Showing posts with label cybersecurity insurance. Show all posts
Showing posts with label cybersecurity insurance. Show all posts

Saturday, March 9, 2024

Hyundai works through breach

 

From the published accounts, there seems to be an uptick in attacks against the automakers. This could be focused on their sales platform, data warehouse, R&D, or other areas holding some form of data. Nissan was a recent victim as Hyundai India is.

Recently the automaker published a breach through their defenses. The breach allowed the attacker(s) in and allowed them to find data or other useful (e.g., expensive) data. The attacker’s focus for this successful attack had been sensitive customer information (i.e., names, addresses, email addresses, telephone numbers, vehicle specifics, and other client data points) for Hyundai India customers only. A portion of the data is very useful. Other data (e.g., registration numbers, colors, engine numbers, and mileage) could also be used for fraud or other cases of misuse.

This has been corrected; however, the events do provide guidance for us. Even if the business is large and global, there is still the need for SAST and DAST. There are areas and dependencies the programmers will do their best to account for and state it’s good, but it just takes one or two vulnerable areas in all the code to create an issue and RUE (Resume Updating Event). 


Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


Sunday, June 14, 2020

Municipalities targeted: City of Florence pwned!


Municipalities have a very distinct problem. They are frequently targeted for ransomware and other attacks, as the attackers know their systems generally are not fully secure unless they been recently successfully attacked and have corrected and mitigated the issues. This is driven by budgetary constraints, not allowing the city, county, etc. to be able to hire exceptional talent, purchase the tools needed in a timely manner, and other requisite uses for cybersecurity. While this is a Catch-22, it leaves these organizations in the wind, hoping to be obscure enough so that they are not noticed and attacked. Even a failed attack can have negative effects on the operations for many reasons.

 

One of these targeted was the city of Florence, located in Alabama. Florence, much like the city in Italy, sounds like an amazing place to live, located on the banks of the Tennessee River with many festivals and other attractions. This is not a massive metropolis, with nearly 40k residents. Of all the places to target, you have to wonder why Florence?

 

Attack

As you can guess, the city’s computer system had been successfully attacked. The entry points were through the email system. Specifically, this was a phishing attack, and the unfortunate phishee was Steve Price, the IT Manager. His credentials were acquired as part of the attack. The phishing email was one of the many samples of the DHL email, where there are dozens of email recipients, all receiving the same package with the same tracking number on the same day. These emails are pretty obvious as to what they really are there for.

 

The illustrious, yet distinguished Brian Krebs notified the mayor’s office of their system’s compromise on May 26. From the published accounts, the city somehow did not know of the breach prior to this. This is odd, as seemingly someone in the IT Department maybe should have noticed a strange IP address accessing the system and pulling data from the network. The following day the System Administrator did contact Mr. Krebs to let him know the computer and network account affected has been isolated and is not in service. It appears the SysAdmin did not quite understand the capabilities of the attackers at this point. On June 5, 2020, the attackers finished deploying the ransomware and began their demand for the ransom payment. The city has 12 days to fully defend against the attack, however, unfortunately only did a part of the work required to address the issue.

 

When the city began to review the situation, it did not appear any of the affected system’s data had been deleted or exfiltrated. This was probably a little too optimistic for the city.

 

On a side note, the attack occurred while the IT department was attempting to have the City Council approved the expense for a third party to do a penetration test of the IT systems.

 

Ransom

The attackers are not going to work through the attack cycle for practice and their mental gymnastics in an attack. The system has been operationalized into a business, and a rather profitable one measured by the return on investment (ROI). In this case, the attackers were DoppelPaymer. The attackers have demanded the ransom $378k in bitcoin. The amount was negotiated down to $330k by a third-party firm, still in bitcoin. This does seem like a rather large sum, given the size of the city. The attackers, however, have realized the power of their leverage on the systems.

 

Post-Attack

Once the city had the opportunity for a quick review, the city’s IT department and a third-party, contracted by the city (Arete Advisors), began to adequately investigate the issue. As time had passed and more effort was placed into the investigation, the city realized the attackers may have at least a portion of the data on the affected systems. The city noted they just don’t know. One would presume they had sufficient access, such that if they wanted, they could have taken the data they wanted to. On this note, the investigation noted the attackers had access beginning in early May 2020 and continued this for nearly the remainder of the month. During this time, the attackers had free access to roam about and check out the network. They did borrow without authorization the personal information on the city’s employees and customers.

 

As the city saw the writing on the wall, the city council voted unanimously to pay the ransom. The funds were to be paid from the insurance fund available for these types of issues.

 

A curious point with this is the city required the attackers, DoppelPaymer, to provide proof they will delete the stolen information they have. The curiosity is, other than promising or a pinky-swear, there really isn’t a way to prove they will delete the data. This is one of the many problems with paying the ransom. The organization is depending on the attackers to follow through and not leave a back-door or recurring malware on the system. Historically, the attackers have followed through and have not left any surprises behind for later easier attacks. They say there is honor among thieves, however, I would not bet on it. The city naturally is also working with law enforcement in the matter.

 

Update

As of June 13, 2020 (10:46 EST), the online network was down. While the website did note an apology, no reason was given.

 

Afterthought

If you are management, SysAdmin, or on the cybersecurity team, please consider this occurrence or any of the thousands of other successful ransomware attacks as examples of why training and an adequate SIEM is so important. While cybersecurity is the focus of the cybersecurity department or team, it is still everyone’s job to be vigilant and not be click-happy. If they aren’t expecting an email, don’t know the person or organization it is from, or it simply leaves them wondering if the link or attachment is appropriate, don’t do it. This will save so much time, energy, frustration, etc. for the staff and budget.

 

Resources

Associated Press. (2020, June 11). Alabama city to pay $300,000 ransom in computer system hack. Retrieved from https://www.newsobserver.com/news/business/article243452091.html

 

Associated Press. (2020, June 12). Alabama city to pay $30,000 ransom in computer system hack. Retrieved from https://www.securityweek.com/alabama-city-pay-300000-ransom-computer-system-hack

 

Brown, M., & Delinski, B. (2020, June 11). City of Florence out nearly $300,000 after ransomware hack. Retrieved from https://www.waff.com/2020/06/11/city-florence-out-nearly-after-ransomware-hack/

 

City of Florence. (n.d.). Florence, alabama. Retrieved from https://florenceal.org/

 

Delinski, B. (2020, June 11). Florence pays nearly $300,000 in bitcoin ransom. Retrieved from https://www.timesdaily.com/news/local/florence-pays-nearly-300-000-in-bitcoin-ransom/article_5dd1200e-58f6-53a5-a3e1-5d7b90edf179.html

 

Erazo, F. (2020, June 10). Alabama city plans to pay ransomware group despite warnings. Retrieved from https://cointelegraph.com/news/alabama-city-plans-to-pay-ransomware-group-despite-warnings

 

Freedman, L. (2020, June 12). Alabama city hit with ransomware. Retrieved from https://www.jdsupra.com/legalnews/alabama-city-hit-with-ransomware-40970/

 

Goud, N. (2020, June). Ransomware attackers demanding $300,000 from florence city of alabama. Retrieved from https://www.cybersecurity-insiders.com/ransomware-attackers-demanding-300000-from-florence-city-of-alabama/

 

Jackson, J. (2020, June 10). City of Florence agrees to pay nearly $300,000 ransom after cyberattack. Retrieved from  https://whnt.com/news/shoals/city-of-florence-agrees-to-pay-nearly-300000-ransom-after-cyberattack/

 

Krebs, B. (2020, June 9). Florence, Ala. Hit by ransomware 12 days after being alerted by KrebsOnSecurity. Retrieved from https://krebsonsecurity.com/2020/06/florence-ala-hit-by-ransomware-12-days-after-being-alerted-by-krebsonsecurity/

 

Lincoln Journal Star. (2020, June 11). Alabama city to pay $300,000 ransom in computer system hack. Retrieved from https://journalstar.com/business/alabama-city-to-pay-300-000-ransom-in-computer-system-hack/article_70114db5-92bd-5ecb-9a5e-edf5f3cf3b24.html

 

Paganini, P. (2020, June 12). City of Florence to pay $300,000 ransom after ransomware attack. Retrieved from  https://securityaffairs.co/wordpress/104666/breaking-news/city-of-florence-ransomware.html

 

SANS. (2020, June 12). Newsletters: Newsbites. Retrieved from https://www.sans.org/newsletters/newsbites/xxii/47

 

Schwartz, M.J. (2020, June 12). City pays ransom despite pre-ransomware outbreak hack alert. Retrieved from https://www.bankinfosecurity.com/city-pays-ransom-despite-pre-ransomware-outbreak-hack-alert-a-14427

 

 

 


Thursday, November 21, 2019

Watch for supply chain management vulnerabilities


Blue Cross Blue Shield of Michigan is a medical insurer located in MI. Their clients are varied, work for employers- small to large-sized, and are located through the state.
Issue
BCBS uses contractors for various roles throughout the company. One vendor is COBX Co. COBX is a wholly-owned subsidiary of BCBS. The subsidiary is tasked with the Medicare Advantage Services for its clients. An employee of COBX had their laptop stolen on October 26, 2018. BCBS of Michigan notified approximately 15,000 Medicare Advantage members of a potential breach. The notification was done via letter. While this is not a good thing, it is pertinent that at least the laptop was encrypted and did have the password required. Normally, this would be fine if the encryption was above a certain baseline protocol. The problem was the employee’s credentials could have been compromised, meaning the person with the laptop would still be able to access the data.
Data
The affected BCBS customer’s social security numbers and financial information was not accessible from the stolen laptop, fortunately. The data that was available was includes the customer’s first name, last name, date of birth, gender, medication, diagnosis, provider information, and enrollee identification numbers.
Remediation
There had been no direct evidence the customer’s data had been accessed. With this type of issue, although there is no direct type of evidence of this being used for malicious means, it does not mean it has not been used and no guaranty it won’t be used in the near future. BCBS of Michigan noted there is a low chance of identity theft due to the nature of the data involved. BCBS is offering the affected parties AllClearID identity protection services. The term for this service is two years and is free to the customers potentially at risk. The contractor involved did have his credentials changed once the issue came to light. BCBS of Michigan is working with COBX in reviewing its policies and procedures. They are also putting additional safeguards in place.
Comments, Concerns, etc.
The laptop required a password for access and was encrypted, which required another password. Normally, this may be a non-issue, as with most industry-accepted encryption protocols to brute force this or decrypt the data would require several lifetimes. Due to the announcement with the notice of the contractor’s credentials may have been compromised, this nearly leads me to believe the credentials may have been openly accessible as in written on a post-it note on the laptop or otherwise easily acquired.
Resources
BCBS of Michigan. (2019, January 2). Data breach affects 15,000 medicare customers of blue cross blue chield of Michigan. Retrieved from https://www.cisomag.com/data-breach-affects-15000-medicare-customers-of-blue-cross-blue-shield-of-michigan/

Dissent. (2019, January 3). Double whammy: BCBS of Michigan policyholders hit by two breaches in December. Retrieved from https://www.databreaches.net/double-whammy-bcbs-of-michigan-policyholders-hit-by-two-breaches-in-December/

Haefner, M. (2018, December 31). BCBS of Michigan: Data breach may have affected 15,000 medicare members. Retrieved from https://www.beckershospitalreview.com/player-issues/bcbs-of-michigan-data-breach-may-have-affected-15-000-medicare-members.html

HIPAA Journal. (2018, December 31). 15,000 customers notified about blue cross blue shield of Michigan data breach. Retrieved from https://www.hipaajournal.com/15000-customers-notified-about-blue-cross-blue-shield-of-michigan-data-breach/

Livengood, C. (2018, December 28). Blue cross alerts 15,000 medicare customers of potential data breach. Retrieved from https://www.crainsdetroit.com/insurance/blue-cross-alerts-15000-medicare-customers-potential-data-breach

Saturday, September 14, 2019

Android Optimization: Not really!



Of the different phones available, android phones clearly are targeted more often, due to many reasons. These malware examples are regularly detected and reverse engineered. One of the recent examples focused on stealing the user’s PayPal funds. 

Latest Example
This latest excursion into malware was discovered in November 2018 by ESET. The malware is presented as a battery enhancement application. This naturally would attract people to download the app, as most want longer battery length. The app itself is titled Android Optimization. In theory, the app would optimize the device’s battery life. This actually was coded to steal $1k euros in 5 seconds through PayPal. What makes this interesting, other than the coding, is this was being circulated by third parties. Although this appears to be mildly novel, this does allow the application to bypass the Google Play Store and the associated checks on the app and code. 
Operations 
The malware sample was coded to exploit Google’s Accessibility Services. The Accessibility Services generally are used to assist those with disabilities. This instead lures the users to give the attackers control over a portion of the phone. The overt control takes place when the user opens specific applications. These applications primarily are PayPal, Google Play, WhatsApp, Skype, Gmail, and a few other banking apps. This uses two functions to attack the user. The first is a pop-up window, which activates the malicious app. The second is a phishing window placed over legit apps to phish for credit card details and gmail login credentials. 

The interesting part is, with the overlay, these are displayed in the lock foreground screen. The user can’t remove it with the home or back buttons. The only way to remove this is to enter the username and password. Fortunately this accepts whatever the user enters. The user could enter completely false data and still use the phone. The attack fails only when there is not the $1k balance in the PayPal account and no credit card is attached to the account. The malware is activated whenever the PayPal app is opened. 
Nuance 
A majority of the malware in the environment works to steal credentials, which are used in the various forms at a later point. This malware on the other hand does ot focus on this, but simply waits in the background for the user to do the work and log into PayPal. This is coupled with the phishing function. 

There are also different variants to this. This may be coded to intercept and send SMS messages, delete SMS messages, and change the SMS application, secure the user’s contact list, make and forward calls, secure the list of installed apps, and install and run apps. 




Resources
EHacking News. (2018, December 13). Android malware steals 1,000 euros in around 5 seconds via paypal. Retrieved from http://www.ehackingnews.com/2018/12/android-malware-steals-1000-euros-in.html 


The Paypers. (2018, December 29). Android malware steals money fast via paypal. Retrieved from https://www.thepaypers.com/digital-identity-security-online-fraud/android-malware-steals-money-fast-paypal/776413-26 

We Live Security. (2018, December 11). Android trojan steals money from paypal accounts even with 2FA. Retrieved from https://www.welivesecurity.com/2018/12/11/android-trojan-steals-money-paypal-accounts-2fa/

Friday, September 13, 2019

Yet another AWS issue! Capital One breached


Capital One-Yet Another Breach
Charles Parker, II
#
There is a saying that we are our own worst enemy. While we may have the best intentions, at times we may create our own issues which act to our own detriment. This has been notable with a single-use case. The focal point has been with AWS and misconfigured servers. This has created so many issues for the data owners and managers. The latest victim is Capital One due to its misconfigured AWS. This certainly won’t be the last incident through the industry.
Breach
To note this was massive would be an understatement. This is one of the biggest data breaches involving a financial services company. There were 106M persons involved. The affected persons were not only in the US, however, were also located in Canada. The breach was open for an extended period of time, from March 19 through July 17, 2018.
Method
The focal point for the attack was the cloud servers rented from AWS. There was an issue with the cloud configuration. The attack was exceptionally successful due to a misconfigured WedApp firewall. The attackers used a special command to extract the files in the Capital One AWS. Oddly, on June 16, 2019, the attacker posted on Twitter exactly how it was done. This was a very odd event. Generally, if you are going to gain unauthorized entry, you don’t want everyone to know exactly who you are. In this case, the attacker did just this.
Data
The data was related to credit card applications filed between 2005 and early 2019. This is a rather large set of time to exfiltrate data for. The attacker accessed credit applications, social security numbers (approximately 40k in the US and 1M Canada social insurance numbers), bank account numbers (approximately 80k), names, addresses, dates of birth, and financial information (e.g. self-reported credit scores). Fortunately, no credit card account numbers or logins were exposed in the breach. Altogether, the total amount of data was approximately 30GB. Somehow, the attacker was able to exfiltrate this data over months, without anyone or an app examining the login or data access for an extended period.
Perpetrator
The FBI has arrested a person in this case. The speedy arrest was greatly due to the attacker letting everyone know who they are, and not trying to hide anything. The attacker previously worked as an Amazon Web services (AWS) engineer. The attacker’s name of record is Paige A. Thompson. Given her lack of intuitiveness, she is certainly a nominee for the Darwin Award. She bragged about the breach and crime on GitHub and social media. She tried to share the data online and not on the DarkWeb. To top off the award nomination, she used her full first, middle, and last name. She also stored the data in a GitHub account for the user “Netcrave”. The GitHub site also happened to have Paige’s resume (oops). She also used the alias “erratic”.

The criminal complaint was filed in the Western District of Washington. The hearing was on August 1, 2019. To further support the allegation with yet more evidence, the FBI executed a search warrant and seized electronic storage devices. The storage devices contained a copy of the data.
Mitigation
The AWS configuration has been corrected. They stated it was not likely the data was used fraudulently. It is very easy to state this, but exceptionally difficult to guaranty. They did promise to provide 12 months of credit monitoring for affected parties. They also are recommending for the affected parties to watch for phishing emails.

Resources
Corcoran, J. (2019, July 30). Former AWS engineer arrested as capital one admits massive data breach. Retrieved from https://threatpost.com/aws-arrest-data-breach-capital-one/146758/

Krebs, B. (2019, July 19). Capital one data theft impacts 106M people. Retrieved from https://krebsonsecurity.com/2019/07/capital-one-data-theft-impacts-106m-people/

McLean, R. (2019, July 30). A hacker gained access to 100 million capital one credit card applications and accounts. Retrieved from https://www.cnn.com/2019/07/29/business/capital-one-data-breach/index.html

U.S. Attorney’s Office. (2019, July 29). Seattle tech worker arrested for data theft involving large financial services company. Retrieved from https://www.justice.gov/usao-wdwa/pr/seattle-tech-worker-arrested-data-theft-involving-large-financial-services-company

Tuesday, January 8, 2019

Woesnotgone Meadow; December 14, 2018


Woesnotgone Meadow
December 14, 2018
#

All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

Here in the Meadow, we haven’t had too many cybersecurity incidents. Possibly we just aren’t on anyone’s radar...yet. Two towns in Alaska have not been this lucky lately though. These attacks crippled the operations of the towns. Having your PC or smartphone infected, and not functioning is disruptive enough. Having two town’s infrastructure down is certainly not a pleasant experience.

Matanuska-Susitna, Alaska
The incident occurred on July 23, 2018. The compromise caused the town’s operations to shut down. This disrupted the city services and slowed any productivity to a snail’s pace. This also affected Valdez, also in Alaska. The affected systems shut down were for the libraries, swimming pools, e-commerce, the local landfill, animal care, and collections. In addition, the phone systems and door lock card swipe systems were partially disabled. These were located in 73 different buildings.

A devastating effect from the attack involved the email system. After a careful review, it appeared this was not completely recoverable. The attack affected 60 of the Windows 7 PCs initially. When IT began to try and remove the malware, it spread to nearly all of the 500 workstations and 120 of the 150 servers. Although not specifically addressed, it appears this was set to spread once the remediation activity started.

The servers were a victim of ransomware. All of the Windows-based production servers were encrypted. The attackers appear to have done the appropriate level of reconnaissance, as this even affected the back-up and Disaster Recovery (DR) servers. In theory, these should have not been affected as these were engineered and configured to not be vulnerable to the known attacks and exploits. The attackers used the BitPaymer ransomware tool and Emotet Trojan. These leveraged the zero-day attacks. These had apparently been on the system since at least May 3, 2018, with an exploit date of July 23, 2018.

The staff was forced to use a pen, paper, and typewriters. It sounds as though they had a very bad day. The end goal for the attack may not have been totally financial. Due to the robust and well-thought-out nature of the attack, there may have been more involved. To remediate the issue, the borough began to reimage from the back-ups. A portion of these were a year old.

Financially, this attack was rather serious. The total estimated cost was $1.4M to restore the systems and servers. For a town, this is a massive amount. Thankfully, the borough did have $1M of insurance.

Valdez, Alaska
The Alaskan municipalities appear to be viable and continued targets. The city of Valdez was successfully attacked. The Valdez attack was so thorough, the staff was reduced to working with pen and paper. The initial symptom was a few glitches in the system, ranging from not being able to login to accounts to other issues. A few viruses were found at this point, as the attack began on July 25-26, 2019. The issue became significantly worse on Friday with a Police Department website outage. This blossomed until nearly all of the systems had to be shut down, including the phone, email, finance, and payroll. This infected 27 of their servers and 170 computers.

The underlying issue was ransomware. The attack was indeed robust, however, the resident’s personal information did not appear to be compromised. The city contracted with a firm from Virginia for a forensic review. To be proactive, the city is working to have a better method for upgrades and tracking changes. In the short-term, the city did pay the ransom (4 bitcoin, or $26,623.07 at the time) for the decrypt key.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.


Resources
Cimpanu, C. (2018, July 31). BitPaymer ransomware infection forces alaskan town to use typewriters for a week.Retrieved from https://www.bleepingcomputer.com/news/security/bitpayment-ransomware-infection-forces-alaskan-town-to-use-typewriters-for-a-week/

Cimpanu, C. (2018, November 21). City of valdez, alaska admits to paying off ransomware infection. Retrieved from https://www.zdnet.com/article/city-of-valdez-alaska-admits-to-paying-off-ransomeware-infection/

Crawley, K. (2018, September 18). Ransomware cripples an alaskan town. Retrieved from https://blog.comodo.com/comodo-news/ransomware-cripples-an-alaskan-town/

Dunn, J.E. (2018, August 3). Alaskan borough dusts off their typewriters after ransomware crims pwn entire network. Retrieved from https://www.theregister.co.uk/2018/08/03/alaskan-town-has-entire-network-owned-by-ransomware-crims/

Kirby, D. (2018, November 18). Four bitcoin for your data: How a roll of the dice by the city of valdez paid off after a cyber attack. Retrieved from https://www.ktuu.com/content/news/City-of-Valdez-paid-four-bitcoin-ransom-to-recover-data-after-July-cyber-attack-500564211.html

Rogers, J. (2018, August 1). Alaskan borough dusts off typewriters after ransomware attack. Retrieved from https://www.foxnews.com/tech/alaskan-borough-dusts-off-typewriters-after-ransomware-attack

Schroeder, S. (2018, August 2). Ransomware attack forces town’s employees to go back to typewriters. Retrieved from https://mashable.com/article/malware-alaska-town/#edAoW3zC80zX

Sowells, J. (2018, November 25). Valdez city, alaska, the newest victim of ransomware to pay for decryption. Retrieved from https://hackercombat.com/valdez-city-alaska-the-newest-victim-of-ransomware-to-pay-fordecryption/

The Associated Press. (2018, July 28). Virus shuts down city computers in valdez. Retrieved from https://www.usnews.com/news/best-states/alaskan/articles/2018-07-28/virus-shuts-down-city-computers-in-valdez

VanWagenen, J. (2018, August). An alaskan municipality suffers a devastating ransomware attack. Retrieved from https://statetechmagazine.com/article/2018/08/alaska-municipality-suffers-devaststing-ransomeware-attack


Weber, S. (2018, August 1). The valdez star-Serving prince william sound and copper river basin. Retrieved from https://www.valdezstar.net/story/2018/08/01/main-news/hacked-by-cybercriminals-city-website-downed-by-ransomware/1987.html