Σάββατο 12 Δεκεμβρίου 2015

Merry Riskmas


People of all ages look forward to Christmas holidays. Children think of the gifts they will receive from Santa, and those of us who are older savor the thought of spending the holidays in joyous company with friends and family. Christmas is considered by most, including myself, as the most wonderful time of year.

Cyber criminals feel the same way about the holidays. They exploit online shoppers’ longing for a good sale by slamming them with phishing scams laden with "special offers" and try to turn our beautiful Christmas to Riskmas.

We have talked about this subject in the past but constant repetition carries conviction.

The holiday season is retailers’ busiest time of year, with an estimated 20% of the year’s shopping taking place between November and December in the UK and over half of online retailers expecting to achieve 20% growth. During this time, retailers arguably face a more difficult problem with IT than other industries for many reasons. The holiday retail "freeze" is underway, which means that any security upgrades or technology additions for retailers are put on hold until after the busy holiday shopping season. For the next few weeks, only critical security patches will get installed. The concept of a holiday IT freeze is outdated in today’s world, and while many retailers implement such a "freeze", there should be exceptions when it comes to areas that support the business. Security should certainly be one of those exceptions.

The main challenge and priority is service availability to the customers, whether it is for online or in-store purchases. At executive level, service availability translates to transactions, which in turn relates to revenue growth. However, executives often neglect the wider collateral damage that can be caused by a data breach, not only in terms of brand damage but also in the resultant fall of consumer confidence and any remediation activities required (legal and operational) to mitigate those losses.

In December 2009, a hacker, then operating under the alias of “igigi,” succeeded in stealing the account credentials for all 32.6 million users after successfully penetrated RockYou, a company which develops games and advertisements for social media sites. All of the information had been stored in clear text, meaning that neither account holders’ usernames nor passwords had been encrypted. Company’s databases were infiltrated as a result of an SQL injection vulnerability, one of the most common security vulnerabilities with respect to web applications today.

Following the breach, the security firm Imperva analyzed the stolen information, portions of which were published online by the hacker. The study revealed that 40% of account holders had used a password consisting only of lowercase letters, 30% had chosen a password less than six characters in length, and nearly 1 in 100 had set their password to "123456".

Nevertheless, companies are not the sole targets of holiday breaches. The amount of unwanted traffic increases significantly before Christmas, and people need to be wary of viruses and other malware. Christmas, like other holidays, is a time of opportunity for junk mailers and information phishers. An ill-advised click can ruin your holiday, when an electronic Christmas card from a friend or business partner installs malware on your computer. People are in holiday spirits and behave more casually in the online environment. For example Christmas greetings sent by email can be disguised so that they look like they have been sent by someone you know. When the unsuspecting recipient opens a picture or link contained in the message, a virus is released.

Back in 2010, just two days before Christmas, attackers sent out an email that spoofed “seasons greetings” from The White House to a number of government employees and contractors. The text of the email was published on Brian Krebs’ website. It read:
“As you and your families gather to celebrate the holidays, we wanted to take a moment to send you our greetings. Be sure that we’re profoundly grateful for your dedication to duty and wish you inspiration and success in fulfillment of our core mission.”
The card then prompted users to click on a link, which downloaded a variant of ZeuS malware.

A control server allegedly based in Belarus manually sent out the email to a small number of recipients, which made the attack undetectable by security traps and sensors. Ultimately, more than 2GB of government documents were stolen in the attack. However, no classified documents were compromised.

On December 2013, Symantec reported a spike in the number of NTP amplification attacks. NTP stands for Network Time Protocol. It was originally developed by a professor at the University of Delaware as a means syncing the clocks of multiple computers.

According to Symantec’s blog post on the topic, NTP attacks are similar to DNS amplification attacks in that they use a small packet to request the delivery of a large amount of data to a specific IP address. In this case, the attackers used the monlist command, a query found in older versions of NTP that sends requesters a list of the last 600 hosts who connected to the server, as part of a series of DDoS attacks against certain targets, including a number of gaming sites in late December. The evolution of NTP amplification attacks in part reflects the Internet’s development thus far.

To sum up, here are some additional tips you can use to avoid becoming a victim of cyber fraud: 
  • Enable 2-factor authentication in all your accounts. You can find a list of services that support this here.
  • Do not respond to unsolicited (spam) e-mail.
  • Do not click on links contained within an unsolicited e-mail. Ask yourself: "Why am I being asked to click here?" If you’re not sure, don’t click!
  • Be cautious of e-mail claiming to contain pictures in attached files; the files may contain viruses. Only open attachments from known senders. Scan the attachments for viruses if possible. Ask yourself: "Does this look authentic?"
  • Avoid filling out forms contained in e-mail messages that ask for personal information.
  • Always compare the link in the e-mail to the link you are actually directed to and determine if they match and will lead you to a legitimate site.
  • Log on directly to the official website for the business identified in the e-mail instead of "linking" to it from an unsolicited e-mail. If the e-mail appears to be from your bank, credit card issuer, or other company you deal with frequently, your statements or official correspondence from the business will provide the proper contact information.
  • Contact the actual business that supposedly sent the e-mail to verify that the e-mail is genuine.
  • If you are requested to act quickly or there is an emergency that requires your attention, it may be a scam. Fraudsters create a sense of urgency to get you to act quickly.
  • Remember if it looks too good to be true, it probably is not.
For organisations: 
  • Ensure your staff are educated ahead of the Christmas period. Phishing presents as much danger to businesses as it does individuals.
  • Get a penetration test now before the Christmas period to test the security of your networks and systems.
Have A Very Merry Christmas and Stay Safe Online!

Δευτέρα 24 Νοεμβρίου 2014

The Ghost of Christmas Yet to Come

Attention holiday shoppers, beware of cyber criminals who are out to steal money and personal information. Scammers use many techniques to defraud consumers, from phishing e-mails offering too good to be true deals on brand-name merchandise to offering quick cash to victims who will re-ship packages to additional destinations. Previously reported scams are still being executed today.

Consider these stats

  • During Christmas period of 2013, online spending was about £13 billion (over US$20 billion) according to Sage Pay.
  • In the UK 2013, 61% of people did at least half of all their Christmas shopping online. This is only set to increase.
  • On 2014, 95% of online shoppers will use companies’ click-and-collect services.
  • eBay expected 2,7 million Christmas-related searches in August. (yes August!!!)
  • Some e-commerce businesses achieve 80% of their total annual revenue during the Christmas period.
While monitoring credit reports on an annual basis and reviewing account statements each month is always a good idea, all of us should keep a particularly watchful eye on our personal credit information at this time of year. Scrutinizing credit card bills for any fraudulent activity can help to minimize any losses. Unrecognizable charges listed on a credit card statement are often the first time consumers realize their personally identifiable information has been stolen.

Bank transactions and correspondence from financial institutions should also be closely reviewed. Bank accounts can often serve as a target for criminals to initiate account takeovers or commit identity theft by creating new accounts in the victims’ name. Consumers should never click on a link embedded in an e-mail from their bank, but rather open a new webpage and manually enter the URL (web address), because phishing scams often start with phony e-mails that feature the bank’s name and logo.

When shopping online, make sure to use reputable sites. Often consumers are shown specials on the web, or even in e-mail offers, that look too good to be true. These sites are used to capture personally identifiable information, including credit card numbers, addresses and phone numbers to make fraudulent transactions. It’s best to shop on sites with which you are familiar and that have an established reputation as trusted online retailers.

If you look for an item or company name through a search engine site, scrutinize the results listed before going to a website. Do not automatically click on the first result, even if it looks identical or similar to the desired result. Many fraudsters go to extreme lengths to have their own website appear ahead of a legitimate company on popular search engines. Their website may be a mirrored version of a popular website, but with a slightly different URL.

Purchases made on these sites could result in one or more of the following consequences: never receiving the item, having your credit card details stolen, or downloading malware to your computer. Before clicking on a result in a search engine, inspect the URL of the destination website. Look for any misspellings or extra characters such as a period or comma as these are indicative of fraud. When taken to the payment page of a website, again verify the URL and ensure it is secure by starting with "https", not just "http".

Here are some additional tips you can use to avoid becoming a victim of cyber fraud:
  • Do not respond to unsolicited (spam) e-mail.
  • Do not click on links contained within an unsolicited e-mail. Ask yourself: "Why am I being asked to click here?" If you’re not sure, don’t click!
  • Be cautious of e-mail claiming to contain pictures in attached files; the files may contain viruses. Only open attachments from known senders. Scan the attachments for viruses if possible. Ask yourself: "Does this look authentic?"
  • Avoid filling out forms contained in e-mail messages that ask for personal information.
  • Always compare the link in the e-mail to the link you are actually directed to and determine if they match and will lead you to a legitimate site.
  • Log on directly to the official website for the business identified in the e-mail instead of "linking" to it from an unsolicited e-mail. If the e-mail appears to be from your bank, credit card issuer, or other company you deal with frequently, your statements or official correspondence from the business will provide the proper contact information.
  • Contact the actual business that supposedly sent the e-mail to verify that the e-mail is genuine.
  • If you are requested to act quickly or there is an emergency that requires your attention, it may be a scam. Fraudsters create a sense of urgency to get you to act quickly.
  • Remember if it looks too good to be true, it probably is not.

For organisations:
  • Ensure your staff are educated ahead of the Christmas period. Phishing presents as much danger to businesses as it does individuals.
  • Get a penetration test now before the Christmas period to test the security of your networks and systems.

Παρασκευή 14 Νοεμβρίου 2014

How does Trust looks like?

A trustmark is a sign displayed on an eCommerce website, it has the purpose to provide an independent guarantee of the trustworthiness and reliability of the webshop.

The aim of trustmarks is to guarantee the quality and security of the online transaction. In some countries, there are trustmarks and trustmark providers that inform consumers whether the website complies with a certain set of rules. The trustmarks can be certified according to a national certification scheme and supervised by the competent authority, or based on mutual agreements. Trustmarks can boost consumer confidence in cyberspace. However, trustmark schemes are often unknown to consumers. As a result, consumers in EU can find it difficult to identify reputable e-merchants in other EU markets and are therefore reluctant to shop online from another country.

The Digital Agenda for Europe clearly pursues the creation of an online internal market, putting in place policies fostering cross-border eCommerce in the EU. One of the key factors of eCommerce, be it cross-border or at national level, is trust between the parties: the purchaser and the merchant. Trustmarks can play a role in establishing trust relations. Trustmarks are especially useful for smaller e-shops that are not (yet) a strong online brand of their own.

The e-Mark U Trust Competition invited all EU design/art students to submit their most innovative designs. Students from all over the European Union were invited to design a simple, original and clever trustmark which conveys a sense of trust and reassurance and indicates that Internet users can carry out their online transactions in a safe, convenient and secure way. On 15 September 2014, 95 logos were submitted within the deadline. The winner and the final ranking will be announced in 2015.

The three finalists, in random order, are:


Image by ELSE
Image by EUSAFE
Image by Noblesse Oblige

Remember, in a few months one of these will be a medal of honor for any site capable of earning it!

Παρασκευή 19 Σεπτεμβρίου 2014

E-Payment: Vulnerable Terminal Devices

Serious safety issues faced by financial companies and companies engaged in e-commerce showed the survey conducted by Kaspersky Lab and B2B International. You can find the full report in pdf here. Specifically, only 52% of financial companies and 46% of businesses engaged in electronic commerce believes that they should take enhanced measures to protect financial transactions. Even fewer companies in this area provide protection for the devices of their customers.

The e-commerce companies are those that focus less on the protection of economic activities. 16% of companies in the industry declare they are not interested to proceed with the installation of specific security solutions against online fraud, while only 38% are willing to invest in such tools.
Overall, 30% of companies that work with online cash flows, is not planning to offer protection to the devices of the customer during a transaction, although it is the weakest point in the security chain, with potential impact the loss of money for customers, but also a blow to earnings and reputation of the company itself. 28% of businesses are not interested in installing anti-fraud software to mobile devices of customers, while 30% of businesses are not trying to protect its own information infrastructure from potential online fraud.

This attitude to protection payments can lead to negative comments from customers. According to the survey, three-quarters (3/4) of the users expect financial companies to take responsibility for the safeguarding of their devices. Also, 40% of respondents feel confident that the company will offer compensation for any money lost.

However, the statistics of Kaspersky Lab show that the number of digital threats targeting financial data of individual users increases constantly. For example, according to the Kaspersky Security Network, the attacks that used malicious software targeting the banking touched 1.4 million during the period May 19-June 19, an increase of 15% compared with the period April 19-May 19.