August 2024 News & Tips | Cybersecurity News Roundup

August 2024 News & Tips | Cybersecurity News Roundup
View this email in your browser
Welcome back to the TCE Strategy monthly technology and cybersecurity newsletter! The mission of this publication is to cut through the clutter of cybersecurity news stories and provide you with the most important, relevant and actionable cybersecurity information.

If this newsletter adds value, fantastic! That is the goal. Please forward it on to friends/colleagues. If not, no hard feelings. Please look to the bottom for an easy to click "unsubscribe" button.
Subscribe
In this issue:
Month's News in Review
Upcoming Speaking Events
Must Read Articles This Month
Cybersecurity Tip of the Month
Enjoy this month's newsletter? You can use this link to post on social media or send to friends! Thanks for sharing!
This Month's News in Review

Welcome back to the monthly TCE Strategy newsletter! It has been a BUSY month in the world of cybersecurity. From General Motors to Microsoft to Cencora, we have a lot to cover. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.

GM didn’t learn the first time around

I wrote in the April and May TCE Strategy newsletters that General Motors got caught selling the driving habits of their customers without their consent. Well, apparently that wasn’t enough for them to get the message, as the Texas Attorney General has filed a lawsuit alleging that GM is engaging in “false, deceptive and misleading” business practices where GM is selling consumer’s driving habits without their knowledge or consent. This is my favorite quote from the Texas AG: “Millions of American drivers wanted to buy a car, not a comprehensive surveillance system that unlawfully records information about every drive they take and sells their data to any company willing to pay for it". Yes. That.

Takeaway: As long as it isn’t illegal, for-profit companies will do anything within their power to make money. Sometimes they do illegal things to make money. I feel that citizens have a fundamental right to privacy. The USA founding fathers did as well, as the 4th and 14th amendments of the Constitution demonstrate. We need to vote for politicians that put citizens’ rights above corporate interests, if such purple squirrels exist.

ALL of our social security numbers have been hacked

A cybercriminal group calling themselves USDoD has claimed to have hacked a company called National Public Data and stolen, well, all of their data. A total of 2.7 billion individual records were stolen from the UK, Canada and the USA, which far outweighs the number of people that have ever lived in those countries, which means the multiple records were likely stolen on every person, living and deceased, that have ever resided in those countries. As bad as this sounds, to be honest, it’s likely a repeat for most people. From the Equifax breach of 2017 to countless other breaches, all of our information is already out there for cybercriminals to purchase. This is a big deal and my good friend Sam Richter did an excellent write-up on it. He is right that this is a giant, unprecedented breach, and it will be very interesting to see if National Public Data will be held to account for it. However, I’m not sure that it exposes us to much additional risk, as most of us had our personal data stolen long ago. 

Takeaway: Freeze your credit with all three major credit reporting agencies, as described in the “Cybersecurity Tip of the Month” section. Recognize that for a few dollars, anyone can purchase details on your social security number, your date of birth, your mother’s maiden name, and so on. You need to assume that criminals will pretend to be you to take out loans or open credit cards. Protect your credit by freezing it.

Cencora likely pays the largest ransomware payment in history

Up until this month, the $40MM payment by CNA Financial in 2019 was the largest known ransomware payment in history. That payment was recently upstaged by a “Fortune 50 company” that made a $75MM payment to the DarkAngels ransomware gang. Cencora is the only Fortune 50 company that has made an SEC filing recently about a cybersecurity incident where no cybercriminal group has claimed responsibility. It doesn’t take a genius to put 2 and 2 together.

Takeaway: Ransomware is a preventable crime. If a Fortune 50 company falls victim to ransomware, it means that their cybersecurity department was underfunded (or grossly incompetent). In my experience, the former is dramatically more likely than the latter. Boards of Directors need to fund reasonable defenses against cybercriminals.

$60MM Wire Fraud

$60 million dollars is a lot of money. If a cybercriminal convinces someone to send $60MM their way, it’s a life-changing amount of money for them. That appears to be the case for an unnamed cybercriminal that convinced Luxembourg-based chemicals and manufacturing company Orion SA to send them a $60MM payment instead of its intended recipient. This was a process and procedure failure of the highest order.

Takeaway: If performing a wire transfer, PICK UP THE PHONE and guarantee that the transaction instructions are valid. Ask questions of the person on the other end that only he/she would know. If there is any doubt in your mind, check again. Get on a plane. A $10k ticket will buy you a first-class plane ticket to anywhere. Is it worth $10k to protect $60 million?

Macs need antivirus too!

I have received several questions over the years about Macs vs Windows and how important antivirus is on both platforms. There is no question that Windows operating systems are targeted more often than Macs, but that’s simply an issue of economy of scale – far more Windows OS computers exist than Macs, and cybercriminals are looking for easy money, so Windows machines look more attractive than Macs. Some cybercriminals are smart enough to take the road less traveled, and they produce malware specifically for Macs, such as this one called “BANSHEE Stealer”

Takeaway: Invest in a strong antivirus program for all of your computers: Windows, Mac and Linux alike.

Elections bring nation-state level hackers like moths to a flame

We know of lots and lots of examples of USA election interference from foreign nations. This is expected behavior. The 2024 election is no different. Interestingly, Iran has been confirmed by a number of news sources to have hacked the Trump campaign. It would not surprise me at all if the Harris campaign announces a breach in the near future, although I hope they have already readied themselves for nation-state level attacks.

Takeaway: When running for a national election, it must be assumed that other nations will push for a candidate favorable to their interests. A “push” will take any/all forms possible. In today’s world, cybersecurity is a powerful push. Without a proactive defense, a breach is ensured.

Patch Windows!

Monthly Windows operating system updates are always important. August’s updates are especially so, as six actively exploited vulnerabilities are patched by this month’s updates. Please set your Windows computers to auto-update, and be sure to reboot at least once a week.

Digital data is the new gold

Finally, when a gold mine suffers a ransomware attack, it is the ultimate in irony about our move from a physical to a digital world. https://therecord.media/evolution-mining-gold-ransomware-incident. Wow. Just, wow.

Until next month, stay safe!

Upcoming Speaking Events

 
Here is a list of the cities that I will be in over the next few months. Please reach out if you have an event in mind!

August 26-29, Warrens, WI

August 30th-September 2nd, Eau Galle, WI

September 10-11, Tallahassee, FL

October 7-8, Brainerd, MN

October 9-11, Cheyenne, WY

October 15-17, Ponte Vedra Beach, FL

December 2-6, Key West, FL

April 15-18, 2025, Las Vegas, NV

Interesting Articles

The healthcare sector is being specifically targeted by cybercriminals. When ERs can't get the blood they need to treat patients, we have a life safety situation. Ransomware defenses are all about Cybersecurity 101 basics + offline backups. It's just that easy.
So the company that is supposed to keep your home safe just lost customer info to cybercriminals. This feels like a story that a middle-school English student made up to illustrate the definition of irony.
 
Cybersecurity Tip of the Month

Credit Freezes
 
With the recent list of data breaches potentially exposing your personal data, now is the time for a refresher on freezing your credit. Concerned about someone taking out a credit card or loan in your name? It’s a very reasonable concern, and since the Equifax breach in 2017, it’s one that you can largely avoid by placing a credit freeze on your information with the companies that handle this data. The three largest are Experian, TransUnion and Equifax. It is now free to freeze and unfreeze your credit (they used to charge for this “privilege” of keeping yourself safe, similar to how phone companies used to charge for not publishing your name in the phone book. Pure robbery.)

There are a few reasons to not freeze your credit. It’s inconvenient to unfreeze it when you really do need a new loan or credit card. Credit checks also occur in unusual places, such as changing cell phone providers or moving utilities (water, power, natural gas, etc.) into your name. That being said, I think it’s the right thing to do for most people, especially now that it’s free to freeze and unfreeze it.

To freeze your credit, you must contact each of the three major consumer credit bureaus (Equifax, Experian and TransUnion) and request a credit freeze. You will need to provide your name, address, birth date, and Social Security number. After answering a few identity verification questions, you will receive a PIN that can be used to unfreeze and refreeze your credit report. Credit freezes are required by federal law to be offered for free by all three credit bureaus.

Equifax: Visit 
https://www.equifax.com/personal/credit-report-services/ or call 1-888-378-4329.

Experian: Visit 
https://www.experian.com/freeze/center.html or call 1-888-EXPERIAN (1-888-397-3742).

TransUnion: Visit 
https://www.transunion.com/credit-freeze or call 1-800-916-8800.
LinkedIn
Twitter
Facebook
Website
Forward Forward
We want your feedback!

< On a scale of 10, how helpful was this newsletter?>

lowest 1   2   3   4   5   6   7   8   9   10   highest

Copyright © 2024 TCE Strategy, All rights reserved.
You are receiving this email because you are on Bryce Austin's contact list

Our mailing address is:
TCE Strategy
18268 Java Trl
Lakeville, MN 55044

Add us to your address book


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list

You can reach Bryce at bryce@bryceaustin.com

Email Marketing Powered by Mailchimp
Subscribe to Newsletter

Browse newsletter archives: