Home Blog Page 100

This “World Backup Day,” Let’s Look at the H.O.L.I.S.T.I.C. Reasons Behind Data Loss

reasons for data loss, data loss, data breach, world backup day

Imagine one morning you wake up and check your mobile phone for emails and messages and you notice that there is no new data on it. Anxious, you rub your eyes and take a closer look. But you cannot even find your older data. You spring out of your bed hysterically and check your laptop. Your laptop data is also completely wiped-out. You are covered in stress sweat and just then the alarm sets off. You wake up, scramble to your study, and check your phone and laptop only to realize it was a nightmare.

By Mihir Bagwe, Technical Writer, CISO MAG

Studies suggest that people experience nightmares only when they are uncertain or insecure about something. And today, these nightmares culminate from the fears of data breach and a corresponding loss of identity, reputation, and much more. So, to get rid of these worst nightmares, we first need to look at the root causes culminating in a data loss incident.

The H.O.L.I.S.T.I.C. Reasons Behind Data Loss

Data loss is a problem for organizations of all sizes. Loss of data amounts to a loss of time and money required for the restoration and retrieval of critical business information. Data loss incidents can occur accidentally or when someone purposely intends to corrupt it. However, you can minimize the data loss by understanding the following H.O.L.I.S.T.I.C. reasons which lead to a data loss.

Human Error

Since humans are fallible, they have often been deemed the “weakest link” in a security chain. They sometimes make the biggest of blunders, which are more often accidental. As per research by David M. Smith, Ph.D., Pepperdine University, trailing just behind hardware failure (40% of data loss happens due to this), human failure (29% of data loss happens due to this) is the second most common cause of data loss. In fact, “accidental deletion” and “physical damage” are regarded as the two most common human mistakes. Thus, having your data properly backed up will no longer give you a sunken gut feeling if you accidentally delete a major project.

Outages

Consider you are writing a long article and have reached halfway, and suddenly the power goes off. You have not saved the changes made to your document, and now it is all gone. The data is lost forever. But wait, did you keep that auto-save feature ‘ON’? Well looks like even Word has a backup in place, doesn’t it?

This is perhaps the simplest example but imagine working with sophisticated databases or creating detail-rich graphic illustrations. Practically, only a few privileged are not at risk of any natural calamity like floods, earthquakes, or hurricanes. Because even natural disasters can cause data loss – which eventually results in a power outage or structural destruction. Thus, having a data backup for running a data recovery process is of utmost importance.

Lack of Budget

Technology budget is often debated in board rooms. And something that does not make an immediate impact on the profits of any organization is regarded as a liability. The top brass does not believe in spending a fortune on systems that may or may not be used. Thus, constricted budgets often leave IT teams with an option of taking backups of only what they feel is critical as opposed to a complete organizational data backup.

The C-suite needs to understand that it is important to invest in data backup technology than exceeding the existing budget or spending twice of it in a disaster recovery process.

Insider Threat

Your organization treats you like a family member and you return to the favor through trust and loyalty. However, not everyone feels this way. Data breaches, as recorded in many cases, happen due to unsuspicious and cunning insiders. One of the largest insider threat episodes, which spanned between 1976 to 2006, was the Boeing incident. Greg Chung of Boeing stole $2 billion worth of aerospace proprietary and highly confidential documents and gave them to China, which was running behind schedule in the race to develop its equivalent of Boeing plane. In this case, intellectual property was lost, denting Boeing’s reputation with a number of stakeholders. Thus, data backups are necessary to fight not just external but also internal adversaries.

Software Corruption

You are late for lunch. So, your colleague simply shuts down your system innocently, telling you the importance of a work-life balance.  The impromptu software shutdown, which seemed trivial or insignificant in that moment, can mar your data. Improper shutdowns delete your progress or corrupt the data permanently. When software is corrupted, it may not run again, and the data stored in that software is lost forever.

While software corruption can sometimes be the result of power outages or other uncontrollable factors, it is important to implement procedures for properly shutting down software after use. Be careful when powering down your computer and shutting off any programs abruptly. When your employees consistently save documents and follow safe shut down procedures, they reduce the risk of data loss from software corruption.

Threat from Ransomware

Ransomware has been a thorn for IT teams off late. There were nearly 200 million ransomware attacks globally in the third quarter of 2020 alone. Threat actors are evolving and no longer targeting just frontline systems, but also data backups and recovery solutions. Once the data backups are encrypted, it gives ransomware operators an upper hand, which they leverage for scooping ransom payments from victims.

A recent recommendation from the Cybersecurity and Infrastructure Security Agency (CISA) states that organizations should routinely backup systems, reinforce basic cybersecurity awareness and education, and revisit cyber incident response plans. However, evolving ransomware attacks that target backup data, backup catalogs, and even storage array snapshots force organizations to go through the reconfiguration of backup solutions even before recovering the data. Thus, a modern data platform should essentially have built-in protection for backups.

Inadequate Incident Response Measures

The five steps for a successful incident response (IR) are:

  1. Preparation
  2. Detection and reporting
  3. Analysis
  4. Containment
  5. Post-incident activity

A well-prepared incident response team is a powerful weapon in any organization’s arsenal. However, off-the-shelf incident response plans are often outdated and ineffective against evolving threats and changing technology. Besides, lack of communication between teams, unmanaged and inadequate IR tools, etc., also delay the IR activities at times. And this lost time is critical. In case of a data breach incident, data is already compromised, and if there is a delayed incident response, a widespread data loss can then be expected.

Computer Theft

Since the onset of the pandemic, more and more people are using BYODs. This often means they are working from laptops or smartphones rather than PCs. Laptop theft is a serious risk and can happen anywhere if a laptop is left unattended. According to a study:

  • 25% of IT theft takes place in cars or other modes of transport.
  • 23% takes place in the workplace.
  • 15% in airports or hotels.
  • 12% in restaurants and eateries.

Computer or laptop theft also poses the threat of a data breach. If your employees have access to or store critical business information on portable devices, it is a must to have means of remotely wiping data from those laptops or respective endpoint devices. Also, organizations need to ensure that critical data stored on these devices is backed up to a safe location.

For desktop computers located in office buildings, ensure they are kept in locked rooms with strict authorization. When closing your business overnight, be sure to have a secure lock-up procedure and surveillance to avoid physical theft.

So, this World Backup Day, practice and implement backup policies, because you won’t always have a server room that stores the bulk of an organization’s data.
About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 

Other Posts from the Author:

Security is inbuilt in women’s DNA

As the world celebrated womanhood and women’s contribution to society on International Women’s Day, we at CISO MAG decided to devote the month of March to all the women in cybersecurity. The purpose of this article is to highlight the role of women in the industry and address several issues they face. This was in the light of the revelation that women’s representation in cybersecurity has been less than a quarter and has remained that way for almost a decade, if not more. Most of the problems faced by women can be traced back to the earliest days of their education, where stereotypes begin.

Here’s what the women in cybersecurity have to say on gender disparity, representation, and diversity in the industry:

1. Security is an aptitude

Right mindset: It has been widely preached that women lack adroitness in technical subjects. And to some extent, it has been imbibed in their beliefs as well. They are said to be good at creativity. What people don’t get is that the crux behind cybersecurity is the figurative thinking of great minds who are enthusiastic about exploring and exploiting cyberspace. So, the day we change the thought process of women that they are born with the skills required to survive in the field, is the day these trends will favor their growth. All that is required is a little practice and patience. It’s all about the mindset.

Gender disparity: I would second that the disparity traces its roots back to school. I have often heard people preaching that “Tech is for men and kitchen is for women”. On the contrary, I have witnessed some unparalleled men in the baking business and women in the tech space. It has nothing to do with gender. It is not just women but everyone in general who needs to be enlightened. Not much has been done about educating students about cybersecurity. I believe there has to be a separate program for bringing up cybersecurity awareness amongst the kids. The pros and cons of cyberspace need to be assimilated deep down into their roots right from the start. This is how we can make a change and our nation cyber safe. One more approach other than the awareness programs would be giving them exposure to unmediated scenarios in the form of games or challenges. This will catch their attention and make them brainstorm about the importance of security of their device and their data. This is how they would safely use their gadgets.

Diversity in cybersecurity: Specifically, with cybersecurity, it’s a specialized niche where you want a varied group of folks to provide that input. Security is an aptitude to look into details and no one is better than women at it. Security is inbuilt in their DNA. The drawback of not having women’s participation is that we miss the most inquisitive minds that the universe has to offer.

The tech industry is grappling with two big challenges. First, it is struggling to fill jobs with qualified candidates. The second, the remedies to which will also help cure problem #1, is diversifying beyond the current homogeneous band that fills the high-tech halls. Both problems are even more acute in the cybersecurity sector.

It’s not a woman or race issue, it’s a people issue that we need to know and be aware of.

 

2. Inclusive workforce

Gender gap: Yes, there is a wide gender gap in the cybersecurity industry. According to (ISC)2 ’s Global Information Security Workforce Study, women in infosec represent 10% of the global workforce. Whereas 26% of IT professionals worldwide are women. There is a perception that cybersecurity is all about “HACKING” and this negative portrayal keeps women away from this industry. Most of them look for safe and respectable career options. Also, it’s a hard reality that cybersecurity is a male-dominated sector, with very few cybersecurity startups/organizations led by women.

To bridge the gap, we need to start with education and initiatives at schools and the college level. Industry connections with engineering colleges should facilitate workshops, classes, and demonstrations to create awareness about various roles and opportunities in the sector. This, in turn, can inspire students to strive for the right career path in cybersecurity.

Also, there is a lack of female role models in the cybersecurity industry. Appointing ambassadors and promoting women in this sector will inspire the younger generation.

Special scholarship programs for girls interested in cybersecurity, discounted trainings, and the participation of women cybersecurity leaders in security conferences will improve the visibility and participation of women in the industry. This participation can act as a strong myth-buster and remove all the negative impressions associated with the term ‘HACKING.’

Hiring opportunities: Given the huge skills gap in the cybersecurity industry, there is a strong need for an inclusive workforce. A diverse workforce is more productive and that research shows increased profitability in companies with more women, at the senior level.

Businesses can start with sharing the stories of women who are succeeding across all levels in the organization. The long-term approach can expand the early-in-career talent funnel that is reaching out to on-campus girl students for internships and placements.

As a matter of a fact, at DigiSec360 we have more women cybersecurity professionals than men.

Training and mentorship: There is no doubt that training and mentorship/coaching are the key initiatives for developing the women workforce in cybersecurity. Collaboration with industry leaders and non-profit organizations, and alignment with local chapters of organizations like WISP, DSCI, WiSYS, InfosecGirls, etc., will yield results.

However, when it comes to mentoring, though women tend to mentor other women more, considering very few women at the senior level, there is a strong need for building a pool of male mentors in the industry.

Sponsoring training and certification for enthusiastic and bright women employees is going to be a welcome step.

 

3. Women role models are scarce

Less representation of women: There is a societal view that a career in Cybersecurity/Information Technology is a path mostly for men even though there is nothing that predisposes men to be more interested in this field. Society has conditioned women to believe that Cybersecurity/Information Technology roles require technical skills or can be tedious, making women lean more towards social sciences.

This has geared the Women’s fold to have low interest even from using it as a career.

The lack of substantive and adequate role models in cybersecurity across the globe is also a contributing factor.

Lack of women role models: The rate of representation of women in cybersecurity is 24% and about 20% in technology; women role models are scarce that other women can look up to, in the field. This is because the cybersecurity field is perceived as a male-dominated one, and there are insufficient women at the leadership level.

Besides, the industry’s limited role models could be based on another perception that the industry abhors work-life balance. It is one of the possible reasons for the gender gap, but it is good to note that this narrative is gradually changing. If an increased number of women excel, it will encourage more ladies to join the industry.

Cybersecurity scholarships for women: In cybersecurity, scholarships are important to encourage more women to get into the field, and many STEM programs are geared towards this. Encouraging and effectively engaging women and young girls in STEM would boost their confidence and lay the groundwork for future leaders who would make substantial cybersecurity contributions.

Funding could be a major issue for female inclusion in the industry; scholarships for women will encourage women’s integration as certifications help prove the women’s capability on a merit basis rather than the subjective opinion of recruiters.

What can men do? As men hold the largest percentage in the workforce leadership, they can support women by leveling the playing field with men. The men in the leadership roles can join women in advocating for inclusion, mentoring, sponsorship, and ending the gendered division of labor in the workplace.

Trusting females with the more technical aspect of the field may help improve confidence and easy integration. Executive management and the board’s support are vital because we are still operating in a male-dominated leadership environment.

Set specific shared goals for the representation of women and regularly measure progress toward them.

Million Dollar Business: Ransomware Gangs Scooped $350 Mn in 2020

ransomware

Ransomware attacks were the most observed security threats among various cybercriminal activities in 2020. Cybercriminals target victims by encrypting their sensitive files, with an end goal to disrupt organizations’ operations and demand ransom or threaten victims by exposing the data on darknet forums. But have you ever wondered how it continues to be a profitable business for adversaries?

A Million Dollar Business

A recent investigation report from Chainalysis revealed that ransomware operators made over $350 million in ransom payments in 2020. It is also found that the total amount of ransom paid by the victims increased by 311% compared to 2019. Infamous ransomware operators such as Ryuk, Netwalker, Maze, Doppelpaymer, REvil, Conti, Snatch, Defray777, and Dharma are the top ransom earners last year.

“The 2020’s ransomware increase was driven by several new strains taking in large sums from victims, as well as a few pre-existing strains drastically increasing earnings,” the Chainalysis report stated.

Young Victims More Likely to Pay Ransom  

One of the questions victims face is whether to pay the ransom. Though it is against the law, several companies pay ransom to recover their critical data. According to Kaspersky’s Consumer IT Security Risks Report 2021, the age of the victim also affects the willingness to pay the ransom.

The survey found that nearly 56% of respondents who were affected by ransomware attacks paid the ransom to restore access to their data. This is highest among those aged between 35-44, of whom 65% paid to restore their data, compared to 52% of those aged between 16-24 and a far smaller 11% of those over the age of 55.

Paying Ransom is not the solution

Paying ransom encourages cybercriminals to continue their ransomware attacks on other companies. And sometimes, it does not guarantee the return of compromised data. While 53% of ransomware victims paid the ransom, 17% of them didn’t recover their data. Only 29% of victims were able to restore all their encrypted or blocked files after an attack. Half lost at least some files: 32% lost a significant amount, 18% lost a small number of files, and 13% lost almost all their data.

“The FBI does not encourage paying ransoms. Payment does not guarantee files will be recovered. It may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. However, the FBI understands that when victims are faced with an inability to function, all options are evaluated to protect shareholders, employees, and customers,” the FBI said.


Related Stories

Zoom’s Video-teleconferencing Platform Still at Risk: FBI Warns

Zoom, video conferencing, webinar, zoom two-factor authentication, top data breaches of 2020

Despite regular security updates and features, cyberthreats on Zoom applications have become rampant. In the wake of the pandemic, the popular video conferencing platform suffered numerous cyberattacks and is still a primary target for many cybercriminal gangs. The company even launched a new feature “At Risk Meeting Notifier” in its latest update to help the conference hosts to block uninvited guests from entering the calls and prevent Zoombombing attacks.

In its latest security advisory, the FBI has alerted members and organizations about rising criminal acts of hackers on Zoom video conferences. The attackers, tracked as Zoombombers, are allegedly breaking into online classes and business meetings to disrupt or just to play pranks. “The FBI has received multiple reports of conferences being disrupted by pornographic and/or hate images and threatening language. As large numbers of people turn to video-teleconferencing (VTC) platforms to stay connected in the wake of the COVID-19 crisis, reports of VTC hijacking (also called Zoombombing) are emerging nationwide,” the FBI said.

What is Zoombombing

In a Zoombombing attack, unauthorized guests (Zoombombers) connect to a Zoom meeting room and disrupt the meeting by doing non-contextual things like hurling insults, playing pornographic content, or making threats to other participants. A  Zoombombing incident takes place when participants knowingly or unknowingly share a Zoom meeting ID (and sometimes its password) on social media or discussion forums like Reddit and Quora threads.

Zoombombing Incidents

The FBI stated that several Massachusetts schools, including other businesses, have reported incidents of Zoombombing attacks. “In late March 2020, a Massachusetts-based high school reported that, while a teacher was conducting an online class using the teleconferencing software Zoom, an unidentified individual dialed into the classroom. This individual yelled profanity and then shouted at the teacher’s home address in the middle of an instruction. A second Massachusetts-based school reported a Zoom meeting being accessed by an unidentified individual. In this incident, the individual was visible on the video camera and displayed swastika tattoos,” the FBI added.

Rise in Video Conference Services

With organizations and educational institutions globally continuing their operations remotely, cybercriminals are taking advantage of this situation by targeting video conference and calling platforms like Zoom.

Related story: DDoS Attacks on E-Learning Platforms Increase by 550%.

Do Your Due Diligence

The FBI also recommended certain security measures to mitigate teleconference hijacking threats. These include:

  • Do not make meetings or classrooms public. In Zoom, there are two options to make a meeting private: require a meeting password or use the waiting room feature and control the admittance of guests.
  • Do not share a link to a teleconference or classroom on an unrestricted publicly available social media post. Provide the link directly to specific people.
  • Manage screen sharing options. In Zoom, change screen sharing to Host Only.
  • Ensure users are using the updated version of remote access/meeting applications. In January 2020, Zoom updated its software. In their security update, the teleconference software provider added passwords by default for meetings and disabled the ability to randomly scan for meetings to join.
  • Lastly, ensure that your organization’s telework policy or guide addresses requirements for physical and information security.

The FBI has asked the victims of teleconference hijacking attacks to contact its Internet Crime Complaint Center at ic3.gov.

Pledge to Backup Your Data This World Backup Day

World backup Day

Information is new money in this modern digital world. Everything revolves around information, and it has become the fuel for many businesses. For instance, the business of social networking platforms like Facebook and Twitter is reliant on consumer data. Despite constant reminders on data protection, many users fail to backup their critical data, as they don’t think it’s important enough to secure it.

 By Rudra Srinivas, Senior Feature Writer, CISO MAG

At a personal level, “backup” involves creating second or more copies of all your important information such as photos, videos, documents, digital certificates, files, and emails. But backups are also crucial at an organizational level – that means making copies of digitalized intellectual property, operational data, transactional data, and financial data. Backups help in restoring data in situations of data loss, breach, or loss of the device. Backups have more importance today, with increased cases of ransomware attacks. Backups are a crucial component of an organization’s disaster recovery and business continuity planning.

Today, March 31, is World Backup Day and it reminds us to protect our valuable digital assets with proper backups. According to a survey, every person on earth created over 1.7 MB of data in every second in 2020. The world’s internet population is significantly growing year-over-year, with the internet receiving nearly 31,384,20 GB of traffic every minute.

Why should I backup my data? 

Backing up data is one of those easy-to-do security measures that most users ignore. It is always better to have a second copy of your valuable information, as it protects you from adversaries.  With technology advancing day-by-day, the threat to user’s data is also increasing. Here are some findings:

  • 1 in 10 computers is infected with malware each month.
  • 30% of people have never backed up.
  • 29% of disasters are caused by accidents.
  • 113 phones are lost or stolen every minute.

Consequences of not backing up your data

  • Identity theft – Here, personal or financial information is at stake and is often misused to commit fraudulent transactions that may damage an individual’s or organization’s reputation.
  • Loss of funds – The pandemic is tough on everyone, hence loss of financial assets or funds in digital wallets might turn out to be entrapping.
  • Financial fraud – This is also a type of identity theft where credit or debit cards are stolen for unlawful activities. Lottery fraud, fake charities, and COVID-19 scams are also used to dupe or mislead people.
  • Ransomware threats – Since ransomware usually targets system data, agencies involved in mission-critical work cannot afford to lose it.

Which data should I backup?

Even today a majority of people don’t backup their data, claiming that they don’t have any critical information to backup. Some even don’t know how to do this, and some forget to do so or postpone it. With cybercriminals leveraging users’ data, it’s imperative for users to backup and secure all kinds of data, which can’t be recovered once lost.

How should I backup?

One can backup data in two ways: external and online.

  • For backing up data on external drives, one can make use of USB flash drives and external hard disks.
  • To backup data online, applications like OneDrive, Google Drive, Dropbox, and Amazon Cloud Drive can be used.

How to backup data on my computer?

Windows OS

  • Windows 10 users can type Backup Settings.
  • Click Add Drive (+)
  • Choose your external hard drive from the list
  • Click Turn on

Mac OS

  • Open the menu and choose System Preferences
  • Click on Time Machine
  • Click Select Disk
  • Choose your USB hard drive from the list and select: Use Disk

Linux OS

  • Open the HUD (click the Ubuntu button in the Dash) and type Backup
  • Click on the search result Backup
  • Click on Just show my backup settings
  • Activate Automatic backups
  • Choose the location to store your backup on the tab Storage (your external drive)
  • Choose how often to backup on the tab Schedule
  • Click on Back Up Nowon the tab Overview to start backing up

 Note: Menu options may differ depending on OS version. But look for equivalents.

Make sure that your external storage device is plugged in always or at least
plug it in often.

Conclusion

Cybercriminals are advancing their techniques to get hold of users’ data. It is high time users realize the potential risks around data loss and keep a backup plan to recover the valuable information.

 About the Author

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

“Build a more robust pipeline for cyber talent”

It has been an age-old myth that women prioritize family over work. Women are under-represented in tech and leadership. According to an (ISC)² Cybersecurity Workforce Report, women working in cybersecurity account for about one quarter (24%) of the overall workforce. Though there’s a continuing inequity, things have begun to look brighter. Workforces – especially post-COVID-19 pandemic and lockdown – have been offering flexibility in timings, empowering women to lead, and showing support through digital mediums. Change happens with time, but it requires consistency. There is a need to go beyond the 24%.

Let’s hear what Kavya Pearlman, Founder and CEO, XR Safety Initiative, has to say about Women in Cybersecurity:

Cybersecurity as a career: Two things come to mind: Pipeline and Retention. Pipeline – Cybersecurity is still portrayed as a career for the “hooded hacker dude,” and our cultural biases around gender roles and careers contribute to the issue. This male-dominating mindset exhibits a “dude-bro” culture, deterring more diverse candidates from entering the domain. On top of this, a misconception amplifies the trend that cybersecurity is a high-stress career with no work-life balance. This is only true for a small set of careers. For example, a Chief Information Security Officer (CISO) for a FinTech or high-risk organization may have less control over their lifestyle. Retention-Burnout, status-quo tech culture, biases, discrimination, harassment, and Diversity & Inclusion simply being used as a tool for PR, etc., are just some of the reasons why women are leaving the cybersecurity career for other more welcoming and diverse career options.

Oftentimes, it goes back to early education. There lies an opportunity to direct female students to choose technical education and building the soft skills necessary for the STEM career paths. We need to build a more robust pipeline for cyber talent. Schools should follow programs and frameworks such as the U.S. cyber challenge, National Initiative for Cybersecurity Education (NICE), K-12 cybersecurity framework that offers a set of best practices that help providers of cybersecurity education and training in the U.S. better prepare their students to enter the cybersecurity workforce and help employers to manage workforce shortages and recruit the talent needed to secure their systems. Privately organized Capture the Flag (CTFs) are also a great way to cultivate interest and desire to learn within young students.

Gender inequality: School must also be considered a potential boost for a cultural change in the way cybersecurity careers are seen. Despite the fact that women are more likely to enroll in university than men, tech jobs are still facing high levels of gender inequality. This will take time, but it’s crucial to use the aforementioned tools to mark a deeper transformation. In a way, given that some cultural constructs follow the society, this will naturally happen as demography is already making the world more diverse. The educational system plays a decisive role in making the change faster.

Gender and race: With the rise of AI-based solutions, the issue is becoming more and more relevant, and the over-representation of white men in the design of these technologies, could undo decades of advances in gender and racial equality. Equally important is a concerted effort to incorporate gender and racial balance in machine learning. It is crucial to prevent algorithms from perpetuating ideologies that disadvantage under-represented groups.


Disclaimer

Views expressed in this article are personal.

Security Researchers Call Out MobiKwik for KYC Data Leak

biggest data breaches in India,data breach, Aptoide Android App Admits Data Breach, Suspends Sign-Up Option Temporarily, Panasonic

India has been planning to ban cryptocurrency for the past few months by introducing a bill against it in the parliament citing concerns over its privacy and rise in unaccounted digital assets. This is seen as a rather surprising move as the country has for long advocated the usage of digital wallets and payment options by introducing its UPI-based payment interface, BHIM, in 2016. Following the suit, many private payment companies came up shortly and established themselves quickly. One such player is the digital payments company MobiKwik. Independent security researchers quoted in this story indicate that MobiKwik accidentally leaked data of 3.5 million users, which is now up for sale on the dark web for 1.5 BTC (approximately $84,000). CISO MAG cannot confirm this and is merely reporting what the researchers are stating.

KYC (Know Your Customer) is a verification process that allows an institution to confirm and thereby verify the authenticity of their customer. Certain identity details such as PAN number, Aadhaar number, addresses, email addresses, bank account numbers, and phone numbers are recorded to verify the identity and the address of the customer. KYC is a mandatory process for financial institutions in India, for onboarding new customers.

 Key Highlights 

  • The data leak was first reported by an independent security researcher Rajshekhar Rajaharia in February 2021.
  • As per Rajaharia’s series of tweets, 11 crore Indian card holders’ data was leaked from a company server in India, and the initial leak contained 6 TB of KYC data and 350 GB of compressed MySQL dump.
  • The findings were then updated and re-confirmed by another researcher going by the Twitter handle name “Elliot Anderson,” who shared the credit with another Twitter handle named “UnderTheBreach”.
  • MobiKwik has however denied all such data breach claims and found no security lapses on their part.

MobiKwik Data Breach the Largest KYC Data Leak?

Rajaharia first raised the flag about this data breach on February 26, 2021. In a series of tweets, he presented details of when and what set of information was leaked.


However, MobiKwik thwarted his claims stating, “We thoroughly investigated his allegations and did not find any security lapses.”


But against the run of play, another user going by the name “Elliot Anderson,” on March 29, 2021, tweeted that MobiKwik’s data was indeed breached and the threat actor had subsequently created a forum on the dark web for its sale.

MobiKwik data breach, Elliot Anderson tweet
Image Credit: Elliot Alderson Tweet

As per the forum image shared by Anderson, it is the “Biggest KYC data leak ever.” The threat actor has also given an option to the interested buyers to search phone numbers or any string as a proof-of-concept. The database though seems to be larger than what Rajaharia had noted. It is 8.2 TB in size and contains 36,099,759 files along with 99,224,559 users’ critical PII details, which include phone numbers, emails, hashed passwords, addresses, bank account, and card details, PAN and Aadhar Card numbers, etc.

As Rajaharia previously suggested in his tweet, we would like to reiterate the same, “Companies should take responsibility for users’ data strongly. There should be a data leak disclosure policy in place too.” Because hiding breaches only keep the customers vulnerable out in the open.

It would now be interesting to see MobiKwik’s stance on these findings. The ball is now in its court. Was it really a breach? Or was it just a data dump from some other breach? We will keep you informed.

MobiKwik Data Breach Update – March 31, 2021:

In view of the serious allegations placed upon them by their users and other security researchers, MobiKwik has confirmed that “it will get a third party to conduct a forensic data security audit.”

MobiKwik assured that “the company has robust internal policies and information security protocols and is subjected to stringent compliance measures under its PCI-DSS, CISA, and ISO 27001:2013 certifications. These include annual security audits and quarterly penetration tests to ensure the security of its platform.”

It reiterated that all of the customer data was safe and that no MobiKwik user accounts and/or wallets were affected due to the alleged incident.

Related News:

Ziggy Ransomware Gang Announces Shutdown; Offers to Refund Ransom Payments

Ransomware Attacks, Graff ransomware attack

Whether it is a discount or inadvertent deduction, getting a refund is always a delight for everyone. But what’s unbelievable is receiving the same refund from the one who robbed you.  In an unusual scenario, ransomware operators announced that they will refund the ransom payments paid by the victims.

Ziggy, an infamous ransomware group stated that it is paying back its victims, after the group announced it would cease operations in February 2021. Usually, victims of ransomware attacks pay ransom to decrypt their critical information or recover stolen data from ransomware operators. The latest announcement from the Ziggy ransomware group is certainly good news for many ransomware victims.

Ziggy’s Shutdown

According to a report, the administrator of the Ziggy ransomware gang felt bad for their cybercriminal actions and decided to publish all the decryption keys to the data they stole. The group released an SQL file with 922 decryption keys that victims could use to decrypt their encrypted data. The group also shared the source code for different decryptor keys that can be used for infected systems which are not connected online.

What do victims need to do for a refund?

The victims of Ziggy ransomware were asked to contact the group admin at [email protected] and send their proof of payment and the computer’s unique ID. The paid ransom will be refunded to the victim’s Bitcoin wallet within two weeks.

Security researcher Shahpasandi said…

Concerns from recent takedowns! 

Several industry experts opine that Ziggy ransomware operators are concerned after the law and federal enforcement authorities disrupted services of multiple ransomware gangs recently. In January 2021, the authorities across Europe and judicial agencies worldwide disrupted the operations of Emotet, an infamous malware strain that affected multiple organizations over the years. Dubbed “Operation Ladybird,” the international coordinated action took control of the Emotet group’s infrastructure.

In a similar move, the infamous Maze ransomware gang that caused chaos and attacked various MNCs, including the IT firm Cognizant, announced its retirement effective November 1, 2020.

Related Story: How Paying Ransom Doubles the Cost of Ransomware Attack

Empowering Marginalized Voices in a Digital World

Over a century ago, the U.S. Congress sanctioned the 19th Amendment (Amendment XIX), which prohibits the states and federal governments to discriminate and deny the right to vote to U.S. citizens on account of gender/ sex. The success of the women’s suffrage movement is considered a milestone in western feminism. The beginning of the 20th century witnessed a turning point – women emerged from homebound duties to wage-earning members in the society. These women belonged to all strata – daughters of immigrants and diverse ethnicities. And this is where Cyber Collective (CyCo) steps in. CyCo smashes patriarchal stereotypes and makes a distinguished statement in the world of information technology and cybersecurity.

By Pooja Tikekar, Feature Writer, CISO MAG

Founded by Tazin Khan Norelius, Cyber Collective is the first and only women of color-owned data ethics, privacy, and cybersecurity research organization. CyCo’s strength lies in research, security awareness, privacy advocation, and data ethics consulting. Given the advancement of tools and systems used for the convenience of end-users, the company firmly believes in engaging in an open dialogue on the modern-day cyber landscape. It explores and analyzes the mechanisms that influence human-technology interactions. Today, engineers, data scientists, and infosec leaders, often find themselves in situations in which they use digital datasets that are collected or shared without informed consent, or those that are impacted by implicit biases. To address this inherent conflict between personal ethics and business goals, CyCo works directly with the community to educate and gather data transparently with an aim of creating a future where technology — though neutral — is overwhelmingly a force for good — for all.

CyCo uses the grounded theory approach in its creative, qualitative research, and then further uses the information to center marginalized folks — those who have historically been pushed to the margins by decision-makers in tech product and policy development — in conversations to impact the next generation of tech product and policy.

Integrating Pop Culture in Learning

Popular culture is an intrinsic element of our social and political lives. CyCo recognizes the value of pop culture in promoting digital literacy and building conversations around technical topics that impact our daily lives, including the impact of technology and how it shapes social dynamics. Using appealing memes, movie references, and unfiltered yet friendly language, the company educates the public and connects with a wider audience through virtual events on Zoom. Through creative and live audience research events, CyCo assesses their knowledge and gathers real-time insights to share workable findings that influence policy and industry. It also caters to its Instagram and Twitter following for social media outreach.

IFundWomen: By the People, For the People

The largest cybersecurity budgets belong mostly to Fortune 500 companies, further confirming that revenue generation or monetization strategies for startups around data privacy research are thinning. Through its IFundWomen Crowdfunding Campaign, CyCo intends to raise financial capital to foster research and bring awareness on the impact of technology on human lives.

Data Rights are Human Rights

Since the U.S. has no single federal law that regulates cybersecurity or data privacy, SMBs and marginalized communities encounter multiple challenges in the way data is consumed. Taking this concern into consideration, CyCo partnered with IT service provider Elroi and non-profit organization, The Markup. Collectively, they launched a new petition to demand the U.S. government to start working on a new national privacy law, to ensure the data protection of marginalized communities that big techs capitalize on. The company’s goal is to:

  • Create diverse and public subcommittees as part of the regulation drafting.
  • Seek an annual review of regulation compared to current technology advancements and interpretations.

To make its petition actionable, CyCo hosted a virtual event on January 28, 2021 – National Privacy Day. The event was graced by Rachel Cash, CEO and Founder of Elroi; Nabiha Syed, President of The Markup; and Brittany Kaiser, Co-Founder at Own Your Data Foundation and Cambridge Analytica whistleblower.

From February 1 to March 30, 2021, CyCo will continue to host webinars, workshops, and seminars to collect information that helps identify the gaps in our systems. It will also investigate tech’s impact on people who have historically been pushed to the margins by decision-makers in tech and policy.

No industry, program, or topic can truly grow if it remains within the parameters of its comfort. It’s 2021, we should all know by now why we “need more women in cybersecurity,” if you don’t, well shame on you. But the women are here, and we’re making space for ourselves. The change is inevitable, it’s just up to us to make it. Be the change you want to see, or watch things stay the same. At Cyber Collective, we are the change and we’re bringing everyone with us,” says Founder & CEO Tazin Khan Norelius.

S N A P S H O T
Company Cyber Collective
Founder & CEO Tazin Khan Norelius

LinkedIn: https://www.linkedin.com/in/tazin-khan-norelius-49930740/

Twitter: https://twitter.com/techwithtaz

Website www.cybercollective.org
Team Members Vanessa Miranda (Head of Engagement)

Caroline HSU (Head of Ethics)

Fara Islam (Manager, Creative Research & Development)

Rebecca Richard (Manager, Creative Research & Development)

Partners/Consulting Partners UCLA Center for Critical Internet Inquiry

https://www.c2i2.ucla.edu/ 

Social Media Handles LinkedIn: https://www.linkedin.com/company/cybercollectiveorg

Instagram: https://www.instagram.com/cybercollectiveorg/

Twitter: https://twitter.com/getcyco

Location(s) Remote organization but based in NYC
Core Strength Qualitative Research
USP Ethical technologists looking to build equitable tech need ethically-sourced data sets + focus groups to provide feedback and participate in beta testing.
Offerings
  • Data Ethics Consulting
  • Security Awareness Workshops


About the Author

Pooja Tikekar is a Feature Writer and part of the editorial team at CISO MAG. She writes news reports and feature articles on cybersecurity technologies and trends.

More from the author. 

“I personally believe girls are naturally blessed analysts and can make great research scholars”

COVID-19 has changed the ways businesses operate today. Like health care and banking, cybersecurity was one of the most impacted industries with phishing and ransomware attacks at an all-time high. The pandemic also negatively influenced the workforce shortage trend, making it prominent and noticeable. One of the troubling elements of this shortage could be the underrepresentation of women in tech and cybersecurity. Women’s representation in cybersecurity has been less than a quarter (24%) and has remained that way for almost a decade, if not more. Lack of women role models in the industry roots from an unconscious bias in the society amongst all cultures that “tech is for men.” Pooja Tikekar, Feature Writer at CISO MAG, engaged in a conversation with Rajpreet Kaur, Senior Principal Analyst at Gartner, to discuss gender stereotypes and the need for more inclusive mentors in the industry.

Rajpreet helps IT leaders in resolving their network security issues across hybrid environments. Her research focuses on network security technologies such as Web application firewalls, DDoS mitigation services, advanced threat detection, deception platforms, and network security policy management tools. Rajpreet also discusses security gap analysis, DDoS threat mitigation, and ways to build cyber resiliency.

Edited experts of the interview follow:

A detailed assessment of security architecture from a technical standpoint helps identify and mitigate hidden risks that threat actors are likely to exploit. What are the most common and critical risks associated with network security that need remediation and improvement for building resiliency and improving an organization’s security posture?

Organizations must be aware of how the threat landscape and the business landscape shift. 2020 ONWARDS there have been swift changes to threats with increased remote work and targeted malware campaigns that take advantage of worldwide events, such as COVID-19. The networks have evolved and hence network security must evolve to secure these hybrid networks. Phishing and other human-facing social engineering tactics remain the primary vectors of successful attacks; however, credential stuffing and scan-and-exploit tactics are also increasing. Digital business and edge computing have inverted access requirements, with more users, devices, applications, services, and data located outside of an enterprise than inside and users working from home.

Performing security gap analysis helps circumvent cybersecurity vulnerabilities. However, this evaluation may vary as compliance standards differ from one organization to another, depending on the scale of the business. And compliance doesn’t necessarily achieve security. How do we close the gaps between security and compliance?  

Compliance as a checklist approach can never help an enterprise to achieve continuous and adaptive security in an enterprise. Enterprises must use a continuous and adaptive risk and trust assessment strategic mindset to enable prediction and prevention, where feasible, and deploy detect and respond capabilities to adjust to changing threats. Enterprises must always remember that compliance is the baseline; our protection is business-risk-driven.

Most DDoS attacks rely on rented botnets. What other attack vectors do adversaries use to launch DDoS attacks? And how can CISOs adopt smarter ways to combat them?

DDoS attacks have become more intense and sophisticated in this pandemic world. Bots have been a primary source to generate these attacks. Security and risk management leaders must anticipate business interruptions by including DDoS preparedness in business continuity/disaster recovery procedures as well as incident response. Also, implement a layered DDoS defense by utilizing the best of cloud scrubbing center, cloud web application firewall, bot mitigation, DNS protection, internet service provider, and on-premises DDoS appliances consistent with your risk assessment.

You hold a master’s degree in Computing Systems and Infrastructure and your research focuses on network security, including technologies such as IPS, web application firewalls, and APT detection. However, sometimes, gender stereotypes and cultural norms falter girls’ interest in STEM. How can educators and industry experts foster a mindset that alters perceptions?

I am observing a strong interest in girls fighting beyond the cultural boundaries and showing great interest and adopting STEM subjects. Girls are making huge strides there. And these achievements of women in the industry have started to change the perception. Things are pretty different in different regions though, in many emerging regions like Asia, we see parents encouraging girls to adopt STEM subjects as it leads to better jobs with good income. I personally believe girls are naturally blessed analysts and can make great research scholars that their contribution to the STEM industry is critical and the employees need to support that along with the society to support them.

Women’s representation in cybersecurity has been less than a quarter (of the total workforce) and has remained that way for almost a decade, if not more. Do you think more inclusive mentors could change this?

I think the primary reason for lesser women in it is that cybersecurity careers don’t have fixed working hours and might require late-night meetings, traveling, etc., considering the criticality of the industry and many find it difficult to manage with no support. Having good mentors can make a huge difference no matter what the gender is. Offering flexibility to help find them a work-life balance is very important. Work from home has provided many women a more flexible working schedule and helping them to find a balance.

Women, sometimes, experience uncertainty at their workplace. What cohesive steps can men/businesses implement to them feel confident and support them to ascend the corporate ladder?

I have been very lucky to have great managers who have hugely contributed to my career, and all of them were men. They strongly practiced gender equality, treating me equally, giving me equal opportunities, and making me a confident employee. Corporate policies implementing strong gender balance and equality can play a critical role to make their women team members feel motivated and equal.


About the Author

Pooja Tikekar is a Feature Writer and part of the editorial team at CISO MAG. She writes news reports and feature articles on cybersecurity technologies and trends.

More from the author.