Home Blog Page 338

Cyber-attack on Luas transport system may affect 3,226 users

Luas

Personal information of 3,226 people who used Luas tram services may have been compromised in a potential cyber-attack. The Dublin-based tram service operator stated that unknown intruders defaced its website and demanded a ransom of one Bitcoin.

In a social media post, Transdev, the company that operates the Luas, declared that its website got compromised and a message from the hackers was displayed on the home page, saying

You are hacked … some time ago I wrote that you have serious security holes [but] you didn’t reply … the next time someone talks to you, press the reply button … you must pay 1 bitcoin in 5 days … otherwise I will publish all data and send emails to your users.”

The company stated the website has been taken down and they’re working on the issue.

“Due to an ongoing issue, please do not click onto the Luas website. We currently have technicians working on the issue. We will be using this forum only for travel updates should the need arise. For any queries, please contact our customer care number on 1850 300 604,” Luas post read.

There are various incidents of cyber-attacks on transport system earlier. On October 24, 2017, Ukraine’s Odessa airport and metro system in Kiev was targeted by a malware called “BadRabbit” and prompted state-run Computer Emergency Response Team (CERT) to ask transport networks to be on alert.

Also, a cybersecurity audit performed on the Washington Metro in July 2018, highlighted that the agency remains vulnerable to attacks that might endanger the security system. The audit report was submitted to Metro’s board of directors in late last month, but the key facts are being kept secret due to the risk from scammers.

The report specifically mentioned the Metro’s incident response measures and whether the security experts in the agency know how to detect and respond to a cyber-attack. In a response to the report, the Metro officials announced that they’re focussing on the security improvements in the entire transport system.

Data breaches lead to higher advertising expenses for hospitals: Report

Health care data breaches

A new study recently showcased the relationship between data breaches and increasing advertising expenditures from the hospitals. Published by American Journal of Managed Care, the study named Understanding the Relationship Between Data Breaches and Hospital Advertising Expenditures revealed that the hospitals who suffered a data breach increased their annual advertising budget by 64 percent.

The researchers Sung J. Choi and M. Eric Johnson stated that they’ve inspected and compared the non-federal acute care inpatient hospitals’ advertising expenditures after a breach to the hospitals without breach history. The analysis, based on the information from the Healthcare Cost Report Information System, market competition, and surveys on media vehicles from 2011 to 2014, stated that the effect of data breaches increased the advertising expenses incurred to restore the hospital’s image.

“We found that breached hospitals were associated with significantly higher advertising expenditures. Repairing the affected hospital’s image and minimizing patient loss to competitors are potential drivers of the increased spending. Regardless of the motivation, breach response adds a financial burden to hospitals and the healthcare system. Advertising and the efforts to fix the damages from a data breach increase healthcare costs and may divert resources and attention away from initiatives to improve care quality. Advertising costs subsequent to a breach are another cost to the healthcare system that could be avoided with better data security,” the report stated.

The Healthcare industry has been a prime target for hackers. Recently, around 15,000 Medicare advantage members of Blue Cross Blue Shield of Michigan were in threat of being affected by a potential data breach. The healthcare and health insurance provider stated that the theft of its employee’s laptop on October 26, 2018, may have compromised the customers’ personal information.

Blockchain cybersecurity startup Xage Security raises $4 million from Saudi Aramco

Firedome Funding

Xage Security, a blockchain security startup, recently raised $4 million investment from Saudi Aramco Energy Ventures (SAEV), a subsidiary of integrated energy and chemicals company Saudi Aramco. The Palo Alto-based start-up stated the new funds will be used to develop the company’s security infrastructure and capabilities of offering services in the energy sector. The company is planning to enable its Industrial Internet of Things (IIOT) deployments across various sectors like oil and gas, renewables, water, and wind.

Xage Security also added Norman Thorlakson as the new Senior Vice President of Sales and Business Development. Founded in December 2017, Xage Security claims to be the only blockchain-protected security fabric for the Industrial Internet of Things (IIoT). The company offers a secured communication medium between machines, people, and data using Xage Security Suite.

“Our mission is to secure all interactions involving industrial networks – whether those are between machines, apps, data, or people – to enable the next wave of connected and improved operations for the global industry,” said Xage Security CEO, Duncan Greatwood. “The support from SAEV is a significant validator for Xage’s solution and its impact on the energy sector, and with the addition of Norman Thorlakson to our executive team, we are extending our reach, and supporting the benefits of IIOT and industrial automation.”

“SAEV invests in technologies and companies that represent the future of energy, and as operational networks become more connected, there’s an opportunity to improve asset management, production, and efficiency,” said Jim Sledzik of SAEV. “Xage has developed an innovative approach to distributed interactions and industrial security for IIOT, and we are proud to partner with them, as they continue to grow and contribute to the evolution of the energy sector.”

Town of Salem game hacked; 7 million users affected

battle of galaxy game

The popular online video game The Town of Salem is the latest victim of a cyber-attack that compromised the personal information of more than 7 million users. The Town of Salem is a role-playing game operated by BlankMediaGames with around 8 million users.

BlankMediaGames confirmed that its servers and databases were hacked, resulting in data theft of users’ names, emails, passwords, IP addresses, and Game & Forum Activity. The gaming company said that it never stores credit card, payment information or personal identifying information of the users. BlankMediaGames notifying the users about the data breach via emails and suggesting them to change their passwords to prevent further loss.

“We don’t store any credit card or payment info. At all. All passwords were hashed and not plain text. This means they do not know what your password is unless they run a program to attempt to guess it against the hashed password. Any reasonably strong password will take a very long time to be guessed. Your accounts should all be safe still if they used the same password, but you can change that as well if you are worried,” BlankMediaGames said in a post.

BlankMediaGames stated the breach was discovered by a hacked-database search engine Dehashed on December 28, 2018. Dehashed stated that it has received information about the breach from an anonymous source. It also said that the breach was caused by an entry-level vulnerability known as LFI / RFI.

“On 12/28/2018 we’ve received an email regarding the popular online RP game “Town Of Salem”s breach. The sender, who wishes to be anonymous at this time, provided Dehashed with evidence of server access and provided the complete database for disclosure. We’ve reached out to BlankMediaGames regarding a statement and to provide assistance with securing their servers,” Dehashed stated in a post.

Even after the improved security measures, the data hacks have become common in the online gaming industry. Recently, Humble Bundle, a digital storefront for video games, revealed that it has suffered a data breach in late November that might have compromised the information like customers’ account details and subscription status.

The company stated that hackers exploited a bug used to gather the subscriber information in the company’s server and illegally gained access to its customers’ email addresses and their Humble Bundle subscription details. However, Humble Bundle clarified that no sensitive information such as customer name, billing address, password, and payment information was exposed in the incident.

HHS releases new guidelines to boost healthcare cybersecurity

HHS

The Department of Health and Human Services (HHS) recently issued guidelines for healthcare sector to reduce the security risks and boost cybersecurity practices across the industry.

HHS recently drafted “Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients” in partnership with more than 150 cybersecurity leaders in the healthcare industry. The guidelines intend to leverage the cybersecurity framework to educate healthcare professionals on cybersecurity and help organizations in implementing cybersecurity practices.

The publication reveals five most relevant and current threats to the healthcare industry and also recommends 10 Cybersecurity Practices to help mitigate these threats. It also includes technical volumes that focus on cybersecurity practices for small, medium and large healthcare organizations, and include resources and templates organizations can use to assess their cybersecurity posture and develop policies and procedures.

“Cybersecurity is everyone’s responsibility.  It is the responsibility of every organization working in healthcare and public health.  In all of our efforts, we must recognize and leverage the value of partnerships among government and industry stakeholders to tackle the shared problems collaboratively,” said Janet Vogel, HHS Acting Chief Information Security Officer.

Healthcare industry has been a prime target for hackers. Recently, BJC HealthCare, a non-profit healthcare networks in the United States, reported a data breach that affected 5,850 people. BJC stated that unknown intruders illegally gained access to its patients’ payment portal and uploaded malware that potentially compromised the personal and credit/debit card information. The security professionals at BJC determined that the malicious code exploited the payment portal and exposed the payment information from October 25, 2018, to November 08, 2018, affecting 5,850 of its users.

Suspected ransomware affects several US newspapers

Chicago Tribune Cyber attack

The Los Angeles Times and several Tribune Publishing newspapers faced printing and delivery issues after encountering a cyber-attack that reportedly involved a ransomware.

The Associated Press quoted the Chicago Tribune reporting that the publishing and printing systems of several Tribune Publishing newspapers were affected due to a computer virus. The Chicago Tribune’s print edition on Saturday, December 29, 2018, was published without paid classified ads and death notices due to the attack. However, the publisher clarified that no customer and financial information was leaked.

“This issue has affected the timeliness and, in some cases, the completeness of our printed newspapers,” Tribune Publishing spokeswoman Marisa Kollias told Associated Press. “Our websites and mobile applications, however, have not been impacted.”

“There is no evidence that customer credit card information or personally identifiable information has been compromised,” Kollias added.

In Los Angeles, the Los Angeles Times, San Diego Union Tribune, the Wall Street Journal and New York Times (West Coast Editions), and some other newspapers were also affected. The Los Angeles Times reported that some people said the attacks appeared to be in the form of “Ryuk” ransomware.

“Because of a major computer breakdown that affected our printing and deliveries, many of you did not receive your copy of Saturday’s Los Angeles Times,” Norman Pearlstine, executive editor of the Los Angeles Times, and Chris Argentieri, its chief operating officer, said in an apology post.

6 Cybersecurity Predictions for 2019

2019 predictions

Contributed by Emma Megan

2018 has been a crazy year for technology as well as the Internet. It started with the announcement that Intel had substantial security flaws in their chip architecture. This was followed by GitHub being subject to a very vicious cyber-attack which completely shook the market. Furthermore, mobile phishing remained at an all-time high throughout the year as mobiles couldn’t provide the same level of security in comparison to other devices.

When we talk about anticipating the year ahead in terms of what is in store for cybersecurity we can take clues from the current year. The familiar forms of attack inflicted on businesses are likely to follow through in the next year as well. The largest potential breach occurred to the firm Exactis, the attack involved exposing around 340 million personal records

Beyond the all too common corporate attacks, 2018 also witnessed fast-paced activity across a range of victims and targets. In the world of social networking, Facebook admitted that cyber criminals stole information of 30 million users. Then there was the breach on Under Armour’s health tracker My Fitness Health which led to the information leak of 150 million people.

After the implementation of GDPR by EU a lot of businesses and large corporations have started to disclose breaches, revealing a list of vulnerabilities. Not only does it show that 2019 better be ready to make up for the shortage of skills in data protection from 2018, but that businesses will need effective measures that will help them keep up with this rapid change in technology again and again.

Regulation on Data Protection

It is predicted by experts that the European Union will punish a few companies that had violated the GDPR in order to make an example for others. With penalties overhead, corporations will take serious measures to protect their users and customers’ data.

It is believed that enforcement will be harsh in the first few months of 2019, in order to get everyone on the same page regarding cybersecurity. Hundreds of complaints have been filed against companies such as Google and Facebook, which demands not only a response but better cybersecurity operations. The coming year is all about the reactions to these compromises.

There is a rising concern about how companies protect or even use the users’ personal information. It is these users who are pushing every day to hold the companies with weak policies accountable. This number is growing day by day.

Microsoft Will Use ATP on All Mainstream Products

The Windows 10 Advanced Threat Protection is one service that lets anyone who has an E5 license to be able to see what an attacker does to the system. It relies heavily on telemetry. In 2019 the software company is expected to fortify its current efforts into building a security focused brand image. The company is using this method to strategize in getting more sales for the Windows products over its competitors by enhancing its security features.

Multi-Factor Authentication for Online Transactions

This may not be the perfect solution but websites will inevitably ditch the password access and go for the additional authentication process for users. It is possible that a lot of people will get frustrated from this lengthy process just to get access to the data or devices.

When you only use a password to authenticate you are still vulnerable to phishing. The unfortunate thing is if this does go into the implementation stage, every platform will be using a different authentication process and each one will just more tedious to use.

Targeted Spear Phishing

Attackers are aware that the more information they obtain from the user, the better they can build a phishing attempt against the user. In the coming year, this will only intensify, especially towards people who earnestly believe that since they have nothing to do with major tech in their work, nor do they keep client information they have nothing to fear.

Spear phishing is likely to rise on an all-time high. These are creepy tactics too, like lurking into your emails even your private ones. One place where this is most common is the mortgage wire scheme. This seems totally secure but it most certainly not. Most people wire their closing fees to the directions given by the mortgage agent’s email, hackers know this common practice and usually hack into the agent’s computers to get their client’s information. This is done so stealthily that even the agent is not aware that their information might be compromised. The hacker then sends the email to the client who unsuspectingly wires the whole amount.

Nations Will Attempt to Put into Place Cyber Warfare Rules

At the moment no such regulations are in place for a cyber-war and every year everyone in the tech industry expects this to change. Over the years it has been getting out of hand, making experts believe that the time is near when laws will be finally enacted. For example, North Korea hacked Sony Pictures, Russia hacked into industrial critical control systems and powerful nations play with the idea of malware to destroy nuclear equipment. Additionally, Nations will also increase their digital surveillance of their citizens to make sure that they have all the data required to protect the Governments main network.

With every attempt digital boundaries are pushed, there isn’t much time left when these lines are pushed back. The truth is that the resources for cyber criminals are increasing, even from the governments themselves, which will inevitably make the world notice the damage the attacks are inflicting on a global scale. This is exactly why national cybersecurity is now more important than ever.

Corporations will Require Masters in CSOs and CISOs

Cybersecurity training is continuously maturing every day. Mere certificates may no longer help professionals to become a fully qualified security expert as every emerging certification revolves around different IT aspects. Hence, people will start specializing in cybersecurity and will obtain the required qualifications and credentials.

Recently master’s degree in cybersecurity are being enlisted in disciplines around major schools like New York University and UC Berkeley. Soon more companies will need to hire CSOs and CISOs with good skills and a master’s degree to run their cybersecurity operations. Furthermore, this means that simply having a mere certificate will not suffice for the development of sound security networks.

Conclusion

It is safe to say that 2019 will be a monumental year in terms of how individuals, businesses and Governments approach cybersecurity. The past few years have induced a pivotal change in the perception of cyber-crimes and how important it is to take every security measure possible. Furthermore, 2019 will show the world how dedicated companies really are in protecting their user’s data and what kind measures they are taking to safeguard data. This outcry for cybersecurity will define the trajectory of 2019 in terms of cyber-crimes and data protection.

Emma Megan is a passionate tech and business blogger. She loves to get engaged with the readers who are seeking for technology and business related information on the internet. Currently, she is associated with a Virginia based Cybersecurity Company ‘Mars Technology’.

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

Vietnam rolls out new cybersecurity law

Vietnam

Vietnam lawmakers approved a new cybersecurity law that controls the Internet content and global tech companies operating in the country. The new cyber law, which came into effect on January 01, 2019, requires Facebook, Google, and other international tech firms to store local users’ data on local servers and set up offices in Vietnam.

The new law prohibits Internet users in Vietnam from spreading anti-government information and posting false information that could cause damage to the country. It also prevents the circulation of content that’s fake, slandering, or inciting violence.

In November 2018, the Vietnam government released a draft declaration on guidelines to implement the law to remediate the shortcomings in Vietnam’s legal corridors and ensure secure cyberspace. The draft recommended social media users to abide by the Constitution and legal regulations while voicing their opinion and discontent.

The Law also addresses the protection of human rights and civil rights, as well as protection of secrets of businesses, individuals and families. It also mandates domestic and foreign telecommunications service providers to keep personal information and accounts of users secured.

 

Nova Entertainment breached; data of 250,000 radio listeners exposed

Radio hacking

The Australia-based entertainment company Nova Entertainment is the latest victim of a data breach. The radio networks firm stated that the personal information of more than 250,000 radio listeners collected between 2009 and 2011 has been exposed.

According to the official statement, the compromised information included user names, home addresses, emails, phone numbers, gender, and date of birth details. However, Nova clarified that no financial information or copies of ID were disclosed in the incident. Cathy O’Connor, the chief executive at Nova, said that the affected individuals were being notified about the incident and the type of information that disclosed.

“We are taking all necessary measures to ensure the strength and effectiveness of our cyber security, and there is currently no evidence of any suspicious activity or threats on Nova Entertainment’s systems,” Ms. O’Connor said.

“We take privacy, and the security of the information we collect from our listeners very seriously, and on behalf of Nova Entertainment I deeply and sincerely regret that this incident has occurred,” she added.

The radio network firm, that runs radio stations in Sydney, Melbourne, Brisbane, Adelaide, and Perth, stated they are notifying the affected people and suggesting to change their passwords and review their credit report for any unusual activity. Nova has informed the Office of the Australian Information Commissioner (OAIC) and is undertaking an investigation to find how the data breach has happened.

The Office of the Australian Information Commissioner (OAIC) recently stated that phishing attacks are the key source of data breaches in Australia. The OAIC recently released the quarterly statistics report on the Notifiable Data Breaches (NDB) occurred between July 1, 2018, and September 30, 2018. The latest report notified 245 data breaches that affected users’ personal information during the quarter. Of the 245 reported breaches, the OAIC stated that 57 percent of incidents were caused by malicious attacks, 37 percent resulted from human error, and 6 percent were due to the system fault.

The report detailed the top five industries that suffered the most breaches are health service providers (45%), finance (35%) legal, accounting, management services (34%), private education providers (16%), and personal service providers (13%).

Data breach affects 15,000 medicare customers of Blue Cross Blue Shield of Michigan

Blue Cross Blue Shield of Michigan

Around 15,000 Medicare advantage members of Blue Cross Blue Shield of Michigan might have affected by a potential data breach. The healthcare and health insurance provider stated that the theft of its employee’s laptop on October 26, 2018, may have compromised the customers’ personal information.

The incident was notified by Blue Cross’s subsidiary company COBX on November 12, 2018. Blue Cross said that while the laptop was encrypted and password-protected, the login details may have been compromised.

“After learning of the theft, we began working with our subsidiary company to promptly change the employee’s access credentials and investigate the issue. To date, we are not aware of any attempted logins to the employee’s laptop since the theft. Although there is no evidence that the laptop contents were accessed, we are notifying just under 15,000 affected Medicare Advantage members in an abundance of caution,” Blue Cross said in a statement.

The access information includes the member’s first name, last name, address, date of birth, enrollee identification number, gender, medication, diagnosis, and provider information. Blue Cross clarified that the Social Security numbers and financial account information were not included in the accessible data.

“Disclosure of protected health information in this way does not meet privacy practices at Blue Cross. Although we believe that the risk of identity theft or financial harm is low in this case, we want to do what we can to alleviate concerns affected members may have,” said Kelly Lange, Blue Cross vice president for enterprise compliance.

“We’re currently working closely with our subsidiary company to review policies and procedures and put additional safeguards in place. At Blue Cross and Blue Care Network, we take the security of our members’ protected health information very seriously and sincerely apologize for this incident,” Lange added.

Blue Cross is notifying the affected members and also providing free identity protection services, which help recover identity theft-related financial losses, restore credit along with fraud alerts, credit monitoring, and identity theft insurance policy, for two years.