Showing posts with label GDPR. Show all posts
Showing posts with label GDPR. Show all posts

Wednesday, April 29, 2020

Lesson one: If you have a breach communicate


Universities are frequently targeted due to the amount of personal, confidential data being held. This is accumulated as part of the application process, along with on-going course attendance. One recent target has been the University of Warwick. The university is located in the Coventry in the UK, and is part of the Russell Group. While the details of the successful attack have not been published, this attack may have been invited in by one of the users. The issue may have all started with a user installing remote viewing software in 2019. At this point, the attackers were able to gain a foothold into the system and pivot into other areas, providing the data and information they sought.

Data
As to be expected, the attack had a focus. In this case, it was the usual data and information. The breach allowed the attackers access to student information. The attackers had also access to the staff and volunteer private information. This would provide the attackers the data needed for various unlawful acts, including taking over someone’s identity, getting credit in the other person’s name, and other fraudulent acts.

Multiple Breaches
In general, one breach is a bad operational defect. This can be devastating to the university, staff, and students in the short- and long-term. This can reach into the full network, or sections, based on the attack and target. If the attacker simply wants to exfiltrate data quickly that is marketable, they may breach the accounting or Human Resource networks. If they want to own the system and possibly extort funds, this is yet another avenue that may be best attacked with ransomware or other malware. In this case, the University was breached several times.

Problematic Factors
Simply stated, the university was breached. Granted, this is a rather unpleasant set of circumstances with potential legal consequences. There appears to be a systemic operational issue though with the breaches. First, there were multiple breaches within the university’s system in 2019. One is bad enough, with the damage that may be done. When you have multiple, the attackers know they are able to get in, get what they want, and exit with ease. If there were to have been an apprehension or concern on the part of the attackers, perhaps they would not have returned so brazenly. For them to return and enter unfettered is indicative of a larger issue.

With these multiple breaches, there is data, intellectual property, and other items possibly removed. There is also the opportunity for them to leave something behind, be it other back doors or malware, to make their life even easier if they would want to enter later. This has a clear impact on the staff and students. From the point in time for the breach, until the notification, the affected persons are blind to the attacker’s using their personal data and information, any researcher’s work product being in unauthorized hands, and generally being open to issues themselves. In this case, the university withheld this information.

One rationale for this was the university did not have the budget and resources to work on this. This, on its own, is an issue. Too many staff do not appreciate the cybersecurity role, and what this actually brings to the organization. Without a robust cybersecurity program in place, there will be issues and many unauthorized persons will have access to your private information. In other words, a reasonably prudent organization would have this in place to protect the data and information which has been given to it to manage and steward.

On another point, prior to the breach, the university was audited by the Information Commissioner’s Office, whose focus is data protection. The report, published in March, noted the chairperson of the university’s data protection privacy group (DPPG) should be replaced with an alternative with more experience. Upon receipt and review, the registrar completely agreed with their findings. Curiously, the registrar and Data Protection Officer are the same people. While the report is after the fact, the indicators had been present for some time and should have been acted on long ago. This report based on the audit was how the staff and students learned of the breaches and that their data had been compromised. Without this report, who knows when the university would have let anyone know of the circumstances. For some reason unbeknownst to many, the registrar joked about the audit, stating it was “tomato colored” and acting dismissive as to the possibility the data was at risk.  
In certain circles, not accomplishing this may be considered negligence.

Apparently, the lack of oversight and resources was to the extent the university may have known they were breached, however, had no idea of what data or systems had been impacted by the attack.

Mitigations
To overcome these problems, the university has created two additional committees to assist with the governance in this area and to provide advice. The university also put a new Chief Information and Digital Officer in place to better the cybersecurity stance.

Lessons
To fully fund the cybersecurity teams and the working group is still vital to operations, and any entity. If you are apathetic as to the network, operations, and any repercussions from a breach and being totally pwned by an unauthorized third party, there is an issue. In these times of budgetary constraints, allocating the resources can be a difficult task. The alternative though tends to be much more expensive financially in the short- and long-term, and provides the opportunity for the organization to be in the news, for all the wrong reasons. There needs to be some form of a balance with the operations. Without this in place, the organization is simply a target waiting to be breached and having to send out the breach notification letters.

There also needs to be the appropriate staff doing the appropriate tasks. There is room for staff with their specific expertise in any organization. When you someone in a role they do not have the experience for, you will have issues. At a senior management level in cybersecurity, there is not the time or the availability of resources to attempt to learn on the job. There will be areas that will be missed in tasks and functions as the person moves through the learning curve. This is not the first time someone has been placed in a management position in cybersecurity without the requisite experience, exemplary of the Peter Principle.

When you have a report publishing of record there are data breaches, as a member of management, you should not act apathetic and as if you are above the findings. The staff in charge of the cybersecurity for a university should take care of the data they are stewarding. They should care enough to ensure their staff and student’s information is not at risk. When an independent third party has to inform you of breaches, something should be done to protect the university, students, and staff other than commenting, as the registrar did, “If I tell you what, I ‘I must kill you.’”

This is a rather serious issue as the breach included personal data and access to the network, unfettered. There is in place during the breach of the GDPR. As time passes, it will be interesting to note if the government actually applies the GDPR or any of the like laws or statutes to the university for the significant error and indifference to the staff and students. The registrar’s response is one of the reasons why there are still numerous breaches.

Anyone affected by this should be wondering why the responsible staff are still present and working at the university, especially the registrar.

Resources
Jay, J. (2020, April 28). Warwick university suffered multiple breaches due to poor security protocols. Retrieved from https://www.teiss.co.uk/warwick-university-data-breaches/ 

Karageorgi, N., & Toms, O. (2020, April 27). University of warwick kept data breach secret from students and staff. Retrieved from https://theboar.org/2020/04/university-of-warwick-kept-data-breach-secret-from-students-and-staff-last-year/ 

Martin, A. (2020, April 27). The university of warwick was hacked and kept secret the breaches of students and staff. Retrieved from https://oltnews.com/the-university-of-warwick-was-hacked-and-kept-secret-the-breaches-of-students-and-staff 

Martin, A. (2020, April 27). Warwick university was hacked and kept breach secret from students and staff. Retrieved from https://news.sky.com/story/warwick-university-was-hacked-and-kept-breach-secret-from-students-and-staff-11978792 

Millman, R. (2020, April). GDPR ignored by warwick university? Retrieved from https://www.scmagazineuk.com/gdpr-ignored-warwick-university-failure-alert-staff-students-data-breach/article/1681689 

Rodger, J. (2020, April 27). Warwick university kept data hack secret from students and staff. Retrieved from https://www.birminghammail.co.uk/news/midlands-news/warwick-university-kept-data-hack-18156758 

Sandford, E. (2020, April 27). Hackers targeted university of warwick. Retrieved from https://www.coventrytelegraph.net/news/coventry-news/hackers-targeted-university-of-warwick-18157358

Thursday, January 17, 2019

Woesnotgone Meadow; December 15, 2018

Woesnotgone Meadow; December 15, 2018

Most residents in the Meadow don’t travel this time of year. With the snow and potential for more snow, ice, and freezing temperatures, there can be a substantial risk. Once the weather breaks, our town begins to travel more. There is also so much to see in the Meadow, with Jerry’s Ice Skating Rink, how many scoops Margie can actually put on a cone before physics takes over, and of course watching the people passing through at the gas station. When we do travel, we have to stay somewhere to rest and sleep at the final destination. As we travel through the nation, there are a number of different chains to accept our business. One of these is the massive Marriott chain of hotels. For those in the Meadow who did travel and stayed at a Marriott, there may be an issue for them to consider.
Marriott Hotel Chain
The Marriott hotel chain is massive. The chain is global with assets in over a hundred countries. In order for you to reserve a room for the stay, the client uses their Starwood application, which is owned and managed by their Starwood division. The Starwood application also services other hotel brands, other than Marriott. These include W Hotels, Sheraton, Le Meridien, and Four Points by Sheraton. The subject Starwood reservation dB was purchased in 2016 by the Marriott, St. Regis, Westin, Sheraton, and W Hotels entities.
Attack
The Starwood dB was rather integral to the business operations for the hotels using this. This one system was responsible for a significant portion of the revenue. The Starwood reservation database was compromised by an unauthorized party. This occurred in 2014. The successful attackers had complete, unfettered access beginning at that time. It seems a bit odd why the detection would require four years. Some persons would be defensive when this point would be brought up. They may even rationale this based on the size of the network and number of attack points being very large.
The alternative of the reality is a much more viable explanation. This should have been caught much, much sooner. For the time the attackers had access there had to have been a blatant trail within the logs at the least. The users and systems do indeed create a mountain of data to review, analyze, and digest. This would be exceptionally difficult to digest. We have this program though, which has the ability to automate tasks, analyze mass amounts of data, and generally catch things we can’t. This involves a SIEM.
This was only detected by an internal security tool on 9/8/2018. The red flag for this event was someone attempting to access the Starwood dB, who was later found to be not authorized. This entity had copied and encrypted the client’s data. The clients are not only US-based but also those abroad, especially the EU. Marriott was not sure exactly how this happened.
Affected
The targeted dB was copied and encrypted by the attackers. This dB contained the records of up to 500M Starwood clients. These were from the W Hotels, St. Regis, Sheraton Hotels & Resorts, Westin Hotels & Resorts, Element Hotels, The Luxury Collection, Tribute Portfolio, Le Meridien Hotels & Resorts, and Four Points by Sheraton. The Design Hotels were also participating in the Starwood Preferred Guest Program, as well as Starwood branded timeshare properties. This covers the properties in over 110 countries. For up to 327M of these clients, this data included a combination of name, mailing address, phone number, email address, passport number, account information, date of birth, gender, and arrive/departure data. A portion of these records also may have encrypted payment card information. Although there was encryption, the keys may also have been stolen. With all of this data available for sale, the attackers have a lot of opportunity for misuse.
Based on this oversight, the state of Hawaii has threatened Marriott with fines. Along with this same point, Marriott International may also receive a massive fine of greater than 17M pounds due to this involving the citizens of the EU. Two US-based law firms have also filed class action lawsuits regarding this. Based on the negative news, Marriott’s stock (MAR) dropped nearly 6% in the premarket training.
Who’s to blame?
In theory, any team from across the globe could be the attackers. There are multiple articles reporting the compromise was done by a nation state, who is known for this type of activity. The attackers, however, appear to have also been connected to attacks focused on health insurers.
Remediation
The business is notifying the affected parties. They also notified the UK’s Information Commissioner’s Office (ICO) of the breach. Also, they are working with law enforcement. To address this and offer information, they created a website and stood up a call center to answer questions. They are offering the affected parties in the UK, US, and Canada a year subscription to a fraud-detecting service (WebWatcher). While this has some level of value in the short-term, the attackers still could use this at the one year and one day mark.

Resources
ABC News. (2018, November). Massive, extended data breach at marriott’s starwood hotels. Retrieved from https://abcnews.go.com/Business/wirestore/massive-data-breach-marriotts-starwood-hotel-59516173
Admin. (2018, December 4). Marriott may face GDPR fine of more than 17M. Retrieved from https://www.travelweekly.co.uk/articles/318325/marriott-may-face-gdpr-fine-of-more-than-17m
Associated Press. (2018, November 30). Massive extended data breach at marriott’s starwood hotels. Retrieved from https://www.apnews.com/d496fce7a77347d6aa058470d38a69bc
BBC News. (2018, November). Marriott hack hits 500 million guests. Retrieved from https://www.bbc.com/news/technology-46401890
Brewster, T. (2018, December 3). Revealed: Marriott’s 500 million hack came after a string of security breaches. Retrieved from https://www.forbes.com/sites/thomasbrewster/2018/12/03/revealed-marriotts-500-million-hack-case-came-after-a-string-of-security-breaches/#4d3f82c8546f
Cimpanu, C. (2018, November 30). Marriott reveals data breach affecting 500 million hotel guests. Retrieved from https://www.zdnet.com/article/marriott-announces-data-breach-affecting-500-million-hotel-guests/
Cook, J. (2018, November 30). Private data of 500 million Marriott guests exposed in massive breach. Retrieved from https://www.telegraph.co.uk/technology/2018/11/30/private-data-500-million-marriott-guests-exposed-massive-breach/
Kilgore, T. (2018, November 30). Marriott’s stock sinks after disclosing data breach affecting up to 500 million guests. Retrieved from https://www.marketwatch.com/story/marriotts-stock-sink-after-disclosing-data-breach-affecting-up-to-500-million-guests-2018-11-30
Murphy, I. (2018, December 3). Marriott data breach shows cyber security risks of mergers. Retrieved from https://www.enterprisetimes.co.uk/2018/12/03/marriott-data-breach-shows-cyber-security-risks-of-mergers/
Ortiz, E. (2018, November 30). Marriott says breach of starwood guest database compromised info of up to 500 million. Retrieved from https://www.nbcnews.com/tech/security/marriott-says-data-breach-compromised-info-500-million-guests-n942041
Osborne, C. (2018, December 12). China blamed for Marriott data breach. Retrieved from https://www.zdnet.com/article/china-blamed-for-marriott-data-breach/
Picchi, A. (2018, November 30). Marriott data breach may expose 500 million guests. Retrieved from https://www.cbsnews.com/news/marriott-data-breach-500-million-starwood-guests-hit-by-data-breach/
Snider, M. (2018, November 30). Marriott says as many as 500 million starwood guests data may have been breached. Retrieved from https://www.usatoday.com/story/money/business/2018/11/30/marriott-data-breach-may-affect-500-million-starwood-hotel-guest/
Tarlow, P.E. (2018, December 2). Marriott security breach: The human side of cyber security breaches. Retrieved from https://www.eturbonews.com/239317/marriott-security-breach-the-human-side-of-cyber-security-breaches
Telford, T. (2018, November 30). Marriott discloses massive data breach affecting up to 500 guests. Retrieved from https://www.washingtonpost.com/business/2018/11/30/marriott-discloses-massive-data-breach-impacting-million-guests/
Valinsky, J. (2018, November 30). Marriott says 500 million starwood accounts compromised. Retrieved from https://www.cnn.com/2018/11/30/tech/marriott-hotels-hacked/index.html

Whittaker, Z. (2018, November 30). Marriott says 500 million starwood guest records stolen in massive data breach. Retrieved from https://techcrunch.com/2018/11/30/starwood-hotels-says-500-million-guest-records-stolen-in-massive-data-breach/