::Trend Micro Threat Resource Center::

Showing posts with label data theft. Show all posts
Showing posts with label data theft. Show all posts

17 November 2015

Most Small UK Businesses Have No Security Oversight

Smaller UK businesses typically don’t assign an employee to be responsible for information security education and implementation—and are becoming fraud victims as a result.


As detailed in its State of the Industry report, appropriately-named information destruction expert Shred-it has found that nearly half (46%) of small business owners have no employee responsible for managing data security issues internally. Even more concerning, more than a quarter (27%) of small businesses do not have information security policies and procedures in place at all.

And, a third of those who do have policies in place admit to never training their employees on their protocols.

If data security is not made a priority, businesses are left exposed to data breaches, fraud, heavy legal fines from the Information Commissioner’s Office (ICO) and other regulatory bodies, and loss of customers and business partners—all of which can cause irreversible damage.

Since April 2010, the ICO has issued over £7 million worth of fines to organizations that have experienced a data breach. Despite such high figures and the irreversible damage to a company’s reputation as a result of a breach, businesses are still not doing enough when it comes to data security, the report concluded.

In addition to appointing a data protection officer, companies can reduce the risk of workplace fraud by implementing a few best practices. For instance, surprise audits: Conduct unscheduled workplace audits to assess how employees process, store and destroy confidential information.

Frequent training on the risks of fraud and how to prevent it is also important, along with education about vulnerable areas in which to avoid leaving confidential information in the office and off-site.

Shred-it is also calling on the UK government to implement legislation to ensure all businesses have a dedicated employee responsible for raising awareness of the importance of data security, understanding changes to legislation and enforcing data security procedures in the workplace.

“There is a strong correlation between data security practices and data breaches. Introducing legislation which mandates an employee specifically responsible for raising awareness of data security in the workplace and implementing a ‘culture of security’, will help protect businesses  against fraud and help them avoid financial or legal penalties,” said Robert Guice, SVP, EMEA, Shred-it.

To ensure all companies in the UK follow similar standards in data protection compliance, Shred-it has also urged the government to introduce legislation which ensures organizations have dedicated employees responsible for managing and monitoring data security issues on a day-to-day basis.

30 August 2015

Deaths linked to Ashley Madison Hack


The data breach at Ashley Madison has escalated (with juicy data dumps!), and is feared to have driven two more people to suicide, following a Texas resident taking his own life last week.

Previously covered here and here

21 August 2015

Ashley Madison 2.0 - Hackers Leak 20GB Data Dump, Including CEO's Emails

The group of hackers behind the breach of Ashley Madison, the popular cheater's dating service, have released a second, even much bigger 'cheat sheet' exposing sensitive materials that include sensitive corporate information.


Two days ago, the hackers released nearly 10GB of its customers' personal data online, which included 36 million emails and hashed passwords, 9.6 Million Credit Card Transactions records and their associated usernames.

Nearly 20GB of Ashley Madison Internal Data LEAKED
This time, the Impact Team leaked nearly 20GB worth of what appears to be internal data – not customers' data – from the adultery website on the dark Web
.
The leaked data appears to include the source code for the site, as well as a massive amount of e-mail from Ashley Madison parent company's Avid Life Media CEO Noel Biderman.
According to the researcher, who analysed the leaked data, the TL;DR of the leak is:

  • The leak contains lots of Source Code
  • 73 different git repositories are present
  • Ashley Madison used gitlab internally
  • The 13GB compressed file appears to contain Ashley Madison CEO's emails seems corrupted
  • The leak contains plain text or poorly hashed (md5) db credentials

Personal Emails of Avid Life Media CEO Noel Biderman Exposed
The trove of information was dumped with a taunting message to the adultery website's founder posted on the same dark web hosting the earlier data dump. The message reads:

"Hey Noel, you can admit it's real now." – presumably directed at CEO Noel Biderman, who has refused to recognize the data is all legitimate.


Dave Kennedy, the founder of cyber security company TrustedSec LLC, has analysed the second data dump and confirmed that it contained nearly 1GB of Biderman's emails.

"The dump appears to contain all of the business/corporate e-mails, the source code for all of [Avid Life Media's] websites, mobile applications, and more," TrustedSec wrote in its official blog post published yesterday.

This is really interesting; having the complete source code to these websites means that hackers now are capable of finding new security holes in Avid Life's websites, and further compromise them more.

However, we have yet to wait for a response to this new release from Avid Life Media officials. If they do, this post will be updated accordingly.

24 July 2015

Adult Dating Website Ashley Madison Hacked; 37 Million Accounts Affected

Life is short. Have an affair," but always remember "Cheaters never prosper."

AshleyMadison.com, an American most prominent dating website, that helps married people cheat on their spouses has been hacked, potentially putting very private details of Millions of its users at risk of being exposed.


The Stolen personal data may include information from users’ real names, addresses and their personal photographs to credit card details and sexually explicit chat logs.
With a Huge Database of over 37 Million users, AshleyMadison.com, owned by Avid Life Media (ALM) company, is a very popular dating website that helps married people have extramarital affairs.

Cougar Life and Established Men, two other dating sites also owned by Avid Life Media, have also had their data compromised.

The Hacker group responsible for the hacks called itself "The Impact Team," a company spokesperson confirmed.

The group apparently raises an objection to the website’s morally dubious business model and were threatening the company to release all its customer records if the Ashley Madison and Established Men are not completely shut down.

The Impact Team claims to have complete access to not only personal account information of the company’s customers, but also their secret sexual fantasies and matching credit card transactions, names, residential addresses, employee documents and emails.

Reason behind the Ashley Madison Hack
The Impact Team of hackers appears to be upset over a website's service called "Full Delete" that promises to erase a customer's profile and all associated data for a $19 fee completely.
However, according to the Impact Team, Ashley Madison made money from the paid "Full Delete" service that does not work.

"Full Delete netted [Avid Life Media] $1.7mm in revenue in 2014. It’s also a complete lie," the group wrote in a statement released Sunday. "Users almost always pay with the credit card; their purchase details are not removed as promised and include real name and address, which is, of course, the most important information the users want to be removed."

The company denied the claims, however, is now temporarily offering its customers the ability to delete their account completely from the website free of charge.

If you are Ashley Madison customer, You should Worry
Avid Life Media is working with law enforcement agencies to investigate this criminal act and also using Digital Millennium Copyright Act to get the personal data the hackers have disclosed so far removed from the Internet.

However, It’s unlikely to be a prevention measure, because once the personal data has been publicly exposed over the Internet, it becomes almost next to impossible to stop its spread.

07 February 2015

Espionage app targets iOS devices

Trend Micro has discovered an interesting poisoned pawn - spyware specifically designed for espionage on iOS devices. While spyware targeting Apple users is highly notable by itself, this particular spyware is also involved in a targeted attack.


The iOS malware found is among those advanced malware and it is believed the iOS malware gets installed on already compromised systems, and it is very similar to next stage SEDNIT malware Trend Micro found for Microsoft Windows’ systems. Two malicious iOS applications were found in Operation Pawn Storm. One is called XAgent and the other one uses the name of a legitimate iOS game, MadCap. XAgent is designed to work specifically with iOS7, which is still in one of every 5 iPhones and iPads. Fortunately, for iOS 8 devices, the user will see multiple notifications that the phone is trying to install an app. And it can’t run without the user launching. Both tools have the ability to record audio, which is very intrusive, and highly suggests the targeting of offline and confidential information.

Following analysis, Trend Micro concluded that both are applications related to SEDNIT – which is a spyware that aims to steal personal data, record audio, make screenshots, and send them to a remote command-and-control (C&C) server. Some of the data theft capabilities include:

  • Collect text messages
  • Get contact lists
  • Get pictures
  • Collect geo-location data
  • Start voice recording
  • Get a list of installed apps
  • Get a list of processes
  • Obtain Wi-Fi status

There may also be other methods of infection that are used to install this particular malware. One possible scenario is infecting an iPhone after connecting it to a compromised or infected Windows laptop via a USB cable.

For a more detailed analysis of the spyware, read here.

Background of Operation Pawn Storm
Operation Pawn Storm is an active economic and political cyber-espionage operation that targets a wide range of entities, like the military, governments, defense industries, and the media.

The actors of Pawn Storm tend to first move a lot of pawns in the hopes they come close to their actual, high profile targets. When they finally successfully infect a high profile target, they might decide to move their next pawn forward: advanced espionage malware.

The iOS malware we found is among those advanced malware. We believe the iOS malware gets installed on already compromised systems, and it is very similar to next stage SEDNIT malware we have found for Microsoft Windows’ systems.

05 January 2015

If Your iCloud Password Is On This List, Change It Before You Get Hacked



Somebody just uploaded a password-hacking tool called iDict to GitHub that promises to use good old fashioned brute force techniques to crack iCloud passwords. The tool also claims to be able to evade Apple's rate-limiting and two-factor authentication security that's supposed to prevent brute force attacks. But it's not quite as bad as it sounds.

iDict's capabilities are limited by the size of the dictionary it uses to guess your password. So you're really only in danger if your password is on the 500-word-long list included with the hacker tool. All of the passwords fulfill the requirements for an iCloud password, but if you're using one of these rather obvious passwords, you should change your password anyways. Here are some examples:

  •     Password1
  •     P@ssw0rd
  •     Passw0rd
  •     Pa55word
  •     Password123
  •     ABCabc123
  •     Devil666
  •     Fuckyou2
  •     ILoveYou2
  •     Blink182

These are the same kinds of passwords that appear almost every year on the most popular password list, making it stupid simple for hackers to wreak havoc. They also follow a lot of the bad password practices we've pointed out before. So for God's sake, change your password if you use a bad password! And if you haven't already, you should also enable two-factor authentication on all your accounts, just for good measure.

All that said, iDict isn't really a plug-and-play hacking device. The developer behind the tool isn't a friend to script-kiddies, he's trying to prove a point: Despite security updates since the brute force attack that gave hackers access to countless celebrities' nude photos, iCloud still isn't completely secure. Apple needs to fix the "painfully obvious" bug before it's "privately used for malicious or nefarious activities," he explains on GitHub. We've reached out to Apple to find out what they're doing about the vulnerability.

It seems like it wouldn't be that hard to swap out the 500-word-long list with an even longer, better list. Then, a tool like iDict could do real damage. Not to mention that ne'er-do-wells are probably gonna be using this tool as-is until the flaw gets fixed. So double-check your iCloud password against this list now, and pick something better even if your bad password isn't listed. Protect yourself while Apple's still working on shoring up that security.

28 December 2014

Hackers leak 13,000 Passwords Of Amazon, Walmart and Brazzers Users

Hackers claiming affiliation with the hacktivist group "Anonymous" have allegedly leaked more than 13,000 username and password combinations for some of the worlds most popular websites, including Amazon, Xbox Live and Playstation Network.

The stolen personal information was released in a massive text document posted to the Internet file-sharing website Ghostbin (now deleted), on Friday. The document contains a huge number of usernames and passwords, along with credit card numbers and expiration dates.

The news came just a day after the hacker group Lizard Squad compromised Sony’s Playstation and Microsoft’s Xbox Live gaming networks on Christmas day, which is estimated to have affected Xbox's 48 million subscribers and PlayStation's 110 million users, making it a total of more than 150 million users worldwide.

However, data breach of 13,000 users is not the biggest data breach we've ever seen. When millions of passwords are used for sites around the globe, chances are very minor that our’s among those compromised. But still it’s important to note as these accounts come from a variety of online sources and among those, some are really very popular.


The Daily Dot's Aaron Sankin has compiled a comprehensive list of sites associated with the username and password leaks, and discovered that the leaks came from the sites run the gamut from pornography to gaming to online shopping. The list of the compromised websites is as follows:

  • Amazon
  • Walmart
  • PlayStation Network
  • Xbox Live
  • Twitch.tv
  • Dell
  • Brazzers
  • DigitalPlayground
  • and see complete list.

Just to be on a safer side, users are recommended to change their passwords if they have accounts on these compromised websites, and also pay attention to your credit card transactions and if any suspicious activity found, immediately communicate with related banks and financial institutions.

Also, don't use the same passwords for banking and online shopping sites, and always keep an eye out for unusual activities or unauthorized purchases with your accounts.

23 December 2014

North Korea Internet partially restored following a 9.5 hours outage

North Korea has regained partial Internet access, following a widespread outage that occurred days after the U.S. vowed to respond to a cyberattack on Sony that was blamed on Pyongyang.


The Korean Central News Agency and the Rodong Sinmun newspaper were back online Tuesday after earlier being inaccessible. It was unclear whether wider Internet service in the North has been restored to its previous levels.

The reason for the massive outage is not yet clear, but it comes just days after President Barack Obama warned the U.S. would retaliate against the North. A State Department spokeswoman, when asked about the situation, declined comment.

However, she did say the U.S. government is discussing a range of options in response to the Sony hacking, some of which, she said, will be "seen" and some that "may not be seen."

Doug Madory, a spokesman for the U.S.-based Internet analysis firm Dyn Research, said the Internet problems in North Korea could be the result of an attack.

Earlier, North Korea had called on the United States to apologize for implicating Pyongyang in the hacking of Sony Pictures and threatened to fight back in a variety of ways, including cyberwarfare.

The National Defense Commission for Pyongyang said in state media late Sunday that the U.S. government was wrong to blame North Korea for the hacking. It also said the claims are groundless.

Meanwhile, China's Foreign Ministry said it does not have enough information to determine whether reports that North Korea used Chinese facilities to stage a cyberattack on Sony Pictures are true.

Foreign Ministry spokesperson Hua Chunying said Monday China is "opposed to all forms of cyberattacks" and would not reach any conclusions without having "enough facts."

However, Hua said China is opposed to attacks on a third party "through making use of the facilities of another country" and is ready to have a "dialogue with other countries."

The United States is in talks with China to possibly help block cyberattacks from Pyongyang

20 December 2014

FBI Officially Blames North Korea in Sony Pictures Hack


Following the high-profile cyber attack against Sony Pictures Entertainment, and continuous threats against  employees and celebrities, the FBI has released an official statement declaring the investigation has lead to “enough information to conclude that the North Korean government is responsible for these actions.”

In a press release issued Friday morning, the FBI listed several factors that lead to its conclusion, including:

  • Technical analysis of the data deletion malware used in this attack revealed links to other malware that the FBI knows North Korean actors previously developed. For example, there were similarities in specific lines of code, encryption algorithms, data deletion methods, and compromised networks
  • The FBI also observed significant overlap between the infrastructure used in this attack and other malicious cyber activity the U.S. government has previously linked directly to North Korea. For example, the FBI discovered that several Internet protocol (IP) addresses associated with known North Korean infrastructure communicated with IP addresses that were hardcoded into the data deletion malware used in this attack.
  • Separately, the tools used in the SPE attack have similarities to a cyber attack in March of last year against South Korean banks and media outlets, which was carried out by North Korea.


President Obama held a news conference shortly after the announcement, where he was asked to comment on the United States’ proportional response to the attack.

“Our first order of business is to try to prevent those attacks from taking place,” said President Obama. “Everything that we can do at the government level to prevent these types of attacks [we’re doing]. We’re coordinating with the private sector but we’re not even close to where we need to be.We need strong cybersecurity laws that provide for data sharing.”

Without further details, President Obama added a response would come “at a time and place we choose.”

Secretary of the Department of Homeland Security Jeh Johnson also stressed in a statement the high-profile event underscored the importance of good cybersecurity practices to rapidly detect cyber intrusions and promote resilience throughout all networks.

“Every CEO should take this opportunity to assess their company’s cybersecurity,” said Johnson. “Every business in this country should seek to employ best practices in cybersecurity.”

The FBI’s statement comes days after Sony Pictures Entertainment called off its plans to release “The Interview” — a comedy depicting the assassination of North Korea’s leader Kim Jong-un, and after several theaters received threats for intending to show the film

02 December 2014

FBI warns of 'destructive' malware in wake of Sony attack

The Federal Bureau of Investigation warned U.S. businesses that hackers have used malicious software to launch destructive attacks in the United States, following a devastating cyber attack last week at Sony Pictures Entertainment.


The five-page, confidential "flash" warning issued to businesses late on Monday provided some technical details about the malicious software that was used in the attack, though it did not name the victim.

An FBI spokesman declined comment when asked if the software had been used against the California-based unit of Sony Corp.

The FBI occasionally issues "flash" warnings to provide businesses with details about emerging cyber threats to help them defend against new types of attacks. It does not name the victims of those attacks in those reports.

The report said that the malware overrides data on hard drives of computers which can make them inoperable and shut down networks.

It is extremely difficult and costly, if not impossible, to recover hard drives that have been attacked with the malware, according to the report, which was distributed to security professionals at U.S. companies.

26 September 2014

Cyber attack on Japan Airlines impacts up to 750,000


A phishing attack may have resulted in the theft of personal information belonging to customers of Japan Airlines's frequent flier club.

The leak was due to an 'unauthorised access' to JAL's database by an external server, an airline official told the local news agency Kyodo on Wednesday

The data compromised includes names, addresses, genders and places of work of anywhere between 110,000 and 750,000 members of the program, according to the Japan Times.

Following an investigation – which found that 23 computers contained malware – the airline determined that no credit card or financial information was impacted by the breach. The airline detected the intrusion on Friday and Monday, however, it believes the attacks have gone undetected for more than one month and were introduced to the airline's network via a phishing email.

This incident follows a similar attack on the airline in February, in which hackers penetrated a different program Japan Airlines offers, which allows customers to trade in mileage points for gift coupons.

24 March 2013

Ten simple things you should do this Data Privacy Day



When was the last time you ran a search on your own name – do you know if someone has been pretending to be you, or if unwanted eyes have easy access to your personal details?

Don’t stand idly by as the trail you leave online gets larger – be vigilant and take steps to protect your own information. In line with Data Privacy Day on January 28, here are ten simple things you can do to better protect
the information you share online.

1. Password protect your mobile devices – only 6 in 10 Singaporeans use passwords on their mobile device. Leaving your devices unprotected is equivalent to leaving your home or car unlocked. If you’re lucky, no one will take advantage of the access. If not, you might find yourself at the mercy of cyber risks and fraud.

2. Run a search on yourself – it’s not narcissistic, and is an easy way to stay on top of what’s available about you online. You never know who might be assuming your identity or sharing your private information.

3. Be stingy with your personal details
– some websites will prompt you for information such as your email, address or phone number. Be cautious as this information might end up being used in unexpected ways.

4. Mobile security software can add another layer of protection
– yes it exists, and yes it works.

5. Unknown sources are usually bad news
– emails and text messages that contain links or ask for information might do you more harm than good. Make sure you know who the sender is before opening these messages.

6. Be in charge of your privacy settings
– some social networks and applications can share your personal information and location with strangers. You should only share personal details with those you trust.

7. Download apps from reliable sources
– mobile malware is spreading via fake app markets. Be mindful of what apps you’re downloading and where you’re downloading them from.

8. Keep your apps updated
– security patches exist for a reason, use them when available.

9. Log off and log out
– unless you want others to have easy access to your accounts, you should always log out after use.

10. Stay informed
– keep up to date with the latest mobile threats and dangers by visiting websites such as MobileSecurity.com, which has the latest news on all things related to protecting yourself and your mobile devices.

21 March 2013

Android, iOS bugs expose phones to voyeurs, data thieves

The first line of defense against smartphone snoops is a handset's lock screen, but the two largest smartphone makers are having trouble keeping them secure.

Bugs were discovered Wednesday in both Android and Apple smartphones.

A bug discovered by Android researcher Terence Eden allows anyone to bypass the security measures in place at a phone's lock screen and gain total access to the contents of a handset.

Eden outlined the method for bypassing the lock screen in his personal blog. The technique exploits the 911 feature of a phone, which allows emergency calls to be made whether a phone is locked or not.

The researcher noted that he found his attack to work only on a Samsung version of Android. It does not work on phones running a stock version of Android from Google.

He tested the attack on a Galaxy Note II from Samsung, but he predicted it would also work on a Samsung Galaxy III, as well as other Samsung devices, too.

Samsung did not respond to a request for comment for this story.

Eden explained that he reported the bug to the company in February, and that he expected a bug fix to be issued shortly.

Meanwhile, another lock screen bug was discovered in Apple's iPhone. The bug was discovered less than a day after Apple began pushing a version of its iOS operating system, version 6.1.3, to address a lock screen flaw discovered several seeks ago.

The bug was revealed by a reader of the Cult of the Mac website. It uses an iPhone's control feature to bypass the lock screen. However, the exploit appears to only work on iPhone 4's.

When a call is voice dialed, the publication explained, if the phone's SIM card is ejected during the dial-up, the phone will display its recent call log. From that screen, a peeper can browse and edit contacts and add pictures to the phone.

Both the Android and Apple bugs are similar, according to Diogo Monica, a security engineer with Square, a mobile payments company in San Francisco.

"They both exploit the emergency call system," he said in an interview. "When an emergency call is made, it allows a logic bug to be exploited and let you access the screen without authentication."

Once the lock screen is bypassed, not only can the information in it be eyeballed, but it can be copied, too. If your phone is unlocked, it can be connected to a computer and its contents dumped to the device, Monica explained.

He estimated that all the important data in a phone can be siphoned into a computer in a couple of minutes. A complete data dump of everything in a phone would take a maximum of 15 minutes.

Faulty lock screens would create serious concerns for corporations, maintained Glenn Chisholm, CSO and vice president of Cylance, a cyber security firm in Reston, Va.

"When you try to access your corporate mail, it usually forces you to enable your lock screen," he explained  in an interview. "If the corporation can't trust a lock screen to protect their corporate information ... that's a big problem."

Another big problem for corporations is lost or stolen smartphones, added Giri Sreenivas, vice president and general manager of mobile for Rapid7.

To mitigate those risks, companies require their employees to secure their phones with a PIN. "These vulnerabilities allow those controls to be bypassed," he said in an interview.


A video run through of the issue:

13 March 2013

Tips for removing data from mobile devices

AVG released tips on how consumers can remove their personal data before they recycle or throw away their old smartphones.



In an era of frequent and seamless device upgrades, it’s easy to ditch an old handset and move on to the next. However, chances are the old device has personal information lingering on it, putting consumers at a greater risk of identity theft.

“Think about all the personal data stored on your phone: text messages, emails, even intimate photos of you or your significant other,” said Tony Anscombe, senior security evangelist at AVG. “Consumers are now carrying more and more personal information on their devices, and AVG wants to ensure everyone is well equipped to wipe out that data when the time comes. Your identity is essentially yours to lose, so take every precaution possible to stay safe.”

While the factory reset button seems like the logical place to start, numerous industry and security experts report that even after consumers carry out this exercise, personal information often remains.

The following tips will help ensure private information is erased:
  • Remove the memory and SIM cards. Both store personal data and are best kept safe in your possession or destroyed.
  • Use a data removal application to ensure data really is deleted.
  • Once the data is deleted, then run a factory reset. Instructions can be found on manufacturers’ or carriers’ websites.
  • If you are going to simply throw away your mobile phone, older handsets can contain toxic materials. Consult your local authority or drop it off at a mobile phone retailer, where they will be able to dispose of it correctly. Additionally, there are specialist companies that will take it apart and recycle each component.
  • Of course, recycling or handing it on for use is a good option; there are many charities and organizations that redistribute old phones and will even send you a pre-paid postage box to send it in. Just search on the Internet for the many options!

16 June 2011

Citigroup data theft the result of a common vulnerability

If the information the NYT has received about the Citigroup breach is correct, and the intrusion was made possible by the exploitation of a vulnerability so frequent and common that it made OWASP's top 10 web application risks list, one wonders how it is possible that the world's largest financial services company hasn't got security experts that would remedy it.

The flaw in question is called insecure direct object reference, and it happens when confidential information is exposed to users because developers did not have the good sense to hide it.

Essentially the process went like this: first, hackers logged into the accountholder website. From there, the attackers used some type of script that allowed them to automatically jump from account to account and harvest any identifiable information merely by changing a portion of the URL. It's not exactly known how the hackers knew to exploit this vulnerability.

A browser and the ability to change the URL string was all that was needed to open hundreds of thousands of accounts to attackers. Oh wonderful.

Once the attackers realized it - I'm guessing one of them probably had an account with Citigroup - it was only a matter of writing a script that would feed random numbers into the URL and every time it successfully accessed an account, the attackers harvested the information contained in it.

If that is true, there is another thing bugging me - why wasn't this "bombarding" the site with requests with bogus combination of numbers over and over again not noticed by anyone? Why wasn't there a mechanism in place that would get triggered by this kind of action?

But maybe, in this case, they couldn't spot it? Maybe the script was written in such a way that the requests were random and spread over a great period of time? One would presume that the attackers would try to get as much information as possible in a short time before the attack was detected, but you never know.

The only thing going for those affected by the Citi hack may be the fact that the attackers do not have expiration dates or security numbers found on the back of the card. This may protect those attacked from serious identity theft, although a lot of other personal information has been disclosed.

All in all, can we now just stop calling it a "sophisticated attack"?

12 May 2011

Facebook apps found giving access to user accounts to third parties

A discovery that really should not surprise anyone has been made yesterday by Symantec - it turns out that due to to a flaw in the authentication schemes used before the now default OAuth 2.0, Facebook IFRAME applications have been leaking access tokens to third parties such as advertisers or analytic platforms.


What it means is that these third parties had access to users' accounts and all that is in them - even if the privacy settings shouldn't have allowed it - and they also had the ability to post messages on the users' behalf.

Symantec points out that these third parties have likely been unaware of their ability to access that information, but that is hardly comforting.

"Access tokens are like ‘spare keys’ granted by you to the Facebook application. Applications can use these tokens or keys to perform certain actions on behalf of the user or to access the user’s profile. Each token or ‘spare key’ is associated with a select set of permissions, like reading your wall, accessing your friend’s profile, posting to your wall, etc," the researchers explain. "By default, most access tokens expire after a short time, however the application can request offline access tokens which allow them to use these tokens until you change your password, even when you aren’t logged in."

They estimate that over the years - starting with 2007, when Facebook applications were first introduced - millions of access tokens have been leaked and they think it possible that a great number of these tokens are still available in log files of third-party servers or still being used by advertisers. Luckily for the users, there is a simple way for making these tokens invalid: changing the Facebook password.

According to Symantec, Facebook has already fixed the flaw, but the fact that vulnerabilities like these seemingly pop up in regular intervals make me believe that Facebook is not actively searching for them - that, in fact, they are there because it suits Facebook's agenda.

On the other hand, Facebook is an extremely complex system, and things like this are inevitable - especially when dealing with legacy technologies. Part of the solution is the company's announcement that it will be pushing app developers to migrate their apps from the old Facebook authentication system to OAuth 2.0.

01 April 2011

Keep Your Portable Devices Encrypted

When you're sitting at home or at the office, most physical threats are avoided. To keep people from accessing your computer, simply lock your office door or put your computer to sleep. Unfortunately, most of the steps taken for desktop security aren't afforded to portable devices. They're easily stolen, or misplaced. Which can lead to sensitive data being leaked.

Just ask BP, who had an employee lose their laptop while on a business trip. The story is of particular note because the laptop stored personal data. With information such as social security numbers, and dates of birth. The information belonged to 13,000 people who submitted claims against the company over the oil spill.

The story shows how vulnerable portable devices are when being transported on long trips, or even short ones as well. According to a recent study, 30 of 144 data breaches announced, occurred on portable devices.

These breaches can be avoidable if encryption software is being used on the device. The problem is many companies don't want to invest in the tools. The presents a problem which bothers, Avivah Litan, an analyst for Gartner Inc, "There really is no excuse for not encrypting laptops"

Litan makes the argument that the cost of protection is worth it, and enterprises can find worthwhile discounts. Volume prices can drop to as little as $15 per laptop. She accuses businesses that have the knowledge of data encryption but refuse to use it as being lazy.

Reports of data loss on portable devices will continue to rise if people and businesses continue to refuse the encryption option. The practice might increase cost, but the consequences of what can happen over certain data leaks has to make it worth the investment.

05 October 2010

CYBER BANKING FRAUD: Global Partnerships Lead to Major Arrests

Just when you thought you could get away with cyber crime just becoz of anonymity online? Think again.

Law enforcement partners in the United States, the United Kingdom, Ukraine, and the Netherlands announced the execution of numerous arrests and search warrants in multiple countries in one of the largest cyber criminal cases ever investigated.

Using a Trojan horse virus known as Zeus, hackers in Eastern Europe infected computers around the world. The virus was carried in an e-mail, and when targeted individuals at businesses and municipalities opened the e-mail, the malicious software installed itself on the victimized computer, secretly capturing passwords, account numbers, and other data used to log into online banking accounts.

The hackers used this information to take over the victims’ bank accounts and make unauthorized transfers of thousands of dollars at a time, often routing the funds to other accounts controlled by a network of “money mules.” Many of the U.S. money mules were recruited from overseas. They created bank accounts using fake documents and phony names. Once the money was in their accounts, the mules could either wire it back to their bosses in Eastern Europe, or turn it into cash and smuggle it out of the country. For their work, they were paid a commission.

On 30 Sept 2010, New York office arrested 10 subjects related to the case, and they are seeking 17 others. Those arrested are charged with using hundreds of false-name bank accounts to receive more than $3 million from victimized accounts.

In all, the global theft ring attempted to steal some $220 million, and was actively involved in using Zeus to infect more computers.

More details here:
http://www.fbi.gov/page2/oct10/cyber_100110.html

15 July 2010

Two Major Breaches Caused By Loss Of Physical Media

AMR loses data of some 79,000 employees; California agency and Care 1st misplace CD containing data on 29,000 patient.

Online attacks might be getting more sophisticated every day, but two incidents last week are reminding the industry that the loss of physical storage media is still among the most common causes of data breaches.

AMR, the parent company of American Airlines, is in the process of notifying some 79,000 current and former employees of the loss of a hard drive containing microfiche records dating from 1960 to 1995. Some of the records included bank information.

And on July 6, the California Department of Health Care Services (DHCS) reported to federal authorities that a missing compact disc (CD) delivered to the department may not have been encrypted by the sender, Care 1st Health Plan. The CD contains personal information, including names and addresses, for 29,808 Care 1st members.

Recent studies indicate that the theft of physical media remains one of the most common causes of data breaches. Both AMR and the California DHCS have discovered that the hard way.

The lost AMR drive contains images of microfilm files, which include names, addresses, dates of birth, Social Security numbers, and a "limited amount" of bank account information, the company told the Associated Press. Some health insurance information might have also been included -- mostly enrollment forms, but also details about coverage, treatment, and other administrative information.

The data spans a period from 1960 to 1995. AMR also believes some of the employee files contained information on beneficiaries, dependents, and other employees. No customer data was affected, the company says.

AMR has sent letters to the people who were impacted by the breach. AMR is offering one year of free credit monitoring for those affected, and is increasing security and testing the vulnerability of its computers.

The data lost between Care 1st and the California DHCS is in peril because the lost CD might not have been encrypted, officials said. Without proper encryption, which is required by DHCS of all of its trading partners who share protected and personal information, the CD could possibly be accessed by unauthorized users.

Care 1st cannot confirm the CD was encrypted. Though DHCS believes the CD is still on its premises and there is no indication of inappropriate access, DHCS reported the incident to the U.S. Department of Health and Human Services as required by law.

When the CD could not be located, DHCS immediately launched an investigation and conducted numerous exhaustive searches of the premises, according to a press release. DHCS then reiterated and reinforced its longstanding direction to Care 1st and all trading partners that all personal information must be transmitted or delivered to DHCS in an approved, secure format. Care 1st now submits the information using secure electronic transfer rather than CDs.

Care 1st delivered the CD to DHCS for the purpose of identifying Care 1st members who are also Medi-Cal beneficiaries. The members whose information is contained on the misplaced CD are mostly Medicare recipients. On April 29, when the information on the CD that was delivered on April 7 was scheduled to be processed, it was determined to be missing.

On June 18, Care 1st began sending individual notification letters to the members whose information was on the CD. The letters gave the members information on steps they could take to protect themselves from any possibility of identity theft. Care 1st also arranged for free credit monitoring services to be provided to the members for one year at no cost.

03 July 2010

The "New" Paper Trail

These days, with threats of computer hackers stealing data to insurance companies "accidentally" publishing hundreds of thousands of peoples most sensitive information on the internet, data security is a very prevalent issue. A CBS news investigation recently turned up a new source of potential data leakage, the standard office copy machine.

Unknown by the majority of Americans, almost every single copier built since 2002 has an internal hard drive which stores a digital copy of each document copied, scanned, or printed using the machine. This can be a useful feature for storing fax cover sheets and other commonly used documents. The problem comes when personal information is copied for office use. For example, doctors making copies of medical records, insurance companies making copies of claims information, or employers making copies of drivers licenses. Each time a copy is made, that information is stored in a way that is easily retrievable by anyone with access to the machine.

There are numerous rental services which rent out copiers to businesses with no set policies on dealing with this kind of security. Some offer to scrub the hard drive when it is returned, but they can charge up to $500 for the service. There are also refurbished copiers for sale containing data from any previous owners. At least in these cases, the owner has physical access to the machine to be able to take steps on their own, such as purchasing an encryption service for the internal hard drive, or their own data deletion tools. What is more worrisome are the copy and print shops where there are no guarantees on document security. Anything copied there is stored on their machines, where it is unlikely that any measures are taken to wipe the drives on a regular basis, if ever.

If your office handles private information, or anything else that doesn't need to be shared with others, steps should be taken to make sure that the information stored inside your copier is safe. There are usually services available from the manufacturers to have the data removed from the device after each job is completed, or at least encrypted, although this can significantly add to the cost of the machine.