Holiday Shopping Disruption Beckons as Retail Bot Attacks Surge 13%

Holiday Shopping Disruption Beckons as Retail Bot Attacks Surge 13%

Security experts have warned of potential disruption to the upcoming holiday shopping season after recording a double-digit year-on-year increase in bot-driven cyber-attacks so far in 2021.

Imperva’s State of Security Within eCommerce report revealed that over half (57%) of attacks targeting retail websites this year were carried out by bots, versus just 33% across other industries.

Account takeover attempts, looking to hijack customers’ accounts to steal personal and financial info, reached 33% so far in 2021, versus 26% across other verticals.

These attacks are often carried out by what Imperva describes as “sophisticated” bots, capable of mimicking human mouse movements and clicks to defeat retailers’ cyber-defenses.

They’re responsible for account takeover and denial of inventory, where items are added to account baskets to take them out of circulation, making them unavailable for legitimate customers.

This could exacerbate existing supply chain issues that threaten stock availability this holiday season, warned Imperva director of technology, Peter Klimek.

“With the global supply chain conditions worsening, retailers will not only struggle to get products to sell in Q4 but will face increased attacks from motivated cyber-criminals who want to benefit from the chaos,” he argued.

“Imperva Research Labs’ data underscores the need for retailers to invest in security that spans from edge to applications and APIs all the way to the data. Only by protecting all paths to data can retailers truly defend their critical systems and the consumers who rely on them.”

To that end, Imperva also recorded a surge in DDoS attacks, including a 200% month-on-month increase in September 2021.

The vendor warned that as retailers build out their website functionality with chatbots and web analytics and connect customers via API to features such as product search and order fulfillment tracking, their cyber-attack surface will continue to expand.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Student Loans Company Dismissals Highlight Insider Risk

Student Loans Company Dismissals Highlight Insider Risk

Over 20 staffers at the Student Loans Company (SLC) have faced disciplinary action for computer misuse and other offenses, including three former employees who were fired, according to new Freedom of Information (FoI) data.

Litigation firm Griffin Law revealed the findings of its FoI requests to the non-profit, which is owned by the UK government’s Department for Education and is responsible for administering loans and grants to students.

While several of the 23 offenses related to excessive internet use during work time, one of which resulted in dismissal, several involved the culprits accessing the accounts of friends and family members.

That resulted in one dismissal in 2019, and this year one individual on a final written warning and another suspended pending an investigation.

Many of the other offenses related to inappropriate use of social media or the sharing of inappropriate content via email.

Several offenders used offensive or aggressive language targeting colleagues on Facebook, while one was fired in 2018 after sharing content on the social network linking a colleague to criminal activity. That was judged to have potentially brought the SLC into disrepute.

On one occasion in 2020, a former SLC employee was sacked after sharing inappropriate and offensive material on Microsoft Teams, according to Griffin Law.

An SLC spokesperson got in touch with Infosecurity seeking to put the findings into context.

“At SLC we have robust policies and procedures in place to ensure that colleagues use technology appropriately, to identify instances of unacceptable behaviour and to take action when required,” they said in a statement. “We employ over 3000 colleagues and as the data rightly demonstrates there have been very few instances over the past four years where action was required.”  

Torsten George, a cyber evangelist at Absolute Software, argued that the FoI data highlights the risk of malicious insiders accessing and potentially stealing sensitive customer information.

“The risk of SLC employees walking away with sensitive data or selling their access credentials has never been greater now that a record number of individuals have been made redundant and face financial hardship due to COVID-19,” he added.

“All too often, large organizations like the SLC are aware of the challenges related to external threat actors, and they, therefore, focus their efforts on creating deterrents to protect against these cyberattacks. In doing so, they often overlook the fact that the biggest threats can arise from within.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

ICO Collects Just 26% of Value of Fines Since 2020

ICO Collects Just 26% of Value of Fines Since 2020

The UK’s data protection and privacy regulator is getting worse at collecting the fines it hands out to penalize erring companies, according to new data from TheSMSWorks.

The SMS API provider has been tracking the progress of the Information Commissioner’s Office (ICO) in such matters since 2018.

Unfortunately, it revealed that just a quarter (26%) of the monetary value of fines it issued from January 2020 to September 2021 had been paid, down from 32% during the last report period (January 2019-August 2020).

That means, out of the 47 individual fines during the current period, amounting to £7m, just 19 had been successfully collected, at a value of only £1.8m.

This excludes the sizeable GDPR penalties for British Airways (£20m) and Marriott International (£18.4m). These companies have reportedly agreed to pay their fines in annual installments.

The news comes despite legislation that effectively makes company directors responsible for paying fines. In the past, many would declare bankruptcy to avoid the fine.

According to TheSMSWorks, many directors simply refuse to pay or initiate a slow and unwieldy appeals process. It claimed that Eldon Insurance, fined £60,000 for email spam in February 2019, still has an unresolved appeal being processed.

Another company, MyIML Ltd, has reportedly not yet fully paid its £80,000 nuisance call fine six years after it was issued.

Over £1m in unpaid fines are said to be currently under appeal.

Henry Cazalet, director of TheSMSWorks, said awareness of the issue often falls under the radar.

“People reasonably assume that if an organization has been fined then it will be paid and the taxpayer will benefit,” he told Infosecurity.

“I think The ICO’s reputation could take a bit of a hit, particularly as it has over 500 members of staff now.”

Cazalet said he had some sympathy with the regulator, which must balance the twin goals of discouraging shady practices and collecting fines effectively.

“However, I believe that the fining policy is just too aggressive,” he concluded. “It makes a great headline to state that you’re fining a rogue organization for a huge sum, but if you can’t collect it, then it’s ultimately just posturing.”

Fines for SMS spam are the most likely to remain unpaid, with 82% of penalties yet to be collected, the report noted.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Predicting the Next OWASP API Security Top 10

API security risk has dramatically evolved in the last two years. Jason Kent, Hacker-in-Residence at Cequence Security, discusses the top API security concerns today and how to address them.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Using Fake Student Accounts to Shill Brands

It turns out that it’s surprisingly easy to create a fake Harvard student and get a harvard.edu email account. Scammers are using that prestigious domain name to shill brands:

Basically, it appears that anyone with $300 to spare can ­– or could, depending on whether Harvard successfully shuts down the practice — advertise nearly anything they wanted on Harvard.edu, in posts that borrow the university’s domain and prestige while making no mention of the fact that it in reality they constitute paid advertising….

A Harvard spokesperson said that the university is working to crack down on the fake students and other scammers that have gained access to its site. They also said that the scammers were creating the fake accounts by signing up for online classes and then using the email address that process provided to infiltrate the university’s various blogging platforms.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Squid Game Cryptocurrency Scam Cheats Investors, Serves as a Warning

It’s little surprise that a digital currency scam based on the popular Squid Games series on Netflix is making the news.  

If you haven’t caught wind of it yet, the story goes along the following lines: 

Note that this Squid Game cryptocurrency had no relationship to the show or to Netflix, aside from hijacking the Squid Game name without permission so that the scammers could use it as bait. 

The Squid Game scam: one of many cryptocurrency scams 

Scams such as this are nothing new. Earlier this year, an “initial coin offering” (ICO) called Mando turned out to be a scam as well. Based on Disney’s popular Star Wars series, The Mandalorian, the scammers used the name and the Star Wars-themed imagery around it without permission. Then, just as suddenly they used the popular name to drum up investments in the ICO, the scammers disappeared with the money they garnered from the “pre-sale” of the bogus Mando cryptocurrency. 

With all the fervor around cryptocurrencies, scams associated with them are on the rise and have been for some time. A study published by Investopedia found that 80% of cryptocurrencies are scams and that only 8% of cryptocurrencies make their way onto legitimate trading exchanges. 

In the case of the Squid Game cryptocurrency, there were several apparent signs that it was bogus to begin with. Reports call out the fact that the currency was not available for purchase on mainstream platforms. Instead, investors could only purchase the cryptocurrency on a platform that doesn’t guarantee the transactions made upon it. Further, investors could only buy the currency, not sell it, effectively locking them in.  

Other indications were found in the accompanying website and technical white paper, which were laden with spelling and grammatical errors, along with apparently unsubstantiated claims. In all, red flags such as those are very similar to the ones associated with phishing attacks—where scammers co-opt the identities of well-known brands and organizations in bogus emails and websites, albeit in an often-clumsy fashion. Errors like those are often a telltale sign that something sketchy is afoot. 

Protecting yourself from cryptocurrency scams 

1. Working with an accredited financial adviser is always a sound step with any investment you choose to make, as is only investing funds you can afford to lose if the investment falls through.  

2. Steer clear of cryptocurrency investments that ask you to contribute money directly from one of your own accounts rather than via a reliable platform that is verified 

3. Consider dependable cryptocurrencies such as Bitcoin, Ethereum, and Litecoin—of course recognizing that even legitimate cryptocurrencies can be highly volatile investments. 

4. Regard any cryptocurrency based on a pop culture reference like movies, memes, and shows with a highly critical eye. It may very well be a scam built around buzz rather than an earnest attempt at launching a legitimate cryptocurrency, such as it was with the Squid Game scam. 

The game where only the scammer are the winners 

Just as Netflix’s Squid Game is one in a long string of hit shows that’ll capture our attention, we can count on a similarly long string of cryptocurrency scams to continue. In this case, the Squid Game cryptocurrency scam was rigged from the start, despite the warning signs. After all, an investment people can only buy into but never sell is scam, plain and simple.  

The post Squid Game Cryptocurrency Scam Cheats Investors, Serves as a Warning appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains