Alleged Capital One hacker may have taken data from dozens of companies, feds say

The person allegedly behind the recent Capital One hack may have siphoned data from more than 30 other companies, according to federal court filings made public Wednesday. In a motion for detention filed in the Western District of Washington state, the U.S. government said investigators found that Paige Thompson took data from multiple companies, and not just Virginia-based bank. The revelation was part of the evidence used to argue that Thompson must be detained before trial, or else pose a danger to the community and a risk of skipping out on further court dates. Thompson, who is currently in federal custody in Washington state, has been charged with stealing data on 106 million Capital One customers after taking advantage of a misconfigured firewall in the bank’s cloud computing system. According to the latest filing, the government has allegedly found terabytes of additional data Thompson took from more than 30 “companies, educational institutions, and […]

The post Alleged Capital One hacker may have taken data from dozens of companies, feds say appeared first on CyberScoop.

Continue reading Alleged Capital One hacker may have taken data from dozens of companies, feds say

What Capital One’s cybersecurity team did (and did not) get right

There was no months-old, unpatched Apache flaw. A S3 bucket wasn’t publicly accessible to anyone with an internet connection. There was no effort to hide what happened behind the company’s bug bounty program. When taken at face value, the Capital One breach looks awfully similar to other massive security failures that have made national news in the past few years. But while people fixate on the amount of information taken, there are some in cybersecurity circles that see a silver lining in the way the bank has handled the incident. Multiple security experts told CyberScoop that while the incident is clearly severe and there are still questions that need to be answered, actions taken by the Virginia-based bank — who did not respond to CyberScoop’s request for comment — prevented this breach from becoming another example of extreme corporate cybersecurity negligence. “While it’s tempting to knock Capital One for this […]

The post What Capital One’s cybersecurity team did (and did not) get right appeared first on CyberScoop.

Continue reading What Capital One’s cybersecurity team did (and did not) get right

Capital One announces massive data breach; lone suspect arrested in Seattle

Financial giant Capital One announced a large data breach Monday, with the company saying that one person accessed personal information of approximately 100 million people in the United States and 6 million in Canada who had applied for or are currently considered users of the company’s credit cards. Additionally, the FBI arrested a woman in Washington state who is suspected of hacking into the company to obtain that information. Paige A. Thompson was arrested Monday and appeared in federal court in Seattle. According to the complaint, Thompson allegedly took wide swaths of personal information from Capital One’s cloud storage instances on March 22 and March 23. The company stored the data taken by Thompson on Amazon Web Services. The company says this information included names, addresses, zip codes/postal codes, phone numbers, email addresses, dates of birth and self-reported income. The information ranged from 2005 to early 2019. Additionally, Capital One […]

The post Capital One announces massive data breach; lone suspect arrested in Seattle appeared first on CyberScoop.

Continue reading Capital One announces massive data breach; lone suspect arrested in Seattle

Stock trading app Robinhood says user passwords were readable on internal systems

Stock trading service Robinhood sent an email to users Wednesday informing them that user credentials were stored in an insecure format inside the company’s internal systems. According to the email obtained by CyberScoop, the problem was discovered Monday night by the company’s security team. “We resolved this issue, and after thorough review, found no evidence that this information was accessed by anyone outside of our response team,” the email reads. A Robinhood spokesperson told CyberScoop that the company has no evidence users’ information was accessed, or that the issue meant user information was breached. “Out of an abundance of caution, we have notified customers who may have been impacted and encouraged them to reset their passwords,” a Robinhood spokesperson told CyberScoop. “We take our responsibility to customers seriously and place an immense focus on working to ensure their information is secure.” Robinhood would not divulge how the error was found […]

The post Stock trading app Robinhood says user passwords were readable on internal systems appeared first on CyberScoop.

Continue reading Stock trading app Robinhood says user passwords were readable on internal systems

Cybersecurity has done more to drive government cloud use than any other feature, intel official says

The cybersecurity features built into cloud computing have allowed the CIA to quickly achieve its technological goals, a top U.S. intelligence official said Tuesday. Sue Gordon, principal deputy director of national intelligence, said that of all the improvements that the cloud has brought to the intelligence community, the protections built into the technology provide the trust needed to handle some of the most sensitive work done by the U.S. government. “The advances we’ve made in security are probably what have allowed the greatest movement of mission,” Gordon said Tuesday at the Amazon Web Services Public Sector Summit in Washington, D.C. “Because of our insistence in the confidence of our processes and our data, and our commitment to the trust the American people place in us, we now have an environment that we trust.” It was a watershed moment for cloud computing when the CIA announced in 2013 that it would […]

The post Cybersecurity has done more to drive government cloud use than any other feature, intel official says appeared first on CyberScoop.

Continue reading Cybersecurity has done more to drive government cloud use than any other feature, intel official says

Chinese hackers found and repurposed elite NSA-linked tools

A hacking group with ties to Chinese intelligence has been using tools linked to the National Security Agency as far back as March 2016, according to research from security firm Symantec. The tools include some released by the Shadow Brokers, a mysterious group that dumped computer exploits once used by the NSA on the open internet in April 2017. Symantec’s research suggests that the Chinese-linked group, which the company calls “Buckeye,” was using the same NSA-linked tools at least a year before they were publicly leaked. According to Symantec, one of the tools used by Buckeye was DoublePulsar, a backdoor implant that allows attackers to stealthily collect information and run malicious code on a target’s machine. DoublePulsar was used in conjunction with another tool, which Symantec calls Trojan.Bemstour, that took advantage of various Microsoft Windows vulnerabilities in order to secretly siphon information off targeted computers. The Trojan.Bemstour exploit allowed attackers […]

The post Chinese hackers found and repurposed elite NSA-linked tools appeared first on CyberScoop.

Continue reading Chinese hackers found and repurposed elite NSA-linked tools

Election tech vendors say they’re securing their systems. Does anyone believe them?

The last few years have been an awakening for Election Systems & Software. Before 2016, very few people were publicly pressing the company to change the way it handled its cybersecurity practices. Now, the nation’s leading manufacturer of election technology has become a lightning rod for critics. Security experts say the small number of companies that dominate the nation’s election technology market, including ES&S, have failed to acknowledge and remedy vulnerabilities that lie in systems used to hold elections across the country. Once left to obscurity, the entire ecosystem has been called into question since the Russian government was found to have interfered with the 2016 presidential campaign. While there has never been any evidence to suggest that any voting machines were compromised, the Department of Homeland Security and FBI recently issued a memo that all 50 states were at least targeted by Russian intelligence. The peak of the criticism came after the Voting Village exhibition […]

The post Election tech vendors say they’re securing their systems. Does anyone believe them? appeared first on CyberScoop.

Continue reading Election tech vendors say they’re securing their systems. Does anyone believe them?

Marcus Hutchins pleads guilty to two counts related to Kronos banking malware

A cybersecurity researcher known for helping stop the global spread of the WannaCry ransomware variant has pleaded guilty to computer hacking crimes related to the creation of banking malware. Marcus Hutchins, a British cybersecurity researcher, was accused of writing malware known as Kronos in 2014. According to a 2017 indictment, Hutchins allegedly created and updated Kronos while another unidentified person sold the malware on dark web marketplace AlphaBay and other cybercrime forums. Kronos was designed to steal log-in credentials and other financial information from online banking websites that are accessible via Internet Explorer, Mozilla Firefox and Google Chrome. Hutchins’ arrest made waves in the cybersecurity community after he was detained by FBI agents at McCarran International Airport in Las Vegas following the 2017 DEF CON security conference. Days later, he pleaded not guilty in federal court in Milwaukee. His trial was expected to begin this summer. The two counts that Hutchins pleaded guilty to […]

The post Marcus Hutchins pleads guilty to two counts related to Kronos banking malware appeared first on CyberScoop.

Continue reading Marcus Hutchins pleads guilty to two counts related to Kronos banking malware

Woman illegally entered Mar-a-Lago with thumb drive full of malware, prosecutors say

A Chinese woman who briefly entered President Donald Trump’s Mar-a-Lago residence last week had two Chinese passports and numerous electronic devices in her possession, including a thumb drive carrying malware, according to federal prosecutors. Yujing Zhang, 32, has been charged with with making false statements toward federal law enforcement agents and unlawfully entering a restricted building or grounds, according to court documents released Monday by the Southern District of Florida. According to the criminal complaint, Zhang was detained on Saturday after initially telling Secret Service guards that she was there to attend an event held by the United Nations Chinese American Association. After a Mar-a-Lago receptionist determined that no such event was being held, Secret Service agents took her into custody. Agents initially expressed confusion over whether she was related to a member of the beach club with the same last name. When she did not respond to questioning, agents believed […]

The post Woman illegally entered Mar-a-Lago with thumb drive full of malware, prosecutors say appeared first on CyberScoop.

Continue reading Woman illegally entered Mar-a-Lago with thumb drive full of malware, prosecutors say

How DHS is following the Pentagon’s plan for internal cybersecurity

The Department of Homeland Security is trying to replicate a strategy used by the Department of Defense to protect and defend its networks, and the plan could soon be used across the entire federal government. DHS is currently assessing its 16 federated security operations centers (SOCs) to determine which agencies meet the parameters by which they could offer services to other agencies in need of various services, according to DHS Chief Information Security Officer Paul Beckman. “We are trying to figure out how we collectively get our arms around all those SOCs and how we optimize that,” Beckman told a crowd at the 2019 IT Modernization Summit, presented by FedScoop. Beckman said the process is following the DOD’s Cybersecurity Service Provider (CSSP) model. That program assesses which internal security centers hit a number of benchmarks. When one center is qualified to provide a certain level of security, other internal agencies […]

The post How DHS is following the Pentagon’s plan for internal cybersecurity appeared first on CyberScoop.

Continue reading How DHS is following the Pentagon’s plan for internal cybersecurity