Results for news

Bell Canada Hacked: Data of 1.9 Million Customers Stolen

June 25, 2018

Bell Canada Hacked: Data of 1.9 Million Customers Stolen

e busy in the WannaCry ransomware menace, two separate data breaches have been reported, one in DocuSign, a major provider of electronic signature technology, and another in BELL, Canada’s largest telecommunications company.

Canadian mobile phone, TV, and internet service provider Bell on Monday confirmed that the company had been hit by an unknown hacker who has managed to access its customer information illegally.

In a brief statement released by Bell Canada, the company said an unknown hacker managed to have his hands on data of millions of Bell customers.
However, the company did not mention the compromised customer details stolen in the hack were pulled from which particular service.

The company said email addresses, names and telephone numbers of its customers had been accessed in the breach.

How many victims Affected?

Bell confirmed the hack and said the unknown hacker has managed to gain access to information on nearly 2 million customers.
 "The illegally accessed information contains approximately 1.9 million active email addresses and approximately 1,700 names and active phone numbers," the company said.
However, Bell assured its customers that there's no indication of hacker's access to "financial, password or other sensitive personal information," and that the incident is not linked to the global WannaCry ransomware attacks.

What's the Missing Link?

The incident seems to be an extortion attempt by a hacker or group of hackers who posted some of the stolen data of Bell Canada customers online and threatened to leak more data if the company fails to cooperate.
 "We are releasing a significant portion of Bell.ca's data due to the fact that they have failed to [co-operate] with us," reads a post on PasteBin published Monday afternoon, several hours before Bell Canada released its apology.
 "This shows how Bell doesn't care for its [customers'] safety and they could have avoided this public announcement… Bell, if you don't [co-operate], more will leak :)."

There is still no explanation for who is behind the extortion demand or what sort of cooperation the hackers were seeking for, but it appears Bell Canada refused to pay the ransom demand.

However, this information remains unconfirmed.

What is Bell Canada doing? The Canada's largest telecommunication said the company is working with the Canadian law enforcement authorities to figure out who was responsible for the attack.
 "We apologize to Bell customers for this situation and are contacting those affected directly," the company said.
 "Bell took immediate steps to secure affected systems. The company has been working closely with the RCMP cyber crime unit in its investigation and has informed the Office of the Privacy Commissioner."


What should Bell Canada customers do?


While Bell Canada believes there is "minimal risk involved for those affected" by the attack, having access to customer information, including email addresses, names and/or telephone numbers, opens the opportunity for targeted phishing attacks to customers.

So, users should particularly be alert of any phishing email, which are usually the next step of cyber criminals after a breach to trick users into giving up further details like financial information.

For the obvious reasons, all Bell Canada customers are highly recommended to change their passwords as soon as possible.
Bell Canada Hacked: Data of 1.9 Million Customers Stolen Bell Canada Hacked: Data of 1.9 Million Customers Stolen Reviewed by Lehvi on June 25, 2018 Rating: 5

sponsorship1

June 24, 2018
This is for girls who want to learn how to code. Our @acecharity all expenses paid Girls Who Code (2) program begins in July, 2018
1. Training is free of charge
2. Transportation cost will be covered by @hiltonabuja
3. Brand new laptops will be provided free of charge
4. Send a cover letter to info@acecharityafrica.org by 6PM Monday 25th of June
5. If you cannot commit to 4 months (Mon-Friday) of learning PLEASE DO NOT APPLY (click here for more details)
Share/Tell a friend who you know will benefit from this. Good luck!
sponsorship1 sponsorship1 Reviewed by Lehvi on June 24, 2018 Rating: 5

Stuffed cloudpets vulnerable to hacking, few retailers stop selling

June 23, 2018

Stuffed cloudpets vulnerable to hacking, few retailers stop selling

Who would have thought hacking is a constraint to only accounts, banks and emails. Today, stuffed pets are being hacked and used for criminal activity. According to reports, around 800,000 accounts relating to the soft toys were recently hacked with data leaked on the internet.

Some of the nation’s largest retailers, including Amazon, Walmart and eBay, stopped selling a stuffed children’s toy this week because of concerns the devices could be easily hacked.

A study conducted by researchers found that cloudpets are hackable with many having already been hacked. Some of these toys work on Bluetooth technology and others on WiFi technology, which renders them vulnerable to being used as a listening device if exploited. Security researchers demonstrated the Bluetooth-enabled devices could be hijacked and turned into a listening device.

An audit was conducted by Mozilla Firefox that highlights that these vulnerabilities are still being widely exploited. Based on this and many other sources, popular retailers have ceased in selling stuffed cloudpets that work on Bluetooth and WiFi.

A bunch of retailers, including Amazon, Target, and Walmart, pulled their listings for a line of smartphone-connected stuffed animals called CloudPets this week after they were found to be storing kids’ voice recordings online without any security measures, among other issues. The news offers them good optics, but the reality is that this security revelation came about in February 2017: it took the massive retailers over a year to remove the stuffed animals, during which time they likely sold at least some of their inventory.

The toy’s removal only happened after the Electronic Frontier Foundation wrote a letter this week to Walmart, Target, and Amazon requesting that the CloudPet listings be taken down. The organization writes that it also urges the stores to “consider putting in place new or improved systems to ensure that products you stock, especially those that collect the information of children, have basic practices in place to respect the trust that consumers place in them.
Stuffed cloudpets vulnerable to hacking, few retailers stop selling Stuffed cloudpets vulnerable to hacking, few retailers stop selling Reviewed by Lehvi on June 23, 2018 Rating: 5

US Imposes Sanctions Over Russian Military, Intelligence Hacking

June 23, 2018

US Imposes Sanctions Over Russian Military, Intelligence Hacking


The United States Treasury Department imposed sanctions on five Russian companies and three individuals for allegedly supporting the country's  military and intelligence services to conduct cyber attacks againt the U.S and its allies.

“The United States is engaged in an ongoing effort to counter malicious actors working at the behest of the Russian Federation and its military and intelligence units to increase Russia’s offensive cyber capabilities,” Treasury Secretary Steven Mnuchin said in a statement.

“The entities designated today have directly contributed to improving Russia’s cyber and underwater capabilities through their work with the FSB [Federal Security Service] and therefore jeopardize the safety and security of the United States and our allies,” Mnuchin said.

The companies and individuals who are facing sanctions will be banned from any kind of transactions involving the US financial system.

This decision is aftermath  reaction  of many Russia-based cyberattacks that had hit the country, and the world worst. It is believed that Russian hackers were behind  the VPNFilter malware that infected more than half a million routers worldwide, power outages in Ukraine and a ransomware attack that the US government called the "most destructive cyberattack in history."

The three cybersecurity companies which have been sanctioned include Kvant Scientific Research Institute, Divetechnoservices (provides underwater equipment and diving systems to Russian agencies), Digital Security, ERPScan and Embedi. However, the latter two are not based in Russia, but, the department said they're owned by Russia-based Digital Security.

 Embedi's marketing head,  Alex Kruglov,  said they are unsure why their company was added in list sanctioned list, and denied working for the Russian government.

"We never worked with Russian government and any government at all," Kruglov said in an email. He said the company isn't clear on what they'll do in their next steps.

The three Russians who worked with Divetechnoservices have also been sanctioned: Aleksandr Lvovich Tribun, Oleg Sergeyevich Chirikov and Vladimir Yakovlevich Kaganskiy.

“Today’s action also targets the Russian government’s underwater capabilities,”Mnuchin said. “Russia has been active in tracking undersea communication cables, which carry the bulk of the world’s telecommunications data.”
US Imposes Sanctions Over Russian Military, Intelligence Hacking US Imposes Sanctions Over Russian Military, Intelligence Hacking Reviewed by Lehvi on June 23, 2018 Rating: 5

Cyber cell arrests man for hacking, blackmailing several women

June 23, 2018

Cyber cell arrests man for hacking, blackmailing several women

A city businessman fell victim to ‘Man In Middle Attack’ — a type of hacking — on May 26 and Rs 2.90 crore was syphoned off from his account to another within minutes without his permission. Thanks to the city cybercrime cell’s quick action, the money was retrieved from a bank in China.

The account is registered in the name of a fraudster who operates primarily as an email hacker.

The businessman approached police on May 26 with his complaint application, stating that he had entered into an agreement with a Chinese firm on April 27 and had placed an order to procure machinery from the company. The firm had demanded some advance from him and he was in touch with its officials through emails.

Man in the middle method of cyber attack involves a hacker who secretly relays and possibly alters the communication between two parties who believe they are directly communicating with each other.

During their investigation, the cyber cell found that the man had hacked into the social media accounts of six other women in the city and blackmailed them. The accused reportedly threatened the women of posting morphed illicit images of them on their social media accounts.

A team headed by deputy commissioner of police (cyber & economics) Sudhir Hiremath and inspectors Jayram Paigude and Manisha Zende acted promptly in the case and managed to recover the lost money. No case was registered, though.

Police inspector of the cyber crime cell, Manisha Zende, told Mirror, “A very renowned company from Hinjawadi, which makes headlights for various vehicles, had been engaged in an email conversation with a China-based company for ordering raw materials on April 27 this year. The deal had been finalised between finance and purchase officials on both sides. The Chinese company had sent an email to the Indian company in which they had requested the transfer of an advance amount and had also asked that the rest of the money be sent across after the delivery.”

The man arrested was identified as Krushna Baliram Fadd, a resident of Jagdish Khanawalkar chawl in Panvel region of Raigad.
Cyber cell arrests man for hacking, blackmailing several women Cyber cell arrests man for hacking, blackmailing several women Reviewed by Lehvi on June 23, 2018 Rating: 5
Powered by Blogger.