Home Blog Page 396

Cybersecurity division of CBA moving out of Australia

Commonwealth Bank

Amid the growing concerns over its capability to monitor fraudulent transactions and also as a measure to cut expenses, Commonwealth Bank of Australia (CBA) is moving critical cybersecurity operations to an undisclosed offshore location. It is heard on the grapevine that the offshore location may be India.  A substantial part of the information technology division will also be moved. The bank has already called a tender to move the staff and several departments.

“Commonwealth Bank works with a number of different global and local IT partners. We’re always looking for ways we can work more effectively with them and use their expertise and we will always safeguard system integrity, security and information,” a spokesman for the CBA who confirmed the tender told The Australian. “When we make these decisions, it is driven by our thinking on what is the best workforce mix, and we assess that on several factors including expertise, skills and expense management.”

The move comes after Ben Heyes’s exit and Yuval Illuz replacing him as the chief information security and trust officer. Illuz has also been responsible for some top-level reshuffle within the organization post taking the office.

Earlier, the Federal Court had issued a notice to the CBA over its failure to report more than 53,000 large cash deposits. According to Australian Transaction Reports and Analysis Centre which served the Federal Court action to the bank, the undisclosed cash may have facilitated money laundering and financing terrorism. A report by The Australian had revealed that “billions of dollars worth of transactions in the US, Europe and Asia were not being monitored which could put the bank in the firing line of global regulators.” The bench which reviewed the bank’s compliance frameworks pointed out that several top levels CBA officials were aware of the large-scale gaps within the organization.

CBA always has taken information technology and cybersecurity very seriously. It is an active advisor to the government. “It was a founding participant in the government’s inaugural Joint Cyber Security Centre, launched in Brisbane in 2017, and established a scholarship program with the University of NSW to increase the number of local graduates and professionals for an industry that has exploded in recent years.”

Under the aegis of Ben Heyes, CBA’s IT expenses saw a jump to 31 percent in 2016-17. But the appointment of lluz hasn’t gone well with several industry experts who think lluz doesn’t have desired expertise in the banking industry as well as Australian market.

Irish expert calls for Anglo-Irish cyber taskforce

Irish cybersecurity expert Paul C. Dwyer has called for an Anglo-Irish Cyber Task Force in the wake of Brexit negotiations that, according to him, are not addressing the “the concerns of the digital community and digital borders on matters relating to cybersecurity and data protection.” Dwyer is the President of the International Cyber Threat Task Force, an online community consisting 4,000 business professionals from more than 100 countries. Formed seven years ago, the community works toward “protecting children, individuals, small businesses, NGOs, enterprises and supporting the efforts of military and the global law-enforcement community”.

Dwyer emphasized on the problems that Brexit could bring to business and cybersecurity communities. Brexit’s implication on the existing laws governing professionals in cybersecurity, privacy, and data-protection sectors is a major concern among these communities.

““Many Irish and UK businesses don’t want to bet on the negotiations between the EU and the UK going well. The awareness among these businesses of the threats posed by cyber criminals is growing rapidly. The overwhelming array of sophisticated cyber attack techniques and the sheer amount of cyber criminals combined with a potential legal impotency post-Brexit is a real concern for many businesses,” he said.

He suggested a joint cross sector approach be taken by the joint cyber task force with Ireland taking the lead in handling the challenges arising from Brexit as well as new EU cyber legislation. A combined effort of the task force and the governments would help in protecting businesses in Ireland and the UK.

Wells Fargo discovers 1.4 million additional fake accounts

A company investigation by Wells Fargo revealed that 1.4 million fake accounts may have been created by its employees. The accounts, created between January 2009 and September 2016, were discovered during the company’s investigation of 165 million retail banking accounts. This is in addition to 2.1 million fake accounts that were discovered by the company in an investigation of 93 million accounts.

To create the fraudulent accounts, employees accessed customers’ personal details and created fake email addresses. The accounts were also enrolled in different online banking platforms. Debit cards and PINs were also issued to the customers.

The scam affected 130,000 customers as they were charged with fines for having insufficient funds and overdraft fees on the fake accounts. Also, more than 60,000 people were wrongly charged finance and interest charges. Wells Fargo said the victims will be reimbursed.

The phony account scandal has already cost 5,300 Wells Fargo employees their jobs over the years. It also forced the company to replace John Stumpf with Tim Sloan as the CEO. Sloan said, “We apologize to everyone who was harmed by unacceptable sales practices that occurred in our retail bank.”

Last year, the Consumer Financial Protection Bureau slapped Wells Fargo with $185 million in fines for fake accounts.  It said, “Spurred by sales targets and compensation incentives, employees boosted sales figures by covertly opening accounts and funding them by transferring funds from consumers’ authorized accounts without their knowledge or consent, often racking up fees or other charges.”

More than 700 million email addresses leaked by misconfigured spambot

A misconfigured spambot leaked more than 700 million email addresses and millions of passwords in a massive data breach. Considered to be one of the largest data breaches ever, the leak contains almost twice the records than those contained in the River City Media breach.

Since the spammers failed to secure one of its servers, almost 711 million records of email addresses were available to visitors for download without needing any credentials. However, the actual number of people affected could be lower due to fake, malformed, and repeated email addresses present in the database. Also, some of the email addresses are incorrectly scraped from the internet, while others could be the result of guesswork.

A blog post in “Have I Been Pwned” website by an Australian computer security expert Troy Hunt said, “The one I’m writing about today is 711m records, which makes it the largest single set of data I’ve ever loaded into HIBP. Just for a sense of scale, that’s almost one address for every single man, woman, and child in all of Europe.”

Millions of passwords are contained in the breach because the spammers reportedly tried to collect information that could be used to break into users’ email accounts and spread spam under their names. However, Hunt said that some passwords may be from previous breaches.

Hunt further added, “Finding yourself in this data set unfortunately doesn’t give you much insight into where your email address was obtained from nor what you can actually do about it. I have no idea how this service got mine, but even for me with all the data I see doing what I do, there was still a moment where I went ‘ah, this helps explain all the spam I get’.”

OurMine group hacks WikiLeaks to answer “Hack Us” challenge

Julian Assange, Julian Assange indictment

The anonymous hacking group OurMine recently hacked WikiLeaks, the data-leaking site owned by Julian Assange. The users of the website were redirected to a page that claimed the attack was a response to a challenge from WikiLeaks to hack them. The message on the redirected page said, “Hi, it’s OurMine (Security Group), don’t worry we are just testing your…. blablablab, oh wait, this is not a security test! Wikileaks, remember when you challenged us to hack you? Anonymous, remember when you tried to dox us with fake information for attacking WikiLeaks? There we go! One group beat you all! #WikileaksHack let’s get it trending on twitter!” This is the third time OurMine hackers have breached WikiLeaks after the two denial-of-service (DDoS) attacks in December 2015 and July 2016.

The attack by OurMine hackers seems to be a low-tech affair, as the security breach is carried out by “DNS poisoning” through WikiLeaks domain provider. DNS poisoning attacks connect to the actual DNS servers to change the location of the website to a redirected server. Apparently, WikiLeaks own servers were not breached.

The hacks by OurMine generally follow the same style. The attackers find the reused passwords of previously compromised accounts and test them on different services till they find the one that works. The group then posts a message claiming the attack to test the victim’s security and links it to the hackers’ website, which offers penetration testing for $30 onwards.

Post the recent WikiLeaks attack, one member of Ourmine tweeted, “they challenged us to hack them about a few months ago, and we’ve been working on this hack for a very long time, and finally we did it! It’s hacked! … We are working to obtain new secret things/emails from WikiLeaks but for now, we are only able to receive new messages that have been sent to [the Wikileaks press contact].”

Other than WikiLeaks, OurMine group has hacked social media accounts of Mark Zuckerberg, Dick Costolo, Jack Dorsey and Sundar Pichai, and website like BuzzFeed. The group had also breached the twitter account of FC Barcelona, Real Madrid C.F., and HBO.

Cyber attack on IT marketplace CeX; two million customer records stolen

In a recent cyber attack on second-hand electronics dealer CeX, the hackers may have stolen personal details of as many as two million customers. The stolen data include names, email addresses, phone numbers, and, in some cases, passwords. The passwords were hashed by the company but it warned the users to change the reused passwords as a weaker password can still be vulnerable.

The hackers were able to access some of the credit and debit card data but the company ruled out the occurrence of any problem saying that in all likelihood the cards have expired as the store had stopped taking that data since 2009. The breach did not impact the company’s physical stores.

CeX did not elaborate on the details of the hacks as they are still investigating the incident. CeX released a statement that said, “We take the protection of customer data extremely seriously and have always had a robust security programme in place which we continually reviewed and updated to meet the latest online threats. Clearly, however, additional measures were required to prevent such a sophisticated breach occurring, and we have therefore employed a cybersecurity specialist to review our processes. Together we have implemented additional advanced measures of security to prevent this from happening again.”

India, EU reaffirm their cyber ties

India and the European Union (EU) have reaffirmed their commitment toward working for “open, free, secure, stable, peaceful, and accessible cyberspace, enabling economic growth and innovation.” The announcement was made at the Fourth India-EU Cyber Dialogue which was held in New Delhi on August 29, 2017.

The Indian contingent at the Cyber Dialogue was led by Sanjay Kumar Verma, Officer on Special Duty (Administration), Ministry of External Affairs. Verma was accompanied by representatives from the Ministry of Electronics and Information Technology, National Security Council Secretariat, Central Bureau of Investigation, Department of Telecommunication, National Critical Information Infrastructure Protection Centre and the National Investigation Agency. Herczynski Pawel, Director for Security Policy, European External Action Service was the European counterpart. Pawel was accompanied by representatives from European External Action Service and officials from the EU Delegation in New Delhi.

“India reaffirmed that the existing principles of international law are, in general, applicable in cyberspace and that there was a need to continue and deepen deliberations on the applicability of international law to cyberspace and set norms of responsible behavior of states,” stated a release from the Ministry of External Affairs (India). “It also emphasized the significance of various regional, international and multilateral initiatives, particularly those initiatives where UN plays a key role, to continue the debate on these issues as well as in Cyber capacity building.”

The focus areas of the discussion were domestic policies of the two regions, bilateral cooperation, threat management and mitigation, cyber governance, and “possible cooperation at various international fora and regional fora.”

The discussion was also a curtain raiser to the 5th Global Conference on Cyber Space which is scheduled to be held in New Delhi between November 23 and 24, 2017. It was also announced that the next India-EU Cyber Dialogue will be held in Brussels in 2018.

FDA instructs pacemaker recall due to cyber vulnerabilities

The Food and Drug Administration of the United States of America recently issued an alert stating that a total of 745,000 pacemaker devices by Abbott Laboratories are vulnerable to hacks and need a firmware update. The radio-frequency enabled devices are marketed by Abbott under brand names Accent, Anthem, Accent MRI, Accent ST, Assurity, and Allure. The patients using the devices have been asked to talk to their health care providers regarding firmware update and cybersecurity vulnerabilities. The FDA revealed that 465,000 pacemakers are affected, while Abbott revealed another 280,000 affected devices.

Abbott said that hacking the pacemaker device would require a complex set of circumstances for any unauthorized access. The Department of Homeland Security supported the claims made by Abbott and said that only an attacker “with high skills” could exploit the vulnerability.

There have been no reports of patient harm until now, however, if the pacemaker is left unpatched, it could be accessed using commercially available equipment. An unauthorized user may also be able to “modify programming commands to the implanted pacemaker, which could result in patient harm from rapid battery depletion or administration of inappropriate pacing,” according to FDA. Patients are asked to return devices not in use while those already have an implant should seek medical attention in cases of low-battery alert, FDA said.

The latest firmware update should take around three minutes and is done by placing the pacemaker close to a radio wave-emitting wand. During the process, the device operates in a backup mode and regulates the heart at 67 beats-a-minute.

This is the second instance of updates announced by Abbott since it acquired St. Jude Medical early this year. Last year, 400,000 heart devices suspected of pacing at potentially dangerous rates or failing due to premature battery depletion were recalled by St. Judy in a separate incident.

UK infrastructure not meeting basic cybersecurity standards, survey reveals

Businesses in U.K. Become More Resilient to Cyberattacks: Report

Corero Network Security, a company that provides DDoS & Network Security Solutions, recently sent Freedom of Information requests to a number of United Kingdom infrastructure organizations to know whether they meet the basic cybersecurity standards issued by the UK government. The responses to the requests were not very encouraging. Corero revealed that more than one-third of the national critical infrastructure organizations failed to meet the basic standards.

The requests were sent in March 2017 to 338 organizations that included fire and rescue services, police forces, ambulance trusts, NHS Trusts, energy suppliers and transport organizations, out of which only 163 organizations responded. Among those who responded, as many as 63 organizations (39 percent) admitted of not completing the “10 Steps” program published by the National Cyber Security Center of UK. Only 58 percent of NHS Trusts completed the scheme. Many organizations that did not respond cited national security as the reason for withholding information.

The findings suggest the lack of resilience among many of the key organizations against the growing and advanced cyber threats. According to Corero, the organizations are “leaving their doors wide-open for malware or ransomware attacks, data theft or more serious cyber attacks” by avoiding the detection and investigation of brief denial-of-service (DDoS) attacks against them. Moreover, only eight organizations (five percent) responded in affirmation when asked, “Have you suffered Distributed Denial of Service (DDoS) cyber attacks on your network in the last year?”

Earlier the government had proposed the implementation of the EU’s Network and Information Systems (NIS) directive and released a guideline to protect organizations from any possible cyber attack. It also proposed imposing fines of up to £17m, or four percent of global turnover to be imposed on the liable critical infrastructure organizations in case of any breach.

 

Ransomware named Defray on the loose

ransomware, ryuk ransomware, cox media

Yet another ransomware is making the rounds. Dubbed Defray, the ransomware is targeting the education, healthcare, manufacturing, and technology sectors.

According to Proofpoint, a cybersecurity firm specializing in advanced threats and compliance risks, this ransomware is highly targeted. It carries out small attacks on specific industry verticals rather than broad attacks on general consumers. So far it appears to be targeting companies in the United Kingdom and the United States.

Defray distributes emails that contain a bogus Microsoft Word attachment embedded with an Object Linking and Embedding (OLE) shell object. If the user clicks on attachment, encryption takes place.

After launching, the ransomware sends a limited number of messages demanding a ransom of $5,000 for the encryption key that will return access to data. So far attacks have been launched on August 15 and 22, with email impersonating third parties as bait. One attack was camouflaged as a message from a hospital director of information management and technology and the other from an aquarium in the United Kingdom.

Unlike other recent ransomware products, Defray does not appear to be on for sale. Not only does Defray encrypt data, but it appears it might also be capable of disabling startup recovery and deleting copy volumes of the original data as well. It is highly advisable to keep backup files offline to prevent this further attack on data.