Showing posts with label Theft. Show all posts
Showing posts with label Theft. Show all posts

Monday, November 28, 2011

Cyber Monday Means Loss of Productivity

As Black Friday has come and gone many consumers are excited for Cyber Monday. The only problem? Many Americans who plan to partake in the deals offered online are doing so at work. According to a recent survey done by the staffing firm Adecco,nearly half of American workers (46 percent) plan to make a dent in their holiday shopping during work hours – either through online shopping while at work, shopping on lunch breaks, taking sick days or cutting out a little early periodically. Another similar survey done by Randstad shows that 40% of employees plan to only spend an hour online shopping at work while 1 in 3 plan to spend over 5 hours of their work day shopping online.


The lure of online deals does not only pose a threat to productivity, but it can also expose the corporate network to malware. Malware and spam attacks are often quickly formulated and executed based on current events and popular online happenings. These malicious websites are found as links that are a part of common searches such as "Cyber Monday Deals". 


Since many people will be ordering online the use of online postal tracking will go up as well, because of this hackers will be sending postage and shipping related emails to trick people into downloading malicious attachments. Websense Security Labs cites this type of spam as one of the "Top 5 Malicious Spam Subjects" .


Security Labs has detailed the type of subjects and email contents everyone should be on the lookout for.

  • USPS Invoice copy ID46298 (numbers vary)
  • FedEx: New Agent File Form, trackid: 1V6ZFZ7FEOHUQ (numbers vary)
  • DHL Express Notification for shipment 90176712199 (numbers vary)
The email will look like this:
The moral of the story is to shop at home, be careful, and no matter how good the deal looks, do not suspend judgement to click on a strange looking link. Also remember that shipping companies will never require you to download an email attachment to get information about your packages and if you are still concerned, check their website for accurate and up to date information.


Monday, November 7, 2011

Advanced Persistent Threats -- Something to worry about or just another buzzword?

In recent months there has been increased discussion in the media about advanced persistent threats (APTs) and even more discussion about how to define an APT. McAfee defines an APT as a "targeted cyberespionage or cybersabotage attack that is carried out under the sponsorship or direction of a nation-state for something other than a pure financial/criminal reason or political protest." Other definitions are more broad describing an APT as a cybercrime category in which the attacker utilizes the full spectrum of attack vectors to reach and compromise the their target. 


Whatever definition is used often is the definition that best serves the main goal of the article or advertisement, which has lead many IT security professionals to put advanced persistent threats in the "buzzword" category. It seems that despite those non-believers almost two-thirds of enterprise information security managers believe their businesses have been targeted by advanced persistent threats and  72% expect to see such attacks continue in the future. These numbers are according to an Enterprise Strategy Group report on  advanced persistent threats. These managers believe that these attacks are being carried out, in order of likelihood, by hacktivist groups such as Anonymous, organized crime rings, competitors conducting reconnaissance or perpetrating industrial espionage, foreign governments, and terrorists.

Whether or not APT is just another catchy acronym we can see that based on the survey results, organizations are responding in the correct way. 51% of respondents said that senior executives have increased the amount of money allocated to training employees on security strategies, 33% now meet more frequently with their Chief Information Security Officer (CISO) or IT risk team and 18% have created the role of CSO or CISO, or another type of senior security position.  The trend of organizations to staff Risk and Security related positions, as direct report positions to the Board of Directors, continues to demonstrate the importance of integrating technology with business process.  Risk and Security of the organization and its critical technology infrastructure (uptime and productivity) and its confidential and sensitive data (GRC, Brand Loss, IP Loss) should be a fundamental to any best-practices organization.   


With the increasing sophistication of the threat matrix, reliance on under managed technologies (AV, IPS, IDS) is simply not enough.  As we continue to build more efficient and open B2B and B2C models, an organization must take into account the context of the information being accessed starting with the roles of people accessing that information, the sensitivity of the information, and the actual use of the information, and enforcement policies.   This takes coordination, via the CISO, of Executives, HR, Legal,  Technology , and Business Unit leaders.

Monday, August 22, 2011

Hacking Group Anonymous Breaches InfraGard

On August 18th hacking group Anonymous published documents stolen from Richard Garcia, senior vice president of Vanguard Defense Industries. The collection of documents contains internal meeting notes and contracts, schematics, non-disclosure agreements, personal information about other VDI employees, and several dozen 'counter-terrorism' documents classified as 'law enforcement sensitive' and 'for official use only.'


Mr. Garcia is also a director of U.S. defense contractor InfraGard, who was breached by one of Anonymous' affiliate hacking groups LulzSec. In the initial post by Anonymous, they state that Mr. Garcia's account was easily hacked because he had not changed some of his passwords after the InfraGard breach in June.


One of the most sensitive emails that was published contains a response from one of Vanguard's chief executives responding to a U.S. Department of Justice contact regarding the suitability of its ShadowHawk drones for use by U.S Marshals. There are also reports that there are documents that show evidence of a Merrill Lynch wealth management adviser giving private advance notice to Garcia about upcoming S&P US credit rating downgrades. This report has yet to be substantiated.



Monday, May 23, 2011

Massachusetts Executive Office of Labor and Workforce Development Breached

Client names, social security numbers, email addresses and residential addresses and bank account detail of users of the Massachusetts Executive Office of Labor and Workforce Development claim system. The 1,200 system users were warned that their personal details may have been accessed by a data-stealing worm named W32.QAKBOT.

Symantec defined the W32.QAKBOT as a worm that is capable of keylogging, collecting cookie data, DNS, operating system, private keys from system certificates and URLs. The virus can spread through a computer network, open a back door on a compromised computer that would allow someone to control the machine and keep itself hidden.

Although the problem has been fixed, Executive Office of Labor and Workforce Development is hoping people continue to use the system. It has been communicated that all possible steps are being taken to avoid future recurrence.

Monday, April 4, 2011

Marketing Firm's Customer Data Exposed by Hackers


One of the country's largest e-mail marketing firms, Epsilon, reported that on March 30th, “a subset of Epsilon clients’ customer data [was] exposed by an unauthorized entry into Epsilon’s email system."


Epsilon is a subsidiary of Alliance Data Systems and sends over 40 billion emails annually for their clients. These clients include 7 of the top Fortune 10 companies.

Companies whose clients may have been affected by this breach include:
Brookstone
Capital One Financial Corp.
Citigroup 
J.P. Morgan Chase & Co.
Kroger Co.
Marriott International Inc. 
McKinsey & Co.
New York & Co.
Ritz-Carlton
TiVo Inc.
US Bancorp
Walgreen Co.

The hackers were only able to access names and email addresses, and it is still unknown if the information has been used in any email based attacks aimed at obtaining credit card or social security numbers.

This attack reminds us to be vigilant and skeptical of all unsolicited emails or emails from unknown senders. Keep in mind the following tips next time you check your email:
  1. Under no circumstances should anyone respond to an email from an unknown or known party that asks for sensitive personal data. 
  2. If you receive an email from an unknown sender, delete it and mark it as spam in your email client. If you receive an email asking for personal or financial information from an organization that you are a customer of, notify their customer service office immediately.
  3. Also, do not click on links in email or pop-up messages that may come up after clicking a link in an email that asks for your personal or financial information. 
  4. Always use anti-spyware software and a firewall to protect your computer.
  5. Never open or download attachments from an email from an unknown sender.



Wednesday, March 30, 2011

Lost Laptop Exposes 13,000 Oil Spill Victims

According to a BP spokesman the laptop was lost on March 1 by an employee on routine business travel.


The laptop held unencrypted information including the names, Social Security numbers, addresses, phone numbers, and dates of birth of people who filed claims related to the Deepwater Horizon accident that occurred last spring.


"The lost laptop was immediately reported to law enforcement authorities and BP security, but has not been located despite a thorough search," BP said Tuesday. They added that the device was equipped with a tool that would allow them to disable the system under certain circumstances. No further details on the nature of the circumstances that would be required to be met were given.


Unfortunately lost laptops containing sensitive personal data are lost every day, and even more commonly when traveling. In Ponemon's "Billion Dollar Lost Laptop Study" the institution found that of laptops lost 46% contained confidential data, and only 30% of those laptops were encrypted, as shown below. Encryption is not the only method used to protect confidential data on a laptop, but it is one of the most easily implemented and trusted ways to protect your company's and customer's sensitive data.




Wednesday, January 12, 2011

Hot Topic: Smartphone Security

Cell phones have come a long way, from the Gordon Geckko 80's brick phone to today’s smartphones which are essentially pocket-sized computers.  Cell phones are no longer "just" a phone, they help us organize our lives, stay in touch via social networking, waste time. As more and more people adopt "smartphones" it is becoming an enticing frontier for hackers everywhere. Smartphone security is going beyond protecting against physical loss.  Many organizations that have employees who use smartphones to store company data often overlook simple security measures that are standard for any laptop or any other device with access to the internet.  

There are many companies that see this space for what it is, a relatively un-penetrated market with room for growth. Virtualization giant VMWare has partnered with smartphone manufacturer LG and they have begun building a smartphone with two virtualized machines, one for work and one for personal usage. These machines would be completely isolated from one another and allow an organization to support, distribute, and secure one type of smartphone while allowing employees to use the phone for personal use as well without risking exposing company data. Internet security firm Check Point Software found in a global survey that 64% of organizations are concerned that the growth in remote users will result in exposure to sensitive data and as a result are looking to encrypt and protect mobile devices. Smartphone manufacturers have also begun building proprietary encryption for their phones, or partnering with encryption companies. The gold standard for secure, encrypted smartphones is Blackberry which has been deemed secure for use in some of the highest levels of government.

Moral of the story is, protect yourself against these developing threats by installing anti-malware software on your smartphone and beware inherent threats when downloading mobile apps and clicking on mysterious links on social networking sites. Treat your cell phone like you treat your laptop, after all, the delineation between these devices is getting fuzzier and fuzzier.

Tuesday, January 4, 2011

Reported Data Breaches in 2010 - Numbers to Increase in 2011

In 2010, 662 breaches were reported exposing a total of 16,200,000 records. This equates to approximately 24,471 records per breach. Sixty-two percent of these breaches involved Social Security numbers and 26% of 2010’s breaches involved credit or debit cards.



The most common ways breaches occurred include hacking into computer systems (17%), theft or loss of laptops, flash drives (16.6%), insider actions (15.4%), and accidental exposure (10.7%).

According to an article published by Identity Theft Resource Center, an estimated 10% to 15% of breaches are actually reported. With cybercrime and data thefts on the rise, breaches will increase, but will the number of reported breaches also grow?  As state and federal government data breach regulations and PCI and FTC rules become more stringent and are enforced, we will likely see more publicized breaches.

Wednesday, December 22, 2010

New York Tourist Credit Card Information Hacked

110,000 credit card numbers of New York City tour patrons have been stolen by hackers using a SQL injection attack. SQL injection attacks are one of the oldest and simplest forms of internet attacks. The hackers were able to access names, addresses, e-mail addresses, credit card numbers with expiration dates and security codes.

The organization, CitySights NY, has begun notifying customers and offering them one year of free credit monitoring as well as a 50% off coupon for a future tour. A spokesperson for CitySights NY’s parent company, Twin America,  says that they are taking steps to improve data security. They have locked down server access and have installed application firewalls.

Tuesday, November 23, 2010

Hospital Fined $250,000 For Late Reporting of Data Breach


Lucile Salter Packard Children's Hospital at Stanford University has been fined $250,000 by California health officials for failing to report within five days a breach of 532 patient medical records in connection with the apparent theft of a hospital computer by an employee. 
Under state law, that amount is the maximum penalty allowed for failing to report such an incident, according to spokesman for the California Department of Public Health, Ralph Montano. The penalty is assessed at the rate of $100 for every day of delayed reporting after the first five days for each patient medical record that was breached, he said. 
Source: http://www.healthleadersmedia.com/page-1/TEC-256217/Hospital-Fined-250000-For-Not-Reporting-Data-Breach