Showing posts with label credit card system. Show all posts
Showing posts with label credit card system. Show all posts

Wednesday, February 27, 2019

Woesnotgone Meadown; December 22, 2018

All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

Baylor Scott & White Medical Center is located in Texas. This is far from the northern region where the Meadow is located and the winter is long and cold. The medical center was organized as a joint venture managed by the United Surgical Partners International (USPI). As we know from the prior attacks on medical facilities and offices, these are rather blatant targets due to several factors, including the cash flow through the facility, and let us not forget the medical records themselves.

The facility’s credit card processing was done by a 3rd party. This same credit card system was breached. The attackers sought to secure the patient’s and guarantor’s payment and credit card data. The hospital detected the attack on September 29, 2018. The breach, while significant, was open from September 22 – 29.

The issue was with the 3rd party’s credit card processing system. This is not a new concept for the attacker’s.  This same vector has been exploited a number of times over the years. One of the larger and more prolific breaches in recent memory occurred using this method. The timing for this was near the end of the year holiday season, with Target being breached. One of their vendors, who had access to the Target system, had a corrupt system, which allowed the attack in.

The breach affected 47,984 persons. These were the patients and/or the guarantors. The medical practice reported the issue to the US Department of Health and Human Services. Per the HIPAA breach notification rule, the affected persons were notified with letters. Fortunately for the patients and guarantors, there has been no evidence to date the data had been misused. Although this is good news, the attackers may use the data at a later point in time, until the payment information changes.

The data that may have been accessed by the attackers includes the name, mailing address, telephone number, date of birth, medical record number, date of service, insurance provider information, account number, last four digits of the credit card used, the credit card CCV number, type of credit card, date of recurring payment, account balance, invoice number, and status of transaction. While the credit card information would need to be used prior to the credit cards being replaced, the data in its entirety could be used with phishing for the longer term. This could also be used for fraudulent transactions and potentially for identity theft for the skilled phishers. A positive point with this is the data did not include the social security numbers or medical record information.

Although the data is inherently pertinent, the attack could have been much worse. The hospital’s systems other systems were not affected by this.

Once the breach was detected, the hospital notified the vendor and terminated the credit card processing handled by the vendor. The medical center is providing a one year free credit monitoring service for the affected parties.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.

Resources
CBS DFW. (2018, December 10). Data breach could impact 47k patients treated at north texas hospital. Retrieved from https://dfw.cbslocal.com/2018/12/10/data-breach-texas-hospital/

Cyware. (2018, December 11). Data breach at baylor scott & white medical center impacts nearly 47,000 patients. Retrieved from https://cyware.com/news/data-breach-at-baylor-scott-white-medical-center-impacts-nearly-47000-patients-646520aa

Davis, J. (2018, December 11). Third-party vendor hack breaches 48,000 baylor frisco patients. Retrieved from https://healthitsecurity.com/news/third-party-vendor-hack-breaches-48000-baylor-frisco-patients

Dissent. (2018, December 10). Baylor Scott & White Medical Center-Frisco notifies 47,000 patients after third-party bill payment vendor was hacked. Retrieved from https://www.www.databreaches.net/baylor-scott-white-medical-center-frisco-notifies-47000-patients-after-third-party-bill-payment-vendor-was-hacked/

McGee, M.K. (2018, December 10). Credit card system hack led to HIPAA breach report. Retrieved from https://www.databreachtoday.com/credit-card-system-hack-led-to-hipaa-breach-report-a-11830


Sunday, January 6, 2019

Woesnotgone Meadow; December 12, 2018

Woesnotgone Meadow
December 12, 2018
#

All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

In the Meadow, most people have a computer. The models vary per the manufacturer and what the residents want the systems to do. The computers are used for menial tasks on up to coding. A portion of the Meadow uses the Dell systems. This may be due to the person having an account at Dell. For this, this just makes sense to purchase there due to the ease. Although this is easier for the client, recently there was an issue with Dell.

Breach
This took place on November 9, 2018. There was unauthorized access attempted to Dell.com, Premier, Global Portal, and support.dell.com. This, fortunately, was detected on the same day when the Admins noted the unusual activity.

The attacker’s focus was on the customer’s information and data. This included the customer’s name, email address, and hashed passwords. The hashed passwords appear to be a great idea. The issue, however, is Dell did not detail the hashing algorithm. In theory, this could be very weak, which could make the security aspect moot.

In this case, the data was possibly exfiltrated. On its own, the data was very marketable. Curiously with this attack, they did not focus on the payment card data, or other private customer data. Dell was not aware of how the compromise was done. This may have been a case of credential stuffing. The compromise did not affect their operations.

Client’s Affected
As of the end of November 2018, Dell was still investigating the issue. Dell has refused to provide an estimate for the number of clients affected.

Remediation
Dell initiated a password reset for the customer accounts on November 14, 2018. They also notified law enforcement and contracted with a digital forensics business to investigate the compromise.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.


Resources

Cimpanu, c. (2018, November 28). Dell announces security reach. Retrieved from https://www.zdnet.com/article/dell-announces-security-breach/

Cluley, G. (2018, November 29). Dell suffers security breach, reset customer passwords (but didn’t tell customers why until now). Retrieved from https://www.grahamcluley.com/dell-suffers-security-breach-resets-customer-passwords/

Fossbytes. (2018, November 29). Dell.com breached: Hackers tried to steal customer data. Retrieved from https://fossbytes.comdell-says-a-security-breach-to-steal-customer-data-was-attempted

KFOR-TV, & Query, K. (2018, November 28). Dell warns customers about ‘potential cybersecurity incident’. Retrieved from https://kfor.com/2018/11/28/dell-warns-customers-about-potential-cybersecurity-incident/

Kumar, M. (2018, November 28). Dell resets all customer’s passwords after potential security breach. Retrieved from https://thehackernews.com/2018/11/dell-data-breach-hacking.html

Media Relations. (2018, November 28). Dell announces potential cybersecurity incident. Retrieved from https://www.dell.com/learn/us/en/uscorp1/press-releases/2018-11-28-customer-update

Nichols, S. (2018, November 28). What the dell? Customer passwords reset after miscreants break into big mike’s IT emporium. Retrieved from https://www.theregister.co.uk/2018/11/28/dell_resets_passwords_hack_alert/

O’Donnell, L. (2018, November 28). Dell warns of attempted breach on network. Retrieved from https://threatpost.com/dell-warns-of-attempted-breach-on-network/1394641  

RTT News. (2018, November 28). Dell announces security breach. Retrieved from https://www.nasdaq.com/article/dell-announces-security-breach-20181128-01275


Winder, D. (2018, N0vember 29). Dell admits to hackers may have stolen customer data. Retrieved from https://www.forbes.com/sites/daveywinder/2018/11/29/dell-admits-hackers-may-have-stolen-customer-data/#412f3fac215c

Thursday, January 3, 2019

Woesnotgone Meadow; December 7, 2018

All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

Here in the Meadow, parking really isn’t an issue. We only have the two meters, both in front of the city hall. Generally, our residents put their dimes in the meters and we are happy. From time to time Margie walks out from her office to write out a ticket. This happens so infrequently, Margie regularly misplaces her ticket pad.

This was not the case in Ames, Iowa. Regularly, visitors and residents receive tickets for parking violations. This tends to give the people a slight headache when they see the paper, waving in the wind beckoning the driver “Hello!” The city even has the option to pay these online.

Issue
Unfortunately, there was a data breach with the online payment system for their parking tickets (Click2Gov). The city learned of the compromise on November 18th or 19th, 2018, through their IT department. Once this occurred, the city notified Click2Gov. In response, the online parking ticket payment system was taken offline. The administrative actions for the issue involved replacing the web server. This service was brought back online on November 20th. Although the service was back online, the city is still reviewing the compromise to review what the vulnerability was allowing the successful attack.

Affected Parties
There were approximately 4,600 Ames, Iowa residents who paid their parking tickets to the city online using the provided service. The other city’s residents not using this service were not affected. The potentially affected residents were mailed the written notice and emailed the same.

Data Exfiltrated
The data for the residents included their data as provided when they were using the service. This included the first name, last name, mailing address, email address, and debit/credit card numbers. If there were to be an enterprising person who just happened to have this data, it may be useful for phishing, fraudulent credit card transactions, and other exciting activities. Due to this compromise, the affected persons will need to monitor their personal credit for years and years to come.

We have the opportunity to learn from this. For this application, a simple static review would be warranted, along with monitoring more closely the SIEM.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.


Resources
Associated Press. (2018, November 30). City of ames warns of parking ticket system data breach. Retrieved from https://www.washingtimes.com/news/2018/nov/30/city-of-ames-warns-of-parking-ticket-system-data-b/

City of Ames. (2018, November 30). Data breach compromises parking ticket payment system. Retrieved from https://www.cityofames.org/Home/Components/News/News/5117/

Leeson, D. (2018, December 2). Ames parking tickets data breach could have compromised 4,600 motorists payment information. Retrieved from http://www.iowastatedaily.com/news/ames-parking-ticket-data-breach-could-have-compromised-motorists-payment/

Olenick, D. (2018, December 3). Ames, Iowa, parking ticket payment system breached. Retrieved from https:/www.scmagazine.com/home/security-news/ames-iowa-parking-ticket-payment-system-breached/

Tribune Staff. (2018, November 30). Data breach found in city’s parking ticket payment system. Retrieved from https://www.amestrib.com/news/2081130/data-breach-found-in-city8217s-parking-ticket-payment-system

U.S. News. (2018, November 30). City of ames warns of parking ticket system data breach. Retrieved frm https://www.usnews.com/news/best-states/iowa/articles/2018-11-30/city-of-ames-warns-of-parking-ticket-system-data-breach 


Friday, November 23, 2018

British Airways Targeted


In this age, credit cards are required for many aspects of our culture. To rent a car, hotel room, or purchase airline tickets, a credit or debit card is required. To purchase these services without a credit card is problematic. One airline providing the travel service is British Airways, a major international airline. Unfortunately, the airline system was breached. This affected 380,000 credit card payments. These were used on the British Airways website and mobile app in August 2018. British Airways did contact the affected parties on September 7, 2018. A large number of affected parties, there are a number of questions of attack methodology. The attackers must have had a clear and in-depth penetration into their system.

Attack
With this attack and compromise, they were able to note when, including the time, the attack occurred. During August 21, 2018 (10:58p) through September 5, 2018 (9:45p), the company’s website and mobile app were successfully attacked and breached. Curiously, BA stated this was a data theft, versus calling this a breach. This may indicate this was an internal threat versus originating from a third party.

Data
The attackers could have targeted a variety of data based on the attack and potential points to pivot from. The attackers were able to access valuable data with the customer’s name, address, email addresses, credit card expiration dates, and other credit card details, including the CVV code. Fortunately for the affected parties, the attackers were not able to exfiltrate the customer’s passport data.

Vulnerability
Throughout several industries, web applications tend to be a valid, robust attack point. This is due to security not being included through the process, new vulnerabilities, and insecure coding, among other issues. BA did remediate the vulnerability.

With these issues, it would be beneficial to know exactly what the vulnerability exploited was, or if there were multiple, what these were. In this case, others could learn from the oversights so that these errors would not be done repeatedly by others in the same and other industries. Unfortunately, in this case, BA had refused to answer any further questions relating to the breach.

Through the issue, BA worked with cybersecurity firms through the forensic review period. The attack period itself is notable. The attackers had over two weeks of full access. Perhaps the SIEM did not detect the compromise in a timely manner, or the logs and reports were not examined at length. This was too long for the compromise, which increased the number of their clients affected by this.

Lessons
The information security teams should have detected this individually or through their tools in place on the systems. The data should have been reviewed prior to the time this was. This is a lesson for others, not only in the airline industry. The logs should be regularly reviewed for anomalies and other unusual activities.


Resources
Buchanan, B. (2018, September 7). British airways hacking? How not to respond to a cyber attack. Retrieved from https://theconversation.com/british-airways-hacking-how-not-to-respond-to-a-cyber-attack-102857

Calder, S. (2018, September 7). BA data breach: What does the british airways hack mean for customers? Retrieved from https://www.independent.co.uk/travel/news-and-advice/british-airways-flights-ba-hacked-data-theft-customers-a8526516.html

Cuthbertson, A. (2018, September 8). British airways hacked: Scale of customers ‘astounding’, security experts say. Retrieved from https:www.independent.co.uk/life-style/gadgets-and-tech/news/british-airways-hacked-customer-data-breach-astounding-ba-security-experts-98527071.html

Davies, R. (2018, September 7). Hacked data-including CVV codes-worth about 20m on dark web, cybersecurity experts say. Retrieved from https://www.theguardian.com/business/2018/sep/07/ba-british-airways-customers-hacked-credit-card-details-dark-web

Detrixhe, J. (2018, September 7). British airways massive data breach has given tech upstarts a chance to promote themselves. Retrieved from https://qz.com/1382301/british-airways-data-breach-monzos-quick-response/

Duckett, C. (2018, September 7). British airways hit with customer data theft. Retrieved from https://www.zdnet.com/article/british-airways-hit-with-customer-data-theft/

Dungay, D. (2018, October 9). British airways announces cyber security breach. Retrieved from https://commsbusiness.co.uk/news/british-airways-announces-cyber-security-breach/

E Hacking News. (2018, September 8). British airways security breach: Credit card details of 380,000 customers stolen. Retrieved from http://www.ehackingnews.com/2018/09/british-airways-security-breach-credit.html

Gulliver. (2018, September 9). British airways admits that over 380,000 customers had their data stolen. Retrieved from https://www.economist.com/gulliver/2018/09/09/british-airways-admits-that-over-380000-customers-had-their-data-stolen

Khandelwal, S. (2018, September 6). British airways hacked-380,000 payment cards compromised. Retrieved from https://thehackernews.com/2018/09/british-airways-data-breach.html

Leyden, J. (2018, September 7). Revealed: British airways was in talks with ibm on outsourcing security just before hack. Retrieved from https://www.theregister.co.uk/2018/09/07/ba_security_outsourcing_consultation_memo/

O’Donnell, L. (2018, September 7). British airways website, mobile app breach comprises 380k. Retrieved from https://threatpost.com/british-airways-website-mobile-app-breach-compromise-380k/137291/

PYMNTS. (2018, September 10). British airways data hack a test case for GDPR. Retrieved from https://www.pymnts.com/news/regulation/2018/british-airways-data-breach-gdpr-compliance-data-security/

Telegraph Reporters. (2018, September 7). British airways hacking: Customers cancel credit cards as airline defends handling of ‘sophisticated’ cyber attacks. Retrieved from https://www.telegraph.co.uk/news/2018/09/07/british-airways-hacking-customers-cancel-credit-cards-airline/

V3 Newsdesk. (2018, September 7). British airways security breach compromises 380,000 credit cards. Retrieved from https://www.V3.co.uk/v3-uk/news/3062330/british-airways-security-breach-compromises-380-000-credit-cards

Whitaker, Z. (2018, September 6). British airways customer data stolen in data breach. Retrieved from https://techcrunch.com/2018/09/06/british-airways-customer-data-stolen-in-data-breach/

Sunday, November 4, 2018

PDQ breached!



PDQ is a chain restaurant in several states in the US. Although based in Florida, the chicken chain had grown through many states northward. Although popular, there was recently an issue affecting primarily the restaurants in the Triangle in North Carolina (NC).

Attack
If you enjoyed eating at the restaurant within the last year and paid with a credit card, it would be prudent to check your credit accounts in detail, as the credit card information may have been affected by an attack. The business was targeted, the attackers went through their cycle of reconnaissance and other steps, and successfully attacked and compromised their credit card system. Naturally, since this is where the data is located, the attackers focussed their attention on this area.

After the breach was successful, and the attackers removed the data they wished, the compromise was discovered much later, and PDQ hired a cybersecurity firm for the forensic work. The firm assuredly would be much better equipped to research the specifics of the attack and compromise. The focus of this may not be overly singular, as the breached restaurant credit card data may be much more expansive, as in the case the attackers were able to pivot from this point into other data-intensive areas. The restaurant, in response to the confirmed breach, informed the North Carolina Department of Justice on June 23, 2018.

Time Frame
After the forensic team analyzed the breach, the team determined the time frame the attackers had unfettered access was May 19, 2017, to April 20, 2018. The attackers had complete access for the 11 months to the credit card system. The attackers were done with their data gathering in late April 2018. The company learned of the breach on June 8, 2018. If the attackers had not gathered as much data as they did, they would have continued until at least June 8th.

With the expanse of the overall breach, it would be difficult to detail how many of their clients actually were affected. Presumptively, the attackers would work to secure all of the credit card information, however, they may not have gathered everything through the entire time of the compromised system.

Attack Vector
Clearly, the attack was successful, as the attackers had an extended amount of time in the system, unknown to the company, and exfiltrated a large amount of data, also unknown to the cybersecurity team.

The attackers is believed to have gained entry into the system through a third party vendor’s remote connection tool. This is much like so many other compromises of larger company’s systems, including a retail establishment from years ago. Here also the entry to the credit card was through the vendor’s system.

This issue also brings to the forefront the issue of trusting vendors, while not asking them for cybersecurity questionnaires. Seemingly the companies would need to vett the other companies being used for work as a third party. The lack of cybersecurity applied here has been costly to many retail establishments.

Data Exfiltrated
The attackers, of course, had planned on securing the data possible for them to market. This included all or a portion of the client's names, credit card numbers, expiration dates, and cardholder verification values. This data is perfectly useful to sell on the dark web and other places and creates a bit of a bother for the affected parties.

Client Recommendation
As the company was breached and data exfiltrated, the situation obligated some form of guidance for the affected parties to be provided. Not all of the affected parties would be savvy and know what to do, or possibly even have an inclination. The North Carolina Department of Justice recommended freezing their credit with the credit reporting agencies (Equifax, Experian, and Transunion). This is a good step, however, there are issues with this. If the client were to apply for additional credit, the client would need to unfreeze their credit, wait 3-5 days, apply, and later re-freeze their credit. Although this does work well, it tends to be problematic in third-party functionality.

The clients also need to regularly check their credit report, if they do not freeze their credit. This provides for a regular review. If the client’s identity were to be used fraudulently, any issues could be managed early on. Although still requiring effort to remediate, this would contain the on-going issue.

Thoughts
The attackers had access for 11 months. This is clearly by far too long of a time for unauthorized parties to have unfettered access. The InfoSec team or in the least their SIEM should have noticed the strange IP addresses accessing the system at rather unique times, or the data being exfiltrated night after night.

The breach was not visited after April 20, 2018, yet this was not discovered until June 8. This is indicative of the attackers securing their quota of credit card numbers. It may be the attackers had all the data they could use. This interim lag in the time allowed the attackers to begin marketing the data unchecked and unknown to PDQ. Had this been found much earlier, any damage could have been limited in some form or manner.


Resources

CBS 17 Staff. (2018, June 25). PDQ restaurant customer credit card info hacked in ‘cyber attack,’ officials say. Retrieved from http://www.cbs17.com/

Charles, A. (2018, June). Restaurant chain PDQ says customer’s credit card info was hacked. Retrieved from https://www.wral.com/restaurant-chain-pdq-says-customer-s-credit-card-info-was-hacked/17649050/

Derickson, C. (2018, June 26). Chicken chain customers’ credit card information at risk. Retrieved from https://www.newsobserver.com/news/business/article2138644864.html

Goud, N. (2018, June). Database of PDQ restaurant hacked and sensitive info leaked. Retrieved from https://www.cybersecurity-insiders.com/database-of-pdq-restaurant-hacked-and-sensitive-infoleaked 

Malik, J. (2018, June 27). Popular US fast food chain hit by data breach. Retrieved from https://www.informationsecuritybuzz.com/expert-community/popularus-fast-food/

Spectrum News Staff. (2018, June 23). Cyberattack impacts NC PDQ restaurant. Retrieved from https://spectrumlocalnews.com/nc/triangle-sandhills/news/2018/06/23/cyberattack-impacts-nc-pdq-restaurants

WTVD. (2018, June 23). PDQ data breach exposes customers’ credit card information. Retrieved from http://abc11.com/pdq-data-breach-exposes-customers-credit-card-information/3643475

Verdict Food Service. (2018, June 26). Restaurant chain pdq reports data breach incident. Retrieved from https://www.verdictfoodservice.com/news/restaurant-chain-pdq-data-breach/

Sunday, September 23, 2018

Another Municipality with Issues



Government entities tend to have a unique situation. The entity has a set amount of revenue received annually. There are fluctuations with this as property values and taxes fluctuate and other sources of fees are collected. These adjustments are not significant. With the limited resources, the government entities have to plan for activities through the year. These usually cost money and don’t allow for a mass amount of changes. There are also the random events that occur that we try and plan for, which also are an expense unless these are certain events covered by the insurance.
City Payment System Breach
The city uses a system to collect payments from its citizens, much like any other. This makes the citizens paying fees a bit easier for them. This system may be done online and in-person. These payments may be for utilities, municipal court fines, and fees. Due to an unknown issue, the system was compromised. The successful attack allowed these persons to take the user’s credit card information including the credit card numbers, security codes, and expiration dates. Unfortunately, along with this, the user’s first name, last name, middle initial, address, city, state, and zip codes were stolen. The only benefit from this situation is not every citizen was affected. This fortunately excluded the citizens that paid at the 24-hour kiosk with a credit card, and those who paid with a credit card over the phone with the IVR system.
Timing
Breach periods vary for each circumstance. These could vary immensely based on the monitoring, configuration, InfoSec teams, and too many other factors to take into consideration. In this circumstance, the period was approximately eight weeks, from June 18-August 22, 2018. Once the city was notified, the payment system was shut down. The payment system was provided by Superion. The service was Click2Gov software. After the notification, the city began to work with Superion to review the client’s data to ensure it was not affected or modified. As a result of this, the city did implement additional security features.
Follow-Up
As to be expected, the city contacted the pool of potentially affected persons. The city is notifying the affected persons to review their credit card statements for any unauthorized charges. Additionally, the users may ask the credit card company to deactivate their card and request a replacement. To monitor the accounts for fraud, the users are also able to request a fraud alert to be placed on their account.

Even though this is being investigated, there are still many questions surrounding the issue, involving who or which group breached the system. Also the credit card processor, Superion, only has a portion of the credit card payments being affected. Did they have two different systems to process the different types of payments? Also, why didn’t their InfoSec team have a clue this occurred? There had to be a relatively significant amount of traffic to exfiltrate this. This should have shown up with the logs. This is notable as the U.S. Secret Service had to notify the city.

Resources

City of Tyler. (2018). Click2gov payment system security breach. Retrieved from http://www.cityoftyler.org/Departments/TylerWaterUtilities/WaterBillingOffice/PayingYourBill.aspx

Kirst, K. (2018, September 10). What you can do to protect your information. Retrieved from http://knue.com/city-of-tylers-online-payment-system-breached-what-you-can-do-to-protect-your-information/

Mansfield, E. (2018, September 10). U.S. secret service reported software back to city of tyler. Retrieved from https://tylerpaper.com/news/local/u-s-secret-service-reported-software-hack-city-of/

Terry, C. (2018, October 10). City of tyler’s click2gov payment system breached. Retrieved from http://www.kltv.com/story/39060322/city-of-tylers-click2gov-payment-system-breached

Wood, C. (2018, September 10). City of tyler notified of payment system breach. Retrieved from https://www.easttexasmatters.com/news/local-news/city-of-tyler-notified-of-breach-for-system-to-collect-utility-and-court-fee-payments/1431720813