A phishing campaign with nation-state hallmarks is targeting Chinese government agencies

Hackers with possible ties to an advanced persistent threat (APT) group are trying to steal usernames and passwords of Chinese government officials as part of an apparent cyber-espionage effort, according to findings provided exclusively to CyberScoop prior to scheduled publication Thursday. Researchers from the threat intelligence company Anomali have uncovered malicious websites with registrations dating back to November 2018 that impersonate email login pages from the Chinese Ministry of Foreign Affairs; China’s National Development and Reform Commission, an economic management agency under the State Council; and the National Aero-Technology Import and Export Corporation, a Chinese state-owned defense company. While it’s not clear who exactly is behind the effort, CyberScoop independently verified the findings with three external threat intelligence practitioners, two of whom said with confidence the attack resembles a nation-state effort. All three spoke only on the condition of anonymity because they were not authorized to speak to reporters. Upon […]

The post A phishing campaign with nation-state hallmarks is targeting Chinese government agencies appeared first on CyberScoop.

Continue reading A phishing campaign with nation-state hallmarks is targeting Chinese government agencies

The FBI is diving deeper into the Methbot ad fraud case

The FBI’s investigation into the largest advertising fraud operation in recent memory isn’t over yet. An application for a search warrant filed by FBI Special Agent Evelina Aslanyana on Aug. 2 and made public this week shows that investigators are seeking access to email, LinkedIn and other data about accused members of the Methbot ad fraud operation, also known as 3ve. Eight suspects were indicted in November in the Eastern District of New York for alleged involvement in a scheme to defraud advertisers out of more than $30 million by using botnets and other technical means to artificially inflate web traffic to dummy websites. Investigators previously had said the operation was disrupted when the apparent ringleaders, led by Aleksandr Zhukov, were arrested last year. The fraud, which the FBI had classified into three distinct time periods, is still underway, according to the search warrant application. In the affidavit, the FBI refers […]

The post The FBI is diving deeper into the Methbot ad fraud case appeared first on CyberScoop.

Continue reading The FBI is diving deeper into the Methbot ad fraud case

Pakistani man allegedly paid AT&T employees big bucks to jailbreak millions of iPhones

A 34-year-old Pakistani man has been charged with paying AT&T employees more than $1 million to plant malicious software that make it possible to use iPhones outside AT&T’s controls, the U.S. Department of Justice said Tuesday. Muhammad Fahd conspired with another man, Ghulam Jiwani, according to a newly unsealed indictment. The scheme, which lasted in some form from April 2012 to September 2017, involved the two men approaching AT&T employees, often through Facebook or by phone, then offering cash in exchange for the employees’ agreement to unlock specific phones, based on their identifying IMEI codes. The scheme unlocked more than 2 million cell phones over the five-year span, prosecutors say. Unlocked devices are compatible with any cell carrier, depriving “the remaining value of the customer’s service contract and, if applicable, remaining payments under the customer’s installment plan,” according to the indictment. Fahd, who also went by the name Frank Zhang, operated under […]

The post Pakistani man allegedly paid AT&T employees big bucks to jailbreak millions of iPhones appeared first on CyberScoop.

Continue reading Pakistani man allegedly paid AT&T employees big bucks to jailbreak millions of iPhones

Risky mobile transactions are up 19% this year as patch providers race to keep up

It’s hardly news that scammers are taking money in various ways from unsuspecting smartphone users, but a new analysis of 30 billion online transactions shows that the fraudsters are adapting and innovating in ways that much of the public doesn’t understand. One number tells the story: Iovation, a fraud detection firm acquired in 2018 by TransUnion, flags risky transactions worldwide and then looks more closely at how they happened. In recent years, about one-third of all flagged transactions involved mobile devices. In the first half of 2019, that number jumped to 49%, according to findings released Tuesday. Iovation defines “risky” based on the number of transactions in a given period of time from a device, geolocation anomalies, potential bot activity and other actions that typically result in fraud. The findings only provide the latest evidence that mobile devices, which will be the primary way most of the world will access the internet within a few years, are […]

The post Risky mobile transactions are up 19% this year as patch providers race to keep up appeared first on CyberScoop.

Continue reading Risky mobile transactions are up 19% this year as patch providers race to keep up

Cybereason raises another $200 million, aims for IPO within 2 years

Japanese multinational SoftBank will invest $200 million in Cybereason, doubling the Boston-based security vendor’s investment total as it marches toward an initial public offering. The deal brings Cybereason’s total funding to $400 million after prior investments from SoftBank, CRV, Spark Capital and Lockheed Martin. The company, founded in 2012 by former members of the Israeli Defense Forces signals intelligence unit, provides endpoint detection services, competing with the likes of Symantec, McAfee and CrowdStrike. This $200 million in Series E funding comes as part of Cybereason’s plan to invest in new services and find new clients, then go public within two years, said CEO Lior Div. “We took the money in order to build a bigger company than we are right now,” Div said on Monday. “Right now we have 500 people in the company, and this plan is to push to even more in order to be ready to go […]

The post Cybereason raises another $200 million, aims for IPO within 2 years appeared first on CyberScoop.

Continue reading Cybereason raises another $200 million, aims for IPO within 2 years

Poshmark users urged to change password as clothing retailer probes breach

Clothing re-seller Poshmark announced in a note to customers it has experienced a data breach that resulted in outsiders making off with some of their personal information. The company sent an email to customers Friday alerting them to a security incident in which an “unauthorized third party” accessed customers’ usernames, first and last names, gender and city. Hackers also stole email addresses, user ID, size information and, most notably, encrypted passwords. Poshmark advised users to update their password as a precaution. “The data acquired does not include any financial or physical address information, and we do not believe your password was compromised,” the company said in the email, echoing a data breach notification posted Thursday on its website. Poshmark did not say how many of its roughly 40 million users are affected. The company has retained security consultancy Kroll to investigate the breach, according to TechCrunch. Poshmark, founded in 2011, […]

The post Poshmark users urged to change password as clothing retailer probes breach appeared first on CyberScoop.

Continue reading Poshmark users urged to change password as clothing retailer probes breach

With Will Hurd’s retirement, Congress loses a key cybersecurity advocate

When Rep. Will Hurd made news Thursday night, just as the cybersecurity community was preparing to descend on Las Vegas for a week of events, it wasn’t about Hurd’s rescinded offer to speak at the Black Hat conference. The Texas Republican announced he will not seek re-election in 2020, becoming the sixth GOP representative and the third Texan in the past 10 days to announce retirement. Hurd, a former CIA officer, had distinguished himself among lawmakers for his attention to cybersecurity issues, including a support for encryption. He was slated to deliver a keynote address at the Black Hat cybersecurity conference next week until organizers canceled his invitation following a TechCrunch article that questioned the congressman’s voting records on women’s rights issues. In a statement on his website, Hurd said that he “made the decision to not seek reelection for the 23rd Congressional District of Texas in order to pursue opportunities outside the halls […]

The post With Will Hurd’s retirement, Congress loses a key cybersecurity advocate appeared first on CyberScoop.

Continue reading With Will Hurd’s retirement, Congress loses a key cybersecurity advocate

Cisco will pay $8.6 million to settle claims it sold US flawed surveillance software

Technology giant Cisco has agreed to pay $8.6 million to settle allegations it knowingly sold video surveillance equipment with security vulnerabilities to federal, state and local government agencies, according to court records unsealed Wednesday. A company whistleblower first informed Cisco in 2008 that a bug in its surveillance software could have enabled hackers to monitor video footage, delete footage and turn on or disable the systems. Government entities including the U.S. Secret Service, the Federal Emergency Management Agency and the New York Police Department had purchased the software, according to the Washington Post, which first reported the news. Cisco’s settlement appears to be the first whistleblower resolution of the False Claims Act, which prohibits defrauding the government, regarding cybersecurity issues. “The tech industry needs to fulfill its professional responsibility to protect the public from their products and services,” whistleblower James Glenn said in a statement. “There’s this culture that tends […]

The post Cisco will pay $8.6 million to settle claims it sold US flawed surveillance software appeared first on CyberScoop.

Continue reading Cisco will pay $8.6 million to settle claims it sold US flawed surveillance software

Capital One is a cautionary tale for companies rushing to embrace new tech

Capital One always said it wasn’t like other banks. While other financial giants cautiously waded into their own digital transformations, Capital One’s leadership has sought to differentiate the $28 billion bank by investing in technology meant to modernize their business. The bank has increased its number of technology staffers to 9,000 today from 2,500 in 2011, assigning employees to software engineering, artificial intelligence and building a digital chatbot to automate reminders to customers about when their bills are due or flag unusually large restaurant tips in case they want to rescind them, Rob Alexander, the bank’s chief information officer told the Wall Street Journal last year. Capital One also was different for its use of Amazon Web Services, a rarity in the financial services industry where most corporate heavyweights simply don’t trust third-parties to store their financial data. At Capital One, the use of AWS was to serve as proof of […]

The post Capital One is a cautionary tale for companies rushing to embrace new tech appeared first on CyberScoop.

Continue reading Capital One is a cautionary tale for companies rushing to embrace new tech

Clues to the alleged Capital One hacker’s crimes were all over the internet

The hacker who allegedly infiltrated Capital One to access personal information belonging to roughly 106 million people made it easy for the FBI to track her down: there were clues spread across a variety of popular websites. Paige A. Thompson, a 33-year-old Seattle-based software engineer, bragged about taking data from Capital One’s Amazon Web Services instances on a private Slack channel and a public GitHub post from an account that displayed her full name. When another GitHub user noticed Thompson’s claims, they alerted Capital One, and it wasn’t long before the bureau was involved. In one private message included in the complaint, Thompson allegedly told a friend via Slack, “I’ve basically strapped myself with a bomb vest, f—ing dropping Capital One dox and admitting it. I wanna distribute those buckets …There’s SSNs..with full name and [date of birth].” Thompson’s Github page also linked to her GitLab profile, which included her […]

The post Clues to the alleged Capital One hacker’s crimes were all over the internet appeared first on CyberScoop.

Continue reading Clues to the alleged Capital One hacker’s crimes were all over the internet