Showing posts with label Scams. Show all posts
Showing posts with label Scams. Show all posts

Friday, June 24, 2016

Source: How to Spot Ingenico Self-Checkout Skimmers — Krebs on Security

A KrebsOnSecurity story last month about credit card skimmers found in self-checkout lanes at some Walmart locations got picked up by quite a few publications. Since then I’ve heard from several readers who work at retailers that use hundreds of thousands of theseIngenico credit card terminals across their stores, and all wanted to know the same thing: How could they tell if their self-checkout lanes were compromised? This post provides a few pointers.
Happily, just days before my story point-of-sale vendor Ingenico produced a tutorial on how to spot a skimmer on self checkout lanes powered by Ingenico iSC250 card terminals. Unfortunately, it doesn’t appear that this report was widely disseminated, because I’m still getting questions from readers at retailers that use these devices.
“In order for the overlay to fit atop the POS [point-of-sale] terminal, it must be longer and wider than the target device,” reads a May 16, 2016 security bulletin obtained by KrebsOnSecurity. “For this reason, the case overlay will appear noticeably larger than the actual POS terminal. This is the primary identifying characteristic of the skimming device. A skimmer overlay of the iSC250 is over 6 inches wide and 7 inches tall while the iSC250 itself is 5 9/16 inch wide and 6 1⁄2 inches tall.”
In addition, the skimming device that thieves can attach in the blink of an eye on top of the Ingenico self-checkout card reader blocks the backlight from coming through the fake PIN pad overlay.

Tuesday, May 17, 2016

Source: Wendy’s: Breach Affected 5% of Restaurants — Krebs on Security

Read blog post at Wendy’s: Breach Affected 5% of Restaurants — Krebs on Security

Wendy’s said today that an investigation into a credit card breach at the nationwide fast-food chain uncovered malicious software on point-of-sale systems at fewer than 300 of the company’s 5,500 franchised stores. The company says the investigation into the breach is continuing, but that the malware has been removed from all affected locations.
“Based on the preliminary findings of the investigation and other information, the Company believes that malware, installed through the use of compromised third-party vendor credentials, affected one particular point of sale system at fewer than 300 of approximately 5,500 franchised North America Wendy’s restaurants, starting in the fall of 2015,” Wendy’s disclosed in their first quarter financial statement today. The statement continues:
“These findings also indicate that the Aloha point of sale system has not been impacted by this activity. The Aloha system is already installed at all Company-operated restaurants and in a majority of franchise-operated restaurants, with implementation throughout the North America system targeted by year-end 2016. The Company expects that it will receive a final report from its investigator in the near future.”
“The Company has worked aggressively with its investigator to identify the source of the malware and quantify the extent of the malicious cyber-attacks, and has disabled and eradicated the malware in affected restaurants. The Company continues to work through a defined process with the payment card brands, its investigator and federal law enforcement authorities to complete the investigation.”
“Based upon the investigation to date, approximately 50 franchise restaurants are suspected of experiencing, or have been found to have, unrelated cybersecurity issues. The Company and affected franchisees are working to verify and resolve these issues.”

Source: Carding Sites Turn to the ‘Dark Cloud’ — Krebs on Security

Read entire blog post at Carding Sites Turn to the ‘Dark Cloud’ — Krebs on Security


Crooks who peddle stolen credit cards on the Internet face a constant challenge: Keeping their shops online and reachable in the face of meddling from law enforcement officials, security firms, researchers and vigilantes. In this post, we’ll examine a large collection of hacked computers around the world that currently serves as a criminal cloud hosting environment for a variety of cybercrime operations, from sending spam to hosting malicious software and stolen credit card shops.


Thursday, April 28, 2016

Source: Dental Assn Mails Malware to Members — Krebs on Security

Dental Assn Mails Malware to Members

Brian Krebs
The American Dental Association (ADA) says it may have inadvertently mailed malware-laced USB thumb drives to thousands of dental offices nationwide.
The problem first came to light in a post on the DSL Reports Security Forum. DSLR member “Mike” from Pittsburgh got curious about the integrity of a USB drive that the ADA mailed to members to share updated “dental procedure codes” — codes that dental offices use to track procedures for billing and insurance purposes.
“Oh wow the usually inept ADA just sent me new codes,” Mike wrote. “I bet some marketing genius had this wonderful idea instead of making it downloadable. I can’t wait to plug an unknown USB into my computer that has PHI/HIPAA on it…” [link added].
Sure enough, Mike looked at the code inside one of the files on the flash drive and found it tries to open a Web page that has long been tied to malware distribution. The domain is used by crooks to infect visitors with malware that lets the attackers gain full control of the infected Windows computer.
Reached by KrebsOnSecurity, the ADA said it send the following email to members who have shared their email address with the organization:
“We have received a handful of reports that malware has been detected on some flash drives included with the 2016 CDT manual,” the ADA said. “The ‘flash drive’ is the credit card sized USB storage device that contains an electronic copy of the CDT 2016 manual. It is located in a pocket on the inside back cover of the manual. Your anti-virus software should detect the malware if it is present. However, if you haven’t used your CDT 2016 flash drive, please throw it away.
To give you access to an electronic version of the 2016 CDT manual, we are offering you the ability to download the PDF version of the 2016 CDT manual that was included on the flash drive.
To download the PDF version of the CDT manual:
1. Click on the link »ebusiness.ada.org/login/ ··· ion.aspx
2. Log in with your ADA.org user ID and password
3. After you log in you will automatically be directed to a page showing CDT 2016 Digital Edition.
4. Click on the “Download” button to save the file to your computer for use.
If you have difficulty accessing or downloading the file, please call 1.800.947.4746 and a Member Service Advisor will be happy to assist you.
Many of the flash drives do not contain the Malware. If you have already used your flash drive and it worked as expected (it displayed a menu linking to chapters of the 2016 CDT manual), you may continue using it.
We apologize if this issue has caused you any inconvenience and thank you for being a valued ADA customer.”
This incident could give new meaning to the term “root canal.” It’s not clear how the ADA could make a statement that anti-virus should detect the malware, since presently only some of the many antivirus tools out there will flag the malware link as malicious.
In response to questions from this author, the ADA said the USB media was manufactured in China by a subcontractor of an ADA vendor, and that some 37,000 of the devices have been distributed. The not-for-profit ADA is the nation’s largest dental association, with more than 159,000 members.
“Upon investigation, the ADA concluded that only a small percentage of the manufactured USB devices were infected,” the organization wrote in an emailed statement. “Of note it is speculated that one of several duplicating machines in use at the manufacturer had become infected during a production run for another customer. That infected machine infected our clean image during one of our three production runs. Our random quality assurance testing did not catch any infected devices. Since this incident, the ADA has begun to review whether to continue to use physical media to distribute products.”

Monday, April 25, 2016

Source: All About Skimmers — Krebs on Security

All About Skimmers — Krebs on Security
Brian Krebs 2010 - 2015

The series I’ve written about ATM skimmers, gas pump skimmers and other related fraud devices have become by far the most-read posts on this blog. I put this gallery together to showcase the entire series, and to give others a handy place to reference all of these stories in one place. Click the headline or the image associated with each blurb for the full story.


Jan. 15, 2010: Would You Have Spotted the Fraud?

Feb. 2, 2010: ATM Skimmers, Part II

March 25, 2010: Would You Have Spotted This ATM Fraud? 

June 3, 2010: ATM Skimmers: Separating Cruft from Craft 

June 17, 2010: Sophisticated ATM Skimmer Transmits Stolen Data Via Text Message

July 20, 2010: Skimmers Siphoning Card Data at the Pump 

Fun With ATM Skimmers, Part III 

Nov. 10, 2010: All-in-One Skimmers

Nov. 23, 2010: Crooks Rock Audio-based ATM Skimmers

Dec. 13, 2010: Why GSM-based ATM Skimmers Rule

Jan. 17, 2011: ATM Skimmers, Up Close

Jan. 31, 2011: ATM Skimmers That Never Touch the ATM

Feb. 16, 2011: Having a Ball With ATM Skimmers

Mar. 11, 2011: Green Skimmers Skimming Green

April 10, 2001: ATM Skimmers: Hacking the Cash Machine

May 18, 2011: Point-of-Sale Skimmers: Robbed at the Register

Sept. 20, 2011: Gang Used 3D Printers for ATM Skimmers

Oct. 13, 2011: ATM Skimmer Powered by MP3 Player

Dec. 7, 2011: Pro Grade (3D Printer-Made?) ATM Skimmer

April 25, 2012: Skimtacular: All-In-One ATM Skimmer…

July 24, 2012: ATM Skimmers Get Wafer Thin…

Sept. 5, 2012: A Handy Way to Foil ATM Skimmers…

Nov. 20, 2012: Beware Card- and Cash-trapping at the ATM… 

Dec. 12, 2012: ATM Thieves Swap Security Camera for Keyboard…

Dec. 18, 2012: Point-of-Sale Skimmers: No Charge…Yet…

Feb. 1, 2013: Pro-Grade Point-of-Sale Skimmer

Apr. 24, 2013: How Not To Install an ATM Skimmer….

July 16, 2013: Getting Skimpy With ATM Skimmers

Oct. 10, 2013: Norstrom Finds Cash Register Skimmers

Dec. 3, 2013: Simple But Effective Point-of-Sale Skimmer

Dec. 18, 2013: The Biggest Skimmers of All: Fake ATMs

Jan. 22, 2014: Gang Rigged Pumps With Bluetooth Skimmers

May 30, 2014: Thieves Planted Malware to Hack ATMs

July 14, 2014: The Rise of Thin, Mini and Insert Skimmers

August 21, 2014: Stealthy, Razor Thin ATM Insert Skimmers

October 20, 2014: Spike in Malware Attacks on Aging ATMs

November 26, 2014: Skimmer Innovation: ‘Wiretapping’ ATMs

December 9, 2014: More on Wiretapping ATM Skimmers

January 6, 2015: Thieves Jackpot ATMs with Black Box Attack

March 17, 2015: Door Skimmer + Hidden Camera = Profit

April 6, 2015: Hacking ATMS, Literally

May 4, 2015: Foiling Pump Skimmers with GPS

July 22, 2015: Spike in ATM Skimming in Mexico?




Wednesday, April 20, 2016

Source: US-CERT to Windows Users: Dump Apple Quicktime — Krebs on Security

US-CERT to Windows Users: Dump Apple Quicktime — Krebs on Security


Brian Krebs April 18, 2016


Microsoft Windows users who still have Apple Quicktime installed should ditch the program now that Apple has stopped shipping security updates for it, warns theDepartment of Homeland Security‘s U.S. Computer Emergency Readiness Team(US-CERT). The advice came just as researchers are reporting two new critical security holes in Quicktime that likely won’t be patched.
US-CERT cited an April 14 blog post by Christopher Buddat Trend Micro, which runs a program called Zero Day Initiative (ZDI) that buys security vulnerabilities and helps researchers coordinate fixing the bugs with software vendors. Budd urged Windows users to junk Quicktime, citing two new, unpatched vulnerabilities that ZDI detailed which could be used to remotely compromise Windows computers.
“According to Trend Micro, Apple will no longer be providing security updates for QuickTime for Windows, leaving this software vulnerable to exploitation,” US-CERT wrote. The advisory continued:
“Computers running QuickTime for Windows will continue to work after support ends. However, using unsupported software may increase the risks from viruses and other security threats. Potential negative consequences include loss of confidentiality, integrity, or availability of data, as well as damage to system resources or business assets. The only mitigation available is to uninstall QuickTime for Windows. Users can find instructions for uninstalling QuickTime for Windows on the Apple Uninstall QuickTime page.”
While the recommendations from US-CERT and others apparently came as a surprise to many, Apple has been distancing itself from QuickTime on Windows for some time now. In 2013, the Cupertino, Calif. tech giant deprecated all developer APIs for Quicktime on Windows.
Apple shipped an update to Quicktime in January 2016 that removed the Quicktime browser plugin on Windows systems, meaning the threat from browser-based attacks on Quicktime flaws was largely mitigated over the past few months for Windows users who have been keeping up to date with the latest version. Nevertheless, if you have Quicktime on a Windows box — do yourself a favor and get rid of it.

Saturday, April 9, 2016

Source: Adobe Patches Flash Player Zero-Day Threat — Krebs on Security

Adobe Patches Flash Player Zero-Day Threat — Krebs on Security

April 8, 2016

Adobe Systems this week rushed out an emergency patch to plug a security hole in its widely-installed Flash Player software, warning that the vulnerability is already being exploited in active attacks.

Adobe said a “critical” bug exists in all versions of Flash including Flash versions 21.0.0.197 and lower (older) across a broad range of systems, including Windows,Mac, Linux and Chrome OS. Find out if you have Flash and if so what version by visiting this link.

In a security advisory, the software maker said it is aware of reports that the vulnerability is being actively exploited on systems running Windows 7 andWindows XP with Flash Player version 20.0.0.306and earlier.

Adobe said additional security protections built into all versions of Flash including 21.0.0.182 and newer should block this flaw from being exploited. But even if you’re running one of the newer versions of Flash with the additional protections, you should update, hobble or remove Flash as soon as possible.

The smartest option is probably to ditch the program once and for all and significantly increase the security of your system in the process. I’ve got more on that approach (as well as slightly less radical solutions ) in A Month Without Adobe Flash Player.

If you choose to update, please do it today. The most recent versions of Flash should be available from the Flash home page. Windows users who browse the Web with anything other than Internet Explorer may need to apply this patch twice, once with IE and again using the alternative browser (Firefox, Opera, e.g.). Chrome and IE should auto-install the latest Flash version on browser restart (I had to manually restart Chrome to get the latest Flash version).

By the way, I’m not the only one trying to make it easier for people to put a lasso on Flash: In a blog post today, Microsoft said Microsoft Edge users on Windows 10 will auto-pause Flash content that is not central to the Web page. The new feature will be available inWindows 10 build 14316.

“Peripheral content like animations or advertisements built with Flash will be displayed in a paused state unless the user explicitly clicks to play that content,” wrote the Microsoft Edge team. “This significantly reduces power consumption and improves performance while preserving the full fidelity of the page. Flash content that is central to the page, like video and games, will not be paused. We are planning for and look forward to a future where Flash is no longer necessary as a default experience in Microsoft Edge.”

Additional reading on this vulnerability:

Kafeine‘s Malware Don’t Need Coffee Blog on active exploitation of the bug.

Trend Micro’s take on evidence that thieves have been using this flaw in automated attacks since at least March 31, 2016.




Tags: cve-2016-1019, Flash Player zero day

Wednesday, April 6, 2016

Source: Official-sounding calls about an email hack | OnGuard Online

Official-sounding calls about an email hack | OnGuard Online

April 6, 2016 by Andrew Johnson
Division of Consumer and Business Education, FTC

There’s a new twist on tech-support scams — you know, the one where crooks try to get access to your computer or sensitive information by offering to “fix” a computer problem that doesn’t actually exist. Lately, we’ve heard reports that people are getting calls from someone claiming to be from the Global Privacy Enforcement Network. Their claim? That your email account has been hacked and is sending fraudulent messages. They say they’ll have to take legal action against you, unless you let them fix the problem right away.
If you raise questions, the scammers turn up the pressure – but they’ve also given out phone numbers of actual Federal Trade Commission staff (who have been surprised to get calls). The scammers also have sent people to the actual website for the Global Privacy Enforcement Network. (It’s a real thing: it’s an organization that helps governments work together on cross-border privacy cooperation.)
Here are few things to remember if you get any kind of tech-support call, no matter who they say they are:
  • Don’t give control of your computer to anyone who calls you offering to “fix” your computer.
  • Never give out or confirm your financial or sensitive information to anyone who contacts you.
  • Getting pressure to act immediately? That’s a sure sign of a scam. Hang up.
  • If you have concerns, contact your security software company directly. Use contact information you know is right, not what the caller gives you.
Read on to learn more about tech-support scams and government imposter scams. And, if you spot a scam, tell the FTC.
Tagged with: emailphone callscam
Blog Topic: Avoid Scams

Sources: Trump Hotels Breached Again — Krebs on Security

Sources: Trump Hotels Breached Again — Krebs on Security

Banking industry sources tell KrebsOnSecurity that the Trump Hotel Collection — a string of luxury properties tied to business magnate and Republican presidential candidateDonald Trump — appears to be dealing with another breach of its credit card systems. If confirmed, this would be the second such breach at the Trump properties in less than a year.


Saturday, March 26, 2016

Source: Water treatment plant hacked, chemical mix changed for tap supplies • The Register

Water treatment plant hacked, chemical mix changed for tap supplies • The Register



Water treatment plant hacked, chemical mix changed for tap supplies

Well, that's just a little scary

Source: Hackers Modify Water Treatment Parameters by Accident

Hackers Modify Water Treatment Parameters by Accident

Bad network design exposes water treatment plant to hacking

Mar 22, 2016 15:25 GMT  ·  By  
A group of hackers, previously involved in various hacktivism campaigns, have accidentally made their way into an ICS/SCADA system installed at a water treatment facility and have altered crucial settings that controlled the amount of chemicals used to treat tap water.
This strange hacking incident is described in Verizon's 2016 Data Breach Digest (page 38, Scenario 8), a collection of case studies that the company's RISK team was brought in to investigate.

Source: The future of our city services? Cyberattackers target core water systems | ZDNet

Source: The future of our city services? Cyberattackers target core water systems | ZDNet

In a recent case, cyberattackers have demonstrated that breaches are not limited to corporate targets. By Charlie Osborne for Zero Day | March 23, 2016 -- 11:25 GMT (04:25 PDT) | Topic: Security.

A group of cyberattackers have shown how weak security has the potential to cripple urban areas worldwide.

The services we rely on every day but often don't think about until a bill is popped through the post -- electricity, water and gas -- keep Western cities running. Without them, businesses would collapse and our daily lives would be very, very different.

But are utilities taking enough care to protect these core services from abuse? Perhaps not, considering a recent case recounted by Verizon's cybersecurity RISK team.

Source: Enterprise Security Solutions: Safeguarding Your Company Data

Enterprise Security Solutions: Safeguarding Your Company Data 

Security Solutions

With cyber attacks growing in strength and number, it’s harder to avoid becoming a victim. Prepare by learning all you can from the latest data on threat patterns and the anatomy of attacks. Recognize where your organization is most vulnerable, where opportunity for data loss is greatest, and how it can be controlled and prevented. And respond strategically, with intelligence-based security protocols and controls that help secure your business around the globe.

Broaden your defenses with intelligence-driven security.

With growth, comes risk. At the enterprise level, the dangers to your organization increase exponentially across countries and geographies. It’s hard to predict the motives of attackers, which can vary from financial to political to personal gain. And their means of disruption and information theft are becoming more sophisticated and faster than ever.

Change the game and get ahead of potential threats by adopting advanced security protocols and controls that can improve your ability to protect your enterprise. With an arsenal of powerful intelligence, we can help you customize your security approach so you can see threats before they happen—and limit the damages with smarter, faster responses.




Source: Security Report & Data Breach Report Resources | Verizon Enterprise Solutions

Security Report & Data Breach Report Resources | Verizon Enterprise Solutions

Industry Reports

Understand the top security threats facing selected industries, and learn how to better manage risk.

DBIR Industry Insights




BookMark