Most states have an agency, under various names, whose responsibility is to assist the citizens and the public when this is needed. This may be in the form of financial assistance, vouchers, or a combination of these. As part of the duties, the staff have to collect data on each person. This is part of the natural standard operating procedure for the service. This personal data has value in various circles.
A recent issue involves the state of Alaska’s Division of Public Assistance. On April 26 or 30, 2018, a Division of Public Assistance was found to have an unauthorized program on it. Normally, this is not the optimal situation, however, this does happen. The opportunity for an issue increases substantially when the program/software was not only unauthorized but unintentional. In this case, the company just happened to be infected with Zeus. Zeus, curiously enough, was coded to steal confidential, sensitive information from the infected system. This data and information were exfiltrated to systems in Russia.
This data included the person’s name, date of birth, social security number, pregnancy status, death records, health billing, driver’s license number, phone number, and Medicaid/Medicare billing codes for those estimated 500 persons affected, living throughout northern Alaska. This basically included most of the data you would need to take over someone’s identity.
The attack vector for this generally has been from a phishing email. The sender historically has been from a government agency or large corporation. The agency did report this, as required by Federal statute, and published a press release on the internet.
Lessons to be Applied
With organizations consisting of multiple sites, the lack of complete communication can provide for certain issues. This hindrance should however not be a roadblock. As an example, after the Western Region detected the compromised system after the incident response was nearly or completely done, a follow-up announcement should have been made and training now and with regularity to reinforce what can happen when staff simply clicks. This example of what occurred in the region and also what people will now have to go through should provide the real-life examples to motivate people to do better. This would reinforce what can actually happen
Resources
Brooks, J. (2018, June 28). Security breach: Hackers access alaskans’ information from computer. Retrieved from http://juneauempire.com/news/state/2018-06-28/security-breach-hackers-access-alaskans-information-state-computer
Downing, S. (2018, June 28). State security breach put public assistance info at risk. Retrieved from https://mustreadalaska.com/state-security-breach-put-public-assistance-info-at-risk/
Freed, B. (2018, June 29). Alaska public assistance agency disclosed data breach from trojan horse virus. Retrieved from https://statescooop.com/alaska-public-assistance-agency-discloses-data-breach-from-trojan-horse-virus
Kirby, D. (2018, June 28). Alaska DHSS data stolen in april hack. Retrieved from http://www.ktuu.com/content/news/Alaska-Dept-of-Health-and-Social-Services-data-targeted-in-April-hack-486879811.html
State of Alaska Department of Health & Social Services. (2018, June 28). HIPAA and APIPA breach notification. Retrieved from http://dhss.alaska.gov/News/Documents/press/2018/2018-HIPAA-Breach.pdf
Miel, LLC Cybersecurity Architecture, Design, and Engineering Cybersecurity architecture is a requirement in today's environment. If you don't address cybersecurity in your organization, there will be problems. Miel, LLC offers architecting and embedded systems hacking services provide proactive cybersecurity services to improve your defenses, so you aren't reactive. Miel, LLC Cybersecurity Architecture, Design, and Engineering 810-701-5511 charles.parker@mielcybersecurity.net
Showing posts with label training. Show all posts
Showing posts with label training. Show all posts
Wednesday, August 15, 2018
Alaska DHSS Breach: Trouble in the North
Labels:
breach,
cyber-security,
cybersecurity,
EHR,
EMR,
HIPAA,
phishing,
training,
Zeus malware
Friday, May 25, 2018
We Truly Need to Learn From Our Mistakes
“Those who cannot remember the past are condemned to repeat it.” -George Santyana
In the InfoSec field, the professionals strive to protect the enterprise, create or update processes to secure the users as much as possible, and if an issue falls through the cracks, to analyze the issue with a forensic lens. Although this sounds like a pretty simple process, this is rather complex with the number of persons and departments involved, all of which have to agree.
One particular area of our operations which tends to be frustrating involves breaches. Occasionally things happen and users click on something (link, picture, etc.) they truly should not have. The lure may be an enticing picture, promise of a package delivery, or virtually any other topic. When, however, this happens repeatedly, especially after the increase in training and announcements, the InfoSec Department begins to wonder what are the users thinking, what can be done so this does not happen again. These thoughts are meandering through the InfoSec mind all the while remediating, or attempting to, the issue. Depending on the compromise, this may be re-imaging a workstation, analyzing effects on a server farm, or simply taking a moment to ponder “Why me?”
An incident like this occurred in Texas recently. This involved ransomware being introduced into the Riverside Fire and Texas Police Department computer servers (http://www.ehackingnews.com/2018/05/texas-police-department-server-again.html). This attack occurred on May 4th of 2018. Ransomware is well-known and used throughout the globe. The issue compounding this was the police department was a victim of ransomware attack previously on April 23rd of 2018. With the initial attack, the police department lost approximately 10 months of sensitive data generated by on-going investigations. In this latest attack, the ransomware was coded to lock the files and delete others located on the affected server.
In this case, the police department did not pay the ransom and was able to recover some of the data. The police department finally had learned their lesson with this set of operational exercises. There is a backup protocol in place, and the admin staff only had to re-enter approximately eight hours of work.
The initial attack vector was the simple phishing email, however, the second attack’s method of successful delivery is unknown. This emphasizes the need for communication and staff training. To supplement this, there may be an internal, entity-based phishing campaign. The results of this may also be used as another training tool and opportunity.
Labels:
breach,
compromise,
cyber-security,
cybersecurity,
data,
InfoSec,
phishing,
security,
training
Subscribe to:
Posts (Atom)