Tag: hackers

  • Instagram introduces new security feature against hackers

    Instagram introduces new security feature against hackers

    Instagram is taking a powerful new step to combat account hacking and malicious activity on their social media platform. If you yourself haven’t experienced your Instagram account getting compromised, you probably know at least a couple of friends who have. It’s a fairly widespread phenomenon, as unpleasant as it may sound, and it’s about time something is done about it.

    As of Tuesday, Instagram is introducing a new feature on the platform called Security Checkup, which is aimed to maximize account security and facilitate recovery for anyone whose personal account may be at risk.

    No matter whether they have already been compromised or are simply vulnerable in some way, Security Checkup will prompt users to go through all the necessary steps to secure their account, which includes updating necessary profile information and account settings.

    In a recent news post, Instagram announced that “Security Checkup will guide people, whose accounts may have been hacked, through the steps needed to secure them. This includes checking login activity, reviewing profile information, confirming the accounts that share login information and updating account recovery contact information such as phone number or email.”

    Even if you haven’t necessarily been hacked, Security Checkup will prompt you to take all the important measures to ensure there is an infinitesimal chance of that ever happening in the future.

    Instagram already strongly encourages you to have two-factor authentication, which drastically decreases the chances of that and can be easily set up by going to Profile > Settings > Security > Two-factor authentication.

    With 2FA enabled, anytime there is a login attempt from an unrecognized location, you’ll be immediately alerted with the option to approve or deny the request from your personal device. Instagram also keeps track of all devices which have recently logged into your Instagram, and which can be viewed by going to Settings > Security > Login Activity. From there, you can remotely log out of any devices you don’t recognize on the list.

    You should also make sure your e-mail and phone number are the ones you are using currently, as keeping that info up to date will ensure smooth verification should any suspicious activity be detected.

    Instagram also emphasizes that one of the most common ways in which malicious parties gain entry into personal accounts is through impersonating Instagram itself, and sending out DM’s pretending they are working for the platform.

    “They may tell you that your account is at risk of being banned, that you are violating our policies around intellectual property, or that your photos are being shared elsewhere,” the post warns. These are apparently fairly common tactics scammers use in an effort to bully people into sharing their login credentials.

    Instagram stresses that it will never, ever try to contact users of the platform via Direct Messages. This means that if you see such a message claiming it’s from Instagram or asking for any personal info, you should automatically know it is malicious and immediately report the message to Instagram and block the account.

    • To report an Instagram post, tap on the three dots appearing at the top right
    • To report a message, tap and hold on it until a menu appears
    • To report an account, go to the profile and tap on the three dots at the top right

    If Instagram ever needs to contact you for any reason, rather than DM-ing you, they can reach you through an “Emails from Instagram” tab in the app’s settings. That is “the only place you will find direct and authentic communication from Instagram on the app,” the company says.

    Thanks to some new updates to the Support Inbox on Instagram, you can now easily view the status of any and all messages, posts, or accounts you have reported, and find out whether or not Instagram has taken any action. You can also keep track of your own posts’ status, to see if they are breaking any rules—and if they are, you can directly repeal them from there.

  • JBS Foods paid hackers US$11 million to end ransomware attack

    JBS Foods paid hackers US$11 million to end ransomware attack

    Meatpacker JBS USA paid the equivalent of $11 million ransom in a cyberattack that disrupted its North American and Australian operations, the company’s CEO has said in a statement.

    The subsidiary of Brazilian firm JBS SA halted cattle slaughtering at all of its US plants for a day last week in response to the cyberattack, which threatened to disrupt food supply chains and further inflate already high food prices.

    The cyberattack followed one last month on Colonial Pipeline, the largest fuel pipeline in the US. It disrupted fuel delivery for several days in the nation’s Southeast.

    The JBS meat plants, producing nearly a quarter of America’s beef, recovered faster than some meat buyers and analysts expected.

    “This was a very difficult decision to make for our company and for me personally,” said Andre Nogueira, CEO of JBS USA of the ransom payment. “However, we felt this decision had to be made to prevent any potential risk for our customers.”

    The Brazilian meatpacker’s arm in the US and Pilgrims Pride Corp, a US chicken company mostly owned by JBS, lost less than one day’s worth of food production. JBS is the world’s largest meat producer.

    Third parties are carrying out forensic investigations and no final determinations have been made, JBS said. No company, customer or employee data was compromised in the attack, it said.

    A Russia-linked hacking group is behind the cyberattack against JBS, a source familiar with the matter said last week. The Russia-linked cyber gang goes by the name REvil and Sodinokibi, the source said.

    The Wall Street journal reported on Wednesday that the JBS ransom payment was made in bitcoin.

    The Justice Department on Monday recovered some $2.3 million in cryptocurrency ransom paid by Colonial Pipeline Co, cracking down on hackers who launched the attack.

  • Over 100 Financial Firms Hit by DDoS Attacks

    Over 100 Financial Firms Hit by DDoS Attacks

    More than 100 financial firms were victims of distributed denial-of-service attacks by the same threat actor with North America and Europe overwhelmingly making up the dominant share, according to a recent report.

    Cyber intelligence sharing group FS-ISAC said that over 100 financial services firms were targets of a wave of distributed denial-of-service (DDoS) attacks – a method of overloading a web system with requests in order to prevent it from functioning properly.

    Interestingly, the report claims that the attacks were conducted by the same threat actor within a short period of time.

    The criminals sent extortion notes threatening to disrupt the firms’ websites and digital services, the report said. The threat actor methodically moved across jurisdictions in Europe, North America, Latin America, and Asia Pacific, hitting dozens of institutions within weeks.

    According to the report, North America and Europe made up an overwhelming share of the DDoS attacks with 43 percent and 38 percent, respectively. Asia (15 percent) and Latin America (3 percent) made up less than one-fifth.

    By sub-sectors, retail banking dominated the list, accounting for 41 percent of the DDoS attacks. This is followed by exchange (15 percent), payments (13 percent) and, securities and investment (10 percent).

    In 2021, we have already seen new cyber threats in the form of supply chain attacks, which we can expect to proliferate and evolve quickly, said FS-ISAC’s chairman of the board Jerry Perullo  «The only way to stay ahead of these ever more sophisticated threat actors is to collaborate. Now more than ever, we need global leaders to model what effective sharing looks like to the rest of our community as well as the industry at large.

  • Apple is giving out a special iPhone that can lead to a $1 million reward

    Apple is giving out a special iPhone that can lead to a $1 million reward

    Apple is giving out special versions of the iPhone to security researchers who have the opportunity to collect as much as $1.5 million from Apple. Announced last week at the Black Rock cybersecurity conference in Las Vegas (where ironically Apple earlier this year put up a billboard reading “What happens on your iPhone stays on your iPhone”), the tech giant is giving these experts the task of hacking into the iPhone to find vulnerabilities and security flaws. Apple security chief Ivan Krstic says that these special iPhones come with “advanced debug capabilities.” Unlike the units sold to consumers, these will allow researchers to access parts of iOS that are off-limits to most users.

    The so-called iOS Security Research Device Program will get underway next year and while anyone can apply to receive one of the special iPhone units, Apple says that there will be a limited amount handed out. Most likely only qualified security researchers will be able to obtain one of these devices. Even though they will be much more open than a store-bought iPhone, the researchers won’t have the same access that Apple’s own internal security team has on their iPhones.

    Companies like Apple and Google pay these researchers to find flaws as an incentive. In addition, Apple would prefer that a security expert who finds a vulnerability tell the company about it instead of selling it or using it for their own evil intentions. Flaws found on iOS are said to bring researchers as much as $1 million from hackers willing to pay that much. Apple announced last week that a researcher can receive $1 million by finding a flaw allowing him or her to take over full control of an iPhone without the owner touching the handset. Other flaws can also handsomely reward a researcher as Apple is willing to pay up to $500,000 for the information. Google announced last month that it will pay up to $30,000 to a researcher finding flaws in its Chrome browser while paying $150,000 if it is told about a flaw that can compromise its Chrome OS.

    “We want to attract some of the exceptional researchers who have thus far been focusing their time on other platforms. Today many of them tell us they look at our platform and they want to do research but the bar is just too high. We have by far the highest maximum payouts in the industry, and we have the iOS security research device program for exceptional researchers that are new to our platform”-Ivan Krstic, head of security engineering and architecture, Apple

    Researchers who find a vulnerability in code found on beta software will receive a 50% bonus from Apple. That is to reward an expert who has identified a problem before the bug is passed along to the public, and brings the top possible award handed out by Apple to $1.5 million. As the company’s security chief points out, “The second-best reason to have a bug bounty is to find out about a vulnerability that’s already in the users’ hands and fix it quickly. The number one best reason is to find a vulnerability before it ever hits a customer’s hands.”

    Apple’s new program might have received more applause if it wasn’t for the limited number of special iPhones it is handing out. As iOS security researcher Will Strafach noted, “It’s a huge step, but I do think it would be great if there were a bit more wide availability of the devices.” Apple might be concerned that the wider availability of these units might lead to several ending up in the wrong hands, creating more problems for the company. Still, with all this money at stake, regular iPhone owners should benefit from the incentives that Apple is throwing at security experts.

  • Stop DDoS from ruining your retail Brand’s sales momentum

    Stop DDoS from ruining your retail Brand’s sales momentum

    On 11 November 2017, Alibaba’s Singles’ Day sales hit a new record high with a 39% increase from last year’s sales. The company’s 2017 profits broke world records of Black Friday and Cyber Monday, marking this Asian sales day as one of the highest revenue sales in history.

    With increasing internet-user penetration, consumer behavior is quickly transitioning in Asia today. Shoppers make most of their retail purchases on-the-go, through mobile applications or via websites. In fact, 90% of this year’s Alibaba sales were made through mobile phones.

    Now more than ever, retail businesses in the Asia-Pacific region need to tap onto an omni-channel approach to be aligned with these changing customer demands. Based on the 2016 e-commerce study, Google and Temasek foresee Southeast Asia to be the next region to boom in this market. The predictions indicated that e-commerce will make up 6% of the region’s total retail sales by 2025.

    Beware of business bullies

    While these statistics show a positive growth for the region, businesses going digital must be aware of the lurking threat factors. The physical shoplifters that pained businesses – especially during big sales such as Great Singapore Sale and Black Friday – have now evolved to become cyber criminals. Unlike thieves, businesses are not physically able to discern these criminals, especially since they attack over the network.

    One of the most devastating kinds of cyberattack for e-commerce businesses today is Distributed Denial of Service (DDoS) which aims to bring down websites, therefore, disrupting online services and businesses. DDoS attacks occur when an unusual and unexpected spike in traffic and connection requests overwhelms a website, slows down the network, or in the worst-case scenario, shuts down the entire system.

    A reliable website that guarantees a good user experience is what defines a successful e-commerce business as it is the main platform for acquiring customers and generating revenues. The damage caused by a network failure or a complete site outage will directly and immediately impact business assets. For instance, Alibaba made US$7 billion within the first 30 minutes of the Singles’ Day sale3. Imagine if they had been hit by a DDoS attack; Alibaba would have lost US$233 million per second. Not only would this be a massive loss, the attack would have also caused long term damage to Alibaba’s brand image and customer loyalty. According to KPMG’s annual consumer survey, one fifth of consumers will turn away from a cyber-attacked company4.

    Don’t fall victim

    With the festive period approaching, online retailers can expect an approximately 20% increase in their web traffic5. To make the most out of this sale period, businesses need to ensure that they are ready to protect themselves against DDoS attacks. This includes re-evaluating their network security to assure they are taking the best protective measures.

    Monitor and Detect

    Businesses cannot fight what they do not know. Monitoring network traffic and flow data with DDoS detection alerts security pros to anomalies before they become full-blown catastrophes.

    One way to get a better understanding of what is happening on the network is baselining to know what the traffic looks like during peacetime. This allows organizations to take the appropriate wartime countermeasures when an attack happens. Effective DDoS detection needs to be able to discern the human traffic from the bots.

    Additionally, organizations need a detection solution that can scale given that attacks are increasingly getting larger in size. The best class solution should not only be able to process the data, but also be equipped with the ability to quickly make intelligent decisions with that data.

    Mitigate and Protect

    DDoS protection requires having the right mitigation in place. Businesses should look for a modern DDoS solution that empowers them to automate defenses – from reports to packet captures to mitigation. This can help security pros reduce stress and thwart attacks quickly.

    Communicate

    As with all security procedures, effective DDoS defense involves a human element, as well. It is imperative for businesses to have a communication plan in place in the event of an attack. This includes critical information such as who to notify during, and after an attack. For example, who should be the first to know if the site goes down due to a DDoS attack? Is that the same person notified if a DDoS attack shuts down the online retail site? Who else is notified if an attack happens? Having communications ironed out ahead of time can reduce time to remediation and lower stress levels.

    Make the most of this year’s sale season

    For businesses, these next few months are the time to peak your revenue and customer traffic. It may be a chance to raise brand awareness or even expand the business. Whichever the case, a DDoS attack can be a fatal roadblock to an organization’s goals. Reacting in an efficient manner is key. Online retailers need to ensure they have an emergency response plan that makes good use of anti-DDoS technologies for unforeseeable attacks. For a happy holiday for all, be on the lookout for any dangers and take the right cautionary actions to protect against any potential threats.

     

  • Indonesia’s Muslim cyber warriors take on IS

    Indonesia’s Muslim cyber warriors take on IS

    A group of Indonesian “cyber warriors” sit glued to screens, as they send out messages promoting a moderate form of Islam in the world’s most populous Muslim-majority country.

    Armed with laptops and smartphones, some 500 members of the Nahdlatul Ulama (NU) – one of the world’s biggest Muslim organisations – are seeking to counter the Islamic State group’s extremist messages.

    “We’ll never let Islam be hijacked by fools who embrace hate in their heart,” tweeted Syafi’ Ali, a prominent member of the NU’s online army, a typical message to his tens of thousands of followers.

    They are trying to hit back at IS’s sophisticated Internet operations, which have been credited with attracting huge numbers from around the world to their cause.

    Internet propaganda is believed to have played a key role in drawing some 500 Indonesians to the Middle East to join IS, particularly among those living in cities where it is easier to get online.

    The dangers of the growing IS influence in Indonesia were starkly illustrated in January when militants linked to the jihadists launched a gun and suicide bombing attack in Jakarta, leaving four assailants and four civilians dead.

    It was the first major attack in Indonesia for seven years, following a string of Islamic militant bombings in the early 2000s that killed hundreds.

    As well as firing off tweets, the NU members have sought to dominate cyberspace by establishing websites promoting the group’s moderate views, an Android app and web-based TV channels, whose broadcasts include sermons by moderate preachers.

    The initiative has been building momentum for a while but started to pick up pace a few months ago. A handful of cyber warriors operate from a small office in Jakarta, while the rest work remotely, and the group mostly communicate with one another over the web.

    But it will be an uphill battle and the NU, which has been promoting moderate Islam for decades, conceded they have previously struggled to take on IS’s hate-filled messages.

    “NU has for a while wrestled with this radical propaganda,” said Yahya Cholil Staquf, secretary general of the NU, which claims at least 40 million followers.

    “Every time we defeated them, it didn’t take long for them to regain their strength.”

    The online drive comes as the NU is set to take its campaign to promote their tolerant form of Islam onto the international stage this week, with a two-day meeting from tomorrow of moderate religious leaders from around the world.

    They aim to showcase their particular brand of the Muslim faith, known as “Islam Nusantara”, to counter the IS jihadists’ radical interpretation of Islam.

    Meaning “Islam of the Archipelago” – Indonesia is the world’s biggest archipelago, comprising over 17,000 islands – it is accepting of diversity and stresses non-violence.

  • Hackers target online retailers, and not just the big ones

    Hackers target online retailers, and not just the big ones

    Many small and midsized retailers assume hackers won’t bother with them. But criminals have figured out small companies are easier to penetrate, and go after them frequently, warns a security expert.

    In spite of high-profile hacks such as against eBay, many Internet retailers still do not believe that they are at risk or have been a victim of undetected hacks by criminal groups.

    In the 2014 Trustwave Global Security Report, retail was the top industry compromised, making up 35% of the attacks investigated. And 54% of those attacks were against e-commerce sites, where hackers target servers and databases that host card data.

    However, many online retailers still seriously underestimate the [black] market value of the data they possess and handle. Just take a look at Pastebin.com—the simple online text storage and sharing platform is being used by hackers to store stolen information.

    Hackers use Pastebin to prove that they conducted a successful hack. Earlier this year, as part of our security research, we found 311,095 user credentials (login/password pairs) for various services, web sites and e-mails, compromised during the last 12 months. In many cases other personal details, such as credit card numbers, addresses and phone numbers of the victims were also published by the hackers. On average each leak record on Pastebin contained 1,000 user credentials.

    Pastebin is just one illustration of the “dark side” of the Internet, where online retailers can check if web site vulnerabilities have been exploited and if their customers’ data is being targeted. 

    With the rise of the Big Data trend, information collection and analysis is becoming more important for online retailers. With more data comes more opportunity for hackers, who are looking for data/records to sell for profit. A report by Risk Based Security and the Open Security Foundation found that in 2013 there were 2,164 data breach incidents exposing 822 million data records. And 59.8% of reported incidents were the result of hacking, which accounted for 72% of exposed records.

    Cybercriminals are highly skilled technically and are also business people, who know how to make money. A recent CNN article said this: “According to one European intelligence service, there are 20-30 criminal gangs in the former Soviet Union that have hacking skills as good as most nations. There are many other groups with lesser skills. These criminals are nimble and inventive, and there are thriving cybercrime black markets where you can buy the latest hacking tools.”

    A recent Javelin Strategy & Research report found that financial institutions are doing a much better job than retailers when it comes to credit card security. Indeed, there are a number of online marketplaces and forums that solely exist to sell information gained by hackers, for example Rescator.la sells stolen credit and debit card information. In such places, customer databases from online stores are often the most expensive on the black market, because they contain correct, up-to-date and complete customer details, sometimes even with their credit card numbers.

    Completeness is a very important factor for pricing on the black market. One customer record from an online store may generate a penny, while a thousand records can easily generate at least $10, or much more, depending on the records’ quality and completeness. For example spammers prefer to purchase e-mails from Internet retailers, simply because they will get a higher click-through rate, generating more revenue, as they can send targeted spam (by country, age, wealth, area of interests, etc.)

    Hackers are also interested in the valuable information on shoppers’ computers, so e-commerce web sites are often infected with malware (an exploit pack targeting and exploiting vulnerabilities in Adobe products or popular browsers). Such attacks often remain unnoticed as they are conducted overnight or at weekends when security team is away. Experienced hackers can go undetected over a long period. For example, French computer hardware retailer LaCie disclosed in April 2014 that its web site had been breached by a malware attack that went undetected for a year. Following the breach, the retailer recommended that buyers check their credit card statements for any fraudulent charges, and keep an eye on their credit reports in case of identity theft.

    The big-name breaches that hit headlines leave many small and midsized e-business owners believing that they will not be attacked, assuming their customer databases are not big enough. This assumption is wrong because in the majority of cases hackers are not looking for customers and data from a specific web shop, they are just looking for commercially exploitable data. The more, the better. It’s much easier, faster and cheaper to hack 50 small e-boutiques than hacking one big one. Moreover, the outcome in terms of number of stolen customer records will be almost the same, probably even bigger. Imagine how much it costs to compromise Amazon.

    Large e-commerce retailers also have much more administrative, financial and legal resources to organize forensics and post-incident investigation, so many hackers try to avoid them. Instead, they often target small retailers that have no capability to fight back.

    As only a small number of Black Hats have the necessary skills, time and resources to launch attacks against the biggest players in the e-commerce industry, hackers prefer to compromise a dozen small and medium online shops per day and get their money on the “every little bit helps” principle. Hacker groups use robots, hidden behind proxies, to crawl the Web in the 24/7/365 mode. They look for known vulnerabilities, outdated versions of web application software or just brute force default or weak passwords. One would be surprised how much information can be just found in Google. And if you have a crawling farm you can compromise thousands of web sites per hour.

    Against this hacker onslaught, online retailers of all sizes need to employ an arsenal that is as flexible and up to date as the hackers’ tools. Retailers need to ensure that their hosting providers or data centers have stringent security procedures, that content management systems are up to date, third-party code is checked thoroughly before use and web sites are regularly audited for weaknesses through a combination of vulnerability scanning and penetration testing.