Tuesday, August 21, 2018

Adidas Issues: Breaches Abound

Most people have seen or are aware of the Adidas brand of shoes, clothing, and other products. These are sold in retail establishments and online. Recently Adidas had the opportunity to experience the excitement of a breach with their online venture.

An unauthorized party accessed the Adidas servers. This was unknown to Adidas until they were notified by a third party. The data was exfiltrated on June 26, 2018. This data included the user’s contact information, usernames, and encrypted passwords. Fortunately for the users, their credit card details and health-oriented data was stored elsewhere. With any breach, the vector and method could, in theory, take many forms. In this case, the method is unknown. To understand how this happened, Adidas is working with a security firm and law enforcement.

The affected parties were the Adidas customers purchasing products on the adidas.com/US website. This has affected literally millions of people.

One open question involves the InfoSec in place at Adidas. Seemingly, the security team, the SIEM, or something would have noticed the mass amount of data for millions of clients leaving the organization. Adidas had to learn of this from a third party. Also, the logs would have indicated, unless modified by the attackers, that this area was accessed by a party that was not authorized. There are these and many other questions re: the breach, which hopefully will be answered in the upcoming weeks.

Looking forward, the enterprise should have some form of a monitoring device or staff in place to review anomalies, unusual access, etc. This would have hopefully been able to note there was an issue and begin to limit the damage.

Resources
Adidas. (2018, June 18). Adidas alerts certain consumers of potential data security incident. Retrieved from https://www.adidas-group.com/en/media/news-archive/press-releases/2018/adidas-alerts-certain-consumers-potential-data-security-incident/

Gibson, K. (2018, June 28). Adidas data-security breach could involve “a few million customers”. Retrieved from https://www.cbsnews.com/news/adidas-security-breach-could-involve-a-few-million-customers/

Green, A. (2018, June 1). Adidas website hacked, changes your passwords now. Retrieved from https://www.komando.com/happening-now/468214/adidas-website-hacked-change-your-password-now

Humphries, M. (2018, June 29). Adidas website hacked, millions of US customer details stolen. Retrieved from https://www.pcmag.com/news/362173/adidas-website-hacked-millions-of-us-customer-details-stolen

Jones, R. (2018, June 29). Adidas warns customers of website hack. Retrieved from https://solecollector.com/news/2018/06/adidas-website-hack

Murdoch, J. (2018, June 29). Adidas hack: ‘Millions’ of U.S. website customers warned of cyber theft. Retrieved from http://www.newsweek.com/adidas-breach-hack-us-website-customers-warned-their-data-has-been-hacked-1000974

Sepe, R. (2018, June 29). Adidas US website hit by data breach. Retrieved from https://www.darkreading.com/cloud/adidas-us-website-hit-by-data-breach/d/d-id/1332186

Wednesday, August 15, 2018

Let's Learn from our Mistakes!: Phishing is still an issue

A bank robber, after being apprehended, years ago was asked “Why did you rob the bank?” The simple and direct response was, “That’s where the money is.” There is no difference today. Organizations will be targeted due to an asset the attackers want access to. This may be data or information, or the familiar cash.

A incident happened in Virginia to a bank and within eight months, the same. These illustrate the importance of relevant, regular training for phishing attacks.

Incidents
The target was The National Bank of Virginia located only in Virginia. The bank was compromised twice in eight months. The total amount stolen was an estimated $2.4M. The first was on May 28, 2016. This attack continued through Monday (Memorial Day), and was subsequently detected. The focus with this and the 2nd successful compromise was cash. Once compromised, the money was stolen through hundreds of ATMs across North America with cards whose magnetic stips had been the true user’s data placed on them. The ATMs initially with the first incident had stolen $569,648.24.

Once detected the bank contracted with Foregenix to complete the forensic review. In June 2016, the bank put in place the additional security protocols recommend. Curiously, the bank was breached again, allegedly by the same group, in January 2017. The attackers through this attack were able to steal $1.8M.

Methodology
The two rather deeply probing and expensive attacks were successfully completed with simple phishing emails with attachments. The user opens the email, clicks on the link or opens the attachment, and potentially the IR (Incident Response) Team and other operations have a long day and/or weekend. With the first attack, the initial compromised computer compromised another. This second computer accessed the STAR Network. This is managed by First Data and is used to manage the debit card, transactions, customer accounts, and the use of ATM and bank cards.

With the compromised computer, the attackers had the ability to disable and modify the anti-theft, and anti-fraud protections. This included the PIN, withdrawal limits for the individual person, daily usage, maximums for the debit cards, and fraud score protections.

The interesting twist is either by luck or learning from the 1st attack, the attackers also gained access to Navigator. Navigator was used by the bank to manage their customer’s debits and credits.

During the compromise #2, the attacker credited the bank ’s client accounts for $1,833,984 from several hundred ATMs. The second compromise also occurred over a weekend, between January 7-9, 2017. To make matters worse, the attackers updated for their needs or removed the bank’s critical security controls.

For the second compromise, Verizon was contracted for the forensic review. Verizon noted this was probably done by the same attackers, and the method for entry was the malicious Word document attached to the phishing email.

Cyber-Insurance
The bank did have cyber-insurance in place and in force at the time of the attacks. The insurance company was Everest National Insurance Company. Once the claim(s) had been filed, the insurance did not want to pay. There were two exclusions, and the insurance company claimed this fell under their Debit Card rider. The bank then filed a lawsuit in the Western District Court of Virginia, Roanoke Division (Civil Action No 7:18CV310).

Lessons Learned
Cybersecurity presents a new environment for the enterprise to thrive in. One aspect that is particularly new is cyber-insurance. The insurance industry is still working to detail the working, interpretation, and the method on how to apply this. In purchasing this service and insurance, the business needs to be wary and complete the due diligence, so senior management is aware of the coverage, as much as they are able to.

One aspect to fully explore is the exclusion riders. These, when possible, should be minimized in number. Where these are required, any ambiguity in the wording should be explored and detailed, while being documented. With this, any ambiguities should be limited. Notwithstanding a section to the contrary, the emails and other documents should fill in the gaps.

With the exclusions, this would work to limit the insurance company’s exposure to certain attacks. The industry may not know of a certain attack or one that had not been published yet. The attack vector may not be known yet. The business may be waiving their right to coverage for an unknown attack, or one that had not been created yet.

The business should actively consider consulting with an attorney specializing in this area with regard to the cyber-insurance policy and rider. The agreement and insurance rider are written with the insurance company’s interests in mind. The sections and riders may be vague where needed, and be able to apply exclusions where they may need it.

Insurance works, in theory, and practice, by pooling risk. The pool consists of individual policies. The insurance companies use large mathematical formulas to determine what factors to take into account. The larger the pool, assumptively the less overall risk, fewer claims, and subsequently larger profits. If there are too many claims, the insurance company’s profits will be lower. The organizations are profit driven, and not an altruistic entity.

Even if the organization follows industry standards and recommendations, there may be issues. The InfoSec environment is ever-changing. There are new attacks, updated old attacks, nuances, or old issues never fixed. To anticipate every issue and attack angle is not possible.

Phishing continues to be a rather viable attack vector. These can be skillfully crafted, with the business symbols and graphics. All it takes is one person in the right department (e.g. accounting, finance, tax, or Human Resources) clicking on one link and the business operations can get very interesting, very quickly. The phishing training needs to be regular, and relevant.

Resources
Krebs, B. (2018, July 18). Hackers breached virginia bank twice in eight months, stole $2.4m. Retrieved from https://krebsonsecurity.com/2018/07/hackers-breached-virginia-bank-twice-in-eight-months-stole-2-4m/

Alaska DHSS Breach: Trouble in the North

Most states have an agency, under various names, whose responsibility is to assist the citizens and the public when this is needed. This may be in the form of financial assistance, vouchers, or a combination of these. As part of the duties, the staff have to collect data on each person. This is part of the natural standard operating procedure for the service. This personal data has value in various circles.

A recent issue involves the state of Alaska’s Division of Public Assistance. On April 26 or 30, 2018, a Division of Public Assistance was found to have an unauthorized program on it. Normally, this is not the optimal situation, however, this does happen. The opportunity for an issue increases substantially when the program/software was not only unauthorized but unintentional. In this case, the company just happened to be infected with Zeus. Zeus, curiously enough, was coded to steal confidential, sensitive information from the infected system. This data and information were exfiltrated to systems in Russia.

This data included the person’s name, date of birth, social security number, pregnancy status, death records, health billing, driver’s license number, phone number, and Medicaid/Medicare billing codes for those estimated 500 persons affected, living throughout northern Alaska. This basically included most of the data you would need to take over someone’s identity.

The attack vector for this generally has been from a phishing email. The sender historically has been from a government agency or large corporation. The agency did report this, as required by Federal statute, and published a press release on the internet.

Lessons to be Applied
 With organizations consisting of multiple sites, the lack of complete communication can provide for certain issues. This hindrance should however not be a roadblock. As an example, after the Western Region detected the compromised system after the incident response was nearly or completely done, a follow-up announcement should have been made and training now and with regularity to reinforce what can happen when staff simply clicks. This example of what occurred in the region and also what people will now have to go through should provide the real-life examples to motivate people to do better. This would reinforce what can actually happen


Resources
Brooks, J. (2018, June 28). Security breach: Hackers access alaskans’ information from computer. Retrieved from http://juneauempire.com/news/state/2018-06-28/security-breach-hackers-access-alaskans-information-state-computer

Downing, S. (2018, June 28). State security breach put public assistance info at risk. Retrieved from https://mustreadalaska.com/state-security-breach-put-public-assistance-info-at-risk/

Freed, B. (2018, June 29). Alaska public assistance agency disclosed data breach from trojan horse virus. Retrieved from https://statescooop.com/alaska-public-assistance-agency-discloses-data-breach-from-trojan-horse-virus

Kirby, D. (2018, June 28). Alaska DHSS data stolen in april hack. Retrieved from http://www.ktuu.com/content/news/Alaska-Dept-of-Health-and-Social-Services-data-targeted-in-April-hack-486879811.html

State of Alaska Department of Health & Social Services. (2018, June 28). HIPAA and APIPA breach notification. Retrieved from http://dhss.alaska.gov/News/Documents/press/2018/2018-HIPAA-Breach.pdf

MyHeritage breach: Those are my credentials!




The attackers are consistently looking for a business’ crown jewels to exfiltrate. Data, in general, tend to be the target with these attacks. Once secured, the attackers may sell, or use this for their own advantage. Of particular interest in the last few years has been a person’s DNA and family history.

This service has grown in use as people may not know their family history. They want to gain a greater grasp of their heritage. The DNA test is a tool to gain a portion of this information.

Target
There are a number of services to get this data for the consumer. One of these is MyHeritage, a web-based genealogy and DNA testing service. As the tenants send in the DNA samples, and these are processed, the business keeps the data on their servers. The attack targeted their business user’s login credentials and used this for the various malicious ends.

Attacks
The system where the data was held was compromised on October 26, 2017. The attackers were able to exfiltrate email addresses and hashed passwords. These were held on a private server, not under the company’s control. There were over 92M affected users. Fortunately, the DNA report results were stored on a different system. This other system had more defences in place. The business had not detected how this was done.

Post-Attack 
The business did not know the attack’s method or the business had been compromised. The business was notified by a non-associated security researcher. The third party researcher noted they detected a file was located on a private server. There had been no evidence yet the data itself had been used for malicious purposes. After the attack, in an attempt to increase the defence, TFA (two-factor analysis) was implemented at a quicker pace.

Resources
Afifi-Sabet, K. (2018, June 6). MyHeritage suffers massive data leak affecting 92M users. Retrieved from http://www.itpro.co.uk/data-breaches/31254/myheritage-suffers-massive-data-leak-affecting-92m-users

Chalfant, M. (2018, June 5). Genealogy platform says hackers stole data on 92M users. Retrieved from http://thehill.com/policy/cybersecurity/390799-genealogy-platform-says-hackers-stole-data-on-92m-users

Monday, August 6, 2018

Android Phones and Pre-Loaded Adware: Not a Good Combination

Generally, when a consumer purchases their new smartphone, the routine is set. The phone is purchased, the consumer is rather exuberant, and the phone is used, while the user assumes all is fine. In certain instances, the users have a surprise.

Avast Threat Labs recently detected adware pre-installed on phones. The affected phones are vast, as a few hundred models and versions are affected. The targeted phones were manufactured by ZTE, Archos, and others. The adware placed on the phones was known to be present for over three years and previously was named Cosiloon. Cosiloon has tended to be difficult to remove from the phone as the adware is placed on the firmware level and applies solid obfuscation.

The annoying addition to the baseline Cosiloon displays an ad in the form of an overlay on the user’s selected webpage. With this being difficult to remove, Google has opted to increase the awareness of the issue by contacting the appropriate firmware engineers and developers.

The deeper issue involves the intentional placement of the adware on the phones, to the detriment of the user, and without their express consent. The standard operating procedure is not appropriate. If the user accepts and knowingly authorizes this, the issue is moot. This is however not the case. The manufacturers may be gaining an additional revenue by placing the adware on the phones. This business practice should cease.

Wednesday, August 1, 2018

More Problems for the city of Atlanta

The city of Atlanta operations had been severely crippled and pwned in March 2018, arising from a rather serious and in-depth ransomware attack. This successful attack made the city of Atlanta operations very difficult. The city is still working to recover from this (https://www.helpnetsecurity.com/2018/06/08/wi-fi-phishing-attacks/). On the tail of the issues being remediated, another attack is passively underway. A security firm has detected hundreds of WiFi phishing sites activelyInfoSec, information security, cybersecurity, cyber-security, defenses, static defenses working. Surprisingly these are located not only proximate to the city hall, but also inside of the building. The research firm also detected active attacks in the Georgia State Capital. This is located merely a few blocks away from the Atlanta City Hall.

The attack was detected by the Coronet Secure Cloud Platform. The specific phishing attacks included Evil Twins, Captive Portals, and ARP Poisoning.

This instance brings up the importance of defensive measures. A static, flat defense is not a workable solution presently. The attackers will utilize the most current methods, pivoting to which method works the best for the circumstance. This does come at a cost, however, this is much better than the costs and expenses associated with breaches.

Static InfoSec Does Not Work Well

Attacks on the enterprise and embedded systems are not slowing down. These are increasing as the attacks are expanding the sophistication, the number of attacks is growing in numbers, the attackers have modified their activities to a business model, and the notoriety associated with an attack has increased the publicity with these. As an increase in the issue’s potency, these attackers are located across the globe.

The mainstream, present response is to put the defensive architecture in place, monitor the SIEM, and respond if there is an issue (e.g. attacker’s successful phishing attack). An immense amount of trust is placed into these appliances to monitor and protect the enterprise. This static thinking has not and will not be acceptable in the future against advanced attackers.

The security operations command (SOC) is under an increasing level of pressure from management and the attackers. This is budgetary from inside sources and external from the seemingly daily attacks, both old and new from attacks not experienced previously. To defend against these using the static security architecture, not consistently updating the applications and tools, looks to create and further problems for the CISO and business.

The InfoSec Architect, to adequately protect the system, has to be flexible and creative. These simple acts would work to directly keep pace with the attackers on various activity and technology levels. Without this in place, then the enterprise would be maintaining the security put in place years prior (e.g. bronze age tools) against an enemy using the current attack technique (e.g. iron age tools).

The enterprise needs to keep pace, or this will continue to be breached and compromised regularly and with ease.