Friday, July 3, 2020

Maine State Police database pwned


Each municipality and state has some form of a police presence. Maine is no different. The police departments hold an immense amount of data on past crimes, current investigations, and other issues.

 

Target

The database was used for information sharing for federal, state, and local law enforcement. The database breach may have jeopardized ongoing investigations. The database, in the Maine Information and Analysis Center (MAIC), is intended to assist with protecting against terrorism and other significant crimes. The database mostly holds information on criminal offenses and bulletins. The bulletins often contain identifying information, such as full name and date of birth under an investigation. This allows regional law enforcement to share data and collaborate to solve crimes.

 

Attack

The state police were notified on June 20, 2020, by Netsential of the data breach. This may have included certain information from Maine Information and Analysis Center (MAIC). Netsential has been contracted by the state police since 2017. The company provides web hosting services to hundreds of law enforcement and government agencies across the country. The attack vector and method(s) used have not been published. This is unfortunate, as this could be a learning experience for others.

 

Post-Breach

The state police contacted the FBI’s Houston Field Office to investigate and determine the extent of the data breach. While the details are scant, this serves as another example of why an organization needs to have an incident response plan in place. While affected a database, it could have been much larger and devastating.

 

 

Resources

Associated Press. (2020, June 27). Security breach impacts maine state police database. Retrieved from https://www.boston.com/news/local-news/2020/06/27/security-breach-impacts-maine-state-police-database

Boston Globe. (2020, June 28). Security breach impacts maine state police database. Retrieved from https://www.newsbreak.com/maine/augusta/news/0PSSTMTZ/security-breach-impacts-maine-state-police-database

Caledonian Record. (2020, June 28). Security breach impacts state police database. Retrieved from https://www.caledonianrecord.com/news/regional/security-breach-impacts-state-police-database/article_868571e7-55ca-5514-99da-fc012f15b021.html

Coleman, M. (2020, June 27). Security breach impacts maine state police database. Retrieved from https://upnewsinfo.com/2020/06/27/security-breach-impacts-maine-state-police-database/

England, K. (2020, June 26). Main state police statement on third-party data breach involving the maine information and analysis center (MIAC). Retrieved from https://www.maine.gov/dps/msp/media-center/public-releases/maine-state-police-statement-third-party-data-breach-involving-maine

WGAN. (2020, June 29). Security breach impacts maine state police database. Retrieved from https://wgan.com/news/074470-security-breach-impacts-maine-state-police-database/


Friday, June 26, 2020

Did I do that? Twitter data leakage

We have all heard of and probably use Twitter. Everyone recognizes the corporate logo and symbol. While there have been other social media outlets, Twitter has stayed the course and continues to be a social media giant.

Breach

Recently, Twitter had an issue with a breach, aka “data security incident” in corporate speak. The problem was detected by Twitter on May 20, 2020.

Affected Users

This did not affect all of the users, which would have been a disaster and epic fail. This only affected the business users who paid for advertisements on the platform, using Twitter Ads and Analytics Manager.

Data

The data involved was not critical, however, it should not have been leaked. This included the business user’s email address, billing address, phone numbers, and the last four digits of their credit card numbers. This could have been much worse for the clients if more of the information, including full credit card numbers, would have been included. What further limits the issue is the attacker would require access to the user’s browser to steal this information. This would have to occur one user at a time with the attacker physically sitting at each machine. With the full method to retrieve the data, this attack, while an issue, is practical in very limited circumstances. If retrieving the data was much easier on a grander scale and more confidential information was available, the story would be totally different.

How?

In this day and age of continued data loss, seemingly there would be a data leakage program in place to check systems, configurations, and just about everything else to ensure, as much as you can, that this does not happen. Unfortunately, there was an issue. If the business were to check their billing information on ads.twitter.com or analytics.twitter.com, which would not be that unusual, the data was stored in the browser’s cache. While this is not the end of the world for the affected parties, it should probably be treated as more of a teachable learning experience. The future employees know not to allow this, and this provides a real-life example of what can happen if you let this go.

Remediation

Clearly, this is a problem. Once Twitter detected the issue, they did resolve it. Twitter needed to update their headers to set to no-store and no-cache. This would in effect disable the data from being stored locally at the machine. One issue with this, other than the configuration allowed this, was the timing. This was detected by Twitter on May 20, 2020. This was not reported to the users for more than a month. While the data leakage issue was limited, as noted, this really should have not taken a month to resolve to notify the affected parties.  

 

Resources

Adhikari, R. (2020, June 24). Twitter apologizes for data security incident. Retrieved from https://www.technewsworld.com/story/86726.html

Admin1. (2020, June 26). Twitter suffered a major data breach-but this is why you’re probably safe. Retrieved from https://marijuanapy.com/twitter-suffered-a-major-data-breach-but-this-is-why-youre-probably-safe/

Financial Press. (2020, June 25). Twitter hack: Social media giant suffers ‘huge’ billing information data breach. Retrieved from https://financial-press.uk/2020/06/23/twitter-hack-social-media-giant-suffers-huge-billing-information-data-breach-world-news/

Ians. (2020, June 24). Twitter sorry for data breach involving business clients. Retrieved from https://kalingatv.com/technology/twitter-sorry-for-data-breach-involving-business-clients/

Jay, J. (2020, June 23). Twitter says business users’ data leaked in security fiasco. Retrieved from https://www.teiss.co.uk/twitter-says-business-users-data-leaked-in-security-fiasco/

McLoughlin, B. (2020, June 23). Twitter hack: Social media giant suffers ‘huge’ billing information data breach. Retrieved from https://www.express.co.uk/news/world/1299728/Twitter-data-breach-hack-latest-billing-information-twitter-business-update-twitter-search

McLoughlin, B., & Wilson, R. (2020, June 23). Twitter businesses’ billing information is hacked in data breach. Retrieved from https://www.examinerlive.co.uk/news/uk-world-news/twitter-businesses-billing-information-hacked-18471270

Riley, D. (2020, June 23). Twitter apologizes after exposing business customer information. Retrieved from https://siliconangle.com/2020/06/23/twitter-apologizes-exposing-business-customer-information/

Security Experts. (2020, June 24). Twitter suffers billing information data breach. Retrieved from https://www.informationsecuritybuzz.com/expert-comments/comment-twitter-suffers-billing-information-data-breach/

Sharma, A. (2020, June 24). Twitter discloses billing info leak after ‘data security incident’. Retrieved from https://news.knowledia.com/IN/en/articles/twitter-discloses-billing-info-leak-after-data-security-incident-1dc82af759dc4c7451ea428b26c622dc5f438e6e

Techradar.com (2020, June 26). Twitter suffered a major data breach-but this is why you’re probably safe. Retrieved from https://www.thetechstreetnow.com/tech/twitter-suffered-a-major-data-breach--but-this-is-why-youre-probably-safe/10326781581085137573/10326781581085137573/

Sunday, June 14, 2020

Municipalities targeted: City of Florence pwned!


Municipalities have a very distinct problem. They are frequently targeted for ransomware and other attacks, as the attackers know their systems generally are not fully secure unless they been recently successfully attacked and have corrected and mitigated the issues. This is driven by budgetary constraints, not allowing the city, county, etc. to be able to hire exceptional talent, purchase the tools needed in a timely manner, and other requisite uses for cybersecurity. While this is a Catch-22, it leaves these organizations in the wind, hoping to be obscure enough so that they are not noticed and attacked. Even a failed attack can have negative effects on the operations for many reasons.

 

One of these targeted was the city of Florence, located in Alabama. Florence, much like the city in Italy, sounds like an amazing place to live, located on the banks of the Tennessee River with many festivals and other attractions. This is not a massive metropolis, with nearly 40k residents. Of all the places to target, you have to wonder why Florence?

 

Attack

As you can guess, the city’s computer system had been successfully attacked. The entry points were through the email system. Specifically, this was a phishing attack, and the unfortunate phishee was Steve Price, the IT Manager. His credentials were acquired as part of the attack. The phishing email was one of the many samples of the DHL email, where there are dozens of email recipients, all receiving the same package with the same tracking number on the same day. These emails are pretty obvious as to what they really are there for.

 

The illustrious, yet distinguished Brian Krebs notified the mayor’s office of their system’s compromise on May 26. From the published accounts, the city somehow did not know of the breach prior to this. This is odd, as seemingly someone in the IT Department maybe should have noticed a strange IP address accessing the system and pulling data from the network. The following day the System Administrator did contact Mr. Krebs to let him know the computer and network account affected has been isolated and is not in service. It appears the SysAdmin did not quite understand the capabilities of the attackers at this point. On June 5, 2020, the attackers finished deploying the ransomware and began their demand for the ransom payment. The city has 12 days to fully defend against the attack, however, unfortunately only did a part of the work required to address the issue.

 

When the city began to review the situation, it did not appear any of the affected system’s data had been deleted or exfiltrated. This was probably a little too optimistic for the city.

 

On a side note, the attack occurred while the IT department was attempting to have the City Council approved the expense for a third party to do a penetration test of the IT systems.

 

Ransom

The attackers are not going to work through the attack cycle for practice and their mental gymnastics in an attack. The system has been operationalized into a business, and a rather profitable one measured by the return on investment (ROI). In this case, the attackers were DoppelPaymer. The attackers have demanded the ransom $378k in bitcoin. The amount was negotiated down to $330k by a third-party firm, still in bitcoin. This does seem like a rather large sum, given the size of the city. The attackers, however, have realized the power of their leverage on the systems.

 

Post-Attack

Once the city had the opportunity for a quick review, the city’s IT department and a third-party, contracted by the city (Arete Advisors), began to adequately investigate the issue. As time had passed and more effort was placed into the investigation, the city realized the attackers may have at least a portion of the data on the affected systems. The city noted they just don’t know. One would presume they had sufficient access, such that if they wanted, they could have taken the data they wanted to. On this note, the investigation noted the attackers had access beginning in early May 2020 and continued this for nearly the remainder of the month. During this time, the attackers had free access to roam about and check out the network. They did borrow without authorization the personal information on the city’s employees and customers.

 

As the city saw the writing on the wall, the city council voted unanimously to pay the ransom. The funds were to be paid from the insurance fund available for these types of issues.

 

A curious point with this is the city required the attackers, DoppelPaymer, to provide proof they will delete the stolen information they have. The curiosity is, other than promising or a pinky-swear, there really isn’t a way to prove they will delete the data. This is one of the many problems with paying the ransom. The organization is depending on the attackers to follow through and not leave a back-door or recurring malware on the system. Historically, the attackers have followed through and have not left any surprises behind for later easier attacks. They say there is honor among thieves, however, I would not bet on it. The city naturally is also working with law enforcement in the matter.

 

Update

As of June 13, 2020 (10:46 EST), the online network was down. While the website did note an apology, no reason was given.

 

Afterthought

If you are management, SysAdmin, or on the cybersecurity team, please consider this occurrence or any of the thousands of other successful ransomware attacks as examples of why training and an adequate SIEM is so important. While cybersecurity is the focus of the cybersecurity department or team, it is still everyone’s job to be vigilant and not be click-happy. If they aren’t expecting an email, don’t know the person or organization it is from, or it simply leaves them wondering if the link or attachment is appropriate, don’t do it. This will save so much time, energy, frustration, etc. for the staff and budget.

 

Resources

Associated Press. (2020, June 11). Alabama city to pay $300,000 ransom in computer system hack. Retrieved from https://www.newsobserver.com/news/business/article243452091.html

 

Associated Press. (2020, June 12). Alabama city to pay $30,000 ransom in computer system hack. Retrieved from https://www.securityweek.com/alabama-city-pay-300000-ransom-computer-system-hack

 

Brown, M., & Delinski, B. (2020, June 11). City of Florence out nearly $300,000 after ransomware hack. Retrieved from https://www.waff.com/2020/06/11/city-florence-out-nearly-after-ransomware-hack/

 

City of Florence. (n.d.). Florence, alabama. Retrieved from https://florenceal.org/

 

Delinski, B. (2020, June 11). Florence pays nearly $300,000 in bitcoin ransom. Retrieved from https://www.timesdaily.com/news/local/florence-pays-nearly-300-000-in-bitcoin-ransom/article_5dd1200e-58f6-53a5-a3e1-5d7b90edf179.html

 

Erazo, F. (2020, June 10). Alabama city plans to pay ransomware group despite warnings. Retrieved from https://cointelegraph.com/news/alabama-city-plans-to-pay-ransomware-group-despite-warnings

 

Freedman, L. (2020, June 12). Alabama city hit with ransomware. Retrieved from https://www.jdsupra.com/legalnews/alabama-city-hit-with-ransomware-40970/

 

Goud, N. (2020, June). Ransomware attackers demanding $300,000 from florence city of alabama. Retrieved from https://www.cybersecurity-insiders.com/ransomware-attackers-demanding-300000-from-florence-city-of-alabama/

 

Jackson, J. (2020, June 10). City of Florence agrees to pay nearly $300,000 ransom after cyberattack. Retrieved from  https://whnt.com/news/shoals/city-of-florence-agrees-to-pay-nearly-300000-ransom-after-cyberattack/

 

Krebs, B. (2020, June 9). Florence, Ala. Hit by ransomware 12 days after being alerted by KrebsOnSecurity. Retrieved from https://krebsonsecurity.com/2020/06/florence-ala-hit-by-ransomware-12-days-after-being-alerted-by-krebsonsecurity/

 

Lincoln Journal Star. (2020, June 11). Alabama city to pay $300,000 ransom in computer system hack. Retrieved from https://journalstar.com/business/alabama-city-to-pay-300-000-ransom-in-computer-system-hack/article_70114db5-92bd-5ecb-9a5e-edf5f3cf3b24.html

 

Paganini, P. (2020, June 12). City of Florence to pay $300,000 ransom after ransomware attack. Retrieved from  https://securityaffairs.co/wordpress/104666/breaking-news/city-of-florence-ransomware.html

 

SANS. (2020, June 12). Newsletters: Newsbites. Retrieved from https://www.sans.org/newsletters/newsbites/xxii/47

 

Schwartz, M.J. (2020, June 12). City pays ransom despite pre-ransomware outbreak hack alert. Retrieved from https://www.bankinfosecurity.com/city-pays-ransom-despite-pre-ransomware-outbreak-hack-alert-a-14427

 

 

 


Wednesday, June 10, 2020

This doesn’t add up: Chartered Professional Accountants Canada Breached!

With most industries, there is a trade association or group. The focus with these is to bring together leaders and members to discuss issues, communicate messages to the membership and be a portal for the industry. Accounting is no different. In the US, we have the AICPA which functions to administer these tasks. This is accomplished is a timely, exceptionally professional manner. Canada is no different in that the accounting industry likewise has this for our northern friends. Another commonality is these are generally targets due to the data they hold for their clients. The Chartered Professional Accountants Canada (CPA Canada) recently found this out, as they were breached.

CPA Canada

Just as the name implies, the organization is involved with Canadian accountants, representing the over 210k members. The organization provides accounting and guidance for its membership. This service is vital for business, accounting firms, and the stock market.

 

Attack

 The organization was unfortunately the victim of a successful phishing attack. The organization on June 3, 2020 notified the affected parties of the breach. Curiously, the organization was aware of the attack on April 24th, meaning it took over a month to notify the persons. The organization will not be disclosing the methodology used in the attack. On a level, this is understandable. The organization may not want the details published as these may be used in other attacks as indications of their security posture. After the issue is corrected though, this could be used as a learning tool or use case for others.

 

Data

CPA Canada definitely held useful information for the attackers to focus on. This included the member's personal information. This included their contact details (names, addresses, email addresses, and employer name). The passwords and credit card numbers, fortunately, were encrypted. The list of persons was primarily composed of the CPA Magazine subscribers. This wasn’t just on the members, but also the stakeholders, totaling over 329k persons.  Granted the data involved was confidential. However, this could have been much worse if the other data was not encrypted, or if the attackers were able to pivot from this point and gain access elsewhere.

 

Post-Breach

The organization has notified its members and others whose data was affected, of the breach. The members and stakeholders were recommended to change their passwords. The organization is also working with cybersecurity personnel to verify the system is secure and exactly what data was copied from them. In addition, they naturally also contact the appropriate law enforcement, the Canadian Anti-Fraud Centre, and other privacy authorities.

 

One point from this to be used is phishing continues to and will be for the foreseeable future, an absolutely viable attack. This has proven to be successful and will not slow down. The organizations need to continue training for this with their employees. The system may be completely secure, however, all it takes is the right person in the right department to click the link, attachment, etc., and we are off to the races.

 

References

Solomon, H. (2020, June 4). Canadian accounting association website gets hacked. Retrieved from https://www.itworldcanada.com/article/canadian-accounting-association-website-gets-hacked/431712

 

Solomon, H. (2020, June 8). Canadian accounting association website gets hacked. Retrieved from https://business.financialpost.com/technology/tech-news/canadian-accounting-association-website-gets-hacked

 

The Canadian Press. (2020, June 4). Canadian accountants’ association suffers cyberattack; data of nearly 330k affected. Retrieved from https://globalnews.ca/news/7025862/cpa-canada-accountants-cyberattack/

 

The IJ Staff. (2020, June 4). CPA Canada hacked, subscriber information exposed. Retrieved from https://insurance-portal.ca/article/cpa-canada-hacked-subscriber-information-exposed/

 


Saturday, May 30, 2020

Sberbank Breached



Banks are located throughout the world. They perform vital services for consumers and commercial organizations in every country they are located in. These are also connected with the respective nation’s banking systems. Another commonality is these hold a mass amount of data also. This is very attractive to the attackers for many reasons. This is also a concern for the consumers, as their personally identifiable information (PII) is in the hands of unauthorized persons. Sberbank is was targeted and data removed without their authorization. Sberbank is Russia’s largest bank, with 45% of all retail deposits within their bank and 41% of the consumer loans held. In this instance, the Russian state owns the controlling stake in the bank.
Attack
Obviously, the attack was successful, which is a problem. The organization estimates the breach occurred near the end of August 2019.  The cause of this breach is unfortunately somewhat common, in the US and abroad. With employees, there is always the chance of the internal threat with the disgruntled, greedy, or unhappy employee. In this case, the bank is reporting the breach of data was due to an employee’s intentional acts. The bank noted it has to be an internal employee due to the data’s location being impossible to breach.

Later, the speculation ended when the bank reported the attacker had been apprehended. During the investigation, the employee had been focused on and eventually confessed. The employee was the head of one of the bank’s divisions. As part of their role, they had access to databases as part of their position, which explains how this was exfiltrated given the data’s remote location and access.
Data
With the attack, millions of Sberbank’s customer's personal data was allegedly initially leaked. Fortunately for the affected persons, the target was the data. The funds in the affected person’s account(s) were not targeted. The bank initially estimated 60M Sberbank credit cardholders have had their personal data stolen and was for sale on the dark web. This estimate appears to have been a bit inflated, and the true number was far less, possibly as low as 5k. The last reported sales price per entry at $0.08/record.

Surprisingly, the data leak and data for sale was not noticed by the bank. For instance, even if the amount of data was the 5k of records, seemingly this would have triggered some form of an alarm. After all, even a division manager probably would not have a need to download 5k individual records. Their position would be more engaged with summaries and forward-looking goals. This oversight was noticed by DeviceLock Cybersecurity, a cybersecurity organization when they noticed the data for sale on the dark web. At times, the seller may make fantastic claims of the data composition for sale. In this case, however, a sample of 200 credit card holder’s data was verified, indicating this is real. The data liberated in this case included the credit card details excluding the three-digit CVV, and place of employment for the last ten years. While the affected persons do have a bit of good news with the CVV not being a part of this, they may still have been targeted for fraud due to the nature of the data itself.
Follow-Through
After the bank was notified, they contacted reported this and is working closely with law enforcement and the Central Bank of Russia to find the culprits. As noted, this was beneficial as the

Resources
Auyezov, O., & Lyrchikova, A. (2019, October 3). Russia’s sberbank investigating potential client data leak. Retrieved from https://www.reuters.com/article/us-sberbank-russia-dataprotection/russias-sberbank-investigating-potential-client-data-leak-idUSKBIN1@i0Wl

Hinchliffe, R. (2019, October 9). Russia’s sberbank catches internal culprit of data leak. Retrieved from https://www.fintechfutures.com/author/hinchliffer/

Leprince-Ringuet, D. (2019, October 4). Russia’s sberbank investigates credit card data leak. Retrieved from https://www.zdnet.com/article/russieas-sberbank-investigates-credit-card-data-leak

Ljubas, Z. (2019, October 19). Russia: Huge data leak hits sberbank. Retrieved from https://www.occrp.org/en/daily/10797-russia-huge-data-leak-hits-sberbank

PMNTS. (2019, October 4). Russia’s sberbank investigating potential client data leak. Retrieved from https://www.pymnts.com/news/security-and-risk/2019/russias-sberbank-investigating-cleint-data-leak/

Spadafora, A. (2019, October 3). Russia’s sberbank hit with huge data leak. Retrieved from https://www.techradar.com/news/russias-sberbank-hit-with-huge-data-leak
The Moscow Times. (2019, October 3). Sberbank hit by huge data breach. Retrieved from https://www.themoscowtimes.com/2019/10/03/sberbank-hit-by-huge-data-breach-a67570

The Moscow Times. (2019, October 3). Sberbank hit by huge data breach. Retrieved from https://www.wedn.com/2019/10/03/sberbank-hit-by-huge-data-breach/

Walker, J. (2019, October 8). Sberbank of Russia completes investigation into the dark web data leak. Retrieved from https://portswigger.net/daily-swig/sberbank-of-russia-completes-investigation-into-dark-web-data-leak  

Thursday, May 28, 2020

Spartans compromised: MSU breached


Michigan State University (MSU), located in East Lansing, Michigan, is one of the premier institutions in the Midwest. This is a 5,300-acre campus with 563 buildings, with nearly 20,000 cares throughout Michigan used for agricultural and natural resources research and education. In Fall 2019, there were 49,809 students. With such a large number of students, the amount of data generated by the students and administration staff is massive year after year. This data, including the confidential data from the students, provided a significant target for the attackers. This proved to draw these persons to the University’s servers and data.

Attack
Ransomware has been a nasty part of our environment from the last few years. This is a good attack tool due to its low operational overhead and potential large payoff. With this mode, it simply takes the right person in the right department to click on the malware or link. Unfortunately for MSU, the tool was used against the university successfully. The attackers were able to breach the network, access the targeted data, and exfiltrate this. The attackers have demanded a ransom to be paid within a week of the successful attack or they will publish the stolen files. If the university happens not to pay the ransom, the attackers are willing to leak the documents.

Data
The university believes, but is not certain, that the breach and subsequent intrusion was to one (1) isolated unit on the campus. While this is a good thing, the breach itself is still an issue. The files included student, e.g. passport scans, and other private, confidential data, along with university financial documents.

Attackers
The attackers apparently used Netwalker, sometimes referred to as Mailto, ransomware. The ransomware variant was coded to attack the enterprise, in comparison to individual user stations. With this ransomware variant, once the clock runs down to zero, the data and the decrypt key are automatically published.

Mitigation

This is a rather significant issue. There is a prominent university pwned, and their data is being held for ransom. After this was detected, the IT Department took offline the affected systems and servers. This was done to prevent further exposure. MSU’s IT Department notified law enforcement, including the MSU Police Department and Michigan State Police, of the successful attack and threats to begin the investigation.

The latest successful attack is yet another clear indication that we need more cybersecurity training that is relevant. Without this, these attacks will continue to be successful and cause an abundance of harm to the organization, staff, and other parties as part of the collateral damage.

Resources
Cimpanu, C. (2020, May 28). Michigan state university hit by ransomware gang. Retrieved from https://www.zdnet.com/article/michigan-state-university-hit-by-ransomware-gang/

Dissent. (2020, May 28). Michigan state hit by ransomware threatening leak of student and financial data. Retrieved from https://www.databreaches.net/michigan-state-hit-by-ransomware-threatening-leak-of-student-and-financial-data/

Freed, B. (2020, May 27). Michigan state hit by ransomware threatening leak of student and financial data. Retrieved from https://edscoop.com/michigan-state-hit-by-ransomware-threatening-leak-of-student-and-financial-data/

Guzman, W. (2020, May 28). Michigan state target of ransomware attack threatening to release university data. Retrieved from https://statenews.com/article/2020/05/michigan-state-target-of-ransomware-attack-threatening-to-release-university-data?ct=content_open&cv=cbox_latest

Marowski, S. (2020, May 28). Ransomware attack threatens to release stolen Michigan state university files. Retrieved from https://www.mlive.com/news/jackson/2020/05/ransomware-attack-threatens-to-release-stolen-michigan-state-university-files.html

Michigan State University. (n.d.). MSU facts. Retrieved from https://msu.edu/about/thisismsu/facts.php

Tuesday, May 26, 2020

Home Chef’s customer data for sale: Come and get it!



Home Chef, a US-based company, is a meal kit delivery service. If you don’t have time to go to the grocery store and am looking for healthy meals, you can contract with them for meal deliveries to your home. The ingredients show up in a box and you are ready to go! While not an overly complex process, this is still pertinent.

Data Breach
As part of the service, you would pay for the deliveries with your credit card. The company isn’t going to ship your food and hope you pay the bill. The organization does collect certain data from its clients to facilitate this, which is part of the standard operating procedure. Nearly all companies follow this model.  

In this case, there was a successful attack. The compromised customer information included the customer’s name, email address, phone number, and last four digits of the credit card numbers. This would be a much bigger issue; however, the Home Chef does not retain full credit card numbers. In addition, the encrypted passwords and certain account details (e.g. frequency of deliveries and mailing addresses) were also compromised.

Home Chef has not stated how many customers were affected. As a clue to the general number, the attackers responsible for this, Shiny Hunters, claim to be selling approximately 8M records. The price of this database was $2,500. Given the number of records and the data for each record, this is not that bad of a deal. To authenticate, Shiny Hunters also provided a sample.

The attack itself also is a bit of a mystery. The company is not stating this occurred, which is unfortunate. We could use this information as a learning tool. Curiously, Home Chef did not know this had occurred, which is a bit strange as the SIEM should have picked up a bit of unusual activity since, you know, a few records (8M) were compromised and exfiltrated. Home Chef learned of this after they discovered the records were being sold on the dark web. Oops. The InfoSec group probably should have picked up on this. It is also notable, in order to complete this compromise, there would need to be a bit of time involved. It is likely the attackers had access to the systems and data for an extended period as they completed their attack.

Mitigation
Naturally, when this occurs, there is a lot of activity very quickly. The company did state they were taking quick and aggressive actions to investigate the breach.

Follow-Up
Too frequently, companies are not overly aggressive in their timeline to contact law enforcement. Home Chef on the other hand handled this efficiently. And contacted them quickly. The company did email the affected customers, which was done quicker than other firms in like circumstances, which is a good thing. The company is also is recommending the customers change their passwords out of an abundance of caution. Remember, the passwords were encrypted, however, the company may have used weak encryption, which would be a problem.  If these were to be decrypted, there would be a big problem for the customers. This is a good idea also due to the potential for credential stuffing, or the attackers using your password to try access for other accounts. If the users did use the same password across several domains these also should be changed. The customers should also use MFA (multi-factor authentication) moving forward as an additional feature.

Resources
Abrams, L. (2020, May 20). Home chef announces data breach after hacker sells 8M user records. Retrieved from https://www.bleepingcomputer.com/news/security/home-chef-announces-data-breach-after-hacker-sells-8m-user-records/

GearBrain Editorial Team. (2020, May 21). Data breach weekly security report: Which company lost control of your information this week. Retrieved from https://www.gearbrain.com/data-breach-cybersecurity-latest-hacks-2633724298.html

Home Chef Help Center. (2020). Home chef data security incident. Retrieved from https://support.homechef.com/hc/en-us/sections/360008878052-Home-Chef-Data-Security-Incident

Mihalcik, C. (2020, May 20). Home chef confirms data breach after customer info reportedly sold on dark web. Retrieved from https://www.cnet.com/news/home-chef-confirms-data-breach-after-customer-info-reportedly-sold-on-dark-web/

S, G. (2020, May 21). Home chef hacked-Hackers selling 8M user records on a dark web marketplace. Retrieved from https://gbhackers.com/home-chef-hacked/

Whitney, L. (2020, May 21). How home chef’s sensitive data was compromised by a cyberattack. Retrieved from https://www.techrepublic.com/article/how-home-chefs-sensitive-customer-data-was-compromised-by-a-cyberattack/