Google Search

Showing posts with label stolen. Show all posts
Showing posts with label stolen. Show all posts

Saturday, November 23, 2013

Opera breached, has code cert stolen, possibly spreads malware - advice on what to do

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Malware

Norwegian-based Opera, makers of one of the most popular browsers outside the Big Four, has announced a scary-sounding network intrusion.

The official story is still somewhat unclear.

But here are the relevant paragraphs from Opera's official mea culpa document:

On June 19th we uncovered, halted and contained a targeted attack on our internal network infrastructure. Our systems have been cleaned and there is no evidence of any user data being compromised. We are working with the relevant authorities to investigate its source and any potential further extent. We will let you know if there are any developments.

The current evidence suggests a limited impact. The attackers were able to obtain at least one old and expired Opera code signing certificate, which they have used to sign some malware. This has allowed them to distribute malicious software which incorrectly appears to have been published by Opera Software, or appears to be the Opera browser.

It is possible that a few thousand Windows users, who were using Opera between 01.00 and 01.36 UTC on June 19th, may automatically have received and installed the malicious software. To be on the safe side, we will roll out a new version of Opera which will use a new code signing certificate.

The title of the article is Security breach stopped, but that doesn't sound quite right to me.

The conclusions I reached, based on the announcement above, were:

The network was breached.A code-signing key was stolen.Malware has been signed with it and circulated.At least one infected file was posted on an Opera server.That file may have been downloaded and installed by Opera itself.Cleanup and remediation has now been done at Opera.

That sounds a bit more like Security breach not stopped to me.

How else could a signed-and-infected file have been automatically downloaded by an already-installed instance of Opera?

Anyway, wouldn't Opera's auto-update have failed or produced a warning due to the expired certificate?

Until Opera has worked out the answer to these questions, Opera users probably want to assume the worst.

The good news is that the malware involved is widely detected by anti-virus tools, and the period of possible exposure via Opera itself was at most 36 minutes.

? According to Opera, Sophos products block the offending file as Mal/Zbot-FG.

So, if you are an Opera for Windows user:

Download a fresh copy of the latest version (since the buggy download appears to be a thing of the past).Make sure your anti-virus is up to date.If you can spare the time, do an on-demand ("scan now") check of your computer.

If we find out more detail about whether malware was distributed by existing Opera installations or not, we'll let you know.

Sophos can help with an emergency cleanup of your Windows PC.

You can use the standalone Sophos Virus Removal Tool to detect and clean malware. This tool can be used alongside your existing anti-virus. (Free download, no registration required.)

You can download a fully-functioning evaluation version of Sophos EndUser Protection for Windows and use it for malware detection, prevention and clean-up. (Free download, registration required.)

Or you can use the Sophos Bootable Anti-Virus utility. SBAV requires you to download a Windows program to create and then use a bootable CD or USB key, so some technical expertise is recommended. The advantage of SBAV is that it is immune to malware already on your PC, as it runs from a self-contained Linux-based operating system. (Free download, no registration required.)

Follow @duckblog


View the original article here

Saturday, November 9, 2013

Stolen webcam video listed at $1 per female victim, $1 per 100 male victims

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Red webcam. Image courtesy of ShutterstockDo only the truly paranoid stick bandages over their webcams so they don't get surreptitiously recorded?

According to a BBC Radio 5 live investigation, the rationale for doing so might be strong enough to vindicate the paranoid, given input from webcam hackers who say that such hacking is simple and that black markets for selling access to compromised computers are "thriving."

One webcam hacker who spoke to the BBC said "loads of people" are hacking webcams because it's so simple to do.

In fact, while he was being interviewed, he was on a forum with tutorials on how to hack webcams. It had about 428,000 posts, he said.

Hackers gain access to their victims' computers with remote-access Trojans (RATs) - malware that gives an intruder administrative control over its targeted computers, including, in this case, the ability to remotely control webcams.

It's an invisibly-installed malware program spread via email attachment or by tricking victims into visiting a booby-trapped site.

The BBC interviewed one victim who thinks she was victimized by webcam hacking.

Rachel Hyndman said that she noticed that her laptop camera had switched itself on while she was watching a DVD in the bath.

She was, of course, horrified:

"I was sitting in the bath, trying to relax, and suddenly someone potentially has access to me in this incredibly private moment and it's horrifying.

"To have it happen to you without your consent is horribly violating."

For the investigation, a BBC producer posed online as a computer security enthusiast in order to contact several webcam hackers from around the world - at least one of whom has since been arrested.

The investigation uncovered websites where hackers share pictures and videos of their victims aka "slaves", pages where they swap photos of "ugly slaves", sites where men swap images of female "slaves", and evidence of at least one black market where you can buy access to a woman's webcam for $1 (64p).

The same amount will get you access to 100 computers owned by men.

How common is this type of hack?

Spy on computer. Image courtesy of ShutterstockGraham Cluley told the BBC that webcam hacking is quite real.

That's evidenced by multiple arrests of perpetrators - including those looking to blackmail victims.

But while it is real, GC says, webcam hacking is rare enough that it's not quite worth freaking out over in the broader scheme of virusy things:

"There are 100,000 new virus threats created every day and it's really important to keep your security up to date because anti-virus software should protect you against most of these threats."

Still, you don't want to be one of the (albeit rare) victims.

A list of tips on avoiding getting webcam-hacked, some of which are adapted from a list provided by ChildNet International and the UK's Child Exploitation and Online Protection Centre:

Keep your antivirus and firewall protection up to date.Patch applications in a timely fashion. Be wary of email and social networking messages from strangers, and refrain from clicking on attachments or links in any such messages.Don't take your webcam into intimate places, even if an error message tells you your computer needs hot steam to clean its sensor (true story!). When not in use, cover your webcam lens (bandages work well) or point it at the wall. Think twice before stripping for a conversation - remember, whomever you're talking to can record and share the video. Teach young people how to behave safely online to avoid them becoming victims.Encourage children who've been victimized via webcam to report it to a trusted adult. If you've been victimized yourself, report it to the authorities.

Stay safe, and keep an eye on that webcam light.

Follow @LisaVaas
Follow @NakedSecurity

Image of webcam and computer spying courtesy of Shutterstock.


View the original article here

Sunday, December 30, 2012

NASA suffers major data breach over stolen laptop that wasn't encrypted

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

NASA image, courtesy of ShutterstockIn March 2011, algorithms used to command and control the International Space Station were exposed.

In March 2012, it was the personally identifiable information (PII) of 2,300 employees and students.

In another incident, it was sensitive data on NASA's Constellation and Orion programs.

This time around, on 31 October, it was PII on an unspecified, but large, number of NASA employees and contractors.

All these instances involved the theft of unencrypted laptops from NASA. With this most recent theft, the space agency is finally doing something about these incidents, beyond the limited scope of its previous remediation efforts.

NASA announced on Tuesday that, effective immediately, the agency is jumping on the encryption fast track.

By 21 December, no NASA-issued laptops containing sensitive information will be allowed to leave a NASA facility unless whole disk encryption software is enabled or sensitive files are individually encrypted.

In a message sent agency-wide to all employees, Associate Deputy Administrator Richard J Keegan Jr. informed NASA staff that somebody or somebodies broke into a locked vehicle and stole official NASA documents on 31 October.

The laptop contained records with PII for a large number of employees, contractors and others, Keegan said.

He gave no explanation as to why the agency waited weeks to inform employees.

Rocket. Image from ShutterstockThe computer was protected only with a password and lacked whole disk encryption, which left the information accessible to thieves.

NASA is taking standard breach precautions, including contracting a data breach specialist, ID Experts, to notify those whose PII was compromised.

The agency is offering free credit and identity monitoring, recovery services in cases of identity compromise, an insurance reimbursement policy, educational materials, access to fraud resolution representatives, and a call center and website.

It's recommending that anybody affected activate these services ASAP.

NASA is also recommending that those affected be wary of suspicious phone calls, emails, and other communications from individuals claiming to be from NASA or other official sources that ask for personal information or verification of it.

NASA and ID Experts won't be contacting employees to ask for or to confirm personal information, Keegan said, so any such communication is sure to be bogus.

NASA's embrace of full-disk encryption has up until now been less than comprehensive.

After the March 2012 stolen laptop and PII exposure, the agency pledged:

...a full review of current IT security policies and practices with the goal of making changes to prevent a similar incident.

At that time, NASA promised that all laptop computers at NASA Kennedy Space Center, not just ones with PII or sensitive data, would have their hard drives encrypted by September 2012.

In retrospect, it would have been smarter to extend that initiative to all hard drives, throughout the entire agency, not just those at Kennedy.

Secure laptop, courtesy of ShutterstockBut that is, apparently, a lesson that NASA has now taken to heart and will implement with all due haste.

The new full-disk encryption applies to all laptops containing PII, International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) data, procurement and human resources information, and other sensitive but unclassified (SBU) data.

Keegan said that NASA's Administrator and CIO have laid out the marching orders for agency CIOs to complete whole disk encryption of the maximum possible number of laptops by 21 November.

NASA plans to complete the effort by 21 December, after which no unencrypted laptop, regardless of whether it contains PII, will be allowed to leave its facilities.

In the meantime, employees working remotely or traveling have been told to use loaner laptops if their NASA-issued laptop contains unencrypted sensitive information.

On Wednesday, a security vendor (or then again, more likely, many security vendors, but only one wrote to me directly) sent out a statement on the NASA breach that said,

"OK, whole-disk encryption might be good, but is it good enough?"

It's a question worth asking. As he said, data is in fact moving to and from laptops, in emails, files, and as data traveling to and from apps and servers.

Fortunately, NASA has also declared that storage of sensitive information on smart phones or other mobile devices is now taboo.

Let's hope they also have an eye toward all the places that data propagates, whether it's in emailed attachments, on mail servers that might be in the cloud, on smartphone mail apps, on backup tapes, or in any internal or outsourced operations.

Follow @LisaVaas
Follow @NakedSecurity

NASA image, courtesy of Songquan Deng / Shutterstock.com. Secure laptop and rocket images courtesy of Shutterstock


View the original article here

Monday, December 24, 2012

Facebook shuts down Albania Pirate Group, after stolen passwords shared

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook and APGIt's easy to understand how hacking groups, involved in undercover cybercrime, might want to keep their activities hidden from the-powers-that-be and law enforcement agencies, and conduct their crimes in secrecy.

Which makes it all the more surprising when you stumble across a group apparently engaged in stealing and sharing login passwords for third party systems, doing so not just on a public-facing website, but on a page hosted by the world's biggest social network.

A reader of Naked Security, who works at a Yorkshire-based security company, contacted us last week to tell us about a particular Facebook page they had stumbled across belonging to the Albania Pirate Group.

Albania Pirate Group on Facebook

On its Facebook page, 600+ fans and members of the Albania Pirate Group were sharing RDP (Windows Remote Desktop) logins, giving hackers unauthorised access to computer systems, and what appeared to be compromised banking details.

The potentially sensitive information was free for anyone to view, even if you hadn't "Liked" the page.

Curiously, the Albania Pirate Group has a similar logo to the Kosova Hacker's Group, who breached servers belonging to the US National Weather Service last month.

Albania Pirate Group on Facebook

Sophos contacted Facebook, and within the hour the social network's security team had closed down the page.

Remember that pages and groups on Facebook are not pre-vetted, and anyone can create a page with ease and use it for illegal purposes. If you stumble across a Facebook page that you believe is involved in law-breaking or breaches the terms and conditions of the site, you should report it to Facebook.

Our thanks go to the Facebook security team for shutting down the page so promptly.

Stay informed about the latest security and privacy issues related to Facebook. Join the Naked Security page on Facebook, where over 190,000 people regularly share information on threats and discuss the latest security news.

Follow @gcluley

View the original article here

Thursday, August 2, 2012

Yahoo Voices hacked, nearly half a million emails and passwords stolen

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Yahoo logoYesterday, we reported on the Formspring website hack. Today, it's Yahoo Voices that has been compromised.

Yahoo Voices, which defines itself as "where your expertise and perspectives take center stage!", allows Yahoo users to post their own articles, videos and slideshows online.

This morning, hacker group D33DS Company, published the 453,491 email addresses and passwords online in plain text, in a document marked "Owned and Exposed".

Owned and exposed

The hackers say they used a "Union-based SQL Injection" to steal the data and posted the information as a "wake-up call"

We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call, and not as a threat.

But even if this hacker group themselves aren't planning to use the information for ill-gotten gains, the data is available for anyone to access.

The only silver lining on the cloud is that the website hosting the passwords is temperamental, and people are experiencing difficulties accessing the information. But maybe the access problems are being caused by so many people trying to access the stolen passwords at once?

D33Ds email addresses

Unfortunately, the list of compromised websites just seems to keep growing. In a little over a month, we've reported on breaches of Formspring, Last.fm, LinkedIn and eHarmony.

If you use Yahoo Voices, you should probably change your password now.

Don't forget to make sure that your password is unique, hard to guess, and that you use a different password on every website you use. If you use the same password in multiple places you are just asking for trouble.

At the time of writing, there is no official word from Yahoo regarding the security breach.

There are certainly questions which need to be answered - such as how were the hackers able to gain access to the information, and what measures was the site taking to ensure that even if its databases were breached, the passwords would not be easy to convert into plain text.

If your company runs a website which stores users' information, don't feel too smug about Yahoo's misfortune. Are you taking enough care of your visitors' credentials and ensuring that they are properly secured?

Follow @NakedSecurity

View the original article here

Wednesday, June 6, 2012

Serco reports 123,000 US government employees' personal information stolen

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Serco logoThe Guardian has called Serco "probably the biggest company you have never heard of." It's on the FTSE 100 (Big!), has 100,000 employees and operates everything from railways in the UK and Australia to driver licensing in Ontario, Canada to retirement accounts for US government employees, members of the armed forces and US Postal Service workers.

Perhaps taking advantage of the holiday weekend in the United States, Serco announced this morning that hackers had compromised systems at its Thrift Savings Plan (TSP) operation.

After extensive forensic investigation it was determined that 43,000 members' names, addresses and Social Security Numbers had been accessed by the intruders, and the Social Security Numbers of another 80,000 may have been involved.

Consistent with the findings presented in this year's Verizon Data Breach Incident Report, Serco did not even realize they were compromised until they were contacted by the FBI in April 2012.

Individuals whose information may have been accessed will receive a letter from the Federal Retirement Thrift Investment Board (FRTIB) in the coming days.

Serco claims that there is no evidence of any financial fraud or identity theft related to the incident, but that does beg the question... How would they know?

Poor Credit Rating image courtesy of ShutterstockThey haven't notified the victims, so if these poor folks had noticed any funny business on their credit report, why would they report it to Serco or even suspect it is related to the company?

As I mentioned in the article about the data breach in Utah, Social Security Numbers aren't disposable. They are a permanent identifying number that can be used to wield enormous power over victims' lives.

The other thing that bothers me about this case is that the press release from Serco makes no attempt at apologizing or admitting that it has not lived up to its responsibilities.

"It was crazy, sophisticated, relentless hackers. It happens all the time. Nothing we could do about it. They stole your personally identifiable information, but we don't think they wanted it."

Shame on you, Serco. If it weren't for the FBI having contacted you, data would still be leaking off of your network. A little data encryption goes a long way toward avoiding this type of situation.

Let us hope Serco is correct and the stolen information will not be used for nefarious purposes.

Victims of this incident should still be on the lookout for any strange activity on their credit reports and may wish to put a "security freeze" on their credit reports with the major agencies.

Update: Further information has been published that shows the original intrusion into Serco's system occurred in July 2011. Information that was accessed has been available to criminals for nearly a year before Serco was notified by the FBI.

Follow @chetwisniewski

Poor credit rating image courtesy of Shutterstock.


View the original article here

Sunday, June 3, 2012

Apple's iCloud syncs stolen iPhone photos to nab thief

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Creative Commons photo of Disney's Wonder cruise ship courtesy of Justin ChampionKaty McCaffrey *had* an iPhone. Until it was stolen aboard the Disney cruise ship Wonder on her April vacation. What to do? As is frequently the case these days, the cloud holds the answer.

After returning home sans iPhone, McCaffrey discovered that photos were showing up in her Apple iCloud account from her missing device.

Taking advantage of the openness of social media and the ability for average folks to get the word out McCaffrey decided to post the photos to Facebook in an attempt to identify the thief.

Titled "Stolen iPhone Adventures" McCaffrey posted humorous captions on the photos allegedly being posted by a crew member named Nelson. The media caught wind of the story and tens of thousands flocked to the page bringing it to the attention of Disney.

It is unclear whether Nelson was in fact the thief, or if he simply purchased the stolen phone from someone else on board the ship. It isn't looking good for him at the moment though.

A Disney spokesperson told USA Today that they had recovered the phone and have placed the crew member on administrative leave and restricted him from guest areas on the ship.

The spokesperson also stated "We have a zero-tolerance policy for this type of behavior, We are taking aggressive action."

This story does raise some legitimate concerns about smartphone safety however. If your phone is stolen, you should immediately report it stolen and cancel the service to prevent the thief from racking up a large cellular phone bill.

Find my iPhoneMcCaffrey clearly was using Apple's iCloud service, so why did she not take advantage of the remote lock/remote wipe service that is part of iCloud?

Playing amateur detective rarely works out the way it appears to have this time and even without the photos the "Find my iPhone" app would likely have allowed law enforcement to locate the thief.

It would also appear that McCaffrey did not bother to secure her phone with a password. Last summer 70% of smartphone users admitted to not using a passcode in a Sophos survey.

The good news? McCaffrey will get her iPhone back and the thief will be investigated for the crime.

The lesson? Don't take chances like McCaffrey. While this story may be entertaining, you are far better off to secure your device, ensure your data is erased if it's stolen and take advantage of our free mobile security toolkit.

http://twitter.com/chetwisniewski

Creative Commons photo of Disney's Wonder cruise ship courtesy of Justin Champion.


View the original article here

Friday, April 6, 2012

MasterCard and Visa payment processor compromised, up to 10 million cards stolen

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Card Terminal photo courtesy of ShutterstockBrian Krebs is reporting that MasterCard and Visa are warning member-banks of a payment processor breach that may impact more than 10,000,000 credit cards.

It is important to note that MasterCard and Visa's own networks were not involved in the attack, it appears to be related to payment processor Global Payments.

Reuters is reporting that Global Payments stock was suspended for trading after falling more than 9% on the Nasdaq stock exchange.

Krebs reported that one of the financial institutions he spoke with had to cancel 56,455 credit cards, of which fraud was detected on 876, or 1.5%.

There is much speculation about the source of the breach as many are reporting that the majority of the fraud is occurring in the greater New York City area, yet cards are being cancelled around the country.

What is a payment processor? Payment processors provide merchants (stores) with access to payment brokering networks like MasterCard, Visa, American Express and Discover. The terminal that processes your card sends the details of the transaction to the payment processor to facilitate the purchase.

It is being reported that the attackers got "full Track 1 and Track 2 data". This is very bad as it would allow for the attackers to fully produce cards including the CVV/CCV code you often need to enter for online transactions.

Strangely, law enforcement contacts told Krebs they believe the breach is related to a Dominican gang in New York and primarily targeted corporate credit and debit cards.

Card statement image courtesy of ShutterstockFortunately consumers don't need to worry too much. Card issuing banks (Bank of America, Chase, etc.) are cancelling cards that are involved in the theft and card holders will not be held responsible for any fraudulent activity.

I wouldn't cancel my card or ask for a new one, but it would certainly be prudent to keep a close eye on your statements to be sure nothing suspicious shows up.

As we find out more details on how this heist came about, we will post information here. From the sound of it the card information sounds like it may not have been encrypted or they wouldn't need to cancel so many cards.

Follow @chetwisniewski

Credit card processing terminal image and card statement image courtesy of Shutterstock.


View the original article here

Monday, March 5, 2012

Hackers claim to have stolen Springfield, Mo., residents' info - STLtoday.com

 SPRINGFIELD, Mo. • Springfield officials are offering 2,100 people free identity theft protection for a year after an internationally known group claimed it hacked into the city's website and stole residents' personal information.

 KYTV reports the city's website was compromised Feb. 17, and a day later a group known as Anonymous tweeted that it had hacked Missouri government websites.

 The group says it will not release information from private citizens, such as Social Security numbers, birth dates and cell phone numbers. But Springfield City Manager Greg Burris says the city is offering one year of ID theft protection insurance to affected residents, just in case.

 Burris says the protection will cost a little less than $50,000 to the city, which also is reviewing security measures to prevent future hacking.


View the original article here

Thursday, June 23, 2011

Sega says 1.29 mln customers' data stolen by hackers

TOKYO (AFP) – Hackers have stolen the personal data of some 1.29 million customers of the Japanese game maker Sega, the company said on Sunday, in a theft via a website of its European unit.

The Sega Pass website, operated by London-based Sega Europe, did not contain credit card information, the Japanese firm said.

But names, dates of birth, email addresses and encrypted passwords were stolen by intruders to the site, Sega said in a Japanese-language statement, adding the theft had been confirmed on Friday.

"We sincerely apologise for troubles this incident has caused to our customers," it said.

The service, which has been suspended, was mainly to announce new product information to registered customers, Sega said.

"An investigation has been launched to find the cause and channels used for the leakage," it said.

No other websites managed by Sega have come under attack, it said.

Sega pledged to strengthen its network security and to release information about the case as it becomes available.

The incident follows a series of hacker attacks on Japanese electronics and entertainment giant Sony in April which forced it suspend online services for weeks.

Sony suffered one of the biggest data breaches since the advent of the Internet, with personal data from 100 million accounts compromised.

The attacks forced the company to halt its Qriocity online music and video distribution services and PlayStation Network online gaming for more than a month.

Sony also suffered attacks on websites including in Greece, Thailand and Indonesia, and on the Canadian site of mobile phone company Sony Ericsson.

This month, a group of hackers known as Lulz Security claimed to have attacked the Sony Computer Entertainment Developer Network and stolen technical information, after stealing customer data from SonyPictures.com.

Websites of major media, game makers, banks and the US government have been constant targets of international hackers.

Nintendo, Citigroup, the CIA and the Malaysian government have recently come under hacker attacks.

Sega, known for "Sonic the Hedgehog", produces games for a range of consoles, including the PlayStation 3, Nintendo DS, Microsoft's Xbox 360 and Nintendo's motion-control Wii.

It became a household name with popular arcade games such as "UFO Catchers" and in 1998 won a fan base with its Dreamcast machine. But it stopped producing the Dreamcast in 2001 under fierce competition from Sony and Nintendo.

The company has since focused on arcade machines and software. It saw a new lease on life after merging in 2004 with Sammy Corp., Japan's top maker of pinball slot machines.


View the original article here