Home Blog Page 345

Data breach at Nordstrom exposes sensitive employee data

Cyber attack

Nordstrom, an American chain of luxury department stores, has suffered a data breach that affected its employees’ personal information. The Seattle-based retailer stated that the breach compromised a wide range of current and past employees’ data, including names, social security numbers, dates of birth, routing numbers, salaries and checking account details. However, Nordstrom clarified that no customer data was involved.

Nordstrom stated the breach was discovered on October 9, 2018, by its security team and it’s believed that a contract worker at a store in Seattle was responsible for the incident. The worker reportedly handled the employees’ data incorrectly, the Seattle Times reported.

The company notified the victims about the intrusion via emails and is taking necessary measures to prevent the further loss.

“We have no evidence data was shared or used inappropriately,” the company said in a statement. “Out of an abundance of caution, we are notifying our employees, so they can take the appropriate steps to monitor for any potential unauthorized activity.”

“We’re putting additional measures in place to help prevent this from happening again. We have no evidence data was shared or used inappropriately. Out of an abundance of caution, we are notifying our employees, so they can take the appropriate steps to monitor for any potential unauthorized activity,” the statement added.

A survey from security ratings firm SecurityScorecard highlighted how the retail industry often fails to manage critical security processes. The firm analyzed around 1,924 companies between January from October 2017, for the survey. The study pointed out that the retail industry ranked fifth among the major U.S industries, where the bottom performers were the clothing retailers.

The study revealed that there were more poor performing clothing stores than poor performing department stores, car dealerships, food stores, grocery/pharmacy stores, wholesale retailers, office supply stores, and stores selling sports good combined.

 

Almost half of New Zealand firms unprepared for data breaches: Report

New Zealand Reserve Bank hacked

A recent survey from the information technology company Hewlett-Packard (HP) revealed that 45 percent of the companies in New Zealand rated themselves as not secure against cyber threats; 50 percent of the firms claimed that they lack in cybersecurity confidence.   The research, dubbed New Zealand IT Security Study, stated that most of the businesses are not able to protect their company’s data when their employees working remotely.

The study was conducted in September 2018 by research firm Perceptive on behalf of HP New Zealand on 434 small and medium businesses (SMBs) across the services, production, retail and hospitality, health and education, and distribution industries. The main intention of the research was to identify New Zealand SMBs’ approach towards cybersecurity, including policies, procedures, and risk management.

According to the research, most of the SMBs allow their employees to work remotely, but only 42 percent of them follow a cybersecurity policy.

“The consequences of a data breach are severe; from financial to brand and reputation damage,” said Grant Hopkins, Managing Director at HP New Zealand. “Organisations need to be vigilant about implementing processes that regularly monitor, detect and report data breaches. Running regular risk assessments and managing your endpoint security is critical in keeping businesses data safe.”

“Endpoint security – at the device level – is critical. Organizations tend to rely solely on third-party software security to protect their devices when, in reality, stronger and better business security must be integrated into the device itself. With hackers able to bypass traditional network perimeter security and antivirus programs, it’s time we scrutinize a hardware’s security as closely, if not more, than our external security solutions,” Grant added.

In related news, a similar survey revealed that employees in EMEA (Europe, the Middle East, and Africa) region are exposing signs of security fatigue towards cybersecurity. The study conducted by Aruba, a Hewlett Packard Enterprise Company, on 2,650 employees across EMEA region found that most workers don’t have cybersecurity discipline and aren’t concerned about the consequences of a security breach.

 

Singapore and Canada sign MoU for cybersecurity cooperation

Canada Singapore

The governments of Singapore and Canada signed a two-year memorandum of understanding (MOU) on November 14, 2018, for cybersecurity cooperation. The agreement between the Cyber Security Agency of Singapore’s (CSA) chief executive David Koh and the High Commissioner of Canada Lynn McDonald is intended to establish bilateral cooperation between both the countries in various areas, including the information exchange on emerging threats, sharing of best practices on human resource development, technical and certification provisions.

The MoU exchange took place at the 33rd ASEAN Summit and was witnessed by Prime Minister Lee Hsien Loong of Singapore and Prime Minister Justin Trudeau of Canada.

“With cybersecurity as a transboundary issue, strong international partnerships remain key to navigating the increasingly complex cyber terrain. The MOU will help to strengthen the cybersecurity landscape of both countries. We are also happy to be working together on cybersecurity capacity building initiatives in the region,” said David Koh.

The Cyber Security Agency of Singapore, a part of the Prime Minister’s Office, engages with various sectors to intensify cybersecurity awareness and counter threats. The CSA stated the cybersecurity cooperation fortifies the Singapore’s cybersecurity ecosystem, collaboration on regional cybersecurity capacity building, and the development of a secure regional cyberspace in the Association of Southeast Asian Nations (ASEAN).

Earlier, the CSA signed MoUs with Australia, France, India, the Netherlands, UK, and the United States, a Joint Declaration on cybersecurity cooperation with Germany, and a Memorandum of Cooperation on cybersecurity with Japan.

After recognizing the evolving cybersecurity landscape and the impending cyber threats that loom over the Singapore cyberspace, the Singapore Parliament passed the Cybersecurity Bill in February 2018. Under the bill, the owners of key bodies like national security, defense, foreign relations, economy, public health, public safety or public order, which the bill calls critical information infrastructure (CII) will have to comply with the standards and regulations mandated by the bill.

Pre-Mortem: Understanding a Data Breach Before it Happens

Cloud of Logs dark web market

Contributed by Ken Mafli, Data Security Evangelist at Townsend Security

On April 1, 2018, Gemini Advisory presented its findings after investigating the notorious JokerStash hacking syndicate in which over 5 million customer records had been exfiltrated from Lord & Taylor’s and Saks Fifth Avenue’s network. By the time Gemini Advisory announced the discovery, approximately 125,000 records had already been released for sale by the hacking collective. It was expected that the entire cache would become available shortly.

And while this is an embarrassing chapter in Hudson Bay’s customer service history (the parent company of both luxury retail chains), the breach itself is not the end of the story. Bernadette Beekman, a customer affected by the breach, has already filed a class action lawsuit.  Beekman claims that “the security breach was caused and enabled by Lord & Taylor’s knowing violation of its obligations to abide by best practices and … by cutting corners on security measures that could have prevented or mitigated the security breach that occurred.”

The Blindspot of Hindsight

After a breach occurs, we tend to look back at how a malicious actor gained access to the sensitive data and wonder why the organizations didn’t see the obvious flaws in their defenses. After all, it seems like common sense actions would have prevented the breach.

The truth of the matter is that common sense defenses could have prevented it.

But if bst practices could eliminate or minimize most breaches, why do they continue to happen? Often, organizations get caught up in current initiatives laid down by executives, get mired in internal politics, or suffer from existing policy inertia—so much so that it creates blind spots to the weaknesses in its own cybersecurity defenses.

But there is another reason: hindsight bias. With hindsight bias, after learning about a breach, we have the tendency to think that we could have foreseen it. Let’s be honest. We tend to look at breaches from a bird’s eye view without any of the surrounding circumstances to set it in context. With this vantage point, we see the path the hackers took to get to the data. And since it seems so plain to us, it can lull us into a sense of false security, thinking we would have done better.

And yet breaches continue to happen on the watch of some very capable people. Organizations need a way to envision likely attack vectors and work to close the gaps in their cyberdefenses. Enter, the pre-mortem.

Dissect Before Your Demise

The idea of a pre-mortem originally comes from project management and it works in the sense of a post-mortem, but in reverse. In its original context, you would gather the plan, resources, and timeline for your project. Then, you would gather the project stakeholders and imagine a scenario wherein 6 months after launch of the project, it is deemed a complete failure. Then you ask “how” and “why.” By imagining the death of a project before it gets launched and take steps to mitigate that death, you increase its odds of survival.

In a similar vein, with your overall cybersecurity posture, you should be doing the same thing. Once you have your cybersecurity policies and procedures outlined and in place, you should invite the stakeholders to conduct a pre-mortem in which you game out potential data breach scenarios. As you do, you should:

  • Use as many real world examples of data breaches to inform your scenarios.
  • Work forwards and backwards in attack scenarios (i.e. what is the last step someone would need to take to access the data and work backward to the first step, and visa versa).
  • Gather as many scenarios as possible.
Shore Up Your Defenses

Once you have gamed out the likely ways your cyber defenses could be breached in a pre-mortem session, it is time to get to work.  Steve Brown from Rutter Networking Technologies has this advice:

“Your client data and intellectual property are some of your business’s most valuable assets. If you are to truly defend it, you must go beyond just perimeter security and extend your cybersecurity strategy throughout your whole network. A vulnerability assessment can be a great help in starting to the discovery process to determine where your best capital can be invested and what areas are in highest need of budget allocation. Those areas may include encryption, endpoint protection, multi-factor authentication, log management and more. Only then can you begin to bridge the gap between known weaknesses and greater security.”

To that end, if you do not have these items in place, your analysis should include how these items (plus much more) would help you avoid the breach scenarios you uncovered:

  • Encryption and proper key management: For data-at-rest, encryption and centralized key management is typically a last line of defense in case someone gains unwanted access to your sensitive data. But since an attack is likely unavoidable, this will ensure the data is useless.
  • SIEM: Monitoring access and activity in your network is vital to mitigating an attack. Your SIEM should be as much of a multi-purpose tool as possible, ensuring that you don’t suffer from tool sprawl and fatigue.
  • Permissions management: Ensuring that you have a policy of least privileges in place and then monitor to make sure everyone is playing by the rules is an effective way to spot anomalies and detect any inside/outside threats.
  • Patch management: Simply put, patch management is having a systematic way of updating software. This ensures a timely way to address vulnerabilities.
  • Social engineering training: Frequent training of employees is one of the best ways to minimize the threat that social engineering poses. The more you can train everyone in the organization to guard their personal data, the more secure your organization will be.

 It’s better to conduct a pre-mortem than a post-mortem. If you can imagine the worst and use it to plan ahead, you will be one step closer to overcoming hindsight bias avoid becoming just another breach statistic.

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Silverfort joins hands with Check Point

The multi-factor authentication solutions provider Silverfort recently announced that it has partnered with cybersecurity solutions provider Check Point. Silverfort stated that the alliance enables customers to use Silverfort’s adaptive authentication platform to activate immediate step-up authentication against cyber threats detected by Check Point.

Headquartered in Israel, Silverfort offers multi-factor authentication process across corporate networks and cloud environments. Silverfort claims its next-generation technology helps enterprises prevent data breaches, identity-based attacks, and insider threats.

“Corporate networks have dramatically changed in recent years creating new security challenges. Perimeters no longer exist, and passwords are no longer enough to validate and trust our users,” says Hed Kovetz, CEO of Silverfort. “By integrating Silverfort’s adaptive authentication with Check Point we enable our customers to trigger step-up authentication based on real-time security alerts and achieve real-time prevention without reducing the productivity of their legitimate users.”

Founded in 1993, Check Point offers cybersecurity solutions to private and government enterprises globally. The company claims that its multi-level security architecture enables its clients to defend against malware, ransomware and other targeted attacks across all networks, cloud and mobile operations.

“The threat landscape is evolving faster than ever before, requiring security practitioners to swiftly and concisely respond to detected threats,” said Snir Hassidim, Business and Corporate Development Manager at Check Point Software Technologies. “This partnership with Silverfort will improve our customers’ ability to respond to these threats, by stepping up the authentication requirements to seamlessly improve validation of user identities.”

A couple of months ago, Check Point’s research revealed how organizations and individuals are vulnerable to hacking through their fax machines. The researchers from Check Point, Yaniv Balmas and Eyal Itkin, stated that fax machines have security vulnerabilities which could possibly allow a hacker to steal data through a company’s network using just a phone line and a fax number.

Data breach at Washington Regional Surgery Center affects 2,393 patients

biggest data breaches in India,data breach, Aptoide Android App Admits Data Breach, Suspends Sign-Up Option Temporarily, Panasonic

The Southwest Washington Regional Surgery Center (SWRSC) stated that they recently suffered a phishing attack that affected nearly 2,400 patients’ protected health information.

According to the official statement, cyber attackers potentially accessed the information between May 27, 2018 and August 13, 2018 through a phishing attack on one of SWRSC’s employees. The SWRSC stated that they’ve notified the affected users on November 6, 2018, about the breach.

“After an extensive forensic investigation and manual email review, SWRSC discovered on September 25, 2018 that the impacted email account that was accessed contained some Protected Health Information, including some patients’ names, Social Security numbers, driver’s license numbers, and/or medical information (diagnosis, treatment, surgery, medications, labs and/or health insurance information). A limited number of patients’ credit card numbers were also contained in the impacted email account. This incident does not affect all SWRSC patients,” the statement read.

SWRSC clarified the affected patients that no information has been misused. However, the health center reminded them to review their account statements for any fraudulent activity. SWRSC specified that they’re providing free credit monitoring and identity theft restoration services to the patients whose social security numbers or license numbers were compromised. SWRSC enhanced its email access protocols and updated its passwords to prevent similar issues in the future.

A recent study revealed that data breaches in Washington are continuing to rise. According to the third annual data breach report, Attorney General Bob Ferguson stated that around 3.4 million residents of Washington fell victim to data breaches between July 2017 and July 2018 and the number keep rising. Out of the three categories that Ferguson defined—malicious cyber-attacks, theft or mistake, and unauthorized access—malicious cyber-attacks are the leading cause of data breaches affecting Washington residents. The report also identified deficiencies in Washington state’s data breach notification law and suggested ways to strengthen the same.

Security bug in Indian Railways ticketing website exposed

Indian Railways

The Indian Railway Catering and Tourism Corporation (IRCTC) unknowingly kept its passengers’ personal data at risk for almost two years, two researchers revealed.

According to the Economic Times, Avinash Jain and Gurunatha pointed out that a security vulnerability in IRCTC’s website and mobile app link connected to a third-party insurance provider would have given cyber miscreants access to at least 200,000 passengers’ personal information such as name, age, address, gender, and insurance nominee details.

IRCTC, which handles the catering and online ticketing operations of the Indian railways, provides free travel insurance to the passengers who book tickets via its website or mobile app. This requires IRCTC to share personal and nominee details of all the travellers with third-party insurance providers. The bug, which existed for two years, was discovered and reported to IRCTC on August 14 this year and got fixed on August 29 by IRCTC, the researchers stated.

According to the Indian Computer Emergency Response Team (CERT), the country witnessed as many as 1,44,496 cyber-attacks from 2014 to 2017. The response team stated that around 44,679 cyber-attacks were reported in 2014. By 2015, the number reached 49,455, and by 2016, the numbers crossed the 50,000 mark. The major cyber incidents included phishing, scanning/probing, website intrusions and defacements, virus/malicious code and denial of service attacks, the CERT stated.

Keeping up with the global trends and to better prepare and address impending cyber threats, Home Minister of India, Rajnath Singh has urged critical infrastructure bodies to conduct regular cybersecurity audits. These infrastructures include power, railways, and nuclear energy sectors. Singh stated the biggest cybersecurity concerns are data theft, fraud, and hacking on the country’s critical infrastructure, and highlighted that there have been several attempts by hackers to penetrate the systems and breach the firewall. The best strategy was to stay prepared and vigilant against the cyber threats, he added.

Leaky server exposes personal data of Amex India customers

ICO fines American Express

An unprotected MongoDB server exposed hundreds of thousands of American Express (Amex) India customers’ personal data, according to a researcher.

Bob Diachenko, Director of Cyber Risk Research at Hacken, discovered that the unsecured server was left visible online without a password exposing customers’ personal data like names, email addresses, phone numbers, and card details.

“On 23rd October I discovered an unprotected Mongo DB which allowed millions of records to be viewed, edited and accessed by anybody who might have discovered this vulnerability.  The records appeared to be from an American Express branch in India,” Bob Diachenko stated in a blog post. “It is important to note that no special programmes were used, and I located these records by simply using IoT search engines such as Shodan and the newly created BinaryEdge.io.”

Most of the exposed data was encrypted but included 2,332,115 records with customers’ names, addresses, Aadhar numbers, PAN card numbers, and phone numbers hosted on the domain americanexpressindia.co.in. Diachenko also stated that the server was maintained by a subcontractor and not by Amex. The issue was immediately reported to the American Express incident response team. The American Express clarified that the MongoDB database was securely encrypted, and they’ve not found any unauthorized access to the exposed data.

“We applaud AmEx’s rapid response to this issue, noting they immediately took down that server upon notification and began further investigations,” Diachenko added.

Equifax Hit with Maximum UK Fine—What Can, and Should, We Learn?

Equifax

Contributed By Tim Roncevich, Partner, CyberGuard Compliance

The United Kingdom issued the maximum fine to Equifax following their massive data breach in 2017.

But it could have been worse.

The £500,000 ($660,000) penalty accounted for only a minuscule percentage of the credit bureau’s $3.3 billion (£2.5 billion) in annual revenue. Regulators could have levied a larger fine if the General Data Protection Regulation (GDPR) had been fully implemented at the time of the breach, which affected as many as 15 million UK citizens.

Now that GDPR is fully in effect, a future breach could draw a fine of up to four percent of a company’s annual global revenue, or £17 million (20m Euro or $22 million), whichever is greater. Companies should consider Equifax’s punishment a warning of stiffer penalties that could come because regulators will maximize fines for data breaches. To put this in perspective, if Equifax had the GDPR’s maximum fine leveled against it, it could have cost them $132 million (£100 million). That’s a law with some serious teeth.

In announcing the fine for Equifax on Sept. 20, regulators with the Information Commissioner’s Office explained that the company was lax in its security and dismissive of its obligations for protecting consumer data. “Equifax Ltd showed a serious disregard for their customers and the personal information entrusted to them, and that led to today’s fine,” Information Commissioner Elizabeth Denham stated.

The average cost of a data breach is already $3.9 million, including damages, fines, and losses. Steeper penalties based on a percentage of revenue would only worsen the blow, even for the largest of corporations with the deepest of coffers.

Learn from the Equifax example. Adopt these cybersecurity measures if you haven’t done so already.

Read more

 

HSBC discloses cyber-attack affecting US customers

Smishing Campaign on HSBC

The Hongkong and Shanghai Banking Corporation recently revealed that some of its U.S. customers’ bank accounts were hacked in October this year. The bank stated the incident affected one percent of its American clients after cyber miscreants allegedly accessed customers’ names, addresses, date of birth, bank account numbers, account balances, statements, transaction histories, and payee details.

HSBC said it has temporarily suspended the internet banking access to the affected customers to prevent further loss and reported the incident to the California Attorney General’s Office.

“HSBC became aware of online accounts being accessed by unauthorized users between October 4, 2018 and October 14, 2018. When HSBC discovered your online account was impacted, we suspended online access to prevent further unauthorized entry of your account. You may have received a call or email from us, so we could help you change your online banking credentials and access your account,” HSBC stated in an official statement. “We apologize for this inconvenience. HSBC takes this very seriously and the security of your information is very important to us.”

Further, the banker stated that it has improved the authentication process of its online banking and is also providing the users with a complimentary subscription to credit monitoring and identity theft protection services.

“HSBC regrets this incident, and we take our responsibility for protecting our customers very seriously,” the bank said in a news statement. “We have notified those customers whose accounts may have experienced unauthorized access and are offering them one year of credit monitoring and identity theft protection service.”

In related news, the Britain-based Tesco Bank was recently slapped with £16 million ($21.4 million) fine for the cyber-attack it suffered in 2016. Nearly £2 million was stolen from 9000 customers using counterfeit cards, with over 40,000 accounts being compromised in the attack. According to the regulatory body Financial Conduct Authority (FCA), the Tesco Bank failed to exercise due skill, care, and diligence and protect account holders of its bank from a foreseeable cyber-attack, which occurred for over 48 hours in 2016.