Home Blog Page 311

Multiple Universities in United States suffer Data Breach

54% of Universities in the U.K. Suffered a Data Breach Last Year, Herff Jones payments card breach

Three Universities in the United States have recently disclosed data breach incidents that exposed personally identifiable information of students and working staff. The three universities, Graceland University, Oregon State University, and Missouri Southern State University, stated that unknown intruders made unauthorized access to some of their employees’ email accounts.

The exposed information included, students’ full name, social security number, date of birth, address, telephone number, email address, parents/children, salary information, and financial aid information for enrollment.

The students and employees whose personal information was potentially stolen or accessed in the incident have been notified. The security professionals at the universities clarified that no evidence has been found of the impacted personal information being stolen or used in a malicious manner.

Oregon State University announced that 636 student records and family details of students containing sensitive information were potentially affected by the incident.

“OSU is continuing to investigate this matter and determine whether the cyber attacker viewed or copied these documents with personal information,” said Steve Clark, the university’s vice president for university relations and marketing. “While we have no indication at this time that the personal information was seen or used, OSU has notified these students and family members of this incident. And we have offered information about support services that are available, including 12 months of credit monitoring services that the university will enable at no cost.”

The Graceland University stated that it became aware of the unauthorized activity in which the hackers gained access to the email accounts of current employees, including the contents and attachments connected to those accounts. The officials said that the intruders accessed the individual accounts on March 29, 2019, and from April 1-30 and April 12-May 1, 2019, respectively. And, the Missouri Southern State University (MSSU) reported to the Office of the Vermont Attorney General about the cyber-attack triggered by a phishing email on January 9, 2019.

“The email contained a link, which, when clicked, allowed the perpetrator, to potentially copy that employee’s Office 365 account. Unfortunately, several employees fell victim to the fraudulent scheme. As soon as it detected this attack, the university contacted law enforcement and was directed to delay notification of potentially affected individuals until its investigation was complete. The university immediately engaged a leading forensic investigation firm to look into the matter and undertook enhancements to its already robust IT systems to block potential email exploitation, including a mass password reset of all employee Office 365 accounts,” the University said in a statement.

Recently, the Australian National University discovered a major data breach that affected students’ and University’s sensitive information. According to the University’s Vice-Chancellor Brian Schmidt, unknown cybercriminals attacked University’s systems and accessed personal information late in 2018, which was recently discovered by the University authorities on May 17, 2019. It’s believed that the hackers had unauthorized access to 19 years of significant amounts of information related to personal staff, students, and visitors.

The exposed information included names, addresses, dates of birth, phone numbers, personal email addresses and emergency contact details, tax file numbers, payroll information, bank account details, passport details, and student academic records, according to Schmidt. However, Schmidt clarified that the data like credit card details, travel information, medical records, police checks, workers’ compensation, vehicle registration numbers, and some performance records were not affected by the incident.

Quantifind partners with Acuris Risk Intelligence to boost AML Investigations

Acuris Risk Intelligence, a provider of data intelligence and cybersecurity professionals, recently announced its partnership with technology company Quantifind in order to boost anti-money laundering (AML) investigations.

The new collaboration allows Quantifind’s clients to have access to a high-quality data source, KYC6, Acuris Risk Intelligence’s online portal, which integrates into Quantifind’s AI platform. It also enables Quantifind to provide compliance teams with key capabilities of individuals via search, on-going monitoring, sanctions, and Enhanced Due Diligence (EDD) report.

Established in 2004 as C6, Acuris Risk Intelligence has now become as one of the top suppliers of proprietary data on PEPs, sanctions, and AML data for due diligence and compliance. It’s a trusted and independent provider of data intelligence for anti-money laundering, anti-corruption, and cybersecurity professionals.

The company claims that it combines a world-class dataset, that includes fraud and cybersecurity content, with expert human analysts and state-of-the-art technology to help organizations manage the risk in business relationships effectively.

“Thanks to this partnership with Acuris, we are adding a global, trusted and high-quality source of Publicly Exposed Persons data to our existing portfolio of data sources. This is a critical step in our journey to bring our financial crime applications to the market and help financial institutions improve the efficiency of the AML and KYC investigations,” says Adam Mulliken, SVP of Analytics and General Manager for Quantifind’s Financial Crimes business line.

“We are delighted to partner with Quantifind and help them enhance their AML investigations with the integration of our data into their systems. Their sophisticated AI techniques will work alongside our world-class data to provide clients with accurate and timely information,” said Joel Lange, Managing Director, Acuris Risk Intelligence.

Cybersecurity startup Critical Start secures $40 million

Funding

Cybersecurity startup Critical Start recently announced that it has received a $40 million investment from the private equity firm Bregal Sagemount. The Plano-based cybersecurity company stated the new funding will accelerate business expansion and help build its team.

Founded in 2012 by Rob Davis, a former RSA Security executive, Critical Start helps organizations by addressing their security challenges and protect its customers’ brand while reducing their risk. The company provides managed security services and security-readiness assessments by using Defendable Network framework, professional services, and product fulfillment.

“The funding will be invested in expanded marketing, training, and support programs for our partners, which will help them to service our Managed Detection and Response (MDR) customers and prospects,” Rob Davis, the CEO of Critical Start, said in a media statement. “Our sales coverage will expand to include additional East and West Coast markets, where now we only have employees in New York and California. Critical Start will continue to add additional technology integrations and double the size of our research and development team.”

“The investment will have very little impact on how the company is run on a day-to-day basis. “We have added Michael Kosty from Sagemount to our Board, but I will continue to run the company as CEO, with myself and my wife and business partner, Tera, owning the majority of the company. However, the investment will help us to accelerate the growth of the company and expand into new markets, which we are very excited about,” Davis added.

Critical Start stated the new investment comes on the heels after its new partnerships with popular companies like Microsoft, Chronicle Backstory, and Palo Alto Networks Cortex.

“Microsoft invests approximately $1 billion in cybersecurity every year and is highly committed to developing advanced security technologies that utilize leading security tools for its existing and future offerings. We share a common goal to positively impact the cybersecurity market with better tools, technology, and expertise, and by collaborating with an innovative, industry leader such as Microsoft, we can improve the security posture for millions of organizations,” Davis said.

Howden and Cytegic join hands for Automated Cyber Risk Assessment

Collaboration, partnership, alliance, KnowBe4 and Agari Partner to Prevent Identity-Based Email Attacks

The cyber risk quantification solutions provider Cytegic recently announced that it has entered into a strategic partnership with Howden, a global international insurance intermediary, to automate the cyber risk assessment and financial impact analysis across global markets.

Founded in 2012, Cytegic is a revolutionary cyber risk quantification platform that provides automated end-to-end solutions. The company is making innovative steps to quantify cyber risk at any level of scale, from SMB’s to Fortune 500. Cytegic claims that its Automated Cyber Risk Officer (ACRO) leverages forward-looking, contextual and quantified global threat intelligence to automatically identify risks to an organization’s business assets.

Speaking on the new alliance Elon Kaplan, the CEO of Cytegic said, “We are excited to partner with Howden, a global leader with extensive expertise in cyber insurance, to drive forward the cyber insurance revolution. Cytegic’s non-invasive and automated cyber risk quantification platform enables end-to-end cost-effective management of cyber insurance policies with precision, validity and financial transparency.”

“After researching numerous solutions and putting the Cytegic platform through a variety of challenging tests, we were able to confirm Cytegic’s unique ability to accurately quantify financial risk through its automated ACRO platform. Rapid evaluation of third-party risk and security posture optimization can be performed automatically through the Cytegic platform, providing clients with greater efficiency and transparency. We will be able to provide a proactive partnership with customers by actively helping them understand and quantify their cyber risk,” said Shay Simkin, the Global Head of Cyber at Howden.

Gaming industry suffered 12 billion cyber-attacks in past 17 months

Gaming

The gaming industry has become an attractive target for cybercriminals with 12 billion credential stuffing attacks reported in the past 17 months (November 2017-March 2019).

According to the Cloud delivery network provider Akamai Technologies, the gaming community is among the most lucrative targets for hackers to make a quick profit. In its research report, “2019 State of the Internet/Security Web Attacks and Gaming Abuse” Akamai stated that there were 55 billion cases of credential stuffing attacks across all industries.

The report highlighted that nearly 67% of credential stuffing attacks target organizations based in the United States. It stated that Russia is the second largest source of application attacks and China is ranked as the fourth highest source country. On the other hand, the United Kingdom ranked as the second highest targeted country with Japan, Canada, Australia, and Italy are all also among the countries most targeted.

“One reason that we believe the gaming industry is an attractive target for hackers is that criminals can easily exchange in-game items for profit,” Martin McKeay, Security Researcher at Akamai said in a statement. “Furthermore, gamers are a niche demographic known for spending money, so their financial status is also a tempting target.”

The attackers look for valid accounts and unique skins in popular games to hack them and sell. Akamai said that hackers focus on more valued video game accounts that are connected to a valid credit card or other financial resources. After compromising the account, the criminal can purchase additional items, such as currency used within the game, and then sell the hacked account at a higher price.

According to a research, young gamers are increasingly turning into hackers to commit cybercrime. The research found that 82% of teens and young adults recruited by online criminals had developed their cybercrime skills through video gaming.

The UK’s National Crime Agency (NCA) held a forum and published a special report about the problem. The agency report looks at ways to identify those at risk of hacking, how to intervene before they go too far, and then inspire them to pursue a career in IT security.

Cybercriminals use Google Calendar alerts to steal sensitive information

Google Calendar

Scammers are making phishing attacks, by abusing Google Calendar services, to trick users into giving away sensitive information like passwords, card details, and other financial data. The threat intelligence and cybersecurity firm Kaspersky stated that it detected many unsolicited pop-up calendar notifications sent to Gmail users by cybercriminals as a sophisticated spam email attack.

“Spam and phishing threats that exploit non-traditional attack vectors can be lucrative for criminals, as they can often successfully trick users who might not fall for a more obvious attack. This is particularly true when it comes to trusted legitimate services, such as email calendar features, which can be exploited through so-called “calendar phishing,” Kaspersky explained.

The calendar phishing emails exploit the automatic addition and notification of calendar invitations feature for people using Gmail on their mobiles, according to Kaspersky.

The scam occurs when an attacker sends an unsolicited calendar invitation carrying a link to a phishing URL and encourage the recipient to click on the link. The user then redirected to a fake website, appears to be original, that features a simple questionnaire and offered a prize after completion. The victim will be asked to fill in personal details like name, phone number, address, and bank details in order to steal the victim’s money or identity.

“The ‘calendar scam’ is a very effective scheme, as most people have become used to receiving spam messages from emails or messenger apps,” said Maria Vergelis, a security researcher at Kaspersky. “But this may not be the case when it comes to the Calendar app, which has the main purpose to organize information rather than transfer it. So far, the sample we’ve seen contains text displaying an obviously weird offer, but as it happens, every simple scheme becomes more elaborate and trickier with time.”

The security also suggested the users turn off the ‘automatically add invitations’ option to the Google calendar to avoid calendar scams. According to a research by Menlo Labs, a company that provides cybersecurity solutions, employees at financial services firms in the United States and the United Kingdom are being targeted by a malicious email campaign.

The researchers revealed that cybercriminals are storing malicious payloads on storage.googleapis.com, the domain of the Google Cloud Storage service. The email campaign might have been active in the United States and the United Kingdom since August 2018. The victims received emails containing malicious links to archive files, which appears to be genuine and related to Google’s cloud storage service. The research report stated the attackers used two types of payloads to compromise PCs and the endpoints by duping employees into clicking on malicious links.

 

Cybersecurity startup Fireblocks emerges from stealth mode with $16 million funding

Firedome Funding

Blockchain cybersecurity startup Fireblocks Inc. recently raised $16 million investment in its first funding round led by Cyberstarts along with additional contributions from Tenaya Capital, EightRoads, Swisscom Ventures, and MState. The New York and Tel Aviv-based startup, which recently emerged from stealth mode, stated the new funding will help accelerate the company’s growth.

Founded in 2018 by a group of security veterans Michael Shaulov, Idan Ofrat, and Pavel Berengoltz, Fireblocks develops a blockchain security service that combines over-the-counter (OTC) transactions, hot wallets, and exchanges into one single platform. Fireblocks claims that its chip-level security and multi-party computation (MPC) technology to help transfer assets across exchanges and wallets securely. Fireblocks security platform uses several layers of security measures including passwords, biometrics, and two-factor identification.

“While blockchain-based assets by themselves are cryptographically secure, moving digital assets is a nightmare. After interviewing over 100 institutional customers, including hedge funds, broker-dealers, exchanges, and banks, we concluded that the current process is slow and highly susceptible to cyber-attacks and human errors,” said Shaulov in a media statement. “We built a platform that secures the process and simplifies the movement of funds into one or two steps.”

“Securing blockchain-based assets is one of the key challenges in modern cybersecurity warfare, and it requires heterogeneous expertise in mathematics, system level programming and years of hands-on cybersecurity experience,” said Sequoia Capital and Cyberstarts partner Gili Raanan. “The Cyberstarts team is thrilled to partner with Michael, Idan, and Pavel, who amazed us with their technology breakthrough to eliminate risk from digital assets management.”

Personal medical data is worth more than financial data: Survey

Medical Data

Cybersecurity experts say cybercriminals are increasingly targeting the healthcare industry to steal sensitive medical information and sell it on the black market.

A recent survey from cybersecurity company Carbon Black stated the rate of cyber-attacks on healthcare industry appear to be increasing exponentially. In its survey report Healthcare Cyber Heists in 2019, Carbon Black has disclosed what is happening to the Personal Health Information (PHI) that was stolen by cybercriminals.

The survey, which involved 20 of the healthcare industry’s Chief Information Security Officers (CISOs), found the healthcare sector being targeted because of how lucrative PHI is when compared to other personal data like credit card numbers. It’s said that personal health information is worth three times more than other personal information since the health information never changes and can be used by cybercriminal groups for extortion or compromise.

The survey revealed that around 83% of surveyed healthcare organizations stated they’ve seen an increase in cyber-attacks over the past year and over 66% surveyed said that cyber-attacks have become more sophisticated over the past year.

A recent report revealed that health care organizations suffered the highest number of data breaches in 2018 across any sector of the U.S. economy. According to Beazley Breach Response, a breach response management and information security insurance solutions provider, the healthcare entities have reported the highest number of data breaches, at 41 percent.

The report, dubbed as Beazley Breach Insights Report, stated that direct hacking, the presence of malware, or due to human error were the causes of data breaches in healthcare organizations. The report also revealed the percentage of breaches in other sectors of the economy. The education sector accounted for 10 percent of security issues, financial institutions reported 20 percent of incidents, and professional services represent 13 percent of cases.

The cybercriminals are attempting to extort cryptocurrency from companies or individuals claiming to have embarrassing evidence of people using adult websites at work, which are related to extortion, the report added.

Also, a survey revealed that employees at U.S. health care institutions may be susceptible to phishing emails. The survey report, Assessment of Employee Susceptibility to Phishing Attacks at US Health Care Institutions, authored by Dr. William Gordon of Brigham and Women’s Hospital and Harvard Medical School in Boston stated that many healthcare organizations remain vulnerable to phishing attacks.

William specified that when the researchers sent simulated phishing emails, nearly one in seven of the emails were clicked by employees of healthcare organizations. The survey also stated the importance of employee awareness of the risks associated with phishing emails. “Cybersecurity is a really important issue for hospitals and healthcare organizations and it’s only getting more important. One of the biggest risks for them is their own employees and it’s manifested through a phishing attack,” said Gordon.

Telegram hit by DDoS Attack! Blames China

Telegram

The popular messaging app Telegram recently suffered a DDoS (Distributed Denial of Service attack) attack that affected the users in the United States, Hong Kong, and in other countries. Telegram, well-known for its encryption, privacy, and self-destructive private messages, stated the users might have experienced connection issues due to the attack.

Telegram took to Twitter to notify its users. “We’re currently experiencing a powerful DDoS attack, Telegram users in the Americas and some users from other countries may experience connection issues,” Telegram said in a Twitter post. Describing the attack Telegram said, “A DDoS is a “Distributed Denial of Service attack”: your servers get GADZILLIONS of garbage requests which stop them from processing legitimate requests. Imagine that an army of lemmings just jumped the queue at McDonald’s in front of you – and each is ordering a whopper.”

“The server is busy telling the whopper lemmings they came to the wrong place – but there are so many of them that the server can’t even see you to try and take your order. To generate these garbage requests, bad guys use “botnets” made up of computers of unsuspecting users which were infected with malware at some point in the past. This makes a DDoS similar to the zombie apocalypse: one of the whopper lemmings just might be your grandpa,” Telegram tweeted.

While confirming that users’ data was not misused in the attack, Telegram said, “There’s a bright side: All of these lemmings are there just to overload the servers with extra work – they can’t take away your BigMac and coke. Your data is safe.”

Meanwhile, the Telegram founder Pavel Durov stated the Chinese government may have been behind the DDoS attack. Durov described the incident as a “state actor-sized DDoS” which came mainly from IP addresses located in China. The attack coincided with the ongoing protests in Hong Kong, where people are using Telegram to avoid detection while coordinating their protests.

Recently, Pavel Durov criticized WhatsApp after it revealed a vulnerability in its network system that allowed hackers to install spyware via an infected WhatsApp voice call. In his blog post, Durov wrote an article, Why WhatsApp will never be secure, criticizing WhatsApp on its latest data breach.

“This news didn’t surprise me though. Last year WhatsApp had to admit they had a very similar issue a single video call via WhatsApp was all a hacker needed to get access to your phone’s entire data,” Pavel Durov stated in his blog post. Every time WhatsApp must fix a critical vulnerability in their app, a new one seems to appear in its place. All their security issues are conveniently suitable for surveillance and look and work a lot like backdoors.”

“Unlike Telegram, WhatsApp is not open source, so there’s no way for a security researcher to easily check whether there are backdoors in its code. Not only does WhatsApp not publish its code, they do the exact opposite: WhatsApp deliberately obfuscates their apps’ binaries to make sure no one is able to study them thoroughly,” Durov added.

Open Systems partners with Equinix to accelerate Global Digital Transformation

Software security firm Open Systems recently announced that it has partnered with global interconnection and data center company Equinix to develop digital transformations and improve end-user experiences globally. Open Systems is a provider of a secure SD-WAN that offers enterprises assured security, AI-assisted automation, and expert management services.

As per the partnership deal, Open Systems integrate its SD-WAN technology with Equinix’s expert engineers, developers, and architects to deliver secure, reliable application performance on a global scale.

Founded in 1998, Equinix is an American multinational company. The California headquartered company is specialized in internet connection and data centers. The company said that its Cloud Exchange Fabric securely and dynamically connects to the Open Systems secure SD-WAN for digital business that enables deployment of digital infrastructure.

“Our customers are moving to the cloud at an unprecedented rate, and the combination of the Equinix Cloud Exchange Fabric and the Open Systems secure SD-WAN makes it easier, faster and simpler to deliver applications in the cloud to users across multiple countries,” said Oren Yehudai, Senior Channel Sales Director, EMEA at Equinix. “We are very excited to be working with Open Systems to deliver this powerful solution on a global scale.”

“Open Systems has spent decades building the most robust, reliable and secure global network infrastructure, and the combination of Open Systems and Equinix provides a single worldwide solution that our customers can rely on to roll out applications powered by our leading secure SD-WAN solution,” said Matt Krieg, Chief Revenue Officer, Open Systems. “This new offering dramatically reduces complexity, increases cybersecurity, improves application performance and eliminates barriers to global expansion.”