Home Blog Page 206

Over 329,000 Canadians’ Data Compromised After Cyberattack on CPA Canada

CPA Canada cyberattack

The Chartered Professional Accountants of Canada (CPA)  disclosed a security breach that affected over 329,000 members and stakeholders of the association. It is said that unknown hackers compromised the CPA Canada website and obtained information related to the distribution of its magazine. The exposed information includes names, home addresses, email addresses, and other sensitive information.  However, CPA clarified that information like passwords and credit card numbers were protected by encryption. “There is no evidence that the encryption keys were affected in this incident and we have no reason to believe the encryption was compromised,” the company said in its security incident report.

According to CPA Canada, the attack by unauthorized third-party members occurred between November 30, 2019 and May 1, 2020. The company warned the compromised data could be used in phishing scams and urged the affected users to remain vigilant. While hackers behind the cyberattack are unknown, CPA Canada stated that it beefed up its security measures and contacted the Canadian Anti-Fraud Centre and privacy authorities for further investigation on the incident.

CPA Canada is the national organization representing the Canadian accounting profession, with over 210,000 chartered professional accountants in Canada and around the world. It conducts research on business issues, supports the setting of accounting, auditing and assurance standards for businesses, non-profits, and the government.

“CPA Canada worked closely with cybersecurity experts to conduct its investigation, to ensure that its systems were promptly secured and to identify what information was involved. In addition to notifying potentially affected individuals directly, we have contacted law enforcement, the Canadian Anti-Fraud Centre, and privacy authorities where applicable,” the company said in a statement.

The statement added, “We encourage individuals to remain vigilant, as always, about any emails, text messages or phone calls you may receive asking you to provide sensitive information or click on links or attachments, or that use urgent or threatening language, even if they appear to come from CPA Canada or an individual or company you know or trust.”

Canadians Refuse to Divulge Personal Data

A survey report from the Canadian Internet Registration Authority (CIRA) revealed that most Canadians refuse to provide their personal information to access free online services. The report “2020 Canadians Deserve a Better Internet Report” disclosed that except online banking services (52%), most Canadians stated that they are unwilling to share their sensitive data for better products and services online. Only 26% of respondents admitted that they are willing to give personal information in return for better video streaming services. Around 23% of Canadians stated that they disclose personal details to use social media services and 15% are willing to share personal data for access to internet-connected devices like baby monitors.

 

Looking for a Job? Beware of Fake CV Phishing Scams!

phishing scam, fake CV phishing scam

The unemployment ratio around the globe has skyrocketed amid the COVID-19 crisis painting a somber image of what can be termed as “The Great Economic Depression 2.0”. As per CNBC’s report, the unemployment rate in the U.S. alone is expected to reach around 20%. With 20.5 million jobs already lost in April, economists estimate another 8.33 million job cuts in May. However, cybercriminals are using this opportunity for luring this already vulnerable group of unemployed people into fake CV phishing scams.

The Fake CV Phishing Scam

Researchers at Check Point, a cybersecurity service provider, have discovered that in May 2020, nearly 250 new domains have been registered that consist of the word “employment.”  Of these, 7% of domains were found to be malicious and 9% were ought to be suspicious. They also observed a doubling-up of the ratio for the past two months with 1 out of every 450 malicious files being a fake CV phishing scam.

The cybercriminals lured potential victims into opening the malicious .xls attachments, firstly by naming the files as a person’s name, which indicated that it is that person’s CV and secondly by using phishing email subject lines such as “applying for a job” or “regarding job.” Victims were then asked to render “enable content” permission, which further initiated the malicious macro file downloading the final payload like a malware, trojan, ransomware.

The U.K. and Romanian Version

Check Point researchers also found another version of a similar campaign running in the U.K. and Romania.

fake CV phishing scam
Image Source: Check Point

However, these emails had a different subject line and a different file format of the malicious attachment. Its subject said, “CV from China” and contained an ISO format file (CV.iso). On opening this .iso file, a malicious .exe file (CV.exe) would run, installing an info-stealing malware on the victim’s system.

With nations coming out of the lockdown and businesses gradually coming back to life, economists expect to see a dip in unemployment ratio from June onwards, while cybersecurity experts hope to see a subsequent dip in the fake CV phishing scams.

Hackers Expose 5 Bn Records in 2019, Costing U.S. Firms $1.2 Tn

BlackMatter Group, Volvo Cars ransomware attack

According to a survey report from identity and access management firm ForgeRock, threat actors exposed more than 5 billion consumer records in 2019, costing over $1.2 trillion to organizations in the U.S.

The report “2019 Consumer Identity Breach Report” revealed that the total data breach incidents over the last two years have cost U.S. enterprises $1.8 trillion. The survey found that the data breaches increased both in numbers and cost. While unauthorized access was the most common attack vector accounting to 40% of breaches,  ransomware and malware was at 15% and phishing at 14%.

Attacks on the Health Care Sector

According to the report, the health care industry emerged as the most targeted industry in 2019, accounting for 382 breaches and costing over $2.45 billion in 2019. Health care providers have become an easy target for attackers, as they hold sensitive information of their patients. Medical records are the most targeted data type in Q1 2020, accounting for 25% of all exposed data. Even though health care being the most targeted industry, technology firms had the highest number of records compromised from data breaches with over 1.37 billion exposed in 2019, costing a total of over $250 billion.

Data Breaches in 2020 Outpace 2019

According to the Q1 2020 data,  this year is set to outpace 2019 in terms of records breached, despite the fact the number of breaches dropped by 57%. There have been 92 data breaches affecting 1.6 billion records in Q1 2020 alone, accounting to 9% more records than Q1 2019. Health care is still the most breached industry in Q1 2020, accounting for 51% of the incidents, which may be due to hackers targeting health care organizations amid the COVID-19 pandemic.

Other Key Findings Include:

  • After health care, the banking, insurance, and financial industries was the second most targeted in 2019, accounting for 12% of all breaches. This is followed by education (7%), government (5%), and retail (5%)
  • Social security numbers and date of birth details were the most targeted data – accounting for 37% of breached information, yet this is down from 54% in 2018
  • Name and addresses (18%) and personal health information (17%) were the second and third most breached data types, respectively
  • Personally identifiable information (PII) remained the most targeted data by attackers and was exposed in 98% of 2019 breaches

Eve Maler, CTO at ForgeRock, said, “When it comes to data breaches, we’re seeing the biggest cybersecurity problem continues to be an identity problem. The Consumer Identity Breach Report’s findings demonstrate that enterprises need to increase their identity and access management maturity. The secret is democratizing data control so organizations can allow known users to hop onto authentication express lanes for a great experience, entrusting them with convenient consent options, and make bad actors jump through extra hoops to help prevent fraud.”

 

Indian Professionals to Set Up Intensive Cybersecurity Training Programs: JA Chowdary

SideCopy Malware Campaign

Covid-19 has pushed everyone to go digital, but they need to adapt and learn to use digital assets securely, said JA Chowdary, IT Advisor, Government of Tamil Nadu, India. Speaking at EC-Council’s Masterclass Virtual CISO Summit on 4 June, Chowdhury said even farmers and non-technical people in India are now using digital tools, but they face the risk of getting hacked, and their data could be stolen. He encouraged Indian startups to create ”Made in India” apps that are more secure. Apps from other nations could have malware and ransomware, he said. Chowdhury also spoke about the educational initiatives taken by professionals in the private sector who are working with some state governments to set up training schools and platforms to spread cybersecurity awareness.

JA Chowdary, IT Advisor, Government of Tamil Nadu, India.
JA Chowdary, IT Advisor, Government of Tamil Nadu, India.

“I observed that the state of Andhra Pradesh was the first to implement eSeva. But IIT students did ethical hacking on the state government assets and found vulnerabilities. We advised the government about this,” said Chowdary.

eSeva is a portal for government to citizen services.  It lists various services, government notices, forms, and orders. It is also a gateway to other industry portals in the state. A note on the homepage says the portal uses “State-of-the-art” technology.

Chowdary said that there are ongoing efforts to set up training institutes and online platforms like Upgrad to increase cybersecurity awareness and address the skills shortage in the country, naming the International Institute of Digital Technologies (IIDT) as an example.

Chowdary who is also the Chairman of the Indian Blockchain Standards Committee, said “This institute will be run by industry professionals and will implement the latest cyber curriculum. It will offer a one-year course. We also plan to introduce a two-year cybersecurity program in Coimbatore run by industry professionals. The pedagogy will include business case studies,” informed Chowdary.

In his role as IT Advisor to the Government of Andhra Pradesh, India, his task was to mobilize investments, create an IT ecosystem, and create employment opportunities. Chowdary will also serve as ex-officio Secretary to the Government in the Chief Minister’s Office. His role includes advising and assisting the government in bringing in investments, generating employment, and encouraging innovation and start-up activities.

He earlier served as the Chairman of the Board of Software Technologies Parks of India (STPI), Hyderabad and Chennai, India. He was one of the key personalities instrumental in bringing about an IT revolution in Hyderabad. He is a well-networked in the Indian IT industry and is a close advisor to former Andhra Pradesh Chief Minister N. Chandrababu Naidu.

Cyberattacks to be the Biggest Challenge for Companies for the Next 12 Months: Report

Cloud Security

Cyberattacks and cyberthreats continue to be the biggest challenges faced by organizations. Cloud data management firm Veeam in its latest “2020 Data Protection Trends Report” has highlighted the same as well as stated that an average ransomware attack costs over $80,000 to restore data. The research paints and alarming figure at a time when organizations are looking to transform their business operations and customer service while embracing digital transformation. Digital Transformation (DX) is at the top of most CXOs’ agendas; in fact, DX spending is expected to approach $7.4 trillion between 2020 and 2023, a CAGR of 17.5%.

The report also indicates that nearly half the global organizations have been impacted in their digital transformation journeys by unreliable, legacy technologies as well as lack of IT skills or expertise which stood at 44%.

“It’s great to see the global drive to embrace technology to deliver a richer user experience, however the Achilles Heel still seems to be how to protect and manage data across the hybrid cloud.  Data protection must move beyond outdated legacy solutions to a higher state of intelligence and be able to anticipate needs and meet evolving demands.  Based on our data, unless business leaders recognize that – and act on it – real transformation just won’t happen,” said Danny Allan, CTO and SVP of Product Strategy at Veeam.

Other key highlights of the report include:

  • The biggest challenge that will impact organizations within the next 12 months is cyberthreats (32%). Shortage of skills to implement technology (30%) and meeting changing customer needs (29%) were also cited as key hurdles.
  • Lack of staff to work on new initiatives (42%) was cited as the most impactful data protection challenge organizations currently have. Lack of budget for new initiatives and lack of visibility on operational performance were also cited.
  • Over a third (39%) of respondents said the ability to improve the reliability of backups is the most likely reason to drive their organization to change its primary backup solution.
  • Over a quarter (27%) of organizations’ data is backed up to the cloud by a Backup as a Service (BaaS) provider. 14% of data across organizations globally is not backed up.
  • Over two in five (43%) organizations plan to leverage cloud-based backup managed by a BaaS provider within the next two years.

“By already starting to modernize their infrastructures in 2020, organizations expect to continue their DX journey and increase their cloud use. Legacy solutions were intended to protect data in physical datacenters in the past, but they’re so outdated and complex that they cost more money, time, resources and trouble than realized. Cloud Data Management provides a simple, flexible and reliable solution that saves costs and resources so they can be repurposed for future development. Data protection can no longer be tied to on-premises, physically-dedicated environments and companies must have flexible licensing options to easily move to a hybrid/multi cloud environment,” Allan concluded.

Remote Work Jeopardizes Corporate Network Security: Report

Remote Security Policy, Remote Work Jeopardizes Corporate Network Security: Report

A recent survey from security firm CyberArk revealed how cyber habits of remote workforce is compromising business systems and making sensitive data vulnerable to attacks. It stated that the surge in remote work brought a new wave of security concerns.

The survey “How Cyber Habits at Home Threaten Corporate Network Security” revealed that work from home employees threaten corporate security.  Nearly 93% of them admitted they reuse passwords and 29% allowed other family members to use their company-issued devices for personal activities like schoolwork, shopping and gaming. It is found that 77% of remote employees are using unmanaged, insecure BYOD (Bring Your Own Devices) to access corporate systems.

While 37% said they insecurely save passwords in browsers on their corporate devices, 66% of employees stated that they are using third-party communication tools like Zoom and Microsoft Teams while working at home. The survey also highlighted that 94% of IT and security teams are confident in their ability to secure the new remote workforce, however, 40% have not increased their security protocols despite the significant change in the way employees connect to corporate systems and the addition of new productivity applications.

The study surveyed 3,000 remote workers and security decision makers across the U.S., U.K., France, and Germany,  and is intended to determine the current scenario of cybersecurity during the ongoing COVID-19 crisis.

“The rush to onboard new applications and services that enable remote work combined with insecure connections and dangerous security practices of employees has significantly widened the attack surface and security strategies need to be updated to match this new dynamic threat landscape. This is especially true when it comes to securing privileged credentials of remote workers, which if compromised could open the door to an organization’s most critical systems and resources,” the report said.

Marianne Budnik, CMO of CyberArk, said, “The security posture of organizations continues to be tested as many remote employees face daunting challenges balancing productivity and security across their professional and personal workspaces. As more organizations extend work-from-home policies for the long term, it’s important to capture lessons learned from the initial phases of remote work and shape future cybersecurity strategies that don’t require employees to make tradeoffs that could put their company at risk.”

Remote Workers Lack Cybersecurity Training

A similar research from cybersecurity firm Promon found that 66% of remote workers in the U.K. haven’t been trained on cybersecurity in the past 12 months, whereas 77% said that they aren’t worried about the security while working remotely. Around 61% said they are using personal devices while working from home. This is adding further security concerns as many of these are likely to be less secure than corporate-issued ones. Cybercriminals are exploiting the current working conditions by carrying out COVID-19-related phishing campaigns and other malicious activities. The findings are based on the responses from 2,000 remote workers in the U.K.

 

Japanese Cryptocurrency Exchange Coincheck Hacked; Customers’ Emails Exposed

Cryptocurrency mining

Cryptocurrency exchange Coincheck admitted that it has become a victim of a security incident in which unknown hackers accessed emails sent to the firm by its customers.

In an official statement, the Tokyo-based firm stated that attackers gained access to DNS records for the coincheck.com domain at the firm’s third-party domain registrar, and altered the records to forward incoming emails to them. It is believed that some emails received between May 31  and June 1, 2020 could be illegally accessed by unauthorized members.

Coincheck stated that compromised mails could have exposed email addresses listed in the recipient and the information listed in the customer’s email, which could later be exploited by cybercriminals. It also said that certain personal information like names, registered address, birth date, phone number, and ID Selfie were exposed in the incident.

While the hackers behind the security incident are unknown, Coincheck clarified that customers’ digital assets are not affected. The company also suspended the remittance of crypto assets temporarily. “Although there is no impact on your assets at this time, we will stop the remittance of crypto assets in our service again, considering the progress of the investigation by the domain registration service operator. Services such as depositing/withdrawing Japanese Yen and receiving/purchasing/selling crypto assets can be used as usual,” Coincheck said.

Coincheck Massive Data Breach

Earlier, in a major cryptocurrency heist, Coincheck lost 58 billion yen ($530 million) after hackers compromised its exchange platform. According to Reuters, the digital coins were stored in a hot wallet instead of the more secure cold wallet, which is not connected to the internet. Coincheck assured that it would return about 90% with internal funds. Japan’s finance regulator Financial Services Agency instructed the company to improve its operations and to submit an incident report.

Surge in Cryptocurrency Crimes

According to a report from U.S. based blockchain security firm CipherTrace, the cryptocurrency industry experienced a huge surge in thefts and frauds in 2019. In its “2019 Cryptocurrency Anti-Money Laundering (AML)” report, CipherTrace revealed that cryptocurrency crimes across the world hit over $4.3 billion in 2019. The report stated that hackers are using sophisticated methods to beat even advanced cybersecurity measures. It also highlighted that cybercriminals robbed around $125 million in Ethereum, Bitcoin, and other digital currencies from different cryptocurrency exchanges in Q2 2019.

 

DopplePaymer Gang Claims it Hit NASA Contractor with Ransomware Attack

NASA

The world was in awe of the successful launch of SpaceX and NASA’s first human-operated rocket. It was a breakthrough and a huge leap forward towards placing humans in space. Soon, wishes and congratulatory messages started pouring in, however, the celebratory mood turned gloomy when an unusual pleasantry was exchanged by the DopplePaymer ransomware gang. They congratulated both SpaceX and NASA for the successful launch, but also announced that they infected a NASA IT contractor with a ransomware attack.

We congratulate SpaceX & NASA for a successful launch. But as for NASA, their partners again don’t care for their data…

DopplePaymer Ransomware Gang

NASA IT Contractor Concedes Ransomware Attack? 

The cybercriminals published this post on a dark web portal, Dopple Leaks, which is DopplePaymer gang’s auction website launched in February 2020. They said that the network perimeter of Digital Management Inc. (DMI), a Maryland-based company providing managed IT and cybersecurity services to corporate and government agencies, was breached. The notorious gang placed the URL of the company hacked along with 20 archive files as proof of their breach. However, this is not the end of the damages done. The gang also posted a long list of 2,583 servers and workstations on DMI’s internal network that have been encrypted and held-up for ransom.

NASA’s Warning

Since COVID-19 forced a majority of Federal workforce to be confined to their homes and work remotely, NASA had warned about a “new wave” of cyberattacks targeted at all Federal Agency Personnel. An agency-wide memo issued by the CIO stated that “NASA employees and contractors should be aware that nation-states and cybercriminals are actively using the COVID-19 pandemic to exploit and target NASA electronic devices, networks, and personal devices. Some of their goals include accessing sensitive information, usernames and passwords, conducting denial of service attacks, spreading disinformation, and carrying out scams.”

The Online Auction Websites Trend

Back in the day, ransomware operators demanded a ransom in exchange for decryption keys. If the victim refused to give in, they simply did not release the keys. This forced the users to completely wipe off previous data and/or replace old systems with new one’s post plugging the security holes. But this model now seems to be an outdated one. However, the ransomware gangs have now started stealing critical and confidential data before encrypting the compromised systems. They then use the stolen data to leverage negotiations. Many ransomware gangs such as Sodinokibi  (also known as REvil) have launched auction websites where they first publish few samples of the leaked data for compelling the victim. If the victim still refuses to pay the ransom, then they hold an auction to sell this leaked data. Either way, it is a win-win scenario and a full-proof plan for the ransomware operators.

80% of Organizations Suffered a Cloud Data Breach in the Past 18 Months

Cloud Security, 80% of Organizations Suffered a Cloud Data Breach in the Past 18 Months

A new research has revealed that 80% of organizations suffered at least one cloud data breach in the past 18 months, while 43% of companies reported 10 or more cloud data breaches.

Ermetic’s research disclosed that nearly 80% of respondents are unable to identify excessive access to sensitive data in IaaS/PaaS environments,  while the top three security concerns associated with cloud production environments include:

  • Security misconfiguration (67%)
  • Lack of adequate visibility into access settings and activities (64%)
  • Identity and access management (IAM) permission errors (61%)

According to the research, most of the cloud data breaches occur due excessive permissions to access cloud data. Cybercriminals could use this opportunity for malicious activities like stealing sensitive data, deploying malware, or disrupting critical business operations. “Excessive permissions may go unnoticed as they are often granted by default when a new resource or service is added to the cloud environment,” the report said.

Shai Morag, CEO of Ermetic, said, “Even though most of the companies surveyed are already using IAM, data loss prevention, data classification and privileged account management products, more than half claimed these were not adequate for protecting cloud environments. Two-thirds cited cloud-native capabilities for authorization and permission management, and security configuration as either a high or an essential priority.”

Some other key findings of the report include:

  • Top three cloud security priorities are compliance monitoring (78%), authorization and permission management (75%), and security configuration management (73%)
  • Top cloud access security priorities are maintaining confidentiality of sensitive data (67%), regulatory compliance (61%) and providing the right level of access (53%)
  • Top cloud access security challenges are insufficient personal/expertise (66%), integrating disparate security solutions (52%) and lack of solutions that can meet their needs (39%)

The research findings are based on the responses from 300 senior security decision makers in the U.S. across the banking (12%), insurance (10%), health care (11%), government entities (8%), utilities (9%), manufacturing (10%), retail (9%), media (11%), software (10%), and pharmaceutical (10%) sectors.