Home Blog Page 251

Random Thoughts on Data Privacy Day

personal data collection, Personal data. Data Privacy

The world marks 28th January 2020 as Data Privacy Day (also called Data Protection Day in Europe). On this occasion, it’s essential to revisit the concerns that consumers have about data privacy. While laws are yet to be established or just rolling out (notably CCPA and India’s Data Protection Bill), consumers need to step forward and question services organizations who are custodians of their data and Personally Identifiable Information (PII). As we go about reporting news daily here at CISO MAG, it is alarming to note that almost every other week, we read about organizations getting hacked and about their customer databases leaked online. Yes, data has become the fluid that keeps the business machinery moving, and it is up to organizations to prioritize the security of this data.

Manish Sehgal, Partner, Deloitte India, said, “Over the past years there have been many conversations on ‘data as new oil,’ or ‘data as an asset.’ However, flipping the coin, if data (personal data to be specific) across its lifecycle is not safeguarded, and is used or processed beyond defined purposes, it may become a liability.”

Countries have taken steps to secure consumer data, and businesses are bound by regulation, some with strict penalties and hefty fines. The EU’s GDPR is an example, and other countries are also working on similar laws and regulations. However, that alone does not guarantee that your data is in safe hands. Organizations in possession of consumer data need to do a lot more and deploy the right security solutions (to address data leakage and ransomware, for instance). They need to go further and ensure that partners in their ecosystem also secure their customer databases. If the data is on the cloud, on a service provider’s server, then the service provider also shoulders that responsibility. And the organization needs to take adequate steps right at the beginning to ensure it.

Sehgal added, “With growing regulations and strengthening rights for data owners, organizations around the world are becoming more answerable than ever before regarding data’s usage, storage, and erasure. Given the anxiety around the protection of data and its storage today, real value for any organization is to be proactive to become privacy enabled and not just a privacy compliant.”

It comes down to legalities, frameworks, policies and guiding principles—and Generally Accepted Privacy Principles (GAPP) is an example.

“Leading practices and frameworks such as GAPP offer necessary guidance for organizations to embark on their data journey. The need of the hour for the majority of Indian enterprises is to strategize, prioritize and initiate their growth path harnessing the power of data,” concluded Sehgal.

So, this is not just another special day marked on our calendars. On Data Privacy Day, we all need to ask ourselves if we are doing enough to protect our data and our customers’ data. We need to raise more awareness and listen to the privacy concerns of our customers.

A responsible organization gains trust and credibility–which leads to business success.

New York Senators Proposes Bill to Ban Ransomware Payments

Two senators of New York state recently came up with two bills to ban government agencies and local municipalities from using public money for paying ransomware to cybercriminals.

The first bill, proposed by Republican NY Senator Phil Boyle, and the second bill, proposed by Democrat NY Senator David Carlucci, are currently under discussion in committee. Apart from ransomware payments, the proposed bills also recommended creation of a state fund to aid government entities improve their cybersecurity capabilities.

“The cybersecurity enhancement fund that will make available grants and financial assistance to villages, towns, and cities with a population of one million or less for the purpose of upgrading the cybersecurity of their local government,” the bill stated.

Several industry experts opined that this is the first time the state authorities have proposed a law that bans paying the ransom.

Earlier this year, the New York State Legislature passed a bill “Stop Hacks and Improve Electronic Data Security Act (SHIELD)” to strengthen its data breach policies.

The bill provides more transparency to consumers while also impose stringent penalties on companies without proper cybersecurity measures.

According to the Attorney General Letitia James, the SHIELD Act updated the state’s breach notification laws, extended notification requirements for companies, and increases the rights of consumers in the event of a breach. The bill also imposed tough obligations on businesses that handle sensitive data of customers.

“It is critical that our laws keep pace with the rapidly changing world of technology,” said State Senator Kevin Thomas. “I’m proud to announce the passage of the SHIELD Act today, as it will allow for increased accountability and diligence in regard to consumer privacy. Now more than ever, it is important that businesses protect the private information of the consumers they serve.”

Betting Companies Access Education Data of 28 Million Children in U.K.

"db8151dd" An Untraceable Data Breach: 22 Mn Emails Compromised

The U.K. government is facing criticism for allowing betting firms to access the Department for Education (DfE) database, called the Learning Record Service, which contained personal data of 28 million children. The database stores information on students aged 14 years and above, from schools and colleges in England, Wales and North Ireland for academics and education purposes. The exposed information included names, ages, addresses, and personal details.

According to a report published by the Sunday Times, Trustopia, a third-party training provider, apparently violated an agreement with the government and gave the database access to data intelligence company GB Group. It’s said that GB Group and its clients, gambling firms Betfair and 32Red, apparently accessed the data for age and ID verification on their websites.

It’s believed that Betfair and 32Red used this information to increase the ratio of youngsters who gamble online. However, Trustopia denied giving database access to GB Group. The DfE and GB Group have notified the incident to U.K.’s privacy protection body Information Commissioner’s Office.

Many industry experts criticized the Department for Education’s diligence practice and asked for an investigation.

In a related news, Active Network, a provider of web-based school accounting software, disclosed a security breach that affected thousands of students’ data.

According to the official notice, unknown intruders gained access to Active Network’s Blue Bear platform, a software that facilitates administration and management of school accounting, student fees and online stores on behalf of schools and other educational institutions.

Active Network stated that the personal information of students or parents who accessed the school’s Blue Bear software between October 1 and November 13, 2019, were affected in the incident. It’s believed that hackers accessed users’ private data like name, payment card number, expiration date, security code, and Blue Bear account usernames and passwords. However, the company clarified that the incident didn’t affect users’ social security numbers, driver license numbers, or similar government ID card numbers.

Trend Micro’s Fake Factory OT Honeypot Lures Real Threat Actors

Number of IoT Devices Expected to Reach 24.1 Bn in 2030: Report

Cybersecurity solutions provider Trend Micro revealed the results of its six-month operational technology (OT) honeypot, which was a look-alike of a real industrial factory. The aim of creating an OT honeypot was to discover potential threat actors that could carry out malicious cyberattacks, exploits, and consumer fraud.

By Pooja Tikekar, Feature Writer at CISO MAG

Deployment of the Honeypot

The team at Trend Micro built a real-time environment that consisted of programmable logic controllers, a human-machine interface (HMI), and other components of an industrial control system (ICS). The faux company presented itself as a rapid prototyping consultancy firm, MeTech, with real human employees, working contact channels, and a client base of organizations from critical industries. The team also designed a professional-looking website using a free web template.

Trend Micro’s research paper, titled, “Caught in the Act: Running a Realistic Factory Honeypot to Capture Real Threats” revealed that the MeTech honeypot went online in May 2019, through a Virtual Network Computing (VNC) and used the same password for multiple workstations. It purposely leaked sensitive information to lure more attackers.

The live honeypot was compromised for cyberthreats such as cryptocurrency mining, system shutdowns, and ransomware infections such as Crysis.

Talking about the rise in industrial cyberthreats, Trend Micro’s Vice President, Greg Young, said, “Too often, discussion of cyberthreats to industrial control systems (ICS) has been confined to highly sophisticated, nation-state level attacks designed to sabotage key processes. While these do present a risk to Industry 4.0, our research proves that more commonplace threats are more likely.”

Young further added, “Owners of smaller factories and industrial plants should therefore not assume that criminals will leave them alone. A lack of basic protections can open the door to relatively straightforward ransomware or cryptojacking attack that could have serious consequences for the bottom line.”

Honeypots Across the Globe

In 2019, cybersecurity company Kaspersky planted more than 50 honeypots across the globe to trap cybercriminals. The honeypots experiment detected 105 million attacks on the Internet of Things (IoT) devices coming from 276,000 unique IP addresses. The company stated that the attacks were nine times greater than the number found in the first six months of 2018.


About the Author

Pooja Tikekar is a Feature Writer, and part of the editorial team at CISO MAG. She writes news and feature stories on cybersecurity trends.

More from the author.

 

 

Ursnif Malware Spam Targets Germany Using German Language

Armor Piercer

Cybersecurity researchers have observed a recent trend of Ursnif malware spam specifically targeting German nationals using a spam email message written in German language. Once the target system is compromised, Ursnif steals system information and attempts to steal banking and online account credentials through various mediums including web browsers.

What is Ursnif?

Ursnif malware spam is popular in the Windows banking Trojan family. Its source code has been active in some form or another since 2007 when it first appeared in the Gozi banking Trojan. Gozi’s source code was mistakenly leaked by its developers in 2010, which gave birth to its advanced version of malware, now known as Ursnif.

How Ursnif Works?

Although there are multiple variants of Ursnif, this version seen in Germany follows this workflow:

  • The campaign begins with a spam email containing a password protected zip file being sent to the targeted victim. The email content contains the password to this zip file. In this campaign, researchers have found 3-digit passwords being used, such as 111333, 555 and 777.
  • On entering the password given in the email text, a Microsoft Word document is extracted from the password-protected zip file. These Word documents are named doc. The Word document also contains a text message written in German. This message directs the user to enable macros in MS Word.
  • Once the macros are enabled, other security features such as Protected Mode are checked by the malware dropper. On confirming a vulnerable Windows host, the dropper pushes the Ursnif malware into the system.
  • Ursnif further loads (executes .exe) into the system and begins stealing multiple sets of information from the system and stores them in a file. It then connects to a malicious command and control (C&C or C2) server and transfers the info file into it.
  • What differentiates the German version of Ursnif malware is this step. The loaded Ursnif malware is seen dropping a few other follow-up payloads that are variants of the original Ursnif source code.

ursnif malware

Indicators of Compromise

Main Ursnif malware IoC details are as follows:

  • 85.157[.]246 port 80 – emblareppy[.]com GET /gunshu/lewasy.php?l=ambobi9.cab
  • port 80 – settings-win.data.microsoft[.]com – GET /images/[long string].avi
  • 85.153[.]218 port 80 – pzhmnbarguerite4819[.]com – GET /images/[long string].avi
  • 169.181[.]33 port 80 – n60peablo[.]com – GET /images/[long string].avi
  • port 443 – settings-win.data.microsoft[.]com – HTTPS traffic
  • 141.103[.]204 port 443 – nk47yicbnnsi[.]com – HTTPS traffic

Follow-up Ursnif malware variant IoC details are as follows:

  • port 80 – google[.]com – GET /
  • port 80 – www.google[.]com – GET /
  • DNS queries for onionpie[.]at – no response from the server
  • DNS queries for tahhir[.]at – no response from the server
  • 249.145[.]116 port 80 – limpopo[.]at – GET /images/[long string]
  • 175[.]7.8 port 80 – estate-advice[.]at – GET /images/[long string]
  • 56.73[.]146 port 80 – sweetlights[.]at – GET /g32.bin
  • 56.73[.]146 port 80 – sweetlights[.]at – GET /g64.bin
  • 56.73[.]146 port 80 – estate-advice[.]at – POST /images/[long string]
  • 95.185[.]58 port 80 – estate-advice[.]at – GET /images/[long string]
  • 249.145[.]116 port 80 – limpopo[.]at – POST /images/[long string]
  • 51.223.47[.]15 port 80 – estate-advice[.]at – POST /images/[long string]

Cyberthreat Incidents Decline in India in 2019: Kaspersky Report

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

Kaspersky, in its report, revealed that India saw a decline in the number of cyberattacks in 2019. It stated that 38.8 percent of Kaspersky users in India were attacked at least once by web-based attacks in 2019, which is less when compared to 2018 (40.4 percent). The primary reason for these attacks was the distribution of malware via removable USB drives, CDs and DVDs, and other offline methods.

The company stated that it detected 142,250,268 unique threats last year, including file-less malware, social engineering attacks, and other web-based attacks. Kaspersky also discovered 231,142,762 local threats in India that brought the country to 69th position in the cyberattack index worldwide, as compared to 47th rank in 2018 with 297,477,131 threats detected.

Saurabh Sharma, a security researcher at Kaspersky, said, “In India, we did see a decrease in the number of adware and malware attacks, however, there has been a huge increase in Riskware attacks from 28 percent in 2018 to 39 percent in 2019. The presence of riskware on your machine will allow threat actors to use that legitimate application for malicious purpose.” Similar research from Cisco revealed that one in three Indian organizations faced financial losses from security breaches and 24 percent of companies lost around US$1 million or more in 2019.

The research titled “2019 Asia Pacific CISO Benchmark Study”, disclosed that nearly 37 percent of organizations in India suffered downtime of over nine hours after a data breach. Around 46 percent of companies surveyed stated that they’ve received more than 5,000 threat alerts in a day, in which 43 percent of them went unattended.

The survey findings were based on responses from 2,000 security leaders from the public and private organizations across 11 countries in the Asia Pacific. The report gathered data in four areas:  Cybersecurity culture; Security alerts and the impact of data breaches; Cybersecurity trends: Cloud and Operational Technology threats; and the Defenders’ approach on managing vendors.

Keys to a Successful Third-Party Risk Management Process

Only 44% of Health Care Providers Meet National Standards on Cybersecurity, OpenEMR vulnerabilities

The risk to health care organizations from a third-party vendor breach is clear—through August of 2019 alone, there have been 33 breaches by a business associate/vendor totaling over 22.5 million records. That’s one breach per week attributed to a third-party. Organizational leaders often struggle to focus on Third-Party Risk Management (TPRM)—or risk posed by third parties, such as vendors who work with an organization and have access to sensitive patient information—despite knowing about the benefits of such a program. With a myriad of other responsibilities, focusing on the security of third parties can seem incredibly complex and time-consuming. And it is. It can take a year or more to develop an effective program, depending on the complexity of the organization and the number of third parties. But once the program is in place, personal health information (PHI) and personally identifiable information (PII) are safer and the organization has a much firmer grasp on their overall risk.

By Sean Friel, CEO, Intraprise Health

Prior to deciding to engage a partner to get a true understanding of third-party risks, it helps to understand the benefits and importance of such an undertaking. Keeping data safe, resolving security gaps—and more importantly understanding where the gaps are—and putting processes and protocols in place ultimately makes your organization stronger and helps sustain and grow your business. It’s not just an IT issue to solve; third-party risk can jeopardize many areas of your hospital, health care facility, or payer organization.

Once you’ve decided to engage a partner to help you with your Third-Party Risk Management (TPRM) program, it’s time to manage expectations internally, and with your new partner, so everyone understands what’s expected of each other and what the process will entail. For instance, you want the process to include every department that works with data and with third parties in an organization.  A TPRM process is enterprise-wide.

You cannot rush this process. Most people who undertake the effort to build a TPRM program are surprised by how long it takes and how much work it involves, despite being educated about the process before it starts. When completed, however, they feel a huge sense of accomplishment. In effect, a solid TPRM program and process improves how organizations think and work in addition to protecting their data.

Make sure there is ownership and accountability in your organization for the TPRM program. Those stakeholders are responsible for keeping people engaged in the process and ensuring objectives are being met. They also regularly remind people why they’re undertaking this huge but necessary endeavor; they are the TPRM organizational cheerleaders.

Utilizing external experts can help implement an effective program. Some TPRM program implementation services might include:

  • Ensuring stakeholders across the supply chain all share a common vision and goals
  • Documenting current and optimal workflows and processes so everyone involved knows what they need to achieve
  • Evaluating and implementing optimized TPRM services such as assessing and revising current state workflows and processes

Here are some milestones that a good TPRM process will employ (keep in mind, each partner will offer various services, but it’s important to understand what the process might include):

  • Request an Assessment – Who is responsible for ensuring requests are made when needed?
  • Know the potential risk a third-party could pose before starting the assessment (often called “tiering”).
  • Develop a solid, thoughtful and customized questionnaire based on the potential risk
  • Collect evidence to validate the questionnaire responses
  • Interview key vendor personnel to ensure they understand and follow a good security program
  • Distill and compile the gathered information into a consumable report for decision makers
  • Log and track any identified risks, regardless of severity

A good software platform can help to facilitate the entire process and might include:

  • Configuring TPRM workflows and dashboards
  • Providing access to third parties who will be active participants in the process
  • Enabling process workflow
  • Collecting evidence and questionnaire responses
  • Risk logging and tracking of remediation

A health care organization’s data is a vital asset that needs to be protected. Make sure the people who help you safeguard it are security-minded experts.

About the Author

Sean Friel, CEO, Intraprise Health, TPRMSean Friel, CEO of Intraprise Health, has dedicated his 35-year career to helping health care organizations implement technology that improves their operations and patient care. He is recognized throughout the industry for his ability to build customer-focused teams that have received industry-leading customer satisfaction scores.

Most recently, Sean led rapid growth at private equity backed leading Health Information Technology companies such a Voalte and Lightning Bolt Solutions. As National Vice President of U.S. Sales for Siemens’ Health care IT division, his team drove sales to more than US$1 billion. Prior to his 13 years at Siemens, Sean played an instrumental role in the success of Shared Medical Systems (SMS), an early leader in automating hospital systems.

Disclaimer: CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

250 Million Customer Records Exposed Due to Misconfiguration: Microsoft

Microsoft Azure Account

Microsoft has admitted to a security blunder of misconfiguring a customer service and support database that exposed 14 years of customer service and support data dating back to 2005, accessible to anyone with a web browser requiring no authentication at all.

As per Microsoft’s blog, on December 5, 2019, a change was made to the said databases’ network security group. It was later found that appropriate measures were not taken to verify the Azure security rules and this misconfiguration further led to the data exposure. The exposure was discovered by a security research team at Comparitech led by Bob Diachenko. He uncovered a total of five Elastic Servers containing 250 million records including logs of communication between Microsoft’s support engineers and its customers.

Diachenko discovered these databases on December 29, 2019, and understanding the critical nature of the security hole quickly reported it to Microsoft. Considering the Holiday Season, he wasn’t sure if the vulnerability could be plugged immediately, but Microsoft secured all the servers and corresponding data by the New Year’s Eve.

Diachenko’s research says that personally identifiable information (PII) of clients was in most cases obscured, but some of these records contained plain text data, such as:

  • Customer email address
  • IP address
  • Location
  • Descriptions of Customer Service and Support query
  • Attending Microsoft support agent email
  • Case number, resolution given, remarks entered, and
  • Internal notes marked as “confidential”

Microsoft said, “We want to sincerely apologize and reassure our customers that we are taking it (database misconfiguration) seriously and working diligently to learn and take action to prevent any future reoccurrence. We also want to thank the researcher, Bob Diachenko, for working closely with us so that we were able to quickly fix this misconfiguration, investigate the situation, and begin notifying customers as appropriate.”

In December 2019, Diachenko discovered an unprotected public database containing over 267 million Facebook user IDs, names, and contact details that were left online without password protection. The incident occurred due to illegal scraping operation or Facebook API abuse by cybercriminals in Vietnam.

Diachenko stated that 267,140,436 records were exposed in the incident, which could be used by attackers to launch SMS spam and phishing campaigns. The exposed data was also posted on a hacker forum for download.

Medical Cannabis Users Suffer Data Breach

Medical Cannabis Users Suffer Data Breach

Researchers Noam Rotem and Ran Locar from security firm vpnMentor discovered an unsecured Amazon S3 bucket on December 24, 2019, that exposed sensitive data of medical cannabis users and multiple cannabis dispensaries across the United States.

The researchers stated the leaky database is owned by THSuite, a Point-Of-Sale and management system used in dispensaries in the U.S.

THSuite later fixed the database on January 14, 2020, after vpnMentor notified the incident. According to VPNMentor, the exposed data included personally identifiable information (PII) belonging to 30,000 individuals, scanned government and employee IDs, full names of patients and staff members, dates of birth, phone numbers, physical addresses, email addresses, medical ID numbers, cannabis used, price, quantity, and receipts.

“Medical patients have a legal right to keep their medical information private. Those whose personal information was leaked may face negative consequences both personally and professionally,” the researchers said.

In a similar incident, Natural Health Services, the operator of Canada’s largest referral network of medical cannabis patients, suffered a data breach that exposed customers’ personal information like medical diagnoses, referrals, encounter notes, and allergies.

The Calgary-based health center stated that unknown intruders accessed personal health records between December 4, 2018, and January 7, 2019. However, the company clarified that patient prescriptions, financial, credit card or social insurance numbers weren’t compromised in the incident. The company notified the affected clients and suggested them to monitor for any unusual activity in their transactions with financial institutions.

“NHS identified that a number of records containing personal health information in the electronic medical record (EMR) system we use were accessed without the authorization of NHS physicians for purposes that may be unrelated to providing medical care,” the company said in a statement. “NHS is working with law enforcement and the Information and Privacy Commissioner of Alberta to investigate this matter. NHS is undertaking all necessary steps to work with the respective provincial privacy commissioners to ensure that this does not happen again.”

Outdated Cyber Law Puts U.K.’s Cybersecurity in Jeopardy , Says CLRNN Report

cyberattacks on U.K. organizations

A joint research by Criminal Law Reform Now Network (CLRNN), scholars from Birmingham and Cambridge universities stated that the U.K.’s Computer Misuse Act 1990 (CMA) is 30 years old and needs an update, as it has jeopardized the country’s cybersecurity.

The research report, Reforming the Computer Misuse Act”, revealed how CMA is preventing security professionals from performing threat intelligence researches. It also stated that the Act restricts journalists and scholars from researching on potential cyberthreats.

The report also suggested a few recommendations which include:

  • A range of measures to better tailor existing offenses in line with the U.K.’s international obligations and other modern legal systems, including new corporate offenses.
  • New public interest defenses to untie the hands of cyberthreat intelligence professionals, academics and journalists to provide better protection against cyberattacks and misuse, while ensuring consistency with overlapping offenses within the Data Protection Act 2018.
  • A set of new targeted guidance for prosecutors, including the prosecution of young defendants.
  • The creation of new sentencing guidelines and provides detail on their formation and function.

Barrister Simon McKay, a member of CLRNN and project lead for the report, said, “The Computer Misuse Act is crying out for reform. It needs to be future- and technology-proofed to ensure it can meet the challenges of protecting the embedded internet-based culture we all live in and depend on. This report delivers a blueprint for the government to use and develop to make the law more effective in policing and prosecuting cybercrime.”