Tag: Cyber

  • Thailand’s Online Scam Fallout: $273M Lost to Cyber Fraudsters in First Half of 2026

    Thailand’s Online Scam Fallout: $273M Lost to Cyber Fraudsters in First Half of 2026

    In the first half of 2026, Thai citizens suffered significant losses from online fraud schemes, with the losses estimated to be nearly 9 billion Thai Baht (US$273 million). The frauds were executed through more than 170,000 reported cases of online deceit.

    According to the latest data from the Thailand Consumers Council (TCC), Facebook was identified as the primary platform for these scams, accounting for over 61% of all recorded cases. The types of scams varied, and included fraudulent pages and accounts, deceptive investment advertisements, schemes involving the buying and selling of merchandise, and cases of impersonation of individuals or organizations.

    Online Scams: A Widespread Concern

    While Facebook reported more fraud cases, the losses via the LINE platform were equally significant, illustrating that the problem is not restricted to one platform. The issue penetrates the entire digital ecosystem, which includes advertising, conversations, solicitations, and monetary transfers.

    As the losses have escalated, the TCC, along with affected consumers, have sought legal redress against the online platforms and associated financial institutions involved in the cases where victims were manipulated into investing via online channels.

    The lawsuits against these financial institutions revolve around alleged breaches of service contracts and deposit contracts, as well as claims of infringements on consumer rights. These legal actions aim not only to seek reimbursement for the initial group of 10 victims but also to tackle the broader issue of the level of responsibility digital platforms and associated service providers should shoulder for consumer safety.

    Legal Challenges and Future Measures

    There have been several challenges in the legal recourse process as some defendants have requested additional time to submit their defense statements. Others have leveraged their legal right to appeal on jurisdictional grounds, arguing the case does not constitute a consumer case.

    The TCC plans to continue pursuing these cases to ensure service providers take responsibility and establish enduring safeguards for consumer protection. The council emphasized that the scams extend beyond the creation of fake pages or accounts, pointing out that ‘mule’ accounts also serve as a key tool for swiftly transferring victims’ money.

    Plans are being developed to establish criteria for listing ‘mule accounts’ through collaboration between the Ministry of Digital Economy and Society, the Bank of Thailand, the Anti-Money Laundering Office, and the Thai Bankers’ Association. The central aspect of this plan is real-time data sharing among banks, a move that could lead to immediate suspension of accounts linked to fraudulent financial activities across all banks.

    Questions & Answers

    What is the estimated amount lost to online scams in the first half of 2026 in Thailand?

    The estimated loss is nearly 9 billion Thai Baht (US$273 million).

    Which platform recorded the highest number of scam cases according to the Thailand Consumers Council (TCC)?

    Facebook was identified as the primary platform for scams, accounting for over 61% of all cases.

    What measures are being taken to address this issue?

    Plans include pursuing lawsuits against online platforms and financial institutions implicated in scams, and initiating real-time data sharing among banks to quickly identify and suspend accounts linked to fraudulent financial activities.

  • HPE Partners with Chunghwa Telecom: Boosting Cyber Resilience with Innovative Disaster Recovery Center in Taiwan

    HPE Partners with Chunghwa Telecom: Boosting Cyber Resilience with Innovative Disaster Recovery Center in Taiwan

    Hewlett Packard Enterprise (HPE) and Chunghwa Telecom’s Enterprise Business Group have recently revealed their plans to establish an international disaster recovery (DR) center in Taiwan. The alliance aims to reinforce cyber resilience and data protection for local companies.

    A Cyber Resilience Vault for Taiwan

    The upcoming DR center will leverage HPE’s Cyber Resilience Vault, incorporating sophisticated ransomware protection and a blend of cyber and disaster recovery technologies. The proposed solution aims to support Taiwanese businesses in setting up a global off-site backup system with second-level Recovery Point Objectives (RPO) and minute-level Recovery Time Objectives (RTO). Furthermore, it promises Continuous Data Protection (CDP) for faster recovery and enhanced defense against ransomware attacks.

    This move comes amidst growing apprehensions about ransomware and data disruption. Recent studies show that organizations globally face an average of 4.2 data disruption incidents annually, including at least one ransomware attack. Surprisingly, despite having backups, 48% of organizations opt to pay ransoms to expedite recovery or limit data loss. Yet, only 20% manage to fully recover their data.

    Addressing Ransomware Attacks and Data Loss

    Jon Wang, HPE’s Managing Director of Taiwan and Hong Kong, commented on the initiative. He highlighted that the HPE Cyber Resilience Vault, integrated with Chunghwa Telecom’s Internet Data Center services, would enable businesses to recover swiftly, decrease downtime, and restore lost data within seconds, thus ensuring full protection and backup of confidential information.

    Pen-Yuang Chang, General Manager of Chunghwa Telecom Enterprise Business Group, emphasized the importance of preventing significant business damage from ransomware attacks. He stated that their collaboration with HPE will allow local businesses to implement extensive disaster recovery mechanisms, thereby boosting their cyber resilience and international competitiveness.

    Through this partnership, Chunghwa Telecom plans to offer this new disaster recovery capability via its Internet Data Center (IDC) Value-Added Services – Equipment Subscription Service. Customers will have the opportunity to deploy protected virtual machines with enterprise-grade reliability, back up mission-critical workloads to Chunghwa Telecom’s robust IDC facilities, and conduct regular disaster recovery drills to validate readiness. The operator also intends to introduce a Disaster Recovery as a Service (DRaaS) model, priced according to the number of protected virtual machines, offering customers greater flexibility and scalability.

    A Proven Disaster Recovery Solution

    A prominent Taiwanese petrochemical manufacturer has already adopted this collaborative solution to secure sensitive operational data. By duplicating critical plant information to Chunghwa Telecom’s data center and utilizing HPE’s continuous data protection, the company has reduced cybersecurity risk, decreased maintenance overhead, and improved confidence in meeting recovery objectives.

    On a technical note, HPE Cyber Resilience Vault integrates various HPE technologies including HPE Alletra Storage MP B10000, HPE ProLiant Compute servers, HPE Zerto disaster recovery software, and HPE Networking wired and wireless solutions. The platform creates an air-gapped, isolated data vault with immutable, FIPS-compliant storage. Its journal-based CDP tracks recovery checkpoints every five to ten seconds, enabling near-synchronous replication, second-level RPO, and minute-level RTO.

    The solution, deployed within Chunghwa Telecom’s IDC satellite data centers, is expected to significantly decrease recovery times and reduce data loss from hours to seconds. It will also speed up service restoration from days to minutes, whilst providing Taiwanese enterprises with a more robust foundation for cyber resilience amid an escalating threat landscape.

    Questions & Answers

    What is the primary goal of the HPE and Chunghwa Telecom partnership?

    The collaboration aims to establish an international disaster recovery center in Taiwan to strengthen cyber resilience and data protection for local enterprises.

    How does the HPE Cyber Resilience Vault benefit businesses?

    The HPE Cyber Resilience Vault enables businesses to swiftly recover from data loss, minimize downtime, and restore lost data within seconds, ensuring comprehensive protection and backup of confidential information.

    What specific services will Chunghwa Telecom offer through this collaboration?

    Chunghwa Telecom will offer the new disaster recovery capability via its Internet Data Center (IDC) Value-Added Services – Equipment Subscription Service. This will allow customers to deploy virtual machines with enterprise-grade reliability, back up mission-critical workloads, and conduct regular disaster recovery drills. They also plan to introduce a Disaster Recovery as a Service (DRaaS) model.

  • Cyberattack Paralyzes Production At Asahi Group: Operations And Timeline In Question

    Cyberattack Paralyzes Production At Asahi Group: Operations And Timeline In Question

    Asahi Group Holdings, a prominent Japanese beer and beverage corporation, has been unable to restart production at its domestic factories following a cyberattack, according to a company spokesperson. The timeline for resuming operations remains uncertain.

    Production Halted

    The company has a network of 30 manufacturing facilities throughout Japan, all engaged in the production of beer, beverages, and food products. Currently, the company is conducting a thorough investigation to determine if all of its plants have ceased production, the spokesperson revealed.

    Operations Suspended

    Asahi Group Holdings, the company behind popular brands such as Asahi Super Dry Beer, Nikka Whisky, and Mitsuya Cider, announced that due to a system outage caused by a cyberattack, its Japanese group companies have temporarily suspended operations. This includes tasks like order processing, shipping, and call centre functions. Fortunately, the company has confirmed that there has been no leakage of personal information as a result of the cyberattack.

    Questions & Answers

    What impact has the cyberattack had on Asahi Group?
    The cyberattack has forced Asahi Group to halt production at its domestic factories, suspend order processing, shipping, and call centre operations. The company is currently unable to predict when normal operations can be resumed.

    Has all production been stopped at Asahi Group’s plants?
    The company is investigating to establish whether all its 30 factories in Japan have suspended production in the aftermath of the cyberattack.

    Was any personal information leaked as a result of the attack?
    According to the company’s spokesperson, no personal information has been leaked due to the cyberattack.

  • Client data exposed in Gucci, Balenciaga and McQueen cyberattack

    Client data exposed in Gucci, Balenciaga and McQueen cyberattack

    Luxury brands Gucci, Balenciaga, and Alexander McQueen have fallen victim to a cyber attack, leading to the potential theft of millions of customer’s private details. The assault targeted Kering, the French corporation that owns these prestigious labels.

    Kering recognized and confirmed the breach but did not publicly name the brands impacted. In a statement made in June, they reported that “an unauthorized third party momentarily gained access to our systems and accessed limited customer data from some of our Houses”.

    This incident is not an isolated event but seems to be part of a broader trend impacting luxury brands and retailers throughout the year. Other brands that suffered similar breaches include Cartier, owned by Richemont, and labels under LVMH. In July, a data leak affecting approximately 419,000 customers at LVMH’s Louis Vuitton was being investigated by Hong Kong’s privacy watchdog.

    The stolen customer data reportedly includes names, email addresses, phone numbers, addresses, and the total amounts spent at the brands’ stores. Notably, Kering has reassured that no financial information, such as credit card or bank account numbers, was stolen during the attack.

    The hackers, referring to themselves as “Shiny Hunters,” allege to have data associated with 7.4 million unique email addresses.

    In response to the breach, Kering stated that its brands promptly reported the incident to the relevant authorities and notified customers in accordance with local regulations. However, Kering did not provide a response when questioned about the countries impacted by the cyber attack.

    Questions & Answers

    What brands were affected by the cyber attack?
    The affected brands include luxury labels Gucci, Balenciaga, and Alexander McQueen, all owned by French parent company Kering.

    What kind of customer information was stolen during the breach?
    Reportedly, the stolen client data includes names, email addresses, phone numbers, addresses and the total amounts spent at the brands’ stores. However, no financial information like credit card or bank account numbers were compromised.

    How did Kering respond to the cyber attack?
    Kering reported that its brands immediately disclosed the breach to relevant authorities and notified customers as per local regulations. However, they did not comment on the specific countries affected by the attack.

  • Globe Business and Blackpanda Unveil Budget-Friendly AI Cybersecurity Solutions for Philippine Enterprises

    Globe Business and Blackpanda Unveil Budget-Friendly AI Cybersecurity Solutions for Philippine Enterprises

    Globe Business has joined forces with Blackpanda, the region’s premier cyber incident response specialist, to provide affordable, enterprise-grade cybersecurity solutions tailored for businesses in the Philippines. Their innovative partnership promises a fixed-cost incident response and digital forensics service designed to help organizations promptly detect, contain, and recover from cyberattacks. This offering, fondly dubbed a “cyber fire department,” includes continuous vulnerability scanning, dark web monitoring, and seamless access to cyber insurance, making it an invaluable resource for local enterprises aiming to neutralize digital threats swiftly.

    KD Dizon, Head of Globe Business, emphasizes the growing urgency of the situation:

    Cyber threats remain a pressing challenge for businesses of all sizes, and AI is amplifying both the sophistication and frequency of these attacks. Our partnership with Blackpanda makes immediate, expert incident response—once prohibitively expensive—accessible to organizations across the Philippines.

    The Rising Tide of Cyber Risks in Southeast Asia

    The threat landscape is escalating in the Philippines and Southeast Asia, fueled by inadequate cybersecurity preparedness, AI-driven vulnerabilities, and skyrocketing costs of attacks. Globe underscores the necessity for robust threat intelligence, skilled incident responders, collaboration, and the latest security technologies. In 2024 alone, 85% of Philippine firms reported AI-related attacks, while 84% faced supply chain breaches, with almost a third unable to detect these intrusions. The cost of breaches across ASEAN averaged an alarming USD 3.23 million last year, with the financial services sector suffering the most, racking up an average cost of USD 5.57 million. The region also witnessed a staggering 29% uptick in cyber incidents, accompanied by a rise in ransomware and phishing activities.

    Transforming Cybersecurity Accessibility with IR-1

    Historically, enterprise-level incident response services have been financially out of reach for many businesses, with hourly rates soaring to USD 500 and annual retainers typically ranging from USD 25,000 to USD 100,000. Blackpanda aims to disrupt this trend with its flagship solution, IR-1, which blends incident response, continuous vulnerability scanning, and cyber insurance support into a budget-friendly subscription model. This transformative approach lowers the financial barriers for firms, enhancing their operational resilience and cybersecurity posture.

    Gene Yu, CEO of Blackpanda, shares the vision behind this collaboration:

    Globe’s reach and trust in the Philippine market make them the ideal partner to scale our IR-1 cyber emergency subscriptions nationwide. By delivering always-on access to expert response through Globe’s trusted network, we’re ensuring that a small manufacturer in Cebu or a growing fintech in Makati can access the same level of cyber emergency support as multinational corporations.

    The IR-1 solution boasts automated access to cyber insurance with coverage up to USD 10 million, continuous monitoring for potential risks, and elite response teams located across Asia—Manila, Singapore, Tokyo, and Hong Kong. Unlike its competitors, IR-1 supports any endpoint detection and response (EDR) solution, offering enterprises maximum freedom and flexibility.

    Questions & Answers

    How will the partnership between Globe Business and Blackpanda benefit Filipino companies?
    The partnership aims to provide accessible, enterprise-grade cybersecurity solutions to Filipino businesses, allowing them to swiftly detect and respond to cyber threats without the prohibitive costs historically associated with such services.

    What are the key features of the IR-1 solution offered by Blackpanda?
    IR-1 includes automated access to cyber insurance, continuous attack surface monitoring, dark web scanning, and support for any endpoint detection and response solution, ensuring comprehensive coverage and flexibility for businesses.

    What trends are driving the increase in cyber incidents in Southeast Asia?
    The rise in cyber incidents is largely attributed to low cybersecurity readiness, the growing number of AI-related threats, and the increasing costs of attacks, necessitating urgent action and investment in cybersecurity measures.

  • Cyber Insurance Market Surges 7% to Reach $15 Billion by 2024: What’s Driving This Growth?

    Cyber Insurance Market Surges 7% to Reach $15 Billion by 2024: What’s Driving This Growth?

    The global cyber insurance market is displaying a mixed bag of results in 2024, achieving a 7% growth to nearly $15 billion in premiums. However, this upward trajectory comes with a caveat: the momentum has decelerated for a second consecutive year, according to a recent analysis by Moody’s Ratings.

    Regional Disparities in Growth

    Interestingly, while growth thrives in regions outside the United States, the American sector is seeing a decline, with premiums dropping 1.5% to $7.1 billion, following a slight dip of 0.7% in 2023. Despite these challenges, the sector has maintained its profitability, demonstrating combined ratios of 79% for primary cyber coverage and 84% for excess coverage.

    Ransomware: The Persistent Threat

    Ransomware attacks continue to dominate the claims landscape, although the total ransom payments slipped by 35% last year to a still-staggering $814 million. Such a significant drop raises eyebrows: are cybercriminals still plotting, or is the market growing more resilient?

    Competitive Landscape Pushes Rates Down

    The rising competition within the sector has led to a reduction in prices. Marsh’s data reveals that U.S. cyber insurance rates fell by 7% during the first half of 2025, while the UK experienced a sharp decline of nearly 19%. In response to this dynamic environment, some insurers are pivoting their strategies, transitioning from quota share to excess-of-loss reinsurance, and exploring innovative options such as catastrophe bonds and industry loss warranties to mitigate systemic risks.

    The Future: Potential Beckons

    Moody’s highlights that while penetration among large corporations remains strong, only about 10% of small and medium-sized enterprises (SMEs) are investing in cyber coverage. This suggests a vast pool of untapped potential that could contribute to future growth. Indeed, Allianz’s 2025 Risk Barometer ranks cyber incidents as the top global risk for the fourth year running, signaling that the appetite for cyber insurance could increase as awareness grows.

    Questions & Answers

    Which regions are driving growth in the cyber insurance market?
    Growth is particularly strong in non-US regions, while the US is experiencing a downturn in premium volumes.

    What is contributing to the decrease in ransom payments?
    The total ransom payments fell by 35% last year to $814 million, indicating a possible shift in the strategies employed by cybercriminals or improvements in defenses.

    What does the future hold for the cyber insurance sector?
    Long-term growth prospects remain robust, especially with only 10% of SMEs currently covered, suggesting significant room for expansion as cyber threats continue to evolve.

  • Telin Teams Up with Digital Realty Bersama to Boost Global Data Center Connectivity and Services

    Telin Teams Up with Digital Realty Bersama to Boost Global Data Center Connectivity and Services

    PT Telekomunikasi Indonesia International (Telin), a subsidiary of Telkom Indonesia that focuses on international telecommunications, has taken a significant leap forward by signing a Memorandum of Understanding (MoU) with Digital Realty Bersama, one of Indonesia’s foremost digital infrastructure providers. This partnership, unveiled at BATIC 2025, aims to enhance data center interconnection and bolster the rapidly evolving digital landscape of the country.

    Connecting Indonesia to the Digital World

    This collaboration promises to leverage Telin’s extensive global network alongside Digital Realty Bersama’s cutting-edge data center platform, ultimately delivering enhanced connectivity for industry players in Indonesia and improving access to international markets.

    Azmal Yahya, Chief of Product at Telin, highlighted the importance of this agreement, stating, “This partnership represents a significant milestone for Telin as we work to deliver more comprehensive and reliable interconnection solutions for our customers. With Digital Realty Bersama’s advanced platform supporting us, we are confident this collaboration will accelerate digital growth for enterprises both in Indonesia and beyond.”

    Opening New Doors for Businesses

    Andha Yudha Permana, Business and Commercial Director of Digital Realty Bersama, echoed this sentiment, expressing enthusiasm about the partnership. “We are honored to partner with Telin, a leading provider of international connectivity. Together, we will offer our customers seamless access to global markets with high speed and reliability, strengthening Indonesia’s role as a crucial digital hub connected to the world. This collaboration will unlock new opportunities for Indonesian businesses to compete on a global scale, facilitating direct and secure international data traffic.”

    A Strategic Leap Forward

    The MoU signifies the commencement of a strategic partnership, with a mutual commitment to innovating services, enhancing interconnection capabilities, and reinforcing Indonesia’s position in the global digital economy. As the nation strides forward, it might just transform into the tech-savvy giant of Southeast Asia that even the most pessimistic pundit couldn’t help but notice.

    Questions & Answers

    What is the primary objective of the MoU between Telin and Digital Realty Bersama?
    The partnership aims to strengthen data center interconnection and support Indonesia’s expanding digital ecosystem, enhancing connectivity and market access for local businesses.

    How does this collaboration benefit Indonesian businesses?
    The collaboration offers Indonesian businesses enhanced access to global markets through improved connectivity, enabling them to compete more effectively on an international scale.

    What role does the partnership play in Indonesia’s digital landscape?
    It is pivotal in reinforcing Indonesia’s position as a significant digital hub in Southeast Asia, unlocking new opportunities for innovation and secure international data exchanges.

  • Cybercriminals Target Organizations with Phony App to Steal Data and Demand Ransoms

    Cybercriminals Target Organizations with Phony App to Steal Data and Demand Ransoms

    In a worrying trend, hackers are escalating their tactics by targeting organizations across Europe and the Americas, employing social engineering to install a modified version of a legitimate data import tool. This seemingly innocuous application opens the door for attackers to steal sensitive information, gain access to cloud services, and navigate through networks, escalating their assaults and demands for extortion.

    Cybercriminals Craft Deceptive Strategies

    Tracking this malicious activity is the threat group known as UNC6040, which makes use of voice phishing, or vishing, to trick unsuspecting employees into downloading the malicious app. Designed to closely imitate a familiar enterprise tool, this rogue application secures an alarming level of access to corporate environments. Once in, it enables the exfiltration of critical data and compromises system integrity with ease.

    Consequences and Scope of the Attack

    The Google Threat Intelligence Group has reported that approximately 20 organizations have fallen victim to these attacks, some enduring confirmed data breaches that threaten their operational security. This ongoing operation is linked to a cybercriminal ecosystem referred to as ‘The Com,’ which engages in various illegal activities, underscoring the complex and interconnected nature of modern cybersecurity threats.

    The Human Element in Cybersecurity

    Experts warn that the root of this threat lies not in software vulnerabilities but in the effectiveness of social engineering tactics. This serves as a crucial reminder of the importance of heightened employee awareness and the implementation of robust controls over app authorization. It turns out that even the most sophisticated cybersecurity measures can be bypassed with a simple phone call — it’s a lesson every organization should take to heart.

    Questions & Answers

    What tactics are hackers using in these attacks?
    Hackers are using voice phishing to deceive employees into downloading a malicious version of a legitimate data import tool, allowing unauthorized access to sensitive data.

    How many organizations have been affected by these cyber attacks?
    Approximately 20 organizations have been affected, with some experiencing confirmed data breaches as a result.

    What steps should organizations take to mitigate such attacks?
    Organizations should focus on improving employee awareness regarding social engineering tactics and enforce stricter controls on app authorization to prevent unauthorized access.

  • UBS Slows Digitalization After Significant Cyberattack

    UBS Slows Digitalization After Significant Cyberattack

    The bank engaged in an extensive review after being one of the banks affected by a Russian ransomware attack early in the year. The first casualty? Going digital.

    It is a small section in UBS’s full second-quarter report, but a telling one. Buried on page 41 is a small but substantial tidbit. The bank has just finished a post-incident review after January’s ION XTP ransomware attack.

    To jog people’s memory given the constant diet of entirely unfamiliar names and acronyms from the criminal fringes of cyberspace, ION XTP is the one with derivatives. It paralyzed the trading operations at several banks, although you wouldn’t know it from ION itself, characterizing the entire thing as a cleared derivatives cyber event…contained to a specific environment.

    UBS had told us about it in its first quarter report, saying the event had disrupted its exchange-traded derivatives clearing activities, although it managed to restore them after 36 hours with workarounds.l

    If nothing else, it made waves and caused a great deal of anxiety. A senior US Treasury Department official weighed in with a virtual «keep moving…there is nothing to see here» exercise over the cyber assault from Russian ransomware gang LockBit, according to a report at the time.

    We’ve now arrived at the legendary financial institution post-incident review. A career killer to some and the unwelcome originator of dozens of findings and remedial actions for many others. UBS maintains it identified needed improvements to its framework and will «take actions» to enhance cyber-risk assessments and controls over third-party vendors.

    That’s unremarkable in most contexts, except this attack had very significant ramifications, a key one being that it seemingly chips away at a cherished cornerstone of UBS’s strategy under previous CEO Ralph Hamers.

    But don’t take my word for it. Let’s hear what the company says in its quarterly report.

    Although we are continuing our efforts regarding innovation and digitalization, to ensure there is the right focus during this initial period of integration we have reprioritized some UBS changes, the bank wrote.

    Turgid stuff indeed. You could make a case for switching a few clauses around for clarity. Still, it sounds pretty transparent and clear. I don’t know about you, but it doesn’t much so

  • PLDT, Smart Lauds Government’s New Cybercrime Lab

    PLDT, Smart Lauds Government’s New Cybercrime Lab

    Philippines’ major telecoms group, Smart and PLDT said it welcomes the country’s new Digital Forensics Platform and Laboratory launched by the Cybercrime Investigation and Coordinating Center, or ICC.

    The new facility aims to improve the government’s initiatives to fight cybercrime, especially, online sexual abuse and exploitation of children.

    Following the unveiling of this new laboratory, the group said that it has strengthened its cyber security systems as it continues its cooperation with the local government in fighting across the digital landscape.

    The new facility will help CICC to work closely with other law enforcement agencies in the country to conduct comprehensive digital and forensic investigations.

    The group’s Chief Information Security Officer, Angel Redoble, meanwhile stressed that they will continue to address these challenges in the cyberspace.

    “Children became more vulnerable to cyberattacks after the pandemic forced them to stay at home and get online to study and connect with friends, and cyber criminals have also been targeting them. We have fortified our cyber defenses and strengthened our coordination with the government to make the internet safer for kids.”

    According to PLDT and Smart, they have beefed up their efforts to support the government in its crackdown on online child abuse. By the end of May this year, it has blocked nearly 300,000 URLs linked to these criminal activities.

    The group has also collaborated with other private and public sectors in urging the country’s president to sign into to law the bill against online child sexual abuse before he steps down from office on June 30.

  • Instagram will try to hide “potentially harmful” content

    Instagram will try to hide “potentially harmful” content

    In the vast cyber jungle we call The Internet there are potential threats lurking in every dark corner, every thick bush. Now, dramatic preludes aside, there is a lot of bad content around the web – such as the pornography that spam bots were peddling on Instagram.

    The popular social network has been constantly testing new methods to filter potentially harmful content, and even halted the development of Instagram Kids, following recent backlash. Now the company has shared another slew of changes on its official blog, aimed to limit the visibility of potentially harmful content.

    Here’s a breakdown of all the changes:

    • Instagram will continue to remove content that goes against its Community Guideline, but now posts that may contain bullying or hate speech, or that may encourage violence, will be shown further down in Feed and Stories.
    • Instagram will down-rank potentially upsetting posts in your Feed based on your history of reporting content.
    • These changes only impact individual posts, not accounts overall. Instagram will also note the violators why their posts have been removed.

    Instagram already has algorithms in place to flag harmful content but now the company is targeting borderline posts and potential gray zones. “To understand if something may break our rules, we’ll look at things like if a caption is similar to a caption that previously broke our rules,” Instagram wrote in an update.

    The second bullet point in the changelog means that Instagram will try to predict the posts you’re likely to report and preemptively down-rank them in your Feed.

    It’s also worth noting that up until now Instagram algorithms have tried to hide harmful content from parts of the app visible to the public users, such as Explore. With the aforementioned changes in place, these posts will also be down-ranked for users following the account posting such content. The changes are already in effect, so be careful what you post, guys and girls!

  • China Tells Firms To Boost Cyber, Data Security Oversight On Connected Vehicles

    China Tells Firms To Boost Cyber, Data Security Oversight On Connected Vehicles

    China’s industry ministry published a notice on Thursday telling companies to step up cyber and data security oversight over connected vehicles, saying that security risks in the industry had become increasingly prominent.

    All relevant companies should establish data security management systems and regularly assess risks from network attacks, the Ministry of Industry and Information Technology said in a statement.

  • IronNet Cybersecurity adds new integrations to Collective Defense Platform

    IronNet Cybersecurity adds new integrations to Collective Defense Platform

    IronNet Cybersecurity, the leader in network detection and response and collective defense, announced new integrations with leading cloud, endpoint, and firewall platforms. These integrations enhance and expand the benefits of IronNet’s Collective Defense Platform for security operations teams.

    New capabilities in this release include integrations with:

    • Amazon Web Services (AWS): Adding new IronNet sensors that enable customers to leverage IronNet’s Collective Defense Platform to secure their AWS deployments.
    • Crowdstrike Falcon EDR: Enabling security analysts to seamlessly investigate threats detected by IronNet from the network to the host, and to contain compromised hosts.
    • Palo Alto Networks Strata Next-Generation Firewalls Native Response: Enabling security teams to generate firewall responses and stop threats detected by IronNet.
    • ZScaler Nanolog Streaming Service (NSS) Analysis: Enabling IronNet customers to apply IronNet’s IronDefenseⓇ NDR behavioral detection to HTTP/HTTPS logs.
    • Microsoft Office 365: Adding IronDefense behavioral detection of malicious login attacks targeting Microsoft’s productivity SaaS suite.

    In addition to these integrations, the new release includes:

    • New User & Entity Behavior Analytics (UEBA) to detect identity- and authentication-focused attack techniques.
    • Improved lateral movement and port-scanning detection.

    “The ability to correlate cloud, network, endpoint, and other security telemetry data into a richer, more complete picture of a risk-based event helps organizations more effectively evaluate and mitigate a threat. And that is the real value that network intelligence and threat analytics solutions like IronNet offer,” said Christopher Kissel, Research Director, Security & Trust Products, IDC. “IronNet’s additional capability to share information anonymously across a community of peers and enable security analysts to collaborate on threats is a noticeable differentiator in light of the rise of nation-state level cyber-attacks.”

    This expansion of IronNet’s capabilities continues the company’s momentum of growth in both technology and partnerships. David Lathrop, Vice President of the Utility Strategic Business Unit with Unlimited Technology, Inc., said, “IronNet’s latest release is exactly the kind of ecosystem support that helps us provide the unique, comprehensive cyber solutions we offer through the Enterprise Security Program Review.” Unlimited Technology is a founding partner, along with IronNet, DirectDefense, and Exero, of the ESPR, announced in January.

    “Empowering security teams and maximizing the effectiveness of their security investments against cyber threats targeting their enterprise, industry, or region is core to our Collective Defense mission,” said Don Closser, IronNet’s Chief Product Officer. “Together with our security ecosystem partners, IronNet can offer our customers a true, defense-in-depth approach that helps them reduce time to detection and scale up their ability to respond to cyber threats. This is especially important as factors like digital transformation and expanding supply chains are increasing the threat landscape exponentially.”

  • How Do Retailers Secure Online Businesses

    How Do Retailers Secure Online Businesses

    Retailers and shoppers are gearing up for holiday shopping as we are heading to the festive Christmas and Chinese New Year. There is a caveat though. With multiple COVID-19 outbreaks this year, the government announces social distancing measures for crowd control and people are advised to stay home. Shoppers go online to enjoy the seasonal sales and promotion deals.

    Since the first pandemic outbreak, the landscape of the retail industry has gone through massive changes. Retailers must quickly ramp up their e-commerce applications and online platform[1]. According a GlobalData research, e-commerce market in Hong Kong will grow at a compound annual growth rate of 9.9% by 2024 to reach US$29 billion[2].

    While the pandemic has fueled a new stay-at-home economy and unleashed the surging demand for online shopping, this has also attracted the attention of cybercriminals. Findings of a Barracuda report supports it with 72% of retail and catering businesses in APAC saying they see the necessity to accelerate digital transformation to ease the pains of traditional business model. Yet, security could be the major roadblock to their digital transformation agendas.

    The Barracuda survey also found that 45% of APAC retail and catering businesses have already had at least one data breach or cyber security incident since they shifted to remote working amid COVID-19. Fifty percent of them were concerned about unknown threats that will cause business disruption in the next 6 months. Within the industry, the chain apparel retailer Bossini was reported to be hit by Maze ransomware and experienced a data breach.

    So how can retailers minimize business disruptions and improve their ability to consistently serve customers in the rapid age of digital transformation? 

    eCommerce Requires Always-on Availability  

    Organizations working to develop a competitive advantage through omnichannel customer experiences cannot afford sluggish responses. With this COVID-19 crisis, we are all in unchartered waters. While consumers are going online more, the traffic patterns and spikes in demand can be quite unpredictable. Just like e-commerce infrastructure itself, web application security solutions need to seamlessly accommodate traffic volume. Perhaps even more importantly, they need to have Distributed Denial of Service (DDoS)[3] protection, as an unmitigated DDoS attack can block all traffic and quickly bring an e-commerce business to its knees.

    Today, retailers need to protect against sophisticated hackers that are very skilled at breaking into online stores and web applications. In addition, we are seeing a rise of malicious human-like bad bots targeting e-commerce sites that use sophisticated techniques such as credential stuffing[4] to quickly cause major damage.

    In mid-November, Barracuda researchers ran Barracuda Advanced Bot Protection in front of a test web application, and the number of bots they detected in just a few days was staggering, with millions of attacks coming in from thousands of distinct IP addresses. Cybercriminals use bots to run distributed denial of service (DDoS) attacks, make fraudulent purchases, and scan for vulnerabilities they can exploit. Retailers need to deploy web application security solutions that can protect against both sophisticated hackers and automated bot attacks.

    Payment Card Industry Data Security Standard (PCI-DSS) Compliance

    In e-commerce and digital retail, protecting your customers’ sensitive information is arguably the most important obligation. all companies that accept, process, store or transmit credit card information maintain a secure environment must comply to the PCI DSS, created by the major payment card brands and launched in September 2006, is a set of security standards[5].

    Non-compliance of the PCIDSS may result in fines, reputation damage or even lawsuits. To avoid these and improve trustworthiness, retailers must take the requirements seriously and compliance with PCI-DSS standards. For example, it is important to use a firewall that provides multiple layers of protection and automatic prevention of unknown malware, spyware, and ransomware. It also helps to certify and offers the highest level of encryption to prevent digital theft.

    Beware of Brand Impersonation

    “Brand impersonation” is designed to impersonate a company or a brand to trick their victims into responding and disclosing personal or otherwise sensitive information. It includes “service impersonation” and “brand hijacking”.

    “Service impersonation” is a type of phishing attack designed to impersonate a well-known company or commonly used business application. It is used in 47% of all spear phishing attacks. Cybercriminals can use this technique to steal personally identifiable information such as credit card and ID card numbers. “Brand hijacking”, on the other hand, occurs when an attacker sends emails with false, or spoofed, domain names that appear to be legitimate appears to use a company’s domain to impersonate a company or one of its employees.

    As we are expecting the shift to e-commerce continue to accelerate, retailers must take steps to secure business and customers data from reputational and financial damages at a time when they can least afford it. Ultimately, that is not an outcome that is good for business.Written by

    James Forbes-May, Vice President, Barracuda Networks Asia Pacific

    [1] https://www.weforum.org/agenda/2020/05/covid19-coronavirus-digital-economy-consumption-ecommerce-stay-at-home-online-education-streaming/

    [2] https://insideretail.asia/2020/07/20/covid-19-fuels-breakthrough-in-hong-kong-e-commerce/

    [3]https://www.barracuda.com/glossary/ddos?utm_source=blog&utm_medium=39697

    [4]https://blog.barracuda.com/2019/04/02/is-2019-the-year-credential-stuffing-dominates-the-threat-landscape/

    [5] https://www.pcicomplianceguide.org/faq/#1

  • Cyberattack-Prone Banks Risk Over Half of Profits in Singapore

    Cyberattack-Prone Banks Risk Over Half of Profits in Singapore

    Banks that lack measures to withstand cyberattacks risk up to 65 percent of their quarterly profits, according to a recent stress test study by the Monetary Authority of Singapore.

    Direct and indirect impact from cyberattacks against banks is estimated to cause losses of 35-65 percent and 20-50 percent of quarterly profits, respectively. According to the study, profit declines are attributable to reputational impact, funds were stolen, legal charges and marketing expenses.

    The stress tests revealed likely vulnerabilities from theft and disruption-related cyberattacks. Examples of theft-related attacks include hacking of ATMs to dispense cash and bank payment systems. Disruption-related impact includes denial-of-service (DoS) attacks to prevent access to the internet and mobile banking apps or disruption to internal payment processing systems. Damage or corruption of client data was also cited as another example of a cyberattack.

    The aforementioned figures reflect costs without contingency measures and when included, risks are significantly improved with banks expected to lose quarterly profits of 20-35 percent and 12-25 percent from direct and indirect impact, respectively. In order to reduce risks from cyberattacks, banks have adopted multiplied layers of security controls to protect data and funds; added DoS mitigation measures such as clean pipe services; and backed up critical data regularly.

    In-house measures aside, it is also heeding greater attention to third-party service providers. Periodic audits are made to verify the ongoing effectiveness of existing security and business continuity measures are in place for a switch to an alternative provider or to in-house operations in the event of a disruption.