Home Blog Page 302

Major fines amid data breach concerns

data breach

We may be in 2019, but that doesn’t mean that the world’s biggest brands have prepared themselves for the massive threats to cybersecurity. One of the biggest data breaches last year was the attack on Marriott International. Since then, the company had to recover from the tainted reputation as well as the losses the issue incurred. Now, they are set to face fines for the damages the breach has caused.

The UK’s Information Commissioner’s Office has stated that it intends to fine US-based Marriott International up to £99,200,396 ($123 million) for violating the data breach regulations that are under the EU’s  General Data Protection Regulation (GDPR). To note, Marriott International’s data breach compromised the personal detail of over 339 million guests.

The data that got leaked included names, addresses, contact information, and passport numbers. However, Marriott International believes that around 100 million customers had their credit card numbers and expiration dates leaked as well. Of the 339 million guests, ICO states that 30 million were residents from 31 countries in the European Economic Area (EEA) and seven million were UK residents.

ICO’s Elizabeth Dunham says that “the GDPR makes it clear that organizations must be accountable for the personal data they hold. This can include carrying out proper due diligence when making a corporate acquisition, and putting in place proper accountability measures to assess not only what personal data has been acquired, but also how it is protected.”

She adds that personal data has real value, and that means organizations are obligated to protect the information that their customers trust them with.

Aside from Marriott International, ICO is also cracking down on British Airways, which is currently facing a fine of more than £183 million due to a customer data breach said to have begun way back in June 2018. The details of the breach were only revealed and discovered by the airline in September that year.

According to ICO’s own investigation, the information that got leaked included names, addresses, log-in details, bank card information, and travel booking details. ICO noted that the data breach was the result of “poor security arrangements.” The hackers organized the attack by diverting passengers to a fake website in which their information was gathered upon input.

While Marriott International’s data breach is easily the bigger issue, it’s British Airways that are going to receive the biggest fine ICO has placed for now. That is because most of the customer information leaked from British Airways was EU residents, whereas only a portion of the victims in Marriott International’s resided in the area.

It is no longer about an issue of which leak is bigger. Even though breaches are common, multinational brands, as well as the consumers themselves, have a lot to learn when it comes to security online. Here are some of the biggest takeaways from the recent issues.

Marriott International’s data breach was discovered only last year. However, reports suggest that the vulnerabilities began when the database of Starwood Hotels Group was compromised way back in 2014. Marriott International acquired the company in 2016, but it failed to see the security issues immediately.

With regards to British Airway’s data breach, we can assume that people are still not as vigilant as they should be when putting in their details online. However, we can’t place all the blame on the customers, as the cybercriminals themselves have become better and more advanced when it comes to hacking methods. Customers are advised to inspect every corner of a page before adding in the information.

The biggest takeaway is that everyone and every brand is susceptible to attacks online. The key to avoiding becoming the victim of a data breach is being more vigilant and careful online. For companies, it might be time for them to see more value in protecting their customer’s private information.

Infographic posted on Hosting Tribunal details “15 of the Biggest Data Breaches in The Last 15 Years.” The infographic also has startling facts around several major breaches.

Data breach affects Sprint’s customer accounts

Samsung Galaxy S7

The U.S.-based telecommunications firm Sprint recently revealed that hackers broke into customers’ accounts through a Samsung.com “add a line” website.

In a letter to its customers, Sprint said the attack occurred on June 22, 2019, and compromised customers’ sensitive information, including first and last name, billing address, phone number, subscriber ID, account number, device type, device ID, monthly charges, account creation date, upgrade eligibility, and any add-on services, the ZDNet reported.

“On June 22, Sprint was informed of unauthorized access to your Sprint account using your account credentials via the Samsung.com “add a line” website. We take this matter, and all matters involving Sprint customer’s privacy, very seriously,” Sprint stated in its letter.

“The personal information of yours that may have been viewed includes the following: phone number, device type, device ID, monthly recurring charges, subscriber ID, account number, account creation date, upgrade eligibility, first and last name, billing address and add-on services. No other information that could create a substantial risk of fraud or identity theft was acquired. Sprint has taken appropriate action to secure your account from unauthorized access and has not identified any fraudulent activity associated with your account at this time,” the letter added.

Sprint urged its customers to follow preventive measures recommended by the Federal Trade Commission (FTC) as a precautionary measure.

Earlier, a suspicious third-party app called ‘Updates for Samsung’ had more than 10 million download attempts to trick Android-based Samsung phone users into paying for their firmware updates. According to a report from CSIS Security Group, the original Updates for Samsung app was meant to provide operating updates for free. But the hackers used the fake application to infect the users’ devices with malicious codes after downloading the fake application.

Detailing how the app worked Aleksejs Kuprins, a security researcher at CSIS Security Group, said “The app is called Updates for Samsung and pledges to deliver any OS update for any Samsung device ever released. It also offers to unlock phones regardless of the network operator and provides Android-related content from the developer’s website, updato[.]com.”

“I’m not a Fan of Cryptocurrencies,” says Donald Trump

Donald Trump

The U.S. President Donald Trump recently voiced his opinion on cryptocurrencies, mentioning Bitcoin and Libra specifically. Trump posted his comments in a series of tweets on July 11.

“I am not a fan of Bitcoin and other Cryptocurrencies, which are not money, and whose value is highly volatile and based on thin air. Unregulated Crypto Assets can facilitate unlawful behavior, including drug trade and other illegal activity,” Trump tweeted. “Similarly, Facebook Libra’s ‘virtual currency’ will have little standing or dependability. If Facebook and other companies want to become a bank, they must seek a new Banking Charter and become subject to all Banking Regulations, just like other Banks, both National and International.”

“We have only one real currency in the USA, and it is stronger than ever, both dependable and reliable. It is by far the most dominant currency anywhere in the World, and it will always stay that way. It is called the United States Dollar!,” the President added.

The tweets, which received a severe backlash online, posted after Trump’s Social Media Summit with several right-wing social media personalities. The president’s comments on cryptocurrencies came as a shock to many crypto leaders, who have criticized Trump for the same.

Recently, the President declared a national emergency over threats against American technology. He has signed an executive order which effectively bars U.S.-based companies from using foreign telecoms, which are believed to pose national security risks. The proposed order is intended to protect the United States communications and computer networks from “foreign adversaries”.

The executive order does not name any company, but it’s believed that the move is expected to precede a ban on U.S. firms doing business with the Chinese telecommunications company, Huawei. According to the White House statement, Trump’s order aims to “protect America from foreign adversaries who are actively and increasingly creating and exploiting vulnerabilities in information and communications technology infrastructure and services”.

FaceApp Challenge: Fun of ageing. But at what cost?

FaceApp

Drake did it, the Jonas Brothers did it, it has also broken the internet. Millions are uploading photos of their future aged versions using the FaceApp. Thanks to the aging challenge that’s doing rounds on Instagram, Facebook and several other social media platforms, literally everyone wants a piece of the cake. It is possibly the biggest internet challenge since bottle cap. The spike in traffic has also triggered several memes over celebrities like Paul Rudd, Keanu Reeves, John Stamos and Anil Kapoor who never age. But unlike the bottle cap challenge, the FaceApp challenge apparently has its own amount of risks and several cybersecurity experts across the world are flagging it red.

It all began after several experts and users finally read the terms and conditions of the app. Over user content, It reads, “You grant FaceApp a perpetual, irrevocable, nonexclusive, royalty-free, worldwide, fully-paid, transferable sub-license to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, publicly perform and display your User Content, and any name, username, or likeness provided in connection with your User Content in all media formats and channels now known or later developed, without compensation to you.”

The app is over two years old and was created by a Russian developer. Now anything related to Russia is perceived to be nefarious and that what several experts are pointing out. “I would be cautious about uploading sensitive data to this company that does not take privacy very seriously, but also reserves broad rights to do whatever they want with your pictures,” said Justin Brookman, a former policy director for the Federal Trade Commission’s Office of Technology Research and Investigation to CNBC.

“They could turn them into stock photos or advertisements in Russia,” he said. “But I don’t know how much the Russianness is concerning, although Russia has been known to use personal information in the past.”

FaceApp has shrugged off all the allegations stating that “99 percent of users don’t log in; therefore, we don’t have access to any data that could identify a person,” and they “don’t sell or share any user data with any third parties.”

Even Forbes suggested that the storm in the internet teacup over privacy and security of the might be a bit far-fetched and it is highly unlikely that the developers are involved in a “nefarious project”. There is one takeaway from all this, it is better you don’t give a random app so much of consent over your photos.

 

 

Foodpanda’s Instagram account hacked!

Foodpanda

Another security incident is reported on Facebook-owned photo-sharing application Instagram. Food delivery service provider Foodpanda recently revealed that its Instagram account was breached. The issue came into light after a customer Jenny Liang reported that she received vulgar messages from the company’s Instagram account. The messages were sent to Liang after she criticized Foodpanda’s delivery service, the Straitstimes reported.

“Over the weekend, foodpanda Singapore’s Instagram account was hacked. We apologize for any inappropriate messages you might have received during this time and we are working hard to resolve this issue. In the meantime, please do not respond to any activity from this account and we’ll update you as soon as the issue is resolved,” the Foodpanda team said in a Facebook post.

Earlier, an unprotected server containing personal information of millions of Instagram influencers, celebrities, and brand accounts have been found online. According to the security researcher Anurag Sen, who discovered the leak and notified TechCrunch, the database had over 49 million records exposed online, allowing anyone to access. The exposed data included users’ biodata, profile picture, the number of followers they have, their location by city and country, and contact information like the Instagram account owner’s email address and phone number.

Anurag stated the leaky database belongs to a social media marketing firm Chtrbox, which is based in Indian state Mumbai. The database was taken offline and called for an investigation on the incident, Chtrbox stated. Commenting on the security breach Facebook said, “We’re looking into the issue to understand if the data described – including email and phone numbers – was from Instagram or other sources. We’re also inquiring with Chtrbox to understand where this data came from and how it became publicly available.”

Suspected hacker behind Bulgaria cyber-attack arrested

Bulgaria

The Bulgarian police have arrested the suspected hacker who allegedly stole the personal details of around 5 million Bulgarians and emailed download links of the stolen data to local media agencies. The police arrested the suspect on July 17,2019, and has launched an investigation to know the damage occurred due to the incident. “We have a suspect that has been detained,” the Bulgarian police said in a statement.*

It’s believed that the compromised data belonged to the country’s National Revenue Agency (NRA), a department of the Bulgarian Ministry of Finance. Boyko Borissov, the Bulgarian prime minister, called an emergency meeting after the cyber-attack, the Capital.bg reported.

Vladislav Goranov, the Finance Minister of Bulgaria, said the stolen data included names, personal data, personal identification numbers, addresses, and financial earnings of individuals and companies. Goranov stated their government has requested help from the European Union’s cybersecurity agency.

The hacker compromised around 10 databases from the NRA’s network, which totals to nearly 21 GB and shared 57 databases, comprising 11 GB of the aggregate data with local news outlets. The hacker, claimed as a Russian man, emailed local media using Yandex.ru email address.

The hacker also called for the release of WikiLeaks founder Julian Assange and mocked the Bulgarian government saying “Your government is stupid. Your cybersecurity is a parody.

“The NRA and the specialized bodies of the Ministry of the Interior and the State Agency for National Security (SANS) check the potential vulnerability of the computer system of the National Revenue Agency. Earlier today, emails of certain media have been sent a link to download files allegedly belonging to the Ministry of Finance of Bulgaria. We are currently verifying whether the data is real. Further information will be provided later,” the NRA said in a statement.

*This story has been updated with the news of suspected hacker’s arrest. 

Icertis secures $115 million to accelerate its AI and Blockchain platform

Aviatrix Funding

Icertis, a provider of enterprise contract management in the cloud, recently secured $115 million in a Series E round led by US-based venture capital firm Greycroft and Premji Invest. The other investors participated in the round included B Capital Group, Cross Creek, Eight Roads, Ignition Partners, Meritech Capital Partners, and PSP Growth.

Icertis offers enterprises Contract Lifecycle Management services in the cloud. The company claims that its Icertis Contract Management (ICM) platform is an innovative and easy-to-use platform, enabling companies to enhance their compliance, improve governance, mitigate risk, and increase user productivity.

With the latest funding, Icertis has become the India’s third software-as-a-service (SaaS) company to be valued at more than $1 billion. Headquartered in India and the U.S., Icertis stated the new proceeds will be used to strengthen its product, invest in new technologies such as blockchain, artificial intelligence, and machine learning. The company also wanted to expand its business reach globally.

“Companies must re-imagine every business process to compete in today’s hyper-competitive global markets,” said Samir Bodas, CEO and Co-founder of Icertis. “Nothing is more foundational than contract management as every dollar in and every dollar out of a company is governed by a contract. As the CLM market takes off, we are thrilled to have Premji Invest join the Icertis family, Greycroft double down by co-leading this round, and all investors re-up their commitment as we execute on our mission to become the contract management platform of the world.”

“As we run a long-term evergreen crossover fund, we look for companies with enduring growth prospects that can execute and thrive well beyond an initial public offering,” said Sandesh Patnam, Lead Partner for Premji Invest in the US. “Icertis has all the hallmarks of a company that will grow into a juggernaut – an innovative product that delivers substantial value for customers, deep cash reserves to develop the market and a track record of flawless execution.”

UK’s cyber watchdog prevents Airport Email Scam

UK airport

The National Cyber Security Centre (NCSC) of the United Kingdom revealed that it prevented a major Phishing Scam that tried to defraud thousands of people using a fake email from one of the UK airports.

NCSC has not revealed the name of the airport. However, stated that the failed email scam involved sending 200,000 emails to the public asking them to pay a fee in order to receive a refund.

In its report dubbed Active Cyber Defence (ACD), the NCSC stated the attackers used a fake gov.uk address to trick the users. But the messages were prevented from reaching their targets. The ACD program, which is intended to improve the security of the UK public sector and the cyber ecosystem, had stopped 140,000 separate phishing attacks and taken down 190,000 fraudulent sites, according to the report.

The U.K. Information Commissioner’s Office (ICO) recently fined British Airways with £183.39 million ($230 million) after the airline failed to protect its customers’ data. The proposed fine relates to a data breach notified to the ICO by British Airways in September 2018, that exposed around 500,000 customers’ personal information.

The ICO said its investigation found that the breach compromised customer details, including login, payment card, name, address, and travel booking information which is collected after being diverted to a fraudulent website. The data breach, which began in June 2018, occurred due to the poor security measures to protect customer information, ICO stated.

British Airways made an announcement regarding the breach on September 6, 2018. It notified its customers that “From 22:58 BST August 21, 2018, until 21:45 BST September 5, 2018, inclusive, the personal and financial details of customers making or changing bookings on our website and app were compromised.” Around 380,000 payment-card details were stolen during the period. The airline has notified the police and investigations are underway. The airlines also assured that it will compensate for all the losses to its customers.

Australian government launches new cybersecurity node

New South Wales data breach disclosure bill

In a bid to drive cybersecurity innovation and harness cybersecurity talent in the region, the New South Wales government and AustCyber have jointly launched the NSW Cyber Security Innovation Node at the harbor city’s Joint Cyber Security Centre. Announced in 2018, the new information security hub will form a part of a series of nodes backed across Victoria, the ACT, Western Australia, South Australia and Tasmania, and will be coordinated by the NSW Cyber Security Network, which is backed by the NSW Government and universities and aligned with AustCyber’s national agenda of sector growth.

“This new node in Sydney, backed by AustCyber and the New South Wales (NSW) state government, will bring together startups, corporations, universities, researchers and government agencies to share expertise and create new ideas,” said Karen Andrews, the federal minister for industry, science and technology.

“The government is determined to reap the rewards of the rapidly growing global cybersecurity market which is expected to be worth 250 billion U.S. dollars by 2026,” Andrews said, “We want to generate more investment and more jobs for Australians.”

The government of Australia has launched several Joint Cyber Security Centers (JCSC) in the region to promote cybersecurity  across government, business, and academia. The facilities are a part of the government’s $47 million JCSC program that bridges the gap between several public and private companies in sectors such as defense, finance, transport, energy, health, mining, and education. The recent one launched in Adelaide, South Australia, and another facility in Perth.

The Centers provide a unique offering to the South Australian community with AustCyber (the Australian Cyber Security Growth Network), locating a Cyber Security Innovation Node within the JCSC. The facilities strengthen the cybersecurity infrastructure of the country and will also be involved in sharing sensitive information, including actionable cyber threat intelligence among myriad bodies in both public and private spaces.

Ransomware hits Syracuse schools and Onondaga County library

Ransomware, supply chain and ransomware

A recent ransomware attack on Syracuse City School District and Onondaga County Public Library has ceased their network systems and disabled the access to the catalogues and online accounts. The school authorities launched an investigation to determine the source and damage of the incident.

According to the official statement, the hackers infected the school’s network system with Ryuk Ransomware and demanded a ransom to set free. It’s believed that the attacker is linked to a criminal group known as Grim Spider based in Eastern Europe.

“On Monday, July 9th, the district experienced a cyber-event in which our computer files and systems were inoperable.  We have been working with cybersecurity and law enforcement professionals to restore our systems.  We have restored some of our back-end systems (human relations, payroll, student management) and are still working on more public facing systems like the email system,” Syracuse City School District said in a statement.

“At this time, we have no indication that any data was compromised but rather the attack froze the district from accessing our own systems.  Our phone service is working, and offices are open and summer school is in session,” the statement added.

Earlier, San Diego Unified School District reported a data breach that affected more than 500,000 students and staff members. According to the official statement, a phishing scam led to unauthorized access to the staff’s log-in information, including the network services and students’ database.

The security officials at the school district stated they discovered the breach in October 2018. It’s believed that the incident occurred between January 2018 and November 2018. The school district declared the compromised students’ information included social security numbers, names, date of birth, mailing address, home address, attendance records, ID numbers, and phone numbers. Some staff members’ information like payroll, deduction information, tax information, direct deposit financial institution name, account number, salary, and leave information was also compromised.