Showing posts with label Card security code. Show all posts
Showing posts with label Card security code. Show all posts

Thursday, September 21, 2017

Equifax Accidentally Directs 200,000 Customers To Fake Phishing Website

And the hits just keep coming for Equifax, the once-trusted credit-monitoring firm that has been embroiled in one of the biggest corporate public-relations disasters in recent memory since disclosing that hackers had penetrated its cyber security defenses and absconded with sensitive personal and financial data belonging to 143 million Americans. Because of the types of data that were stolen, including drivers" license, social security and credit-card numbers, experts have described the hack as possibly the most damaging corporate hack yet.


As if this weren’t enough to permanently sully the firm’s reputation (amid cries of “you had one job!”) – the staggering irony of a credit monitoring firm inadvertently divulging the sensitive information that it was supposed to safeguard hasn’t been lost on consumers) a series of subsequent disclosures have portrayed the firm’s executives as bungling, at best, and nefarious, at worst.


In the nearly two weeks since the story broke…





  • It was revealed that three of the firm’s executives, including its CFO, cashed out of stocks and options worth some $2 million in the month between when the company first learned about the hack, and when it was disclosed to the public. A federal prosecutor in Atlanta has opened a criminal investigation into Equifax that will focus both on whether the firm was criminally negligent in failing to patch a hole in its cybersecurity systems, as well as whether the suspect stock sales constitute securities fraud.

  • The company’s head of cyber security was revealed to have no background in computer science or security – a fact the company tried to hastily cover up by scrubbing her social-media profiles. Susan Mauldin, Equifax’s chief information security officer, has a bachelor’s degree in music composition and a master’s in fine arts from the University of Georgia.

  • Several Congressional committees have asked the company to turn over information relating to the hack as multiple investigations appear to be getting under way. The attorneys general of a handful of states, including Massachusetts and Rhode Island, have joined a probe into the company’s handling of the breach.

  • The company has been hit with dozens of lawsuits from consumers alleging fraud, abuse and negligence.

  • Equifax CEO Rick Smith has been called to testify before a special House panel early next month.


When Equifax first set up a website to allow consumers to check whether their information was compromised, it carried a waiver stating that by using the service consumers would forfeit the right to sue Equifax. The internet quickly exploded in outrage, and the company quickly clarified that the waiver didn’t apply to this hacking incident, which…sure. Now, The Verge, The New York Times and a handful of other media outlets are reporting that Equifax accidentally tweeted the link to an imposter website set up by a white-hat hacker hoping to expose gllaring errors that the firm had made in setting up its verification website. This happened not once, but three times. And in at least one instance, the tweet with the phony link was left up for a whole day.



Here’s The Verge:





“Today, Equifax ended up creating that exact situation on Twitter. In a tweet to a potential victim, the credit bureau linked to securityequifax2017.com, instead of equifaxsecurity2017.com. It was an easy mistake to make, but the result sent the user to a site with no connection to Equifax itself. Equifax deleted the tweet shortly after this article was published, but it remained live for nearly 24 hours.”



Luckily for consumers, the fake site wasn’t malicious. Instead, it was set up by developer Nick Sweeting to try and expose the glaring security vulnerabilities that the company had embedded in its recovery website, which it set up as a separate domain, rather than making it a subdomain of Equifax’s main website.





“Luckily, the alternate URL Equifax sent the victim to isn’t malicious. Full-stack developer Nick Sweeting set up the misspelled phishing site in order to expose vulnerabilities that existed in Equifax"s response page. “I made the site because Equifax made a huge mistake by using a domain that doesn"t have any trust attached to it [as opposed to hosting it on equifax.com],” Sweeting tells The Verge. “It makes it ridiculously easy for scammers to come in and build clones — they can buy up dozens of domains, and typo-squat to get people to type in their info.”



Sweeting says no data will leave his page and that he "removed any risk of leaking data via network requests by redirecting them back to the user"s own computer," so hopefully data entered on his site is relatively safe. Still, Equifax"s team linked out to his page. That isn"t reassuring.”



Prior to Equifax customer service sharing the imposter site, Sweeting says he emailed the company’s support team and tweeted to Equifax that he spotted a potential vulnerability. By the time the site was taken down, Sweeting says it had received more than 200,000 hits. In the spirit of transparency, Sweeting included a disclaimer on his site warning consumers that it was a fake – and blasting Equifax for its sloppy security practices.


According to the NYT, phishers cannot create a page on the equifax.com domain, so if the website were hosted there instead, it would be easy for users to tell that the page was legitimate.





“Fortunately for the people who clicked, Mr. Sweeting’s website was upfront about what it was. The layout was the same as the real version, complete with an identical prompt at the top: “To enroll in complimentary identity theft protection and credit file monitoring, click here.” But a headline in large text differed: “Cybersecurity Incident & Important Consumer Information Which is Totally Fake, Why Did Equifax Use A Domain That’s So Easily Impersonated By Phishing Sites?”



The legitimate Equifax domain was securityequifax2017.com. Sweeting’s was equifaxsecurity2017.com. And as one cybersecurity expert told the NYT, even the legitimate website looks fake because it’s not a subdomain of the larger Equifax site.





“You would think that would be the obvious place to start,” said Rahul Telang, a professor of information systems at Carnegie Mellon University. “Create a subdomain so that if somebody tries to fake it, it becomes immediately obvious.”



The company’s actions, Telang told the NYT, suggest that it had never anticipated or planned for a breach.


This has become clear in the last few weeks. Now, the only thing left to be decided is whether the fact that the company was almost comically unprepared for a hack rises to the level of criminal negligence.

Monday, September 18, 2017

Muddy Waters' Carson Block Sues Equifax For $500,000

Disgraced credit-monitoring company Equifax, which has seen its stock drop by nearly 40% since disclosing what will likely be remembered as one of the most damaging data breaches in US history, eliciting dozens of class-action lawsuits, calls for investigations by at least one state attorney general, and requests from multiple Congressional committees for more information about the exact timeline of when Equifax learned about the hack, and when it was disclosed – because somewhere between those two events, several of the company’s executives, including its CFO, cashed out of some $2 million in stock and options.



In the latest humiliating blow to a company that failed at its only job – safeguarding Americans’ sensitive personal and financial data – famed short-seller Carson Block has announced that he has decided to sue the company over its “abysmal” handling of the hack.


And here’s the kicker: He doesn’t even have an open short position against the company. In other words: There’s no profit motive here. Block – like millions of Americans - is just really, really pissed.


Here’s the Financial Times:





“Veteran short-seller Carson Block has launched a private lawsuit against Equifax, accusing the credit-reporting company of an “abysmal” handling of one of the worst cyber security incidents in history. Equifax said on September 7 that its systems were breached by criminals in a raid that went on for more than two months — an admission that has prompted a flood of regulatory inquiries, dozens of private lawsuits and a more than one-third collapse in the company’s share price. The data of up to 143m Americans was compromised, the company said, along with up to 400,000 people in the UK.



One of those was Mr Block, whose suit filed on Friday accuses Equifax of negligence in failing to safeguard and protect his personal identifying information from criminals, as well as a failure to disclose the breach in a timely fashion.”


Apparently, Block has learned that his personal information was compromised in the hack because he’s suing for personal damages. He has also accused the company of failing to disclose the breach in a timely fashion. The company’s CEO, Rick Smith, who is expected to deliver Congressional testimony early next month, has said that the company at first believed the hack was relatively minor."



According to the FT, the famed short sellers is seeking $500,000 in damages, a paltry sum considering Muddy Waters reportedly produced double-digit returns last year.





“Mr Block’s firm, Muddy Waters, has no short position that would benefit from a fall in the stock. In the suit, filed in the Northern District of California, San Francisco division, he seeks damages of at least $500,000 for the “stress, nuisance and annoyance” of dealing with issues stemming from the breach.



The suit notes that Equifax’s business revolves around being a “secure storehouse” for data and providing a clear financial profile of consumers that lenders and other businesses can rely on. According to its own description, Equifax organises, assimilates and analyses data on more than 820m consumers and more than 91m businesses worldwide.



Equifax could not be reached for comment at the time of publication.”



As the FT explains, hackers gained access to the company’s systems by exploiting a vulnerability in Apache Struts, a popular open-source framework for developing web applications in the Java programming language. On Friday, Equifax said that it had patched the hole on July 30, one day after it had detected strange activity on its servers. But cybersecurity experts note that the fix had been available since March, when the Apache Foundation put out an update which had been widely disseminated in tech circles. In short, the company’s cybersecurity experts committed an unforced error by neglecting to invest the meager resources required to patch the fix.



Amid the firestorm of controversy that has engulfed the company in the aftermath of the hacking disclosure, Equifax has actively tried to cover up the fact that Susan Mauldin, Equifax’s chief information security officer, and the person who was responsible for keeping the highly confidential and secret information of over 100 million Americans, has zero security or technology credentials…in fact, she was a music major at the University of Georgia.


Smith, Mauldin and nine other executives are named in Block’s lawsuit.  Mauldin, Equifax said, would retire immediately from the company on Friday, along with David Webb, chief information officer.


According to the suit, Equifax should’ve been more careful following two big breaches in 2016. In one of those, 430,000 names and other vital pieces of information were lost as a result of the company using “alarmingly poor” security for the generation of PINs from the last four digits of a social-security number and the four-digit year of birth.


Of course, with North Dakota Democrat Heidi Heitkamp calling for a criminal investigation into securities fraud, Block’s lawsuit for a meager half a million is probably the least of the company’s worries…
 

Sunday, September 17, 2017

Here's What Your Identity Sells For On The Dark Web

Millions of Americans who trusted Equifax with sensitive personal and financial data, including social security numbers and credit-card information, are now nervously wondering whether they will be among the unlucky minority of affected customers whose identities are successfully “repurposed” by online criminal groups.


One researcher from security firm SecureWorks shared some details about today’s burgeoning marketplace for stolen data with Bloomberg, and the conclusion is clear: It is now easier – and cheaper – for criminals to access and abuse illicit data than ever before. In fact, a high-limit American express card with a high chance of working can be purchased online for less than $20. Criminals can buy files with thousands of low-limit card numbers for pennies on the dollar.


According to Bloomberg, “verified” high-limit credit cards from developed countries like the US, Japan, and South Korea are selling on the dark web for the bitcoin equivalent of about $10 to $20.



“Verified” means the seller has tested out transactions on the card and found it hasn’t been canceled yet. For scammers on a budget, there’s unverified stolen credit card data, which comes out to pennies a card when bought in bulk.


Here’s a screengrab from one dark-web marketplace.



Luckily for criminals, cards generally aren’t selling any cheaper on the dark web these days, said Alex Tilley, a researcher at Secureworks. Today’s buyers are more likely to get higher-quality cards, ones with sizable limits that can be used fraudulently with ease. It isn’t as hit-or-miss as it used to be, a welcome change for criminals, chilling news for most of us.


Criminals have even set up sophisticated “rating systems” to help value the data. Business cards are preferred, Tilley said, because they don’t have a limit. Those and high-end personal cards—say, a Platinum American Express that has been verified and has an 85 percent rating (judged by the seller to have an 85 percent chance of being successfully used in a fraud)—will go for $15 to $20. A regular Mastercard that doesn’t have a high limit might go for $9.



One underground hacker market inexplicably called Trump’s Dumps is selling full identities of individuals just like you for as little as $10 apiece. They’re called fullz, “dossiers that provide enough financial, geographic and biographical information on a victim to facilitate identity theft or other impersonation-based fraud.” Fullz can help a criminal get past those irritating “secret questions” that sites ask to verify your identity.


Recently, Secureworks’ researchers have seen more offers of bulk pre-verified card details, along with more identifying information about the owners. In some cases, offers even include the cardholder’s mother’s maiden name. Still, they cost just $10 to $12. Below is a fullz offer with a lot of personal identification on a Korean consumer.


In a massive breach like Equifax, hackers can easily walk away with hundreds of millions of dollars in profits from selling the data. Meanwhile, the identity thieves who purchased it can reap their own fortune running their scams.


Congress, the FTC and Equifax customers – enraged by both the company’s reluctance to initially disclose the breach and its carelessness (some would say tight-fistedness) concerning its cybersecurity defenses – have buried the company in lawsuits and official inquiries.


As USA Today revealed yesterday, hackers took advantage of an Equifax security vulnerability two months after an industry group discovered the coding flaw and shared a fix for it, raising questions about why Equifax didn"t update its software successfully when the danger became known.


We’re looking forward to hearing the whole story from CEO Rick Smith when he testifies before Congress early next month. Whether Smith manages to hang on to his job remains to be seen - calls for his resignation after a 12-year-long scandal-free tenure are mounting. CNBC"s Jim Cramer said last night that Smith "should be fired today."


But perhaps more worrying for Smith and his C-Suite companions are calls from North Dakota Sen. Heidi Heitkamp, who has demanded a criminal investigation into whether the company"s executives - several of whom sold stock during the period between when the company first learned about the hack and when it disclosed it to the public - commited securities fraud.


"If that happened, then somebody needs to go to jail," she said.

Friday, September 8, 2017

Massive Data Breach At Equifax: As Many As 143 Million Social Security Numbers Hacked

Credit-reporting company Equifax shocked investors, and more than a third of America, when it announced on Thursday afternoon that hackers had breached its data systems, compromising the personal information of approximately 143 million U.S. consumers. The information accessed "primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers." In other words, pretty much everything that should have been hidden behind an n-number of firewalls, is now available to the dark net"s highest bidder. 


The company, which in delightful irony offers credit-monitoring and identity-theft protection products to "guard consumers’ personal information", said that it had learned of the incident on July 29, 2017, at which point it reported the intrusion to law enforcement and contracted a cybersecurity firm to conduct a forensic review: based on the company’s investigation, the unauthorized access occurred from mid-May through July 2017. Oddly enough, it took shareholders and over a third of America, more than a month longer to learn that all their personal data may have been compromised.


As if 143 million leaked social security numbers wasn"t enough, Equifax said that criminals also accessed credit card numbers for approximately 209,000 U.S. consumers, and certain dispute documents with personal identifying information for approximately 182,000 U.S. consumers. But wait, there"s more: the company also identified unauthorized access to limited personal information for certain UK and Canadian residents.


The good news, is that according to Equifax, "this issue has been contained." The bad news is that, well, as many as 143 million social security numbers have been hacked. So no, it"s not contained.


“This is clearly a disappointing event for our company, and one that strikes at the heart of who we are and what we do,” Equifax Chief Executive Richard Smith said in prepared remarks. “I apologize to consumers and our business customers for the concern and frustration this causes.”


In a Q&A posted on the company"s website, the management team revealed what"s really important with the following question and answer:





Does this cybersecurity incident impact your capital allocation priorities going forward?



Our capital allocation priorities are unchanged at this time. As we have previously indicated, our investment
priorities in order of importance are: (1) internal investment; (2) dividends; (3) acquisition; and (4) share
repurchase. We do, however, expect to increase our capital spending in an effort to further accelerate IT
infrastructure, systems and data security and resiliency improvement actions
.



Oh, good, because a hack involving 143 million SSNs is one of those cases where capex probably should have taken precedence over stock buybacks.  Don"t worry though, because as it explains in the same quesionnaire, "Equifax remains committed to delivering on the long term financial model of 7-10% revenue growth and 11%- 14% growth in Adjusted EPS on average over a business cycle. Equifax’s long term financial model reflects our continuing fundamental ability to utilize our unique and differentiated data assets and leading analytical capability to deliver high value products and services to our customers."


Uhm, after this... what customers?


After falling as much as 12% in the after hours, EFX stock stabilized... then fell as much as 19%.



And now the best news: with Putin clearly behind this hack - as "all 17 intelligence agencies", WaPo and NYT will shortly "confirm" - the US economy is about to undergo a renaissance as hundreds of millions of (unsolicited) purchases prompt a golden age for US retailers while sending Amazon market cap into the $1 trillions...  even if the shipping address for said purchases happen to be small, frigid villages deep in the Russian taiga.


Full statement from Equifax here.


Update:


In appears there was a reason why EFX decided to hold on to the hacking news a little longer than seems reasonable. As Bloomberg reports, "three Equifax Inc. senior executives sold shares worth almost $1.8 million in the days after the company discovered a security breach that may have compromised information on about 143 million U.S. consumers."





The credit-reporting service said late Thursday in a statement that it discovered the intrusion on July 29. Regulatory filings show that three days later, Chief Financial Officer John Gamble sold shares worth $946,374 and Joseph Loughran, president of U.S. information solutions, exercised options to dispose of stock worth $584,099. Rodolfo Ploder, president of workforce solutions, sold $250,458 of stock on Aug. 2. None of the filings lists the transactions as being part of 10b5-1 pre-scheduled trading plans.



Surely, it was all purely a coincidence, even though had they waited until today, their proceeds would be well over 10% lower...