Retail News CRM

Tag: hacking

  • 26 million devices are infected by malware that steals bank card data including passwords

    26 million devices are infected by malware that steals bank card data including passwords

    25 million device users were targeted by a certain type of malware attack in 2023 and 2024. Infostealer malware does exactly what its name would suggest it does and grabs important information such as bank card numbers, passwords, and other sensitive data. Cyber security firm Kaspersky estimates that 2.3 million bank cards were leaked on the dark web in 2023-2024. The company says that every 14th infostealer infection ends up with the attacker scoring stolen bank card data.

    Including the 9 million devices infected by infostealers in 2024 alone, a total of 26 million have been, in the words of Kaspersky, “compromised” by such malware. While only 1% of bank cards issued globally have been leaked on the dark web, 95% of the card numbers spotted are “technically valid” according to the report. But there’s more to this type of malware that goes beyond stealing bank card account numbers.

    Kaspersky’s report goes on to state that this malware also steals credentials which is information used to verify a user’s identity. And that includes passwords. This data, along with cookies, are distributed to the dark web community. Victims can get into trouble without realizing that they are about to infect their phone, tablet, or computer. An infostealer is often disguised as legitimate software. Kaspersky’s report uses a game cheat as an example. The victim typically downloads the software and runs a malicious file.

    The malware is then spread to other devices via phishing links, malicious email attachments, infected websites, and other methods. Last year, Redline was the most widespread infostealer as it accounted for 34% of infections. The fastest growing of the infostealers was Risepro whose share of infections rose from 14% in 2023 to 23% last year. Another rapidly growing infostealer is Stealc which debuted in 2023 with a 3% share of infections. That number grew to 13% in 2024.

    Kaspersky says that if you do find yourself the victim of an infostealer, monitor your bank accounts and notifications. Have your bank card reissued and change the passwords for your bank app and website. Enable two-factor authorization and set spending limits if your bank allows you to do so. Be on the lookout for phishing attacks, fake texts, and bogus phone calls. If you’re not sure if a notification, email, or text is legit, call your bank. Kaspersky also suggests running security scans on your devices making sure to remove any detected malware.

  • Nearly 35,000 PayPal user accounts were hacked due to reused passwords

    Nearly 35,000 PayPal user accounts were hacked due to reused passwords

    Nearly 35,000 PayPal user accounts have been breached by so-called “credential stuffing”. PayPal managed to stop the two-day intrusion and reset the affected users’ passwords.

    In fact, PayPal’s own servers weren’t hacked. The reason for the hack was the so-called “credential stuffing”, a technique the hackers used to gain access to the user accounts. This type of attack is when a hacker uses previously leaked login info – and if the user has reused it for their PayPal account, the hacker can get access.

    The intrusion reportedly lasted two days, between December 6 and December 8, 2022, and it affected 34,942 user accounts. It is possible that the hackers were able to access a significant amount of personal information for the affected users, including full names, birth dates, postal addresses, social security numbers, and individual tax identification numbers. On top of that, hackers had access to transaction histories, connected credit and debit card details, and PayPal invoicing data.

    However, PayPal was able to stop the attack and reset the passwords for the users so the hackers would lose access. The popular online payments platform reassures that no unauthorized transactions were attempted. The affected users also get two free years of credit monitoring from Equifax.

    All in all, this could have become a very bad situation if the hackers were trying to make transactions from the affected users’ accounts. Fortunately, this didn’t happen. The entire situation shows that not reusing the same password across platforms (especially PayPal or other payment platforms) is of primary importance.

    Basically, PayPal wasn’t hacked; so if the users had not reused passwords, they wouldn’t have been hacked either. So, better not to reuse passwords. If you’re having trouble remembering all your passwords, you can use a service like 1Password or other password managers. Also, you can benefit from PayPal’s two-factor authentication for an even tighter security of your account.

  • Shinhan acquires 10 pct stake in Tiki

    Shinhan acquires 10 pct stake in Tiki

    South Korea’s Shinhan Financial Group said it has reached an agreement to acquire a 10 percent stake in Vietnam-based e-commerce company Tiki.

    The South Korean group said its two units, Shinhan Bank and Shinhan Card, will pick up 7.44 and 2.56 percent stakes in Tiki, respectively. It has invested $90 million in the e-commerce player.

    “Based on Shinhan’s financial expertise and Tiki’s database in a broad range of areas, we are expecting to build a new converged digital ecosystem in Vietnam,” a Shinhan representative said in a statement.

    The deal was first reported by DealStreetAsia in January, with initial investment of around $40 million.

    Founded in 2010, Tiki is the fifth most popular e-commerce site in Vietnam with 17.9 million monthly visitors last year, according to data portal Statista.

    It closed the Series E round last November with $258 million, which was led by insurance group AIA. The company has raised about $450.5 million in total, according to Crunchbase.

    The round brought Tiki closer to unicorn status, with a valuation of around $832 million.

    Shinhan Bank, the largest foreign lender in Vietnam in terms of assets, has around 650,000 users of its online platform, which was launched in 2018.

  • Apple warns Thai rapper of state hacking

    Apple warns Thai rapper of state hacking

    Apple has sent messages to a Thai rapper and at least five other government critics warning that state-sponsored hackers could be accessing their data remotely, as well as accessing their iPhones’ camera and microphone.

    Previously arrested for sedition but subsequently released, Dechathorn “Hockhacker” Bamrungmuang from the Rap Against Dictatorship group, expressed shock of a possible hack. He posted a screenshot of the message that read: “Apple believes you are being targeted by state-sponsored attackers who are trying to remotely compromise the iPhone associated with your Apple ID.”

    On Tuesday, Apple filed a lawsuit against NSO Group, an Israeli company, for surveilling and targeting Apple users. Apple is also seeking a permanent injunction to ban NSO Group from using any Apple software, services or devices to safeguard the interests of its users.

    After Dechathorn spoke out on this, two political activists in Ghana, an opposition politician in Uganda, and a dozen journalists from Salvadoran have stepped forward with similar warning messages from Apple.

  • DBS Announces More Tech Job Openings

    DBS Announces More Tech Job Openings

    DBS continues to add tech talent with plans to hire around 150 related positions via a virtual hackathon.

    DBS will hire for around 150 technology positions through a virtual hackathon, Hack2Hire, an annual program in its fourth edition, according to a statement.

    The positions will be for 14 developer and engineering roles across artificial intelligence (AI), machine learning and blockchain technologies.

    Successful candidates from the hackathon will be invited for a final interview during the event.

    The latest expansion follows 140 job openings previously announced in May during the bank’s female-focused virtual career fair.

    With Covid-19 greatly accelerating the pace of digital adoption, it is now more important than ever to ensure that our digital offerings continue to stay ahead of our customers’ needs, said DBS’ group head of big data/AI and consumer banking technology Soh Siew Choo.

  • Microsoft takes action against hackers from North Korea

    Microsoft takes action against hackers from North Korea

    In a recent blog post on the Microsoft website, the company detailed steps it has taken to take legal action against a cybercrime group and protect customer information.

    The security threat came from a group known as Thallium, which reportedly is based in North Korea. The group used a technique called ‘spear phishing’ to steal sensitive information, in which the group replicated the form and design of a genuine Microsoft security email while embedding dangerous links that, when clicked, would allow the group to extract sensitive account information.

    According to the Washington-based firm, the threat was focused on users affiliated with the government, universities, human rights groups, and other organizations, with most of the victims concentrated in the US, Japan, and South Korea.

    The particularly dangerous part of the scheme is that once Thallium takes control of an account in this way, it is possible for it to set up automatic forwarding in a way that gives the group access to any new emails the victim receives, even after the password is reset.

    The cybercrime group was able to use this method by using domains such as “rniscoroft.com”, which uses the combination of ‘r’ and ‘n’ to facsimile the authentic Microsoft domain. Thus, the Windows company filed a court case and was able to take control of 50 such domains in order to stop the attacks.

    Microsoft states that this is the fourth nation-state cybercrime group they have taken legal action against. The security threat has hopefully now been neutralized, but users are advised to be wary of suspicious emails and always check carefully before clicking email links or entering sensitive information.

  • Telegram CEO blames China for cyber attack

    Telegram CEO blames China for cyber attack

    One of the top ten most popular messaging apps in the world is Telegram, available for iOS and Android. Not as widely used in the U.S., the app offers end-to-end encryption and group chats for as many as 200,000 people. The app also can share videos, even those with large file sizes, and documents of any type. A tweet from Telegram CEO Pavel Durov blames China for a cyberattack that hit the Telegram app and affected its subscribers earlier this week.

    Durov says that a large Distributed Denial of Service (DDoS) attack originated from internet addresses inside China. These DDoS attacks sent huge amounts of requests at one time to Telegram, clogging up the app and making it unusable for many subscribers. The executive called it a “powerful,” targeted attack that was related to the protests taking place in Hong Kong. Huge throngs of protestors are complaining about a new law that will allow people in the city to be extradited to China. Durov said that in the past, similarly sized DDoS attacks coincided with protests in Hong Kong,

    Because of the encryption used to hide the content of messages, Telegram is popular among protestors in any country, allowing them to coordinate plans with up to 200,000 people out of the eyeshot of authorities. A DDoS attack on Telegram would prevent the protestors in Hong Kong from making arrangements to gather at a certain place and time.

    The Chinese government denied that it was responsible for the attack. Chinese foreign ministry spokesman Geng Shuang said at a briefing yesterday that he was unaware of the incident.

  • Kathmandu suffers a data breach, customers potentially exposed

    Kathmandu suffers a data breach, customers potentially exposed

    An unidentified third-party has breached Kathmandu’s website and potentially accessed customers’ personal information and payment details, the outdoor retailer revealed on Wednesday.

    The business was alerted to the breach, which took place between January 8 and February 12, 2019, through bank fraud monitoring.

    A Kathmandu spokesperson told that the business is currently investigating how many customers are affected by the breach, but that it remains an ongoing process.

    “Whilst the independent forensic investigation is ongoing, we are notifying customers and relevant authorities as soon as practicable,” Kathmandu chief executive Xavier Simonet said.

    “As a company, Kathmandu takes the privacy of customer data extremely seriously and we unreservedly apologise to any customers who many have been impacted.”

    The business has enlisted the help of external IT and cyber security experts to assist in investigating the circumstances, and to confirm which customers have been impacted.

    While the financial impact of the incident is still unclear, the dual-listed retailer saw its stock price fall to $2.31 per share after the announcement, though rebounded to $2.37 by the end of trade.

  • Surge in Hong Kong Cybercrime

    Surge in Hong Kong Cybercrime

    Hong Kong has experienced a surge in fraudulent banking websites this year. In August alone, there were 15 reports of such incidents, compared with only two cases of fake websites or phishing attempts in the same month a year ago, according to the Hong Kong Monetary Authority (HKMA). In September, seven incidents were reported, up from one a year ago.

    And the trend seems to continue, with eight cases reported in October so far. Customers of DBS, Hongkong and Shanghai Banking Corporation, as well as Dah Sing have been among the targets of the criminals. With the rise of financial technology firms and mobile banking apps, experts predict that novice mobile banking users will become prime targets.

    Digital Banks Attract Attackers

    While the use of digital banking tools is spreading quickly, the technology is also attracting the attention of cybercriminals, said cybersecurity specialist Securelist in a report earlier this year. «We are sure that the world of cybercrime will see increasing attacks against this type of banks and their customers,» Securelist said in its report

    Fraudsters have long tried to trick users to visit fake bank website via e-mail messages pretending to be from the bank. On these fake websites, they try to trick account holders into revealing their access credentials. On mobile devices, the connection with the bank is typically via an application, rather than a website.

    Tricks Of Criminals

    Banks’ usage of chat applications increases the possibility that criminals could try impersonating the bank in social media chats and try to trick users into downloading and installing an «updated» version of the bank’s app. In reality, such an app would be malicious and could help attackers steal credentials from the phone.

    «Other social engineering scams have emerged which try and trick the genuine user into revealing the authentication code for their chat app and hence lose control of the account. Even if this is only temporary, it may allow enough time for a fraud to be perpetrated,» Jackson said in an interview.

    Attacks Focused On Smaller Vendors

    Experts predicts there could be more attacks on fintechs or payment providers going forward. This is due to lower investments into cybersecurity versus traditional banks, and criminals’ evolving technological skills.

    «Large financial organizations invest considerable resources in cybersecurity, thus the penetration of their infrastructure is not an easy task. However, a threat vector that is likely to be actively used by cybercriminals in the coming year is attacks on software vendors supplying financial organizations,» Securelist said. Most of these vendors have a lower level of protection compared with the financial organizations themselves.

    Attacks Via Software

    For the coming year, the cybersecurity experts expect criminals to stage attacks via software for the finance business, including such for ATMs and PoS terminals. «A few months ago we registered the first attempts of this kind, when attackers embedded a malicious module into a firmware installation file, and placed it on the official website of one of the American ATM software vendors,» Securelist wrote.

    Based on a 2017 study by Accenture, the financial services industry posted annual costs of nearly $18.3 million per firm from cyber attacks.

  • China’s online retail market to reach $1.1tn soon

    China’s online retail market to reach $1.1tn soon

    China’s online retail market will hit $1 trillion this year, a year ahead of predictions, according to Forrester.

    The Forrester report revealed the growth in mobile shopping and consumer spending in categories like fashion and grocery would see China’s retail sales reach $1.1tn in 2018.

    Chinese online shoppers will continue to grow by 4.6% annually to reach 631 million by 2022, up from the current 502 million.

    The report, which provides online retail forecasts for Asia Pacific, found China remains the largest market accounting for close to 83% of all retail sales across the region.

    Japan is the second largest with $97bn, followed by South Korea with $69bn, Australia with $31bn and India with $27bn. India continues to be the region’s fastest growing market and is expected overtake Australia in 2019.

    One-fourth of all retail sales in APAC will occur online by 2022, led by China and South Korea.

    Online retail via mobile devices continues to accelerate across the region and is expected to grow 17.64% annually to reach $1.7tn in 2022, up from $735bn in 2017. Mobile sales will account for 80% of online retail sales in 2022.

  • Stop DDoS from ruining your retail Brand’s sales momentum

    Stop DDoS from ruining your retail Brand’s sales momentum

    On 11 November 2017, Alibaba’s Singles’ Day sales hit a new record high with a 39% increase from last year’s sales. The company’s 2017 profits broke world records of Black Friday and Cyber Monday, marking this Asian sales day as one of the highest revenue sales in history.

    With increasing internet-user penetration, consumer behavior is quickly transitioning in Asia today. Shoppers make most of their retail purchases on-the-go, through mobile applications or via websites. In fact, 90% of this year’s Alibaba sales were made through mobile phones.

    Now more than ever, retail businesses in the Asia-Pacific region need to tap onto an omni-channel approach to be aligned with these changing customer demands. Based on the 2016 e-commerce study, Google and Temasek foresee Southeast Asia to be the next region to boom in this market. The predictions indicated that e-commerce will make up 6% of the region’s total retail sales by 2025.

    Beware of business bullies

    While these statistics show a positive growth for the region, businesses going digital must be aware of the lurking threat factors. The physical shoplifters that pained businesses – especially during big sales such as Great Singapore Sale and Black Friday – have now evolved to become cyber criminals. Unlike thieves, businesses are not physically able to discern these criminals, especially since they attack over the network.

    One of the most devastating kinds of cyberattack for e-commerce businesses today is Distributed Denial of Service (DDoS) which aims to bring down websites, therefore, disrupting online services and businesses. DDoS attacks occur when an unusual and unexpected spike in traffic and connection requests overwhelms a website, slows down the network, or in the worst-case scenario, shuts down the entire system.

    A reliable website that guarantees a good user experience is what defines a successful e-commerce business as it is the main platform for acquiring customers and generating revenues. The damage caused by a network failure or a complete site outage will directly and immediately impact business assets. For instance, Alibaba made US$7 billion within the first 30 minutes of the Singles’ Day sale3. Imagine if they had been hit by a DDoS attack; Alibaba would have lost US$233 million per second. Not only would this be a massive loss, the attack would have also caused long term damage to Alibaba’s brand image and customer loyalty. According to KPMG’s annual consumer survey, one fifth of consumers will turn away from a cyber-attacked company4.

    Don’t fall victim

    With the festive period approaching, online retailers can expect an approximately 20% increase in their web traffic5. To make the most out of this sale period, businesses need to ensure that they are ready to protect themselves against DDoS attacks. This includes re-evaluating their network security to assure they are taking the best protective measures.

    Monitor and Detect

    Businesses cannot fight what they do not know. Monitoring network traffic and flow data with DDoS detection alerts security pros to anomalies before they become full-blown catastrophes.

    One way to get a better understanding of what is happening on the network is baselining to know what the traffic looks like during peacetime. This allows organizations to take the appropriate wartime countermeasures when an attack happens. Effective DDoS detection needs to be able to discern the human traffic from the bots.

    Additionally, organizations need a detection solution that can scale given that attacks are increasingly getting larger in size. The best class solution should not only be able to process the data, but also be equipped with the ability to quickly make intelligent decisions with that data.

    Mitigate and Protect

    DDoS protection requires having the right mitigation in place. Businesses should look for a modern DDoS solution that empowers them to automate defenses – from reports to packet captures to mitigation. This can help security pros reduce stress and thwart attacks quickly.

    Communicate

    As with all security procedures, effective DDoS defense involves a human element, as well. It is imperative for businesses to have a communication plan in place in the event of an attack. This includes critical information such as who to notify during, and after an attack. For example, who should be the first to know if the site goes down due to a DDoS attack? Is that the same person notified if a DDoS attack shuts down the online retail site? Who else is notified if an attack happens? Having communications ironed out ahead of time can reduce time to remediation and lower stress levels.

    Make the most of this year’s sale season

    For businesses, these next few months are the time to peak your revenue and customer traffic. It may be a chance to raise brand awareness or even expand the business. Whichever the case, a DDoS attack can be a fatal roadblock to an organization’s goals. Reacting in an efficient manner is key. Online retailers need to ensure they have an emergency response plan that makes good use of anti-DDoS technologies for unforeseeable attacks. For a happy holiday for all, be on the lookout for any dangers and take the right cautionary actions to protect against any potential threats.

     

  • Android ransomware abuses accessibility services

    Android ransomware abuses accessibility services

    ESET researchers have discovered DoubleLocker, an innovative Android malware that combines a cunning infection mechanism with two powerful tools for extorting money from its victims.

    “DoubleLocker misuses Android accessibility services, which is a popular trick among cybercriminals,” commented Lukáš Štefanko, the ESET malware researcher who discovered DoubleLocker.

    “Its payload can change the device’s PIN, preventing the victim from accessing their device and encrypts the victim’s data. Such a combination hasn’t been seen yet in the Android ecosystem.”

    On top of being ransomware, DoubleLocker is based on the foundations of a particular, already documented banking Trojan. According to Štefanko, the functionality for harvesting users’ banking credentials and wiping out their accounts can be added easily.

    “The additional functionality will turn this malware into what can be called ransom-banker,” warns Lukáš Štefanko, who claims he spotted a test version of such a ransom-banker in the wild in May 2017.

  • Heightened danger in Singapore as cyber attacks increase

    Heightened danger in Singapore as cyber attacks increase

    Ransomware has rapidly moved from a “nuisance” to a public threat which could now endanger lives, a director of Singapore’s Cyber Security Agency told the CommunicAsia2017 conference on Tuesday.

    Ho Ka Wei, a director at the National Cyber Threat Analysis Center at the Cyber Security Agency of Singapore, said an increase in attacks in recent weeks-including the global WannaCry attack-has put agencies on “high alert” and led to “sleepless nights and non-stop action.”

    Ransomware attacks on the health system and facilities such as hospitals have the potential to threaten people’s lives, he said.

    “The number of attacks is increasing,” said Ho. “No one is spared.”

    “Critical infrastructure and government institutions continue to be attractive targets, and we see new sophisticated forms of ransomware and malware,” he said. “And now they are coming in malicious combos like WannaCry-which is both ransomware and a worm.”

    Attacks were also increasing in strength and power, with some measured at over one terabyte per second, where previously “20 gigabytes a second was considered quite high.”

    Ho outlined recent Advanced Persistent Threat (APT) attacks at two Singapore Universities in April, which were “carefully planned” with perpetrators seeking to steal government information and research.

    The APTs were designed to gain unauthorized access to networks and lurk there for long periods to access information.

    These attacks, at NTU and NTS, were identified and computers were isolated and then replaced.

    The threat environment, said Ho, escalates on a monthly basis, and will reach new levels with the unstructured rise of the IoT if rigorous action is not taken and standards enforced.

    “If IoT devices are unsecured by default, then they can be controlled and used,” said Ho. “The level of escalation is serious.”

    Singapore created the Cyber Security Agency two years ago under the auspices of the Prime Minister’s Office, and the country announced its first Cyber Strategy in October last year.

    Ho outlined four pillars to the strategy: to build a resilient infrastructure, create safer cyberspace, develop a vibrant cybersecurity ecosystem, and strengthen international partnerships.

    Digital technology, he said, was critical to Singapore’s “smart nation efforts” and the increased number of attacks from “new vectors” was a key national risk to overcome.

  • BlackBerry working with automakers on anti-hack tool

    BlackBerry working with automakers on anti-hack tool

    BlackBerry is working with at least two automakers to develop a security service that would remotely scan vehicles for computer viruses and tell drivers to pull over if they were in critical danger, according to a financial analyst.

    The service, which would also be able to install security patches to an idle car, is being tested by luxury automakers Aston Martin and Range Rover, Macquarie analyst Gus Papageorgiou said in a note to clients sent late on Monday.

    Auto security is among several areas that BlackBerry is betting will boost its revenue after the Canadian company lost its dominance of the smartphone market to Apple Inc and others over the past decade.

    John Wall, the head of BlackBerry’s QNX division, and company spokeswoman Sarah McKinney both declined to comment.

    Matthew Clarke, a spokesman for Aston Martin, said in an email he was not aware of the company testing such a product. Representatives with Range Rover’s parent company, Jaguar Land Rover, could not be reached for comment.

    The service could be launched as early as next year, generating about $10 a month per vehicle for BlackBerry, according to Papageorgiou, who has followed BlackBerry for more than 15 years.

    Vehicles increasingly rely on dozens of computers that connect to each other as well as the internet, mobile networks and Bluetooth communications systems that make them vulnerable to remote hacks.

    “Although a connected, more software-centric automobile offers tremendous advantages to consumers, it also opens the doors to hackers,” Papageorgiou wrote in his note.

    Automaker interest in cyber security has risen dramatically since 2015, when two hacking experts uncovered vulnerabilities in Fiat Chrysler vehicles that led to a U.S. recall of 1.4 million autos.

    BlackBerry shares rose 5.3 percent to close at C$13.84 after touching C$14.15, the highest since March 2015.

  • Cyber attack not disrupting stock market at IDX

    Cyber attack not disrupting stock market at IDX

    WannaCry malware attack has not disrupted the countrys share market, Tito Sulistio, President Director, Indonesia Stock Exchange (IDX), stated here, Monday.

    “The stock authority performs a routine check two hours before opening at 9 a.m. I directly oversaw todays monitoring system; I hope the market is protected from any threats, including the virus (ransomware),” Sulistio said in Jakarta.

    Some 88 countries, including Indonesia, have adopted a multi-layered security system which was already being used by US-based Nasdaq stock market.

    “We have Nasdaqs JATS-NextG (Jakarta Automated Trading System Next Generation) in our security protocols,” Sulistio revealed, while adding that the stock authority would continue to protect the system from any upcoming threats.

    During a separate occasion, earlier, Adena T Friedman, Nasdaq President, remarked her agency had committed to support IDXs trading and monitoring systems.

    “We have been partnering with Indonesia Stock Market to provide technology application for improving supervision and trading activities,” Friedman affirmed.

    Concerning the malware threat, the Indonesian Internet Service Providers Association (APJII) had suggested several preventive acts to reduce the impact of ransomware WannaCry.

    As the malware has infected only Microsoft-based computers, users have been asked to update the system by downloading Security Update Patch MS-17-010.

    “If the users are not aware about system updates, they can disconnect from any internet wires (LAN), or Wifi, and download the security patch from a non-Microsoft computer.

    Rifan has also recommended that users back up their files in a separate flash drive (USB) or a portable hard disk, before updating the security system on the computer.

    He further revealed that WannaCry malware had attacked computers in some 200 countries, including Indonesia.

    The malware works by locking the computers internal system and encrypting the file, after which the users are asked to pay a “ransom” in exchange for their data.