Retail News CRM

Tag: ransomware

  • TRAI Takes Action Against Spam and Cyber Fraud: What Retailers Need to Know!

    TRAI Takes Action Against Spam and Cyber Fraud: What Retailers Need to Know!

    In a bid to address the growing menace of spam, cyber fraud, and the misuse of telecom infrastructure, the Telecom Regulatory Authority of India (TRAI) gathered the Joint Committee of Regulators (JCoR) on Tuesday. This pivotal meeting took place at TRAI’s headquarters, bringing together influential figures from various sectors.

    Representatives from top regulatory bodies, including the Reserve Bank of India (RBI), the Securities and Exchange Board of India (SEBI), the Insurance Regulatory and Development Authority of India (IRDAI), and the Pension Fund Regulatory and Development Authority (PFRDA), joined their counterparts from the Ministry of Electronics and Information Technology (MeitY). Also present were officials from the Department of Telecommunications (DoT), the Ministry of Home Affairs (MHA), and the National Payments Corporation of India (NPCI).

    A united front against digital threats

    During the meeting, TRAI Chairman Anil Kumar Lahoti emphasized the necessity of collaboration among different regulatory bodies in an increasingly digital marketplace. He said, “In a digital-first economy, collaboration among financial sector regulators, digital communication regulators, and security agencies becomes paramount. TRAI appreciates the swift collaboration being facilitated through JCoR in building a reliable and safer communication environment.”

    The agenda took a concentrated approach at combating digital payment fraud while enhancing consumer protection measures. One significant proposal discussed was the phased adoption of a dedicated 1600-series number range for service and transactional calls in banking and finance, aimed at reducing confusion and potential scams.

    Innovating security with digital consent

    Additionally, the meeting reviewed advancements in the Digital Consent Acquisition (DCA) pilot. This innovative initiative replaces traditional paper-based consent methods with a secure digital system, making the process streamlined and efficient. The pilot, a joint effort between TRAI and RBI, involves participation from major telecom companies and banks, including SBI, PNB, ICICI, HDFC, Axis Bank, Canara Bank, and Kotak Mahindra Bank.

    Speeding up fraud prevention

    To further combat fraud, the regulators discussed methods for facilitating automatic data sharing between the Indian Cyber Crime Coordination Centre (I4C), the DoT’s Digital Intelligence Platform, and the telecom industry’s Distributed Ledger Technology (DLT) systems. This collaboration is intended to expedite responses to fraudulent activities involving illicit phone numbers and telecom resources.

    Concerns about the misuse of SIP and PRI lines for bulk spam calls were also raised, leading participants to explore remedies such as assigning these lines from controlled number ranges and implementing additional security measures. This meeting followed a workshop co-hosted by TRAI and RBI, where banks and telecom providers delved into DCA’s development and pledged to enhance collaboration.

    Questions & Answers

    What key topics did the TRAI meeting focus on?
    The meeting centered on tackling spam, cyber fraud, and enhancing consumer protection, particularly in the context of digital payments.

    Which organizations participated in the JCoR meeting?
    Representatives from the TRAI, RBI, SEBI, IRDAI, PFRDA, MeitY, DoT, MHA, and NPCI were present, highlighting a robust collaboration across various sectors.

    What is the significance of the Digital Consent Acquisition pilot?
    The DCA pilot aims to streamline communication consent by replacing paper-based approvals with a secure digital system, involving major telecom operators and banks.

  • 26 million devices are infected by malware that steals bank card data including passwords

    26 million devices are infected by malware that steals bank card data including passwords

    25 million device users were targeted by a certain type of malware attack in 2023 and 2024. Infostealer malware does exactly what its name would suggest it does and grabs important information such as bank card numbers, passwords, and other sensitive data. Cyber security firm Kaspersky estimates that 2.3 million bank cards were leaked on the dark web in 2023-2024. The company says that every 14th infostealer infection ends up with the attacker scoring stolen bank card data.

    Including the 9 million devices infected by infostealers in 2024 alone, a total of 26 million have been, in the words of Kaspersky, “compromised” by such malware. While only 1% of bank cards issued globally have been leaked on the dark web, 95% of the card numbers spotted are “technically valid” according to the report. But there’s more to this type of malware that goes beyond stealing bank card account numbers.

    Kaspersky’s report goes on to state that this malware also steals credentials which is information used to verify a user’s identity. And that includes passwords. This data, along with cookies, are distributed to the dark web community. Victims can get into trouble without realizing that they are about to infect their phone, tablet, or computer. An infostealer is often disguised as legitimate software. Kaspersky’s report uses a game cheat as an example. The victim typically downloads the software and runs a malicious file.

    The malware is then spread to other devices via phishing links, malicious email attachments, infected websites, and other methods. Last year, Redline was the most widespread infostealer as it accounted for 34% of infections. The fastest growing of the infostealers was Risepro whose share of infections rose from 14% in 2023 to 23% last year. Another rapidly growing infostealer is Stealc which debuted in 2023 with a 3% share of infections. That number grew to 13% in 2024.

    Kaspersky says that if you do find yourself the victim of an infostealer, monitor your bank accounts and notifications. Have your bank card reissued and change the passwords for your bank app and website. Enable two-factor authorization and set spending limits if your bank allows you to do so. Be on the lookout for phishing attacks, fake texts, and bogus phone calls. If you’re not sure if a notification, email, or text is legit, call your bank. Kaspersky also suggests running security scans on your devices making sure to remove any detected malware.

  • Personal Data of Passengers, Employees Stolen in Ransomware Attack on AirAsia

    Personal Data of Passengers, Employees Stolen in Ransomware Attack on AirAsia

    AirAsia, a budget airline that operates out of Malaysia, is dealing with the aftermath of a ransomware attack that saw the personal data of some five million people stolen.

    To add insult to injury, the gang of responsible cyber criminals said they would not follow up on the beleaguered airline due to how “sloppy” its internal organization and management appeared to be.

    The perpetrators of the ransomware attack appear to be “Daixin Team,” a group that is thought to be based in or around China and that has become active enough in recent months to merit an alert from the FBI and CISA. The group has been active since at least June 2022, but previously had shown a strong preference for targeting healthcare and public health facilities via unpatched VPN vulnerabilities.

    The ransomware attack on AirAsia occurred on November 11 and 12, with samples of the stolen personal data being leaked to the group’s dark web site about a week later. The posted samples contain employee personal information as well as passenger booking information. The group says that it has captured “all employees” personal data and an unspecified quantity of passenger data.

    While Daixin Team continues to shake down AirAsia using the stolen personal data, it said there would be no further ransomware attacks on the company due to its “chaotic organization” and poor cybersecurity. However, this did not appear to be out of pity, but at frustration at having to sort through a tangled internal network to find information of value; the group said it would leave it to “newcomers” to pick through the “garbage.” However, the hackers also said they would stop short of locking anything that could be life-threatening, such as air traffic control and radar systems.

    Founded in 1993, AirAsia has the largest fleet in Malaysia and flies to the greatest range of international and domestic destinations. The airline carried a total of about 4.81 million passengers in 2021, indicating that the personal data stolen by the attackers may be limited to bookings taking place within the last year or so. Part of the leak of sample data stolen during the ransomware attack shows a database of passenger names with ID numbers and the total cost of their ticket.

    Ransomware attacks have become both more frequent and more expensive to weather in recent years, but they have also become more dangerous. Attackers have now demonstrated that they are willing to cause real-world damage, potentially even death, if they think it will increase their chances of a payout. That was a red line that was really not crossed before the major attacks on critical infrastructure and hospitals in 2021.

    It is unclear if Daixin Team’s claim that it had access to air traffic control and other sensitive airline applications that could cause physical damage is accurate. This would generally require direct access to an individual airport’s systems rather than an airline’s internal network or booking system. There have been numerous attacks on both airlines and the public-facing portion of airport websites at this point, none of which have yielded that sort of access; about the closest example was an attack on Bristol Airport in 2018 that caused outages of the flight status screens for two days, but did not impact actual aircraft operations. Another attack in India earlier this year disrupted flight scheduling for several days, but did not prevent planes from flying. FedEx’s air shipment service has also been hit by ransomware attacks at least twice, but flight operations are not known to have been impacted.

    Ransomware attacks have been demonstrated to be capable of indirectly causing death at this point, however, in the health care industry that Daixin Team likes to target. In 2020 a German patient being transported by ambulance for emergency services was turned away from a hospital that had its systems shut down by ransomware, and died en route to the next closest facility. And in 2021, a baby in Alabama died after a mother was not given tests that may have saved its life, due to ransomware limiting hospital capabilities at the time. Though hospitals are generally not well-funded, hackers target them due to the wealth of personal data they hold and the fact that they cannot afford to have systems down for any length of time.

    Nick Tausek, Lead Security Automation Architect at Swimlane, notes that this is a risk that all types of organizations now need to consider: “Since June of this year, the Daixin Team has attacked several healthcare organizations, including the OakBend Medical Center in Texas and the Fitzgibbon Hospital in Missouri. Both attacks resulted in the exposure of personally identifiable information (PII) on the dark web and represented a significant threat to patient and employee safety. Now, the Daixin Team seems to be shifting towards new targets – global critical infrastructure. Like prior Daixin Team attacks, the attack on AirAsia has resulted in sensitive data exposure. Unfortunately, AirAsia will most likely face large financial burdens and a crisis of confidence from its consumer base due to this attack.”

    “To mitigate the chances of similar attacks in the future, it is imperative that organizations adopt low-code security automation to help detect and respond to threats in real-time by allowing complete visibility into IT environments. Endpoint security tools that integrate low-code security automation give organizations a cohesive protection strategy that protects customers and employees as well as keeps essential services like air travel up and running,” recommended Tausek.

  • Tokio Marine Hit by Ransomware Attack in Singapore

    Tokio Marine Hit by Ransomware Attack in Singapore

    Japanese-headquartered insurer Tokio Marine Group was the latest ransomware victim with an attack launched on its Singapore unit.

    Some of Tokio Marine Insurance Singapore’s (TMiS) internal servers were targeted on July 31, according to a statement, which was isolated detection to prevent further damage. The Japanese insurer also filed reports to local governmental agencies.

    We sincerely apologize for any inconvenience and concern caused to our customers or related parties, the group said.

    The group is still identifying the extent of the damage but thus far, there has been no indication of loss of any customer or confidential information and none of TMiS’ core insurance operating systems were affected.

    The life insurance unit Tokio Marine Life Insurance Singapore (TMLS) was also unaffected as it maintains different servers but TMLS still took immediate action to screen its own servers and adopt additional safeguards.

    Tokio Marine has also appointed an external specialist to perform a third-party analysis of its systems to determine the scope of the attack’s impact.

    A growing number of companies have been victims of attacks via ransomware – typically malware that threatens to publish data or block access unless a ransom is paid.

    In May, French insurer AXA also announced that it was also a ransomware victim in Asia with affected operations in Thailand, Malaysia, Hong Kong and the Philippines.

  • JBS Foods paid hackers US$11 million to end ransomware attack

    JBS Foods paid hackers US$11 million to end ransomware attack

    Meatpacker JBS USA paid the equivalent of $11 million ransom in a cyberattack that disrupted its North American and Australian operations, the company’s CEO has said in a statement.

    The subsidiary of Brazilian firm JBS SA halted cattle slaughtering at all of its US plants for a day last week in response to the cyberattack, which threatened to disrupt food supply chains and further inflate already high food prices.

    The cyberattack followed one last month on Colonial Pipeline, the largest fuel pipeline in the US. It disrupted fuel delivery for several days in the nation’s Southeast.

    The JBS meat plants, producing nearly a quarter of America’s beef, recovered faster than some meat buyers and analysts expected.

    “This was a very difficult decision to make for our company and for me personally,” said Andre Nogueira, CEO of JBS USA of the ransom payment. “However, we felt this decision had to be made to prevent any potential risk for our customers.”

    The Brazilian meatpacker’s arm in the US and Pilgrims Pride Corp, a US chicken company mostly owned by JBS, lost less than one day’s worth of food production. JBS is the world’s largest meat producer.

    Third parties are carrying out forensic investigations and no final determinations have been made, JBS said. No company, customer or employee data was compromised in the attack, it said.

    A Russia-linked hacking group is behind the cyberattack against JBS, a source familiar with the matter said last week. The Russia-linked cyber gang goes by the name REvil and Sodinokibi, the source said.

    The Wall Street journal reported on Wednesday that the JBS ransom payment was made in bitcoin.

    The Justice Department on Monday recovered some $2.3 million in cryptocurrency ransom paid by Colonial Pipeline Co, cracking down on hackers who launched the attack.

  • E-Land hit by ransomware attack as McAfee warns retailers of more to come

    E-Land hit by ransomware attack as McAfee warns retailers of more to come

    One of South Korea’s largest retailers had to shut down nearly half of its retail stores on Sunday after a ransomware attack.  E-Land said its corporate network system was attacked early in the morning, forcing it to close 23 of its 50 NC department stores and NewCore outlets.  According to Yonhap, E-Land quarantined part of its corporate network system to contain the damage and police are now investigating the attack’s origins.  Ransomware is malicious software that blocks us.

  • Android ransomware abuses accessibility services

    Android ransomware abuses accessibility services

    ESET researchers have discovered DoubleLocker, an innovative Android malware that combines a cunning infection mechanism with two powerful tools for extorting money from its victims.

    “DoubleLocker misuses Android accessibility services, which is a popular trick among cybercriminals,” commented Lukáš Štefanko, the ESET malware researcher who discovered DoubleLocker.

    “Its payload can change the device’s PIN, preventing the victim from accessing their device and encrypts the victim’s data. Such a combination hasn’t been seen yet in the Android ecosystem.”

    On top of being ransomware, DoubleLocker is based on the foundations of a particular, already documented banking Trojan. According to Štefanko, the functionality for harvesting users’ banking credentials and wiping out their accounts can be added easily.

    “The additional functionality will turn this malware into what can be called ransom-banker,” warns Lukáš Štefanko, who claims he spotted a test version of such a ransom-banker in the wild in May 2017.