Home Blog Page 185

Hackers Favored Google and Amazon for Brand Phishing Attacks in Q2 2020

Hackers Favored Google and Amazon for Brand Phishing Attacks in Q2 2020

Google and Amazon were the top used brands in phishing attacks (13%) during Q2 2020, according to Check Point’s Brand Phishing Report. The report highlighted various other brands that were frequently impersonated by hackers in their cyber activities to steal victims’ sensitive information. Check Point stated that technology, banking, and social networking are the most targeted sectors in brand phishing attacks.

Brand Phishing Attack: An Overview

  • In brand phishing attacks, attackers impersonate the official website of a popular brand by creating a similar domain name or URL of the original site.
  • The links to the fraudulent website are then sent to targeted individuals via email or SMS.
  • Once the user clicks on the link, it redirects them to a fake website which often contains a form intended to steal user credentials, payment details, or sensitive information.

Top Phishing Brands

According to the report, WhatsApp and Facebook stood at third and fourth positions with 9% brand phishing attacks. Similarly, Microsoft and its brand Outlook, which stood at fifth and sixth spots, were imitated in 7% and 3% of attacks, respectively. Apple (the leading phishing brand in Q1 2020) fell to seventh place in the current rankings with 2% of attacks, followed by Netflix, Huawei, and PayPal at eighth, ninth and tenth spots (2% attacks).

Image Source: Check Point

Top Phishing Brands Per Vector

Email phishing exploits were the second most common type after web-based exploits.  “The reason for this change may be the easing of global Covid-19 related restrictions, which have seen businesses re-opening and employees returning to work,” the report said.

Top 3 Attacked Vectors

table

How to Stay Safe

Check Point recommended certain security measures to avoid falling victim to phishing scams, these include:

  • Verify you are using or ordering from an authentic website. One way to do this is NOT to click on promotional links in emails, and instead Google your desired retailer and click the link from the Google results page.
  • Beware of special offers. An 80% discount on a new iPhone is usually not a reliable or trustworthy purchase opportunity.
  • Beware of lookalike domains, spelling errors in emails or websites, and unfamiliar email senders.

 

“In the COVID-19 situation, 98% employees are working from home and this invites many new risks”

Bharat Panchal is working as a Chief Risk Officer for India, Middle East & Africa for FIS, a Fortune 500 and global fintech leader.

He is responsible for creating risk culture at FIS and its ecosystem by way of designing, implementing and monitoring risk controls. Panchal holds an MBA degree in Information Systems and has around 26+ years of experience in risk management, mainly in the banking and telecommunication industry. He has been honoured with prestigious “Security Leader of the Year” Award in 2014 and 2017 by Data Security Council of India (DSCI) for his significant contribution to cybersecurity in the banking sector.

By Augustin Kurian, Senior Feature Writer, CISO MAG

You are responsible for creating a risk culture at FIS and its ecosystem. What are the biggest challenges you face in doing so, and how do you overcome these challenges? Apart from this, what is your charter at FIS and your plan for this year?

Today, ‘risk’ is not a static or dry subject. Technology has brought lots of dynamic changes in our life, so risk is also now dynamic in the ever-changing threat landscape. This is an amalgamation of many things. It should begin by changing the attitude of people. Because even if you have good technology and processes, you will need to nurture people to increase their risk-taking ability. When it comes to risk management, it gives confidence to people on how much more risk they can take. Because risk management is a function that is safeguarding them by early warning about such events – it is how efficiently you can manage it.

Risk is more about predictability. So, for any risk manager, the plan is always to identify more and more risk which may occur. So, if we have impacted in certain areas, which are probably a concern for risk, compliance and security and many other central functions. We continuously monitor such activities and events which may potentially turn into a risk later. We are cautious about that. We are aware of those risks and try to mitigate them as and when they occur. It is always a future-proof planning.

The big difference you need is to walk the talk — become a role model, and that is how you can bring a risk culture in the organization. So, in a nutshell, it is about influencing people that risk should be considered as an enabler.

Looking back on your career, especially your role as Chief of Risk Management for National Payments Corporation of India (NPCI) – what were your biggest achievements? What were some of the innovations on the security side that were introduced during your tenure at NPCI?

I think this was the best era that India has ever witnessed with the digital wave – be it for the financial sector, be it for banking, be it even for a common man. India, at large, was introduced with the DBT (Direct Benefit Transfer) in banking in the last ten years. Earlier, the bank branch was the only option for any banking transactional activities. Unless you physically visited the bank, nothing was possible. Now, everything has moved into the digital space. It has spread across the banks and now almost every banking institution in the country is implementing mobile-based transaction, web-based transaction or UPI.

I was lucky to be part of this first-ever digital evolution in India’s banking sector. What we did at NPCI is what every Indian is using today — be it mobile banking, IMPS, UPI, RuPay, NETC, BBPS or AEPS, the most efficiently used product by the government today for DBT (Direct Benefit Transfer). I think, for me, it was a worthy field on which I have roped. In addition to the implementation of robust security controls within NPCI’s own infrastructure, whatever risk framework or controls I have created for the entire ecosystem have become staple today. Some of them are like real-time fraud monitoring, implementation of a network compliance program for over 2000 banks by a single network, member onboarding program, card vendor security program, very unique settlement risk management etc.

The implementation of common adequate control across banks was really a big challenge because India is a country with diversity in terms of digital banking — public sector, private sector banks, cooperative banks, and very small community banks. So, every bank had a different way of dealing with security. Hence, keeping every bank connected with NPCI’s central platform in a controlled environment, with millions of transactions occurring every day while providing safety and security in each transaction were few of our key achievements.

More businesses are embracing digital and outsourcing pieces of IT functionality to third parties. Third-party vendors in-turn outsource to sub-contractors. That increases the risk quotient and broadens the attack surface for the organization. What should organizations be doing to mitigate these new risks?

Banks are becoming technology companies today due to the fact of increased dependency on technology. Yet their biggest functionality remain is banking. Nobody else understands about credit risk, market risk and liquidity risk better than banks do. But when it comes to technology risks, banks or the financial institutions are not always capable to manage them in an efficient way.

And this is the point when there is more reliance on outsourcing. Fintech approach for the IT infrastructure has helped increase the digital footprint of banks to meet the demand from customers for seamless availability 24/7. Earlier banks used to stop activities at 4 pm. Now it is round the clock as it is outsourced to Fintech companies who are running the show. Fintechs need not know banking, all they need to know is how to run the technology for banking. So, that is a good model which has emerged.

Selection of IT partners for outsourcing is a very important aspect and risk parameters for outsourcing decision-making must include safety, security and availability as a core risk requirement and that is where FIS comes in. We provide safety, security, availability, which are the prominent requirement for the bank, from the outsourcing perspective, which provides so much efficiency. Today, we are present in 132 countries because of this reason. This model is working successfully for a large sector of banks in the US, India, Europe or in Latin America.

But when it comes to outsourcing, one needs to understand very clearly what to outsource and what not to outsource. Regulatory compliance has become stricter and demands lots of checks and balances on the risk appetite of banks and eventually, the banks are responsible to comply. Hence, banks must know that what they are outsourcing in view of the business compliance requirements.

We see a lot of fraud happening in India and people are now hesitant to use mobile wallet apps. There are reported cases where people have lost their life savings through wallet fraud. Do you think it is a weakness of the technology and poor security controls or is it just a lack of awareness and alertness?

Well, frauds can happen because of two reasons. One, there is a technical flaw, which the customer is not aware of, but a fraudster or hacker exploits it and uses it to commit frauds. Second, the customers knowingly or unknowingly give away credentials to fraudsters which are used later to commit fraudulent activities.

When a customer goes to an ATM and his card is skimmed, he will never come to know of it. He has just done the transaction as he has been doing. Later, his card gets used fraudulently. So, here the customer is not involved. But that’s not the case in all type of channels. Let’s take an example of UPI. In UPI or any mobile wallet based on UPI, there are three layers of security, which cannot be compromised technically.

All frauds happening today on UPI are not because of a technical flaw but because of the customers’ unawareness. Unless a customer shares some information to a fraudster, one cannot just compromise an account. It is just impossible. With my experience after investigating so many frauds in my previous role, I have concluded that no UPI frauds are happening today without the customers’ involvement. In my view, 80% of fraud in India, especially in this segment of mobile and UPI happen out of greed. Customers often get calls like – you have got a bonus; you have got PF (Provident Fund); you have got some LIC policy which you had started two years ago; or you have got some reward. So, you know, all this is out of greed and people are giving information to fraudsters.

20% of frauds are happening because of fear like – your account is going to be blocked or account will be deactivated unless some amount is paid. All this is because of the fear that is being created. Eventually, it is social engineering that is used successfully by fraudsters and customers are falling prey to it. When the customer shares all the credentials, shared OTP, received fraud SMS, clicked a link somewhere which they received on WhatsApp or email or SMS which have been redirected to a Google form which asks the customers to fill in details such as – name, mobile number, card number, expiry date, CVV, OTP, everything. If the customers fill up this form, no technology can safeguard them. However, I am not saying that technology is 100% fool proof. It could be possible that some or the other flaw may be detected. But the current platform is much secure compared to any other products.

What are the initiatives taken by the regulator and the Indian authorities to address wallet fraud?

There is continuous improvement happening in all aspects. RBI has now formed a fraud data repository in which banks need to compulsorily report frauds, which can be used for analytics purpose and some action can be taken to overcome them. Banks are now investing in resources for the real-time monitoring of fraud. We have a solution for the real-time fraud monitoring – Memento – which many banks have implemented or are in the process to implement in India. This can successfully predict the probability of frauds before the accounts are debited. Banks are investing in these kinds of innovative products. We are also helping our customers, those who are availing services from FIS, to invest not only in technology but also in people and services. So, together we can provide them with some experts and technology to solve this fraud mania. A lot of innovation is happening by banks, by regulators and by leaders like us in terms of fraud prevention.

With the current WFH situation and moratorium announcement by the RBI, there have been reports on the surge in attacks on several fronts. What are the key things to keep in mind to mitigate frauds?

I think there are no credible data available, as of now, which can confirm that there is a significant increase in the number of attacks. But, from the informal sources and going by the trend that I have been following, there is an increase in the number of cyberattacks. But eventually what will happen is that they will come in light only when people come back to the office, brainstorm, analyse the data and compare it with pre and post-Corona situation.

Only then we will have the real statistics about the increase. There are two parts to it. One, for sure, is that while we all know maximum people are working from home, it is too difficult to replicate the same controlled environment of working from the office. So, there is a possibility where some or the other weak control may be exploited by the fraudsters, resulting in damage. Fortunately, no such events have been reported so far. But there could be a remote possibility because the level of control varies from work from home than in the organization. Probably the critical infrastructure and the big organizations are having adequate controls, but they may want to enhance the controls than what it is right now.

The second is on the consumer side. There are many frauds reported especially with the announcement of the moratorium of loans. And it is a universal fact that fraudsters are always much ahead of us. The day moratorium was announced, people started selling false products, asking people for their card details, account details, OTP and everything. There is greed, as I mentioned earlier. Customers give everything without knowing that there is no need to give username and password of net banking accounts to avail moratorium benefits. There are multiple cases of this new modus operandi in this moratorium and fraudsters have duped people with the false information that RBI has announced three months but they can extend the time up to another three months.

Customers are asked to pay some amount which the fraudsters get. Again, it is not an account taking over. But you know if I am paying, let’s say INR 2 lakh a month (approximately US$2,633.44), and INR 6 lakh for three months (approximately US$7,900.64), instead of that I am going to save INR 12 lakh for six months (approximately US$15,801.28), I might not mind giving INR 10000 (approximately US$131.683) to a guy who is offering me a six months ease of payment.

People have paid money to fraudsters in such cases where they get an extension in the moratorium for six months. Several such things are happening and unfortunately, people are falling into the trap of fraudsters. But again, my take on this is that greed and fear are the biggest reasons. Customers need to act wisely. There is no bank anywhere in the world that will ask for username and password ever, for any reason whatsoever. This message must go to the customer and that is how one can prevent frauds.

How will the world be after this COVID-19 phase? What do you expect to be different in a post-lockdown world?

I think the service culture must change significantly post the COVID-19 situation, because the way we used to analyse risk in terms of various scenarios and various probabilities, has gone for a toss completely.

Because, for example, we used to have business continuity from city to city and country to country. But nobody ever thought that the whole world will be shut for so many days. So that has changed completely. We never envisaged that not more than 1 or 2% people will work from home if there is a demand and remaining will be available. The situation has completely reversed. Only 1 or 2% of the people are working in the office and 98% are working from home. This invites many new risks. And therefore, these were never thought of.

From a credit perspective, whatever business proposition we did about receivables has gone for a toss, which has impacted other liquidity issues. Because at no point of time did anyone envisage a lockdown for three or four months down the line. I believe it is the time where we, the risk professionals, must think for complete different risk scenarios in the future because of newer risks which were never ever thought of, have emerged. A newer risk covering product may come from the insurance side with new risk modelling or risk analytics models for banking may completely change for the aforementioned scenarios.

Newer services and newer methods will be identified because the world has changed significantly right now and that will impact the ability of risk managers to see things differently and control those in the time ahead. So that is something which is very, very important from the risk side.

Augustin Kurian is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news features on cybersecurity trends.

Now Patched! Vulnerabilities in Newsletter Plugin Affect Over 300,000 Sites

Cybercriminals Tried to Access Database Logins of 1.3 Mn WordPress Sites

The threat intelligence team from cybersecurity firm Wordfence, urged users of WordPress sites to update their installations to defend against threat actors who are trying to exploit vulnerabilities  in WordPress plugins. The plugin vulnerabilities are now fixed.

Rated as medium and high severity issues, the two flaws “Reflected Cross-Site Scripting (XSS)” and “PHP Object Injection”  were found in the Newsletter WordPress plugin, which has over 300,000 installations. If exploited successfully, the vulnerabilities may allow hackers to create backdoors, add rogue admins, or take control over the website, affecting around 300,000 sites. Wordfence advised users to fix the vulnerabilities by updating them with the latest version 6.8.3.

Reflected Cross-Site Scripting Flaw

The Cross-Site Scripting (XSS) vulnerabilities are used to take over a website if an administrator accesses a page on their site containing a malicious JavaScript. An attacker can trick a victim into clicking a specially crafted link to make changes to a site.

Exploiting a Reflected XSS vulnerability usually relies on an attacker tricking their victim into clicking a malicious link which sends the victim to the vulnerable site along with a malicious payload. This can be done in a number of ways, but it is common to first link to an intermediate site controlled by the attacker, which then sends a request containing a malicious payload to the vulnerable site on behalf of the victim     

–    researchers explained

PHP Object Injection Vulnerability

Attackers use the PHP Object Injection flaw to inject a PHP object that might be processed by code from another plugin or theme. It is used to execute arbitrary code, upload files, or other tactics that could lead to website takeover.

The researchers strongly recommended users to update to the latest version of the Newsletter plugin to avoid any intrusions.

Hackers Target 1.3 Mn WordPress websites

Recently, security experts discovered that cybercriminals targeted around 1.3 million WordPress websites in a single day to steal database login credentials. It is found that hackers tried to steal config files by exploiting known XSS vulnerabilities in WordPress plugins and themes. The attackers tried to download the wp-config.php WordPress configuration file, which contains connection details, authentication unique keys, and salts along with database credentials. In case attackers successfully exploited any vulnerable plugins used by the targeted sites, they could easily steal login credentials from the databases and take control over the websites.

 

Google Ads Gear-up to Implement SCC Post EU-U.S. Privacy Shield Invalidation

Google Ads, Google LLC, Google Ads honors EU-U.S. Privacy Shield Invalidation

On July 16, 2020, the European Court of Justice (ECJ) annulled the “EU-U.S. Privacy Shield” framework, which was accepted by the European Union (EU) four years back on July 12, 2016, and came into effect since August 01, of the same year. The ECJ cited gaps in the data security measures of the U.S. Surveillance Law and regarded them as “inadequate” to protect the data privacy rights of the EU citizens as defined under the General Data Protection Regulation (GDPR) formulated in 2018. Abiding by the judgment, Google, a tech giant that harnesses and uses personal data for certain features and apps, is all set to move towards Standard Contractual Clauses (SCCs) for transfers of online advertising data out of Europe Economic Area, Switzerland and the U.K.

By Mihir Bagwe, Tech Writer, CISO MAG

  Key Highlights  

  • EU-U.S. Privacy Shield was invalidated by ECJ on July 16, 2020.
  • ECJ asked businesses to follow the Standard Contractual Clauses (SCC) provision.
  • Google has already adapted the SCC for addressing its data transfer requirements of Google Cloud and G Suite products.
  • It is now all set to move Google Ads to SCC from August 12, 2020.
  • As a result, it will be updating their existing Google Ads Data Processing Terms, Google Ads Controller-Controller Data Protection Terms and Google Measurement Controller-Controller Data Protection Terms.
  • The invalidation is proving costly and time consuming for many businesses.

Google Moves to Standard Contractual Clauses (SCC)

This is not the first instance of scrapping a data transfer framework between the transatlantic. In 2015, a similar framework known as Safe Harbor was taken down by the ECJ and thus, companies were asked to use the SCC to authorize the transfer of data across the continents. Similarly, the ECJ has again asked companies to revert to the SCCs and data regulators to keep a close eye on the GDPR compliance of the U.S. companies.

Adhering to this, Google has already implemented the SCC to address EU data-transfer requirements for Google Cloud Platform and G Suite. However, one of its most aggressively profit-making products – Google Ads – was still not aboard this ship. But this is all set to change on August 12, 2020. Google Ads has sent an intimation to all its users stating that it honors the ECJ’s ruling of invalidating the EU-U.S. Privacy Shield and is moving towards the SCC.

Google Ads GDPR Compliance Notice
Google’s Mail

The effect of these changes will be seen in the existing Google Ads Data Processing Terms, Google Ads Controller-Controller Data Protection Terms and Google Measurement Controller-Controller Data Protection Terms. Google was also quick to clear the air that they are implementing the SCC only to fulfill the GDPR compliance and that these changes will not give them any additional data rights over its users.

Effects of EU-U.S. Privacy Shield Invalidation

ECJ’s ruling came as a shock to the U.S. Department of Commerce. However, it is optimistic and looking forward to improving the personal data privacy measures of the Privacy Shield. They strongly feel that the framework can be reestablished in the coming years for the ease of businesses between the two continents.

In the meanwhile, the existing members of the shield, of which 70% are small and medium-sized enterprises (SMEs), are facing an uphill task reverting to the SCCs in the wake of the ongoing pandemic. Many businesses have contracted resources and are bootstrapped on the financial front.  The legal teams of software companies that solely relied on the Privacy Shield are scampering to update their terms and conditions and issuing updated versions of existing contracts if they wish to continue processing EU data. Companies are now completely dependent on their lawyers for creating thousands of new contracts, which also need to be signed manually as per SCCs requirement. Hence, this shift to Standard Contractual Clauses is not only proving to be costly but also a time-consuming affair.

About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 


Other Posts from the Author:

Online Shopping or Scam? FBI Alerts Consumers About Fraudulent E-Commerce Schemes

online shopping, International Fraud Awareness Week

The FBI warned consumers to be vigilant while shopping online, as cybercriminals are targeting e-commerce shoppers to steal sensitive information. In a security alert, the FBI stated that it has seen a spike in online shopping scams. Attackers are targeting shoppers by redirecting them to fraudulent websites via social media platforms and search engines.

Online Shopping or Monetary Loss?

According to the Federal Trade Commission (FTC), the number of complaints on online shopping scams has grown every year and victims have lost a total of $420 million dollars since 2015. The commission received more than 86,000 complaints related to online shopping issues in 2019.

The FBI received several complaints from victims stating they have not received items they purchased and were led to fraudulent websites via ads on social media platforms or while searching for specific items on online shopping pages. Complaints reported to the FBI include:

  • Disposable face masks shipped from China were received regardless of what was ordered.
  • The payment was made using an online money transfer service.
  • The retail websites provided valid but unassociated U.S. addresses and telephone numbers under a ‘Contact Us’ link, misleading victims to believe the retailer was located within the U.S.
  • Many of the websites used content copied from legitimate sites; in addition, the same unassociated addresses and telephone numbers were listed for multiple retailers.

Some victims who complained to the vendor about their shipments were offered partial reimbursement and told to keep the face masks as compensation. Others were told to return the items to China in order to be reimbursed, which would result in the victim paying high postage fees, or agreeing to a partial reimbursement of the product ordered without returning the items received. All attempts made by the victims to be fully reimbursed, or receive the actual items ordered, were unsuccessful.

FBI 

How Attackers Target Online Shoppers

The FBI listed the indicators of the fake websites that attackers used to target online shoppers:

  • Instead of .com, the fraudulent websites used the Internet top-level domains (TLD) “.club” and “.top.”
  • Websites offered merchandise at significantly discounted prices.
  • Uniform Resource Locator (URL) or web addresses were registered recently (within the last six months).
  • Websites used content copied from legitimate sites and often shared the same contact information.
  • The websites were advertised on social media.
  • Criminal actors utilized a private domain registration service to avoid personal information being published in the WHOIS Public Internet Directory.

How to Spot/Avoid a Fraudulent Shopping Site

Based on victims’ complaints, the FBI said that fake shopping sites have multiple things in common and can be easily detected with simple security checks, including:

  • Do your homework on the retailer to ensure it is legitimate.
  • Check the WHOIS Public Internet Directory for the retailer’s domain registration information.
  • Check other websites regarding the company for reviews and complaints.
  • Check the contact details of the website on the “Contact Us” page, specifically the address, email, and phone number, to confirm whether the retailer is legitimate.
  • Be wary of online retailers offering goods at significantly discounted prices.
  • Be wary of online retailers who use a free email service instead of a company email address.
  • Do not judge a company by their website; flashy websites can be set up and taken down quickly.

The FBI recommended online shoppers to be alert about unreliable offers/low prices on an online store, when compared to other online stores.

 

Operation North Star: A New Phishing Campaign Disguised as Job Posting

Doxing attacks

McAfee’s advanced threat research team discovered a new phishing campaign linked to the North Korean hackers targeting the U.S. defense and aerospace sectors with fake job opportunities. The campaign, which is dubbed as “Operation North Star,” began in late March and lasted till May 2020, McAfee said in a security alert.

Operation North Star’s Modus Operandi

The hackers impersonated recruiters and  sent malicious emails with Microsoft Office templates to high-profile employees  with an aim of injecting malware in the targeted devices to obtain  network systems access and steal data. The Microsoft Office templates were hosted on a command and control server and the download link was embedded in the first stage document. The malicious documents contained job postings  from leading U.S. defense  contractors to lure victims into opening them and ultimately execute the payload.

The hackers coaxed the victims to recruit for leading U.S. defense and aerospace programs and groups including:

  • F-22 Fighter Jet Program
  • Defense, Space and Security (DSS)
  • Photovoltaics for space solar cells
  • Aeronautics Integrated Fighter Group
  • Military aircraft modernization programs

McAfee researchers also observed fake job offers pertaining to sectors outside of defense and aerospace, such as a finance position for a leading animation studio.

Attack Overview

Image Source: McAfee

The researchers also stated that the attack techniques or TTPs (Techniques, Tactics, and Procedures) of Operation North Star are similar to previously discovered campaigns associated with “Hidden Cobra,” a North Korean state-sponsored hacking group which was active from 2017 to 2019.

Hidden Cobra group consists of multiple threat actor groups like Lazarus, Kimsuky, KONNI, and APT37, which target organizations around the world by gathering data around military technologies to cryptocurrency theft from leading exchanges.

“Our analysis indicates that one of the purposes of the activity in 2020 was to install data gathering implants on victims’ machines. These DLL implants were intended to gather basic information from the victims’ machines with the purpose of victim identification. The data collected from the target machine could be useful in classifying the value of the target. McAfee ATR noticed several different types of implants were used by the adversary in the 2020 campaigns,” the researchers said in a report.

“The TTPs of this campaign align with those of previous Hidden Cobra operations from 2017 using the same defense contractors as lures. The 2017 campaign also utilized malicious Microsoft Word documents containing job postings relating to certain technologies such as job descriptions for engineering and project management positions involving aerospace and military surveillance programs. These job descriptions are legitimate and taken directly from the defense contractor’s website. The exploitation method used in this campaign relies upon a remote Office template injection method, a technique that we have seen state actors use recently,” the report added.

 

Securing the Hybrid Workforce Begins with Three Crucial Steps

hybrid workforce

The global shift to a remote workforce has redefined the way organizations structure their business models. As executives reestablish work policies to accommodate remote employees well beyond the initially anticipated duration, a new era of work will emerge: the hybrid workforce, one more largely split between office and remote environments. While this transition brings a wave of opportunity for organizations and employees, it also opens new doors for bad actors to capitalize on strained IT departments who have taken on additional responsibility to ensure sensitive data remains secure, whether on or off the corporate network.

By Rick Vanover, Senior Director of Product Strategy for Veeam Software

While threats to company data range in attack method, ransomware continues to be the most prominent risk known to organizations worldwide, with a 41% increase in 2019 alone. It’s important that companies focus on acknowledging this threat and deploying strategies to prepare, defend and repair incidents, before adapting to a hybrid workforce model. This process will prevent organizations from falling victim to attacks where data loss or ransom payment are the only unfortunate options. To win the war on ransomware, organizations should incorporate a plan for IT organizations that ensures they have the resilience needed to overcome any attack. Let’s explore three crucial steps for ransomware resilience in more detail.

1. Focus on education first, avoid reactive approaches to threats later

Education – beginning after threat actors are identified – should be the first step taken on the path towards resilience. To avoid being caught in a reactive position, should a ransomware incident arise, it’s important to understand the three main mechanisms for entry: internet-connected RDP or other remote access, phishing attacks and software vulnerabilities. Once organizations know where the threats lie, they can tactfully approach training with strategies to refine IT and user security, putting additional preparation tactics in place. Identifying the top three mechanisms can help IT administration isolate RDP servers with backup components, integrate tools to assess the threat of phishing attacks to help spot and respond correctly, and inform users on recurrent updates to critical categories of IT assets, such as operating systems, applications, databases and device firmware.

Additionally, preparing how to use the ransomware tools in place will help IT organizations familiarize themselves with different restore scenarios. Whether it be a secure restore process that will abort when malware is detected or software that can detect ransomware ahead of restoring a system, the ability to perform different restore scenarios will become invaluable to organizations. When an attack does happen, they will recognize, understand and have confidence in the process of working towards recovery. By taking the education aspect of these steps seriously, organizations can decrease the ransomware risks, costs and pressure of dealing with a ransomware incident unprepared.

2. Implement backup solutions that maintain business continuity

An important part of ransomware resiliency is the implementation of backup infrastructure to create and maintain strong business continuity. Organizations need to have a reliable system in place that protects their servers and keeps them from ever having to pay to get their data back. Consider keeping the backup server isolated from the internet and limit shared accounts that grant access to all users. Instead, assign specific tasks within the server that are relevant for users and require two-factor authentication for remote desktop access. Additionally, backups with an air-gapped, offline or immutable copy of data paired with the 3-2-1 rule will provide one of the most critical defenses against ransomware, insider threats and accidental deletion.

Furthermore, detecting a ransomware threat as early as possible gives IT organizations a significant advantage. This requires tools in place to flag possible threat activity. For endpoint devices displaced remotely, backup repositories that are set up to identify risks will give IT further insight into an incredible surface area to analyze for potential threat introduction. If implementations don’t prohibit attacks, another viable option is encrypting backups wherever possible for an additional layer of protection – threat actors charging ransom to prevent leaking data do not want to have to decrypt it. When it comes to a ransomware incident, there isn’t one single way to recover, but there are many options aside from these that organizations can take. The important thing to remember is that resiliency will be predicated on how backup solutions are implemented, the behavior of threat and the course of remediation. Take time to research the options available and ensure that solutions are implemented to protect your company.

3. Prepare to remediate an incident in advance

Even when there are steps in place that leverage education and implementation techniques to combat ransomware before an attack hits, organizations should still be prepared to remediate a threat if introduced. Layers of defense against attacks are invaluable, but organizations need to also map out specifically what to do when a threat is discovered. Should a ransomware incident happen, organizations need to have support in place to guide the restore process so that backups aren’t put at risk. Communication is key, having a list of security, incident response, and identity management contacts in place if needed – inside the organization or externally – will help ease the process towards remediation.

Next, have a pre-approved chain of decision makers in place. When it comes time to make decisions, like whether to restore or to fail over company data in an event of an attack, organizations should know who to turn to for decision authority. If conditions are ready to restore, IT should be familiar with recovery options based on the ransomware situation. Implement additional checks for safety before putting systems on the network again – like an antivirus scan before restoration completes – and ensure the right process is underway. Once the process is complete, implement a sweeping forced change of passwords to reduce the threat resurfacing.

The threat that ransomware poses to organizations both large and small is real. While no one can predict when or how an attack will happen, IT organizations that have a strong, multi-layered defense and strategy in place have a greater chance for recovery. With the right preparation, the steps outlined here can increase any organization’s resiliency – whether in office, remote or a combination of the two – against a ransomware incident and avoid data loss, financial loss, business reputation damage or more.

About the Author

Rick VanoverRick Vanover (Cisco Champion, VMware vExpert) is a Senior Director of Product Strategy for Veeam Software based in Columbus, Ohio. Vanover’s experience includes system administration and IT management; with virtualization, cloud and storage technologies being the central theme of his career recently.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

3 in 4 Security Leaders See Cybersecurity as a Top Priority in 2020

Harness Your System, Free Decryptor, federal government, cybersecurity

CrowdStrike Inc., the developer of cloud-delivered endpoint protection solutions, stated that organizations are seeing cybersecurity as a top priority in 2020.

In its recent survey, “2020 CrowdStrike Asia Pacific and Japan (APJ) State of Cybersecurity Report” the company stated that 74% of respondents believe there should be more investment in cybersecurity to enhance organizations’ security posture. Nearly, 44% of security leaders said the pandemic accelerated their move to cloud solutions, while 82% said COVID-19 changed the way they interact or deliver products and services to customers. CrowdStrike also found a jump in cybercrimes by over 330% since the start of the year, as compared to cybercrimes in 2019.

Other notable findings include:

  • Though organizations have changed their IT environments to accommodate remote workers, 39% of respondents have not changed their security programs because of COVID-19, potentially exposing their organizations to cyber risks from new and more sophisticated attacks.
  • Employee education and communication are key to a successful cybersecurity strategy, yet 20% of business leaders do not know what to do in the event of a data breach, and 36% of respondents have not received communications about COVID-19 themed malware. Moving forward, 76% of APJ business leaders say they plan on additional security training in the future.
  • As we look to the new normal, 67% of business leaders believe that their organizations should invest more in building a remote work environment.
  • The top cybersecurity challenges expected in the next 18 months include remote workforce (54%), new regulation (49%) and costs of compliance (48%), with limited budgets (47%) and additional training (41%) ranking not far behind.

Andrew Littleproud, Vice President, APJ at CrowdStrike, said, “The speed and size of change to a remote workforce led to some inevitable gaps, particularly in the cybersecurity of organizations. Business leaders understand these gaps and expect to address them in the recovery, going beyond good enough’ security measures to ensure their employees remain secure against sophisticated threat activity regardless of where they are located. In the new business normal, it will be vital to implement solutions that can be quickly deployed at scale to detect new threats, adhere to new regulations, and leverage the cloud so they can be easily managed remotely.”

The survey findings are based on the responses from 2,017 business leaders in Australia, New Zealand, India, Singapore, Philippines, Thailand, Malaysia, Indonesia, Hong Kong, and Japan.

 

Meet the Teen “Mastermind” Behind the Greatest Twitter Hack

Twitter hack

Twitter and Twitterati went berserk on July 15, 2020, when a high-profile hack compromised nearly 130 Twitter accounts including verified accounts of known personalities like Jeff Bezos, Bill Gates, Elon Musk, Barack Obama, Joe Biden, and corporate accounts of Apple, Uber and many more. It was a one of a kind hack, and ever since, it has been termed as “The Greatest Twitter Hack,” simply because multiple verified accounts were hacked simultaneously for scamming people.

The FBI Crackdown

The cybercriminals quite literally basked in the glory of their achievements as they successfully collected more than $118,000 by scamming people. However, their happiness was cut short by the Federal Bureau of Investigation (FBI). With regard to the case, the FBI has now arrested a 17-year-old, Graham Ivan Clark, a resident of Tampa, Florida, and pressed 30 counts of felony charges against him for perpetrating the Twitter hack. The FBI also found out that there were two more people, 19-year-old Mason John Sheppard from the U.K. and 22-year-old Nima Fazeli from Orlando, Florida, who acted as accomplices to Clark.

This is not a game… these are serious crimes with serious consequences.

– Andrew Warren, Florida State Attorney

Things We Now Know

  • FBI has arrested Graham Ivan Clark and pressed 30 charges of Felony against him including organized fraud, communications fraud, identity theft, and hacking.
  • Clark had two more accomplices, a 19-year-old Mason John Sheppard from the U.K. and 22-year-old Nima Fazeli from Orlando.
  • The hack reportedly began on May 3, 2020, when Clark, aka Kirk#5270 (Discord username), through social engineering means convinced a Twitter employee that he was a colleague of his and required credentials to access the internal systems of Twitter for certain work.
  • Clark impersonated himself later as a Twitter employee and approached two other hackers (Fazeli aka “Rolex#037” and Sheppard aka “ever so anxious#0001” – both are Discord usernames).
  • He modified the settings of an account owned by Rolex#037 as a proof-of-concept and sold him access to the Twitter account @foreign.
  • Similarly, Clark also sold Sheppard access to multiple Twitter accounts, such as @xx, @dark, @vampire, @obinna, and @drug
  • The FBI tracked the trio from various sources.
    • It used data shared on social media and news outlets to get chat logs and user details from Discord.
    • They further obtained data from Coinbase about the Bitcoin addresses involved in the hacks.
    • After correlating the data, they found that unknowingly some of the culprits had used their original driving licenses and email IDs to register with cryptocurrency exchanges for withdrawing the scammed money.

“This is not an ordinary 17-year-old”

Andrew Warren, Florida state attorney, in a press conference said, “This is not an ordinary 17-year-old. This could have had a massive, massive amount of money stolen from people, it could have destabilized financial markets within America and across the globe; because he had access to powerful politicians’ Twitter accounts, he could have undermined politics as well as international diplomacy. This is not a game… these are serious crimes with serious consequences.”

According to the officials, Clark is charged as an adult in the State of Florida and shall get sentenced accordingly, if found guilty in any of his 30 charges. Similarly, Fazeli faces a maximum of five years in prison and a $250,000 fine, if found guilty for one count of computer intrusion. However, Sheppard is being charged on three counts, which include computer intrusion, wire fraud conspiracy, and money laundering conspiracy. The maximum for these crimes is a 20-year in a prison sentence and a $250,000 fine.

That Refurbished Smartphone Might be Unsafe to Use!

That Refurbished Smartphone Might be Unsafe to Use!

A new investigation from the consumer advocacy organization Which? revealed that 3 in 10 second-hand smartphones are vulnerable to being hacked as they are no longer supported by security updates from the manufacturer, leaving the future owners open to potential cyber risks. If your phone is not running on the latest version of its software, your device security and data privacy may be at risk, Which? said.

The investigation centered around three pre-owned mobile phone retailers, SmartFoneStore, Music Magpie, and CeX. Almost a third (31%) of the phones at CeX could be vulnerable. A fifth (20%) of the phone models found on Music Magpie and one in six (17%) on SmartFoneStore are also exposed to cyberthreats.

According to Which?, some of the phones being resold without security updates include Apple iPhone 5, Huawei P10, Google Pixel XL, Samsung A8 Plus, and the Samsung Galaxy S7. In the wake of the Which? investigation, Music Magpie has removed the unsupported devices from its platform. SmartFoneStore also issued an update, adding a warning on unsupported devices so consumers are aware before they buy them.

Other findings from the investigation include:

  • Around 62% said they think a mobile phone is broken down for parts when it is sent for recycling, but Which? investigation found most phones are actually resold.
  • Music Magpie told Which? it refurbishes 95% of the products it receives from consumers, all of which are resold in the U.K. It sells more than 250,000 phones a year.
  • CeX said the majority of phones are resold in the U.K. – it sold approximately one million phones in 2019.
  • SmartFoneStore, which sources phones from businesses and retailers, told Which? it sells around 2,000 per month.

“Out-of-support devices might not immediately have problems, but without security updates, the risk to the user of being hacked is increased. The lack of robust, sustainable solutions for the disposal of mobile phones is an ongoing concern. With effective options in place to resell pre-owned devices, the potential is there to prolong their lifespans – but until manufacturers offer complete transparency about how long devices will be supported, and those offering only a couple of years of support do better, it is more difficult to take advantage of these services without putting consumers at risk,” Which? said in its analysis.

Kate Bevan, Which? Computing editor, said, “Keeping mobile phones in circulation for longer is better for the environment but it shouldn’t come at the cost of customer security. Unless manufacturers become more transparent, and those offering vital updates for only a couple of years do better, there is a risk that second-hand phones will be vulnerable to hackers or end up dumped in a landfill site. If your mobile phone is no longer receiving security updates you should consider upgrading as soon as possible. While you continue to use an out-of-support device, you must take steps to mitigate the risks – including using mobile antivirus software, managing app permissions and only downloading from official stores.”