Monday, October 13, 2014

Malware Based Credit Card Breach at Kmart

Sears Holding Co. late Friday said it recently discovered that point-of-sale registers at its Kmart stores were compromised by malicious software that stole customer credit and debit card information. The company says it has removed the malware from store registers and contained the breach, but that the investigation is ongoing.
“Yesterday our IT teams detected that our Kmart payment data systems had been breached,” said Chris Brathwaite, spokesman for Sears. “They immediately launched a full investigation working with a leading IT security firm. Our investigation so far indicates that the breach started in early September.”
According to those investigators, Brathwaite said, “our systems were infected with a form of malware that was currently undetectable by anti-malware systems. Our IT teams quickly removed that malware, however we do believe that debit and credit card numbers have been compromised.”
Brathwaite stressed that the data stolen included only “track 2″ data from customer credit and debit cards, and did not include customer names, email address, physical address, Social Security numbers, PINs or any other sensitive information.
However, he acknowledged that the information stolen would allow thieves to create counterfeit copies of the stolen cards. So far, he said, Sears has no indication that the cards are yet being fraudulently used.
Sears said it has no indication that any Sears, Roebuck customers were impacted, and that the malware infected the payment data systems at Kmart stores only.
More on this developing story as updates become available. For now, see this notice on Kmart’s home page.


Thank you to Brian Krebs for keeping us informed on all of these breaches....

Wednesday, September 24, 2014

Some Tips to Protect against Identity Theft

1. Do not sign the back of your credit cards. Instead put "PHOTO ID REQUIRED"; although merchants and their employees are still hit-and-miss on actually checking that ID, more of them are paying attention.
1.     2. When you order your checks, don't list any telephone number. You can always write it on the check at the time of the transaction. If you have a PO Box, use that instead of your home address or your work address.
2.     3. Be aware of which credit cards you carry now have embedded RFID chips because the information on one of those chips can be read surreptitiously by someone near you using a simple hand-held scanner.

3.     4.Place the contents of your wallet on a photocopy machine. Do both sides of each license, credit card, etc. You will know what you had in your wallet and all of the account numbers and phone numbers to call and cancel. Store    those photo copies in a secure place and refresh it when you change cards.

Tuesday, September 23, 2014

10 tips for spotting a phishing email


Phishing emails insinuate themselves into inboxes year-round, but the holidays bring out a rash of new scams. Help your users spot "fishy" emails.  Every day countless phishing emails are sent to unsuspecting victims all over the world. While some of these messages are so outlandish that they are obvious frauds, others can be a bit more convincing. So how do you tell the difference between a phishing message and a legitimate message? Unfortunately, there is no one single technique that works in every situation, but there are a number of different things that you can look for. This article lists ten.

1. The message contains a mismatched URL
One of the first things that I recommend checking in a suspicious email message is the integrity of any embedded URLs. Often times the URL in a phishing message will appear to be perfectly valid. However, if you hover your mouse over top of the URL, you will see the actual hyperlinked address (at least that’s how it works in Outlook). If the hyperlinked address is different from the address that is displayed. then the message is probably fraudulent or malicious.

2. URLs contain a misleading domain name
Often times people that launch phishing scams depend on their victims not knowing how the DNS naming structure for domains works. It is the last part of a domain name that is the most telling.

For example, the domain name info.brienposey.com would be a child domain of brienposey.com because brienposey.com appears at the end of the full domain name (on the right hand side). Conversely, brienposey.com.maliciousdomai.com would clearly not have originated from brienposey.com because the reference to brienposey.com is on the left side of the domain name, not the right.

I have seen this trick used countless times by phishing artists as a way of trying to convince victims that a message came from a company like Microsoft or Apple. The phishing artist simply creates a child domain bearing the name Microsoft, Apple, or whatever. The resulting domain name looks something like this: Microsoft.maliciousdomainname.com.

3. The message contains poor spelling and grammar
Whenever a large company sends out a message on behalf of the company as a whole, the message is usually reviewed for spelling, grammar, legality, and a number of other things. As such, if a message is filled with poor grammar or spelling mistakes it probably didn’t come from a major corporation’s legal department.
To give you a rather amusing example, I received an email message a few weeks ago that was supposedly from one of the large real estate companies. However, the body of the email merely said, “Me buy house fast”. Obviously, that email was not legit.
I’ll concede that this particular message was more of a spam than a phishing message, but the same basic principle applies to phishing emails as well.

4. The message asks for personal information
No matter how official an email message might look, it is always a bad sign if the message asks for personal information. Your bank doesn’t need you to send them your account number. They already know what it is. Similarly, a reputable company should never send an email asking for your password, credit card number, or the answer to a security question.

5. The offer seems too good to be true
There is an old saying that if something seems too good to be true, it probably is. That saying holds especially true for email messages. If you receive a message from someone unknown to you who is making big promises, then the message is probably a scam. After all, why would a Nigerian prince that you have never heard of contact you to help him smuggle money out of his country?

6. You didn’t initiate the action
Just yesterday I received an email message informing me that I had won the lottery!!!! The only problem is that I never bought a lottery ticket. If you get a message informing you that you have won a contest that you did not enter then you can bet that the message is a scam.

7. You are asked to send money to cover expenses
One telltale sign of a phishing E-mail is that you will eventually be asked for money. You might not get hit up for cash in the initial message, but sooner or later a phishing artist will likely ask for money to cover expenses, taxes, fees, or something like that. If that happens, then you can bet that it’s a scam.

8. The message makes unrealistic threats
Although most of the phishing scams seem to try to trick people into giving up cash or sensitive information by promising the victim instant riches, other phishing artists try to use intimidation to scare the victim into giving up information. If a message makes unrealistic threats then the message is probably a scam. Let me give you an example.

About ten years ago, I received a very official looking letter that was allegedly from US Bank. Everything in the letter seemed completely legit except for one thing. The letter said that my account had been compromised and that if I did not submit a form (which asked for my account number) along with two forms of picture ID then my account would be canceled and my assets seized.
I’m not a lawyer, but I’m pretty sure that it’s illegal for a bank to close your account and seize your assets simply because you didn’t respond to an email message.
The amusing part however, was that the only account that I had with US Bank was a car lease. There were no deposits to seize because I did not have a checking or savings account with the bank.

9. The message appears to be from a government agency
Phishing artists who want to use intimidation don’t always pose as a bank. Sometimes phishing artists will send messages claiming to have come from a law enforcement agency, the IRS, the FBI, or just about anything else that could scare the average law abiding citizen.
I can’t tell you how government agencies work outside of the United States. In America however, government agencies do not normally use email as the initial point of contact. That isn’t to say that law enforcement and other government agencies do not use email – they do. However, law enforcement agencies follow certain protocols. They do not engage in email-based extortion (at least that hasn’t been my experience).

10. Something just doesn’t look right

In Las Vegas casino security teams are taught to look for anything that JDLR (as they call it). The idea is that if something just doesn’t look right, then there is probably a good reason why. This same principle almost always applies to email messages. If you receive a message that seems suspicious then it is usually in your best interest to avoid acting on the message.

Monday, September 22, 2014

Fake Cell Phone Towers Across the US

Earlier this month, there were a bunch of stories about fake cell phone towers discovered around the US These seems to be IMSI catchers, like Harris Corporation's Stingray, and are used to capture location information and potentially phone calls, text messages, and smart-phone Internet traffic. A couple of days ago, the Washington Post ran a story about fake cell phone towers in politically interesting places around Washington DC. In both cases, researchers used security software that's part of CryptoPhone from the German company GSMK. And in both cases, we don't know who is running these fake cell phone towers. Is it the US government? A foreign government? Multiple foreign governments? Criminals?
This is the problem with building an infrastructure of surveillance: you can't regulate who gets to use it. The FBI has been protecting Stingray like it's an enormous secret, but it's not a secret anymore. We are all vulnerable to everyone because the NSA wanted us to be vulnerable to them.
We have one infrastructure. We can't choose a world where the US gets to spy and the Chinese don't. We get to choose a world where everyone can spy, or a world where no one can spy. We can be secure from everyone, or vulnerable to anyone. And I'm tired of us choosing surveillance over security.

Home Depot information

Home Depot said today that cyber criminals armed with custom-built malware stole an estimated 56 million debit and credit card numbers from its customers between April and September 2014. That disclosure officially makes the incident the largest retail card breach on record.
pwnddepot
The disclosure, the first real information about the damage from a data breach that was initially disclosed on Krebs Website, also sought to assure customers that the malware used in the breach has been eliminated from its U.S. and Canadian store networks.

“To protect customer data until the malware was eliminated, any terminals identified with malware were taken out of service, and the company quickly put in place other security enhancements,” the company said via press release (PDF). “The hackers’ method of entry has been closed off, the malware has been eliminated from the company’s systems, and the company has rolled out enhanced encryption of payment data to all U.S. stores.”
That “enhanced payment protection,” the company said, involves new payment security protection “that locks down payment data through enhanced encryption, which takes raw payment card information and scrambles it to make it unreadable and virtually useless to hackers.”

Saturday, August 23, 2014

Social Media Fatigue


One of the biggest push-backs I hear from people when I talk about how wonderful I think LinkedIn will be for business professionals is that they’re tired. They’re tired of joining a new social network. They’re tired of going through the dance of re-adding their friends and connections on yet another platform. They’re tired of having to think up even more content for yet another platform, after having finally committed to Facebook or Twitter or wherever else.

Social Media Fatigue
For a lot of people, the fatigue comes from that sense that they’re doing all the work, but not seeing the results. For another group, it’s that feeling that we've all done this before, so why do it again? For others, it’s just that we’re getting to the point where we feel maybe that we've shared all we can think of sharing, and we’re tired of rehashing the same old things over and over again.

Are any of these you?

Wake Up
Writing about social media can be boring. Writing about how to empower people, however, is pretty much always interesting. Telling people the same old thing on Linkedin that you’d have shared on Twitter or Facebook or Google + is about as boring as it sounds. Maybe try doing something new with the platform. I wonder why I’ve given myself permission to do so here.” Wake up. We can all find new ways to talk about social media by NOT TALKING ABOUT SOCIAL MEDIA. (Queue the Fight Club comments.) The thing is this: we’re using these tools to enable new connections. We’re using them to make different kinds of business happen. We’re using these tools to help causes that matters, and so much more.

It’s Your Choice
Look at your last 20 posts on any social network, and/or your blog. What are you talking about? Do you find yourself interesting? What else could you talk about instead? What would really change the nature of the conversation? How could you move from “talking about what everyone else is talking about” into talking about what’s next, what’s new, what’s personal, what’s helpful?

Make Your Own Media
These tools let you tell the stories you want to tell. They let you make something meaningful to you, to your business, to your pursuits. Nothing dictates how you use the tools to be your own media platform except your imagination and your ability to create. With that in mind, think up a few ways you might want to put these tools to use to tell the stories you want to tell.

If you’re a real estate professional, why not bring the neighborhoods you’re selling to life in stories and videos.
If you’re a freelance photographer, share the stories behind the photos.
If you’re a corporate blogger, tell us the passionate stories behind the big official posts.
If you’re writing just for your own passion, show us what you’re passionate about.
If you’re someone selling something, tell us the stories around that product or service.

The opportunity is for us to make something interesting and worthwhile, to be helpful, to empower others, to encourage and inspire others. If we’re fatigued, let’s all wake up.

I’ll do it too, okay?

4.5 Million Records Stolen from Community Health by Chinese Hackers

Another day, another multi-million record data breach: national healthcare chain Community Health Systems (CHS) says that about 4.5 million pieces of “non-medical patient identification data related to our physician practice” have been stolen by what are likely Chinese hackers.
The attacks occurred in April and June, and were disclosed in a regulatory filing, according toReuters. However, the stolen records stretch back beyond that timeframe, affecting patients who have used the company’s physicians' service over the past five years.
Franklin, Tenn.-based CHS operates 206 hospitals in 29 states. No medical/clinical information or credit card numbers were lifted, but the data included information that would be useful for identity theft: patient names, addresses, birth dates, telephone numbers and social security numbers from millions of individuals.
CHS is liable for personal patient information under the Health Insurance Portability and Accountability Act, better known as HIPAA, and has thus hired Mandiant to investigate the breach while it works with federal authorities on the heist. Mandiant said that the score appeared to make use of an unspecified, “highly sophisticated malware and technology.” That has since been eradicated from the system, and Mandiant said that it has put in place “other remediation efforts that are designed to protect against future intrusions of this type.”
And thanks to its cyber liability and privacy insurance, CHS said that the incident will likely not have a “material adverse effect on its business or financial results.”
However, that is likely a too-bullish comment, researchers said. “Community Health Systems leadership has now invested in what [they] believe has remediated the security breach at this time,” Kyle Kennedy, CTO of STEALTHbits Technologies, said in an email. “However; those remediation tools will not bring back customer confidence, brand and or market share lost due to this security breach occurring. I have said this before – remediation is always more expensive than prevention – how many more security breaches will the healthcare industry need to have published before preventative projects are green lighted proactively as opposed to reactively?”
According to Reuters, Mandiant and federal officials told CHS that the people believed to be responsible for the purloined information typically specialize in the theft of “valuable intellectual property, such as medical device and equipment development data.” This incident therefore marks a change in strategy—but one that makes sense given the relative ease of gaining access to such financially attractive information.
Kevin Mandia, Mandiant founder and COO at FireEye, told FOX Business recently that because people generally demand medical records be accessible quickly, security measures often take a backseat within healthcare organizations in general. It’s a concern that the federal government also noted back in April.
“This is another example of the ‘remediation is more expensive than prevention’ roller-coaster all organizations are embracing day-in and day-out on where to spend time, resources and money to secure their organization,” Kennedy said. “Knowing where the most valuable sensitive data and information lies within an organization is paramount to being able to present true business-risk calculation that an organization can react and invest in, to properly reduce risk.”
But yet, healthcare data – particularly in the US – has become highly prized by hackers, especially because the data can be “laundered” in a sense, and passed off as legitimately obtained.
“Data attacks are increasingly being carried out to gain access to information, which can then be used – and re-used again and again – sometimes even for marketing purposes,” David Gibson, vice president at the data governance specialist Varonis, told Infosecurity  earlier this summer. “The irony of this situation is that, although the initial breach is carried out by people operating on the wrong side of the law, once the data is passed along – usually generating money in the process – the recipients are usually unaware of its origins,” he said.
“Obviously, if someone presents you with an intimate database on several tens of thousands of people, you would be suspicious as to its origin, but if the data is only partially revealed, then it will be classed as normal – and permission-based – marketing information,” he added.
Data attacks are increasingly being carried out to gain access to information, which can then be used – and re-used again and again – sometimes even for marketing purposes

Wednesday, June 11, 2014

6 Tips to Prevent Social Engineering Attacks

6 Tips to Prevent Social Engineering Attacks

No matter how strong your network security is, end-users are often the weakest link in the security chain. Hackers exploit employee gullibility to resort to hacking techniques and phishing scams via social engineering tactics.

Here are 6 tips for IT admins to share with your employees so nobody falls victim to social engineering attacks and risk organizational security!

  1. DO NOT provide confidential information and even non-confidential data and credentials via email, chat messenger, phone or in person to unknown or suspicious sources.
  2. If you are following a link from an email or an unknown site, double check the URL's target domain carefully before opening it. If it looks fishy, it probably is!
  3. Look for misspelled words, @ signs (that indicate a redirect), and suspicious sub-domains.
  4. If it is insecure and looks really suspicious, run a quick online diagnostics test to check if the website is associated with any scams, or listed in any online blacklists.
  5. Do not follow nested links as they might be advanced hacking techniques to gradually lead you to a malicious site.
  6. Watch out for uninitiated or automatic downloads. It could be a malware piggybacking on to your system.

Wednesday, May 28, 2014

Be careful with cybercafé computers

Cybercafé’s offer a convenient way to use a networked computer when you are away from home or office. But be careful. It's impossible for an ordinary user to tell what the state of their security might be. Since anyone can use them for anything, they have probably been exposed to viruses, worms, Trojans, keyloggers, and other nasty malware. Should you use them at all? They're okay for casual web browsing, but they're NOT okay for connecting to your email, which may contain personal information; to any secure system, like the network or server at your office, bank or credit union; or for shopping online.

A perfect example is a current co-worker who went to the local Starbucks for his morning coffee. He opened up his mobile device and connected to the free Wi-Fi. Now this in itself was not a bad thing but what happens next is the issue. He logged onto his Wells Fargo account. Made a few inquiries and transactions and logged out of his session. A couple of days later he was notified of a compromise on his Wells Fargo account. Alas, he was the victim of cyber theft.
This co-worker has now spent the last two weeks working with the fraud group to get his account moved over to a new account. I don’t feel bad for the co-worker only because he is blaming Wells Fargo for all the complications in getting his account back up and running.  Wells needs to follow protocol. Being a large bank different departments are scattered across multiple call centers throughout the country. Yes it is frustrating for the consumer but the bigger issue here is that the co-worker decided to connect to a public Wi-Fi and conduct personal business.

The moral of this story is, you never know who is watching. Hackers are everywhere. It’s ok to connect to the free Wi-Fi at a hotel, coffee shop etc but please do not conduct any personal or confidential business. You never know who will be watching.

Have a safe day.

JMS

Monday, May 5, 2014

Windows XP based ATMs could be hacker’s paradise

Windows XP based ATMs could be hacker’s paradise

A recent study shows that 90% of American banks ATMs still run Windows XP or even worse Windows CE. Microsoft has discontinued support of XP as of April 8, 2014. What could this mean for the banking and finance industry? The main concern across the board is security, as hackers could soon have an unmonitored forum, putting data and end users at risk.

Some major banks are cutting deals with Microsoft to extend life support for their Windows XP machines while they replace their fleet of ATMs, according to CNN, but replacing ATM operating systems is a major undertaking. There are over 200 thousand ATMs in the United States, according to Retail Banking Research in London. The labor required to upgrade software, or even replace the entire system inside an ATM, could cost anywhere between $1000 and $3500 apiece.

After April 8, bank customers might be less concerned to use nondescript ATM found in malls, bars and small convenience stores. These 190,000 independently run kiosks make up the other half of the nation’s ATMs, and nearly all of them run and even older, simpler operating system which Microsoft still supports.

As a consumer you will not know what the operating system behind the scenes is. Ask questions of your bank to see what their plans are for upgrading. I have read where Dibold is working with financial institutions on upgrading systems. My one take away from this is, we all knew XP was going away. Microsoft provided us 18 months to prepare. Why didn’t these banks begin the process. Was it money or man power? Whatever the reason, for the next few months you will see more issues centered around ATMs and it will truly be a hacker’s paradise.

Be safe.

                

Sunday, April 27, 2014

Heartbleed follow-up

Overview of events
On Monday April 7th, a serious vulnerability was identified in one of the most popular implementations of the SSL protocol, called OpenSSL.  SSL is a very important security protocol used throughout the Internet. Not only does SSL encrypt your online communications, but it helps ensure you are connecting to legitimate websites when you do things like shop or bank online


What it does
The Heartbleed vulnerability allows a hacker to connect to a webserver and harvest sensitive information, which may include your login and password. If an attacker were able to harvest such information, they could use that information to log into any of your accounts using the same username and password. Most sites including Facebook, Yahoo, CNN were affected.


Steps you should take
There are several steps you can take to protect yourself. Not only will these steps help protect you against the Heartbleed vulnerability, but they will help protect you against many other attacks in the future

·         First, change your passwords on websites that you know were vulnerable and have patched the vulnerability, starting with your most important accounts first. If you do not know if a website was vulnerable, go ahead and change your password anyway. This is a great time to update your passwords and improve your online security.
·         Make sure you update your passwords you use strong, hard-to-guess passwords. In addition, if the website supports something called two-step verification, enable it. This is an additional step that helps make your online account more secure. Finally, if your password has personal questions, we recommend changing the answers.
·         Make sure you are using a separate, unique password for each of your online accounts. That way, even if one website is compromised, all of your other accounts will still be safe. Can’t remember all of your passwords? Congratulations, that means you are using strong passwords. We highly recommend you use this opportunity to start using a password manager that stores all of your passwords securely. These are great tools that can not only simplify your online activities, but help make them far more secure.
·         Do not forget your email clients. If your email client, such as Outlook or Apple Mail, is using SSL to connect to your mail server, you may need to change those passwords as well.

Have a safe day


Protecting Your Business From Your Remote Employees

A significant portion of your workforce is currently moving to perform full- or part-time remote work as a result of COVID-19.  As you modif...