SolarWinds Attackers Hit Active Directory Servers with FoggyWeb Backdoor

Microsoft is warning that the Nobelium APT is compromising single-sign-on servers to install a post-exploitation backdoor that steals data and maintains network persistence.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Executive Spotlight: Q&A with VP of Products and Marketing, Anand Ramanathan

I spoke with Anand Ramanathan, VP of Products and Marketing who brings over 20 years of enterprise SaaS product experience ranging from high growth startups to established market leaders. Read the interview below to understand his thoughts on McAfee Enterprise and where he see’s the company going in the coming years.

Q: What is your ideal way to spend a Sunday?

Every ideal Sunday has 3 components:

  1. Starts with keeping the body fit – a game of tennis with close friends.
  2. Spending time with family – making and eating lunch together.
  3. Preparing for the week ahead – planning out my work schedule and prioritizing the actions.

Q: With cybersecurity and AI capabilities expanding at a rapid pace, what will the future look like for companies like McAfee Enterprise in the coming years?

The adversarial landscape has always been a digital cat and mouse game. McAfee Enterprise’s investment in AI over the years has allowed its solution to stay ahead of adversaries and provide industry-best protection for its customers. With adversaries pivoting their techniques at a more rapid pace, it has become imperative for security solutions to leverage the cloud and AI capabilities.

Q: Can you talk about McAfee Enterprise’s history of Insights and how it is used to improve cybersecurity capabilities, including protecting against cyber threats?

Insights was born out of two very simple questions that CISOs get asked: Were we impacted by a given threat? Will our defenses protect us from the threat?

With an increase in security breaches being covered by popular press; board and executive management are becoming more attune with the threat landscape. We are seeing them start to ask the important questions to their security teams.

At McAfee Enterprise, we saw the gap in knowledge within security teams to give quick and efficient answers to the two pivotal questions. And given our depth in threat research and data analytics capabilities, innovated with the industry’s first proactive security solution in MVISION Insights, we feel we can answer the above questions, placing crucial information in the hands of the security teams. The feedback from our customers has been tremendously positive.

Q: What goals and initiatives are you focusing on to drive the company for the rest of 2021 and beyond? What IT capabilities do you have your eye on?

McAfee Enterprise is at the center of three key buzzwords of 2021 – SASE, ZTNA, and XDR. We have been at the forefront of innovating in these areas with the release of MVISION Insights, MVISION Private Access, and MVISION UCE with integrated Remote Browser Isolation. We also have leadership in MITRE based attack detection for endpoint and cloud and MVISION marketplace for security ecosystem integration. We will be continuing this innovation velocity and lead the market with new capabilities on Zero Trust and XDR integration with the security ecosystem. Stay tuned, more to come!

The post Executive Spotlight: Q&A with VP of Products and Marketing, Anand Ramanathan appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Why Can’t We Automate Everything?

You can’t automate every business process. While I love automation and promote the concept, I know its limitations. This viewpoint needs to be recognized and observed as more security officials implement automation within their organizations.

I’d estimate that for most enterprises, the first 80 percent of migrating and integrating processes to automation is easy to do. The last 20 percent is hard to accomplish.

This breakdown helps you set realistic expectations about automation. I enjoy how automation saves time by generating useful data through repetition. But right now, data compiled from some activities still require a human being to examine the results and make a decision. You will still need a critical eye from your security operations team or managed security services provider when looking at the useful data or anomalies.

We still need to address the 20 percent and realize that the situation may not be as much of a challenge as we think initially. Here are some examples of what I mean.

Where Automation Needs a Human Touch

Your automation detects and notes that one of your executives is connecting to your network from Russia. How do you know whether that executive is actually in Russia or if someone there is impersonating that executive? For optimal security, there needs to be human interaction to review the information and determine whether to let that person should be allowed to connect.

Or consider when IT officials at a hospital used the McAfee Enterprise ePolicy Orchestrator (ePO) console to automate a deeper level scan of physicians’ laptops. This scan occurred before the physicians began their daily scans by sending over someone from the hospital’s operations department to clean the laptop and comply with HIPAA regulations. To collect the events compiled from the laptops, the IT officials used IBM® QRadar® Device Support Module (DSM) for McAfee Enterprise ePO. This platform integrated from IBM Security™ uses analytics for insights into potential threats to data.

With this setup, whenever an anomaly appeared in QRadar, such as some unusual behavior at the network level, an IT official at the hospital would right-click and add the IP address to a different scan group in ePO through the application programming interfaces (APIs). Automating that initial first pass of scanning the laptop finds these discrepancies quickly. But ultimately humans like IT officials must review the notification and send a message to McAfee Enterprise expert to clean the anomaly from the laptop themselves and confirm the anomaly was removed.

So, it’s hard to automate the 20 percent done by humans in your organization as shown here. But what the 80 percent of easy automation does for the rest of your business processes can outweigh that perceived drawback.

How and Why the 80 Percent Easy Automation Matters More

You can easily find yourself at work engulfed in an ocean of data. Indicators from your automation help you find out what’s important. Activity from the endpoints of your network gives you or an MSSP a view of what’s happening with your data.

Most systems today have everything connected to the internet. The endpoints interact with your network. Having broad visibility and detection across your network — whether it’s looking at DNS logs, proxy logs, traffic and so on — allows you to correlate information and identify what’s taking place right now.

The real-time aspect of automation for data on your network is vital important. Threats to your network depends both on how much time they require to activate and how long before they are detected and remediated. Automation that’s easy to implement helps find attacks quickly with a real-time detection engine that can minimize the damage that takes place.

Experts at McAfee Enterprise and our partners at IBM Security can help with troubleshooting by providing support for the 20 percent automation you can’t fulfill. You can investigate a full lifecycle of endpoint events using McAfee Enterprise MVISION and IBM QRadar integrated together. And you can automate remediation with the IBM Security SOAR (security orchestration, automation and response) platform.

With these tools, you can integrate the data available from threat feeds in one platform for better visibility and context. IBM’s managed security services experts can help you answer questions around how to best configure, administrate and manage endpoint security incidents based on that data collected by automation.

We can also help you learn about other technologies and trends that are happening that our experts deal with every day. Consultants can help you identify how to lower or minimize costs of attacks and breaches as well as work proactively to address these issues. Automation can’t provide you with these resources, but we can.

What to Expect for the Future

We have researchers at work looking how to merge that last hard 20 percent of automation implementation into the 80 percent of easy migration and conversion. For now, accept the notion that automation can handle most tasks for your organization and save you time and costs in the process. And what automation can’t do in those areas, we at McAfee Enterprise and IBM Security can help fill in the gaps.

Learn more about what automation with expert support can do for you by reviewing the features of MVISION Endpoint Security and IBM Managed Security Services. Or schedule a free 30-minute consultation with IBM Security by clicking the “Let’s talk” button on the IBM Managed Security Services homepage.

 

The post Why Can’t We Automate Everything? appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Apple AirTag Bug Enables ‘Good Samaritan’ Attack

The new $30 AirTag tracking device from Apple has a feature that allows anyone who finds one of these tiny location beacons to scan it with a mobile phone and discover its owner’s phone number if the AirTag has been set to lost mode. But according to new research, this same feature can be abused to redirect the Good Samaritan to an iCloud phishing page — or to any other malicious website.

The AirTag’s “Lost Mode” lets users alert Apple when an AirTag is missing. Setting it to Lost Mode generates a unique URL at https://found.apple.com, and allows the user to enter a personal message and contact phone number. Anyone who finds the AirTag and scans it with an Apple or Android phone will immediately see that unique Apple URL with the owner’s message.

When scanned, an AirTag in Lost Mode will present a short message asking the finder to call the owner at at their specified phone number. This information pops up without asking the finder to log in or provide any personal information. But your average Good Samaritan might not know this.

That’s important because Apple’s Lost Mode doesn’t currently stop users from injecting arbitrary computer code into its phone number field — such as code that causes the Good Samaritan’s device to visit a phony Apple iCloud login page.

A sample “Lost Mode” message. Image: Medium @bobbyrsec

The vulnerability was discovered and reported to Apple by Bobby Rauch, a security consultant and penetration tester based in Boston. Rauch told KrebsOnSecurity the AirTag weakness makes the devices cheap and possibly very effective physical trojan horses.

“I can’t remember another instance where these sort of small consumer-grade tracking devices at a low cost like this could be weaponized,” Rauch said.

Consider the scenario where an attacker drops a malware-laden USB flash drive in the parking lot of a company he wants to hack into. Odds are that sooner or later some employee is going to pick that sucker up and plug it into a computer — just to see what’s on it (the drive might even be labeled something tantalizing, like “Employee Salaries”).

If this sounds like a script from a James Bond movie, you’re not far off the mark. A USB stick with malware is very likely how U.S. and Israeli cyber hackers got the infamous Stuxnet worm into the internal, air-gapped network that powered Iran’s nuclear enrichment facilities a decade ago. In 2008, a cyber attack described at the time as “the worst breach of U.S. military computers in history” was traced back to a USB flash drive left in the parking lot of a U.S. Department of Defense facility.

In the modern telling of this caper, a weaponized AirTag tracking device could be used to redirect the Good Samaritan to a phishing page, or to a website that tries to foist malicious software onto her device.

Rauch contacted Apple about the bug on June 20, but for three months when he inquired about it the company would say only that it was still investigating. Last Thursday, the company sent Rauch a follow-up email stating they planned to address the weakness in an upcoming update, and in the meantime would he mind not talking about it publicly?

Rauch said Apple never acknowledged basic questions he asked about the bug, such as if they had a timeline for fixing it, and if so whether they planned to credit him in the accompanying security advisory. Or whether his submission would qualify for Apple’s “bug bounty” program, which promises financial rewards of up to $1 million for security researchers who report security bugs in Apple products.

Rauch said he’s reported many software vulnerabilities to other vendors over the years, and that Apple’s lack of communication prompted him to go public with his findings — even though Apple says staying quiet about a bug until it is fixed is how researchers qualify for recognition in security advisories.

“I told them, ‘I’m willing to work with you if you can provide some details of when you plan on remediating this, and whether there would be any recognition or bug bounty payout’,” Rauch said, noting that he told Apple he planned to publish his findings within 90 days of notifying them. “Their response was basically, ‘We’d appreciate it if you didn’t leak this.’”

Rauch’s experience echoes that of other researchers interviewed in a recent Washington Post article about how not fun it can be to report security vulnerabilities to Apple, a notoriously secretive company. The common complaints were that Apple is slow to fix bugs and doesn’t always pay or publicly recognize hackers for their reports, and that researchers often receive little or no feedback from the company.

The risk, of course, is that some researchers may decide it’s less of a hassle to sell their exploits to vulnerability brokers, or on the darknet — both of which often pay far more than bug bounty awards.

There’s also a risk that frustrated researchers will simply post their findings online for everyone to see and exploit — regardless of whether the vendor has released a patch. Earlier this week, a security researcher who goes by the handle “illusionofchaos” released writeups on three zero-day vulnerabilities in Apple’s iOS mobile operating system — apparently out of frustration over trying to work with Apple’s bug bounty program.

Ars Technica reports that on July 19 Apple fixed a bug that llusionofchaos reported on April 29, but that Apple neglected to credit him in its security advisory.

“Frustration with this failure of Apple to live up to its own promises led illusionofchaos to first threaten, then publicly drop this week’s three zero-days,” wrote Jim Salter for Ars. “In illusionofchaos’ own words: ‘Ten days ago I asked for an explanation and warned then that I would make my research public if I don’t receive an explanation. My request was ignored so I’m doing what I said I would.’”

Rauch said he realizes the AirTag bug he found probably isn’t the most pressing security or privacy issue Apple is grappling with at the moment. But he said neither is it difficult to fix this particular flaw, which requires additional restrictions on data that AirTag users can enter into the Lost Mode’s phone number settings.

“It’s a pretty easy thing to fix,” he said. “Having said that, I imagine they probably want to also figure out how this was missed in the first place.”

Apple has not responded to requests for comment.

Update, 12:31: Rauch shared an email showing Apple communicated their intention to fix the bug just hours before — not after — KrebsOnSecurity reached out to them for comment. The story above has been changed to reflect that.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#IMOS21: Global Threat Brief – The Most Dangerous Attack Techniques in 2021

#IMOS21: Global Threat Brief – The Most Dangerous Attack Techniques in 2021

During Infosecurity Magazine’s North American Online Summit, editorial director Eleanor Dallaway moderated a session dedicated to the most dangerous attack techniques in 2021. In her opening statement, she stated that the last two years have seen a huge amount of change and evolution, and cyber attack vectors and attack techniques have been no exception. 

Dallaway was joined by an expert panel including Brad LaPorte, partner of High Tide Advisors,  Miranda Richie, director of cyber threat operations at Orbia; and Michael F.D. Anaya, head of attack surface analysis, Palo Alto Networks & ex-cyber special agent, FBI. 

Cyber Attacks and COVID-19

The opening question of the Q&A concerned the speed of cyber-attacks changing in the context of COVID-19. LaPorte brought up  that crimeware-as-a-service (CaaS) has become widespread. He pointed out that around 2018, criminals changed their hacking approach. In effect, cyber-criminals have become managed service providers. The attack surface is now “everywhere” because of hybrid work models. Moreover, cyber-threat groups are more extensive and can now make a lot of money. Anaya responded to the question by stating that criminals will always find new opportunities. Phishing is still a big thing; it is easy to execute and will not disappear anytime soon, he noted. Richie raised the topic of initial access brokers, who she claims are enjoying rich pickings amid the COVID-19 chaos. LaPorte points out that alongside crime-as-a-service, DDoS-as-a-service and ransomware-as-a-service have become very popular during the pandemic. Additionally, hacker groups can easily break into companies and then sell the keys to the highest bidder.

 Anaya, agreeing with the points raised by the other two panelists, emphasized that while it’s true that threats are also evolving because of the amount of information sharing on the dark web, it’s also happening on open forums. At this stage, Richie asks Anaya whether this typically goes beyond collaborative efforts. What about the mafia? Anaya claimed that it is hard for law enforcement to obtain the identities of threat actors because of the factor of anonymity. 

Threat Actors and Competition

The second question  concerned whether there is an ostensible competition between threats actors? Anaya gave a succinct response, claiming that, unlike most organizations that struggle to share information because of legal barriers, there are no obvious barriers between threat actors. However, this is something that needs to change, according to Anaya, because organizations must share information more freely and effectively. 

“International hacker networks, nation-states and gangs are all collaborating”Brad LaPorte

Threat Actors Working Together

Dallaway shifted the question to the topic of money and how threats actors work together. LaPorte responded, stating that it makes sense to work together if no person’s wallet is affected. If people do not believe that threat actors are working together, people need to “wake up,” he said, adding that international hacker networks, nation-states and gangs are all collaborating.

The first audience poll asked viewers which of the following attack techniques do they consider to be the most dangerous. The results were as follows: 

  1. Supply chain attack (46%) 
  2. DDoS as a ransom (26%)
  3. RaaS (14%)
  4. API attacks (12%)

Ransomware-as-a-Service

The conversation shifted at this stage when Dallaway raised the question of ransomware-as-a-service. To this question, Richie explained what ransomware-as-a-service is while emphasizing the rise of double-extortion techniques, particularly exfiltration and encryption.  Anaya emphasized that when publicly sharing information when an organization is a victim of a ransomware attack, there is no regulation to force an organization to disclose it publically. LaPorte drew attention to 2018 when one third of ransomware victims would report an attack. However, in 2021 that number has shrunk to 13%. Unfortunately, even the FBI doesn’t have relevant information since many organizations don’t come forward. 

Off the back of this point, Dallaway asked whether fewer people are paying up. LaPorte contended that cyber-attacks are increasing in frequency, but also ransom demands are increasing. Essentially, attacks are still happening. Worryingly, hackers will look at other ways to get organizations to pay. Moreover, the costs associated with breaches are also increasing. Miranda Ritchie questioned whether authorities are going after the attackers en masse.

Michael F.D. Anaya argued that the FBI was trying to identify threat actors, but the task was very complicated since attackers are notoriously hard to identify
Michael F.D. Anaya argued that the FBI was trying to identify threat actors, but the task was very complicated since attackers are notoriously hard to identify

To this previous point, Anaya replied that the FBI was trying like other government departments, but the task was very complicated: he contended that attackers are notoriously hard to identify. According to Anaya, there is a lot of delineation in the government, and the FBI is “siloed,” which presents various problems. LaPorte added that this gets more complicated when factoring in things like insurance. The best practice should be to share intel and to make the process “ubiquitous.” Here Anaya added that organizations could not achieve this without being empowered to share intel strategically so law-enforcement agencies can identify threat actors. 

Commodity Malware

Dallaway shifted the conversation to a question posed by the audience regarding commodity malware, asking why cybersecurity experts do not place enough emphasis on this.  Anaya replied to this point by asking to look at the most significant threat: commodity malware. Furthermore, this is what government entities are setting their sights on. 

The results of the second poll, namely, which of the following attack techniques do voters consider to be the most dangerous, were: 

  1. Supply Chain Zero Day exploit (50%) 
  2. Cloud misconfiguration (26%)
  3. Business email compromise (19%)
  4. EPP/EDR bypass (3%)

Ransomware and Supply Chain Attacks

Dallaway raised another critical topic in the global threat landscape in light of the second poll results. Directing the question at  Richie, Dallaway asked why voters likely picked ransomware and supply chain attacks as the most concerning threats. Richie highlighted that we should look at the Kaseya supply chain attack this year, which caused widespread downtime for over 1,000 companies. The SolarWinds attack this year is another example, which targeted US federal agencies and over 100 companies. Not only do they have a huge impact on businesses, operationally and financially, but they are notoriously hard to detect and defend. LaPorte emphasized remote code execution — if attackers can execute this effectively, they have significant power in their attacks. 

“Ransomware and supply chain attacks not only have a huge impact on businesses, operationally and financially, but they are notoriously hard to detect and defend”Miranda Richie

Artificial Intelligence

Dallaway raised a question from the audience focusing on AI-based attacks. Since attackers are using AI to execute supply chain attacks, the question asked, must companies use AI to protect themselves effectively? LaPorte responded by pointing out that companies using AI will decrease work and costs. Moreover, AI-led detection and response are significantly effective at protecting organizations.

Anaya remarked that machine learning could assist businesses greatly since AI can learn patterns of “normal” behavior in an organization and detect and investigate anomalies. In response to this point, LaPorte claimed that studies show an 80% reduction in costs when organizations use both AI and automation. Richie added that the industry is well aware of SOC fatigue; AI can help automate the repetitive tasks SOCs typically tackle. 

Cloud Misconfiguration

The penultimate question raised concerned the threats associated with cloud misconfiguration. Anaya responded that the MFA (multi-factor authentication) base isn’t rotated enough, presenting innumerable threats. Additionally, rotation isn’t a policy that organizations enforce enough. A follow-up point concerned EPP and EDRs being bypassed and zero-day exploits. LaPorte highlighted that attackers can, in effect, do various things on IoT without detection. Additionally, modern tech is an ever more complicated and increasing issue. 

The result of the third poll, asking voters what 2022 will be the year of, revealed the following:

  1. Ransomware…again (43%)
  2. Who on earth knows?! (25%) 
  3. Zero trust (16%)
  4. AI (9%)
  5. Data breaches (4%)

2022 Is the Year Of? 

The final question was posed as a quick-fire round, asking what each panelist believed 2022 would be the year of. Richie believed 2022 to be when the lines between physical and digital will be blurred. Real-life examples include hospitals and pipelines. This trend, she argued, will increase. Anaya agreed with Richie, adding that there are three things that organizations can do here to protect themselves: 1) organize a dedicated team, 2) empower that team and 3) see cybersecurity as a critical cost. Finally, LaPorte wrapped up the commentary, stating that organizations can also protect themselves with ‘operational readiness.’ 


The session is now on-demand and can be viewed here.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

California Hospital Sued Over Data Breach

California Hospital Sued Over Data Breach

An academic health-care system in California is facing legal action over a data breach that potentially exposed the information of nearly half a million patients, employees, and students.  

UC San Diego Health disclosed a security incident in July via a public notice. The notice indicated that unauthorized access to “some employee email accounts” had taken place from December 2, 2020, to April 8, 2021. 

The incursion occurred after an employee with a health-system email account took the bait proffered in a phishing attack. Suspicious activity was detected in the system’s network on March 12, and compromised email accounts were shut down on April 8.

“When UC San Diego Health discovered the issue, we terminated the unauthorized access to these accounts and enhanced our security controls,” said the health-care provider.  

The health system said that data potentially accessed and exfiltrated in the attack may include the full names, addresses, dates of birth, email addresses, fax numbers, claims information including dates and costs of care received, laboratory results, medical diagnoses and conditions, medical record numbers, prescription information, treatment information, Social Security numbers, government identification numbers, financial account numbers, student identification numbers, usernames, and passwords of a “subset of our patient, student and employee community.”

On September 7, UC San Diego Health began notifying 495,949 individuals – where contact information was available – that they may have been affected by the breach.

The San Diego Union-Tribune reports that lawyers representing a cancer patient from El Cajon filed a suit last week against UC San Diego Health over the data breach. The plaintiff has accused the health-care system of breach of contract, negligence, and violating California consumer privacy and medical confidentiality laws.

“This breach was preventable had UC San Diego Health had the right data protection protocols in place,” said San Diego attorney Jason Hartley.

The plaintiff asserts that the health-care system failed to adequately train employees on how to avoid phishing attacks and neglected to implement reasonable security practices. 

The suit is seeking class-action status and unspecified damages for all the individuals whose medical data and personal information may have been exposed.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Port of Houston Quells Cyber-Attack

Port of Houston Quells Cyber-Attack

A leading port in the United States has successfully fended off an attempted cyber-attack, which authorities believe was sponsored by a foreign power.  

Cybersecurity and Infrastructure Security Agency (CISA) director Jen Easterly revealed to a Senate committee on September 23 that malicious hackers had targeted the Port of Houston in August.

The 25-mile-long port complex is one of the largest on the US Gulf Coast and handles around 247 million tons of cargo per year, according to the port’s website.

Easterly divulged to the Senate Homeland Security and Governmental Affairs Committee that while attribution of cyber-attacks “can always be complicated,” she was of the opinion that a “nation-state actor” was to blame in this case. 

“At this point in time, I would have to get back with my colleagues, but I do think it is a nation-state actor,” said Easterly. However, the cyber leader did not go so far as to name which one she believed to be responsible. 

The Port of Houston put out a brief statement on Thursday announcing that a digital assault against its systems had come to naught.

“The Port of Houston Authority (Port Houston) successfully defended itself against a cybersecurity attack in August. Port Houston followed its Facilities Security Plan in doing so, as guided under the Maritime Transportation Security Act (MTSA), and no operational data or systems were impacted as a result,” read the statement.

Hackers exploited a previously unknown vulnerability in password management software to break into one of the port’s web servers at 2:38pm UTC on August 19, according to Coast Guard analysis of the incident, obtained by CNN.

The threat actor installed malicious code to expand their access to the system and then exfiltrated all the log-in credentials for a piece of Microsoft password management software used to control network access. 

“If the compromise had not been detected, the attacker would have had unrestricted remote access to the [IT] network,” the unclassified report by US Coast Guard Cyber Command reportedly reads.  

“With this unrestricted access, the attacker would have had numerous options to deliver further effects that could impact port operations.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Huawei CFO Released After Admitting She Misled Bank

Huawei CFO Released After Admitting She Misled Bank

Huawei’s CFO is finally back in China after striking a plea deal with the US authorities in which she admitted playing a pivotal role in a scheme designed to defraud a global financial institution.

Meng Wanzhou, the daughter of Huawei founder Ren Zhengfei, was indicted by the US in 2019 on charges associated with the firm’s alleged breaking of US sanctions on Iran.

According to the Department of Justice (DoJ), she lied to a banking partner about the scale and nature of the firms’ business in Iran to preserve the relationship with the financial institution.

Specifically, she told the senior exec at the bank that subsidiary Skycom, which operated in Iran, was just a business partner rather than wholly controlled by Huawei. She also said Huawei had sold all its shares in Skycom, when, in fact, it sold them to another entity controlled by Huawei.

The DoJ said she also lied in claiming Huawei “operates in Iran in strict compliance with applicable laws, regulations and sanctions” and that “there has been no violation of export control regulations” by “Huawei or any third party Huawei works with.”

As a result of her false reassurances, the bank helped clear around $100m in transactions from Skycom, some of which came from its Iran dealings, in contravention of US sanctions.

According to the plea deal, Meng pleaded not guilty to charges of bank fraud and wire fraud, conspiracy to commit bank fraud and conspiracy to commit wire fraud, but did admit most facts underpinning the DoJ’s case.

“Her admissions in the statement of facts confirm that, while acting as the Chief Financial Officer for Huawei, Meng made multiple material misrepresentations to a senior executive of a financial institution regarding Huawei’s business operations in Iran in an effort to preserve Huawei’s banking relationship with the financial institution,” said acting US attorney Nicole Boeckmann.

“The truth about Huawei’s business in Iran, which Meng concealed, would have been important to the financial institution’s decision to continue its banking relationship with Huawei. Meng’s admissions confirm the crux of the government’s allegations in the prosecution of this financial fraud — that Meng and her fellow Huawei employees engaged in a concerted effort to deceive global financial institutions, the US government and the public about Huawei’s activities in Iran.”

Meng had been under house arrest in Canada awaiting extradition to the US when the deal was struck. However, the two Canadians under arrest by the Chinese authorities in an apparent tit-for-tat ploy were released shortly after, apparently countering Beijing’s claims that they had committed severe spying offenses.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains