Posts

Showing posts with the label talktalk

Book Review: Crime Dot Com, From Viruses to Vote Rigging, How Hacking Went Global

Image
I had the great delight of reading Geoff White’s new book, “ Crime Dot Com: From Viruses to Vote Rigging, How Hacking Went Global ”, I thoroughly recommend it. The book is superbly researched and written, the author’s storytelling investigative journalist style not only lifts the lid on the murky underground world of cybercrime but shines a light on the ingenuity, persistence and ever-increasing global scale of sophisticated cybercriminal enterprises. Crime Dot Com: From Viruses to Vote Rigging, How Hacking Went Global In Crime Dot Com Geoff takes the reader on a global historic tour of the shadowy cybercriminal underworld, from the humble beginnings with a rare interview with the elusive creator of the ‘Love Bug’ email worm, which caused havoc and panic back in 2000, right up to the modern-day alarming phenomenal of elections hacking by nation-state actors. The book tells the tales of the most notorious hacks in recent history, explaining how they were successfully planned a...

Cyber Security Roundup for June 2020

Image
A roundup of UK focused Cyber and Information Security News, Blog Posts, Reports and general Threat Intelligence from the previous calendar month, May 2020. EasyJet's disclosure of a "highly sophisticated cyber-attack", which occurred in January 2020, impacting 9 million of their customers was the biggest cybersecurity story of May 2020 in the UK. Although no details about this 'cyber-attack' were disclosed, other than 2,208 customers had their credit card details accessed.   Using terms like "highly sophisticated" without providing any actual details of the cyberattack makes one think back to when TalkTalk CEO Dido Harding described a cyber-attack as " significant and sustained cyber-attack " in 2015. In TalkTalk's case, that cyber attack turned out to be a bunch of teenage kids taking advantage of a then 10-year-old SQL injection vulnerability.  City A.M. described Dido's responses as "naive", noting when asked if the aff...

Cyber Security Roundup for November 2018

One of the largest data breaches in history was announced by Marriott Hotels at the end of November. A hack was said to have compromised up to a mind-blowing "half a Billion" hotel guests' personal information over a four year period.  See my post,  Marriott Hotels 4 Year Hack Impacts Half a Billion Guests  for the full details.  The Radisson Hotel Group also disclosed its Rewards programme suffer a data compromise . Radisson said hackers had gained access to a database holding member's name, address, email address, and in some cases, company name, phone number, and Radisson Rewards member number. Vision Direct reported a website compromise , which impacted users of their website between 3rd and 8th November, some 16,300 people were said to be at risk  A   fake Google Analytics script  was placed within its website code by hackers.  Eurostar customers were notified by email to reset their passwords following presumably successful a utom...

Cyber Security Roundup for March 2018

In the wake of the global political fallout over the Salisbury nerve agent attack, there are reports of a growing threat of Russian state or Russian state-affiliated hacking groups conducting cyber attack reprisals against UK organisations, government officials have directly warned bosses at electricity, gas and water firms, Whitehall departments and NHS hospitals to prepare for a state-sponsored cyber assault .  Russian group Fancy Bear (APT28) were suspected of being behind an unsuccessful attack against the UK anti-doping agency , and China tied hacking group APT15 were found to have infiltrated a UK government contractor’s computer systems by NCC researchers . Large-scale data breaches were disclosed with Under Armour’s Fitness App MyFitnessPal (1.5 million personal records compromised) , Orbitz (880k payment cards at risk) , and at a Walmart partner (1.3 million personal records compromised) . The latter was caused when an AWS S3 bucket holding a Walmart dat...

Cyber Security Roundup for August 2017

TalkTalk yet again made all the wrong cyber security headlines in the UK this month, after it was handed a £100,000 fine by the Information Commissioner's Office (ICO) for not adequately protecting customer records from misuse by its staff. The ICO investigated the Internet Service Provider after receiving complaints from customers, who said they received cold calls from scammers who knew their TalkTalk account information. Second-hand goods firm CeX disclosed a compromise of up to 2 million online customer accounts due to a hack, however, CeX has yet to disclose any details about the cyber attack. My blog post and advice about this is here  http://blog.itsecurityexpert.co.uk/2017/08/up-to-2-million-cex-customer-account.html Hackers had a field day taking over social media accounts, from Real Madrid and FC Barcelona to Game of Thrones , much embarrassment could have been avoided if they had adopted multi-factor authentication on the accounts, aside from the spate of...

Cyber Security Roundup 2016: The Year of the Big Data Hack

A decade ago I was walking into Boardrooms clutching newspaper clippings of half dozen data breaches which had occurred during the previous years, in a bid to warn of future threats and to persuade executives to increase their information security budgets. Those days are long gone, as most executives I encounter tend to be already worried about the cyber threat to their business, all reinforced by the mainstream media which today reports hacks most days. "Big Data" is a recent marketing buzzword used to usher in the age of businesses utilising the vasts amount of data which they process and store for increasing efficiently and profit. The problem is much of this "Big Data" is our personal data, and there are cyber criminals also seeking to profit from it. So here we are in the era of "Big Data Hacks", which sums up 2016 quite well. I have compiled a list of media headlines of data breaches in 2016 below, the volumes involved with these data theft hacks are...

Cyber Security Roundup for December 2016

Yahoo announced the largest ever data breach in history, with over 1 billion Yahoo user accounts compromised by a past cyber attack, which I covered in  Yahoo's Mind-blowing One Billion Data Theft Hack . This truly humongous data hack is distinct from the 2014 breach of 500 million accounts reported by Yahoo in September. Elsewhere KFC, Topps, The Daily Motion and LinkedIn’s Lynda.com also reported large customer data breaches of millions of records during December.  We need to be mindful of never to "get use to" and accepting these massive numbers of hacked online accounts, by businesses we entrust with our personal information, especially where these businesses have been found 'wanting' on the cyber security defences by under investing. The old spin doctor excuses of indefensible super hacks orchestrated by sophisticated nation-state backed dark forces tends not to stand up once the facts are uncovered. There is nothing sophisticated about ...