Monday, November 19, 2018

Insider Threats Still Viable

The InfoSec team for a business plan at length for attacks from the various sources, and compromises, if these were to occur, in the form of incident response. These external threats are from across the globe and take a significant amount of time to plan for. The teams may harden the network, provide training, and other measures against these external threats. One area, however, that has not been significantly examined has been the insider threat. This is difficult to plan for the defense. The Admins may attempt to limit the rules to the employee’s role, or other measures. There may, however, be an issue if this were to not be configured correctly. The system could log the workflow; however, this may be problematic as the logs require some level of analysis, which requires time. Also, certain persons may have access to the logs, and write access, which could modify these to show there had been no wrong-doing. A recent issue much like this involved the Chicago Public Schools.

Perpetrator
The issue started with Kim Sims, a 28-year-old contract worker. Her unauthorized access was discovered, she was fired and later charged with computer tampering and four felony counts of identity theft. Her access was allowed due to her position with the Chicago Public Schools (CPS).
There are contract workers in the CPS in varying capacities, working with various data throughout the school year. Most of the time, there is not an issue.

Acts
The contractor’s responsibilities included conducting background checks on CPS employees. This would give the person access to gather certain germane data to upload into the system. This would not, however, give the person access to download data from other files. In this case, Sims was not authorized for this function as this was not part of her role. She unfortunately illegally downloaded the personal data of district employees she had access to. There were approximately 80,000 CPS employees, contractors, volunteers, and vendors affected by this. She was fired and the CPS Board of Education found that she had accessed and downloaded the personal data.

Data
The affected person’s data has value to many others, much to the person’s detriment. The data downloaded and exfiltrated included the employee’s name, addresses, date of birth, criminal background information and history, employee ID numbers, phone numbers, and potential information from the state Department of Children and Family Services.
Fortunately, this did not include the affected person’s social security number. The investigators noted they were not aware of the data had not been shared with other unauthorized parties. Once the law enforcement authorities executed their search warrant, the files were retrieved.

Follow-Up
As a result of the issue, CPS conducted a forensic audit. The focus of the audit was on computers and cell phones.
The insider threat is problematic. The business wants to fully trust the employees, but this can be difficult in certain instances. When the company over-monitors the employees, there is a perceived trust issue. Although this compromise was rather low-tech, the issue still caused a mass amount of work to correct, and the contractor has legal issues for an extended period of time.
There should be a greater level of rules set in place to reduce the opportunity for this to occur in the future.


Resources
Chicago Sun-Times. (2018, November 4). Ex-cps employee steals info on 80,000 people in latest data breach. Retrieved from https://wsoe.org/ex-cps-employee-steals-info-on-80000-people-in-latest-data-breach/
Crews, J. (2018, November 2). Ex-CPS employee stole personal info on 80,000 people in data breach. Retrieved from https://wgntv.com/2018/11/02/ex-CPS-employee-stole-personal-info-on-80000-people-in-data-breach/
Dissent. (2018, November 2). Ex-chicago public schools worker accused of stealing info on 80,000 people in latest data breach. Retrieved from https://www.databreaches.net/ex-chicago-public-schools-worker-accused-of-stealing-info-on-80000-people-in-latest-data-breach/
Edwards, b. (2018, November 1). Fired CPS employee steals personal data of 70,000 people, charged with multiple felonies. Retrieved from https://chicago.cbslocal.com/2018/11/01/cps-employee-data-theft/
Spoerre, A., & Crepeau, M. (2018, November 3). CPS worker charged with illegally downloading personal data of district employees. Retrieved from https://www.chicagotribune.com/news/local/breaking/ct-met-crime-hickory-hills-woman-charged-school-identity-theft-2018-1102-story.html
The Associated Press. (2018, November 4). Worker charged with illegally downloading personal data. Retrieved from https://www.thestate.com/news/business/national-business/article221113415.html
Victory, L. (2018, November 2). Fired CPS employee charged with stealing database containing files on 70,000 people. Retrieved from https://chicago.cbslocal.com/2018/11/02/cps-data-breach-fired-employee-kristi-sims-charged-stolen-database-personal-information-identity-theft/


Saturday, November 10, 2018

Insider threats still viable


There are colleges and universities located throughout the nation in small and large communities. One of these of special notice is the Savannah College of Art and Design (SCAD), located in Georgia. The school naturally has to monitor and secure the campus. The area could not be open and accessible to anyone without having some form of a staff there to protect the students. SCAD, to accomplish this, contracted with G4S Secure Solutions.

Unauthorized Data Exfiltration
There were dozens of social security numbers associated with work hours and pay rates for the G4S employees that were accessed by a supervisor. The supervisor sent this data to other G4S workers via an unsecured email on yahoo and Gmail accounts. The supervisor also happened to have left hard copies in one of the patrol vehicles. This affected nearly 60 persons. After G4S discovered the issue, allegedly the company attempted to hide that the data had been mishandled.

Actions After the 3rd Party Actions
Naturally, the affected people were exceptionally upset. These parties are suing G4S Secure Solutions due to their personal data and information being treated like a crossword puzzle. Of these 60 persons, 39 were involved with the lawsuit. Two items being sued for are damages and years of credit monitoring.

Insider Threats
This is a blatant example of an insider threat. Companies have to trust their staff to do the right thing. At times, this trust is misplaced. Allegedly, the superior access these records emailed these, and printed these off, leaving the hard copy in a patrol vehicle used by others. The intent or lack thereof shall be elucidated as the lawsuit progresses. This does, however, show what could happen at a minimum. This applied insider threat could have been much expansive, and the data could have spread much further than a few yahoo and gmail accounts.


Resources
Davis, A. (2018, October 15). SCAD security contractor facing lawsuit. Retrieved from https://www.wsav.com/news/local-news/only-on-3-scad-security-contractor-facing-lawsuit/1526250688

WTOC. (2018, October 17). Security company sued after alleged information leak. Retrieved from https://www.wtoc.com/2018/10/17/security-company-sued-after-alleged-information-leak/

Water processing utilities under attack!

There are a number of high-value targets in the market for the attackers to pursue. The attackers have the opportunity for 15 minutes of fame, and data to exfiltrate. One industry not given the positive attention by cybersecurity community has been the water utility industry. The service they provide is required by civilization. Any issue with the process has the potential to be a disaster for anyone or business using the water after processing.

A recent issue occurred in North Carolina at the Onslow Water and Sewer Authority. The water utility’s computers, including PCs and servers were attacked. The perpetrator attempted to use ransomware.

This was not a complete success for the attackers. The utility’s customer information was not compromised during the attack, however, other databases were affected. The attacks began on October 3, 2018. Fortunately, the compromise was limited. If this had pivoted to other points within the business, which could have managed the water purification process.

This does, however, highlight an issue. The water processing industry has not been receiving the attention it should have been. The issues presented by the industry are rather pertinent to consumers and the commercial sector. With adulterated water, the effects have the tendency to be rather serious.

Resources
AP. (2018, October 15). Feds investigate after hackers attack water utility. Retrieved from http://www.hastingstribune.com/feds-investigate-after-hackers-attack-water-utility/

AP. (2018, October 16). Feds investigate after hackers attack water utility. Retrieved from https://www.securityweek.com/feds-investigate-after-hackers-attack-water-utility

Associated Press. (2018, October 15). Feds investigate after hackers attack water utility. Retrieved from https://www.washingtontimes.com/news/2018/oct/15/feds-investigate-after-hackers-attack-water-util/

Associated Press. (2018, October 15). Feds investigate after hackers attack water utility. Retrieved from https://www.wsoctv.com/news/north-carolina/feds-investigate-after-hackers-attack-wate-utility/853625381/

The State. (2018, October 15). Feds investigate after hackers attack water utility. Retrieved from https://www.thestate.com/news/business/national-business/article220064300.html

Sutter Health Medical Records Issue

Medical records hold a mass amount of data. These include not only the medical diagnosis but may also include payment information along with health insurance data. Per each individual record, the sales price may not be large, however, the value resides more in the data itself. The price depends on not only the data in each file but also how these are bundled.

The medical records are limited as to the access. Not every person in the medical facility requires access to these. The data may lure staff members of the medical facility to view these records, when not authorized, to gain knowledge. Certainly, this could be more of a curiosity issue or more of a malicious slant with the exfiltration and sale of the data. In prior years, this had occurred with celebrities or other prominent figures.

Another incident of this type occurred recently. Sutter Health in California recently fired two employees after they accessed medical records. Normally this would not be an issue as many persons are allowed to view medical records as part of their role and responsibility for their position, however, the staff members were not authorized to do so. The two employees allegedly accessed the medical records of Joseph DeAngelo. He is suspected to be the Golden State Killer.

Naturally, medical records are to be held in an exceptionally secure manner and accessed by authorized parties only when required for their position. This not only includes data segregation and encryption but also authorization.

Minnesota Department of Human Services Email Compromise

The state agencies tend to be in a rather unique circumstance. The revenue source is relatively stable year after year. Their circumstances are not like a retailer which can have a sale and generate additional revenue/income periodically through the year. On the other side are the expenses. These generally increase annually at various levels based on the products or services. Inflation does not stop, increasing the expenses or inputs to the product or service. The municipality or state, if there were to begin to be a shortfall, would need to be creative or raise taxes, which tends to be very unpopular. This leads to various issues and cost-cutting. These measures may be in training for the staff, or may take the form of the inverse with the agency not being fiscally able to train their staff on certain measures, e.g. phishing awareness training. Recently an expensive issue arose during the state of Minnesota Department of Human Services.

Attack Vector
With many industries and businesses across the nation, phishing continues to be an issue, and successful for the attackers. This was also recently the case with the Minnesota Department of Human Services. In this specific circumstance, the department was the victim of a successful phishing attack. With this attack, all it takes is one person in the correct department, and the successful attack is completely able to stop workflow. In this case, two employees clicked on the phishing link or attachment. This successful attack was on two employee email accounts. This allowed, once the email accounts were compromised, the attackers access to the confidential data held within. The department had the opportunity to work through this in the summer of 2018, specifically on June 28th and July 9th.

In this issue, the circumstances warrant a simple, yet direct question. The first attack was noted, managed, and worked through by the department, management, and the IT department. This was a rather significant issue and took a mass amount of time and resources to analyze, review, and remediate issues (if done correctly). As this was the case, and the total cost was more than minimal, the circumstances would appear to warrant additional training so it would not occur again. Curiously though, there was a second successful phishing attack. This also occurred very soon after the first successful attack. It almost seemed as though the IT security team did not notice the first attack.

Once the 2nd attack was detected, naturally the account email was secured. As with any phishing attack, this did not involve only focussing on one user. There were many others who were targeted during the phishing campaign.

Target
As noted the state of Minnesota Department of Human Services was targeted. The department stores a mass amount of data on thousands of persons. This data is communicated throughout the department from user to user, through the different systems, and through various other channels. This data, while used day in and day out by the users, almost desensitized to its pertinence, has intrinsic value to attackers. This is marketable to many other, unauthorized persons across the globe.

Data Exfiltrated
Unfortunately for the department, there was data accessed. This data included the client’s social security numbers, medical information, employment records, and their financial details. Other information, while marketable but on a second tier but useful, included the person’s full names, telephone numbers, and addresses. This is still pertinent although the attackers could gather this information from other sources with moderate ease.

While the emails were accessed, the department was not able to fully verify the data had been exfiltrated or not. Although bad enough operationally and the far-reaching effects, this could have been much worse. It is notable the state was unsure if the data had been exfiltrated. The attackers would not have gone through the full operation and effort of the full attack cycle to compromise the emails just to note they did it. The attackers treat this like a business. The more probably result is the attackers accessed and exfiltrated the data for their use or to sell this.

Remediation
As the PHI was involved, the department was required to notify the persons affected by the oversight. The notifications had to be done by October 9th. There was a significant level of forensic work involved with this. The attackers would have compromised the email system, exfiltrated what they could from here, and attempted to pivot to other systems to further gain access into the systems. The department appears to have a systemic issue, as evidenced by the two attacks, which were proximate. There should be additional training as to phishing awareness.


Resources

Brown, D. (2018, October 12). Minnesota department of human services issues notice to residents after data breach. Retrieved from https://www.clinical-innovation.com/topics/privacy-security/minnesota-dhs-issues-notice-residents-data-breach

Davis, J. (2018, October 12). Two phishing attacks on Minnesota DHS breach 21,000 patient records. Retrieved from https://www.healthcareitnews.com/news/two-phishing-attacks-minnesota-dhs-breach-32-patient-records

HIPAA Editor. (2018, October 12). Phishing attacks on minnesota dhs potentially compromised phi of 21,000 patients. Retrieved from https://www.hipaanswers.com/phishing-attacks-n-minnesta-dhs-potentially-compromised-phi-of-21000-patients/

HIPAA Journal. (2018, October 12). Minnesota dhs notifies 21,000 patients that their PHI has potentially been compromised. Retrieved from https://www.hipaajournal.com/minnesota-dhs-21000-patients-phishing-attack/

Rodgers, B. (2018, October 11). Minnesota DHS subject to two data breaches, officials say. Retrieved from https://kstp.com/news/minnesota-dhs-subject-to-two-data-breaches-officials-say/5104784/

Schubert, K. (2018, October 18). Phishing scam hits minnesota state agency: 21,000 accounts affected. Retrieved from http://www.brainerddispatch.com/news/government-and-politics/4516152-phishing-scam-hits-minnesota-state-agency-21000-accounts

Smith, K. (2018, October 12). About 21,000 minnesotan’s information affected in data breach from department of human services. Retrieved from http://m.startribune.com/about-21-000-minnesotans-information-affected-in-data-breach-from-department-of-human-services/497266381

Cosmos Bank Compromise

Banks are a universal feature throughout the world. These are present in the varied governmental forms, in various asset sizes, and to make loans in various amounts. The loan sizes vary from the micro-loan of a few hundred dollars to millions of dollars in most cases. India is no different than the other countries as it relates to banking. One of the banks in India is Cosmos Bank, which is the 2nd largest cooperative bank. The bank is based in the western city of Pune.

Attack
Banks are attacked and compromised for two primary reasons. There is ample personal data for the clients. This includes but is not limited to legal name, address, credit score, social security number, account numbers with balances, and an epic amount of further data. There is also the little issue of money, which may be exfiltrated physically or digitally.

This attack occurred from August 11 to 13, 2018. Malware was placed on the bank’s ATM servers, which approve the transactions. In this case, which made this work so well, the main banking system received debit card payment requests through a “switching system”. With the attack, this system was bypassed after the firewall in place had been bypassed. The attackers put a proxy switch in the network. The approvals for the fraudulent payments were made through this alternative, unauthorized false proxies.

The attack operation itself occurred within the three days and was well-planned. This attack was intended to be carried out in multiple phases. First, there were 12k-15k withdrawals done within a relatively short time period from the affected accounts. The fraudulent proxy server approved the transactions without verifying the card’s authenticity. These 12k withdrawals added up to a rather significant amount. Of the 12k transactions, a majority occurred overseas. All of the countries in which these occurred had not been released yet. A sample of these includes Canada, Hong Kong, India, and other countries. The ATM portion of the overall attack operation occurred within 7 hours in these 22-28 countries with 450 cloned cards. Curiously many of these transactions occurred in Canada. Even with merely these specific security issues, the bank’s chairman stated the bank’s security systems had not been compromised. Clearly, this process was well-managed.

Later in the day on August 11, 2018 there were another 2,800 card transactions used to steal 2.5 crore rupees. Also, 944m rupees or $13.5M USD was wired to a Hong Kong-based entity. On August 13, 2018, the last day of the attack $2.1m USD or 13.94 crore rupees was wired to the ALM Trading Ltd., a Hong Kong company. The wires or transfers were done within the SWIFT system.

After the Attack
As a natural standard operating procedure, the bank filed a complaint with the police. The bank alleged in the complaint the malware used by the attackers to breach the system was also used to clone the customer’s cards. With the extent of the breach and what attackers were able to accomplish, the situation makes one question what fraud and cybersecurity processes were in place at the bank and “actively” working.

The bank’s response, in a statement, was the bank had adequate IT security in place, although the facts discourage this interpretation. The bank also contracted with a professional cybersecurity forensic agency. The firm began reviewing the logs. As the investigation continues, there are a number of questions left to be answered. These include:
How many ATMs were used for the withdrawals across the various countries?
A mass number of people had to be involved to operate and manage the attacks. What entity was the primary managing entity for the operation across all the countries?
With this large number of cards used in so many countries, who created and distributed these cards?
There should have been a fraudulent activity monitoring system in place, yet there were no issues noted through a majority of the attack. Was this actively monitoring the system’s transactions in real time?
The attack and exfiltration were unfortunate, however, this was a well-planned and distributed attack. There are many areas to be reviewed.


Resources

Dimitrova, M. (2018, August 16). Indian cosmos bank malware attack ends with theft of $13.5 million. Retrieved from https://securityboulevard.com/2018/08/indian-cosmos-bank-malware-attack-ends-with-theft-of-13-5-million/

Goswami, S. (2018, August 17). Police investigate cosmos bank hack. Police investigate cosmos bank hack. Retrieved from https://www.bankinfosecurity.com/police-investigate-cosmos-bank-hack-a-11379

Hindu Business Line. (2018). Cosmos bank’s server hacked; Rs 94 cr siphoned off in 2 days. Retrieved from https://www.thehindubusinessline.com/money-and-banking/cosmos-banks-server-hacked-rs-94-cr-siphoned-off-in-2days/article24675

Inamdar, N. (2018, August 14). 15,000 transactions in 7 hours: Cosmos bank’s server hacked, Rs 94 cr moved to Hong Kong. Retrieved from https://www.hindustantimes.com/india-news/15-000-transactions-in-7-hours-cosmos-bank-s-server-hacked-rs-94-cr-moved-to-hong-kong/story-wazUXZs3LRhcbPlg7Lyx

Jadhav, R. (2018, August 14). India’s cosmos bank loses $13.5 mln in cyber attack. Retrieved from https://www.reuters.com/article/cyber-heist-india/indias-cosmos-bank-loses-135-mln-in-cyber-attack-idUSL4N1V55l1G

Nichols, S. (2018, August 15). India’s cosmos bank raided for $13m by hackers. Retrieved from https://www.tgheregister.co.uk/2018/08/15/cosmos_bank_raided/

PTI. (2018, August 14). Cosmos bank’s server hacked; $s 94 crore siphoned off in 2 days. Retrieved from https://enconomictimes.com/industry/banks-server-hacked-rs-94-crore-siphoned-off-in-2=days/articleshow/65399477/cms

Tanksale, M., & Iyer, S. (2018, August 14). Pune-based cosmos bank loses rs 94 crore in cyber attack. Retrieved from https://timesofindia.indiatimes.com/busienss/india-business/pune-based-cosmos-bank-loses-rs-94-crore-in-cyber-hack/cyber-hack/articleshow/65399204.cms

Sunday, November 4, 2018

PDQ breached!



PDQ is a chain restaurant in several states in the US. Although based in Florida, the chicken chain had grown through many states northward. Although popular, there was recently an issue affecting primarily the restaurants in the Triangle in North Carolina (NC).

Attack
If you enjoyed eating at the restaurant within the last year and paid with a credit card, it would be prudent to check your credit accounts in detail, as the credit card information may have been affected by an attack. The business was targeted, the attackers went through their cycle of reconnaissance and other steps, and successfully attacked and compromised their credit card system. Naturally, since this is where the data is located, the attackers focussed their attention on this area.

After the breach was successful, and the attackers removed the data they wished, the compromise was discovered much later, and PDQ hired a cybersecurity firm for the forensic work. The firm assuredly would be much better equipped to research the specifics of the attack and compromise. The focus of this may not be overly singular, as the breached restaurant credit card data may be much more expansive, as in the case the attackers were able to pivot from this point into other data-intensive areas. The restaurant, in response to the confirmed breach, informed the North Carolina Department of Justice on June 23, 2018.

Time Frame
After the forensic team analyzed the breach, the team determined the time frame the attackers had unfettered access was May 19, 2017, to April 20, 2018. The attackers had complete access for the 11 months to the credit card system. The attackers were done with their data gathering in late April 2018. The company learned of the breach on June 8, 2018. If the attackers had not gathered as much data as they did, they would have continued until at least June 8th.

With the expanse of the overall breach, it would be difficult to detail how many of their clients actually were affected. Presumptively, the attackers would work to secure all of the credit card information, however, they may not have gathered everything through the entire time of the compromised system.

Attack Vector
Clearly, the attack was successful, as the attackers had an extended amount of time in the system, unknown to the company, and exfiltrated a large amount of data, also unknown to the cybersecurity team.

The attackers is believed to have gained entry into the system through a third party vendor’s remote connection tool. This is much like so many other compromises of larger company’s systems, including a retail establishment from years ago. Here also the entry to the credit card was through the vendor’s system.

This issue also brings to the forefront the issue of trusting vendors, while not asking them for cybersecurity questionnaires. Seemingly the companies would need to vett the other companies being used for work as a third party. The lack of cybersecurity applied here has been costly to many retail establishments.

Data Exfiltrated
The attackers, of course, had planned on securing the data possible for them to market. This included all or a portion of the client's names, credit card numbers, expiration dates, and cardholder verification values. This data is perfectly useful to sell on the dark web and other places and creates a bit of a bother for the affected parties.

Client Recommendation
As the company was breached and data exfiltrated, the situation obligated some form of guidance for the affected parties to be provided. Not all of the affected parties would be savvy and know what to do, or possibly even have an inclination. The North Carolina Department of Justice recommended freezing their credit with the credit reporting agencies (Equifax, Experian, and Transunion). This is a good step, however, there are issues with this. If the client were to apply for additional credit, the client would need to unfreeze their credit, wait 3-5 days, apply, and later re-freeze their credit. Although this does work well, it tends to be problematic in third-party functionality.

The clients also need to regularly check their credit report, if they do not freeze their credit. This provides for a regular review. If the client’s identity were to be used fraudulently, any issues could be managed early on. Although still requiring effort to remediate, this would contain the on-going issue.

Thoughts
The attackers had access for 11 months. This is clearly by far too long of a time for unauthorized parties to have unfettered access. The InfoSec team or in the least their SIEM should have noticed the strange IP addresses accessing the system at rather unique times, or the data being exfiltrated night after night.

The breach was not visited after April 20, 2018, yet this was not discovered until June 8. This is indicative of the attackers securing their quota of credit card numbers. It may be the attackers had all the data they could use. This interim lag in the time allowed the attackers to begin marketing the data unchecked and unknown to PDQ. Had this been found much earlier, any damage could have been limited in some form or manner.


Resources

CBS 17 Staff. (2018, June 25). PDQ restaurant customer credit card info hacked in ‘cyber attack,’ officials say. Retrieved from http://www.cbs17.com/

Charles, A. (2018, June). Restaurant chain PDQ says customer’s credit card info was hacked. Retrieved from https://www.wral.com/restaurant-chain-pdq-says-customer-s-credit-card-info-was-hacked/17649050/

Derickson, C. (2018, June 26). Chicken chain customers’ credit card information at risk. Retrieved from https://www.newsobserver.com/news/business/article2138644864.html

Goud, N. (2018, June). Database of PDQ restaurant hacked and sensitive info leaked. Retrieved from https://www.cybersecurity-insiders.com/database-of-pdq-restaurant-hacked-and-sensitive-infoleaked 

Malik, J. (2018, June 27). Popular US fast food chain hit by data breach. Retrieved from https://www.informationsecuritybuzz.com/expert-community/popularus-fast-food/

Spectrum News Staff. (2018, June 23). Cyberattack impacts NC PDQ restaurant. Retrieved from https://spectrumlocalnews.com/nc/triangle-sandhills/news/2018/06/23/cyberattack-impacts-nc-pdq-restaurants

WTVD. (2018, June 23). PDQ data breach exposes customers’ credit card information. Retrieved from http://abc11.com/pdq-data-breach-exposes-customers-credit-card-information/3643475

Verdict Food Service. (2018, June 26). Restaurant chain pdq reports data breach incident. Retrieved from https://www.verdictfoodservice.com/news/restaurant-chain-pdq-data-breach/