Global Cyber News Digest

Daily News Digest

Stay current on the global cyber threat landscape and industry developments with CCOE’s daily digest and library of cybersecurity news and articles.

  • Why should we care about a data breach?

    • Data breaches allow cyber criminals to supplement their existing databases of personally identifiable consumer information. Since data is the lifeblood of any digital business today, its abuse can cause financial and reputational damages to a business.
    • When a social media platform—that you have a profile on—suffers a data breach and your personal details are among the data stolen, you become vulnerable to many types of threats. Cyber criminals can use your account to request for money from your network.
    • They can post details of non-existent, expensive items purportedly on sale for a limited period and dupe people into paying for them, without ever receiving them. Your account can be used for phishing campaigns to lure people into sharing their personal details. It can also be used to send out spam emails laced with malware or ransomware. In worst cases, your account can be abused for drug- or human-trafficking.
    | December 2, 2020
    hak-iq.us20.list-manage.comDecember 2, 2020
  • That email about your delivery could be fake: Phishing scammers increase their attack on online shoppers

    • There's been a huge rise in one particular form of phishing attack as cyber criminals look to exploit the combination of the holiday season shopping rush and the move to shopping online.
    • More online shopping means people are receiving more emails about the shipment and deliveries of their orders and cyber criminals are actively looking to take advantage of this with phishing emails impersonating internationally-known shipping companies.
    • Emails are designed to look like they come from shipping companies and retailers and feature messages claiming that there's been a "delivery issue" or urging users to "track your shipment".
    • In order to help protect against shipping email and other phishing attacks, users are urged to be suspicious of unexpected messages, particularly those which claim to require some sense of urgency as it's a common psychological trick used by cyber criminals.
    • If users are concerned that a request could be legitimate, they shouldn't follow links in the email, but they should visit the retailer or shipping company page directly.
    - Danny Palmer | December 1, 2020
    hak-iq.us20.list-manage.comDecember 1, 2020
  • The biggest hacks, data breaches of 2020

    • Cyberattackers certainly haven't given anyone a break this year. Data breaches, network infiltrations, bulk data theft and sale, identity theft, and ransomware outbreaks have all occurred over 2020 and the underground market shows no signs of stopping.
    • As a large swathe of the global population shifted to work from home models and businesses rapidly transitioned to remote operations, threat actors also pivoted.
    • Research suggests that remote workers have become the source of up to 20% of cybersecurity incidents, ransomware is on the rise, and we are yet to learn that "123456" is not an adequate password.
    - Charlie Osborne | December 1, 2020
    hak-iq.us20.list-manage.comDecember 1, 2020
  • Royal Dutch Cycling Union refuses to pay ransom following data breach

    • The KNWU said it had received a ransom demand that said the stolen data would be returned to the body if it paid up.
    • However, the association, which did not disclose the sum demanded, said it would not pay the ransom because it had backups of the data, and because doing so would not guarantee that the attackers wouldn’t abuse the data for illegal purposes anyway.
    • The database in question was stolen from a previous incarnation of the ‘MijnKNWU’ platform, which members log into to access benefits.
    • KNWU members were urged not to click on any emails purporting to come from the KNWU, and to phone or email the association to validate the authenticity of any invoices or payment requests received.
    • The body said it had alerted the police and the Dutch Data Protection Authority.
    - Adam Bannister | December 1, 2020
    hak-iq.us20.list-manage.comDecember 1, 2020
  • 28 Million Licensed Texan Drivers Hit by a Data Breach

    • Chances are high that your personal information might have been stolen in a hack of nearly 28 million Texas driver’s license. An insurance software company with access to DMV records says it was breached.
    • The company says they reported it to the Texas Office of the Attorney General, the Texas Department of Motor Vehicles, and the Texas Department of Public Safety and wrote, “Vertafore’s notice was delayed at law enforcement’s request.”
    • Vertafore says they hired a third-party firm to investigate but identified no misuse of the information so far.
    • Drivers can contact Vertafore to see if their information was hacked by calling 888-479-3560.
    TheDigitalHacker | November 30, 2020
    hak-iq.us20.list-manage.comNovember 30, 2020
  • SMBs Disclosing Data Breaches Minimize Financial Impact

    • SMBs that are disclosing data breaches to their stakeholders and the public are less likely to lose as much as those staying quiet.
    • Costs for SMBs that disclose a breach are approximately $93,000. Those with an incident leaked to the media, however, suffered $155,000 in damage.
    • A managed detection and response (MDR) service instantly increases the protection levels against complex threats through fast turnkey deployment, she said. Outsourced professionals can also help to resolve the incident more effectively if it has already occurred.
    - Edward Gately | November 30, 2020
    hak-iq.us20.list-manage.comNovember 30, 2020
  • Why even smart people fall for phishing

    • By now, most of us know better than to trust that marvelous Nigerian fellow who needs you – and only you – to receive all this money just found.
    • Black Friday, around the world, is a day celebrated particularly by phishing artists working with fake Amazon emails – the number of these rises by 45 per cent just before and on that day.
    • Urgency is a particular character of so-called whaling attacks. These are addressed to busy top executives.
    • Because phishing attacks have become personal, they can be devastating. Take the proper precautions – it can happen to anyone if the phishing attack just pushes the right buttons.
    - Andrew Rosenbaum | November 29, 2020
    hak-iq.us20.list-manage.comNovember 29, 2020
  • DoppelPaymer Ransomware Hits Masterchef, Big Brother Producer

    • Reportedly, the Masterchef, Big Brother producer firm has suffered an attack from the DoppelPaymer ransomware attack.
    • It’s presently unclear how the hackers managed to infiltrate the firm’s network, what ransom amount they have demanded, and whether or not Banijay would pay the ransom. Yet, given the firm’s huge presence and DoppelPaymer’s history, it’s safe to presume a huge amount. Earlier this year, DoppelPaymer targeted the paper-making division of Mitsubishi.
    - Abeerah Hashim | November 29, 2020
    hak-iq.us20.list-manage.comNovember 29, 2020
  • The Data Protection Law to Safeguard Privacy and Promote Inclusive Growth

    • Globally, 107 countries have introduced some form of legislation for data privacy and security. 
    • The implementation rate in Europe is high, but a majority of APAC economies are catching up on formulating local regulatory frameworks for protecting data privacy and security.
    • India is one of the newest participants in the data protection ring, with the Personal Data Protection (PDP) Bill already approved by the cabinet of the Government of India.
    • These regulatory developments are necessary considering the rising digital footprint of consumers and the patchy track of sensitive data they leave behind, namely — on the web, mobile, storage media, and other IoT devices where data might get processed or stored without intent or approval.
    • Data today is at perpetual risk of a breach, leak, and abuse, with major repercussions in the form of identity theft, financial fraud, coercion and harassment, brand damage, customer loss, and even lawsuits.
    - Bharat Panchal | November 29, 2020
    hak-iq.us20.list-manage.comNovember 29, 2020
  • 8 Resolutions For A More Secure And Rewarding New Year

    • For many, the coronavirus pandemic meant scrapping their carefully crafted strategic plans and focusing their security efforts and resources on adapting to the new normal. Business models—and the IT needed to support the business—changed overnight.
    • There’s no harm in setting some goals that will make your organization more secure; make your team feel more connected and engaged; and make you a smarter, more balanced security leader.
    - Ali Neal | November 23, 2020
    hak-iq.us20.list-manage.comNovember 23, 2020