Showing posts with label Security engineering. Show all posts
Showing posts with label Security engineering. Show all posts

Monday, September 18, 2017

Muddy Waters' Carson Block Sues Equifax For $500,000

Disgraced credit-monitoring company Equifax, which has seen its stock drop by nearly 40% since disclosing what will likely be remembered as one of the most damaging data breaches in US history, eliciting dozens of class-action lawsuits, calls for investigations by at least one state attorney general, and requests from multiple Congressional committees for more information about the exact timeline of when Equifax learned about the hack, and when it was disclosed – because somewhere between those two events, several of the company’s executives, including its CFO, cashed out of some $2 million in stock and options.



In the latest humiliating blow to a company that failed at its only job – safeguarding Americans’ sensitive personal and financial data – famed short-seller Carson Block has announced that he has decided to sue the company over its “abysmal” handling of the hack.


And here’s the kicker: He doesn’t even have an open short position against the company. In other words: There’s no profit motive here. Block – like millions of Americans - is just really, really pissed.


Here’s the Financial Times:





“Veteran short-seller Carson Block has launched a private lawsuit against Equifax, accusing the credit-reporting company of an “abysmal” handling of one of the worst cyber security incidents in history. Equifax said on September 7 that its systems were breached by criminals in a raid that went on for more than two months — an admission that has prompted a flood of regulatory inquiries, dozens of private lawsuits and a more than one-third collapse in the company’s share price. The data of up to 143m Americans was compromised, the company said, along with up to 400,000 people in the UK.



One of those was Mr Block, whose suit filed on Friday accuses Equifax of negligence in failing to safeguard and protect his personal identifying information from criminals, as well as a failure to disclose the breach in a timely fashion.”


Apparently, Block has learned that his personal information was compromised in the hack because he’s suing for personal damages. He has also accused the company of failing to disclose the breach in a timely fashion. The company’s CEO, Rick Smith, who is expected to deliver Congressional testimony early next month, has said that the company at first believed the hack was relatively minor."



According to the FT, the famed short sellers is seeking $500,000 in damages, a paltry sum considering Muddy Waters reportedly produced double-digit returns last year.





“Mr Block’s firm, Muddy Waters, has no short position that would benefit from a fall in the stock. In the suit, filed in the Northern District of California, San Francisco division, he seeks damages of at least $500,000 for the “stress, nuisance and annoyance” of dealing with issues stemming from the breach.



The suit notes that Equifax’s business revolves around being a “secure storehouse” for data and providing a clear financial profile of consumers that lenders and other businesses can rely on. According to its own description, Equifax organises, assimilates and analyses data on more than 820m consumers and more than 91m businesses worldwide.



Equifax could not be reached for comment at the time of publication.”



As the FT explains, hackers gained access to the company’s systems by exploiting a vulnerability in Apache Struts, a popular open-source framework for developing web applications in the Java programming language. On Friday, Equifax said that it had patched the hole on July 30, one day after it had detected strange activity on its servers. But cybersecurity experts note that the fix had been available since March, when the Apache Foundation put out an update which had been widely disseminated in tech circles. In short, the company’s cybersecurity experts committed an unforced error by neglecting to invest the meager resources required to patch the fix.



Amid the firestorm of controversy that has engulfed the company in the aftermath of the hacking disclosure, Equifax has actively tried to cover up the fact that Susan Mauldin, Equifax’s chief information security officer, and the person who was responsible for keeping the highly confidential and secret information of over 100 million Americans, has zero security or technology credentials…in fact, she was a music major at the University of Georgia.


Smith, Mauldin and nine other executives are named in Block’s lawsuit.  Mauldin, Equifax said, would retire immediately from the company on Friday, along with David Webb, chief information officer.


According to the suit, Equifax should’ve been more careful following two big breaches in 2016. In one of those, 430,000 names and other vital pieces of information were lost as a result of the company using “alarmingly poor” security for the generation of PINs from the last four digits of a social-security number and the four-digit year of birth.


Of course, with North Dakota Democrat Heidi Heitkamp calling for a criminal investigation into securities fraud, Block’s lawsuit for a meager half a million is probably the least of the company’s worries…
 

Friday, September 8, 2017

Massive Data Breach At Equifax: As Many As 143 Million Social Security Numbers Hacked

Credit-reporting company Equifax shocked investors, and more than a third of America, when it announced on Thursday afternoon that hackers had breached its data systems, compromising the personal information of approximately 143 million U.S. consumers. The information accessed "primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers." In other words, pretty much everything that should have been hidden behind an n-number of firewalls, is now available to the dark net"s highest bidder. 


The company, which in delightful irony offers credit-monitoring and identity-theft protection products to "guard consumers’ personal information", said that it had learned of the incident on July 29, 2017, at which point it reported the intrusion to law enforcement and contracted a cybersecurity firm to conduct a forensic review: based on the company’s investigation, the unauthorized access occurred from mid-May through July 2017. Oddly enough, it took shareholders and over a third of America, more than a month longer to learn that all their personal data may have been compromised.


As if 143 million leaked social security numbers wasn"t enough, Equifax said that criminals also accessed credit card numbers for approximately 209,000 U.S. consumers, and certain dispute documents with personal identifying information for approximately 182,000 U.S. consumers. But wait, there"s more: the company also identified unauthorized access to limited personal information for certain UK and Canadian residents.


The good news, is that according to Equifax, "this issue has been contained." The bad news is that, well, as many as 143 million social security numbers have been hacked. So no, it"s not contained.


“This is clearly a disappointing event for our company, and one that strikes at the heart of who we are and what we do,” Equifax Chief Executive Richard Smith said in prepared remarks. “I apologize to consumers and our business customers for the concern and frustration this causes.”


In a Q&A posted on the company"s website, the management team revealed what"s really important with the following question and answer:





Does this cybersecurity incident impact your capital allocation priorities going forward?



Our capital allocation priorities are unchanged at this time. As we have previously indicated, our investment
priorities in order of importance are: (1) internal investment; (2) dividends; (3) acquisition; and (4) share
repurchase. We do, however, expect to increase our capital spending in an effort to further accelerate IT
infrastructure, systems and data security and resiliency improvement actions
.



Oh, good, because a hack involving 143 million SSNs is one of those cases where capex probably should have taken precedence over stock buybacks.  Don"t worry though, because as it explains in the same quesionnaire, "Equifax remains committed to delivering on the long term financial model of 7-10% revenue growth and 11%- 14% growth in Adjusted EPS on average over a business cycle. Equifax’s long term financial model reflects our continuing fundamental ability to utilize our unique and differentiated data assets and leading analytical capability to deliver high value products and services to our customers."


Uhm, after this... what customers?


After falling as much as 12% in the after hours, EFX stock stabilized... then fell as much as 19%.



And now the best news: with Putin clearly behind this hack - as "all 17 intelligence agencies", WaPo and NYT will shortly "confirm" - the US economy is about to undergo a renaissance as hundreds of millions of (unsolicited) purchases prompt a golden age for US retailers while sending Amazon market cap into the $1 trillions...  even if the shipping address for said purchases happen to be small, frigid villages deep in the Russian taiga.


Full statement from Equifax here.


Update:


In appears there was a reason why EFX decided to hold on to the hacking news a little longer than seems reasonable. As Bloomberg reports, "three Equifax Inc. senior executives sold shares worth almost $1.8 million in the days after the company discovered a security breach that may have compromised information on about 143 million U.S. consumers."





The credit-reporting service said late Thursday in a statement that it discovered the intrusion on July 29. Regulatory filings show that three days later, Chief Financial Officer John Gamble sold shares worth $946,374 and Joseph Loughran, president of U.S. information solutions, exercised options to dispose of stock worth $584,099. Rodolfo Ploder, president of workforce solutions, sold $250,458 of stock on Aug. 2. None of the filings lists the transactions as being part of 10b5-1 pre-scheduled trading plans.



Surely, it was all purely a coincidence, even though had they waited until today, their proceeds would be well over 10% lower...

Monday, August 7, 2017

Where Snowden Failed, THIS Won't

By Chris at www.CapitalistExploits.at


When in 2013 Ed Snowden revealed to Joe Sixpack that his data was indeed being hacked and intercepted, not by crazy vodka swilling Ivan in Novgorod but by team America, there was the sort of surprise and outrage that comes with finding your 5-year old just wiped snot across your brand new leather sofa. A lot of yelling and screaming, limbs flailing, and a decent level of embarrassment for Johnny Snotnose, who in this instance was the NSA.


Less than 12 months later, all was forgotten. In the end nobody gave an isht.


In the ghettos of social media the Kardashians were calling and "Hey look, did you know there are pornos on the Internet with woman and farm animals?"


Joe Sixpack doesn"t care about the fact that his photos are accessible, even the naughty ones. Indeed almost every app downloaded today requests permission to breach that gap. Joe doesn"t care about his contacts list being breached. He clicks the "Sure, rape me" "Accept Permissions" button with glee, eager to get the download finished so that he can start sharing photos of what"s on his dinner plate with the whole world because... well, actually I have no idea.


It"s insane to me. Sadly the hoi-polloi spend more time looking at Joe"s dinner choice than reading the fine print on the permissions they"ve just granted to the apps downloaded.


You"d be forgiven for thinking that a goldfish-like memory could be to blame. I certainly thought people would care but obviously I was wrong because ever since then we"ve had more reasons to be outraged over real problems of this nature than you could shake a stick at.


Since Snowden, Wikileaks have provided an absolute deluge of additional fodder in this space. What"s happened?


Nothing! Nobody cares.


Just yesterday we were alerted to "Dumbo" a CIA project.



Try finding anything on the MSM about it and it"s like searching for a Texan cattle farmer at a vegan food festival.


Sure, we know the MSM are a complete joke but the masses still gather around the MSM drinking fountain for their daily dose of intellectual junk food. What did they have to say on the topic?


Instead of outrage and public humiliation showered on the perpetrators, we"re treated to snowflakes, daffodils, and bubble bath enthusiasts fighting the injustices perpetrated on Joey, who goes by the name Sheila due to his desire to don a frock and spend all his money rearranging his bits at the cosmetic surgeon.



There is, however, one thing that"s going to change it all...


Money.


Data security is like a seatbelt. It only matters when you park the beemer into a gum tree at speed.


People only protect data when that data is attached to economic value.


Ask anyone who"s bought, sold, and transacted in bitcoin what computer they use and not one will say a Windows machine.


The reasons for this are quite simple. That"d be like driving blindfolded at speed without a seatbelt, after chugging back a half a bottle of Glenfiddich.


This is just a first step in data security, and I use bitcoin as an example because typically the folks who have spent any time figuring it out know a thing or two about data security and cryptography.


Back to the masses, though.


Clearly when the wet-lipped psychopaths at some three letter agency are looking at Joe"s Facebook content or the naughty video he made last night with his girlfriend, Joe doesn"t much care. But when Joe begins storing real value and assets on his computer or smartphone and they get stolen, then, and only then, will Joe very quickly attach value to his data security. The learning curve promises to be steep.


That world is coming super fast as I mentioned previously.


Adoption of safety measures will come faster than Brangelina were picking up new ethnic babies from Nambabwia or wherever a few years back. When people realise that their livelihood is directly attached to their data security, then, and only then, will the begin to care.


I posted this chart previously in an article on the rise of cyber security:



Mark Andreessen famously stated that software is eating the world and by George, he was right. With all that software though comes a different set of problems. One of those problems, one even larger than John Prescott, is cyber security.


Now once again, I suspect Joe Sixpack won"t give an isht if someone can see that he"s turning on his heating system from his smartphone while on the way home. But when it gets disrupted and hacked and his phone automatically pays for a weekend at the Marriott in Bali without his knowledge, Joe will search for solutions in a blind panic.


When Joe begins getting paid via smart contracts and in value tokens attached to his workplace and it"s all done on a network, Joe will care a lot.


Economic incentives, both fear and greed, never change. What"s changing is our financial architecture and how we"re going to have to deal with that.


Fortunes will be made on the back of what promises to be an explosion in data security. Watch!


- Chris


"The great fear that I have is that nothing will change." — Edward Snowden


--------------------------------------


Liked this article? Then you"ll probably like my other missives on


this topic as well. Go here to access them (free, of course).


--------------------------------------

Wednesday, June 28, 2017

3 Out Of 4 US Energy Firms Were Hacked In 2016

Authored by Zainab Calcuttawala via OilPrice.com,



Hackers have targeted Russian oil giant Rosneft, the company said on Tuesday, just as Deloitte released a report on cyber-attacks targeting U.S. oil companies.


A “powerful hacker” attacked the company’s server in an assault that, according to TASS news agency, could be related to ongoing legal proceedings.


A Russian court recently froze assets of a holding company called Sistema as part of a suit lodged by Rosneft and Bashneft. The two companies are trying to recover $2.9 billion lost during Sistema’s 2014 restructuring.


Russian companies are not the only ones facing the new frontier in corporate espionage. U.S. consulting major Deloitte released a report on Monday that said American energy companies showed “limited strategic appreciation” for cyber-threats.



Analysts said three of every four U.S. oil and gas companies experienced a cyber-attack in 2016, but only a few firms said the computerized attacks posed a major security risk.





"Whether hackers use spyware targeting bidding data of fields, malware infecting production control systems, or denial of service that blocks the flow of information through control systems, they are becoming increasingly sophisticated and, specifically alarming, launching coordinated attacks on the industry," the report said.



Low crude prices have caused energy companies to focus their spending on operations that maximize value for shareholders, instead of investing in protective cyber security measures.



On the most vulnerable aspects of the oil and gas supply chain, Deloitte wrote:





“Among the upstream operations, development drilling and production have the highest cyber risk profiles; while seismic imaging has a relatively lower risk profile, the growing business need to digitize, e-store, and feed seismic data into other disciplines could raise its risk profile in the future.”


Thursday, June 15, 2017

"Active Shooter" Reported At Travis AFB: Public Ordered To Shelter In Place

In what appears could be day"s third shooting incident, moments ago NBC reported that officials on Wednesday are responding to a "real world security incident" at Travis Air Force Base in Fairfield. The Bay Area outlet reports that a  Facebook post around 3:30 p.m. PDT advised people to avoid the area so emergency responders can do their jobs. People were also urged to shelter in place and asked to lock doors and windows.




According to the Fairfield police twitter account, the facility"s main gate was closed,  and social media users reported an alleged active shooter situation.



As VOA"s Steven Herman notes, the situation involves an "Active Shooter"



The base is asking people to follow their updates on Facebook, where an official post from Travis Air Force Base officials says:


"Travis Air Force Base is currently responding to a real world security incident. More details will be released as they become available. The public is being asked to stay away from the base to ensure emergency responders can respond accordingly."



Scenes from an NBC-affiliate chopper showed people walking around at the base, a sprawling campus located in Solano County. Some people were holding hands as they were being escorted to safety, and police cars dotted the parking lot. The main gate at the base is closed and cars to the campus are being rerouted.


A live chopper feed is available at NBC Bay Area"s website.


Friday, May 12, 2017

"Massive" Ransomware Attack Goes Global: "This Is Huge"

We earlier reported in the disturbing fact that hospitals across the United Kingdom had gone dark due to a massive cyber-attack. The situation has got significantly worse as The BBC reports the ransomware attack has gone global.


Screenshots of a well known program that locks computers and demands a payment in Bitcoin have been shared online by parties claiming to be affected.



It is not yet clear whether the attacks are all connected. One cyber-security researcher tweeted that he had detected 36,000 instances of the ransomware, called WannaCry and variants of that name.





"This is huge," he said.



There have been reports of infections in the UK, US, China, Russia, Spain, Italy, Vietnam, Taiwan and others.


The BBB details a number of Spanish firms were among the apparent victims elsewhere in Europe.





Telecoms giant Telefonica said in a statement that it was aware of a "cybersecurity incident" but that clients and services had not been affected.



Power firm Iberdrola and utility provider Gas Natural were also reported to have suffered from the outbreak.



There were reports that staff at the firms were told to turn off their computers.



In Italy, one user shared images appearing to show a university computer lab with machines locked by the same program.



Bitcoin wallets seemingly associated with the ransomware were reported to have already started filling up with cash.





"This is a major cyber attack, impacting organisations across Europe at a scale I"ve never seen before," said security architect Kevin Beaumont.



According to security firm Check Point, the version of the ransomware that appeared today is a new variant.





"Even so, it"s spreading fast," said Aatish Pattni, head of threat prevention for northern Europe.



Several experts monitoring the situation have linked the attacks to vulnerabilities released by a group known as The Shadow Brokers, which recently claimed to have dumped hacking tools stolen from the NSA.

Thursday, February 2, 2017

Hackers Took Down D.C.'s CCTV System Ahead Of Trump Inauguration, Demanded Ransom

Submitted by Shepard Ambellas via Intellihub.com,


Officials and others unsure of what may have taken place during a massive citywide CCTV outage


Between the dates of Jan. 12 and Jan. 15, for about a 48-hour span, 70% of the CCTV cameras in Washington D.C. were rendered useless by hackers adding an element of uncertainty in regards to what may have taken place in and around D.C. just days before Donald Trump’s Inauguration.


Secret Service and city officials said that cyber attackers used ransomware to infect nearly 130 of 187 network storage devices linked to the city’s closed-circuit camera network, disallowing the storage of any incoming imagery data also while simultaneously requesting a ransom to be paid.


According to the city’s Chief Technology Officer official Archana Vemulapalli, the attack prompted city officials to willingly take the entire CCTV network offline by removing all related software, later forcing a reboot of each site independently, which left at least a 48-hour window of opportunity for criminal activity to take place without being recorded.


Although city officials claim that the hack appeared to be a “localized” extortion attempt, one must question what group or agency is actually responsible and what attackers intentions really were.


Vemulapalli said that on the day of Jan. 12 D.C. Metro Police noticed that four camera pods were not properly functioning and reported their findings to the technology office (OTCO), who later identified the devices to be infected with ransomware thus prompting a “citywide sweep,” as reported by the Washington Post.


Police Chief fill-in Peter Newsham addressed the hack publically and said that there was ‘no known significant impact’ as a result of the hack, but an active open investigation may suggest otherwise as it was admitted that city officials took the cameras offline themselves, ultimately creating a window of opportunity for illicit activity to occur undetected which also dovetails with the stand down ordered on police body cameras during the Inauguration, as reported by Intellihub on Jan. 18.


Furthermore, a report by TendMicro.com details how “Ransomware is a type of malware that prevents or limits users from accessing their system, either by locking the system’s screen or by locking the users’ files unless a ransom is paid. More modern ransomware families, collectively categorized as crypto-ransomware, encrypt certain file types on infected systems and forces users to pay the ransom through certain online payment methods to get a decrypt key.” Additionally, ant to point out that ransomware prices can be set to any amount and are often requested in cryptocurrencies such as Bitcoin.


1RedDrop.com reports:





The most alarming part about all this is that ransomware is now being sold under the ransomware-as-a-service model, similar to a lot of cloud computing offerings. Under this model, ransomware can be purchased and deployed even by people with no hacking experience. The buyer then commits to give the seller a percentage of the “take”, usually set at 40%.



One of the most active ransomeware groups today is Cerber, which actually offers a “ransomware for dummies” type of package that provides the buyer with all the resources they need. That makes Cerber potentially far more dangerous than any other hacking group, including Locky, which operates with just one person, or threat actor, and doesn’t sell or share its methods with anyone.



The Herjavec Group published a report titled “Hackerpocalypse: A Cybercrime Revelation” which maintains that by the year 2021 “cybercrime will cost the world in excess of $6 trillion annually” and is growing rapidly.


The report mentions how “Cybersecurity Ventures predicts global annual cybercrime costs will grow from $3 trillion in 2015 to $6 trillion by 2021, which includes damage and destruction of data, stolen money, lost productivity, theft of intellectual property, theft of personal and financial data, embezzlement, fraud, post-attack disruption to the normal course of business, forensic investigation, restoration and deletion of hacked data and systems, and reputational harm.” All of which will create a vast market for individuals, corporations, and governments to defend against cyber crime which is “projected to exceed $1 trillion over the next five years.”


D.C. authorities are currently investigating the matter and all ransomware has been removed from the entire system.


h/t @Tabertronic