Showing posts with label Cyberattack. Show all posts
Showing posts with label Cyberattack. Show all posts

Cyber Strikes on U.S. Water Supply Linked to Iran

Cyber Strikes on U.S. Water Supply Linked to Iran

Iranian-affiliated hackers have widened their attacks on U.S. water systems in 2026, exploiting weak security in control systems and causing operational disruptions across multiple states. Federal agencies including the EPA, FBI, CISA, and NSA have confirmed that these attacks directly threaten public health and community resilience.

According to The New York Times, cyberattacks on U.S. water systems have spread to at least seven states, and experts warn the problem could be even bigger. Authorities are rushing to protect the nation’s water supply, with evidence pointing to hackers linked to Iran

What Happened

  • Joint Advisory (April 2026): The EPA, FBI, CISA, and NSA issued a nationwide warning about Iranian-affiliated cyber actors targeting drinking water and wastewater systems.
  • Attack Escalation (March–July 2026): Iranian APT groups linked to the IRGC began exploiting programmable logic controllers (PLCs) in water, energy, and government infrastructure.
  • Methods Used: Hackers accessed internet-exposed PLCs (Siemens, Allen-Bradley, Unitronics) using default or weak passwords, wiping configurations and tampering with sensors.
  • Impact: Disruptions included loss of water pressure, flooding, boil water notices, and manual system resets.
The reason U.S. water systems are vulnerable to cyberattacks is because many of their control devices, like programmable logic controllers (PLCs) and supervisory control systems, are directly connected to the internet without proper safeguards. Hackers exploit weak passwords, outdated software, and exposed remote access points to disrupt operations.

The U.S. water supply is vulnerable because automation and remote access were added without strong cybersecurity protections. Smaller utilities, with limited budgets, are especially at risk. Hackers don’t need advanced tools—just poor cyber hygiene is enough to cause loss of water pressure, flooding, or unsafe drinking water.

Why It Matters

  • Public Health Risk: Cyberattacks can disrupt water treatment, potentially introducing contaminants into drinking water.
  • Critical Infrastructure Vulnerability: Smaller utilities with limited budgets and outdated systems are the most exposed.
  • Geopolitical Context: Analysts assess these attacks as retaliation amid heightened U.S.–Iran tensions, showing Iran’s ability to cause real-world disruption without advanced exploits.

Government Response

  • EPA & FBI Guidance: Utilities are urged to adopt cybersecurity best practices, report incidents immediately, and work with investigators.
  • Support Programs: The EPA offers free cybersecurity assessments, technical assistance, and training to help even small utilities strengthen defenses.
  • National Cyber Strategy: The U.S. is imposing costs on malicious actors while building resilience across critical infrastructure.

Attack Overview

SectorImpactMethods UsedNotes
Water systemsBoil water notices, flooding, manual resetsWeak/default PLC credentialsHighest number of confirmed incidents
Energy sectorLimited disruption, reconnaissancePLC exploitationNo full shutdown yet
Government servicesTraffic & municipal systems disruptedInternet-exposed HMIsOpportunistic targeting

Defensive Measures for Utilities

  • Remove internet-exposed control systems where possible.
  • Enforce strong, unique credentials for PLCs and SCADA systems.
  • Apply patches and updates to legacy infrastructure.
  • Report incidents promptly to FBI and CISA.

Big Picture

The widening scope of Iranian-linked hacks underscores systemic vulnerabilities in U.S. water infrastructure. While large metropolitan systems are better defended, smaller community utilities remain prime targets. These attacks highlight the urgent need for cyber hygiene, federal support, and coordinated resilience measures to safeguard America’s lifeline services.

Japan Airlines Faces Cyberattack Disrupting More Than 20 Domestic Flights

Japan Airlines Faces Cyberattack Disrupting More Than 20 Domestic Flights

Japan Airlines faced a cyberattack that disrupted more than 20 domestic flights. The attack, which occurred on December 26, 2024, was identified as a denial-of-service (DDoS) attack designed to overwhelm the airline's network with massive data transmissions. Ticket sales for same-day flights were temporarily suspended.

Fortunately, the airline managed to halt the attack and restore its systems within hours, ensuring that flight safety was not compromised.

The cyberattack disrupted both internal and external systems, leading to delays of over 30 minutes for 24 domestic flights. Despite the disruption, Japan Airlines confirmed that no customer data was compromised. The incident highlights the ongoing challenges and vulnerabilities in cybersecurity, especially as Japan strengthens its defense strategies and collaborations with international partners.

Japan Airlines took immediate action by shutting down the affected router to prevent further damage. Systems were restored later in the day, and flights resumed normally by December 27.

This incident is a stark reminder of the importance of robust cybersecurity measures in today's digital age.

In the past year, Japan has experienced several high-profile cyberattacks.To recall, in June 2024 Japanese space agency, JAXA, reported a series of cyberattacks since 2023. Although no critical data related to rockets, satellites, or defense systems was compromised, the agency took steps to bolster its cybersecurity measures.

Last year, a cyberattack paralyzed operations at a container terminal in Nagoya city of Japan, for three days. This incident highlighted the vulnerabilities in Japan's digital infrastructure.

In 2018, Cathay Pacific Airways of America suffered a data breach that compromised the personal data of 9.4 million customers, including credit card information and passport details. The breach continued until May 2020.

These incidents underscore the urgent need for enhanced cybersecurity measures in the aviation industry to protect operations, passenger safety, and organizational reputation.

With 13.7% of All Cyber Attacks, India is Most Targeted Country; 100% Increase in State-Sponsored Attacks

With 13.7% of All Cyber Attacks, India is Most Targeted Country;  100% Increase in State-Sponsored Attacks
  • India is the most targeted country with 13.7% of all cyber attacks directed at it
  • US, Indonesia and China are next 3 most targeted countries by threat actors
  • Govt agencies across nations emerge as the topmost target with 95% of the cyber attacks aimed at them
  • State sponsored cyber attacks increased by 100% on India in 2022
  • Healthcare sector most targeted in India followed by education, research, govt and military sectors
  • Cyfirma research shows 39 active campaigns against India in 2023 coming from state sponsored threat actors from China, North Korea, Pakistan, Russia
  • Threat actors actively targeting India include FancyBear, Mission 2025 (China), TA505 (Russia), Transparent Tribe (Pakistan) Turla Group, Stone Panda and Lazarus Group (North Korea)
CYFIRMA, an external threat landscape management platform, has released India Threat Landscape report 2023 focusing on threats targeting India and strategies to counter them.

According to the report, India is the most targeted country, with 13.7% of all attacks followed by the US with 9.6%, Indonesia and China with 9.3% and 4.5% respectively. The number of cyberattacks on government agencies has increased significantly year-on-year. In the second half of 2022, there were 95% more cyberattacks on government agencies than in the same period in 2021. The number of state-sponsored cyber attacks in India increased by more than 100% in 2022 compared to 2021. India was the most targeted country in 2022 as attacks on government agencies more than doubled.
 
TRENDS OBSERVED IN THE INDIAN THREAT LANDSCAPE

Healthcare is the most targeted sector by hackers followed by education, research, government and military sectors. The data from the report shows that an organization in India was attacked 1,866 times per week on average in 2022.

The most common types of cyber attacks in India are — phishing attacks, malware attacks, and ransomware attacks. 78% of Indian organizations experienced a ransomware attack in 2021, with 80% of those attacks resulting in data encryption.

 
INDIAN THREAT LANDSCAPE PHISHING

BILLIONS SPENT - YET UNABLE TO PROVIDE THE RIGHT LEVEL OF PROTECTION

Kumar Ritesh, CEO & Founder, Cyfirma, says, “It comes as no surprise that India is the most targeted country in the world by threat actors. India’s growing prominence at the world stage and push from Western economies to favour India over other large countries, a young and tech savvy population with low cybersec maturity has played a key role in hackers coming after critical assets, govt agencies with an intent to breach them and harm India’s strategic interests. While sectors like BFSI, healthcare and software companies have spent significantly on improving their security posture, there is an urgent need to understand the external threat landscape. We believe that unless you don't know who to defend against, billions spent in cybersec will not yield expected results.”

India’s geo-political importance has never been greater than it is today. This has given way to threat actors uniting against India. A disturbing trend of North Korean threat actors collaborating with China and Russia has been observed with the former offering itself as hacker as a service (HaaS) for financial gains.

Between Jan to July 2023, as part of the external threat landscape monitoring and analysis, CYFIRMA observed 39 campaigns targeting various industries in India. Known groups like FancyBear, TA505, Mission 2025, Stone Panda and Lazarus Group are suspected to be behind these campaigns. Of these 39 campaigns, 14 have been orchestrated by China State sponsored groups with an intent of espionage. 11 of these campaigns were planned by North Korea backed hackers as part of HaaS. While 10 attacks originated from Russian threat actors, of which only 4 were state sponsored.

Key trends and attack methods being used by threat actors:

Ransomware: Ransomware operators are continuously improving their techniques with an intent to intimidate and force victims to pay the ransom. At present, ransomware operators are suspected to follow a 4-layer approach of targeting organizations which includes:
  1. Infiltrate into the target organization’s network.
  2. Exfiltrate and encrypt data.
  3. Demand ransom and “Name & Shame”.
  4. Leave behind footprints in the targeted organizations to come back and attack again.
Crimeware- as-a service: CaaS threats include SMS spoofing, phishing kit,custom spyware, hackers for hire, exploit kit.

Carpet Bombing of SMEs: SMEs are not spared by cyberwar, businesses of all sizes are targeted.

Supply Chain disruption: Software supply chain will continue to be targeted

With the rising attacks, it is critical for the govts and Organizations to engage a comprehensive ETLM tool, which can take the intel gathered and relate it back to infrastructure, digital footprint, brand, industry, technology, and geolocation. Because when you unify different capabilities, you get a prioritized list of actions to prepare an effective response plan.

CYFIRMA is an external threat landscape management platform company. We combine cyber intelligence with attack surface discovery and digital risk protection to deliver early warning, personalized, contextual, outside-in, and multi-layered insights. Our cloud-based AI and ML-powered analytics platforms provide the hacker’s view with deep insights into the external cyber landscape, helping clients prepare for impending attacks. CYFIRMA is headquartered in Singapore with offices in Japan, India, the US, and the EU. Customers include both government as well as Fortune 500 companies across manufacturing, financial services, retail, industrial products, natural resources and pharmaceutical Industries.

 

Cost Per DNS Attack in India Remains Close to $800K, While Volume of Attacks Per Company on the Rise - Report


  • Sensitive customer information was stolen for over one in four companies in India

  • Cloud service downtime, as a result of attacks, reached 65% in India.


EfficientIP, a leading specialist in DNS security for service continuity, user protection and data confidentiality, today announced the results of its 2020 Global DNS Threat Report. The annual research, which was conducted in collaboration with leading market intelligence firm International Data Corporation (IDC), sheds light on the frequency of the different types of DNS attack and the associated costs for the last year.

Nearly four out of five organizations (79%) experienced DNS attacks, with the average cost of each attack hovering around US$924K. The Report shows that organizations across all industries suffered an average 9.5 attacks this year. These figures illustrate the pivotal role of the DNS for network security, as threat actors make use of DNS' dual capacity as either a threat vector or a direct objective.

Costs of attacks in India decreased by 6.08%, from about US$835K to US$784K. This is a slightly higher decrease in costs compared to the entire Asia region, which saw a decrease of 2.62% from US$814K to US$792K. Despite a decrease in costs per attack, of the countries surveyed, India saw the highest number of attacks suffered by a company, 12.13 per organisation. 27% of companies in India had sensitive customer information stolen, compared to 16% globally. Poor brand image is also of major concern; India surpassed the global average of 29%, with 44% of companies surveyed in India suffering brand damage due to DNS attacks.

Attackers appear to increasingly target the cloud. As the number of business-critical applications hosted in hybrid-cloud environments has increased, so has the attack surface for cybercriminals. The Threat Report shows that the number of businesses that suffered from cloud service downtime increased from 41% in 2019 to 50% in 2020, a sharp growth of nearly 22%. Cloud service downtime in India surpassed the global average, reaching 65%. The increased adoption of cloud services during the global COVID-19 pandemic could make the cloud even more attractive for attackers.

In-house app downtime remained extremely high: 62% this year compared to 63% last year. As a whole, application downtime-whether in-house or in the cloud-remains the most significant result of DNS attacks; of the companies surveyed, 82% said that they had experienced application downtime of some kind.

The Threat Report, now in its sixth year, shows the broad range and changing popularity of attack types ranging from volumetric to low signal. This year phishing led in popularity (39% of companies experienced phishing attempts), malware-based attacks (34%), and traditional DDoS (27%). Crucially, the size of DDoS attacks is also increasing, with almost two-thirds (64%) being over 5Gbit/s.

Despite these worrying numbers, enterprise awareness of how to combat these attacks is improving: 77% of respondents in the 2020 Threat Report deemed DNS security a critical component of their network architecture, compared to 64% in the previous year. Additionally, use of Zero Trust strategies is maturing: 31% of companies are now running or piloting Zero Trust, up from 17% last year. Use of predictive analytics has increased from 45% to 55%.

"Recognition of DNS security criticality has increased to 77% as most organizations are now impacted by a DNS attack or vulnerability of some sort on a regular basis," says Romain Fouchereau, Research Manager European Security at IDC. "The consequences of such attacks can be very damaging financially, but also have a direct impact on the ability to conduct business. Ensuring DNS service availability and integrity must become a priority for any organization."

DNS offers valuable information against would-be hackers that is currently going underutilized. According to results from the 2020 Threat Report, currently 25% of companies perform no analytics on their DNS traffic (compared to 30% last year). 35% of organizations do not make use of internal DNS traffic for filtering, and only 12% collect DNS logs and correlate through machine learning.

"In this era of key IT initiatives like IoT, Edge, SD-WAN and 5G, DNS should play a much larger role in the security ecosystem," says Ronan David, VP of Strategy for EfficientIP. "It offers valuable information that can make security strategies against hackers much more proactive and preventative. The COVID-19 pandemic has exacerbated the need to shore up DNS defenses, when any network or app downtime has major business implications."

There are several ways that companies can make better use of DNS with threat intelligence and User Behavioral Analytics, to enhance attack protection capacity. A DNS security solution can feed SIEMs and SOCs with actionable data & events, thus simplifying and accelerating detection and remediation. Of companies surveyed, 29% used Security and Event Management (SIEM) software to detect compromised devices, and 33% of companies passed DNS information to SIEM for analysis (up from 22% in 2019).

The full 2020 Global DNS Threat Report is available online. Read the full report here: www.efficientip.com/resources/idc-dns-threat-report-2020/

The research was conducted by IDC from January to April 2020. The data collected represents respondents experience for the previous year. The results are based on 900 respondents in three regions - North America, Europe and Asia Pacific. Respondents included CISOs, CIOs, CTOs, IT Managers, Security Managers and Network Managers.

About EfficientIP

EfficientIP is a network automation and security company, specializing in DNS-DHCP-IPAM solutions (DDI), with the goal of helping organizations worldwide drive business efficiency through agile, secure and reliable infrastructure foundations. We enable IP communication and simplify network management with end-to-end visibility and smart automation, while our patented technology secures DNS services to safeguard data and ensure application access. Companies in all sectors rely on our offerings to face the challenges of key IT initiatives such as cloud applications and mobility.

For further information, please visit: www.efficientip.com.

Google Issued 1755 Warnings to Users Globally on Govt-backed Attackers in April

Google sent out 1,755 warnings to users globally, including up to 100 in India, in April whose accounts were the target of "government-backed attackers".

In a blog post, Google said its Threat Analysis Group (TAG) tracks more than 270 targeted or government-backed groups from over 50 countries. It, however, did not clarify which governments have targeted these users.

Google shared recent findings on government-backed phishing, threats and disinformation, as well as a new bulletin to share information about actions it has taken against accounts that it attributes to coordinated influence campaigns.

"Last month, we sent 1,755 warnings to users whose accounts were targets of government-backed attackers," it said.

A heatmap on "Distribution of targets of government-backed phishing attempts in April 2020" showed that 51-100 users in India had received such warnings.

The tech giant said government-backed or state-sponsored groups have different goals in carrying out their attacks.

"...Some are looking to collect intelligence or steal intellectual property; others are targeting dissidents or activists, or attempting to engage in coordinated influence operations and disinformation campaigns," it added.

The company emphasised that its products are designed with robust built-in security features, like Gmail protections against phishing and Safe Browsing in Chrome, but it still dedicates significant resources to developing new tools and technology to help identify, track and stop this kind of activity.

"In addition to our internal investigations, we work with law enforcement, industry partners, and third parties like specialized security firms to assess and share intelligence," it said.

Outlining steps taken by the company, Google said it swiftly removes such content from its platforms and terminates these actors' accounts. It also routinely exchanges information and shares its findings with others in the industry, it added.

Google said in March, it terminated three advertising accounts, one AdSense account, and 11 YouTube channels as part of its actions against a coordinated influence operation linked to India.

The campaign, which was sharing messages in English supportive of Qatar, was consistent with similar findings reported by Facebook, it added.

"Since March, we've removed more than a thousand YouTube channels that we believe to be part of a large campaign and that were behaving in a coordinated manner. These channels were mostly uploading spammy, non-political content, but a small subset posted primarily Chinese-language political content...," it said. PTI SR MBI

Trust Lacking Within the Cybercriminal Underground - Trend Micro Research

Report details changing tactics and global demand for new malicious services like Deepfake ransomware and AI bots


Trend Micro Incorporated, a global leader in cybersecurity solutions, today released new data on cybercriminal operations and patterns for buying and selling goods and services in the underground. Trust has eroded among criminal interactions, causing a switch to e-commerce platforms and communication using Discord, which both increase user anonymization.

"This report highlights the threat intelligence we collect and analyze from global cybercriminal networks that enables us to alert, prepare and protect our corporate customers and partners," said Ed Cabrera, chief cybersecurity officer for Trend Micro. "This research helps us inform businesses early about emerging threats, such as Deepfake ransomware, AI bots, Access-as-a-Service and highly targeted SIM-swapping. A layered, risk-based response is vital for mitigating the risk posed by these and other increasingly popular threats."

The report reveals that determined efforts by law enforcement appear to be having an impact on the cybercrime underground. Several forums have been taken down by global police entities, and remaining forums experience persistent DDoS attacks and log-in problems impacting their usefulness.

Loss of trust led to the creation of a new site, called DarkNet Trust, which was created to verify vendors’ and increase user anonymity. Other underground markets have launched new security measures, such as direct buyer-to-vendor payments, multi-signatures for cryptocurrency transactions, encrypted messaging, and a ban on JavaScript.

The report also reveals the changing market trends for cybercrime products and services since 2015. Commoditization has driven prices down for many items. For example, crypting services fell from US$1,000 to just $20 per month, while the price of generic botnets dropped from $200 to $5 per day. Pricing for other items, including ransomware, Remote Access Trojans (RATs), online account credentials and spam services, remained stable, which indicates continued demand.

However, Trend Micro Research has seen high demand for other services, such as IoT botnets, with new undetected malware variants selling for as much as $5,000. Also popular are fake news and cyber-propaganda services, with voter databases selling for hundreds of dollars, and gaming accounts for games like Fortnite can fetch around $1,000 on average.

Other notable findings include the emergence of markets for:

  • Deepfake services for sextortion or to bypass photo verification requirements on some sites.

  • AI-based gambling bots designed to predict dice roll patterns and crack complex Roblox CAPTCHA.

  • Access-as-a-Service to hacked devices and corporate networks. Prices for Fortune 500 companies can reach up to US$10,000 and some services include access with read and write privileges.

  • Wearable device accounts where access could enable cybercriminals to run warranty scams by requesting replacement devices.


Trends in underground marketplaces will likely shift further in the months following the global COVID-19 pandemic, as attack opportunities continue to evolve. To protect against the ever-changing threat landscape, Trend Micro recommends a multi-layered defense approach to protect against the latest threats and mitigate corporate security risk.

To find out more and read the full report, please visit: https://www.trendmicro.com/vinfo/in/security/news/cybercrime-and-digital-threats/trading-in-the-dark

IT Major Cognizant hit by 'Maze' Ransomware Attack

IT services major Cognizant said it has become a victim of the 'Maze' ransomware attack that has caused disruptions to some of its clients.

The company, which has about 2 lakh employees based in India, said it is in ongoing communication with clients and has provided them with indicators of compromise (IOCs) and other technical information of a defensive nature.

"Cognizant can confirm that a security incident involving our internal systems, and causing service disruptions for some of our clients, is the result of a Maze ransomware attack," Cognizant said in a statement.

It added that its internal security teams, supplemented by leading cyber defense firms, are actively taking steps to contain this incident.

A ransomware typically logs users out of their own systems through forced encryption of data and asks them to pay a ransom if they want to access the encrypted data.

"Cognizant has also engaged with the appropriate law enforcement authorities," the statement noted.

The incident comes at a time when businesses have been disrupted by coronavirus pandemic that has forced companies to turn to initiatives like work from home to ensure business continuity.

This has also led to concerns around security of data.

"Based on present information, we don't believe the reaction to the COVID-19 pandemic or Cognizant's efforts to enable associates to work from home facilitated this incident," a Cognizant spokesperson said.

Microsoft undertakes Co-Ordinated Action with Global Internet agencies to Disrupt the World’s Largest Online Criminal Network

Microsoft and partners across 35 countries took coordinated legal and technical steps to disrupt one of the world’s most prolific botnets, called Necurs, which had infected more than 9 million computers worldwide. This disruption is the result of eight years of tracking and planning and will help ensure the criminals behind this network are no longer able to use key elements of its infrastructure to execute cyberattacks.

The Necurs botnet is one of the largest networks in the spam email threat ecosystem, with victims in nearly every country in the world. The breakdown by countries for the first seven days of March 2020 showed 13.59% of the distinct infected IP addresses coming only from India. India is also home to one of the largest number of super-nodes, also known as P2P (peer-to-peer) communication channels which is created by cybercriminals in order to prevent botnet disruption by law enforcement, network operators and researchers.

Microsoft’s Digital Crimes Unit, BitSight and others in the security community first observed the Necurs botnet in 2012, and Microsoft has since collaborated with law enforcement agencies, the government and Internet Service Providers (ISPs) to rid computers of malware associated with the Necurs botnet. In India, the Microsoft Digital Crimes Unit partnered with the Computer Emergency Response Team (CERT-IN) and National Internet Exchange of India (NIXI) to disrupt cyberattacks led by the botnet. This effort prevented the criminals behind Necurs from registering new domains to execute attacks in the future in India.

Tom Burt – CVP, Customer Security & Trust, Microsoft, shares details about Microsoft’s coordinated efforts to disrupt the botnet system, while also revealing how the system operated and its potential to affect more 40.6 million victims across the world.

Necurs is believed to be operated by criminals based in Russia and has also been used for a wide range of crimes including pump-and-dump stock scams, fake pharmaceutical spam email and “Russian dating” scams. It has also been used to attack other computers on the internet, steal credentials for online accounts, and steal people’s personal information and confidential data. Interestingly, it seems the criminals behind Necurs sell or rent access to the infected computer devices to other cybercriminals as part of a botnet-for-hire service.

Necurs is also known for distributing financially targeted malware and ransomware, cryptomining, and even has a DDoS (distributed denial of service) capability that has not yet been activated but could be at any moment.

On Thursday, March 5, the U.S. District Court for the Eastern District of New York issued an order enabling Microsoft to take control of U.S.-based infrastructure Necurs uses to distribute malware and infect victim computers. With this legal action and through a collaborative effort involving public-private partnerships around the globe, Microsoft is leading activities that will prevent the criminals behind Necurs from registering new domains to execute attacks in the future.

In Last 6 Months, Indian Entities Cyber-Attacked on Avg. 1565 Times/Week, 3 Times More than Global Avg.

Indian organisations have faced over three times more cyberattack than the global average, with cryptocurrency mining malware impacting most of the entities, according to a research.

Most of the attacks have come on Indian companies via online medium, Israel-based firm Check Point Software Technologies said in its report for 2019.

"An organization in India is being attacked on average 1,565 times per week in the last 6 months, compared to 474 attacks per organization globally. 93 per cent of the malicious files in India were delivered via the Web, compared to 35 per cent of malicious files globally," the report said.

The report cited cyber attack on Kundankulam Nuclear Power Plant (KKNPP) by a malware designed for data extraction as one of the major attacks in India.

"The malware, linked by experts to the North-Korean group Lazarus, infected a computer in the plants external network, rather than the operational one," the report said.

It said that on May 19, an "unprotected MongoDB database" has exposed over 275 million records of Indian citizens.

"The exposed data included names, emails, mobile phone numbers, education details, professional info and current salaries. Despite the massive amounts of information, the database could not be linked to a specific owner," the report said.

Indian organisations were most adversely impacted by XMRig malware, which uses computer resources to mine cryto currencies.

"The top malware in India is XMRig, impacting 17 per cent of organizations," the report said.

On average, cryptocurrency mining malware accounted for 26.9 per cent, botnet 20.4 per cent, mobile malwares 20 per cent, banking 13.2 per cent and infostealer 8.7 per cent.

Check Point said that the Shade ransomware (also known as Troldesh), which historically targets Russian victims, has recently expanded to the United States, Japan, India, Thailand and Canada by English-language malspam.

A ransomware takes over the victim's computer and demands payments to unlock it. PTI PRS

Cos Likely to Extensively use AI to Deal with Cyberattacks, says Study

Artificial intelligence (AI) and machine learning (ML) will be powering the 'cyber war rooms' in organisations to help them protect from increasing cyberattacks, as well as detect, predict and respond to the same, a PwC India and Data Security Council of India (DSCI) study said.

The study titled 'Cyber Security India Market: What lies beneath' also notes that the regulatory landscape for privacy and data protection is expected to reach a tipping point in 2020, forcing Indian organisations to comply with not only global regulations but also with the proposed law on personal data protection, the Aadhaar Act.

"On the flip side, cyber attackers too would be weaponising AI/ML to initiate attacks with record speeds and precision," it said, adding that businesses are expected to adopt tools and solutions embedded with AI/ML capabilities to keep threats and attacks at bay.

As per the study, almost all organisations will increase their expenditure on upgrading their security in their cloud environments because of the uniqueness of the threat actors on these systems.

"Organisations will be concerned to protect their cloud-based infrastructure and invest in people, processes and technology to fortify the layers of cloud-based networks, including insider threats," said the joint study.

Further, there will be increased focus on adopting security operation centres to strengthen breach response capabilities, and organisations will leverage emerging tools and technologies with built-in AI/ML capabilities and regularly practice and refine their breach response plans.

As per the study, organisations will begin to recognise the fact that most of the breaches today start at the endpoint, allowing threat actors to sneak into the company networks.

The number of endpoints (including mobile devices) continues to rise and so does the business data being processed/stored in them.

While threats like mobile malware seem to have a low direct impact on businesses, "we do see an increase in the number of data breaches related to mobile device use and misuse", it added.

Every device used to access company systems is yet another endpoint for the organisation to secure.

Organisations need to be careful and avoid deploying tools and solutions to solve an immediate problem or a single case. PTI NKD CS

43,000 Clipsa Malware Attacks on PCs in India -Avast

PC security maker Avast on Wednesday said it has detected and blocked over 43,000 attacks of Clipsa malware which steals passwords and mines cryptocurrencies that slows down computers.

Clipsa disguises itself as software for installing media players and infects computers when it is downloaded.

"Clipsa is an unusual password stealer. In that it supports a wide range of functionalities. Instead of just focusing on passwords and cryptowallets present on the victim's computer, Clipsa also makes PCs do cybercriminals' dirty work, like searching for vulnerable WordPress websites on the internet and brute-forcing their credentials," said Jan Rubin, malware researcher at Avast.

The campaign is most prevalent in India, where Avast has blocked more than 43,000 Clipsa infection attempts, protecting more than 28,000 users in the country from the malware, the statement said.

If a device is infected with Clipsa, users may notice PC performing slower than usual, due to malicious cryptocurrency mining being executed by the malware in the background. PTI PRS

Cyber Attacks in the Healthcare Sector: Diagnosis and Treatment

Healthcare sector is an inevitable part of the society that has not only helped in increasing the lifespan but also, has improved the quality of life. Healthcare is one of the fastest developing sectors since the measure of development it has seen is incomparable to other sectors. Unlike other sectors, almost everyone is connected to this sector.

The advancement in technology has resulted in advancement in the healthcare sector as well. Medical devices are being based on the state-of-the-art technology. From simple wearable devices like smart inhalers, insulin pen, continuous glucose monitoring device, connected contact lenses to equipment such as MRI machines, smart drills, smart beds et. Researchers are using virtual reality to integrate robotic in medical surgeries. Even a few surgeries are being performed by robots in some parts of the world.

According to a report, healthcare sector has been the number one target with losses accounting to $1 billion. There are number of reasons behind its popularity among the attackers.

According to a report by Ponemon institute, within the timespan of two years, 89% of the healthcare organizations have suffered from data breaches in the U.S that resulted in the loss of an estimated $6.2 dollars to the sector.

As per HIPAA journal, breach in patient records during the year 2018 have doubled to more than 13 million records.

Journal of Cyber security predicts that there is a 75.6% chance of potential breach in 5 million records during the next year.

Huge database: In many cases of healthcare breaches, it has been observed that attackers breach into database, access patients records, steal them and sell them. According to a report, patient records are being sold for a meagre $50 on the dark web. In countries like U.S. attackers can access expensive medical services, products as well as expensive medicines with the help of stolen medical records. Healthcare sector has proven to be extremely fruitful for the attackers with a single record costing at an average $408.

Take the case of Anthem breach for example. Treated as the biggest data breach attack in the healthcare industry. On 4th of February 2015, attackers hacked into the server of Anthem Inc. and stole the records of 78.8 million people.

Around 1.5 million patient records including the record of country’s prime minister, were accessed from Singapore government’s health database.

Research: Healthcare sector survives on research, invention and implementation. There was a time when a simple case of ‘fever’ would have cost a life. Nowadays, medical science has become advance enough to treat almost every form of cancer. Let alone a case of ‘fever’. The credit goes to the continuous research that is taking place in the healthcare sector. Many healthcare companies have become multi-million businesses because of an invention that has changed the medical science. Many of the cyber-attacks have led to attackers hacking into the system, stealing valuable research data and stealing it to the competition.

To mint money: As per the 2018 Verizon's Data Breach Investigations Report, ransomware attacks account to 85% of all the cyber-attacks on the healthcare sector. In 2016 alone, 88 percent of all the ransomware attacks were targeted on the healthcare sector in U.S. Indiana based healthcare system, Hancock health was hit by a ransomware attack that locked up the computers. The attack costed the company around $55,000 in bitcoins.

This integration of technology, its connectivity and reach within healthcare sector has made this sector extremely susceptible to cyber-attacks.

These statistics are extremely concerning since vulnerable and sensitive information such as PHI is in the hands of malicious entities that can misuse this information. On an average, 60 to 80 percent of the data breaches go unreported. As per the Thales report, only 32% of the organizations use encryption to protect their cloud data. Organizations are investing their money in security tools that are not updated and are unable to protect the data effectively. Healthcare industry invests less than 6% of its budget in cybersecurity.

Putting money where it belongs

Organizations are required to invest their money in the cyber security of their organization. They need to adopt cyber-security measures that are capable to protect sensitive data and information from cyber-attackers. Managed security services such as Penetration Testing, help organizations in patching loopholes that might give attackers an access to the system.

Employee Awareness

It has been discovered that 90% of the cyber-attacks take place due to employee negligence. Cyber -attacks like Phishing and Ransomware are deployed through emails. A single click can destroy the entire organization. It is therefore, extremely important to conduct training programs for employees that can help them understand the methodology of such attacks.

Restricting the access

Organizations should limit employee access across different levels of the network. This will limit the risk exposure towards probable cyber-attacks.

Securing the ‘smart’ devices

Many medical equipment is based on ‘IoT’ technology. It is therefore, extremely important to secure these devices. IoT devices security testing helps in minimizing the vulnerabilities that might damage the entire infrastructure of the organization.

The world is changing every second. ‘Older’ decays and ‘new’ blooms. That’s how nature works. It is important to shed the older methods that have proven to be ineffective in the long run.

69% Indian Firms Face Serious Cyber Attack Risk: Study

While 69 per cent Indian and 63 per cent Australian companies are most at risk of cyber attack, 35 per cent of organisations in the region suffered at least one cyber security incident in the last 12 months, says a sector study.

According to a recent study by leading IT analyst firm Frost & Sullivan, findings of which were released on May 9 here by Forcepoint, a leader in global cyber security, around 83 per cent of organisations in the Asia Pacific region do not think about cyber security while embarking on digital transformation projects.

Although a majority of the organisations (72 per cent) conduct regular breach assessment to protect themselves against cyber attacks, still 55 per cent of them continue to be at risk.

"It's clear from this study that many APAC organisations are on the back foot when it comes to enterprise cyber security in the borderless organisation," said Kenny Yeo, Industry Principal, APAC ICT, Frost & Sullivan.

With 95 per cent of respondents having embarked on a digital transformation journey, adopting emerging technologies, including cloud computing, mobility, Internet of Things, and artificial intelligence/machine learning, the study reveals a big push among APAC organisations for digitization.

However, 65 per cent of respondents acknowledged that they were seriously hampered in execution of digital transformation projects due to rising cyber attacks.

One of the key reasons for this is the less mature approach by business leaders to involve cyber security when designing digital transformation projects. It is also evident from the fact that around 83 per cent of the companies did not consider cyber security until after their digital transformation projects had begun.

The news first appeared in ET Telecom.

India Needs A Cyber Security Strategy, Concurs 1st Meeting of the Cyber Patriots Task Force


With cyber inroads in today’s networked world, the threats to cyber security have grown manifold. As we digitize, this will inadvertently lead further cyber-crime and terrorism. Are we equipped to handle such crisis and is there any level of preparedness that the state is working towards in the face of cyber threats? In an attempt to address Cyber security and discuss the right perspective on practicing patriotism from various practical angles including Cyber Patriotism, SKOCH Group, India’s topmost think-tank for socio-economic issues today organized India’s national summit on Practising Patriotism at 57th SKOCH Summit.





First of its kind focusing on the subject of patriotism, the Summit opened a new debate on India’s emergent need for Cyber Security Policy in public domain. First meeting of the Cyber Patriots Task Force was organized, which was chaired by Dr Gulshan Rai, National Cyber Security Coordinator. The multi-stakeholder discussion was attended by members and experts drawn from the government, Big-5 consulting, enforcement agencies, economists and academia.









Talking about Cyber Security, Brijesh Singh, Inspector General of Police-Cyber, Maharashtra, said "It is a Bank’s responsibility to secure the client’s money. A digital incident cannot be blamed on the customer’s ignorance. States are at different stages of maturity in terms of implementing the policies. Almost 1000 cyber incidents are happening every day, not all of which gets registered. We have to understand that cybersecurity is not a technology problem. Maharashtra has a Rs 1000 crore project where we are building cyber labs and cyber police stations in each district.”





Speaking on the need for Cyber Patriotism, Sameer Kochhar, Chairman of SKOCH Group and an eminent reforms historian, said “Cyber Security Policy in public domain is what we need today in this digital world. 90% of country’s IT capability is outside the Government. Cyber Patriotism can play a vital role in breaking the existing cyber monopoly in the country. Even before we begin to talk about cyber security, it would be important to know the intensity of the threat and it’s evolution.”





Dr. Shefali Dash, Former Director General, National Informatics Center, said “The government alone cannot handle Cyber security issues that face us. The private sector has more resources, research and knowledge in this space. We need government and private collaboration to deal with the issues and protect our cyber space.”





Gokul Kumar Simli, Principal Consultant & CTO, Passport Seva, Ministry of External Affairs, said "It is imperative that we understand our data to be able to protect it. It is important that when a person connects with us he/she should feel empowered. Only when we understand what are the values that we are trying to deliver? What our data is all about? When we understand all the stakeholders and the whole ecosystem, we will be able to puts the right security measures and checks. "





Jaspreet Singh Partner-Cyber Security, Africa, India & Middle East(AIM), Ernst &Young, said “Traditionally we thought that Army was enough for security but now we need cybersecurity too. When we include cyber warfare, we have to look at it from a nation’s perspective.”





Akhilesh Tuteja, Global Co-Leader-Cyber Security KPMG said, “ We are trying to protect singularity of interests with a cyber security strategy. Most people are not thinking about the possibilities technology domination can create for monopolies.”





Eminent dignitaries, government representatives and cyber security experts including Akhilesh Tuteja, Global Co-Leader-Cyber Security KPMG , Rohan Kochhar, Director, Public Policy, SKOCH Group, Shefali Dash, Former Director General ,National Informatics Centre, Sivarama Krishnan, Leader-Cyber Security PwC, Brijesh Singh, IG Police-Cyber, Maharashtra, Gokul Kumar Simli, Principal Consultant & CTO, Passport Seva, Ministry of External Affairs, SS Sharma, Director CERT-In, MeitY, Gautam Kapoor, Partner, Deloitte India, Dr. Gursharan Dhanjal, MD & Editor, SKOCH Group, Jaspreet Singh Partner-Cyber Security, Africa, India & Middle East(AIM), Ernst & Young, Gulshan Rai, National Cyber Security Coordinator discussed the need for Cyber Patriotism and various challenges that Indian Cyber security is facing today.





The Summit successfully addressed key Cyber security issues such as:





  1. Is India understanding how Cyber Vulnerable it is?
  2. Imperative role of PPP as private sector has more resources and knowledge base?
  3. Dire
    need for a blue book of Cyber Security and why the protection
    regulations need to see the issues as ecosystem issues and not
    individual issues.




Cyber
security experts also discussed the challenges of cyber security
infrastructure such as a huge number of attacks that are being made
every day, the huge gap between design of protection framework
and implementation and the upscaling of the government/ regulator and
private Sector interaction which is right now deep into audit only.





About SKOCH Group, it is India’s topmost think-tank for socio-economic issues with a focus on inclusive growth since 1997. Its research is accepted across political spectrum and is used for parliamentary replies as well as policy formulation. SKOCH Group specializes in action research that brings felt-need of the grassroots to the policy table. It has published seven books thus far that are valued as recommended reading. The repertoire of services includes field interventions, consultancy, research reports, impact assessments, policy briefs, books, journals, workshops and conferences. SKOCH Group has instituted India’s highest independent civilian honours in the field of governance, finance, technology, economics and social sector.


With 67% Attacks, Indian Businesses At High Risk From Ransomwares

India is at top when it comes to being the victim of ransomware attacks. With 67% Indian companies hit by ransomware -- 38% twice -- they are at a high risk of repeated ransomware attacks and are vulnerable to exploits, showed a study conducted by security software maker Sophos.

The study report further said that, $13.74 million were spent by 3% of the organisations worldwide to rectify the impact of ransomware and among this India's share remained the highest at $1.17 million.

It is also to be noted that, that 91% Indian organisations claimed running up-to-date endpoint protection when impacted by ransomware.

The study, The State of Endpoint Security Today, surveyed 2,700 IT managers in organizations of 100 to 5,000 users in the United States, United Kingdom, France, Germany, India, Canada, Mexico, Australia, Japan and South Africa. The number of respondents in India was 300.

More than 70 percent surveyed do not have anti-exploit technology, which means these businesses are easy prey for data breaches and complex threats like WannaCrypt.

Over 70 percent of IT professionals surveyed were unable to identify the correct definition of anti-exploit technology, despite how critical it is for modern attack prevention.

The survey also pointed out some significant variation in plans for predictive technologies across the globe. Canada, India and South Africa, whch showed to have the highest levels of machine learning technology, lead with 34 per cent of respondents already using predictive threat technologies such as deep and machine learning. Mexico has the most extensive plans for these technologies, with 72 per cent planning to implement them within the next year. India is most optimistic about the potential of machine learning.

Notably, this is one of many warnings given to India time to time regarding cyberattacks, for which the country is unprepared. To recall, in last October an IBM report revealed that India can not handle big cyber attacks despite of the fact that the country has abundant talent and tools.

In the same month, QuickHeal, a global IT security firm, revealed that a forum on DarkNet is reportedly selling data stolen from over 6,000 Indian businesses that includes Internet Service Providers (ISPs), some of the key government organisations, banks and enterprises.

Hackers Attack Indian Bank To Transfer Out $2 Million

Last October, an IBM study report warned India that despite talents and tools, the country is still unprepared to protect itself from a big cyberattack.

Within four months of this IBM warning report, cybercriminals have managed to hack and transferred US$2 million from India’s City Union Bank through three unauthorized remittances to lenders based abroad via the SWIFT financial platform, the institution revealed over the weekend, said a Reuters report.

Cyber criminals hacked into the system and did three transactions. The three fraudulent remittances were sent via correspondent banks, to accounts in Dubai, Turkey, and China.

“This is basically a cyberattack by international cybercriminals,” the bank’s CEO N. Kamakodi told Reuters.

"There was no evidence internal staff was involved, but that it was clear account holders are part of the fraud", he added.

City Union Bank, a small private lender based in south India, blocked one of the remittances for US$500,000 that was being sent through a Standard Chartered Bank account in New York to a Dubai-based lender and another transfer of EUR300,000 (US$370,110) routed through Frankfurt to Turkey.

The tactics used by hackers are very similar to those employed in the unsolved cyber heist of $81 million from Bangladesh's central bank in 2016. Notably, more than one-third companies suffered losses due to cyber attacks in year 2016, globally.

The bank said it was working with the Ministry of External Affairs and officials in Turkey and China to repatriate the funds.

It’s possible that blockchain technology could have prevented the City Union attack.

Other Indian financial institutions, such as Axis Bank, Yes Bank and ICICI have already adopted blockchain technology for payment and remittance related transactions.

It was the ICICI Bank that had first announced about using the blockchain solutions for international trade finance and remittances in October 2016. This was followed by Yes Bank announcing the usage of the technology for vendor financing and then Axis Bank in January 2017.

Last year, India's billion dollar food delivery startup Zomato was hacked and passwords of about 17 million users were stole, however later the company managed to brought every thing in right place. Prior to that, in 2015 cab-hailing startup Ola website got hacked however the company denied any breach.

Hackers Attack Indian Bank To Transfer Out $2 Million

Last October, an IBM study report warned India that despite talents and tools, the country is still unprepared to protect itself from a big cyberattack.

Within four months of this IBM warning report, cybercriminals have managed to hack and transferred US$2 million from India’s City Union Bank through three unauthorized remittances to lenders based abroad via the SWIFT financial platform, the institution revealed over the weekend, said a Reuters report.

Cyber criminals hacked into the system and did three transactions. The three fraudulent remittances were sent via correspondent banks, to accounts in Dubai, Turkey, and China.

“This is basically a cyberattack by international cybercriminals,” the bank’s CEO N. Kamakodi told Reuters.

"There was no evidence internal staff was involved, but that it was clear account holders are part of the fraud", he added.

City Union Bank, a small private lender based in south India, blocked one of the remittances for US$500,000 that was being sent through a Standard Chartered Bank account in New York to a Dubai-based lender and another transfer of EUR300,000 (US$370,110) routed through Frankfurt to Turkey.

The tactics used by hackers are very similar to those employed in the unsolved cyber heist of $81 million from Bangladesh's central bank in 2016. Notably, more than one-third companies suffered losses due to cyber attacks in year 2016, globally.

The bank said it was working with the Ministry of External Affairs and officials in Turkey and China to repatriate the funds.

It’s possible that blockchain technology could have prevented the City Union attack.

Other Indian financial institutions, such as Axis Bank, Yes Bank and ICICI have already adopted blockchain technology for payment and remittance related transactions.

It was the ICICI Bank that had first announced about using the blockchain solutions for international trade finance and remittances in October 2016. This was followed by Yes Bank announcing the usage of the technology for vendor financing and then Axis Bank in January 2017.

Last year, India's billion dollar food delivery startup Zomato was hacked and passwords of about 17 million users were stole, however later the company managed to brought every thing in right place. Prior to that, in 2015 cab-hailing startup Ola website got hacked however the company denied any breach.

India No.2 Source Country in IoT Attacks Globally

The Internet of Things or IoT, as many of us famously call it, is considered as one of the few emerging technologies that has the potential of changing the way the entire world works. Gartner predicts that there will be about 8.4 billion connected devices by the end of this year, a figure which is up by a whopping 31% in 2016. In fact, according to a report by F5 Networks, this figure will rise to reach 20.4 billion by 2020 .

While there are people excited about the rise of IoT and its devices, there are others who are a little overwhelmed thinking about the havoc that can be created if botnet building attackers end up choosing unregulated IoT devices as their cyber weapon delivery system of choice.

According to the report by the American firm, while Spain comes at the top with 25.5 million attacks, the Indian subcontinent occupies the second position globally in the top 20 attack source countries of 2017.

The F5 Networks report highlighted that 83 per cent of all the attacks originated from Spain and 93 percent of these attacks happened between January and February. Apart from Spain and India, other countries that made an appearance on the list by contributing to the attacks included Russia, South Korea and Seychelles. However, interestingly, India’s neighbour and arch rival China has worked hard at diluting its contribution in the attacks this time when compared to previous years.

Apart from attack vectors originating from the Indian subcontinent, the report also highlighted the presence of Persirai-infected IP cameras across the country.

For the uninitiated, Persirai is a malware which attacks IP cameras with DDoS attacks.

Headquartered in Seattle, Washington, F5 Networks specializes in application delivery networking (ADN) technology for the delivery of web applications and the security, performance, availability of servers, data storage devices, and other network and cloud resources.

Disappointingly, IoT devices are vulnerable to attacks because they’re dependent on wireless communication which is unprotected most of the time and the devices still have very little computing power.

Talking to ETtech over telephone, David Holmes, Principal Threat Research Evangelist, F5 Labs, threw some light on IoT products and security. He revealed, that most of the IoT products are designed without taking security into consideration. They usually work on old un-patched operating systems with default passwords on devices which are never changed and have multiple points of vulnerability. Furthermore, most of these IoT devices are being made available through Telnet and can be easily hacked due to lack of high security controls.

According to a comprehensive economic study done by the consulting firm, McKinsey and Company, about IoT’s much talked about economic potential benefits, it was revealed that the total economic benefit of IoT in the year 2025 could hit anywhere between $3.9 trillion to $11.1 trillion, with the high estimate equivalent of 11 percent of world GDP in 2025. However, if the attacks keep happening the way they are right now, meeting these figures seems like a far-fetched dreams.

According to industry experts, while IoT will lead to a huge explosion of data, but the innovators are still not giving that much importance to the security side of this as they should. It was only last year that a distributed denial-of-service (DDoS) attack had forced a temporarily taken down of some of the most popular websites including Twitter and Netflix. This particular incident send out a panic wave across the industry with almost 90% of developers believing that IoT products do not have the necessary security in place and 85% admitting that they have rushed an IoT application to the market despite knowing about security concerns.

Last year, Mirai, the malware, had single-handedly caused one of the worst distributed denial of service (DDoS) cyberattacks that the world had experienced in the last few years, and had managed to spread and infect internet-connected devices in over 177 countries all around the world.

When it comes to cyber security, India doesn’t have the best of reputation. According to a recent IBM study conducted by Ponemon Institute, while the average cost of a data breach in 2017 decreased by 10 per cent globally when compared to the 2016 figure, but for the Indian enterprises, it grew by 12.3 percent from Rs 97.3 million in 2016 to Rs 110 million in 2017.

Elaborating on the findings of the IBM study, John Shier, Senior Security Expert at the Abingdon, UK-headquartered Sophos, did an interview with IANS and said, “India has well-trained, well-educated and capable IT people. The country has got access to all the tools it needs to secure its systems. Yet, in the case of a big cyber attack, India is still unprepared.”

This development was first reported in ETtech.

[Image: ReadWrite]

India No.2 Source Country in IoT Attacks Globally

The Internet of Things or IoT, as many of us famously call it, is considered as one of the few emerging technologies that has the potential of changing the way the entire world works. Gartner predicts that there will be about 8.4 billion connected devices by the end of this year, a figure which is up by a whopping 31% in 2016. In fact, according to a report by F5 Networks, this figure will rise to reach 20.4 billion by 2020 .

While there are people excited about the rise of IoT and its devices, there are others who are a little overwhelmed thinking about the havoc that can be created if botnet building attackers end up choosing unregulated IoT devices as their cyber weapon delivery system of choice.

According to the report by the American firm, while Spain comes at the top with 25.5 million attacks, the Indian subcontinent occupies the second position globally in the top 20 attack source countries of 2017.

The F5 Networks report highlighted that 83 per cent of all the attacks originated from Spain and 93 percent of these attacks happened between January and February. Apart from Spain and India, other countries that made an appearance on the list by contributing to the attacks included Russia, South Korea and Seychelles. However, interestingly, India’s neighbour and arch rival China has worked hard at diluting its contribution in the attacks this time when compared to previous years.

Apart from attack vectors originating from the Indian subcontinent, the report also highlighted the presence of Persirai-infected IP cameras across the country.

For the uninitiated, Persirai is a malware which attacks IP cameras with DDoS attacks.

Headquartered in Seattle, Washington, F5 Networks specializes in application delivery networking (ADN) technology for the delivery of web applications and the security, performance, availability of servers, data storage devices, and other network and cloud resources.

Disappointingly, IoT devices are vulnerable to attacks because they’re dependent on wireless communication which is unprotected most of the time and the devices still have very little computing power.

Talking to ETtech over telephone, David Holmes, Principal Threat Research Evangelist, F5 Labs, threw some light on IoT products and security. He revealed, that most of the IoT products are designed without taking security into consideration. They usually work on old un-patched operating systems with default passwords on devices which are never changed and have multiple points of vulnerability. Furthermore, most of these IoT devices are being made available through Telnet and can be easily hacked due to lack of high security controls.

According to a comprehensive economic study done by the consulting firm, McKinsey and Company, about IoT’s much talked about economic potential benefits, it was revealed that the total economic benefit of IoT in the year 2025 could hit anywhere between $3.9 trillion to $11.1 trillion, with the high estimate equivalent of 11 percent of world GDP in 2025. However, if the attacks keep happening the way they are right now, meeting these figures seems like a far-fetched dreams.

According to industry experts, while IoT will lead to a huge explosion of data, but the innovators are still not giving that much importance to the security side of this as they should. It was only last year that a distributed denial-of-service (DDoS) attack had forced a temporarily taken down of some of the most popular websites including Twitter and Netflix. This particular incident send out a panic wave across the industry with almost 90% of developers believing that IoT products do not have the necessary security in place and 85% admitting that they have rushed an IoT application to the market despite knowing about security concerns.

Last year, Mirai, the malware, had single-handedly caused one of the worst distributed denial of service (DDoS) cyberattacks that the world had experienced in the last few years, and had managed to spread and infect internet-connected devices in over 177 countries all around the world.

When it comes to cyber security, India doesn’t have the best of reputation. According to a recent IBM study conducted by Ponemon Institute, while the average cost of a data breach in 2017 decreased by 10 per cent globally when compared to the 2016 figure, but for the Indian enterprises, it grew by 12.3 percent from Rs 97.3 million in 2016 to Rs 110 million in 2017.

Elaborating on the findings of the IBM study, John Shier, Senior Security Expert at the Abingdon, UK-headquartered Sophos, did an interview with IANS and said, “India has well-trained, well-educated and capable IT people. The country has got access to all the tools it needs to secure its systems. Yet, in the case of a big cyber attack, India is still unprepared.”

This development was first reported in ETtech.

[Image: ReadWrite]

Stolen Data From Over 6,000 Indian Businesses Available On Darknet, Claims Quickheal

In a worrying piece of news coming in for the Indian companies, a forum on DarkNet is reportedly selling data stolen from over 6,000 Indian businesses that includes Internet Service Providers (ISPs), some of the key government organisations, banks and enterprises. The advertisement was recently spotted by global IT security firm Quick Heal's Enterprise Security brand Seqrite.

In a company statement, Seqrite shared further details about the advertisement they discovered along with its partner seQtree InfoServices. According to the statement, the mastermind hacker behind the advertisement is demanding 15 Bitcoins (nearly INR 42 lakh) for the information and is offering network takedown of affected organisations for an unspecified amount.

The security firm believes that if the information falls into wrong hands, it has the potential of becoming a major tool of mass disruption.

The organisations whose services are most likely to be affected if the data gets leaked are: UIDAI (Aadhaar), Employees' Provident Fund Organisation, Idea Telecom, Bombay Stock Exchange (BSE), Flipkart, DRDO, Aircel, Reserve Bank of India, BSNL, SBI, TCS, ISRO, ICICI Prudential Mutual Fund, VMWare and several other Indian government portals, among others.

Talking to IANS, Rohit Srivastwa, Senior Director, Cyber Education and Services at Quick Heal said, "We have alerted the government authorities well within time. If someone gets control over this massive data that is currently up for sale on DarkNet, the above-mentioned organisations and enterprises can get affected.”

For the uninitiated, a DarkNet can be best described as any overlay network that can be accessed only with specific software, configurations, or authorization, often using non-standard communications protocols and ports. Two typical darknet types are friend-to-friend networks (usually used for file sharing with a peer-to-peer connection) and privacy networks such as Tor.

Related Reading: What is Dark Web and How It Works

According to Seqrite, after they spotted the advertisement, they ran a detailed investigation, which revealed the identity of the affected organisation to be India's national Internet registry IRINN (Indian Registry for Internet Names and Numbers) which comes under National Internet Exchange of India (NIXI).

Their next step was to bring Asia Pacific Network Information Centre (APNIC) and Indian government authorities up to catch with what had happened and recommend them to quickly alert all the potentially affected organisations to change their passwords and get their servers and systems patched with latest updates.

The security firm researchers also reveal that the hacker selling the data claims that he has the ability to tamper the IP allocation pool. If this indeed is true, it could end up causing a massive outage or Denial of Service (DoS) attack-like situation.

“This could impact various content delivery network (CDN) and hosting providers as well. If the hacker gets an interested buyer, then an attack on the system could disrupt Internet IP allocation and affect Internet services in India," read the company statement.

Along with the access, the seller is also ready to give credentials and various contractual business documents. He also claims to be in the possession of a large database of Asia Pacific Network Information Centre (APNIC).

Yesterday, we reported how an IBM study had deduced that despite of having such talented workforce, India is still unprepared to protect itself if a cyberattack to the scale of ‘WannaCrypt’ or ‘Petya’ ever hits home turf.

According to a recent IBM study conducted by Ponemon Institute, while the average cost of a data breach in 2017 decreased by 10 per cent globally when compared to the 2016 figure, but for the Indian enterprises, it grew by 12.3 percent from Rs 97.3 million in 2016 to Rs 110 million in 2017.

This development was first reported in Firstpost.

[Image: Appknox ]

Market Reports

Market Report & Surveys
IndianWeb2.com © all rights reserved