Showing posts with label insider threat. Show all posts
Showing posts with label insider threat. Show all posts

Saturday, May 30, 2020

Sberbank Breached



Banks are located throughout the world. They perform vital services for consumers and commercial organizations in every country they are located in. These are also connected with the respective nation’s banking systems. Another commonality is these hold a mass amount of data also. This is very attractive to the attackers for many reasons. This is also a concern for the consumers, as their personally identifiable information (PII) is in the hands of unauthorized persons. Sberbank is was targeted and data removed without their authorization. Sberbank is Russia’s largest bank, with 45% of all retail deposits within their bank and 41% of the consumer loans held. In this instance, the Russian state owns the controlling stake in the bank.
Attack
Obviously, the attack was successful, which is a problem. The organization estimates the breach occurred near the end of August 2019.  The cause of this breach is unfortunately somewhat common, in the US and abroad. With employees, there is always the chance of the internal threat with the disgruntled, greedy, or unhappy employee. In this case, the bank is reporting the breach of data was due to an employee’s intentional acts. The bank noted it has to be an internal employee due to the data’s location being impossible to breach.

Later, the speculation ended when the bank reported the attacker had been apprehended. During the investigation, the employee had been focused on and eventually confessed. The employee was the head of one of the bank’s divisions. As part of their role, they had access to databases as part of their position, which explains how this was exfiltrated given the data’s remote location and access.
Data
With the attack, millions of Sberbank’s customer's personal data was allegedly initially leaked. Fortunately for the affected persons, the target was the data. The funds in the affected person’s account(s) were not targeted. The bank initially estimated 60M Sberbank credit cardholders have had their personal data stolen and was for sale on the dark web. This estimate appears to have been a bit inflated, and the true number was far less, possibly as low as 5k. The last reported sales price per entry at $0.08/record.

Surprisingly, the data leak and data for sale was not noticed by the bank. For instance, even if the amount of data was the 5k of records, seemingly this would have triggered some form of an alarm. After all, even a division manager probably would not have a need to download 5k individual records. Their position would be more engaged with summaries and forward-looking goals. This oversight was noticed by DeviceLock Cybersecurity, a cybersecurity organization when they noticed the data for sale on the dark web. At times, the seller may make fantastic claims of the data composition for sale. In this case, however, a sample of 200 credit card holder’s data was verified, indicating this is real. The data liberated in this case included the credit card details excluding the three-digit CVV, and place of employment for the last ten years. While the affected persons do have a bit of good news with the CVV not being a part of this, they may still have been targeted for fraud due to the nature of the data itself.
Follow-Through
After the bank was notified, they contacted reported this and is working closely with law enforcement and the Central Bank of Russia to find the culprits. As noted, this was beneficial as the

Resources
Auyezov, O., & Lyrchikova, A. (2019, October 3). Russia’s sberbank investigating potential client data leak. Retrieved from https://www.reuters.com/article/us-sberbank-russia-dataprotection/russias-sberbank-investigating-potential-client-data-leak-idUSKBIN1@i0Wl

Hinchliffe, R. (2019, October 9). Russia’s sberbank catches internal culprit of data leak. Retrieved from https://www.fintechfutures.com/author/hinchliffer/

Leprince-Ringuet, D. (2019, October 4). Russia’s sberbank investigates credit card data leak. Retrieved from https://www.zdnet.com/article/russieas-sberbank-investigates-credit-card-data-leak

Ljubas, Z. (2019, October 19). Russia: Huge data leak hits sberbank. Retrieved from https://www.occrp.org/en/daily/10797-russia-huge-data-leak-hits-sberbank

PMNTS. (2019, October 4). Russia’s sberbank investigating potential client data leak. Retrieved from https://www.pymnts.com/news/security-and-risk/2019/russias-sberbank-investigating-cleint-data-leak/

Spadafora, A. (2019, October 3). Russia’s sberbank hit with huge data leak. Retrieved from https://www.techradar.com/news/russias-sberbank-hit-with-huge-data-leak
The Moscow Times. (2019, October 3). Sberbank hit by huge data breach. Retrieved from https://www.themoscowtimes.com/2019/10/03/sberbank-hit-by-huge-data-breach-a67570

The Moscow Times. (2019, October 3). Sberbank hit by huge data breach. Retrieved from https://www.wedn.com/2019/10/03/sberbank-hit-by-huge-data-breach/

Walker, J. (2019, October 8). Sberbank of Russia completes investigation into the dark web data leak. Retrieved from https://portswigger.net/daily-swig/sberbank-of-russia-completes-investigation-into-dark-web-data-leak  

Monday, November 19, 2018

Insider Threats Still Viable

The InfoSec team for a business plan at length for attacks from the various sources, and compromises, if these were to occur, in the form of incident response. These external threats are from across the globe and take a significant amount of time to plan for. The teams may harden the network, provide training, and other measures against these external threats. One area, however, that has not been significantly examined has been the insider threat. This is difficult to plan for the defense. The Admins may attempt to limit the rules to the employee’s role, or other measures. There may, however, be an issue if this were to not be configured correctly. The system could log the workflow; however, this may be problematic as the logs require some level of analysis, which requires time. Also, certain persons may have access to the logs, and write access, which could modify these to show there had been no wrong-doing. A recent issue much like this involved the Chicago Public Schools.

Perpetrator
The issue started with Kim Sims, a 28-year-old contract worker. Her unauthorized access was discovered, she was fired and later charged with computer tampering and four felony counts of identity theft. Her access was allowed due to her position with the Chicago Public Schools (CPS).
There are contract workers in the CPS in varying capacities, working with various data throughout the school year. Most of the time, there is not an issue.

Acts
The contractor’s responsibilities included conducting background checks on CPS employees. This would give the person access to gather certain germane data to upload into the system. This would not, however, give the person access to download data from other files. In this case, Sims was not authorized for this function as this was not part of her role. She unfortunately illegally downloaded the personal data of district employees she had access to. There were approximately 80,000 CPS employees, contractors, volunteers, and vendors affected by this. She was fired and the CPS Board of Education found that she had accessed and downloaded the personal data.

Data
The affected person’s data has value to many others, much to the person’s detriment. The data downloaded and exfiltrated included the employee’s name, addresses, date of birth, criminal background information and history, employee ID numbers, phone numbers, and potential information from the state Department of Children and Family Services.
Fortunately, this did not include the affected person’s social security number. The investigators noted they were not aware of the data had not been shared with other unauthorized parties. Once the law enforcement authorities executed their search warrant, the files were retrieved.

Follow-Up
As a result of the issue, CPS conducted a forensic audit. The focus of the audit was on computers and cell phones.
The insider threat is problematic. The business wants to fully trust the employees, but this can be difficult in certain instances. When the company over-monitors the employees, there is a perceived trust issue. Although this compromise was rather low-tech, the issue still caused a mass amount of work to correct, and the contractor has legal issues for an extended period of time.
There should be a greater level of rules set in place to reduce the opportunity for this to occur in the future.


Resources
Chicago Sun-Times. (2018, November 4). Ex-cps employee steals info on 80,000 people in latest data breach. Retrieved from https://wsoe.org/ex-cps-employee-steals-info-on-80000-people-in-latest-data-breach/
Crews, J. (2018, November 2). Ex-CPS employee stole personal info on 80,000 people in data breach. Retrieved from https://wgntv.com/2018/11/02/ex-CPS-employee-stole-personal-info-on-80000-people-in-data-breach/
Dissent. (2018, November 2). Ex-chicago public schools worker accused of stealing info on 80,000 people in latest data breach. Retrieved from https://www.databreaches.net/ex-chicago-public-schools-worker-accused-of-stealing-info-on-80000-people-in-latest-data-breach/
Edwards, b. (2018, November 1). Fired CPS employee steals personal data of 70,000 people, charged with multiple felonies. Retrieved from https://chicago.cbslocal.com/2018/11/01/cps-employee-data-theft/
Spoerre, A., & Crepeau, M. (2018, November 3). CPS worker charged with illegally downloading personal data of district employees. Retrieved from https://www.chicagotribune.com/news/local/breaking/ct-met-crime-hickory-hills-woman-charged-school-identity-theft-2018-1102-story.html
The Associated Press. (2018, November 4). Worker charged with illegally downloading personal data. Retrieved from https://www.thestate.com/news/business/national-business/article221113415.html
Victory, L. (2018, November 2). Fired CPS employee charged with stealing database containing files on 70,000 people. Retrieved from https://chicago.cbslocal.com/2018/11/02/cps-data-breach-fired-employee-kristi-sims-charged-stolen-database-personal-information-identity-theft/


Saturday, November 10, 2018

Insider threats still viable


There are colleges and universities located throughout the nation in small and large communities. One of these of special notice is the Savannah College of Art and Design (SCAD), located in Georgia. The school naturally has to monitor and secure the campus. The area could not be open and accessible to anyone without having some form of a staff there to protect the students. SCAD, to accomplish this, contracted with G4S Secure Solutions.

Unauthorized Data Exfiltration
There were dozens of social security numbers associated with work hours and pay rates for the G4S employees that were accessed by a supervisor. The supervisor sent this data to other G4S workers via an unsecured email on yahoo and Gmail accounts. The supervisor also happened to have left hard copies in one of the patrol vehicles. This affected nearly 60 persons. After G4S discovered the issue, allegedly the company attempted to hide that the data had been mishandled.

Actions After the 3rd Party Actions
Naturally, the affected people were exceptionally upset. These parties are suing G4S Secure Solutions due to their personal data and information being treated like a crossword puzzle. Of these 60 persons, 39 were involved with the lawsuit. Two items being sued for are damages and years of credit monitoring.

Insider Threats
This is a blatant example of an insider threat. Companies have to trust their staff to do the right thing. At times, this trust is misplaced. Allegedly, the superior access these records emailed these, and printed these off, leaving the hard copy in a patrol vehicle used by others. The intent or lack thereof shall be elucidated as the lawsuit progresses. This does, however, show what could happen at a minimum. This applied insider threat could have been much expansive, and the data could have spread much further than a few yahoo and gmail accounts.


Resources
Davis, A. (2018, October 15). SCAD security contractor facing lawsuit. Retrieved from https://www.wsav.com/news/local-news/only-on-3-scad-security-contractor-facing-lawsuit/1526250688

WTOC. (2018, October 17). Security company sued after alleged information leak. Retrieved from https://www.wtoc.com/2018/10/17/security-company-sued-after-alleged-information-leak/

Sutter Health Medical Records Issue

Medical records hold a mass amount of data. These include not only the medical diagnosis but may also include payment information along with health insurance data. Per each individual record, the sales price may not be large, however, the value resides more in the data itself. The price depends on not only the data in each file but also how these are bundled.

The medical records are limited as to the access. Not every person in the medical facility requires access to these. The data may lure staff members of the medical facility to view these records, when not authorized, to gain knowledge. Certainly, this could be more of a curiosity issue or more of a malicious slant with the exfiltration and sale of the data. In prior years, this had occurred with celebrities or other prominent figures.

Another incident of this type occurred recently. Sutter Health in California recently fired two employees after they accessed medical records. Normally this would not be an issue as many persons are allowed to view medical records as part of their role and responsibility for their position, however, the staff members were not authorized to do so. The two employees allegedly accessed the medical records of Joseph DeAngelo. He is suspected to be the Golden State Killer.

Naturally, medical records are to be held in an exceptionally secure manner and accessed by authorized parties only when required for their position. This not only includes data segregation and encryption but also authorization.