Fake ransomware named after Donald Trump tries to trick victims out of a buck

Donald Trump can add ransomware to the list of things named after him, thanks to scammers who again have demonstrated how current events create opportunities to steal data. Security researchers from Cisco’s Talos threat intelligence team on Tuesday published findings explaining how hackers are using the likeness of the president, his predecessor and other political figures to dupe victims into paying up. Numerous ransomware attacks, screenlockers and remote access trojans are named after Trump, Barack Obama, Hillary Clinton and Vladimir Putin. It’s the latest evidence that digital miscreants will use any trending topics to woo potential victims. “One of the unexpected aspects of the investigation was the presence of lures that dropped malware associated with multiple nation-state attacks in the past, showing how even advanced, sophisticated adversaries will use any means to achieve their nefarious goals,” researchers wrote. The scammers’ emails mention the world leaders to catch victims’ attention, or […]

The post Fake ransomware named after Donald Trump tries to trick victims out of a buck appeared first on CyberScoop.

Continue reading Fake ransomware named after Donald Trump tries to trick victims out of a buck

Alleged Capital One hacker Paige Thompson to be released before trial

Paige Thompson will be free to move throughout the Seattle area before her case goes to trial. The accused Capital One hacker is scheduled to be released from jail Tuesday after a judge determined the 33-year-old defendant does not pose enough of a threat to the community to warrant her incarceration. Thompson, who is transgender, was arrested in July for allegedly hacking Capital One to access information about 106 million people, and has been held in a men’s detention center in Seattle in the months since. U.S. District Judge Robert Lasnik previously told attorneys he was “very concerned” about whether Thompson would receive adequate mental health treatment from the Bureau of Prisons, citing previous cases in which trans inmates have resorted to self-harm behind bars. The former Amazon Web Services software engineer is charged with computer fraud and abuse and wire fraud in connection with a breach at Capital One. Prosecutors say […]

The post Alleged Capital One hacker Paige Thompson to be released before trial appeared first on CyberScoop.

Continue reading Alleged Capital One hacker Paige Thompson to be released before trial

Cyber deals continue with Proofpoint’s $225 million acquisition of ObserveIT

Email security company Proofpoint has agreed to purchase an insider threat detection company for $225 million in cash, a move meant to boost its appeal to larger enterprise clients. Sunnyvale-based Proofpoint announced Sunday it intends to buy ObserveIT, which promises to stifle data loss by monitoring employees, gauging trends in user activity and watching user behavior on client networks. ObserveIT, founded in 2006, is based in Boston with a research and development center in Tel Aviv. The company has raised $53 million in funding from investors such as Bain Capital, Spring Lake Equity Partners and others. In an unrelated deal, Sumo Logic, an event management firm, also announced the acquisition of the security operations startup Jask. Terms of the deal were not disclosed. Proofpoint offers an enterprise security service that includes email protection, data loss prevention, mobile security and other offerings. It reported $717 million in revenue last year, and […]

The post Cyber deals continue with Proofpoint’s $225 million acquisition of ObserveIT appeared first on CyberScoop.

Continue reading Cyber deals continue with Proofpoint’s $225 million acquisition of ObserveIT

Japanese media giant Nikkei says $29 million lost in BEC scam

Scammers fleeced the publishing conglomerate Nikkei out of $29 million by impersonating an executive at the international firm. Nikkei America, the U.S. subsidiary of the Japanese company, said on Oct. 30 that one of its employees transferred the funds, equivalent to roughly 3.2 billion Japanese yen, “based on fraudulent instructions by a malicious third party” posing as a corporate boss. It’s the latest high profile business email compromise attack carried out by fraudsters who expoit employees’ inherent trust in other people in their organization. The company didn’t provide any specific details, saying only that it quickly realized it had been defrauded, and that the firm had notified law enforcement in the U.S. and Hong Kong. (Hackers frequently divert stolen money to accounts based in Hong Kong.) “We are investigating and verifying the details of the facts and causes of this incident,” Nikkei said in a statement. The company publishes the Nikkei 225 stock […]

The post Japanese media giant Nikkei says $29 million lost in BEC scam appeared first on CyberScoop.

Continue reading Japanese media giant Nikkei says $29 million lost in BEC scam

Alleged Russian hacker at center of international dispute poised for extradition to U.S.

An accused Russian cybercriminal arrested in Israel four years ago is scheduled to be extradited to the U.S. despite ongoing efforts by the Kremlin to bring him home. Israeli Justice Minister Amir Ohana signed an order on Wednesday to send Aleksey Burkov, 29, to the U.S. to face hacking-related charges in a Virginia court, Haaretz first reported. Prosecutors have reportedly charged Burkov, a St. Petersburg native, with running a website where thieves could buy and sell stolen credit card information, along with identity theft and money laundering, per Haaretz. As the extradition request moved forward, Russian authorities arrested an Israeli woman, Naama Issachar, for allegedly carrying marijuana in a Moscow airport earlier this year. Russian state media suggested in October the Kremlin would swap Issachar in exchange for Burkov. A Russian court ultimately sentenced the 26-year-old woman to more than seven years in prison, a punishment her family described as […]

The post Alleged Russian hacker at center of international dispute poised for extradition to U.S. appeared first on CyberScoop.

Continue reading Alleged Russian hacker at center of international dispute poised for extradition to U.S.

Hackers who tried extorting Uber, Lynda plead guilty

Two men pleaded guilty on Wednesday to charges related to hacking Uber and LinkedIn subsidiary Lynda.com in 2016, then trying to blackmail both companies into paying them to keep quiet about the incidents. Brandon Glover, a 26-year-old Florida man, and Vasile Mereacre, a 23-year-old Canadian, acknowledged their role iin a scheme to access personal information belonging to tens of millions of customers. The men said they were able to obtain customers’ information from Uber and Lynda by accessing Amazon Web Services accounts from both companies’ employees, then downloading troves of data. Then, they anonymously contacted security teams from both companies, promising to remain silent in exchange for hundreds of thousands of dollars. Uber agreed to the terms, saying it would pay the hackers $100,000 in bitcoin that the company later classified as a bug bounty payment, as long as the thieves would sign confidentiality agreements about the breach affecting 57 […]

The post Hackers who tried extorting Uber, Lynda plead guilty appeared first on CyberScoop.

Continue reading Hackers who tried extorting Uber, Lynda plead guilty

Accounts focused on African politics are linked to a Russian tycoon, Facebook says

A Russian financier with ties to Vladimir Putin was behind three networks of Facebook accounts that worked to interfere in the domestic politics of eight countries in Africa, the social media company said. Facebook took down a total of 66 accounts, 83 pages, 11 groups and 12 Instagram pages for their part in information campaigns meant to manipulate legitimate users, the company said Wednesday. The operations focused on issues like elections in Madagascar, Russian involvement in Africa, Sudanese-Russian relations and U.S. foreign policy, Facebook said. The company’s cybersecurity team traced all of the activity to Yevgeniy Prizgohin, a businessman previously indicted by former U.S. Special Counsel Robert Mueller in connection with the Russian Internet Research Agency. The IRA is the so-called Russian troll farm that sought to manipulate U.S. social media users before and after the 2016 presidential election. Since then, Prigozhin reportedly has directed his energy into boosting Russia’s presence […]

The post Accounts focused on African politics are linked to a Russian tycoon, Facebook says appeared first on CyberScoop.

Continue reading Accounts focused on African politics are linked to a Russian tycoon, Facebook says

Imperva planned to keep its CEO through a merger. Two months after a breach, he’s out.

Two months after Imperva disclosed a data breach, the CEO of the enterprise security company reportedly has resigned. Chris Hylen left his position on Oct. 21,. Hylen began in that role in August 2017, according to his LinkedIn page, and led the company to a reported $2.1 billion acquisition by Thoma Bravo, an American private equity firm. Imperva’s chairman, Charles Goodman, will assume the interim CEO position while the board seeks a permanent replacement, a company spokesperson said in a statement. “Effective Tuesday, October 22, 2019, Chris Hylen stepped down from his role as Chief Executive Officer,” athe spokesperson said. “This decision was made mutually by Mr. Hylen and the Thoma Bravo board.” The Israeli news outlet CTECH first reported the news. Imperva in August said that data belonging to customers of its cloud-based web application firewall product was exposed, resulting in the compromise of scrambled passwords, email addresses and SSL […]

The post Imperva planned to keep its CEO through a merger. Two months after a breach, he’s out. appeared first on CyberScoop.

Continue reading Imperva planned to keep its CEO through a merger. Two months after a breach, he’s out.

Scammers just posted 1.3 million payment card numbers on Joker’s Stash, a market for ID theft

A database containing roughly 1.3 million credit and debit card numbers belonging primarily to Indian bank customers was uploaded this week to Joker’s Stash, an online market specializing in stolen personal data, according to new findings by security researchers. Group-IB, in a statement e-mailed Tuesday to CyberScoop, said the database was uploaded Oct. 28, and is worth more than $130 million, the equivalent value of roughly one dollar per record. Ninety-eight percent of the files belong to Indian banks, while 1% originate with a Colombian entity. Group-IB did not name any of the banks affected, victims included in the database or speculate on who may have uploaded the information. This addition of credit card information came just days after researchers determined that Joker’s Stash is growing. Over its four-year lifespan, the illicit card shop has become a dumping ground for financial information stolen from organizations like Hy-Vee, Sonic Drive-In and others. Now, […]

The post Scammers just posted 1.3 million payment card numbers on Joker’s Stash, a market for ID theft appeared first on CyberScoop.

Continue reading Scammers just posted 1.3 million payment card numbers on Joker’s Stash, a market for ID theft

Fancy Bear hackers targeted at least 16 athletic organizations ahead of Tokyo Olympics

State-sponsored Russian hackers are targeting anti-doping authorities and other sports-related organizations ahead of the Tokyo Olympics in 2020, Microsoft announced on Monday. The hacking group known as Fancy Bear — or Strontium, APT28 and other names — targeted at least 16 national and international organizations across three continents starting Sept. 16, Tom Burt, Microsoft’s vice president for customer security and trust said in a blog post. That date roughly coincides with when World-Anti Doping Agency officials told international media outlets that Russia may be banned from all international sporting events over “inconsistencies” at its Moscow testing facility. Microsoft reported Monday that some of the attacks detected in recent weeks were successful, but “the majority were not.” The company did not name any specific victims. The news comes less than a year before the next Summer Games begin in July 2020. The World Anti-Doping Authority long has been a target of interest for Russian hackers. Fancy […]

The post Fancy Bear hackers targeted at least 16 athletic organizations ahead of Tokyo Olympics appeared first on CyberScoop.

Continue reading Fancy Bear hackers targeted at least 16 athletic organizations ahead of Tokyo Olympics