Friday, 2 August 2019
HACKERS ATTACK LOS ANGELES POLICE DEPARTMENT; THOUSANDS OF OFFICERS ARE BLACKMAILED USING THEIR PERSONAL DATA
ORIGINAL CONTENT: https://www.securitynewspaper.com/2019/07/30/hackers-attack-los-angeles-police-department-thousands-of-officers-are-blackmailed-using-their-personal-data/
Cybersecurity incidents keep happening in various public departments in multiple areas of the United States. This time, vulnerability analysis specialists report a data breach in Los Angeles Police Department (LAPD) systems. The incident would have compromised some personal details, such as full names, phones, email addresses, and passwords stored by the agency.
According to reports, the personal information of about 2,500 active officers and about 17,500 applicants to join the corporation were exposed during the incident, detected just a few days ago. Hackers even accessed the records of the LAPD applications status.
Through a statement, the department confirmed the data breach and stated that it has already begun work on containment and recovery of the incident. “We have notified directly to all potentially affected officers and applicants; we will continue to provide updates to the incident as they become available.”
“Everyone at LAPD is constantly working to understand everything related to this incident. We will also be implementing the relevant measures to ensure the security of all information held by the corporation. At LAPD we are fully committed to protecting the privacy of anyone associated with this agency,” the LAPD statement adds.
On the other hand, Mayor Eric Garcetti’s office confirmed that “the incident occurred in a database that was no longer used by LAPD since long time ago, so the compromised information is outdated and limited.”
According to vulnerability analysis specialists, how the data breach was conducted has not yet been determined; similarly, the appearance of compromised records in dark web forums or the like has not been reported. The exact time the information remained exposed online is also unknown.
The Los Angeles police union trade stated that those affected should be protected against any variables of identity fraud, and the city’s vulnerability analysis experts will have to implement the necessary measures to prevent a similar incident occur again.
Experts in vulnerability analysis from the International Institute of Cyber Security (IICS) mention that data breaches that compromise information from members of law enforcement agencies are particularly concerning cases, as affected are exposed to highly targeted phishing attacks that could help hackers to further access LAPD sensitive information.
The frequency with which cyberattacks occur in public institutions in the U.S. has concerned authorities and members of the cybersecurity community. A couple of months ago a ransomware outbreak began affecting operations and services in local governments in some cities in Florida, New York, among other states. In addition, the Louisiana government recently issued a state level cybersecurity alert regarding a malware infection in the systems of dozens of schools. A verifiable link has not yet been found between all these incidents, however, the U.S. authorities aren’t ruling out any possibility.
100 MILLION CAPITAL ONE CUSTOMERS HACKED BY THIS GIRL
ORIGINAL CONTENT: https://www.securitynewspaper.com/2019/07/30/100-million-capital-one-customers-hacked-by-this-girl/
Although legislation in various parts of the world has become much tighter on the protection of confidential information, multiple companies remain highly vulnerable to data breach incidents, affecting millions of users, as reported by experts in ethical hacking.
This time the turn is for the renowned bank Capital One; according to reports, a hacker managed to access the records of more than 100 million accounts of the bank’s customers and users of the company’s app, making this incident one of the largest data breaches ever.
The bank has accused Paige Thompson, a former IT engineer. According to the U.S. Department of Justice (DOJ), Thompson accessed a bank server and compromised about 1 million Social Security numbers from Canadian citizens and about 140k of U.S. residents, plus 80k bank account numbers and one undetermined number of full names, addresses, credit histories, and other confidential details of Capital One customers.
The incident affected more than 6 million Capital One customers in Canada and 100k users in the U.S. However, the bank ensures that your customers’ login credentials and credit card numbers are secured.
According to ethical hacking specialists close to the case, the bank filed a complaint against Thompson arguing that the defendant planned to share the information with other unidentified actors online. Previously, the 33-year-old had collaborated as a software engineer on Amazon Web Services, which provides cloud hosting services to the bank. Capital One maintains that Thompson entered the server by exploiting a misconfigured firewall deployment. Finally, U.S. authorities arrested Thompson last Monday; so far the defense has made no comment.
According to the bank’s ethical hacking staff, the attack occurred sometime between March 22 and 23 and the compromised records date back to 2005. Capital One added that the vulnerability in its systems has already been corrected and assured that the likelihood of the information being used for malicious purposes is low, as the person responsible was stopped before she could sell the stolen data. “We apologize for the inconvenience this has caused, activity on our systems will be restored shortly,” said Richard Fairbank, CEO of Capital One.
According to ethical hacking specialists from the International Cyber Security Institute (IICS), the defendant would have posted the stolen information on GitHub using her full name, in addition, through her social media profiles, claiming to have access to millions of company records.
In addition, Thompson used a channel from the corporate chat service Slack to explain the method used to access the bank’s servers. “The defendant claims to have put in place a special command to extract the company files stored on Amazon Web Services,” the DOJ said.
The defendant made no attempt to conceal her identity; According to the reports, she identified herself in Slack using the nickname “erratic”, which was the same name that Thompson used on her Twitter account and on other platforms, such as the Meetup chat service. After the information was posted on GitHub, a user informed Capital One, which in turn reported the incident to the FBI, which accomplished Thompson’s apprehension, who has allegedly acknowledged that she acted for malicious purposes.









