Russian Twitter bots laid dormant for months before impersonating activists

Twitter accounts deployed by Russia’s troll factory in 2016 didn’t only spread disinformation meant to influence the U.S. presidential election. A small handful tried making a buck, too. An analysis of 3,836 Twitter accounts and nearly 10 million tweets published Wednesday by Symantec shows how Russian efforts to amplify propaganda went further than previously reported. The Kremlin’s Internet Research Agency thoughtfully planned its information operations, creating Twitter accounts an average of 177 days before sending the first tweet. Many accounts also posed as falsified news operations, and spread content meant to antagonize U.S. citizens across the political spectrum by impersonating users affiliated with pro-Trump and Black Lives Matter movements. Accounts typically remained active for 429 days, mostly from the beginning of 2015 through August 2016, when many suddenly went quiet. “Most accounts were primarily automated, but they would frequently show signs of manual intervention, such as posting original content or […]

The post Russian Twitter bots laid dormant for months before impersonating activists appeared first on CyberScoop.

Continue reading Russian Twitter bots laid dormant for months before impersonating activists

Imperva to acquire Distil Networks to add bot mitigation to its offerings

Security vendor Imperva will acquire bot mitigation company Distil Networks to bolster its services amid a frenzied period of merger and acquisition activity in the cybersecurity market. Imperva announced Tuesday its executives have signed a deal that will result in Distil being folded into a comprehensive security platform, Imperva CEO Chris Hylen said in a statement. The company told CyberScoop the transaction has not yet closed, and at this time things remain business as usual for both companies. Terms of the deal were not disclosed. Distil will continue to function and serve its customers while integration plans are implemented. “Distil Networks gives us a comprehensive bot management solution that identifies, responds to and manages a full range of automated attacks no matter whether there’s applications or APIs are deployed,” Hylen said. Imperva, founded in 2002, promises clients real-time activity monitoring, threat mitigation and risk management services. The company was acquired […]

The post Imperva to acquire Distil Networks to add bot mitigation to its offerings appeared first on CyberScoop.

Continue reading Imperva to acquire Distil Networks to add bot mitigation to its offerings

Bank heist with FIN7 traits went down while leaders were on the run, research suggests

Digital thieves who spent more than two months lurking inside the networks of an Eastern European bank last year used the same techniques as the infamous cybercriminal gang known as FIN7 or Carbanak, according to new research. Romanian security vendor Bitdefender said Tuesday its researchers have uncovered new details about a bank heist in which hackers patiently collected employee credentials and other data meant to help them access banking data and control ATM networks. These findings coincide with previous researchers’ suggestion that FIN7 is a relatively large group made of perhaps a dozen individuals who have been able to weather law enforcement pressure while updating their hacking tactics. The 2018 breach at the bank, which Bitdefender declined to identify, occurred as international authorities were taking action against alleged members of FIN7, an organized crime group that threat intelligence researchers may have stolen $1 billion. The group carried out the attack detailed in […]

The post Bank heist with FIN7 traits went down while leaders were on the run, research suggests appeared first on CyberScoop.

Continue reading Bank heist with FIN7 traits went down while leaders were on the run, research suggests

Quest Diagnostics pins breach affecting 11.9 million patients on debt collector

Medical data and financial information of nearly 12 million people may have been compromised in a data breach at a billing firm that works with Quest Diagnostics, the laboratory company said in a regulatory document. The exposed information included credit card numbers and bank account details, Quest said Monday in a U.S. Securities and Exchange Commission filing. The New Jersey-based corporation is one of the giants in the medical testing industry, with more than $7.5 billion in revenue in 2018. Quest said the American Medical Collection Agency notified it on May 14 about a security incident. AMCA discovered that an outsider infiltrated its web payment system and accessed data belonging to other companies, including Quest Diagnostics. Quest had outsourced its billing work to Optum360, a health care revenue-cycle manager, which contracted AMCA. AMCA describes itself as a provider of “professional debt collection services are providers that specialize in collecting delinquent accounts,” according to […]

The post Quest Diagnostics pins breach affecting 11.9 million patients on debt collector appeared first on CyberScoop.

Continue reading Quest Diagnostics pins breach affecting 11.9 million patients on debt collector

Another fast-food hack, this time at Checkers and Rally’s restaurants

Checkers Drive-In Restaurants says hackers compromised payment machines at more than 100 of the fast-food company’s locations, providing the latest example of how buying a drive-through cheeseburger can come with the risk of a data breach. Point-of-sale malware was lurking at 102 of Checkers and Rally’s locations in 20 states, the Florida-based company said in a bulletin Wednesday. Thieves collected data stored on magnetic card strips, including cardholders names, payment card numbers, card verification codes and expiration dates — everything they would need to steal to conduct their own transactions or re-sell that data on cybercriminal forums. The exposure period for many of the affected stores ended in April, though some locations were vulnerable dating back to 2016 or 2015, in the case of one California restaurant. The company did not specify the number of customers affected. Checkers didn’t offer many details about the hack, but the almost non-stop breach disclosures from similar […]

The post Another fast-food hack, this time at Checkers and Rally’s restaurants appeared first on CyberScoop.

Continue reading Another fast-food hack, this time at Checkers and Rally’s restaurants

Alleged LinkedIn hacker Yevgeniy Nikulin will stand trial in U.S. court, despite mental illness symptoms

Yevgeniy Nikulin is headed back to court. The Russian accused of hacking a number of sites, including LinkedIn and Dropbox, was ruled fit to stand trial in a May 29 decision by U.S. District Judge William Alsup. Nikulin previously was ordered to undergo a psychiatric evaluation for refusing to communicate with his attorneys about his case, despite an ability to communicate about other topics without difficulty. Government attorneys previously argued “there is no comparison to the present case, where the defendant has stated that he has no complaint regarding his representation, but chooses not to discuss the proceedings with his counsel.” The defense has argued that Nikulin suffers from post-traumatic stress disorder related to his brother’s suicide and an abusive father, and that he has exhibited irrational behavior. Now, Alsup has ruled that the case against Nikulin will move forward. In his decision, the judge said Nikulin’s refusal to participate […]

The post Alleged LinkedIn hacker Yevgeniy Nikulin will stand trial in U.S. court, despite mental illness symptoms appeared first on CyberScoop.

Continue reading Alleged LinkedIn hacker Yevgeniy Nikulin will stand trial in U.S. court, despite mental illness symptoms

Recorded Future acquired for $780 million by venture firm

New York venture capital and private equity firm Insight Partners has acquired a controlling stake in threat intelligence company Recorded Future for $780 million. The cash deal, announced Tuesday, is the highest sale price ever for a firm that provides clients with threat intelligence about the digital risks they need to mitigate. Recorded Future now works with more than 400 clients, including Bank of America, Target, and SC Johnson. The firm previously raised $57.9 million from sources including Insight, and says this deal will accelerate its growth. “This partnership lays the foundation to take our products and software to the next level to best serve our clients, changing the face of our industry as we drive an intelligence-led strategy to help reduce risk and enable business operations for clients around the globe,” Christopher Ahlberg, CEO and co-founder of Recorded Future, said in the announcement. Corporate heavyweights for a generation now […]

The post Recorded Future acquired for $780 million by venture firm appeared first on CyberScoop.

Continue reading Recorded Future acquired for $780 million by venture firm

New York could soon pass its own GDPR-inspired data security law

New Yorkers could soon have clearer insight into when, where and how their data has been compromised under the terms of a bill expected to pass this week in the state’s legislature. The state’s lawmakers are debating whether to approve a bill that would update the state’s data breach notification law to cover more personal information and force firms to disclose ransomware infections, among other measures. The Stop Hacks and Improve Electronic Data Security Handling (SHIELD) Act also would cover any business that holds sensitive data of New York residents, rather than only firms that do business in the state. It’s an important detail cribbed from the European Union’s General Data Protection Regulation (GDPR), which compels organizations to report breaches affecting EU citizens, no matter where the hacked company is located, to regulators within 72 hours. The SHIELD Act requires notification to affected individuals “without unreasonable delay,” a time period […]

The post New York could soon pass its own GDPR-inspired data security law appeared first on CyberScoop.

Continue reading New York could soon pass its own GDPR-inspired data security law

Chinese database exposes 42.5 million records compiled from multiple dating apps

Tens of millions of records about users of different dating apps have been discovered in a single database that doesn’t include any password protection, according to new research findings. The records discovered by researcher Jeremiah Fowler mostly were about American users, based on accessible IP addresses and geolocation information. Other data included age, location and account names — a roadmap Fowler followed to identify users across multiple other platforms and dating apps to verify they were real. A sampling of 10,000 users revealed that 8,063 were from the U.S., 356 were from the U.K., 219 from Canada and 151 from Australia and other random English-speaking countries, he said in an email to CyberScoop. About 42.5 million records were exposed, Fowler said. Dating logs made up 38.3 million records, while 3.87 million consisted of “geonames,” Fowler said. He did not reveal the location of the database, which uses the Elastic format. While it’s not clear […]

The post Chinese database exposes 42.5 million records compiled from multiple dating apps appeared first on CyberScoop.

Continue reading Chinese database exposes 42.5 million records compiled from multiple dating apps

Facebook scrubbed 2.2 billion fake accounts in the first quarter of 2019, a new high

Facebook says its disabled roughly 2.2 billion fake accounts in the first quarter of this year, a record number of removals that targeted spammers, propagandists and others working to exploit the social media platform. The number is a sharp uptick compared to the 1.2 billion accounts removed between October and December, according to a Community Enforcement standards update released Thursday. The standards report provides evidence that the social media giant is making inroads to mitigating malicious activity on its services. Fake accounts made up roughly 5 percent of Facebook’s worldwide monthly active users during the first quarter of 2019. The overwhelming majority are detected within minutes of their registration, according to the company, meaning they are not included in Facebook’s active user metrics. “These numbers are driven largely by automated attacks by bad actors who try to create millions of accounts,” Facebook vice president of product management Guy Rosen said […]

The post Facebook scrubbed 2.2 billion fake accounts in the first quarter of 2019, a new high appeared first on CyberScoop.

Continue reading Facebook scrubbed 2.2 billion fake accounts in the first quarter of 2019, a new high