Drug Dealers Get 27 Years After Police Crack EncroChat Comms

Drug Dealers Get 27 Years After Police Crack EncroChat Comms

A drug dealer has been given a ten-year jail sentence after officers monitored his encrypted communications with other suppliers, according to the National Crime Agency (NCA).

Lee Broughton, 40 from Epsom, was sentenced last week at Kingston Crown Court after pleading guilty back in April to supplying cocaine.

His case was one of the many that the NCA is working on as part of Operation Venetic, after international law enforcers cracked a popular encrypted chat platform.

The agency revealed last year that it had been working on cracking EncroChat since 2015. The service is said to have had 60,000 users globally, 10,000 of whom were in the UK. It was reportedly used for trading drugs and other illegal goods, laundering money and planning hits on rivals.

The service offered users special devices, costing around €1000 each, and would charge €1500 for a six-month subscription offering worldwide coverage. Devices didn’t require users to associate a SIM card with their account and used a dual operating system with an encrypted interface.

Law enforcers have already arrested over 700 individuals in the UK due to their success in infiltrating EncroChat.

Broughton used the username “Sleekyak” to communicate with 22 contacts via the service — boasting he could sell 10 to 20kg of cocaine per week. He was apparently linked to the EncroChat moniker after revealing in one conversation the date of his birthday.

In related news, Michael Devine, 45, from Pete Best Drive in Derby, was this week sentenced to 17 years behind bars after using EncroChat to discuss sailing hundreds of kilograms of cocaine across the Atlantic.

According to reports, police were able to unmask Devine as the individual behind the “lawfularbor” and “mixedtree” accounts thanks to his references to family members, his poker playing, his car and Costco membership.

Police have scored several wins with other encrypted chat services used by criminals. They took down Sky ECC in March 2021 and, more recently, disrupted the notorious Anom service.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Cybercrime Losses Triple to £1.3bn in 1H 2021

Cybercrime Losses Triple to £1.3bn in 1H 2021

Individuals and organizations lost three times more money to cybercrime and fraud in the first half of the year compared to the same period in 2020, as incidents soared, according to new figures.

The data comes from the National Fraud Intelligence Bureau (NFIB), which collects reports of cybercrime and fraud from Action Fraud, the UK’s national reporting center for such crimes.

It revealed that between January 1 and July 31 2020, victims lost £414.7m to cybercrime and fraud. However, the figure surged to £1.3bn for the same period in 2021.

This can be partly explained by the huge increase in cases from last year to this. In the first half of 2020, there were just 39,160 reported to Action Fraud, versus 289,437 in the first six months of 2021.

In both periods, individuals comprised the vast majority of cases and the majority of losses. However, organizations lost 6.6 times more money in the first half of 2021 compared to 1H 2020, while individual victims lost 2.6 times more during the period.

Experts urged the government to do more to educate individuals about the dangers of phishing and the importance of cybersecurity best practices and argued that organizations should be more proactive in mitigating home working risks.

“The pandemic has opened up many opportunities for malicious hackers to intercept individuals, remote workers and businesses as we have been thrown out of our usual routines and away from the safety of corporate firewalls. For many businesses, the rush to move their products and services online, or into the cloud, has left the door open as cybersecurity took a back seat to business continuity,” explained Outpost24 CSO, Martin Jartelius.

“Across the country, millions of people have switched to work from home and remain digital-only for the past 18 months. This gives hackers the time to test out different attack techniques, learn what works — sometimes from other hacking groups — and evolve their tactics to achieve maximum return.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Tech CEOs to Discuss Cybersecurity with Biden Today

Tech CEOs to Discuss Cybersecurity with Biden Today

The CEOs of some of the world’s biggest tech companies are set to meet President Biden today to discuss how their products can improve the security of America’s businesses and critical infrastructure providers, according to a report.

Apple boss Tim Cook, Amazon CEO Andy Jassy and Microsoft supremo Satya Nadella are attending the meeting. At the same time, the CEOs of Google, IBM, JP Morgan Chase and utility firm Southern Co have also been invited, according to Bloomberg.

A senior official familiar with the event told the news site that part of the discussion would be focused on how software can enhance supply chain security.

It’s thought that critical infrastructure could also be a focus — particularly in light of the Colonial Pipeline ransomware attack in May, which led to surging fuel prices for days up and down the US East Coast.

Digital supply chain attacks are also increasingly commonplace, with the SolarWinds campaign highlighting the lengths state-backed threat actors are prepared to go to infiltrate US government organizations. Microsoft claimed shortly after that over 1000 Kremlin operatives had worked on the campaign.

The line between state-sponsored and financially motivated cybercrime attacks has become increasingly blurred over recent months. The Kaseya ransomware campaign appeared inspired in some part by SolarWinds, targeting an IT management software provider to hit thousands of downstream customers.

The Biden administration appears more determined to tackle these challenges than its predecessor, although, to an extent, they have become more acute over the past few months.

The President himself warned last month that if a “real shooting war” broke out with a major power, it could result from a significant cyber incident.

That follows tense negotiations with the Kremlin over Russia’s apparent harboring of cybercrime groups like those that hit Colonial Pipeline, Kaseya and meat processing giant JBS USA.

He is reported to have told President Putin that critical infrastructure providers should be considered off-limits.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Cyber-thieves Scam New Hampshire Town Out of $2.3m

Cyber-thieves Scam New Hampshire Town Out of $2.3m

A New Hampshire town is reeling from the “very shocking” cybercrime that claimed more than 14% of its annual budget.

Peterborough is a 7,000-person town with a budget for the fiscal year of just over $15.8m. Cyber-thieves conned the town out of $2.3m through two business email compromise (BEC) scams. 

First the criminals used forged documents and compromised email accounts to pose as staff at the local school district. This enabled them to divert a million-dollar transfer made to the district by the town into a bank account under their control. 

The theft came to light on July 26 when the ConVal School District notified the town that it had missed a $1.2m monthly payment.

On August 18 it emerged that cyber-thieves had stolen more money by posing as general contractor Beck and Bellucci, hired by the town to repair Main Street Bridge.

Town administrator Nicole MacStay and select board chair Tyler Ward said it was not yet clear whether any of the town’s losses would be covered by their insurance policy.

In a phone interview on Tuesday, MacStay said: “It’s very shocking to us to be quite honest. It’s just been very difficult to work through all this, and try to do the best we can to recover these funds … to mitigate the burden on our residents and taxpayers.”

An investigation into the thefts has been launched by the United States Secret Service. While the investigation is carried out, the town’s finance department staff have been placed on leave.

A press release issued by Ward and MacStay suggests that finance department staff were unwitting pawns in the thefts, which have been attributed to threat actors that appear to be based outside of the United States.

“Investigations into these forged email exchanges show that they originated overseas,” stated the release.

“These criminals were very sophisticated and took advantage of the transparent nature of public sector work to identify the most valuable transactions and focus their actions on diverting those transfers.” 

The town is reviewing its procedures regarding electronic financial transfers and has canceled all automated clearing house transfers.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Signs Cybersecurity Agreements with Singapore

US Signs Cybersecurity Agreements with Singapore

The United States and Singapore have agreed to cooperate on cybersecurity and climate change issues.

On August 23, Singapore’s prime minister, Lee Hsien Loong, announced that three cybersecurity agreements had been signed by the cyber, defense, and finance agencies of both countries. 

The announcement was made during a visit to Singapore by US vice president Kamala Harris. On Monday, Loong and Harris spent 90 minutes together in a meeting that Harris described as “productive.”

Speaking at a joint press conference on Tuesday, Harris said: “Today, we are in Singapore to stress and reaffirm our enduring relationship to this country and in this region, and to reinforce a shared vision of a free and open Indo-Pacific region, and to reaffirm our mutual interests in peace and stability in Southeast Asia.”

Loong said that the agreements would deepen collaboration between the two countries on critical technology, data security, the sharing of best practices, and infrastructure defense.

The first agreement is a bilateral Memorandum of Understanding (MOU) between the US Treasury and the Monetary Authority of Singapore that aims to help both financial sectors share information on cyber-threats to financial markets and be more prepared for and resilient to cyber-threats.

A second MOU was signed between the US Defense Department and the Singapore Ministry of Defense. The White House said the agreement “will support broad defense cooperation to advance cybersecurity information sharing, exchange of threat indicators, combined cyber training and exercises, and other forms of military-to-military cooperation on cyber issues.”

The US Cybersecurity and Infrastructure Security Agency (CISA) and the Cyber Security Agency of Singapore (CSA) signed the third MOU in a bid to improve the exchange of intelligence on cyber-threats and defensive measures, increase coordination for cyber-incident response, and enable cybersecurity capacity building across Southeast Asia.  

The two countries further agreed to start a new Climate Partnership oriented toward green solutions around goods, services and technology, and carbon credits. 

Harris began a three-day visit to Singapore on August 22 by meeting with Singapore’s president, Halimah Yacob. The meeting took place at the Istana, where a new orchid hybrid – the Papilionanda Kamala Harris – had been named in the vice president’s honor. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

FBI Issues Ransomware Group Flash Alert

FBI Issues Ransomware Group Flash Alert

The Federal Bureau of Investigation’s Cyber Division has issued a flash warning over an organized cyber-criminal gang calling itself OnePercent Group. 

In a TLP: WHITE alert published Monday, the FBI said the group has been targeting companies in the United States since November 2020. 

OnePercent’s modus operandi is to use the threat emulation software Cobalt Strike to perpetuate ransomware attacks. The infection process begins in the victim’s inbox.

“OnePercent Group actors compromised victims through a phishing email in which an attachment is opened by the user,” states the FBI warning. “The attachment’s macros infect the system with the IcedID banking trojan.”

The malicious attachment appears as a zip file containing a Microsoft Word or Excel document. Once activated, the banking trojan downloads extra software onto the victim’s computer, including Cobalt Strike, which the FBI said “moves laterally in the network, primarily with PowerShell removing.”

After accessing a victim’s computer, OnePercent encrypts their data and exfiltrates it from the network using rclone. A virtual ransom note is left that tells the victim they have one week from the date of infection to make contact with the ransomware group. 

“OnePercent Group actors’ extortion tactics always begin with a warning and progress from a partial leak of data to a full leak of all the victim’s exfiltrated data,” warned the FBI.

If no contact is made, the group contacts the victim via a ProtonMail email address or over the phone using spoofed phone numbers. Victims are told that a small portion of their data will be leaked through The Onion Router (TOR) network and clearnet, unless a ransom payment is made. 

Should a victim refuse to pay up after this initial “one percent leak,” the ransomware group threatens to sell their data to the ransomware gang Sodinokibi  (REvil) to publish at an auction. 

The FBI said that OnePercent Group threat actors have been spotted entering a victim’s network around a month before ransomware is deployed. 

US companies are urged by the FBI to back-up their critical data offline and use multi-factor authentication with strong passphrases to protect themselves from ransomware attacks. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Time to Fix High Severity Apps Increases by Ten Days

Time to Fix High Severity Apps Increases by Ten Days

The average time taken to fix high severity application security flaws has increased by ten days in just a month, according to the latest data from NTT Application Security.

The security vendor’s AppSec Stats Flash report for August offers a broad view of the current state of application security across various verticals.

Most important is the data that details how quickly or otherwise organizations are at closing the window of exposure (WoE) between a patch becoming available and one being applied.

Although it found the “time to fix” had dropped overall by two days, from 202 days to 200 days, for high severity vulnerabilities, it increased from 246 days last month to 256 days in this month’s analysis.

The report found that utilities and retail firms, in particular, were performing poorly.

“Applications in the utility space continue to suffer from high window of exposure, with 67% of applications having at least one serious exploitable vulnerability throughout the year,” it noted.

“Retail Trade saw an increase of three base points in its WoE — from 58% last time to 61% this time. As we get closer to the final quarter of the year, there will be an expected increase in the transactions and activity on retail web and mobile applications. As such, applications in this sector are going to be rich targets for exploits.”

The most vulnerable sector was once again the “Management of Companies and Enterprises” vertical.

NTT Application Security warned that vulnerable applications are an increasingly dangerous vector for embedding ransomware and enabling supply chain attacks.

The top five vulnerability types by volume were HTTP response splitting, query language injection, cross-site scripting (XSS), cross-site request forgery and remote file inclusion.

These remain unchanged from previous months, indicating a “systemic failure” to address well-known security issues and making the task of threat actors even easier, the vendor claimed.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains