Home Blog Page 391

US casino reveals patrons’ social security numbers due to “human error”

Casino breach

Personally Identifiable Information (PII) of some patrons of Graton Casino and Resort has been reportedly compromised. The casino said that an employee “accidentally” included customer information, such as, addresses and social security numbers in an attachment that was sent along with an undisclosed number of emails between February and August 2017.

While calling it a “human error”, Lori Nelson, Casino spokeswoman declined to announce it a “data breach” or a “hack”. The incident came to light on September 1, but with more than a month gone, the exact number of affected customers has not been disclosed yet.

Saying that casino officials regret any inconvenience caused by the release of information, Nelson added, “We place the integrity, safety, and trust of our relationships with our guests at Graton Resort and Casino as our top priority”.

In a two-page form letter, Casino officials said that it “discovered that certain personal information was inadvertently distributed in a small number of email attachments as ‘hidden’ information that could be revealed via certain manipulation by the recipients”.

“Upon discovering the situation, we immediately ceased distribution of the information, took steps to stop further distribution of the material and took steps to ensure it does not happen again,” the notice read.

The notice further advised affected patrons to “closely monitor your financial accounts and credit reports for fraudulent transactions.”

In an attempt to cover up its blooper, the casino is providing affected customers with a free one-year subscription to a credit monitoring service.

Whole Foods Market hacked; many customers affected

Whole Food Market

Whole Food Market, which was recently acquired by Amazon, was reportedly hacked last week. Hackers gained access to customers’ credit card information, who made purchases at some of its outlets.

In a press release, Whole Foods said, “When Whole Foods Market learned of this, the company launched an investigation, obtained the help of a leading cyber security forensics firm, contacted law enforcement, and is taking appropriate measures to address the issue”, while adding, “Amazon.com systems do not connect to these systems”.

The press release further stated, “Hackers targeted “point of sale systems” — or the machines where customers swipe or insert their cards — in order to steal the data”.

So far, the cyber attack-hit company has not revealed how many customers have been affected and not disclosed the locations targeted by hackers. The company also plans to update their customers about the ongoing investigation.

Whole Food Market also joins the high-profile list of recently hacked Sonic restaurants. The U.S. fast food chain suffered a major security breach which compromised its millions of customers’ debit card and credit card numbers. Around five million stolen credit and debit card accounts were put up for sale on an underground marketplace called Joker’s Stash, priced between $25 and $50 per piece, on September 18.

75% of Dutch not concerned about workplace cybersecurity

Dutch workplace cybersecurity

About 75 percent of Dutch people are unconcerned about cybersecurity at their workplace, a National Cybersecurity Awareness Study revealed. However, almost half of Dutch are concerned when it comes to ensuring cybersecurity at home, compared to 29 percent in 2016.

The study that was published in Alert Online also revealed that most of the employees were unaware of their company’s security procedures and half of the employees asserted that they have no information about online safety measures from their employer.

Most of the Dutch claim that they excellently tackle potentially dangerous cybersecurity issues but at the same time, some of them greatly underestimate the impact of various forms of cyber breaches.

Respondents estimated the risk of computer damage in all forms of cyber crimes at less than 15 percent. Around half of respondents said that they became more cautious after falling prey to a cyber attack and 20 percent took measures against cyber attacks.

Dutch people consider that emails with hyperlinks or infected attachments are most risky. About 55 percent of them said that hackers tried to trick them into phishing through their private email addresses. On the other hand, 39 percent of the people received a hacking attempt at their work email addresses.

Erik Jan Koedijk, chairman of Alert Online’s advisory board, said “Much less well known is that such links are also distributed through social media and messaging services such as WhatsApp, Facebook Messenger and Telegram”.

 

San Francisco sues Equifax, demands $2,500 per violation

Equifax breach

Equifax, which is under the scanner since its high-profile attack, now has one more reason to worry. San Francisco has sued the credit monitoring firm for failing to protect the personal data of 15 million Californian residents. The city’s Attorney Dennis Herrera on September 26 filed the lawsuit in San Francisco Superior Court on behalf of the state residents affected.

It has been alleged that Equifax violated state law pertaining to unlawful, unfair or fraudulent business practices by:

  • failing to implement and maintain reasonable security procedures
  • failing to provide timely notice of the breach to affected consumers
  • providing incomplete and difficult-to-understand information about the breach.

The lawsuit has demanded compensation for California consumers who purchased credit monitoring services from Equifax prior to Sept. 7, 2017, to the tune of $2,500 per violation. San Francisco becomes the first city in the U.S. to sue Equifax for compromising the personal information of 143 million consumers.

“Equifax made a bad situation worse”

Herrera said, “Equifax’s incompetence would be comical if the subject matter weren’t so serious,” while adding, “This company fell asleep at the switch and upended the lives of millions of people. The information that Equifax failed to safeguard is what people need to open a bank account, buy a home or rent an apartment. Now Californians have been put at risk of identity theft for years to come.”

Herrera also claimed that the credit reporting company discovered the massive data breach on July 29, 2017, but it alerted the consumers (some of them are based out of the U.S.) after six weeks on September 7, 2017.

“Equifax made a bad situation worse,” Herrera said while adding, “Their delay prevented more than 15 million California consumers from taking immediate action to protect themselves from the risk of identity theft and fraud.”

Amidst the turmoil, embattled Equifax gets a new CEO

Ironically, the lawsuit was filed on the same day when Equifax’s CEO Richard Smith “stepped down”, following the company’s chief security officer and chief information officer also retiring. Meanwhile, Paulino do Rego Barros Jr. has been appointed as interim chief executive as the company searches for a permanent replacement.

In an open letter titled, “On Behalf of Equifax, I’m Sorry”, published in The Wall Street Journal, Barros wrote, “On behalf of Equifax, I want to express my sincere and total apology to every consumer affected by our recent data breach. People across the country and around the world, including our friends and family members, put their trust in our company. We didn’t live up to expectations”.

While declining to comment on pending litigation, a spokesperson from Equifax told the media, “it wants to reassure consumers that we are remaining focused on helping them navigate the situation and providing the best customer support possible.”

Probe underway

The Department of Justice in Atlanta and the Federal Trade Commission have initiated an investigation into the massive data breach by Equifax. The credit reporting giant that faces more than 20 private breach-related lawsuits nationwide has also begun an internal investigation with FBI officials.

The breach, which reportedly took place in May to July this year, is considered serious as the data includes names, social security numbers, addresses, credit card numbers, and other financial details that could be used by criminals to steal people’s identities for financial gain.

Australia seeking to employ 11,000 cybersecurity experts

Cryptocurrency scams in Australia

In an effort to improve its online security and to keep growing cyber threats in check, Australia is seeking to employ over thousands of cybersecurity experts over the next decade, a report tabled by the Australian Cyber Security Growth Network (ACSGN) declared.

According to Australian cybersecurity experts, it is becoming difficult for governments to keep pace with the constantly evolving threat of cyberterrorism. While speaking to Australian Broadcasting Corporation (ABC) radio, ACSGN CEO Craig Davies said it was time for the government to encourage tertiary institutions to offer courses in cybersecurity.

Davies, a former chief security information officer with Australian software company Atlassian, was quoted as saying, “The demand for skills has outstripped anyone’s ability to produce skilled candidates in this space. It’s just a rocket ship, this industry, and we have zero unemployment and the demand is massive. Education and growing that skillset is important, and we’re working with the vocational sector very closely. We will certainly make a substantial dent in that (need of 11,000 employees).”

Patrick Walsh, vice president of cybersecurity company FireEye, said that in such a risky cyber landscape, further collaboration between the private and government cybersecurity sectors was needed to stay on top of the threat.

Meanwhile, coding expert Tim Edwards said that in a world which continues to rely on the Internet and computers, the art of coding needed to become “common knowledge” for young Australians.

A recent report published in ABC.net announced that Australia has been suffering due to shortage of cybersecurity professionals. One of the reasons cited behind the lack of skilled experts is immigration of some of the brightest professionals abroad to pursue better career opportunities and higher salaries.

In October 2016, Australian Bureau of Meteorology’s computer system was hacked by foreign spies to steal sensitive documents and compromise other government networks.

In April 2016, Australian Prime Minister Malcolm Turnbull launched Australia’s cybersecurity strategy that’s prime objective was to ensure more information was shared between government agencies and the private sector about cyber threats, and that universities were training “skilled cyber security professionals.”

 

Do not enforce new cybersecurity law, US tell China

U.S. and China

In an attempt to prevent any damage to global trade services, the U.S. has asked China not to implement its stringent cybersecurity law. China passed its new cybersecurity law in November 2016, but it came into effect in June 2017. The law prohibits service providers from recording and selling the personal information of Internet users.

In a two-page document submitted for debate at the World Trade Organisation (WTO) Services Council, the U.S. claimed that China’s new cybersecurity norms can have a huge impact on cross border services supplied through a commercial presence abroad.

“China’s measures would disrupt, deter, and in many cases, prohibit cross-border transfers of information that are routine in the ordinary course of business,” the U.S. document published by the WTO said.

The U.S. document further raised the concerns saying, “The United States has been communicating these concerns directly to high level officials and relevant authorities in China,” while adding it wanted to raise awareness among WTO members about the potential impact on trade. “We request that China refrain from issuing or implementing final measures until such concerns are addressed”, it said.

“The impact of the measures would fall disproportionately on foreign service suppliers operating in China, as these suppliers must routinely transfer data back to headquarters and other affiliates,” the U.S. document said. “Companies located outside of China supplying services on a cross-border basis would be severely affected, as they must depend on access to data from their customers in China.”

While addressing the WTO conference panel on September 26, Zhang Xiangchen, China’s Envoy to the WTO, said, “trade protectionism was an underestimated problem that was causing a crisis at the WTO”.

Rejecting United States’ allegation that China was guilty of protectionism, Xiangchen told Reuters, “There’s no definition of protectionism and each member has his own legitimate right to adopt a trade policy legally in the WTO system. But we have to be cautious to say which one is (legal within the (WTO) … and which is illegal.”

China, which has been a member of WTO since December 11, 2001, is seeking to require companies to store all data within China and pass security reviews, fitting China’s ethos of “cyber sovereignty”.

In China, search engine and social media including Google and Facebook are banned, as the country maintains a strict censorship regime.

Sonic Drive-In card breach puts millions of customers at risk

Sonic Inn

The U.S. fast food chain Sonic Drive recently suffered a major security breach which compromised its millions of customers’ debit card and credit card numbers. Around five million stolen credit and debit card accounts were put up for sale on an underground marketplace called Joker’s Stash, priced between $25 and $50 per piece, on September 18.

The news was first reported by security expert Brian Krebs on September 26, on his personal blog website KrebsOnSecurity. The breach was reported from Oklahoma-based Sonic Drive-In branch.

Krebs reported, “The accounts apparently stolen from Sonic are part of a batch of cards that Joker’s Stash is calling ‘Firetigerrr,’ and they are indexed by city, state and ZIP code”.

The price of the stolen cards depended on many factors, including the type of card issued, the card’s level, whether the card is debit or credit and the issuing bank.

Sonic Drive-In, which runs 3,600 food outlets across 45 states, was notified by its credit card processor of “fraudulent activity” related to its credit cards. Two sources, who purchased a handful of cards from the theft bazar, confirmed to Krebs that all those cards were previously used at Sonic. After getting the tip-off, Krebs passed the information to Sonic.

In a statement, the company said, “The security of our guests’ information is very important to Sonic”, while adding “We are working to understand the nature and scope of this issue, as we know how important this is to our guests. We immediately engaged third-party forensic experts and law enforcement when we heard from our processor. While law enforcement limits the information we can share, we will communicate additional information as we are able.”

“The probe is going on in its initial stages, and the company has still no count of how many or which of its stores may be impacted,” said Christi Woodworth, vice president of public relations at Sonic.

While reacting on the incident, Dan Berger, president and CEO of the National Association of Federally Insured Credit Unions, told Krebs, “These big card breaches are going to continue until there’s a national standard that holds retailers and merchants accountable”.

Meanwhile, Fortune reported on September 27 Sonic’s stock plunged to its lowest value in two months, after credit and debit card hack was confirmed. The company’s shares dropped by at least 4.4% to $23.52, the biggest drop within one day since August 8.

Cyber crime costs $11.7 million per organization every year: Report

Cyber crime, cyber espionage

Accenture and the Ponemon Institute conducted a new study titled, “The Cost of Cybercrime” that indicated cyber crime incidents cost an organization $11.7 million per year on an average. The study had 2,182 security and IT professionals across 254 organizations participating.

“Over the last two years, the accelerating cost of cyber crime means that it is now 23 percent more than last year and is costing organizations, on average, US$11.7 million,” the report said. The cost has increased by 23% since 2016 and 62% over the past five years.

Researchers concluded that on an average, each company experiences 130 breaches per year. The number has risen by more than 27 percent since last year.

The study focused on four major impacts of cybercrime: information or data loss, revenue loss, equipment damage, and business disruption. According to the report, 43 percent of respondents said that information loss is most damaging. “It is this threat landscape that demands organizations reexamine their investment priorities to keep pace with these more sophisticated and highly motivated attacks,” the report said.

The most expensive cyber attacks are malware infections which cost global businesses $2.4 million per incident, followed by Web-based attacks, which cost $2 million per incident globally. The hardest hit sectors this year include financial services and energy with average annual costs of $18.28 million and $17.20 million, respectively.

Australia reports the lowest total average cost from a cyber attack at $5.41 million, while the United Kingdom had the lowest change over the last year from $7.21 million to $8.74 million. Japan experienced a 22 percent increase in costs to $10.45 million – the third highest increase of the countries in the survey.

The report suggested following three steps the organizations can take to improve the effectiveness of their cybersecurity efforts to fend off and reduce the impact of cyber crime:

  1. Build cybersecurity on a strong foundation: invest in the ‘brilliant basics’ such as security intelligence and advanced access management and yet recognize the need to innovate to stay ahead of hackers.
  2. Undertake extreme pressure testing: Organizations should not rely on compliance alone to enhance their security profile but undertake extreme pressure testing to identify vulnerabilities more rigorously than even the most highly motivated attacker.
  3. Invest in breakthrough innovation: Balance spend on new technologies, specifically analytics and artificial intelligence, to enhance program effectiveness and scale value.

IOActive review on popular mobile apps opens a can of worms

vishing attacks

In what can be described as a major threat, a security firm has warned that popular mobile stock trading applications are riddled with vulnerabilities, spelling more trouble for them.

Security vendor IOActive recently reviewed 21 of the most used mobile apps for investment trading on Google Play and Apple Store. It was revealed that majority of them were exposing millions of users worldwide to various security risks.

The applications enable users to do a variety of things from buying and selling stock to funding accounts, keeping track of equity and available buying power as well as creating alerts for specific thresholds.

“I tested the 14 security controls, which represent just the tip of the iceberg when compared to an exhaustive list of security checks for mobile apps,” said Alejandro Hernandez, senior security consultant for IOActive. “The exercise showed that some of the most well known and most used mobile trading apps are even more insecure than some personal banking apps were back in 2013 when IOActive conducted similar tests”.

Hernandez further added, “The user would never have to see the logging console, but for attackers with physical access to the phone it’s a gold mine. Data in the log files can also be read by other applications, including malware, thereby opening a way for remote data exfiltration”.

“On the other hand, if the phone is stolen or lost, it’s easy to extract valuable information, such as the investment portfolio and money balances,” Hernandez warned.

Painting a bleak picture overall, the sensational review brought forward following weaknesses:

  • Only one trading app supports “Privacy Mode,” which protects the customers’ private information displayed on the screen in public areas where shoulder-surfing attacks are feasible.
  • At least four of the applications stored the user’s password in plaintext without encryption in either a configuration file within the phone or in the logging console.
  • More than 60 percent of the apps sent sensitive data to log files, and 67 percent stored it unencrypted.
  • In two applications, an unencrypted HTTP channel was used for authentication in addition to logging the username and password.

During the review, it was also found out that 10 of the applications were configured to execute JavaScript code, giving attackers a way to trigger Cross-Site Scripting attacks.

Most of the applications that were reviewed had sensitive data like cryptographic keys and third-party service partner passwords hardcoded in the apps, while 10 had sensitive and confidential data, such as internal hostnames and IP addresses of the internal environments where the apps were developed or tested.

As a part of their action plan, IOActive has reportedly notified the details of its research findings to 13 brokerage firms whose trading applications had high-risk flaws. The company said that only two firms have responded so far.

Mission Solutions Group acquires Surveillance and Cyber Security Services LLC

Acquisition

Mission Solutions Group (MSG), a Veteran Owned Small Business (VOSB), recently announced that it has successfully completed the acquisition of Surveillance and Cyber Security Services LLC (SCSS) that provided cybersecurity services to a wide variety of government customers.

Kevin Ferraro, MSG’s COO said, “We are extremely pleased to have finalized our acquisition of SCSS and we are excited about bringing its capability into the MSG family. Jim and the team he has built at SCSS will be a foundation piece of our cyber business and will decisively position us in the ever-growing cyber security market”.

Jim Rogers, SCSS’ founder and president said, “I am very excited about becoming part of MSG and am looking forward to being able to take the next step in capitalizing on the success we’ve experienced to date by expanding our ability to help protect our customers’ information and data. Helping to protect our government’s assets from cyber attack has been our mantra since we stood the company up, and now we will be able to do this for more and more customers”.

Mission Solutions Group Inc., a Delaware Corporation was founded in 1998. It is a family of premier companies that provides dedicated mission critical support around the world in two focused areas- C4I/SATCOM and Sustainment. MSG deals with three companies namely- Marshall Communications, Sidecar Enterprises and Blue Jay Products.