Thursday, December 6, 2018

Woesnotgone Meadow; November 30, 2018


All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth. The weather has been unusually cold earlier this week. This has kept many of the residents inside. With the activities limited by the cold, many people worked on their online banking, but not with HSBC Bank.

HSBC Bank has a presence in several countries. Notably for this case is the HSBC Bank subsidiary located in the US. Their system was attacked and compromised. The bank learned of this unauthorized access between October 4 through the 14th, 2018. The attackers were able to exfiltrate data, which was the target, with the client’s names, addresses, date of birth, account numbers, transaction histories, payee details, and balances. With this data, the attackers and whomever the data is sold to on the darkweb, have the ability to make the affected parties life “interesting” for over the next decade. This data allows for the unauthorized parties to use the identity to falsely open accounts, access other websites the clients may have accounts, and overall keep the persons monitoring their credit reports.

This affected thousands of online customers of HSBC Bank USA. The bank did not publish the full amount but did state this number was less than 1% of the US customers. Based on this, the affected parties could number up to 12,000 persons. This was the initial estimate and may increase as time passes and the forensic review continues. The bank, per California state law, notified the California Attorney General, as the breach affected 500 or more California residents.

The bank, attempting to be the good corporate citizen and limit liability, suspended the affected online accounts. The bank also in response to the compromise worked to improve their client authentication process. They also recommended the clients update their passwords and add security features to their login. This included the usual recommendation of using a unique password and changing these regularly.

The compromise was due to some form of a lack of cybersecurity. HSBC Bank has not however published how this occurred. The details noted so far seem to indicate this was a credential stuffing attack. This vulnerability is so usable for the attackers due to the users reusing the same username and passwords with the different website logins. Here, the credentials from one login and tried in other likely used websites and services.

If anyone in the Meadow is using the same logins or passwords for multiple websites, you may want to change these to something unique.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.


Resources
E Hacking News. (2018, November 7). HSBC online banking customers’ data compromised: Confirms the bank. Retrieved from https://www.ehackingnews.com/2018/11/hsbc-online-banking-customers-data.html

HSBC. (2018, November 2). Notice of data breach. Retrieved from https://oag.ca.gov/system/files/Res%20102923?20PIB%20Main%20v3_1.pdf

Nichols, S. (2018, November 6). HSBC now stands for hapless security, became compromised: Thousands of customer files snatched by crims. Retrieved from https://www.theregister.co.uk/2018/11/06/hsbc_security_broken/


Winder, D. (2018, November 6). HSBC bank USA admits breach exposing account numbers and transaction history. Retrieved from https://www.forbes.com/sites/daveywinder/2018/11/06/hsbc-bank-usa-admits-breach-exposingaccount-numbers-and-transaction-history/#394417d35af3

Monday, December 3, 2018

Woesnotgone (Woes-not-gone) Meadow; November 28, 2018


All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth. It seems as though winter has crept in like the wind. This has limited our activities somewhat as the roads have a not-so-nice layer of ice, which at times can be difficult to see, let alone drive on.

Seems as though the city of Muscatine, Iowa had their own event slowing down workflow also. As with most industries, nearly everyone with assets with value is a target. Local municipalities are not sheltered from this risk. Thankfully, the Meadow has not been targeted in recent years. In Muscatine, Iowa however several of their servers were targeted, including one used by the finance department.

The attackers used ransomware as their tool. This occurred at approximately 1am on October 17, 2018. This was very successful for the attackers. The servers were targeted and compromised. One of these included in the pool was used by the finance department, which was the Springbrook server. The other servers were used by the city hall departments and library. As this was successful, the affected departments had to use pen and paper for over a week. As of the latest report, the city officials were still reviewing what happened to allow the ransomware in. This has not been published yet.

The city officials did publish a press release on October 18, 2018, describing in general terms what happened. Fortunately, the critical servers were still operating. It is notable that the city did not pay the ransom. Years ago, the city decided to purchase cyber insurance, and this proved to be a benefit, from not only being insured, however, also the insurance company was very active in the response.

To remediate this, the city or insurance company contracted with a third party to assist with the issue. They believe they were able to isolate the ransomware and move forwards. Perhaps it would be prudent to provide additional training for the staff to be alert for general phishing attacks, USB sanitary practices, and what to not click on in the future.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.


Resources
City of Muscatine. (2018, October 18). [Archived] City of muscatine servers hit with ransomware attack. Retrieved from https://www.muscatineiowa.gov/CivicAlerts.aspx?AID=760&ARC=1030

City of Muscatine. (2018, November 2). City slowly recovering from ransomware attack. Retrieved from https://www.muscatineiowa.gov/CivicAlerts.aspx?AID=770

Coleman, S.B. (2018, November 2). Update: City of muscatine “well on the way” to return of normal operations after ransomware attack. Retrieved from https://www.kwqc.com/content/news/City-of-Muscatine-reports-ransomware-attack-497981371.html

Hanson, A. (2018, October 23). City of muscatine responds to cyber attack. Retrieved from https://www.kwqc.com/content/news/City-of-Muscatine-responds-to-cyber-attack-498364541.html

Journal Staff. (2018, November 2). Muscatine still recovering from ransomware attack. Retrieved from https://muscatinejournal.com/muscatine/news/local/muscatine-still-recovering-from-ransomware-attack/

Loging, S. (2018, November 15). Muscatine coming back online after cyber attack left them in the dark. Retrieved from https://www.ourquadcities.com/news/muscatine-coming-back-online-after-cyber-attack-left-them-in-the-dark/1600554261

WQAA Digital Team. (2018, October 19). Muscatine cyber attack targets government financial server. Retrieved from https://wqad.com/2018/10/19/muscatine-cyber-attack-targets-government-financial-server/

WQAD Digital Team. (2018, November 2). Muscatine government cyber attack recovery ‘a slow process’. Retrieved from https://wqad.com/2018/11/02/muscatine-government-cyber-attack-recovery-a-slow-process/

Friday, November 23, 2018

PageUp Breach


PageUp is an Australian firm. Their business is a Human Resources software provider. PageUp has a global presence with 2M users across 190 countries. The vast number of these clients are corporate. These include Wesfarmers (Coles, Target, Kmart, and Officeworks), NAB, Telstra, Commonwealth Bank, Lindt, Aldi, Linfox, Reserve Bank of Australia, Australia Post, Medibank, ABC, Australian Red Cross, University of Tasmania, AGL, and Jetstar.


Attack
PageUp, unfortunately, was on the receiving end of a successful malware attack. This took the form of an unauthorized person gaining access to its system. The precise method or attack point has not been published yet.

Exfiltrated
The focus with this attack was not, in this case, encrypting their servers or destroying the data, as with ransomware or other malicious acts. Data acquisition was the end-goal. As noted, the attack was successful. The attackers were able to access their customer’s information. This was the data relating to the client’s personal data (i.e. names, street address, email address,   telephone numbers, bank details, tax file numbers, diversity information, and emergency contact information), placement agencies, applicants, references, and own employees. The passwords may have been accessed, however per the company these were hashed.

Detection
For this attack to be successful, there was a significant amount of activity. PageUp detected what the company noted as “unusual” activity with its IT infrastructure in May 2018. PageUp began their forensic investigation on May 23, 2018. The detection took the form of malware being detected on its systems. Fortunately, the investigation confirmed this as the issue five days later. The business is working with the Australian Cyber Security Centre, several third-party cybersecurity firms, and the Australian Federal Police.

Remediation
This was a substantial issue. As noted, this was detected internally by their systems. Until this was resolved the business did not accept new apps. Due to the level of penetration into the business, a portion of the customers was still wary and treating the situation cautiously.

GDPR
Nearly every person is familiar with GDPR. This new set of laws in the EU is focused on the data security for the people in the EU and is rather far-reaching. This affects not only businesses in the EU, but anyone holding, managing, or processing any of this data.

PageUp has interests and works in the EU. The breach and compromise may be considered a violation of the GDPR. PageUp may possibly face a massive fine of up to 4%of their global turnover. The business is also dealing with other issues, including reputational problems, costs associated with the forensic work, and potential for a class action lawsuit.

Affected
The data exfiltrated was confidential and personal, and marketable by the attackers. The data and amount of data were great for a person’s seeking to perpetrate identity fraud. The affected clients have years of potential issues to deal with including monitoring their credit for fraudulent charges and accounts.


Resources
Bunker, G. (2018, June 11). What the pageup data breach means in a post-GDPR world. Retrieved from https://www.informationsecuritybuzz.com/expert-comments/what-the-pageup-data-breach/

Crozier, R. (2018, June 12). PageUp people all but confirms personal data ‘accessed’. Retrieved from https://www.itnews.com.au/news/pageup-people-all-butconfirms-personal-data-accessed-493481

Davies, A. (2018, June 7). PageUp data breach: Thousands of job seekers’ details potentially exposed. Retrieved from https://www.theguardian.com/technology/2018/jun/07/thousands-of-job-seekers-details-potentially-exposed-in-hack

Duerden, J. (2018, June 12). Blame pageup breach on security industry. Retrieved from https://www.theaustralian.com.au/business/technology/blame-pageup-breach-on-security-industry/news-story/

Duke, J. (2018, June 11). PageUp data breach: ABC, Asoki, Myer, Macquarie pull jobs pages. Retrieved from https://www.smh.com.au/business/companies/pageup-data-breach-abs-asaki-myer-macquerie-pull-jobs-pages-20180611-p4zktj.html

McLean, A. (2018, June 12). PageUp says it is ‘probable’ customer data was externally accessed. Retrieved from https://www.zdnet.com/article/pageup-says-it-is-probable-customer-data-was-externally-accessed/

Paganini, P. (2018, June 6). HR software firm pageup is the last victim of a data breach, the company has 2.6 million active users across over 190 countries. Retrieved from https://securityaffairs.co/wordpress/73242/data-breach/pageup-data-breach.html

PageUp. (2018, June 12). Unauthorized activity on IT system. Retrieved from https://www.pageuppeople.com/unauthorized-activity-on-it-system/

Air Canada Compromised!

Each country has its own set of airlines servicing its area. Based on the market, certain countries have more or less than the others. These fly throughout their respective nation and world. Most persons, as a national course of business, go online, enter their information, including credit card numbers, to purchase the airline tickets. This occurs throughout the globe every single day without an issue. An option also is to do this with a mobile device.

Issue
Air Canada has a number of users purchasing tickets. A portion of these purchases are done on a mobile device using the mobile app. These were the focus of the attack. A subset of these, who had entered into the system their passport information, may have had their data stolen.

Attack
Air Canada had been previously criticized for their weak password system. The prior convention used was 6-10 characters (letters and numbers), but no other symbols. With this possibly short passwords in place, there are two issues. One is the lack of complexity with the acceptable passwords, and the other is the potential for the users to use these passwords across multiple domains. In comparison, the official guidance from the Canadian government is for passwords to have a minimum length of eight characters and at least one character that is not a letter or number. Seemingly, Air Canada would have followed the guidance from their own government.

After the attack Air Canada required the password to be at least 10 characters and one symbol. Air Canada was not sure yet how the mobile app breach occurred. This was a relatively serious issue as approximately 20k account’s data is believed to have been stolen. This is approximately 1% of their clientele. The data did not include the credit card details, as these were encrypted. This did include the client’s name, email address(es), phone numbers, passport numbers, passport country of issuance, expiration date, nationality, gender, and country of residence.

This list is rather substantial and the data someone would need to assume another’s identity. Also the attackers, or persons subsequently with this data could set up other accounts at banks, open credit cards, and other actions which would negatively impact the user’s credit scores.

On a tangent, Air Canada did however respond quickly to the issue. Their effort is applauded. The business also updated the password convention to a more appropriate level.

Indications
The attack and compromise would not have been something unknown for an extended period. There had been a large, unusual level of activity between August 22-24, 2018. This was in the form of the large number of log-ins during this period. The volume was well outside of the normal value, even with a margin of error attached.

Remediation
The airline, to be thorough, locked down the entirety of the 1.7M accounts. The management did not want subsequent issues continuing if a handful of the accounts were missed. In order to continue to use the service, the users would need to reset their password to access their account again.

Lessons
Passwords are a touchy subject with users. The users want passwords that are easy to remember and short. In the alternative, the users would like to not use passwords at all. However, some form of authentication is required. For the users, dependent on the use case, a password manager or generator may work well. Also using MFA would be beneficial.




Resources

BBC News. (2018, August 29). Air canada app data breach involves passport numbers. Retrieved from https://www.bbc.co.uk/news/technology-45349056

Constantin, L. (2018, August 30). Hackers access data. Retrieved from https://securityboulevard.com/2018/08/air-canada-resets-customers-passwords-after-hackers-access-data/

Dunn, J.E. (2018, August 30). Air canada resets 1.7 million accounts after app breach . Retrieved from https://nakedsecurity.sophos.com/2018/08/30/air-canada-resets-1-7-million-accounts-after-app-breach/

Evans, P. (2018, August 29). Air canada mobile app breach affects 20,000 people. Retrieved from https://www.cbc.ca/news/business/air-canada-mobile-app-1.4802879

Johnson, B. 92018, August 30). All 1.7 million air canada app users must reset passwords after breach. Retrieved from https://www.itworldcandda.com/article/all-1-7-million-air-canada-app-users-must-reset-password-after-breach/

Osborne, C. (2018, August 30). Air canada reveals mobile data breach, passport numbers potentially exposed. Retrieved from https://www.zdnet.com/article/air-canda-reveals-mobile-data-breach-passport-numbers-potentially-exposed/

Reynolds, C. (2018, August 29). Air canada says mobile app breach may affect up to 20,000 customers. Retrieved from https://www.ctvnews.ca/business/air-canda-says-mobile-app-breach-may-affect-up-to-20-000-customers-1.4072467

Seals, T. (2018, August 30). Travel breaches hit air canada and asia-pac hotelier. Retrieved from https://threatpost.com/travel-breaches-hit-air-canda-and-asia-pac-hotelier/137059/

Security Experts. (2018, August 30). Air canada breach. Retrieved from https://www.informationsecuritybyzz.com/expert-comments/security-experts-comments-air-canada-breach/

Whittaker, Z. (2018, August 29). Air canada confirms mobile app data breach. Retrieved from https://techcrunch.com/2018/08/29/air-canada-confirms-mobile-app-data-breach/

British Airways Targeted


In this age, credit cards are required for many aspects of our culture. To rent a car, hotel room, or purchase airline tickets, a credit or debit card is required. To purchase these services without a credit card is problematic. One airline providing the travel service is British Airways, a major international airline. Unfortunately, the airline system was breached. This affected 380,000 credit card payments. These were used on the British Airways website and mobile app in August 2018. British Airways did contact the affected parties on September 7, 2018. A large number of affected parties, there are a number of questions of attack methodology. The attackers must have had a clear and in-depth penetration into their system.

Attack
With this attack and compromise, they were able to note when, including the time, the attack occurred. During August 21, 2018 (10:58p) through September 5, 2018 (9:45p), the company’s website and mobile app were successfully attacked and breached. Curiously, BA stated this was a data theft, versus calling this a breach. This may indicate this was an internal threat versus originating from a third party.

Data
The attackers could have targeted a variety of data based on the attack and potential points to pivot from. The attackers were able to access valuable data with the customer’s name, address, email addresses, credit card expiration dates, and other credit card details, including the CVV code. Fortunately for the affected parties, the attackers were not able to exfiltrate the customer’s passport data.

Vulnerability
Throughout several industries, web applications tend to be a valid, robust attack point. This is due to security not being included through the process, new vulnerabilities, and insecure coding, among other issues. BA did remediate the vulnerability.

With these issues, it would be beneficial to know exactly what the vulnerability exploited was, or if there were multiple, what these were. In this case, others could learn from the oversights so that these errors would not be done repeatedly by others in the same and other industries. Unfortunately, in this case, BA had refused to answer any further questions relating to the breach.

Through the issue, BA worked with cybersecurity firms through the forensic review period. The attack period itself is notable. The attackers had over two weeks of full access. Perhaps the SIEM did not detect the compromise in a timely manner, or the logs and reports were not examined at length. This was too long for the compromise, which increased the number of their clients affected by this.

Lessons
The information security teams should have detected this individually or through their tools in place on the systems. The data should have been reviewed prior to the time this was. This is a lesson for others, not only in the airline industry. The logs should be regularly reviewed for anomalies and other unusual activities.


Resources
Buchanan, B. (2018, September 7). British airways hacking? How not to respond to a cyber attack. Retrieved from https://theconversation.com/british-airways-hacking-how-not-to-respond-to-a-cyber-attack-102857

Calder, S. (2018, September 7). BA data breach: What does the british airways hack mean for customers? Retrieved from https://www.independent.co.uk/travel/news-and-advice/british-airways-flights-ba-hacked-data-theft-customers-a8526516.html

Cuthbertson, A. (2018, September 8). British airways hacked: Scale of customers ‘astounding’, security experts say. Retrieved from https:www.independent.co.uk/life-style/gadgets-and-tech/news/british-airways-hacked-customer-data-breach-astounding-ba-security-experts-98527071.html

Davies, R. (2018, September 7). Hacked data-including CVV codes-worth about 20m on dark web, cybersecurity experts say. Retrieved from https://www.theguardian.com/business/2018/sep/07/ba-british-airways-customers-hacked-credit-card-details-dark-web

Detrixhe, J. (2018, September 7). British airways massive data breach has given tech upstarts a chance to promote themselves. Retrieved from https://qz.com/1382301/british-airways-data-breach-monzos-quick-response/

Duckett, C. (2018, September 7). British airways hit with customer data theft. Retrieved from https://www.zdnet.com/article/british-airways-hit-with-customer-data-theft/

Dungay, D. (2018, October 9). British airways announces cyber security breach. Retrieved from https://commsbusiness.co.uk/news/british-airways-announces-cyber-security-breach/

E Hacking News. (2018, September 8). British airways security breach: Credit card details of 380,000 customers stolen. Retrieved from http://www.ehackingnews.com/2018/09/british-airways-security-breach-credit.html

Gulliver. (2018, September 9). British airways admits that over 380,000 customers had their data stolen. Retrieved from https://www.economist.com/gulliver/2018/09/09/british-airways-admits-that-over-380000-customers-had-their-data-stolen

Khandelwal, S. (2018, September 6). British airways hacked-380,000 payment cards compromised. Retrieved from https://thehackernews.com/2018/09/british-airways-data-breach.html

Leyden, J. (2018, September 7). Revealed: British airways was in talks with ibm on outsourcing security just before hack. Retrieved from https://www.theregister.co.uk/2018/09/07/ba_security_outsourcing_consultation_memo/

O’Donnell, L. (2018, September 7). British airways website, mobile app breach comprises 380k. Retrieved from https://threatpost.com/british-airways-website-mobile-app-breach-compromise-380k/137291/

PYMNTS. (2018, September 10). British airways data hack a test case for GDPR. Retrieved from https://www.pymnts.com/news/regulation/2018/british-airways-data-breach-gdpr-compliance-data-security/

Telegraph Reporters. (2018, September 7). British airways hacking: Customers cancel credit cards as airline defends handling of ‘sophisticated’ cyber attacks. Retrieved from https://www.telegraph.co.uk/news/2018/09/07/british-airways-hacking-customers-cancel-credit-cards-airline/

V3 Newsdesk. (2018, September 7). British airways security breach compromises 380,000 credit cards. Retrieved from https://www.V3.co.uk/v3-uk/news/3062330/british-airways-security-breach-compromises-380-000-credit-cards

Whitaker, Z. (2018, September 6). British airways customer data stolen in data breach. Retrieved from https://techcrunch.com/2018/09/06/british-airways-customer-data-stolen-in-data-breach/

Leave the breweries alone! Arran Brewery compromised

Unfortunately, ransomware is quite common as an attack vector across the business. This is partially due to the delivery method being low impact, cost-efficient, and easily done. This form of attack has the capability to provide for a large ROI (return on investment) when the attack is marginally effective. Any business with capital or data of value is a viable target.

One particular attack point not used significantly as it could have been being the Human Resources Department. The Human Resource Department staff expect dozens of resumes and documents daily from persons seeking positions with the business. The Human Resources staff are trained in human resource matters and have not exactly been trained to watch for malware. The staff may open the documents without actually thinking about it. This, unfortunately for the business, may have unintended results.

Arran Brewery
There is a small brewery in Scotland. The brewery sells Arran Blonde and Arran Red Squirrel. The business is based on the Isle of Arran. Through the year the business has multiple job openings and accepts resumes and other documents from the various applicants.

Attack
As noted, the business was the victim of ransomware. The business termed this as a sophisticated attack. Most ransomware attacks are labelled as such when these may be a normal strain. As with ransomware, the target opened the email with the resume as the attachment. Reportedly with this incident, the ransomware was in the PDF. This ransomware was a variant of the Dharma ransomware. This functions to rename files with the .bip extension.

The Human Resource Department member would have had no idea of the ransomware. With the dozens of documents, they would receive, it would have been difficult to discern which resume was the malware-ridden one. The attacker had the job posting placed in several other career sites to increase the number of resumes received. This should have been noted as a symptom of an issue when the business began to receive resumes from across the country and globe. This worked brilliantly to camouflage the email with malware among the large numbers received from various sources, which normally would not have been received.

This locked the brewery out of their system. This also worked to encrypt a portion of their back-ups. The decryption key ransom was two bitcoins. Arran Brewery declined to pay. The business lost three months of sales data from one server. They had been attempting to restore the data. In order to relatively ensure the malware was not present on the servers going forward, the business contracted with a consultant to purge this.

Effects
As you would expect, there was a rather significant disruption to the business. This includes, but was not limited to the lost sales data, the direct labour and overhead associated with the staff working on this issue, and also the contracted parties fees. This was not a cheap endeavour to remediate this. In a non-financial sense, the management lost partially their confidence in the cybersecurity system.

When the Human Resources staff member opened the malicious file, the staff member was just following the standard operating procedures with receiving the resumes, opening these, and reviewing the qualifications. Of the hundreds of resumes received, at least one made it through the malware filter and was opened. This shows the need for the blue (defensive) team to think more creatively to defeat those that would attack the system.

This also highlights the need for additional training to remove as much as possible the potential for ransomware in the enterprise.

Resources
BBC. (2018, September 20). Arran brewery hit by ransomware attack. Retrieved from https://www.bbc.com/uk-scotland-scotland-business-45587903

Burton, G. (2018, September 21). Arran brewery attacked with ransomware under cover recruitment-ad CV spam. Retrieved from https://www.computing.co.uk/ctg/news/3063224/arran-brewery-attacked-with-ransomware-under-cover-of-recruitment-ad-CV-spam

Dissent. (2018, September 21). UK: Arran brewery blackmailed by hackers as scottish beer firm becomes latest victim of sophisticated ransomware attack. Retrieved from https://www.databreaches.net.net/uk-arran-breery-blackmailed-b7-hackers-as-scottish-beer-firm-becomes-latest-victim-of-sophisticated-ransomware-attack/

French, P. (2018, September 21). Arran brewery victim of ‘very devious’ cyber attack. Retrieved from https://www.thedrinksbusiness.com/2018/09/arran-brewery-victim-of-very-devious-cyber-attack/

Leyden, J. (2018, September 21). Scottish brewery recovers from ransomware attack. Retrieved from https://www.theregister.co.uk/2018/09/21/arran_brewer_ransomware/

N., B. (2018, September 24). Arran brewery hits massive ransomware attack-Warned other companies to stay safe. Retrieved from https://gbhackers.com/arran-brewery/

Nexit. (2018, September 21). Scotland’s arran brewery slammed by dharma bip ransomware. Retrieved from https://www.next-it.net/scotlands-arran-brewery-slammed-by-dharma-bip-ransomware/

Olenick, D. (2018, September 21). Scottish brewery ransomware attack leverages job opening. Retrieved from https://www.scmagazine.com/home/news/scottish-brewery-ransomware-attack-leverages-job-opening/

Schwartz, M.J. (2018, September 21). Scotland’s arran brewery slammed by dharma bip ransomware. Retrieved from https://www.bankinfosecurity.com/scottish-brewery-slammed-by-dharma-ransomware-variant-a-11537

Smith. (2018, September 23). Brewery became victim of targeted ransomware attack via job vacancy ad. Retrieved from https://www.csoonline.com/article/3307193/security/brewery-became-victim-of-targeted-ransomware-attack-via-job-vacancy-ad.html

Sussman, B. (2018, September 21). Tear in my beer: Brewery hit by ransomware. Retrieved from https://www.secureworldexpo.com/industry-news/ransomware-hr-case

Whitelaw, J. (2018, September 20). ‘Pay up’ arran brewery blackmailed by hackers as scottish beer firm becomes latest victim of sophisticated ransomware attack. Retrieved from https://www.thescottishsun.co.uk/tech/3235218/arran-brewery-blackmailed-hackers-ransomware-attack/


Tuesday, November 20, 2018

Hacking from Prison: Yes, it's a thing

Prison has the mission to rehabilitate the person who had committed the crime which warranted the stay in the prison. The prisoners, while being rehabilitated, are able to contact their families, play games, learn a trade, work, receive therapy, and other activities. One option for the incarcerated person is to use tablets for a few of these functions. These pieces of equipment have become more popular with the inmates.

JPay
This option for the prisoners involves basic technology. The inmates have the option to, towards this end, use JPay tablets. JPay has been working with the prison system to provide these since 2002 across 35 states. These are supplied to the prison system and prisoners by CenturyLink and JPay. The inmate’s family or friends purchase these for the inmates. In limited instances, JPay has given these to the inmates. JPay did this for 53k inmates in the New York State prison system recently. The others have had to pay for this.
The tablets function to allow prisoners to email their families and friends, video chat with these persons, watch videos of an educational nature, and download and play games and music, which had been purchased. The inmates could also use this for ebooks and news. The prisoner’s family and friends are able to put their funds, to pay for the non-free items, on the JPay account for the inmate. As an example, the inmate may send one page of an email for 50 cents. This is very useful for the inmates.

Vulnerability Exploited
Seemingly, the process for using the technology should have worked rather smoothly, which it did for years. Recently, however, the inmates using these detected a vulnerability and exploited this to the extreme. The exploitation was detected by the Idaho Department of Corrections on July 2, 2018. The inmates were able to add $225k in credits to their accounts while the families and friends had actually not added the funds to their accounts. This involved 364 inmates.

Remediation
The vulnerability has been resolved. Unfortunately, the specific steps for the exploit or the point of the vulnerability has not been published. This is due to JPay claiming this is proprietary information. This also does not allow others to learn from their errors or oversights.
The inmates involved with this issue may still use the email on their tablets. They are however not able to download games or music until the respective inmates repay what was stolen. Of the $225k, $65k has been recovered. The involved inmates did receive disciplinary offense reports.

Lessons
This current incident emphasizes the need for SecDevOps, or adding cybersecurity into the development cycle. Without the sufficiently trained and experienced staff, there will continue to be issues. The people will continue to look for different methods to break the hardware and software.

Resources
And one, D. (2018, July 27). Idaho prisoners hacked tablets and gave themselves $225,000 in credit. Retrieved from https://www.cnn.com/2018/07/27/us/idaho-inmates-hack-tablets/index.html
Digital Trends. (n.d.). Idaho prisoners hack $225,000 in credits from jpay computer tablets. Retrieved from https://www.digitaltrends.com/mobile/inmates-hacks-jpay-tablets/
Fortin, J. (2018, July 27). Idaho inmates hacked prison service for $225,000 in credit. Retrieved from https://www.nytimes.com/2018/07/27/us/idaho-prison-hack-jpay-nyt.html
Fussell, S. (2018, July). Inmates ‘hack’ prison issued tablets, swiping $225,000 in app bucks for music and games.
Hatmaker, T. (2018, July 27). Idaho inmates hacked prison-issued tablets for $225,000 in credits. Retrieved from https://techcrunch.com/2018/07/27/inmates-idaho-jpay-hack/
KTVB. (2018). After tablet hack-or glitch?-many rooting for Idaho inmates. Retrieved from https://www.ktvb.com/articles/news/local/idaho/after-tablet-hack-or-glitch-many-rooting-for-idaho-inmates/277-578135801
Law, V. (2018, July 27). How a group of imprisoned hackers introduced jpay to the world. Retrieved from https://www.wired.com/story/how-a-group-of-imprisoned-hackers-introduced-jpay-to-the-world/
McDermid, B. (2018, July 27). Idaho inmates hacked prison tablets and stole $225,000. Retrieved from https://www.engadget.com/2018/07/27/inmates-jpay-tablet-hack-email-music-games-idaho/  
Statt, N. (2018, July 26). Idaho prison inmates exploited tablet vulnerability to steal $225,000 in credits. Retrieved from https://www.theverge.com/2018/07/26/17619972/idaho-prison-inmates-tablet-hacks-jpay-stolen-credits-250-thousand
Vaas, L. (2018, July 30). Prisoners exploit tablet vulnerability to steal nearly $225k. Retrieved from https://nakedsecurity.sophos.com/2018/07/30/prisoners-exploit-tablet-vulnerability-tosteal-nearly-225k/