Posts

What is Artificial Intelligence (AI)?

Image
Artificial Intelligence (AI) has many business and security benefits but has risks and concerns.  AI can be a complicated subject matter to initially understand, so I thought it would be useful to share a great AI Infographic by ZeroCater , which simply explains what AI is and how it is already being adopted.

British Airways Hack Update: Caused by Injected Script & PCI DSS Non-Compliance is Suspected

Image
On Friday (7th September 2018),  British Airways disclosed   between 21st August 2018 and 5th September 2018, 380,000 BA customer's payment card transactions were compromised by a third party through its website and mobile app. This data included the customer's full name, email address, debit\credit card 16 digit number (PAN), expiry date and card security code i.e. CVV, CV2 Details of how the hack was orchestrated have now come to light.  In  a blog post RiskIQ researchers  have claimed to have found evidence that a web-based card skimmer script was injected into the BA website, very  similar to the approach used by the Magecard group, who are believed to be behind a similar attack against the  Ticketmaster website recently . Web-based card skimmer script attacks have been occurring since 2015. In this case, once the customer has entered their payment card details and then submits the payment either on a PC or on a touchscreen de...

British Airways Customer Data Stolen in Website and Mobile App Hack

Image
In a statement, British Airways stated: " From 22:58 BST August 21 2018 until 21:45 BST September 5 2018 inclusive, the personal and financial details of customers making bookings on ba.com and the airline’s app were compromised ." The airline said they will be notifying affected customers, and if anyone has been impacted to contact their bank or credit card providers. The Telegraph reported 380,0000 payments were compromised, and that BA customers had experienced payment card fraud as a result before the BA breach disclosure, which strongly suggests unencrypted debit\credit cards were stolen. There are no details about the data theft method at the moment, but given the statement said the BA website and BA mobile app was compromised, I think we could be looking at another example of an insecure API being exploited, as per the  Air Canada breach  and the T-Mobile breach last month. We'll see what comes out in the wash over the next few days and weeks, but...

Cyber Security Roundup for August 2018

The largest data breach disclosed this month was by T-Mobile , the telecoms giant said there had been "unauthorised access" to potentially 2 million of their 77 million customer accounts. According to the media, a hacker took advantage of a vulnerability in a T-Mobile API (application programming interface). It was a  vulnerable API used by Air Canada mobile App which was also exploited, resulting in the compromise of 20,000 Air Canada customer accounts . Air Canada promptly forced a password change to all of its 77 million customer accounts as a result, however, the airline faced criticism from security experts for advising a weak password strength. Namely, a password length of 8, made up of just characters and digits. Both of these hacks underline the importance of regularly penetration testing Apps and their supporting infrastructure, including their APIs. Hackers stole up to 34,000 Butlin guest records, reportedly breaching the UK holiday camp firm through a p...

Latest on the Currys PC World Data Breach Impacting 10 Million Customers

Following further investigations, Currys PC World today confirmed 10 million of their customer personal details may have been stolen by hackers, a revised number from the 1.2 million customers and 5.9 million payment cards it advised back in June. In June 2018, the company said t here was "an attempt to compromise" 5.8 million credit and debit cards but only 105,000 cards without chip-and-pin protection had been leaked after hackers attempted access to company's payment processing systems. The hack was said to have occurred nearly a year before it was disclosed, so it either went undetected, which is common where there is inadequate security monitoring in place, or the business knew about the breach but choose not to disclose it to their impacted customers. The Information Commissioner's Office (ICO) fined the Dixons Carphone £400,000 for a data in 2015 breach, however, Currys PC World stated the incidents were not connected. The business stressed it has now impro...

Cyber Security Roundup for July 2018

The importance of assuring the security and testing quality of third-party provided applications is more than evident when you consider an NHS reported data breach of 150,000 patient records this month. The NHS said the breach was caused by a coding error in a GP application called SystmOne, developed by UK based 'The Phoenix Partnership' (TTP). The same assurances also applies to internally developed applications, case-in-point was a publically announced flaw with Thomas Cook's booking system discovered by a Norwegian security researcher . The research used to app flaw to access the names and flights details of Thomas Cook passengers and release details on his blog . Thomas Cook said the issue has since been fixed. The Information Commissioner's Office (ICO) fined Facebook £500,000 , the maximum possible, over the Cambridge Analytica data breach scandal, which impacted some 87 million Facebook users . Fortunately for Facebook, the breach occurred before the General D...

Cyber Security Roundup for June 2018

Dixons Carphone said hackers attempted to compromise 5.9 million payment cards and accessed 1.2 million personal data records . The company, which was heavily criticised for poor security and fined £400,000 by the ICO in January after been hacked in 2015 , said in a statement the hackers  had attempted to gain access to one of the processing systems of Currys PC World and Dixons Travel stores. The statement confirmed 1.2 million personal records had been accessed by the attackers. No details were disclosed explaining how hackers were able to access such large quantities of personal data, just a typical cover statement of "the investigation is still ongoing".  It is likely this incident occurred before the GDPR law kicked in at the end of May, so the company could be spared the new more significant financial penalties and sanctions the GDPR gives the ICO, but it is certainly worth watching the ICO response to a repeat offender which had already received a record ICO fine this...