81% of Organizations Experienced Increased Cyber-Threats During COVID-19

81% of Organizations Experienced Increased Cyber-Threats During COVID-19

More than four in five (81%) organizations experienced increased cyber-threats during the COVD-19 pandemic, according to a new study by McAfee and FireEye.

The global survey of 1451 IT and line of business decision-makers found that close to half (43%) have suffered from downtime due to a cyber concern. This resulted in costs of $100,000 for some organizations.

Despite the increased threat landscape and the fact that over half (57%) of organizations saw a rise in online/web activity, 24% of respondents revealed they have had their technology and security budgets reduced over this period.

The study also highlighted cybersecurity concerns felt by a number of organizations ahead of this year’s holiday season. Despite many industries expecting to see a surge in demand for goods and services, three-quarters (75%) of organizations admitted they struggle to maintain a fully staffed security team during the festive period. Additionally, 73% of respondents expect at least half of their organization’s employees to work remotely over this time, making them more vulnerable to attacks.

McAfee highlighted e-commerce and retail as a particularly vulnerable sector, with cyber-criminals likely to take advantage of increased online shopping in this period. Common attack methods include compromised payment credentials and cloud storage, as well as various forms of retail fraud and theft.

Additionally, the company said the UK’s supply chain crisis, brought about by loss of manufacturing capacity and employee power, has potentially created a weak and vulnerable infrastructure cyber-criminals can exploit.

Fabien Rech, EMEA vice president at McAfee, highlighted that businesses should learn from these findings: “While the current climate paints a bleak picture, this should really serve as a reminder to businesses that there’s never been a more important time to ensure their security architecture is robust enough to contain and respond to any emerging threats.

“As we enter into peak holiday season and the goods and services industries face logistical and supply challenges during a time of high demand, organizations need to strengthen their infrastructure and ramp up their security efforts, making it more challenging for-cyber criminals to break through.”

This week, McAfee announced a $14bn takeover by private investors.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

McAfee Sold to Investor Group for $14bn

McAfee Sold to Investor Group for $14bn

McAfee’s storied history took another turn this week after it announced a $14bn takeover by private investors.

The all-cash deal will see ownership of the firm transferred to an investor group led by Advent International Permira Advisers LLC, Crosspoint Capital Partners, Canada Pension Plan Investment Board, GIC Private, 

and a wholly-owned subsidiary of the Abu Dhabi Investment Authority.

It’s the latest twist in an increasingly complicated corporate tale for the security giant, widely regarded as launching the first-ever anti-virus product back in 1987.

Since then, Intel bought it for nearly $8bn in 2010 and rebranded to Intel Security, before the chip giant partnered with TPG seven years later to turn the firm into a jointly owned, independent cybersecurity company, with the McAfee name returning.

McAfee’s enterprise business was then sold to Symphony Technology Group for $4bn earlier this year.

That left a consumer-focused cybersecurity company that the investor group has just purchased for $26 per share, which it claimed is a 23% premium on McAfee’s closing share price last week.

Bryan Taylor, head of Advent’s technology investment team and a managing partner in Palo Alto, argued that McAfee is still one of the world’s most trusted consumer brands.

“As consumers face new and complex cyber risks, we see tremendous opportunity to build on McAfee’s differentiated technology platform to continue delivering innovative solutions that can protect all facets of the digital lives of people around the world,” he claimed.

“We look forward to working alongside our investment partners and the talented McAfee team to continue setting the bar for consumer digital protection.”

The group certainly appears to have industry experience on its side. Crosspoint Capital managing partner, Greg Clark, is a former CEO of Symantec.

The deal is expected to close in the first half of 2022.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Euro Police Arrest Two More REvil Affiliates as US Issues Sanctions

Euro Police Arrest Two More REvil Affiliates as US Issues Sanctions

European law enforcers announced the arrests of two suspected REvil affiliate members on Monday, bringing their total for the year to five, as the US published its own indictments and sanctions designed to hobble the ransomware collective.

Romanian authorities arrested the unnamed duo on November 4, claiming they had been responsible for 5000 attacks which netted half a million euros.

Its Operation GoldDust involved police from Europe, the US, South Korea, Australia and the Philippines.

Since February this year, it has also led to arrests of three other suspected REvil affiliates and two suspected GandCrab affiliates. Three of these were reportedly cuffed in South Korea and one in Kuwait. Together, the seven arrested so far this year are thought to have been responsible for attacking 7000 victims.

“All these arrests follow the joint international law enforcement efforts of identification, wiretapping and seizure of some of the infrastructure used by Sodinokibi/REvil ransomware family, which is seen as the successor of GandCrab,” said Europol.

The disclosure comes as US authorities indicted two men for their involvement in REvil yesterday.

Ukrainian Yaroslav Vasinskyi was actually arrested in Poland last month and will face charges connected with the infamous Kaseya ransomware attack. Russian Yevgeniy Polyanin is still at large, but the Department of Justice (DoJ) announced the seizure of over $6m he allegedly stole from victims.

At the same time, the US Treasury announced sanctions against both men, including a company owned by Polyanin and cryptocurrency exchange Chatex, for its alleged involvement in ransomware.

It said the firm has direct ties to the Russian exchange Suex, which has already been sanctioned.

“Analysis of Chatex’s known transactions indicate that over half are directly traced to illicit or high-risk activities such as darknet markets, high-risk exchanges, and ransomware,” the Treasury noted.

The State Department has also offered a new $10m reward for information leading to the “identification or location” of REvil leadership figures. This follows a similar move last week to elicit intelligence on the DarkSide group.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Robinhood Data Breach Hits Seven Million Customers

Robinhood Data Breach Hits Seven Million Customers

Trading app Robinhood has revealed a significant data breach affecting the personal information of an estimated seven million customers.

The firm claimed an unauthorized third party could access the data on November 3, after targeting an employee.

“The unauthorized party socially engineered a customer support employee by phone and obtained access to certain customer support systems. At this time, we understand that the unauthorized party obtained a list of email addresses for approximately five million people and full names for a different group of approximately two million people,” a statement explained.

“We also believe that for a more limited number of people – approximately 310 in total – additional personal information, including name, date of birth, and zip code, was exposed, with a subset of approximately ten customers having more extensive account details revealed.”

However, Robinhood said that no Social Security, bank account or debit card numbers were exposed in the breach, and it does not believe that any customers were financially impacted.

That said, the threat actor has purportedly demanded a ransom payment in return for the stolen data, so the information that has been taken could be monetized on the cybercrime underground in follow-on fraud attempts.

“As a safety-first company, we owe it to our customers to be transparent and act with integrity,” said Robinhood CSO Caleb Sima. “Following a diligent review, putting the entire Robinhood community on notice of this incident now is the right thing to do.”

The bare-bones stock trading app was fined a record $70m by the US Financial Industry Regulatory Authority (FINRA) over the summer for inflicting “widespread and significant harm” on customers. It was claimed the firm misled those customers about their investments, leaving them out of pocket.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US to Charge Suspects Over Kaseya Ransomware Attack

US to Charge Suspects Over Kaseya Ransomware Attack

The US justice department is expected to announce it has charged a suspect over the damaging Kaseya ransomware attack in July, it has been reported.

CNN said Ukrainian national Yaroslav Vasinskyi and Russian national Yevgeniy Polyanin will face charges relating to the deployment of ransomware known as REvil in the incident, which affected up to 1500 organizations throughout the world. These include conspiracy to commit fraud, money laundering and other charges.

Vasinskyi was arrested in Poland last month, although Polyanin currently remains at large.

It is expected US officials will also reveal they seized at least $6m in ransomware payments received by Polyanin as part of their investigation into the incident.

REvil is believed to be responsible for numerous other high-profile ransomware attacks this year, including Colonial Pipeline, Apple and JBS. While the group was forced offline following the Kaseya attack, it’s ‘Happy Blog’ site re-emerged last month. However, it was quickly shut down again following operations by U.S. Cyber Command and a foreign government that targeted the criminals’ servers.

The news will be a great boost to the efforts of the Biden administration to disrupt the actions of ransomware gangs amid surging attacks. Last month, it was revealed the US Treasury has tracked $5.2bn worth of Bitcoin transactions likely to have been ransomware payments in the first half of 2021.

Commenting on the story, Bob Rudis, chief data scientist at Rapid7, said: “REvil has caused massive damage during their tenure as the “Amazon” of criminal ransomware as a service (RaaS) operators. The Kaseya attack enabled by their platform was not a minor event and caused havoc in both meatspace and cyberspace, impacting families, schools, municipalities, healthcare providers, small businesses and large enterprises across the globe. It is encouraging to see what can be done when policy meets enablement and authorities are given support and resources to take decisive action. I’m hopeful that as more criminals are caught and prosecuted, and as their ill-gotten gains are recovered, we will finally start to see attackers move on to other, less risky business models (or go away completely, but that is more of a dream than likelihood).”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

The New Frontier of Enterprise Risk: Nth Parties

The average number of vulnerabilities discovered in a Cyberpion scan of external Fortune 500 networks (such as cloud systems) was 296, many critical (with the top of the scale weighing in at a staggering 7,500).

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains