information security

Hackers demand ransom to open disabled door locks

February 12th, 2017

Austria’s four-star, 111-year-old Romantik Seehotel Jagerwirt mentioned that its internal systems were recently breached. Hackers disabled both the hotel’s electronic door locks and the reservation system. The attack against the facility means that the new keys couldn’t be created and also reservations couldn’t be checked or confirmed.

Hotel has to pay 2 Bitcoins (almost $2,000) to get control of the systems back to the hotel.

“The house was totally booked with 180 guests, we had no other choice,” hotel managing director Christoph Brandstaetter told The Local. “Neither police nor insurance help you in this case.”

This was the third cyber attack for the hotel, Brandstaetter said.  It also faced fourth attack as new computers were placed along with new security standards.

“The restoration of our system after the first attack in summer has cost us several thousand Euros,” Brandstaetter said. “We did not get any money from the insurance so far because none of those to blame could be found.”

“We are planning at the next room refurbishment for old-fashioned door locks with real keys,” he said. “Just like 111 years ago at the time of our great-grandfathers.”

As per the recent research survey of nearly 1,000 enterprise IT buyers, half believe that the security is crucial.  Still many are moving towards IOT. Around 90 percent of enterprises plan to increase IoT spending. The research showed that the IoT-related spending will increase by 33 percent.

Other finding include:

Fifty four percent said a lack of trained IoT staff is not an issue for their organizations.

Forty six percent said they’re having difficulty filling IoT-related positions.

“When it comes to IoT adoption, pragmatism rules,” 451 Research director Laura DiDio said in a statement. “The survey data indicates enterprises currently use IoT for practical technology purposes that have an immediate and tangible impact on daily operational business efficiencies, economies of scale and increasing the revenue stream.”

___________________________________________________________________________________

Alertsec helps you comply with HIPAA, PCI and SOX requirements.

Funding for bug bounty vendor

February 9th, 2017

As per the recent news, one can make money in the rewarding business of security researchers for finding security vulnerabilities. HackerOne published that they have raised a $40M Series C round of funding. Total funding received till date for the San Francisco based company is $74 Million.

Dragoneer Investment Group led new round of funding. It will be used to help HackerOne grow its business.

“HackerOne is at the forefront of the burgeoning bug bounty movement,” Marc Stad, Founder and Managing Partner of Dragoneer Investment Group, said in a statement. “It is borderline silly for a company not to utilize a bug bounty platform given the immediate reduction in security vulnerabilities and the relatively low price point compared to other security options.”

Rice, co-founder and CTO of HackerOne in the video interview mentioned the statistics of business growth. Also, discussed the bugs found by HackerOne’s community of researchers.

Hacking the pentagon program was one of the major successes of HackerOne. The results were positive. It has 1,400 security researchers participating in the program. It also discovered 138 serious vulnerabilities which were fixed quickly. Also, the U.S. Department of Defense also got involved in the program.

HackerOne faces competition from bug bounty vendor Bugcrowd. The rival has raised $24 million in funding to date which includes $15 million Series B round.

“When I started the company in 2013, I spent most of my time explaining what a bug bounty was to people,”Bugcrowd founder and CEO Casey Ellis said. “I don’t have to do that anymore.”

“How we do things today is we prove a concept manually first, apply human intelligence to the problem set and then take the repeatable learnings and codify that,” Ellis said.

The market of buy bounty is competitive but there is demand. Rice also mentioned that more bugs have been found by third party bug bounty companies as compared to vendors.

_____________________________________________________________________________________________________

Alertsec’s cloud-based information security service provides an easy and convenient way to protect information on your organization’s laptops and computers.

Stolen laptop results in data breach

February 2nd, 2017

Children’s Hospital Los Angeles (CHLA) and Children’s Hospital Los Angeles Medical Group (CHLAMG) recently suffered data breach when one of its unencrypted laptop was stolen. The laptop contained personal health information of 3,600 patients.

According to the reports, laptop was taken away by thief from the locked vehicle of a CHLAMG physician at CHLA. Investigation conducted by the facility found that the laptop was encrypted to up-to-date institutional standards along with password-protection. But later review mentioned the possibility of unencrypted status of laptop.

Facility is notifying patients whose information was stored on the laptop. Affected information includes names, addresses, medical record numbers, and certain clinical information.

“Following the notification regarding the burglary, an investigation took place to determine whether patient health information existed on the laptop,” CHLA spokesman Lorenzo Benet said in a statement. “Based on the investigation, the laptop has not been used to access the internet. From that information, we believe that all data may have been erased from the device without any patient data being accessed.”

Also, a protocol is created to erase data from the laptop when it logs onto the internet next time. Notification letters sent by facility will instruct individuals to review health insurance documents for evidence of misuse or identify theft.

Facility also asked patients to review their Explanation of Benefits statements in case of any unusual behavior . Also, they are advised to notify the hospital immediately for any issues.

About Childrens Hospital Los Angeles

“Children’s Hospital Los Angeles has been named the best children’s hospital in California and among the top 10 in the nation for clinical excellence with its selection to the prestigious U.S. News & World Report Honor Roll. Children’s Hospital is home to The Saban Research Institute, one of the largest and most productive pediatric research facilities in the United States. Children’s Hospital is also one of America’s premier teaching hospitals through its affiliation with the Keck School of Medicine of the University of Southern California since 1932.”

___________________________________________________________________________________

Alertsec Endpoint Encrypt is certified according to Common Criteria AEL4 and FIPS 140-2.

CoPilot security breach

January 28th, 2017

CoPilot Provider Support Services, Inc. recently suffered a data breach. Facility mentioned that it detected unauthorized access at one of its databases. Potentially affected patients of this incident are notified. Facility has no information or evidence that the accessed data is misused.

“CoPilot recognizes the importance of protecting patient information and is committed to taking steps to prevent this type of incident from occurring again in the future, including the monitoring of its databases by K2 Intelligence, Inc., an independent and nationally renowned forensic IT firm. “

Incident affected database which included information on approximately 220,000 individuals. Patient names, addresses, health insurers, and Social Security numbers are included in the breach. Facility immediately launched an investigation into the incident. The investigation concluded that no sensitive PHI was accessed by an unauthorized party. It also found out that no financial information, medical treatment records or other sensitive information were accessed.

CoPilot issued letters to potentially affected patients informing them about the ways to protect themselves in the future. Facility has offered identity theft protection services to impacted individuals. They are also advised to regularly check their financial institution statements, account statements, and any other relevant accounts for possible unauthorized activity. Also, individuals are supposed to immediately report any suspicious activity.

The database was intended for healthcare professionals in the U.S. to let know patients on whether certain aspects of treatment are covered by insurance.

About CoPilot Provider Support Services, Inc.

“CoPilot is a fully integrated healthcare administrative services and information technology organization supporting providers in understanding the complexities of health insurance benefits, coding, coverage, and payments for each of their patients to ensure optimal treatment and better healthcare outcomes. CoPilot leadership includes executives with managed care, government, healthcare IT, call center and innovative portal development/operations experience. “

Company has setup dedicated call center to address the queries of affected patients.

____________________________________________________________________________________________

Alertsec’s cloud-based information security service provides an easy and convenient way to protect information on your organization’s laptops and computers.

Ukraine Blackout

January 27th, 2017

According to the Ukraine’s national power company Ukrenergo, blackout in Kiev was due to cyber attack. Initial reports suggested that workstations and SCADA systems at a 330-kilowatt substation were attacked by hackers. The Company didn’t mention the source from which the attack originated.

“The analysis of the impact of symptoms on the initial data of these systems indicates a premeditated and multi-level invasion,” Ukrenergo said.

“The attackers actually attacked more but couldn’t achieve all their goals.” Said Honeywell lead cyber security researcher Marina Krotofil.

Marina said that the attackers hid in the network for six months. She added, “The team involved had quite a few people working in it, with very serious tools and an engineer who understands the power infrastructure.”

In 2015, a similar attack was attributed to Russian hackers. It affected 225,000 people in western Ukraine while damaging power distribution equipment.

“Cyber attacks that cripple critical infrastructures continue to grow at a rapid pace — the repeated attacks on power plants in Ukraine, resulting in a loss of power to hundreds of thousands, [are] just the latest example,” Dtex Systems CEO Christy Wyatt told eSecurity Planet by email.

“It is crucial for all public and private sector organizations to focus on not only mitigating these attacks, but preventing nation state actors from gaining access to their networks in the first place,” Wyatt added.

Recent Survey Tripwire of 200 IT professionals working for governments has below findings –

Ninety-eight percent believe smart cities are at risk for cyber attacks

Thirty-eight percent said smart grids have the greater cyber security risks

Twenty percent said they have smart city initiatives

Fifty-five percent says they don’t have enough cybersecurity resources

“Security isn’t usually glamorous, and it can be difficult to    sell the need for added time and cost on a project, even when it’s to ensure that services are secure,” Tripwire senior director of IT security and risk strategy Tim Erlin said in a statement. “Smart city initiatives are pushing the technological envelope for urban infrastructure management, and it’s clear from the survey results that cyber security is being left out of the conversation.”

____________________________________________________________________________________________

Alertsec Endpoint Encrypt is the full disk encryption service that delivers a mobile data protection system for all information stored on laptops used throughout your organization.

Largest number of data breaches in US in 2016

January 25th, 2017

Identity Theft Resource Center (ITRC) and CyberScout, 2016 conducted survey and mentioned that US suffered an all-time high of 1,093 reported data breaches. Previous year breaches stands at 780. Thus making a 40 percent increase in the breach count.

ITRC president and CEO Eva Velasquez said he is not sure whether the increased number is due to increase in the breaches or more companies making it public.

“For the 10 years, the ITRC has been aware of the under-reporting of data breach incidents on the national level and the need for more state or federal agencies to make breach notifications more publicly available,” Velasquez said in a statement. “This year we have seen a number of states take this step by making data breach notifications public on their websites.”

According to the survey the breaches categories include –

The business sector – 494  incidents

Healthcare industry – 377 incidents

The education sector – 98 incidents

The government/military -72 incidents

Banking/credit/financial sector – 52 incidents

Other findings include –

Hacking and phishing  attacks – 55.5 percent of breaches

Employee error – 8.7 percent breaches

Fifty-two percent exposed Social Security numbers

“For businesses of all sizes, data breaches hit close to home, thanks to a significant rise in CEO spear phishing and ransomware attacks,” CyberScout CEO Matt Cullina said in a statement. “With the click of a mouse by a naive employee, companies lose control over their customer, employee and business data.”

“In an age of an unprecedented threat, business leaders need to mitigate risk by developing C-suite strategies and plans for data breach prevention, protection and resolution,” Cullina added.

“The database compromises of 2016 confirmed yet again that breaches are the third certainty in life and we are all living in a constant state of cyber insecurity,” CyberScout chairman and founder Adam Levin said in a statement. “Hackers and identity thieves continue to evolve. They are very sophisticated, extremely creative and dogged in their pursuit of what is ours.”

Separately, 10Fold recently published a list of top ten breaches of 2016.

“If 2015 was the year of the healthcare data breach — breaches impacted nearly 40 million people — then 2016 was the year of the social media breach,” Angela Griffo, vice president of 10Fold’s cyber security practice, said in a statement. “Four of the top 10 breaches were social media related and impacted more than 640 million people.”

“But the biggest surprise of the year was Yahoo revealing that the information of more than 1.5 billion people had been stolen by attackers,” Griffo added. “Regardless of an attacker’s motive, any compromised information leaves users susceptible to identity theft and fraud.”

____________________________________________________________________________________________

Alertsec is powered by Check Point Endpoint Security products, which are positioned in the leaders quadrant in Gartner’s Magic Quadrant for Mobile Data Protection. The implemented encryption has the highest security certifications – FIPS, Common Criteria and BITS.

Cybersecurity breach at Virginia hospital

January 23rd, 2017

Sentara Healthcare announced data breach when one of its third party vendors suffered a cybersecurity breach. The incident affected personal health information. Vascular and thoracic procedures occurring between 2012 and 2015 at a Sentara facility where involved in this breach. Potentially accessed information includes patients’ names, medical records, and Social Security numbers.

“We assure our patients that we are committed to the security of the personal information we maintain and are taking this matter very seriously. To help prevent something like this from happening in the future, the vendor has informed us that it is enhancing its system security. In addition, Sentara continually strengthens policies and procedures and invests in technologies which protect our information technology systems.”

Sentara started the investigation by reaching third party vendor. It also called upon law enforcement. It has started sending and mailing advisory to affected individuals.

Facility suggested that the affected patients should check for any signs of possible fraud. Also, they are advised to review account statements and get free credit reports. Organisation has provided resources to help for future security.

“If you believe you are the victim of identity theft or have reason to believe your personal information has been misused, you should immediately contact the Federal Trade Commission and/or the Attorney General’s office in your state. You can obtain information from these sources about steps an individual can take to avoid identity theft as well as information about fraud alerts and security freezes.  You should also contact your local law enforcement authorities and file a police report.  Obtain a copy of the police report in case you are asked to provide copies to creditors to correct your records.”

Sentara is one of the nation’s top integrated healthcare systems. It works on a not-for-profit system which includes imaging centers, nursing and assisted-living centers, outpatient campuses, physical therapy and rehabilitation services, home health and hospice agency, a 3,800-provider medical staff and four medical groups. It also provides medical transport ambulances and nightingale air ambulance.

____________________________________________________________________________________________

Alertsec is powered by Check Point Endpoint Security products, which are positioned in the leaders quadrant in Gartner’s Magic Quadrant for Mobile Data Protection.

Data breach at Delaware

January 21st, 2017

Sixteen self-insured customers and nineteen thousand Highmark members were vulnerable due to a potential attack at Highmark Blue Cross Blue Shield in Delaware.The Delaware Department of Insurance released the information to the public after the incident.

Summit Reinsurance Services, Inc., in Indiana and BCS Financial in Illinois were the two subcontractors involved in the breach. Highmark didn’t specify the explicit nature of the breach. According to the reports, this incident is one of the several data breaches which is related to Summit Reinsurance Services, Inc. in 2016.

Early in November 2016, Summit reported a ransomware attack which impacted thousands of current and former Black Hawk College employees. Affected information contained PHI, including Social Security numbers and health insurance information.

There was also a potential data breach at Louisiana Health Cooperative, Inc. A ransomware compromised sensitive patient information including Social Security numbers.

Trinidad Navarro, the Delaware Insurance Commissioner mentioned that they are looking into the breach.

“I would like to ensure Delaware consumers that the Department of Insurance takes this matter seriously and is currently investigating how this occurred,” Navarro said. “I have directed my staff to closely monitor the situation as it develops. Many Delawareans have received mailed correspondence from Summit Reinsurance explaining the breach. Unfortunately, we fear that many may have misinterpreted or inadvertently discarded the latter as some form of sales ad.”

The Delaware Department of Insurance is helping affected patients by providing resources to answer any questions.

“The Commissioner has ordered an investigation into the reported breach. Highmark Blue Cross Blue Shield of Delaware is cooperating with the Delaware Department of Insurance to resolve the matter.”

“If consumers have received a letter from SummitRe regarding this situation and have questions, they may contact the Delaware Department of Insurance.”

____________________________________________________________________________________________

Alertsec Endpoint Encrypt is the full disk encryption service that delivers a mobile data protection system for all information stored on laptops used throughout your organization.

HIPAA violated by VA Senator

January 19th, 2017

A Virginia State Senator act of unlawful sharing of patient information led to an investigation into alleged HIPAA breach. As per the reports, senator during her 2015 campaign used patient contact information to send political solicitations. It violated federal health privacy rules.

Senator Dunnavant sent emails and print letters to 1500 patients during the 2015 election campaign. She ran in a four-way Republican primary for the 12th District seat. US Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) mentioned that senator broke federal HIPAA law due to the use of patients’ information and her decision to disclose the same with her campaign manager.

Conservative blogger Tom White and an unnamed individual filed a complaint against Dunnavant after receiving the letter during her campaign. HHS investigators mentioned that the case is closed. They mentioned that senator Dunnavant will not face any penalties or fines as she took prompt actions to minimize the damage.

“For me, it’s really all about the fact that none of my patients were harmed,” Dunnavant said.

She also added that it is regrettable. The senator said that she ran the letter by her medical practice board and lawyers. They took no issue with it. She also mentioned the sharing of information with campaign manager was done under HIPAA’s Privacy and Security rule. Investigators denied the legitimacy of her claim.

“Dr. Dunnavant’s position that the disclosure and use of (protected health information) to and by the campaign committee was strictly related to treatment or health care operations is not supported by the evidence,” Barbara J. Holland, the mid-Atlantic regional manager for the HHS OCR, wrote in a letter dated Dec. 6. “The letter expressly encouraged patients to participate in campaign activities and invited patients to contact the campaign for additional information.”

HHS mentioned that they are willing to take additional steps if more complaints or evidence of misconduct comes forward in the future.

____________________________________________________________________________________________

Alertsec helps you comply with HIPAA, PCI and SOX requirements.

Data breach due to virus

January 10th, 2017

Brandywine Pediatrics, P.A in Delaware recently suffered data breach exposing PHI for many patients. Brandone came to know about the incident when it discovered a file server which was locked due to virus.

Facility immediately recovered the files from backup tapes. Also, it started the investigation and took help of a forensic computer expert. This incident has affected certain PHI which includes name, address, and health insurance and medical information.

Brandwine mentioned that there is exposure of health information but it has not found any evidence which suggests that it was misused. It also included in statement that there is no chance of compromise of patients’ Social Security numbers or payment card information.

Affected individuals are notified about the incident and had asked to take steps to protect them. Facility has improved the security of its systems. Also, policies and procedures are reviewed.

Brandwine mentioned that the privacy and protection of the patients is a top priority.  It also deeply regret any inconvenience or concern this incident may cause. The number of affected individuals are not mentioned in the statement.

Types of attack to gain database access

Physical theft or loss of the device

Rogue employee or other insiders misusing privileges to gain financial or personal gains

Attacks on website and application by finding weaknesses in coding

Phishing to gain passwords and usernames. Legitimate-looking email are sent to employees

Installing malicious software which misdirects users to fraudulent websites

‘Dedicated Denial of Service’ attacks

Ransomware attacks

Point-of-sale intrusions

Remote attacks

Payment card skimmers

Viruses

Worms

Trojan Horses

 Data breaches also occur due to human errors which includes below –

Sending sensitive information to the wrong person by email or fax by mistake

Making information publicly available on a web server or website by mistake

Incorrect disposing of data which also includes paper data

Losing electronic device which contains sensitive data

____________________________________________________________________________________________

Alertsec’s cloud-based information security service provides an easy and convenient way to protect information on your organization’s laptops and computers.