News

Meta Sues to Disrupt Prolific Phishing Campaign

Meta Sues to Disrupt Prolific Phishing Campaign

Facebook’s parent company is taking legal action again in a bid to tackle the scourge of phishing – in particular, a campaign abusing its own brands.

Meta said it filed in a Californian court yesterday against those behind a phishing effort that involved the creation of more than 39,000 websites impersonating the login pages of Facebook, Messenger, Instagram and WhatsApp.

Users drawn to those phishing sites were then tricked into entering their usernames and passwords.

“As part of the attacks, defendants used a relay service to redirect internet traffic to the phishing websites in a way that obscured their attack infrastructure. This enabled them to conceal the true location of the phishing websites, and the identities of their online hosting providers and the defendants,” explained Meta’s director of platform enforcement and litigation, Jessica Romero.

“Starting in March 2021, when the volume of these attacks increased, we worked with the relay service to suspend thousands of URLs to the phishing websites.”

She added that the action was being taken “to uncover the identities of the people behind the attack and stop their harmful conduct.”

Meta has become increasingly willing to launch legal action against adversaries in a bid to disrupt and raise the potential cost of attacking its brands.

In 2019, WhatsApp launched a case against Israeli spyware-maker NSO Group after reports that its software had illegally targeted around 1000 users of the popular messaging service.

Then in January this year, it took two developers to court for violating its terms of service by scraping user data.

“This lawsuit is one more step in our ongoing efforts to protect people’s safety and privacy, send a clear message to those trying to abuse our platform, and increase accountability of those who abuse technology,” Romero concluded.

“We will also continue to collaborate with online hosting and service providers to identify and disrupt phishing attacks as they occur. We proactively block and report instances of abuse to the hosting and security community, domain name registrars, privacy/proxy services, and others. And Meta blocks and shares phishing URLs so other platforms can also block them.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

UK Cyber Cops Share 225 Million Passwords with Breach Site

UK Cyber Cops Share 225 Million Passwords with Breach Site

UK cyber investigators have handed over 225 million stolen passwords to a popular data breach checking website, significantly expanding its reach.

HaveIBeenPwned allows users to easily check if their email, phone number or password has been involved in a breach, enabling them to take action accordingly.

However, the service is only as useful as the volume of compromised information stored in its databases.

That’s why founder Troy Hunt is particularly grateful to the National Crime Agency (NCA) for the new addition, which amounts to roughly a third of the 613 million credentials already stored in the site’s Pwned Passwords service.

The full set handed over by the NCA was nearly 586 million but ­­reduced in size once already known passwords were stripped out.

“During recent NCA operational activity, the National Cyber Crime Unit’s Mitigation@Scale team were able to identify a huge amount of potentially compromised credentials (emails and associated passwords) in a compromised cloud storage facility. Through analysis, it became clear that these credentials were an accumulation of breached datasets known and unknown,” explained an NCA statemement.

“The fact that they had been placed on a UK business’s cloud storage facility by unknown criminal actors meant the credentials now existed in the public domain, and could be accessed by other third parties to commit further fraud or cyber-offenses.”

The NCA said that because the credentials were not attributable to a single platform or company, it decided sharing with Hunt would be the best option so individuals and companies globally could benefit.

The news comes as Hunt announced a new “ingestion pipeline,” which will enable law enforcement agencies like the FBI to continuously feed any newly discovered breached credentials into the service.

“The premise is simple: during the course of their investigations, they come across a lot of compromised passwords and if they were able to continuously feed those into HIBP, all the other services out there using Pwned Passwords would be able to better protect their customers from account takeover attacks,” said Hunt.

“If you’re using the Pwned Passwords API to check passwords, you’re already benefiting; every new password added to the service will automatically be checked each time you call that API. Further, passwords already in the service are having their prevalence value updated to ensure you know just how bad those passwords really are.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

British Council Struck by Two Ransomware Attacks in Five Years

British Council Struck by Two Ransomware Attacks in Five Years

A major UK public body has fallen victim to two successful ransomware attacks over the past five years, official figures have shown.

The data, obtained from a freedom of information (FoI) request by the Parliament Street think tank, revealed that the British Council suffered a total of 12 days of downtime due to the incidents; five days in the first and seven in the second. No ransom was paid in either incident.

The British Council is a non-departmental public organization that aims to connect people in the UK and other countries through culture, education and the English language. The official data also revealed that the body experienced a further six unsuccessful ransomware attacks over the five years. In these cases, either the ransomware was detected and blocked, or the malware was not deployed on the endpoint.

There have been numerous ransomware incidents impacting UK public bodies in recent years. These include damaging attacks on Redcar & Cleveland Borough Council and Hackney Council in 2020. This weekend, it was reported that the notorious Clop ransomware gang published confidential data held by UK police on the dark web following an attack on an IT service provider.

Last week, the UK government published a new wide-ranging national cyber strategy, which included plans to increase funding in public sector cybersecurity.

Commenting on the figures, Edward Blake, area vice president EMEA for Absolute Software, said: “Every organization is vulnerable to ransomware attacks. A large portion of time and resources are spent trying to prevent them, but it is a matter of when they happen, not if they happen, and it is on organizations and businesses to put in place effective cybersecurity measures to deal with ransomware attacks when, not if, they occur.

“Zero trust protocols are one of the most effective methods to preventing bad actors, which may already have access to a system, from infecting other aspects of the network or moving laterally through a system to seize even more data. What’s more, maintaining a healthy network through effective cybersecurity measures is paramount to protecting organizations against cyber-criminals – self-healing capabilities are the perfect solution to ensuring that applications remain healthy without compromising on performance or productivity.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Scam Phishing Network Costs Victims $80m Per Month

Scam Phishing Network Costs Victims $80m Per Month

Researchers have uncovered a sophisticated phishing campaign estimated to cost millions of global victims around $80m per month.

Security vendor Group-IB claimed the campaign targets users in over 90 countries, including the US, Canada, South Korea and Italy. It offers fake surveys and giveaways from popular brands, designed to steal their personal and financial data.

The firm said that a single network targets around 10 million victims and 120 brands.

“Fraudsters trap their victims by distributing invitations to partake in survey, after which the user would allegedly get a prize. Each such offer contains a link leading to the survey website. For ‘lead generation,’ the threat actors use all possible legitimate digital marketing means: contextual advertising, advertising on legal and completely rogue sites, SMS, mailouts, and pop-up notifications,” Group-IB explained.

“To build trust with their victims, scammers register look-alike domain names to the official ones. Less frequently, they were also seen adding links to the calendar and posts on social networks. After clicking the targeted link, a user gets in the so-called traffic cloaking, which enables cyber-criminals to display different content to different users, based on certain user parameters.”

While the victim is being redirected to this ’branded survey,’ information about their session is recorded and used to customize a final malicious link that can only be opened once – complicating efforts to detect and take down the scam.

“At the final stage, the user is asked to answer questions to receive a prize from a well-known brand and to fill out a form asking for their personal data, which is allegedly needed to receive the prize,” Group-IB noted.

“The data required usually includes the full name, email, postal address, phone number, bank card data, including expiration date and CVV.”

The vendor’s head of digital risk protection in Europe, Dmitriy Tiunkin, described the current landscape as a “scamdemic.”

The firm found 60 different networks operating similar targeted links, each containing over 70 domain names.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

How to protect yourself from identity theft after a data breach

How does that information get collected in the first place? We share personal information with companies for multiple reasons simply by going about our day—to pay for takeout at our favorite restaurant, to check into a hotel, or to collect rewards at the local coffee shop. Of course, we use our credit and debit cards too, sometimes as part of an online account that tracks our purchase history. 

In other words, we leave trails of data practically wherever we go these days, and that data is of high value to hackers. Thus, all those breaches we read about. 

Data breaches are a (sad) fact of life 

Whether it’s a major breach that exposes millions of records or one of many other smaller-scale breaches like the thousands that have struck healthcare providers, each one serves as a reminder that data breaches happen regularly and that we could find ourselves affected. Depending on the breach and the kind of information you’ve shared with the business or organization in question, information stolen in a breach could include: 

  • Usernames and passwords 
  • Email addresses 
  • Phone numbers and home addresses 
  • Contact information for friends and family members 
  • Birthdays and Driver’s license numbers 
  • Credit and debit card numbers or bank account details 
  • Purchase history and account activity 
  • Social security numbers 

What do crooks do with that data? Several things. Apart from using it themselves, they may sell that data to other criminals. Either way, this can lead to illicit use of credit and debit cards, draining of bank accounts, claiming tax refunds or medical expenses in the names of the victims, or, in extreme cases, assuming the identity of others altogether.  

Examples of data breaches over the recent years 

In all, data is a kind of currency in of itself because it has the potential to unlock several aspects of victim’s life, each with its own monetary value. It’s no wonder that big breaches like these have made the news over the years, with some of the notables including: 

Facebook – 2019: Two sets of data exposed the records of more than 530 million users, including phone numbers, account names, and Facebook IDs. 

Marriott International (Starwood) – 2018: Half a million guests had names, email and physical mailing addresses, phone numbers, passport numbers, Starwood Preferred Guest account information, dates of birth, and other information about their stays exposed. 

Equifax – 2017: Some 147 million records that included names, addresses, dates of birth, driver’s license numbers, and Social Security Numbers were exposed, along with a relatively small subset of 200,000 victims having their credit card information exposed as well. 

As mentioned, these are big breaches with big companies that we likely more than recognize. Yet smaller and mid-sized businesses are targets as well, with some 43% of data breaches involving companies of that size. Likewise, restaurants and retailers have seen their Point-of-Sale (POS) terminals compromised, right on down to neighborhood restaurants. 

Staying secure in light of data breaches 

When a company experiences a data breach, customers need to realize that this could impact their online safety. If your favorite coffee shop’s customer database gets leaked, there’s a chance that your personal or financial information was exposed. However, this doesn’t mean that your online safety is doomed. If you think you were affected by a breach, there are multiple steps you can take to help protect yourself from the potential side effects.  

1. Keep an eye on your bank and credit card accounts 

One of the most effective ways to determine whether someone is fraudulently using one or more of your accounts is to check your statements. If you see any charges that you did not make, report them to your bank or credit card company immediately. They have processes in place to handle fraud. While you’re with them, see if they offer alerts for strange purchases, transactions, or withdrawals. 

2. If you’re a victim, report it to local authorities and to the FTC for assistance.  

File a police report and a Federal Trade Commission (FTC) Identity Theft Report. This will help in case someone uses your Social Security number to commit fraud, since it will provide a legal record of the theft. The FTC can also assist by guiding you through the identity theft recovery process as well. Their site offers a step-by-step recovery plan that you can follow and track your progress as you go. 

3. Place a fraud alert 

If you suspect that your data might have been compromised, place a fraud alert on your credit. This not only ensures that any new or recent requests undergo scrutiny, but also allows you to have extra copies of your credit report so you can check for suspicious activity. You can place one fraud alert with any of the three major credit reporting agencies (Equifax, Experian, TransUnion) and they will notify the other two. A fraud alert typically lasts for a year, although there are options for extending it as well. 

4. Look into freezing your credit if needed 

Freezing your credit will make it highly difficult for criminals to take out loans or open new accounts in your name, as a freeze halts all requests to pull your credit—even legitimate ones. In this way, it’s a far stronger measure than placing a fraud alert. Note that if you plan to take out a loan, open a new credit card, or other activity that will prompt a credit report, you’ll need to take extra steps to see that through while the freeze is in place. (The organization you’re working with can assist with the specifics.) Unlike the fraud alert, you’ll need to contact each major credit reporting agency to put one in place. Also, a freeze lasts as long as you have it in place. You’ll have to remove it yourself, again with each agency. 

5. Update your passwords 

Ensure that your passwords are strong and unique. Many people utilize the same password or variations of it across all their accounts. Therefore, be sure to diversify your passcodes to ensure hackers cannot obtain access to all your accounts at once, should one password be compromised. You can also employ a password manager to keep track of your credentials, such as one you’ll find in comprehensive online protection software. 

6. Consider using identity theft protection 

A solution such as this will help you to monitor your accounts and alert you of any suspicious activity. Specifically, our own Identity Protection Service will monitor several types of personally identifiable information, alert you of potentially stolen personal info, and offer guided help to neutralize the threat. Also, it can help you steer clear of some types of theft with preventative guidance that can help keep theft from happening in the first place. With this set up on your computers and smartphone you can stay in the know and address issues immediately. 

7. Use online protection software, and expand your security toolbox 

To use your credit card safely online to make purchases, add both a VPN and password manager into your toolbox of security solutions. A VPN keeps your shopping experience private, while a password manager helps you keep track of and protect all your online accounts. Again, you’ll find a VPN as part of comprehensive online protection software. 

The post How to protect yourself from identity theft after a data breach appeared first on McAfee Blogs.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains