Macy’s and Bloomingdale’s just announced a data breach that’s exposed sensitive customer info
|
|
|
|
|
|
|
|
|
|
| NOTICE OF DATA BREACH |
|
To the MyFitnessPal Community:
We are writing to notify you about an issue that may involve your MyFitnessPal account information. We understand that you value your privacy and we take the protection of your information seriously. What Happened? On March 25, 2018, we became aware that during February of this year an unauthorized party acquired data associated with MyFitnessPal user accounts. What Information Was Involved? The affected information included usernames, email addresses, and hashed passwords – the majority with the hashing function called bcrypt used to secure passwords. What We Are Doing Once we became aware, we quickly took steps to determine the nature and scope of the issue. We are working with leading data security firms to assist in our investigation. We have also notified and are coordinating with law enforcement authorities. We are taking steps to protect our community, including the following:
What You Can Do We take our obligation to safeguard your personal data very seriously and are alerting you about this issue so you can take steps to help protect your information. We recommend you:
For More Information For more information, please go to https://content.myfitnesspal. Sincerely, Paul Fipps |
2017 was a tough year for cyber security companies and professional as phishing attacks, ransomware and state-sponsored attacks took front stage. So what should we expect for 2018? I say bigger breaches and new types of attacks if the current trend continues. With that being said, her are a few of my ideas on the types of attacks that will cover our headlines in 2018:
These are just a few of the concerns I predict will have security practitioners up at night, the good news, our awareness of this threats have increased and security tools are being implemented to assist in defending our information systems and data. What do you think?
In recent years security breaches have been a big topic as it has impacted many of our lives and 2017 is not different. securityorb.com/ recently reviewed some of the most notable hacks of 2017 and compiled a list of the top 3 security breaches.
Let us know what you think of the list, what else should have been on the list in your opinion?
I recently received an email from Hotels.com stating an unauthorized user may have accessed user’s accounts and are urging customers to change their password. Read the actual email below.
“We are writing to make you aware of recent activity involving Hotels.com accounts that leads us to believe that some of your personal information, including your reward nights, may have been accessed by an unauthorized user. However, rest assured that your full credit card information was not compromised on our website.
On May 22-29, 2017, we detected unusual user activity with a number of accounts, including yours, which we believe resulted from an unauthorized user accessing the accounts using customers’ usernames and passwords. The accessed data could have included your name, address, e-mail address, hotel booking history, reward nights, and the last four digits of your stored credit card—but only if a user selected the option to save credit card numbers.
If we’re able to verify that free nights were recently removed from your account without your authorization, we will quickly restore those nights.
We are taking steps to ensure the continued security of your data, including resetting all compromised passwords. When you attempt to log in to your account, you will receive a message that will provide you with instructions on how to change your password.
The following are tips on how better to protect your account:
The security of our customers’ account information is of the utmost importance to us, and we apologize for any inconvenience this issue may cause you. If you have questions, please feel free to contact Hotels.com at 800-246-8357. Please note that our Customer Service agents will not be able to assist you with changing your password—only you can change your password online.
Sincerely,
Hotels.com Customer Support”
An article by Brian Krebs from KrebsonSecurity.com:
For the second time in less than three years, Kmart Stores is battling a malware-based security breach of its store credit card processing systems.
Last week I began hearing from smaller banks and credit unions who said they strongly suspected another card breach at Kmart. Some of those institutions received alerts from the credit card companies about batches of stolen cards that all had one thing in common: They were all used at Kmart locations.
Asked to respond to rumors about a card breach, Kmart’s parent company Sears Holdings said some of its payment systems were infected with malicious software:
“We recently became aware that Sears Holdings was a victim of a security incident involving unauthorized credit card activity following certain customer purchases at some of our Kmart stores. We immediately launched a thorough investigation and engaged leading third party forensic experts to review our systems and secure the affected part of our network.”
“Our Kmart store payment data systems were infected with a form of malicious code that was undetectable by current anti-virus systems and application controls. Once aware of the new malicious code, we quickly removed it and contained the event. We are confident that our customers can safely use their credit and debit cards in our retail stores.”
Based on the forensic investigation, NO PERSONAL identifying information (including names, addresses, social security numbers, and email addresses) was obtained by those criminally responsible. However, we believe certain credit card numbers have been compromised. Nevertheless, in light of our EMV compliant point of sale systems, which rolled out last year, we believe the exposure to cardholder data that can be used to create counterfeit cards is limited. There is also no evidence that kmart.com or Sears customers were impacted.”
Sears spokesman Chris Brathwaite said the company is not commenting on how many of Kmart’s 735 locations nationwide may have been impacted or how long the breach is believed to have persisted, saying the investigation is ongoing.
Read the rest here.
On Friday night, the Jester gained access to the Russian government ministry’s website. And he left a message: Stop attacking Americans.
“Comrades! We interrupt regular scheduled Russian Foreign Affairs Website programming to bring you the following important message,” he wrote. “Knock it off. You may be able to push around nations around you, but this is America. Nobody is impressed.”
MID.ru is the official website of the Russian agency that is in charge of maintaining that country’s international diplomacy — equivalent to the U.S. Department of State.
His hacking of the website included this gag: Visitors are subjected to the ear-piercing sound of an American civil alert message — that shrieking dial tone that accompanies emergency weather broadcasts.
Read more here.
Last week on my radio show, I discussed how some of the most powerful hacking tools created by the NSA’s elite hacking group known as the “Equation Group” have been released in the public by a hacking group calling themselves “The Shadow Brokers”.
Many experts in the InfoSec arena including the security firm Kaspersky stated, “The files posted by The Shadow Brokers and tools used by the Equation group, “share specific and rare characteristics”, so the probability of falsification is “highly unlikely.”
The tools that were release are much more sophisticated than many of the open source and freely available hacking tools that are available on the internet. These tools can easily circumvent the security of many of the major government and corporate networks both in the US and abroad. These tools can also be used to take over firewalls that are used in the largest and most critical environments around the world.
The Shadow Brokers are asking for 1 Million in Bitcoins (around $568 Million Dollars) in an auction to release more hacking tools in the public.
How can this happen you ask?
The main suspect is Russia, and it’s not clear if the hackers broke into the secure NSA computer network or, more likely, an NSA employee left the hacking tools on an unsecured intermediate server during a hacking operation.
In a tweet about the event, Edward Snowden, former NSA employee and whistle blower stated, “NSA’s hackers are told not to leave their hack tools (‘binaries’) on the server after an op,” but later stated, “But people get lazy.”
If Russia is indeed responsible as many security researchers believe, it seems they have taken their cyber-attacks to a new level with the recent occurrence pertaining to the hacked emails and stolen documents from the Democratic Party.
How should the US respond?
Republican nominee Donald Trump pleaded directly Wednesday with the Russian government to meddle in the U.S. presidential election by finding and releasing tens of thousands of private emails from his Democratic opponent, Hillary Clinton — an extraordinary and perhaps unprecedented maneuver in American politics.
“Russia, if you’re listening, I hope you’re able to find the 30,000 emails that are missing,” Trump said during a news conference at one of his South Florida resorts. He added later, “They probably have them. I’d like to have them released.”
Asked whether Russian espionage into the former secretary of state’s correspondence would concern him, Trump said, “No, it gives me no pause. If they have them, they have them.”
The emails cited by Trump are from Clinton’s time at the State Department, where her use of a private server prompted a federal investigation. The FBI concluded that no prosecution was necessary.
Read More Here
As the Democratic National Convention continues its week-long stay in Philadelphia, accusations of Russian hacking continue to cloud the proceedings. At this point, it seems likely that Russia is responsible. What’s less clear is what that will mean going forward.
It’s been a bad stretch for the Democratic National Committee. Hackers broke into its servers months ago, stealing private emails, opposition research, and campaign correspondence. Last Friday, Wikileaks made nearly 20,000 of those private emails public, revealing embarrassing details of the political machine’s inner workings. DNC official allege that the Russian government is behind the breach. The New York Times reports that US intelligence agencies increasingly share that opinion. According to a number of top cybersecurity researchers, they’re probably right.
Read more Here
By now, it’s pretty clear that Russian hackers are responsible for breaches of the Democratic National Committee networks that occurred last summer and in April of this year — several forensic security firms have found evidence that traces the breach back to Russia. Now that DNC emails harvested during the breaches are starting to appear on Wikileaks, pundits are speculating that Russia leaked the emails in a bid to land Donald Trump in the Oval Office. But is the email leak also attributable to hackers on Russia’s government payroll?
A new analysis released by security consulting firm ThreatConnect has marshaled more evidence to prove that hackers linked to the Russian government communicated with journalists about the leaked documents.
A hacker set up a website and Twitter account to take credit for the DNC breach soon after it was initially reported, calling himself Guccifer 2.0 (a moniker modeled after a Romanian hacker who is recently pleaded guilty to hacking American political operatives). That claim shed doubt on initial reports from The Washington Post and others that laid the responsibility for the breach squarely at the feet of organizations with ties to the Russian government and its president, Vladimir Putin. But ThreatConnect’s research suggests that Guccifer 2.0 is simply an invention of the Russian government to deflect attention from its involvement in the breach.
Read More Here
By JACK GILLUM and TED BRIDIS
Published: Aug 20, 2015
WASHINGTON (AP) – Hundreds of U.S. government employees – including some with sensitive jobs in the White House, Congress and law enforcement agencies – used Internet connections in their federal offices to access and pay membership fees to the cheating website Ashley Madison, The Associated Press has learned.
The AP traced many of the accounts exposed by hackers back to federal workers. They included at least two assistant U.S. attorneys; an information technology administrator in the Executive Office of the President; a division chief, an investigator and a trial attorney in the Justice Department; a government hacker at the Homeland Security Department and another DHS employee who indicated he worked on a U.S. counterterrorism response team.
Few actually paid for their services with their government email accounts. But AP traced their government Internet connections – logged by the website over five years – and reviewed their credit-card transactions to identify them. They included workers at more than two dozen Obama administration agencies, including the departments of State, Defense, Justice, Energy, Treasury, Transportation and Homeland Security. Others came from House or Senate computer networks.
The AP is not naming the government subscribers it found because they are not elected officials or accused of a crime.
Hackers this week released detailed records on millions of people registered with the website one month after the break-in at Ashley Madison’s parent company, Toronto-based Avid Life Media Inc. The website – whose slogan is, “Life is short. Have an affair” – is marketed to facilitate extramarital affairs.
Many federal customers appeared to use non-government email addresses with handles such as “sexlessmarriage,” ”soontobesingle” or “latinlovers.” Some Justice Department employees appeared to use pre-paid credit cards to help preserve their anonymity but connected to the service from their office computers.
“I was doing some things I shouldn’t have been doing,” a Justice Department investigator told the AP. Asked about the threat of blackmail, the investigator said if prompted he would reveal his actions to his family and employer to prevent it. “I’ve worked too hard all my life to be a victim of blackmail. That wouldn’t happen,” he said. He spoke on condition of anonymity because he was deeply embarrassed and not authorized by the government to speak to reporters using his name.
The AP’s analysis also found hundreds of transactions associated with Department of Defense networks, either at the Pentagon or from armed services connections elsewhere.
Defense Secretary Ash Carter confirmed the Pentagon was looking into the list of people who used military email addresses. Adultery can be a criminal offense under the Uniform Code of Military Justice.
“I’m aware it,” Carter said. “Of course it’s an issue because conduct is very important. And we expect good conduct on the part of our people. … The services are looking into it and as well they should be. Absolutely.”
The AP’s review was the first to reveal that federal workers used their office systems to access the site, based on their Internet Protocol addresses associated with credit card transactions. It focused on searching for government employees in especially sensitive positions who could perhaps become blackmail targets. The government hacker at the Homeland Security Department, who did not respond to phone or email messages, included photographs of his wife and infant son on his Facebook page.
One assistant U.S. attorney declined through a spokesman to speak to the AP, and another did not return phone or email messages.
A White House spokesman said Thursday he could not immediately comment on the matter. The IT administrator in the White House did not return email messages.
Federal policies vary for employees by agency as to whether they would be permitted during work hours to use websites like Ashley Madison, which could fall under the same category as dating websites. But it raises questions about what personal business is acceptable – and what websites are OK to visit – for government workers on taxpayer time, especially employees who could face blackmail.
The Homeland Security Department rules for use of work computers say the devices should be used for only for official purposes, though “limited personal use is authorized as long as this use does not interfere with official duties or cause degradation of network services.” Employees are barred from using government computers to access “inappropriate sites” including those that are “obscene, hateful, harmful, malicious, hostile, threatening, abusive, vulgar, defamatory, profane, or racially, sexually, or ethnically objectionable.”
The hackers who took credit for the break-in had accused the website’s owners of deceit and incompetence, and said the company refused to bow to their demands to close the site. Avid Life released a statement calling the hackers criminals. It added that law enforcement in both the U.S. and Canada is investigating and declined comment beyond its statement Tuesday that it was investigating the hackers’ claims.
___
Associated Press writers Alicia Caldwell and Lolita C. Baldor in Washington and Raphael Satter in London contributed to this report.
___
Follow Jack Gillum on Twitter at https://twitter.com/jackgillum and Ted Bridis at https://twitter.com/tbridis
