More stories

  • in

    Cybersecurity teams are reaching their breaking point. We should all be worried

    Image: Getty Images Cybersecurity professionals are “reaching their breaking point” as ransomware attacks increase and create new risks for people and businesses. A global study of 1,100 cybersecurity professionals by Mimecast found that one-third are considering leaving their role in the next two years due to stress and burnout. The report found that rising rates […] More

  • in

    Australia seeks stiffer penalty for data breaches amidst spate of security incidents

    Australia wants organisations to dig deeper for serious or repeated data privacy breaches, forking out maximum fines of up to AU$50 million ($31.57 million). The move to increase penalties for violations comes amidst a spate of cybersecurity incidents that compromised customer data, with the latest involving insurance group Medibank. Attorney-General Mark Dreyfus unveiled plans to introduce legislation in parliament this week would push financial punishment for privacy violators up from the current AU$2.22 million ($1.4 million). The new rules will be outlined in Australia’s Privacy Legislation Amendment  (Enforcement and Other Measures) Bill 2022, which can be applied under the Privacy Act 1988 for “serious or repeated” privacy breaches. Following the update, companies found to have committed the breaches will be fined AU$50 million, or three times the value of any benefit it obtained through the misuse of information, or 30% of the company’s adjusted turnover in the relevant period, whichever is greater. The Bill also will afford the Australian Information Commissioner “greater power” to resolve privacy breaches as well as strengthen the Notifiable Data Breaches scheme, which will provide the Commissioner with full knowledge of information that compromised in a breach so it can assess the risks of harm to affected individuals. In addition, the Commissioner as and Australian Communications and Media Authority will be better empowered to share information in the event of a data breach. Dreyfus said: “When Australians are asked to hand over their personal data they have a right to expect it will be protected. Unfortunately, significant privacy breaches in recent weeks have shown existing safeguards are inadequate. It’s not enough for a penalty for a major data breach to be seen as the cost of doing business.”We need better laws to regulate how companies manage the huge amount of data they collect and bigger penalties to incentivise better behaviour,” he said. Australian policy makers earlier had pushed for more severe fines to be meted out following a major breach involving local telco Optus, which compromised the data of 9.8 million customers including email addresses, phone numbers, and other personal identification information. Medibank breach compromises health recordsIn another breach that followed Optus’, Medibank on October 13 revealed it detected “unusual activity” on its network that was later found to have compromised the personal data of customers under its subsidiary, ahm, as well as international student customers. In a statement yesterday, it had received files from the alleged hacker that contained 1,100 ahm policy records comprising personal and health claims data, and some Medibank and further ahm and international student customer information. One of Australia’s largest health insurance companies, Medibank last week said the hacker claimed to have stolen 200GB worth of data that included customer names, addresses, dates of birth, and policy numbers. Compromised data concerning customer claims included the location at which the customer received medical services and codes related to their diagnosis and procedures. The hacker also said it had data related to credit card security, though, Medibank said it had yet to verify this. “Given the complexity of what we have received, it is too soon to determine the full extent of the customer data that has been stolen,” it said. “We will continue to analyse what we have received to understand the total number of customers impacted and, specifically, which information has been stolen.”The insurance company added that the breach currently was under criminal investigation by the Australian Federal Police. It also was working with cybersecurity vendors, the Australian Cyber Security Centre, and other relevant government agencies, it said.Medibank said: “As we continue to investigate the scale of this cybercrime, we expect the number of affected customers to grow as this unfolds.”Financial services regulator Australian Prudential Regulation Authority (APRA) on Monday released a statement reminding industry players to put in place data security controls and ensure they complied with sectoral regulations. Pointing to requirements outlined in Prudential Standard CPS234 Information Security, the government agency said APRA-regulated entities should have clearly defined cybersecurity roles and responsibilities held by their boards, senior management, governing bodies as well as individuals.  They also had to maintain an information security capability in line with the size and extent of threats to its data assets as well as deploy controls to safeguard their data assets and run systematic tests to ensure the effectiveness of such controls. APRA added that the recent security breaches served as a reminder that such threats continued to escalate. It underscored the need for regulated entities to review and regularly test incident response plans. RELATED COVERAGE More

  • in

    Criminals are starting to exploit the metaverse, says Interpol. So police are heading there too

    Image: Getty/Cristina_Annibali_Krinaphoto The International Criminal Police Organization, aka Interpol, has launched its ‘global police Metaverse’ as part of an effort to train members how to police in a virtual world.  Last week, Interpol unveiled what it says is the “the first ever Metaverse specifically designed for law enforcement worldwide.” It says the “Interpol Metaverse” gives […] More

  • in

    FBI warning: This ransomware group is targeting poorly protected VPN servers

    The FBI and other agencies are warning of a rise in Daixin Team ransomware and data extortion attacks on healthcare providers.   The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and Department of Health and Human Services (HHS) has issued a joint warning about Daixin Team activity against the healthcare and public […] More

  • in

    5 quick tips for better Android phone security right now

    Shutterstock/MS_studio ZDNET Recommends Attention, all Android phone users: Keeping your phone secure is important.  These days, it’s sadly easy for malicious hackers to drain your bank account or steal your data.  Keeping up with your security practices on the front end makes it a lot less likely you’ll have to spend time, energy, and maybe […] More

  • in

    Your guide to the dark web and how to safely access .onion websites

    When the dark web is mentioned online, it is usually in tandem with criminal marketplaces and arrests made by law enforcement agencies. Drugs, weapons, and stolen IP and data are all hot businesses in the dark web, with hundreds of terabytes of information on offer. Traders cash in on stolen credit card data dumps, initial access points to vulnerable systems, credentials, and intellectual property belonging to companies comprised during cyberattacks. According to Kela’s 2022 Threat Intelligence report (PDF), 48% of organizations have no documented dark web threat intelligence policy in place, despite the obvious danger. However, the dark web has far more uses for organizations and individuals than what a small subset of criminals do under its umbrella.To access a dark web address, you must use a VPN and a suitable browser (it should be Tor). The aim is to reduce your online footprint as much as possible, anonymize your traffic, and disguise your location. There are many legitimate uses for dark web services and communication. For example, this can include tools hosted for combating censorship — critical services for individuals in countries with stringent government surveillance and control, as well as privacy-enhancing anonymous email and whistleblower drop boxes.Also: What is torrenting and how does it work?Some media outlets also maintain an online presence via the dark web when their surface websites are blocked, and other websites do the same when they are banned at the ISP level by countries during unrest and protests. Yes, the dark web has an unsavory reputation. However, remaining anonymous can be invaluable to protesters, civil rights groups, journalists, lawyers, and other vulnerable groups. More