Home Blog Page 220

Hackers Illicitly Access 160,000 Nintendo Accounts

Nickel, Hackers, Twitch source code

Nintendo admitted that over 160,000 of its gamers’ accounts have been hacked, after hackers exploited Nintendo Network ID (NNID) login system. In an official release, the Japanese consumer electronics giant stated that attackers illegally obtained users’ login IDs and passwords and made unauthorized logins and purchases. A NNID is like a user ID, which can be linked to Nintendo account and used as a login option. If an NNID is compromised, the attackers can access the Nintendo account linked to it.

The company revealed that hackers may have accessed users’ nicknames, dates of birth, countries, email address, and other information linked to NNIDs. Nintendo notified the affected users to reset their account passwords and advised them to set up two-factor authentication for an extra layer of protection. Nintendo also disclosed that the registered credit cards or PayPal accounts of users linked to their Nintendo accounts may have been used at the My Nintendo Store or Nintendo eShop. However, the company clarified that no credit card information was stolen.

Nintendo gamers have been reporting suspicious activities on their accounts over the past few weeks. According to the complaints reported on Twitter and Reddit, threat actors were logging into victims’ accounts to abuse the payment cards linked to the accounts. It is said that hackers made purchased digital goods on Nintendo’s online stores. “Someone hacked my PayPal and spent $200 on Nintendo games,” a gamer reported.

Even after the improved security measures, the data hacks have become common in the online gaming industry. Earlier, the popular online video game Town of Salem suffered a cyberattack that compromised the personal information of more than 7 million gamers. The Town of Salem is a role-playing game operated by BlankMediaGames with around 8 million users.

BlankMediaGames confirmed that its servers and databases were hacked, resulting in data theft of users’ names, emails, passwords, IP addresses, and Game & Forum Activity. The gaming company said that it never stores credit card, payment information or personal identifying information of the users. BlankMediaGames notified the users about the data breach via emails and suggested they change their passwords to prevent further loss.

Vietnam’s APT32 Group Uses COVID-19 to Target Chinese Health Authorities

Phishing Campaign on FINRA

According to a report from Fireeye, the Vietnamese threat group APT32 is suspected to have carried out a series of attacks aimed at the Wuhan province government and China’s Ministry of Emergency Management to collect intelligence on the COVID-19 crisis. The researchers noted that the attackers targeted multiple users through a spear-phishing campaign run from at least January to April 2020.

The COVID-19 crisis poses an intense, existential concern to governments, and the current air of distrust is amplifying uncertainties, encouraging intelligence collection on a scale that rivals armed conflict.

– Fireeye

Brief History of APT32

APT32 aka OceanLotus or APT-C-00, is suspected to be backed by the Vietnamese government. APT32 is popularly known to carry out cyber espionage campaigns against companies and countries doing business, manufacturing, or preparing to invest in Vietnam. The threat actors leverage a phishing mail to initiate an attack that contains ActiveMime files. They make use of social engineering as a bait to lure the victim into enabling the macros. Once executed, the initialized file downloads multiple malicious payloads like Soundbite, Windshield, Phoreal, Beacon, and Komprogo from a remote server.

Phishing Emails with Tracking Links

The first phishing attack was traced to January 6, 2020, when APT32 sent an email to China’s Ministry of Emergency Management using the sender address as lijianxiang1870@163[.]com and the subject 第一期办公设备招标结果报告 (translation: Report on the first-quarter results of office equipment bids). The email’s content had an embedded link that sent the victim’s email address and codes back to the threat actors indicating them that the email was opened.

phishing, APT32
Figure: Phishing email to China’s Ministry of Emergency Management (Image Source: Fireeye)

Researchers also found that the libjs.inquirerjs[.]com domain was being used since December as a C2 domain for a METALJACK phishing campaign to target Southeast Asian countries. APT32 likely used COVID-19-themed malicious attachments in Chinese-Language as a decoy to drop a METALJACK payload.

Threat Summary
Threat Group APT32
Threat type Spear-phishing, phishing
Payload Name METALJACK
Target Audience South-east Asia, Chinese speaking
Campaign Active Since From at least January 2020
Domain Indicators ·    m.topiccore[.]com

·    jcdn.jsoid[.]com

·    libjs.inquirerjs[.]com

·    vitlescaux[.]com

Email Address Used lijianxiang1870@163[.]com
Malicious File Names MD5: d739f10933c11bd6bd9677f91893986c – METALJACK loader

MD5: a4808a329b071a1a37b8d03b1305b0cb – METALJACK Payload

MD5: c5b98b77810c5619d20b71791b820529 – Decoy Document (Not Malicious)

Damages caused Intellectual and confidential COVID-19 related state and government data can be compromised. Additional trojans and malware infections can be installed to exfiltrate data in future.

 

Researchers added that, “The COVID-19 crisis poses an intense, existential concern to governments, and the current air of distrust is amplifying uncertainties, encouraging intelligence collection on a scale that rivals armed conflict. National, state or provincial, and local governments, as well as non-government organizations and international organizations, are being targeted. Until this crisis ends, we anticipate related cyber espionage will continue to intensify globally.”

South Korean and US Payment Card Records Valued at $2 Mn up for Sale on Dark Web

one million card data exposed

Security researchers from Group-IB, a Singapore-based cybersecurity company, recently discovered a database containing  397,365 payment card records uploaded on a Darknet forum for sale. The researchers stated that the card records were related to South Korean and the U.S. banks,  valued up to $2 million on Joker’s Stash, an infamous underground marketplace. It was found that the database mainly contains Track 2 information of the credit and debit cards, including magnetic stripes of the cards, which contain the bank identification number (BIN), the account number, expiration date, and CVV numbers.

While the source of the database remains unknown, Group-IB stated that 49.9% of card details (198,233 items valued at $ 991,165) were from South Korean banks and financial organizations and 49.3% were related to the U.S. banks and financial entities.

Advertisement of Data Dump on Joker’s Stash

Image Courtesy: Group-IB

“During cardshop monitoring Group-IB Threat Intelligence system has detected a database under the name «SCARFACE-DISCOUNT-SALE-5USD (fresh skimmeD): USA (STATES MIX + few EU) TR1 + TR2/TR2, VALID 30-40%, uploaded 2020-04-09 (NON-REFUNDABLE BASE)» released and put up for sale on April 9. Joker’s Stash — the infamous underground marketplace — put a USD 1,985,835 price tag on the set, at USD 5 apiece, and announced that dump had 30-40% valid rate,” Group-IB said.

Payment Card Details Kept For Sale

Image Courtesy: Group-IB

Group-IB notified the incident to the national CERTs and financial organizations in South Korea and the U.S. and are working closely with its partners in these countries to investigate on the incident.

Shawn Tay, Senior Threat Intelligence analyst of Group-IB, concluded, “Even though, there is not enough information in this dump to make online purchases, fraudsters who buy this data can still cash out stolen records. If a breach is not detected promptly by the card-issuing authority, crooks usually produce cloned cards (white plastic) and swiftly withdraw money via ATMs or use cloned cards for illicit in-person purchases.”

 Joker’s Stash – A Hacker’s Marketplace

There were multiple incidents where hackers traded stolen cards’ data on Joker’s Stash. Recently, threat intelligence firm Gemini Advisory revealed that hackers kept payment card details of Wawa’s customers on Joker’s Stash. In an official statement, Wawa confirmed that hackers tried to sell customers’ card information that breached in the security incident occurred on December 10, 2019. The data belonged to 30 million Americans and over one million foreigners from more than 100 different countries.

“CISA is taking a holistic approach to securing systems across sectors”

Brian Harrell, CISA, DHS

Brian Harrell was appointed by the President of the United States in December 2018 to serve as the Department of Homeland Security’s Assistant Secretary for Infrastructure Protection. He now serves as the first Assistant Director for Infrastructure Security within the newly renamed U.S. Cybersecurity and Infrastructure Security Agency (CISA). He was recently recognized as Security Magazine’s “Most Influential People in Security”. Harrell is the former Managing Director of Enterprise Security at Duke Energy Corporation. He is also the former Director of the Electricity ISAC and Director of Critical Infrastructure Protection Programs at the North American Electric Reliability Corporation (NERC), where he was charged with helping protect North America’s electric grid from physical and cyberattacks. Brian has spent time during his career in the U.S. Marine Corps and various private-sector agencies with the goal of protecting the United States from security threats.

In an exclusive e-mail interview with Augustin Kurian of CISO MAG, Brian Harrell, Assistant Director for Infrastructure Security, CISA, DHS speaks about the role of CISA and its recent accomplishments in protecting organizations across industries from cyberattacks. He also explains how the Cybersecurity and Vulnerability Identification and Notification Act enables CISA to get past the hurdle of obtaining crucial information about vulnerable systems from ISPs, for its cybersecurity investigations.

How is CISA as a federal agency addressing the fact that several types of cyberattacks can have physical consequences?

Today, our physical infrastructure relies on web-enabled technology to operate efficiently, making it significantly more interdependent than ever before.  When one company or network experiences a disruption, impacts can quickly ripple across the rest of the sector and many other sectors as well. The Cybersecurity and Infrastructure Security Agency (CISA), as the nation’s risk advisor, is taking a holistic approach to securing these systems. Last year, we worked with the private sector to develop a set of National Critical Functions, which provides a risk management approach to understanding those functions whose interruption may have a cascading effect across sectors. In addition, we continue working closely with public and private stakeholders to share information, provide cybersecurity tools, incident response services and assessment capabilities that safeguard networks essential to operations. At the same time, CISA coordinates security and resilience efforts and provides consolidated all-hazards risk analysis for U.S. critical infrastructure. CISA also conducts cyber and physical exercises with government and private sector partners to enhance the security and resilience of critical infrastructure. All these efforts can help inform risk mitigation activities and the development of new resources within the critical infrastructure community.

When it comes to threats, how should organizations go about securing their supply chain — that includes partners, contractors, and vendors?

Supply chain risk management is very important, especially with the globalization of vendors and suppliers, as well as the upcoming rollout of new technologies, including information and communications technology (ICT) like 5G.  Additionally, as the cyber and physical worlds converge, threat actors are using a variety of tactics to exploit any weakness. CISA, government partners, and the private sector are all engaging in a more strategic and unified approach towards improving our nation’s overall defensive posture against malicious activity in the connected systems which underpin our critical infrastructure. In 2018, CISA established the Information and Communication Technology Supply Chain Risk Management Task Force as a collaborative endeavor between representatives of industry and government.  The Task Force helps investigate and recommends methods to manage ICT supply chain risks. In September 2019, the Task Force released an Interim Report intended to provide insight and transparency on the work of the Task Force. The document serves as a reference to help industry and government stakeholders more effectively identify and manage risks to global ICT supply chains.

We believe the security of ICT networks and services is a critical element of national security, as they play a crucial role in the safety, security, and prosperity of all nations and are an attractive target for foreign adversaries and malicious cyber actors—5G is a prime example. Because of these concerns, CISA has urged governments at all levels, as well as the private sector, to adopt a risk-based security framework for the construction of all elements of 5G networks, and to conduct a careful evaluation of potential hardware and software equipment vendors and the supply chain.

Tell us the crucial role a CISO must play while handling insider threats as well as threats that may occur from a third-party vendor, since the role of a CISO has changed drastically over the last few years. 

With new and evolving threats, the role of CISOs is becoming more important every day, especially as it relates to the significant challenge of managing insider threats. Employees tend to have a strong understanding of organizational operations, and they have the potential to cause catastrophic damage, whether intentionally or unintentionally. A CISO must understand the risks posed by insiders, consider potential implications of a successful attack or unintended action, and prepare mitigating measures. A critical step toward preventing a threat or mitigating the damage from one entails positioning the CISO in a leadership role within the establishment, as well as having an insider threat mitigation program, including a threat management team, in place.

How can an organization’s management and its HR team set up a more proactive or reactive measure toward addressing insider threats? What are the best practices that should be established?

While each organization’s structure and requirements are specific to that organization, any management or HR team should be actively engaged in recognizing and identifying early insider threat warning signs and practicing (in advance) how to address a potential insider threat situation.  Whether individuals attempt to join an organization with the intention to inflict harm, become a disgruntled employee who feels he/she has been wronged, or unintentionally introduces a threat through carelessness, the consequences of insider actions can be detrimental.  In addition to considering cyber impacts, recent incidents demonstrate that organizations should increasingly be aware of the potential for workplace violence.   CISA provides comprehensive information to support organizations in establishing a program through our insider threat mitigation website.

What are your thoughts on the need for Red Teaming for organizations? As Red Teaming is one method where both physical security and cybersecurity of organizations are thoroughly checked time and again. Do you think Red Teaming must be staple of organizations?

Red teaming is a great way to test vulnerabilities and risks within an organization. CISA helps both public and private sector stakeholders identify and test these vulnerabilities through our exercise resources. Exercises provide stakeholders with effective and practical mechanisms to examine plans and procedures, identify areas for improvement, and share best practices. They also inform future planning, technical assistance, training, and education efforts. CISA offers both discussion-based and operations-based exercises. Among other things, these exercises are employed to validate or enhance understanding of plans and procedures, rehearse concepts, assess incident response and recovery needs, identify strengths and areas of improvement, simulate reality by presenting complex and realistic problems that require critical thinking, rapid problem solving, and effective responses by trained personnel; thereby testing and validating many facets of planning and preparedness. Overall, red teaming is a very useful tool for an organization to test, mitigate, and manage overall risk to business operations.

Tell us a bit about the CISA’s subpoena Bill which will give the agency better authority to probe cyber risks on critical infrastructure? Tell us about the benefits of having the Bill passed?

CISA analysts work around the clock to identify and address critical infrastructure cybersecurity vulnerabilities and, ultimately, share this timely risk management information with CISA’s partners.  Unfortunately, too often we come across cybersecurity vulnerabilities in industrial control systems and other critical networks sitting on the public internet and are unable to act because we cannot identify the owner of the vulnerable system.  For these vulnerable systems, CISA is unable to identify the system’s owner or operator because of the internet protocol (IP) address, or the unique address that identifies the device or system, generally resolves to an internet services provider (ISP), which masks the owner or operator’s contact information.  We need a legal mechanism, whereby if we identify the IP address of a potentially vulnerable system, the ISP can give us the contact information for the vulnerable entity so we can notify them of the vulnerability and provide valuable mitigation information.

The Cybersecurity and Vulnerability Identification and Notification Act establishes the legal mechanism necessary that allows CISA to request subscriber information to alert system owners and operators of vulnerabilities, which, if left unmitigated leave the system open to attack.  The authority applies to a very narrow set of circumstances where CISA has specific information about a known vulnerability and is unable to determine the entity’s identity. The authority honors long-held privacy fair information practice principles, ensuring that CISA only obtains information for a cybersecurity purpose, that the information is used only for the purpose for which it was collected, and that CISA asks only for the minimal information necessary to contact the owner or operator and alert them to the vulnerability.

CISA has a long history of working with private and public-sector companies to collect sensitive data through voluntary programs and a demonstrated history of protecting information.  This authority does not change the voluntary relationship between CISA and its critical infrastructure partners. It allows CISA to contact a vulnerable entity, notify them of the existing risk, and offer mitigation advice or assistance. CISA cannot compel companies to act or to work with CISA on the basis of this authority.

After years of trying several different methods to contact these affected entities and share what we’ve found, the status quo is simply not working. This new proposed legal authority is a smart, reasonable, and targeted tool that will allow the men and women of CISA to live up to the mission Congress set out for us—to improve American critical infrastructure cybersecurity.

 

Artificial Intelligence: The Ultimate Weapon in the War against Cyber Criminals

Dr. Erdal Ozkaya Webinar

For a legion of cybersecurity experts from across the globe, CISO MAG hosted a Fireside Chat with Dr. Erdal Ozkaya on the topic, “AI: The Ultimate Weapon in the War against Cyber Criminals.” Dr. Ozkaya is a an award-winning CISO of a regional bank. The Fire Chat, held on April 21, 2020, was moderated by Brian Pereira, Principal Editor of CISO MAG.

Dr. Ozkaya started the webinar by talking about the inception of cloud, how people were aversive towards it initially and eventually how cloud became a staple for organizations; and compared it to AI. He mentioned the aversiveness toward adoption of AI among organizations right now. Dr. Ozkaya stressed how adoption of AI will be similar to the adoption of cloud. He also spoke elaborately on the profound impact AI will have in the future where human and machine intelligence complement each other, and how AI should not simply be seen as a substitute. He discussed the scope of AI and the future of security as the sheer volume of threats is becoming very difficult to track by humans alone.

Commenting on the roles of the CISO, he is of the opinion that CISOs need to invest in tools and methodologies that enable their organizations to be more efficient and secure. According to him, automation, orchestration, machine learning, and artificial intelligence can enable machines to take over the repetitive grunt work currently done by security personnel. He also addressed several pressing issues surrounding the adoption of AI, including scenarios like job loss and even bot wars — AI becoming self-aware.

Dr. Ozkaya also took questions from the audience on topics like “How will AI disrupt cybersecurity and help the industry fight the battle against cybercriminals in the future?”. Hackers are using AI too. In what way? How should we respond?

Following the Q&A, Dr. Erdal also promised copies of his latest book, the second edition of “Cybersecurity-Attack and Defense Strategies” to several members of the audience of the CISO MAG Fireside chat. The audience also participated in a snap poll during the webinar.

Dr. Ozkaya is a tenured cybersecurity professional and has juggled the roles of a security advisor, speaker, lecturer, and author. Having excelled in business development, management, and academics, he is focused towards securing the cyberspace and he is passionate about imparting knowledge from his hands-on experiences. As an award-winning technical expert, Dr. Ozkaya has received many accolades. His recent awards are the Cyber Security Professional of the year MEAHall of Fame by CISO MagazineCybersecurity Influencer of the year (2019), Microsoft Circle of Excellence Platinum Club (2017), NATO Center of Excellence (2016) Security Professional of the year by MEA Channel Magazine (2015), Professional of the year Sydney (2014). He has been a speaker at many conferences And also holds Global Instructor of the Year awards from EC-Council & Microsoft.

The full version of the Fireside chat can be found here.

The next Fireside Chat ‘The Superhero CISO’ will be held on April 30, 2020 with researcher, hacker and CISO, Chris Roberts.

Through the Fireside Chat series, CISO MAG will be partnering with industry experts and solution providers from across the world to host similar webinars thrice a month to discuss some of the pressing issues and trends in the cybersecurity. Stay tuned.

About CISO MAG

CISO MAG is a publication from EC-Council, which provides unbiased and useful information to the professionals working to secure critical sectors. The information security magazine includes news, comprehensive analysis, cutting-edge features, and contributions from thought leaders, that are nothing like the ordinary. Within the first year of launch, the magazine reached a global readership of over 50,000 readers. The magazine also has an Editorial Advisory Board that comprises some of the foremost innovators and thought leaders in the cybersecurity space. Apart from this, CISO MAG also presents a platform that reach out to the cybersecurity professionals across the globe through its Summits and Awards and Power List surveys.

About EC-Council

EC-Council, officially incorporated as the International Council of E-Commerce Consultants was formed to create information security training and certification programs to help the very community our connected economy would rely on to save them from a devastating Cyberattack. EC-Council rapidly gained the support of top researchers and subject matter experts around the world and launched its first Information Security Program, the Certified Ethical Hacker. With this ever-growing team of subject matter experts and InfoSec researchers, EC-Council continued to build various standards, certifications and training programs in the electronic commerce and information security space, becoming the largest cybersecurity certification body in the world.

67% of Small Businesses Aim to Increase Cybersecurity in 2020: Report

CISO, Cybersecurity

With the surge in the number of data breaches, experts opined that small businesses must evaluate their data security measures. As employees are working remotely during the pandemic, cybersecurity for small businesses become especially critical. According to a new report from The Manifest, one-fifth of small businesses (15%) suffered either a hack (7%), virus (5%), or data breach (3%) in 2019. The report revealed that 67% of small businesses reported they will devote more resources to enhance their cybersecurity in 2020. The findings are based on the responses from 383 small business owners and security leaders.

“Small business cyberattacks might not garner the same news headlines as those impacting larger companies, but they happen. A cyberattack on a small business can have dire consequences, losing it time, money, and customer loyalty,” the report said.

Small Businesses Want to Increase Cybersecurity Resources

The Manifest revealed that, at the time of the survey in December 2019, most small businesses (64%) said they were planning to allocate more resources to cybersecurity in 2020. The present economic dip due to the ongoing COVID-19 pandemic may result in small businesses failing with their cybersecurity improvement plans. However, small businesses can follow cost-effective solutions to cybersecurity like restricting employee access to certain data and maintaining strong passwords.

According to the report, the most popular strategies small businesses carry out for cybersecurity are limiting employee access to data (46%) and encrypting data (44%), followed by requiring strong passwords (34%) and training employees on data safety (34%).

Image Courtesy: The Manifest

A similar survey by the Cyber Readiness Institute (CRI) on small businesses revealed that 60% of small businesses do not have a cybersecurity policy. The survey, which included 412 small business owners, revealed that while most small business owners are concerned about cyberattacks, many lack the resources to invest in necessary security measures – and half of them are worried that remote work will lead to more cyberattacks. It revealed that only 40% of small businesses have implemented a cybersecurity policy. Around 40% of businesses stated that economic uncertainty prevents them from making security investments. While 46% have offered training to help their employees stay secure while working remotely.

Hackers Trick Three UK Private Equity Firms into Transferring $1.3 Mn Via BEC Attack

Threat Alert! Attackers Use Malicious Email Accounts to Launch BEC Attacks

Three British private equity firms were duped into making bank transfers worth £1.1 million (around US$1.3 million) following a sophisticated Business Email Compromise (BEC) attack, according to Check Point’s newly released threat report. Check Point’s Incident Response Team (CPIRT) discovered a hacker group dubbed “The Florentine Banker,” which targeted three unnamed firms for several months via phishing attacks, using fake emails and look-alike domains.

It is said that hackers made four separate bank transactions, in December 2019, to transfer £1.1 million to fraudulent bank accounts in Hong Kong and the U.K. An emergency intervention allowed banks to salvage £570,000 (US$702,067), the rest of the money lost permanently.

The Florentine Banker group targeted senior executives and those in charge of money transactions, including CEOs and CFOs via phishing attacks.

What is a BEC Attack?

A BEC attack is a sophisticated scam targeting an end-user or a business entity that performs electronic payments like wire transfers or automated clearing house transfers. In a BEC attack, the attackers first steal legitimate business email account credentials, which are later used to launch financial fraud campaigns like fraudulent email messages, requests for out-of-channel funds transfers, and deleted accounting trails.

How is the Attack Initiated?

Hackers try to lure the target into clicking on a link that lets them download malware onto their devices or trick into entering usernames and passwords that allow the attacker to steal credentials. Once the hackers gain control over the officials’ emails, they continue the attacks for weeks to gain control of other email accounts and carry out reconnaissance to understand the financial picture of the companies.

Phishing email sent by the Florentine Banker group

Image Courtesy: Check Point

The hackers create mailbox rules to divert emails related to the theft to special inboxes monitored by the hacker group. This is done via Man-in-the-Middle (MITM) attack. Apart from infiltrating email accounts, the hackers also register lookalike domains that mimic the original ones of the targeted entities. Hackers then launch a MITM attack by sending emails from the fraudulent domains on behalf of the original enterprises.

With this set-up, the hackers inject fraudulent bank account information (associated with accounts located in Hong Kong and the U.K.) in the emails to divert money transfers and initiate new transfer requests.

Email Flow Before and After the Setup

Image Courtesy: Check Point

“The Florentine Banker manipulates the conversation until the third-party approves the new banking details and confirms the transaction. If the bank rejects the transaction due to a mismatch in the account currency, beneficiary name or any other reason, the attackers are there to fix the rejects until the money is in their own hands,” Check Point added.

FBI Warns About Rising BEC Attacks

Recently, the FBI warned that organizations that use cloud-based email systems are at high risk to BEC attacks. The bureau advised employees about the email scams that begin with phishing kits designed to mimic two popular cloud-based email services to lure employees into compromising business email accounts and misdirecting funds transfers. The FBI stated that its Internet Crime Complaint Center (IC3) received complaints, between January 2014 and October 2019, claiming more than US$2.1 billion losses from BEC scams.

NCSC’s New Cyber Service Flags Over 5,000 Suspicious Emails on Day One

“PerSwaysion” Phishing Campaign Targets High-Ranked Professionals Across The Globe, IKEA email reply-chain attack

With over 5,000 suspected emails flagged and more than 80 malicious campaigns taken down, NCSC’s Suspicious Email Reporting Service (SERS) is a success on its launch day itself. The service was launched on Tuesday, April 21, 2020, as part of Cyber Aware campaign, to keep a check on the fake COVID-19-related messages duping people with online scams.

NCSC’s Suspicious Email Reporting Service has been co-developed with the City of London Police.  SERS acts as a reporting system for U.K.’s general public but more so, provides U.K. police live time analysis and reports, and helps identify new patterns of online scams and frauds.

The immediate take-up of our new national reporting service shows that the U.K. is united in its defense against callous attempts to trick people online. While we have not seen a rise in email scams in the last month, coronavirus is the top lure currently used to conduct cybercrime, exploiting public unease and fear of the pandemic. We hope the success of the Suspicious Email Reporting Service deters criminals from such scams.

 

– Ciaran Martin, NCSC Chief Executive Officer

The SERS builds on NCSC’s existing takedown services, which has already removed more than 2,000 online scams related to Coronavirus in the month of March, including:

  • 471 fake online shops selling fraudulent coronavirus related items
  • 555 malware distribution sites
  • 200 phishing sites exfiltrating personal information such as passwords or credit card details
  • 832 advance-fee frauds

However, since reporting of these emails contains sharing of critical information of the reporter, there was a sense of concern among the common public. This concern has been resolved by NCSC as they highlighted how they treat the security of the data and with whom the data can be shared in the following ways:

  • NCSC protects all the information shared with them as confidential information. It is stored securely, with strict access control.
  • Under strict control, the information can however be shared with Law Enforcement agencies, such as the National Crime Agency (NCA) and the City of London Police, to help investigate, identify and mitigate malicious cyber activities.
  • This bit of information is also exempted from Freedom of Information (FoI) requests.

Ghana Ranks 9th on World Bank’s Vulnerable Countries List in Sub-Saharan Africa

Ghana Ranks 9th on World Bank’s Vulnerable Countries List in Sub-Saharan Africa

The World Bank recently ranked Ghana ninth out of 11 countries in Sub-Saharan Africa that are vulnerable to cyberattacks. It is said that South Africa is the first country in Sub-Saharan Africa with the highest security vulnerabilities. Kenya and Nigeria stood second and third, respectively. Botswana ranked fourth and Zimbabwe ranked fifth. Djibouti, Egypt, and Tanzania ranked sixth, seventh, and eighth, respectively. And Uganda, DR Congo, and Ethiopia followed Ghana in tenth, eleventh, and twelfth, respectively.

South Africa – A Vulnerable Target

Experts opined that the South African technology landscape and skills base is not mature enough to protect against the potential cyberthreats and vulnerabilities. This makes the country vulnerable and an easy target for cybercriminals. A recent analysis by rating agency Fitch revealed that there is increased technology for health services in the country, but data security remains a risk. Fitch’s analysis report “Upsides for Accelerating Demand For Digital Services In Africarevealed that the lack of secure cybersecurity infrastructure makes the country vulnerable to data theft and potential cybercrimes.

Network Attacks in SA Amid COVID-19

Businesses in South Africa suffered several network attacks between March 15 to March 21, 2020, a recent research revealed. It was found that cybercriminals attacked up to 310,000 devices in one week. Most of the hacking attempts in South Africa involved brute force attacks, which are intended to steal passwords and other credentials. With millions of people in the country accessing corporate networks remotely, hackers have increased attacks on IT networks. The research also highlighted that hackers targeted corporate network systems to gain control over them and compromise sensitive information.

Malware Attacks in SA

South Africa is one of the most malware attacked countries especially via fake dating applications, a research from Kaspersky revealed. The country saw a circulation of 1,486 malware threats disguised as over 20 popular dating apps. It is said that South Africa is the most targeted country by fake dating apps accounting to 58%, while Kenya reported 10% and Nigeria 4%. Around 7,734 attacks were detected on 2,548 users in 2019. The research highlighted that hackers used popular dating apps like Tinder, Bumble, and Zoosk as bait to spread malware and access personal data.