Home Blog Page 216

Stop Auto-Forwarding Emails to Prevent Data Theft: Microsoft

Hackers Target Office 365 Users with SurveyMonkey Phishing Campaign

With more than 200 million active Office 365 users in FY20Q1 (now nearing 258 million) and the corresponding urge to up the security features, Microsoft has now introduced a ‘stop auto-forwarding emails’ configuration. It helps enterprises disable Office 365’s email forwarding capabilities to external recipients by default, putting a tap on enterprise data theft which takes place through email forwarding. Office 365 has now been rebranded as Microsoft 365.

Stop Auto-Forwarding Emails

Threat actors are leveraging fear of the current pandemic situation to carry out smishing and phishing attacks. With work from home and remote access via less or unsecured endpoints, it’s easier for threat actors to compromise an organization’s security perimeter. Consider if one gets access to a user’s mailbox, they can then auto-forward the user’s confidential email(s) to an outside address and access the individual’s and/or organization’s proprietary information. To prevent this malpractice, users need to create a default mail flow rule with the following steps:

  1. Go to Microsoft 365 admin center, select Exchange à mail flow, and on the Rules tab, select the plus sign and choose Create a new rule.
  2. Select More options and enter your new rule Name.
  3. Then click on the drop-down for Apply this rule if, select The sender…, and then is external/ internal.
  4. Select the sender location as Inside the organization and click OK.
  5. Click on the add condition button to open a drop-down. Select The message properties… and further click on include the message type.
  6. On select message type drop-down, choose Auto-forward, and click OK.
  7. Open the Do the following… drop-down, select Block the message…, then reject the message and include an explanation.
  8. Specify a reason for your rejection. This message will pop-up when one tries to send emails to external entities, then select OK.
  9. At the bottom of the screen select Save.

Congratulations! The rule has been created and the threat actors will no longer be able to auto-forward your confidential and critical email messages to external entities. The email forwarding configuration will allow  Office 365 admins to enable the feature only to select employees in their organizations.

Unacademy Suffers a Data Breach; 22 Mn User Records for Sale on Dark Web

DEO data breach

India-based online learning platform Unacademy suffered a data breach that exposed details of 22 million users, cybersecurity firm Cyble revealed. It was also found that the unknown hackers kept 21,909,707 user records for sale at $2,000 on darknet forums. The compromised information included usernames, hashed passwords, date of joining, last login date, account status, email addresses, first and last names, and other account profile details.

Founded in 2010, Unacademy offers thousands of video tutorials with around 14,000 teachers and over 20 million registered online learners.

According to BleepingComputer, most of the Unacademy accounts were created using corporate emails, with the users from companies like Wipro, Infosys, Cognizant, Google, and Facebook. In case these corporate learners used the same password on both their corporate network and Unacademy platform, it could allow hackers to compromise those networks too.

Hemesh Singh, Co-founder and CTO of Unacademy, confirmed the data breach and stated that only 11 million users were affected and no sensitive information like financial data, location or passwords were exposed.

“We have been closely monitoring the situation and can confirm that basic information related to around 11 million learners has been compromised. We follow stringent encryption methods using the PBKDF2 algorithm with a SHA256 hash, making it highly implausible for anyone to access the learner passwords. We also follow an OTP based login system that provides an additional layer of security to our learners. We are doing a complete background check and will be addressing any potential security loophole to further our efforts of ensuring a robust security mechanism,” Singh commented in a media statement.

In a similar data breach discovery, Cyble found hackers selling over 267 million Facebook records for £500 (US$623) on dark web sites and hacker forums. Cyble claimed that the records contain information that could allow attackers to perform spear phishing or SMS attacks to steal credentials.

The exposed information includes email addresses,  first and last names, last connection, status, age, phone numbers, Facebook IDs, dates of birth, age, and other personal data. Facebook clarified that none of the records include passwords. However, the breached information is enough for hackers to launch phishing campaigns, and other online frauds, experts stated.

Password Carelessness Put American Millennials at Cyber Risk: Report

common password of 2021,Password Protection, password spray attacks, Microsoft accounts passwords

Three-quarters of millennials in America use the same password for more than ten different devices, apps, and other social media accounts, according to a study by Clario and OnePoll.

The survey revealed certain alarming statistics about the password practices followed by Americans. Most of the respondents admitted they were using the same password in over 50 different places.

One in fifty millennials believe their smartphone is 100% safe while more than 80% of Americans between the age of 25 and 34 are concerned about the security of their mobile devices, yet 44% use risky features like password autofill, according to survey findings.

Security experts stated that using a single password for all business and personal accounts is not secure. Doing so might lead to massive data loss when someone cracks your password. A hacker would only need just one password to gain access to your entire digital life.

Commenting on the survey findings, Alun Baker, CEO at Clario said, “Smartphones are an integral part of our lives and they contain a huge amount of personally valuable data ranging from personal finance, family photos to private health information. Passwords are not just passwords, they’re keys to our digital life. Using multi-factor authentication, a secured password manager, VPN, and staying up-to-date on data breaches is a good way of protecting yourself from unwanted hacks.”

Security experts at Clario also recommended few steps on good password practices. These include:

  • Use a trusted password manager app instead of password autofill which, unlike autofill, makes it more difficult for other users to gain access to your saved passwords.
  • VPN is not just for work. Use it any time that you connect to WiFi – even if you think it is a secure network.
  • Avoid storing photos or scans of important documents in your photos folder – use a trusted service like Dropbox instead.
  • Check your app permissions. Stay vigilant about the level of permissions that you give to apps on your device, especially if they want to access data that’s irrelevant to their function.
  • Create separate accounts on your devices – for every member of the family.

How the COVID-19 Pandemic Reinforced Hackers’ Revenue Models

Cybercrimes in COVID-19 Pandemic

The industrious and criminal-minded threat actors behind the majority of cyberattacks have reinvented their attack approaches during the ongoing COVID-19 pandemic. Since the advent of the outbreak, cybercriminals are developing new phishing tools, hacking strategies, and exploring different attack avenues to benefit from the crisis and eventually prove their cyber prowess.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

Several new cybersecurity scams and malicious activities have risen during the pandemic.  According to a survey the key cause for the emergence of these new threats is likely due to social distancing norms and malware authors being bored and stuck at home due to the lockdown.

COVID-19 has certainly reshaped the way darknet forums operate. CISO MAG learned four intriguing ways cybercriminals are trying to cash in on public fears.

1. Fake Products in Darknet Markets

Since the beginning of 2020, Coronavirus-related vaccines, virus testing kits, and other fake products are being peddled on the deep web and darknet markets. Hackers are taking advantage of panic as people look for safeguards against the disease. Several security experts warned that the products selling in these hacking forums are in no way real, and buyers are sure to be scammed. For instance, there are fake “vaccines” being sold on the darknet.

2. New Phishing Strategies

COVID-19-related phishing lures, scams, disinformation campaigns, weaponized websites, and malware infections have become widespread across the internet. Recently, a hacker group targeted the World Health Organization (WHO) via a sophisticated phishing attack, which involved an email hosted on a phishing domain that tried to trick the employees into entering their credentials. Researchers are noticing new types of phishing campaigns that pretend to be from authenticate sources, trying to trick users into downloading malicious attachments or entering sensitive data in fake forms.

Recently, a security firm discovered that threat actors distributed malware disguised as “Coronavirus Map” to steal personal information that is stored in the user’s browser. Attackers designed multiple websites related to Coronavirus information to prompt users to click/download an application to keep themselves updated on the situation. The website displays a map (a lookalike of a genuine one) representing the COVID-19 spread. The map generates a malicious binary file and installs it on victims’ devices.

3. Demand for Ransom Soars

With organizations working remotely, the security of the remote employees’ devices becomes a major concern for companies across the globe. Several industry experts stated that remote work increased the risks of cyberthreats like never before. Ransomware attacks on remote workers have become an additional threat level to organizations, especially for health care providers and businesses in financial, federal, and state agencies that deal with sensitive data. The ransomware operators are forcing enterprises to pay high ransom in order to get decryption keys. The average enterprise ransom payments increased 33% ($111,605) in Q1 of 2020 from Q4 of 2019, a survey revealed.

Information technology services provider Cognizant admitted that it is a recent victim of a ransomware attack. The IT giant stated that it was hit by Maze ransomware that caused service disruptions for some of its clients.

4. Income from Selling Credentials

Stolen user credentials and financial information have long been prevalent commodities on hacking forums. But with large swaths of remote workers depending on video conferencing apps and other virtual private networks, hackers are refocusing on these attack surfaces. As endpoint security at home is not as secure as it is in the office, attackers are trying to exploit loopholes.

Over 500,000 account credentials of video conference platform Zoom are being sold on the darknet. According to a recent investigation by IntSights’ researchers, hackers have shared a database containing more than 2,300 usernames and passwords to Zoom accounts on dark web forums. The exposed database contains usernames and passwords of personal Zoom accounts, including corporate accounts belonging to banks, consultancy companies, educational facilities, software vendors, and healthcare providers. Researchers also highlighted that they’ve found various posts and threads of dark web forum members discussing different approaches of targeting Zoom’s conferencing services.

The Flipside

Organizations across the globe are suffering from Coronavirus-related cyberattacks, but on the flipside, several ransomware groups came forward to assure that they would hold back from attacking health organizations during the Coronavirus crisis.

We can only hope that more hacker groups have a change of heart and spare institutions providing services to save lives. Hackers should instead turn a leaf and become security consultants, who are in great demand these days.

About the Author

Rudra Srinivas

 

Rudra Srinivas is part of the editorial team at CISO MAG and writes on cybersecurity trends and news features.

 

Hybrid Cloud Security Solution is the Most Trusted Cloud Strategy: CISO MAG Survey

CISO MAG Cloud Security

Is cloud the ultimate data storage solution? That remains a hot and widely debated topic. Every day more and more organizations are unplugging their data centers and are moving to the cloud. As for most organizations, cloud migration is a rather safe drill. Along with that, cloud security solutions enable organizations to increase agility, accelerate time to market, and reduce costs.

Even though cloud computing presents cybersecurity and regulatory compliance challenges, which make organizations hesitant to move to the public cloud, that sentiment is changing as cloud security technologies have vastly improved. Lately, organizations feel more confident about adopting cloud security services, and it is common for an organization to have its infrastructure on multiple clouds — in some cases as many as 10 or 15 clouds. As part of their digital transformation initiatives, organizations are opting for more cloud security service providers. Yet some have concerns about data residency, data privacy, and confidentiality of data.

Key findings

In the previous Cloud Security Power List issue (July 2019), CISO MAG conducted a survey of information security experts to gauge their responses on the trends in cloud security space. The findings of the survey were:

  • Hybrid cloud security solutions are considered the most trusted cloud strategy among the companies surveyed. The subsequent biggest strategies were private cloud in second place, public cloud as the third most popular, and community cloud as the least adopted method.
  • The biggest cloud security challenge for companies is detecting and responding to security incidents. Meeting regular compliance requirements is a close second.
  • The biggest cloud security threat is data leaks. Surprisingly, only one-fifth of the companies surveyed think insufficient due diligence is the most prominent threat.
  • When it comes to cloud computing security services, a large number of respondents think traditional security tools are not sufficient to manage security across cloud environments.
  • The most critical factor when deciding on cloud-based security services is meeting compliance requirements. In second place, almost one-third of the companies surveyed consider cost-effectiveness as the most prominent factor when deciding on a cloud provider.
  • About 40% of the companies surveyed think budget is the most important criteria when selecting a cloud vendor for migration. Ease of patching, certification, and security compliance tied as the second most important requirement.

CISO MAG editors also picked and profiled the best cloud security companies to look out for. These profiles included:

  • Symantec
  • Akamai
  • Fortinet
  • CISCO
  • Trend Micro
  • Safe T
  • Oblique Drive

The necessity for cloud adoption varies from companies to companies. And in most cases, the benefits of cloud computing depend on the kind of business the organization is into. Organizations ultimately have their risk profile depending on various vectors like staffing and access, resource allocation, regulatory policies within the organization, and most importantly its potential for a huge data breach.

This year, CISO MAG Editors will again conduct a survey to gauge the changing sentiment about Cloud Security. They will invite leaders and decision-makers in businesses of all sizes, and across geographies, to participate in this survey. — The results will culminate in a report for the June 2020 issue, titled Power List – Cloud Security. The report will also shed light on the trends and adoption of cloud technology solutions.

For more information about the Power List issue on Cloud Security, write to: [email protected]

About CISO MAG

CISO MAG is a publication from EC-Council which provides unbiased and useful information to the professionals working to secure critical sectors. The information security magazine includes news, comprehensive analysis, cutting-edge features, and contributions from thought leaders, that are nothing like the ordinary. Within the first year of launch, the magazine reached a global readership of over 50,000 readers. The magazine also has an Editorial Advisory Board that comprises some of the foremost innovators and thought leaders in the cybersecurity space. Apart from this, CISO MAG also presents a platform that reach out to the cybersecurity professionals across the globe through its Summits and Awards and Power List surveys.

About EC-Council

EC-Council, officially incorporated as the International Council of E-Commerce Consultants was formed to create information security training and certification programs to help the very community our connected economy would rely on to save them from a devastating Cyber Attack. EC-Council rapidly gained the support of top researchers and subject matter experts around the world and launched its first Information Security Program, the Certified Ethical Hacker. With this ever-growing team of subject matter experts and InfoSec researchers, EC-Council continued to build various standards, certifications and training programs in the electronic commerce and information security space, becoming the largest cybersecurity certification body in the world.

Attackers Target 900,000 WordPress Sites in a Week

Cybercriminals Tried to Access Database Logins of 1.3 Mn WordPress Sites

Threat actors tried to hack nearly one million WordPress sites in the last week, according to a security alert issued by cybersecurity firm Wordfence. The threat intelligence team at Wordfence stated that hackers launched attacks from 24,000 different IP addresses and tried to break into more than 900,000 WordPress sites.

It was found that since April 28, 2020, unknown hackers engaged in this massive campaign that caused a 30 times increase in the volume of attack traffic. The attacks peaked on May 3, 2020, when the group launched more than 20 million hacking attempts against half a million domains. Attackers largely abused cross-site scripting (XSS) vulnerabilities to inject malicious JavaScript code on websites and redirect them to malicious sites.

“We found that this threat actor was also attacking other vulnerabilities, primarily older vulnerabilities allowing them to change a site’s home URL to the same domain used in the XSS payload in order to redirect visitors to malvertising sites,” Wordfence’s security team said.

Indicators of Compromise

Wordfence also listed the top 10 IP addresses performing these attacks to help users to monitor their sites. These include:

185.189.13.165

198.154.112.83

89.179.243.3

132.148.91.196

104.236.133.77

188.166.176.210

77.238.122.196

74.94.234.151

188.166.176.184

68.183.50.252

“As these attacks appear to be targeted at vulnerabilities that have been patched for months or years, both Wordfence Premium and free Wordfence users should be protected,” the team added.

Wordfence urged users to update their website plugins and deactivate any plugins that have been removed from the WordPress plugin repository. “We did not see any attacks that would be effective against the latest versions of any currently available plugins, running a Web Application Firewall can also help protect your site against any vulnerabilities that might have not yet been patched,” it added.

An earlier independent study from WPScan stated that WordPress plugins are the biggest source of vulnerabilities and data breaches. It accounts to 54% of the global WordPress vulnerabilities count.

COVID-19: Securing Newly Remote Users and Admins by Extending Zero-trust Segmentation

Remote Work

IT organizations around the world have been forced to make it possible for millions of previously in-office workers to become remote employees, often with no more than a day or two to prepare. Ensuring that everyone has the tools and access they need to be productive was, of course, the priority. But now that people are, for the most part, able to work from home, IT needs to consider the security issues created by rapidly moving people to a work-from-home model. Cybercriminals are quick to take advantage of weaknesses to launch attacks and IT needs to address these new vulnerabilities as soon as possible.

By Dan Perkins, Director of Products & Solutions, Edgewise Networks

To illustrate just how quickly some organizations had to convert to remote, we have customers in sensitive industries that require high security whose employees were working on desktops in isolated, segmented-off networks. These companies faced a tough choice: send employees home without the ability to do their critical work or load their desktops into their cars so they can continue to be productive using their personal Wi-Fi service. They chose to send them home with their workstations. Further complicating the issue was that those desktop machines were connected to their segmented networks in the office via ethernet and had to be adapted to work on employees’ home Wi-Fi networks.

Most IT organizations didn’t face a choice quite that stark, but most recognized they’d just have to send devices home and figure out the security issues later. And the security issues are serious.

For starters, with employees now working from home and connecting to the Internet and corporate resources through their personal Wi-Fi or via a cable to a router, organizations have exponentially expanded their attack surface, which increases risk. What’s more, most companies centralize scanning for malware, unusual network behavior and threat signatures. With employees all working from their individual home internet connections, that kind of traffic inspection is no longer possible.

Those home networks, themselves, can also pose a serious security risk. Let’s say a cybercriminal wants to target an organization. It’s not hard to track down specific employees by title on LinkedIn who likely possess the privileges that they need to access the data they want. Once identified, it’s a trivial exercise to find their address, park within range of their home Wi-Fi signal and brute-force their way in.

On top of that, the VPNs may themselves be insecure. After all, few organizations were prepared to support remote work for their entire workforce, which means that IT admins had to hurriedly configure and scale their VPN infrastructure to accommodate a huge surge of connections. VPNs are complex to manage, as anyone who’s worked with them can tell you, and especially given the short time frame IT was given to expand VPN access, they are likely to have insufficiently strong policies and misconfigurations that will create vulnerabilities attackers can exploit. A classic example is split tunneling, which allows the VPN to communicate simultaneously with both the local and remote networks. This simple configuration error can give attackers remote access through the VPN.

But even if cybercriminals don’t compromise VPNs to tunnel into the corporate network, with nearly all employees working outside of the firewall, remote workers have unprotected egress, which increases the risk of data exfiltration by bad actors.

Phishing is also a much higher risk during the pandemic. with people on edge about the virus and the severe economic shocks it has already produced. Hackers are creating highly targeted attacks that prey on people’s hopes and fears, masquerading as inquiries about government assistance, virus treatments and health information. Employees are understandably anxious and working outside of the office and without the protections in place possessed by corporate networks, they’re more likely to click through a well-crafted phishing email.

Solving remote security issues through zero-trust

The central theme that runs through all these threats is this: centralized control for monitoring threats typically relies on a physical network connection, a security model that the current crisis has broken. Very few have a physical connection to their corporate network these days, which means we need a different model, in which security follows devices. We’re already seeing this shift for cloud security, where appliance-based control isn’t feasible. To protect corporate data and IT assets during the current lockdowns, security must reside in the device itself.

Identity-based zero-trust security offers a solution. In a zero-trust environment, all internal communications are treated as potentially hostile, and only authorized communications between verified applications and devices are allowed to go through. To accomplish this, we first need to map the entire network to identify all assets in the environment. That’s historically been a huge barrier to microsegmentation and enabling zero-trust, but thanks to the advent of machine learning (ML), this process can be automated, which is not only more accurate, but also can be accomplished in just a few days instead of months.

Once that’s accomplished, the next step is to reduce the attack surface by eliminating unnecessary communications pathways. Again, this is a task best left to ML. Typically, more than 90% of existing pathways can be shut down without any impact on the environment. Once this is accomplished, the environment needs to be microsegmented with policies defined according to software and device identity.

Identity is the key to effective zero-trust policies. In the past, microsegmentation and zero-trust relied on trusted network addresses, which is a problematic approach. For starters, networks change constantly, which means policies need to be constantly updated as applications and devices move. Plus, they’re completely ineffective in the cloud and other autoscaling environments where IP addresses are ephemeral.

But even if the system were able to continually update policies to reflect network changes, it’s still ineffective because there’s no way for IT to determine what is communicating, only how it is doing so. It’s as if the police intercept a conversation between two gangsters, and, as soon as they realize they’re speaking in English over the regular phone system, the officers assume that the gangsters’ communications are completely innocent. That’s almost exactly what network-based security systems do. They look at the protocol and the network address. So long as they check out, communications are allowed, even though IT has no idea what or who, exactly, is trying to communicate.

In an identity approach to microsegmentation, each device and software asset is assigned an immutable, unique identity based on dozens of properties of the asset itself, such as a SHA-256 hash of a binary or the UUID of the bios. Because the identity is based on intrinsic attributes, this method prevents spoofed or altered software, devices and hosts from communicating.

So, once zero-trust is operational in the company network, it’s a simple process to extend it to employee endpoints. First, IT creates a segment for the remote devices and verifies the identity of all the software trying to communicate over the VPN. After IT segments the endpoint and creates policies, it’s best to leave it in simulate mode for a couple of days to ensure that policies work as expected without blocking necessary communications. If the test shows everything is working as expected, simply enforce the new policies and your remote user is now working in a zero-trust environment. As a result, even if their machine or VPN is compromised, attackers will be unable to communicate with the corporate network to wreak havoc.

Organizations do not have to settle for sub-par security while everyone is remote during the current pandemic. Identity-based zero-trust segmentation can extend from the cloud or data center to follow desktops and laptops to ensure everyone is working safely.

About the Author

Dan PerkinsDan Perkins is Director of Products and Solutions for Edgewise Networks, where he oversees the direction and development of Edgewise’s zero-trust platform. Prior to Edgewise, Dan was Director of Product Management at Infinio, where he was responsible for product vision and the ongoing quality and applicability of Infinio’s solution. He also previously served in several software engineering and quality assurance roles for Citrix. Dan holds a B.S. in computer engineering from Northeastern University.

Disclaimer

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

50% of Organizations Are Not Prepared For Cyberattacks: Report

Top Cybersecurity Jobs in 2021

Only 51% of security leaders and professionals are confident that their cybersecurity teams are ready to detect and respond to cyberattacks during the ongoing COVID-19 pandemic, according to a new research by Information Systems Audit and Control Association (ISACA).

Only 59% said that their security teams have the required tools and resources at home while working remotely while 58% respondents stated that hackers are taking advantage of the outbreak to steal digital assets and disrupt organizations’ operations.

While 92% of respondents said that cyberattacks on individuals are rising, 87% of them believe the rapid transition to remote work as the main cause.  The survey findings are based on 3,700 IT audit, risk, governance, and cybersecurity professionals across 123 countries.

ISACA CEO David Samuelson, said, “A surge in the number of remote workers means there is a greater attack surface. Remote work is critically important right now, so security has to be at the forefront along with employee education. ISACA professionals have an especially critical role to play in protecting their enterprises, customers and stakeholders during this pandemic.”

According to the research, the respondents are extremely concerned about various impacts from the COVID-19, which include:

  • Economic impact on my national economy (49%)
  • Health of family and friends (44%)
  • Personal health (30%)
  • Economic impact on my organization (24%)

ISACA CTO Simona Rollinson, said, “What we do now is that tech professionals, including the IT audit, risk, governance and security professionals in our community, are more necessary than ever to their enterprises, and they are well-positioned to adapt and even thrive, regardless of what changes may be in store.”

Earlier, in similar research, ISACA revealed that there is a lot more to be done in information and technology in terms of overall governance, cybersecurity policies, and defenses. The study further revealed that the board of directors and a team of leaders are emerging as a chink in the cybersecurity armor. As a result, several leadership teams are increasing funding for cybersecurity and risk management programs. It highlighted that 90% of surveyed business leaders agreed that strong technology governance contributes to improved business outcomes.

Ransom Payments Up 33% In Q1 2020; Sodinokibi and Ryuk Tops the List

Ransomware Attacks, Graff ransomware attack

The average enterprise ransom payments increased 33% ($111,605) in Q1 of 2020 from Q4 of 2019, according to the Coveware Ransomware Marketplace Research report. The research revealed that ransomware operators succeeded in targeting large organizations and forcing ransom payments.

It was found that Sodinokibi (used in 26.7% of attacks), Ryuk (19.6%), and Phobos and Dharma (7.8%) were the top three most used ransomware variants in Q1 of 2020. Coveware stated that Maze, Dopplepaymer, and Sodinokibi operators are using content before encrypting the data, and holding it hostage to threaten to post it unless the target agrees to pay.

Rank Ransomware Type Market Share % Change in Ranking from Q4 2019
1 Sodinokibi 26.7%
2 Ryuk 19.6%
3 Phobos 7.8%
4 Dharma 7.8% +1
5 Mamba 4.8% +4
6 GlobeImposter 4.4% +5
7 Snatch 2.6% +1

 Data Source: Coveware

The research highlighted that each of the ransomware variants were used to target different sizes of organizations – Ryuk ransomware was used against large organizations with more than 1,000 employees. While Sodinokibi attacked medium size enterprises with around 370 people, and Phobos focused on small businesses averaging 81 people. Ryuk earned the largest ransom payouts worth $1.4 million, compared to $327,931 for Sodinokibi and $15,761 for Phobos.

Image Courtesy: Coveware

The most common attack vector that threat actors used was Remote Desktop Protocol (RDP) access points, used about 60% of the time. While email phishing attacks were reported as the second most used attack type, accounting for about 30%.

“Poorly secured Remote Desktop Protocol (RDP) access points continued to be the most common attack vector.  RDP credentials to an enterprise IP address can be purchased for as little as $20 on dark marketplaces. Combined with cheap ransomware kits, the costs to carry out attacks on machines with open RDP were too economically lucrative for criminals to resist. Until the economics of carrying out ransomware balance ransomware and cyber extortion will continue to gain prevalence,” the report stated.

Image Courtesy: Coveware

The research findings also revealed that small and medium sized service providers like law firms, IT, and CPA firms continued to be the primary target for ransomware attacks in Q1 2020. However, government organizations and educational institutions jumped in popularity due to the COVID-19 outbreak.

7TB of Data Leak Exposes Over 10 Bn Adult Website Records

data leak

The research team at Safety Detectives has discovered a data leak, which potentially exposed over 10 billion records of an Ireland-based adult live-streaming website CAM4.com. The exposed database exceeded 7TB (terabytes) of information including its production logs. The researchers contacted CAM4 informing them of the data leak, and prompt response was received to secure the exposed database.

Data Leaked from the Adult Website

CAM4.com is owned by a parent company Surecom Corp., which has another adult website Smart-X.net registered under its banner. Researchers said that millions of leaked entries were unprotected and publicly viewable.

adult website data leak
Fig: Public View of Exposed Records. Image Source: Safety Detectives

These exposed records consisted of both user and critical company information like personally identifiable information (PII) and production logs including:

  • First and last names
  • Login credentials
  • Country of origin
  • Sign-up dates and login logs
  • Gender preference and sexual orientation
  • Device information (MAC/IP addresses, OS details)
  • User conversations
  • Transcripts of email correspondence
  • Password hashes
  • Payments logs including credit card type, the amount paid and currency type
  • Fraud/Spam detection logs

The log files revealed users’ password information, however, many sets of private information were incomplete, while password fields were masked in a majority of the instances investigated. Most of the users affected belonged to the U.S. followed by Brazil and Italy. It is difficult to gauge the precise number of records and their respective locations due to multiple duplications of entries, however, here is a country-by-country view of exposed email records:

adult website country log
Image Source: Safety Detectives

 

Threat Summary
Website Name CAM4.com (adult live-streaming website)
Threat type Data leak
Affected Audience Mainly U.S., Brazil, and Italy
Campaign Active Since From at least March 16, 2020
No. of Leaked Records 10.88 billion including personally identifiable information (PII)
Leaked Server Info
  • Size: 7TB (terabytes)
  • Location: The Netherlands, hosted by Mojohost B.v
Damages Caused The leaked records are at risk of identity theft, financial fraud, phishing scams, and blackmail. Additionally, the leaked website’s backend data could be assessed to create a backdoor and exploit the website with further threats including ransomware attacks.