Showing posts with label data. Show all posts
Showing posts with label data. Show all posts

Sunday, March 24, 2024

Autonomous Vehicles (AVs) have a Substantial Attack Surface

 This is a fantastic age to live in. We have vehicles that notify us when another vehicle is near us, when we’re too close to the vehicle in front of us or the side of the road, when we are sliding inadvertently into the next lane, and log our activities. This is a massive step from the vehicles of 10-15 years ago. The sensors installed within the vehicle offer cutting edge technology for the driver. These also have improved safety for the occupants along with others on the roadmap. Have pentested an AV, I can attest this is a delight.

While I sing the praise of the AVs, there are issues. This has potential threats to the AVs due to the platform, sensors, and OS. These are all new attack surfaces and vulnerabilities. If exploited, these provide an opportunity for disaster. The new threats come from various sources. These new machines, as they are heavily dependent on software, are open to remote attacks. If successful, modules could be compromised. Depending on which one is targeted and breached, there are varying levels of criticality. For instance, steering or brake ECUs are relatively serious.

Data is the new gold and oil. This is especially the case with vehicles. Each collects a mass amount of data from general operations and the sensors. The data may be used in multiple scenarios.

While sensors have improved vehicle operations and safety, there are potential issues here also. The sensors could be spoofed, providing false data to the vehicle and data processing. The fake data could provide a false set of data for the surroundings. This could lead the vehicle on the wrong path.

While this could provide for issues, there are preventive measures to the taken. The software may be hardened, making these more robust. Patching is also pertinent. This occurring regularly limits the attack surface. Encryption should be used with vehicles data and communication. This limits the weak points which are targets.

  

Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


Chicago Children's Hospital Targeted

 

There’s been a lot written about medical facilities being targeted and compromised over the last five years. The compromises have varied with their penetration into the network and data. The greater the attack’s expanse, the more potential for patient suffering. In late January/early February, Lurie Children’s Hospital system was compromised. This was rather significant with their phones, email, internet service, and medical equipment affected. These systems are in different operational areas in their network, which indicates this was a bit more than the usual attack. The department for penetration in the different systems is notable.

The timeframe for the affected systems was relatively short, at two days. This was still devastating for the staff and patients. The situation was further complicated by the data from the operations that did continue having to be merged into existing data sets.

With hospitals holding so much valuable data, this trend will continue if not grow. There is ample to do with all the patient PII, insurance information, medical history, and other data the hospitals have accumulate every day.

To rebound from this is much more than getting the systems up. The security staff needs to also understand the attack vector and how it was implemented, what systems were breached (not only the ones that were overly noticed), and what data was accessed.

The hospital has much work to do with the incident response. This unfortunately is a prime example of what can happen. Systems need not only be secured but monitored and the tooling reviewed at a regular cadence. Just like the industry is dynamic, so is the tolling. There may be better options or configurations available in the next review cycle.

 


Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


Wednesday, February 14, 2024

Targeted Hospitals

 


Hospitals have a prolific amount of data. This isn’t one type of data but covers the patient’s visit and includes all their information for their insurance and diagnosis. This is collected every single day. The mountain of the data warehouse is coveted by attackers, hospital peers due to its value.

The data’s value has drawn numerous attacks over the years with most thankfully being unsuccessful. The successful attacks have proven to be somewhat disastrous affecting already stretched finances and patient care. To support cybersecurity in hospitals, and by extension decrease the number of compromises and breaches, the Biden administration has a new plan. This would force the hospitals to put more effort and resources into cybersecurity. Within the next few months, they plan on pushing a proposal requiring hospitals to put in place basic cybersecurity defenses. Without this in place, the hospitals would no received federal funding.

One area not detailed is the definition of basic digital security defenses. There is an idea in play now for this. One would think these would already being place, especially the present federal statutes in place. This will be interesting from the aspect of what the final definition will be for the cybersecurity tasks and the implementation. This assuredly won’t be cheap. 


Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) 


 charles.parker@mielcybersecurity.net 810-701-5511



Tuesday, January 9, 2024

Diversity of Data

 

I’ve said many times data is the new gold. This may be used/sold many times and cut for the purchaser’s needs. Another aspect which makes this attractive to attackers is diversity. If a company has more than one type of data, there are more targets of different types which could be liberated from the company and sold or ransomed. For example, they may be industrial data with schematics and product design. This would certainly be a crown jewel to seek. Couple this data warehouse with another data set (e.g., consumer data) and there are more targets.

This is notable as Nissan Motor Corporation and Nissan Financial Services in Australia and New Zealand experienced a breach. This was confirmed on December 22, 2023. In this case, the company is assessing the extent of the breach. What is known however is an estimated 100GB of data were stolen by the infamous Akira ransomware group.

While this is troubling, there are lessons to learn from this to assist others in not making the same oversight. With each set of data, a security check should be done. The data could be held in different locations or platforms. Each of these should be reviewed for vulnerabilities. The greater likelihood is these are not co-located and may present unique vulnerabilities on their own.

Thank you.


Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture

Red Team Pentesting | HW & SW BoMs | CBoM | 

Vulnerability Management | Tabletop Exercises (TTX) | 

Embedded Systems Architecture | Threat Intelligence | 

TARA (Threat Assessment and Remediation Analysis) 


Disabled Veteran Owned and Operated 

 


Thursday, June 24, 2021

Here we go again; another ransomware pwnage

 

I remember the days of cameras, purchasing color film or if you wanted to be artsy, using the black & white film. There were several different manufacturers to choose from for the film. With time and technology, there has been a shift from the physical medium to digital. One firm still in the industry is FujiFilm. FujiFilm is probably the best known for its photography equipment. Curiously the company also manufactures a range of medical products. As a large firm, there is ample data gathered everyday from customer interactions, business operations, and other aspects of the business cycle. This provides for a substantial target.

It appears that FujiFilm was targeted and successfully attacked. This was evidenced by the company shutting down a portion of the network and disconnecting this from any external contact. It appears this was de to a ransomware attack.

This continues to be an issue across many industries. With the ease of use for ransomware tools and simply using encryption to accomplish the successful attack, this will likely continue and grow.

 

 

Sunday, June 14, 2020

Municipalities targeted: City of Florence pwned!


Municipalities have a very distinct problem. They are frequently targeted for ransomware and other attacks, as the attackers know their systems generally are not fully secure unless they been recently successfully attacked and have corrected and mitigated the issues. This is driven by budgetary constraints, not allowing the city, county, etc. to be able to hire exceptional talent, purchase the tools needed in a timely manner, and other requisite uses for cybersecurity. While this is a Catch-22, it leaves these organizations in the wind, hoping to be obscure enough so that they are not noticed and attacked. Even a failed attack can have negative effects on the operations for many reasons.

 

One of these targeted was the city of Florence, located in Alabama. Florence, much like the city in Italy, sounds like an amazing place to live, located on the banks of the Tennessee River with many festivals and other attractions. This is not a massive metropolis, with nearly 40k residents. Of all the places to target, you have to wonder why Florence?

 

Attack

As you can guess, the city’s computer system had been successfully attacked. The entry points were through the email system. Specifically, this was a phishing attack, and the unfortunate phishee was Steve Price, the IT Manager. His credentials were acquired as part of the attack. The phishing email was one of the many samples of the DHL email, where there are dozens of email recipients, all receiving the same package with the same tracking number on the same day. These emails are pretty obvious as to what they really are there for.

 

The illustrious, yet distinguished Brian Krebs notified the mayor’s office of their system’s compromise on May 26. From the published accounts, the city somehow did not know of the breach prior to this. This is odd, as seemingly someone in the IT Department maybe should have noticed a strange IP address accessing the system and pulling data from the network. The following day the System Administrator did contact Mr. Krebs to let him know the computer and network account affected has been isolated and is not in service. It appears the SysAdmin did not quite understand the capabilities of the attackers at this point. On June 5, 2020, the attackers finished deploying the ransomware and began their demand for the ransom payment. The city has 12 days to fully defend against the attack, however, unfortunately only did a part of the work required to address the issue.

 

When the city began to review the situation, it did not appear any of the affected system’s data had been deleted or exfiltrated. This was probably a little too optimistic for the city.

 

On a side note, the attack occurred while the IT department was attempting to have the City Council approved the expense for a third party to do a penetration test of the IT systems.

 

Ransom

The attackers are not going to work through the attack cycle for practice and their mental gymnastics in an attack. The system has been operationalized into a business, and a rather profitable one measured by the return on investment (ROI). In this case, the attackers were DoppelPaymer. The attackers have demanded the ransom $378k in bitcoin. The amount was negotiated down to $330k by a third-party firm, still in bitcoin. This does seem like a rather large sum, given the size of the city. The attackers, however, have realized the power of their leverage on the systems.

 

Post-Attack

Once the city had the opportunity for a quick review, the city’s IT department and a third-party, contracted by the city (Arete Advisors), began to adequately investigate the issue. As time had passed and more effort was placed into the investigation, the city realized the attackers may have at least a portion of the data on the affected systems. The city noted they just don’t know. One would presume they had sufficient access, such that if they wanted, they could have taken the data they wanted to. On this note, the investigation noted the attackers had access beginning in early May 2020 and continued this for nearly the remainder of the month. During this time, the attackers had free access to roam about and check out the network. They did borrow without authorization the personal information on the city’s employees and customers.

 

As the city saw the writing on the wall, the city council voted unanimously to pay the ransom. The funds were to be paid from the insurance fund available for these types of issues.

 

A curious point with this is the city required the attackers, DoppelPaymer, to provide proof they will delete the stolen information they have. The curiosity is, other than promising or a pinky-swear, there really isn’t a way to prove they will delete the data. This is one of the many problems with paying the ransom. The organization is depending on the attackers to follow through and not leave a back-door or recurring malware on the system. Historically, the attackers have followed through and have not left any surprises behind for later easier attacks. They say there is honor among thieves, however, I would not bet on it. The city naturally is also working with law enforcement in the matter.

 

Update

As of June 13, 2020 (10:46 EST), the online network was down. While the website did note an apology, no reason was given.

 

Afterthought

If you are management, SysAdmin, or on the cybersecurity team, please consider this occurrence or any of the thousands of other successful ransomware attacks as examples of why training and an adequate SIEM is so important. While cybersecurity is the focus of the cybersecurity department or team, it is still everyone’s job to be vigilant and not be click-happy. If they aren’t expecting an email, don’t know the person or organization it is from, or it simply leaves them wondering if the link or attachment is appropriate, don’t do it. This will save so much time, energy, frustration, etc. for the staff and budget.

 

Resources

Associated Press. (2020, June 11). Alabama city to pay $300,000 ransom in computer system hack. Retrieved from https://www.newsobserver.com/news/business/article243452091.html

 

Associated Press. (2020, June 12). Alabama city to pay $30,000 ransom in computer system hack. Retrieved from https://www.securityweek.com/alabama-city-pay-300000-ransom-computer-system-hack

 

Brown, M., & Delinski, B. (2020, June 11). City of Florence out nearly $300,000 after ransomware hack. Retrieved from https://www.waff.com/2020/06/11/city-florence-out-nearly-after-ransomware-hack/

 

City of Florence. (n.d.). Florence, alabama. Retrieved from https://florenceal.org/

 

Delinski, B. (2020, June 11). Florence pays nearly $300,000 in bitcoin ransom. Retrieved from https://www.timesdaily.com/news/local/florence-pays-nearly-300-000-in-bitcoin-ransom/article_5dd1200e-58f6-53a5-a3e1-5d7b90edf179.html

 

Erazo, F. (2020, June 10). Alabama city plans to pay ransomware group despite warnings. Retrieved from https://cointelegraph.com/news/alabama-city-plans-to-pay-ransomware-group-despite-warnings

 

Freedman, L. (2020, June 12). Alabama city hit with ransomware. Retrieved from https://www.jdsupra.com/legalnews/alabama-city-hit-with-ransomware-40970/

 

Goud, N. (2020, June). Ransomware attackers demanding $300,000 from florence city of alabama. Retrieved from https://www.cybersecurity-insiders.com/ransomware-attackers-demanding-300000-from-florence-city-of-alabama/

 

Jackson, J. (2020, June 10). City of Florence agrees to pay nearly $300,000 ransom after cyberattack. Retrieved from  https://whnt.com/news/shoals/city-of-florence-agrees-to-pay-nearly-300000-ransom-after-cyberattack/

 

Krebs, B. (2020, June 9). Florence, Ala. Hit by ransomware 12 days after being alerted by KrebsOnSecurity. Retrieved from https://krebsonsecurity.com/2020/06/florence-ala-hit-by-ransomware-12-days-after-being-alerted-by-krebsonsecurity/

 

Lincoln Journal Star. (2020, June 11). Alabama city to pay $300,000 ransom in computer system hack. Retrieved from https://journalstar.com/business/alabama-city-to-pay-300-000-ransom-in-computer-system-hack/article_70114db5-92bd-5ecb-9a5e-edf5f3cf3b24.html

 

Paganini, P. (2020, June 12). City of Florence to pay $300,000 ransom after ransomware attack. Retrieved from  https://securityaffairs.co/wordpress/104666/breaking-news/city-of-florence-ransomware.html

 

SANS. (2020, June 12). Newsletters: Newsbites. Retrieved from https://www.sans.org/newsletters/newsbites/xxii/47

 

Schwartz, M.J. (2020, June 12). City pays ransom despite pre-ransomware outbreak hack alert. Retrieved from https://www.bankinfosecurity.com/city-pays-ransom-despite-pre-ransomware-outbreak-hack-alert-a-14427

 

 

 


Wednesday, June 10, 2020

This doesn’t add up: Chartered Professional Accountants Canada Breached!

With most industries, there is a trade association or group. The focus with these is to bring together leaders and members to discuss issues, communicate messages to the membership and be a portal for the industry. Accounting is no different. In the US, we have the AICPA which functions to administer these tasks. This is accomplished is a timely, exceptionally professional manner. Canada is no different in that the accounting industry likewise has this for our northern friends. Another commonality is these are generally targets due to the data they hold for their clients. The Chartered Professional Accountants Canada (CPA Canada) recently found this out, as they were breached.

CPA Canada

Just as the name implies, the organization is involved with Canadian accountants, representing the over 210k members. The organization provides accounting and guidance for its membership. This service is vital for business, accounting firms, and the stock market.

 

Attack

 The organization was unfortunately the victim of a successful phishing attack. The organization on June 3, 2020 notified the affected parties of the breach. Curiously, the organization was aware of the attack on April 24th, meaning it took over a month to notify the persons. The organization will not be disclosing the methodology used in the attack. On a level, this is understandable. The organization may not want the details published as these may be used in other attacks as indications of their security posture. After the issue is corrected though, this could be used as a learning tool or use case for others.

 

Data

CPA Canada definitely held useful information for the attackers to focus on. This included the member's personal information. This included their contact details (names, addresses, email addresses, and employer name). The passwords and credit card numbers, fortunately, were encrypted. The list of persons was primarily composed of the CPA Magazine subscribers. This wasn’t just on the members, but also the stakeholders, totaling over 329k persons.  Granted the data involved was confidential. However, this could have been much worse if the other data was not encrypted, or if the attackers were able to pivot from this point and gain access elsewhere.

 

Post-Breach

The organization has notified its members and others whose data was affected, of the breach. The members and stakeholders were recommended to change their passwords. The organization is also working with cybersecurity personnel to verify the system is secure and exactly what data was copied from them. In addition, they naturally also contact the appropriate law enforcement, the Canadian Anti-Fraud Centre, and other privacy authorities.

 

One point from this to be used is phishing continues to and will be for the foreseeable future, an absolutely viable attack. This has proven to be successful and will not slow down. The organizations need to continue training for this with their employees. The system may be completely secure, however, all it takes is the right person in the right department to click the link, attachment, etc., and we are off to the races.

 

References

Solomon, H. (2020, June 4). Canadian accounting association website gets hacked. Retrieved from https://www.itworldcanada.com/article/canadian-accounting-association-website-gets-hacked/431712

 

Solomon, H. (2020, June 8). Canadian accounting association website gets hacked. Retrieved from https://business.financialpost.com/technology/tech-news/canadian-accounting-association-website-gets-hacked

 

The Canadian Press. (2020, June 4). Canadian accountants’ association suffers cyberattack; data of nearly 330k affected. Retrieved from https://globalnews.ca/news/7025862/cpa-canada-accountants-cyberattack/

 

The IJ Staff. (2020, June 4). CPA Canada hacked, subscriber information exposed. Retrieved from https://insurance-portal.ca/article/cpa-canada-hacked-subscriber-information-exposed/

 


Saturday, May 30, 2020

Sberbank Breached



Banks are located throughout the world. They perform vital services for consumers and commercial organizations in every country they are located in. These are also connected with the respective nation’s banking systems. Another commonality is these hold a mass amount of data also. This is very attractive to the attackers for many reasons. This is also a concern for the consumers, as their personally identifiable information (PII) is in the hands of unauthorized persons. Sberbank is was targeted and data removed without their authorization. Sberbank is Russia’s largest bank, with 45% of all retail deposits within their bank and 41% of the consumer loans held. In this instance, the Russian state owns the controlling stake in the bank.
Attack
Obviously, the attack was successful, which is a problem. The organization estimates the breach occurred near the end of August 2019.  The cause of this breach is unfortunately somewhat common, in the US and abroad. With employees, there is always the chance of the internal threat with the disgruntled, greedy, or unhappy employee. In this case, the bank is reporting the breach of data was due to an employee’s intentional acts. The bank noted it has to be an internal employee due to the data’s location being impossible to breach.

Later, the speculation ended when the bank reported the attacker had been apprehended. During the investigation, the employee had been focused on and eventually confessed. The employee was the head of one of the bank’s divisions. As part of their role, they had access to databases as part of their position, which explains how this was exfiltrated given the data’s remote location and access.
Data
With the attack, millions of Sberbank’s customer's personal data was allegedly initially leaked. Fortunately for the affected persons, the target was the data. The funds in the affected person’s account(s) were not targeted. The bank initially estimated 60M Sberbank credit cardholders have had their personal data stolen and was for sale on the dark web. This estimate appears to have been a bit inflated, and the true number was far less, possibly as low as 5k. The last reported sales price per entry at $0.08/record.

Surprisingly, the data leak and data for sale was not noticed by the bank. For instance, even if the amount of data was the 5k of records, seemingly this would have triggered some form of an alarm. After all, even a division manager probably would not have a need to download 5k individual records. Their position would be more engaged with summaries and forward-looking goals. This oversight was noticed by DeviceLock Cybersecurity, a cybersecurity organization when they noticed the data for sale on the dark web. At times, the seller may make fantastic claims of the data composition for sale. In this case, however, a sample of 200 credit card holder’s data was verified, indicating this is real. The data liberated in this case included the credit card details excluding the three-digit CVV, and place of employment for the last ten years. While the affected persons do have a bit of good news with the CVV not being a part of this, they may still have been targeted for fraud due to the nature of the data itself.
Follow-Through
After the bank was notified, they contacted reported this and is working closely with law enforcement and the Central Bank of Russia to find the culprits. As noted, this was beneficial as the

Resources
Auyezov, O., & Lyrchikova, A. (2019, October 3). Russia’s sberbank investigating potential client data leak. Retrieved from https://www.reuters.com/article/us-sberbank-russia-dataprotection/russias-sberbank-investigating-potential-client-data-leak-idUSKBIN1@i0Wl

Hinchliffe, R. (2019, October 9). Russia’s sberbank catches internal culprit of data leak. Retrieved from https://www.fintechfutures.com/author/hinchliffer/

Leprince-Ringuet, D. (2019, October 4). Russia’s sberbank investigates credit card data leak. Retrieved from https://www.zdnet.com/article/russieas-sberbank-investigates-credit-card-data-leak

Ljubas, Z. (2019, October 19). Russia: Huge data leak hits sberbank. Retrieved from https://www.occrp.org/en/daily/10797-russia-huge-data-leak-hits-sberbank

PMNTS. (2019, October 4). Russia’s sberbank investigating potential client data leak. Retrieved from https://www.pymnts.com/news/security-and-risk/2019/russias-sberbank-investigating-cleint-data-leak/

Spadafora, A. (2019, October 3). Russia’s sberbank hit with huge data leak. Retrieved from https://www.techradar.com/news/russias-sberbank-hit-with-huge-data-leak
The Moscow Times. (2019, October 3). Sberbank hit by huge data breach. Retrieved from https://www.themoscowtimes.com/2019/10/03/sberbank-hit-by-huge-data-breach-a67570

The Moscow Times. (2019, October 3). Sberbank hit by huge data breach. Retrieved from https://www.wedn.com/2019/10/03/sberbank-hit-by-huge-data-breach/

Walker, J. (2019, October 8). Sberbank of Russia completes investigation into the dark web data leak. Retrieved from https://portswigger.net/daily-swig/sberbank-of-russia-completes-investigation-into-dark-web-data-leak  

Tuesday, May 26, 2020

Home Chef’s customer data for sale: Come and get it!



Home Chef, a US-based company, is a meal kit delivery service. If you don’t have time to go to the grocery store and am looking for healthy meals, you can contract with them for meal deliveries to your home. The ingredients show up in a box and you are ready to go! While not an overly complex process, this is still pertinent.

Data Breach
As part of the service, you would pay for the deliveries with your credit card. The company isn’t going to ship your food and hope you pay the bill. The organization does collect certain data from its clients to facilitate this, which is part of the standard operating procedure. Nearly all companies follow this model.  

In this case, there was a successful attack. The compromised customer information included the customer’s name, email address, phone number, and last four digits of the credit card numbers. This would be a much bigger issue; however, the Home Chef does not retain full credit card numbers. In addition, the encrypted passwords and certain account details (e.g. frequency of deliveries and mailing addresses) were also compromised.

Home Chef has not stated how many customers were affected. As a clue to the general number, the attackers responsible for this, Shiny Hunters, claim to be selling approximately 8M records. The price of this database was $2,500. Given the number of records and the data for each record, this is not that bad of a deal. To authenticate, Shiny Hunters also provided a sample.

The attack itself also is a bit of a mystery. The company is not stating this occurred, which is unfortunate. We could use this information as a learning tool. Curiously, Home Chef did not know this had occurred, which is a bit strange as the SIEM should have picked up a bit of unusual activity since, you know, a few records (8M) were compromised and exfiltrated. Home Chef learned of this after they discovered the records were being sold on the dark web. Oops. The InfoSec group probably should have picked up on this. It is also notable, in order to complete this compromise, there would need to be a bit of time involved. It is likely the attackers had access to the systems and data for an extended period as they completed their attack.

Mitigation
Naturally, when this occurs, there is a lot of activity very quickly. The company did state they were taking quick and aggressive actions to investigate the breach.

Follow-Up
Too frequently, companies are not overly aggressive in their timeline to contact law enforcement. Home Chef on the other hand handled this efficiently. And contacted them quickly. The company did email the affected customers, which was done quicker than other firms in like circumstances, which is a good thing. The company is also is recommending the customers change their passwords out of an abundance of caution. Remember, the passwords were encrypted, however, the company may have used weak encryption, which would be a problem.  If these were to be decrypted, there would be a big problem for the customers. This is a good idea also due to the potential for credential stuffing, or the attackers using your password to try access for other accounts. If the users did use the same password across several domains these also should be changed. The customers should also use MFA (multi-factor authentication) moving forward as an additional feature.

Resources
Abrams, L. (2020, May 20). Home chef announces data breach after hacker sells 8M user records. Retrieved from https://www.bleepingcomputer.com/news/security/home-chef-announces-data-breach-after-hacker-sells-8m-user-records/

GearBrain Editorial Team. (2020, May 21). Data breach weekly security report: Which company lost control of your information this week. Retrieved from https://www.gearbrain.com/data-breach-cybersecurity-latest-hacks-2633724298.html

Home Chef Help Center. (2020). Home chef data security incident. Retrieved from https://support.homechef.com/hc/en-us/sections/360008878052-Home-Chef-Data-Security-Incident

Mihalcik, C. (2020, May 20). Home chef confirms data breach after customer info reportedly sold on dark web. Retrieved from https://www.cnet.com/news/home-chef-confirms-data-breach-after-customer-info-reportedly-sold-on-dark-web/

S, G. (2020, May 21). Home chef hacked-Hackers selling 8M user records on a dark web marketplace. Retrieved from https://gbhackers.com/home-chef-hacked/

Whitney, L. (2020, May 21). How home chef’s sensitive data was compromised by a cyberattack. Retrieved from https://www.techrepublic.com/article/how-home-chefs-sensitive-customer-data-was-compromised-by-a-cyberattack/


Sunday, March 8, 2020

Zendesk will need to meditate after this one: Pwned!

Zendesk is a cloud-based ticketing platform widely used. There are 145k customers across 160 countries. With the issue, there are Zendesk “customers” who are companies who have contracted with Zendesk and have embedded their software for customer chat and support ticketing system into the customer’s websites. There are also agents who are the employees of these companies, who are actively managing the tickets and answering the user’s chats.
Breach
Zendesk was breached in November 2016.  This, unfortunately, happens all too often in this day and age. The issue is this was announced in early October 2019. Zendesk stated they just detected the breach on September 24, 2019. Somehow the unauthorized third party was able to compromise the parameter and breach their systems and maintain a presence for nearly three years, unknown and undetected. The circumstances beg the question, how did other organizations accomplish for so long?
To add to this, Zendesk was alerted by a third party of the compromise, per their Updated Notice Regarding the 2016 Security Incident. Both of these combined make one wonder what the cybersecurity team was doing instead of monitoring their logs, operations, etc.
This does sound bad, and it clearly is, however, this goes beyond the normal level of breach. This also lists its customers like Airbnb, Slack, Uber, Shopify, Tesco, and OpenTable.
There are a number of open questions at this time. One of which involves the attacker’s access. Were they able to move laterally whenever they wanted, accessing everything, and only part of the attack was published? The company website noted the company follows industry standards as this relates to storage. While that sounds great, what would this really mean in simple English?
Data
Email addresses, names, and phone numbers of agents (employees of the companies that work with the Zendesk software for ticketing and chats with users) and end-users of certain Zendesk products were included in the compromise. Also, agent and end-user passwords (these were hashed and salted), TLS encryption keys for approximately 700 clients, configuration settings of apps installed from the Zendesk app marketplace or private applications. These were in a database, which the attackers were able to gain access to. Thus, there was PII involved with the compromise, which did not help the situation much.
The data affected was for tens of thousands of persons. On September 24, 2019, they identified nearly 15k Zendesk Support and Chat accounts affected by this. Later, approximately 7k customer accounts, some no longer active, had their authentication information accessed.
Post-Compromise

The attackers did access 10k passwords. While this is a detriment, Zendesk noted they detected no evidence that the passwords were used in a malicious manner.
Zendesk appreciates the level of error this involves. To address this, they have expanded their single sign-on (SSO) and multi-factor authentication across their workspaces increased their security monitoring and logging, increased security scanning at the application level and corporate enterprise. Zendesk is also expanding its third party testing. This should definitely assist with the prevention of future issues.
Zendesk also has contacted law enforcement, naturally, and forensic experts to help with the breach investigation.
There have been financial repercussions from this also. Zendesk (NYSE: ZEN) lost approximately 4% of its stock value the day after the disclosure. The markets watch this type of activity closely in the short term.
Notification
Of all their clients, the affected sample is, fortunately, a small ratio of their entire customer base. This could easily have been much worse.
Given the magnitude and depth of the breach, Zendesk was required to notify the affected parties. This was done with the mass number of emails. Zendesk also plans on a large password reset for the users in the system prior to November 1, 2016. This is a massive task. There are going to be many, many calls to the IT Help Desk from the affected parties. Fortunately, if anyone had changed their password since the breach or who have been using the single sign-on (SSO) are exempt from this. This will reduce the potential call-load for complaints and questions.
Not the first rodeo
Usually, a company gets pwned once at this scale and there are no issues heard for a long-long time. Well, this isn’t Zendesk’s first incident with this type of issue. Zendesk was also successfully attacked in 2013. This breach affected Twitter, Tumblr, and Pinterest.
Resources
Betz, B. (2019, October 2). Zendesk -4% after disclosing data breach. Retrieved from https://seekingalpha.com/news/3503496-zendeskminus-4-after-disclosing-data-breach
Cimpanu, C. (2019, October 12). Zendesk discloses 2016 data breach. Retrieved from https://www.zdnet.com/article/zendesk-discloses-2016-data-breach/
Daniel, E. (2019, October 22). Zendesk-Discloses 2016 data breach after three years. Retrieved from https://medium.com/datadriveninvestor/zendesk-discloses-2016data-breach-after=three-years-i-e-on-september-24-2019-820d14d14fa0bea
Duran. (2019, October 3). Zendesk reveals that a data breach affected the emails and passwords of 10,000 users in 2016. Retrieved from https://www.cyclonis.com/zendesk-reveals-data-breach-affected-emails-passwords-10000-users-2016/
Gatlan, S. (2019, October 2). Zendesk security breach may impact orgs like uber, slack, and fcc. Retrieved from https://www.bleepingcomputer.com/news/security/zendesk-security-breach-may-impact-orgs-like-uber-slack-and-fcc/
Hashim, A. (2019, October 3). Zendesk alerts users of data breach that occurred in 2016! Retrieved from https://latesthackingnews.com/2019/10/03/zendesk-alerts-users-of-data-breach-that-occurred-in-2016/
Heller, M. (2019, October 3). Zendesk breach in 2016 affected 10,000 customers. Retrieved from https://searchsecurity.techtarget.com/news/252471927/Zendesk-breach-in-2016-affected-10000-customers
Kovacs, E. (2019, October 3). Zendesk discloses old data breach affecting 10,000 accounts. Retrieved from https://www.securiytweek.com/zendesk-discloses-old-data-breach-affecting-10000-accounts
Muncaster, P. (2019, October 3). Zendesk breach hits 10,000 corporate accounts. Retrieved form https://www.infosecurity-magazine.com/news/zendesk-breach-hits-10000/
Panettieri, J. (2019, October 2). Zendesk discloses chat data breach. Retrieved from https://www.channele2e.com/technology/security/zendesk-chat-data-breach/
Paganini, P. (2019, October 2). Zendesk 2016 security breach may impact uber, slack, and other organizations. Retrieved from https://securityaffairs.co/wordpress/92051/data-breach/zendesk-2016-security-breach.html
Payne, D. (2019, October 2). Zendesk has disclosed a 2016 data breach. Retrieved from https://www.internetnewsflash.com/zendesk-has-disclosed-a-2016-data-breach/
Pawluk, A. (2019, October 3). Security breach in zendesk discovered. Retrieved from https://blog.verohum.com/news/security-breach-in-zendesk-discovered/
Secure Reading. (2019, October 3). Zendesk discloses security breach. Retrieved from https://securereading.com/zendesk-discloses-security-breach/
Swartz, J. (2019, October 2). Shares of Zendesk drop 4% after it discloses security breach. Retrieved from https://www.marketwatch.com/story/shares-of-zendesk-drop-4-after-it-discloses-security-breach-2019-10-02
Van Horenbeeck, M. (2019, November 22). Updated notice regarding 2016 security incident. Retrieved from https://www.zendesk.com/blog/security-update-2019/
Winant, D. (2019, October 6). Zendesk discloses 2016 data breach. Retrieved from https://seclists.org/dataloss/2019/q4/20



Monday, March 2, 2020

EA's code oversight


Everyone loves a good video game every now and again. These vary in their genre and computing power. These grasp and hold the player’s attention for hours upon hours. This has grown into such an industry, there are massive corporations creating and hosting these games, and also hosting the tournaments. One example is Electronic Arts (EA).
Issue
As part of its services, EA offers a tournament series. The subject here is EA’s FIFA 20 Global Series. To those unfamiliar with the group and game, this is a big deal. This is a $3M competitive circuit. This is a rather competitive tournament using the organizations’ FIFA 20 soccer-themed game and the focus. There just happened to be a minor issue with this. On October 3, 2019, right after the website used to sign people up was put online, the gamers noted immediately the other person’s private information was being leaked. EA inadvertently leaked approximately 1,600 user’s personal data, who previously entered the data with EA’s service.
Data
What would happen is the gamer would enter their information and while entering their respective information, the gamers were shown other gamer’s data. Naturally, this created an issue as the gamer is not going to confirm other gamer’s information as to their own. The leaked data included the user/player’s ID, birthday, email address(es), and country of origin. While this is not a good thing, it could have been much worse. This is more embarrassing than an epic fail. Once the leak was discovered, the website was taken down, which took approximately 30 minutes. While this is much quicker than other companies, this still allowed for 1,600 user’s information to be leaked. This quick response was definitely a positive thing. If they would have been the victim of paralysis by analysis, this would have been much worse.
Remediation
EA has apologized for their oversight, which is fair. At this point, no information or data was leaked which could be used for identity theft. This was, however, their oversight and a portion of the affected gamers are still displeased with EA.
Resources
Carpenter, N. (2019, October 4). EA data breach could impact 1,600 FIFA 20 players. Retrieved from https://www.polygon.com/2019/10/4/20898543/fifa-20-global-series-data-breach-ea-sports
Cimpanu, C. (2019, October 4). EA website snafu leaks data of 1,600 FIFA 20 pro gamers. Retrieved from https://www.zdnet.com/article/ea-website-snafu-leaks-data-of-1600-fifa-20-pro-gamers/
Lyles, T. (2019, October 4). EA discloses massive data breach affected thousands of competitive FIFA players. Retrieved from https://www.digitaltrends.com/gaming/ea-fifa-data-breach/

Tuesday, October 22, 2019

Just when you think it can't get any worse: VFEmail attack

Organizations have a few options when it comes to their email service. They could have this on-premises, or with a service. One such service is VFEmail. The paramount aspect of this service is the data. Without the emails, active and archived, there are issues. These show up pretty much immediately also. Misplacing this is unthinkable. Losing this permanently would be epic. To state this would be a nightmare would be an understatement. Unfortunately, this occurred in February 2019 with VFEmail when the organization was successfully attacked, deleting the current data and backups. 

VFEmail.net was a US-based secure, private email provider. The organization was started in 2001 by Rick Romero. The organization provided the services free and for a fee. 
Attack
The attack took place on February 11. The staff happened to notice a problem when its servers went offline. There was no anticipated outage planned, which made this especially odd. The attacker was caught during the backup server being formatted. This particular server was located in the Netherlands. The end result of the attack was all the disks were completely wiped. This erased the organization’s entire infrastructure. This included the mail hosts, VM hosts, and a SQL server cluster. The attack appeared to have originated from IP 94.155.49.9 with the username “aktv”. This is registered in Bulgaria. All this damage occurred within a few hours. Fortunately, the servers in the Netherlands with the backups were not affected. 
Data 
The affected data included emails and backup files. In effect, this deleted nearly 20 years of data. The odd aspect of this attack was there was not a reason to delete the data. There was no ransom request ignored or other rationales to do this. The attackers just did it. These are generally the more encountered attacks. 
Post-Attack
The attacker was still unknown. Also, the attack method has not been published. VFEmail rebounding from this will be difficult, not only from the technical aspect but also from customer rapport. 

Resources
Al-Heeti, A. (2019, February 12). Email provider hack destroys nearly two decades’ worth of data. Retrieved from https://www.cnet.com/news/email-provider-hack-destroys-nearly-two-decades-worth-of-data/ 

Boyd, C. (2019, February 14). Hacker destroys VFEmail service, wipes backups. Retrieved from https://blog.malwarebytes.com/cybercrime/2019/02/hacker-destroys-vfemail-service-wipes-backups/ 

Emerson L. Sullivan. (2019, February 18). Hackers destroyed VFEmail service-Deleted its entire data and backups within hours. Retrieved from https://blog.yoocare.com/hackers-destroyed-vfemail-service-deleted-entire-data-backups-within-hours/ 

Goodin, D. 92019, February 12). “Catastrophic” hack on email provider destroys almost two decades of data. Retrieved from https://arstechnica.com/information-technology/2019/02/catastrophic-hack-on-email-provider-destroys-almost-two-decades-of-data/ 

Khandelwal, S. (2019, February 13). Hackers destroyed VFEmail service-deleted its entire data and backups. Retrieved from https://thehackernews.com/2019/02/vfemail-cyber-attack.html 

Krebs, B. (2019, February 19). Email provider VFEmai suffers “catastrophic” hack. Retrieved from https://krebsonsecurity.com/2019/02/email-provider-vfemail-suffers-catastrophic-hack/ 

Paganini, P. (2019, February 13). Hacker deleted all data from VFEmail servers, including backups. Retrieved from https://securityaffairs.co/wordpress/81030/hacking/femail-destructive-cyberattack.html 

Reynolds, C. (2019, February 13). “Catastrophic destruction”: Hacker takes a match to email provider. Retrieved from https://www.cbronine.com/author/conor/ 

Tech Info Gig. (2019, February 19). Hackers destroyed VFEmail service deleted its entire data and backups. Retrieved from https://techinfogig.blogspot.com/2019/02/hackers-destroyed-service.html