The Week In Breach 7/15/2020 to 7/21/2020

by Wally Moore

on July 22, 2020

in Data Breach

The Week In Breach 7/15/2020 to 7/21/2020

DTS InfoTech is a hard-working Trusted Advisor for any business that has questions about computers, computer networks, and technology. One way to earn the title of Trusted Advisor is to provide FREE practical education in the technology field for visitors to our website.

Cybersecurity has become a matter of business life and death for computer and technology users of all types. With your security in mind, we are sharing Data Breach Examples in weekly posts entitled “This Week In Breach” from our friends at ID Agent.

ID Agent provides a comprehensive set of threat intelligence and identity monitoring solutions to private and public sector organizations and millions of individuals impacted by cyber incidents.

Read this short article and learn about cybersecurity and Data Breach examples from the experts in the field. The life of your business may depend upon it.

July 22nd, 2020 by Kevin Lancaster

This Week in Cybersecurity News: In cybersecurity news this week: Even tech giants have basic cybersecurity woes, third-party data breaches put every business at risk, and a webinar featuring 5 steps to success.  

Cybersecurity News: Dark Web ID’s Top Threats

  • Top Source Hits: ID Theft Forum
  • Top Compromise Type: Domain
  • Top Industry: Finance & Insurance
  • Top Employee Count: 251-500

Cybersecurity News: United States 

United States – Twitter

https://apnews.com/860daee9d51ceb588c9bd0feebddc323

Exploit: Account Compromise 

Twitter: Social Media Platform 

Severity Meter

Risk to Small Business: 1.216 = Extreme
The hack heard ‘round the world this week is a huge embarrassment for social media powerhouse Twitter, after dozens of high-profile accounts were accessed illegally and used to transmit messages inviting their followers to “invest” in a bitcoin scam. Some of the affected accounts included Bill Gates, Barack Obama, Elon Musk, and Jeff Bezos. The hack was quickly discovered, and those accounts were frozen briefly while Twitter assessed and fixed the security flaw. Twitter is now reporting that the hackers targeted 130 accounts, were able to take control of 45, and 8 accounts had data downloaded. While early reports speculated on the threat actors as a sophisticated hacking group, The New York Times uncovered that the attack was actually carried out by a few unorganized hackers using a Discord server who obtained access through a “social engineering attack”. The attack is under investigation by numerous authorities including the FBI.

Severity Meter

Individual Risk: 2.890 = Moderate
The hackers were able to obtain some personal information and change passwords for some of the celebrity accounts, but did not gain access to any financial information, past password records, or other sensitive data in all but 8 cases. Those 8 cases are still being investigated, but it’s unlikely that any sensitive data was compromised. 

Customers Impacted: 130

How it Could Affect Your Customers’ Business: A “social engineering attack” is often just a fancy way of saying “phishing attack”. Failing to protect sensitive communications and data channels for your clients because of failing to undertake basic training in phishing resistance will not only cause an expensive recovery when an attack lands, it can also be embarrassing. Plus, the potential regulatory scrutiny is bound to be a headache and give ammunition to those who are looking to add more regulation to social media platforms through future legislation.

ID Agent to the Rescue: Phishing resistance training is a must for any organization. Bolster your cdefense against phishing with BullPhish ID, featuring constantly updated training with video content for today’s biggest threats including COVID-19 threats. LEARN MORE>>

United States – BlackBaud

https://www.zdnet.com/article/cloud-provider-stopped-ransomware-attack-but-had-to-pay-ransom-demand-anyway/?&web_view=true

Exploit: Ransomware

BlackBaud: Cloud Services & Financial Technology 

Severity Meter

Risk to Small Business: 2.177 = Severe
BlackBaud admitted that its’ success in preventing a recent ransomware attack in May 2020 wasn’t quite as straightforward as it seemed. It turns out that they did pay a ransom to the hackers, but not to decrypt files. The ransom was paid to prevent the release of the stolen data in an increasingly popular double-extortion ransomware scheme. The cloud provider, which primarily works with non-profits, foundations, educational charities, and healthcare organizations, said the incident only impacted the data of only a small subset of its customers, which they have now notified. 

Severity Meter

Individual Risk: 2.797 = Moderate
According to BlackBaud’s statement about the incident,  no credit card information, bank account information, or Social Security numbers were stolen.  

Customers Impacted: Unknown

How it Could Affect Your Customers’ Business Ransomware is the bane of every company in today’s threat environment. Improved security awareness training, especially around phishing threats, is the best way for companies to quickly boost their defenses against ransomware.

United States – MyCastingFile.com

https://www.zdnet.com/article/us-actor-casting-company-leaked-private-data-of-over-260000-individuals/?&web_view=true

Exploit: Unsecured Database 

MyCastingFile.com: Entertainment Staffing Platform 

Severity Meter

Risk to Small Business: 1.643 = Severe
Researchers discovered an unsecured Elasticsearch database owned by MyCastingFile.com and filled with information about clients of the casting agency, including current and aspiring actors. It’s estimated that the breach started on May 31 and wasn’t addressed until mid-June. The New Orleans based company acted quickly after they were informed of the problem, but still suffered a breach estimated to be 1GB in size, with over 260,000 user profiles leaked of clients, actors, and members of staff, including minors. 

Severity Meter

Individual Risk: 2.349 = Severe
The leak included names, physical addresses, email addresses, phone numbers, work histories, dates of birth, height and weight, ethnicity, and physical descriptions. Anyone with a profile at the platform should be alert for potential identity theft and spear phishing attempts.  

Customers Impacted: 260,000 

How it Could Affect Your Customers’ Business:  Failure to secure a database is a rookie move, and no company’s clients are going to look at that kindly – especially when that failure involved children. Customers today are concerned about data privacy, and more aware of Dark Web danger than they used to be – and they will not want to continue doing business with companies that can’t keep their information safe.

ID Agent to the Rescue:  Dark Web activity has never been higher, and in the wake of the global pandemic, the Dark Web has changed just as much as the rest of the world. Get an overview of what’s happening on the Dark Web now and how that can affect your  security in our eBook “State of the Dark Web 2020”. DOWNLOAD IT>>

United States – LiveAuctioneers

https://portswigger.net/daily-swig/liveauctioneers-data-breach-millions-of-cracked-passwords-for-sale-say-researchers

Exploit: Unauthorized Database Access 

LiveAuctioneers: Online Antiques Auction House 

Severity Meter

Risk to Small Business: 2.172 = Severe
LiveAuctioneers has reported a major data breach courtesy of one of its third-party data processing partners. The company first noted the incident on July 10, 2020, after monitors spotted Dark Web posts advertising the sale of the company’s records company records of 3.4 million LiveAuctioneers users, as well as three million cracked username and password combinations. 

Severity Meter

Individual Risk: 2.172 = Severe
While no financial data has been reported as compromised, the investigation is still ongoing. Those affected have been notified via email. Every user should reset their account password and be alert to potential identity theft.  

Customers Impacted: 3.4 million 

How it Could Affect Your Customers’ Business: Third party risk is a growing menace that’s hard for businesses to overcome. By maintaining a constant watch on Dark Web markets, businesses can get notified when credentials, including those used in accounts at third party partners, suffer a breach, lowering their risk of compromise from the stolen information.

Cybersecurity News: United Kingdom

United Kingdom – Tesco

https://www.infosecurity-magazine.com/news/consumers-targeted-tesco-scam/

Exploit: Phishing/Impersonation

Tesco: Grocery Retailer

Severity Meter

Risk to Small Business: 2.877 = Moderate
Retail giant Tesco was recently used as a front for an elaborate phishing operation that used a fake Facebook page as well as SMS and email communication to trick consumers into handing over their details and steal confidential and payment data as part of a fake giveaway for a  new HD TV. Facebook users who shared the post helped it spread.

Victims received an email offering them the chance to “register to claim their prize. A button in the message then linked victims to a landing page to enter their name, home address, telephone number, and bank account details. 

Severity Meter

Individual Risk: 2.667 = Moderate
The Facebook portion of the scam was shut down quickly, but some consumers did fall for the email, providing bad actors with personal and financial data, and the scam may still be circulating via email. 

Customers Impacted: Unknown

How it Could Affect Your Customers’ Business: In a booming Dark Web economy, everything is for sale. Your client’s brand is just as valuable as their data. Digital risk protection can’t stop impersonation schemes, but it can prevent bad actors from masquerading as your client in Dark Web forums or on social media if your client is alerted to the problem quickly enough.

Cybersecurity News – European Union

France – Orange 

https://www.bleepingcomputer.com/news/security/orange-confirms-ransomware-attack-exposing-business-customers-data/?&web_view=true

Exploit: Ransomware  

Orange: Telecom Provider 

Severity Meter

Risk to Small Business: 2.323 = Severe
French telecommunications giant Orange has confirmed that they suffered a data breach affecting customers in their Orange Business Services Division. The Nefilim ransomware group added Orange to its data leak site on July 15, 2020. Orange noted that it was quickly able to mitigate the attack and stop the leak, but some business clients had their data captured by the hackers. No mention of a ransom or payment was released by Orange.   

Individual Risk: No individual personal or financial data has been reported as compromised, but no details have been released about the contents of those 20 compromised enterprise accounts.  

Customers Impacted: Unknown

How it Could Affect Your Customers’ Business: Ransomware is everywhere these days, and cybercriminals are often choosing to make more targeted attacks than in the past to lower their chances of quick detection. Every company needs to make defending against ransomware a top security training priority.

ID Agent to the Rescue: The most common vehicle of delivery for ransomware is through email. Keep those attacks from landing with phishing resistance training using a dynamic solution like BullPhish ID – with training available in 8 languages. LEARN MORE>>

Belgium – Argenta Bank

https://cyware.com/news/jackpotting-attackers-are-back-in-action-belgiums-argenta-bank-targeted-072676cb

Exploit: Malware 

Argenta Bank: Banking and Financial Services 

Severity Meter

Risk to Small Business: 1.778 = Severe
Argenta Bank is the latest victim of an increasingly popular malware attack, jackpotting. In these schemes, cybercriminals infect operating systems for ATM machines, turning them into free money fountains. These very precise attacks require specific knowledge and technical skills, and the machines affected were manufactured by Diebold Nixdorf. The bank was forced to turn off 143 machines at various times over two days. 

Individual Risk: No consumer personal or financial data was reported as stolen in this breach.

Customers Impacted: Unknown

How it Could Affect Your Customers’ Business: Sophisticated attacks that require specialized information are becoming more common as attackers seek maximum profit from minimum work and malicious insiders offering cybercrime services like access credentials“as a service” become more common. Guarding against insider threats helps reduce the chance of this kind of crime. 

ID Agent to the Rescue: Insider threats are a constant worry for businesses, while most insider threats are caused by accidental actors, malicious insiders are also a danger that has to be guarded against. Learn how to spot and stop insider threats in our “Stop Insider Threats” resource package. DOWNLOAD IT>>

Cybersecurity News – Australia & New Zealand

Australia – Western Australia Department of Health 

https://www.msn.com/en-au/news/australia/wa-department-of-health-data-breach-under-investigation-after-confidential-information-published-online/ar-BB16XYAT

Exploit: Unauthorized Database Access 

Western Australia Department of Health: Government Agency 

Severity Meter

Risk to Small Business: 2.227 = Severe
Confidential data from the state’s Department of Health was made publicly available on a website after it was distributed over a third-party paging service. Security researchers discovered that a website was recently set up which provided confidential information about Western Australian patients and doctors, including those with suspected COVID-19 infections. The State Government and Western Australia Police are working to have the site taken down, but it was still up as of a recent check.  

Severity Meter

Individual Risk: 2.623 = Moderate
No financial information was reported stolen, but sensitive health data may have been compromised. Affected users should be alert for potential spear phishing attempts or blackmail using this data. 

Customers Impacted: Unknown

How it Could Affect Your Customers’ Business: Health data is extremely valuable right now, especially COVID-19 related data. Both private companies and international threat actors are paying top dollar for research and treatment data as healthcare organizations race to find a lucrative vaccine or treatment that works against COVID-19. This incident combines a third-party data breach with a reliance on outdated technology to create trouble.  

ID Agent to the Rescue: As password fraud is often a gateway to other cybercrime, it pays to put an additional layer of protection between data thieves and critical information and systems. The powerful combination of multifactor authentication, single sign on, and easy remote management makes it simple to make sure that access is safely controlled fast. LEARN MORE>

Cybersecurity News: South America

Argentina – Telecom Argentina

https://www.zdnet.com/article/ransomware-gang-demands-7-5-million-from-argentinian-isp/?&web_view=true

Exploit: Ransomware 

Telecom Argentina: Telecom and Internet Service Provider

Severity Meter

Risk to Small Business: 2.870 = Severe
REvil gang attackers made a bold foray into Telecom Argentina last week, culminating in successfully gaining entry to an internal Domain Administration account, giving them free access to deploy their ransomware payload to more than 18,000 workstations. The company moved quickly to combat the incident, and alerted workers to the danger of potentially corporate network, not to connect to its internal VPN network, and not open emails containing archive files. 

Individual Risk: No individual personal or financial data is reported as affected at this time. 

Customers Impacted: Unknown

How it Could Affect Your Customers’ Business: Administrator accounts are often compromised through whaling, a type of phishing – and an expressway for cybercriminals to race into the heart of a business. Combat that risk by putting extra protections in place like multifactor authentication that help keep administrator accounts safe. 

ID Agent to the Rescue: As password fraud is often a gateway to other cybercrime, it pays to put an additional layer of protection between data thieves and critical information and systems. The powerful combination of multifactor authentication, single sign on, and easy remote management makes it simple to make sure that access is safely controlled fast. LEARN MORE>

Cybersecurity News – Asia

Hong Kong – UFO VPN

Exploit: Unsecured Database 

UFO VPN: Virtual Private Network Host/ Provider 

Severity Meter

Risk to Small Business: 1.086 = Extreme
Users who were relying on VPN provider UFO for a safe, anonymous way to secure their communications and data got a nasty surprise this week. Researchers uncovered more than 20 million user logs from the company available on the Dark Web. It’s a double reputation blow for a VPN provider that claims to retain no login or usage information. The 894 GB database was reportedly hosted on an Elasticsearch cluster that was not even password protected.  The data allegedly included plaintext passwords, IP addresses, timestamps of user connections, session tokens, device information, and user operating system types, along with geographical information in the form of tags. 

Severity Meter

Individual Risk: 1.910 = Severe
Anyone who has used the service for a VPN should be concerned about compromise, spear phishing, identity theft, blackmail, or fraud connected to this event.  

How it Could Affect Your Customers’ Business: Securing a remote workforce can be complex, especially as communications tools become more easily compromised, like messaging and SMS text. One common security measure that companies take when setting up for remote work is encouraging staffers to connect through a VPN. Failing to adequately investigate the safety record of that VPN provider could create additional risk instead of decreasing it.

ID Agent to the Rescue: As password fraud is often a gateway to other cybercrime, it pays to put an additional layer of protection between data thieves and critical information and systems. The powerful combination of multifactor authentication, single sign on, and easy remote management makes it simple to make sure that access is safely controlled fast. LEARN MORE>

The Week in Breach Risk Levels

1 – 1.5 = Extreme Risk
1.51 – 2.49 = Severe Risk
2.5 – 3 = Moderate Risk

Risk scores for The Week in Breach are calculated using a formula that considers a wide range of factors related to the assessed breach.

The Week in Breach: Added Intelligence

Go Inside the Ink to Get the Inside Scoop on Cybersecurity News 

Every weekday, our blog features timely cybersecurity news, problem-solving advice, and expert analysis of today’s threats, plus insight that helps you plan for tomorrow. Don’t miss it!

Catch up on what you need to know now:

Free eBook of the Week

Learn to Spot and Stop Insider Threats Fast

One common thread that we saw this week in breach news was the danger of insider threats. Whether it’s a malicious insider or a careless employee, insider threats are one of the biggest threats any business faces.

It’s essential to know what constitutes an insider threat and how they happen so easily. Learn how to spot and stop insider threats using simple solutions in our eBook “Combatting Insider Threats”, included with our “Stop Insider Threats” resource package.

Download “Combating Insider Threats” GET IT NOW>> 

The Week in Breach Cybersecurity News Spotlight

Does Remote Work Really Increase Cyberattack Risks? 

It’s long been debated whether remote work demonstrably increases the risk of a cyberattack. As we move through the pandemic, we’re all taking part in an unexpected experiment in remote working – and we’re just starting to see if the increased risk that’s often associated with remote work is fact or fiction

The third Global Threat Report is out, and it’s got some important data to consider when debating the risk of remote work or securing a remote workforce. According to researchers, 91% of executives surveyed believe that remote work has placed their companies at higher risk for a cyberattack, with a high incidence of phishing attempts named as the biggest factor that drove that opinion.  

The study, conducted in March and April of 2020, found that 85% of the surveyed executives (chief information officers, chief technology officers, and chief information security officers) felt that breach risks were too high because their workforce had not been properly equipped, trained, or secured to work from home, with 28% citing severe known gaps in security.

As the pandemic continues to affect the way that business is done, companies need to take adequate measures to secure their remote workforce long term. Our resource package “Remote Working Cybersecurity” can help with a checklist and more! DOWNLOAD IT>>

Over 29% of the surveyed executives cited a lack of multifactor authentication as the biggest threat facing their organization, rising to 50% for companies in the financial services sector, and 46% for companies with 251-500 employees. COVID-19 related malware was reported by 43% of respondents as the biggest perceived threat organizations with 50-250 employees. 

Companies should be proactive to avoid future headaches. By adding MFA and the remote workforce support power of our digital risk protection platform now, businesses can be ready for tumultuous times and avoid hazards like scrambling for added security or a costly data breach as we continue to grapple with the global pandemic. 

A note about cybersecurity news for your customers:

Multifactor Authentication is a Security Must-Have in 2020

Today’s risk landscape is more complicated than ever. There’s a new danger to your systems and data lurking around every corner, and a new solution that you need to buy to mitigate it. Third-party data breaches are a constant worry not to mention the risk that comes from staff password recycling, or unintentional insider threats like falling for a phishing attack. So how can you provide an extra layer of security against most risks without spending a fortune? 

Multifactor authentication (MFA). Adding MFA on every user account us a fast, easy way to secure your company’s entry points. Even if cybercriminals are able to obtain a credential that would allow them access to your systems and data from an outside source, that credential isn’t going to do them any good without an authentication token like a code that’s sent to the real account holder’s cellphone. 

DTS is very good at cybersecurity solutions for small businesses.

Seriously, we are, and we can prove it. We like being heroes!

We also know how intimidating technology can be, we make a living helping business owners and managers just like you who have questions about all things technology, and that includes cybersecurity.

Most small businesses do not have the technical resources or time to understand all this geek stuff. If this describes you, let us help you.

If you would like more information about cybersecurity as a service give us a call, we’re always happy to chat, and the call is free, every time you call!

Return to the Learning Center

Dedicated to your success,

Wally Moore

Business Development Manager

dts|infotech . . . secure computer networks that work

503.359.1275

www.dtsinfotech.com

GET HELP NOW