Showing posts with label Insider Threat. Show all posts
Showing posts with label Insider Threat. Show all posts

Thursday, November 7, 2019

Insider Threat - Any/Every organization can be affected. It time that we take "Zero Trust" security model seriously - Trend Micro saw about 100,000 of its consumer customers have their account information stolen



The cybersecurity company said in a statement today the first inkling something was wrong came in August 2019 when some customers complained of receiving scam phone calls from people purportedly from Trend Micro. The information the callers disclosed to their targets during the conversations led the company to believe it had to have come from an insider.

The company said it never calls customers unannounced.

By late October the company was able to fully determine the attack was an inside job. An employee used fraudulent means to gain access to customer support databases, retrieve the data and sell it.

“Our open investigation has confirmed that this was not an external hack, but rather the work of a malicious internal source that engaged in a premeditated infiltration scheme to bypass our sophisticated controls,” the company said.

https://www.scmagazine.com/home/security-news/insider-threats/trend-micro-hit-with-insider-attack/

Tuesday, August 6, 2019

Insider Threat - Money talks BS Walks - In this case - AT&T employees took bribes to unlock millions of smartphones, and to install malware and unauthorized hardware (rogue Wireless Access points) on the company's network.More than $1 million in bribes were paid to several AT&T employees.



The bribery scheme lasted from at least April 2012 until September 2017

Fahd bribed AT&T employees to install malware on AT&T's network at the Bothell call center.

In November 2014, as Fahd began having problems controlling this malware, the DOJ said he also bribed AT&T employees to install rogue wireless access points inside AT&T's Bothell call center. These devices helped Fahd with gaining access to AT&T internal apps and network, and continue the rogue phone unlocking scheme.

The DOJ claims Fahd and Jiwani paid more than $1 million in bribes to AT&T employees, and successfully unlocked more than two million devices, most of which were expensive iPhones. One AT&T employee received more than $428,500 in bribes over a five year period,

https://www.zdnet.com/article/at-t-employees-took-bribes-to-plant-malware-on-the-companys-network/

Tuesday, July 16, 2019

Insider Threat - Forget DLP, how many of us block USB or Cloud Storage?

- A newly unsealed federal indictment charges a software engineer for stealing proprietary information from his workplace and bringing it to China,
Within two weeks of his hiring date, Yao downloaded more than 3,000 files containing proprietary and trade secret data related to the system that runs the company's locomotives. Over the following six months he continued to download electronic files containing technical documents and software source code.


https://www.darkreading.com/risk/software-engineer-charged-for-taking-stolen-trade-secrets-to-china/d/d-id/1335224

Thursday, July 5, 2018

Insider Threat - They are real, and they will eventually cause an incident in every organization. Proper preparation, training, and vigilance can prevent or mitigate related negative consequences. The focus is generally on Detection , what about Prevention/ response?




  • First, we should ensure all employees understand organizational policies regarding use of information resources and workplace behaviour. Second, any policy violation should result in a quick response by management. The response should match the level of the offense. Further, every employee, without exception, should understand the consequences

  • Terminating an employee is one way to deal with a potential problem. However, we often value employees who are simply going through rough personal times. Further, termination without prior efforts to resolve issues can result in litigation. It is often better to remediate than quickly terminate.


https://www.hackread.com/managing-insider-threats-with-internal-monitoring/

Thursday, December 28, 2017

From Scammer to Slammer (Talk about insider theft)


Ajay Garg, an assistant programmer at the Central Bureau of Investigation (CBI), has been arrested by his own agency for developing a software that exploits the vulnerabilities of the IRCTC railway ticketing system to book over 1000 Tatkal tickets at a time.

Rather than reporting the vulnerabilities found by him, Garg instead used them for his own gain and amassed a huge wealth by making his software available to travel agents through his accomplice Anil Gupta, who can then easily book Tatkal tickets for clients for a fee using the software.

For More:
http://www.ehackingnews.com/2017/12/tatkal-ticket-scam-uncovered-cbi.html

Wednesday, March 26, 2014

Insider Threat - 5 ways to limit them , according to ISACA.



"Insider Threat" - Dangerous. Difficult and mostly  ignored by organizations


According to the article:- 


  1. Trust, but verify
  1. Privileged user management
  1. Segmentation of duties
  1. Third-party monitoring
  1. Behavior monitoring




The links below has more information:

http://www.isaca.org/About-ISACA/-ISACA-Newsletter/Pages/at-ISACA-Volume-7-26-March-2014.aspx?cid=1004028&Appeal=EDMi#1