Analysis: COVID-19 as a Cybercrime Opportunity episode artwork

EPISODE · Mar 20, 2020

Analysis: COVID-19 as a Cybercrime Opportunity

from Info Risk Today Podcast · host InfoRiskToday.com

The latest edition of the ISMG Security Report analyzes how cybercriminals are exploiting the COVID-19 pandemic. Also featured: A discussion of potential 2020 election changes; tips for staying secure in a remote workplace.

Episode metadata supplied by the publisher feed · Published Mar 20, 2020

Embed this episode

NOW PLAYING

Analysis: COVID-19 as a Cybercrime Opportunity

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

How cyber criminals are exploiting the COVID-19 crisis, the 2020 elections, can we have them if we're still social distancing in November, and fight tips to securing the remote workplace? These stories and more, in this week's ISMG security report. Hello, I'm Nick Holland. It's an ill wind that blows no on any good, as they say.

The current COVID-19 crisis is indeed a very ill wind, but that's not stopping cyber criminals from exploiting the pandemic for their own nefarious ends. With a rundown of coronavirus cyber crime, here's ISMG's executive editor, thanks to Richard Day and Europe, Matthew Schwartz. As the old saying goes, never waste a good crisis. Unfortunately, cyber criminals have been taking that saying to heart.

As the COVID-19 pandemic rages on, crooks are continuing to take advantage of the outbreak. Security experts forecast that the quantity of online attacks, including malware and phishing campaigns, plus network intrusions, will continue to mount, as attackers increasingly gone for organizations that may have more employees working remotely now, as well as fewer IT and security staff at the ready to mitigate hack attacks and successful intrusions. Having more workers working remotely also means an increase in the threat posed by phishing campaigns, which have been surging. Attackers have been using COVID-19 themed messages that include links to malicious sites, or which have attached Microsoft Office documents, with malicious macros designed to download and execute malware on a victim's system.

Some of these messages appear to come from the World Health Organization, or U.S. Center for Disease Control, and exploit individuals' obvious need to know more about the pandemic. They're not the only ones talking about it. New research from Security Firm Digital Shadows has found a massive increase in cyber crime-form chatter about the disease.

It says that, since February 19, dark web search activity for COVID-19 increased more than 7-fold, just as it has on the clear web, with people searching for information via Google. Despite cyber crime-form users talking about COVID-19, however, it's not clear that many of them are attempting to profit from it. In particular, Dark Shadows says that forum posters asking for ways to exploit the pandemic are often met with a barrage of criticism from their fellow cyber crime aficionados. Unfortunately, this hasn't blunted all attempts to turn COVID-19 to some criminal's advantage.

Two ransomware gangs, maize and double-pamer, have promised to provide free decryptors to any hospital they hit. But such promises, even if true, but lie to the fact that it takes time to unlock systems. Any interruption of healthcare facilities never mind their suppliers will likely lead to more people dying unnecessarily. Intelligence agencies in the U.S., U.K.

Europe, Israel, and beyond are no doubt tracking these attacks and attempting to tie them back to perpetrators. Anyone who disrupts healthcare facilities will likely become a major target, once the COVID-19 pandemic clears. In the short term, however, what can organizations do to better protect themselves? For IT, testing the backup and recovery plans in place is a must, not least for the healthcare sector, which continues to face an elevated risk of being hit by crypto logging nowhere.

On that front, Kudos go to Ransomware Response from Codeware and Security from MCSoft, which, this week, announced jointly that effective immediately, they'll provide free help to any healthcare organization that gets hit by Ransomware. IT teams must also ensure that remote workers have a full suite of security defenses, including antivirus and email filtering software to better protect them. IT also needs to be using software that allows it to monitor for unusual activity. Unfortunately, unusual is the word of the day, and attackers remain likely to exploit the current corporate chaos, as personnel who might be suddenly working from home get hit with out of the ordinary, legitimate requests to install this piece of software, or maybe even click this link accordingly.

Common Sense must prevail, especially as organizations continue to get the right defenses in place to protect an IT ecosystem that for many organizations and individuals changed virtually overnight. For Information Security Media Group, I'm Matthew Schwartz. You're listening to the ISMG security report on ISMG radio, ISMG, your number one source for information security news. Last week, your cyberdome announced the formation of the first-ever information-sharing and analysis organization for political campaigns, or PC ISO.

I spoke with Matt Barrett and Joe Dristle, two of the founders of your cyberdome about this recent initiative aimed at sharing cyber threat information between political campaigns, and then the conversation pivoted to something a bit more topical. Can we actually have a presidential election for unable to gather in public places in November? Is there a response? So this is Joe, and yes, I actually believe we can hold an election.

I do think it's going to require some forethought. I do think it will require some innovation, and I also think it will require some additional dollars to be put towards it. The absentee ballot process is pretty mature in a lot of the states, so that is one option. Of course, that may reduce the number of people that vote, so if you want to get the volume up, they may need to come up with another solution.

The biggest concern that I have is in a lot of these situations, and you'll find this in the IT community, and in particular, the cybersecurity community gets a little worried about these kinds of situations, is that we move quickly to create a solution that we don't properly assess from a cybersecurity perspective, and that opens the door up for all sorts of things to go sideways on us. So if you really think about it, there's a way to do this. If they think about it now, and they start working on it now, there's a way to do this and make it happen right, and maybe just work on getting a word out to folks, hey, you need to get an absentee ballot, get them into the mail, make sure people have an opportunity to return them, and also let's look at the other things that maybe we can do to make it easier for people to vote online. Yeah, Matt here, let me chime in on that one.

I background at the National Institute of Standards and Technology, participating in such projects as a voluntary voting system guideline. In support of Election Assistance Commission, we are seeing this increasing trend toward voting and voting, you know, an app-based sort of voting versus a voting machine sort of voting. So this is a, that's more a statement on what the future may hold and where we may need to focus as a society, so that four parties that can't get out to vote, they still have the opportunity to do so. absentee ballot is certainly a great idea.

In the short run, there may be a more of a real time way to do that in the future, because after all, there's a lot of our society that can't get out to vote, and it's not about a pandemic. It's about a whole bunch of lifestyle sort of factors, and sometimes folks just can't get out to vote. So I think increasingly we need to embrace those sort of technologies to increase the amount of votes. Finally, it's a very strong possibility that this is the first week you're listening to this podcast from home.

If you're lucky, this is from a dedicated home office. If you're less fortunate, there's a good chance that you're at your kitchen table fighting for real estate with homecraft projects and kids playing Minecraft. This involuntary shift from any of us from work being somewhere you go to something you do wherever you can has cybersecurity implications. And this week, Ice and G's SVP of Edits Royal Tom Field spoke with Phil Ridinger of the Global Cyber Alliance, a nonprofit organization focused on eradicating systemic cybersecurity risks.

Phil provided five tips that they published for securing a remote workplace. Here he is. I'm actually for most people going to limit it to three. I'll talk about all of them, but I think there are three things that workforce that workers and employers absolutely need to do.

One is what I said, patch your systems, right? And it's not just patch your work laptop at home. Make sure your router at home is fully up to speed. If there are other devices on your network, make sure they're patched as well to give you the best protected service area possible.

The second is what I just mentioned, that you really need to use multi-factor authentication. So many of the services that you're already using, a lot of people use Office 365 or use Gmail, G Suite or other cloud-based email services. Most of those sorts of services you can turn on two-factor authentication by checking the box. And so that would be something that is not that hard to do and would be a super significant additional layer of security.

The other thing that I suggest and I'm focusing on things that are super easy to do is to use a protective DNS service. All you have to do is go into the settings on your device and set up so it uses a protective DNS service like One9. It can be done in literally one or two minutes, and it provides a substantial additional barrier for attackers to go through. So that won't completely protect you.

But if you do those three things, you'll do a lot. I'll suggest there are a couple more things. So the best idea, as we all know, is to stay at home. And if you need a coffee, then you make your coffee pot, right?

But some people are going to Starbucks. Some people need to get around and get out and do stuff for a while. If you do that, sit away from other people and do a couple of things. One, be really aware of physical security.

It's very easy for somebody to walk by and grab your laptop or walk away with your phone if you're just distracted for a second. It's really fun. Everybody's on the internet, right? Go to the City of London Police Twitter account and look at the videos they've got of scooter theft where people are driving by and just grabbing cell phones out of your hands as they go through the streets of London on scooters.

It's like that, but it's really a lot easier when somebody's in a Starbucks or a coastal or a pizza, the coffee shop that you prefer. The other thing is, and this is a little if you're some people don't think this is necessary, but I still think it's pretty smart to use a virtual private network if you are accessing corporate resources through public Wi-Fi. I just like the extra touch of authentication and knowing that I'm going through a secure tunnel to get to my workplace and the resources I'm trying to reach, and then I'm not being redirected in some way. Those are the five things that I would strongly recommend people do.

That's it for this week's Ice and Security Report. Theme music is by either audio. I'm Nick Collins. Catch you next time.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on March 20, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!