NCA and Europol Formalize Cooperation on Cybercrime

NCA and Europol Formalize Cooperation on Cybercrime

Crime-fighters in Europe and the UK have signed a new agreement to boost cooperation on cybercrime and other investigations.

The working agreement between the UK’s National Crime Agency (NCA), which investigates serious and organized crimes, and Europol will sit under the UK-EU trade and cooperation agreement (TCA). That’s the limited post-Brexit free trade agreement between the two parties signed at the end of 2020.

Although the NCA claimed that “operational cooperation” between the two had continued “effectively and without interruption” since the start of this year, the new working and administrative arrangement will herald a more formal working relationship.

“Shared capabilities protected under the TCA, and now also the new arrangement, include the presence of UK/NCA liaison officers based in Europol headquarters, access to Europol’s secure messaging system, the ability to attend and organize operational and other meetings at Europol, the ability to contribute to Europol analysis projects in order to benefit from the agency’s coordination and analytical functions, and the fast and effective exchange of data,” it explained.

The NCA pointed to its role in helping to ‘takedown’ the Emotet botnet and the DoubleVPN cybercrime service this year as proof of its enduring close relationship with law enforcement agencies in EU member states.

Cooperation on such matters was a key concern of security experts following the Brexit vote in 2016.

Given cybercrime’s borderless, transnational nature, police across jurisdictions recognize the need to share intelligence to promptly track and disrupt organized gangs.

“This arrangement with Europol supports our continued work to tackle the full range of crime threats facing the UK and our European neighbors,” said the NCA’s outgoing director-general, Lynne Owens.

“We are relentlessly focused on tackling serious and organized criminals, including those who abuse children, who fuel violence through trafficking drugs and firearms, who steal money and information through fraud and cybercrime, and those behind the people smuggling which risks the lives of migrants for profit.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Infant Fatality Could Be First Recorded Ransomware Death

Infant Fatality Could Be First Recorded Ransomware Death

A tragic case making its way through the courts in the US could prove to be the first recorded death due to ransomware.

According to papers filed in June 2020 (via NBC), Teiranni Kidd of Mobile, Alabama, is accusing Springhill Memorial Hospital and its owners of failing to mitigate a crippling cyber-attack and then conspiring to hide its impact on patient care.

Kidd’s daughter Nicko was born with her umbilical cord wrapped around her neck, a problem that has purportedly led to brain damage and the infant’s death several months later.

Fetal heart rate monitors would have usually picked up the issue. Yet, according to the Wall Street Journal, medical staff could not access these from the usual location as a display had been locked by threat actors seeking a ransom payment.

Computing systems were disabled for a total of eight days, including wireless tracking of medical staff and digital patient records, the report claimed.

“Nurses and other healthcare personnel were forced to use outdated paper charting methods and paper documentation to record and document Teiranni’s labor and Nicko’s delivery. Some of the paper forms used outdated terminology and had not been used in years,” the court documents allege.

“As a result, the number of healthcare providers who would normally monitor her labour and delivery was substantially reduced, and important safety-critical layers of redundancy were eliminated.”

If Kidd had known the extent of the technology outage at the hospital, she would have chosen to have her baby elsewhere, the suit contends.

The hospital denies any wrongdoing.

The case highlights the potentially tragic real-world consequences of mounting cyber-attacks. Hospitals came under particular strain during the pandemic as many ransomware groups spotted an opportunity to monetize their attacks.

One study in August claimed that half of US hospitals had been forced to shut down their networks during the previous six months due to ransomware.

In September 2020, it emerged that a woman died after being diverted from a German hospital compromised by ransomware. However, it was later reported that her injuries were so severe that she would likely have died even if the hospital had been able to admit her.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Friday Squid Blogging: Squid Game

Netflix has a new series called Squid Game, about people competing in a deadly game for money. It has nothing to do with actual squid.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Read my blog posting guidelines here.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

A Death Due to Ransomware

The Wall Street Journal is reporting on a baby’s death at an Alabama hospital in 2019, which they argue was a direct result of the ransomware attack the hospital was undergoing.

Amid the hack, fewer eyes were on the heart monitors — normally tracked on a large screen at the nurses’ station, in addition to inside the delivery room. Attending obstetrician Katelyn Parnell texted the nurse manager that she would have delivered the baby by caesarean section had she seen the monitor readout. “I need u to help me understand why I was not notified.” In another text, Dr. Parnell wrote: “This was preventable.”

[The mother] Ms. Kidd has sued Springhill [Medical Center], alleging information about the baby’s condition never made it to Dr. Parnell because the hack wiped away the extra layer of scrutiny the heart rate monitor would have received at the nurses’ station. If proven in court, the case will mark the first confirmed death from a ransomware attack.

What will be interesting to see is whether the courts rule that the hospital was negligent in its security, contributing to the success of the ransomware and by extension the death of the infant.

Springhill declined to name the hackers, but Allan Liska, a senior intelligence analyst at Recorded Future, said it was likely the Russianbased Ryuk gang, which was singling out hospitals at the time.

They’re certainly never going to be held accountable.

Another article.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

FCC Proposal Targets SIM Swapping, Port-Out Fraud

The U.S. Federal Communications Commission (FCC) is asking for feedback on new proposed rules to crack down on SIM swapping and number port-out fraud, increasingly prevalent scams in which identity thieves hijack a target’s mobile phone number and use that to wrest control over the victim’s online identity.

In a long-overdue notice issued Sept. 30, the FCC said it plans to move quickly on requiring the mobile companies to adopt more secure methods of authenticating customers before redirecting their phone number to a new device or carrier.

“We have received numerous complaints from consumers who have suffered significant distress, inconvenience, and financial harm as a result of SIM swapping and port-out fraud,” the FCC wrote. “Because of the serious harms associated with SIM swap fraud, we believe that a speedy implementation is appropriate.”

The FCC said the proposal was in response to a flood of complaints to the agency and the U.S. Federal Trade Commission (FTC) about fraudulent SIM swapping and number port-out fraud. SIM swapping happens when the fraudsters trick or bribe an employee at a mobile phone store into transferring control of a target’s phone number to a device they control.

From there, the attackers can reset the password for almost any online account tied to that mobile number, because most online services still allow people to reset their passwords simply by clicking a link sent via SMS to the phone number on file.

Scammers commit number port-out fraud by posing as the target and requesting that their number be transferred to a different mobile provider (and to a device the attackers control).

The FCC said the carriers have traditionally sought to address both forms of phone number fraud by requiring static data about the customer that is no longer secret and has been exposed in a variety of places already — such as date of birth and Social Security number. By way of example, the commission pointed to the recent breach at T-Mobile that exposed this data on 40 million current, past and prospective customers.

What’s more, victims of SIM swapping and number port-out fraud are often the last to know about their victimization. The FCC said it plans to prohibit wireless carriers from allowing a SIM swap unless the carrier uses a secure method of authenticating its customer. Specifically, the commission proposes that carriers be required to verify a “pre-established password” with customers before making any changes to their accounts.

According to the FCC, several examples of pre-established passwords include:

-a one-time passcode sent via text message to the account phone number or a pre-registered backup number
-a one-time passcode sent via email to the email address associated with the account
-a passcode sent using a voice call to the account phone number or pre-registered back-up telephone number.

The commission said it was also considering updating its rules to require wireless carriers to develop procedures for responding to failed authentication attempts and to notify customers immediately of any requests for SIM changes.

Additionally, the FCC said it may impose additional customer service, training, and transparency requirements for the carriers, noting that too many customer service personnel at the wireless carriers lack training on how to assist customers who’ve had their phone numbers stolen.

The FCC said some of the consumer complaints it has received “describe wireless carrier customer service representatives and store employees who do not know how to address instances of fraudulent SIM swaps or port-outs, resulting in customers spending many hours on the phone and at retail stores trying to get resolution. Other consumers complain that their wireless carriers have refused to provide them with documentation related to the fraudulent SIM swaps, making it difficult for them to pursue claims with their financial institutions or law enforcement.”

“Several consumer complaints filed with the Commission allege that the wireless carrier’s store employees are involved in the fraud, or that carriers completed SIM swaps despite the customer having previously set a PIN or password on the account,” the commission continued.

Allison Nixon, an expert on SIM swapping attacks chief research officer with New York City-based cyber intelligence firm Unit221B, said any new authentication requirements will have to balance the legitimate use cases for customers requesting a new SIM card when their device is lost or stolen. A SIM card is the small, removable smart card that associates a mobile device to its carrier and phone number.

“Ultimately, any sort of static defense is only going to work in the short term,” Nixon said. “The use of SMS as a 2nd factor in itself is a static defense. And the criminals adapted and made the problem actually worse than the original problem it was designed to solve. The long term solution is that the system needs to be responsive to novel fraud schemes and adapt to it faster than the speed of legislation.”

Eager to weigh in on the FCC’s proposal? They want to hear from you. The electronic comment filing system is here, and the docket number for this proceeding is WC Docket No. 21-341.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains