Home Blog Page 147

Ex-Microsoft Employee Sentenced to 9 Years Jail time in a $10 Mn Fraud Scheme

Prison Tablet

A $10 million digital currency fraud scheme earned an ex-Microsoft employee a $160,000 car and a lakefront home in Renton, Washington. But karma came biting as he now must sleep on the hard prison bed for the next nine years with a view of his prison cell.

The Fraud Scheme

Volodymyr Kvashuk, a 26-year-old Ukrainian residing in Renton, Washington, worked as a tester at Microsoft. Kvashuk was assigned to test Microsoft’s online retail sales platform. While testing the platform, he found a few illegal ways of mining the digital currency used across the platform. From the backend, he stole digital currency in the form of gift cards or subscription/discount codes that could be redeemed for Microsoft products or gaming subscriptions and then resold them through various channels on the open internet.

Related News:

Jailed! East London Duo Sentenced for 700 Bank Account Frauds

The Conviction

Earlier in February, a federal jury had already convicted Kvashuk on counts of tax evasion, money laundering, and fraud charges. However, in the recent sentencing, the U.S. District Judge James Robart has ordered the accused to pay more than $8.3 million in restitution and serve a term of nine years for running his fraud scheme. Kvashuk could later be deported following his prison term.

The case investigations found that much of the money was stolen from email accounts associated with other Microsoft employees. Seattle U.S. Attorney Brian Moran said in a news release, “Stealing from your employer is bad enough, but stealing and making it appear that your colleagues are to blame widens the damage beyond dollars and cents.”

Before getting fired in June 2018, and after the incident came to light, Kvashuk made quite a fortune from the fraudulent money laundering scheme. He splurged on a lavish lifestyle, which includes a Tesla car worth $160,000 and a $1.7 million lakefront home. But as all good things come to an end, all bad things also come to an end.

Related News:

Dozens of Hospital Computers Compromised, Former Employee Pleads Guilty

Microsoft and NCSC Join Hands to Support U.K.’s Cyber Accelerator Program

NCSC and Microsoft Cyber Accelerator program

Microsoft has partnered with the U.K.’s National Cyber Security Centre (NCSC) to support its Cyber Accelerator program to boost cybersecurity startups in the country. The tech giant stated that innovative companies in the U.K. are given the support to develop new security products and tools that can protect organizations against evolving threats.

This will be the seventh program in the Cyber Accelerator program series, which will run from January to March 2021. As per the partnership deal, Microsoft will provide access to its Accelerator alumni network and subject matter experts across cybersecurity and cloud for eligible startups.

The latest alliance comes after the rising cybersecurity threats in the U.K. Recently, the NCSC dealt with 723 cybersecurity incidents involving nearly 1,200 victims past year.

The NCSC and Microsoft alliance will focus on solutions that enable the safe use of data at scale in smart cities and the cyber risks associated with, including:

  • Data Insights: Solutions that enable the safe use of data at scale and are operationally viable in a smart city.
  • Situational Awareness: Tools capable of identifying non-traditional devices such as IoT from a range of different vendors, all with their own cybersecurity risk profile.
  • Interfacing to critical national infrastructure (CNI): Solutions to help shape NCSC guidance across this emerging landscape of smart technologies interfacing with the CNI.
  • Manufacturing and Robotics: Given the mobile nature of robotic systems in uncontrolled and semi-controlled environments, we are looking for innovative ways to scale or adapt existing mitigations that provide assurance of correct robot operation to avoid harm, accident or malicious performance degradation.

Matt Warman, Minister for Digital Infrastructure, said, “Good cybersecurity is the bedrock of our digital economy and will help power our post-pandemic recovery. It gives people the confidence to shop, work and play online and makes business resilient against cybercrime. As well as government investment in the NCSC Cyber Accelerator, we are backing tech start-ups through the LORCA program, which is paying dividends with its network of cutting-edge U.K. start-ups breaking investment targets and helping create jobs across the country.”

Chris Ensor, Deputy Director for Cyber Skills and Growth at the NCSC, said, “I would encourage all cybersecurity companies in the U.K. to take a look at the Cyber Accelerator program and consider applying. Successful applicants will receive support from our world-class experts, setting them on their way to delivering the most cutting-edge security solutions of the future.”

Endpoint Security: Your First Line of Defense

Plus ça change, plus c’est la même chose,” an epigram by French writer Jean-Baptiste Alphonse Karr (1849) translates as “the more things change they remain the same.” There is an eerie parallel of governments’ reaction, the proliferation of fake news, and potential treatment between the Spanish flu of 1918 and the current Coronavirus pandemic. Do check out the podcast by Paul Combs – The Revisionist History, if you are interested.

By Pankit Desai, Co-founder and CEO, Sequretek

One may wonder what the above context has got to do with the topic of endpoint security — to start with: there is a “Virus” with a play here and, like its biological cousin, it seems to morph to a changing landscape, albeit technological in this case. It was way back in 1971 that the world encountered its first computer virus, “Creeper.” Since then, there has been a constant game of one-upmanship between the attackers and defenders. For a while, it seemed like the good guys had the upper hand only to be proven wrong, and for a few legitimate reasons.

Technological Changes and its Impact

Lowering of costs and complexity has resulted in the democratization of technologies like – IoT, cloud, big data, mobility, robotics, and additive manufacturing.  This technology infusion has transformed manual and offline systems into automated and networked employees moving out of their offices and data centers, moving to the cloud.

Before COVID, the companies who understood technology’s power had started embracing this transformation and absorb its impacts. However, the laggards ended up getting caught pretty much unaware. They were forced to quickly figure out a way to enable their enterprises to “work from home” scenarios and open up their internal processes to external access. As if this was not enough, the WFH creates an additional challenge where ‘personal assets are being used for professional purposes’ and ‘professional assets are being used for personal purposes.’

Enhanced Security Risks and Responses

Technological advances and changing circumstances have impacted how enterprises have configured their IT infrastructure, forcing them to rethink how they now need to be secured.

Traditionally there was an emphasis on a strong perimeter defense to protect critical assets, be it endpoints or servers in one’s datacentre, since they were supposed to protect the perimeter. However, there was a lopsided budget allocation leading to a strong perimeter but weak device security. For most of them, a signature-based antivirus was sufficient for endpoint security, and patching was done sporadically, if at all, for servers.

The result is for everyone to see. Pull up any report by analysts or security experts, and one sees varied statistics suggesting that attacks on the endpoints are on the rise and are the cause of the majority of breaches. Thankfully, there is a consensus that the endpoint is the new perimeter that needs to be defended.

Reactive Approach Leads to New Challenges

The industry has gone about addressing the threat perception by offering a series of layered products, each of whom solves a specific security challenge.

Antivirus (AV) was the first technology, launched in the late 80s, to address external threats by leveraging signature, behavior, and heuristics-based models. As zero-day attacks and advanced persistent threats (APT) started coming in somewhere in early 2010, one saw emulator based Anti-APT technologies coming into the market. We are now witnessing the proliferation of machine learning-based technology Endpoint Detection Protection and Response (EDR) to address the challenges of file-less malware, the effectiveness of emulator technologies, and signature dependencies with AV.

On the other hand, the need to understand and improve environmental hygiene resulted in another technology set.  Asset management to get an understanding of the heterogeneous landscape, both hardware and software. Application whitelisting to reduce the software asset sprawl and the consequent security risk. Vulnerability / Configuration Management to identify software vulnerabilities, followed by Patch Management, to fix the same.

Add technologies like encryption, device control, data loss prevention, host firewall, VPN, and you get the drift. It almost seems that every time there was a new security challenge, the industry’s response was to offer a new product, not only that, most of these technologies don’t talk to each other. It’s a classic case of six blind men and the elephant story, where each one touches a different part of the elephant to give a view on what they were seeing. In most enterprises, the endpoint security realm is about managing multiple management consoles, each reporting their point of view on devices’ health. The situation becomes even more complicated when the consoles can’t even agree on the inventory count as each of them reports independent numbers with considerable time spent on reconciliation.

Technology Bloat and Ensuing Challenges

Way back in 2015, Gartner coined the term “endpoint protection platform” (EPP), defining it as a solution that would converge endpoint device functionality into a single product that would combine several point technologies into one. Most of the technologies mentioned earlier are part of the Advanced EPP feature set.

It’s been more than five years since. A recent report by a security leader identified that, on average, there 50-70 different security tools that enterprises end-up investing in, and 35% of the security products had overlapping functionality. These findings should not come as a surprise, looking at how one sees the bloat of technologies for the endpoint space.

As if the technology bloat challenges weren’t enough, the same report identifies 80% of the tools as poorly configured. The way the market today operates, the product companies come out with products with rich but complicated feature sets. The implementation and subsequent management are left to poorly trained customers or resellers, leading to misconfigurations.

Therefore, the result is to talk to any CXO these days, and one hears a familiar grouse, “I spend so much money on these complicated three-letter acronym products. I, however, don’t get an answer to a simple question: Am I secure?” This has caused significant consternation with the security community that will need rectification.

Is there a way forward?

While the sins of the past have come to haunt us as the endpoint security battle remains unsolved and probably more complicated than before, we can take a series of measures to earn the trust back by thinking in the customer’s interest.

Machine Learning: Effective use of ML would be an effective method to remove the challenges of continuous security updates. However, there are two schools of thought on where the ML capability should reside agent v/s cloud. While the cloud gives much better control, there is an issue, especially in countries with relatively poor internet infrastructure or data residency issues, sending packets to the cloud for analysis may not be viable. A hybrid model with some localized capability for ML may be a better option.

Single Agent, Single Console: It is high time that products start looking at the endpoint security as an integrated problem, and not silos. It is heartening to note that companies branch into adjacent spaces and the coverage points seem to be improving. There are a lot of paths still to be covered.

Reduce feature bloat: In a zeal to differentiate the products, there are quite a few features that have made the products too complex to implement and run. There needs to be a critical view of what is essential as a feature set and what can be knocked off to make them simple to implement and manage.

Open interfaces: In the short run, at least till the consolidation play pans out, there needs to be an agreed API framework that allows the product to co-exist and lean on each other to become part of the security chain.

Platform v/s product: It is essential to think of a platform-based approach where products (yours or someone else) can be plugged in as new technologies or needs come. Expecting customers to overhaul their security architecture every time a new digital transformation wave comes in (5G, IoT) is not viable.

In closing

The federated nature, heterogeneity, and volume of endpoints make them the weakest link for enterprise security. It will need stakeholders’ collective efforts to overcome the inherent nature of the risk attached to them.

Till then, maintain social distance and stay safe for overcoming the risk attached to another virus that is running rampage across the world.


About the Author

Pankit  Desai,  Co-founder and CEO of Sequretek, a Mumbai-based cybersecurity company, launched it in 2013 with an aim to provide enterprise clients an end-to-end cybersecurity platform. Pankit, a veteran of the IT industry, brings 20+ years of hard-core technology and leadership experience from the information technology industry to lead Sequretek. Prior to Sequretek, he was with Rolta as the President of Business Operations. He has also served in a senior leadership capacity with NTT Data Inc, Intelligroup, Wipro, and IBM India. His vast experience has given him the ability to manage and scale global business units and service lines rapidly and efficiently. Pankit has diversified business operations and created an organization that has a multidimensional growth, understanding of business support functions, Financial Planning and Analysis, Recruitment and Operations, Internal IT, Quality, Marketing, and Alliance.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


Endpoint Security SurveyIs Your Endpoint Device Secure? Take our Endpoint Security Survey and win exciting goodies. Don’t miss out! Take Survey Now!

Endpoint Security

RedMart Suffers Data Breach; Details of 1.1 Mn Accounts Exposed

data breach

RedMart, a Singapore-based online grocery platform, is the latest victim of a data breach incident that allegedly exposed personal data and records of about 1.1 million customers. Lazada, the parent company which owns RedMart, claimed that unknown threat actors illicitly accessed the RedMart-only database, which is hosted on a third-party service provider. The incident may have potentially exposed users’ sensitive information like name, mailing address, encrypted passwords, and partial credit numbers.

The breach was found while Lazada’s security experts were carrying out their regular proactive monitoring check. Lazada informed the customers about the breach and logged them out from their accounts, asking them to create new passwords for precautionary measures. “We have taken immediate action to block unauthorized access to the database. For the avoidance of doubt, Lazada’s current data is not affected by this incident. This RedMart-only information is more than 18 months out of date and not linked to any Lazada database,” Lazada said in a statement.

The company also reported the incident to Singapore’s Personal Data Protection Commission and the Singapore Police Force for further investigation.

Lazada recommended its users to practice certain security measures. These include:

  • If you receive any calls claiming to be from Lazada or RedMart asking for payment information, credit card numbers, or any other confidential information, you should hang up. Do not provide any information to the caller.
  • Please also continue to be on the alert for spam emails requesting personal or sensitive information, as well as any unusual activity.
  • Never share confidential information with anyone over the phone, email, or text, even if they claim to be someone you know.
  • Delete messages from numbers or names you do not recognize.
  • Change your passwords frequently and avoid using the same email and password combination across different services.

What is the “Cyberchology of Human Error” in Cybersecurity?

A joint report from cybersecurity firm ESET and business psychology provider the Myers-Briggs Company revealed that human error has led to an increase in the cybersecurity risks and challenges for 80% of businesses during the pandemic. The report “Cyberchology: The Human Element” analyzed the mindsets of 2,000 consumers and over 100 CISOs in the U.K., examining the link between cybersecurity, employee personality, and stress levels while working remotely.

The report stated that employees’ awareness and their personality play a key role in protecting organizations against evolving cyberthreats. Human error was the biggest cybersecurity challenge for most CISOs during the pandemic. Cybercriminal activities surged by 63% since the lockdown was introduced and nearly 47% of people are concerned about their ability to manage stress during the crisis. It was found that 75% of organizations said 50% of their business is being undertaken by employees who are now working remotely in a distributed work environment.

According to the report, stress affects different personality types in different ways, highlighting that each employee has their own specific blind spot towards cybersecurity. As the pandemic has raised stress levels, employees are more likely to panic and click on a malicious link or fail to report a security breach to their IT team, depending on their personality type.

Jake Moore, Cybersecurity Specialist at ESET said, “Remote working has brought greater flexibility to the workforce but has also dramatically altered business processes and systems. The combination of fractured IT systems, a lack of central security, the sudden shift to home working, and a global climate of stress and concern is a perfect breeding ground for a successful cyberattack. The fact that only a quarter of businesses have faith in their own remote working strategy is shocking and shows there is much work to be done to secure working from home.”

John Hackston, Head of the Myers-Briggs Company, said, “Cybersecurity has long been thought of as the responsibility of IT departments alone, but in order to build a holistic cybersecurity strategy that accounts for the human factor, IT and HR departments must work together. Using psychometric testing and self-awareness tools, HR can help to identify the makeup of teams and pinpoint potential vulnerabilities. IT teams can use this insight to create comprehensive security protocols, and a proactive cyber strategy to stay one step ahead of potential threats.”

Hong Kong Set to Embrace Cybersecurity Fortification Initiative 2.0

Over 126 Mn People are Victims of Cybercrime Across U.S. and U.K.

Hong Kong’s central banking institution – the Hong Kong Monetary Authority (HKMA) – has announced the launch of an upgraded Cybersecurity Fortification Initiative 2.0 (CFI 2.0). The changes will come into effect from January 1, 2021, and further enable banking institutions to close the gap on emerging threats across the sector.

The Cybersecurity Fortification Initiative

The Cybersecurity Fortification Initiative was first introduced in 2016 by HKMA to help build the cyber resilience of Hong Kong’s banking sector. The upgraded framework does not make amends to the three core pillars of the original framework, which are:

  • Cyber Resilience Assessment Framework (C-RAF): It seeks to establish a common risk-based framework for banks to assess their risk profiles and determine the level of defense and resilience required.
  • Professional Development Program (PDP): It aims at providing training and certification programs in Hong Kong to grow its cybersecurity talent pool.
  • Cyber Intelligence Sharing Platform (CISP): It allows for the sharing of threat intelligence among banks as well as additional collaboration.

The Changes in CFI 2.0

HKMA recently conducted a holistic review of the CFI 1.0 through surveys, interviews, and industry-based consultations. It was observed that over 90% of the banks found the C-RAF useful and a whopping 100% of the banks said that the intelligence-led Cyber Attack Simulation Testing (iCAST) helped them in preparing against cyberattacks.

Considering this positive response, CFI, intending to streamline the cyber resilience assessment process, has implemented the following changes in Cybersecurity Fortification Initiative 2.0:

  • C-RAF: It now includes the latest ways of approaching incident response (IR) and recovery while responding to the latest forms of cyberthreats.
  • PDP: The list of certifications offered has been expanded to include qualifications equivalent to those in international jurisdiction.
  • CISP: It now offers advanced sharing of threat intelligence among banks as well as additional collaboration.

Talking about the changes in CFI 2.0, Arthur Yuen, Deputy Chief Executive of the HKMA, said, “Since the launch of the CFI in 2016, the global cybersecurity landscape has continued to evolve and banks have undergone further digital transformation.  We have therefore enhanced the CFI to reflect the latest trends in technology and incorporate recent developments in global cyber practices.  Enhancements have also been made to facilitate the development of the local talent pool for better management of cybersecurity risk.  We believe CFI 2.0 will raise the cyber resilience of the banking sector to an even higher level.”

Although the CFI 2.0 comes into effect in the new year, HKMA has provided a phased approach that will allow the banks and other financial institutions a total time of two years for complete implementation. Read more about the phased approach in this circular.

Related News:

Lack of Digital Interaction is a Barrier Between U.K. Banks and Customers: FICO

Half of Mobile Banking Apps are Vulnerable to Fraud Data Theft

India’s E-Commerce Platform BigBasket Allegedly Suffers Massive Data Breach

BigBasket Allegedly Suffers Data Breach, Customer Data on Dark Web for Sale

BigBasket, an India-based grocery e-commerce platform, suffered a potential data breach incident that could have exposed personal details of over two crore customers. According to cyber intelligence firm Cyble, the data breach was discovered on October 30, 2020, during its regular dark web monitoring activity.

Data on Dark Web

Cyble reported that an unknown threat actor group kept a database belonging to BigBasket for sale on a dark web market. Hackers are selling the database for over $40,000 with the table name “member_member.” The size of the database (SQL file) is around 15 GB and contains over 20 million customers’ personal data.

The potential leaked information included users’ full names, contact details, email IDs, password hashes (potentially hashed OTPs), pin, full addresses, date of birth, location, and IP addresses of logins among many others.

While the exact details of the threat actors’ group behind the incident is unknown, BigBasket stated that it has reported the breach to the Cyber Crime Cell for further investigation.

“Most online stores require your personal details, such as Credit or Debit card details for easy transactions, along with your residential address and mobile number for the delivery of products purchased. These details are stored in their databases for easy reference next time you decide to avail their services,” Cyble said.

Online Shopping or Monetary Loss?

Several incidents have been reported in recent times on hackers selling stolen information on the darknet markets. According to the Federal Trade Commission (FTC), the number of complaints on online shopping scams has grown every year and victims have lost a total of $420 million dollars since 2015. The commission received more than 86,000 complaints related to online shopping issues. For more details Click here…

Related Story: Ask Yourself These 4 Questions Before Shopping Online

The Evolving Role of Endpoint Detection and Response

endpoint detection and response

With the increase in myriad devices and its constant use in this connected world, cybersecurity is a major concern for both users and enterprises. For many organizations, a perfect storm of increasing cloud and BYOD adoption, combined with ineffective technology and stretched security teams, is exposing sensitive data to unnecessary risk. Added to this is the growing attack surface due to the shift towards data-centric business models.

By Nilesh Jain, Vice President, Southeast Asia and India, Trend Micro

Today, the major area of concern in any organization is to secure the endpoints and servers where most of the breaches and frauds happen. It’s not surprising in that context that so many IT leaders see endpoint security as a critical issue. In fact, endpoint security has become a hot topic on the cybersecurity front and is rising ever higher on IT managers’ to-do lists. IT leaders want a more effective, easier to use solution to address this issue. They need to find products that can consolidate a range of security capabilities into one easy-to-manage suite.

Endpoint security has changed fundamentally over the last two decades, in many ways mirroring the evolution of the wider information security market. From the first basic anti-malware scanners of the ‘90s, through innovations in black- and whitelisting, intrusion detection, web and email filtering, and today’s sophisticated targeted attack detection products – we’ve surely come a long way.

EDR – The Black Box of Breaches

EDR systems offer defenders the first line of defense that gives them a way to gain greater visibility into what is happening at the interface between production systems and the internet, with all its threats and malicious activity.

With traditional endpoint security technology, visibility into how a threat entered the network and its travel path is limited. One reason is that, when a hacker has compromised a device, he is likely to wipe away his criminal traces. Once an attack is discovered, customers want to know what the root cause was, and how it spread. When security teams go back to investigate a breach, the devices look pristine. They do not have enough information to piece the breach together. Now, with endpoint detection and response (EDR) technology, they are finally able to.

EDR works by recording the security events on any device connected to the corporate network. These endpoint devices include desktop computers, laptops, smartphones, tablets, thin clients, printers, or other specialized hardware such as POS terminals, etc. EDR is the black box of breaches. Some of these events may be regular activities; some may reveal a clue to how the threat inched towards the irreversible catastrophe. When a breach has taken place, EDR enables security teams to playback the infection and understand what has, and how it happened.

EDR Adoption

As per a global survey by Enterprise Strategy Group, 70% of organizations are already using EDR. Enterprises are always looking for new techniques to protect themselves from increasingly sophisticated malware and some standalone EDR vendors deliver their detection and response capabilities as part of EDR. To use it effectively, one would require years of training and hands-on experience. Not all companies have a security team that can do that. The downside of EDR is that it is operationally intensive. When you combine that with a global skills shortage in cybersecurity and the high level of skills needed to use the root cause tools, many customers can’t keep with EDR. While EDR tools can be difficult to use for less experienced operators, they can improve overall security efficiency by reducing the time to detect and respond to security incidents.

EDR is crucial for advanced endpoint protection solutions capable of detecting suspicious behaviors at all levels of the computing stack from the device to the user. Another key EDR functionality is that it enables security teams to do proactive threat hunting. As the EDR market matures, Gartner expects feature improvements to focus on increasing the capabilities of the adaptive security architecture to provide more holistic and integrated security capabilities.

EDR from a Security Provider and a User Standpoint

As threats continue to become stealthier and capable of evading traditional cyber defenses, cybersecurity leaders today need a comprehensive enterprise cybersecurity strategy that pre-empts threats, reduces risk, and responds to every regulatory requirement. Security leaders are concerned with increasing complexity in their endpoint environment, compounded by advanced, multistage attacks going beyond typical malware.

Endpoint security suites are now more than ever being tasked with protecting against targeted-style threats that utilize multiple stages involving user interactions, exploit chaining and script-based attacks. As mass threats increase in sophistication, buyers and vendors have begun focusing on behavioral detection with an automatic response. According to Forrester, endpoint security suite customers should look for providers that:

  • Tightly integrate threat prevention, detection, and response
  • Extend visibility and control over a broad endpoint ecosystem
  • Offer flexibility in a variety of environments and risk tolerances

The highest priority for customers is improved detection and response, and hence we’ve integrated these capabilities into our endpoint protection platform to leverage the automation that already exists, which provides enterprises with better-layered protection. For instance, advanced detection capabilities such as behavioral analysis, pre-execution machine learning, run-time machine learning, and vulnerability protection work in concert with other endpoint detection and remediation capabilities.

Customers require a multi-layered approach to endpoint security incorporating tools that combine superior performance with low cost and centralized management. We believe it’s all about delivering the best in threat protection across all endpoints, email, and web; and ensuring that customer data is safe whether it’s run in a physical, virtual or hybrid environment. For enterprises that want to have root cause analysis capabilities on top of their advanced detection and response, endpoint sensor allows them to query endpoints and build a detailed analysis of how and where advanced attacks occurred. For those enterprises that may not have skilled threat researchers to develop this, we are expanding their MDR services that are already available in some limited geographies.

EDR is Here to Stay

Needless to say, EDR is a complex technology; its overarching benefits will make it indispensable for organizations in this highly connected digital world. Gartner’s predictions validate that EDR is here to stay. Their findings suggest that by 2022, 60% of organizations that leverage endpoint detection and response capabilities, will use the endpoint protection solution from the same vendor or managed detection and response (MDR) services.

Hence, for enterprises that are increasingly looking for scalability, strong data management, flexible analytics and open integration, EDR would be a mainstay in the 21st century.


About the Author

Nilesh JainNilesh Jain heads South East Asia and India Operations for Trend Micro since January 2018, before that he was head of India operation as Managing director of Trend Micro India business. During his stint at Trend Micro, Nilesh has been instrumental in scaling business through Sales Management, Profitable growth & adding new Customers in the fold.

With over one has half-decade of a successful Sales career at Trend Micro, Nilesh has handled Channels, SMB, Enterprise & Govt segments with equal excellence. As head of the Business, Nilesh is responsible for all functions, with foremost emphasis on managing Sales Operations, Profit & Revenue in India, and SEA (Southeast Asia) region.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


Endpoint Security SurveyIs Your Endpoint Device Secure? Take our Endpoint Security Survey and win exciting goodies. Don’t miss out! Take Survey Now!

Endpoint Security

Operation Egypto: U.S. and Brazil Seize $24 Mn in Cryptocurrency

Sardonic, BitMart

Law enforcement authorities from the U.S. and Brazil seized $24 million in cryptocurrency that was procured via online fraud. According to the Department of Justice (DoJ), federal authorities from both the countries participated in “Operation Egypto,” a Brazilian ongoing federal investigation into the suspected fraud scam. Brazilian authorities estimate that attackers have obtained more than $200 million through this scheme, defrauding tens of thousands of Brazilians.

According to the DoJ, fraudsters lured investors with innovative investment opportunities advertised online and in-person claiming to offer high returns in cryptocurrencies.  The Brazilian court found that the defenders invested little amounts in cryptocurrencies and returned very little to the investors.

The U.S. seizures were tied to Brazilian Marcos Antonio Fagundes’ alleged role in the scheme. He has also been charged with several criminal violations of Brazilian law, including fraudulent management of a financial institution, misappropriation, and money laundering, and securities law violations.

“To carry out the scheme, the conspirators are alleged to have made false and inconsistent promises to investors about the way the funds were invested and exaggerated the rates of return. From August 2017 to May 2019, Fagundes and other defendants solicited funds from prospective investors over the internet, sometimes in combination with telephone and other means, and held the funds received in a manner that subjected it to regulation as a financial institution under Brazilian law, with which Fagundes and the other defendants failed to comply,” DoJ said.

Terrorists Funding Cryptocurrency

Earlier, the DOJ seized three cyber-enabled terrorist financing campaigns, involving the al-Qassam Brigades, Hamas’s military wing, al-Qaeda, and the Islamic State of Iraq and the Levant (ISIS).  Read more…

65% of Financial Services Firms Suffered a Cyberattack Last Year

Financial Sector

A new research, “Cybersecurity Challenges in Financial Services,” from data security provider HelpSystems revealed that 65% of major financial services organizations have suffered a cyberattack in the last 12 months. The research, which surveyed 250 CISOs and CIOs globally, highlighted the impact of COVID-19 on the cybersecurity of financial services firms. Nearly, 45% of respondents reported an increase in cyberattacks since the pandemic began. While securing the remote workforce has become a primary objective for 42% of organizations, 47% of firms have already invested in security collaboration tools.

Nearly 92% of organizations have increased their cybersecurity investment over the last 12 months. The main investment priorities for CISOs in the coming year include secure file transfer (64%), protecting the remote workforce (63%), and cloud/Office365 (56%). Over 50% of respondents believe that COVID-19 has brought a huge change in their security landscape.

According to the research findings, cybersecurity weaknesses in the supply chain (46%) and increased remote workforce (36%) are the major risks to organizations. “It’s a highly challenging cybersecurity landscape for the financial services sector, with many CISOs focused on battling day-to-day threats alongside trying to achieve broader strategic objectives. Technology is a key part of cybersecurity of course, and no organization will ever be secure without the right security solutions to protect the organization here and now. But of equal importance, especially for longer-term strategic goals, is ensuring the right processes are in place and educating and training employees,” said Kate Bolseth, CEO, HelpSystems

“Cyberattacks are growing in volume and severity, so financial firms need to not only protect the organization against day-to-day threats, but also make the transition to digital, meet regulatory demands, and secure a remote workforce in the light of COVID-19. It’s really tough and there’s no silver bullet, just constant evolution in the face of the changing threats,” Bolseth added.