Retail News CRM

Tag: Cyber

  • Cyber attacks on the rise in Singapore

    Cyber attacks on the rise in Singapore

    Cyber attacks in Singapore are on the rise, with 72% of CIOs detecting more now than 12 months ago, according to research commissioned by specialist recruiter Robert Half.

    Findings show that 85% of Singaporean CIOs expect their companies will be attacked more often because they lack skilled IT security talent – well above the 78% average of the eight countries surveyed.

    The only two countries with a higher percentage than Singapore are Brazil (93%) and Japan (87%).

    Singapore has the highest percentage of CIOs predicting “significantly more” cyber-attacks in the next five years – 30% compared to the global average of 19%.

    “The fight against rising cyber threats is entering a critical phase as Singapore is experiencing a shortage of IT professionals with the right cyber security skills to defend companies against these attacks,” said David Jones, senior managing director of Robert Half Asia Pacific.

    “Companies know they need to take action to confront cyber attackers,” said Jones. “This means investing in a cyber-security strategy that brings together the right mix of technology and people.”

    IT leaders say the top three cyber security risks facing Singaporean organizations in the next five years are data abuse/data integrity (59%), spying/spyware/ransomware (54%) and cybercrime (53%).

    “New technologies raise new security concerns,” said Jones. “This can result in a skills gap where the available expertise has not kept pace with the evolving IT threats.”

    “As demand for new cyber-specialists entering the IT market outstrips supply, companies are being forced to reconsider their training and retention programs,” he said. “They are also recruiting from overseas, partnering with educational organisations, and developing flexible hiring strategies that include both permanent and contract specialists, including external risk agencies.”

    In response to the new wave of cyber-attackers, almost a quarter (23%) of Singaporean CIOs plan to add new permanent IT security professionals to their team in the next 12 months. One in three (29%) say they are planning to hire IT professionals for newly added contract positions within their team.

    Several specialised cyber-security roles are in high demand as organisations are confronted with additional security threats, including mobile, application and Big Data analytics security.

  • Cybercriminals use insiders to attack telcos

    Cybercriminals use insiders to attack telcos

    Cybercriminals are using insiders to gain access to telecommunications networks and subscriber data, recruiting disaffected employees through underground channels or blackmailing staff using compromising information gathered from open sources.

    This is among the findings of a Kaspersky Lab intelligence report into security threats facing the telecommunications industry.

    Telecommunications providers are a top target for cyber-attacks. They operate and manage the world’s networks, voice and data transmissions and store vast amounts of sensitive data. This makes them highly attractive to cybercriminals in search of financial gain, as well as nation-state sponsored actors launching targeted attacks, and even competitors.

    To achieve their goals, cybercriminals often use insiders as part of their malicious ‘toolset’ to help them breach the perimeter of a telecommunications company and perpetrate their crimes.

    New research by Kaspersky Lab and B2B International reveals that 28% of all cyber-attacks and 38% of targeted attacks now involve malicious activity by insiders. The intelligence report examines popular ways of involving insiders in telecoms-related criminal schemes and gives examples of the things insiders are used for.

    Compromising employees

    According to the Kaspersky Lab researchers, attackers engage or entrap telecoms employees in the following ways:

    • Using publicly available or previously stolen data sources to find compromising information on employees of the company who they intend to hack. They then blackmail targeted individuals – forcing them to hand over their corporate credentials, provide information on internal systems or distribute spear-phishing attacks on their behalf.
    • Recruiting willing insiders through underground message boards or through the services of “black recruiters”. These insiders are paid for their services and can also be asked to identify co-workers who could be engaged through blackmail.

    The blackmailing approach has grown in popularity following online data breaches such as the Ashley Madison leak, as these provide attackers with material they can use to threaten or embarrass individuals. In fact, data-leak related extortion has now become so widespread that the FBI issued a Public Service Announcement on June 1, warning consumers of the risk and its potential impact.

    The insiders most in demand

    According to the Kaspersky Lab researchers, if an attack on a cellular service provider is planned, criminals will seek out employees who can provide fast track access to subscriber and company data or SIM card duplication/illegal reissuing. If the target is an internet service provider, the attackers will try to identify those who can enable network mapping and man-in-the-middle attacks.

    However, insider threats can take all forms. The Kaspersky Lab researchers noted two non-typical examples, one of which involved a rogue telecoms employee leaking 70 million prison inmate calls, many of which breached client-attorney privilege. In another example, an SMS center support engineer was spotted on a popular DarkNet forum advertising their ability to intercept messages containing OTP (One-Time Passwords) for the two-step authentication required to login to customer accounts at a popular fintech company.

    “The human factor is often the weakest link in corporate IT security,” Kaspersky Lab security expert Denis Gorchakov said.

    “Technology alone is rarely enough to completely protect the organization in world where attackers don’t hesitate to exploit insider vulnerability. Companies can start by looking at themselves the way an attacker would. If vacancies carrying your company name or some of your data start appearing on underground message boards, then somebody somewhere has you in their sights. And the sooner you know about it, the better you can prepare.”

  • Singtel teams with SIT to train cybersecurity talent

    Singtel teams with SIT to train cybersecurity talent

    Singtel has announced a new partnership with the Singapore Institute of Technology (SIT) to train cybersecurity talent.

    The work-study program will support SIT students in the areas of Information Security and Software Engineering, which is expected to lead to career pathways such as cyber security R&D, product development, and management, cyber analysis and forensics, operations and cyber architects.

    Singtel country CEO and CEO, Group Enterprise Bill Chang said the undertaking aims to address two critical skills needs locally – the short supply of trained software engineers and the growing worldwide threat posed by cyber threats.

    “The economy is in great need for trained cybersecurity professionals,” he said.

    Under the work-study programs, participating students are trainees of the supporting company. They get to gather meaningful work experiences through industry induction, close mentorship, attachments and capstone projects to deepen industry-relevant skills.

    The students would acquire skills and experience relevant to the needs of the company while the company gains a productive contributor and an avenue to recruit, assess, groom and retain talent.

    Singtel has also worked with the InfoComm Development Authority of Singapore (IDA) on the Cyber Security Associates and Technologists Program.

  • SmarTone launches cyber security suite

    SmarTone launches cyber security suite

    Hong Kong operator SmarTone has launched ST Protect, an anti-cyberattack software with on-device AI and a Machine Learning behavioral engine designed to protect smartphones from known and even unknown threats.

    Cyberattacks have rocketed in recent years. In Hong Kong, there was an 86% increase in the number of security issues related to mobile devices in 2015 compared to the previous year. Globally, more than 87% of the top mobile apps have been hacked.

    Stephen Chau, SmarTone’s interim CEO, said the new product is design to help their customers to “actively combat” mobile security threats.

    “Recently we have observed the increasing trend of mobile threats and cyberattacks around the world as well as in Hong Kong, with WiFi attacks, viruses and malware continuing to become more prevalent,” he noted. “In many cases, these mobile security issues could lead to severe consequences for smartphone users – from financial loss to the exposure of their private data or personal communications to the public, and even ID theft. There is a pressing need for smartphone users to protect their phones.”

    ST Protect is powered by Zimperium, a US-based security and technology company that has invented the world’s first mobile AI intrusion prevention system. It provides continuous and real-time protection to smartphones against the following mobile threats.

    WiFi attacks and hacking, especially Man-in-the-middle (MITM) attacks, no matter whether users are in Hong Kong or overseas: ST Protect alerts users to immediately terminate unsafe WiFi connections if threats are found.

    ST Protect detects and stops abnormal app activities with patented behavioral analytics, and ensures apps only access permitted information. It also offers protection for known and unknown threats and even zero-day attacks. It also alerts users when their smartphone is under attack.

  • Cyber attacks on US retailers drop, but records stolen remain high

    Cyber attacks on US retailers drop, but records stolen remain high

    Cyber attacks agains US retailers declined by as much as 50 percent since 2012, but the number of records stolen from them remains at near record highs, a new IBM study shows.

    IBM Security researchers recently reported that during the year cyber attackers still managed to steal more than 61 million records from retailers despite the decline in attacks, demonstrating cyber criminal’s increasing sophistication and efficiency.

    According to the research, cyber attackers are using new techniques to obtain massive amounts of confidential records with increased efficiency. This is why despite the decline in the number of attacks, the perpetrators were able to impact a far greater number of victims with each incident.

    “The threat from organized cyber crime rings remains the largest security challenge for retailers,” said Kris Lovejoy, General Manager, IBM Security Services. “It is imperative that security leaders and CISOs in particular, use their growing influence to ensure they have the right people, processes and technology in place to take on these growing threats.”

    Surprisingly, majority of cyber attackers scaled back their hacking efforts around Black Friday and Cyber Monday, the two biggest shopping days of the year.

    IBM’s Digital Analytics Benchmark, the number of daily cyber attacks during the two week period (24 November – 5 December) was 3,043, nearly one third less than the 4,200 average over this period in 2013.

    In a year’s time, the number of breaches also dropped by more than 50 percent for Black Friday and Cyber Monday. In 2013, there were more than 20 breaches disclosed including several large breaches that caused the number of records compromised to rise drastically, reaching close to 4 million. Over the same period in 2014, 10 breaches were disclosed which resulted in just over 72,000 records getting compromised

    Despite this “cyber threat slow down,” the retail and wholesale industries emerged as the top industry target for attackers in 2014, a potential result of the wave of high profile incidents impacting name brand retailers.

    IBM need that while there has been a rise in the number of Point of Sale (POS) malware attacks, the vast majority of incidents targeting the retail sector involved Command Injection or SQL injection. The complexity of SQL deployments and the lack of data validation performed by security administrators made retail databases a primary target.