Home Blog Page 180

Who’s Responsible for a Safer Cloud?

Cloud Security, 80% of Organizations Suffered a Cloud Data Breach in the Past 18 Months

With today’s explosion of remote workers, we’re seeing an overwhelming reliance on the cloud. Its agility, anywhere access, and dynamic scalability make the cloud ideal for this new working paradigm. But what about cloud security? Whose responsibility is it anyway?

By Phil Alberta, President and Chief Information Officer, IPM

With so much reliance on multiple cloud providers and solutions, from diverse locations and sources, protecting and securing the cloud has gotten much more complex, and in some cases even misunderstood. This leaves risky gaps and exposure. Yes, cloud providers including Microsoft Azure and AWS handle infrastructure security – including compute, storage, database, and networks. But it’s vital to understand that once your data arrives in the cloud, its full security fate rests in your own hands.

Embracing a Shared Responsibility Model

There is a duality to cloud security that requires deep understanding and strategic management in a practice that can be called a shared responsibility model. Here, the cloud provider is responsible for the secure infrastructure of the cloud. The customer on the other hand takes primary responsibility for protecting data in the cloud including user data, platforms, applications, identity access management, as well as the operating system, firewall configuration, and other components.

It’s important to note that this shared responsibility for security doesn’t fall into place automatically. It takes careful planning, precise implementation, and continuous monitoring to perfect. To build your secure cloud environment, consider the following five best practices:

1. Develop a comprehensive plan: Take another look at your cloud provider(s) agreement and identify where they can help you to improve security, and where you may need to add technology and solutions to your overall strategy. In the shared responsibility model, you need to know where the cloud provider’s agreed-upon responsibility ends and yours begins. Then you can better integrate your provider’s security controls into your overall security strategy.

Using this greater detail from your cloud provider, you can develop a plan to include:

  • An assessment of new assets that need to be budgeted for. i.e., threat detection and response software, automated patching updates, swapping out high-risk legacy hardware for more secure devices.
  • Forecasting of your organization’s potential workforce shift to determine the longer-term effects and needs of remote working and related devices.
  • Alignment between IT, security, and HR on a timetable to execute security improvements. This may entail giving employees new devices, training on new software and security protocols, and budgeting priorities.

2. Understand your compliance requirements: Reassess your compliance needs and then identify and use the tools your cloud provider makes available to help you monitor and prove compliance. Azure Policy is one tool offered to centralize compliance data for quicker auditing and tracking. It enables policy creation at the core of Azure and supports ongoing enforcement by setting guardrails on resources.

3. Know your risk tolerance: Fully understand what data you need to secure and what risks you are willing to accept for that data. Map out your data risk tolerance by data type and the strategy you will implement to protect it. By classifying your data based on its sensitivity such as personally identifiable information (PII) or HIPAA regulated health records, you’ll have a strong idea of which data sets you need to best protect.

4. Design and implement technology controls: Organizations can use managed services and solution providers to help design and execute a cloud security plan and help navigate the complexities of cloud data security protocols. This plan can include application and access controls needed to further ensure sensitive cloud data is not compromised and can be recovered. Given the expected increase in remote users, it is imperative to limit access to applications in accordance with work productivity needs. Phishing attacks and malware introduction into networks are a common result of inadequate control at the device endpoint.

5. Develop a continuous monitoring program: Security threats and risks function in a fluid environment. This demands regular assessment of the controls in place and the agility to adapt as situations change. It includes evaluation of your threat response system, secure onboarding and offboarding of employees’ devices, timeliness of all patching updates, and due diligence in making use of updated security controls across all major programs.

The responsibility for a secure cloud is a shared one. And as organizations continue to rely more heavily on cloud-powered workloads, your security strategy must be a priority that remains front and center. By inspiring collaboration and consensus between your cloud providers, solutions providers, and internal IT security staff, you’ll enable a more productive and secure environment in which workers will thrive.

About the Author

phil albertaPhil Alberta is President and Chief Information Officer for IPM, an IT consulting firm focused on supporting secure cloud transformations with field-proven expertise in planning, deploying, and supporting today’s hybrid IT infrastructure.

 

Disclaimer 

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Need for Automation! 93% of Firms Believe Human Error Causes Cloud Data Threats

93% of Organizations Believe Human Error Cause Cloud Data Breaches

A survey from Tripwire, a provider of security and compliance solutions, revealed that several organizations face shortcomings in securing their cloud environments. In its “Implementing Cloud Security Best Practices” report, Tripwire revealed that the majority of security professionals (76%) have difficulties in maintaining security configurations in the cloud. Nearly 37% of respondents said their risk management capabilities in the cloud are worse compared with other parts of the security landscape.

Almost 93% are concerned about human error causing accidental exposure of their cloud data. Despite concerns about human errors, 22% of organizations still assess their cloud security posture manually. The report stated, “Attackers are known to run automated searches to find sensitive data exposed in the cloud, making it critical for organizations to monitor their cloud security posture on a recurring basis and fix issues immediately.”

Other Notable Findings from the Survey include:

  • Only 21% of organizations assess their overall cloud security posture in real time or near real time. While 21% said they conduct weekly evaluations, 58% do so only monthly or less frequently.
  • While 91% of organizations have implemented some level of automated enforcement in the cloud, 92% still want to increase their level of automated enforcement.
  • Only 51% of organizations have automated solutions that ensure proper encryption settings are enabled for databases or storage buckets.
  • 45% of organizations automatically assess new cloud assets as they are added to the environment.
  • A slim majority (51%) have automated alerts with context for suspicious behavior.

Tim Erlin, Vice President of product management and strategy at Tripwire, said, “Security teams are dealing with much more complex environments, and it can be extremely difficult to stay on top of the growing cloud footprint without having the right strategy and resources in place. There are well-established frameworks which provide prioritized recommendations for securing the cloud. However, the ongoing work of maintaining proper security controls often goes undone or puts too much strain on resources, leading to human error.”

The survey findings are based on the responses from 310 security professionals surveyed on the implementation of cloud security best practices.

Cloud Security Risks on Rise

A similar survey, “State of Cloud Security,” conducted by Fugue revealed that IT and cloud security professionals are concerned about the security of their cloud environments as several organizations working remotely. The survey found that 96% of cloud engineering teams are at present 100% working from home, while 83% of them completed the transition or are still in the process. Around 84% (who are making the shift) are concerned about security vulnerabilities created during the swift adoption of new access policies, networks, and devices used for managing cloud infrastructure remotely.

 

Hackers Use Fake “Get Rich Quick” Investment Schemes to Attract Users

Phishing Campaign on FINRA

The U.K.’s National Cyber Security Centre (NCSC) warned online users about cybercriminals promoting fake investment schemes via bogus endorsements that use the faces of celebrities like Ed Sheeran, Sir Richard Branson, and Martin Lewis. In a security alert, the cybersecurity watchdog stated that it took down over 300,000 malicious URLs linked to fake investment schemes and adverts over the last four months.

Threat actors are using fabricated news articles, phishing emails, and paid advertisements to attract users into clicking malicious links. Several such links were identified by NCSC’s recently launched Suspicious Email Reporting Service (SERS), which allows citizens to report fraudulent and malicious URLs to the authorities. The SERS received over 1.8 million reports from the citizens since its launch in April 2020 and blocked more than 16,800 malicious URLs in which 50% were related to cryptocurrency investment scams.

NCSC Chief Executive Officer, Ciaran Martin, said, “These investment scams are a striking example of the kind of methods cybercriminals are now deploying to try to con people. We are exposing them today not only to raise public awareness but to show the criminals behind them that we know what they are up to and are taking action to stop it. I would urge the public to continue to forward anything they think doesn’t look right to our Suspicious Email Reporting Service.”

Sir Richard Branson, Virgin Group Founder, said, “We have dealt with hundreds of instances of fake sites and fraudsters impersonating me or my team online. We are working in partnership with organizations such as NCSC to report these sites and do all we can to get them taken down as quickly as possible. Sadly, the scams are not going to disappear overnight, and I would urge everyone to be vigilant and always check for official website addresses and verified social media accounts.”

NCSC Warns About Cyberthreats

Recently, the NCSC warned about the increasing cyber risks like phishing, ransomware attacks, and Business Email Compromise (BEC) schemes targeting football clubs, teams, and sports authorities. In its report “The Cyber Threat to Sports Organizations,” NCSC revealed that around 70% of sports organizations suffered a breach or a security incident and 30%  reported over five incidents in the last 12 months that caused a financial damage of £10,000 (US$ 12,700), with the biggest single loss of over £4 million (US$ 5,100,000).

 

Jack Daniel’s and Carnival Cruise Land “On the Rocks” with Ransomware Attacks

Shipping cybersecurity, carnival cruise line

Over the past weekend, two incidents of ransomware attacks – one on alcoholic beverages giant Brown-Forman, which owns renowned brands like Jack Daniel’s, Finlandia Vodka and Korbel champagne, and the other on the world’s largest cruise line, the Carnival – have been reported. Brown-Forman said in a statement that none of its files were encrypted however, some data may have been stolen. Whereas, in the latter incident Carnival Corporation has accepted that one of its brand’s IT systems was partly encrypted during the ransomware attack, which also includes download of certain data files from the system.

 Key Highlights 

  • REvil hacking group, or also known as Sodinokibi, has taken responsibility for the attack on Brown-Forman.
  • Brown-Forman said that none of the systems were encrypted but some data may have been stolen.
  • REvil gang claimed the thievery of 1TB confidential data in the attack process and posted screenshots on their leak site as a proof.
  • Carnival Corp. has filed Form 8-K with the Securities and Exchange Commission (SEC) disclosing the data breach incident.
  • No information about the ransomware group has been revealed in the attack on the cruising company.

Ransomware Attack on Jack Daniel’s

Brown-Forman is a Kentucky-based distillery having some big notable brands including Jack Daniel’s. The ransomware attack first came to light when the REvil ransomware gang published screenshots of Brown-Forman’s internal tree architecture and file names on its data leak site. It claimed to have stolen 1 TB of the company’s confidential data. This includes internal employee conversations, multiple contracts information, and database backups. REvil further said that the initial compromise took place a month back and they carefully monitored the entire network, cloud storage, and user services of Brown-Forman to steal highly sensitive data.

However, before the hackers could deploy the encryption script, Brown-Forman’s IT team detected the intrusion and locked out the perpetrators from further access. Thus, although the data may have been stolen, Brown-Forman is not keen on negotiating with the ransomware gang to retrieve it. On the other hand, REvil is all set to auction the stolen data if the victimized company denies paying the ransom.

How Carnival was Impacted

On August 15, 2020, Carnival Corp. disclosed that one of its brands suffered a ransomware attack. The cruise line did not issue a formal press release but gave limited information through an 8-K Form filed with the Security and Exchange Commission (SEC) as per the mandatory reporting procedure. Carnival did not reveal any information about the ransomware gang or type of ransomware attack it suffered. However, it accepted that one of its brand’s IT systems faced a ransomware attack that partly encrypted certain data files.

Carnival failed to patch its edge gateway devices and firewalls, even though patches have been available to fix both issues since earlier this year.

   – Chris Hauk, Consumer Privacy expert at Pixel Privacy

It further added: “We expect the security event included unauthorized access to personal data of guests and employees, which may result in potential claims from guests, employees, shareholders, or regulatory agencies.”

Chris Hauk, Consumer Privacy expert at Pixel Privacy said, “This is another case of a company not taking the steps to properly defend their networks against the bad actors of the world. As mentioned by cybersecurity firm Bad Packets, Carnival failed to patch its edge gateway devices and firewalls, even though patches have been available to fix both issues since earlier this year. As for Carnival customers, they will need to keep their eyes open for phishing attempts and other “attacks” designed to separate them from their personal information and hard-earned money, as bad actors may attempt to take advantage of the data gleaned from this attack and the data breach that occurred earlier this year.”

In times of COVID-19 where the food, travel, and the hospitality sector are taking the brunt of it, these ransomware attacks come as a blow below the belt.

Customized Automation: How to Optimize VRM

Top Cybersecurity Jobs in 2021

Vendor risk management (VRM) is a big problem. Vendors are cybercriminals’ favorite avenue of attack. 61% of the U.S. organizations experienced data breaches caused by third-party vendors. And these breaches can damage a company’s reputation and stock price.

By Mike Kelly, CEO of ProcessBolt, and Gaurav Gaur, CTO and Co-founder of ProcessBolt

According to a survey conducted by Deloitte, only 1% of firms rate their VRM process as “optimized” and fully up to the task of reducing vendor risk.

So, what is the path to optimizing such an important business process?

An important first effort is standardization — creating uniform methods for completing VRM tasks. Then these standard methods are automated by integrating them into VRM software. This saves time, enabling the information security team to identify and remediate vendor risks.

But over-use of standardization can hinder VRM optimization. This is where customization plays a critical role.

VRM customization accommodates higher complexity. It allows companies to support process variations that increase complexity but reduce vendor risk exposure.

Does your VRM software facilitate customization?
If not, you have a substantial VRM optimization opportunity.

Standardization

The path to VRM optimization begins with identifying repetitive manual tasks that can be standardized. Standardization emphasizes simplicity and efficiency. There are hundreds of specific VRM tasks that can be streamlined.

Cloud-based survey capability is a great example of a VRM process to simplify. Spreadsheet uploading errors, such as duplications or missing data, are greatly reduced. This leads to improved decision-making and vast savings in administrative time and effort.

Customization

As companies strive to automate, they can err on the side of too much standardization. They eliminate important nuances and complexities which sub-optimizes VRM effectiveness.

Customization lets you take the best parts of standardized formats like NIST (National Institute of Standards and Technology) or a SIG questionnaire (Standardized Information Gathering) but you then add other important questions. For example, maybe you should ask questions about regulatory compliance that are unique to your industry or your firm. Maybe you need GDPR-related (General Data Protection Regulation) questions if you do business in Europe. Other questions may be needed to explore CCPA compliance (California Consumer Privacy Act). Or, companies increasingly have ESG (Environment, Social, and Governance) issues that call for very specific compliance questions.

The solution is to strike the right balance between standardization and customization:

  • Standardize task variations that do not affect VRM effectiveness.
  • Customize your software solution to accommodate task variations that improve VRM effectiveness.

Striking the Right Balance

The VRM process can be summarized as flowing through five steps. Each affords opportunities to improve efficiency through standardization and effectiveness through customization. Here’s an abbreviated checklist of typical opportunities within each of the five VRM process steps.

VRM Step 1: Inventory Vendors and Inherent Risks, Track Contract Performance

Standardize

  • Use ERP feeds to populate vendor lists, business units served, responsible parties, contact information, vendor contract specifics, etc.
  • Prepare missing information reports, distribute them to responsible parties.
  • Crosscheck vendors against excluded persons and vendors’ databases.
  • Catalog risk assessment policies (e.g., inherent risks associated with each type and level of information access, integration of risk management with RFP/RFQ process).
  • Track measures per vendor

Customize

  • Facilitate custom missing information memos.
  • Accommodate multiple methods for missing information submission.
  • Enable multiple sets of risk assessment policies, inherent risk assignments and weightings, and vendor performance measures per business unit, contract size, partnership status, etc.

VRM Step 2: Plan Vendor Assessments

Standardize

  • Maintain inventory of prior assessment surveys, facilitate the creation of new surveys, track completion.
  • Propose vendors to survey based on the inherent risk profile.
  • Create a standard risk management calendar/schedule per vendor, prompt responsible parties, and track progress.

Customize

  • Facilitate the creation of new surveys, like initial assessment, quarterly check-up, specific new threat questionnaires, etc.
  • Vary criteria for selecting vendors to be surveyed based on business unit, contract type, risk profile, strategic importance, etc.

VRM Step 3 Design and Distribute Surveys, Assess Vendor Risk

Standardize

  • Solicit vendor participation in the survey, monitor for completion, thank the vendor for completion, and populate the database.
  • Score surveys, flag key risk factors, record adjustments and notes.

Customize

  • Tag assessment questions for each survey by business unit, vendor type, security framework, etc.
  • Set different standards for designating a survey as “complete” based on vendor’s or project’s strategic importance.
  • Score surveys relative to unique policies set in step 1.

VRM Step 4: Generate Assessment Reports, Initiate Remediation

Standardize

  • Update the VRM dashboard and reports.
  • Track new VRM tasks per vendor on the master calendar, track updates, notify responsible parties.

Customize

  • Tailor VRM dashboards and drilldowns based on audience preferences and requirements.
  • Customize answer flagging per business unit, contract type, etc.

VRM Step 5: Manage Emerging Threats

Standardize

  • Update vendor risk profile with continuous monitoring data feeds.
  • Flag threats, notify responsible parties, record new tasks, assignments, and progress.

Customize

  • Facilitate unique continuous monitoring data feeds per type of inherent risk, vendor, business unit, etc.
  • Test alternative risk assessment algorithms.

GRC Overreach

A common complaint about GRC (Governance Risk Management & Compliance) solutions is that they go too far with VRM standardization, sacrificing customization for standardization. The result, sacrificing VRM effectiveness and risk reduction.

These solutions emphasize standardization because they deal with the whole enterprise’s internal cybersecurity. Then VRM is added along with other services such as disaster recovery and regulatory compliance to create a total business risk management solution. So, even without customization, GRC systems are highly complex. Adding customization is unthinkable … a bridge too far.

The Better Solution

Just because you have a GRC solution does not mean you need to rely on it exclusively for VRM. A customized VRM solution can automatically feed your GRC platform with primary outputs such as:

  • Inherent risk profiles and vendor assessment scores
  • Red flags for late vendor surveys, new potential risks
  • Central risk management dashboard inputs

By integrating a customized VRM solution with GRC, you can have the best of both worlds: a fine-tuned VRM solution and enterprise-wide integration with risk management.

About the Authors

Mike_Kelly_ProcessboltMike Kelly is the CEO of ProcessBolt, Inc., a Saas company that automates regulatory compliance and third-party risk assessments both for companies issuing assessments and those responding to assessments. Before joining ProcessBolt, Kelly led and ultimately grew and sold several software and analytics businesses in a variety of industries from healthcare to business and legal services.

Gaurav_Gaur_ProcessBoltGaurav Gaur is the CTO and Co-founder of ProcessBolt. He has an extensive background in cybersecurity, vendor management, and software engineering. Before starting ProcessBolt, Gaur was the VP of Software Development at NetSPI Inc., a cybersecurity-focused software and consulting firm.

 

Disclaimer 

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Canada Revenue Agency Shut Down Services after Cyberattacks

Canada Revenue Agency Shut Down Services after Cyberattacks

The Canada Revenue Agency (CRA) temporarily halted operations after discovering two cyberattacks on its systems where attackers exploited thousands of stolen usernames and passwords to illegally obtain government services and to compromise Canadians’ data, as reported by CBC.

The attacks affected the GCKey service, an online portal that allows Canadians to access government services, used by the CRA, and over 30 federal departments. Hackers compromised passwords and usernames of 9,041 GCKey account holders to access government services. In addition, about 5,500 CRA users’ accounts were targeted in the incident, the authorities said.

According to the CBC, several Canadians have reported that their bank details linked to their CRA agency accounts have been modified by unknown parties. Payments related to the Canadian Emergency Benefit, a financial assistance package from the government in the wake of the pandemic, have also been issued to other bank accounts without their knowledge.

The CRA spokesperson Christopher Doody said, “The CRA quickly identified the impacted accounts and disabled access to these accounts to ensure the safety and security of the taxpayer’s information. The CRA is continuing to analyze both incidents. Law enforcement assistance has been requested from RCMP and an investigation has been initiated.”

329,000 Canadians’ Data Hacked

Recently, the Chartered Professional Accountants of Canada (CPA) disclosed a security breach that affected over 329,000 members and stakeholders of the association. It is said that unknown hackers compromised the CPA Canada website and obtained information related to the distribution of its magazine. The exposed information includes names, home addresses, email addresses, and other sensitive information. However, CPA clarified that information like passwords and credit card numbers were protected by encryption.

“There is no evidence that the encryption keys were affected in this incident and we have no reason to believe the encryption was compromised,” the company said in its security incident report.

 

Scam Alert! Tea at Ritz London Leaves a Sour Aftertaste Among Diners

Ritz london diners scammed

Diners visiting the popular Ritz hotel in London were left with a sour aftertaste as scammers posing as “extremely convincing” hotel staff stole their payment card details. The potential data breach indicates the possibility that this incident may have had an insider hand or their system network was compromised by a cyberattack that enabled the leak of reservation details. Ritz has notified the Information Commissioner’s Office (ICO) and is further investigating the potential data breach.

 Key Highlights 

  • Scammers phoned people with exact details of their bookings at the Ritz hotel, London.
  • Under the pretext of confirming their booking and order, they asked for payment card details.
  • Scammers used Caller ID spoofing to fool people into believing it as a legitimate caller.
  • Ritz informed the ICO and confirmed that it is investigating a ‘potential data breach.’
  • Scammers used the stolen card details to make transactions worth more than £1,000 at Argos.

From High Tea to High Threat

According to the BBC, one of the victims received a call a day before her reservation for an afternoon tea at the Ritz. The caller ID displayed the real number of the Ritz hotel and thus, with a sense of assurance she answered it. The person on the other side knew the exact details of her reservation and thus she was not alerted. In order to “confirm” her booking and order, the scammer asked her to share the payment card details to which she obliged. However, the caller said that the card was declined and would require details of another card, to which she again agreed. Apparently, both these cards were later used to make multiple transactions in excess of £1,000 at Argos, an online retail shop.

Another lady also confirmed a similar modus operandi. She was called from a legitimate-looking number (through a spoofed caller ID) and asked for payment card details. However, the lady smelled something fishy when the scammer was unable to spontaneously tell her about the hotel’s facilities on offer.

What’s Caller ID Spoofing

Caller ID spoofing is a practice of impersonating another person or company’s legitimate name and telephone number. It causes the telephone network to indicate the receiver of a call that the originator of the call is a station or person other than the true originating station. This can lead to a caller ID displaying a phone number different from that of the telephone from which the call is made.

Caller ID spoofing technique is legitimately used by call centers while tele calling its customers on behalf of multiple clients. The caller ID information is manipulated to accurately display their client’s name and telephone number. This method is also used by some doctors while communicating with their patients. They display the hospital’s general call back number on the caller ID so that future communications and appointments can be channelized appropriately. However, scammers are now using this technique to dupe people by making them believe they are talking to a legitimate person on the other side of the line.

Cryptocurrency Seizure! U.S. Govt Disrupts Three Cyber-Enabled Terrorist Campaigns

cryptocurrency heist

The U.S. Department of Justice (DOJ) announced the seizure of three cyber-enabled terrorist financing campaigns, involving the al-Qassam Brigades, Hamas’s military wing, al-Qaeda, and the Islamic State of Iraq and the Levant (ISIS).  This is the U.S. government’s largest-ever disruption of cryptocurrency that was used for terrorist activities, the DOJ said in a release.

According to the DOJ, the terrorist groups used multiple social media profiles and cryptocurrency accounts for their online presence to raise funds for their terrorist operations. The authorities detained over 300 cryptocurrency accounts, millions of dollars, four websites, and four Facebook pages related to the terrorist groups.

“These three terror finance campaigns all relied on sophisticated cyber-tools, including the solicitation of cryptocurrency donations from around the world.  The action demonstrates how different terrorist groups have similarly adapted their terror finance activities to the cyber age,” DOJ said.

Al-Qassam Brigades Campaign

In 2019, Al-Qassam Brigades posted a message on its social media page asking for Bitcoin donations to fund its terror activities. The request was later made via its official websites, alqassam.net, alqassam.ps, and qassam.ps. “The al-Qassam Brigades boasted that bitcoin donations were untraceable and would be used for violent causes.  Their websites offered video instruction on how to anonymously make donations, in part by using unique bitcoin addresses generated for each individual donor,” the DOJ added.

However, the Internal Revenue Service (IRS), Department of Homeland Security (HSI), and FBI agents tracked and seized over 150 cryptocurrency accounts that laundered funds to and from the al-Qassam Brigades’ accounts.

Al-Qaeda Campaign

A second campaign run by Al-Qaeda group operated a Bitcoin money laundering network using multiple Telegram channels and other social media accounts to request cryptocurrency donations. The forfeiture complaint details that “In some instances, they purported to act as charities when, in fact, they were openly and explicitly soliciting funds for violent terrorist attacks.” The authorities seized around 155 virtual currency assets tied to this terrorist campaign.

ISIS Campaign

The third disrupted campaign highlights a scheme by Murat Cakar, an ISIS facilitator responsible for managing select ISIS hacking operations to sell fake personal protective equipment via a fake website FaceMaskCenter.com. “The website claimed to sell FDA approved N95 respirator masks, when in fact the items were not FDA approved.  Site administrators claimed to have near unlimited supplies of the masks, despite such items being officially designated as scarce.  The site administrators offered to sell these items to customers across the globe, including a customer in the United States who sought to purchase N95 masks and other protective equipment for hospitals, nursing homes, and fire departments,” DOJ said.

Attorney General William P. Barr, said, “It should not surprise anyone that our enemies use modern technology, social media platforms and cryptocurrency to facilitate their evil and violent agendas.  We will prosecute their money laundering, terrorist financing and violent illegal activities wherever we find them.  We will seize the funds and the instrumentalities that provide a lifeline for their operations whenever possible.”

How to Safeguard Your Cryptocurrency Wallet from Digital Exploits

ONUS Log4j, Cryptocurrency Wallet Security

Recently, the largest cryptocurrency, Bitcoin, rose to more than $12,000 in trading value, which is its highest level since August 2019. The price swings of cryptocurrencies are erratic, attracting both investors and cybercriminals. Since its inception in 2009, there have been numerous hacks and heists reported on cryptocurrency exchanges and crypto wallets. According to the “2019 Cryptocurrency Anti-Money Laundering (AML)” report from blockchain security firm CipherTrace, cryptocurrency crimes across the world hit over $4.3 billion in 2019. Cybercriminals robbed over $125 million in Ethereum, Bitcoin, and other digital currencies from different cryptocurrency exchanges in 2019.

By Rudra Srinivas, Feature Writer, CISO MAG

The threat to your digital currencies is mainly through cryptocurrency wallets (digital wallets) or exchange providers. A crypto wallet does not store your digital coins, but it holds a private key, which allows you to trade cryptocurrency online. This private key is your digital identity to the cryptocurrency market and anyone who gets hold of this can perform fraudulent transactions or steal your crypto coins. Cybercriminals use sophisticated techniques to compromise digital wallets and steal/transfer crypto assets without the user’s knowledge. Securing your wallet is essential when it comes to protecting your digital currency against cyberattacks.

Here are some of the ways to secure your cryptocurrency:   

1. Use a Cold Wallet

Unlike hot wallets, cold wallets do not connect to the internet therefore, they are not prone to cyberattacks.  Storing your private keys in a cold wallet, also known as a hardware wallet, is the most viable option as these come encrypted, keeping your keys secure.

In 2019, the Japanese exchange BITpoint discovered an unauthorized withdrawal of $32 million from its hot wallet in different cryptocurrencies targeting more than 50,000 users. The exchange held five cryptocurrencies in its hot wallet: Bitcoin, Bitcoin Cash, Ethereum, Litecoin, and Ripple. However, BITpoint clarified that its cold wallet and cash holdings were not affected in the incident.

2. Use Secure Internet

While trading or making crypto transactions, use only a secure internet connection and avoid public Wi-Fi networks. Even when accessing your home network, use a VPN for additional security. A VPN changes your IP address and location, keeping your browsing activity safe and private from threat actors.

3. Maintain Multiple Wallets

Since there is no limitation for wallet creation, you can diversify your cryptocurrency investments in multiple wallets. Use one wallet for your daily transactions and keep the rest in a separate wallet. This will protect your portfolio and mitigate the loss of any breach to your crypto account.

4. Secure Your Personal Device

Make sure your personal device is up to date with the latest virus definitions to defend against newly discovered vulnerabilities. Use a strong anti-virus and firewall to improve your device’s security to avoid hackers from taking advantage of the weakness by writing code to target the vulnerability.

5. Change Your Password Regularly

We cannot underrate the importance of a strong password while talking about security. According to a  study, three-quarters of millennials in the U.S. use the same password on more than 10 devices, apps, and other social media accounts. It also stated that most of them were using the same password in over 50 different places. Make sure you have a strong and complex password, which is difficult to guess, and change it on a regular basis. Use separate passwords if you have multiple wallets. Opt for two-factor authentication (2FA) or multi-factor authentication (MFA) for additional security.

6. Don’t Get Phished

Phishing scams via malicious ads and emails are rampant in the cryptocurrency world. Be careful while making crypto transactions and avoid any suspicious and unknown links.

In a recent cryptocurrency heist, a hacking group “CryptoCore” targeted cryptocurrency exchanges via spear-phishing campaigns. Attackers stole cryptocurrency worth $200 million in two years, targeting companies in the U.S. and Japan since 2018. ClearSky stated that CryptoCore initiated a reconnaissance phase to identify the email accounts of the cryptocurrency exchange’s employees and security executives before conducting a spear-phishing attack. These attacks were performed using fake domains impersonating affiliated organizations and employees,  and by embedding malicious links in documents via emails.

Wrap Up   

The cryptocurrency industry is constantly evolving, and it is your sole responsibility to protect your digital funds by securing your wallet with essential safety precautions. Update yourself with the latest security news, attack techniques, and prevention strategies.

About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.