Posts

Showing posts from September, 2018

What is Artificial Intelligence (AI)?

Image
Artificial Intelligence (AI) has many business and security benefits but has risks and concerns.  AI can be a complicated subject matter to initially understand, so I thought it would be useful to share a great AI Infographic by ZeroCater , which simply explains what AI is and how it is already being adopted.

British Airways Hack Update: Caused by Injected Script & PCI DSS Non-Compliance is Suspected

Image
On Friday (7th September 2018),  British Airways disclosed   between 21st August 2018 and 5th September 2018, 380,000 BA customer's payment card transactions were compromised by a third party through its website and mobile app. This data included the customer's full name, email address, debit\credit card 16 digit number (PAN), expiry date and card security code i.e. CVV, CV2 Details of how the hack was orchestrated have now come to light.  In  a blog post RiskIQ researchers  have claimed to have found evidence that a web-based card skimmer script was injected into the BA website, very  similar to the approach used by the Magecard group, who are believed to be behind a similar attack against the  Ticketmaster website recently . Web-based card skimmer script attacks have been occurring since 2015. In this case, once the customer has entered their payment card details and then submits the payment either on a PC or on a touchscreen de...

British Airways Customer Data Stolen in Website and Mobile App Hack

Image
In a statement, British Airways stated: " From 22:58 BST August 21 2018 until 21:45 BST September 5 2018 inclusive, the personal and financial details of customers making bookings on ba.com and the airline’s app were compromised ." The airline said they will be notifying affected customers, and if anyone has been impacted to contact their bank or credit card providers. The Telegraph reported 380,0000 payments were compromised, and that BA customers had experienced payment card fraud as a result before the BA breach disclosure, which strongly suggests unencrypted debit\credit cards were stolen. There are no details about the data theft method at the moment, but given the statement said the BA website and BA mobile app was compromised, I think we could be looking at another example of an insecure API being exploited, as per the  Air Canada breach  and the T-Mobile breach last month. We'll see what comes out in the wash over the next few days and weeks, but...

Cyber Security Roundup for August 2018

The largest data breach disclosed this month was by T-Mobile , the telecoms giant said there had been "unauthorised access" to potentially 2 million of their 77 million customer accounts. According to the media, a hacker took advantage of a vulnerability in a T-Mobile API (application programming interface). It was a  vulnerable API used by Air Canada mobile App which was also exploited, resulting in the compromise of 20,000 Air Canada customer accounts . Air Canada promptly forced a password change to all of its 77 million customer accounts as a result, however, the airline faced criticism from security experts for advising a weak password strength. Namely, a password length of 8, made up of just characters and digits. Both of these hacks underline the importance of regularly penetration testing Apps and their supporting infrastructure, including their APIs. Hackers stole up to 34,000 Butlin guest records, reportedly breaching the UK holiday camp firm through a p...