Home Blog Page 156

Biggest ICO Fine! British Airways Fined £20 Mn over 2018 Data Breach

British Airways

The Information Commissioner’s Office (ICO) in the U.K. fined British Airways (BA) £20 million (approximately US$26 million) for failing to protect its customers’ sensitive information in a cyberattack in 2018. ICO’s investigation found that the airline was handling its customers’ data without adequate cybersecurity measures.

“The attack affected potentially 429,612 customers and staff, including names and financial details. British Airways failed to put in place a number of IT security measures, such as multi-factor authentication, and they were not aware of the attack until a third-party alerted them,” ICO said.

The data breach, which began in June 2018, was undetected for two months exposing the personal and financial details of more than 400,000 users. The compromised details included customers’ login, payment card, name, address, and travel booking information, which was collected by attackers after diverting users to a fraudulent website.

Biggest Fine till Date

In June 2019, the ICO issued a notice of intent to fine British Airways with £183.39 million (approximately US$230 million). However, the regulator decreased the penalty amount considering the economic impact of COVID-19 on their business.

“Because the British Airways breach happened in June 2018, before the U.K. left the EU, the ICO investigated on behalf of all EU authorities as lead supervisory authority under the GDPR. The penalty and action have been approved by the other EU DPAs through the GDPR’s cooperation process,” ICO added.

Information Commissioner Elizabeth Denham said, “People entrusted their personal details to BA and BA failed to take adequate measures to keep those details secure. Their failure to act was unacceptable and affected hundreds of thousands of people, which may have caused some anxiety and distress as a result. That is why we have issued BA with a £20m fine – our biggest to date. When organizations take poor decisions around people’s personal data, that can have a real impact on people’s lives. The law now gives us the tools to encourage businesses to make better decisions about data, including investing in up-to-date security.”

Related story: How Attackers Compromised British Airways Systems

State of Enterprise IT Landscape [INFOGRAPHIC]

Centrify, a provider of Identity-Centric Privileged Access Management (PAM) solutions, partnered with CensusWide to explore the state of enterprise IT landscapes six months into the global pandemic. The research revealed that nearly half of IT decision-makers’ companies had to accelerate their cloud migration plans (48%) and IT modernization overall (49%) during the COVID-19 pandemic.

Maintaining flexibility/security for remote work (38%) and digitizing more processes using cloud-native services (36%) remain the top two modernization priorities for the next 12 months. Nearly 60% of companies had to review and adjust their cybersecurity postures and supporting tools due to the sudden shift to a decentralized or distributed workforce.

Challenges of Distributed Workforce

  • Downtime or unexpected outages (59%)
  • Attempted breaches (23%)
  • Data loss (21%)
  • Phishing attacks (17%)
  • Insider threats (13%)
  • Ransomware (11%)

 

October is National Cybersecurity Awareness Month, and there is no better time to take stock of how organizations are staying ahead of digital transformation by migrating to the cloud, which introduces new attack surfaces that require granular access control. Our research shows that enterprises are learning from the pandemic and that the availability and flexibility gained in the cloud are must-haves in the new reality. This revelation will inform the world’s IT and security decisions long after COVID-19 diminishes at threat level.

 

– Flint Brenton, President and CEO of Centrify.

Complete results of the survey are available at http://bit.ly/CENSurvey.

Related story: Cybersecurity in Times of a Pandemic [INFOGRAPHIC] 

These are the Two Key Reasons Behind 65% of GDPR Fines

GDPR Fines

New analysis from data discovery firm Exonar revealed that organizations across Europe have suffered over £313 million (US$404 million) in GDPR fines for failing to protect customers/employees’ private data and not having appropriate cybersecurity in place.  Exonar claimed that so far 50 penalties totaling £482 million (US$ 622 million) have been issued under GDPR, in which 65% of them are mainly due to two key issues- insufficient security and storing unsecured data.

Nearly 39% of GDPR fines were due to insufficient security measures in organizations, which affected companies including British Airways, Active Assurances, and DSK Bank, totaling to £188,865,900 (US$ 243,727,981) fines to date. Storing unsecured data was responsible for 26% of fines totaling £123,663,350 (US$ 159,562,925) affecting high-profile organizations including Marriott, Deutsche Wohnen, and 1&1 Telecom.

In addition, illicit use of personally identifiable information (PII) and failing to comply with Data Subject Access Requests (DSAR) were responsible for 19% of fines totaling £92,055,300 (US$ 118,774,866). The remaining 16% fines totaling to £77,135,050 (US$ 99,540,611) were due to various issues like Uber’s failure to report a breach fast enough, Unicredit’s incorrect sharing of data, and H&M’s massive €35.2 (US$41.1 million) this month for unlawful use of employee data.

Exonar’s CEO, Danny Reeves, said, “Nearly 65% of GDPR fines were caused because of insufficient security and storing unsecured data. Securing your data first can play a vital role in not only meeting GDPR standards but also help mitigate the risk of the insufficient security – as it will be harder for hackers to access any data in the event of a breach. Reeves continued. Many organizations simply do not know what data they have got, or how much over-retained data they hold because it is no longer visible. Dark data like this is a point of weakness in any organization – and in order to fully secure the data, organizations need to first get a clear understanding of what data they hold.”

Related Story: Four Biggest GDPR Fines of 2020 

Cybersecurity Industry Sees Positive Trend in Salary and Job Satisfaction

96% of Cybersecurity Professionals are Happy With Their Roles

A survey from Exabeam, a cybersecurity and Security Information Event Management (SIEM) company, revealed that the cybersecurity industry witnessed a positive trend in salary and job satisfaction over the past three years. The survey, “The 2020 Cybersecurity Professionals Salary, Skills and Stress,” stated that 96% of respondents admitted they are happy in their role, and 87% are satisfied with their earnings. It also found an improvement in gender diversity in the sector, with female respondents increasing from 9% in 2019 to 21% this year.

Nearly, 53% said their jobs are either stressful or very stressful, which decreased from last year (62%).  100% of respondents aged 18-24 admit they feel secure in their roles and responsibilities and 93% are happy with their salaries. However, majority of the young employees are more concerned that technology will replace their roles despite 88% of cybersecurity professionals believing automation will make their jobs easier.

On automation software, 89% of respondents under 45 years said it will improve their jobs, yet 47% are still threatened by its use. On a geographic basis, 47% of the U.S. respondents were concerned about job security when automation software is in use, as well as Singapore (54%), Germany (42%), Australia (40%), and the U.K. (33%).

Samantha Humphries, Security Strategist at Exabeam, said, “The concern for automation among younger professionals in cybersecurity was surprising to us. In trying to understand this sentiment, we could partially attribute it to lack of on-the-job training using automation technology. As we noted earlier this year in our State of the SOC research, ambiguity around career path or lack of understanding about automation can have an impact on job security. It’s also possible that this is a symptom of the current economic climate or a general lack of experience navigating the workforce during a global recession.”

“There is evidence that automation and AI/ML are being embraced, but this year’s survey exposed fascinating generational differences when it comes to professional openness and using all available tools to do their jobs. And while gender diversity is showing positive signs of improvement, it’s clear we still have a very long way to go in breaking down barriers for female professionals in the security industry,” said Phil Routley, Senior Product Marketing Manager, APJ, Exabeam.

Lemon Duck Quacks Again with its Cryptocurrency-Mining Botnet

Coinbase, QNAP Devices

Researchers from Cisco Talos discovered a cyber campaign leveraging a multi-modular botnet to mine Monero cryptocurrency. The campaign dubbed as “Lemon Duck” uses a cryptocurrency mining payload that compromises computer resources and spreads the malware through various methods like sending infected RTF files using email, psexec, WMI and SMB exploits, including the infamous Eternal Blue and SMBGhost threats that affect Windows 10 machines. Cisco’s researchers also stated that Lemon Duck attackers use tools like Mimikatz to increase the number of systems participating in their mining pool.

While the Lemon Duck operators are active since the end of December 2018, the researchers noticed an increase in its activity at the end of August 2020. The exploits originated in Asia, with countries including the Philippines, Vietnam, and India. Some malicious activities have been recorded in Iran and Egypt and there are infected devices in the U.S. and Europe as well.

How Lemon Duck Operates

Cisco’s researchers revealed that Lemon Duck actors use over 12 independent attack vectors to distribute its malware payload. This includes compromising Windows devices by exploiting the BlueKeep vulnerability that exists in some versions of Windows. In Linux devices, attackers target vulnerabilities in Redis and YARN Hadoop.

They also send malicious attachments and spam emails to spread malware. Once the malware is downloaded on the victim’s device, it installs a PowerShell script that disables the system’s security feature to escape detection. “Its final delivered payload is a variant of the Monero cryptocurrency mining software XMR. It is one of the more complex mining botnets with several interesting tricks up its sleeve. Although it has been documented before, we have recently seen a resurgence in the number of DNS requests connected with its command and control and mining servers,” Cisco researchers said.

“Defenders need to be constantly vigilant and monitor the behavior of systems within their network to spot new resource-stealing threats such as cryptominers. Cryptocurrency-mining botnets can be costly in terms of the stolen computing cycles and power consumption costs. While organizations need to be focused on protecting their most valuable assets, they should not ignore threats that are not particularly targeted toward their infrastructure,” the Cisco researchers added.

How Hardware Security is Getting Weaker as the Industry Changes its Cybersecurity Models

cybersecurity practices, Automotive Cybersecurity

Cybersecurity in the last few years has become one of the biggest challenges in the computing world as the impact of cyber compromises has reached an all-time high.  Although increased efforts are being made to suppress cyberattacks, many of the cybersecurity solutions being implemented today are ineffective – in fact, they are moving in the wrong direction to keep up with the increasingly sophisticated world of hacking.

By Rob Pike, Founder and CEO, Cyemptive Technologies

Although artificial intelligence (AI) and machine learning (ML) technologies are being touted as a solution by attempting to solve the problem faster, the scale and frequency of cyber compromise have still gotten worse during the last five years at an alarming rate.  The time for hackers to break into any environment and extract data out of a network is measured in seconds and minutes while detection is still measured in days, weeks, and even months, after the compromise has occurred.  At the same time, the detection technologies are hitting such high false positives and false negatives, it causes a decline in progress on detecting and stopping the elite hackers of the world, making it almost impossible to stop them.  Even the less experienced hackers have gained traction on infiltrating networks and systems with the use of AI tools.

On top of all that, we have new industry standards and directions for a hardware design that we believe is significantly eroding the levels of network security.  The changing design, combined with the failure of cybersecurity solutions to protect against cyberattacks, is resulting in weaker security at the hardware level – so much so that hackers can potentially access your computer, even when it is turned off.

The Problem with AI and Cybersecurity

AI (along with machine learning) can operate faster and more efficiently than humans and other technologies to identify and detect against hackers and their various forms of cyberattacks, the thinking goes.

The one big comment that most people who talk about AI for cybersecurity do not explain is that AI stands for “Already Infiltrated” to the top cyber insiders of the world. AI is too little too late.

The problem with artificial intelligence is that although it can be faster and more efficient than other technologies, it simply cannot keep up with the frequency and speed of today’s cyberattacks, which can take place in seconds to minutes.  Even with AI and ML, today’s cybersecurity solutions take days to weeks or even months to detect attacks.  By that time, the hackers have gotten in and the damage has been done.

Changing Hardware Security Standards

At the same time, hardware providers are changing their security standards at the hardware level.  Many are moving in a direction away from supporting legacy BIOS, to only supporting UEFI.  With UEFI, security layers are added to the UEFI stack.  Settings are controlled by custom applications added to the UEFI web application stack.

The idea behind UEFI is to provide more manageability to infrastructure.  However, as is the case with any new standards, there are also new issues that arise.  Such is the case with the UEFI security approach.

Security Issues with the New Hardware Standards

With the UEFI approach to security, hackers have the potential to gain control over the hardware before the operating system is booted – in some cases enabling full network stack before an operating system is booted.  This design enables hackers anytime access to hardware even when it is powered off.

For example, at Cyemptive, we see numerous worms and exploits from hackers on the UEFI web application stack.  In addition, the issues we are encountering in the operating system’s web application stacks are now showing up in the UEFI layer, because they are enabling similar application stacks to be loaded.  This in turn causes more exploits that weaken, not strengthen, the security model.  What should be simple is now turning into a complete mess.

As part of this, with the UEFI security approach, there are thousands of lines of code involved.  All are potentially available to hackers at the physical hardware layer of our systems.  At Cyemptive, we regularly detect multiple hacks against our customer’s UEFI.  While Cyemptive is able to detect and prevent these attacks from entering their systems, UEFI is a long way from being able to secure systems properly and to be called a secured platform.

Solutions

 What is needed now is for hardware providers to step back and take a look at the UEFI security approach.  At present, adding thousands of lines of code to firmware – which is the case with UEFI – is now allowing hackers remote access to our laptops, workstations, and servers, even when they are turned off.  Instead, hardware providers should consider moving back to a more simplified model.

For years, legacy BIOS has been the standard for hardware providers.  It is a worthwhile standard to consider going back to.  Legacy BIOS has seen far fewer security problems than what is now showing up in the current UEFI implementations.  It also doesn’t enable hackers to remotely hijack into the systems stack before an OS is enabled, the way UEFI does.

Conclusion

What the industry should do now is to remove the thousands of lines of code that presently allow hackers remote access to our physical hardware layer of systems today.  Relying on the application stacks in the firmware is not the proper way to secure hardware.  Rather, a different approach is needed, and sometimes simplest is best. Legacy BIOS offers stronger security than UEFI.

Although UEFI can offer companies more manageability in their infrastructure, enabling hackers to remotely hijack into the systems UEFI stack before an operating system is enabled is the wrong approach to cybersecurity. After all, manageability is useless if the hackers in the world can use the same tools to take control of the hardware and OSs running on that hardware.  Let’s prevent hackers from having remote control of our laptops, workstations, and servers, even when turned off.


About the Author

As Founder and CEO of Cyemptive Technologies, a provider of pre-emptive cybersecurity products, Rob Pike brings a wealth of experience in creating new technologies and bringing them to market for companies both large and small.  Pike founded Cyemptive in 2014, with his vision of ushering in a new era of cybersecurity.  Working in stealth mode, the company focused on developing a revolutionary approach to solving cyberthreats, using a preemptive strategy to remove hackers and threats in real-time.  He also has served as Chief Strategy Officer at Hitachi Data Systems in Japan, where he invented Hitachi’s cloud platform UCP, as well as at Microsoft, where he served in a variety of capacities culminating with Virtualization Architect and invented an internal cloud solution.  He has founded several startups, in addition to Cyemptive Technologies.  Pike holds numerous patents in servers, storage, networking, monitoring, security, and management.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

EY Partners with CrowdStrike for Cyber Risk Management Capabilities

Partnership

Popular risk consulting firm Ernst & Young (EY) announced its partnership with cloud-delivered endpoint security provider CrowdStrike to integrate cybersecurity operations and risk management within organizations. The EY-CrowdStrike alliance integrates CrowdStrike’s cybersecurity technologies with consulting capabilities and cybersecurity services provided by EY. The collaboration also offers comprehensive security services to help clients better identify, prevent, and respond to cyberthreats.

With the new collaboration, EY professionals can now help clients achieve their cybersecurity objectives by leveraging CrowdStrike’s Falcon platform to provide deep insights into cyber risks within their organizations. In addition, enterprises across major industries like financial services, health care, retail, manufacturing, and energy can gain risk insights to help enable better business decision-making from the security operations center to the boardroom

Dave Burg, EY Americas Cybersecurity Leader, said, “Implementing quality cybersecurity technology is essential as cyberattacks become increasingly advanced and prevalent. EY professionals can combine transformational consulting experience with the CrowdStrike platform to help businesses establish proactive cybersecurity plans to both mitigate and prevent potential cyberattacks.”

George Kurtz, Co-Founder and CEO, CrowdStrike said, “CrowdStrike Falcon has been selected by businesses worldwide as a transformative solution that delivers simplicity, speed and efficacy for an overwhelming cybersecurity threat operations landscape, helping security teams to quickly identify and stop breaches before they occur. Being named an EY preferred technology platform for security services provides the benefit of collaborating on innovating and leading transformational consulting services to aid organizations in achieving maximum value in cybersecurity operations – positively impacting business objectives and elevating the cybersecurity conversation from the security operations center to the boardroom.”

Barnes & Noble Cyberattack May Have Unknowingly Compromised Customer Info

cyberattacks on U.S. and U.K., Barnes & Noble cyberattack, zero trust

Barnes & Noble is one of the biggest bookselling retail chains in the U.S. However, the era of e-books or Kindle Reader took a bit of its shine away. To compete with the changing times, the bookseller launched its Nook online service in 2009. Nook is an e-book reader and storage platform made available to users as a paid premium service. However, this adoption of digitization may have just cost Barnes & Noble dearly as a cyberattack may have potentially compromised their user data.

The When and What of the Cyberattack

In an email to its customers, Barnes & Noble informed customers about being a victim of a cyberattack on Saturday, October 10, 2020, when it detected unauthorized access to its corporate systems. However, the company assured that there is no visible proof of payment details of customer purchases being exposed as they always keep all credit card payment and financial information encrypted and tokenized to protect from such malicious incidents.

Despite taking these measures, the bookseller said that there was personal information stored on the compromised servers, including customers’ email addresses, billing and shipping addresses, and telephone numbers that could have been compromised and leaked during the cyberattack.

Additionally, the compromised servers also contained information of customers’ past transactions, revealing a history of books and other products that have been purchased from the retailer in the past. This information can potentially be used for targeted social engineering attacks.

The confirmation of the cyberattack came after a weekend of complaints from Barnes & Noble customers who said they were unable to download books they had purchased for their Nook e-book readers. To this, Nook initially reported a system failure that was interrupting its content.

What Experts Say

Discussing the cyberattack incident, Ilia Sotnikov, VP of product management, Netwrix, told CISO MAG, “The recent breach at Barnes and Noble shows us that we now live in a new reality when ransomware attacks and data breaches happen every week. If financial or healthcare data is not involved, we don’t even pay special attention to such news.

While the Barnes and Noble team did their best to protect their customers by encrypting cardholder data, I would like to highlight the importance of good old cybersecurity measures such as proper network segmentation. System breakdown often follows a data breach. It puts additional pressure on IT teams that need to do both, mitigate the attack, and keep the system up and running. Else, such incidents prevent customers from making their purchases, which may lead to their frustration and add to the company’s financial losses.

Network segmentation is a cornerstone to combat ransomware. If done correctly, the virus that started in the corporate office should not have made its way to the cash desks and prevent orders from being placed. Also, it limits the attack surface, and makes it easier to investigate the incident and close security gaps.”

How IoT Will Transform Industrial Control Systems Security

Industrial IoT

While the digitalization of industrial infrastructure is ongoing, over 55% of organizations believe that the Internet of Things (IoT) will transform the cybersecurity posture in Industrial Control Systems (ICS). A research from Kaspersky revealed that 20% of organizations have already prioritized IoT-related security incidents. Cyberattacks on the Industrial Internet of Things (IIoT) has become a primary security concern for 1 in 5 organizations.

Addressing these issues require highly skilled security professionals than regular IT teams. It became a challenge for most organizations as 44% of security personnel in 50% of the enterprises surveyed are working on initiatives to protect digitalized OT systems. While 19% of enterprises implemented traffic monitoring services, 14% have introduced network anomaly detection as these solutions allow security teams to track anomalies or unauthorized activities in IoT systems.

Kaspersky also recommended certain steps to ensure their IIoT systems are used effectively and securely:

  • Consider protection at the very beginning of IIoT implementation by using dedicated security solutions.
  • Assess the status of a device’s security before its implementation. Preferences should be given to devices that have cybersecurity certificates and products from those manufacturers that pay more attention to information security.
  • Conduct regular security audits and provide the security team responsible for protecting IoT systems with up-to-date threat intelligence.
  • Establish procedures for obtaining information on relevant vulnerabilities in software and applications, and available updates to ensure proper and timely responses to any incidents.
  • Implement cybersecurity solutions designed to analyze network traffic and detect anomalies and prevent IoT network attacks, then integrate the analysis into the enterprise network security system.

Grigory Sizov, Head of Kaspersky business unit said, “While industrial enterprises will only increase the implementation of connected devices and smart systems, they should strive for the same efficiency level when it comes to protection. To achieve this, protection should be built-in when a project is initiated, and for some companies, it should be done today. IIoT components must be secure at their core to eliminate the possibility of an attack on them. Along with traffic protection and other technologies, this makes the entire system secure by design and this means it becomes immune to cyber-risks.”

DFS Calls for Cybersecurity Protection of Social Media Platforms After Twitter Hack

blockchain-based social media, Parental Consent for Minors, Iranian Facebook accounts

The New York State Department of Financial Services (DFS) released a notification calling for a new cybersecurity regulatory framework for social media companies following an investigation on high-profile Twitter hacks in July 2020. The DFS stated that social media platforms lack adequate cybersecurity measures and did not have a CISO.

The DFS, in its investigation report, said that Twitter and other popular social media networks do not have a dedicated federal or state regulator to address the security risks to their digital operating models. These companies are mostly self-regulated and have no accountability for significant cybersecurity lapses. The DFS added that all social media firms, whose platforms reach millions of people globally, should be designated as critical institutions with prudent cybersecurity regulations.

“The Department is issuing this report to alert consumers and voters as they prepare to exercise their basic rights in American democracy, in one of the most consequential elections in generations,” the DFS said.

The recommendations come after the report disclosed the facts surrounding the Twitter hack and the reasons it occurred, which include:

  • The hackers accessed Twitter’s systems with a simple technique: by calling Twitter employees and claiming to be from Twitter’s IT department.  After the hackers duped four employees into giving them their login credentials, they hijacked the Twitter accounts of politicians, celebrities, and entrepreneurs, including Barack Obama, Kim Kardashian West, Jeff Bezos, Elon Musk, and several cryptocurrency companies regulated by the Department – accounts with millions of followers.
  • The hackers tweeted simple “double your bitcoin” messages, with a link to send payments in bitcoins. In the end, they stole over $118,000 worth of bitcoins from consumers.
  • The Department’s regulated cryptocurrency companies, Coinbase, Square, Gemini Trust Company, and Bitstamp responded quickly to block attempted transfers to the Bitcoin addresses the fraudsters used.
  • Despite being a global social media platform boasting over 330 million average monthly users in 2019, Twitter lacked adequate cybersecurity protection.  At the time of the attack, Twitter did not have a chief information security officer, adequate access controls and identity management, and adequate security monitoring – some of the core measures required by the Department’s first-in-the-nation cybersecurity regulation.

“Social media platforms have quickly become the leading source of news and information, yet no regulator has adequate oversight of their cybersecurity. The fact that Twitter was vulnerable to an unsophisticated attack shows that self-regulation is not the answer. As we approach an election in fewer than 30 days, we must commit to greater regulatory oversight of large social media companies. The integrity of our elections and markets depends on it. The swift and effective response of DFS-regulated cryptocurrency companies illustrates how effective regulation can foster innovation and growth, while also protecting consumers,” said Superintendent of Financial Services Linda A. Lacewell.