22% of Brits Received Proof of Vaccination Phishing Email in Past Six Months

22% of Brits Received Proof of Vaccination Phishing Email in Past Six Months

Nearly a quarter (22%) of Brits have received phishing emails asking them to download their ‘proof of vaccination’ in the past six months, according to new research by Tessian.

The analysis found that most of these scam messages received in the UK impersonated the National Health Service (NHS), the public body that manages official vaccination pass documentation in the country.

The researchers noted many of these phishing messages look genuine, containing official logos, using accurate display names and correct spelling. The emails commonly looked to convey a sense of urgency to panic victims into acting without thinking clearly. This included using subject lines with terms like “IMPORTANT” and “OFFICIAL,” and describing the potential repercussions of failing to act on the message, such as an inability to travel or requirement to quarantine if instructions are not followed.

Figure 1 was displayed as an example of a message of this type:

Figure 1
Figure 1

Most of these emails then redirected the recipient to a website requesting sensitive data to receive their proof of vaccination. These include personal details and credit card or banking details. These websites were often highly sophisticated, appearing to be genuinely from the NHS (Figure 2).

Figure 2
Figure 2

Tessian also found more than one in three (35%) US citizens received a phishing email requesting proof of vaccination in the past six months.

The findings come during Cybersecurity Awareness Month 2021, in which one of the themes is ‘Fight the Phish.’ This campaign urges online users to slow down and think before clicking on any suspicious emails, links or attachments.

Regarding the proof of vaccination scams, the researchers pointed out that NHS services are free for UK residents, and the institution would never ask for payment details or other financial information. US residents noted that COVID-19 vaccination providers could not charge you for a vaccine or charge you for any administration fees, copays or coinsurance.

Charles Brook, a threat intelligence researcher at Tessian, commented: “Throughout the pandemic, we’ve seen cyber-criminals leverage COVID-related trends as lures in their phishing campaigns. Now they’re capitalizing on the uncertainty surrounding vaccination certificates to dupe people into sharing login credentials and personal or financial information.

“In many cases, the emails purporting to come from the NHS look very convincing. Detecting these scams requires everyone to question messages they receive via phone, text or email. If you are unsure whether a text or email is a scam, then assume it is. Avoid clicking any links or attachments or handing over any information until the sender has been verified. And remember, the NHS won’t charge you for a COVID NHS pass, so any email asking for payment details should be deleted. If you have further questions, go to the official NHS or gov.uk website.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Halloween Horror-Show for Candy-Maker Hit by Ransomware

Halloween Horror-Show for Candy-Maker Hit by Ransomware

A major US confectionary manufacturer has been hit by ransomware at one of its busiest times of the year, according to reports.

Chicago-based Ferrara – which produces popular treats including Nerds, Everlasting Gobstoppers, Juicy Fruits and Gummy Bears – had some of its systems encrypted earlier this month.

It’s now working with law enforcement and third-party experts to restore these critical assets and get operations fully up and running again.

“We have resumed production in select manufacturing facilities, and we are shipping from all of our distribution centers across the country, near to capacity,” noted a company statement published by the Chicago Tribune. “We are also now working to process all orders in our queue.”

George Papamargaritis, MSS operations director at Obrela Security Industries, argued that threat actors are increasingly researching to plan attacks when target organizations are most vulnerable to ransomware lockdowns.

“Attackers are using ransomware to put organizations into a corner, where they are forced to pay. Unless you are prepared for ransomware, you stand to lose everything from these attacks,” he said.

“The best defense when it comes to ransomware all comes down to resilience and hardening systems through regular incidence response training.”

In related news, Taiwanese hardware manufacturer Gigabyte suffered its second ransomware compromise in three months, according to Privacy Sharks.

The AvosLocker group posted a 15MB trove of exfiltrated data to its leak site, featuring internal passwords and usernames, employee payroll details, info on job candidates, and confidential information about third-party business partnerships, including one with a cybersecurity company.

It’s threatening to release more stolen data if the firm doesn’t pay up, although there’s been no word yet from Gigabyte.

It’s the second Taiwanese company to be targeted twice in quick succession by ransomware actors of late. Acer suffered an attack on its servers in India last week and then another by the same group a few days later, this time targeting its Taiwan HQ.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Over 80% of Brits Deluged with Scam Calls and Texts

Over 80% of Brits Deluged with Scam Calls and Texts

Some 45 million Brits received fraudulent phone calls and texts over the summer, according to new data from Ofcom.

The UK’s telecoms regulator polled 2,000 adults on September 18-19 2021, to assess how many had been affected in the previous three months.

Some 82% said they had, with the vast majority (71%) claiming they’d received suspicious text messages. Three-quarters (75%) of those people were aged 16-34.

Over two-fifths (44%) of those who’d received messages said they were hit at least once a week.

For older individuals, scam calls appear to be a more significant threat. Some 61% of respondents aged 75 and over reported receiving a potential scam call to their landline, with more than half (53%) of those getting a call at least once a week.

Unfortunately, 2% of respondents admitted following the scammers’ instructions in a message or call, which amounts to roughly one million Brits.

Most mobile users (79%) said they weren’t aware of the 7726 number, which can report a suspected text or call.

“Criminals who defraud people using phone and text scams can cause huge distress and financial harm to their victims, and their tactics are becoming increasingly sophisticated,” claimed Ofcom networks and communications director Lindsey Fussell.

“Stay alert to any unsolicited contact. Put the phone down if you have any suspicion that it is a scam call, and don’t click on any links in text messages you’re unsure about. Report texts to 7726 and scam calls to Action Fraud or Police Scotland.”

According to data compiled by Griffin Law, privacy watchdog the Information Commissioner’s Office (ICO), recorded a 60% rise in reports of nuisance calls, texts and emails in the first six months of 2021 compared to the whole of 2020.

Tessian CEO, Tim Sadler, argued that scammers are getting more persistent and sophisticated with their campaigns.

“Distraction and fatigue are some of the most common explanations for why someone might fall victim to an online scam. It’s so important, then, to take a couple of seconds to think before you comply with any request,” he added.

“Inspect the sender’s details and ask yourself whether that organization would ask you for this information. If in doubt, hang up or press delete. You can always verify the request by contacting the company in question, using the details provided on their legitimate website.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Government Agents Compromise REvil Backups to Force Group Offline

Government Agents Compromise REvil Backups to Force Group Offline

The US authorities appear to have scored another win in their fight against ransomware by forcing the infamous REvil group offline. Experts have warned that there could be repercussions for former breach victims.

One former official and three private-sector cybersecurity experts confirmed to Reuters that an international operation was responsible for taking the group’s data leak site “Happy Blog” offline a few days ago.

Government specialists managed to compromise some of the group’s backups so that when it restarted services after another outage in July, they were already in the hands of law enforcement.

Although official sources declined to comment, the White House has been ramping up the pressure on ransomware actors since the Colonial Pipeline outage in May, an attack that REvil-linked DarkSide group carried out.

REvil and its affiliates were responsible for the monumental supply chain attack on Kaseya and many others, amassing a fortune in the process.

The Biden administration launched a DoJ Ransomware and Digital Extortion Task Force in April and signaled its intent to treat these offenses as they would terrorist attacks.

Jake Williams, CTO at BreachQuest, said news of the REvil take-down has been circulating in closed threat intelligence groups for several days.

The leader of the group, “Unknown,” disappeared in July, with Williams suggesting it’s likely either they or a close conspirator were arrested and forced to provide access to the group’s infrastructure.

However, he warned that there might be more pain in store for previous victims of REvil affiliates that have had data stolen in “double extortion” attacks.

“These affiliates stay in line and don’t release [exfiltrated] data because doing so would remove them from future work with the core group, effectively their cash cow. As work from REvil is clearly drying up now, affiliates will need new sources of revenue,” Williams argued.

“It won’t be surprising to see stolen data sold on the dark web. I anticipate that some organizations who believed their data was safe because they paid an REvil ransom are in for a rude awakening.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

REvil Servers Shoved Offline by Governments – But They’ll Be Back, Researchers Say

A multi-country effort has given ransomware gang REvil a taste of its own medicine by pwning its backups and pushing its leak site and Tor payment site offline.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Threat Actors Abuse Discord to Push Malware

The platform’s Content Delivery Network and core features are being used to send malicious files—including RATs–across its network of 150 million users, putting corporate workplaces at risk.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Friday Squid Blogging: Squid Eating Maine Shrimp

Squid are eating Maine shrimp, causing a collapse of the ecosystem. This seems to be a result of climate change.

Maine’s shrimp fishery has been closed for nearly a decade since the stock’s collapse in 2013. Scientists are now saying a species of squid that came into the Gulf of Maine during a historic ocean heatwave the year before may have been a “major player” in the shrimp’s downturn.

In 2012, the Gulf of Maine experienced some of its warmest temperatures in decades. Within a couple of years, the cold-water-loving northern shrimp had rapidly declined and the fishery, a small but valued source of income for fishermen in the offseason, closed.

Anne Richards, a biologist at the Northeast Fisheries Science Center in Woods Hole, Massachusetts, and Margaret Hunter, a biologist with the Maine Department of Marine Resources, studied the collapse and found that it coincided with an influx of longfin squid, a major shrimp predator.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Read my blog posting guidelines here.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains