News

US Issues Alert Over Russian Hackers

US Issues Alert Over Russian Hackers

The FBI, CISA, and the NSA have warned those in charge of the United States’ critical infrastructure network to prepare themselves against cyber-attacks originating in Russia.

In a joint advisory issued January 11, the three agencies provided an overview of Russian state-sponsored cyber-operations; commonly observed tactics, techniques, and procedures (TTPs); detection actions; incident response guidance; and mitigations. 

The agencies shared attack vectors that have been favored by Russian-based cyber-criminals in the past and urged the cybersecurity community to “adopt a heightened state of awareness and to conduct proactive threat hunting.”

Tactics cited in the advisory include spear phishing, brute force, exploiting known vulnerabilities, compromising third-party software, and developing and deploying custom malware.

“Russian state-sponsored APT actors have used sophisticated cyber-capabilities to target a variety of US and international critical infrastructure organizations, including those in the Defense Industrial Base as well as the Healthcare and Public Health, Energy, Telecommunications, and Government Facilities Sectors,” the joint advisory reads.

The warning came as no surprise to Vectra CTO and technical director Tim Wade. 

He told Infosecurity Magazine: “I can’t recall a time in my life when Russia wasn’t aggressively probing Western resolve, ranging from tactical incursions into air space to pulling strategic economic levers.

“This activity is just a continuation of that longstanding tradition, and I read this advisory as another periodic reminder of the background radiation of global politics – if you’re operating critical infrastructure and are under the impression that you aren’t squarely in an operator’s crosshairs, you’re wrong.”

John Bambenek, principal threat hunter at Netenrich, was similarly insouciant about the latest cybersecurity alert to be issued by the Biden administration.

“Advisories like this do little to help defenders actually protect themselves,” he said. “I read this and don’t have any more insight into detecting and preventing these attacks than before.”

Bambenek called for the NSA, FBI, and CISA to take a different and more direct approach to help America’s critical infrastructure defend against cyber-threats.

“It’s 2022,” he said. “These agencies hopefully can reach directly out to organizations with more-specific guidance, because public announcements aren’t helpful and there are reasons not to be too specific in them as well.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

World Economic Forum: Cybersecurity an Increasing Global Threat

World Economic Forum: Cybersecurity an Increasing Global Threat

Cybersecurity was once again identified as a major short and medium-term threat to the world in this year’s World Economic Forum’s (WEF’s) The Global Risk Report. The analysis was based on insights from nearly 1000 global experts and leaders who responded to the WEF’s Global Risks Perception Survey (GRPS).

Perhaps unsurprisingly, environmental issues like climate action failure and extreme weather ranked highest on the risks facing the world over the short (0-2 years), medium (2-5 years) and long-term (5-10 years). In addition, a number of challenges exacerbated by the pandemic, such as livelihood crises, infectious diseases and mental health deterioration, also scored highly. Overall, this added up to a pessimistic assessment, with 84.2% of respondents stating they were either “worried” or “concerned” about the global outlook.

Digital challenges, such as “cybersecurity failures,” were also viewed as a significant and growing problem to the world. Nearly one in five (19.5%) respondents believe cybersecurity failures will be a critical threat to the world in just the next 0-2 years, and 14.6% said it would be in 2-5 years.

Interestingly, cybersecurity failures didn’t score as highly as a long-term risk. Reflecting on this, the report stated: “This suggests lower relevance to respondents – or a blind spot in perceptions given the potential damage of cyber-risks – compared to economic, societal and environmental concerns.”

Cybersecurity failures also ranked seventh (12.4%) in the risks that have worsened since the start of COVID-19, reflecting how increased reliance on digital technologies has created more opportunities for cyber-threat actors to strike.  

During a WEF press conference launching the report, Carolina Klint, risk management leader, Continental Europe, of Marsh, highlighted cybersecurity as a particularly grave business threat. She noted that the intensification of attacks over recent years means “that cyber-threats are now growing faster than our ability to prevent and manage them effectively.”

The pandemic has offered new opportunities for cyber-criminals to strike, with businesses forced to digitize and adopt new automation technologies rapidly. “Too often this has been built on the back of aging technology, which has led to supply chain disruption and greater exposure to cyber-attacks,” added Klint.

She also noted that the financial costs of cyber-attacks, such as ransomware, have surged in recent years. For example, the report cited data showing a four-fold rise in the total cryptocurrency value received by ransomware addresses last year, reaching $406.34m. In addition, Klint observed that “in 2021, we saw the highest average cost of a data breach in almost two decades.”

Overall, Klint identified four main cyber-risks that need to be tackled over the coming years. These are critical infrastructure failures, an increasingly aggressive regulatory environment, unprecedented identity theft and the failure to execute digital transformation effectively. She warned: “Companies soon won’t be able to claim good ESG credentials without addressing these key areas.”

To address these cyber challenges and more, companies must enhance their resiliency, “which is a journey, not a destination.” These efforts must not only focus on their own internal assets, “but also the vulnerabilities of those in their supply chain.”

In the GRPS survey, the respondents had a dim view of current cyber-threat mitigation efforts. Close to three-quarters (73%) said international risk mitigation efforts in the area of cross-border cyber-attacks and misinformation had either not started or are in early development. The Global Risk Report warned of severe consequences if international cooperation in this area is not improved. This includes the potential for open cyber warfare as governments continue to retaliate against perpetrators and growing “mistrust between societies, business and government.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Banks Still Struggling to Spot the Signs of Human Trafficking

Banks Still Struggling to Spot the Signs of Human Trafficking

Financial institutions are struggling to spot the tell-tale signs of human trafficking due to resource constraints and the nature of the anti-money laundering (AML) compliance environment, according to experts.

Today marks National Human Trafficking Awareness Day in the US. Also known as “modern slavery,” it refers to a range of heinous crimes, including forced begging, debt bondage, domestic servitude and sex trafficking.

The most recent stats from the International Labour Organization (ILO) claim over 40 million people around the world are currently trapped in modern slavery. According to the UN, the share of children among these victims has tripled over the past 15 years, while the share of boys has increased five-fold.

Banks should play an important part in the fight to detect such activities by spotting suspect money flows, according to Nicola Eschenburg, FinCrime Testing Service venture lead at BAE Systems Applied Intelligence.

“Virtually all crime is conducted for profit, and that profit can’t be recognized if the money can’t be laundered and spent,” she told Infosecurity.

However, the nuances of human trafficking activity can often be missed by compliance staff, as they can appear innocent to the untrained eye.

“For example: a young woman staying in multiple low-cost hotels around the country, mostly eating late at night at fast food joints and visiting pharmacies several times a week. That’s indicative of sexual trafficking, but you need a number of the elements plus some profiling to be able to draw the bigger picture,” Eschenburg explained.

Part of the challenge is compounded by the nature of AML compliance. There are 22 “predicate offenses” outlined by the EU linked to money laundering, of which human trafficking is just one.

Compliance staffers must monitor all of them, each of which has multiple typologies or behaviors associated with them.

“This means that most teams by nature have to have generalists rather than specialists in certain types of crime, which in turn means subtle nuances or indicators can get missed,” argued Eschenburg.

“Compounding this is the sheer volume of activity that needs to be monitored and analyzed – it becomes a bit of a treadmill of working through alerts which doesn’t leave much if any free time for conducting open-source research, speaking to law enforcement about what criminal behaviors look like on the front line, reading court transcripts and honing and refining detection techniques as the output.”

BAE’s AML report out earlier this year claimed that 76% of compliance officers believe AML compliance has become little more than a box-ticking exercise, and 62% said criminal activity is getting harder to spot. Half (50%) of money laundering goes undetected, it estimated.

Brian Ferro, director of AML at Feedzai, told Infosecurity that better technology is only one part of the solution and that stronger public-private partnerships were essential.

“To date, there hasn’t been a lot of collaboration between regulators, banks and law enforcement to put together best practices and updates to regulations. One of the biggest complaints from the banks is the lack of feedback when filing regulatory reports with law enforcement. While the information provided to law enforcement could aid in an ongoing investigation, completing their investigation could take several months if not years. So while not compromising their ongoing investigations, there needs to be regular feedback from law enforcement agencies to the banks so that the bank investigators know what information or activity is useful, new or emerging trends and what to look for in their own work,” he explained.

“On the regulatory side, the information from law enforcement could benefit banks in looking for new types of criminal activities. However, banks are hesitant to change their surveillance policies for fear of being penalized by the same regulators for not identifying previously unknown patterns of suspicious behavior. There has to be a partnership with regulators to encourage the use of new technologies, and at the same time allows the banks to build better detection models without fear of repercussions.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Corporate Cyber-Attacks Spike 50% in 2021

Corporate Cyber-Attacks Spike 50% in 2021

Global weekly cyber-attacks hit an all-time high in Q4 2021 of 925 attempts per organization, according to new data from Check Point.

The security vendor analyzed information collected by hundreds of millions of global sensors from its Threat Prevention products across networks, endpoints and mobiles.

It claimed attempted attacks have been continuously increasing since Q2 2020, with 50% more attacks seen per week on corporate networks in 2021 compared to 2020.

The education and research sector experienced the highest volume of attacks during 2021, amounting to an average of 1605 per organization every week, a 75% increase on 2020.

It was followed by government/military with 1136 attacks, up 47% year-on-year, and communications with 1079, up 51%.

Africa experienced the highest volume of weekly attacks in 2021, with an average of 1582 per organization, a 13% increase from 2020. However, European organizations experienced the most significant increase in weekly attacks, up 68% to 670, according to the report.

Ransomware was particularly prevalent over 2021. Check Point warned last October that attacks had spiked 40% since 2020, with one out of every 61 organizations worldwide impacted each week.

Check Point urged firms to segment their networks, patch promptly, educate their employees and layer up advanced security controls like sandboxing and anomaly detection.

Hank Schless, senior manager of security solutions at Lookout, argued that the persistent impact of the pandemic might explain some of the 2021 findings.

“Attackers almost always go after groups that they perceive to be most vulnerable in order to have the greatest chance of success. The idea of e-learning was in very early stages when the pandemic hit, so for entire school systems, universities, research centers and more to have to flip their continued collaboration and education to fully remote infrastructure overnight was beyond difficult,” he added.

“Before, there may have been some basic cloud-based apps or infrastructure in place that enabled teachers and staff to collaborate or for students to turn in work, but the capacity and security was not ready to take on the complexity of remote learning at the drop of a hat.”

Jasmine Henry, field security director at JupiterOne, warned that the discovery of more bugs like Log4Shell could make 2022 another record year for attackers.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Romance Scammers Stole £92m From Victims Last Year

Romance Scammers Stole £92m From Victims Last Year

UK police have warned that the period between Christmas Day and Valentine’s Day is the most dangerous for users of dating sites as scammers are out in force.

Many fraudsters seek to establish contact and build a rapport with their victims during this time, leading to a spike in reports of romance scams and financial loss in the weeks and months after, said Action Fraud.

Those losses soared from £8.7m last March to £14.6m in May as a result, according to figures from the National Fraud Intelligence Bureau (NFIB).

Total financial losses from romance fraud over the year (November 2020 to October 2021) stood at a staggering £92m. That’s based on 8,863 cases that were reported to the NFIB, up from 6,968 in the 2020 calendar year.

However, this is likely to be an under-estimate since many victims feel too ashamed to get the police involved.

A plurality of victims (20%) over the reporting period were aged 50-59, and half were wome. Two-fifths (39%) were men, and 11% did not record their gender.

Police are asking relatives of online daters to protect family members from being scammed by flagging the warning signs.

“Typically, romance fraudsters will spend weeks gaining their victims’ trust, feeding them fabricated stories about who they are and their lives – and initially make no suggestion of any desire to ask for any money, so the victim may believe their new love interest is genuine,” explained detective chief superintendent Matt Bradford, from the City of London Police.

“But weeks, or sometimes months later, these criminals will ask for money for a variety of emotive reasons, and as the emotional relationship has already been formed, victims often transfer money without a second thought.”

Typical excuses designed to elicit money include paying for travel to visit the victim, emergency medical expenses, or investment opportunities.

Some scammers might also try to trick their victims into opening bank accounts in their name, making them unwitting money mules.

“It is essential users educate themselves on how to be a smart online dater, and to be aware of the actions fraudsters will use to manipulate them. Daters should check in with trusted family and friends during their online dating journey to share experience, and friends and family can watch for any change in behavior,” argued Hannah Shimko, policy director at the Online Dating Association.

“Other healthy online dating advice includes staying on the dating platform which has processes in place to protect users; getting to know the person, not just the profile; and never disclosing personal information until the dater is ready. Finally, remember to never send money to someone met only online.”

Romance scams were the second highest-grossing cybercrime type reported to the FBI in 2020, accounting for over $600m in losses.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains