tip: If you must conduct transactions on a public Wi-Fi connection, consider McAfee Total Protection. It includes antivirus and safe browsing software, plus a secure VPN.  

4. You have too many unvetted apps. We love apps, but can we trust them? Unfortunately, when it comes to security and privacy, apps are notoriously risky and getting tougher to trust as app technology evolves. So, what can you do? Safe Family Tips: A few things you can do include a) Double-checking app permissions. Before granting access to an app, ask yourself: Does this app need what it’s asking me to share? Apps should not ask for access to your data, b) researching the app and checking its security level and if there have been breaches, c) reading user reviews, d) routinely deleting dormant and unused apps from your phone. This is important to do on your phone and your laptop, e) monitor your credit report for questionable activity that may be connected to a malicious app or any number of online scams.  

5. You’ve gotten too comfortable online. If you think that a data breach, financial theft, or catfish scam can’t happen to you or your family, it’s a sign you may be too comfortable online. Growing strong digital habits is an ongoing discipline. If you started strong but have loosened your focus, it’s easy to get back to it. Safe Family Tips: Some of the most vulnerable areas to your privacy can be your kids’ social media. They may be oversharing, downloading malicious apps, and engaging with questionable people online that could pose a risk to your family. Consider regularly monitoring your child’s online activity (without hovering or spying). Physically pick up their devices to vet new apps and check they’ve maintained all privacy settings.  

6. You lack a unified family security strategy. Consider it: If each family member owns three devices, your family has countless security gaps. Closing those gaps requires a unified plan. Safe Family Tips: a) Sit down and talk about baseline security practices every family member should follow, b) inventory your technology, including IoT devices, smartphones, game systems, tablets, and toys, c) make “keeping the bad guys out” fun for kids and a challenge for teens. Sit and change passwords together, review privacy settings, reduce friend lists. Come up with a reward system that tallies and recognizes each positive security step. 

7. You ignore updates. Those updates you’re putting off? They may be annoying, but most of them are security-related, so it’s wise to install them as they come out. Safe Family Tip: Many people make it a habit to change their passwords every time they install a new update. We couldn’t agree more.  

Technology continues to evolve and open extraordinary opportunities to families every day. However, it’s also opening equally extraordinary opportunities for bad actors banking on consumers’ casual security habits. Let’s stop them in their tracks. If you nodded to any of the above habits, you aren’t alone. Today is a new day, and putting better digital habits in motion begins right here, right now.  

The post 7 Common Digital Behaviors that Put Your Family’s Privacy at Risk appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

CyberVetsUSA Pilots Nebraska Project

CyberVetsUSA Pilots Nebraska Project

The skills-to-job consortium CyberVetsUSA is launching a new pilot program in Nebraska that aims to fast-track military veterans into new cybersecurity careers. 

CyberVetsUSA exists as a public-private partnership between non-profit and Veteran Service Organizations (VSOs), tech employers, institutions of higher education, and local government agencies. 

It was launched in 2017 with the mission to increase the available pool of qualified cyber talent by helping military veterans and their spouses become part of the cybersecurity workforce. In 2018, the program served nearly 300 military veterans and their spouses by minimizing barriers to entry. 

Under the CyberVetsUSA program, America’s veterans are provided with training, certification and employment opportunities through the Cisco Networking Academy, Institute for Veterans & Military Families at Syracuse University, Onward to Opportunity, and Fortinet NSE Training Institute.

Coinciding with Veterans Day in the United States, CyberVetsUSA has partnered with the civic venture Digital Innovation Engine to trial a free cybersecurity training scheme in Nebraska that will start in the new year.

“Beginning in January 2022, this 15-week program offers an instructor-led course which provides trainees with both technical and tactical skills to effectively protect organizations’ critical infrastructure, applications and data,” said a spokesperson for Digital Innovation Engine.

“It will make veterans ready on day one to work on the front lines of a Security Operation Center (SOC), defending against the most sophisticated digital threats and attacks.”

The pilot is open to transitioning service members, veterans, National Guard and Reservists, and military spouses who reside in Nebraska. Those who complete the program will gain a Cisco Certified CyberOps Associate level certification – Cisco Certified CyberOps Associate At-a-glance. 

Additional introductory cybersecurity courses will be offered through the program for those without a previous background in IT. The courses are CyberVetsUSA VetPrep Introduction to Cybersecurity and CyberVetsUSA VetPrep Cybersecurity Essentials. 

“Upon completion, trainees will receive world-class employment support from Randstand, and direct access to job opportunities through Cisco Networking Academy’s Talent Bridge Matching Engine,” said a spokesperson for Digital Innovation Engine.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

CEO of Blacklisted Spyware Firm Quits

CEO of Blacklisted Spyware Firm Quits

The newly appointed chief executive officer of Pegasus spyware maker NSO Group has relinquished his role following the company’s recent addition to the United States’ Department of Commerce blacklist. 

Isaac Benbenisti was announced as the NSO Group’s new CEO on October 31 but had not yet taken the reins of his new leadership position when he handed in his notice. Before his appointment to the top, Benbenisti had served as one of the NSO Group’s co-presidents. 

The resignation was reported by Israeli media on Thursday, with Benbenisti attributing his decision to the Biden administration’s blacklisting of NSO Group last week. NSO Group is yet to comment on their new appointee’s decision to step down.

NSO Group was one of four companies added to the Entity List by the Biden administration on November 3 “for engaging in activities that are contrary to the national security or foreign policy interests of the United States.”

The other companies were Candiru, which is also based in Israel, the Russian-based Positive Technologies, and Computer Security Initiative Consultancy PTE, LTD., which is based Singapore.

The US Commerce Department’s Bureau of Industry and Security said in a statement that the four entities were added “on a determination that they traffic in cyber tools used to gain unauthorized access to information systems, threatening the privacy and security of individuals and organizations worldwide.”

The move makes it difficult for NSO to sell its software globally and would require the Group to obtain a special license to purchase parts and components from companies in the US. 

US Secretary of Commerce Gina Raimondo said: “The United States is committed to aggressively using export controls to hold companies accountable that develop, traffic, or use technologies to conduct malicious activities that threaten the cybersecurity of members of civil society, dissidents, government officials, and organizations here and abroad.”

NSO Group’s blacklisting follows allegations that its signature spyware product – Pegasus – was deployed by several governments to collect information on diplomats, journalists, clergy members, and dissidents. 

A consortium of journalists working with the French non-profit group Forbidden Stories reported multiple cases of activists and journalists, including American citizens, who were hacked by foreign governments using Pegasus.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#BHEU: 5 Ways to Approach Ransomware Negotiations

#BHEU: 5 Ways to Approach Ransomware Negotiations

Five key approaches organizations should take during ransomware negotiations with extorters to improve the outcome were outlined by Pepijn Hack, cybersecurity analyst of Fox-TT, part of NCC Group, in a session at Black Hat Europe 2021.

Hack observed that when a successful ransomware attack occurs and payment demand issued, the attackers immediately have the upper hand in the negotiations that follow. This is firstly because they already have knowledge of their victim through research undertaken before the attack, helping them understand if they are likely to pay and how much they can afford. Secondly, they will have experienced numerous ransomware negotiations in the past, but it is likely the first time the victim is in that situation.

Presenting research carried out with a colleague at Fox-TT, Hack outlined what the attackers will consider during a ransom negotiation. These are the final ransom price, whether the victim will pay or not, the cost and risk to themselves and how many attacks are successfully carried out.

A comparison of two ransomware groups was then made via data collected between late 2019 and early 2021. For the first group, records of 681 negotiations were observed. For the second group, there were 105 negotiations. Across both, a similar amount (roughly 15%) of the victims paid the ransom. However, the average ransom amount paid was much lower in the first group than in the second, with the latter focusing on bigger companies and issuing higher demands. This suggests focusing on fewer but higher-value targets is a more fruitful approach for attackers.

Another interesting finding from this analysis was that “two companies with the same revenue, regardless of what the initial ransom demand was, the payment was quite similar.” This is interesting to note as it shows threat actors have “adopted an optimization strategy,” whereby they calculate “how much the victim is willing to pay in the end,” according to Hack.

“Adversaries have the advantage, but they still are only human, and we can take advantage of that”Pepijn Hack

Despite organizations in this position being in a dire situation, Hack said there are several actions they can take to improve their situation, whether they plan to pay or aim to buy time. It should be remembered that “adversaries have the advantage, but they still are only human, and we can take advantage of that.” Using insights gained from research into numerous ransomware negotiations, Hack offered five strategies organizations should employ in negotiations.

  1. Be respectful – while Hack acknowledged this might sound strange given your company has been hacked, he emphasized that staying polite and respectful during communications with the attackers is much more likely to lead to better outcomes. “One thing we saw was that when victims got angry or frustrated with the adversary, chats would get closed – good luck getting your files back then,” he stated. “Look at this like a business transaction,” added Hack.
  2. Ask for more time – Hack warned that attackers will try and pressure you into making quick decisions, which will be more likely to lead to bad outcomes for the victims. However, “in almost all cases, they were willing to extend the timer if you were still negotiating.” This can give victims more opportunity to assess their options, for example, if they are waiting to see if they can get backups for the stolen data.
  3. Promise to pay a small amount now or a larger amount later – Hack re-emphasized like cyber-attackers are people, and like all humans, “are not that good at delaying gratification.” Additionally, the adversaries are likely to want to conclude the negotiation as quickly as possible. Therefore, victims should try and take advantage of this mentality during negotiations. For example, if they have decided they have no choice but to pay, the victim can make it clear they can pay a much lower price now, and there would be a delay for a higher payment.
  4. Convince the adversary you cannot reach the ransom amount – Hack gave one example of a negotiation he analyzed as part of the research, in which the victim stated that the maximum they could pay was $500,000 (from a $13m demand). In the end, this was all they ended up paying, which was a far lower cost. This approach can even work for larger companies, with Hack revealing a Fortune 500 firm received a decryption key despite paying a far lower sum than was originally asked.
  5. Do not tell anyone you had cyber-insurance – “If the adversaries find out you have cyber-insurance, your negotiation is going to get a lot more difficult,” said Hack. He showed communications from attackers where they stated they knew the victim could pay a large amount because they had cyber insurance. As this information can often be obtained from stolen files, Hack advised: “keep the fact you have cyber-insurance secret, keep the files off your network. You might even want to go as far as making an agreement with your insurance company that they also keep it a secret on their end.”

Concluding, Hack reiterated that companies will always be on the back foot in ransomware negotiations. Nevertheless, there still are approaches that can be taken to mitigate the damage of the attack. “Depending on what your goal is during the negotiation – you want to stall for time while bringing up your backups, or you have decided the only way forward is to pay – there’s a different strategy you can use.”

He added it is crucial to provide this advice for organizations because, sadly, “ransomware is not going anywhere, it’s way too valuable a business.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ransomware Attack Hits UK Fertility Clinic

Ransomware Attack Hits UK Fertility Clinic

Data from a private fertility clinic has been put at risk following a ransomware attack that hit a document management firm.

The Lister Fertility Clinic said that Stor-a-file Limited, which the clinic uses for scanning medical records, had been “hacked” by a “cyber-gang” in a letter that it sent to its 1700 patients.

The document management firm revealed that 13 organizations had been impacted, with six being healthcare-related.

While it had informed the police and the Information Commissioner’s Office, Store-a-file Limited said that the possibility hackers accessed medical information “cannot be ruled out.”

“From our investigations, the incident is limited to the small number of records we hold electronically,” it said.

In a letter that The Lister Fertility Clinic sent to its 1700 patients, it said that patient medical records were on the Stor-a-file IT system affected by the attack. The medical records included consent forms, medical history and test results, treatment recommendations and fertility treatment records. Credit or debit card details were not included. 

“We were advised by Stor-a-file that the cyber-gang that accessed their systems made a ransom demand which was not paid, and that the gang has released some of the data that they accessed on the dark web,” it added. 

Commenting on the news, George Papamargaritis, MSS Director of Obrela Security Industries, said: “This is a devastating cyber-attack. The information could be used in further extortion attacks or sold on the dark web, with healthcare information earning cyber-criminals much more money than credit card data. 

“Healthcare organizations have recently become a major target for cyber-criminals, with a recent study from Obrela revealing that 81% of UK healthcare organizations have suffered a ransomware attack in the last year, which resulted in 38% paying a ransom demand. 

“Given these increased attacks, healthcare organizations must work to prioritize their cybersecurity now, by implementing tools which prevent prioritize getting into systems and deploying malware, while always verifying the security of their supply chain.” 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#BHEU: Can Time Be Hacked?

#BHEU: Can Time Be Hacked?

Time synchronization is a fragile ecosystem that is vulnerable to being hacked, with the potential for enormous damage to be caused. This was the message of Adam Laurie, global associate partner and lead hardware hacker, IBM X-Force Red, during the keynote address on day two of Black Hat Europe 2021.

Laurie pointed out that time has been a source of fascination for centuries, underpinning the scientific theories of Isaac Newton and Albert Einstein. Nowadays, accurate, centralized time is critical for the functioning of a number of important industries. This includes navigation, forensics (who did what when), cryptocurrency and blockchain (proof of work) and the transportation of trains, airplanes and automobiles. “You can go on and on, pretty much everything depends on it,” said Laurie.

To emphasize this further, he highlighted a UK report in 2017, which estimated the cost of the time synchronization system failing to be £1bn per day. Laurie observed this would even dwarf the financial costs of COVID-19. This issue has therefore come to the attention of government and big industry.

Worryingly, there is currently an overwhelming reliance on GPS for time synchronization, which was never intended to be the de facto standard for everything. This has arisen due to its cheapness and easy availability. However, should there be a satellite failure, this would create “an existential threat to the whole ecosystem because everyone comes back to that same point,” commented Laurie.

He cited another report from 2020, which recommended diversifying sources of time to prevent a single source of failure. However, Laurie pointed out that many of the suggested alternative models, such as telco networks, are “themselves just synchronized back to GPS.”

Numerous real-world synchronization failures have highlighted the fragility of the use of GPS. One example highlighted by Laurie occurred in New York in 2019, when critical systems were not updated when the clocks were rolled over on April 6th. This caused failures in the city’s traffic light system that lasted nearly two weeks, causing chaos.

A concerning real-world scenario of how easily GPS can be manipulated occurred when a delivery driver in Ontario, Canada, purchased a cheap jammer to hide his location from his bosses. As he was near an airport, “his jamming device didn’t just hide their ability to track him, it actually grounded flights.” Considering the scale of the accidental damage caused by a cheap GPS jammer, Laurie asked, “can you go further than that and actually spoof GPS and create a different time signal?”

The answer to this is yes. For example, Laurie discovered an SDR simulation package online, which can be used to “override the time parameters transmitted in the plane and set whatever time you want. It will then create a scenario that will spoof satellites that appear visible to your local receiver, and the receiver will see the time that you have set rather than the real time.”

During the presentation, Laurie also provided a hacking demo of another source of time – low-frequency radio broadcasts – to show how easily these methods can be manipulated. He had two clocks; one synchronized to the UK atomic clock via the network time protocol (NTP) and the other controlled by radio frequency, receiving an MSF signal, adjusting itself every 10 minutes. “I was curious if I could spoof that signal,” and Laurie soon discovered that “people have written software” for this purpose. Over the course of the rest of the session, he overrode the transmission signal using a software package and produced an incorrect time.

Concluding, Laurie noted that society takes time too much for granted, although government and big industries are waking up to the fragility of the current ecosystem. Alternative cheap and easily accessible sources of synchronization are urgently required, and these must be secure as “attackers and their tools are becoming increasingly sophisticated.” Laurie added: “If you can spoof a signal and take out an entire city’s GPS clocks from a powerful transmitter, that’s clearly a big problem.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Researchers Uncover Prolific Hacker-for-Hire Group

Researchers Uncover Prolific Hacker-for-Hire Group

Trend Micro has revealed details of a new Russian-speaking cyber-mercenary group responsible for at least 3500 victims over the past six years.

Dubbed “Void Balaur” after an evil creature from Eastern European folklore, the group goes by the name “Rockethack” on underground Russian language forums, where it has been advertising since 2018 to 100% positive reviews.

According to Trend Micro’s report on the outfit, it focuses on compromising email and social media accounts and selling sensitive personal and financial information, including telco data, passenger flight records, banking data and passport details.

Its global targets range from Russian telcos to ATM vendors, financial services firms, medical insurers and IVF clinics. These are selected as they store lucrative personal and corporate information that can be sold at a relatively high price. The group charges over $800 for phone call records with cell tower locations, for example.

However, Void Balaur also targets journalists, human rights activists, politicians, scientists, doctors, telco engineers and cryptocurrency users.

Some of these overlap with individuals targeted by the notorious Kremlin-backed Pawn Storm group (APT28, Fancy Bear), although it’s not thought the two groups are otherwise connected.

According to Trend Micro, phishing and info-stealing malware and its main tools to compromise its victims. That makes multi-factor authentication (MFA), end-to-end encrypted apps, “robust” email and corporate detection and response tools a must, the vendor claimed.

The proliferation of groups like Void Balaur is a consequence of a highly professionalized cybercrime economy, argued Trend Micro senior threat researcher Feike Hacquebord.

“Given the insatiable demand for their services and harboring of some actors by nation-states, they’re unlikely to go away anytime soon,” he added. “The best form of defense is to raise industry awareness of the threat in reports like this one and encourage best practice cybersecurity to help thwart their efforts.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Scam PACs Allegedly Stole $3.5m from Trump Voters

Scam PACs Allegedly Stole $3.5m from Trump Voters

Three men have been charged with multiple counts of fraud and money laundering after allegedly running scam fund-raising operations that tricked Trump donors into handing over millions.

The three defendants are Matthew Nelson Tunstall, 34, of Los Angeles; Robert Reyes Jr, 38, of Hollister, California; and Kyle George Davies, 29, of Austin, Texas.

They’re accused of soliciting funds from voters during the 2016 election cycle via two fraudulent political action committees (PACs): Liberty Action Group PAC and Progressive Priorities PAC.

They allegedly managed to trick donors into handing over $3.5m, which they pocketed and used to fund more fraudulent adverts, according to the Department of Justice (DoJ). Tunstall and Reyes are also alleged to have laundered more than $350,000 from the scheme via a third-party vendor.

Although the indictment did not name the candidates that the trio was purporting to collect for. Reports claim they used the name and likeness of Donald Trump to solicit donations.

A Politico investigation in 2019 found a dozen pro-Trump PACs which had no affiliation with the former President. In fact, the FBI issued a warning in April this year about scams of this sort.

One fraudulent fundraiser, Harold Russell Taub, was sentenced to 36 months in prison after soliciting more than $1.6m in donations, which were spent on “things like excessive travel, wine, cigars, trips to Las Vegas, gambling,” according to the FBI.

Tunstall and Reyes are charged with conspiracy to commit wire fraud and make a false statement to the Federal Election Commission (FEC), multiple counts of wire fraud and multiple counts of money laundering.

Davies is charged with conspiracy to commit wire and make a false statement to the FEC and multiple counts of wire fraud.

If found guilty on all counts, the first two face a maximum jail term of 125 years, while Davies faces 65 years.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Firms Hit with Largest Ransoms Globally

US Firms Hit with Largest Ransoms Globally

Over 80% of global organizations have been hit by ransomware in the past two years, but executives still have a false sense of security about being able to prevent future attacks, according to Mimecast.

The email security firm polled 742 cybersecurity professionals worldwide to compile its latest report, State of Ransomware Readiness: Facing the Reality Gap.

It revealed that victim organizations in the US are paying a much higher price for security breaches. The average ransom here was $6.3m, versus just $848,000 in the UK and $59,000 in Australia. On average, 39% of victims said they paid.

However, the ransom itself comprises only one element of the financial and reputational risk stemming from a successful attack. Others cited by respondents were operational disruption (42%), significant downtime (36%), lost revenue (28%) and lost current customers (21%).

Two-fifths (39%) of executives also claimed they could lose their jobs over an attack, while a quarter (24%) saw changes to the C-suite following a breach.

Yet despite this recognition, executives appear over-confident in their organization’s ability to repel attacks. Some 83% believe they can get all their data back without paying a ransom, while over three-quarters (77%) think they can get operations back to normal within just five days.

“Ransomware attacks have never been more common, and threat actors are improving each day in terms of their sophistication and ease of deployment,” said Jonathan Miles, Mimecast head of strategic intelligence & security research.

“Preparation is key in combating these attacks. It’s great to see cybersecurity leaders feel prepared, but they must continue to be proactive and work to improve processes. This report clearly shows ransomware attacks pay, which gives cyber-criminals no incentive to slow down.”

The most common threat vector was listed as malicious attachments in phishing emails (54%).

Many respondents argued that their organization needs more advanced security (45%) and more frequent end-user training (46%) to tackle the threat.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Dallas Police Surveillance Footage Leaked

Dallas Police Surveillance Footage Leaked

Video apparently stolen from American law enforcement agencies in Texas and Georgia has been leaked online by transparency collective Distributed Denial of Secrets (DDoSecrets).

The collective shared 1.9TB of data it says consists of 600 hours of aerial surveillance footage taken by police helicopters in and around Dallas, Texas, and Atlanta, Georgia.

“The extensive footage reveals the capabilities of the ‘military-grade’ technology behind police surveillance,” states DDoSecrets on their website.

“It also highlights the voyeurism inherent in surveillance and how it often focuses on protected first amendment activities and people who have no idea they’re being watched and who’ve done nothing to justify the intrusion of surveillance.”

Emma Best, a co-founder of the collective, said that the video footage had been sent to them by an anonymous hacker. The unnamed source reportedly targets unsecured data stored in the cloud. 

“In some of the videos (like gsp 2peachtree 64), they use infrared tech to look at people inside buildings with thinner walls,” she wrote on Twitter. “The video provides no justifying context.”

Best went on to write: “I’d post screenshots, but I’m pretty sure Twitter would jump on the excuse and ban me over it, so.”

Aric Toler, a volunteer at the independent international collective of researchers, investigators and journalists Bellingcat commented: “The surveillance footage is as terrifying as you imagine it being. The helicopter zooms in super close to a bunch of people’s yards. 

“Not posting it here, but one point the helicopter focuses in on an elderly woman unloading groceries from her car, in super-high resolution.”

Following the release of the footage, the Dallas City Council scheduled a closed session on Wednesday with its lawyers to discuss a “potential data breach” within the Dallas Police Department (Dallas PD).

The alleged leak occurred three months after Dallas County prosecutors confirmed that 22 terabytes of case data belonging to the Dallas Police Department had been mistakenly deleted.

Data including millions of archived videos and images was lost when an individual employed by the city’s IT department messed up the transfer of files from cloud storage to a server owned by the city. That employee was fired from their job in August. 

While many files were later recovered, the Dallas County District Attorney’s office and the Dallas PD said that more than four million files were permanently lost, affecting around 17,500 cases.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains