Sunday, July 26, 2020

BMW breached

Attackers are always looking for new targets rich with data. One industry frequently targeted has been the auto manufacturers. This may take the form of patent information, technology secrets, mechanical solutions, corporate secrets, intellectual property, schematics, new systems, or other personally identifiable information. Nearly all of this is marketable on the dark web and for industrial espionage.

Targets

The number of attacks continues to grow with each month, quarter, and year. In recent history, there have been successful attacks on the OEMs. These entities hold a mass amount of data on their operations, projections, and corporate confidential data. One recent notable attack was on Toyota in Australia.  

Attackers

The attack was perpetrated allegedly by APT32, the Vietnamese group with ties to the Vietnamese government. The group is also known as Ocean Lotus. They have been operating since at least 2014. This group is responsible for the subject BMW breach, and they have been active with other recent attacks including Hyundai.

Breach

With an attack on a large enterprise, distinguishing when the attack actually took place or was initiated may not be as simple as it may seem. With the breach, a branch of BMW had its network compromised sometime in the spring of 2019. In this instance, BMW did detect the breach. The management did allow the attackers to maintain their presence. While this seems counter-intuitive, there was a rationale for this. They wanted to follow their actions to gauge how far the attackers were able to penetrate into the network. BMW did remove their access once they were able to understand the attack and the extent in November 2019.

Method

Breaching a system for a global manufacturer may not be an easy task. In this case, the attackers used an indirect method, versus attacking the network head-on. The attacker’s set-up a website that appeared to be for the BMW branch in Thailand. Curiously, the same method was used successfully with Hyundai. Once connecting, Cobalt Strike infected the hosts. This is a legitimate cybersecurity assessment tool. This is used to perform assessment and penetration tests. For this use case, the tools showed any misconfigurations and vulnerabilities not patched. This allowed the attackers to gain further access into the network, monitor and control systems, gaining login credentials, and increasing the infected areas. They also installed a backdoor into the breached network, which was how they were detected.

Data

BMW noted no sensitive data was access by the attackers, which is positive.

In closing…

This successful attack shows the importance of working with the staff. The staff needs to understand how important cybersecurity is and how it is everyone’s responsibility. This isn’t to be addressed once a year with the mandatory training. The training should reinforce the issues with websites and what can happen when the wrong website is visited. Attention detail is important.

 

Resources

Cimpanu, C. (2019, December 6). BMW and Hyundai hacked by Vietnamese hackers, report claims. Retrieved from https://www.zdnet.com/article/bmw-and-hyundai-hacked-by-vietnamese-hackers-report-claims/

EHacking News. (2019, December 7). BMW and Hyundai networks compromised by Vietnamese hackers. Retrieved from https://www.ehackingnews.com/2019/12/bmw-and-hyundai-networks-compromised-by.html

Gatlan, S. (2019, December 6). BMW infiltrated by hackers hunting for automotive trade secrets. Retrieved from https://www.bleepingcomputer.com/news/security/bmw-infiltrated-by-hackers-hunting-for-automotive-trade-secrets/

NewtonBaba. (2019, December 7). BMW & Hyundai hacked by Vietnamese hackers-Report. Retrieved from https://www.newtonbaba.com/bmw-hyundai-hacked

Paganini, P. (2019, December 7). Alleged Vietnamese ocean lotus (APT32) hackers breached the networks of the car manufacturers BMW and hyundai to steal trade secrets. Retrieved from https://securityaffairs.co/wordpress/94805/hacking/ocean-lotus-hacked-BMW-hyundai.html

Toulas, B. (2019, December 7). Vietnamese hackers “APT32” hacked Hyundai and BMW. Retrieved from https://www.technadu.com/vietnamese-hackers-apt32-hacked-hyundai-bmw/86959/

 


Tuesday, July 21, 2020

Here we go again: Jackpotting ATMs

 

Everyone loves money. This allows us a certain level of freedom for the items we use, where we would like to travel, gifts to our friends, and a level of comfort for the future. They say cash is king, and certainly, during this time period, it has tended to be. One piece of equipment that holds a mass amount of cash is the ATM. People have dreamed of simply walking by and money flying out at them. As bizarre as this sounds, these attacks have been part of the proof-of-concept since at least 2010. The history lesson begins with Black Hat in 2010. Barnaby Jack’s presentation showed two different methods to the jackpot, or direct the ATM to spew out the bills it contained. One of the attacks was done over the internet and the other required hardware access through the front of the machine. The audience was naturally excessively impressed by his expertise. At the time he was the Director of Security Research at IOActive Labs. Over the years, the research continued and other methods to jackpot the ATMs were found and published.

The new attack is focused on the Diebold Nixdorf machines. Diebold Nixdorf made $3.3B from ATM sales and the associated service plans in 2019. This is one of the favored and notable manufacturers for ATM machines.

New Attack

Well, there is a new ATM attack in town. This does not work on all ATMs. The attackers have been using the new method against Diebold’s ProCash 2050xe USB terminals. The newly published attack utilizes a black box applying proprietary code to the attack surface in the ATM. The code is from the ATM manufacturer (Diebold). The attackers have to connect the black box to the ATM to complete the attack. This is done through unlocking the ATM chassis, drilling holes into the chassis at selected points, or otherwise physically bypassing the physical security. At this point, the attacker would plug their patch cord into the CMD-V4 dispenser in the place of the cord already plugged in. At this point, the ATM pwned as the attacker issues the malicious dispense commands.

The end result is for the cash to flow from the machine to the attackers, who are not authorized to receive the money. Depending on the inventory held in the ATM, this could be as many as 40 bills every 23 seconds or $800/23 seconds if the machine only holds $20’s.

From what is known, the attacks appear to use a portion of the ATM software stack. It isn’t known for certain how the attackers were able to gain access to the code, as the software is proprietary and anyone isn’t able to simply goto Dr. Google and download it. They may have, however, gained the requisite information from an unencrypted hard drive that was unaccounted for.

PoC or not?

By noting an attack is workable and potentially viable is one thing. To show this and also show where this has been done outside of the lab in the real world is another issue completely. In this case, this attack has been used across Europe.

Mitigations

All is not lost and there does not need to be a 24-hour security guard at these specifically affected machines. Diebold has provided mitigations for this and urgently recommended their customers verify if these were in place yet. These include using the firmware version 2011 or later for CMD V4, enabling the firmware fuse, secure encryption handling, enhanced keystore format, 3DES encryption, and verify this encryption is active and verify this is actually being done. The document from Diebold is very helpful in the implementation.

Potential

Yes, indeed this is a viable attack and not just a lab exercise. This, however, would need to be done is a very limited scope of potential events. After all, if one of these was in the mall, someone isn’t going to waltz up at noon on a Saturday and gingerly pry open the front of the ATM and hope no one notices or calls law enforcement, or better yet drill through the aluminum plating several times and thread a patch cord through a hole. There is always the key to unlock the ATM, however, this would probably appear a bit fishy also as the attackers plug in the cord to the machine. If the machine were to be outside, perhaps the attack could be done in the darkness. The issue with this is there are cameras everywhere in the environment. The attackers probably would be recorded, and they also run the risk of law enforcement stopping by.

It is also notable that the black box does not need to be a 13-inch monitor laptop. This could be built with an Arduino or Raspberry Pi. The housing for these is also very small comparatively. While this would indeed appear a little odd to the shoppers in our scenario or others, the hardware is easily hiding and manipulated.

 

Resources

Diebold Nixdorf. (2020, July 15). 020-27/0003-Jackpotting with black box in Europe. Retrieved from https://dd80b675424c132b90b3-e48385e382d2e5d17821a5e1d8e4c86b.ssl.cf1.rackcdn.com/external/diebold-nixdorf-security-alert-2.pdf

Diebold Nixdorf. (n.d.). Cyber attacks are on the rise. Find out how you can protect your network comprehensively. Retrieved from https://www.dieboldnixdorf.com/-/media/diebold/files/banking/insights/brochures/dn_brochure_security-jackpotting-overview_fa_20181005.pdf

Goodin, D. (2020, July 20). Crooks have acquired proprietary diebold software to “jackpot” ATMs. Retrieved from https://arstechnica.com/information-technology/2020/07/crooks-are-using-a-new-way-to-jackpot-atms-made-by-diebold/

ThreatPost. (2020, July 21). Diebold ATM terminals jackpotted using machine’s own software. Retrieved from https://www.newsbreak.com/news/1604274576845/diebold-atm-terminals-jackpotted-using-machines-own-software and https://www.thetechstreetnow.com/tech/diebold-atm-terminals-jackpotted-using-machines-own-software/1305153191397515153/1305153191397515153/ and https://threatpost.com/diebold-atm-terminals-jackpotted-using-machines-own-software/157575/

Zetter, K. (2010, July 20). Researcher demonstrates ATM ‘jackpotting’ at black hat conference. Retrieved from https://www.wired.com/2010/07/atms-jackpotted/

 


Friday, July 17, 2020

If someone has to tell you of your compromise...

Marketing has changed over the years. In the last decade or so, this has transitioned from the prior print, radio, and television media to digital media. While these have the same goal, the media itself has changed. The persons involved with this, social influencers, aren’t just taking selfies, but have made this into a business for themselves. One firm embracing this is Preen.Me, based in Tel Aviv. The firm is a next-generation marketing platform. A bi-product of this involves cybersecurity and attacks, which they found out the hard way.

Attack

This is an odd situation. Yes, there was a breach and the data and information were exfiltrated. This is documented via the sample provided. Generally, when this happens, the situation demands everyone relevant to get involved to investigate it. There may also be third parties involved with this to fully review the attack, methods, and other aspects. At least through the three weeks after the organization learned of the breach, they still have not announced anything with this attack. The publication of the attack methods and post-breach remediation will probably not be announced either. It’s interesting the organization did not know they had been breached. With the third party letting them know, seemingly, the cybersecurity department would be really working intensely on this to find the root of the issue. 

Discovery

As a rule of thumb, the organization should generally be aware when they have been breached. The cybersecurity area should be there to review the logs, alerts, and other red flags indicating there has been a problem. When the organization has no idea, this infers there is some form of a systemic problem. In this case Preen.Me was notified by Risk Based Security of the issue. Risk Based Security discovered the compromise on June 6, 2020, when the attacker revealed they had successfully attacked Preen.Me’s system and exfiltrated the data. To document this, 250 of these records were posted to PasteBin on June 6th.  

Data

While this was not the largest breach, the number of those affected is still significant. In this case, approximately 100,000 social media influencers had their personal information accessed by an unauthorized third party. While this was detrimental, this breach also led to another 250,000 social media users have their information likewise on a dark web site. The data itself consists of the social media influencer’s links to their individual social media accounts, email addresses, names, phone numbers, and home addresses.

Effects

While merely having the data in the dark web for anyone to view is not the optimal scenario, there is another use of this for the attackers. The data, curiously, may also be used for scamming the persons involved. This does not appear, from the published accounts, to have confidential data stolen that the attackers could sell rapidly (e.g. social security numbers). The hope is the company does provide an announcement and do something for the affected persons.

 

Resources

Coker, J. (2020, June 25). 350,000 social media influencers and users at risk following data breach. Retrieved from https://www.infosecurity-magazine.com/news/data-breach-social-media/

Dissent. (2020, June 25). Personal data of 350,000+ social media influencers and users compromised following preen.me hack. Retrieved from https://www.databreaches.net/personal-data-of-350000-social-media-influencers-and-users-compromised-following-preen-me-hack/

Duran. (2020, June 29). The personal data of 350,000 social media influencers and users is at risk after a preen.me data breach. Retrieved from https://www.cyclonis.com/personal-data-of-350000-social-media-influencers-users-at-risk-after-preen-me-data-breach/

RBS. (2020, June 24). Personal data of 350,000+ social media influencers and users compromised following preen.me hack. Retrieved from https://www.riskbasedsecurity.com/2020/06/24/personal-data-of-350000-social-media-influencers-and-users-compromised-following-preen-me-hack/

Security Experts. (2020, June 26). Experts on 350,000 social media influencers and users at risk following data breach. Retrieved from https://www.informationsecuritybuzz.com/expert-comments/experts-on-350000-social-media-influencers-and-users-at-risk-following-data-breach/


Friday, July 3, 2020

Maine State Police database pwned


Each municipality and state has some form of a police presence. Maine is no different. The police departments hold an immense amount of data on past crimes, current investigations, and other issues.

 

Target

The database was used for information sharing for federal, state, and local law enforcement. The database breach may have jeopardized ongoing investigations. The database, in the Maine Information and Analysis Center (MAIC), is intended to assist with protecting against terrorism and other significant crimes. The database mostly holds information on criminal offenses and bulletins. The bulletins often contain identifying information, such as full name and date of birth under an investigation. This allows regional law enforcement to share data and collaborate to solve crimes.

 

Attack

The state police were notified on June 20, 2020, by Netsential of the data breach. This may have included certain information from Maine Information and Analysis Center (MAIC). Netsential has been contracted by the state police since 2017. The company provides web hosting services to hundreds of law enforcement and government agencies across the country. The attack vector and method(s) used have not been published. This is unfortunate, as this could be a learning experience for others.

 

Post-Breach

The state police contacted the FBI’s Houston Field Office to investigate and determine the extent of the data breach. While the details are scant, this serves as another example of why an organization needs to have an incident response plan in place. While affected a database, it could have been much larger and devastating.

 

 

Resources

Associated Press. (2020, June 27). Security breach impacts maine state police database. Retrieved from https://www.boston.com/news/local-news/2020/06/27/security-breach-impacts-maine-state-police-database

Boston Globe. (2020, June 28). Security breach impacts maine state police database. Retrieved from https://www.newsbreak.com/maine/augusta/news/0PSSTMTZ/security-breach-impacts-maine-state-police-database

Caledonian Record. (2020, June 28). Security breach impacts state police database. Retrieved from https://www.caledonianrecord.com/news/regional/security-breach-impacts-state-police-database/article_868571e7-55ca-5514-99da-fc012f15b021.html

Coleman, M. (2020, June 27). Security breach impacts maine state police database. Retrieved from https://upnewsinfo.com/2020/06/27/security-breach-impacts-maine-state-police-database/

England, K. (2020, June 26). Main state police statement on third-party data breach involving the maine information and analysis center (MIAC). Retrieved from https://www.maine.gov/dps/msp/media-center/public-releases/maine-state-police-statement-third-party-data-breach-involving-maine

WGAN. (2020, June 29). Security breach impacts maine state police database. Retrieved from https://wgan.com/news/074470-security-breach-impacts-maine-state-police-database/


Friday, June 26, 2020

Did I do that? Twitter data leakage

We have all heard of and probably use Twitter. Everyone recognizes the corporate logo and symbol. While there have been other social media outlets, Twitter has stayed the course and continues to be a social media giant.

Breach

Recently, Twitter had an issue with a breach, aka “data security incident” in corporate speak. The problem was detected by Twitter on May 20, 2020.

Affected Users

This did not affect all of the users, which would have been a disaster and epic fail. This only affected the business users who paid for advertisements on the platform, using Twitter Ads and Analytics Manager.

Data

The data involved was not critical, however, it should not have been leaked. This included the business user’s email address, billing address, phone numbers, and the last four digits of their credit card numbers. This could have been much worse for the clients if more of the information, including full credit card numbers, would have been included. What further limits the issue is the attacker would require access to the user’s browser to steal this information. This would have to occur one user at a time with the attacker physically sitting at each machine. With the full method to retrieve the data, this attack, while an issue, is practical in very limited circumstances. If retrieving the data was much easier on a grander scale and more confidential information was available, the story would be totally different.

How?

In this day and age of continued data loss, seemingly there would be a data leakage program in place to check systems, configurations, and just about everything else to ensure, as much as you can, that this does not happen. Unfortunately, there was an issue. If the business were to check their billing information on ads.twitter.com or analytics.twitter.com, which would not be that unusual, the data was stored in the browser’s cache. While this is not the end of the world for the affected parties, it should probably be treated as more of a teachable learning experience. The future employees know not to allow this, and this provides a real-life example of what can happen if you let this go.

Remediation

Clearly, this is a problem. Once Twitter detected the issue, they did resolve it. Twitter needed to update their headers to set to no-store and no-cache. This would in effect disable the data from being stored locally at the machine. One issue with this, other than the configuration allowed this, was the timing. This was detected by Twitter on May 20, 2020. This was not reported to the users for more than a month. While the data leakage issue was limited, as noted, this really should have not taken a month to resolve to notify the affected parties.  

 

Resources

Adhikari, R. (2020, June 24). Twitter apologizes for data security incident. Retrieved from https://www.technewsworld.com/story/86726.html

Admin1. (2020, June 26). Twitter suffered a major data breach-but this is why you’re probably safe. Retrieved from https://marijuanapy.com/twitter-suffered-a-major-data-breach-but-this-is-why-youre-probably-safe/

Financial Press. (2020, June 25). Twitter hack: Social media giant suffers ‘huge’ billing information data breach. Retrieved from https://financial-press.uk/2020/06/23/twitter-hack-social-media-giant-suffers-huge-billing-information-data-breach-world-news/

Ians. (2020, June 24). Twitter sorry for data breach involving business clients. Retrieved from https://kalingatv.com/technology/twitter-sorry-for-data-breach-involving-business-clients/

Jay, J. (2020, June 23). Twitter says business users’ data leaked in security fiasco. Retrieved from https://www.teiss.co.uk/twitter-says-business-users-data-leaked-in-security-fiasco/

McLoughlin, B. (2020, June 23). Twitter hack: Social media giant suffers ‘huge’ billing information data breach. Retrieved from https://www.express.co.uk/news/world/1299728/Twitter-data-breach-hack-latest-billing-information-twitter-business-update-twitter-search

McLoughlin, B., & Wilson, R. (2020, June 23). Twitter businesses’ billing information is hacked in data breach. Retrieved from https://www.examinerlive.co.uk/news/uk-world-news/twitter-businesses-billing-information-hacked-18471270

Riley, D. (2020, June 23). Twitter apologizes after exposing business customer information. Retrieved from https://siliconangle.com/2020/06/23/twitter-apologizes-exposing-business-customer-information/

Security Experts. (2020, June 24). Twitter suffers billing information data breach. Retrieved from https://www.informationsecuritybuzz.com/expert-comments/comment-twitter-suffers-billing-information-data-breach/

Sharma, A. (2020, June 24). Twitter discloses billing info leak after ‘data security incident’. Retrieved from https://news.knowledia.com/IN/en/articles/twitter-discloses-billing-info-leak-after-data-security-incident-1dc82af759dc4c7451ea428b26c622dc5f438e6e

Techradar.com (2020, June 26). Twitter suffered a major data breach-but this is why you’re probably safe. Retrieved from https://www.thetechstreetnow.com/tech/twitter-suffered-a-major-data-breach--but-this-is-why-youre-probably-safe/10326781581085137573/10326781581085137573/

Sunday, June 14, 2020

Municipalities targeted: City of Florence pwned!


Municipalities have a very distinct problem. They are frequently targeted for ransomware and other attacks, as the attackers know their systems generally are not fully secure unless they been recently successfully attacked and have corrected and mitigated the issues. This is driven by budgetary constraints, not allowing the city, county, etc. to be able to hire exceptional talent, purchase the tools needed in a timely manner, and other requisite uses for cybersecurity. While this is a Catch-22, it leaves these organizations in the wind, hoping to be obscure enough so that they are not noticed and attacked. Even a failed attack can have negative effects on the operations for many reasons.

 

One of these targeted was the city of Florence, located in Alabama. Florence, much like the city in Italy, sounds like an amazing place to live, located on the banks of the Tennessee River with many festivals and other attractions. This is not a massive metropolis, with nearly 40k residents. Of all the places to target, you have to wonder why Florence?

 

Attack

As you can guess, the city’s computer system had been successfully attacked. The entry points were through the email system. Specifically, this was a phishing attack, and the unfortunate phishee was Steve Price, the IT Manager. His credentials were acquired as part of the attack. The phishing email was one of the many samples of the DHL email, where there are dozens of email recipients, all receiving the same package with the same tracking number on the same day. These emails are pretty obvious as to what they really are there for.

 

The illustrious, yet distinguished Brian Krebs notified the mayor’s office of their system’s compromise on May 26. From the published accounts, the city somehow did not know of the breach prior to this. This is odd, as seemingly someone in the IT Department maybe should have noticed a strange IP address accessing the system and pulling data from the network. The following day the System Administrator did contact Mr. Krebs to let him know the computer and network account affected has been isolated and is not in service. It appears the SysAdmin did not quite understand the capabilities of the attackers at this point. On June 5, 2020, the attackers finished deploying the ransomware and began their demand for the ransom payment. The city has 12 days to fully defend against the attack, however, unfortunately only did a part of the work required to address the issue.

 

When the city began to review the situation, it did not appear any of the affected system’s data had been deleted or exfiltrated. This was probably a little too optimistic for the city.

 

On a side note, the attack occurred while the IT department was attempting to have the City Council approved the expense for a third party to do a penetration test of the IT systems.

 

Ransom

The attackers are not going to work through the attack cycle for practice and their mental gymnastics in an attack. The system has been operationalized into a business, and a rather profitable one measured by the return on investment (ROI). In this case, the attackers were DoppelPaymer. The attackers have demanded the ransom $378k in bitcoin. The amount was negotiated down to $330k by a third-party firm, still in bitcoin. This does seem like a rather large sum, given the size of the city. The attackers, however, have realized the power of their leverage on the systems.

 

Post-Attack

Once the city had the opportunity for a quick review, the city’s IT department and a third-party, contracted by the city (Arete Advisors), began to adequately investigate the issue. As time had passed and more effort was placed into the investigation, the city realized the attackers may have at least a portion of the data on the affected systems. The city noted they just don’t know. One would presume they had sufficient access, such that if they wanted, they could have taken the data they wanted to. On this note, the investigation noted the attackers had access beginning in early May 2020 and continued this for nearly the remainder of the month. During this time, the attackers had free access to roam about and check out the network. They did borrow without authorization the personal information on the city’s employees and customers.

 

As the city saw the writing on the wall, the city council voted unanimously to pay the ransom. The funds were to be paid from the insurance fund available for these types of issues.

 

A curious point with this is the city required the attackers, DoppelPaymer, to provide proof they will delete the stolen information they have. The curiosity is, other than promising or a pinky-swear, there really isn’t a way to prove they will delete the data. This is one of the many problems with paying the ransom. The organization is depending on the attackers to follow through and not leave a back-door or recurring malware on the system. Historically, the attackers have followed through and have not left any surprises behind for later easier attacks. They say there is honor among thieves, however, I would not bet on it. The city naturally is also working with law enforcement in the matter.

 

Update

As of June 13, 2020 (10:46 EST), the online network was down. While the website did note an apology, no reason was given.

 

Afterthought

If you are management, SysAdmin, or on the cybersecurity team, please consider this occurrence or any of the thousands of other successful ransomware attacks as examples of why training and an adequate SIEM is so important. While cybersecurity is the focus of the cybersecurity department or team, it is still everyone’s job to be vigilant and not be click-happy. If they aren’t expecting an email, don’t know the person or organization it is from, or it simply leaves them wondering if the link or attachment is appropriate, don’t do it. This will save so much time, energy, frustration, etc. for the staff and budget.

 

Resources

Associated Press. (2020, June 11). Alabama city to pay $300,000 ransom in computer system hack. Retrieved from https://www.newsobserver.com/news/business/article243452091.html

 

Associated Press. (2020, June 12). Alabama city to pay $30,000 ransom in computer system hack. Retrieved from https://www.securityweek.com/alabama-city-pay-300000-ransom-computer-system-hack

 

Brown, M., & Delinski, B. (2020, June 11). City of Florence out nearly $300,000 after ransomware hack. Retrieved from https://www.waff.com/2020/06/11/city-florence-out-nearly-after-ransomware-hack/

 

City of Florence. (n.d.). Florence, alabama. Retrieved from https://florenceal.org/

 

Delinski, B. (2020, June 11). Florence pays nearly $300,000 in bitcoin ransom. Retrieved from https://www.timesdaily.com/news/local/florence-pays-nearly-300-000-in-bitcoin-ransom/article_5dd1200e-58f6-53a5-a3e1-5d7b90edf179.html

 

Erazo, F. (2020, June 10). Alabama city plans to pay ransomware group despite warnings. Retrieved from https://cointelegraph.com/news/alabama-city-plans-to-pay-ransomware-group-despite-warnings

 

Freedman, L. (2020, June 12). Alabama city hit with ransomware. Retrieved from https://www.jdsupra.com/legalnews/alabama-city-hit-with-ransomware-40970/

 

Goud, N. (2020, June). Ransomware attackers demanding $300,000 from florence city of alabama. Retrieved from https://www.cybersecurity-insiders.com/ransomware-attackers-demanding-300000-from-florence-city-of-alabama/

 

Jackson, J. (2020, June 10). City of Florence agrees to pay nearly $300,000 ransom after cyberattack. Retrieved from  https://whnt.com/news/shoals/city-of-florence-agrees-to-pay-nearly-300000-ransom-after-cyberattack/

 

Krebs, B. (2020, June 9). Florence, Ala. Hit by ransomware 12 days after being alerted by KrebsOnSecurity. Retrieved from https://krebsonsecurity.com/2020/06/florence-ala-hit-by-ransomware-12-days-after-being-alerted-by-krebsonsecurity/

 

Lincoln Journal Star. (2020, June 11). Alabama city to pay $300,000 ransom in computer system hack. Retrieved from https://journalstar.com/business/alabama-city-to-pay-300-000-ransom-in-computer-system-hack/article_70114db5-92bd-5ecb-9a5e-edf5f3cf3b24.html

 

Paganini, P. (2020, June 12). City of Florence to pay $300,000 ransom after ransomware attack. Retrieved from  https://securityaffairs.co/wordpress/104666/breaking-news/city-of-florence-ransomware.html

 

SANS. (2020, June 12). Newsletters: Newsbites. Retrieved from https://www.sans.org/newsletters/newsbites/xxii/47

 

Schwartz, M.J. (2020, June 12). City pays ransom despite pre-ransomware outbreak hack alert. Retrieved from https://www.bankinfosecurity.com/city-pays-ransom-despite-pre-ransomware-outbreak-hack-alert-a-14427

 

 

 


Wednesday, June 10, 2020

This doesn’t add up: Chartered Professional Accountants Canada Breached!

With most industries, there is a trade association or group. The focus with these is to bring together leaders and members to discuss issues, communicate messages to the membership and be a portal for the industry. Accounting is no different. In the US, we have the AICPA which functions to administer these tasks. This is accomplished is a timely, exceptionally professional manner. Canada is no different in that the accounting industry likewise has this for our northern friends. Another commonality is these are generally targets due to the data they hold for their clients. The Chartered Professional Accountants Canada (CPA Canada) recently found this out, as they were breached.

CPA Canada

Just as the name implies, the organization is involved with Canadian accountants, representing the over 210k members. The organization provides accounting and guidance for its membership. This service is vital for business, accounting firms, and the stock market.

 

Attack

 The organization was unfortunately the victim of a successful phishing attack. The organization on June 3, 2020 notified the affected parties of the breach. Curiously, the organization was aware of the attack on April 24th, meaning it took over a month to notify the persons. The organization will not be disclosing the methodology used in the attack. On a level, this is understandable. The organization may not want the details published as these may be used in other attacks as indications of their security posture. After the issue is corrected though, this could be used as a learning tool or use case for others.

 

Data

CPA Canada definitely held useful information for the attackers to focus on. This included the member's personal information. This included their contact details (names, addresses, email addresses, and employer name). The passwords and credit card numbers, fortunately, were encrypted. The list of persons was primarily composed of the CPA Magazine subscribers. This wasn’t just on the members, but also the stakeholders, totaling over 329k persons.  Granted the data involved was confidential. However, this could have been much worse if the other data was not encrypted, or if the attackers were able to pivot from this point and gain access elsewhere.

 

Post-Breach

The organization has notified its members and others whose data was affected, of the breach. The members and stakeholders were recommended to change their passwords. The organization is also working with cybersecurity personnel to verify the system is secure and exactly what data was copied from them. In addition, they naturally also contact the appropriate law enforcement, the Canadian Anti-Fraud Centre, and other privacy authorities.

 

One point from this to be used is phishing continues to and will be for the foreseeable future, an absolutely viable attack. This has proven to be successful and will not slow down. The organizations need to continue training for this with their employees. The system may be completely secure, however, all it takes is the right person in the right department to click the link, attachment, etc., and we are off to the races.

 

References

Solomon, H. (2020, June 4). Canadian accounting association website gets hacked. Retrieved from https://www.itworldcanada.com/article/canadian-accounting-association-website-gets-hacked/431712

 

Solomon, H. (2020, June 8). Canadian accounting association website gets hacked. Retrieved from https://business.financialpost.com/technology/tech-news/canadian-accounting-association-website-gets-hacked

 

The Canadian Press. (2020, June 4). Canadian accountants’ association suffers cyberattack; data of nearly 330k affected. Retrieved from https://globalnews.ca/news/7025862/cpa-canada-accountants-cyberattack/

 

The IJ Staff. (2020, June 4). CPA Canada hacked, subscriber information exposed. Retrieved from https://insurance-portal.ca/article/cpa-canada-hacked-subscriber-information-exposed/