<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>hacking Archives - International Finance</title>
	<atom:link href="https://internationalfinance.com/tag/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>https://internationalfinance.com/tag/hacking/</link>
	<description>International Finance - Financial News, Magazine and Awards</description>
	<lastBuildDate>Mon, 02 Mar 2026 14:51:19 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.9</generator>

<image>
	<url>https://internationalfinance.com/wp-content/uploads/2020/08/favicon-1-75x75.png</url>
	<title>hacking Archives - International Finance</title>
	<link>https://internationalfinance.com/tag/hacking/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Google disrupts Chinese hacking operations in more than 40 nations</title>
		<link>https://internationalfinance.com/technology/google-disrupts-chinese-hacking-operations-more-than-nations/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-disrupts-chinese-hacking-operations-more-than-nations</link>
					<comments>https://internationalfinance.com/technology/google-disrupts-chinese-hacking-operations-more-than-nations/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Mon, 02 Mar 2026 14:51:19 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google cloud]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[malware]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=54864</guid>

					<description><![CDATA[<p>Google terminated all of the attackers' authority over Google Cloud Projects as part of the disruption operations, cutting off their ongoing access to GridTide-compromised environments</p>
<p>The post <a href="https://internationalfinance.com/technology/google-disrupts-chinese-hacking-operations-more-than-nations/">Google disrupts Chinese hacking operations in more than 40 nations</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Online search engine giant <a href="https://internationalfinance.com/technology/if-insights-google-vs-microsoft-the-battle-for-infrastructure-power/"><strong>Google</strong></a>, in a major successful move, has gone after a global espionage network which has pestered governments and telecom services in over 40 countries.</p>
<p>Google’s Threat Intelligence Group (GTIG), partnering with Mandiant (a subsidiary of Google Cloud and a premier cybersecurity firm specialising in threat intelligence, incident response, and managed defence) and others, ended up exposing Chinese state-backed organisation UNC2814’s spy operations. The group has now been classified as an Advanced Persistent Threat (APT).</p>
<p>In the most recent campaign, the organisation used GridTide, a backdoor malware that had never been seen before and used the Google Sheets API for C2 infrastructure. The backdoor blends with regular company traffic and causes no concerns because it sends HTTPS queries to authentic Google infrastructure rather than connecting to a distant server to obtain commands and steal data.</p>
<p>Every command is kept in a spreadsheet cell within an attacker-owned document. The malware periodically examines, decodes, and executes the encoded instructions that the operators inject into designated rows or cells.</p>
<p>Exfiltrated data may occasionally be written back into the sheet. GTIG stated that it did not see any examples of data exfiltration. With reports of its activity dating back to 2017 or potentially earlier, UNC2814 is a somewhat well-known threat actor.</p>
<p>Google terminated all of the attackers&#8217; authority over Google Cloud Projects as part of the disruption operations, cutting off their ongoing access to GridTide-compromised environments. They restricted access to the Google Sheets API requests, disabled attacker accounts, and located and stopped all known UNC2814 infrastructure. Lastly, it published a list of IoCs connected to the UNC2814 infrastructure that has been operational since at least 2023.</p>
<p>The campaign started in 2023 and affected at least 53 organisations in 42 countries. Google suspects that UNC2814 is present in at least 20 more countries. Most of Latin America, Eastern Europe, Russia, parts of Africa, and parts of South Asia seem to have been hit. Except for Portugal, Western Europe is mostly unscathed. The United States was not touched as well.</p>
<p>The activity is distinct from separate high-profile, telecommunications-focused Chinese hacking activity tracked as “Salt Typhoon,” Google told Reuters. That campaign, which the US government has linked to Beijing, targeted hundreds of American organisations, in addition to prominent political figures.</p>
<p>Chinese Embassy spokesperson Liu Pengyu, while reacting to the news, said, &#8220;<a href="https://internationalfinance.com/technology/start-up-week-armed-with-fresh-funding-chainguard-eyes-become-major-cybersecurity-player/"><strong>Cybersecurity</strong></a> is a common challenge faced by all countries and should be addressed through dialogue and cooperation. China consistently opposes and combats hacking activities in accordance with the law, and at the same time firmly rejects attempts to use cybersecurity issues to smear or slander China.&#8221;</p>
<p>The post <a href="https://internationalfinance.com/technology/google-disrupts-chinese-hacking-operations-more-than-nations/">Google disrupts Chinese hacking operations in more than 40 nations</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/google-disrupts-chinese-hacking-operations-more-than-nations/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Crypto in 2024: Losses jump to USD 2.2 billion</title>
		<link>https://internationalfinance.com/currency/crypto-losses-jump-usd-billion/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=crypto-losses-jump-usd-billion</link>
					<comments>https://internationalfinance.com/currency/crypto-losses-jump-usd-billion/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Thu, 02 Jan 2025 12:50:33 +0000</pubDate>
				<category><![CDATA[Currency]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Bitcoin]]></category>
		<category><![CDATA[crypto]]></category>
		<category><![CDATA[cryptocurrency]]></category>
		<category><![CDATA[digital asset]]></category>
		<category><![CDATA[Donald Trump]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[United States]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=51785</guid>

					<description><![CDATA[<p>According to Chainalysis, cryptocurrency hacking associated with North Korea more than doubled in size from a year ago to reach a record high of USD 1.33 billion in 2024</p>
<p>The post <a href="https://internationalfinance.com/currency/crypto-losses-jump-usd-billion/">Crypto in 2024: Losses jump to USD 2.2 billion</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>According to a report released by blockchain analysis firm Chainalysis, the amount of money obtained through <a href="https://internationalfinance.com/currency/insights-cryptocurrency-market-going-witness-potential-altcoin-season/"><strong>cryptocurrency</strong></a> platform hacking increased by 21% from the previous year to USD 2.02 billion in 2024.</p>
<p>It stated that the number of hacking incidents increased to 303 from 282 in 2023 and that the total hacking amount surpassed USD 1 billion for the fourth consecutive year.</p>
<p>In 2023, hackers had taken USD 1.08 billion. As Bitcoin BTC increased 140% in 2024 to reach the USD 100,000 mark, attracting institutional participation and support from United States President-elect Donald Trump, there has been an increase in cryptocurrency thefts.</p>
<p>&#8220;As the digital asset market booms, it is typical to see the illicit use of crypto grow in tandem. Countering the proliferation of these crimes — especially fraud — will undoubtedly be a key challenge for the industry in the new year,&#8221; Chainalysis&#8217; cybercrimes research lead Eric Jardine said, as reported by Reuters. </p>
<p>According to the report, the majority of cryptocurrency thefts in 2024 were caused by breaches in the private key that governs access to users&#8217; assets, with centralised platforms being the target of the majority of attacks. The most prominent hacks include the May theft of over USD 305 million from Japan&#8217;s cryptocurrency exchange DMM Bitcoin and the July loss of USD 235 million from India&#8217;s WazirX.</p>
<p>According to Chainalysis, cryptocurrency hacking associated with North Korea more than doubled in size from a year ago to reach a record high of USD 1.33 billion in 2024.</p>
<p>According to the United Nations, North Korea can evade international sanctions by using cryptocurrency. Participation in cyber hacking or crypto heists is frequently denied by the nation.</p>
<p>Meanwhile, Ethereum wants to hit USD 4,500 in the next cryptocurrency boom, and investors are keeping a careful eye on the market to find ways to increase their profits. Despite Ethereum&#8217;s continued dominance in the blockchain market, new initiatives like DLUME are gaining popularity due to their potential to yield even greater profits.</p>
<p>Also, <a href="https://internationalfinance.com/currency/bitcoin-surges-past-usd-for-the-first-time/"><strong>Bitcoin</strong></a> more than doubled in 2024 driven by the American markets regulator’s approval for exchange-traded funds tied to its spot price, and optimism over easing regulatory hurdles with Donald Trump returning to the White House.</p>
<p>The world’s largest and most well-known cryptocurrency hit USD 100,000 in December 2024, a milestone that has ignited ‘animal spirits’ among supporters of the once-nascent asset class.</p>
<p>According to CoinGecko data, there is more than 120% surge in Bitcoin and a nearly 50% jump in ether, the second-largest cryptocurrency, have propelled the sector’s market value to roughly USD 3.5 trillion</p>
<p>“We remain convinced USD 100,000 is not the final milestone. We expect Bitcoin to hit a cycle-high of USD 200,000 in late 2025,” analysts at brokerage Bernstein wrote in a client note earlier this month.</p>
<p>MicroStrategy, a software firm that has become the world’s largest corporate holder of Bitcoin, has seen its shares surge nearly five-fold in 2024. The stock, which joined the benchmark Nasdaq-100 index recently, is now seen as a proxy for Bitcoin, with its movement closely tied to sentiment towards the digital asset. Several smaller companies are following its playbook and allocating portions of their cash to Bitcoin.</p>
<p>“We expect Bitcoin to emerge as the new-age premier store of value asset eventually replacing gold over the next decade and becoming a permanent part of institutional multi-asset allocation and a standard for corporate treasury management,” Bernstein analysts continued further.</p>
<p>In January 2024, the United States Securities and Exchange Commission (SEC) approved the first ETFs to track the spot price of Bitcoin, marking a watershed moment for the broader crypto industry.</p>
<p>The move gave the sector institutional legitimacy and improved its mainstream appeal as traditional finance heavyweights including BlackRock and Fidelity launched the products.</p>
<p>The victory of Donald Trump, who has promised to make the United States the “crypto capital of the planet,” further bolstered the industry’s position by 2024 end. Crypto advocates donated millions during the election, hoping to elect candidates that favour the sector.</p>
<p>While most crypto stocks have also benefited from the industry-wide rally, with the big winners being MicroStrategy, crypto exchange Coinbase and Bitcoin miner Hut 8, several other crypto miners reeled under shrinking margins due to higher energy and hardware costs, thereby missing out from the gold rush. Prominent are Riot Platforms, Marathon Digital and Bit Digital, whose shares lost between 26% and 32% in 2024.</p>
<p>The post <a href="https://internationalfinance.com/currency/crypto-losses-jump-usd-billion/">Crypto in 2024: Losses jump to USD 2.2 billion</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/currency/crypto-losses-jump-usd-billion/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Digital extortion: Doxing in the crypto era</title>
		<link>https://internationalfinance.com/magazine/technology-magazine/digital-extortion-doxing-in-the-crypto-era/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=digital-extortion-doxing-in-the-crypto-era</link>
					<comments>https://internationalfinance.com/magazine/technology-magazine/digital-extortion-doxing-in-the-crypto-era/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Tue, 12 Nov 2024 10:07:00 +0000</pubDate>
				<category><![CDATA[Magazine]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[cryptocurrency]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Doxing]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[gaming]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[SIM-Swapping]]></category>
		<category><![CDATA[social media]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=51328</guid>

					<description><![CDATA[<p>Many doxing attempts revolve around Doxbin, a website that hosts over 176,000 public and private doxes</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/digital-extortion-doxing-in-the-crypto-era/">Digital extortion: Doxing in the crypto era</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Since the early 1990s, doxing, the practice of revealing someone&#8217;s identity online and stealing their anonymity, has been utilised as a destructive form of online retaliation. However, the toxic practice has resurfaced in recent years, with victims being doxed, blackmailed, and threatened with physical harm in the worst situations, all in exchange for cryptocurrency.</p>
<p>Security researcher Jacob Larsen, who was doxed about ten years ago when someone tried to extort him for a gaming account, has been keeping an eye on doxing groups, observing the methods used to uncover identities, and speaking with well-known doxing community members for the past year.</p>
<p>According to Larsen&#8217;s interviews, &#8220;well over six figures annually&#8221; have been made as a result of doxing actions. One technique involves feigning law enforcement requests to obtain people&#8217;s personal information.</p>
<p>“The primary target of doxing, particularly when it involves a physical extortion component, is for finance,” says Larsen, who leads an offensive security team at cybersecurity company CyberCX but conducted the doxing research in a personal capacity with the support of the company.</p>
<p>Larsen conducted interviews with &#8220;Ego&#8221; and &#8220;Reiko,&#8221; two members of the doxing community, during several online chat sessions in August and September of 2023.</p>
<p>Reiko served as an administrator of Doxbin, the largest public doxing website, last year in addition to being involved in other groups. Ego is thought to have been a member of the five-person doxing group known as ViLe, though neither of their offline identities is known to the public.</p>
<p>In June 2024, two additional members of ViLe pleaded guilty to charges of identity theft and hacking. Larsen, Ego, and Reiko mentioned that both individuals deleted their social media accounts, which made it impossible for them to be interviewed.</p>
<p>People can be doxed for a variety of reasons, such as inciting political violence or harassing others in online gaming. According to Bree Anderson, a digital criminologist at Deakin University in Australia who has studied the issue with colleagues, doxing can &#8220;humiliate, harm, and reduce the informational autonomy&#8221; of those who are targeted.</p>
<p>According to Anderson, there are two types of harms: immediate or &#8220;first-order,&#8221; like risks to one&#8217;s safety, and longer-term or &#8220;second-order,&#8221; like worry about information disclosures in the future.</p>
<p>The majority of Larsen&#8217;s study was on people who were doxing for financial gain. Many doxing attempts revolve around Doxbin, a website that hosts over 176,000 public and private doxes. These doxes can include names, social media accounts, Social Security numbers, residential and workplace addresses, and other similar details belonging to an individual&#8217;s family.</p>
<p>Larsen believes that extortion is the primary motivator for most doxing incidents on Doxbin, although there are other reasons such as seeking attention. Unless the uploaded information violates the website&#8217;s terms of service, it will not be removed.</p>
<p>“It is your responsibility to uphold your privacy on the internet,” Reiko said in one of the conversations with Larsen, who has published the transcripts.</p>
<p>Ego added, “It’s on the users to keep their online security tight, but let’s be real, no matter how careful you are, someone might still track you down.”</p>
<p><strong>Impersonating police, violence as a service</strong></p>
<p>It is nearly hard to be completely anonymous online, and many people don&#8217;t even try; instead, they frequently use their real names and other personal information in their online accounts and when sharing content on social media.</p>
<p>Some of the doxing techniques outlined in the charges against ViLe members include using shared passwords to access accounts, hacking into private and public databases, and using social engineering to carry out SIM-swapping attacks. There are also many malicious techniques in existence.</p>
<p>Additionally, Larsen notes that emergency data requests (EDR) can be misused. When there may be a risk to people&#8217;s safety, law enforcement officials can use EDRs to obtain the names and contact information of individuals from tech companies without a court order.</p>
<p>In general, these requests must originate from official government or law enforcement email addresses and are sent straight to tech platforms, frequently via specialised online portals.</p>
<p>“If a threat actor can intercept that process, it’s the fastest way for them to get highly accurate sensitive data on the victim. They’re stepping up and using that as their primary method for doxing victims,” Larsen explained.</p>
<p>In the past, this type of request has been used as a weapon against security researchers and to harass women and children.</p>
<p>Larsen claims to have infiltrated multiple Telegram groups during his research, where individuals were offering access to systems for creating EDRs and the government emails required to submit requests.</p>
<p>Using a United States Department of Justice email address and claiming to have an FBI email address, one person, according to screenshots released by Larsen, claimed to be selling access to TikTok&#8217;s law enforcement platform. Someone else asserted that they could create official email addresses for $125 per, originating from Mozambique, the Philippines, Pakistan, and Brazil.</p>
<p>According to Larsen, he gave law enforcement authorities the information. A representative for TikTok referred to the company&#8217;s public policies regarding emergency data requests and the procedures it follows to verify their validity, but the FBI declined to comment on fraudulent EDRs. A request for comment from the US Cybersecurity and Infrastructure Security Agency was not answered.</p>
<p>“Violence as a service” groups have appeared from SIM-swapping communities in recent years as well, allowing people to pay for violent acts to be carried out. Digital extortion can lead to physical extortion, Larsen says, adding that Doxbin doesn’t allow threats or discussions of violence to be posted on its platform.</p>
<p>“I’ve seen people get doxed and that ends up in them being bricked, getting their house shot up, getting a Molotov thrown through their windows, gang stalked, all in an attempt to extort them for money. Videos of attacks are sometimes posted online. Things get pretty wicked online, much more than people realise,” Ego said in a conversation with Larsen.</p>
<p>These incidents can involve people trying to extort cryptocurrency from people with large stashes—although some violence services have been used by feuding online groups.</p>
<p>“Unless these platforms get taken down, or more actors get punished, both in the US and abroad, it&#8217;s just going to continue to rise. Particularly as cryptocurrency becomes more adopted by more people,&#8221; Larsen said.</p>
<p><strong>Few doxing protections</strong></p>
<p>Although some aspects of doxing may be covered by laws about stalking, harassment, or data protection, there aren&#8217;t many legal safeguards against it worldwide.</p>
<p>“Laws worldwide are simply not fit to provide protection. Victims have no way to swiftly regain control of information that has been published with the intent to harass, intimidate, and/or harm them,&#8221; Amanda Manyame, digital rights adviser at Equality Now, a feminist human rights NGO said.</p>
<p>“The prompt takedown of doxing-related content is very important for victims, and governments need to enact laws that mandate the removal of such content within 24 hours, with Equality Now’s research stating that doxing can disproportionately impact women and girls,&#8221; Manyame added.</p>
<p>Doxbin releases a transparency report detailing the quantity of removal requests it receives, emulating the actions of Big Tech platforms and highlighting the difficulties in obtaining information removed.</p>
<p>According to Larsen, there are about 160 requests from lawyers and local and federal law enforcement agencies from 27 different countries. Most of these requests are turned down because they don&#8217;t violate Doxbin&#8217;s restrictive terms of service.</p>
<p>There are steps people can take to lessen some of the effects associated with doxing and other widespread online privacy abuses, even though there are few legal avenues to get data removed.</p>
<p>Common cybersecurity precautions, such as locking down social media accounts and refraining from posting images or personal information, turning on multi-factor authentication for as many accounts as possible, and not reusing passwords across apps and websites, can all be helpful on an individual basis, according to Larsen.</p>
<p>Using usernames and emails that aren&#8217;t connected to the same email address or online handle could be a good starting point for those who want to go further.</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/digital-extortion-doxing-in-the-crypto-era/">Digital extortion: Doxing in the crypto era</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/magazine/technology-magazine/digital-extortion-doxing-in-the-crypto-era/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>LockBit ransomware: The global cyber menace</title>
		<link>https://internationalfinance.com/magazine/technology-magazine/lockbit-ransomware-the-global-cyber-menace/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=lockbit-ransomware-the-global-cyber-menace</link>
					<comments>https://internationalfinance.com/magazine/technology-magazine/lockbit-ransomware-the-global-cyber-menace/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Mon, 17 Jun 2024 18:30:51 +0000</pubDate>
				<category><![CDATA[Magazine]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Boeing]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[LockBit]]></category>
		<category><![CDATA[LockBitSupp]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[Russia]]></category>
		<category><![CDATA[United States]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=50198</guid>

					<description><![CDATA[<p>The LockBit group managed to extort at least $500 million from victims in 120 countries</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/lockbit-ransomware-the-global-cyber-menace/">LockBit ransomware: The global cyber menace</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A Russian national named Dmitry Yuryevich Khoroshev has hit the headlines, for all the vile reasons, as law enforcement authorities in the United States, United Kingdom, and Australia have jointly named the person as the alleged operator of the LockBitSupp handle and the organisational mastermind behind the notorious LockBit ransomware group, which has been on a multiyear hacking rampage exporting an estimated USD 500 million from its victims.</p>
<p>&#8220;LockBit ransomware is malicious software designed to block user access to computer systems in exchange for a ransom payment. LockBit will automatically vet for valuable targets, spread the infection, and encrypt all accessible computer systems on a network. This ransomware is used for highly targeted attacks against enterprises and other organisations,&#8221; States Kaspersky.</p>
<p>LockBit attackers have been on the news frequently for threatening global organisations, disrupting their operations, extorting the victims financially, stealing data and illegally publishing them on the dark web.</p>
<p>LockBit has transformed itself into a subclass of ransomware known as a ‘crypto virus’ due to its ability to form its ransom requests around financial payment in exchange for decryption. The element focuses mostly on enterprises and government organisations rather than individuals.</p>
<p>&#8220;Attacks using LockBit originally began in September 2019, when it was dubbed the “.abcd virus.” The moniker was in reference to the file extension name used when encrypting a victim’s files. Notable past targets include organisations in the United States, China, India, Indonesia, and Ukraine. Additionally, various countries throughout Europe (France, UK, Germany) have seen attacks,&#8221; Kaspersky commented.</p>
<p>&#8220;Viable targets are ones that will feel hindered enough by the disruption to pay a heavy sum — and have the funds to do so. As such, this can result in sprawling attacks against large enterprises from healthcare to financial institutions. In its automated vetting process, it seems to also intentionally avoid attacking systems local to Russia or any other countries within the Commonwealth of Independent States. Presumably, this is to avoid prosecution in those areas,&#8221; the cybersecurity firm added further.</p>
<p>LockBit functions as ransomware-as-a-service (RaaS). Willing parties put a deposit down for the use of custom for-hire attacks, and profit under an affiliate framework. Ransom payments are divided between the LockBit developer team and the attacking affiliates, who receive up to three-fourths of the ransom funds.<br />
How LockBit hit the news?</p>
<p>As recent as May 2024, reports emerged about the cybercriminals targeting American aviation giant Boeing using the LockBit ransomware platform in October 2023, during which these threat actors also demanded a $200 million extortion payment.</p>
<p>Boeing reportedly did not pay any ransom to LockBit after roughly 43 gigabytes of company data was posted to LockBit’s website in November 2023, according to BleepingComputer. Boeing, however, confirmed a “cyber incident” and said the incident was impacting elements of its parts and distribution business. The company refrained from commenting publicly in detail about the incident. However, they eventually admitted the episode during a US Justice Department indictment, which identified Dmitry Yuryevich Khoroshev as the main administrator and developer behind the LockBit ransomware operation.</p>
<p>&#8220;The reference in the indictment to the unnamed company (read Boeing) was an example of the ‘extremely large’ ransom demands made by Khoroshev and his co-conspirators, as they racked up more than $500 million in ransoms paid by victims since late 2019 or early 2020,&#8221; Cyberscoop reported further.<br />
“I believe this may be the second biggest ransom demand to date — or, perhaps more accurately, to have become public knowledge,” said Brett Callow, a ransomware analyst with the cybersecurity firm Emsisoft, while interacting with Cyberscoop.</p>
<p>Callow said that it was “unlikely” that LockBit “had the ability to accurately determine just how sensitive that data was — or how much Boeing may be willing to pay to prevent it being published — and so made a ridiculously high demand simply to see what would happen. They probably had no realistic expectation of actually being paid that amount.”</p>
<p>LockBitSupp, the online persona that communicates with journalists and others online on behalf of LockBit, also confirmed to CyberScoop that Boeing was the unnamed company.</p>
<p>&#8220;US and British law enforcement authorities said that Khoroshev is LockBitSupp. A message posted to LockBitSupp’s account on the messaging platform said the authorities identified the wrong person,&#8221; Cyberscoop commented further.</p>
<p><strong>Meet Dmitry Yuryevich Khoroshev</strong></p>
<p>Has LockBitSupp played a mind game by stating Khoroshev as the &#8220;Wrong Person?&#8221; There is no definitive answer to this question, except the fact that the Russian individual we are talking about has been named by the American and British law enforcement authorities behind the LockBit ransomware attacks.<br />
The Wired states, &#8220;LockBitSupp has evaded identification and bragged that people wouldn’t be able to reveal their offline identity—even offering a $10 million reward for their real name.&#8221;</p>
<p>Law enforcement’s linking of Khoroshev to LockBitSupp comes after the UK police infiltrated the LockBit group’s systems and made several arrests—taking its servers offline, gathering the group’s internal communications, and putting a stop to LockBit’s hacking spree. The law enforcement takedown, dubbed “Operation Cronos” and led by the UK’s National Crime Agency (NCA), has essentially neutralised the hacking group and sent ripples through the wider Russian cybercrime ecosystem. Not only Boeing, LockBitSupp even targeted sandwich chain Subway.</p>
<p>In addition to being named, Khoroshev has also been sanctioned by the US, UK, and Australia. According to the United States Office of Foreign Assets Control, Khoroshev is 31 and lives in Russia, with details of his sanction designation also listing multiple email addresses and cryptocurrency addresses, alongside his Russian passport details. Washington has also filed an indictment against him.</p>
<p>The indictment says Khoroshev has acted as the LockBit group&#8217;s “developer and administrator” since around September 2019, designing and developing its “control panel” used within ransomware attacks. The LockBit group managed to extort at least $500 million from victims in 120 countries, including Khoroshev&#8217;s home country Russia.  The indictment further says that he received around $100 million from this activity.</p>
<p>In early 2024, before the crackdown by Western authorities, LockBit had risen to become one of the most prolific ransomware groups ever, launching hundreds of attacks on a monthly basis and ruthlessly publishing stolen data from companies if they refused to pay.</p>
<p>As per the Wired, investigators are also starting to unpick more details about the scale and scope of LockBit’s operations. An unnamed UK National Crime Agency (NCA) senior investigating officer, who is involved with the probe, says LockBit listed 2,350 victims publicly on its leak site up to the end of December 2023, but that this is just a small fraction of its hacking activity.</p>
<p><strong>Judging gravity of the situation</strong></p>
<p>As per Kaspersky, LockBit attacks are self-spreading in nature, when they target an organisation, meaning they don&#8217;t require manual direction from the human threat agents. The attacks don&#8217;t happen in a scattershot manner like spam malware, and the acts can be conducted through tools like Windows Powershell and Server Message Block (SMB).</p>
<p>During the attack stage, LockBit can self-propagate itself, meaning the malware spreads on its own. In its programming, LockBit is directed by pre-designed automated processes. This makes it unique from many other ransomware attacks that are driven by manually living in the network, sometimes for weeks, to complete reconnaissance and surveillance tasks.</p>
<p>&#8220;After the attacker has manually infected a single host, it can find other accessible hosts, connect them to infected ones, and share the infection using a script. This is completed and repeated entirely without human intervention,&#8221; Kaspersky described the nature of LockBit attacks exactly in these words.</p>
<p>&#8220;Furthermore, it uses tools in patterns that are native to nearly all Windows computer systems. Endpoint security systems have a hard time flagging malicious activity. It also hides the executable encrypting file by disguising it as the common .PNG image file format, further deceiving system defences,&#8221; it added further.</p>
<p>Breaking down the stages of LockBit attacks, the initial breach looks much like other malware attacks. An organisation may be exploited by social engineering tactics like phishing, in which attackers impersonate trusted personnel or authorities to request access credentials. Equally viable is the use of brute force attacks on an organization’s intranet servers and network systems. Without proper network configuration, attack probes may only take a few days to complete. Once LockBit makes its way into the network, the ransomware prepares the system to release its encrypting payload across every device it can.</p>
<p>In stage two, LockBit infiltrates deeper to complete the attack setup if needed. From here onwards, the LockBit programme directs all activity independently.</p>
<p>&#8220;It is at this stage that LockBit will take any preparative actions before deploying the encryption portion of the ransomware. This includes disabling security programmes and any other infrastructure that could permit system recovery,&#8221; it continued further, while adding, “the goal of infiltration is to make unassisted recovery impossible, or slow enough that succumbing to the attacker’s ransom is the only practical solution. When the victim is desperate to get operations back to normal, this is when they will pay the ransom fee.&#8221;</p>
<p>In the third stage, the malware deploys the encryption payload. Once the network has been prepared for LockBit to be fully mobilised, the ransomware will begin its propagation across any machine it can touch. A single system unit with high access can issue commands to other network units to download LockBit and run it.<br />
The encryption portion will place a “lock” on all the system files. Victims will only be able to unlock their systems via a custom key created by LockBit’s proprietary decryption tool. The process also leaves copies of a simple ransom note text file in every system folder. It provides the victim with instructions to restore their system and has even included threatening blackmail in some LockBit versions.</p>
<p>&#8220;With all the stages completed, the next steps are left up to the victim. They may decide to contact LockBit’s support desk and pay the ransom. However, following their demands is not advised. Victims have no guarantee that the attackers will follow through on their end of the bargain,&#8221; Kaspersky remarked.</p>
<p><strong>Rise of LockBit</strong></p>
<p>The malware first emerged in 2019 as a fledgling “ransomware-as-a-service” (RaaS) platform. Under this setup, a core handful of individuals, organised by the LockBitSupp handle, created the group’s easy-to-use malware and launched its leak website. This particular group is still reportedly licencing LockBit’s code to “affiliate” hackers who launch attacks and negotiate ransom payments, eventually providing LockBit with around 20% of their profits.</p>
<p>Despite launching thousands of attacks, the group, in its starting days, maintained a low-profile, compared to other threat actors. Over time, as the malware started to dominate the cybercrime ecosystem, its members became more brazen and careless. As per an unnamed NCA senior investigator, these individuals pulled data about 194 affiliates from LockBit’s systems and were piecing together their offline identities. </p>
<p>The NCA investigator further pointed out “numerous” examples of the LockBit administrator directly “taking responsibility” for high-profile/high-ransom negotiations after affiliates had initially attacked the companies or organisations.</p>
<p>The US DOJ indictment claims Khoroshev, as LockBitSupp, kept a close track of his affiliates, keeping databases of each affiliate and the victims they had targeted. In some cases, the Russian demanded identification documents from his affiliate co-conspirators, which he also maintained on his infrastructure.<br />
Jon DiMaggio, a researcher at cybersecurity firm Analyst1, who has been aggressively researching LockBit, apart from communicating with the LockBitSupp handle, told Wired, “He (Khoroshev) treated it like a business and often sought out feedback from his affiliate partners on how he could make the criminal operation more effective.&#8221;</p>
<p>&#8220;The LockBitSupp character would ask affiliates what they needed in order to more effectively do their work. He did not simply take money for himself, but he reinvested it into developing his operation and making it more desirable to criminals,&#8221; DiMaggio noted.</p>
<p>DiMaggio says the person he was speaking to privately using the LockBitSupp moniker was “arrogant but all business and very serious,” apart from sending cat stickers as part of chats.</p>
<p>&#8220;Publicly, on Russian language cybercrime forums where hackers trade data and discuss hacking politics and news, LockBitSupp was entirely different. The persona he amplified on the Russia hacking forums was a mix of a supervillain and Tony Montana from Scarface. He flaunted his success and money, and it rubbed people the wrong way at times,&#8221; DiMaggio continued further.</p>
<p>&#8220;In addition to setting a bounty on their own identity, LockBitSupp’s more innovative and erratic side also organised an essay-writing competition on the hacking forums, offered a bug bounty if people found flaws in LockBit’s code, and said they would pay $1,000 to anyone who got the LockBit logo as a tattoo. Around 20 people posted pictures and videos of their tattoos,&#8221; Wired continued.</p>
<p>Immediately after law enforcement claimed to reveal LockBitSupp’s identity, DiMaggio published new research about Khoroshev. Using a tip he received, plus open source intelligence and leaked dark web information, DiMaggio found social media profiles and extra personal information allegedly linked to the Russian national.<br />
LockBitSupp was reportedly banned from two prominent Russian-language cybercrime forums in January 2024 after a complaint was made about their behaviour.</p>
<p><strong>And the downfall finally came</strong></p>
<p>In February 2024, an international task force of law-enforcement agencies from 10 countries, dubbed &#8220;Operation Cronos,&#8221; disrupted LockBit&#8217;s operations. LockBit’s technical infrastructure and its public-facing leak site on the dark web were seized after a months-long operation.</p>
<p>On 20 February, the NCA published details of the operation, and replaced content on the LockBit website, with an expose on LockBit’s operations and capabilities, including decryption keys, news of two arrests and a $10 million reward for information on ‘LockBitSupp’.</p>
<p>However, the battle was far from over, as it took LockBitSupp only five days to create replica versions of the group’s leak site. The website then started to be filled with apparent victims and it seemed like the LockBit group hadn’t been impacted by having all of its internal secrets accessed by Law enforcement agencies.<br />
The NCA says the number of LockBit affiliates has dropped to 69 since its February takedown, while the DOJ indictment says LockBit’s victim count has “greatly diminished” since then.</p>
<p><strong>What to expect now?</strong></p>
<p>As per the DOJ indictment, post &#8220;Operation Cronos,&#8221; Khoroshev got in touch with law enforcement, in an attempt to “stifle his competition.”</p>
<p>&#8220;He offered his services in exchange for information regarding the identity of his RaaS competitors. Specifically, Khoroshev asked law enforcement during that exchange to, in sum and substance, give me the names of my enemies,” the indictment mentioned further.</p>
<p>Ahead of law enforcement naming Khoroshev, a countdown appeared on the website, and LockBitSupp responded by publishing scores of victims.</p>
<p>“LockBitSupp has a lot of enemies and people waiting to take his place,” said DiMaggio, the Analyst1 researcher, while adding that the group would unlikely stop their actions.</p>
<p>As per the NCA, the task force has seized LockBit’s bespoke data exfiltration tool, Stealbit, which was based in three countries and used to steal data, as well as 28 servers belonging to the group’s affiliates.</p>
<p>Europol, on the other hand, coordinated the arrest of two LockBit members in Poland and Ukraine and froze 200 cryptocurrency accounts linked to the group.<br />
In the United States, indictment charges were brought against Russian nationals Artur Sungatov and Ivan Kondratyev, aka ‘Bassterlord’, for using LockBit against businesses globally.</p>
<p>Operation Cronos has also obtained more than 1,000 decryption keys, which can help victims recover their data. All these coordinated actions from the legal authorities are hitting LockBit hard. How long will the group remain defiant? Let’s wait and watch.</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/lockbit-ransomware-the-global-cyber-menace/">LockBit ransomware: The global cyber menace</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/magazine/technology-magazine/lockbit-ransomware-the-global-cyber-menace/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>IF Insights: UAE&#8217;s digital transformation faces cybersecurity challenges</title>
		<link>https://internationalfinance.com/technology/if-insights-uaes-digital-transformation-faces-cybersecurity-challenges/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=if-insights-uaes-digital-transformation-faces-cybersecurity-challenges</link>
					<comments>https://internationalfinance.com/technology/if-insights-uaes-digital-transformation-faces-cybersecurity-challenges/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Thu, 02 May 2024 04:20:13 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[cyberattacks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[economy]]></category>
		<category><![CDATA[Gulf]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Meta]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Middle East]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[UAE]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=49880</guid>

					<description><![CDATA[<p>Although the UAE's Digital Strategy 2025 provides a strong basis for a digital future, it also necessitates the improvement of cybersecurity measures in tandem</p>
<p>The post <a href="https://internationalfinance.com/technology/if-insights-uaes-digital-transformation-faces-cybersecurity-challenges/">IF Insights: UAE&#8217;s digital transformation faces cybersecurity challenges</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Something is terrifying below the glamorous and chaotic cyberworld. Look at this local data if you&#8217;re still not convinced about the dangers that lurk in digital interactions and transactions. It is a fact that the public sector in the United Arab Emirates is subject to approximately 50,000 attempts at cyberattacks every day.</p>
<p>In the first three quarters of last year, the nation prevented over 71 million attempted cyberattacks. Around 87% of UAE-based businesses experienced various cyber events, with 25% of them being the result of employees&#8217; wilful harmful behaviour.</p>
<p>Such was the extent of the danger that Dr Mohammed Al Kuwaiti, the head of the Gulf country&#8217;s Cybersecurity Council, had to call on organisations (both public and private) to remain vigilant against hackers.</p>
<p>The Cybersecurity Council, established by the UAE government in 2020, has been busy from day one. As of November 2023, it was fending off over 50,000 cyber-attacks daily. There were successes, as the ransomware attacks in the UAE declined by more than 70% at the start of 2023, compared with the same period in 2022. However, according to a report from cybersecurity firm Proofpoint in 2023, about two in three businesses (64%) in the country were still experiencing ransomware attacks.</p>
<p><strong>Iran’s Daring Attempt In 2023</strong></p>
<p>Things got heated up in the beginning of 2024, as Iranian state-backed hackers interrupted TV streaming services in the <a href="https://internationalfinance.com/insurance/insurance-claims-rain-related-losses-uae-may-face-denial/"><strong>UAE</strong></a> to broadcast a deepfake newsreader delivering a report on the Gaza conflict. As per Microsoft analysts, the hacking operation, run by the Islamic Revolutionary Guards, a key branch of the Iranian armed forces, had disrupted streaming platforms in the UAE with an AI-generated news broadcast branded “For Humanity”.</p>
<p>&#8220;The fake news anchor introduced unverified images that claimed to show Palestinians injured and killed in Israeli military operations in Gaza. Analysts at Microsoft said the hacking group, known as Cotton Sandstorm, published videos on the Telegram messaging platform showing it hacking into three online streaming services and disrupting news channels with the fake newscaster,&#8221; reported Guardian on the incident in February 2024.</p>
<p>Though wealth and connectivity may make some nations more appealing to attackers than others, all nations are equally vulnerable, when it comes to dealing with cyber-attacks. It makes sense that the UAE, which bills itself as a worldwide centre of innovation and business, is leading the charge on the digital revolution, which comes with a unique set of difficulties, especially in the area of cyber security. Regrettably, the quick adoption of digital technology also attracts the attention of increasingly skilled cybercriminals, exposing holes in the system.</p>
<p>The UAE Digital Government Strategy 2025, which is somewhat ambitious, is guiding the country towards a future that prioritises digitalisation and inclusivity. This plan aims to create smart, resilient cities, as outlined in the Smart Dubai 2021 Strategy and combines 64 digital projects arranged among six pillars.</p>
<p>It promises to revolutionise public services through the Unified Digital Platform. However, a plan is only adequate if everyone involved is willing to take on the challenge. The swift proliferation of technologies like artificial intelligence, cloud computing, and operational technology expands the attack surface and gives cyber criminals more avenues for exploitation.</p>
<p><strong>Survey Paints A Grim Picture</strong></p>
<p>According to a January 2024 research from Kaspersky, 87% of companies in the UAE have faced different forms of cyber incidents in the past two years. Although businesses in the Gulf nation are facing high levels of vulnerability against the threat actors, the problem is not getting any better.</p>
<p>A December 2023 study from the same <a href="https://internationalfinance.com/technology/cybersecurity-company-dragos-failed-ransomware-attack-public/"><strong>cybersecurity</strong></a> company, showed that 77% of APAC (Asia-Pacific) companies don&#8217;t possess the tools required for spotting cyberattacks. Meanwhile, 87% of firms are plagued by a shortage of cybersecurity talent, making it harder to stop cyber criminals in their tracks.</p>
<p>In the past, security leaders in the UAE have struggled to ensure secure access to remote employee and corporate-owned devices, said Mohammed Al-Moneer, regional senior director for META at Infoblox, while interacting with the Dark Reading. The official also mentioned businesses fearing data leaks and cloud attacks &#8220;and do not believe they have a firm handle on the insider threat.&#8221;</p>
<p>Gopan Sivasankaran, general manager of the META region at Secureworks, explained that the UAE&#8217;s booming digital economy and greater use of data makes the Gulf nation an &#8220;attractive&#8221; target for both cybercriminals and hostile states.</p>
<p>&#8220;The insight from the incident response engagements and active attacks on organisations we&#8217;ve worked on in the Middle East over the last year show organisations in the UAE have been victims to large scale wiper attacks as well as nation-state sponsored attacks,&#8221; Sivasankaran remarked.</p>
<p>&#8220;Across the Middle East we can see that banking, manufacturing, retail, and healthcare organisations are the most likely to reach out to us for help with a cyber-incident. But government, hospitality, and transportation are also highly prized targets,&#8221; he added further.</p>
<p>An inclusive and comprehensive digital governance structure is necessary as the Gulf country grapples with the challenges of data protection and integration as it continues to adopt cutting-edge technologies to diversify and modernise its economy. The UAE must handle the risks related to cross-border data flows as a global hub, including adhering to international data protection laws.</p>
<p>Inclusion is a key component of the UAE&#8217;s strategy, which guarantees that no one is left behind by digital government programmes. Adopting transparent procedures and emphasising accessibility for all demographics—particularly the old, the disabled, women, and children—are part of this.</p>
<p>The UAE seeks to use cutting-edge technologies to foresee and proactively address disasters under the resilience dimension. This entails strengthening government operations and disseminating information about cybersecurity best practices and hazards to the general public and companies.</p>
<p>The plan also establishes national digital priorities and encourages cross-sectoral cooperation. Deep digital technology integration is necessary at all governmental levels. To improve engagement and convenience, the UAE plan highlights the significance of creating digital services around people&#8217;s needs with a focus on user-driven services. All policy procedures must undergo digital transformation, and continual experimentation is required to keep up with the rapid improvements in technology.</p>
<p>The data-driven aspect acknowledges the importance of data in improving public services. To avoid security lapses and maintain public confidence, it is crucial to handle this data ethically and securely. By emphasising proactiveness, the plan seeks to improve interactions with government services through the use of technologies such as the UAE National Digital ID. This lowers administrative barriers and calls for sophisticated security measures to prevent identity theft and unauthorised access.</p>
<p>Ensuring top-notch digital infrastructure and integrated services that cater to user needs are among the main goals of the UAE&#8217;s digital strategy. It is essential to commit to improving digital skills and making sure laws are ready for the digital transition. To successfully manage risks, attaining these goals necessitates a comprehensive cybersecurity infrastructure that keeps up with technological changes.</p>
<p>Although the UAE&#8217;s Digital Strategy 2025 provides a strong basis for a digital future, it also necessitates the improvement of cybersecurity measures in tandem. It is critical to address the lack of qualified cybersecurity specialists and improve the current digital infrastructure to prevent and withstand advanced cyberattacks. The UAE won&#8217;t be able to safeguard its goals for digital transformation against the constantly changing cyber threat landscape until then.</p>
<p>The goal of the strategy is to make the nation a global leader in innovation, the digital economy, and public services. But like any big digital transformation plan, it has its share of difficulties, especially with cybersecurity. To guarantee that the technological innovations it encourages do not turn into weaknesses, the approach will need to change to meet the escalating cybersecurity requirements. Achieving this goal mostly depends on creating and maintaining an extensive cybersecurity framework that outlines best practices, standards, and reactions to <a href="https://internationalfinance.com/technology/lexmark-security-bug-exposes-thousands-printers-cyberattacks/"><strong>cyberattacks</strong></a>.</p>
<p>To guard against growing cyber threats, the UAE&#8217;s strategy must keep creating strong cybersecurity frameworks. This includes technical advancements as well as legislative and regulatory frameworks that are flexible enough to adjust to the constantly evolving nature of cyber threats and the requirement for dynamic response tactics. Along with constant attention and development, the UAE&#8217;s proactive approach to cybersecurity strategy updates and international collaboration is essential to managing these dangers.</p>
<p>The post <a href="https://internationalfinance.com/technology/if-insights-uaes-digital-transformation-faces-cybersecurity-challenges/">IF Insights: UAE&#8217;s digital transformation faces cybersecurity challenges</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/if-insights-uaes-digital-transformation-faces-cybersecurity-challenges/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Twitter&#8217;s cybercrime mess</title>
		<link>https://internationalfinance.com/magazine/technology-magazine/twitters-cybercrime-mess/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=twitters-cybercrime-mess</link>
					<comments>https://internationalfinance.com/magazine/technology-magazine/twitters-cybercrime-mess/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Thu, 19 Oct 2023 00:47:36 +0000</pubDate>
				<category><![CDATA[Magazine]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Blogging]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[cryptocurrency]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Scammers]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Tweets]]></category>
		<category><![CDATA[Twitter]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=48291</guid>

					<description><![CDATA[<p>According to the 2023 Axios Harris reputation rankings, Twitter under Elon Musk is the fourth-most-despised brand in the United States</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/twitters-cybercrime-mess/">Twitter&#8217;s cybercrime mess</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The abrupt resignation of Twitter officials in charge of brand safety and content moderation, after Elon Musk’s takeover of the micro-blogging platform in October 2022, has made the portal more open to hate speech and cybercrime than before.</p>
<p>Ella Irwin, the vice president of trust and safety at Twitter, left the organization. A.J. Brown, the organization&#8217;s head of brand safety and ad quality, and Maie Aiyed, a program manager who handled brand-safety relationships, reportedly resigned after Irwin left.</p>
<p>It has been close to a year since Elon Musk completed the $44 billion acquisition of Twitter, an investment which has so far proven to be a colossal loss for the maverick tech billionaire. He has significantly downsized the company&#8217;s employees and reversed content distribution-related restrictions. As a result, several companies stopped or reduced their advertising expenditures.</p>
<p>According to the 2023 Axios Harris reputation rankings, Twitter under Elon Musk is the fourth-most-despised brand in the United States. And the scepticism around his ownership of Twitter keeps growing.</p>
<p>Since Elon Musk took control, phishing attempts against Twitter (now rebranded as X) have increased. The changes to the ‘Twitter Blue Premium Verification&#8217; service have given threat actors a pretext to steal users&#8217; login information.</p>
<p>Researchers at cybersecurity vendor Proofpoint have noticed an upsurge in Twitter-related phishing attacks. According to the Proofpoint team, numerous advertisements have employed enticements relating to Twitter verification or the new Twitter Blue offering, such as &#8220;Twitter Blue Badge Billing Statement Available.&#8221;</p>
<p>After taking over the company, Elon Musk added an $8 monthly fee for the ‘Twitter Blue’ service. He has guaranteed that tweets from verified users will be prioritized on Twitter feeds. Users who paid were verified with the website&#8217;s well-known blue tick. The plan has been suspended, nevertheless, due to several spoof account issues.</p>
<p><strong>Twitter and phishing attempts</strong></p>
<p>Twitter phishing attempts use URLs that redirect to criminal infrastructure in addition to Google Forms for data harvesting. Vice President of threat research and Detection Sherrod DeGrippo stated, “These initiatives typically target members of the media and the entertainment industry, including journalists and Twitter users who have the appearance of being verified. Frequently, the email address is the same as the Twitter handle used, or it may be found in the user&#8217;s Twitter bio.”</p>
<p>&#8220;While we have occasionally seen Twitter credential phishing employing lures linked to verification from cybercrime threat actors in the past, the activity has picked up recently,&#8221; the official added further.</p>
<p>In the past, TA482, a hacker gang, has frequently used Twitter-related phishing to target media users. But research published in July 2023 by Check Point Research claimed that delivery service DHL is the most impersonated company for phishing scams, followed by Microsoft and LinkedIn. When it comes to the most-targeted brands for these kinds of attacks, Twitter (rebranded as X) does not even make the top ten.</p>
<p>DeGrippo stated further, &#8220;To maximize the possibility that a user would interact with social engineering content, cybercriminal threat actors frequently exploit themes connected to important news stories and relevant to people&#8217;s interests.”</p>
<p>Even if Twitter and the social media platform are currently quite active, acquiring access to accounts is still profitable. Twitter accounts that are legitimately verified typically have larger audiences than the average user, and compromised accounts can be used to spread false information, persuade users to interact with additional malicious content like fraudulent cryptocurrency scams and expand phishing campaigns to other users. </p>
<p>De Grippo warned that &#8220;pig butchering&#8221; fraud, or attacks that start on social media networks before moving on to other services with the ultimate goal of obtaining cryptocurrency, might be launched via Twitter phishing. This kind of activity has increased lately, according to Proofpoint.</p>
<p><strong>Cybercrime on Twitter post takeover</strong></p>
<p>Impersonation of well-known firms has plagued the new authentication system Elon Musk created. Following fake tweets sent by spoof accounts using the names of their respective companies, Eli Lilly and Lockheed Martin suffered a decline in their share prices.</p>
<p>With the ransomware gang Yanluowang joining X in July 2023 to sell their wares, concerns have been raised that the network will be used by hackers to sell stolen data due to the billionaire Tesla&#8217;s devotion to free speech.</p>
<p>He cut down the number of employees responsible for X’s safety and content moderation before the most recent high-profile departures from the concerned department took place. He fired the whole artificial intelligence ethics team, which was in charge of making sure that consumers weren&#8217;t pushed harmful information by algorithms.</p>
<p>The billionaire recently downplayed worries about the prevalence of hate speech on Twitter. During a Wall Street Journal event, he asserted that hate speech on the site has decreased since he took over the firm in October 2022 and that Twitter has reduced &#8220;spam, frauds, and bots&#8221; by &#8220;at least 90%.&#8221;</p>
<p>There is no data to back up those assertions, experts, and ad industry insiders told CNBC. Some even claim that Twitter is purposefully obstructing independent researchers from tracking these numbers.</p>
<p><strong>Ponzi schemes</strong></p>
<p>X is among the most well-known social networks in the world. Naturally, it is also a sanctuary for scammers of all stripes and cybercriminals.</p>
<p>It&#8217;s important to familiarize yourself with common Twitter scams and how they operate, the risk quotient and how to successfully defend yourself against them.</p>
<p>There are many Ponzi schemes out there such as phishing, account hacking scams, conversation frauds, bitcoin scams, and bot scams. </p>
<p>Phishing, a sort of cyberattack in which a threat actor impersonates someone or something they are not, can affect any social media network. With Twitter (rebranded as X), a con artist has virtually endless opportunities to phish users. To provoke the target into entering their credentials, they can use email phishing, by sending false messages.</p>
<p>In November 2022, not long after seizing control of Twitter, Elon Musk unveiled ‘Twitter Blue’, a monthly subscription service that costs money and adds a blue checkmark to a user&#8217;s account.</p>
<p>According to a study by Bleeping Computer, con artists promptly took note of this attempt and launched a sophisticated phishing assault to steal the usernames and passwords of users who wanted to confirm their accounts.</p>
<p>Since Twitter&#8217;s creation, similar phishing campaigns have plagued the social media platform, with fraudsters coming up with ever-creative ways to steal user credentials. The best thing a user can do is to set up two-factor verification and carefully examine each email that purports to be from Twitter because this won&#8217;t change regardless of who is in charge of the social network.</p>
<p>X&#8217;s security and user experience have deteriorated under Elon Musk&#8217;s ownership, becoming increasingly perilous for users. In a recent story published by Wired.com, Tim Utzig, a visually impaired individual was deceived by scammers on the micro-blogging platform. Tim, relying on a screen reader, couldn&#8217;t detect the scam indicators when responding to a tweet from a compromised account. He lost $1,000 in the process.</p>
<p>The author, concerned by the social media portal&#8217;s lack of responsiveness, teamed up with a social engineering expert named Steve to track down the scammers. The efforts revealed a network of fraudsters using elaborate methods, exploiting vulnerabilities, and leveraging blockchain transactions to deceive victims. Multiple individuals were identified through their payment accounts, linked to real-world addresses, underscoring the scope of the scam.</p>
<p>This story illuminates several critical issues with X. The rise in fraudulent activities on the platform, exemplified by Tim&#8217;s case, indicates a worrisome lack of effective security measures. The decline in accessibility support for visually impaired users further compounds the problem, leaving vulnerable individuals like Tim susceptible to exploitation.</p>
<p>The narrative also raises concerns about Twitter&#8217;s changing priorities, as evidenced by its rebranding to &#8220;X&#8221; and ambitious plans to become an &#8220;everything app.&#8221; This pivot, while aiming to expand the platform&#8217;s capabilities, poses significant security risks given the existing vulnerabilities that scammers exploit. The story serves as a cautionary tale, emphasizing the need for users to be vigilant and the urgent necessity for Twitter to prioritize both accessibility and security to prevent further harm to its user base.</p>
<p>Then there are account hacking scams. The blue checkmark on Twitter has always been reserved for the most eminent people, including celebrities, politicians, and influencers. On the other hand, cybercriminals have always coveted the social evidence that comes with obtaining a blue check. They routinely hack verified accounts to get one.</p>
<p>For instance, a 17-year-old teenager hacked the Twitter accounts of Joe Biden, the then-presidential contender, and Bill Gates, the co-founder of Microsoft, in 2020 using a straightforward social engineering technique. The adolescent received a three-year prison sentence after his actions, but they demonstrate how simple it is for cybercriminals to hack verified Twitter accounts, according to The Guardian.</p>
<p>It&#8217;s easy to suppose that many people fell for the young boy&#8217;s con after he hacked into Biden and Gates&#8217; accounts to demand a Bitcoin payment. However, this was not an isolated incident; breaches occur much too regularly, and most often, regular users are the ones who suffer. This is why it&#8217;s crucial to keep in mind that you shouldn&#8217;t ever blindly believe what you see on Twitter. Even if it seems like your favourite celebrity is truly tweeting, make sure to confirm that their message is authentic before taking any action.</p>
<p>Conversion frauds are also tricky. Cybercriminals are developing more inventive ways to con consumers because everyone wants a blue checkmark. Whether you use Facebook, Twitter, or Instagram, you&#8217;ve received a message from someone promising to quickly verify your account.</p>
<p>There are only two ways to have a verified Twitter account in practice. One is a holdover from the first approach, namely making a formal verification request through the platform. There were several requirements you had to meet to receive the blue badge. Most importantly, you had to demonstrate that you are a &#8220;notable&#8221; person involved in politics, the media, or other fields. This is no longer functional, although those who previously had verified accounts may still appreciate the blue tick icon.</p>
<p>There is currently just one method to get the tiny blue checkmark, which is to join up for ‘Twitter Blue’ if you still want one.</p>
<p>Additionally, be sure to report any con artists who offer to verify your account to Twitter. Visit X&#8217;s support page and complete the necessary form there to accomplish this.</p>
<p>In the cryptocurrency industry, scams are all too rampant, and many of them take place on Twitter. You have probably encountered one if you follow cryptocurrency-related accounts or occasionally post about cryptocurrencies.</p>
<p>Twitter cryptocurrency scams come in a variety of forms, some of which are glaringly evident while others are more subtle. One way con artists do this is by pretending to be a well-known digital currency influencer or analyst, posting false tweets, or even sending direct messages to their intended victims. Their tweets may promote worthless cryptocurrencies that will eventually lose value or advertise phoney airdrops and dubious services.</p>
<p>Another scammer favourite is fake cryptocurrency giveaways. This kind of hoax relies on persuading the victim that they would receive a huge reward in exchange for a tiny cryptocurrency deposit to pay a &#8220;fee&#8221; or something comparable. Of course, the fraudster will just take your money and move on to the next victim if you make the mistake of depositing it.</p>
<p>Make sure you thoroughly research any information regarding a specific asset and only trade on reputable cryptocurrency exchanges if you want to avoid falling victim to crypto-related scams on Twitter.</p>
<p>Then there are bot scams. As you may already be aware, social media sites are crawling with bots—computer programs that mimic human activity. Twitter is no different. A 2022 study from the online analytics firm Similarweb discovered that 5% of Twitter users are bots and that they produce between 21% and 29% of the network&#8217;s content.</p>
<p>Although bots are not inherently evil, con artists frequently use them to disseminate false and misleading information, encourage victims to click on harmful links, install malware, and carry out other harmful activities. On Twitter, networks of bots may work together to retweet and like posts to reach a larger audience.</p>
<p>You should always carefully examine any account that sounds suspicious, especially if it frequently spams links in responses to other tweets or sends direct messages, as some Twitter bots can be challenging to recognize and initially resemble real accounts. Block or mute the account in question, and then report it to the micro-blogging platform if you believe it to be a harmful bot.</p>
<p>The recent developments surrounding Twitter, including the departure of key officials responsible for brand safety and content moderation, have raised concerns about the platform&#8217;s susceptibility to hate speech and cybercrime. The abrupt resignation of prominent figures like Ella Irwin, A.J. Brown, and Maie Aiyed has had an impact on the platform&#8217;s ability to maintain a safe and controlled online environment.</p>
<p>Since Elon Musk acquired Twitter and his subsequent changes, there have been notable shifts in the platform&#8217;s policies and practices. These changes have led to decreased content restrictions and alterations to the premium verification service, which has been exploited by cybercriminals for phishing attempts. These phishing attacks use various tactics, including false email messages and Google Forms, to trick users into revealing their login credentials.</p>
<p>Additionally, Elon Musk&#8217;s takeover seems to have made Twitter a more attractive target for hackers, increasing phishing attempts. The compromised accounts, particularly those with the coveted blue checkmark, can be used to spread false information, promote scams, and expand phishing campaigns to other users.</p>
<p>Furthermore, concerns have been raised about the rise of cybercrime on Twitter, such as the selling of stolen data and the potential for pig butchering fraud, which involves using the platform as a stepping stone to other services and ultimately targeting cryptocurrency.</p>
<p>It&#8217;s worth noting that while Elon Musk has claimed improvements in reducing hate speech and spam on the platform, these assertions lack concrete data to support them. The prevalence of scams and cybercrime, including Ponzi schemes, phishing, account hacking, and bot scams, remains a significant challenge for Twitter users.</p>
<p>In navigating this landscape, users are advised to exercise caution, practice good online hygiene, and be sceptical of unsolicited messages or offers. Implementing two-factor authentication, carefully scrutinizing emails and messages, and reporting suspicious accounts are crucial steps to protect oneself from falling victim to cybercrime on the platform. As Twitter continues to evolve under Elon Musk&#8217;s ownership, vigilance and awareness remains the key to staying safe in this ever-changing digital environment.</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/twitters-cybercrime-mess/">Twitter&#8217;s cybercrime mess</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/magazine/technology-magazine/twitters-cybercrime-mess/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Data protection: Banks must rethink strategies</title>
		<link>https://internationalfinance.com/magazine/banking-and-finance-magazine/data-protection-banks-must-rethink-strategies/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=data-protection-banks-must-rethink-strategies</link>
					<comments>https://internationalfinance.com/magazine/banking-and-finance-magazine/data-protection-banks-must-rethink-strategies/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Thu, 20 Apr 2023 05:00:02 +0000</pubDate>
				<category><![CDATA[Banking and Finance]]></category>
		<category><![CDATA[Magazine]]></category>
		<category><![CDATA[Bank]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=46777</guid>

					<description><![CDATA[<p>Criminals can threaten to publish the stolen data on the dark web after the encryption</p>
<p>The post <a href="https://internationalfinance.com/magazine/banking-and-finance-magazine/data-protection-banks-must-rethink-strategies/">Data protection: Banks must rethink strategies</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>While the COVID pandemic has acted as a booster in online banking’s growth story, the risks surrounding the financial services’ cybersecurity front are rising as well. As a result, institutions must be proactive to avoid coming under the regulatory hammer, while dancing to the hackers’ tunes.</p>
<p>While additional rules are appreciated, frequent operational modifications as per these regulations only increase the load on institutions. For example, in response to the increasingly unstable security environment financial institutions are currently confronting, the New York State Department of Financial Services (NYDFS) recently recommended significant revisions to the Part 500 Cybersecurity Regulation. By the proposed changes, anticipated to take effect in 2023, there will be much higher expectations for cyber expertise from businesses. There will also be earlier notifications of cybersecurity events and ransom payments, apart from stricter auditing for large organizations.</p>
<p>As we saw with the initial 23 NYCRR 500, the NYDFS is not afraid to enforce laws harshly, and several fines totalling millions of dollars have already increased the stakes for compliance. However, the advice offered to banks to accomplish this compliance still needs to be clarified. All too frequently, after enforcement measures have been taken, banks and covered entities, such as health insurers and credit unions, are left to rely on hindsight, only considering the lessons learned and fines paid after the fact. Security decision-makers urgently need to rethink their approach to data protection as pressure on banks to comply with regulations grows.</p>
<p><strong>Being pursued by everyone</strong></p>
<p>Since they hold on millions of consumers&#8217; wallet data, banks and credit unions are top targets for cybercriminals. Although this has always been the case, UK-based IT firm Sophos&#8217; yearly analysis of financial services security shows how threats have increased in size, intelligence, and ruthlessness. For instance, ransomware increased by 62% in 2021. Although more than half (52%) of the targeted firms paid the ransom, only 10% had their data returned. These alarming statistics demonstrate how vulnerable banks are becoming in front of these data theft attempts. With the significant increase in double-extortion ransomware tactics, risks abound when hackers first steal copious amounts of confidential data before encrypting the target&#8217;s files. Criminals can threaten to publish the stolen data on the dark web after this encryption.</p>
<p>Additionally, zealous regulators can cause severe reputational and financial harm to organizations. The NYDFS collected USD 6.3 million in fines for cybersecurity non-compliance from four separate companies in the state in just three months in 2021. Despite having protections in place, one of these companies, Residential Mortgage Services, Inc. (RMS), paid USD 1.5 million for neglecting to notify about a 2019 data breach. In addition, a USD 3 million punishment was levied against National Securities for several security violations, including the absence of multifactor authentication (MFA) or &#8220;equivalent&#8221; cybersecurity measures. These businesses not only paid hefty fines but also incurred expenses for forensic investigations and cleanup, in addition to reputational damage.</p>
<p><strong>No time for security checkboxes</strong></p>
<p>The increased accountability in the financial services sector can only be good. However, banks are mainly left to their own devices to navigate the path to successful and compliant cybersecurity, as &#8220;constructive ambiguity&#8221; shapes the original NYDFS rule. This indicates that many still rely on cursory checkbox methods for automatic measures like encryption.</p>
<p>Organizations must alter their trajectory in the face of increasing pressure from regulators and threat actors. Because of today&#8217;s enlarged data thefts, banks&#8217; accelerated digital transformation, and growing cloud use, centralized approaches to data security need to be revised. Any bank that forgoes using specialized and efficient encryption exposes itself to even the simplest ransomware and data exfiltration assaults.</p>
<p>This is because centralized identity and downstream access control invariably open the door to illicit activity. From the moment they obtain legitimate credentials, attackers, both internal and external, are granted complete, continuous access to all systems, databases, and files. The organization could then lose millions of dollars due to the exfiltration of sensitive information files.</p>
<p>In recent years, industry giants like Equifax, Yahoo, and the Office of Personnel Management, have had significant data breaches caused by stolen credentials. The use of compromised credentials is once again the most frequent cause of a data breach, costing an average of USD 4.5 million per event, according to the most recent IBM report.</p>
<p>Data encryption is irrelevant when centralized controls and checkbox identities are used. Furthermore, conventional encryption lacks protection against data exfiltration because it relies on centralized keys connected to the same user credentials that the attacker has stolen or copied.</p>
<p><strong>An additional layer of protection: Multifactor encryption</strong></p>
<p>Banks must abandon antiquated defence methods and alter their mitigation strategies as the security and regulatory environments change. To protect sensitive data, even when nefarious actors are present inside the perimeter, they require layered solutions that function when everything else fails.</p>
<p>It is crucial to have a sophisticated, decentralized data protection plan. Financial businesses can stop relying on identification as the cornerstone of all data security through the deployment of multifactor encryption and distributed key management (DKM), guaranteeing that sensitive data is protected during an exfiltration event. Criminals rapidly realize that there is no one point of weakness, making all their efforts futile.</p>
<p>What is the operation of multifactor encryption? AES-256 is used for data encryption at rest. To eliminate central points of attack, main points of failure, and risky reliance on identity and access management controls, a multifactor solution generates a unique key for each object before automatically fragmenting and distributing the critical shards across physical devices, such as laptops, mobile devices, tablets, or servers.</p>
<p>Due to multifactor encryption with DKM in place, hackers cannot decrypt files even after gaining access to a system. This is also true when banks move data to the cloud because unstructured data is still encrypted with several factors, making it impossible for anyone to access it, not even the cloud provider. As a result, only a small group of individuals have access to the critical shards on the approved physical devices.</p>
<p>The examination of data consumption and encryption status for compliance and business reporting requirements is also made possible by multifactor encryption. For example, banks can demonstrate their active compliance with authorities during audits and inspections, thanks to an irrefutable audit trail, assisting firms in meeting escalating standards. Administrators can also design unique notifications and warnings with detailed user activity logging, enabling data insights to be fed into current security monitoring programs.</p>
<p><strong>Overcoming the regulatory obstacle</strong></p>
<p>Account numbers must be unreadable when stored electronically by large non-financial institution originators, third-party service providers, and senders, according to the US-based National Clearing House Association (NACHA). This organization oversees electronic payment systems between nearly every bank and credit union account within the American jurisdiction. This represents a significant departure from obsolete identity and access management security methods. Financial companies would benefit significantly from technology like multifactor encryption, which eliminates the risk of file exfiltration while skillfully balancing user accessibility and data protection.</p>
<p>Banks must rely on something other than checkbox solutions and traditional centralized encryption when regulatory scrutiny and ransomware concerns are at an all-time high. Firms across the industry may secure themselves and demonstrate best-in-class regulatory compliance using distributed vital management and multifactor encryption, avoiding the shame of excessive fines and reputational embarrassment.</p>
<p><strong>New regulatory trends in data privacy</strong></p>
<p><strong>Uncertainty is a result of fragmented regulations</strong></p>
<p>Similar to the EU&#8217;s GDPR, China&#8217;s centralized Personal Information Privacy Law offers a comprehensive set of regulations regarding data protection. The US still has a uniform privacy framework, but as more states embrace laws like Virginia&#8217;s Consumer Data Protection Act, which will go into effect in 2023, calls for federal data protection legislation will grow.</p>
<p>Businesses may experience uncertainties due to the fragmented compliance requirements imposed by the US and international data privacy laws. In addition, the lack of a data transfer agreement between the EU and the US will increase doubts about the legitimacy of transatlantic data transfers.</p>
<p><strong>Compliance is only one aspect of privacy</strong></p>
<p>Privacy is undoubtedly a compliance component, but the organization&#8217;s culture must be changed for it to matter genuinely. Poorly controlled access within an organization frequently results in data privacy violations. Humans are the weakest link in the chain of privacy and security. Thus people and processes are just as important as technology. However, as remote working becomes more prevalent, controlling user access and protecting your essential data becomes more challenging.</p>
<p><strong>Organizations seeking ISO 27001 certifications</strong></p>
<p>Obtaining independent external certifications for their privacy program and practices is crucial for new entrants to confirm they are handling personal data correctly. These include ISO 27701, the EU&#8217;s binding corporate rules, and APEC&#8217;s cross-border privacy rules. In addition, these designations can benefit newcomers working on delicate, mission-critical operations, such as core-system modernization, as they can save time and effort during contract negotiations.</p>
<p>Thought Machine has applied for and been granted ISO 27001 certification and SOC 2 Type 2 accreditation, which outline requirements for putting in place information security management systems and show that internal controls and procedures are reliable and safe. Along with adhering to GDPR, the vendor complies with all pertinent data privacy legislation in other significant countries where it conducts business, including Singapore, Australia, and the US.</p>
<p><strong>Cookies</strong></p>
<p>Web cookies and Apple&#8217;s Identifier for Advertisers are two tracking techniques that have enabled personalization and targeting of advertisements at a level of complexity never before achieved. However, they have also raised the possibility of privacy abuses. Providers may no longer be able to rely on cookies to increase the effectiveness of customer outreach in various jurisdictions. Institutions that need to develop a plan to protect and expand their access to first-party data may need to increase their sales and marketing expenditures by 10 to 20% to achieve the same results.</p>
<p>In the meantime, the UK&#8217;s Department for Digital, Culture, Media, and SPORT is considering using cookies in local circumstances without user consent or where it would benefit the user.</p>
<p><strong>Storing data</strong></p>
<p>Financial institutions are finding it more difficult to transfer data among entities and across borders, to create target state data flow, and to build an insightful analysis for credit scoring due to global bank rules around data security, customer privacy, and ethical use of data, such as GDPR. Additionally, the use of data produced by various activities is governed by multiple legal restrictions. For instance, personal information from a profile on a social networking platform cannot be utilized for the same purposes as information from a financial transaction.</p>
<p>The post <a href="https://internationalfinance.com/magazine/banking-and-finance-magazine/data-protection-banks-must-rethink-strategies/">Data protection: Banks must rethink strategies</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/magazine/banking-and-finance-magazine/data-protection-banks-must-rethink-strategies/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AnyDesk domain impersonation row: Company says countermeasures being taken</title>
		<link>https://internationalfinance.com/technology/anydesk-domain-impersonation-row-company-says-countermeasures-being-taken/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=anydesk-domain-impersonation-row-company-says-countermeasures-being-taken</link>
					<comments>https://internationalfinance.com/technology/anydesk-domain-impersonation-row-company-says-countermeasures-being-taken/#respond</comments>
		
		<dc:creator><![CDATA[International Finance Business Desk]]></dc:creator>
		<pubDate>Thu, 19 Jan 2023 09:51:07 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AnyDesk]]></category>
		<category><![CDATA[Dropbox]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[macOS]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[Vidar]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=45868</guid>

					<description><![CDATA[<p>AnyDesk is used by millions of people across the globe</p>
<p>The post <a href="https://internationalfinance.com/technology/anydesk-domain-impersonation-row-company-says-countermeasures-being-taken/">AnyDesk domain impersonation row: Company says countermeasures being taken</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>After International Finance reported about the website named AnyDesk being impersonated in large numbers using more than 1,300 domains, the company responded to us stating that providing safe infrastructure to IT professionals is their top priority.</p>
<p>AnyDesk remarked, &#8220;Misusing our name to spread malware is unacceptable for AnyDesk. We are committed to doing everything in our power to help end fraud attempts. Our team is already actively taking countermeasures.&#8221;</p>
<p>&#8220;Millions of IT professionals worldwide depend on AnyDesk to securely connect to work computers and help with technical issues. Providing them with a safe infrastructure is our top priority,&#8221; it added further.</p>
<p>The impersonating domains are linking to a Dropbox folder that recently released the virus called ‘Vidar’ that steals information.</p>
<p>AnyDesk is used by millions of people across the globe. It is a well-liked remote desktop programme for Windows, Linux, and macOS, for safe remote connectivity or carrying out system administration.</p>
<p>AnyDesk is frequently misused in malware distribution because of the tool’s popularity. For instance, Cyble revealed in October 2022 that the developers of Mitsu Stealer were promoting their new malware through an AnyDesk phishing site.</p>
<p>The latest iteration of the AnyDesk was discovered by SEKOIA threat analyst crep1x, who tweeted a warning and provided the full list of the campaign’s malicious hostnames. These hostnames all lead to 185.149.120[.]9, the same IP address.</p>
<p>Typosquats for major programmes including AnyDesk, MSI Afterburner, 7-Zip, Blender, Dashlane, Slack, VLC, OBS, bitcoin trading apps, and other software are included in the list of hostnames. No matter the name, all of them point to the same AnyDesk clone website.</p>
<p>Most domains are still active, however, some have been reported and taken offline by registrars or are banned by antivirus software. After the malicious file was reported to the cloud storage service, even for the websites that are up, their Dropbox links are no longer functional. However, the malicious attacker can easily solve this by changing the download URL to another site.</p>
<p>It has been found out that the websites were disseminating a ZIP file with the name “AnyDeskDownload.zip” [VirusTotal] that claimed to be an AnyDesk software installer. But instead of AnyDesk zip files ‘Vidar stealer’, a malware that has been around since 2018 has been getting installed.</p>
<p>Once activated, the malware will take the victims’ browsing history, login information, previously-saved passwords, cryptocurrency wallet data, banking details, and other private information. This information may be used for other nefarious purposes or sold to other malicious attackers.</p>
<p>In one such recent incident, a man from India lost Rs 5 lakh while attempting to fix his TV display. He reportedly downloaded the AnyDesk app on his phone and within seconds his bank account was robbed of Rs 5 lakh.</p>
<p>The post <a href="https://internationalfinance.com/technology/anydesk-domain-impersonation-row-company-says-countermeasures-being-taken/">AnyDesk domain impersonation row: Company says countermeasures being taken</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/anydesk-domain-impersonation-row-company-says-countermeasures-being-taken/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Ransomware’s new target: US public sector</title>
		<link>https://internationalfinance.com/technology/ransomwares-new-target-us-public-sector/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ransomwares-new-target-us-public-sector</link>
					<comments>https://internationalfinance.com/technology/ransomwares-new-target-us-public-sector/#respond</comments>
		
		<dc:creator><![CDATA[International Finance Business Desk]]></dc:creator>
		<pubDate>Mon, 09 Jan 2023 08:08:41 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[LockBit]]></category>
		<category><![CDATA[public sector]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=45631</guid>

					<description><![CDATA[<p>Ransomware attackers usually don't go after people in the medical field</p>
<p>The post <a href="https://internationalfinance.com/technology/ransomwares-new-target-us-public-sector/">Ransomware’s new target: US public sector</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Ransomware attacks impacted more than 200 public sector organizations in the United States in 2022.</p>
<p>After searching through publicly accessible reports, disclosure statements, dark web leaks, and third-party intelligence, New Zealand-based Emsisoft, known for its anti-virus software solutions, alleged that businesses in the government, education, and healthcare sectors were most impacted by threat actors.</p>
<p>Ransomware attackers usually don&#8217;t go after people in the medical field, because a potentially fatal outcome would probably mean the end of all their activities and freedom.</p>
<p>The LockBit ransomware creators dissociated themselves from an affiliate after the latter launched a data theft attack against a children’s hospital. LockBit also stated that the act was against their guidelines. It also offered the decryptor, while expressing regret for the mishap.</p>
<p>In roughly half of the events that were found, threat actors stole personal information.</p>
<h4>Concealing the events</h4>
<p>In the ransomware attacks that took place in 2022, 105 counties, 44 universities and colleges, 45 school districts, and 24 healthcare organizations became the targets.</p>
<p>Despite thorough investigation, Emsisoft claimed that the figures were probably inconclusive because not all businesses are keen to report cybersecurity problems. Public organizations are more likely than private businesses to disclose the specifics of such instances, yet it&#8217;s still possible that some incidents went unreported.</p>
<p>Emsisoft said in its research report, &#8220;the truth is that nobody can say with certainty whether the number of attacks is flat, heading upward or downward.”</p>
<p>One example of an incident that may have been taking place at the same time that Emsisoft was preparing its report is the attack that reportedly happened at the CentraState Medical Centre on December 30, 2022. </p>
<p>It&#8217;s possible that further events were covered up. During that time period, the organisation said that &#8220;due to a cybersecurity issue,&#8221; it would no longer be accepting new patients.</p>
<p>The post <a href="https://internationalfinance.com/technology/ransomwares-new-target-us-public-sector/">Ransomware’s new target: US public sector</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/ransomwares-new-target-us-public-sector/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>After Optus &#038; MyDeal, hackers target Medibank</title>
		<link>https://internationalfinance.com/insurance/after-optus-mydeal-hackers-target-medibank/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=after-optus-mydeal-hackers-target-medibank</link>
					<comments>https://internationalfinance.com/insurance/after-optus-mydeal-hackers-target-medibank/#respond</comments>
		
		<dc:creator><![CDATA[International Finance Business Desk]]></dc:creator>
		<pubDate>Tue, 15 Nov 2022 03:43:36 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Insurance]]></category>
		<category><![CDATA[australia]]></category>
		<category><![CDATA[Cyberattack]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Medibank]]></category>
		<category><![CDATA[MyDeal]]></category>
		<category><![CDATA[Optus]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=45329</guid>

					<description><![CDATA[<p>Medibank said that the breach affected some significant amounts of health claims’ data</p>
<p>The post <a href="https://internationalfinance.com/insurance/after-optus-mydeal-hackers-target-medibank/">After Optus &#038; MyDeal, hackers target Medibank</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Australia’s largest health insurer Medibank has faced a cyberattack, compromising the personal data of all its four million customers.</p>
<p>The revelation from Medibank comes at a time when the Anthony Albanese-headed government introduces legislation increasing penalties against companies erring on cybersecurity and data protection fronts.</p>
<p>Medibank said that the breach affected some “significant amounts of health claims’ data”. The incident also resulted in the halting of trading in the company’s shares. As per the police complaint, the thief has demanded a ransom from the company in exchange for the data related to customers’ diagnoses and treatments record.</p>
<p>As per the Australian government’s latest cybersecurity regulation reforms, the penalties for serious Privacy Act breaches will increase from 2.2 million to 50 million Australian dollars (USD 1.4m to USD 32m). The erring businesses can also be fined up to 30% of their revenues in serious cases.</p>
<p>The government intervention comes after a series of data thefts targeted toward high-profile businesses within the country.</p>
<p>Data of nearly 10 million current and former customers of Optus were stolen recently, affecting over one-third of Australia’s 26 million population.</p>
<p>In another such incident, online retail company MyDeal lost the data of its 2.2 million customers.</p>
<p>Medibank has also said that it lacks cyber insurance and this cyberattack will reduce the health insurer’s earnings by some 25-35 million Australian dollars by 2023. After the incident, its shares went down by more than 14%.</p>
<p>The post <a href="https://internationalfinance.com/insurance/after-optus-mydeal-hackers-target-medibank/">After Optus &#038; MyDeal, hackers target Medibank</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/insurance/after-optus-mydeal-hackers-target-medibank/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
