Showing posts with label data breach. Show all posts
Showing posts with label data breach. Show all posts

Wednesday, November 20, 2024

Data theft-It’s not just for medical facilities

 There’s been volumes written about data theft in medical facilities, methods, and effects. This is no

wonder given the mountain of data created daily from the patient care and operations. Another viable

target would be auto dealerships. This hold much the same data hospital would generally. When a

person purchases their vehicle, as a course of the process, they provide their name, address, data of

birth, SSN, financial information, and other data. The hospital or medical care facility collects much the

same, with additional data for the patient care.

In this case an automotive dealership was compromised. On or about May 27, 2023, the Jeff Wyler

Automotive Family an unauthorized party compromised their perimeter security and was able to access

the consumer information (e.g., name, date of birth, SSN, driver’s license or state ID #, medical

information, health insurance information, and financial information). This was detected on January 29,

2024.

The method of attack unfortunately was not detailed. Anytime this event occurs, there’s something to

learn and use to build up your defenses. This experience does highlight the need for regular

cybersecurity assessments. This, depending on the environment and budget, may consist of vulnerability

scans, per tests, and threat feeds for your equipment. This also includes working on the vulnerabilities to

remove these and secure your system.

Sunday, June 14, 2020

Municipalities targeted: City of Florence pwned!


Municipalities have a very distinct problem. They are frequently targeted for ransomware and other attacks, as the attackers know their systems generally are not fully secure unless they been recently successfully attacked and have corrected and mitigated the issues. This is driven by budgetary constraints, not allowing the city, county, etc. to be able to hire exceptional talent, purchase the tools needed in a timely manner, and other requisite uses for cybersecurity. While this is a Catch-22, it leaves these organizations in the wind, hoping to be obscure enough so that they are not noticed and attacked. Even a failed attack can have negative effects on the operations for many reasons.

 

One of these targeted was the city of Florence, located in Alabama. Florence, much like the city in Italy, sounds like an amazing place to live, located on the banks of the Tennessee River with many festivals and other attractions. This is not a massive metropolis, with nearly 40k residents. Of all the places to target, you have to wonder why Florence?

 

Attack

As you can guess, the city’s computer system had been successfully attacked. The entry points were through the email system. Specifically, this was a phishing attack, and the unfortunate phishee was Steve Price, the IT Manager. His credentials were acquired as part of the attack. The phishing email was one of the many samples of the DHL email, where there are dozens of email recipients, all receiving the same package with the same tracking number on the same day. These emails are pretty obvious as to what they really are there for.

 

The illustrious, yet distinguished Brian Krebs notified the mayor’s office of their system’s compromise on May 26. From the published accounts, the city somehow did not know of the breach prior to this. This is odd, as seemingly someone in the IT Department maybe should have noticed a strange IP address accessing the system and pulling data from the network. The following day the System Administrator did contact Mr. Krebs to let him know the computer and network account affected has been isolated and is not in service. It appears the SysAdmin did not quite understand the capabilities of the attackers at this point. On June 5, 2020, the attackers finished deploying the ransomware and began their demand for the ransom payment. The city has 12 days to fully defend against the attack, however, unfortunately only did a part of the work required to address the issue.

 

When the city began to review the situation, it did not appear any of the affected system’s data had been deleted or exfiltrated. This was probably a little too optimistic for the city.

 

On a side note, the attack occurred while the IT department was attempting to have the City Council approved the expense for a third party to do a penetration test of the IT systems.

 

Ransom

The attackers are not going to work through the attack cycle for practice and their mental gymnastics in an attack. The system has been operationalized into a business, and a rather profitable one measured by the return on investment (ROI). In this case, the attackers were DoppelPaymer. The attackers have demanded the ransom $378k in bitcoin. The amount was negotiated down to $330k by a third-party firm, still in bitcoin. This does seem like a rather large sum, given the size of the city. The attackers, however, have realized the power of their leverage on the systems.

 

Post-Attack

Once the city had the opportunity for a quick review, the city’s IT department and a third-party, contracted by the city (Arete Advisors), began to adequately investigate the issue. As time had passed and more effort was placed into the investigation, the city realized the attackers may have at least a portion of the data on the affected systems. The city noted they just don’t know. One would presume they had sufficient access, such that if they wanted, they could have taken the data they wanted to. On this note, the investigation noted the attackers had access beginning in early May 2020 and continued this for nearly the remainder of the month. During this time, the attackers had free access to roam about and check out the network. They did borrow without authorization the personal information on the city’s employees and customers.

 

As the city saw the writing on the wall, the city council voted unanimously to pay the ransom. The funds were to be paid from the insurance fund available for these types of issues.

 

A curious point with this is the city required the attackers, DoppelPaymer, to provide proof they will delete the stolen information they have. The curiosity is, other than promising or a pinky-swear, there really isn’t a way to prove they will delete the data. This is one of the many problems with paying the ransom. The organization is depending on the attackers to follow through and not leave a back-door or recurring malware on the system. Historically, the attackers have followed through and have not left any surprises behind for later easier attacks. They say there is honor among thieves, however, I would not bet on it. The city naturally is also working with law enforcement in the matter.

 

Update

As of June 13, 2020 (10:46 EST), the online network was down. While the website did note an apology, no reason was given.

 

Afterthought

If you are management, SysAdmin, or on the cybersecurity team, please consider this occurrence or any of the thousands of other successful ransomware attacks as examples of why training and an adequate SIEM is so important. While cybersecurity is the focus of the cybersecurity department or team, it is still everyone’s job to be vigilant and not be click-happy. If they aren’t expecting an email, don’t know the person or organization it is from, or it simply leaves them wondering if the link or attachment is appropriate, don’t do it. This will save so much time, energy, frustration, etc. for the staff and budget.

 

Resources

Associated Press. (2020, June 11). Alabama city to pay $300,000 ransom in computer system hack. Retrieved from https://www.newsobserver.com/news/business/article243452091.html

 

Associated Press. (2020, June 12). Alabama city to pay $30,000 ransom in computer system hack. Retrieved from https://www.securityweek.com/alabama-city-pay-300000-ransom-computer-system-hack

 

Brown, M., & Delinski, B. (2020, June 11). City of Florence out nearly $300,000 after ransomware hack. Retrieved from https://www.waff.com/2020/06/11/city-florence-out-nearly-after-ransomware-hack/

 

City of Florence. (n.d.). Florence, alabama. Retrieved from https://florenceal.org/

 

Delinski, B. (2020, June 11). Florence pays nearly $300,000 in bitcoin ransom. Retrieved from https://www.timesdaily.com/news/local/florence-pays-nearly-300-000-in-bitcoin-ransom/article_5dd1200e-58f6-53a5-a3e1-5d7b90edf179.html

 

Erazo, F. (2020, June 10). Alabama city plans to pay ransomware group despite warnings. Retrieved from https://cointelegraph.com/news/alabama-city-plans-to-pay-ransomware-group-despite-warnings

 

Freedman, L. (2020, June 12). Alabama city hit with ransomware. Retrieved from https://www.jdsupra.com/legalnews/alabama-city-hit-with-ransomware-40970/

 

Goud, N. (2020, June). Ransomware attackers demanding $300,000 from florence city of alabama. Retrieved from https://www.cybersecurity-insiders.com/ransomware-attackers-demanding-300000-from-florence-city-of-alabama/

 

Jackson, J. (2020, June 10). City of Florence agrees to pay nearly $300,000 ransom after cyberattack. Retrieved from  https://whnt.com/news/shoals/city-of-florence-agrees-to-pay-nearly-300000-ransom-after-cyberattack/

 

Krebs, B. (2020, June 9). Florence, Ala. Hit by ransomware 12 days after being alerted by KrebsOnSecurity. Retrieved from https://krebsonsecurity.com/2020/06/florence-ala-hit-by-ransomware-12-days-after-being-alerted-by-krebsonsecurity/

 

Lincoln Journal Star. (2020, June 11). Alabama city to pay $300,000 ransom in computer system hack. Retrieved from https://journalstar.com/business/alabama-city-to-pay-300-000-ransom-in-computer-system-hack/article_70114db5-92bd-5ecb-9a5e-edf5f3cf3b24.html

 

Paganini, P. (2020, June 12). City of Florence to pay $300,000 ransom after ransomware attack. Retrieved from  https://securityaffairs.co/wordpress/104666/breaking-news/city-of-florence-ransomware.html

 

SANS. (2020, June 12). Newsletters: Newsbites. Retrieved from https://www.sans.org/newsletters/newsbites/xxii/47

 

Schwartz, M.J. (2020, June 12). City pays ransom despite pre-ransomware outbreak hack alert. Retrieved from https://www.bankinfosecurity.com/city-pays-ransom-despite-pre-ransomware-outbreak-hack-alert-a-14427

 

 

 


Wednesday, June 10, 2020

This doesn’t add up: Chartered Professional Accountants Canada Breached!

With most industries, there is a trade association or group. The focus with these is to bring together leaders and members to discuss issues, communicate messages to the membership and be a portal for the industry. Accounting is no different. In the US, we have the AICPA which functions to administer these tasks. This is accomplished is a timely, exceptionally professional manner. Canada is no different in that the accounting industry likewise has this for our northern friends. Another commonality is these are generally targets due to the data they hold for their clients. The Chartered Professional Accountants Canada (CPA Canada) recently found this out, as they were breached.

CPA Canada

Just as the name implies, the organization is involved with Canadian accountants, representing the over 210k members. The organization provides accounting and guidance for its membership. This service is vital for business, accounting firms, and the stock market.

 

Attack

 The organization was unfortunately the victim of a successful phishing attack. The organization on June 3, 2020 notified the affected parties of the breach. Curiously, the organization was aware of the attack on April 24th, meaning it took over a month to notify the persons. The organization will not be disclosing the methodology used in the attack. On a level, this is understandable. The organization may not want the details published as these may be used in other attacks as indications of their security posture. After the issue is corrected though, this could be used as a learning tool or use case for others.

 

Data

CPA Canada definitely held useful information for the attackers to focus on. This included the member's personal information. This included their contact details (names, addresses, email addresses, and employer name). The passwords and credit card numbers, fortunately, were encrypted. The list of persons was primarily composed of the CPA Magazine subscribers. This wasn’t just on the members, but also the stakeholders, totaling over 329k persons.  Granted the data involved was confidential. However, this could have been much worse if the other data was not encrypted, or if the attackers were able to pivot from this point and gain access elsewhere.

 

Post-Breach

The organization has notified its members and others whose data was affected, of the breach. The members and stakeholders were recommended to change their passwords. The organization is also working with cybersecurity personnel to verify the system is secure and exactly what data was copied from them. In addition, they naturally also contact the appropriate law enforcement, the Canadian Anti-Fraud Centre, and other privacy authorities.

 

One point from this to be used is phishing continues to and will be for the foreseeable future, an absolutely viable attack. This has proven to be successful and will not slow down. The organizations need to continue training for this with their employees. The system may be completely secure, however, all it takes is the right person in the right department to click the link, attachment, etc., and we are off to the races.

 

References

Solomon, H. (2020, June 4). Canadian accounting association website gets hacked. Retrieved from https://www.itworldcanada.com/article/canadian-accounting-association-website-gets-hacked/431712

 

Solomon, H. (2020, June 8). Canadian accounting association website gets hacked. Retrieved from https://business.financialpost.com/technology/tech-news/canadian-accounting-association-website-gets-hacked

 

The Canadian Press. (2020, June 4). Canadian accountants’ association suffers cyberattack; data of nearly 330k affected. Retrieved from https://globalnews.ca/news/7025862/cpa-canada-accountants-cyberattack/

 

The IJ Staff. (2020, June 4). CPA Canada hacked, subscriber information exposed. Retrieved from https://insurance-portal.ca/article/cpa-canada-hacked-subscriber-information-exposed/

 


Tuesday, May 26, 2020

Home Chef’s customer data for sale: Come and get it!



Home Chef, a US-based company, is a meal kit delivery service. If you don’t have time to go to the grocery store and am looking for healthy meals, you can contract with them for meal deliveries to your home. The ingredients show up in a box and you are ready to go! While not an overly complex process, this is still pertinent.

Data Breach
As part of the service, you would pay for the deliveries with your credit card. The company isn’t going to ship your food and hope you pay the bill. The organization does collect certain data from its clients to facilitate this, which is part of the standard operating procedure. Nearly all companies follow this model.  

In this case, there was a successful attack. The compromised customer information included the customer’s name, email address, phone number, and last four digits of the credit card numbers. This would be a much bigger issue; however, the Home Chef does not retain full credit card numbers. In addition, the encrypted passwords and certain account details (e.g. frequency of deliveries and mailing addresses) were also compromised.

Home Chef has not stated how many customers were affected. As a clue to the general number, the attackers responsible for this, Shiny Hunters, claim to be selling approximately 8M records. The price of this database was $2,500. Given the number of records and the data for each record, this is not that bad of a deal. To authenticate, Shiny Hunters also provided a sample.

The attack itself also is a bit of a mystery. The company is not stating this occurred, which is unfortunate. We could use this information as a learning tool. Curiously, Home Chef did not know this had occurred, which is a bit strange as the SIEM should have picked up a bit of unusual activity since, you know, a few records (8M) were compromised and exfiltrated. Home Chef learned of this after they discovered the records were being sold on the dark web. Oops. The InfoSec group probably should have picked up on this. It is also notable, in order to complete this compromise, there would need to be a bit of time involved. It is likely the attackers had access to the systems and data for an extended period as they completed their attack.

Mitigation
Naturally, when this occurs, there is a lot of activity very quickly. The company did state they were taking quick and aggressive actions to investigate the breach.

Follow-Up
Too frequently, companies are not overly aggressive in their timeline to contact law enforcement. Home Chef on the other hand handled this efficiently. And contacted them quickly. The company did email the affected customers, which was done quicker than other firms in like circumstances, which is a good thing. The company is also is recommending the customers change their passwords out of an abundance of caution. Remember, the passwords were encrypted, however, the company may have used weak encryption, which would be a problem.  If these were to be decrypted, there would be a big problem for the customers. This is a good idea also due to the potential for credential stuffing, or the attackers using your password to try access for other accounts. If the users did use the same password across several domains these also should be changed. The customers should also use MFA (multi-factor authentication) moving forward as an additional feature.

Resources
Abrams, L. (2020, May 20). Home chef announces data breach after hacker sells 8M user records. Retrieved from https://www.bleepingcomputer.com/news/security/home-chef-announces-data-breach-after-hacker-sells-8m-user-records/

GearBrain Editorial Team. (2020, May 21). Data breach weekly security report: Which company lost control of your information this week. Retrieved from https://www.gearbrain.com/data-breach-cybersecurity-latest-hacks-2633724298.html

Home Chef Help Center. (2020). Home chef data security incident. Retrieved from https://support.homechef.com/hc/en-us/sections/360008878052-Home-Chef-Data-Security-Incident

Mihalcik, C. (2020, May 20). Home chef confirms data breach after customer info reportedly sold on dark web. Retrieved from https://www.cnet.com/news/home-chef-confirms-data-breach-after-customer-info-reportedly-sold-on-dark-web/

S, G. (2020, May 21). Home chef hacked-Hackers selling 8M user records on a dark web marketplace. Retrieved from https://gbhackers.com/home-chef-hacked/

Whitney, L. (2020, May 21). How home chef’s sensitive data was compromised by a cyberattack. Retrieved from https://www.techrepublic.com/article/how-home-chefs-sensitive-customer-data-was-compromised-by-a-cyberattack/


Saturday, May 16, 2020

Canadian University Breached



Universities have been targeted for well over a decade. These institutions are the steward of their student’s data and information. As this is valuable for the persons attacking the institutions, the attacks tend to be rather frequent. Recently, York University, a university in Canada was successfully attacked.
Attack Timing
When you are planning an attack, you probably don’t want to begin this when the cybersecurity staff is there, monitoring the systems, and ready to address the attack right after it is detected. It would be much better to wait until there is not a full staff present to work to stop the attack.

The attackers took the page from the standardized attack playbook and began their attack on Friday evening. At this point, the staff was headed home for the weekend and not thinking about cybersecurity.

Attack
The attackers were focused on the areas which were holding the data, which they were seeking to exfiltrate. The target, in this case, were the servers and workstations at the University.

Mitigation
While the attack was timed well, the staff was able to detect this quickly. Without their work, the attack effects would have been much worse. The staff was able to directly address this to limit the successful aspects of the attack. The primary method to resolve this was to shut down the University’s computer systems, disconnecting these from the internet.

After the attack, they also contracted with external computer forensic professionals. Their role was to fully research the attack. The attack, per the University, was complex. Regardless of this, the research work will take a fair amount of time to fully complete.

Over the weekend the University was able to restore the Office 365, password change, on-campus student access to the internet, and the University website.

The University also worked on restoring the VPN for HR and Finance, central mail, and the remaining faculty websites.

The University is requiring everyone with the University to reset their passwords. This was directly due to the successful attack.

Additional Information?
At this stage, there has not been much information provided. The forensic examination would require the time needed to fully explore the attack. As much as possible, every facet needs to be detailed and correct.

While this is the standard operating procedure, the University has not provided much information regarding the attack. This should be released so that the industry can learn from this.
One aspect the students did not appreciate was the lack of communication from the attack. The University did not communicate this to the students. The students had to learn of this from statements posted online and on social media. With an attack of this nature, potentially having their data compromised to whoever did the attack, really should have had an official communication.

Resources
Cameroon Magazine. (2020, April 5). York university falls victim to a serious attack. Retrieved from https://fr.cameroonmagazine.com/actualite-internationale/york-university-falls-victim-to-a-serious-cyber-attack-news/
CBC News. (2020, May 4). Students, experts call for explanation after York university suffers ‘extremely serious’ cyber attack. Retrieved from https://www.cbc.ca/news/canada/toronto/york-university-cyber-attack-1.5555106  
DH Toronto Staff. (2020, May 4). York university falls victim to a “serious cyber attack”. Retrieved from https://dailyhive.com/toronto/york-university-serious-cyber-attack  

Wednesday, April 29, 2020

Lesson one: If you have a breach communicate


Universities are frequently targeted due to the amount of personal, confidential data being held. This is accumulated as part of the application process, along with on-going course attendance. One recent target has been the University of Warwick. The university is located in the Coventry in the UK, and is part of the Russell Group. While the details of the successful attack have not been published, this attack may have been invited in by one of the users. The issue may have all started with a user installing remote viewing software in 2019. At this point, the attackers were able to gain a foothold into the system and pivot into other areas, providing the data and information they sought.

Data
As to be expected, the attack had a focus. In this case, it was the usual data and information. The breach allowed the attackers access to student information. The attackers had also access to the staff and volunteer private information. This would provide the attackers the data needed for various unlawful acts, including taking over someone’s identity, getting credit in the other person’s name, and other fraudulent acts.

Multiple Breaches
In general, one breach is a bad operational defect. This can be devastating to the university, staff, and students in the short- and long-term. This can reach into the full network, or sections, based on the attack and target. If the attacker simply wants to exfiltrate data quickly that is marketable, they may breach the accounting or Human Resource networks. If they want to own the system and possibly extort funds, this is yet another avenue that may be best attacked with ransomware or other malware. In this case, the University was breached several times.

Problematic Factors
Simply stated, the university was breached. Granted, this is a rather unpleasant set of circumstances with potential legal consequences. There appears to be a systemic operational issue though with the breaches. First, there were multiple breaches within the university’s system in 2019. One is bad enough, with the damage that may be done. When you have multiple, the attackers know they are able to get in, get what they want, and exit with ease. If there were to have been an apprehension or concern on the part of the attackers, perhaps they would not have returned so brazenly. For them to return and enter unfettered is indicative of a larger issue.

With these multiple breaches, there is data, intellectual property, and other items possibly removed. There is also the opportunity for them to leave something behind, be it other back doors or malware, to make their life even easier if they would want to enter later. This has a clear impact on the staff and students. From the point in time for the breach, until the notification, the affected persons are blind to the attacker’s using their personal data and information, any researcher’s work product being in unauthorized hands, and generally being open to issues themselves. In this case, the university withheld this information.

One rationale for this was the university did not have the budget and resources to work on this. This, on its own, is an issue. Too many staff do not appreciate the cybersecurity role, and what this actually brings to the organization. Without a robust cybersecurity program in place, there will be issues and many unauthorized persons will have access to your private information. In other words, a reasonably prudent organization would have this in place to protect the data and information which has been given to it to manage and steward.

On another point, prior to the breach, the university was audited by the Information Commissioner’s Office, whose focus is data protection. The report, published in March, noted the chairperson of the university’s data protection privacy group (DPPG) should be replaced with an alternative with more experience. Upon receipt and review, the registrar completely agreed with their findings. Curiously, the registrar and Data Protection Officer are the same people. While the report is after the fact, the indicators had been present for some time and should have been acted on long ago. This report based on the audit was how the staff and students learned of the breaches and that their data had been compromised. Without this report, who knows when the university would have let anyone know of the circumstances. For some reason unbeknownst to many, the registrar joked about the audit, stating it was “tomato colored” and acting dismissive as to the possibility the data was at risk.  
In certain circles, not accomplishing this may be considered negligence.

Apparently, the lack of oversight and resources was to the extent the university may have known they were breached, however, had no idea of what data or systems had been impacted by the attack.

Mitigations
To overcome these problems, the university has created two additional committees to assist with the governance in this area and to provide advice. The university also put a new Chief Information and Digital Officer in place to better the cybersecurity stance.

Lessons
To fully fund the cybersecurity teams and the working group is still vital to operations, and any entity. If you are apathetic as to the network, operations, and any repercussions from a breach and being totally pwned by an unauthorized third party, there is an issue. In these times of budgetary constraints, allocating the resources can be a difficult task. The alternative though tends to be much more expensive financially in the short- and long-term, and provides the opportunity for the organization to be in the news, for all the wrong reasons. There needs to be some form of a balance with the operations. Without this in place, the organization is simply a target waiting to be breached and having to send out the breach notification letters.

There also needs to be the appropriate staff doing the appropriate tasks. There is room for staff with their specific expertise in any organization. When you someone in a role they do not have the experience for, you will have issues. At a senior management level in cybersecurity, there is not the time or the availability of resources to attempt to learn on the job. There will be areas that will be missed in tasks and functions as the person moves through the learning curve. This is not the first time someone has been placed in a management position in cybersecurity without the requisite experience, exemplary of the Peter Principle.

When you have a report publishing of record there are data breaches, as a member of management, you should not act apathetic and as if you are above the findings. The staff in charge of the cybersecurity for a university should take care of the data they are stewarding. They should care enough to ensure their staff and student’s information is not at risk. When an independent third party has to inform you of breaches, something should be done to protect the university, students, and staff other than commenting, as the registrar did, “If I tell you what, I ‘I must kill you.’”

This is a rather serious issue as the breach included personal data and access to the network, unfettered. There is in place during the breach of the GDPR. As time passes, it will be interesting to note if the government actually applies the GDPR or any of the like laws or statutes to the university for the significant error and indifference to the staff and students. The registrar’s response is one of the reasons why there are still numerous breaches.

Anyone affected by this should be wondering why the responsible staff are still present and working at the university, especially the registrar.

Resources
Jay, J. (2020, April 28). Warwick university suffered multiple breaches due to poor security protocols. Retrieved from https://www.teiss.co.uk/warwick-university-data-breaches/ 

Karageorgi, N., & Toms, O. (2020, April 27). University of warwick kept data breach secret from students and staff. Retrieved from https://theboar.org/2020/04/university-of-warwick-kept-data-breach-secret-from-students-and-staff-last-year/ 

Martin, A. (2020, April 27). The university of warwick was hacked and kept secret the breaches of students and staff. Retrieved from https://oltnews.com/the-university-of-warwick-was-hacked-and-kept-secret-the-breaches-of-students-and-staff 

Martin, A. (2020, April 27). Warwick university was hacked and kept breach secret from students and staff. Retrieved from https://news.sky.com/story/warwick-university-was-hacked-and-kept-breach-secret-from-students-and-staff-11978792 

Millman, R. (2020, April). GDPR ignored by warwick university? Retrieved from https://www.scmagazineuk.com/gdpr-ignored-warwick-university-failure-alert-staff-students-data-breach/article/1681689 

Rodger, J. (2020, April 27). Warwick university kept data hack secret from students and staff. Retrieved from https://www.birminghammail.co.uk/news/midlands-news/warwick-university-kept-data-hack-18156758 

Sandford, E. (2020, April 27). Hackers targeted university of warwick. Retrieved from https://www.coventrytelegraph.net/news/coventry-news/hackers-targeted-university-of-warwick-18157358

Friday, April 26, 2019

Woesnotgone Meadow; April 26,2019



All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

Cebuana Lhuillier is located in the Philippines and is one of the leading and largest financial services firm. Cebuana Lhuillier is differentiated as this is not a bank. The firm has nearly 2,500 branches throughout the nation. The services include a pawn service, remittance, micro-insurance, and micro-loans.

With the business operations, the data held by the firm is exceptionally valuable to the attackers who successfully compromise the system. There were attempted connections to the business servers was detected on January 15, 2019. There was a previous attack that was successful, which led to unauthorized downloads from the business servers on August 5, 8, and 12, 2018. It is curious why the second compromise was not deterred. When there is a significant compromise, as a rule of thumb the cybersecurity staff or at least the IT staff harden the systems so the business is not compromised again.

We should persevere to learn from not only our mistakes but others. With at least the second compromise, the attack vector and method were not published.

More than 900,000 clients were affected by the breach. This is approximately 3% of the entire clientele. Although 3% is not that high of a percent relative to the entire clientele, this is still a rather large number of clients. The attackers may have accessed the client’s personal data, including the dates of birth, addresses, and sources of income. Thankfully, the details for the transactions were not included with the potentially compromised client data.

The firm was surprised by the compromise. The firm, as a result of the compromise, coordinated efforts with the National Privacy Commission (NPC). The firm also contracted with a third party to manage the compromise. The parties were investigating the issue. The company has already implemented safety measures to protect the client’s data. The firm did suggest to the clients for them to change their passwords.

This compromise emphasizes the need for a strong perimeter defense.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.

References
Cyware Hacker News. (2019, January 22). Data breach at cebuana lhuillier affects over 900,000 clients. Retrieved from https://cyware.com/news/data-breach-at-cebuana-lhuillier-affects-over-900000-cleints-b247b34b
Langsdon, M. (2019, January 19). Philippine financial service firm flags data breach affecting 900,000 clients. Retrieved from https://www.reuters.com/article/us-hilippines-cebuana/huillier-data-idUSKCNIPD078
Merey, A. (2019, January 19). Over 900,000 affected by ceduana lhuillier data breach. Retrieved from https://news.abs-cbn.com/business/01/19/19/over-900000-affected-by-cebuana-lhuillier-data-breach
Philstar. (2019, January 19). Cebuana lhuillier hit by data breach. Retrieved from https://www.philstar.com/business/2019/01/19/1886427/cebuana-lhuillier-hit-data-breach



Tuesday, January 8, 2019

Woesnotgone Meadow; December 14, 2018


Woesnotgone Meadow
December 14, 2018
#

All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

Here in the Meadow, we haven’t had too many cybersecurity incidents. Possibly we just aren’t on anyone’s radar...yet. Two towns in Alaska have not been this lucky lately though. These attacks crippled the operations of the towns. Having your PC or smartphone infected, and not functioning is disruptive enough. Having two town’s infrastructure down is certainly not a pleasant experience.

Matanuska-Susitna, Alaska
The incident occurred on July 23, 2018. The compromise caused the town’s operations to shut down. This disrupted the city services and slowed any productivity to a snail’s pace. This also affected Valdez, also in Alaska. The affected systems shut down were for the libraries, swimming pools, e-commerce, the local landfill, animal care, and collections. In addition, the phone systems and door lock card swipe systems were partially disabled. These were located in 73 different buildings.

A devastating effect from the attack involved the email system. After a careful review, it appeared this was not completely recoverable. The attack affected 60 of the Windows 7 PCs initially. When IT began to try and remove the malware, it spread to nearly all of the 500 workstations and 120 of the 150 servers. Although not specifically addressed, it appears this was set to spread once the remediation activity started.

The servers were a victim of ransomware. All of the Windows-based production servers were encrypted. The attackers appear to have done the appropriate level of reconnaissance, as this even affected the back-up and Disaster Recovery (DR) servers. In theory, these should have not been affected as these were engineered and configured to not be vulnerable to the known attacks and exploits. The attackers used the BitPaymer ransomware tool and Emotet Trojan. These leveraged the zero-day attacks. These had apparently been on the system since at least May 3, 2018, with an exploit date of July 23, 2018.

The staff was forced to use a pen, paper, and typewriters. It sounds as though they had a very bad day. The end goal for the attack may not have been totally financial. Due to the robust and well-thought-out nature of the attack, there may have been more involved. To remediate the issue, the borough began to reimage from the back-ups. A portion of these were a year old.

Financially, this attack was rather serious. The total estimated cost was $1.4M to restore the systems and servers. For a town, this is a massive amount. Thankfully, the borough did have $1M of insurance.

Valdez, Alaska
The Alaskan municipalities appear to be viable and continued targets. The city of Valdez was successfully attacked. The Valdez attack was so thorough, the staff was reduced to working with pen and paper. The initial symptom was a few glitches in the system, ranging from not being able to login to accounts to other issues. A few viruses were found at this point, as the attack began on July 25-26, 2019. The issue became significantly worse on Friday with a Police Department website outage. This blossomed until nearly all of the systems had to be shut down, including the phone, email, finance, and payroll. This infected 27 of their servers and 170 computers.

The underlying issue was ransomware. The attack was indeed robust, however, the resident’s personal information did not appear to be compromised. The city contracted with a firm from Virginia for a forensic review. To be proactive, the city is working to have a better method for upgrades and tracking changes. In the short-term, the city did pay the ransom (4 bitcoin, or $26,623.07 at the time) for the decrypt key.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.


Resources
Cimpanu, C. (2018, July 31). BitPaymer ransomware infection forces alaskan town to use typewriters for a week.Retrieved from https://www.bleepingcomputer.com/news/security/bitpayment-ransomware-infection-forces-alaskan-town-to-use-typewriters-for-a-week/

Cimpanu, C. (2018, November 21). City of valdez, alaska admits to paying off ransomware infection. Retrieved from https://www.zdnet.com/article/city-of-valdez-alaska-admits-to-paying-off-ransomeware-infection/

Crawley, K. (2018, September 18). Ransomware cripples an alaskan town. Retrieved from https://blog.comodo.com/comodo-news/ransomware-cripples-an-alaskan-town/

Dunn, J.E. (2018, August 3). Alaskan borough dusts off their typewriters after ransomware crims pwn entire network. Retrieved from https://www.theregister.co.uk/2018/08/03/alaskan-town-has-entire-network-owned-by-ransomware-crims/

Kirby, D. (2018, November 18). Four bitcoin for your data: How a roll of the dice by the city of valdez paid off after a cyber attack. Retrieved from https://www.ktuu.com/content/news/City-of-Valdez-paid-four-bitcoin-ransom-to-recover-data-after-July-cyber-attack-500564211.html

Rogers, J. (2018, August 1). Alaskan borough dusts off typewriters after ransomware attack. Retrieved from https://www.foxnews.com/tech/alaskan-borough-dusts-off-typewriters-after-ransomware-attack

Schroeder, S. (2018, August 2). Ransomware attack forces town’s employees to go back to typewriters. Retrieved from https://mashable.com/article/malware-alaska-town/#edAoW3zC80zX

Sowells, J. (2018, November 25). Valdez city, alaska, the newest victim of ransomware to pay for decryption. Retrieved from https://hackercombat.com/valdez-city-alaska-the-newest-victim-of-ransomware-to-pay-fordecryption/

The Associated Press. (2018, July 28). Virus shuts down city computers in valdez. Retrieved from https://www.usnews.com/news/best-states/alaskan/articles/2018-07-28/virus-shuts-down-city-computers-in-valdez

VanWagenen, J. (2018, August). An alaskan municipality suffers a devastating ransomware attack. Retrieved from https://statetechmagazine.com/article/2018/08/alaska-municipality-suffers-devaststing-ransomeware-attack


Weber, S. (2018, August 1). The valdez star-Serving prince william sound and copper river basin. Retrieved from https://www.valdezstar.net/story/2018/08/01/main-news/hacked-by-cybercriminals-city-website-downed-by-ransomware/1987.html

Friday, January 4, 2019

Woesnotgone Meadow; December 9, 2018

All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

In the Meadow, we have the usual life events for the residents. These include birthdays, anniversaries, occasional weddings, and other events we publish in the Gazette. Our local jeweler, Margie’s Bling, is our main source for gifts given with an open heart for these occasions. A recent issue with Jared and Kay Jewelers showed the Meadow there can be issues even with a simple jewelry purchase.  

Data leaks are occurring at a greater rate than in prior years. The individual leaks themselves appear to be allowing more data to escape. The combination of this tends to be a bit scare and a rather significant, growing issue. On the bright side, these tend to be remediated rather quickly on average. The data are not all handled in the same manner though. When these are not fixed immediately, the user’s data may be present to be exfiltrated and used or sold.

Related to this, Jared and Kay Jewelers had a bit of an issue. When a customer purchases the jewelry online, they have the option to have the receipt emailed to them. This is handy and may be a benefit. The client receives a link in an email for this receipt. The attack focusses on the link. After the attacker was to post the modified link in the web browser, they were able to access another client’s data (e.g. name, billing and shipping addresses, email address, phone number, the items ordered, total cost, tracking link, delivery date, and last four digits of the credit card number). All of this would be very useful and marketable on the dar web. The attacker could also use a quicker, more direct method to be unjustly enriched. They could complete an automated search for packages within a driving distance of their location. Any packages being delivered in the future could be picked up by the unauthorized person after delivered and prior to the recipient actually picking up the package from their porch.

They could also social engineer the business since they know all of the relevant information the customer service representative would ask. They could also social engineer the client, with the same information used for the prior attack. A simpler attack would involve the plain phishing attack for all the clients the data had been gathered on.

Jared’s parent company, Signet Jewelers, was notified of the issue. This problem only affected the Jared and Kay Jewelers client, not the other entities owned by Signet Jewelers (Zales and Piercing Pagoda). After a few weeks, there was no resolution to the issue. KrebsOnSecurity was contacted in mid-November 2018. At this point, Signet Jewelers thought it was pertinent enough to address. The CISO noted the issue was fixed for the future orders at that point. They did not understand the issue also applied to past orders. This was later fixed. The issue was with the coding not taking cybersecurity into account.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.

Resources
Bradley, B. (2018, December 3). If you’ve ordered jewelry from these sites, your information may have been exposed. Retrieved from https://www.komando.com/happening-new/516632/jared-kay-jewlers-data-leak

Krebs, B. (2018, December 3). Jared, kay jewelers parent fixes data leak. Retrieved from https://krebsonsecurity.com/2018/12/jared-kay-jewelers-parent-fixes-data-leak/