Norsk Hydro’s cyber insurance has paid just a fraction of its breach-related losses so far

Norsk Hydro received an insurance payout of $3.6 million following a highly publicized cyberattack earlier this year, the company revealed in its third quarter earnings report. The insurance payout represents about 6% of the $60 million to $71 million in costs created by the incident through the third quarter, the company said. The Norwegian aluminum and energy giant expects more compensation will come as more costs are totaled. Norsk Hydro, which had a market capitalization of $12 billion last year, said after the attack in March that its policy, led by AIG, was “solid.” The company said it was struck with a large ransomware attack that started in its U.S. facilities then spread. It wasn’t until summer when Norsk Hydro determined the situation was stable. Incident responders determined the ransomware strain was LockerGoga, which has haunted the industrial sector. Norsk Hydro did not pay the ransom demand, deciding instead to restore its systems from digital backups. The firm also […]

The post Norsk Hydro’s cyber insurance has paid just a fraction of its breach-related losses so far appeared first on CyberScoop.

Continue reading Norsk Hydro’s cyber insurance has paid just a fraction of its breach-related losses so far

Ukrainian cops just arrested an alleged hacker in one of Kyiv’s ‘most expensive’ hotels

Police in Kyiv, Ukraine announced on Friday they’ve detained an unnamed 32-year-old man accused of hacking U.S. companies. The suspect is accused of stealing $6 million from accounts of U.S. financial institutions, interfering with computer systems, theft and money laundering. The man’s identity and firms he’s accused of breaching are not public, but the arrest is the result of an operation from the country’s Cyber Police Department, Criminal Investigation Department of the National Police and the Metropolitan Criminal Investigation Department and the Prosecutor General’s Office of Ukraine. The Federal Bureau of Investigation and the Financial Crime Investigation Service, a unit of Lithuania’s Ministry of the Interior, also were involved in the investigation. Ukrainian police also said the “extradition of the U.S. detainee is being addressed.” The FBI began investigating the matter in 2010, police said. It continued into this year, when Ukrainian authorities said they received a request for international […]

The post Ukrainian cops just arrested an alleged hacker in one of Kyiv’s ‘most expensive’ hotels appeared first on CyberScoop.

Continue reading Ukrainian cops just arrested an alleged hacker in one of Kyiv’s ‘most expensive’ hotels

Mistrust lingers between government, industry on cyber information sharing

Sharing cybersecurity information between the government and private sector won’t do much good if neither side trusts the other. “Information sharing” for a generation has been proposed as a solution by executives in corporate America and agency leaders in Washington as a necessary step in helping both sides keep ahead of hackers. The quick, reliable transmission of threat data, attacker objectives and the latest techniques for stealing U.S. secrets should be a key component of how security teams in the public and private sectors protect their systems. In order for that to work, decision-makers need to understand the incentives that make sharing their own threat information worth the effort. More than six years after former National Security Agency contractor Edward Snowden started leaking documents detailing government espionage on U.S.-built technology, there’s still a lingering sense of unease between Washington and Silicon Valley, Matt Olsen, chief trust and security officer at […]

The post Mistrust lingers between government, industry on cyber information sharing appeared first on CyberScoop.

Continue reading Mistrust lingers between government, industry on cyber information sharing

Sens. Warren, Wyden want to know if Amazon shares some blame for the Capital One breach

Sens. Elizabeth Warren and Ron Wyden are asking federal regulators to investigate whether Amazon’s cloud computing unit made any mistakes that could have led to a breach at Capital One involving the data of more than 100 million people. Warren, D-Mass., and Wyden, D-Ore., want the Federal Trade Commission to probe whether Amazon Web Services failed to account for a hacking technique known as a “server side request forgery.” Capital One is one of the few major financial companies — if not the only one — to rely on AWS and its public cloud to protect its information, portraying the decision as a move to modernize its business. “Amazon knew, or should have known, that AWS was vulnerable to SSRF attacks,” the senators wrote in the letter, sent Thursday. “Although Amazon’s competitors addressed the threat of SSRF attacks several years ago, Amazon continues to sell defective cloud computing services to business, government agencies and to the general […]

The post Sens. Warren, Wyden want to know if Amazon shares some blame for the Capital One breach appeared first on CyberScoop.

Continue reading Sens. Warren, Wyden want to know if Amazon shares some blame for the Capital One breach

Joker’s Stash, once a forum for credit data, grows as breaches yield more stolen data

If it’s possible to describe a cybercriminal marketplace as “reputable” while maintaining a straight face, then Joker’s Stash fits the description as well as any other. The site has emerged in recent years as a destination for scammers who buy and sell credit card information stolen after data breaches from victims including the Hy-Vee supermarket chain, Sonic Drive-In and others. Now, the site has expanded to include an array of personal information on high-value targets, including members of the Trump administration, as part of an evolution toward making illicit transactions more user friendly, according to research published Thursday by threat intelligence firm Recorded Future. It’s also available without the use of Tor, the well-known anonymity software that unlocks websites not accessible with mainstream web browsers. Researchers who explored Joker’s Stash following reports that information stolen from Hy-Vee had been made available also found a new section dedicated entirely to Social Security […]

The post Joker’s Stash, once a forum for credit data, grows as breaches yield more stolen data appeared first on CyberScoop.

Continue reading Joker’s Stash, once a forum for credit data, grows as breaches yield more stolen data

NordVPN admits ‘isolated’ data breach was discovered last year

Virtual private network provider NordVPN, which operates in more than 60 countries, was breached last year after an outsider infiltrated a Finnish data center, the firm said Monday. In a statement on its website, NordVPN said it learned in March 2018 about the intrusion, which occurred on a server that NordVPN rents from another company. The hacker leveraged an unprotected remote management system left exposed by the data center. The VPN provider says usernames and passwords could not have been intercepted, and user activity logs likewise seem safe. It may have been possible, though, for the intruder to abuse website traffic and monitor some user activity, NordVPN says. The affected server was taken offline and “ceased to exist” on March 5, 2018, while NordVPN ended its contract with the data center provider as a result of the incident. “This was an isolated case, and no other data center providers we use have been […]

The post NordVPN admits ‘isolated’ data breach was discovered last year appeared first on CyberScoop.

Continue reading NordVPN admits ‘isolated’ data breach was discovered last year

Microsoft banks on new silicon chips built by Intel, others to fend off firmware attacks

Microsoft is pushing an initiative meant to protect its computers’ most sensitive data amid recent revelations that nation-state hackers are beginning to exploit the fragmented nature of the company’s supply chain. The company on Monday started pushing Secured-core PCs, its term for machines that will come with Windows 10, Microsoft’s latest PC operating system; Windows Hello, which allows users to log in without a password; and, most importantly, silicon microchips built by Intel Corp., Qualcomm and AMD that are meant to more closely guard sensitive data. By ensuring that PCs are loading legitimate Windows operating systems when a devices activate, the plan goes, Microsoft will ensure that users aren’t actually loading a malicious OS inserted by an outsider. The effort goes public more than a year after security researchers at ESET caught APT28 — a group of suspected Russian hackers also known as Fancy Bear — testing out malware that launched malicious code on a computer when […]

The post Microsoft banks on new silicon chips built by Intel, others to fend off firmware attacks appeared first on CyberScoop.

Continue reading Microsoft banks on new silicon chips built by Intel, others to fend off firmware attacks

Thousands of Twitter accounts have been amplifying pro-Turkish propaganda

A barrage of social media disinformation has accompanied Turkey’s military incursion into Kurdish-held regions of northern Syria in what is the latest example of friendly Twitter bots backing a government at a time of international scrutiny. Thousands of Twitter accounts in recent weeks have sent tweets including the hashtag #BabyKillerPKK, according to findings published Wednesday by the Atlantic Council’s Digital Forensic Research Lab. The hashtag is a reference to the Kurdistan’s Worker’s Party (PKK), which the U.S. has designated as a terrorist organization despite the PKK’s ties to the Kurdish People’s Protection Units (YPG), a traditional U.S. ally. Turkey does not make a distinction between the two groups, and Turkish-backed forces have assaulted Kurdish positions in the days since U.S. military personnel began withdrawing from the conflict at the direction of President Donald Trump. While Turkey’s military has launched airstrikes and backed militias that have killed civilians, bot-like Twitter accounts […]

The post Thousands of Twitter accounts have been amplifying pro-Turkish propaganda appeared first on CyberScoop.

Continue reading Thousands of Twitter accounts have been amplifying pro-Turkish propaganda

Cozy Bear kept moving after 2016 election, ESET says

One of the Kremlin-linked hacking groups that breached the Democratic National Committee in 2016 has remained active in the years that followed, even if it’s been less visible. Cozy Bear, also known as APT29 and the Dukes, began using different malicious software and new hacking techniques after 2016, according to findings published Thursday by the Slovakian security firm ESET. There wasn’t much public evidence of the group’s activity, but researchers say it did not go quiet after interfering in the U.S. presidential election. The hackers targeted U.S. think tanks in 2017, defense contractors in 2018 and three European countries’ ministries of foreign affairs. (The U.S. security firm FireEye suggested in November that Cozy Bear was showing signs of activity.) “Our new research shows that even if an espionage group disappears from public reports for many years, it may not have stopped spying,” ESET said in its report. “The Dukes were able […]

The post Cozy Bear kept moving after 2016 election, ESET says appeared first on CyberScoop.

Continue reading Cozy Bear kept moving after 2016 election, ESET says

Accused Capital One hacker had as much as 30 terabytes of stolen data, feds say

Investigators probing the Capital One data breach say they have between 20 and 30 terabytes of data in their possession as they prepare for trial against the alleged hacker, Paige Thompson, according to court documents obtained by CyberScoop. The government now is parsing through millions of individual files, prosecutors said, as well as a spreadsheet agents say they found recently on Thompson’s computer, which contains aggregated information apparently stolen from Capital One. “[B]asically, each line is one credit card applicant and information about that person,” Assistant U.S. Attorney Andrew Friedman told a federal court during a detention hearing Oct. 4. “Some of it is coded information that means nothing to us, like what particular offer they received; some of it … is the names and dates of birth and the last four digits of Social Security numbers and things like that. … It’s hard to know exactly what this is.” Friedman […]

The post Accused Capital One hacker had as much as 30 terabytes of stolen data, feds say appeared first on CyberScoop.

Continue reading Accused Capital One hacker had as much as 30 terabytes of stolen data, feds say