Thomas Cook Customers and Employees Targeted By Phishing Attacks
Security researchers at Skurio Ltd have warned employees and customers of Thomas Cook to be vigilant after it detected the registration of 53 Thomas Cook-related domains in the week after the travel operator went into receivership.
Phishing Risk
The risk is that cyber-criminals may be seeking to exploit a search for information from customers and staff affected by the company’s collapse to launch phishing attacks. For example, Thomas Cook-related domains that have been registered but don’t have a holding page or landing-page on them could be used to create a legitimate-looking email address as part of phishing attempts.
German Site
One of the Skurio analysts, John Evans, reported finding a .de Thomas Cook-related domain that hosted a page that pretended to be a legitimate business, but was using the Thomas Cook likeness to make money from customer refund claims.
25% Just Piggybacking
The Skurio researchers found that 25% of the domains registered appeared to be just simply piggybacking off the collapse of Thomas Cook, and were using their domains to simply redirect to other websites.
Holding Pages + Advert Clicks
The researchers discovered that 50% of the recently registered domains had holding pages for websites on platforms like Wix or WordPress (awaiting a full live site). Some other domains were discovered to be used for ad clicks and ad revenue e.g. with adverts for booking a new holiday or finding jobs for Thomas Cook employees.
Thomas Cook Contracted Skurio
Skurio were monitoring the Thomas Cook-related domain situation because (as reported by Skurio) Thomas Cook, had contracted Skurio, long before its collapse, to monitor surface, deep and Dark Web sources in order to provide early data breach detection services. It was as part this service Skurio was scanning for new domain registrations relating to Thomas Cook services. According to Scurio, this scanning involved looking for domains set up with subtle spelling errors or additional terms that a customer may expect to see, in order send phishing emails, create fake social media accounts or capture customer details online.
What Does This Mean For Your Business?
It is not uncommon for cyber-criminals to launch campaigns to take advantage of a popular information search by customers after events such as a high-profile security breach or company collapse. This is because people may let their guard down and may simply not suspect such an underhand tactic, which is the kind of human error based on emotion that cyber-criminals are counting on.
Phishing attacks are all-too-common, and a recent APWG report showed that phishing attacks continued to rise in summer of 2019, with cyber-criminals focusing branded webmail and SaaS providers.
Companies can help guard against phishing attacks by educating and training all staff to be able to spot possible fraudulent tactics, and by encouraging and empowering them to question and refer any suspicious activity that could help to protect the business. Having clear systems for staff to follow, including carefully verifying any new payment requests before authorising them, and continuously promoting online vigilance can be well worth the effort in the fight against phishing, and the generally increasing number of social engineering attacks that companies are facing.
Tech Tip – Twobird
New email client app ‘Twobird’ allows you to put all your emails in one place and create notes and reminders on the fly (and attaches the notes on emails).
Twobird has been billed as “a new kind of email app” that offers email at the speed of live chat. It includes all your everyday tools – writes emails, creates notes, set reminders and assign to-dos — all in your inbox. If, for example, if you’ve scheduled an appointment it will alert you at just the right time.
Features include:
– Remind: allowing you to schedule an email or note to appear in your inbox later.
– Low Priority: so you can set aside automated messages so you don’t get distracted.
– Pinned and Recent: this lets you keep important notes and conversations easily accessible.
– Tidy Up: archives any inactive conversations
Police Auction Hacker’s £240,000 of Cryptocurrency
The £240,000 of cryptocurrency confiscated from a teenager who was jailed for hacking ISP TalkTalk has been auctioned by police with the proceeds going towards fighting crime.
TalkTalk Hack
Elliott Gunton, (now 19) was jailed for 20 months in August this year for hacking offences, money laundering and for the breach of a Sexual Harm Prevention Order that was issued to him in 2016 for another offence. The hack on ISP TalkTalk took place when Gunton was 16 years old, and he is reported to have sold the stolen customer data on the dark web to other cybercriminals for £2,469 in bitcoin.
The total amount that police were able to trace that was raised by sales of the stolen data was around £275,000 worth of cryptocurrency, including Bitcoin Ripple and Ethereum.
Hidden
Mr Gunton is reported to have used sophisticated methods to hide the large amount of cryptocurrency under his control but left several key clues which led to his arrest. These included describing himself on a Twitter account as a “full-time crypto trader”, tweeting about how he had lots of money without people knowing, and telling a police officer that he was dealing in shares and would soon be a millionaire.
Parents
Mr Gunton’s parents were also charged (at a later date) with helping their son to move some of his cryptocurrency, earned from dark web sales, out of a seized police-bitcoin wallet.
Auction First
The auction of the cryptocurrency, via Wilson’s Auctions, by the Eastern Region Special Operations Unit of the police was the first auction of its kind. Chief Inspector Martin Peters, of the ERSOU Cyber Crime Unit, is reported as saying that the sale would be a way to instil public confidence in the police force’s method of recouping the proceeds of crime in a way that was secure, innovative and transparent.
What Does This Mean For Your Business?
We often hear reports about hacks and dark web sales of data but we rarely hear about convictions or about what happens to the proceeds of crime for those hackers who have been successfully convicted. For many businesses and individuals who have fallen victim to cybercriminals, a report of this kind may offer some kind of reassurance that something is being done, and in a productive way that puts more money into fighting crime.
For those victims of the TalkTalk hack, who may well have been targeted by cybercriminals after having their details stolen and sold by Gunton, they may well have wished for tighter security by TalkTalk in the first place and may hope that ISPs are investing enough of their own money in keeping their cyber defences up to date.
Worldwide Rollout of ‘Personal Vault’ OneDrive Security Features
Microsoft has announced that the ‘Personal Vault’ security features for its OneDrive storage service are now available worldwide on all OneDrive consumer accounts.
What Is Personal Vault?
Personal Vault is a protected area in OneDrive that can only be accessed with a strong authentication method or a second step of identity verification. These methods include a fingerprint, face, PIN, or a code sent to the OneDrive user via email or SMS.
The idea of Personal Vault is to add another layer of protection to important files, photos, and videos e.g. copies of documents such as a passport, driver’s licence, or insurance information. Even though the new feature means that users must go through a verification process, Microsoft has stressed that it won’t slow users down and that they should still be able to quickly access their files on a PC, OneDrive.com or on their mobile device.
Protection Against Lost, Stolen, or Unauthorised Access
The Personal Vault security measures should mean that files are not being stored unprotected on a PC and have additional protection, even if the Windows 10 PC or mobile device is lost, stolen, or if someone gains access to it or to the user’s account.
Other Security Measures
In addition to the second layer of identity verification, Personal Vault also includes security measures such as :
- Scan and shoot, which enables documents to be scanned or photos to be shot directly into the secure Personal Vault area rather than leaving them on a camera or unsecured device.
- Automatic locking of the Personal Vault after a period of inactivity to protect against private files being left open accidentally.
- BitLocker encryption on Windows 10 PCs, so that all Personal Vault files are synced to a BitLocker-encrypted area of the local hard drive.
- Restricted sharing so that Personal Vault and shared items moved into Personal Vault can’t be shared.
Some Limitations
Personal Vault does come with some limitations. For example, users with OneDrive’s free or standalone 100GB storage plan can store up to three files in Personal Vault, and Office 365 subscribers can store as many files as they wish as long as this doesn’t exceed their normal storage limits.
What Does This Mean For Your Business?
For Microsoft Personal Vault, this is another step in its competition with its most popular competitor, Dropbox, which recently partnered with BetterCloud to help with it provide cutting-edge data protection and orchestration.
For businesses using OneDrive, these new security features should prove attractive, particularly when most businesses need safe, fast Cloud storage for mobile devices and work PCs, and need an easy, reliable and convenient way to store sensitive and personal files and data.
Windows Virtual Desktop Generally Available Now
Microsoft has announced that its Windows Virtual Desktop is now generally available worldwide on Azure and will include Windows 7 free Extended Security Updates for up to three years.
Windows Virtual Desktop
Windows Virtual Desktop from Microsoft, which was announced last September but has just been made generally available worldwide, is a Cloud-based ‘virtual’ version of Windows that can be accessed by employees from any device from anywhere, provides full multi-session, and is always up to date. The Virtual Desktop has been designed with modern working practice in mind where not all employees sit in an office, use just one device or work from secure locations.
According to Microsoft, Windows Virtual Desktop is the only virtual desktop infrastructure (VDI) that can provide simplified management, multi-session Windows 10, optimizations for Office 365 ProPlus, as well as and support for Remote Desktop Services (RDS) environments.
The Virtual Desktop enables Windows desktops and apps to be deployed and scaled on Microsoft’s Azure portal in minutes, and it includes built-in security and compliance features.
Supported Transition to Windows 10
One key sweetener of the new service for those companies facing the end of support for their old Windows 7 deployments is that it offers free extended security updates for the Windows 7 virtual desktop including more support options for previous app versions while users transition to Windows 10.
Migrate
Microsoft is keen to emphasise that its Virtual Desktop can work with your current Remote Desktop Services (RDS), and can therefore easily be migrated on Azure.
Trust
Microsoft is also keen to emphasise that businesses can trust the new Windows Virtual Desktop not least because Microsoft invests more than USD $1 billion annually on cybersecurity research and development, employs 3,500+ security experts, and Azure has more compliance certifications than any other cloud provider.
What Does This Mean For Your Business?
With Virtual Desktop, Microsoft is hoping to capitalise on the fact that many businesses have workers in multiple locations with multiple devices who need to have convenient and secure access to a constantly updated version of their desktop. Microsoft also knows that companies are getting more confident about moving more of their infrastructure to the Cloud, and want a secure, scalable ‘as-as-Service’ offering where they don’t need to worry about having the expertise in-house.
The easy migration aspect of the service and the offer of extended Windows 7 support may be of value to businesses looking to make a leveraged move forward to Windows 10 and may help Microsoft retain valuable business customers.
Email Signature Legally Binding For Lawyer
A recent ruling by the High Court that an email containing an automated signature is legally binding proved costly to the lawyer who sent such an email on behalf of his client that included the wrong price for a land sale.
£25,000 Below
The unfortunate lawyer, Daniel Tear, who sent an email to another lawyer setting out the terms for an owner’s land/property sale (but with the sale price listed as £25,000 lower than the asking price) the ruling about his email signature at the County Court in Manchester proved to be very costly.
In the case, which related to a dispute over the sale of land near Lake Windermere listed as a “jetty/boat landing plot/mooring”, it has been reported that the land should have been offered for sale at the asking price of £200,000 but (according to published court documents) but Mr Tear’s email to the lawyer of those wishing to purchase the land specified a price of “ £175,000 (one hundred and seventy-five thousand pounds”.
The lawyer acting for the buyer accepted the deal, and despite Mr Tear later emailing all the parties to say the deal had not been finalised by email, the court ruling went against him and his client.
Why?
According to the published court documents which refer to matters related to certain sections of the Law of Property Act of 1989, Mr Tear’s auto-signature (using Microsoft Outlook) which appeared at the bottom of his email, accompanied by the words “Many Thanks” (which link the email’s contents to the signature) were enough to make the contents of the email’s agreement binding.
In a hearing which considered the many difficulties around an email footer possibly being treated as a sufficient act of signing the judge stated that he was “satisfied that Mr Tear signed the relevant email on behalf of the Defendant” and that “the Claimants are entitled to the order for specific performance that is sought”.
Mr Tear’s argument that the case fell under Section 2 (1) of the Law of Property Act of 1989 i.e. “The document incorporating the terms or, where contracts are exchanged, one of the documents incorporating them (but not necessarily the same one) must be signed by or on behalf of each party to the contract” was, therefore, not accepted by the court.
What Does This Mean For Your Business?
As with most legal matters, if you read the court documents (here: https://www.bailii.org/ew/cases/EWHC/Ch/2019/2462.html) there were many different considerations based around the case. One thing that businesses can take away from this case, however, is that if you create and add an email signature section to the footer of your Outlook emails, even though it is automatically added to each of your emails, it may still prove to be enough to legally bind you to the contents of the email, even though you may have made a mistake. It goes without saying, therefore, that businesses need to be very careful to check that prices and quotes emails to clients (where an email signature is included) are correct and that any terms are clearly stated. This ruling could now and in future have implications for many businesses in disputes relating to the contents of business emails.