Cyber Security Today for June 22, 2022 – A possible lesson from a bank’s second data breach, and more

Share post:

A possible lesson from a bank’s second data breach, and more. Welcome to Cyber Security Today. It’s Wednesday, June 22nd, 2022. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com.
Cyb er Security Today on Amazon Alexa Cyber Security Today on Google Podcasts Subscribe to Cyber Security Today on Apple Podcasts
  A U.S. bank has acknowledged a second recent hack. Flagstar said this one happened in December and led to the theft of personal information of 1.5 million customers. The earlier one was a ransomware attack in January involving the theft of data of 1.4 million customers. The bank said it only learned about the December intrusion recently, and at the beginning of this month how big it was. But according to a commentator at the SANS Institute for security training, this discovery of the second data theft might have been detected earlier. That’s because while there was an investigation of the ransomware attack, it isn’t clear that included a look at the bank’s overall security gaps. If it had, the December attack might have been found sooner. That’s why any expert investigation of the causes of a security incident should include a wider look at possible security gaps. Speaking of ransomware, once double-extortion gangs get into an organization they cherry-pick the data they want to steal and threaten to disclose. According to researchers at Rapid7, they prefer financial data, customer data or healthcare patient information. That makes sense: This is often the most sensitive data that corporations, hospitals and clinics have, and therefore the most likely they would want to pay a ransom for. The report reminds IT leaders that protecting sensitive data with strong encryption is one of the best ways to protect against any data theft. So is network segmentation. Think your firm has been seeing more payment fraud attempts recently? You’re not alone. Canadian small businesses recently surveyed said attempted fraud by text messages, email and social media platforms went up 30 per cent during the pandemic. Fraud attempts through online retail sites or apps went up 25 per cent. On the other hand, 51 per cent of those surveyed said they are more aware of how to recognize payment fraud scams. Almost the same number said their firms are more aware of how to protect themselves. The survey was done for Payments Canada, which is responsible for the physical infrastructure used by payment systems. Here’s a different look at Canadian online scan numbers: Since 2017 Canadians have lost $380 million to online scammers. The three most hit provinces were Ontario, Alberta and British Columbia, with residents or businesses reporting around $3 million a year in losses in each province. Manitoba was a close fourth. Investment and romance scams were the most common tactics, with extortion coming third. The numbers come from an analysis of reports from the Canadian Anti Fraud Centre by a website called SocialCatfish. To protect yourself don’t give money or personal information to someone on the internet who you haven’t met in person. Finally, here’s another warning about scanning and using QR codes: Security researchers say crooks are getting around two-factor login authentication on the Discord discussion platform by abusing QR codes. It works like this: A target is sent a messaging asking them to authenticate with the included QR code. If the victim falls for this scans the code, it logs in the attacker and bypasses two-factor authentication. Beware of a QR code or a link to a code unexpectedly being sent to you. That’s it for now Remember links to details about podcast stories are in the text version at ITWorldCanada.com. That’s where you’ll also find other stories of mine. Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker. Thanks for listening. I’m Howard Solomon The post Cyber Security Today for June 22, 2022 – A possible lesson from a bank’s second data breach, and more first appeared on IT World Canada.
Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for several of ITWC's sister publications including ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, Week in Review for week ending Friday April 19, 2024

On this episode Jen Ellis, co-chair of the Ransomware Task Force, talks about ways of fighting one of the biggest cyber threats to IT d

Cyber Security Today, April 19, 2024 – Police bust phishing rental platform, a nine-year old virus found on Ukrainian computers, and more

This episode reports on a threat actor targeting governments in the Middle East with a novel way of hiding malware is going international

Controversial expansion of US surveillance powers nears Senate vote

The US Senate is poised to vote on a significant expansion of Section 702 of the Foreign Intelligence...

Russian-linked hackers target U.S. and European water systems

A Russian military-affiliated hacking group, Sandworm, is suspected of coordinating recent cyberattacks on water utilities in the U.S.,...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways