Showing posts with label Hacker culture. Show all posts
Showing posts with label Hacker culture. Show all posts

Tuesday, September 26, 2017

Massive Hack At Deloitte: Entire Internal Email System Compromised, Client Emails Exposed

Another day, another major hacking.


The Guardian reports that in the latest corporate cyber breach, one of the world’s “big four” accounting and consultancy firms, Deloitte, was been targeted by a sophisticated hack that "compromised the confidential emails and plans of some of its blue-chip clients." And just like Equifax, New York-headquartered Deloitte was similarly the victim of a cybersecurity attack that went unnoticed for months. The Guardian understands Deloitte discovered the hack in March this year, but it is believed the attackers may have had access to its systems since October or November 2016.


Responding to questions from the Guardian, Deloitte confirmed it had been the victim of a hack but insisted only a small number of its clients had been “impacted”. It would not be drawn on how many of its clients had data made potentially vulnerable by the breach. Alas, the company has yet to provide a full disclosure of just who and which clients were violated: an estimated 5 million emails were in the hacked email cloud and could have been been accessed by the hackers. Deloitte said the number of emails that were at risk was a fraction of this number but declined to elaborate.


While unlike Equifax Deloite is not a public public company and is not accountable to countless shareholders, with $37 billion in revenue last year and over 263,000 worldwide employees, Deloitte is a corporate behemoth which provides auditing, tax consultancy and - like Equifax - high-end cybersecurity advice to some of the world’s biggest banks, multinational companies, media enterprises, pharmaceutical firms and government agencies.  Here the Guardian reports that Deloitte clients "across all of these sectors had material in the company email system that was breached. The companies include household names as well as US government departments."





So far, six of Deloitte’s clients have been told their information was “impacted” by the hack. Deloitte’s internal review into the incident is ongoing.



The hacker compromised the firm’s global email server through an “administrator’s account” that, in theory, gave them privileged, unrestricted “access to all areas”.



Embarrassingly, the administrator level hack required only a single password and did not have “two-step“ verification, much like Deloitte and other companies strongly urge everyone to do.


As the Krebs on Security blog separately notes, "according to a source close to the investigation, the breach dates back to at least the fall of 2016, and involves the compromise of all administrator accounts at the company as well as Deloitte’s entire internal email system"





The source told KrebsOnSecurity they were coming forward with information about the breach because, “I think it’s unfortunate how we have handled this and swept it under the rug. It wasn’t a small amount of emails like reported. They accessed the entire email database and all admin accounts. But we never notified our advisory clients or our cyber intel clients.



This same source said forensic investigators identified several gigabytes of data being exfiltrated to a server in the United Kingdom. The source further said the hackers had free reign in the network for “a long time” and that the company still does not know exactly how much total data was taken.



Penetrating the unknown number of emails involved breaching the Microsoft cloud used the by the company. Emails to and from Deloitte’s 244,000 staff were stored in the Azure cloud service, which was provided by Microsoft. This is Microsoft’s equivalent to Amazon Web Service and Google’s Cloud Platform.


In addition to emails, the Guardian adds the hackers had "potential access to usernames, passwords, IP addresses, architectural diagrams for businesses and health information. Some emails had attachments with sensitive security and design details."


Until today"s report, the hack had been disclosed to the public: the breach, which was US-focused, was regarded as so sensitive that only a handful of Deloitte’s most senior partners and lawyers were informed.





The team investigating the hack is understood to have been working out of the firm’s offices in Rosslyn, Virginia, where analysts have been reviewing potentially compromised documents for six months.



It has yet to establish whether a lone wolf, business rivals or state-sponsored hackers were responsible.



Translation: while Putin wasn"t accused of hacking Equifax, he may yet get the blame this time.


Making this breach even more complicated, it is still unknown what information the hackers acquired: Guardian sources said if the hackers had been unable to cover their tracks, it should be possible to see where they went and what they compromised by regenerating their queries. This kind of reverse-engineering is not foolproof, however.





“In response to a cyber incident, Deloitte implemented its comprehensive security protocol and began an intensive and thorough review including mobilising a team of cybersecurity and confidentiality experts inside and outside of Deloitte,” a spokesman said. “As part of the review, Deloitte has been in contact with the very few clients impacted and notified governmental authorities and regulators.



“The review has enabled us to understand what information was at risk and what the hacker actually did, and demonstrated that no disruption has occurred to client businesses, to Deloitte’s ability to continue to serve clients, or to consumers. We remain deeply committed to ensuring that our cybersecurity defences are best in class, to investing heavily in protecting confidential information and to continually reviewing and enhancing cybersecurity. We will continue to evaluate this matter and take additional steps as required."



“Our review enabled us to determine what the hacker did and what information was at risk as a result. That amount is a very small fraction of the amount that has been suggested.”



Deloitte declined to say which government authorities and regulators it had informed, or when, or whether it had contacted law enforcement agencies.


Of course, as noted above, the breach is a deep embarrassment for Deloitte, which offers clients advice on how to manage the risks posed by sophisticated cybersecurity attacks. If only the company had followed its own advice.  Even more awkward, in 2012 Deloitte was ranked the best cybersecurity consultant in the world and has a “CyberIntelligence Centre” to provide clients with “round-the-clock business focussed operational security." It is unclear if that unit was also hacked.


While we await an official statement from Deloitte, what comes next is lots of lawsuits and even more settlements. According to the Guardian, on 27 April Deloitte hired US law firm Hogan Lovells on “special assignment” to review what it called “a possible cybersecurity incident”. The Washington-based firm has been retained to provide “legal advice and assistance to Deloitte LLP, the Deloitte Central Entities and other Deloitte Entities” about the potential fallout from the hack.

Saturday, September 9, 2017

Hackers Can Now Cause Blackouts On America's Electrical Grid, Report

It was inevitable that someday, hackers would have the ability to exert control over the U.S. electrical grid.  According to the computer security firm Symantec, someday is today.



Hacking attacks over the last several months that targeted U.S. energy companies have been able to gain "operational control" over systems, thus threatening blackouts across the U.S., says Symantec.


 The hacker group known as DragonFly 2.0 was able to gain control in at least 20 places, according to the firm.


Wired:





Symantec on Wednesday revealed a new campaign of attacks by a group it is calling Dragonfly 2.0, which it says targeted dozens of energy companies in the spring and summer of this year. In more than 20 cases, Symantec says the hackers successfully gained access to the target companies" networks. And at a handful of US power firms and at least one company in Turkey – none of which Symantec will name – their forensic analysis found that the hackers obtained what they call operational access: control of the interfaces power company engineers use to send actual commands to equipment like circuit breakers, giving them the ability to stop the flow of electricity into US homes and businesses.



"There"s a difference between being a step away from conducting sabotage and actually being in a position to conduct sabotage ... being able to flip the switch on power generation," says Eric Chien, a Symantec security analyst. "We"re now talking about on-the-ground technical evidence this could happen in the US, and there"s nothing left standing in the way except the motivation of some actor out in the world."



Never before have hackers been shown to have that level of control of American power company systems, Chien notes. The only comparable situations, he says, have been the repeated hacker attacks on the Ukrainian grid that twice caused power outages in the country in late 2015 and 2016, the first known hacker-induced blackouts.



Security firms like FireEye and Dragos have pinned those Ukrainian attacks on a hacker group known as Sandworm, believed to be based in Russia. But Symantec stopped short of blaming the more recent attacks on any country or even trying to explain the hackers" motives. Chien says the company has found no connections between Sandworm and the intrusions it has tracked. Nor has it directly connected the Dragonfly 2.0 campaign to the string of hacker intrusions at US power companies – including a Kansas nuclear facility – known as Palmetto Fusion, which unnamed officials revealed in July and later tied to Russia.



Chien does note, however, that the timing and public descriptions of the Palmetto Fusion hacking campaigns match up with its Dragonfly findings. "It"s highly unlikely this is just coincidental," Chien says. But he adds that while the Palmetto Fusion intrusions included a breach of a nuclear power plant, the most serious DragonFly intrusions Symantec tracked penetrated only non-nuclear energy companies, which have less strict separations of their internet-connected IT networks and operational controls.



The first question I would want answered is, if they have that sort of control, why not exercise it?  Why no blackouts or service interruptions in the U.S.?


Hacking Sony or another private business is one thing.  Fooling with our electrical infrastructure is many orders of magnitude more serious.  If a sovereign nation were behind such an event, it would be tantamount to a declaration of war.  Unless the attacking nation was supremely confident that the hack couldn"t be traced back to it, the nation would be unlikely to attempt it.


Causing a blackout in a major urban area would almost certainly result in many deaths.  We know this from previous blackouts in New York City, where the 2003 power outage is estimated to have resulted in 100 deaths.  This would be intolerable, and if the attack could be traced back to Russia or China, it would result in retaliation by the U.S.  We"re no slouches ourselves when it comes to cyber-warfare, and we could almost certainly make any country pay dearly.


But in a time of war, that kind of control over our electrical grid could wreak havoc and sow confusion and fear among the populace.  In the meantime, it would behoove the government to work with industry to harden our systems to prevent that kind of catastrophe.

Saturday, June 3, 2017

Mapping America's Most Misspelled Words

Amid Murica"s spelling-bee week, Google mapped the nation"s most mis-spelled words...


"Sauerkraut" in Pennsylvania, "Chaos" in Tennessee, Diarrhea" in New Hampshire, and "Chihuahua" in South Carolina"?



Source: Google


And here are the most-used words in each state...



Source: xkcd.com

Thursday, March 16, 2017

McDonalds Tweets Trump: "You Are A Disgusting Excuse Of A President, Also You Have Tiny Hands"

Update: It appears McDonalds needed Twitter to tell Robert Gibbs and the company"s Corporate relations team that their account had been "compromised."



And so, as MCD has washed its hands of the rogue tweet and blamed "compromising" actors, the company has generated substantial media buzz... the only question is whether the buzz will lead to more or less sales.


*  *  *



One day after Twitter stock tumbled after a pervasive hack showed just how vulnerable the underperforming social network (where 15% of total users appear to be bots) remains, moments ago McDonalds tweeted to president Trump, in what appears to be the latest hack of a prominent account, that "You are actually a disgusting excuse of a President and we would love to have @BarackObama back, also you have tiny hands."



The confrontational tweet was even pinned for a moment:



We assume, of course, that this is a hack. If not, the media is about to have a field day with the latest member of the "resistance."


Of course, it could have been just a rogue employee who is about to join the "unemployed resistance."


It is worth noting that Trump was once in a commercial for the fast food giant, and has posted images eating McDonald"s food on his social media accounts during his campaign.


Of course, it may not have been a "rogue employee" at all: former Obama press secretary Robert Gibbs is now the executive vice president and global chief communications officer at McDonald"s. To wit:





June 09, 2015 McDonald’s Corporation today announced the appointments of Robert Gibbs as Executive Vice President, Global Chief Communications Officer and Silvia Lagnado as Executive Vice President, Global Chief Marketing Officer. Both will report to McDonald’s President and CEO Steve Easterbrook.



In his new role, Gibbs will lead McDonald’s corporate relations group, which manages internal and external communications and government and public affairs. He will lead McDonald’s in communicating clear, coordinated messages to internal and external constituencies, enhancing the brand and supporting corporate strategies. 



Gibbs joins McDonald’s from The Incite Agency, a strategic communications advisory firm he co-founded in 2013. Prior to that he held several senior advisory roles in the White House, serving as President Barack Obama’s press secretary during his first term, then as senior campaign advisor during his re-election campaign.



Which means he also has access to the company"s twitter account...


* * *


Update: the tweet has since been deleted although it does not appear that McDonalds was actually hacked as the account continues its back and forth with other customers in a far more calm and collected manner.

Tuesday, January 3, 2017

Washington Post Admits Its 'Russians Hacked A US Utility' Story Was 'Fake News'

Over the weekend we noted that the Washington Post was caught spreading "fake news" about an alleged attempt by "Russian hackers" to take over a Vermont Utility (see "Washington Post Caught Spreading More Fake News About "Russian Hackers"").  Within hours of reporting that the "Russian hackers" had gained access to the electrical grid, the Burlington Electric Department in Vermont had to issue a statement confirming that the provocative Wapo story simply wasn"t true and that a laptop found to be infected with malware was never actually connected to the grid.  An embarrassed Wapo was subsequently forced to change it"s sensationalized headline and publish a retraction.


Now, as they often do, it appears this Wapo "fake news" rabbit holes gets even deeper.  Not only are "federal officials" now confirming that "Russian hackers" never targeted the Vermont electrical grid, but the whole mishap was derived from an employee"s attempt to check his Yahoo email account which, as Wapo reports, resulted in his computer connecting to a "suspicious IP address" that is "found elsewhere in the country suggesting the company wasn"t being targeted by Russians."




Moreover, not only was the malware not linked to a specific attempt of "Russian hackers" to penetrate the U.S. electrical grid, the software in question isn"t even linked to the "Grizzly Steppe" group that the Obama administration says is behind the DNC and John Podesta email hacks.  Of course, this is a direct contradiction to the opening paragraph of Wapo"s original story which directly connected the Vermont "hack" back to "Grizzly Steppe"...apparently with no evidence whatsoever.





U.S. officials are continuing to investigate the laptop. In the course of their investigation, though, they have found on the device a package of software tools commonly used by online criminals to deliver malware. The package, known as Neutrino, does not appear to be connected with Grizzly Steppe, which U.S. officials have identified as the Russian hacking operation. The FBI, which declined to comment, is continuing to investigate how the malware got onto the laptop.



Wapo goes on to point out that the "murkiness of the information" makes it difficult to relay meaningful information to the public about alleged "hackings." 





The murkiness of the information underlines the difficulties faced by officials as they try to root out Grizzly Steppe and share with the public their findings on how the operation works. Experts say the situation was made worse by a recent government report, which they described as a genuine effort to share information with the industry but criticized as rushed and prone to causing confusion. Authorities also were leaking information about the utility without having all the facts and before law enforcement officials were able to investigate further.



Here"s an idea, how about you simply avoid reporting "murky" information until you have all the facts?  But that wouldn"t help advance your "Russian hacking" narrative now would it?