US advisory meant to clarify ransomware payments only spotlights widespread uncertainty

If a Treasury Department advisory threatening financial penalties against anyone paying ransomware hackers was intended to send a clear message, it may have done the exact opposite. The Oct. 1 advisory from the Office of Foreign Assets Control warned that paying or helping to pay ransoms to anyone on its cyber sanctions list could incur civil penalties. Across some of the industries mentioned in the advisory — like cybersecurity incident response firms and insurance providers — reactions have ranged from confusion to silence, from yawns to raised eyebrows, from praise to fear of a blizzard of potentially unintended consequences. The worst case scenarios involve ransomware victims in the health sector having to make a life-or-death decision on whether to pay to unlock their systems while at risk of incurring Treasury’s wrath, or situations where victims try even harder to keep attacks quiet to avoid OFAC fines, which sometimes total millions […]

The post US advisory meant to clarify ransomware payments only spotlights widespread uncertainty appeared first on CyberScoop.

Continue reading US advisory meant to clarify ransomware payments only spotlights widespread uncertainty

As voters cast their ballots, courts nationwide issue election security edicts

Legal battles with election security implications raged across the country over the holiday weekend, even with early voting well underway at historic levels in many states. In no state did those two things coincide more than in Georgia. Peach State voters amassed in lines marked by reports of 10-hour waits on Tuesday, following two key court rulings. Northern District of Georgia Judge Amy Totenberg on Sunday denied a bid to scuttle touch screen voting machines over cybersecurity vulnerabilities. On Monday, she also denied a request to require a specific number of emergency ballots to be on hand at Georgia polling sites. The ruling Sunday represented a setback for election integrity advocates who contend that Georgia’s machines have not been secure enough, and still aren’t. Totenberg ruled last year that Georgia must phase out its existing paperless voting machines, citing doubts about cybersecurity safeguards for direct-recording election equipment tabulations that couldn’t be audited without a paper record. […]

The post As voters cast their ballots, courts nationwide issue election security edicts appeared first on CyberScoop.

Continue reading As voters cast their ballots, courts nationwide issue election security edicts

Facebook removes fake accounts it linked to Turning Point USA

Facebook said it removed hundreds of fake accounts and pages on Thursday that had denigrated Democratic presidential candidate Joe Biden while boosting GOP President Donald Trump. The company also said it had banned a marketing agency as part of the influence operation that it linked to prominent, youth-driven conservative organization Turning Point USA. The marketing firm, Rally Forge, also worked to undermine mail-in voting with comments on news stories posted to its platform, Facebook said. In all, the social media giant took down 200 Facebook accounts and 55 pages, as well as 76 Instagram accounts. The removal is a reminder that, with just weeks before Election Day, social media companies still are contending with the deliberate spread of misinformation from both foreign and domestic sources. Facebook in recent months has taken action against networks of white supremacists, and alleged Russian propagandists, among other networks. Other Silicon Valley firms, such as Twitter, also have taken […]

The post Facebook removes fake accounts it linked to Turning Point USA appeared first on CyberScoop.

Continue reading Facebook removes fake accounts it linked to Turning Point USA

SEC settles with trader accused of illegal trades using hacked data

The U.S. Securities and Exchange Commission agreed to settle charges with one of the traders who relied on hacked data from an SEC company filing system to collectively make millions of dollars, the agency said in a federal court filing on Wednesday. The SEC settlement includes both Sungjin Cho, the trader, and Kyungja Cho, his mother. Sungjin Cho made 66 illegal trades under his own name relying on the hacked information, and placed or directed four more under accounts in his mother’s name, according to the original complaint. Last year, the SEC and Justice Department filed charges against alleged hackers and the group of traders whom they said benefited from the scheme dating back to 2016 to steal secrets from EDGAR. EDGAR is a filing system for public companies that sometimes contains information that has not yet been made public. The scheme netted at least $4.1 million for the traders, according to the SEC. Among the […]

The post SEC settles with trader accused of illegal trades using hacked data appeared first on CyberScoop.

Continue reading SEC settles with trader accused of illegal trades using hacked data

Hackers exploit Trump’s COVID-19 diagnosis to spread a different kind of virus

Opportunistic hackers have seized on President Donald Trump’s illness from COVID-19 to fool email recipients into clicking on malware, researchers found, in what was a quick turnaround from the news that dominated the weekend and beyond. Proofpoint said it had detected an active, “medium volume” email campaign on Wednesday sent to several hundred U.S. and Canadian organizations. The messages are designed to bamboozle victims into downloading the BazaLoader backdoor, a kind of trojan commonly linked to the developers of the TrickBot hacking tool. Scammers frequently seize on major news events to try duping victims into providing access to their sensitive data. The apparent TrickBot gang email campaign comes less than a week after Proofpoint highlighted another that swiped Democratic National Committee website language in a bid to infect potential party volunteers. In this case, emails contain subject lines like “Recent materials pertaining to the president’s illness.” The body of the messages contain a hyperlink to an attached […]

The post Hackers exploit Trump’s COVID-19 diagnosis to spread a different kind of virus appeared first on CyberScoop.

Continue reading Hackers exploit Trump’s COVID-19 diagnosis to spread a different kind of virus

John McAfee arrested in Spain, charged with tax evasion

The Justice Department unsealed an indictment Monday against cybersecurity pioneer John McAfee following his arrest in Spain. McAfee stands accused of evading taxes, in part by using cryptocurrency. McAfee founded the antivirus firm that bears his name, but has spent at least a decade in frequent brushes with the law, and not just in the United States. The indictment, dated from June, does not allege that McAfee received any money from, or otherwise had any connection to his former company during the period he allegedly failed to pay taxes, from 2014 to 2018. McAfee left the security firm more than 20 years ago. The indictment states that his millions of dollars in income during the four-year stretch came from promotion of cryptocurrencies, consulting work, speaking engagements and the rights to his story for a documentary. McAfee, the indictment alleges, routed his income into cryptocurrency exchange accounts and bank accounts of others, and sought to conceal assets, including […]

The post John McAfee arrested in Spain, charged with tax evasion appeared first on CyberScoop.

Continue reading John McAfee arrested in Spain, charged with tax evasion

Helping to pay off ransomware hackers could draw big penalties from the feds

Anyone who helps ransomware victims pay off hackers who are under U.S. sanctions could face stiff punishment themselves, the Treasury Department said Thursday. The advisory from Treasury’s Office of Foreign Assets Control served notice to financial institutions and cyber insurance companies — as well as cybersecurity firms that help ransomware victims identify and respond to attacks — that they could suffer fines if they aided payments to attackers from places like Russia, North Korea or Iran that are on the U.S. sanctions list. And OFAC indicated it would be inclined to be strict about it: Those civil penalties could be levied against companies that didn’t know they were facilitating ransom payments to hackers on its sanctions list. “OFAC may impose civil penalties for sanctions violations based on strict liability, meaning that a person subject to U.S. jurisdiction may be held civilly liable even if it did not know or have reason […]

The post Helping to pay off ransomware hackers could draw big penalties from the feds appeared first on CyberScoop.

Continue reading Helping to pay off ransomware hackers could draw big penalties from the feds