Home Blog Page 249

Lack of Quality Cybersecurity Workforce Hurting West African Banks

Threat Alert! Attackers Use Malicious Email Accounts to Launch BEC Attacks

Dataprotect, a Morocco-based information security company, examined the cybersecurity stance of 148 banks against various cyberattacks from the eight UEMOA (Translated: West African Economic and Monetary Union) member countries and three Central African countries, including Gabon, the Congo and the Democratic Republic of Congo. They also conducted a survey in the same region titled, “Banking Fraud in sub-Saharan Africa,” which saw a participation of nearly 21 banks directly and indirectly.

In the analysis report, Dataprotect states that the  estimated cost of cybercrime in Africa is €3.5 billion (approximately US$3.87 billion), compared to €528 billion (US$585 billion) worldwide. However, Africa still falls short in handling cybersecurity challenges. The analysis highlights that the lack of skilled and qualified workforce and lesser investments in cybersecurity has made West African banks vulnerable to cyberattacks including bank card fraud, phishing, intrusions, etc.

Types of Cyberattacks in Numbers: Survey

  • Nearly 85 percent of the banking institutions surveyed, accepted that they had already fallen victim to at least one cyberattack resulting in losses, while some faced recurrent attacks.
  • 30 percent of these cyberattacks involved bank card fraud.
  • One-third of the attacks involved phishing.
  • Ranked third in the list, cyberattacks accounted for 24 percent of all cases, which includes viruses and intrusions affecting information systems in core banking services.
  • In addition to these cyberattacks, the banks are also impacted by information leakage, identity theft, money transfer fraud and fake check scams.

The average estimated losses of the banks reporting cyberattacks is €770,000 (approximately US$852,350), over the past few years, while the average cost of each computer infection due to malware costs companies €9,000 (approximately US$9,963). 85 percent of the banks surveyed by Dataprotect said, they annually invested at least €500,000 (approximately US$553,475) to address cybersecurity threats, while 50 percent reported an annual investment between €100,000 and €500,000 (approximately between US$110,695 and US$553,475).

Past Hacking Efforts in Africa

Earlier, Symantec stated that it had detected four distinct hacking campaigns targeted against financial firms in Africa. The first cyberattack started in mid-2017 and infected computers with a malware known as NanoCore (Trojan.Nancrat). The second type of cyberattack began in late 2017, in which cybercriminals used malicious PowerShell scripts and credential-stealing tool Mimikatz (Hacktool.Mimikatz) to exploit their targets.

The third cyberattack was targeted at banks in Ivory Coast using a malware called Remote Manipulator System RAT (Backdoor.Gussdoor), alongside Mimikatz and two custom Remote Desktop Protocol (RDP) tools. The fourth cyberattack started in December 2018. The intruders used a malware known as Imminent Monitor RAT (Infostealer.Hawket) to attack banks in Ivory Coast. Symantec stated that all the four attacks were discovered through alerts generated by its Targeted Attack Analytics (TAA), which uses artificial intelligence to analyze and spot targeted attacks.

Israel Electric to Prevent Cyberattacks During Tokyo 2020 Olympic Games

Tokyo 2020 Olympics

Israel’s national electricity provider, Israel Electric Corporation (IEC), has struck a deal with Japan’s leading energy utility to tackle cyberattacks during the Tokyo 2020 Olympic games, said the chairman of the IEC, Yiftah Ron-Tal, at the Cybertech 2020 cybersecurity conference in Tel Aviv, without disclosing the name of the Japanese corporation.

Yosi Shneck, the head of cyber entrepreneurship and business development at the Israeli firm said, “The idea behind the deal was to help the Japanese company secure its critical infrastructure during the (Tokyo 2020) Olympic games and for additional cooperation even after the games are over.”

IEC is a public and government-owned (99.846% owned by the State of Israel) electricity provider, generating and supplying electricity to all major sectors. Along with this, it also has a suite of cybersecurity products and services developed in-house that includes both software and hardware to protect the energy industry from cyberattacks. These products don’t replace the traditional cybersecurity practices; however, they create an additional layer that increases the ability of organizations to protect their infrastructure from cyberattacks.

In 2019, the IEC saw an average of 11,000 suspected cyber events per second. Thus, to tackle the risk of cyberattacks, it developed a set of latest cybersecurity tools that would help secure its infrastructure and the same were unveiled during the conference. These are developed making use of artificial intelligence (AI) and machine learning (ML) that help prioritize cybersecurity events and bifurcate between false or a real alarm. The products also monitor information about vulnerabilities coming in from the supply chains and calculates the “butterfly effect” of cyber events happening around the world on the respective organization.

Earlier, owing to the high volume of tourists expected during the Tokyo 2020 Olympic games and possible threat analysis conducted by the governing authorities, Japan’s Communication Ministry tabled a set of an emergency proposal that includes guidelines to mitigate risks and incidence response for cyberattacks. The Communication Ministry panel identified certain devices and technologies including IoT (Internet of Things) devices that are vulnerable to cyberattacks. The emergency package says that, “It is desirable to consider publishing information on cyberattacks swiftly at the point in which leaks of personal information are suspected,” calling for information-sharing with relevant organizations.

The panel also recommended cybersecurity training to local government municipalities, as nearly half of its staff is unaware of basic cyberattack precautionary and response measures.

OurMine Group Announces Comeback, Hacks 15 NFL Teams’ Twitter Handles

Twitter hack

The cybercriminal group OurMine hacked 15 Twitter accounts of the U.S. National Football League (NFL) teams including NFL’s handle and posted a message, “Hi, we’re back. We are here to show people that everything is hackable.”

Exact details of the account hijacking remained unclear, however, the majority of the tweets posted by the OurMine operators on the hijacked accounts came from Khoros. It is a web-based third-party application used by the organization’s digital marketing and public relations departments to manage their social media accounts and gain useful insights into public engagements across different platforms.

As per ZDNet, along with Twitter, the OurMine group also managed to hack some of NFL Teams’ Facebook and Instagram accounts including:

  • NFL (Twitter account)
  • Arizona Cardinals (Twitter account)
  • Buffalo Bills (Instagram and Facebook accounts)
  • Chicago Bears (Twitter account)
  • Cleveland Browns (Twitter account)
  • Dallas Cowboys (Twitter, Facebook, and Instagram accounts)
  • Denver Broncos (Twitter account)
  • Green Bay Packers (Twitter account)
  • Houston Texans (Twitter account)
  • Indianapolis Colts (Twitter account)
  • Kansas City Chiefs (Twitter account)
  • New York Giants (Twitter account)
  • Minnesota Vikings (Instagram account)
  • Philadelphia Eagles (Twitter account)
  • San Francisco 49ers (Twitter account)
  • Tampa Bay Buccaneers (Twitter account)

OurMine’s Hacking History

This is not the first time that the OurMine group has hacked the social media accounts of known personalities and teams. In 2017, OurMine operators hacked Twitter handles of Futbol Club Barcelona and Real Madrid Club de Futbol. The hackers sent out tweets from Real Madrid Club de Futbol’s  Twitter account in English and Spanish, which announced the joining of major rival player Lionel Messi. They also posted video footage from an earlier match which showed Messi scoring for Barcelona against Real Madrid. The tweets were visible for almost 90 minutes on the football club’s handle but were later removed. The welcoming post of Messi had grabbed the attention of the fans by then, as the tweet received almost 2,800 likes and 3,100 retweets.

Other victims in this list include Wikipedia co-founder Jimmy Wales, Facebook co-founder Mark Zuckerberg, Google CEO Sundar Pichai, as well as organizations such as Buzzfeed. The group also breached the social media accounts of the home media giant, HBO. OurMine claims that the cybersecurity breaches are done by them to expose weaknesses in the victim’s system and promote its own cybersecurity services.

Employees Send Over 130 Emails to Wrong Recipients Every Week: Report

Business Email Compromise Attacks

Most companies rely on e-mail as the primary means of communication even when it comes to sharing classified information like customer account numbers, employee credentials, and confidential negotiations. A new report from the security firm, Tessian revealed that large organizations inadvertently suffer data breaches if one of their employees unintentionally sends sensitive data to an unauthorized recipient via email.

The report also highlighted that employees mistakenly send over 130 emails per week to wrong recipients, leaving the data security at risk. Tessian claims that workers sending company’s sensitive data to unauthorized/personal email accounts to over 200,000 times per year.

“Misdirected emails – emails accidentally sent to the wrong person – are particularly dangerous. Beyond just embarrassment over cc’ing the wrong person, for example, we are seeing serious repercussions as more people expose personal and corporate data. Simply misspelling a name can result in sensitive data or company secrets falling into the wrong hands and your company facing a regulator’s wrath,” the report stated.

Recently, a similar survey“Current Status of Data Privacy Compliance”, from Email security provider Egress revealed that 44 percent of employees admit that they’ve mistakenly exposed personally identifiable information (PII) or business-sensitive information using their corporate email accounts. Over 70 percent of respondents experienced this type of breach during the last five years, with half of these incidents occurring in the previous 12 months.

The survey also highlighted that accidental internal breaches are rising. Based on the responses from 500 IT security decision-makers in the U.S., accidental employee breaches are ranked as one of the top three security concerns (46 percent), behind external hacks (55 percent), and malware attacks (53 percent).

To conclude, it is time companies realize that all communications made via emails may not be as private as they think. A single negligent employee’s action may break the safety and security of the organization.

U.K. CEOs Delete Social Media Accounts to Prevent Cyberattacks

active directory
active directory

Most of the Chief Executive Officers (CEOs) in the U.K. are concerned about potential cyberattacks on their organizations, ZDNet reported. According to a report from PwC, nearly 48.4 percent of the U.K.’s CEOs deleted their social media accounts and erased their personal information online. The report, “23rd Annual Global CEO Survey”, also stated that four-in-five CEOs (around 80 percent) have changed their online behavior fearing cyber risks.

The findings are based on the responses from a global survey on 1,600 CEOs from 83 countries across the world. The primary intention of the survey is to expose the problems affecting the cybersecurity strategies of CEOs in the U.K.

Apart from cyberattacks, the growing concerns of CEOs include data privacy regulations, vulnerabilities in supply chains, and shortage of cybersecurity talent.

Richard Horne, Cybersecurity Chairperson at PwC, said, “It’s clear that cybercrime continues to grow as an issue for CEOs around the world, meaning that for many, the threat to their margins, their brands and even their continued existence from cyberattacks is no longer an abstract risk that can be ignored. Criminals are becoming more adept at monetizing their breaches, with a sharp rise in ransomware attacks this last year. They can have a devastating impact on the organizations they hit, as seen in many high-profile cases.”

Cyberthreats in the Past

Earlier, a survey from data security firm Clearswift revealed that more than half of the companies in the U.K. experienced a security incident in 2019.

The research, which surveyed 100 senior business decision-makers from financial organizations in the U.K., highlighted that most of the attacks have originated due to employees who failed to follow proper data protection policies. Apart from employees’ errors, the survey also revealed other reasons, that led to attacks, including downloads of malware or viruses from third-party devices like USB pen drives, and file transfers to unsecured sources.

More than 3,000 Indian Government E-Mails Kept on Dark Web: Cyber Researcher

SideCopy Malware Campaign

Sai Krishna Kothapalli, a security expert and founder of cybersecurity startup Hackrew, claimed that he found 3,202 Indian government email IDs and their passwords leaked on the dark web across multiple databases.

According to Kothapalli, the exposed email accounts belong to key officials from around 20 different government institutions and ministries, including Indian Space Research Organization (ISRO), Bhabha Atomic Research Centre (BARC), Securities and Exchanges Board of India (SEBI), and Indira Gandhi Atomic Research Center (IGARC).

Senior government officials including former and current ambassadors, serving and retired scientists in ISRO, and senior bureaucrats across state governments, especially scientists working in nuclear technology are being targeted via phishing emails. It’s said that the exposed emails on the dark web are with “gov.in” extension.

As per Kothapally’s research findings, 365 e-mail accounts are leaked from IGARC, which is the highest number in the breach. Whereas, 325 e-mail credentials from BARC have become public, followed by 157 from SEBI.

“I’m in the process of finishing the remaining investigation and contacting the respective government organizations to alert them on this issue. It is not just government organizations, but the details of the employees of several multinational companies, Indian companies, etc. have also been leaked. At this stage, it is important to be proactive, revoke those credentials and take proper security measures. It is high time that two-factor authentication is introduced to access email accounts of employees in sensitive organizations. Another simple measure that will prevent damage from future attacks is to use a password manager and set separate passwords for various web-based services,” Kothapalli said in a media statement.

Earlier, a similar research by hardware networking firm, Cisco revealed that one in three Indian organizations faced huge financial losses from security breaches.

The research, “2019 Asia Pacific CISO Benchmark Study”, disclosed that nearly 37 percent of organizations in India suffered downtime of over nine hours after a data breach. Around 46 percent of companies surveyed stated that they’ve received more than 5,000 threat alerts in a day, in which 43 percent of them went unattended. The survey findings were based on responses from 2,000 security leaders across 11 countries in the Asia Pacific, from public and private organizations.

Normalcy Retained at AWS Sydney Post API Errors and Latencies

Remote Access Scams

Amazon Web Services (AWS) in Sydney faced a sudden increase in API errors and corresponding latencies. These affected seven dependent services of AWS including Appstream 2.0, Elastic Cloud Compute (EC2), Elastic Load Balancing (ELB), ElastiCache, Relational Database Service (RDS), Workspaces, and Lambda. However, services were gradually restored by late evening.

On January 23, 2020, around 12 noon (Australia time zone), AWS Status Updates page—under its EC2 Sydney chapter—first reported this issue, saying connectivity to existing instances was not impacted. Later, AWS said, it had identified the root cause of the issue that mainly affected EC2 RunInstances and VPC related API requests. Launch requests from regional objects like subnets, which already existed, continued successfully as they did not depend on the affected subsystem. Thus, known subnet IDs were suggested to be used to launch instances within the region.

“A data store used by a subsystem responsible for the configuration of Virtual Private Cloud (VPC) networks is currently offline and the engineering team are working to restore it. While the investigation into the issue was started immediately, it took us longer to understand the full extent of the issue and determine a path to recovery,” said AWS, an hour later, on its Status Updates page.

Australia on High Alert

The consequences of the API errors and latencies were faced by customers, including the Australian Capital Territory (ACT) Emergency Services Agency (ESA), which keeps the locals updated with the state of emergencies. Currently, Australia is on a high alert due to the wild bushfires in the surrounding region of the ACT. Thus, locals have been advised to report to ACT through its website in case of heavy smoke spotting. AWS apologized for the inconvenience and restored the ACT’s ESA website by late evening to reinstate normalcy.

Recently, in order to help the people fighting it out on the frontline of Australian bushfires, many organizations set up online donation gateways on their respective websites. But, the Malwarebytes Threat Intelligence Team discovered a legitimate donation collecting website that was compromised by a MageCart script.

Hackers planted a Magecart script on the checkout page of the website to steal the payment information of the donors. This information was then sent to a domain controlled by the hackers. The research team confirmed that the software used for skimming is known as ATMZOW. On completing the donation process successfully, the stolen card details were then sent to a website, vamberlo.com. The malignant domain used by the hackers was later shut down.

Is Connectivity Making Industrial Cybersecurity More Vulnerable?

Industrial IoT

It can be argued that industrial facilities have taken to digital transformation much earlier than other enterprises. While it’s only now that some businesses are committing to adopting digital tools, factories have been using robots and programmable logic controllers (PLCs) decades before the dotcom boom of the nineties. Industrial cybersecurity comes to the forefront as industries increasingly adopt digital technologies.

Contributed by Joshua Blackborne

What’s probably sweeping industries today are technologies that rely on connectivity: the cloud, mobile computing, and the Internet-of-Things (IoT). These technologies offer some very exciting applications. The cloud has allowed organizations to shift part of their IT infrastructure off-premises and easily scale their available computing resources. Mobile computing and connectivity have allowed engineers to monitor and control their machines remotely. Sensors and robots are now even smarter, and through the IoT, are capable of interfacing with external artificial intelligence (AI) or analytics engines that allow these machines to automatically adjust for greater efficiency even without human intervention.

The need for Industrial Cybersecurity

However, this increasing connectivity of industrial facilities is now also raising cybersecurity concerns calling for more attention to industrial cybersecurity. Previously, industrial facilities were largely air-gapped, so hackers had to manipulate staff through social engineering attacks, or infiltrate facilities themselves. But as more industrial IT components connect to the internet, they become more exposed to cyberattacks from advanced persistent threats (APTs).

“Industrial facilities have become more connected. Cloud computing has prompted a growing number of enterprises to shift their workload online. More facilities are also incorporating smart devices into their infrastructure. Unfortunately, this is also expanding the attack surface. Given how tenacious threat groups are these days, increasing connectivity can make these enterprises vulnerable to attack,” Oren Eytan, CEO of enterprise cybersecurity firm odix, shares.

Here are three areas where industries are becoming more connected and how they can expose infrastructure to possible attacks:

Adoption of Cloud Components

One area that should concern industries regarding their cybersecurity is their adoption of cloud computing. For many organizations, the emergence of cloud computing has been a boon. They can now essentially outsource their computing needs to providers, lessening the need for acquiring and maintaining servers and applications on-site.

Unfortunately, cloud instances can be compromised whether through vulnerabilities at the provider’s end or through weak access controls at the user’s end. Hackers can then steal, hijack, and destroy critical data. They can even perform supply chain hacks that could introduce malicious code or malware into the company’s cloud storage and repositories. Access to these cloud components is often whitelisted, allowing malware to reach the facility’s infrastructure unhindered.

“What could be more troubling is that hackers have become crafty, disguising their malware within legitimate files. They can even feature polymorphic code that continuously changes, allowing it to evade conventional signature-based detection. What’s often needed is for enterprises to integrate solutions like content disarm and reconstruction that can sanitize all files coming into the network, whether through email or repositories, to ensure that they are safe,” Eytan adds.

Introduction of Smart Devices and IoT

Another way that industries are becoming more connected is through the adoption of smart IoT devices. Previously, industries relied on PLCs to control their machinery which had limited connectivity outside facilities. Today, sensors and robots are connecting directly to the Internet, allowing them to readily send and receive data, or be remotely controlled.

However, since these devices directly access the Internet, it’s possible for attackers to quickly interface with them. Unless they are equipped with capable security features, they may easily be compromised. One only has to recall how the Mirai malware compromised hundreds of thousands of low-security IP cameras and home routers and made them part of a massive botnet that nearly took down the Internet in 2016.

“It’s reasonable for companies to be concerned about the security of IoT device deployments in industrial environments. Each device has an associated risk to data and operational integrity. A compromised internet-connected device could create a pathway for attacks on connected systems, including critical control systems,” writes Sid Snitkin, VP of industry and infrastructure advisory firm ARC.

It is critical then for enterprises to be aware of these concerns and look to integrate only those devices have ample security features such abilities to change default administrator credentials, disable unused features, and update device firmware and applications. The industry has been working toward promoting device certification through bodies like ISASecure but manufacturers have yet to make this practice standard.

Use of 5G for Industrial Applications

5G is set to explode this year as more areas and territories get better coverage. In the U.S., service providers are already gearing up to launch their mobile 5G services in major cities. Manufacturers have already released 5G-capable devices in their flagship and premium models. The feature is expected to trickle down to their more mainstream models as wider coverage becomes available.

Aside from being capable of gigabit-level speeds, 5G is supposedly capable of much lower latency. This becomes a definite advantage where faster response times are critical, especially for remotely controlling devices, and machinery that requires precision. Self-driving cars can receive traffic and road data coming from external sources sooner, allowing them to make real-time adjustments. In Healthcare, this could enable remote robotic surgery to be done in even the most isolated locations.

But the use of wireless connectivity has its weaknesses as well. Hackers can perform man-in-the-middle attacks where they hijack signals or use fake cell towers so that they can steal data in transit or even inject malware into connected devices.

Committing to Industrial Cybersecurity

Enterprises now have to weigh the risks and benefits of adopting these new technologies. As businesses, they would definitely want to leverage better connectivity to improve efficiency and enable new use cases.

Still, they also have to seriously consider the cybersecurity threats that adopting these technologies can introduce to their infrastructures. Fortunately, security solutions providers are continually developing their tools to accommodate all these changes.

Organizations and facilities must ultimately revisit their security strategies and practices to ensure that they keep their perimeters secure even if they choose to introduce new components and endpoints to their infrastructure.

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Hackers Put 30 Million Wawa Customers’ Data for Sale

Massive Data Breach at Wawa Stores Affected Customers’ Data

Security pros from threat intelligence firm Gemini Advisory revealed that hackers kept payment card details of Wawa’s customers on “Joker’s Stash” a dark web marketplace for trading stolen cards data. Researchers stated that hackers advertised the stolen card data as “BIGBADABOOM-III”, and the data belongs to 30 million Americans and over one million foreigners from more than 100 different countries.

It’s believed that Joker’s Stash contains debit/credit card details from the U.S., European, and global cardholders, including their geolocation data like state, city, and ZIP Code. In an official statement, Wawa confirmed that hackers tried to sell customers’ card information that breached in the security incident occurred on December 10, 2019.

“We became aware of reports of criminal attempts to sell some customer payment card information potentially involved in the previous Data Security Incident announced by Wawa on December 19, 2019. We have alerted our payment card processor, payment card brands, and card issuers to heighten fraud monitoring activities to help further protect any customer information. We continue to work closely with federal law enforcement in connection with their ongoing investigation to determine the scope of the disclosure of Wawa-specific customer payment card data,” the statement read.

Breach Overview

According to Chris Gheysens, Wawa’s CEO, the company discovered a malware payload in its payment processing systems on December 10, 2019. The security team at Wawa blocked the malware and believed that the malware no longer posed any risk to customers making payments at Wawa stores.

However, the malware affected the customers who made payments at Wawa stores and gas stations.Since March 4, 2019, the incident potentially affected 850 stores, which are operated by Wawa across the East Coast from Pennsylvania to Florida.

The exposed financial information included debit and credit card numbers, expiration dates, and cardholder names. However, PINs and CVV numbers were not exposed. The company also clarified that there is no evidence of any unauthorized use of exposed payment information.

 Investigation Under Process

In a related incident, a class-action lawsuit was filed against Wawa Stores for failing to protect customers’ data. The lawsuit, which was filed in the U.S. District Court for the Eastern District of Pennsylvania, brought several people who claim they were impacted by the breach.

The lawsuit claimed that Wawa failed to secure its computer systems from hackers who installed malware that potentially affected Wawa’s payment systems. It also accused Wawa for breach of contract and violating consumer protection laws.

U.K.’s Cybersecurity Industry Worth £8.3 Billion: Report

Cybersecurity Skill Shortage Leads U.K. Firms to Outsourced Security Services

According to the U.K.’s Department for Digital, Culture, Media, and Sport (DCMS), the number of active cybersecurity firms in the country increased by 44 percent,  up from 846 firms in 2017 to over 1,200 in 2019, indicating a growth in the cybersecurity industry.

In its report, “The U.K. Cybersecurity Sectoral Analysis 2020”, DCMS stated the security industry in the U.K. has seen a significant surge in security investments, annual revenue, and employment. It also highlighted that around 43,000 full-time employees are currently working in the industry.

The annual revenue in the cybersecurity sector rose by 46 percent to an estimated worth of £8.3 billion (approximately US$10.8 billion). The sector received more than £348 million (approximately US$452.4 million) of investment last year.

Digital Minister Matt Warman said, “It plays a vital role in protecting the country’s thriving digital economy and keeping people safe online. It’s great to see our cybersecurity sector going from strength to strength. We are committed to seeing it grow and are investing £1.9 billion over five years through our National Cyber Security Strategy to make sure we lead the way in cyber innovation, develop and attract the best talent.”

Recently, the U.K. government introduced a legislation to improve the security standards of the consumer IoT (Internet of Things). The law, launched by DCMS, mandates that all the IoT devices sold in the country must adhere to advanced security standards.

The regulations, jointly developed by DCMS and the National Cyber Security Centre, were intended for companies that manufacture and sell consumer IoT devices. According to DCMS, the use of connected devices increased. It’s estimated that there will be around 75 billion IoT devices in homes globally by the end of 2025.