Retail News CRM

Tag: Malware

  • Coupang Data Breach: Unmasked Details of 33 Million Customers Sparks Privacy Fears

    Coupang Data Breach: Unmasked Details of 33 Million Customers Sparks Privacy Fears

    Increased apprehension has gripped South Korea following a significant data leak at e-commerce giant, Coupang. Officials have indicated that this breach could have been overlooked for an extended period.

    Scale of Data Leakage

    Coupang, a United States-listed merchant, revealed on a recent Saturday that the private information of 33.7 million consumers, essentially its entire client base, had been jeopardized. The vulnerable data encompass names, contact numbers, email addresses, and delivery locations. The company reassured that financial information, credit card specifics, and login details remained untouched.

    Based on Coupang’s findings, unauthorized infiltration into the delivery-related private data seems to have been carried out via foreign servers from June 24 onwards.

    Investigation Update

    Individuals familiar with the situation have shared that the police have pinpointed at least one suspect. The person is allegedly a former Chinese worker of Coupang who has since dissociated from both the company and the nation. The authorities initiated an inquiry after receiving a complaint.

    Coupang confirmed detecting the data leak on November 18 and informed the regulators within the subsequent two days. The corporation initially stated that approximately 4,500 accounts had been impacted.

    Implications of the Breach

    The magnitude of the data exposure, which is now proven to be considerably more extensive and long-standing than initially conveyed, has unsettled consumers. They are apprehensive that their data might be exploited for fraudulent activities or phishing strategies. The event now surpasses the cyber breach at SK Telecom in April, which affected data from 23.2 million users and led to a record penalty of 134.8 billion won.

    The final repercussions could escalate as the investigation progresses. A similar recent incident involving Lotte Card initially denied leakage of financial data following a breach in September. The company had to backtrack two weeks later and admit that credit card numbers and other critical data had indeed been laid bare.

    Questions & Answers

    What type of data has been compromised in the breach at Coupang?
    Names, phone numbers, email addresses, and delivery locations of customers have been exposed.

    Who has been identified as a possible suspect in this data breach incident?
    The police have identified a former Chinese worker of Coupang as a possible suspect.

    What are the possible implications of the data breach at Coupang?
    This breach has unsettled consumers who fear their personal data might be exploited for fraudulent purposes or phishing schemes. There is also a possibility of monetary penalties for the company.

  • SK Telecom Hit by Cyber Attack

    SK Telecom Hit by Cyber Attack

    The mobile carrier reported that the breach occurred due to malicious code infiltrating its systems. While the exact scope and nature of the data leak are still under investigation, the company stated it took immediate steps to report the incident to the Korea Internet and Security Agency (KISA), aligning with regulatory requirements.

    In a message to employees, CEO, Ryu Young-sang, conveyed his regret and accepted responsibility for the breach. He urged staff to take stronger measures to improve the company’s cybersecurity framework and enhance efforts to protect customer data.

    SK Telecom confirmed it has notified the Personal Information Protection Commission of the incident and is working closely with investigators. The company added that it promptly deleted the malicious code and isolated the affected equipment upon detecting a possible breach. There have been no confirmed reports of the leaked data being misused.

    The company said it will adopt stronger security measures, including comprehensive system inspections, upgraded detection and blocking systems for illegal SIM-related activities, and improved alert protocols in cases of potential threats. A free SIM protection service is also being offered through its website and T World platform.

    In response to the incident, the Ministry of Science and ICT (MSIT) has set up an emergency task force in collaboration with the Cyber Security and Network Policy Bureau. The ministry requested that SK Telecom preserve and submit relevant data for analysis. Officials from KISA were dispatched to the telecom provider’s Seoul headquarters for an on-site investigation.

    Depending on the outcome of the investigation, the government may form a joint task force encompassing both the public and private sectors to co

  • 26 million devices are infected by malware that steals bank card data including passwords

    26 million devices are infected by malware that steals bank card data including passwords

    25 million device users were targeted by a certain type of malware attack in 2023 and 2024. Infostealer malware does exactly what its name would suggest it does and grabs important information such as bank card numbers, passwords, and other sensitive data. Cyber security firm Kaspersky estimates that 2.3 million bank cards were leaked on the dark web in 2023-2024. The company says that every 14th infostealer infection ends up with the attacker scoring stolen bank card data.

    Including the 9 million devices infected by infostealers in 2024 alone, a total of 26 million have been, in the words of Kaspersky, “compromised” by such malware. While only 1% of bank cards issued globally have been leaked on the dark web, 95% of the card numbers spotted are “technically valid” according to the report. But there’s more to this type of malware that goes beyond stealing bank card account numbers.

    Kaspersky’s report goes on to state that this malware also steals credentials which is information used to verify a user’s identity. And that includes passwords. This data, along with cookies, are distributed to the dark web community. Victims can get into trouble without realizing that they are about to infect their phone, tablet, or computer. An infostealer is often disguised as legitimate software. Kaspersky’s report uses a game cheat as an example. The victim typically downloads the software and runs a malicious file.

    The malware is then spread to other devices via phishing links, malicious email attachments, infected websites, and other methods. Last year, Redline was the most widespread infostealer as it accounted for 34% of infections. The fastest growing of the infostealers was Risepro whose share of infections rose from 14% in 2023 to 23% last year. Another rapidly growing infostealer is Stealc which debuted in 2023 with a 3% share of infections. That number grew to 13% in 2024.

    Kaspersky says that if you do find yourself the victim of an infostealer, monitor your bank accounts and notifications. Have your bank card reissued and change the passwords for your bank app and website. Enable two-factor authorization and set spending limits if your bank allows you to do so. Be on the lookout for phishing attacks, fake texts, and bogus phone calls. If you’re not sure if a notification, email, or text is legit, call your bank. Kaspersky also suggests running security scans on your devices making sure to remove any detected malware.

  • Do not install this fake Flash Player Android app even if a friend urges you to

    Do not install this fake Flash Player Android app even if a friend urges you to

    What do you get when you combine the untimely death of a hugely popular piece of software once used on everything from smartphones to PCs with the insatiable thirst for unlawful financial gains of highly skilled hackers?

    A scary new malware campaign that, to be perfectly honest, should be pretty easy to avoid by now for anyone who’s done even the least amount of research possible on this sort of stuff before. Of course, it’s never too late to start educating yourself on the daily dangers of modern mobile life, and the first thing you need to keep in mind is that you should never, ever, ever, EVER download an Android app from an untrusted source.

    Unfortunately, because the bad actors behind this latest “FluBot” distribution scheme know exactly what they’re doing, you might receive a link to a shady website trying to feed you the vicious aforementioned banking trojan via a bogus Flash Player app from someone you 100 percent trust, like a close friend, family member, or someone else from your contacts list.

    That’s because, once your phone is infected, one of the symptoms of said infection will be the unauthorized access of your contacts, with the added malware ability to send text messages without user permission.

    Bottom line, no matter where a link seems to be coming from, you should exercise good judgment and refuse to install random APK (Android Package) files. We know, we miss Adobe’s Flash too, but the San Jose-based software giant would never use APKs to revive something that’s been dead since 2020 and dying since 2017.

    Of course, the sneakiness of this malware campaign’s authors can often go beyond just sending a text from one random Android user to a friend or family member. Because asking someone to download a “Flash Player” app from outside the Play Store would be too obvious a tell for many people, the malicious texts you should… simply ignore may try to fool you into opening links by advertising various video-related things.

    A good idea in such a case would probably be to ask whoever sends you a message containing a potentially malicious link one or two simple questions, thus making sure their intentions are pure.

    If the name FluBot happens to ring a bell, that might be because the same trojan has infected countless devices in the past using methods as diverse as posing as a security update, parcel delivery notice, and other legit apps from popular developers.

    While the main goal is and always has been to steal money with the help of banking credentials you might have stored on your Android phone, the secondary purpose is to spread like wildfire by hijacking your contacts and messages.

  • Malware costs Vietnam $900 mln

    Malware costs Vietnam $900 mln

    Malware caused Vietnamese users damage worth VND20.89 trillion ($900.8 million) last year, up 40 percent year-on-year.

    The surge came with the rising number of computers contaminated with malware from advanced persistent threats (APT), according to a report released Thursday by Vietnam’s cybersecurity firm BKAV.

    The number of computers infected with malware rose 3.5 percent year-on-year to 85.2 million in 2019. This means 57.7 percent of computers nationwide were infected.

    Increasing virus infections occurred via email, from 4 percent of the 2018 total to 20 percent last year.

    Another reason for the high contamination is Vietnamese users’ habit of downloading files without checking the authenticity. Eight out of 10 computers were infected with malware because of this behavior, the report stated.

    Rising threats resulted in 1.8 million computers losing data last year, up 12 percent from 2018.

    A large-scale foreign attack last year saw the hack of devices via manipulation of weak passwords.

    The attack caused 420,000 computers to be infected with dangerous W32. Fileless malware, which BKAV experts say have “invisibility” as it does not leave behind traces on hardware like other malware.

    BKAV forecast malware would become increasingly dangerous this year as hackers use them for financial benefits, like accessing bank accounts.

  • IoT malware grew threefold in H1

    IoT malware grew threefold in H1

    In the first half of 2018, IoT devices were attacked with more than 120,000 modifications of malware, according to the Kaspersky Lab IoT report. That’s more than triple the amount of IoT malware seen in the whole of 2017.

    Kaspersky Lab warns that the snowballing growth of malware families for smart devices is a continuation of a dangerous trend: 2017 also saw the number of smart device malware modifications rise to 10 times the amount seen in 2016.

    The market for IoT devices and their role in everyday life, is growing exponentially. But cybercriminals are seeing the financial opportunities too, and are multiplying and differentiating their attacks as a result.

    The danger for consumers who love their IoT gadgets, is that threats can strike unexpectedly, turning seemingly harmless devices into powerful machines for illegal activity. This can include malicious cryptocurrency mining, DDoS attacks, or the discreet inclusion of devices in botnet activities.

    Aware of these dangers, Kaspersky Lab experts regularly review the data collected from various sources including our honeypots – decoy devices used to attract the attention of cybercriminals and analyze their activities. The latest updates are striking: during the first half of 2018, the number of malware modifications aimed at IoT devices registered by researchers was more than three times higher than the number registered in the whole of 2017.

    The statistics show that the most popular method of IoT malware propagation is still the brute forcing of passwords – repetitive attempts at various password combinations. Brute forcing was used in 93% of detected attacks. In most of the remaining cases, access to an IoT device was gained using well-known exploits.

    The devices most often attacking Kaspersky Lab honeypots were routers (by a large margin). 60% of the registered attempts to attack our virtual devices were coming from them. The remaining share of compromised IoT gadgets included a variety of different technologies, such as DVR-devices and printers. The honeypots even registered an attack coming from 33 washing machines.

    Different cybercriminals may have different reasons to exploit IoT, but the most popular goal is to facilitate DDoS-attacks by creating botnets. Some malware modifications are also tailored to turn off competing malware, fix its own vulnerabilities and shutdown vulnerable services on the device.

    “Compared to personal computers and smartphones, IoT devices might not seem powerful enough to attract cybercriminals and be used in their illegal activity,” notes Mikhail Kuzin, security researcher at Kaspersky Lab. “However, their lack of performance is more than outweighed by their number, and the fact that some smart gadget manufacturers are still not paying enough attention to the security of their products.”

    Kuzin adds that even if vendors begin to provide their devices with better security now, it will be a while before old vulnerable devices have been phased out of our homes.

    “In addition, IoT malware families are customizing and developing very fast, and while previously exploited breaches have not been fixed, criminals are constantly discovering new ones. IoT products have therefore become an easy target for cybercriminals who can turn simple machines into a powerful device for illegal activity, such as spying, stealing and blackmailing.”

  • Emerging APAC nations most exposed to malware

    Emerging APAC nations most exposed to malware

    Emerging APAC nations are the most vulnerable to malware, according to Microsoft’s bi-annual Security Intelligence Report (SIR).

    Of the top locations across the globe most at risk of malware infection in the first quarter of 2017, most of them are developing economies in the region.

    The report found that Bangladesh and Pakistan have the highest malware encounter rates around the world. This is followed by two ASEAN nations – Cambodia and Indonesia. Approximately one in four computers running Microsoft real-time security products in these countries reported a malware encounter from January to March 2017.

    Other top areas facing malware threats include Myanmar, Nepal, Thailand, Vietnam, each with an average malware encounter rate of more than 20% in the first quarter of 2017. This is more than double the global average of 9%.

    On the other hand, markets with higher levels of IT maturity, namely Australia, Hong Kong, Japan, New Zealand and Singapore, performed better than the worldwide average. In fact, Japan has been ranked the safest country in the world, with only 2% of its computers reporting a malicious program incident.

    Ransomware attacks on the rise

    Ransomware is one of the most infamous malware families in 2017. In the first half of the year, two waves of ransomware attacks, WannaCrypt and Petya, exploited vulnerabilities in outdated Windows operating systems worldwide, disabling thousands of devices by illegitimately restricting access to data, through encryption. This not only disrupted individuals’ daily lives but also crippled many enterprises’ operations.

    The attacks were disproportionately concentrated in Europe while most of the Asia markets have not been too heavily impacted. In fact, Japan and China were listed as the two top countries with the lowest ransomware encounter rates. One of the few exceptions in the region is Korea, which has the second highest ransomware occurrence rate worldwide.

    Attackers evaluate several factors when determining which regions to target, such as a country’s GDP, average age of computer users and available payment methods. A region’s language can also be a key contributing factor as a successful attack often depends on an attacker’s ability to personalize a message to convince a user to execute the malicious file.

    Cloud accounts and services under cyber siege

    As cloud migration increases, the cloud has become the central data hub for the majority of organizations. This also translates into more valuable data and digital assets being stored the cloud, making it an increasingly attractive target for cybercriminals.

    The SIR highlighted a 300% increase in consumer and enterprise accounts managed in the cloud being attacked globally over the past year while the number of logins attempted from malicious IP addresses have increased by 44% year-over-year.

    In addition, a large majority of these security compromises were the result of weak, guessable passwords and poor password management, followed by targeted phishing attacks and breaches of third-party services. As the frequency and sophistication of attacks on user accounts in the cloud accelerates, there is an increased emphasis on the need to move beyond passwords for authentication.

    Malware Encounter Rates for Markets in Asia in Q1 2017 (from highest to lowest):

    1. Bangladesh
    2. Pakistan
    3. Cambodia
    4. Indonesia
    5. Mongolia
    6. Myanmar
    7. Vietnam
    8. Nepal
    9. Thailand
    10.  Philippines
    11.  Sri Lanka
    12.  China
    13.  India
    14.  Malaysia
    15.  Taiwan
    16.  Korea
    17.  Hong Kong
    18.  Singapore
    19.  Australia
    20.  New Zealand
    21.  Japan
  • Cyber attack not disrupting stock market at IDX

    Cyber attack not disrupting stock market at IDX

    WannaCry malware attack has not disrupted the countrys share market, Tito Sulistio, President Director, Indonesia Stock Exchange (IDX), stated here, Monday.

    “The stock authority performs a routine check two hours before opening at 9 a.m. I directly oversaw todays monitoring system; I hope the market is protected from any threats, including the virus (ransomware),” Sulistio said in Jakarta.

    Some 88 countries, including Indonesia, have adopted a multi-layered security system which was already being used by US-based Nasdaq stock market.

    “We have Nasdaqs JATS-NextG (Jakarta Automated Trading System Next Generation) in our security protocols,” Sulistio revealed, while adding that the stock authority would continue to protect the system from any upcoming threats.

    During a separate occasion, earlier, Adena T Friedman, Nasdaq President, remarked her agency had committed to support IDXs trading and monitoring systems.

    “We have been partnering with Indonesia Stock Market to provide technology application for improving supervision and trading activities,” Friedman affirmed.

    Concerning the malware threat, the Indonesian Internet Service Providers Association (APJII) had suggested several preventive acts to reduce the impact of ransomware WannaCry.

    As the malware has infected only Microsoft-based computers, users have been asked to update the system by downloading Security Update Patch MS-17-010.

    “If the users are not aware about system updates, they can disconnect from any internet wires (LAN), or Wifi, and download the security patch from a non-Microsoft computer.

    Rifan has also recommended that users back up their files in a separate flash drive (USB) or a portable hard disk, before updating the security system on the computer.

    He further revealed that WannaCry malware had attacked computers in some 200 countries, including Indonesia.

    The malware works by locking the computers internal system and encrypting the file, after which the users are asked to pay a “ransom” in exchange for their data.

  • Mobile malware infections continue to rise

    Mobile malware infections continue to rise

    Nokia’s latest Threat Intelligence Report indicates that there was a steady increase in mobile device infections throughout 2016.

    Malware struck an estimated 1.35% of all mobile devices in October – the highest level seen since reporting started in 2012.

    The overall infection rate meanwhile increased 63% sequentially in the second half of 2016.

    Smartphones were the top malware targets by far, accounting for 85% of all mobile device infections in the second half of 2016. The report also revealed a surge of nearly 400% in smartphone malware attacks in 2016.

    While Android-based smartphones and tablets continued to be the primary targets (81%), reflecting the prevalence of the operating system worldwide, iOS-based devices also suffered attacks in the second half of the year (4%), primarily by Spyphone surveillance software that tracks users’ calls, text messages, social media applications, web searches, GPS locations and other activities.

    The Threat Intelligence Report also exposed major vulnerabilities in the rapidly expanding universe of IoT devices, underscoring the need for the industry to re-evaluate its IoT deployment strategies to ensure these devices are securely configured, managed and monitored.

    In late 2016, the Mirai botnet assembled an army of compromised IoT devices to launch three of the largest DDoS attacks in history, including an assault that took down many high-profile web services. These attacks underscored the urgent requirement for more robust security capabilities to protect IoT devices from future attacks and exploitation.

    ”The security of IoT devices has become a major concern,” commented Kevin McNamee, head of the Nokia Threat Intelligence Lab. “The Mirai botnet attacks last year demonstrated how thousands of unsecured IoT devices could easily be hijacked to launch crippling DDoS attacks. As the number and types of IoT devices continue to proliferate, the risks will only increase.”

    The report also indicates that Windows/PC systems accounted for 15% of malware infections in the second half of 2016, down from 22% in the first half of the year.

    The monthly infection rate in residential fixed broadband networks averaged 10.7% in the second half of 2016, down from 12% in the first half, and down from 11% in late 2015.

    While moderate threat level adware activity decreased in the second half of 2016, high-level threats (e.g., bots, rootkits, keyloggers and banking Trojans) remained steady at approximately 6%.

  • Global Threat Index shows rise in malware attacks

    Global Threat Index shows rise in malware attacks

    The number of malware attacks increased in October, according to Check Point Software’s monthly Global Threat Index.

    Check Point’s Threat Intelligence Research Team found that both the number of active malware families and number of attacks increased by 5% during the period, pushing the number of attacks on business networks to near peak levels, as seen earlier this year.

    Locky ransomware attacks continued to rise, moving it up from third to second place, while the Zeus banking trojan moved up two spots, returning it to the top three.

    The reason for Locky’s continued growth is the constant variation and expansion of its distribution mechanism, which is primarily through spams emails. Its creators are continually changing the type of files used for downloading the ransomware, including doc, xls and wsf files, as well as making significant structural changes to the spam emails.

    The actual ransomware itself is nothing exceptional, but cyber criminals are investing a lot of time into maximizing the number of machines that become infected by it.

    For the seventh consecutive month, HummingBad, an android malware that establishes a persistent rootkit to carry out an array of malicious purposes, remained the most common malware used to attack mobile devices.

    Once again Conficker retained its first place position as the world’s most prevalent malware, responsible for 17% of recognized attacks. Both second placed Locky, which only started its distribution in February of this year, and third placed Zeus, were responsible for 5% of known attacks.

    “With the number of attacks and malware families increasing, the scale of the challenge organizations face in ensuring their networks remain secure is tremendous,” Check Point head of threat protection Nathan Shuchami said.

    “It is particularly concerning that a malware family as established and well known as Conficker is so effective, suggesting that organizations aren’t using the latest, multi-layered defenses.”