Home Blog Page 260

Wawa Faces Class-Action Lawsuit After Reporting Data Breach

Surveillance Legislation (Identify and Disrupt) Amendment Bill

A class-action lawsuit has been filed against Wawa Stores in the wake of a massive financial data breach that was revealed by the company. The lawsuit, which was filed in the U.S. District Court for the Eastern District of Pennsylvania, brought several people who claim they were impacted by the breach.

Wawa operates around 850 convenience stores, which are located across the East Coast, from Pennsylvania to Florida.

The lawsuit claimed that Wawa failed to secure its computer systems from hackers who installed malware that potentially affected Wawa’s payment systems. It also accused Wawa for breach of contract and violating consumer protection laws.

According to Chris Gheysens, Wawa’s CEO, the company discovered the malware payload in its payment processing systems on December 10, 2019. The security team at Wawa blocked the malware on December 12, 2019, and it is believed that the malware no longer poses any risk to customers making payments at Wawa stores.

Gheysens said that the malware affected customers who made payments at Wawa stores and gas stations. However, the company clarified that the store’s ATMs were unaffected.

The number of affected customers is still unknown. It’s said that the incident potentially affected 850 stores since March 4, 2019.

The exposed financial information includes debit and credit card numbers, expiration dates, and cardholder names. However, PINs and CVV numbers were not exposed. The company also clarified that there is no evidence of any unauthorized use of exposed payment information.

Gheysens stated that they’ve informed law enforcement and payment card companies and appointed an external forensics firm for further investigation. The company also notified the affected users and offered free credit monitoring services.

“I want to reassure you that you will not be responsible for any fraudulent charges on your payment cards related to this incident,” Gheysens said.

Ryuk Ransomware Took Down U.S. Coast Guard Operations

ransomware, fonix, fonix ransomware, Cybereason Partners with Intel for Hardware-Enabled Ransomware Prevention, Kronos

The officials of the U.S. Coast Guard (USCG) recently disclosed a Ryuk ransomware infection that took down the entire corporate IT network of a Maritime Transportation Security Act (MTSA) regulated facility for more than 30 hours. The authorities stated the ransomware interrupted the camera and physical access control systems.

It’s believed that a malicious email sent to one of the maritime facility’s employees was the entry point for the ransomware infection, according to USCG officials.

“Forensic analysis is currently ongoing but the virus, identified as Ryuk ransomware, may have entered the network of the MTSA facility via an email phishing campaign,” USCG said in a statement.

Once an employee clicks the embedded malicious link in the email, the ransomware corrupts the enterprise IT network files, encrypts them, and prevents the facility’s access to critical files. The officials stated that the incident impacted the facility’s IT network, industrial control systems that monitor, and control systems of cargo transfer operations.

“The virus further burrowed into the industrial control systems that monitor and control cargo transfer and encrypted files critical to process operations. The impact to the facility included disruption of the entire corporate IT network (beyond the footprint of the facility), disruption of camera and physical access control systems, and loss of critical process control monitoring systems. These combined effects required the company to shut down the primary operations of the facility for over 30 hours while a cyber-incident response was conducted,” the statement added.

Numerous companies and state governments have been plagued by ransomware attacks. Recently, Virtual Care Provider, a technology services provider for nursing homes and acute care sites, was hit with a Ryuk ransomware attack that seized access to patients’ health records. The Milwaukee-based company reported that unknown attackers injected ransomware inside its network systems.

The company stated that hackers demanded US$14 million to restore access to its hijacked servers. Virtual Care Provider said around 110 nursing homes across the country were unable to access their patient records, to use the Internet, pay employees, and order crucial medications.

According to the Chief Executive and owner of Virtual Care, Karen Christianson, the incident affected 80,000 computers and other facilities, including Internet service and email, access to patient records, client billing, phone systems, and payroll operations.

Amazon’s Ring Slammed with Federal Lawsuit

Ring, a home security product provider owned by e-commerce platform Amazon, has been hit by a class-action lawsuit in the U.S. for reports of multiple hacking incidents on its Amazon Ring security cameras that left victims traumatized.

Ring manufactures security products for smart homes that incorporate outdoor motion-detecting cameras like the Ring Video Doorbell.

According to the lawsuit, Amazon and Ring are being sued for negligence, breach of an implied contract, invasion of privacy, breach of an implied warranty, and unfair enrichment. The lawsuit also claimed that the companies were already aware of the deficiency of their products’ security.

“Ring does not fulfill its core promise of providing privacy and security for its customers. Hackers routinely terrorize occupants, invade their privacy and undermine their sense of safety and security,” said a statement from the lawsuit.

The Amazon Ring camera lawsuit was filed by a U.S. resident, Plaintiff John Baker Orange, in the U.S. District Court for the Central District of California. In his lawsuit, John claimed that his security camera was hacked while his children were playing. He also alleged that Amazon and Ring neglected to provide two-factor authentication and other security protocols to users.

The lawsuit also revealed hacking incidents that have occurred in the U.S.

The Internet of Things has become a primary target for cybercriminals, exploiting vulnerabilities in them. Last month, security researchers disclosed a flaw in Amazon’s Ring Video Doorbell that could have given hackers unauthorized access to the user’s wi-fi network and potentially to other connected devices on it.

The vulnerability was discovered by researchers at cybersecurity firm Bitdefender. Ring Doorbells are internet-connected doorbells that provide motion-sensing and video surveillance capabilities. It allows the users to see and communicate with the people outside their doors via an app, even if they’re outside.

According to researchers, the vulnerability stems when the Ring smartphone app sends the wireless network connections to the Amazon Ring servers in the cloud. It’s found that this process is taking place in an insecure manner, which can be exploited by an attacker.

Maastricht University Ransomware Attack: All Systems Blacked-Out

Maastricht University

Maastricht University in the Netherlands is trying to recover from a hard fall it took from a massive ransomware attack that hit them just two days before Christmas. The University later announced that the attack took down “almost all Windows systems” at the university and particularly affected the University’s email services.

Maastricht University is placed amongst the top 500 universities in the world for the past two years. Thus, an attack so severe is not only devastating for its students and employees but also dents its reputation. The University said, “The Executive Board and the deans of the faculties deeply regret the inconvenience this is causing for both students and staff. In the days to come, they want to see in what way students and staff who are experiencing problems due to this situation can be accommodated.”

The University has rightfully reported this incident to the police. The type of ransomware attack has not been disclosed yet, but as part of the incidence response, help has been immediately taken from cybersecurity specialists. “IT staff at UM (Maastricht University), along with external specialists in this field, have been working all-out since the discovery of the attack. The current phase involves forensic investigation and repairs.”

In order to contain the damages and complete the ransomware attack analysis, the University itself has taken down all its systems. “Everything is aimed at giving students and employees access to the systems as soon as possible in phases. Given the size and extent of the attack, it is not yet possible to indicate when that can be done exactly.”

In a similar incidence in the other sphere, the Australian National University discovered a major data breach that affected students’ and University’s sensitive information. According to the University’s Vice-Chancellor Brian Schmidt, unknown cybercriminals attacked the University’s systems and accessed personal information late in 2018, which was discovered by the University authorities only on May 17, 2019. The exposed information included names, addresses, dates of birth, phone numbers, personal email addresses and emergency contact details, tax file numbers, payroll information, bank account details, passport details, and student academic records, according to the University’s Vice-Chancellor Brian Schmidt.

However, Schmidt also clarified that data like credit card details, travel information, medical records, police checks, workers’ compensation, vehicle registration numbers, and some performance records were not affected by the incident.

Click here for the latest update on this story as on February 5, 2020.

6 Practices to Strengthen Your Password Hygiene in 2020

User Verification Policy, zero trust approach

By Rudra Srinivas

The National Cyber Security Centre (NCSC) of the United Kingdom recently issued a warning to its citizens to have stronger and unique passwords after releasing a file that contained the top 100,000 commonly hacked passwords from the “Have I Been Pwned” data set. With unprotected databases and online services getting breached often, leaked/stolen passwords from data breaches can pose a severe threat if users continue reusing their weak passwords.

Practicing good password hygiene is one of the most essential security measures to deter online intruders. Most people choose passwords based on how easy-to-remember they are, rather than as security. With the rising concerns over data breaches, the organizations must encourage employees to practice necessary password protection measures to avoid any cybersecurity mishap.

We list the six imperative password security measures that strengthen data security:

1. Using Two-Factor Authentication

Two-factor authentication (2FA) acts as an extra layer of security that requires an additional step before the user logs into the account. In 2FA, the user receives an OTP (one-time password) via text message or email, which is required for verification, to ensure that only the right people have access.

However, most websites let users mark their devices as trusted while validating for the first time. This over-rides 2FA for trusted devices, and users can access their accounts with only passwords from thereon. This might seem convenient while using, but it’s not good in terms of security. If you’re over-riding 2FA for a trusted device, you’re making your accounts open to hackers.

2. Use Passphrases Instead of Passwords

According to NCSC, the most commonly hacked passwords globally were “12345,” “123456,” “123456789,” “abc123,” “qwerty,” “1111111,” and even the term “password.” Cybercriminals are using advanced hacking tools to crack even the most complex passwords. Be creative and use hard-to-guess passwords, so that attackers can’t guess your password.

Using a passphrase over a password will give you maximum security for your account. But make sure the passphrase you choose is easy-to-remember and complex as well. Pick a line from your favorite song or quotation, but preferably not a common one that can be simply guessed by someone who knows you.

For instance, a passphrase such as “I Love My Job 100%” is easy-to-remember, meets the complexity requirements (numbers, letter case and special characters), and is hard to crack because most of the password cracking tools break down at 10 characters.

3. Observe Proper Web Security

With hackers using advanced tools to steal the data, it’s imperative to follow the right web security measures.  The most common method that hackers use for identity theft is sending phishing emails or malicious links. Build a defense system by installing a proper antivirus and anti-malware software on all your devices. Also, make sure that you update these software applications regularly for complete protection.

4. Avoid Reusing Passwords

A recent study by the Microsoft threat research team revealed that 44 million users were reusing their usernames and passwords. The survey also exposed that the largest percentage of passwords were weak and used for a long period.

Using a common password for various accounts might seem convenient, but it could be a potential threat for other accounts if an attacker broke into one account. Even if you have a strong password, try to use different passwords for every account you use. Also, make sure that you change your passwords regularly.

Don’t choose your personal information (your name, the names of your spouse or children, your pets) as a password, as these are known to the people who know you. Try to use a different combination of phrases for every account you use.

If you find it difficult to remember multiple passwords, then use a  password manager application.

5. Protect Your Password List

With multiple accounts and passwords, people tend to keep them in one place making a list. But ensure you save the password list securely that it can’t be authorized by others. It’s better to hide any physical records that contain passwords. In case you need to give your credentials to a colleague to get an important file, make sure that you change the password as soon as possible.

6. Don’t Mix the Business Email Account with Personal

 According to Microsoft, 30 percent of reused or modified passwords can be cracked within just 10 guesses. This puts users at risk of a breach replay attack. If attackers get hold of leaked credentials, they can try to execute a breach replay attack by trying the same credentials on different service accounts.

Using a single email account for business and personal correspondence is not recommended. Doing so might lead to massive data loss when someone cracks your password. Multiple email accounts allow you to consolidate all your work emails into a single work account, friends, and family communication in a personal account, and a recreational account for various website registrations.

Rudra Srinivas is part of the editorial team at CISO MAG and writes on cybersecurity trends and news features. 

Wyze Data Breach May Have Exposed 2.4 M Users’ Information

Panasonic network breach

Internet of Things Vendor Wyze confirmed that it suffered a data breach earlier this month that may have exposed details of 2.4 million users for 22 days. The U.S.-based startup sells IoT devices like security cameras, smart lightbulbs, smart door locks, smart plugs, and other smart home devices.

According to Dongsheng Song, co-founder of Wyze, the breach occurred after an internal database was accidentally exposed online. The exposed database was an Elasticsearch server that stored users’ personal information.

The issue came to light after researchers from cybersecurity firms Twelve Security and IPVM discovered and reported the incident to Wyze.

“We have been auditing all our servers and databases since then and have discovered an additional database that was left unprotected. This was not a production database and we can confirm that passwords and personal financial data were not included in this database. We are still working through what additional information was leaked as well as the circumstances that caused that leak,” Dongsheng Song said in a statement.

Weeks-Long Data Breach

It’s believed that the leaky database exposed information from December 4 to December 26, when an employee failed to maintain security protocols during the data transfer process. The exposed information included email addresses, body metrics, nicknames users assigned to their Wyze security cameras, Wi-Fi network SSID identifiers, and Wi-Fi network IDs. However, Wyze clarified that no passwords or financial information were exposed in the incident.

Wyze stated it’s notifying the affected users about the security incident. “We are working on an email notification to all affected customers and plan to release it soon. To balance thoroughness and speed, we will be sending the information that we have on hand and will provide further updates as we continue forward with our investigation,” Song said.

Keeping users’ personal information secure continues to be a risky task for database administrators. This is not the first Elasticsearch servers leak. Multiple security incidents were reported on Elasticsearch servers earlier. Recently, security researchers Bob Diachenko and Vinny Troia disclosed an open Elasticsearch server that contained unique data records of around 1.2 billion users. The leaky server stored more than 4 terabytes of data, without password protection or authentication.

The exposed data included names, email addresses, phone numbers, LinkedIn and Facebook profile information. It’s believed that the exposed data appeared to have originated from two different data enrichment companies namely People Data Labs (PDL) and OxyData.Io (OXY).

Equating cryptocurrency to illegal conduct is lack of understanding

Coleman Watson is the Managing Partner of Watson LLP, and his background has a unique blend of engineering, business, and finance interposed with the practice of law. He is a registered patent attorney with the United States Patent & Trademark Office, and he counsels and advises clients on intellectual property and technology issues. Coleman also has broad experience in patent litigation, trademark litigation, videogame law, blockchain and cryptocurrencies, government investigations, qui tam claims, and “bet the company” litigation.

Where do you see the cryptocurrency industry in the next five years?

Cryptocurrency will start to become more disruptive to the global financial system, much like decades of credit card use after they were first injected into the financial system back in the 1950s. Cryptocurrency represents the perfect storm for today’s consumer who generally wants more autonomy with sending, receiving and using their own money with a moment’s notice and for little to no fees. Unfortunately, close to the outset, cryptocurrency (specifically Bitcoin) was cast in a negative light from infamy such as Silk Road. So that was a setback to the consumer perception of its value.

Even today, it is not uncommon for the average consumer to make some tall claim like “Bitcoin is only used for the dark Internet.” But equating cryptocurrency to per se illegal conduct is a lack of understanding: to say that is really no different than saying “all cars are bad because drug dealers drive them.” A positive public perception of cryptocurrency will be the tipping point and that will happen when a trusted major public platform (e.g., Amazon, eBay, etc.) begins to accept cryptocurrency as a form of payment.

In the United States, there is no consistent legal approach to cryptocurrencies. Bitcoin is classified as a commodity by CFTC, while the IRS treats it as property. What can be done to overcome this problem?

The problem is that there is no federal legislation on cryptocurrencies. This is unsurprising in light of the recent congressional hearings where sitting members of Congress had difficultly grasping issues as simple as how Facebook makes money or whether Facebook is on the Internet. That leaves us with legislators who are uneducated and unprepared to deal with an important incremental change in the financial services industry. But people need clarity.

The system we have now where various states classify cryptocurrencies as different types of instruments, juxtaposed against the Securities and Exchange Commission, Commodity Futures Trading Commission, Financial Crimes Enforcement Network and Internal Revenue Service’s classifications (which all differ) is not a sustainable system. To be effective, the law must be clear. However, it is promising that Congress seems to be finally close to weighing in on the issue, as U.S. Reps. Warren Davidson and Darren Soto recently introduced the Token Taxonomy Act to provide some clarity to cryptocurrency classifications.

A lot of tokens traded on exchanges have circumvented SEC regulations by declaring themselves utility tokens. How can this problem be solved?

First off, the SEC determines what is and what is not a “security” by reference to a court case from 1946 (SEC v WJ Howey Co.). At issue in that case was whether contracts directed to orange groves were securities. Put simply, Howey finds a security if a person invests money in a common enterprise and is led to expect profits solely from the efforts of a third party. Cryptocurrency launched about 60 years after Howey, so we are living in a system where the SEC is applying a broad definition to technology that was not contemplated at the time the Supreme Court handed down the decision.

The problem must be solved with legislation that addresses the world we live in today, not the world of yesterday. The Token Taxonomy Act is a great start because it would amend the Securities Act of 1933 and the Exchange Act of 1934 by adding a definition for “digital tokens.” Under certain scenarios they would be exempt from the securities laws.

Read more

Pensacola Ransomware: Hackers Release 2GB Data as a Proof

Ransomware Attacks, Graff ransomware attack

Hackers who carried out Maze Ransomware attack in the Pensacola city of Florida have released two gigabytes of data files stolen before encrypting the data on the internet. This was done to prove that they possessed credible data which could be put up for sale on the dark web. They held the media responsible for this as they called them names and instigated to take such drastic steps.

When it happened?

On Saturday December 7, the Pensacola city of Florida was hit by a cyber-attack that forced the city to suspend majority of its networks. At the time, severity and critical nature of the attack was not known and the City’s IT employees worked tirelessly to restore services. It was later confirmed that the outage was caused by a ransomware attack. Florida Department of Law Enforcement sent an official letter to the County Commissioner stating that it was a Maze Ransomware attack and the hackers demanded a ransom of US$1 million in order to restore all the services.

What was affected?

All email and telephone services along with 311 customer service was affected by the ransomware attack. Hackers emphasized and told Bleeping computers that, “no one of the socially significant services has suffered (for example 911).” They further added, “We don’t attack hospitals, cancer centers, maternity hospitals and other socially vital objects, up to the point that if someone uses our software to block the latter, we will provide a decrypt for free.”

Why did they release 2GB of stolen data?

On December 23, while the City was still recovering from the ransomware attack, hackers released 2GB of data files from the total 32GB of data that they claimed was stolen prior to encrypting the City’s network with the maze ransomware. In the statement given to the Bleeping Computer, the hackers said, “This is the fault of mass media who writes that we don’t exfiltrate data (worth) more than a few files. We did not want to make a pressure on the city, we still don’t make it right now. We’ve shown that our intentions are real.”

In a similar incident earlier this month, New Orleans, a city in Louisiana became a victim of a ransomware attack. The city declared a state of emergency and shut down its computer and network systems on detecting suspicious ransomware and a pool of phishing emails. The incident affected multiple services in New Orleans like Municipal courthouses and the city’s Healthcare for the Homeless, according to Mayor LaToya Cantrell. It’s said that most employees at government agencies were using their Gmail accounts to handle requests, as the city’s email server was taken offline.

Colin Cowie, researcher and founder of cybersecurity research firm Red Flare Security, stated that Ryuk Ransomware might be behind the New Orleans attack. Cowie stated that he observed similarities of Ryuk ransomware on the affected computer systems.

Mastercard Ups its Cybersecurity Game, Acquires RiskRecon

Federal Bank Blocks Debit Card Fraud

In a quest to strengthen its cybersecurity front, Mastercard announced its agreement to acquire RiskRecon, an artificial intelligence and data analytics solutions provider that helps enhance the cybersecurity needs of its customers. The acquisition has been finalized for an undisclosed amount and is subject to standard approvals. The deal closure is expected to be completed by early 2020.

RiskRecon, the cybersecurity startup founded in 2015 by Kelly White (CEO and Co-Founder) and Eric Blatte (President and Co-Founder) recently raised US$3 million in seed funding. Later, in Series A and Series B rounds, RiskRecon saw a cash flow coming in from several heavyweight investors like Dell Technologies Capital, Accel, General Catalyst and F-Prime Capital. According to Crunchbase, RiskRecon has managed to draw a total of US$40 million since its inception.

RiskRecon uses information of a certain company freely available on the web to understand the security risks to its network and system architecture. White had earlier said, “If you stand up web servers and DNS servers, these are intentionally discoverable because they are providing services on the internet. Systems reveal the software being run and version information from which you can determine (their) security performance.” RiskRecon’s scanning and evaluation technologies can actively help in mitigating cyber risks, safeguard intellectual property and critical customer and payment data.

“Mastercard has been one of those brands that has stood out as a true innovator, focusing on the real problems of real businesses,” said White. “By becoming part of their team, we have an opportunity to scale our solution and help companies in new industries and geographies take steps to better manage their cybersecurity risk.”

Ajay Bhalla, President of Cyber and Intelligence for Mastercard sounded equally ecstatic and said “The innovations from the talented team at RiskRecon will further accelerate our suite of cyber solutions designed to help financial institutions, merchants and governments secure their digital assets. Through a powerful combination of AI and data-driven advanced technology, RiskRecon offers an exciting opportunity to complement our existing strategy and technology to secure the cyber space.”

Earlier, in a bid to provide users an easy and more secure online payment experience Mastercard along with a consortium consisting of major credit card companies like American Express, Visa and Discovery introduced a one-click checkout feature.

The new one-click checkout is not only a faster and secure mode of credit card payment but also satisfied the new EMV (Europay, MasterCard and Visa) Secure Remote Commerce (SRC) standard–a global benchmark for card payments made across merchant websites, mobile applications, and other connected devices. It simplifies the digital payment experience by allowing users to make payments without logging into the associated account. SRC technology has been successfully tested by networks in the market environment on merchant websites and shall soon be available on majority of the websites by early 2020 in the United States.

No “Happy Holidays”, with Love – RavnAir

Bangkok Airways

For people of Alaska, flight cancellations are common during winter due to heavy blizzards. But in the latest one with RavnAir, a cyberattack threw travelers’ schedule off the runway. RavnAir cancelled at least a half-dozen flights in Alaska following what the company described as “a malicious cyberattack” on its computer network. The cancellations affected around 260 passengers, according to company spokeswoman Debbie Reinwand. The cancelled flights included only the Dash 8 aircrafts “because the cyberattack forced us to disconnect our Dash 8 maintenance system and its back-up,” said the company’s written statement.

As per the official statement, the cause and nature of the cyberattack is unknown, but the company is working collectively with the FBI, other government authorities and cybersecurity experts to restore the affected systems at the earliest. However, since other backup servers remained unaffected, PenAir flights and RavnAir Connect flights remained operational, said Reinwand.

Earlier in 2018, a cyberattack at Bristol Airport caused technical issues which led to the malfunction of flight information screens. The airport authorities notified that the customers were unable to read any arrival or departure information as the flight information screens went blank. The authorities used manual processes to inform passengers about flights information.

“We believe there was an online attempt to target part of our administrative systems and that required us to take a number of applications offline as a precautionary measure, including the one that provides our data for flight information screens,” said Bristol Airport spokesman James Gore “The indications are that this was a speculative attempt rather than targeted attack on Bristol Airport.”

Keeping the growing cyberattacks and cyber threats to the Aviation industry in mind, ResearchAndMarkets.com released a report titled Aviation Cyber Security Market – Growth, Trends, and Forecast (2019 – 2024). According to the report, the aviation cyber security market is expected to register a CAGR of around 11 percent during the forecast period of 2019-2024.

The aviation sector has benefitted from the increasing level of connectivity and digitization across the value chain. The enabling technological advancements in the aviation sector are creating enormous opportunities to have better customer service, security, flight efficiency, operations and the passenger experience both on the ground and in the air.