Retail News CRM

Tag: hack

  • Metas AI Blunder: How a Chatbot Hack Shook Up Instagram and Spurred Investor Jitters

    Metas AI Blunder: How a Chatbot Hack Shook Up Instagram and Spurred Investor Jitters

    A concerning vulnerability was recently exposed in Meta’s AI support chatbot due to an Instagram hack. The attackers manipulated the chatbot into providing access to high-profile accounts, including the inactive Obama White House page, beauty retailer Sephora, and a high-ranking US Space Force official.

    AI Security Breach

    The hackers persuaded the chatbot to reset account credentials without authentication, effectively changing a trusted security tool into a glaring weakness. This event highlights a wider vulnerability – tech companies giving AI systems sweeping authority over sensitive tasks like account recovery, despite the systems’ susceptibility to manipulation through “prompt injection” attacks.

    Meta’s stumble comes at a sensitive time. The social media magnate has committed heavily to AI, with significant job losses and up to $145 billion dedicated to AI infrastructure. This incident may amplify concerns about the company speeding up automation before the technology is adequately equipped to handle these tasks safely.

    On Monday, Meta stated that the issue was resolved and steps were being taken to secure impacted accounts. However, the incident shook investors already anxious about Meta’s substantial AI investment, leading to a more than 5% drop in share price.

    AI and Security

    The attack, which occurred over the weekend, saw users locked out of their accounts and led to numerous complaints on various platforms. The hack underlines the latest challenge for Meta in its attempt to incorporate AI throughout its products.

    The company introduced the support chatbot in March to address the ongoing issue of inadequate human support for users who lose account access or face inaccurate penalties. Since its launch late in 2022, AI chatbots have been exploited by hackers using prompt-based attacks.

    Analysts and experts warn that this problem isn’t isolated to Meta, predicting more such exploits as hackers utilize AI. Unforeseen issues are arising with the use of AI, presenting a new type of risk. Previously, individuals were targeted by scams. Now, AI agents or autonomous digital assistants capable of performing complex tasks are being targeted.

    Questions & Answers

    What is the potential risk of using AI in critical functions?
    AI systems’ potential risks include susceptibility to manipulation, especially when given significant authority over sensitive tasks without adequate safeguards or verification processes.

    How was the Instagram hack carried out?
    The hackers manipulated Meta’s AI support chatbot into resetting account credentials, effectively turning a high-trust security tool into a significant weakness and gaining access to high-profile accounts.

    What implications does this incident have on Meta’s efforts towards AI?
    This breach heightens concerns about Meta’s heavy investment in AI. It suggests that the company’s push for automation might be outpacing the technology’s readiness to handle such critical tasks safely.

  • UBS Faces Major Darknet Data Breach Exposing Personal Details of 130,000 Employees

    UBS Faces Major Darknet Data Breach Exposing Personal Details of 130,000 Employees

    A significant cybersecurity breach has rattled UBS, as sensitive data concerning 130,000 of its employees has surfaced on the darknet following a hacker attack on its procurement service provider. But UBS isn’t the only one feeling the heat from this incident.

    Chain IQ: The Breach Exposed

    The breach traces back to Chain IQ, a procurement service provider and former UBS spinoff, which has also served other prominent clients such as Pictet, Manor, and Implenia. The troubling news was first reported by the Swiss daily Le Temps, shedding light on a severe data theft that occurred in June.

    Among the leaked information are names, email addresses, landline numbers, and, in some instances, mobile numbers—one of which belongs to UBS CEO Sergio Ermotti. Other details include job levels, languages spoken, and office locations within the bank.

    Service Provider in the Spotlight

    Chain IQ, headquartered in Baar with additional offices in Geneva and Zurich, has established itself firmly in the procurement sector, delivering services that cover human resources, IT systems, waste management, and more.

    The Victorious Hacker’s List

    The data leak is not just a concern for UBS. Chain IQ’s client list is also up for grabs on the darknet; a troubling revelation. The firm has previously engaged with over 400 partners, and now exposed are the details of contracts, service types, and the internal contacts for each partner. Noteworthy clients include Pictet, insurance giants like Swiss Life and Axa, and global entities such as FedEx and IBM.

    UBS’s relationship with Chain IQ includes support in managing supply chain due diligence and company credit card administration. The leaked dataset spans 137,192 rows, each representing an employee.

    Darknet Deals and Criminal Risks

    Concerns escalate as reports confirm that the leaked file has been sold multiple times on the darknet. Such information poses a risk of being exploited for criminal activities, including identity theft and fraud.

    In response, Chain IQ is treating this situation with the utmost seriousness. The company has activated its security protocols, assembled a dedicated team of internal and external experts, and contacted the Zug cantonal police. They also aim for transparency, having informed all stakeholders promptly.

    A UBS spokesperson confirmed their awareness of the cyberattack on Chain IQ, assuring that they are monitoring the developments closely.

    Pictet’s Invoice Data Under Scrutiny

    In an additional twist, the leaked data allegedly includes information from Pictet, detailing “tens of thousands of invoices.” While the invoices themselves are not part of the leak, the records describe various expenditures by companies and employees, including groceries, dining, travel, and security services.

    A representative from Pictet stated that the compromised data does not include sensitive employee information or customer data, but mostly concerns invoice details from select suppliers. Precautionary measures are being implemented to mitigate further risks.

    As the world turns more digital, will we see a rise in such cyber capers, or can the industry step up its defenses to combat these digital bandits?

    Questions & Answers

    What type of data was leaked in the UBS incident? The data includes names, email addresses, phone numbers, and job-related details for 130,000 UBS employees.

    Which companies are involved in the breach? Chain IQ, former UBS spinoff, is the main service provider affected, alongside other clients like Pictet and Manor.

    What actions are being taken in response to the breach? Chain IQ has activated security protocols, mobilized a dedicated response team, and contacted law enforcement while keeping stakeholders informed.

  • 26 million devices are infected by malware that steals bank card data including passwords

    26 million devices are infected by malware that steals bank card data including passwords

    25 million device users were targeted by a certain type of malware attack in 2023 and 2024. Infostealer malware does exactly what its name would suggest it does and grabs important information such as bank card numbers, passwords, and other sensitive data. Cyber security firm Kaspersky estimates that 2.3 million bank cards were leaked on the dark web in 2023-2024. The company says that every 14th infostealer infection ends up with the attacker scoring stolen bank card data.

    Including the 9 million devices infected by infostealers in 2024 alone, a total of 26 million have been, in the words of Kaspersky, “compromised” by such malware. While only 1% of bank cards issued globally have been leaked on the dark web, 95% of the card numbers spotted are “technically valid” according to the report. But there’s more to this type of malware that goes beyond stealing bank card account numbers.

    Kaspersky’s report goes on to state that this malware also steals credentials which is information used to verify a user’s identity. And that includes passwords. This data, along with cookies, are distributed to the dark web community. Victims can get into trouble without realizing that they are about to infect their phone, tablet, or computer. An infostealer is often disguised as legitimate software. Kaspersky’s report uses a game cheat as an example. The victim typically downloads the software and runs a malicious file.

    The malware is then spread to other devices via phishing links, malicious email attachments, infected websites, and other methods. Last year, Redline was the most widespread infostealer as it accounted for 34% of infections. The fastest growing of the infostealers was Risepro whose share of infections rose from 14% in 2023 to 23% last year. Another rapidly growing infostealer is Stealc which debuted in 2023 with a 3% share of infections. That number grew to 13% in 2024.

    Kaspersky says that if you do find yourself the victim of an infostealer, monitor your bank accounts and notifications. Have your bank card reissued and change the passwords for your bank app and website. Enable two-factor authorization and set spending limits if your bank allows you to do so. Be on the lookout for phishing attacks, fake texts, and bogus phone calls. If you’re not sure if a notification, email, or text is legit, call your bank. Kaspersky also suggests running security scans on your devices making sure to remove any detected malware.

  • Microsoft takes action against hackers from North Korea

    Microsoft takes action against hackers from North Korea

    In a recent blog post on the Microsoft website, the company detailed steps it has taken to take legal action against a cybercrime group and protect customer information.

    The security threat came from a group known as Thallium, which reportedly is based in North Korea. The group used a technique called ‘spear phishing’ to steal sensitive information, in which the group replicated the form and design of a genuine Microsoft security email while embedding dangerous links that, when clicked, would allow the group to extract sensitive account information.

    According to the Washington-based firm, the threat was focused on users affiliated with the government, universities, human rights groups, and other organizations, with most of the victims concentrated in the US, Japan, and South Korea.

    The particularly dangerous part of the scheme is that once Thallium takes control of an account in this way, it is possible for it to set up automatic forwarding in a way that gives the group access to any new emails the victim receives, even after the password is reset.

    The cybercrime group was able to use this method by using domains such as “rniscoroft.com”, which uses the combination of ‘r’ and ‘n’ to facsimile the authentic Microsoft domain. Thus, the Windows company filed a court case and was able to take control of 50 such domains in order to stop the attacks.

    Microsoft states that this is the fourth nation-state cybercrime group they have taken legal action against. The security threat has hopefully now been neutralized, but users are advised to be wary of suspicious emails and always check carefully before clicking email links or entering sensitive information.

  • Hong Kong Stock Exchange Website Hit By DoS Attacks

    Hong Kong Stock Exchange Website Hit By DoS Attacks

    The Hong Kong Exchanges and Clearing Limited faced a day of tech hiccups, including the latest denial-of-service attacks on its website.

    According to HKEX CEO, Charles Li Xiaojia, the bourse’s website was subject to distributed denial-of-service attacks (DDoS) – a cyberattack whereby overwhelming traffic is imposed to slow or restrict access from other browsers – and was subsequently unable to display exchange prices and other financial data.

    We will continue to invest more to safeguard and improve” the information and technical infrastructure at the exchange, Li said at a press conference. We hope the public has confidence in the robustness of our system.

    The cyberattack was not the only tech hiccup the HKEX faced just in that single day. Earlier yesterday afternoon, the HKEX had to halt derivatives trading due to a bug in the system before resuming today. According to an update from its website, the issues were caused by software issues in the vendor-supplied trading system.»

  • Surge in Hong Kong Cybercrime

    Surge in Hong Kong Cybercrime

    Hong Kong has experienced a surge in fraudulent banking websites this year. In August alone, there were 15 reports of such incidents, compared with only two cases of fake websites or phishing attempts in the same month a year ago, according to the Hong Kong Monetary Authority (HKMA). In September, seven incidents were reported, up from one a year ago.

    And the trend seems to continue, with eight cases reported in October so far. Customers of DBS, Hongkong and Shanghai Banking Corporation, as well as Dah Sing have been among the targets of the criminals. With the rise of financial technology firms and mobile banking apps, experts predict that novice mobile banking users will become prime targets.

    Digital Banks Attract Attackers

    While the use of digital banking tools is spreading quickly, the technology is also attracting the attention of cybercriminals, said cybersecurity specialist Securelist in a report earlier this year. «We are sure that the world of cybercrime will see increasing attacks against this type of banks and their customers,» Securelist said in its report

    Fraudsters have long tried to trick users to visit fake bank website via e-mail messages pretending to be from the bank. On these fake websites, they try to trick account holders into revealing their access credentials. On mobile devices, the connection with the bank is typically via an application, rather than a website.

    Tricks Of Criminals

    Banks’ usage of chat applications increases the possibility that criminals could try impersonating the bank in social media chats and try to trick users into downloading and installing an «updated» version of the bank’s app. In reality, such an app would be malicious and could help attackers steal credentials from the phone.

    «Other social engineering scams have emerged which try and trick the genuine user into revealing the authentication code for their chat app and hence lose control of the account. Even if this is only temporary, it may allow enough time for a fraud to be perpetrated,» Jackson said in an interview.

    Attacks Focused On Smaller Vendors

    Experts predicts there could be more attacks on fintechs or payment providers going forward. This is due to lower investments into cybersecurity versus traditional banks, and criminals’ evolving technological skills.

    «Large financial organizations invest considerable resources in cybersecurity, thus the penetration of their infrastructure is not an easy task. However, a threat vector that is likely to be actively used by cybercriminals in the coming year is attacks on software vendors supplying financial organizations,» Securelist said. Most of these vendors have a lower level of protection compared with the financial organizations themselves.

    Attacks Via Software

    For the coming year, the cybersecurity experts expect criminals to stage attacks via software for the finance business, including such for ATMs and PoS terminals. «A few months ago we registered the first attempts of this kind, when attackers embedded a malicious module into a firmware installation file, and placed it on the official website of one of the American ATM software vendors,» Securelist wrote.

    Based on a 2017 study by Accenture, the financial services industry posted annual costs of nearly $18.3 million per firm from cyber attacks.

  • Android ransomware abuses accessibility services

    Android ransomware abuses accessibility services

    ESET researchers have discovered DoubleLocker, an innovative Android malware that combines a cunning infection mechanism with two powerful tools for extorting money from its victims.

    “DoubleLocker misuses Android accessibility services, which is a popular trick among cybercriminals,” commented Lukáš Štefanko, the ESET malware researcher who discovered DoubleLocker.

    “Its payload can change the device’s PIN, preventing the victim from accessing their device and encrypts the victim’s data. Such a combination hasn’t been seen yet in the Android ecosystem.”

    On top of being ransomware, DoubleLocker is based on the foundations of a particular, already documented banking Trojan. According to Štefanko, the functionality for harvesting users’ banking credentials and wiping out their accounts can be added easily.

    “The additional functionality will turn this malware into what can be called ransom-banker,” warns Lukáš Štefanko, who claims he spotted a test version of such a ransom-banker in the wild in May 2017.