Poland Extradites Alleged Botnet Operator to US

Poland Extradites Alleged Botnet Operator to US

A Ukrainian accused of decrypting the credentials of thousands of computers across the globe and selling them on the dark web has been extradited to the United States.

US authorities indicted Glib Oleksandr Ivanov-Tolpintsev in October 2020 in connection with charges of conspiracy, trafficking in unauthorized access devices, and trafficking in computer passwords. 

Polish authorities arrested 28-year-old Ivanov-Tolpintsev on October 3, 2020. The defendant, who is from Chernivtsi, Ukraine, was recently extradited to the US, where he was presented before US magistrate Julie S. Sneed on September 7, 2021.

According to the indictment, from as early as May 2016, Ivanov-Tolpintsev used a botnet and brute-forcing malware to compromise and unlawfully obtain the login credentials of computers all over the world. 

It is alleged that in or around January 2017 he created an account on a dark website called The Marketplace and listed the login credentials of compromised computers for sale. Ivanov-Tolpintsev is further accused of selling the credentials and using the funds generated by their sale for his own personal enrichment. 

“Once sold on this website, credentials were used to facilitate a wide range of illegal activity, including tax fraud and ransomware attacks,” said the Department of Justice. 

The botnet allegedly deployed by Ivanov-Tolpintsev was capable of decrypting the login credentials of at least 2,000 computers each week, according to the indictment.

By April 2017, the Ukrainian had allegedly amassed the login credentials of 20,000 compromised computers. 

Among the alleged victims of Ivanov-Tolpintsev whose decrypted login credentials were purchased on the dark web were individuals located in Florida, Maryland, California, and Colorado. 

According to the indictment, the United States intends to forfeit $82,648, which it alleges can be traced to proceeds of the offenses, from Ivanov-Tolpintsev.

If convicted of all the charges laid against him, Ivanov-Tolpintsev could be sentenced to up to 17 years in federal prison. 

The investigation into the Ukrainian and his alleged illegal botnet activities was led by the Tampa Division of the Federal Bureau of Investigation, the Internal Revenue Service – Criminal Investigation’s Tampa Field Office, and Homeland Security Investigations – Tampa Division. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Colorado County Clerk Charged with Cybercrime

Colorado County Clerk Charged with Cybercrime

Formal charges have been filed against a deputy county clerk from Colorado who allegedly entered a county building and used her boss’s computer after being placed on paid leave. 

Belinda Gail Knisley, who works for Mesa County, was placed on administrative leave by the county’s director of human resources on August 23. 

According to an affidavit, the county suspended Knisley after receiving numerous complaints from multiple sources that she had “engaged in inappropriate, unprofessional conduct in the workplace.”

Mesa County’s IT team disabled Knisley’s access to Mesa County computers, networks, and servers on the same day that she was placed on leave. 

Two days later, Knisley was found inside a secure area in the county DMV office, allegedly attempting to print documents from a work computer belonging to Mesa County clerk and recorder, Tina Peters.

County officials were alerted to Knisley’s presence when several print-request emails were sent to Mesa County’s IT department from an email address belonging to Peters. 

“Items were sent to the print server, but were not ultimately printed,” states the affidavit. 

“What those items were was not immediately clear and remains under investigation.”

A search warrant executed for Peters’ Mesa County work notebook computer appeared to show that Knisley had used Peters’ workstation to access the secure Mesa County computer network.

The affidavit alleges that Knisley gained access by using Peters’ password and her yubikey – a physical dongle that is plugged into a computer assigned to a unique user to validate their credentials. 

The 66-year-old suspended deputy clerk turned herself in to authorities on September 1 after a warrant was issued for her arrest. 

Knisley has been charged with second-degree burglary of a building, a class 4 felony, and cybercrime – unauthorized access, a class 2 misdemeanor.

On Thursday, the 21st Judicial District Attorney’s Office stated that the charges levied against the deputy county clerk are not part of an ongoing probe by its office and the Federal Bureau of Investigation into possible election security breaches concerning voting equipment belonging to Mesa County. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Menlo Appoints Devin Ertel as CISO

Menlo Appoints Devin Ertel as CISO

Cloud security company Menlo Security has appointed Devin Ertel as its Chief Information Security Officer (CISO).

Ertel takes up the post following nearly 20 years of experience as an information security professional. Most recently, he was CISO at FinTech firm BlackHawk Network, where he managed a global team responsible for security, risk and compliance.

Prior to this role, he was head of security IT at SaaS company Guidebook, where he built and oversaw its security program. Other experiences include directly tackling high-profile breaches at Mandiant and the US Federal Reserve.

Ertel is also a respected thought leader in cybersecurity, regularly speaking at industry events and advising early-stage companies on their security strategy.

At Menlo, he is responsible for providing cybersecurity direction and insights both internally and for customers. He will also oversee the company’s efforts to reduce its risk and security exposure globally.

Devin Ertel takes up the post following nearly 20 years of experience as an information security professional
Devin Ertel takes up the post following nearly 20 years of experience as an information security professional

Commenting on his appointment, Ertel said: “Organizations are often under the impression that productivity or user experience must be sacrificed to achieve security, and that is simply not true anymore.

“I’m eager to build a security program that not only addresses industry challenges but also enables our customers to do the same for their respective businesses. Menlo Security provides a unique, differentiated approach to securing work for the modern business, and I’m excited to be a part of the journey.”

Poornima DeBolle, co-founder and CPO at Menlo, said: “Our leadership team is made up of unrelenting cybersecurity professionals and Devin is no exception. He brings the perfect blend of hands-on experience as a security practitioner with a proven track record of building and scaling successful security programs.

“As a security company that aims to secure work for everyone, we’re thrilled to have Devin on board to enhance our own security program as Menlo Security’s CISO.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Personal Information of Nearly 80,000 MyRepublic Customers Accessed After Breach

Personal Information of Nearly 80,000 MyRepublic Customers Accessed After Breach

The personal data of approximately 80,000 MyRepublic mobile subscribers was accessed without authorization last month.

The Singaporean communications services provider released a statement on Friday (September 10) claiming that the breach took place on August 29 via a third-party data storage platform used to store customer data.

The unauthorized access reportedly affected 79,388 mobile subscribers based in Singapore. The customer data contained personal information, including scanned copies of NRICs, proof of residential address documents and names and mobile numbers. 

MyRepublic added that there is no reason to believe other sensitive data, such as payment information, was breached. The communications service provider has since secured and contained the incident. 

The telco stressed that the unauthorized access had no operational impact on its services. Nevertheless, it has informed the Infocomm Media Development Authority and the Personal Data Protection Commission of the incident. 

MyRepublic also activated its cyber incident response team, comprising a group of external expert advisors to work closely with its internal IT and Network teams. 

“We are disappointed with what has happened, and I would like to personally apologize for any inconvenience caused,” said MyRepublic chief executive officer Malcolm Rodrigues.

MyRepublic said that it would give all affected customers a complimentary credit monitoring service through Credit Bureau Singapore (CBS), which will monitor their credit report and notify them when any suspicious activity occurs. 

Rodrigues added: “We are reviewing all our systems and processes, both internal and external, to ensure an incident like this does not occur again.” 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

UK to Revamp ICO as Part of Data Rules Reform

UK to Revamp ICO as Part of Data Rules Reform

The UK government has unveiled plans to “overhaul” the Information Commissioner’s Office (ICO) as it launched a consultation designed to reform the nation’s data sector.

The Department for Digital, Culture, Media and Sport (DCMS) said it wants to revamp the structure of the ICO, the independent body responsible for upholding information rights in the UK. This includes creating an independent board and chief executive to mirror other regulatory authorities, such as the Competition and Markets Authority (CMA) and Ofcom.

The government also plans to expand the ICO’s remit and enable the Information Commissioner to champion examples of innovative and responsible data use, particularly in critical sectors such as healthcare.

The proposed changes have come shortly after the government announced its preferred candidate to be the new Information Commissioner, John Edwards, who is currently the New Zealand Privacy Commissioner. In the same release, it outlined its ambition to reform the UK’s data laws to unlock the full potential of data throughout the economy.  

The reforms outlined in the new consultation build on this pledge, aiming to “remove unnecessary barriers to responsible data use.” This is particularly to facilitate innovation in sectors such as healthcare, science and emerging technologies like AI. The DCMS pointed out that the use of AI and machine learning will increase significantly in the coming years and believes greater flexibility in the UK’s data rules is required to ensure the risk of bias in these algorithmic systems can be better understood and mitigated.

The government also signaled its intention to move away from a “one-size-fits-all” approach to data and allow organizations to “demonstrate compliance in ways more appropriate to their circumstances.”

Additionally, new obligations could be placed upon organizations to protect personal data and individual privacy. This includes proposals to impose tougher penalties and fines for nuisance calls and text messages.

Digital Secretary Oliver Dowden commented: “Data is one of the most important resources in the world, and we want our laws to be based on common sense, not box-ticking.

“Now that we have left the EU, we have the freedom to create a new world-leading data regime that unleashes the power of data across the economy and society.

“These reforms will keep people’s data safe and secure, while ushering in a new golden age of growth and innovation right across the UK, as we build back better from the pandemic.”

Bojana Bellamy, president of Centre for Information Policy Leadership (CIPL), said: “The UK government’s plan to reform data protection regime is bold and much needed in the modern digital and data-driven age. It could be a win-win for all — organizations, individuals and society.

“It enables organizations to leverage data responsibly, for economic and societal benefits, and to build their brand as trusted data stewards. It gives individuals assurances and more effective protection from genuine harms.

“Accountability, risk and outcome-based approach will be welcomed by all — these are the founding blocks of modern regulation and a modern regulator. I hope other countries follow the UK’s lead.”

Recently, Infosecurity interviewed Bojana Bellamy about potential changes to the UK’s data laws, including GDPR, post-Brexit.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

5 Steps For Securing Your Remote Work Space

With so many people still working from home, cybercriminals are trying to cash in. Cyberattacks have increased 300% and the risk of losing important data or being compromised is much greater at home.

Here are five recommendations for securing your home office.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains