Last week in security news, Capital One disclosed a security incident that exposed the personal information of more than 100 million customers. Security researchers also came across a new family of Android ransomware, a new installation method for AgentTesla and a new TrickBot version. Finally, digital attackers used scams to commit click fraud and steal access to users’ bank accounts.

Top Story of the Week: The Capital One Breach

Capital One revealed that it had discovered a security incident on July 19 in which an outside individual gained unauthorized access to the bank holding company’s systems. This party subsequently obtained personal information about Capital One credit card customers as well as individuals who had previously applied for the company’s products. Overall, Capital One estimated the impact of the breach at approximately 100 million Americans and about 6 million Canadians.

Upon discovering the incident, Capital One fixed the issue and began working with federal law enforcement.

Source: iStock

Also in Security News

  • Researchers Discover a New Android Ransomware Family: ESET witnessed bad actors spreading around the ransomware, detected as Android/Filecoder.C, by submitting malicious posts to Reddit and the XDA Developers forum. Upon successful infection, the ransomware pivoted to a victim’s contact list and sent out SMS messages with malicious links to all contacts. It then encrypted most files on the victim’s device before displaying its ransom note.
  • Attackers Embrace a New AgentTesla Delivery Method: At the end of July, My Online Security spotted digital attackers using Choice.exe, a Microsoft default file found in all current Microsoft OS versions, to distribute the AgentTesla keylogger/infostealer. Even so, they didn’t stray from generic order/invoice emails as their preferred attack vector.
  • New TrickBot Version on the Lookout for Windows Defender: According to Bleeping Computer, security researchers detected a new version of TrickBot that goes after Windows Defender, the native antivirus software installed on a Windows 10 machine. Following execution, this malware initiated a loader that attempted to disable Windows services and processes associated with security software such as Defender.
  • Malvertising Campaign Delivering Malicious Flash Player Installer: In June 2019, Cisco Talos spotted digital attackers leveraging a technique known as “domain parking” to launch a malvertising campaign. Specifically, the operation used a website redirecting Safari browsers to a domain to deliver a malicious Flash Player installer.
  • Scammers Using Malicious QR Codes to Target Bank Accounts: Malwarebytes learned of a scam in which fraudsters asked if users would pay for their parking by scanning a QR code using their mobile banking app. If they did scan the code, however, the users inadvertently forfeited their account credentials to the fraudsters.
  • WhatsApp Scam Lures in Users With Promise of Free Internet: At the end of July, ESET researchers in Latin America received a WhatsApp message that claimed the service could provide them with 1,000 gigabytes worth of free internet. Clicking on the message’s link redirected users to a page hosting a questionnaire; this page then instructed users to tell 30 of their contacts about the questionnaire for the hidden purpose of committing click fraud.

Security Tip of the Week: How to Defend Against Scam Campaigns

ESET noted in its analysis of the WhatsApp ruse that digital attackers will continue to use social attacks like scams to lure in users:

“Attacks that rely on social engineering are rampant, simply because they continue to be very effective. Con artists know full well that everybody likes to receive something for free or help others, and these are just some of our traits that make us susceptible to fraud…. If we want to avoid getting caught out, we need to keep up on the scammers’ methods and watch out for red flags.”

Security professionals can help in this regard by using test engagements to strengthen all employees’ awareness of scams, phishing attacks and other social campaigns. Companies should situate this emphasis on training within the context of a layered email security strategy that also employs spam control, mail scanning and other security controls.

More from

Did Brazil DSL Modem Attacks Change Device Security?

From 2011 to 2012, millions of Internet users in Brazil fell victim to a massive attack against vulnerable DSL modems. By configuring the modems remotely, attackers could redirect users to malicious domain name system (DNS) servers. Victims trying to visit popular websites (Google, Facebook) were instead directed to imposter sites. These rogue sites then installed malware on victims' computers. According to a report from Kaspersky Lab Expert Fabio Assolini citing statistics from Brazil's Computer Emergency Response Team, the attack ultimately…

Who Carries the Weight of a Cyberattack?

Almost immediately after a company discovers a data breach, the finger-pointing begins. Who is to blame? Most often, it is the chief information security officer (CISO) or chief security officer (CSO) because protecting the network infrastructure is their job. Heck, it is even in their job title: they are the security officer. Security is their responsibility. But is that fair – or even right? After all, the most common sources of data breaches and other cyber incidents are situations caused…

Transitioning to Quantum-Safe Encryption

With their vast increase in computing power, quantum computers promise to revolutionize many fields. Artificial intelligence, medicine and space exploration all benefit from this technological leap — but that power is also a double-edged sword. The risk is that threat actors could abuse quantum computers to break the key cryptographic algorithms we depend upon for the safety of our digital world. This poses a threat to a wide range of critical areas. Fortunately, alternate cryptographic algorithms that are safe against…

Securing Your SAP Environments: Going Beyond Access Control

Many large businesses run SAP to manage their business operations and their customer relations. Security has become an increasingly critical priority due to the ongoing digitalization of society and the new opportunities that attackers exploit to achieve a system breach. Recent attacks related to corrupt data, stealing personal information and escalating privileges for remote code execution all highlight the new and varied entry points threat actors have taken advantage of. Attackers with the appropriate skills could be able to exploit…