Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

FBI, CISA issue ransomware advisory prior to Labor Day weekend

on 9:50 AM

 The Federal Bureau of Investigation and Cybersecurity and Information Sharing Agency issued a joint cybersecurity advisory Thursday warning of increasing attacks against U.S. entities on or around holiday weekends. The agencies note they do not currently have any specific threat reporting indicating a cyberattack will occur over the upcoming Labor Day holiday.

“Cyber actors have conducted increasingly impactful attacks against U.S. entities on or around holiday weekends over the last several months. The FBI and CISA do not currently have specific information regarding cyber threats coinciding with upcoming holidays and weekends,” the advisory reads. “Cyber criminals, however, may view holidays and weekends—especially holiday weekends—as attractive timeframes in which to target potential victims, including small and large businesses.

The agencies suggest organizations engage in preemptive threat hunting on their networks. Threat hunting is a proactive strategy to search for signs of threat actor activity to prevent attacks before they occur or to minimize damage in the event of a successful attack

Indicators of suspicious activity that threat hunters should look for include:

  • Unusual inbound and outbound network traffic
  • Compromise of administrator privileges or escalation of the permissions on an account
  • Theft of login and password credentials
  • Substantial increase in database read volume
  • Geographical irregularities in access and log in patterns
  • Attempted user activity during anomalous logon times
  • Attempts to access folders on a server that are not linked to the HTML within the pages of the web server
  • Baseline deviations in the type of outbound encrypted traffic since advanced persistent threat actors frequently encrypt exfiltration.

Digital fraud focuses on younger consumers

on 4:52 PM

 The abrupt shutdown of retail a year ago led to a rise of digital shopping — and fraud. And the most tech-savvy consumers may be the most vulnerable.

In the last 12 months, fraud attempts in digital channels against businesses worldwide increased 46%, according to a new TransUnion study. On the consumer side, 36% of users said they were targeted by digital fraud related to COVID-19 in the last three months, versus 29% who said so approximately a year ago, before the virus spread around the world. TransUnion based its findings on a study of billions of global transactions flowing through its fraud-analysis screening tools.


Younger consumers — typically considered digital natives — were more likely than retirees to be vulnerable to scams during the pandemic, according to new research from TransUnion.

Among U.S.-based Gen Z consumers born between 1995 and 2002, 53% experienced digital fraud attempts, while 40% of U.S. millennials born between 1980 and 1994 were hit by digital fraud, TransUnion said.

“Ordinarily younger generations tend to be more tech-savvy and less likely to fall for scams, but when you have a situation like the pandemic where millions of people are on unemployment and expecting checks or stimulus funds, that mindset and need interferes with their judgment,” said Melissa Gaddis, senior director of customer success in TransUnion’s global fraud solutions unit.

Fraud declined in only one area — community forums where fraudsters have to work to convince victims to leave the forum and share their payment details. That fact underscores the relative ease of perpetrating simpler types of fraud in the pandemic’s chaos, Gaddis said.

When consumers were quarantined and stores and businesses quickly rushed to online and curbside sales, gaps opened that fraudsters immediately began to exploit, she said.  “Many businesses pivoted to doing business online so quickly they left the door open to fraud and fraudsters took full advantage of those opportunities,” Gaddis said.

The telecom industry saw a 58% increase in credit card fraud attempts over the last year (such as using a stolen card to buy an unlocked phone), while identity theft attempts at financial institutions soared 57%, according to TransUnion’s data.

Retailers were hit by a 39% increase in fraud attempts around promotions and the travel industry was hit by a 30% increase in credit card fraud attempts, the study suggested.

Community forums, including online dating and networking sites, saw an 11% decrease in fraud attempts leveraging profile misrepresentation during the same period. “With profile misrepresentation, the fraudster has to work harder to persuade a victim to leave the forum to talk one on one and send money, and the profit margin in that kind of fraud wasn’t worth it with other, easier paths available to criminals during the pandemic,” Gaddis said.

TransUnion’s study found a 21% rise in phishing attacks worldwide, with the increase tied to scams associated with COVID-19, TransUnion’s data indicated. The top three global regions where fraud originated over the last year were the Seychelles, Kazakhstan and Turkmenistan, TransUnion said.
Tempe, Ariz., Hamtramck, Mich., and Colonial Park, Pa., were the top U.S. cities fraudsters chose as addresses for fake identities and accounts, the data suggested. “These towns have unassuming names and fraudsters hope they sound more legit,” Gaddis said.

Even as pandemic restrictions ease, the year has given scammers a much bigger playing field than they had before.  “The pandemic shifted many more consumer and business transactions to digital channels, dramatically increasing the attack surface,” said Julie Conroy, a senior analyst with Aite Group.
About 40% of consumers tried a new digital channel or digital service during the pandemic — such as P2P, subscriptions or home delivery of goods — and many plan to stick with these new digital behaviors, she said. “Many of these digital newbies will be more susceptible to social engineering and scam-based attacks, and I don’t see the problem getting better until we fundamentally adjust our approach to identity-proofing and authentication in the digital channels,” Conroy said.

Solar Winds - What to do Next?

on 9:18 AM

 As most readers know, the network management software firm SolarWinds experienced a massive cyberattack in March that went undetected until mid-December. The breach pushed malicious code to an estimated 18,000 SolarWinds customers via an update of the company’s Orion software. These customers included government agencies, Fortune 500 companies, financial institutions, and vendors serving financial institutions.

Many credit unions are currently in the process of determining what, if any, impact this breach will have on their IT operations:

  • Credit unions running SolarWinds Orion software should refer to the company’s security alert(s) to determine whether systems were compromised, and obtain the company’s breach mitigation recommendations.
  • Non-SolarWinds customers aren’t necessarily in the clear. They’ll need to contact their IT vendors to determine whether they utilized the SolarWinds Orion software, and if so, what steps they’re talking to ensure that the credit union’s data is secure.
  • Affected credit unions should contact their cyber-liability insurance provider to help manage this process and determine next steps, as appropriate.

What if credit union member data was compromised? The credit union will need to follow its incident response program per Part 748, Appendix B of NCUA’s regulations if there has been unauthorized access to sensitive member information retained in “member information systems” (i.e., "all of the methods used to access, collect, store, use, transmit, protect, or dispose of member information,” including systems maintained by the credit union’s service providers).

 The credit union’s data breach response program should contain procedures to:

  • Assess the nature and scope of an incident; identify what member information systems and types of member information have been accessed or misused.
  • Notify the appropriate NCUA Regional Director or applicable state supervisory authority as soon as possible when the credit union becomes aware of an incident involving unauthorized access to or use of "sensitive" member information.
  • Notify appropriate law enforcement authorities in situations involving criminal violations requiring immediate attention.
  • File a timely Suspicious Activity Report (SAR) for reportable violations.
  • Take appropriate steps to contain and control the incident to prevent further unauthorized access to or use of member information (e.g., monitoring, freezing, or closing affected accounts) while preserving records and other evidence.
  • Notify affected members when the incident involves unauthorized access to member information systems that could result in substantial harm or inconvenience to the member.

Lastly, don’t forget about state law! Please check with your state league regarding state data breach requirements.

For more information:

Solar Winds Security Advisory 

CISA Emergency Directive 21-01 

CUNA News: CISA confirms ‘active exploitation’ of SolarWinds software 

CUNA News: CUNA Seeks Insight from NCUA on SolarWinds Cyberattack



 


Holiday Fraud — Expect the Unexpected in 2020

on 9:06 AM

  •  2020 is the year of the unexpected — and this holiday shopping season will be no different. The pandemic has changed our world in so many ways, especially when it comes to how we shop and pay for goods and services. Consumer spending has shifted to e-commerce channels to limit contact with others, and many merchants have ramped up their online efforts to make sure they’re reaching customers, offering curbside pickup and delivery options to meet today’s new social distancing requirements. It’s no surprise that this holiday season will be like none other and could redefine holiday shopping for years to come.

What to Expect This Holiday Shopping Season

In the wake of the pandemic and economic uncertainty, merchants are testing the holiday shopping waters by offering early deals. This is designed to gauge consumers’ willingness to spend money this holiday season and reduce the mad dash to stores that could make responsible social distancing impossible. No merchant wants to see their store featured on the news as the newest super-spreader event.

However, overall holiday spending is still expected to be strong this year, and the shopping will look more like Cyber Monday than Black Friday. E-commerce activity has skyrocketed since the onset of the pandemic and will drive a surge in online holiday spending. Card-present activity will be significantly less this year as a result.

In-store deals will be offered as well, but to help manage social distancing and limit contact at the store, merchants are planning to time the release of sales and offer tickets to consumers to pick up items in person.

Preparing for Holiday Fraudsters

The increased willingness of consumers to shop this time of year provides fraudsters many opportunities to target and profit from your members. Here’s what your credit union and members can expect this holiday season.

  • Fraudsters will target card-not-present channels this year. Many merchants have hastily developed e-commerce strategies because of the pandemic, and fraudsters will capitalize on any gaps in these new systems.
  • Merchants might relax their fraud controls to accommodate first-time e-commerce shoppers who typically shop in store. This will make online shopping easier for customers, but allow fraudsters to exploit the gaps here as well.
  • Merchants will utilize the 3D Secure protocol even more to increase sales and shift fraud liability to the issuer.
  • Chargeback fraud, also known as friendly fraud, will also increase this season. This type of fraud can be difficult to detect and contain because the fraudster is a member, which leads to difficult decisions for credit unions. An estimated 70% of card-not-present fraud is actually friendly fraud.
  • Fraudsters will use P2P (peer-to-peer) payments to scam your members with too-good-to-be-true holiday offers.

Holiday Fraud Prevention Tips

In this rollercoaster year, many of us have felt like 2020 has been one elongated holiday season with all of the major shifts in consumer spending and increased fraud alerts. Here are some tips to help keep your credit union and members alert to holiday fraud threats.

  • Continue to educate your members about common online scams and threats. Fraudsters often monetize scams with a gift card or P2P payment app. Reminding your members about this can help stop a scam in its tracks.
  • P2P payments are a major avenue for fraudsters, so it’s important to remind members not to send funds to someone if they’ve never met the requester in person. P2P payments have limited fraud protection and members may not realize this.
  • Check with your credit union’s payments processor about enrolling in a 3D Secure solution. 3D Secure protects your credit union from fraudulent e-commerce transactions. Issuers are typically liable for any fraudulent transactions processed via 3D Secure, so it’s important for your credit union to be protected online.
  • Also work with your payments processor to identify fraud trends and implement strategies to mitigate fraud losses for your credit union. The more information they have, the better they can protect your credit union and members.

As with many of the fraud challenges credit unions are faced with today, a multi-layered approach to preparedness, detection and responsiveness will help to prevent and mitigate losses and sustain member satisfaction this holiday season.

COVID-19 Fraud Schemes

on 4:08 PM

The NCUA Board is issuing this alert to inform credit unions about the risk of fraud associated with the COVID-19 pandemic. Those committing fraud often attempt to take advantage of opportunities made possible through new or expanded large government programs arising from emergency situations, such as the Coronavirus Aid, Relief, and Economic Security Act (CARES Act).

The CARES Act provides many ways for financial institutions to work with members impacted by the pandemic. This alert describes increased risks associated with routine operations, outlines red flags associated with common fraud schemes in major CARES Act programs, provides references and avenues to report fraud or misconduct to the most appropriate authorities, and also provides member education resources.

Compliance: FinCEN addresses cybercrime exploiting COVID-19

on 9:46 AM

The Financial Crimes Enforcement Network (FinCEN) issued an advisory July 30 to alert financial institutions to potential indicators of cybercrime and cyber-enabled crime observed during the COVID-19 pandemic. Many illicit actors are engaged in fraudulent schemes that exploit vulnerabilities created by the pandemic, according to FinCEN.

The advisory contains descriptions of COVID-19-related malicious cyber activity and scams, associated financial red flag indicators, and information on reporting suspicious activity.

Scams and their associated red flags include:

Targeting and exploitation of remote platforms and processes through fraudulent identity documents and the use of stolen credentials. Red flags include:
  • The spelling of names in account information does not match the government-issued identity documentation provided for online onboarding;
  • Pictures in identity documentation, especially areas around faces, are blurry or low resolution, or have aberrations;
  • Images of identity documentation have visual irregularities that indicate digital manipulation of the images, especially around information fields likely to have been changed to conduct synthetic identity fraud.
  • A customer’s physical description on identity documentation does not match other images of the customer;
  • A customer refuses to provide supplemental identity documentation or delays producing supplemental documentation;
  • Customer logins occur from a single device or Internet Protocol (IP) address across multiple seemingly unrelated accounts, often within a short period of time;
  • Customer logins occur within a pattern of high network traffic with decreased login success rates and increased password reset rates; and
  • A customer calls a financial institution to change account communication methods and authentication information, then quickly attempts to conduct transactions to an account that never previously received payments from the customer.
Phishing, malware and extortion which are increasingly utilizing offers of COVID-19 information and supplies. Red flags include:
  • Information technology enterprise activity related to transaction processes or information is connected to cyber indicators that have been associated with possible illicit activity. Malicious cyber activity may be evident in system log files, network traffic, or file information;
  • Email addresses purportedly related to COVID-19 do not match the name of the sender or the corresponding domain of the company allegedly sending the message;
  • Unsolicited emails related to COVID-19 from untrusted sources encourage readers to open embedded links/files or to provide personal or financial information, such as usernames and passwords or other account credentials;
  • Emails from untrusted sources or addresses similar to legitimate telework vendor accounts offer remote application software, often advertised at no or reduced cost;
  • Emails contain subject lines identified by government or industry as associated with phishing campaigns;
  • Text messages have embedded links purporting to be from or associated with government relief programs and payments;
  • Embedded links or webpage addresses for purported COVID-19 resources have irregular URLs that do not match that of the expected destination site or are similar to legitimate sites but with slight variations in the domain;
Business email compromise schemes, which in the COVID-19 environment often involve criminals interesting themselves into communications by impersonating a critical player in a transaction. Red flags include:
  • A customer’s transaction instructions contain different language, timing, and amounts in comparison to prior transaction instructions, especially regarding transactions involving healthcare providers or supplies purchases;
  • Transaction instructions, typically involving a healthcare-sector counterparty or referencing purchase of healthcare or emergency response supplies, originate from an email account closely resembling, but not identical to, a known customer’s email account;
  • Emailed transaction instructions direct payment to a different account for a known beneficiary. The transmitter may claim a need to change the destination account as part of a COVID-19 pandemic response and assert urgency to conduct the transaction; and
  • Emailed transaction instructions request to move payment methods from checks to ACH transfers as a response to the pandemic.
FinCEN will continue issuing COVID-19-related information to financial institutions to help enhance their efforts to detect, prevent, and report suspected illicit activity on its website.

Equifax Settles CU Suit Over Data Breach

on 11:53 AM

Equifax has settled a lawsuit with financial institutions, most of which are credit unions, following its 2017 data breach that affected more than 147 million U.S. consumers.

CUNA initially filed the lawsuit and was later joined by both the Pennsylvania and New Jersey credit union leagues, now called CrossState, and dozens of other plaintiffs, including state leagues and individual credit unions seeking to recover costs related to reissuing cards, reimbursing members and more.

In its settlement, Equifax has agreed to:
  • Pay up to $5.5 million to settlement class members who submit valid claims documenting unreimbursed out-of-pocket expenses associated with the breach and fraud reimbursement amounts paid to customers between July 6 and Dec. 20, 2017
  • Spend a minimum of $25 million over the next two years on relevant data security measures
  • Pay settlement costs and court-approved attorneys’ fees, expenses, and service awards 

Marriott Announces 5.2m Hotel Guest Data Breach

on 1:37 PM

Yesterday the Marriott hotel chain disclosed a security breach that impacted more than 5.2 million hotel guests who used the company's loyalty app.  According to a breach notification posted on its website, the hotel chain learned of the security breach at the end of February when it discovered a hacker had used the login credentials of two employees from one of its franchise properties to access customer information from the app's backend systems.

Marriot says the hack dated back to mid-January but did not disclose additional details about how it happened. The hotel chain said that the intruder(s) had direct access to Marriott Bonvoy loyalty data such as:

  • Contact details (e.g., name, mailing address, email address, and phone number)
  • Loyalty Account Information (e.g., account number and points balance, but not passwords)
  • Additional Personal Details (e.g., company, gender, and birthday day and month)
  • Partnerships and Affiliations (e.g., linked airline loyalty programs and numbers)
  • Preferences (e.g., stay/room preferences and language preference)
  • The hotel said that at this moment in the investigation, it did not believe that the hacker did not gain access to account passwords, account PINs, payment card information, passport information, national IDs, or driver's license numbers.
The hotel said that it doesn't believe the hacker gained access to account passwords, account PINs, payment card information, passport information, national IDs, or driver's license numbers.

Marriott launched a web portal for Bonvoy app users to check if they're one of the 5.2 million users impacted by the security breach, and what data the hacker might have accessed.

This is the second security breach Marriott disclosed in the past 16 months. In November 2019, Marriott said that hackers gained access to the Starwood Hotels reservation system, from where they stole the personal details of more than 383 million hotel guests (revised from the initial figure of 500 million). See our post-mortem coverage, here. US authorities said they suspected Chinese hackers of being behind the breach, but only put out a statement, but no official charges.

Scammers exploiting coronavirus fears to steal information

on 8:33 AM

The spread of the coronavirus is allowing bad actors to exploit fears and target consumer data, CUNA Chief Advocacy Officer Ryan Donovan wrote to all 535 Congressional offices Thursday. Donovan cites a recent NBC News article saying the disease is a “dream come true for criminals who will use it as basis for email attacks designed to snag personal information, steal money and infect computers with malware.”

“While you are hard at work trying to keep your constituents safe from the coronavirus disease, scammers are working just as hard to steal your constituents’ digital identities,” Donovan wrote. “We look forward to continuing to work with your office on data security and privacy legislation that will keep Americans' digital identities secure.”

The message links to information on CUNA’s advocacy efforts to secure data in order to make communities safer. CUNA is strongly pushing for Congressional action on a national data security and privacy standard that preempts state laws and applies to all entities that collect, use and store consumer data.

CUNA President/CEO Jim Nussle wrote in The Hill last week, during CUNA’s Governmental Affairs Conference, that data breaches aren’t going away and Congress needs to take definitive steps to protect consumer data.

CUNA has launched a resource page for information and other materials on the coronavirus (COVID-19) disease as they become available. CUNA is closely following all developments and will update the page as necessary with business continuity recommendations and information about CUNA/CUNA Council conferences and events.

Credit unions have a new cybersecurity risk to monitor: deepfakes.

on 8:17 AM

As reported by Melissa Angell from Credit Union Journal, A form of synthetic media using artificial inteligenc to manipulate a person’s image into a doctored photo or video, deepfakes appear to present individuals as saying or doing things they didn’t actually do. Some well-known examples include a 2019 altered video that made it appear House Speaker Nancy Pelosi was slurring her words during public remarks or a clip in which Facebook founder Mark Zuckerburg appears to say the app’s purpose is merely to “manipulate” users.
The threat for credit unions comes in the possibility for deepfakes to infiltrate banking. CUs and other financial institutions are already waging war against fraud in a variety of fashions, but the rise of deepfake technology creates a new layer of trouble, since it makes it more difficult to tell whether fraud is even happening.

Because technology makes these videos appear authentic, they can impact credit union employees and members. Stephen Ritter, chief technology offier at ID verification firm Mitek, suggested cybercriminals could use the technology to impersonate a member during an identification verification process to gain entry to a member’s bank account. Another example is if a fraudster targets a credit union executive and impersonates them, which could lead a credit union employee to transfer or send funds from the credit union’s business account.

That “can lead to serious repercussions for the entire business,” he said.

The new threat is also on the minds of leaders at Credit Union of America in Wichita, Kan.
“The list of things that users can’t trust is continuing to grow and as the technology gets better, you may not be able to trust a loved one’s voice if someone calls asking for money,” said IT Security Manager Blake Penner. “And so it just widens the scope of what really can’t establish trust for you.”
The costs financial institutions will face incurred from deepfake scams are projected to exceed $250 million in 2020, according to data from Forrester Research. That’s another concern credit unions will need to add to their checklist along with their checkbooks, as Gartner projects worldwide cybersecurity spending to touch $133.7 billion by 2022.

It's difficult to pinpoint when deepfakes first emerged. Academic research published in 1997 shows the technology in a premature form in the “Video Rewrite Program,” which involved modifying video footage of a speaking subject to depict them mouthing words to a different audio track. While deepfakes were circulated during the 2016 presidential election, the term itself was coined by Reddit users one year later.

Though deepfake technology has been around for a while, the effects have yet to be measured. Researchers from Cornell University published a paper in October 2019 on adversarial learning of deepfakes in accounting, noting in the paper’s summary that, "the research of such developments and their potential impact on the finance and accounting domain is still in its early stage.”
But that doesn’t mean that credit unions are unable to get ahead of the curve now.
To protect themselves against this emergent technology, Mitek’s Ritter recommended credit unions consider adopting liveness detection into their cybersecurity regimens, which is viewed as one of the most effective methods for not only detecting deepfakes, but also preventing them. The system first requires a user to blink or move in real-time to take a photo, which would prevent fraudsters from using a printed image to impersonate someone. Ritter said the technology also analyzes light and texture from a submitted image or video which could expose a deepfake threat.

“As access to deepfake technologies expands, we’re seeing more financial institutions integrate liveness detection capabilities into their apps to protect their users,” he said.

Ritter added that it’s equally important to incorporate liveness detection into web browsers in order to protect members who access their accounts through the web via a desktop or laptop computer.
Dave Excell, founder of Featurespace, which works with banks and CUs to combat financial crime, said that as with most cybersecurity measures, credit unions are advised to utilize a multi-faceted approach. Along with liveness detection, he recommended CUs require challenging information unlikely to be known to fraudsters before gaining entry to an account, such as recent transaction histories, secret questions and more.

“Credit unions should look at the context of what a [member] has done before and the future transactions [a member] is asking to make,” Excell said.

The good news is that credit unions need not change their tactics all that much, so long as they have cybersecurity protocol in place today. As Credit Union of America’s Penner sees it, it’s an additional layer to social engineering, so a lot of existing training is still applicable today.
That said, these attacks are continuing to evolve each day and credit unions will need to continue advancing their approaches.

“We’ve definitely been paying attention to deepfakes,” Penner. “I think as it becomes more accessible and easier for people to pull off, we’ll probably see a lot more of it layered into existing social engineering attacks so that’s something worth watching.”

Credit Unions Should 'Increase Phishing Identification' in 2020

on 6:51 PM

With the cyberthreats of Iranian operatives still hanging over organizations, a number of incidents affecting financial service companies, some predating the latest Iran-U.S. crisis, but all raising eyebrows, made news recently.

ZDNet reported a security researcher with the Twitter handle @vrNicknack alerted Troy Hunt, the Have I Been Pwned? search engine operator with a notice received from P&N Bank, a division of Police & Nurses Limited and operating in Western Australia. The notice warned of an information breach “of certain personal information” occurring through its customer relationship management platform as a result of online criminal activity. The cyberattack occurred on or around December 12 when the bank performed a server upgrade. Speculation is a company P&N Bank hired to provide hosting provided the entry point.

Stephan Chenette, co-founder/chief technology officer at AttackIQ, said, “The financial industry is one of the largest targets for cybercriminals and unfortunately, breached data from those types of organizations can be damaging for years to come.” Chenette noted the number of accounts is unknown, P&N Bank is one of the largest banks in Western Australia. As a result, a complete set of personally identifiable information is available on the dark web, further exposing the account holders to future fraud or phishing attacks. “Organizations must take proactive approaches to protect their data. This should include mapping organizational capabilities and security controls to specific attack scenarios to measure their preparedness to detect, prevent and respond to these threats.” Additionally, organizations should do their due diligence in ensuring third-party partners are practicing adequate security measures and extend testing to partners as well.”

In another incident, Bleeping Computer reported a group tracked as Ancient Tortoise is targeting accounts receivable professionals, tricking them into sending over aging reports (collections of outstanding invoices) and consequently amassing data on customers they can scam in future attacks.

Click to continue reading this article from Credit Union Times