|
Welcome back to the monthly TCE Strategy newsletter! From a BBC reporter being recruited by a cybercriminal gang to 11 death sentences for leaders of a scam center in Myanmar to Windows 10 support coming to an end, October has given us a lot to review. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.
11 cybercriminal leaders sentenced to death, 12 others jailed for 5+ years
Myanmar, Laos and Cambodia have become hotbeds of organized cybercriminal activity, with a total annual revenue of $40 billion USD. The crimes these groups focus on are not the usual ransomware attacks that make so much press, but rather in wire transfer fraud, fake technical support scams, and “pig butchering”, where cybercriminals start fake investment scams, often by luring in victims via online romance relationships. In a rather shocking takedown, the Chinese government collaborated with Myanmar and Thailand to shut down some very large centers that were running these scams, often with workers being forced to run these rackets against their will. A total of 7000 workers (which appear to be prisoners of the cybercriminal ringleaders in this case) were freed, and 11 leaders were sentenced to death. 12 other leaders received prison sentences ranging from 5 to 24 years.
Takeaway: The business model of these organized crime gangs is extremely strong. This appears to be a win for the good guys, but until people become more aware of these scams (so they don’t fall for them), this is going to be a game of whack-a-mole as other centers open up elsewhere. If your computer sends you an alert stating that you have been infected by a virus and need to call a phone number to get help, it’s a scam. If you get unsolicited connection requests from social media, they are often scammers. If you get a call from your local sheriff’s office, hang up and find the correct number online to call them back to verify it’s not a scam. NEVER invest money with someone you haven’t met face-to-face (unless they are with a very well-known investment company such as Vanguard). Scammers will take everything you have if you let them.
BBC reporter recruited by a cybercriminal gang
I don’t know if this falls under the category of brazen or foolish cybercriminal activity, or maybe it’s somewhere in between. A few weeks ago, a BBC reporter named Joe Tidy received a Signal message from someone claiming to be from the ransomware gang called Medusa, stating, "If you are interested, we can offer you 15% of any ransom payment if you give us access to your PC." He then upped his offer, stating "We aren't sure how much the BBC pays you but what if you took 25% of the final negotiation as we extract 1% of the BBC's total revenue? You wouldn't need to work ever again." Getting a foothold into an organization is a strong first step in committing a ransomware attack. Apparently the BBC has very strong cybersecurity best practices, as this is an extremely generous offer for an employee’s credentials that isn’t an IT person with “domain administrator” access. After Tidy refused the offer, he began getting hundreds of requests to reset his password, which is a technique that cybercriminals use called MFA bombing. He was smart enough not to fall for it, and to involve his IT team to help put additional protections on his account.
Takeaway: This reporter was asked to do something illegal, and if he had chosen to live the rest of his life in a country that doesn’t extradite suspected criminals to the UK, he may (or may not) have received enough money to be comfortable for the rest of his life. It is important to educate your employees on these sorts of scams, and how they should reach out to your cybersecurity team in the event that they are targeted with this type of proposal.
Windows 10 comes to an end
Windows 10 has been a terrific operating system, but Microsoft has formally deemed it end-of-life as of October 14th. This has very serious repercussions for business and home users alike. Every month, Microsoft releases patches to fix vulnerabilities in Windows. Sometimes these are just “best practice” to install, but other times (such as this month), they fix vulnerabilities that are being actively exploited on the Internet. Windows 10 will no longer receive updates unless organizations pay for them. Individual users have a one-year reprieve if they enroll into a free one-year extension program that Microsoft recently announced (previously they stated that individual users would have to pay for updates just like larger companies, but they backtracked on this). Your options are as follows:
-
Update your computer to Windows 11.
-
If your computer can’t run Windows 11, purchase a new one.
-
Sign up for Microsoft’s one-year extended support.
-
Pay Microsoft for updates.
None of these options are terrific, as there isn’t a compelling reason to abandon Windows 10 other than the artificial end-of-life decision made by Microsoft. That being said, it is hard to keep older operating systems safe, as the risks on the Internet continue to evolve.
Takeaway: If you have a Windows 10 computer, it is time to find a path forward using one of the four options above. Doing nothing is a recipe for a cybercriminal to take advantage of you.
Update to the Jaguar Land Rover cyberattack
Last month, this newsletter covered the massive cyberattack that has disrupted Jaguar Land Rover operations in several of their manufacturing facilities. How is their recovery going? Not a lot of data is coming out about it, but the UK government gave them a loan of £1.5 billion ($2 Billion USD), which suggests that they have had a devastating hit from this breach.
Takeaway: Reactive cybersecurity is expensive. Very, very expensive. Proactive cybersecurity measures to prevent these sorts of breaches from taking place are much less costly. You can’t put your seatbelt on after the car accident and have it do any good. Ransomware is a preventable crime, and it’s all about the basics. Strong passwords. Multi-factor authentication. System patching. Annual penetration tests. It isn’tnhard to do, but sometimes it is hard to make time for. Imagine how much time is being sucked up at Jaguar Land Rover because of their breach.
Finally, I’d like to give a shout-out to my colleague and fellow professional speaker, Jamie Champagne from Honolulu, HI. She has written a terrific book called The Business Analyst’s Career Master Plan, available on Amazon or at Packt. I found it very informative and recommend you check it out.
Until next month, stay safe!
|