Showing posts with label supply chain. Show all posts
Showing posts with label supply chain. Show all posts

Wednesday, November 20, 2024

Supply Chain Lesson #587

 Bank of America is massive with branches throughout most of the nation and other countries. Being

such a large operation, the bank could not reasonably maintain all aspects of their operations from a

central hub. The vast expanse of this would increase their FTEs significantly. This standard operating

procedure is used in most industries.

One area BoA uses this is with their service providers. Infosys McCamish Systems (IMS) was

compromised on or around November 3, 2023. The next day in the chronology was November 24 when

IMS notified BoA the data with their deferred compensation plans may have been compromised. This

included for the individuals their name, address, social security number, date of birth, and financial

information (account number, credit card number, etc.). For this compromise, approximately 57,028

clients were impacted. This ransomware attacked was claimed by LockBit.

This set of data is perfect to sell and be abused. With this the attackers or whomever purchases the data

has ample people to attack.

Tuesday, June 29, 2021

Military vehicle manufacturer hacking

 

The Department of Defense (DoD) business contractors continue to be regularly targeted. These organizations tend to work with secret and top-secret data and information as they develop new systems for use in the military. These could be ground vehicles, jets, ships, and other projects. One contractor, Navistar, was targeted and successfully breached. This was published with their Form 8-K filing with the Securities and Exchange Commission (SEC). The company detected the compromise on May 20, 2021.

With the data involved, the company could not be affected by paralysis by analysis, and immediately went into action to contain the breach, and work towards mitigating the effects from this. After these steps, Navistar began investigating the attack. This was done with security and forensic subject matter experts. They also contacted law enforcement.

As a result, from this, the organization took steps with its infrastructure to strengthen its structure and protect the data from unauthorized parties. Through the attack, the systems continued to be operational. While they aggressively worked to minimize any damage, on May 31 they did receive a communication that data had been exfiltrated during the attack. Considering the updated information, they continue dot investigate the issue and determine the scope of the data involved.

This is another example of what could happen. While you continuously work towards securing the enterprise, there is always a vector available. Arriving at this may be difficult, but it is still there.

Carmaker's vulnerabilities aren't just with embedded systems

 

Few companies have full vertical integration of their supply chain, meaning most companies require inputs from outside of the company for their products or services. For vehicle OEMs, they require modules or parts from other manufacturers. The supply chain for this may be rather extensive, depending on the unit or vehicle. This includes the hardware and software.

With all these other companies involved in the vehicle business there is bound to be the occasional issue. With all the third parties involved, there will be a problem or several problems somewhere along the supply chain. This has happened before and will certainly happen again. In particular, VW and its subsidiary had the pleasure of addressing this recently.

Customer records, depending on the data, have varying levels of value to the company and third parties with malicious intent. VW had over 3.3M customer records exposed. This incident is not directly their fault. A vendor happened to leave a cache of customer data open on the internet. We all know what happens when you leave data open and available on the internet. This was not left available for a week or two for anyone to peruse through. The data was left open from August 2019 to May 2021, or nearly two years. To make it worse, the customer data was not for a quarter or year, but for five years (2014-2019). That is a large amount of data there to be viewed. This is very usable in many applications. This is not only a cybersecurity issue, but also data science. This would be valuable to VW’s competitors for a variety of uses.

The data itself was collected for VW’s marketing and sales department. This included the customer’s personal information (name, mailing address, email address, and phone number). Also over 90K customers in the US and Canada had loan eligibility information exposed. This also included driver’s license numbers. Of this sample, a small number also had the customer’s date of birth and social security numbers available.

VW informed law enforcement and regulators regarding the issue. They are also working with cybersecurity subject matter experts (SMEs). There is the situation being handled, however the issue is a bit deeper. The supply chain is a requirement in our society. There are few businesses which have full vertical integration. There will be external vendors involved with your product. While the vendors are present and provide their service, the company still should complete their due diligence not only at the beginning of the business relationship, but periodically through the time when there are transactions. By simply checking the box that the work had been examined in years past is not sufficient. Cybersecurity is a constantly changing industry requiring updated monitoring and adjustment.