Banksy NFT Scammer Returns £240,000 to Victim

Banksy NFT Scammer Returns £240,000 to Victim

An online scammer who duped an art collector into spending over £240,000 for a non-fungible token (NFT) has returned the money, according to the BBC.

The unnamed investor told the news site that he bought the NFT after being alerted to its sale by an anonymous person in his community on Discord on Monday morning.

Their tip-off took him to the website of famous British street artist Banksy, which had just launched a new NFT page. That page included a link to an auction site selling an NFT called “Great Redistribution of the Climate Change Disaster.”

However, unknown to the man, the link he clicked on appears to have been inserted on the site by the scammer.

It took him to an auction site where Banksy’s supposed first-ever NFT was up for sale. The individual is said to have bid 90% more than rival bidders to secure the token — subsequently sending the funds via Ethereum to the scammer.

“It does seem to be some hack of the site. I confirmed the URL on PC and mobile before bidding. I only made the bid because it was hosted on his site,” he told the BBC. “When the bid was accepted I immediately thought it was probably fake.”

However, in a bizarre twist, the fraudster had returned all the money except for a £5000 transaction fee by the same evening.

“The refund was totally unexpected. I think the press coverage of the hack plus the fact that I had found the hacker and followed him on Twitter may have pushed him into a refund,” the victim noted.

“I feel very lucky when a lot of others in a similar situation with less reach would not have had the same outcome.”

It’s still unclear exactly how the scammer managed to hack Banksy’s website to insert the offending link.

A spokesperson for the Bristol-based artist confirmed: “The artist Banksy has not created any NFT artworks.”

NFTs are a unit of data stored on a blockchain that provide proof of digital ownership for items like artworks, which can then be traded online.

However, they’re also fertile ground for cyber-criminals looking for ways to extract money from buyers, according to ESET cybersecurity specialist, Jake Moore.

“It is vital — as with any online transaction — to purchase from a verified location, but unfortunately this advice becomes redundant when legitimate websites are hacked,” he warned.

“Those looking to buy should remain largely sceptical of NFTs while they are in these early stages and always err on the side of caution. Scammers are very good at manipulating people, and the makeup of NFTs themselves is easily abused due to the lack of a physical product or service.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Victim of Cyber-Theft Sues Parents of Alleged Culprits

Victim of Cyber-Theft Sues Parents of Alleged Culprits

A man from Colorado is suing the parents of two British youths who he claims stole Bitcoin worth nearly $800K from his digital wallet. 

Cyber-thieves used malware to swipe 16.4 Bitcoin from Andrew Schober back in January 2018 when he was attempting to move his crypto-currency between virtual wallets. 

To track his stolen funds, the aggrieved party hired private investigators, spending approximately $10,000 to discover who had swiped his crypto.  

After investigators fingered two British lads who were minors at the time the offense was committed as the perpetrators of the theft, Schober wrote to one of the boys’ parents. 

In his letter of December 2019, Schober communicated that he would not take legal action against the boy’s parents if the stolen funds were returned.

After receiving no response to his letter, Schober filed an official complaint against Benedict Thompson and Oliver Read and their parents.

In the complaint, Schober describes Thompson and Read as “skilled software developers and computer science students” who created and deployed clipboard hijacking malware and then used it to steal his 16.4552 bitcoins.

Schober says the Bitcoin stolen from him “accounted for approximately 95% of his net wealth at the time” and that its loss has placed him “in a severe state of distress for the past three years.”

In the complaint, Schober alleges that Thompson and Read hit his wallet with malware that used a “Man-in-the-Middle” attack vector.

“Mr. Schober believed he was communicating only with his own crypto-currency wallet, but because of the malware, either Benedict or Oliver or both intercepted and altered the communications between Mr. Schober and the Bitcoin blockchain,” it states. 

Schober claims that the parents of the alleged cyber-thieves “knew or reasonably should have known that their child engaged in illegal computer abuse(s) and/or crypto-currency theft(s) in a careless and/or reckless manner” and that they “failed to take reasonable steps” to prevent their son from committing illegal computer abuse and/or crypto-currency theft.

Neither Thompson nor Read has denied Schober’s accusations. The defendants have argued that Schober’s suit should be dismissed as the statute of limitations on the theft elapsed prior to the date on which the claim was filed.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Indonesians Told to Delete Unsecured Tracing App

Indonesians Told to Delete Unsecured Tracing App

The Indonesian government is exhorting the public to delete a COVID-19 test and trace app that left users’ personal information exposed on an unsecured server.  

The data breach in the Indonesian government’s electronic Health Alert Card (eHAC) program was discovered by a research team at vpnMentor led by Noam Rotem and Ran Locar. 

The program and the eHAC app were created in 2021 to monitor the coronavirus infection status of people entering the country. Obtaining an eHAC was mandatory for any traveler, including native Indonesians, when entering the Republic from overseas or taking a domestic flight within Indonesia. 

Researchers discovered that the app’s developers “failed to implement adequate data privacy protocols and left the data of over 1 million people exposed on an open server.”

In total, 2GB of data belonging to the Republic’s Ministry of Health were exposed on an Elasticsearch server. Researchers said the data included more than 1.4 million records and that approximately 1.3 million individuals had been impacted. 

Information left unsecured included Personal Identifiable Information (PII), medical records, contact details, travel information, and COVID-19 infection status. 

Researchers noted: “Had the data been discovered by malicious or criminal hackers, and allowed to accumulate data on more people, the effects could have been devastating on an individual and societal level.”

The database of unprotected records was discovered by researchers on July 15. It was reported to the Ministry of Health on July 21 and to the Indonesian Computer Emergency Response Team (ID-CERT) on July 22. 

“Our team discovered eHAC’s records with zero obstacles, due to the lack of protocols put in place by the app’s developers,” wrote researchers in a blog post detailing the leak. 

“Once they investigated the database and confirmed the records were authentic, we contacted the Indonesian Ministry of Health and presented our findings.”

Despite twice flagging the open database to the Indonesian government and CERT, the researchers only received a response about the security incident in August after contacting Indonesia’s National Cyber and Encryption Agency (BSSN), which shut down the server on August 24.  

The eHAC app has now been integrated into a new app called PeduliLindungi. However, the Health Ministry, which publicly responded to the research findings earlier today, urged eHAC users to delete the app as a precaution.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Illinois Physicians Notify 600K Patients of Data Breach

Illinois Physicians Notify 600K Patients of Data Breach

The largest independent group of physicians in Illinois is notifying hundreds of thousands of patients that their personal information may have been exposed.

DuPage Medical Group (DMG) said that patient data could have been compromised when its computer network was hacked last month. 

On Monday, DMG announced that it would be mailing letters to 600,000 patients to warn them of the potential threat to their data’s security.

Patient information that may have been accessed by the hackers includes names, addresses, dates of birth, diagnosis codes, information on medical procedures, and treatment dates. For some patients, there is a chance that their Social Security number may also have been compromised.

The cyber-attack, which took place on July 13, caused a network outage at DMG. Third-party cyber-forensic specialists hired to investigate the security incident determined that unauthorized actors had gained access to the DMG network between July 12, 2021, and July 13, 2021, and that it was they who had caused the outage.

In a statement published Monday, DMG said: “With the assis­tance of the forensic specialists, DMG conducted a thorough and time-consuming review of its systems to under­stand whether any patient information may have been impacted as a result of this event. 

“On August 17, 2021, we determined that certain files stored within our environment that contained patient information may have been impacted by this incident.”

The group said that the exposed data did not include any financial account numbers and that the investigation found no evidence of data misuse following the attack. 

Since being targeted by hackers, DMG has implemented additional cybersecurity mea­sures and says it is reviewing existing security policies “to further protect against future inci­dents and improve our technol­ogy roadmap to better serve patients.”

DMG is offering free credit monitoring and identity theft protection to those individuals affected and potentially affected by this incident.

The group has also established a dedicated call center to field questions from concerned patients regarding the possible data breach. 

Patients are advised to remain vigilant against fraud and identity theft and to review their account statements, credit reports, and explanation of benefits forms for suspicious activity.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

UK Government Considers New Regulations for Video Streaming Platforms

UK Government Considers New Regulations for Video Streaming Platforms

The UK government is considering introducing new regulations for video-on-demand (VoD) services to protect users from harmful material such as misinformation.

The Department of Digital, Culture, Media and Sport (DCMS) has launched a consultation on the new provisions to level the regulatory playing field between mainstream VoD services and traditional broadcasters in the UK, like the BBC and Sky.

Currently, in the UK, video streaming services such as Netflix, Amazon Prime Video and Disney+ are not subject to Ofcom’s Broadcasting Code, which sets out standards for content, including harmful or offensive material, accuracy, fairness and privacy. This means that viewers of VoD content are much more likely to be exposed to harmful content, such as pseudoscience documentaries or misleading health advice.

The government’s plans have come amid a surge in popularity for on-demand services in recent years, exacerbated during the COVID-19 lockdowns. Ofcom data has shown that 75% of UK households have used a subscription VoD service as of this year.

The UK’s departure from the EU means that the government is free to go beyond minimum standards set out in the revised Audiovisual Media Services Directive. This legislation governs EU-wide coordination of national legislation on all audiovisual media.

As part of the consultation, the DCMS is asking whether UK audiences watching TV-like VoD programs would like a similar level of protection to when they are watching traditional TV. Additionally, it wants to ensure that any regulatory change is proportionate and does not curtail essential protections such as freedom of speech.

Culture Secretary Oliver Dowden commented: “We want to give UK audiences peace of mind that however they watch TV in the digital age, the shows they enjoy are held to the same high standards that British broadcasting is world-renowned for.

“It is right that now we have left the EU, we look at introducing proportionate new rules so that UK audiences are protected from harm.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

BEC Scammers Seek Native English Speakers on Underground

Cybercrooks are posting help-wanted ads on dark web forums, promising to do the technical work of compromising email accounts but looking for native English speakers to carry out the social-engineering part of these lucrative scams.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains