Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Saturday, October 08, 2022

Uber’s Chief Security Officer Convicted: A Cyber Teaching Moment

Joseph Sullivan, the former Chief Security Officer of Uber Technologies, Inc. (“Uber”), was convicted on Wednesday October 5, 2022 on charges of covering up data breach.  According to court records Sullivan’s wad involved in two separate hacks of Uber’s databases.  While Sullivan was hired as Uber’s Chief Security Officer (“CSO”) in April 2015 he was involved in two hacks: one in 2014 and another in 2016.  When Sullivan was hired, Uber disclosed to the FTC that it had been the victim of a data breach in 2014 and that the breach was related to the unauthorized access of approximately 50,000 consumers’ personal information, including their names and driver’s license numbers.

In May 2015, the month after Sullivan was hired, the FTC served a detailed Civil Investigative Demand on Uber demanding  extensive information about any other instances of unauthorized access to user personal information, and information regarding Uber’s broader data security program and practices.  In his new role as CSO, Sullivan supervised Uber’s responses to the FTC’s questions, participated in a presentation to the FTC in March 2016, and testified under oath, at length, to the FTC on November 4, 2016, regarding Uber’s data security practices. Sullivan’s testimony included specific representations about steps he claimed Uber had taken to keep customer data secure. 




Ten days after his FTC testimony, Sullivan learned that Uber had been hacked again. The hackers reached out to Sullivan directly, via email, on November 14, 2016. The hackers informed Sullivan and others at Uber that they had stolen a significant amount of Uber user data, and they demanded a large ransom payment from Uber in exchange for their deletion of that data. Employees working for Sullivan verified the accuracy of these claims and the massive theft of user data, which included records on approximately 57 million Uber users and 600,000 driver license numbers.

After learning the extent of the 2016 breach and rather than reporting it to the FTC, any other authorities,, Sullivan told a subordinate that they “can’t let this get out,” instructed them that the information needed to be “tightly controlled,” and that the story outside of the security group was to be that “this investigation does not exist.” Sullivan then arranged to pay off the hackers in exchange for them signing non-disclosure agreements in which the hackers promised not to reveal the hack to anyone, and also contained the false representation that the hackers did not take or store any data in their hack. Uber paid the hackers $100,000 in bitcoin in December 2016, despite the fact that the hackers had refused to provide their true names. Uber was ultimately able to identify the two hackers in January of 2017 and required them to execute new copies of the non-disclosure agreements in their true names and emphasized that they were not allowed to talk about the hack to anyone else. Sullivan orchestrated these acts despite knowing that the hackers were hacking and extorting other companies as well as Uber, and that the hackers had obtained data from at least some of those other companies.




Despite knowing that Uber had suffered another data breach directly responsive to the FTC’s inquiry, Sullivan continued to work with the Uber lawyers handling or overseeing that inquiry, including the General Counsel of Uber, and never mentioned the incident to them. Instead, he touted the work that he and his team had done on data security. Uber ultimately entered into a preliminary settlement with the FTC in summer 2016, supported fully by Sullivan, without disclosing the 2016 data breach to the FTC.

In Fall 2017, Uber’s new management began investigating facts surrounding the 2016 data breach. At the time Sullivan lied, falsely telling the new CEO that the hackers had only been paid after they were identified and deleting from a draft summary prepared by one of his reports that the hack had involved personally identifying information and a very large quantity of user data. Sullivan lied again to Uber’s outside lawyers conducting an investigation into the incident. Nonetheless, the truth about the breach was ultimately discovered by Uber’s new management, which disclosed the breach publicly, and to the FTC, in November 2017. 

In finding Sullivan guilty, the jury concluded he obstructed justice, and that he knew that a federal felony had been committed and took affirmative steps to conceal that felony.

 

A Teaching Moment. I often argue that a security professional’s worse nightmare is the Inside Threat:  Insiders with motive have Motive, Means and Opportunity (MOM) to commit a crime.  In Sullivan’s case, the Inside Threat is a second order effect and not too bright:  He brought his subordinates on board with not visible incentive, other than the implicit threat of being fired. Yesterday, the FBI Boston Office released a “Trust In Me public service announcement. During the announcement, Joseph R. Bonavolonta, Special Agent in Charge of the FBI Boston Division said “The first step towards protecting yourself from cyber incidents is to develop a relationship with the FBI. Doing so enables you to identify who to call in the event you do suffer a cyber incident, granting quick and efficient access to our rich network of resources. Cybersecurity is national security, and by working together and reporting these incidents to us, you are working to help prevent these bad actors from victimizing others, and potentially from re-victimizing you.”  I disagreed with Mr. Bonavolonta then and now.  With all due respect to Special Agent Joseph R. Bonavolonta, the first step towards protecting yourself from cyber incidents is not to develop a relationship with the FBI.  While a relationship with the FBI is important, given the trust and competency issues: . For example, The FBI’s Cyber Guardian system “rather than a beacon of trust, as the moniker implies, an audit report from the Justice Department’s internal watchdog paints a picture of a guardian that is not dependable, given to simple errors and late with needed information.”    The FBI’s email servers was previously  hacked, resulting in spam emails being sent to the public that appeared to be from the agency and the Department of Homeland Security.  Instead, we first recommend a review of the $1.00 fence for the $1,000 horse.  There are two types of businesses;  Those who know they have been victims of security breaches and those that don’t.  Why it is important to identify and prioritize the stored information aka as intellectual property.  We also suggest a paradigm change:  The higher the trust level in your computer, the least trust.  The people you trust the most, are the most dangerous.  This is known as the Inside Threat, which we have been preaching for years, but the FBI often leaves out: In remarks prepared April 27, 2022 for delivery to the Domestic Security Alliance Council, FBI Director Christopher Wray finally referred to the Inside Threat and  made it clear the counterintelligence threat posed by China is top of mind and " nothing presents a broader, more severe threat to our ideas, our innovation, and our economic security than the People’s Republic of China.". 

 

 Number three, develop a relationship with the FBI.  In the Uber case, bringing in Mr. Sullivan to Uber at the highest level of trust, management should have treated him with the least trust. The accounting issue should have been a big red flag for management as Uber paid the hackers $100,000 in bitcoin in December 2016.  Who signed off on the payment?  Where were the lawyers.

 

 

 

 

Wednesday, July 20, 2022

Bulletproof Hosting Service Cybercriminal "Virus" Extradited

 Mihai Ionut Paunescu, a Romanian National known as “Virus” was extradited for operating “Bulletproof Hosting” service that facilitated the distribution of destructive malware.  Bulletproof hosting operations are similar to regular web hosting. Bulletproof hosting services are often found in countries with more relaxed laws about what type content is hosted on these servers, and also have less strict extradition laws, therefore making it easier to evade law enforcement. Due to the different laws in different countries, this creates a huge grey area that allow the owners to claim immunity to what their customers host. Bulletproof Hosting is the technology behind of malware, ransomware, botnets, and the like. 




A lot of the owners of these facilities take the approach that they are just a service for customers. Many of these hosting servers have massive amounts on data on them, and it can be very difficult to track every move each customer makes. John Karlung of Banhoff Hosting states that his service is like the postal service—“a mailman doesn’t read the mail, he just delivers it.” He claims that his hosting is a legitimate law abiding service, and that any nefarious activity lies with his customers. He is also an advocate for privacy for his customers, and requires a formal warrant to remove any of his servers.

However, the DOJ and FBI announced today that  Mihai Ionut Paunescu, a/k/a “Virus,” a dual Romanian and Latvian national, was extradited from Colombia for running a bulletproof hosting service that enabled cyber criminals to distribute the Gozi Virus, one of the most financially destructive computer viruses in history.  It is also alleged that Paunescu  enabled other cybercrimes, such as distributing malware including the “Zeus Trojan” and the “SpyEye Trojan,” initiating and executing distributed denial of service (“DDoS”) attacks, and transmitting spam.  Paunescu was initially arrested in Romania in December 2012 and released on bail, and he was arrested again in Colombia last year at the request of the United States.  Paunescu was presented yesterday before U.S. Magistrate Judge Gabriel W. Gorenstein and detained.  The case is assigned to U.S. District Judge Lorna G. Schofield.

The Gozi Virus is malicious computer code or malware.that stole personal bank account information, including usernames and passwords, from the users of affected computers. The Gozi Virus infected over one million victim computers worldwide, among them at least 40,000 computers in the United States, including computers belonging to the National Aeronautics and Space Administration (“NASA”), as well as computers in Germany, Great Britain, Poland, France, Finland, Italy, Turkey and elsewhere, and it caused tens of millions of dollars in losses to the individuals, businesses, and government entities whose computers were infected.  Once installed, the Gozi Virus – which was intentionally designed to be undetectable by anti-virus software – collected data from the infected computer in order to capture personal bank account information, including usernames and passwords.  That data was then transmitted to various computer servers controlled by the cyber criminals who used the Gozi Virus.  These cyber criminals then used the personal bank account information to transfer funds out of the victims’ bank accounts and ultimately into their own personal possession.

The Zeus Trojan is an insidious malware kit commonly used to steal banking information. With millions of Windows computers infected, it’s one of the most widespread and successful strains of malware in the history of the internet

SpyEye is a malware program that attacks users running Google Chrome, Opera, Firefox and Internet Explorer on Microsoft Windows operating systems. This malware uses keystroke logging and form grabbing to steal user credentials for malicious us

Paunescu, 37, of Bucharest, Romania, is charged with one count of conspiracy to commit computer intrusion, which carries a maximum penalty of 10 years in prison; one count of conspiracy to commit bank fraud, which carries a maximum penalty of 30 years in prison; and one count of conspiracy to commit wire fraud, which carries a maximum penalty of 20 years in prison. This case is being handled by the Office’s Complex Frauds & Cybercrime Unit.  Assistant United States Attorney Sarah Lai is in charge of the prosecution.


Wednesday, May 18, 2016

Ransomware and what to do about it – Digital Hygiene

Deputy Assistant Attorney General Richard Downing Testifies before Senate Judiciary Committee at Hearing Entitled “Ransomware: Understanding the Threat and Exploring Solutions”


Posted by CotoBlogzz





Testimony as prepared for delivery
Good afternoon Chairman [Lindsey] Graham, Ranking Member [Sheldon] Whitehouse and members of the subcommittee.  Thank you for the opportunity to discuss the Department of Justice’s response to the ransomware threat.  I want to thank the chair and ranking member for their continued leadership on the issues of cybersecurity and fighting cybercrime.  We appreciate your work to ensure that the Department of Justice has the tools and resources necessary to address cyber threats.
The Attorney General has repeatedly made clear that fighting cybercrime is one of the department’s highest priorities.  Cyber threats continue to grow more prevalent, more sophisticated and more destructive.  As was described in your opening statements, one threat has been particularly troubling: the rise of ransomware.  And because some ransomware variants can infect other computers, a single person opening an email or visiting an infected website can result in the network of an entire organization being held hostage.
The threat from ransomware is staggering.  One ransomware scheme extorted an estimated $27 million in just its first two months.  While ransom fees are typically between $200 and $10,000, victims suffer additional harms due to things like lost productivity and the cost of mitigation.   
The growth in ransomware is fueled by many factors.  Our computers are still more vulnerable that we would like.  And advances in technology – such as anonymizing proxy networks and bitcoin – offer even average criminals highly sophisticated tools to avoid detection. 
Despite these challenges, law enforcement is actively working to disrupt and deter ransomware schemes.  The FBI currently has dozens of active investigations into different ransomware variants.  And this hard work has paid off.  In 2014, for example, the Department of Justice led a multi-nation effort that disrupted a highly sophisticated ransomware scheme called Cryptolocker, which had encrypted computer files on more than 260,000 computers. 
Defeating ransomware schemes, however, requires a strategy that encourages the public and private sectors to work together.  Computer owners everywhere need to improve their “digital hygiene” by taking steps like installing the latest patches and ensuring that backups are up to date.  The department has tried to assist in raising awareness by issuing public service announcements about the dangers of ransomware, and which provide tips on how to protect systems and respond to malware infections. 
In addition, we must work to disrupt the means used to distribute and profit from ransomware.  Like other malicious software, ransomware is often facilitated by botnets.  As you may know, botnets are networks of computers infected with malware, or “bots,” that criminals can control remotely to do their bidding.  They allow small groups of criminals to use hundreds – or hundreds of thousands – of infected computers to attack other victims.  As botnets grow more sophisticated, and as the threat from botnets continues to evolve, we must continually strive to ensure that our laws remain up to date and provide law enforcement with the tools and authorities it needs to address this threat. 
Congress has a significant role to play.  The Computer Fraud and Abuse Act (or CFAA) clearly makes it a crime to hack into computers to create a botnet, and of course we could bring charges against criminals who use botnets to commit other crimes.  It is not clear, however, that the CFAA also criminalizes selling or renting access to botnets, which is increasingly common among cybercriminals.  We support closing this loophole. 
In addition, federal law currently provides courts with authority to issue civil injunctions to disrupt botnets – but only if the botnet is being used to commit certain specific categories of crime.  Yet botnets are used for many types of criminal activity, such as denial of service attacks and sending phishing emails.  The administration has proposed updating the law to allow courts to issue civil injunctions to stop botnets no matter what the criminals are using them for.
While use of civil injunctions is a valuable tool, there may be circumstances in which it is preferable to seek a warrant from a court in order to disrupt a botnet.  Because of this, the department supports the Supreme Court’s recent action to amend Rule 41 of the Federal Rule of Criminal Procedure to clarify which court is the right court to consider warrant applications.  While this amendment would not change the substantive authority to authorize such a warrant, it would eliminate needless inefficiency in the process for applying for this sort of warrant.   

Thank you again for the opportunity to testify today on this important issue, and I look forward to answering your questions.