Home Blog Page 176

Start Measuring Your Cybersecurity Maturity Today

Security

We, cybersecurity professionals, have been hiding behind lies for a few years now.

“Cybersecurity is a new industry. There is not enough data to measure maturity”

“Maturity models work where there are well-defined processes to follow. Like software development. Not cybersecurity. We live a new problem every day.”

All hogwash. Or as Roald Dahl’s BFG would put it – ‘Redunculus.’

It’s about time CISOs stop making excuses – and started taking concrete steps to measure their cybersecurity maturity.

By Chaitanya Kunthe, Co-founder and Chief Operating Officer at Risk Quotient

What exactly is a maturity model?

Every CISO has faced existential questions like these:

Is our cybersecurity improving? What do we do to improve further?

Are we better off today than we were last year? How do we know that?

Capability and maturity models answer these questions. For more details read this paper.

A maturity model allows an organization to assess its practices against a clear set of benchmarks. Evaluating against these benchmarks provides an organization with a clear understanding of where they currently are and provides a roadmap to improve its maturity.

There are two types of maturity models – ‘progression’ models and ‘capability’ models. Combining the two creates a third type – hybrid.

Progression Models: Logs enabled and reviewed on servers → Centralized Logging and Alerting → SIEM implemented. Here, the core requirement is the monitoring of logs. What changes is the way monitoring is done. Automated ways of doing things move you up the ranking. You progress from a manual way of doing things to an automated way of doing things.

Capability Maturity Models: Ad hoc event reporting → Defined events and incidents → Risk-based event and incident monitoring and reporting. Here, the core requirement is reporting and managing incidents. The focus is on process maturity. You progress from an ‘ad-hoc’ process to a managed and measured process.

Both of these models have certain inherent problems. The progression model might lead you down a very sticky ‘tool’ driven path where the solution to every problem would be to implement a new tool. The capability maturity model can take you down a very theoretical path of ‘measured,’ ‘monitored,’ ‘managed’ and creating MBs of documents and processes. The hybrid model blends the best part of both these approaches.

Hybrid Models: Incidents reported in an ad-hoc manner → Criteria for reporting defined. Central Logging enabled → Pattern analysis to detect incidents automatically, risk-based incident scoring. A hybrid model uses a mix of both progression and capability maturity models.

Why go for a cybersecurity maturity model?

Measuring cybersecurity is like trying to find that irritating noise in your car. You know it is there. You can hear it. You just don’t know where it is. You know you have to measure cybersecurity effectiveness. You just don’t know what to measure and how.

Is your cybersecurity effective? There are two ways to find out – the simple way and the hard way.

The simple way is to go through a third-party audit and certification. Rely on global standards like ISO 27001, PCI-DSS, NIST-CSF. Hire auditors. Trust that the auditors you have hired understand your environment and assess you. In a fair and accurate manner that it improves your cybersecurity.

The hard way is to define your own metrics and measurement based on risks. This is way more effective, but a self-assessment is not what your customers and regulators will accept easily.

In both these methods, you do not have a clear path to improvement. Cybersecurity maturity frameworks give you this path (Not to mention it helps getting budgets approvals).

Which one, then?

If you’ve read so far, you are probably wondering which framework to go for. Veterans in information security would recollect a maturity model called the SSE-CMM. Systems Security Engineering – Capability & Maturity Model. The SSE-CMM website no longer exists, but you can see what the standard was like by visiting this URL: SSE-CMM Home Page.

This was way back in 2003. Then for more than a decade, no one spoke of cybersecurity maturity. Today, there are two good cybersecurity maturity frameworks that you can choose from.

The first one is the Cybersecurity Maturity Model Certification (CMMC) from the U.S. Department of Defense. This model is in the news as it is now mandatory for defense contractors in the U.S. to certify themselves on the CMMC. The CMMC is a hybrid model. There are five maturity levels in the CMMC.

  • Level 1 – Performed
  • Level 2 – Documented
  • Level 3 – Managed
  • Level 4 – Reviewed
  • Level 5 – Optimizing

The maturity levels combine with the 17 domains of NIST 800-171 to make the model.

-NIST 800-171

The second framework comes from the U.S. Department of Energy. It is the Cybersecurity Capability Maturity Model or the C2M2. C2M2 was built for critical infrastructure in the energy sector. It has now expanded to include models specific to the electricity sub-sector and the oil and natural gas sub-sector. Further sector specific models are planned too.

This framework has four maturity indicator levels (MIL)

  • MIL0 – No practices
  • MIL1 – Ad-Hoc practices
  • MIL2 – Initial level of institutionalization of practices
  • MIL3 – Further institutionalized and managed

C2M2 model has 10 domains. You can be on different levels in different domains.

C2M2 Domains

Another interesting maturity model to consider is the FISMA metrics. Again, a U.S. government initiative. It focuses on maturity around five function areas of Identify, Protect, Detect, Respond, and Recover, though it might not directly map to NIST-CSF.

How should you go about it?

Go through the domains of both the standards and choose the framework most appropriate to you. Perform a self-assessment – know where you stand. Be ruthlessly honest about it. If you have a trusted and mature third party who can do the assessment for you, bring them in.

The self-assessment is the beginning. What you do after that is more important. Create a dashboard of the domains and your maturity at each domain and control. Define a ‘to-be’ maturity goal for your organization. Get the relevant stakeholders to agree on this goal. This dashboard becomes your maturity tracker. Implement practices and controls as required and regularly assess yourself for where you stand. Involve the security leadership, else it will reduce to a compliance show that you put up.

A word of warning: Do not go about this exercise as a simple compliance exercise – else you will be subject to the same problems as any other compliances that you maintain. For more information, read:

Cybersecurity Maturity Model Certification: An Idea Whose Time Has Not Come And Never May

If you choose to go about this exercise, then here are some tips to make it effective:

  • Involve the security leadership, else it will reduce to a compliance show that you put up.
  • Focus on improvement and measuring that improvement (through your dashboard). Not only on moving up maturity levels.
  • You do not have to be at the highest maturity level. Choose your goals wisely based on your risks.

Finally, remember, any exercise of cybersecurity maturity and measurement can be effective or ineffective based on the intent behind the exercise. Choose wisely.

About the author

Chaitanya KuntheChaitanya Kunthe is a seasoned cybersecurity mentor who believes in simplifying things. He is the Co-founder and Chief Operating Officer at Risk Quotient, where he mentors the team to provide innovative and practical cybersecurity advice.

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

8 in 10 Consumers are Concerned to Share their Personal Data to Companies

Experian API Flaw

According to a latest survey from security firm Privitar, nearly 78% of consumers globally are concerned or very concerned on personal data protection and more than 50% of them still wary of sharing their personal data with companies. In its survey report “2020 Consumer Trust and Data Privacy Report”, Privitar found that more than three-quarters of respondents are concerned or very concerned about protecting their personal data, with 42% of consumers admitted that they wouldn’t share sensitive data with a business for any reason.

Consumer Sentiment vs Data Protection

The research revealed that most of the consumers aren’t fully aware of how organizations are securing their personal information, with 43% of consumers stating that they don’t know if they’ve worked with a business that has been impacted by a data breach. While 28% admit to not reading privacy notices at all, 42% admitted to only skimming the text. Around 51% said they are still not comfortable sharing their personal information. One-third of respondents said they are most concerned about data being stolen in a breach with 26% worried about it being shared with a third party.

When asked about sharing health care data, only 27% of respondents said they would share health information for health care advancements and research. Another 21% of consumers surveyed would share health data for contact tracing purposes.

Data Privacy Builds Customers’ Loyalty

The report stated that “When working with a business, 40% of consumers think the brand’s trustworthiness is most important when it comes to brand loyalty and 31 percent say it is the brand’s commitment to protecting their data. Evenly matched up with the 30 percent of consumers who believe customer service matters most, the results prove that data protection is just as critical to keeping customers coming back for more.”

However, the survey also highlighted that broken trust and lost responsibility for protecting that data have severe consequences, with 24% of respondents said that they have either stopped doing business or done less business with a company after it was breached.

Jason du Preez, CEO and co-founder of Privitar, said, “The global COVID-19 pandemic has underscored the importance of the trust relationship companies and governments need to build with consumers in an increasingly digital world,” “The results of the survey affirm the growing need for brands to focus on building and maintaining this trust, starting first and foremost with protecting customer data. As more businesses utilize the cloud to enable data driven insights, a firm commitment to data privacy will help to ensure long-term loyalty, consumer satisfaction and shareholder value.”

Unsecured Internet-connected Printers at Risk of Getting Hijacked

HP multi-function printers, Unpatched vulnerabilities

Security researchers from CyberNews warned that cybercriminals could take advantage of unsecured internet-connected printers to control corporate networks and access sensitive information like device names, locations, device models, firmware versions, IPP (Internet Printing Protocol) port, and Wi-Fi SSIDs. In a bid to make users aware of the potential cyberthreats associated with connected printers, the CyberNews security team hacked over 27,944 vulnerable printers globally and forced them to print a document.

The Experiment

The researchers found more than 800,000 unsecured printers online by using Internet of Things (IoT) search engines based on the printer location, manufacturer, and protocols used to access the printers. All these open devices use common printer ports, protocols, and were accessible over the internet. Out of 800,000, the research team successfully targeted around 500,000 printers.

“After selecting a sample of 50,000 open printers and creating a custom printing script, we managed to print out PDF documents on 27,944 unprotected devices,” CyberNews said.

The Result

The researchers stated that they were able to compromise vulnerable printers using their customized printing script. “We managed to hijack 27,944 printers out of the 50,000 devices that we targeted, which amounts to a 56% success rate. Taking this percentage into account, we can presume that out of 800,000 internet-connected printers across the world, at least 447,000 are unsecured. These numbers speak volumes about the general lack of protection of networked devices worldwide,” the researchers said.

How to Secure Your Printer

CyberNews stated that the safety of the internet-connected printers can be ensured by:

  • Securing your printing ports and limiting your printer’s wireless connections to your router
  • Using an updated firewall
  • Updating printer firmware to the latest version
  • Changing the default password

“Many users and organizations still use internet-connected devices without thinking about security, installing firmware updates, or taking into account the implications of leaving their devices publicly accessible. This means that the humble printer remains one of the weakest links in the security of both organizational and home networks,” CyberNews added.

 A Persistent Threat

Similar research from Quocirca revealed the risks of unsecured printers. It stated that 60% of businesses in the U.K., the U.S., France, and Germany suffered a print-related data breach last year, which resulted in a data loss that cost companies an average of more than $400,000. In addition to financial loss, data breach victims also suffer damage to productivity, consumer confidence, and brand value, the report said.

Ransomware Attack on Paytm Mall! ‘Data Safe and Secure,’ Says Company

BlackMatter Group, Volvo Cars ransomware attack

Cyber intelligence firm Cyble claimed that a threat actor group “John Wick” demanded ransom after gaining unrestricted access to a database belonging to Paytm Mall, an e-commerce unit of payment solutions provider Paytm. Cyble stated that the group uploaded a backdoor/Adminer on the company’s website to obtain access to their production database and compromised all accounts and related information of Paytm Mall.

An Insider Job!

According to Cyble, an insider is suspected to have helped the cybercriminal group gain access to Paytm Mall’s database. While the volume of the data breach is unknown, the hackers demanded 10 Ethereum (equivalent to US$ 4,000). Cyble also reported that John Wick, under the alias “South Korea” and “HCKINDIA,” targeted multiple Indian organizations earlier for ransom.

“According to the messages forwarded to us by our source, the perpetrator claimed the hack happened due to an insider at Paytm Mall. The claims, however, are unverified, but possible. Our sources also forwarded us the messages where the perpetrator also claimed they are receiving the ransom payment from the Paytm Mall as well. Leaking data when failing to meet hackers’ demands is a known technique deployed by various cybercrime groups, including ransomware operators. At this stage, we are unaware that the ransom was paid,” Cyble said.

Paytm in Denial

The authorities at Paytm Mall denied the data breach allegations saying that the company’s data is secure.

“We would like to assure that all user, as well as company data, is completely safe and secure. We have noted and investigated the claims of a possible hack and data breach, and these are absolutely false. We invest heavily in our data security, as you would expect. We also have a Bug Bounty program, under which we reward responsible disclosure of any security risks. We extensively work with the security research community and safely resolve security anomalies,” Paytm Mall said in a media statement

“COVID-19 is a humanitarian crisis but also emerging as a data security challenge”

Nikhil Korgaonkar on data security and protection

Data security has become the talk of the town and is being discussed over a cup of coffee to a beer in hand, and from board rooms to pool tables. Even world-renowned leaders and dignitaries like the Democratic nominee for President, Joe Biden, and the Hon. Prime Minister of India, Narendra Modi, are taking note of these trends and levelling up their game to match the sophistication of the threats at bay. So, we decided to take the discussion forward with a veteran in this field and get a deeper insight into what exactly is this fuss around data security all about.

In an exclusive interview with Mihir Bagwe, Tech Writer at CISO MAG, Nikhil Korgaonkar, Regional Director, Arcserve India & SAARC, tells us how data security has continued to evolve even in times of the COVID-19 pandemic and the threats that organizations are facing. Additionally, he also sheds some light on the data security and privacy policies that organizations of different sizes are abiding by around the world for the greater good of the people.

Korgaonkar comes with 20+ years of experience in this field and has worked with Dell India, Symantec – Veritas, DHL, Wockhardt, and is currently serving at Arcserve. As the Regional Sales Director with Arcserve, he manages the India and SAARC P&L. He is extensively involved in internal and customer policymaking.

Let’s take a look at the edited excerpts of the Q&A below:

1. Worth of Data

Nikhil Korgaonkar on data security and protection

A.  Businesses are doing a lot to protect their online systems, but not nearly enough to protect the data that enables them to keep operations running in the event of a disaster or cyberattack. One of the more challenging aspects is that there is often a disconnect between their cybersecurity and data protection stances, and the two are often found functioning in silos within organizations, with separate budgets, solutions, and processes. What we need instead is a comprehensive strategy to ensure the security of both systems and data, as well as a Disaster Recovery and Business Continuity Plan that is well-tested and implemented. By implementing an integrated strategy and solution, organizations have a first and last line of defense against cyber threats and data loss.

2. The Need for a Universal Data Regulatory Body

Nikhil Korgaonkar on data security and protection

A. Businesses are reeling under the challenge of what we call compliance fatigue. GDPR in Europe; HIPAA, SOX, and FACTA in the U.S.; the California Consumer Protection Act, which came into force earlier this year; LGPD in Brazil; there is a multitude of compliance regulations that businesses face today. According to an estimate, CISOs spend 30% of their time dealing with compliance issues, an indication of how much productive mind space is being consumed by the fragmented regulatory landscape. There is certainly a need for a universal regulatory body and policy relating to data protection and privacy.

For that to happen, however, all the countries will need to come up with the same level of data security preparedness and understanding. It will have to be a symphony where each player plays their part to bring out a well-coordinated piece, which is music to everyone’s ears.

Meanwhile, we have every country drafting their version of a cybersecurity policy, which is a welcome move as it shows the seriousness of intent about data protection. In India too, the Prime Minister recently announced the government’s intent to formulate a National Cybersecurity Policy, which is a welcome move. This initiative will boost the adoption of data protection measures and stronger policies that shall protect the privacy and interests of customers, businesses, and the public of the country. Formulation and adoption of policies might still take time, but this is a clarion call to the Indian internet users to pay attention to such attacks, create robust ‘firewalls,’ and conduct regular cybersecurity and data protection audits.

3. Guarding the Remote Workforce

Nikhil Korgaonkar on data security and protection

A. A remote and fragmented workforce poses several security risks since remote workers are outside the secure periphery of the organization. With more employees working from home, cybercriminals have more access points to exploit networks. A comprehensive security infrastructure is therefore critical to securing remote access and ensuring the organization can back up the data their employees are producing on their laptops to reduce the risk of data loss. This infrastructure must include centrally managed, cloud-driven cybersecurity, and data protection solutions with enhanced detection and response, ransomware protection, and firewalls, among other things. Lack of data back-up is one of the weak links in the remote access security chain. Many users assume that cloud-based SaaS apps like O365 are automatically backed up. That is simply not the case.

Making investments in third-party remote backup tools is essential to mitigate the risk of data loss when the company starts working from home (or even when it does not!). Centrally managed cloud-to-cloud backup and DR solutions are ideal for remote work situations, which is especially important since most remote workers are not likely to have proper security and data protection measures at home.

Last but not the least, educating employees on cyber hygiene and regular testing of apps is key to ensuring a well-synchronized approach to secure remote access.

4. Impact of “EU-U.S. Privacy Shield” Invalidation

Nikhil Korgaonkar on data security and protection

A. The European Court of Justice (ECJ) annulled the “EU-U.S. Privacy Shield” framework, citing gaps in the data security measures of the U.S. Surveillance Law. It regards them as inadequate to protect the data privacy rights of the EU citizens as defined under the General Data Protection Regulation (GDPR). Europe is known to be very proactive and sensitive to the issue of data privacy and their concern is understandable. On the flip side, this is likely to hit hard, the small and medium enterprises doing business with Europe. The alternative for them is to sign the Standard Contractual Clauses, which is not an easy process. There is a clause within GDPR that will still enable necessary data transfer, but the exact contours of what is deemed necessary and whatnot, are yet to become clear. This looks like a major setback to transatlantic trade, but businesses must work together with their security partners to understand how best they can navigate the situation and ensure business continuity.

5. COVID-19 and Data Security

Nikhil Korgaonkar on data security and protection

A. The COVID-19 pandemic is a humanitarian crisis, but it is also emerging as a data security challenge. Cybercriminals are rampant during this crisis and are increasingly targeting businesses due to the remote and fragmented nature of the workforce currently. According to an IBM estimate, there has been a 4300% increase in the Coronavirus-themed spams. As early as March 28, 2020, just a few days into the COVID-19 lockdown in India, CERT-In stated that cyberattacks on personal computer networks and routers had increased exponentially. They stressed on the importance of deploying VPNs to better protect sensitive data.

6. Bridging the Cloud

Nikhil Korgaonkar on data security and protection

A. Cloud providers strive to provide the best security standards, but security breaches do happen. It is important for businesses to assess the security levels of their cloud providers. Datacenter security certifications, physical security standards, security audit reports, encryption policies for in-flight, and at-rest data are some of the key parameters you should look for before deciding upon a cloud provider. Cloud backups are crucial to ensure business continuity in case of an inevitable attack. On-premises back-ups can be compromised too, and offline data stored in physical storage devices may not be up to date, besides being slow to retrieve. A secure cloud backup integrated with proven cybersecurity technology provides the best of both worlds in terms of business continuity, but businesses must ensure they do their due diligence before choosing their cloud partner.

7. Challenges Faced

Nikhil Korgaonkar on data security and protection

A. Enterprise-grade cloud services offer elevated levels of security, but data breaches can happen when data is in transit or is in interaction with other systems. We see more cyberattacks aimed at the backups themselves. It is therefore important to check the encryption standards for in-flight and at-rest data. Multi-tier encryption is key to ensuring that in-flight data remains secure, while AES encryption is key to at-rest data. Compliance is another area where businesses need to be extremely vigilant because as owners of data, they will be ultimately responsible for any compliance breaches. There are multiple compliance regulations to take care of today, including GDPR, HIPAA and OHSAS, FINRA, FERPA, and other regional regulations. A cloud provider needs to demonstrate the expertise to navigate this complex regulatory landscape and offer security and privacy standards that are compliant with all these regulations.

8. The Risks of the Third-Party

Nikhil Korgaonkar on data security and protection

A. Outsourcing non-core business processes, customer and proprietary data, and partnering with vendors in infrastructure, security and other support services is intrinsic to the business models of most companies today. This makes them vulnerable to unauthorized data access, security breaches, malicious use by insiders, and other threats that are beyond the business’ control.

Businesses must therefore ensure that they do their due diligence before trusting an external vendor or parting with their data. This involves assessing all the standard processes such as datacenter certifications, security protocols, compliance standards, and policies relating to the handling of data in transit. Businesses must also ensure that they safeguard all the rights to their own data stored with a third party, including the right to deny certain kinds of processing, right to rectify or forget certain data, right to transfer it to another partner, and so on. Most importantly, businesses should ask for copies of their data being handled by third party vendors and ensure they back-up these copies regularly

9. Latest Trends

Nikhil Korgaonkar on data security and protection

A. Cybercriminals are intent on staying one step ahead and are constantly evolving their methods to gain access and hold data hostage. For example, one of the trends we are seeing is ransomware focused on the backups themselves – which are critical for organizations to have available in the event they become infected and data encrypted. If an organization does not have access to current backups, whether on-premises or in the cloud, they are really at the mercy of the cybercriminals. Moreover, organizations in industries such as manufacturing must be aware that more cybercriminals are now aiming at their production facilities, going beyond holding data hostage. Stealing data is one thing, but shutting an organization or its production systems down is another new and highly concerning threat.

10. Suggestions for Businesses

Nikhil Korgaonkar on data security and protection

A. With larger attack surfaces driven by telecommuting and exponential data growth, and cybercriminals set to prey on new vulnerabilities, organizations must have a proactive approach that combines cybersecurity and data protection. Protecting an infrastructure from security threats, data loss, and downtime is tough enough. But juggling multiple strategies, processes, vendors, SLAs, and support teams only adds complexity and leaves organizations open to security gaps and data erosion.

The only way to become truly cyber ready is to deconstruct their siloed operations with technology that works together to securely back up mixed workloads, detect and prevent attacks, respond and prevent threats, and instantly restore data if needed. This brings organizations a first and last line of defense against cyberattacks and data loss while removing complexity and improving SLAs.

About the Interviewer

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 


Other Posts from the Author:

Research Finds Increase in Botnet and Exploit Activity in Q2 2020

Research Finds Increase in Botnet and Exploit Activity in Q2 2020

A recent research from Nuspire, a managed security services provider (MSSP), revealed new cybercriminal activities and tactics, techniques, and procedures (TTPs) adopted by threat actors. In its research, “Q2 2020 Quarterly Threat Landscape Report,” Nuspire stated that as organizations are settling into remote working conditions, new attack vectors for cybercriminals and new challenges for security administrators are been introduced.

The research found an increase in botnet and exploit activity in the Q2 2020 by 29% and 13% respectively, which is more than 17,000 botnet and 187,000 exploit attacks a day. While attackers targeted remote work technology at the source to obtain access to the enterprise in Q1 2020, the research found hackers changed their attacking tactics to leverage botnets to obtain a foothold of the targeted network systems. Home routers typically are not monitored by the IT teams, and therefore have become a viable attack method that avoids detection while infiltrating corporate networks.

“Now six months into the pandemic, attackers pivoted away from COVID-19 themes, instead utilizing other prominent media themes like the upcoming U.S. election, and exploiting the Black Lives Matter movement to wreak havoc,” the report said.

Other notable findings from the research include:

  • The ZeroAccess botnet made a resurgence in Q2, coming in second as the most used botnet. ZeroAccess was originally terminated in 2013 but has made rare resurgences over the last seven years.
  • Nuspire also witnessed a significant spike (1,310% peak mid-quarter) in exploit attempts against Shellshock, an exploit discovered in 2014, demonstrating that attackers attempted to exploit old vulnerabilities to catch old operating systems and unpatched systems.
  • A new signature, dubbed MSOffice Sneaky was also detected during Q2. This attack vector is increasingly dangerous, especially when remote employees disconnect from their VPN.
  • DoublePulsar, the exploit developed by the NSA, also responsible for Wannacry, continues to dominate the exploit chart, consisted of 72% of all exploit attempts witnessed at Nuspire.

Lewie Dunsworth, CEO of Nuspire, said, “The pandemic has complicated an already complex threat landscape. CISOs are under great pressure to ensure their virtual organizations are secure. Threat vectors will continue to evolve as the uncertainty of our world continues to play out. That’s why our team analyzes the latest threat intelligence daily and uses this data to engage in proactive threat hunting and response to ensure our clients have the upper hand.”

Tesla Avoids a Cyberattack Bump; Acknowledges the Earnest Employee

Tesla avoids cyberattack, tesla zero-click vulnerabilities

Remember the famous dialog from the 1987 movie “Wall Street” where Lou gives a life lesson to the junior stockbroker Bud? Well, for the millennials who rather prefer “The Wolf of Wall Street” from 2013 over the 80’s classic, here is a walkthrough. It said, “The main thing about money, Bud… it makes you do things you don’t wanna do.” However, this has been proven wrong by a Tesla employee, who not only denied a $1 million reward for betrayal but also helped the FBI in arresting the conspirator and averted a huge cyberattack on the tech giant Tesla.

 Key Highlights 

  • A Russian-speaking, non-U.S. citizen working at Tesla’s Gigafactory Nevada was contacted by Egor Igorevich Kriuchkov (conspirator) on July 16, 2020.
  • He told the employee about a “Special Project” that would require him to install malware on the company’s system.
  • Kriuchkov offered a payout of $1 million for carrying out this activity.
  • The employee, however, reported this to its employer who in turn reported it to the FBI.
  • The FBI finally arrested Kriuchkov on August 22, 2020, in Los Angeles on the count of “Conspiracy to Intentionally Cause Damage to a Protected Computer” under Title 18, United States Code, Section 371.

The Story, as it Happened

On July 16, 2020, a Russian-speaking, non-U.S. citizen working at Tesla’s Gigafactory Nevada was contacted by another Russian speaking person named, Egor Igorevich Kriuchkov, over WhatsApp under the pretext of meeting him in person in the District of Nevada. The meeting was set for August 1, 2020, at a hotel in Reno, Nevada.

Initially, Kriuchkov befriended Tesla’s employee and spent time with his associates at the employee’s home and other public places. Only after gaining enough trust, on August 3, 2020, Kriuchkov told the employee about a “Special Project” that he and some others were working on, which would require a Tesla insider to install malware on the company’s computer system. This malware would be provided by his co-conspirators and would require him to do a manual installation once. With the help of this malware, the conspirators planned to carry out DDoS attacks on the company’s computer network and search for private and confidential information, probably with the intent of withholding it for a ransom. To woo the employee into carrying out this cybercriminal activity, Kriuchkov offered a $1 million payout to the Tesla employee.

The Earnest Hero

The offer was tempting, but the earnest employee instead turned in the cyber conspirators. He reported these inappropriate advances to the authorities at Tesla, who in turn informed the FBI. The FBI asked the employee to continue communications with the conspirator to expose the entire nexus. Over the next couple of weeks, the FBI wired the Tesla employee and monitored Kriuchkov’s movements. On August 21, 2020, Kriuchkov informed the employee that the plan was getting postponed by a few days and that he shall soon get his money through Bitcoins. He also informed that he was going away for a few days and handed a mobile phone, which he asked to keep on airplane mode until further intimation.

The FBI went on a high alert since this communication and followed Kriuchkov from Reno to Los Angeles (LA), where he drove down on the same night. He was in readiness to flee the country from LA and, thus, the FBI eventually arrested Kriuchkov on August 22, 2020. The cybercriminal was charged under Title 18, United States Code, Section 371, on the count of “Conspiracy to Intentionally Cause Damage to a Protected Computer.”

Tesla CEO Elon Musk accepted that the tech giant avoided a planned cyberattack owing to an earnest employee and acknowledged him on Twitter saying, “Much appreciated.”

However, it’s time for corporates to stay vigilant about such insider threats because, “Buddy, money can make you do things that you don’t want to do.”

Global Bank Heist! North Korea’s “BeagleBoyz” are After Bank ATMs

Cybercriminals are “Jackpotting” ATMs in Europe to Steal Cash

Organizations in the banking and financial sector are the primary targets for cybercriminals. Several industry experts stated that this sector suffers a constant stream of cyberattacks when compared to other sectors. Recently, several U.S. federal agencies warned about a hacking group “BeagleBoyz” linked to North Korea for allegedly stealing money from international banks using malicious remote access tools.  The hacker group targeted global banks and financial institutions across 30 plus countries including, Argentina, Brazil, Bangladesh, Ecuador, Ghana, India, and Indonesia.

The joint advisory released by the Cybersecurity and Infrastructure Security Agency (CISA), the Department of the Treasury (Treasury), the FBI, and the U.S. Cyber Command (USCYBERCOM) stated that they have identified malware and indicators of compromise (IOCs) used by the North Korean hackers to make fraudulent money transfers and cause ATM cash-outs. The advisory warned the world about the potential cyberthreats posed by the North Korean hackers to the global banking and financial institutions.

History of BeagleBoyz’s Bank Heists

The BeagleBoyz group is a part of the North Korean government’s Reconnaissance General Bureau and is said to have been active since 2014. It is estimated that BeagleBoyz stole nearly $2 billion since 2015 by manipulating critical computer systems at banks and financial institutions. In 2018, a bank in Africa halted its ATMs and point of sale services for its customers for two months after BeagleBoyz compromised their systems. The group also deployed a wiper malware in 2018 against a bank in Chile that compromised thousands of computers and servers to send fraudulent messages from the bank’s SWIFT terminal.

BeagleBoyz Attack Method

Image Source: us-cert.cisa.gov

Measures to Counter Cyberthreats

The agencies advised organizations to follow certain practices to strengthen their security posture, which includes:

  • Implement chip and PIN requirements for debit cards.
  • Require and verify message authentication codes on issuer financial request-response messages.
  • Perform authorization response cryptogram validation for chip and PIN transactions.
  • Maintain up-to-date antivirus signatures and engines.
  • Keep operating system patches up to date.
  • Disable file and printer sharing services. If these services are required, use strong passwords or Active Directory authentication.
  • Restrict users’ ability (permissions) to install and run unwanted software applications. Do not add users to the local administrators’ group unless required.

“Any BeagleBoyz robbery directed at one bank implicates many other financial services firms in both the theft and the flow of illicit funds back to North Korea. BeagleBoyz activity fits a known North Korean pattern of abusing the international financial system for profit. Fraudulent ATM cash-outs have affected upwards of 30 countries in a single incident. The conspirators have withdrawn cash from ATM machines operated by various unwitting banks in multiple countries, including in the United States,” the advisory said.

Patched! Cisco Fixes High-Severity Bugs Impacting its Fabric Services Component

Cisco Vulnerabilities

Cisco released a security advisory addressing vulnerabilities in its Fabric Services component of Cisco FXOS software, Cisco NX-OS software, and its Data Management Engine (DME). The networking and hardware company stated that it found eight vulnerabilities, in which six vulnerabilities are reported as high severity flaws.

According to the security advisory, the high-severity flaws affecting Cisco’s NX-OS software were tracked as CVE-2020-3397, CVE-2020-3398, CVE-2020-3338, CVE-2020-3415, CVE-2020-3517, and CVE-2020-3454. The two medium severity bugs impacting Cisco’s NX-OS software include CVE-2020-3397 and CVE-2020-3398. These flaws could allow an attacker to cause process crashes, which could result in a denial of service (DoS) condition on an affected device.

“The vulnerabilities are due to insufficient error handling when the affected software parses Cisco Fabric Services messages. An attacker could exploit these vulnerabilities by sending malicious Cisco Fabric Services messages to an affected device. A successful exploit could allow the attacker to cause a reload of an affected device, which could result in a DoS condition,” the advisory stated.

In addition to the eight vulnerabilities, Cisco also fixed a high severity flaw CVE-2020-3504 that impacted Cisco’s web services interface, Adaptive Security Appliance (ASA), and the Firepower Threat Defense (FTD) software. This vulnerability could have allowed an unauthenticated remote attacker to perform directory traversal attacks and steal sensitive data.

Counterfeit Cisco Switches

Recently, an investigation report from F-Secure revealed a pair of counterfeit network switches  impersonating the  Cisco network switches.   The counterfeit devices, versions of the Cisco Catalyst 2960-X series switches, were designed to bypass authentication processes to system components. According to the investigation, the counterfeit devices did not have any backdoor functionalities, but had the ability to bypass security controls.  The counterfeits were physically and operationally similar to an authentic Cisco switch. Threat actors either invested heavily in imitating Cisco’s original design or had access to proprietary engineering documentation to create fake copy, the report said.

DSCI-PayPal Report Shows Increase in Online Payment Fraud in India

Federal Bank Blocks Debit Card Fraud

Online banking and digital transactions have grown massively in India due to the temporary closure of shops and malls. The Indian e-commerce market is also seeing unprecedented growth, especially in tier-II and tier-III cities. Bad actors are taking advantage of the situation, with a jump in online fraud, phishing, and vishing cases in India. A joint study by NASSCOM’s Data Security Council of India and Paypal on “Fraud & Risk Management in Digital Payments” confirms this, with insights and data points. The results of the study appear in the DSCI-PayPal report.

In a virtual event on August 26, 2020, the DSCI-PayPal report was released by Lt. Gen (Dr) Rajesh Pant, National Cyber Security Coordinator, Government of India (GoI) in the presence of K. Rajaraman, Addl. Secretary, Dept. of Economic Affairs, Ministry of Finance.

Lt. Gen (Dr) Rajesh Pant, National Cyber Security Coordinator, GoI, said, “Digitization and cybersecurity is at the core of Digital India’s mission and online payment safety is paramount for India to emerge as a leader globally. The Government has taken many steps to support businesses, SMBs across their digital journey, however, upcoming legislation and strategies will further aid the positive momentum. COVID has also provided an opportunity to fast-track both adoption and regulatory focus. The report provides a good insight into the Digital Payment Fraud landscape and recommendations for the payment ecosystem to focus and remediate issues.”

Digital payments have been growing in India at a much faster pace than global markets and thus safeguarding payments for consumers, MSMEs, businesses is of utmost priority.

Current Indian Scenario

  • E-commerce market is expected to grow to $200 billion by 2026 from $50 billion in 2018.
  • The internet userbase is expected to grow to 835 million by 2023 from 560 million in 2018.
  • Growth of online shoppers is 73% for tier-I and staggering 400% for tier-II and tier-III cities.
  • As of March 31, 2019, 925 million debit and 47 million credit cards have been issued in India, second only to China.
  • MSME’s adopting digital channels and transformation have grown twice as compared to their peers using traditional approaches.
  • Inline Digital India’s vision, digital payments are on an accelerated growth path with UPI alone clocking 1.49 billion in volume and $41 billion in transaction value, in July 2020.
  • The retail sector is increasingly leveraging advanced AI technologies like machine learning, computer vision, conversational AI, Data Science and NLP to bring out better user experience.
  • RBI (India’s Banking regulator) predicts the number of digital transactions to increase from INR 2069cr (approximately $280 million) in December 2018 to INR 8707cr (approximately $1178 million) by December 2021.
Rama Vedashree, CEO, DSCI. DSCI-PayPal report
Rama Vedashree, CEO, DSCI,

Rama Vedashree, CEO, DSCI, said, “Digital Payment Safety is one of our key focus areas to alleviate the emerging concerns and underlying causes leading to mushrooming payment frauds. This report is an attempt to initiate discussions and develop solutions towards real-time fraud prevention and mitigation strategies. The Government is already working closely with the Industry and COVID has proved to be an accelerator. In order to find the right balance between enablement and protection, it is critical that a collaborative effort be undertaken by all stakeholders involved, to establish a comprehensive fraud management framework for digital payments in India.”

The DSCI-PayPal Report

The report attempts to discuss the sophisticated online payment fraud mechanisms, threats in the payment ecosystem, incorporating better fraud prevention strategies, role of upcoming technologies, and recommendations for various stakeholders involved in the payment ecosystem.

The DSCI-PayPal report covers various types of fraud scenarios such as buyer side, merchant side and cybersecurity frauds, and recent fraud case studies with their modus operandi. The key challenges to safeguard frauds remain fraud detection, investigation and legislative challenges, multilevel awareness, cross-industry collaboration, security as a cost overhead, privacy laws, and organized criminal involvement. Future fraud possibilities can shape up from exploitation of supply chain vulnerabilities, exploiting risk transfer controls and spoofing current fraud prevention mechanisms. Therefore, the report showcases how upcoming technologies like AI/ML, computer vision, NLP can come to the rescue. There is a significant focus on recommendations for various stakeholders involved in the payment ecosystem.


Download the DSCI-PayPal Report here: https://www.dsci.in/content/fraud-and-risk-management-in-digital-payments


Type of Frauds

E-Commerce frauds can be broadly categorized into:

  • Buyer side frauds – fraudulent claims, chargebacks, fake buyer accounts, promotion/coupon abuse
  • Merchant side frauds – selling counterfeit, non-fulfillment
  • Cybersecurity frauds – account takeover, identity theft, card detail theft, triangulation fraud, etc.

Key Challenges

  • Fraud detection, enforcement, investigation, and legislative challenges
  • Lack of multilevel awareness
  • Cross-industry or expertise collaboration
  • Security is seen as a cost overhead and not essential investments by stakeholders
  • Privacy laws
  • Organized criminal involvement

Steven Chan, Sr. Director, Head of Govt. Relations, APAC, PayPal Inc., said, “COVID-19 has been a catalyst for digitalization as businesses are rapidly adapting their strategies to evolve with changing consumer behaviors. As a result, we have seen significant acceleration of digital payment adoption and India is at the forefront of this transformation. While we have witnessed a tremendous shift in commerce and financial services, there has been an increase in cyberattacks and the global pandemic has revealed gaps in business continuity plans and IT operations. The joint DSCI-PayPal report examines the various types of fraud focusing on consumers, merchants, and cybersecurity as well as future fraud possibilities, amplified by COVID-19, such as supply chain vulnerabilities and risk transfer controls.  Small businesses and vulnerable communities will continue to struggle as the pandemic and its economic consequences continue to play out. Therefore, developing the right solutions will be essential to enhancing small business resiliency and the recovery of the overall economy.”