Over a Third of Organizations Damaged by Ransomware or Breach

Over a Third of Organizations Damaged by Ransomware or Breach

Over one-third of organizations worldwide have experienced a ransomware attack or breach that blocked access to systems or data in the previous 12 months, according to new research.

In a survey conducted by the International Data Corporation (IDC), it was found that many organizations that fell victim to ransomware experienced multiple ransomware events. In the US, the incident rate was notably lower (7%) compared to the worldwide rate of 37%.

“Ransomware has become the enemy of the day; the threat that was first feared on Pennsylvania Avenue and subsequently detested on Wall Street is now the topic of conversation on Main Street,” commented Frank Dickson, program vice president, cybersecurity products, IDC. “As the greed of cyber miscreants has been fed, ransomware has evolved in sophistication, moving laterally, elevating privileges, actively evading detection, exfiltrating data and leveraging multifaceted extortion. Welcome to digital transformation’s dark side.”

The research, entitled IDC’s 2021 Ransomware Study: Where You Are Matters!, showed that the manufacturing and finance industries reported the highest ransomware incident rates. The transportation, communication and utilities and media industries reported the lowest.

When it came to paying the piper, only 13% of organizations said that they had experienced a ransomware attack and not paid the ransom. For those that did, the average ransom payment was almost $250,000, with a few large ransom payments of over $1m.

In the report shared the responses of nearly 800 IT decision makers and influencers. The July 2021 survey focused on topics such as attention by the board of directors, ransomware payments, size of ransomware, number of ransomware payments and the exfiltration of data. 

Based on the responses, IDC found that companies who were further along in the digital transformation journey were less likely to have experienced a ransomware attack.

Joseph Carson, chief security scientist and advisory chief information security officer at ThycoticCentrify, believes that traditional cybersecurity solutions have failed to prevent ransomware from infecting organizations and creating mass disruption: “Conventional, signature-based antivirus programs are unable to prevent and detect these types of attacks due to the unique and quickly growing variants of ransomware.

“Encrypting your data doesn’t necessarily deter ransomware attacks either,” he continued. “Attackers may still threaten to publicly disclose that data, expecting that others are willing to pay for the opportunity to break the encryption.”

The research comes after Accenture, the global consulting firm, was the victim of a ransomware attack known as Lockbit 2.0. The Australian Cyber Security Centre (ACSC) also alerted organizations in the country that cyber-criminals were frequently using Lockbit 2.0 ransomware.

“The ACSC has received reporting from several Australian organizations that have been impacted by LockBit 2.0 ransomware,” said the alert. “This activity has occurred across multiple industry sectors.”

Oliver Tavakoli, CTO at Vectra, a San Jose, Calif.-based AI cybersecurity company, explained that while company culture of educating employees is helpful in preventing ransomware, it will “only get you so far.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Sporting Fans Heavily Targeted by Bad Bots This Summer

Sporting Fans Heavily Targeted by Bad Bots This Summer

Bad bot activity rose on sporting and betting sites during sporting events such as Tour De France, EURO 2020 and the Tokyo Olympics.

Imperva Research Labs has revealed that punters were left at risk of account takeover (ATO) attacks, leaving their digital wallets vulnerable to exploitation. Alarmingly, during the Tokyo Olympics, the company saw a spike in search engine impersonators during the first week and by week two, it grew by 103% above average.

“Bad bots typically masquerade as legitimate users to remain undetected,” explained Imperva researchers in a blog post. “Incoming traffic to sporting sites saw an unusual 48% increase in Yahoo impersonators, 66% increase in Baidu impersonators and 88% increase in Google impersonators.

“Imperva Research Labs also found ATO attacks grew 43% the week prior to the start of the Olympic Games, and spiked 74% during the first week of competition.”

In the run up to the EURO 2020 football tournament, the organization monitored a 96% year-on-year increase in bot traffic on global sporting sites. ATO attacks also spiked by two or three times the daily average on the days when England played.

Imperva also monitored a pattern of attacks getting larger as the tournament progressed with a notable peak occurring at the start of the Round of 16 teams. 

A similar trend was spotted at the beginning of the Tour De France—bot activity on sporting and gambling sites spiked 52% as the race was scheduled to begin.

“Bot comment spammers were pervasive, with traffic increasing 62%,” the blog post stated. “The spammers took advantage of the interest in the event to post comments in Russian about an array of topics including: adult sites, crypto, coupons/discounts, casino sites and loans and investment opportunities.”

ATO attacks are a type of fraud where cyber-criminals use a botnet to gain illegal access to accounts that belong to other users. According to Imperva, this is usually achieved through brute force login techniques such as credential stuffing, credential cracking or a dictionary attack.

“Gambling sites are a lucrative target for account takeover attacks because user profiles often have financial information or even funds stored,” explained the blog post. “A successful account takeover can result in financial fraud, theft of personal data or sensitive business information.”

According to the Imperva Bad Bot Report 2021, websites face an ATO attack 16% of the time. The report also found that one third of all login attempts in 2020 were malicious. With the English Premier League and other elite football leagues in Europe set to begin playing matches and the Beijing 2022 Winter Olympics and football World Cup in Qatar on the horizon, the organization is concerned that the threat of bad bots targeting fans during these global sporting events is likely to grow.

“The bad bot problem is increasingly complex as automated web activity accounted for more than a quarter of all web traffic in 2020,” Imperva added in its blog post. “This trend is likely to grow as fans spend more time online searching for scores, placing bets and engaging in sport community forums. To mitigate automated threats across web, mobile and APIs, companies must take proactive steps to keep their users’ data secure.”

The organization advises that sporting and betting sites should block or CAPTCHA outdated user agents and browsers, block known hosting providers and proxy services, monitor for failed login attempts and evaluate a bot protection solution such as web application and API protection (WAAP). 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Hacker Partially Returns Money Stolen in Cryptocurrency Heist

Hacker Partially Returns Money Stolen in Cryptocurrency Heist

The hacker behind the largest-ever cryptocurrency theft ever recorded has paid back nearly half ($260m) of the money to the victim organization, Poly Network.

Earlier this week, it was reported that hackers exploited a vulnerability in Poly Network, a company that implements interoperability between different blockchains, that enabled them to change the address of the “keeper role” of a blockchain contract and “construct any transaction at will and withdraw any amount of funds from the contract.”

This enabled the hacker to transfer $610m to three different addresses.

Following the incident, Poly Network took to Twitter to urge the attackers to return the money, stating: “We want to establish communication with you and urge you to return the hacked assets. The amount of money you hacked is the biggest one in defi history. Law enforcement in any country will regard this as a major economic crime and you will be pursued. It is very unwise for you to do any further transactions. The money you stole are from tens of thousands of crypto currency members, hence the people.

“You should talk to us to work out a solution.”

The hacker subsequently posted a three-page ‘Q&A’ in which they provided more details on how they carried out the heist and claimed to have ethical motives, stating it was “always the plan” to return the funds and that they “not very interested in money.” The hacker added: “I know it hurts when people are attacked, but shouldn’t they learn something from those hacks?”

Poly Network has since revealed that $260m of “assets” have been returned via three types of cryptocurrencies: $3.3m worth of Ethereum, $256m worth of Binance Coin and $1m worth of Polygon. However, $269m worth of Ethereum and $84m worth of Polygon are still not recovered.

Commenting on the story, Arseny Reutov, head of the application security research team at Positive Technologies, said: “When such a massive hack occurs, everyone’s attention is fixed on a particular cryptocurrency address. Although DeFi is non-custodial, some protocols can blacklist any address, for example, USDT stablecoin, which blacklisted the attacker’s address preventing him or her from moving the funds. 

“Withdrawing such a large amount of money is a challenge in cryptocurrency. Although there are some cryptocurrency mixers that can complicate the tracking of the funds, it appears the hacker quickly realized he or she didn’t  have a plan for this, which likely led to the decision to transfer the stolen funds back.”

Speaking to Infosecurity, BitK, technical ambassador at crowdsourced bug bounty platform YesWeHack, provided more insights into the possible motives of the hacker: “Incidents in which a hacker steals money, or cryptocurrency in this instance, and then returns what they stole is not something you see every day. It’s clear the hacker intentionally targeted Poly Network and found a bug to exploit to their advantage. Whether they did this as a publicity stunt or to make a huge fortune is up for debate. There is no real way of knowing whether the intention was always to return the funds or if legal threats pressured them into doing so.  

“For businesses looking to avoid falling into the same predicament as Poly Network, one strong preventive method would be to work with ethical hackers in the context of a bug bounty program. This enables companies to identify flaws in advance, and thus prevent a malicious hacker from finding and exploiting them. However, in cases such as this which involve large sums of money or cryptocurrency, the bounty offered by the organization would have to be substantial enough to encourage the best hackers to participate and deter them from illegally taking the jackpot.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Amazon’s Plan to Track Worker Keystrokes: A Sign of Controls to Come?

Data theft, insider threats and imposters accessing sensitive customer data have apparently gotten so bad inside Amazon, the company is considering rolling out keyboard-stroke monitoring for its customer-service reps. A confidential memo from inside Amazon explained that customer service credential abuse and data theft was on the rise, according to Motherboard which reviewed the document. […]

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Chanel Apologizes for Data Breach

Chanel Apologizes for Data Breach

The Korean arm of French luxury brand Chanel has issued an apology after personal data belonging to its customers was exposed.

In a statement issued earlier this week, Chanel Korea blamed the data leak that happened on August 8 on a recent cyber-attack. A database belonging to the famed perfume and fashion brand is believed to have been compromised by a hacker or hackers at some point between August 5 and 6. 

Data exfiltrated in the attack and later leaked included some customers’ names, birth dates, gender, phone numbers, and shopping history.

The Korea Herald reported that other sensitive information contained in the compromised database, including customers’ IDs, passwords, and payment information, had not been leaked. 

“Parts of our database, containing the personal information of the customers who had registered for our cosmetics brand membership, have been compromised. The leaked personal information included names, birthdays, phone numbers and product purchase lists,” Chanel Korea wrote on its official website. 

The company asked customers who suspect that their data has been misused to make contact by phone or email.

“We sincerely apologize to our customers for the matter and the inconvenience it caused,” stated Chanel Korea.

The company went on to say that it has hired “a leading independent cybersecurity firm” to investigate the attack and gauge its full impact. 

Chanel Korea said that it had not found any “evidence of further impact on other systems and data” but had reported the incident to the Korea Internet & Security Agency (KISA). The matter is also under investigation by Korea’s Personal Information Protection Commission (PIPC).

Customers are reportedly being informed of the cyber-attack and data breach via email and text messages. Chanel Korea has not published details on how many individuals were impacted by the security incidents. 

One Chanel Korea customer told the Korea Times that the brand ought to do more than just apologize to its customers.

They said: “When we think of Chanel, we expect the best-quality products and high-level service. That is why we spend thousands of dollars at their boutiques. Chanel Korea should compensate its customers who were affected by the cyber-attack.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Friday Squid Blogging: A Good Year for Squid?

Improved ocean conditions are leading to optimism about this year’s squid catch.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Read my blog posting guidelines here.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains