Pages

Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Friday, 10 July 2015

Over 22M Social Security numbers stolen in OPM hacks, agency says

Katherine Archuleta, director of the Office of Personnel Management, at a House Oversight and Government Reform Committee hearing on Capitol Hill.Mark Wilson/Getty Images
If you were affected by recent hacks on US government databases, you're in good company.
The federal government announced Thursday that the total number of people affected by cyberattacks on the US government's personnel office was more than 22 million. The agency said 21.5 million Social Security numbers were stolen from one source and 4.2 million from another. Both attacks were announced in June.
Some people were hit with a double whammy, having their information compromised in both breaches, leading to the government's total figure of 22.1 million stolen Social Security numbers.
The breadth of the attack exceeds some of the worst estimates that government officials and security experts had shot around in the past month, showing that the government's databases were an unsecured stockpile of valuable information when the attack occurred. It's the largest blemish on the government's record of controlling its systems, and follows a string of attacks that includes the hacking of the CIA's public website, the interception of White House emails and the breach of a military Twitter account. A previous attack blamed on China attempted to intercept information on federal employees with top secret security clearance in March 2014, according to The New York Times.
FBI Director James Comey purportedly estimated that 18 million people were affected by the attacks on OPM databases, according to CNN, which prompted US Congressman Jason Chaffetz (R-Utah) to grill Office of Personnel Management Director Katherine Archuleta on the total number at a congressional hearing in late June. Archuleta declined to give a number at the time, saying the agency was still sorting out how many people's Social Security numbers were in the forms.
And it got even more invasive than that.Attackers lifted the 21.5 million Social Security numbers from stolen background check documents. About 1.8 million of the people caught up in the hack were married to or lived with the applicants seeking a security clearance, the Office of Personnel Management announced Thursday.
"As noted above, some records also include findings from interviews conducted by background investigators and approximately 1.1 million include fingerprints," the agency said in its press release.
The two database breaches were "related," an OPM spokesman said, and added that the FBI is still determining who was responsible for hacking the background-check documents. The first hack has been tied by some in the federal government to Chinese hackers, but few further details have emerged.
The OPM press release also detailed the assistance the government will provide those affected, including credit and fraud monitoring, identity theft insurance and "full service identity restoration support and victim recovery assistance." The OPM spokesman said the agency was still contracting these services out and did not have an estimate of how much it would cost taxpayers.
Unions representing the federal employees have criticized the amount of information and assistance provided by OPM. Two unions have sued the federal government on behalf of their members, and before the agency announced the second, larger hack, the American Federation of Government Employees accused the government of downplaying the number of people affected and the extent of the compromised records.
"There is no information at this time to suggest any misuse or further dissemination of the information that was stolen from OPM's systems," the agency's release said. But the impact of the lost information will be impossible to guess, security experts said.
"While we haven't seen the personal information being used yet, this is to be expected," said Chris Wysopal, a security expert at Veracode, a company that checks source code used in 90 percent of software applications for known flaws. "It's rare that information that can be used for blackmail or as precursor information for phishing attacks would be seen being used."
In fact, Wysopal said, that we haven't seen the hackers tip their hand and identify themselves by using the data shows their level of sophistication.
"I was just talking to a federal officer last week," said Stephen Coty, an executive at Alert Logic and security researcher. "He knows his information's in there, and so are all his colleagues." Indeed, Comey -- the FBI director -- told National Journal reporters that he knows his information was compromised in the hack.
The breach of data on federal agents, including extremely personal background-check interviews, at the FBI and beyond gives hackers tools for blackmail and espionage, Coty said.
"It really puts them in harms way more than ever before," he said "It's already been tough to be in federal law enforcement."

Saturday, 24 January 2015

Sony seeks to delay filing earnings in wake of cyberattack


Sony is still working to restore some of its key computer applications in the wake of a devastating hack that hit its movie studio late last year. As a result, the company has asked for an extension in filing its next earnings report.
On Friday, Sony said that most of the "financial and accounting applications and many other critical information technology applications" for Sony Pictures Entertainment won't be up and running until early February because of the "amount of destruction and disruption that occurred" following the cyberattack. Sony has asked the Financial Services Agency of Japan to move the deadline for its fiscal third-quarter earnings from February 16 to March 31.
On November 24, the company discovered that the computer network of Sony Pictures had been hacked. A group calling itself #GOP, aka "Guardians of Peace," claimed responsibility and said it had obtained internal information. The security breach turned out to be more serious and pervasive than initially believed. Hackers leaked the personal information -- including Social Security numbers -- of more than 47,000 celebrities, freelancers, and current and former Sony employees. They also leaked yet-to-be released movies, as well as emails between Sony Pictures executives, among other internal documents. The company was forced to shut down its entire network.
The hackers claimed they attacked the network because they objected to the Sony Pictures movie "The Interview," a comedy about an assassination attempt on North Korean leader Kim Jong-un. Sony initially decided not to release the film after the hackers implied that movie theaters screening it would be attacked. But the studio reconsidered and the film has since been released in theaters and online. TheFBI has blamed North Korea for the attack. North Korea denied that it was responsible but expressed support for the hack.
While Sony continues working to restore its damaged systems, the company said it will hold a press conference on February 4 to provide forecasts for its fiscal third-quarter results based on whatever information is available at that point.

Sunday, 11 January 2015

Today's computers face more attacks than ever


CBS
Nestled into a storefront at the top of San Francisco's tree-lined Valencia Street is one of the city's top defenses in the war against malicious-software infections: a computer repair shop owned by Del Jaljaa.
People bring their infected computers to Jaljaa's San Francisco Computer Repair store 5 to 10 times a day, desperate for help restoring their devices to working order. In the past few years malware has grown to be about a third of his business. "It's our bread and butter," he said.
Getting computer infections more often? You're not alone.
Infections from malicious software -- harmful code that's also known as malware and that includes things like computer viruses and worms -- are keeping repair specialists like Jaljaa busy, thanks in part to an exponential rise in the types of malware hitting PCs. Malware detections by AV-Test, a company that tests the effectiveness of antivirus software, spiked in 2014 to more than 143 million, up 72 percent from last year, according to a report released Thursday.
To put that in perspective: there was more malware found over the last 2 years than in the previous 10 years combined.
Other malware watchers, such as security-software makers Malwarebytes and Kaspersky, have noticed similar trends. Kaspersky saw four times more mobile malware attacks in 2014 than the year before, said Patrick Nielsen, a researcher with the company.
For years, antivirus software blocked malware based on the malicious software's code. But would-be hackers found a way around that: They can buy or freely download malware code; then change just a few pieces of it. Suddenly, the code is invisible to the antivirus programs, and free to wreak havoc.
It's not unlike plagiarizing grade-school homework, said Timo Hirvonen, a senior researcher at security-software maker F-Secure. "It's as easy as removing a word or adding a letter to a Microsoft Word document," he said. As a result, malware is changing so often that it's getting harder to stop.
The security industry has attempted to find an answer. One of the newest techniques is to keep track of how malware behaves and what it tries to do. Imagine malware that attempts to copy your online-banking password: any file doing this would be tracked by these new security tools.
nbz-r3bawgzx88dhcqbdb08ucpxt0uhkthy7doog1afplwsktzwxvw1h-xttttasua7kki9fft0zaqiulsol3zmoisbg5-w1566-h645.png
Data from AV-Test shows malware attack rates spiking.AV-Test.org
Even then, however, security researchers say they're barely keeping their heads above water.
"At the pace we're going, that's just not feasible [to defend against] anymore," said Jérôme Segura, senior security researcher at Malwarebytes.
The escalating game of cat and mouse has even entered the world of cryptography. Hackers are jumbling the code of their malware to avoid getting caught, using the same techniques companies use to protect sensitive files.
Avoiding "shady websites," as Nielsen put it, isn't enough in an age when malware can be delivered by ads on legitimate sites like Yahoo News.
So should we just swear off computers forever?
Jaljaa, the computer-repair-shop owner, said there are simple things people can still do to keep themselves safe. Users still need to install antivirus and other security tools, as they've been doing for years, he said. But they should also make sure to keep all their software up to date.
And if you do get a malware infection you can't get rid of? Well, there are always people like Jaljaa to bail you out. But it'll cost about $130.

Thursday, 8 January 2015

The biggest cyberthreat to companies could come from the inside


getty-morgan-stanley-121815825.jpg
The Morgan Stanley Building in Times Square, New York City. The financial services firm revealed on Monday an employee had stolen data from more than 350,000 accounts.Getty Images
Companies spend billions of dollars each year to protect from determined hackers attacking from across the Internet, but experts warn they shouldn't ignore a closer threat they aren't even ready for: Inside jobs.
Morgan Stanley, one of the world's largest financial services firms, revealed Monday its customer information was breached. But it wasn't the result of determined hackers or sophisticated email attacks. Instead, Morgan Stanley said it was an employee who stole data from more than 350,000 customer accounts.
The move is a wake-up call to companies, which spent an estimated $71.1 billion in 2014 on cybersecurity, up nearly 8 percent from the year before. And while hackers have successfully attacked large companies like JPMorganTarget and Home Depot, experts warn employees pose just as much a threat, whether they act intentionally or by accident.
While the cybersecurity industry is devising an ever growing list of technology to protect from intrusions, it turns out there's relatively little that can be done to stop an insider who already has access to a company's otherwise highly protected data.
"There's always going to be a way, just like with hacking, for insider attacks to happen," said Lucas Zaichkowsky, who used to manage computers at a major credit card processor and is now a security expert at Resolution1.
Attacks by insiders are often characterized in three ways: They're hard to detect and don't happen often. But when an attack does come from the inside, it can be devastating. Security researchers at thePonemon Institute say 88 percent of IT pros surveyed say they struggle to identify insider attacks, and security consultants at SpectorSoft say less than half of companies are even capable of noticing.
Few companies publicly disclose these types of attacks, and when they do they rarely estimate the damage. SpectorSoft said insider attacks -- 35 percent of all those committed -- cost US companies $40 billion in 2013 alone.

Few ways to protect

Despite the challenges in detecting and blocking insider attacks, there are ways that can help companies reduce the risk of insider attacks.
First, experts recommend companies tighten restrictions on highly sensitive data, locking files behind passcodes and security systems only employees and trusted business partners who must have access actually do. One way to do that is with cryptographic computer code, which jumbles a file's contents using an algorithm that only those with the proper computer keys have.
If the information does have to be accessible on the company network, "try to come up with a data policy that segregates it," said Andrew Conway, a site and data breach expert for security company Cloudmark.
Companies also need to monitor the actions of the employees who do have access, to ensure the data isn't copied or destroyed without approval. Many attacks have been spotted by warning systems, but the alarms went unnoticed.
Other long-standing techniques include preventing files from being copied to USB by physically blocking USB ports with liquid cement, and removing cameras from the screens of laptop and desktop computers. Some companies even use "air-gapped" computers -- machines which are neither connected to the Internet nor to other computers.
The US government has gone to some lengths to ensure certain kinds of data are better protected than others. Nuclear facilities, for example, have used air-gapped computers for years. There are also laws governing how medical data is stored and accessed, requiring companies to keep extensive logs every time the files are read.
Another option for companies is to bring on a chief security officer, someone who understands and knows how to balance security with a company's day-to-day business, and sets rules for how files are stored and accessed. Ponemon backed up this assertion in a 2013 study which found the cost per record exposed in a breach goes down when a company has hired such a person.
Even if companies implement all those measures, experts say they can't entirely secure their systems from a determined insider.
Consider famous information leakers like Edward Snowden and Chelsea Manning, each of whom accessed and leaked thousands of classified government documents. In both cases, they were able to circumvent some of the US government's most secure computer systems by virtue of being on the inside.
"If the NSA can't prevent an insider breach, then how is an enterprise company going to stop one?" Conway said.