Demand for cyber insurance grows as volatility scares off some providers

There’s at least one part of the financial sector where hackers are good for business. Direct cyber insurance premiums grew to $2 billion last year, up 26 percent since 2015, according to figures published July 25 by Moody’s Investors Service. That figure represents less than 1 percent of premium insurance revenue in the U.S., but it’s clear the increasing claims over the past three years are driven largely by concerns about data breaches, distributed denial-of-service attacks and, perhaps most notably, ransomware. The problem, despite all the demand, is that some insurers are now re-thinking whether it’s in their best interest to keep offering the plans that help clients recover from devastating cyberattacks. Swiss Re Americas, a reinsurer that primarily backs governments and other insurance companies, is reluctant to embrace the cyber insurance market because of unpredictable, and expensive, attacks like the 2017 NotPetya incident, which the White House said caused $10 billion in […]

The post Demand for cyber insurance grows as volatility scares off some providers appeared first on CyberScoop.

Continue reading Demand for cyber insurance grows as volatility scares off some providers

New York updates its breach notification law in response to Equifax, GDPR

Businesses throughout the U.S. will now be required to notify New Yorkers as quickly as possible when their information is compromised in a security incident, under a bill that Gov. Andrew Cuomo signed Thursday. The consumer-friendly data protection law updates New York’s current rules to cover biometric data, and forces firms to alert consumers when their email address, combined with the corresponding passwords or security questions and answers, are compromised. The state legislature quietly passed the Stop Hacks and Improve Electronic Data Security Act, or SHIELD Act, in June. The law, which takes effect March 2020, requires companies to notify individuals “in the most expedient time possible and without unreasonable delay,” a time period that generally means 30 days, state Sen. Kevin Thomas, who re-introduced the SHIELD Act after it failed to pass in 2017, previously told CyberScoop. If the incident affects more than 500 New York residents, the affected business is required to provide written […]

The post New York updates its breach notification law in response to Equifax, GDPR appeared first on CyberScoop.

Continue reading New York updates its breach notification law in response to Equifax, GDPR

FBI investigators describe Methbot investigation as ‘beautiful concert of things shutting down’

Maybe the only thing more complicated than the Methbot advertising fraud scheme was the plan that ultimately shut it all down. Last year, the FBI led a takedown operation that, with help from the bot detection firm White Ops and more than a dozen other companies, resulted in the arrest of three accused fraudsters in three different countries, as well as the seizure of more than 50 web servers and numerous bank accounts. The law operation, detailed Wednesday by FBI officials at the International Conference on Cyber Security, targeted the Methbot/3ve fraud scheme. The ad-fraud ring defrauded digital advertisers and web publishers out of more than $30 million by charging marketers for access to internet users who didn’t actually exist, according to the U.S. Department of Justice. Advertising fraud, already a billion-dollar problem, is set to cost the ad industry $44 billion by 2022. The investigation, which lasted more than […]

The post FBI investigators describe Methbot investigation as ‘beautiful concert of things shutting down’ appeared first on CyberScoop.

Continue reading FBI investigators describe Methbot investigation as ‘beautiful concert of things shutting down’

NSA Director Paul Nakasone had an awkward chat with Ted Koppel

Well, that was weird. When Gen. Paul Nakasone appeared Tuesday at the International Conference on Cybersecurity at Fordham University, he probably expected to hear questions about the new reorganization at the National Security Agency, or about the U.S. government’s ability to safeguard what’s expected to be one of the most contentious elections in recent memory amid historic levels of foreign meddling. It was not to be. Nakasone spent roughly an hour politely engaging Ted Koppel, the longtime broadcast journalist and author of a 2015 book on cybersecurity, in a bizarre conversation that alternated between Koppel questioning the decorated NSA director about the agency’s basic responsibilities, and whether Nakasone struggled with fake news from “tens of thousands” of “self-appointed journalists.” The “fireside chat” was perhaps the most widely anticipated presentation scheduled at ICCS, a regular gathering of some of the most powerful officials from the U.S. intelligence community. Koppel set the tone for […]

The post NSA Director Paul Nakasone had an awkward chat with Ted Koppel appeared first on CyberScoop.

Continue reading NSA Director Paul Nakasone had an awkward chat with Ted Koppel

Teenage hackers are offered a second chance under European experiment

European authorities are testing out the idea that not every cybercrime investigation has to end with a hacker in handcuffs. Police in the U.K. and the Netherlands have created a legal intervention campaign for first-time offenders accused of committing cybercrimes, officials explained Tuesday at the International Conference on Cybersecurity at Fordham University. The effort, called “Hack_Right,” is aimed at first-time offenders between 12 and 23 years old who may be skirting the law from behind their keyboard and not even realize it. The experiment, which began last year, already has involved interactions with more than 400 young people in the U.K., the officials said. “We do this … to get out and find them and get them into computing clubs before we have to investigate someone and lock them up,” said Gregory Francis, acting national prevent lead at the National Cyber Crime Unit of the National Crime Agency. “[Cybercrime] is not a law […]

The post Teenage hackers are offered a second chance under European experiment appeared first on CyberScoop.

Continue reading Teenage hackers are offered a second chance under European experiment

Equifax expected to settle breach investigations for $700 million

Credit monitoring firm Equifax has agreed to pay up to $700 million to settle investigations from U.S. regulators and state attorneys stemming from the 2017 data breach that compromised personal information about 147 million people. The penalty includes payments of $425 million to affected customers, $100 million in payments to 48 states, the District of Columbia and Puerto Rico, and also pay $100 million to resolve a federal investigation from the U.S. Consumer Financial Protection Bureau, which examined the company in cooperation with the Federal Trade Commission, regulators said Monday. The deal is the largest settlement resulting from a data breach in U.S. history. It comes nearly two years after Equifax revealed hackers had accessed U.S. citizens’ Social Security numbers, credit data, addresses, birth dates and some driver’s license numbers because of flaws in the company’s technology. Attorneys are scheduled to propose the deal to a court in Atlanta on […]

The post Equifax expected to settle breach investigations for $700 million appeared first on CyberScoop.

Continue reading Equifax expected to settle breach investigations for $700 million

Active Chinese hacking campaign targeted diplomats from Slovakia, South America

Suspected Chinese hackers who have haunted military and government targets for a generation have updated their malicious software tools to target diplomatic missions. The Ke3chang cyber-espionage group has been active since at least 2010, researchers say, gathering intelligence about international government contractors, military organizations and breached computers used by foreign ministries before the 2012 G20 Summit, according to FireEye. Now, there’s new evidence the group updated its tactics in a series of attacks aimed at diplomats in Belgium, Brazil, Chile, Guatemala, and Slovakia. Security specialists at the Slovakian antivirus company ESET published research Thursday demonstrating how the Ke3chang group used a technical backdoor, Okrum, and an updated version of the Ketrican malware. The hacking tools allow Ke3chang hackers to intercept information about victims, including their username, IP address, operating system and build number, their language and country name, and other communication. ESET’s research contains findings dating back to 2015, when […]

The post Active Chinese hacking campaign targeted diplomats from Slovakia, South America appeared first on CyberScoop.

Continue reading Active Chinese hacking campaign targeted diplomats from Slovakia, South America

Bulgaria hacking suspect worked on government cybersecurity before tax agency breach

Bulgarian authorities have arrested a 20-year-old government contractor in connection with a hack on the country’s national tax agency that involved information about roughly 5 million adults, prosecutors said Wednesday. Prosecutors described the suspect only as “KB,” though Bulgarian media quickly identified him only as Christian Boykov, or Kristian Boykov, a computer specialist from the city of Plovdiv. The Sofia City Prosecutor’s Office described the hacking suspect as a “cyber security expert” who is “involved in testing and auditing information systems,” according to a translation of their announcement. Boykov has been conducting cybersecurity training for the GDOC, a Bulgarian government agency, his lawyers told MediaPool.ng. The arrest is related to the data breach at the National Revenue Agency, which announced Monday that an outsider had compromised its systems, prosecutors said. A hacker had contacted local media outlets from a Russian email provider with databases containing millions of rows of Bulgarians’ personal […]

The post Bulgaria hacking suspect worked on government cybersecurity before tax agency breach appeared first on CyberScoop.

Continue reading Bulgaria hacking suspect worked on government cybersecurity before tax agency breach

Criminals made off with $301 million per month last year via business email compromise scams

If your boss sends you an email asking for a wire transfer, you should think twice. Hackers are using compromised corporate email accounts to steal more money than ever, according to new findings from a federal anti-money laundering watchdog. Business email compromise scams, in which scammers impersonate corporate executives to request money transfers, cost organizations an average of $301 million every month last year, according to a report released Tuesday by the Financial Crime Enforcement Network (FinCEN), a U.S. Department of Treasury unit. The federal anti-money laundering watchdog said it received roughly 14,000 suspicious activity reports related to BEC scams last year, compared to about 6,000 in 2016. The findings add more evidence to the notion that, despite more corporate training, stronger anti-phishing and anti-spoofing measures, and more security attention, thieves from around the world are continuing to siphon dollars from U.S. businesses of all sizes. “BEC continues to be […]

The post Criminals made off with $301 million per month last year via business email compromise scams appeared first on CyberScoop.

Continue reading Criminals made off with $301 million per month last year via business email compromise scams

Ukrainian hacker arrested after allegedly providing bulletproof hosting to Russian security

Ukrainian police have arrested an accused cybercriminal who allegedly facilitated a web hosting scheme that made it possible for hackers to carry out attacks while avoiding international law enforcement. Mikhail Rytikov, a Ukrainian national, was apprehended in Odessa as part of an operation carried out with help from the U.S. and U.K., Ivan Bakanov, the head of Ukraine’s national security service, said in a statement Tuesday. U.S. police have sought Rytikov’s arrest since he was indicted in 2013, accusing him of orchestrating a hosting service that was used to gain access to corporate networks and steal more than 160 million credit card numbers, causing hundreds of millions of dollars in losses. In his statement Tuesday, Bakanov said Rytikov was involved with a data center that held 150 servers and equipment that was used for distributed denial-of-service attacks as well as to spread spam and pornography. Rytikov controlled roughly 40 percent of the […]

The post Ukrainian hacker arrested after allegedly providing bulletproof hosting to Russian security appeared first on CyberScoop.

Continue reading Ukrainian hacker arrested after allegedly providing bulletproof hosting to Russian security