You are on page 1of 1

NEWS

...Continued from front page big increase in targeting of the WHO, This is the second breach the firm
engaged in the virus response” and and other cyber security incidents. There has suffered in less than 18 months.
added that it has issued a ‘Purple Notice’ are no hard numbers, but such com- In November 2018 it admitted that
alerting police in all its 194 member promise attempts against us and the use its Starwood Hotels guest reserva-
countries to the heightened ransomware of impersonations to target others have tion database was compromised, with
threat. more than doubled.” unauthorised access going back as far
“As hospitals and medical organisa- The pandemic certainly hasn’t blunted as 2014. That affected 383 million
tions around the world are working non- the ability of China-based hackers to customers.
stop to preserve the wellbeing of indi- carry out espionage attacks. Security firm The ramifications of that earlier
viduals stricken with the coronavirus, FireEye said it has seen a spike in activ- breach continue. The UK’s Information
they have become targets for ruthless ity by the state-backed group dubbed Commissioner’s Office (ICO) said it
cyber criminals who are looking to make APT41, which has been targeting more intended to fine the company £99m.
a profit at the expense of sick patients,” than 75 organisations, including manu- The imposition of that penalty was
said Jürgen Stock, the agency’s secretary facturers, media companies, healthcare delayed in January for three months
general. “Locking hospitals out of their firms and non-profits. FireEye’s report over legal discussions. And now, due
critical systems will not only delay the said it was “one of the broadest cam- to Covid-19, the fine has been further
swift medical response required dur- paigns by a Chinese cyber espionage delayed to June 1.
ing these unprecedented times, it could actor we have observed in recent years.” British Airways, which is also facing a
directly lead to deaths.” The APT41 group was particularly data breach fine from the ICO, has had
Meanwhile, Microsoft has been con- focused on exploiting recently disclosed its penalty of £183m similarly pushed
tacting dozens of hospitals to warn them vulnerabilities in Cisco, Citrix and Zoho back – to May1.
that they may have vulnerable VPN products to attempt penetration of net-
devices and gateways on their networks. works in the US, Canada, UK, Mexico,
There have been recent examples of the Saudi Arabia, Singapore and more
E-commerce fraud to
REvil (aka Sodinokibi) group targeting than a dozen other countries. There’s top $25bn
Pulse VPN devices to infect targets with more information here: https://bit.
ransomware – the best-known example
being the Travelex breach. And the
ly/34hb0zG.
F raud losses from online payments
will jump by 52% in the next
DoppelPaymer and Ragnarok groups Marriott breached few years to exceed $25bn a year
have been exploiting the Citrix ADC again by 2024, according to a report from
(NetScaler) CVE-2019-1978 vulnerabil- Juniper Research.

M
ity to compromise networks. arriott International has ‘Online Payment Fraud: Emerging
“We identified several dozen hospi- revealed that it suffered a Threats, Segment Analysis & Market
tals with vulnerable gateway and VPN data breach earlier this year that Forecasts 2020-2024’ suggests that
appliances in their infrastructure,” said may affect around 5.2 million stronger security – in large part due to
Microsoft in a blog post. “To help these guests with Marriott Bonvoy loyalty the EMV initiative – for card-present
hospitals, many already inundated with scheme accounts. payments is driving fraudsters online.
patients, we sent out a first-of-its-kind “At the end of February 2020, we That, combined with the ever-growing
targeted notification with important noticed that an unexpected amount popularity of online shopping, is going
information about the vulnerabilities, of guest information may have been to result in bigger fraud losses for
how attackers can take advantage of accessed using the login credentials of two e-commerce operations, especially in
them, and a strong recommendation to employees at a franchise property,” the China, which will account for 42% of
apply security updates.” company said in a statement. “We believe e-commerce fraud by 2024.
The World Health Organisation this activity started in mid-January 2020. Juniper’s predictions take into
(WHO) has come under attack by Upon discovery, we immediately ensured account the much-delayed Secure
sophisticated hackers – possibly mem- the login credentials were disabled, began Customer Authentication (SCA) initia-
bers of the DarkHotel group, which an investigation, implemented heightened tive in Europe. Part of the EU’s PSD2
has been engaged in cyber espionage monitoring and arranged resources to banking regulations, SCA is now sched-
operations since at least 2007. A domain inform and assist guests.” uled to come into effect at the end of
name was registered that closely mim- The company also said that there is this year in EU countries and March
icked that used by the WHO’s internal no “reason to believe that the infor- 2021 in the UK. The regulations will
mail system. mation involved included Marriott require that certain types of transac-
Flavio Aggio, CISO at the WHO, Bonvoy account passwords or PINs, tions employ some form of two-factor
told Reuters that the attack was unsuc- payment card information, passport authorisation (2FA).
cessful and the identity of the hackers information, national IDs, or driver’s The report is available here:
unknown. He added: “There has been a licence numbers.” https://bit.ly/2RgxNX1.

3
April 2020 Computer Fraud & Security

You might also like