While Bulgaria investigates financial breach, hackers tease more data

Hackers stole financial information about millions of Bulgarians as part of a security incident at the country’s tax agency in what appears to be the largest breach of personal information to ever affect the Eastern European nation. The National Revenue Agency in a statement Monday said it was working with other government organizations to investigate whether a vulnerability in its computer systems made it possible for hackers to steal financial files. Hackers had previously contacted local media offering access to databases containing millions of rows of personal information about Bulgarian citizens including names, addresses, earning numbers and other financial data. Various media reports suggested the leaked information included data on 5 million of Bulgaria’s roughly 7 million citizens. While the cause and extent of the breach still are investigation, Finance Minister Vladislav Goranov told journalists that hackers behind the attack contacted Bulgarian media outlets from an email address on Yandex.ru, […]

The post While Bulgaria investigates financial breach, hackers tease more data appeared first on CyberScoop.

Continue reading While Bulgaria investigates financial breach, hackers tease more data

Fake Telegram app on more than 100,000 phones infected U.S., UAE Androids

A bogus version of the messaging app Telegram infected downloaders’ phones with a pernicious strain of malware that sent devices searching for malicious sites on an endless loop, according to Symantec research published Monday. The MobonoGram 2019 app was downloaded more than 100,000 times — mostly by users in Iran, the U.S. and the United Arab Emirates — before it was scrubbed from Google’s marketplace. The program’s developers borrowed open-source code from the real Telegram app, a program that provides encrypted messaging, while adding code that forced the app to try to connect to gaming sites, pornography and other suspicious URLs on a constant basis. The app also contained Android.FakeYouWon, a malware that displays websites promoting fake offers and scams. Symantec’s discovery of MobonoGram 2019 provides the latest reminder that scammers use programs in the Google Play Store as Trojan horses to infiltrate users’ phones. Many international users would have been […]

The post Fake Telegram app on more than 100,000 phones infected U.S., UAE Androids appeared first on CyberScoop.

Continue reading Fake Telegram app on more than 100,000 phones infected U.S., UAE Androids

Indiana county meets $130,000 ransomware demand, despite advice against payment

This is starting to become all too familiar. Officials in La Porte County, Indiana, agreed to pay $130,000 in bitcoin to alleviate the pain from a ransomware attack that affected two domain controllers, knocking network services offline, according to WSB-TV. While an insurer will cover $100,000 of that fee, the northern Indiana county is the latest local government to pay digital extortionists to unlock a compromised network amid a spree of similar incidents throughout the country. Attackers hit La Porte on July 6, deploying the Ryuk ransomware to disable the city’s computer network, website and email service systems. Versions of Ryuk, which the FBI said has had a “disproportionate impact” on small municipalities, also have been blamed for attacks on Georgia’s court system and on small towns in Florida. In this case, La Porte County leaders told WSB-TV they decided to pay the ransom after a decryption key provided by […]

The post Indiana county meets $130,000 ransomware demand, despite advice against payment appeared first on CyberScoop.

Continue reading Indiana county meets $130,000 ransomware demand, despite advice against payment

Virginia state lawmaker accused of breaching former campaign manager’s Facebook, Gmail accounts

Dawn Adams, a sitting member of the Virginia House of Delegates, is accused in a new lawsuit of violating federal anti-hacking laws for allegedly accessing the Facebook, banking and other personal accounts of her former campaign manager. Maureen Hains, Adams’ former campaign manager and communications director, filed suit Thursday, alleging her former boss broke laws including the Computer Fraud and Abuse Act, the Stored Communications Protection Act and the Virginia Computer Crimes Act. Hains was working for Adams, a Democrat representing a district outside Richmond, as a legislative assistant in April of this year when she experienced a health crisis for which she needed to be hospitalized. According to the 20-page complaint, upon learning of Hains’ condition, Adams immediately began asking Hains about her condition and when she would return to work. During the hospital stay, according to the lawsuit, Adams asked Hains’ girlfriend for the password to her personal […]

The post Virginia state lawmaker accused of breaching former campaign manager’s Facebook, Gmail accounts appeared first on CyberScoop.

Continue reading Virginia state lawmaker accused of breaching former campaign manager’s Facebook, Gmail accounts

Premera Blue Cross settles state data breach investigations for $10 million

The largest health insurance company in the Pacific Northwest says it will pay $10.4 million to 30 states to settle an investigation into a data breach that compromised information on more than 10 million people. The settlement, entered into court Thursday, requires Premera Blue Cross to pay $5.4 million to Washington to resolve an investigation that determined the company was slow to patch known security vulnerabilities. Hackers had access to customers’ medical records, bank account information and Social Security numbers from May 2014 until May 2015. The remaining $5 million will be split between other states. The case is the latest example of how, in the absence of federal leadership, state attorneys are taking legal action following large-scale security incidents. Connecticut and Illinois have opened investigations into the breach this year at the American Medical Collection Agency, which affected at least 20 million people. Other state lawsuits have resulted in […]

The post Premera Blue Cross settles state data breach investigations for $10 million appeared first on CyberScoop.

Continue reading Premera Blue Cross settles state data breach investigations for $10 million

Judge won’t toss ex-hedge fund manager’s claim Brevet Capital hacked his email

A federal judge has ruled that a former managing director of Brevet Capital Management — an asset firm that oversees billions of investment dollars — can move forward with a proposed lawsuit alleging that the company hacked into his personal accounts. U.S. District Judge William H. Pauley on Tuesday denied a request from Brevet Capital to reconsider a previous court decision not to dismiss the case. In May, another judge ruled that Paul Iacovacci could move forward with claims that Brevet had violated the Computer Fraud and Abuse Act and other laws by accessing accounts and hard drives to read his personal email and extract data from his personal hard drives. Brevet previously has acknowledged accessing the data but denies any wrongdoing. The case, first filed in September, highlights uncomfortable questions about what information employers can access about their employees, and how they obtain that access. The issue is an especially pressing security question, as […]

The post Judge won’t toss ex-hedge fund manager’s claim Brevet Capital hacked his email appeared first on CyberScoop.

Continue reading Judge won’t toss ex-hedge fund manager’s claim Brevet Capital hacked his email

Automated Magecart spree hit thousands of sites via misconfigured cloud servers, RiskIQ says

One of the most notorious e-commerce scams has expanded into a “mass compromise” that preys on vulnerable cloud infrastructure to skim data from thousands of websites, according researchers with security vendor RiskIQ. Hackers using so-called Magecart techniques have infiltrated more than 17,000 sites by sneaking into misconfigured cloud repositories, reports the San Francisco-based company. The crooks are automatically scanning the web for vulnerable Amazon Web Services S3 buckets and adding malicious code that captures financial information, the researchers say. While AWS does have automatic protections for S3 buckets, it’s common for the repositories to be misconfigured and thus vulnerable to outsiders. Many e-commerce sites use S3 buckets to store sensitive data. The thieves started compromising insecure buckets in April, RiskIQ says. This campaign, which RiskIQ says has affected websites in Alexa’s top 2,000 internet rankings, is the latest Magecart-style attack after previous incidents at British Airways, Ticketmaster, and other international shipping sites. “Magecart” doesn’t refer to a single cybercriminal gang, but a style […]

The post Automated Magecart spree hit thousands of sites via misconfigured cloud servers, RiskIQ says appeared first on CyberScoop.

Continue reading Automated Magecart spree hit thousands of sites via misconfigured cloud servers, RiskIQ says

Synthetic identity theft is the fastest-growing financial crime in the U.S.

A new kind of identity theft that combines stolen personal data with fabricated information is on the rise, and it’s helping more digital thieves ruin Americans’ credit without fear of detection, according to a new white paper from the U.S. Federal Reserve. Known as “synthetic identity theft,” the tactic is distinct from traditional forms of identity fraud. Instead of stealing a person’s name, Social Security number and opening lines of credit, thieves combine a fake name and other fictional personal data such as a date of birth with a true Social Security number. It’s the fastest-growing type of financial crime in the U.S. thanks mostly to a huge uptick of personal information exposed in data breaches in recent years, according to the paper published Monday. “With synthetic ID fraud you can run the same playbook over and over again with 10 or 20 identities and they can’t even track you […]

The post Synthetic identity theft is the fastest-growing financial crime in the U.S. appeared first on CyberScoop.

Continue reading Synthetic identity theft is the fastest-growing financial crime in the U.S.

A Chinese company has 25 million Android devices tangled in an ad fraud scheme

A malicious software campaign tied to a Chinese internet company has exploited known vulnerabilities in Android mobile phones to infect roughly 25 million devices as part of a far-reaching ad fraud scheme, according to findings published Wednesday by Check Point. Hundreds of apps in a third-party Android marketplace disguised cocktails of malicious software that researchers say leveraged a number of known security issues to broadcast fraudulent advertisements. It’s only the latest example of near-daily revelations about apps acting in ways unwitting victims could not have anticipated — though this malicious activity is especially innovative. The programs — which mostly masqueraded as gaming, adult entertainment or photo apps — also contained code that allowed scammers to reach into legitimate apps that already existed on a victims’ phone, and commandeer those apps to broadcast advertisements. By displaying banner ads to so many users, the fraudsters could charge real advertisers for access to millions […]

The post A Chinese company has 25 million Android devices tangled in an ad fraud scheme appeared first on CyberScoop.

Continue reading A Chinese company has 25 million Android devices tangled in an ad fraud scheme

How identifying bogus checks at M&T Bank is a lot like hunting cybercriminals

It turns out the crimes of yesteryear are being thwarted with some of the same tools that stop today’s criminal activity. Until recently, the process of detecting check fraud at M&T Bank involved a team of 15 employees who manually looked through physical checks or scanned documents, trying to trace how scammers had attempted to fleece the financial institution. For M&T, it could take up to 900 man-hours to investigate a check-fraud campaign, according to chief information security officer David Stender. “In the typical old-school check fraud world you’d look at hundreds and hundreds of checks until you found the one that was fake,” he says. “People still rob banks. Even if it doesn’t yield much money anymore, they still do it. And people still write bad checks.” High-profile financial crimes these days typically include some breakdown in cybersecurity, like business email compromise, ATM jackpotting attacks, or fraudulent money transfers made possible by advanced malware. […]

The post How identifying bogus checks at M&T Bank is a lot like hunting cybercriminals appeared first on CyberScoop.

Continue reading How identifying bogus checks at M&T Bank is a lot like hunting cybercriminals