A month teaching us that when everyone pitches in and does their part, then almost everyone is protected
The post Cyber Security Awareness Month is here! appeared first on WeLiveSecurity
from WeLiveSecurity https://ift.tt/33k6npW
via IFTTT
A month teaching us that when everyone pitches in and does their part, then almost everyone is protected
The post Cyber Security Awareness Month is here! appeared first on WeLiveSecurity
from WeLiveSecurity https://ift.tt/33k6npW
via IFTTT
ESET researchers discover surprisingly many indicators of close cooperation among Latin American banking trojans’ authors
The post LATAM financial cybercrime: Competitors‑in‑crime sharing TTPs appeared first on WeLiveSecurity
from WeLiveSecurity https://ift.tt/3jmTroF
via IFTTT
If you have children visiting or staying with family members (such as grandparents), make sure the family members know your rules concerning technology that your kids must follow. Just because your kids leave the house does not mean the rules about what they can do online change.
from SANS Institute Security Awareness Tip of the Day https://ift.tt/3nbvSSc
via IFTTT
An executive from Singapore’s Cyber Security Agency examines the role of security in a nation increasingly dependent on technology.
from Dark Reading: https://ift.tt/3l4VfmD
via IFTTT
White-hat hackers will receive $10,000 for each security bug they discover plus a base fee, under this invitation-only initiative.
from Dark Reading: https://ift.tt/3njIvL4
via IFTTT
An alarming new advisory issued today by the federal government could upend ransomware response.
from Dark Reading: https://ift.tt/2GkrMGB
via IFTTT
From WarGames, to Aaron Swartz, to bug bounties, to Van Buren, here’s what cybersecurity researchers should know about the US’s primary anti-hacking law before it gets its day in the Supreme Court.
from Dark Reading: https://ift.tt/3naQY2P
via IFTTT
The deal is expected to close in mid-October.
from Dark Reading: https://ift.tt/36mO05o
via IFTTT
To protect your organization from all emerging file-borne threats, the security and leadership teams must align to develop a streamlined approach to file security.
from Dark Reading: https://ift.tt/30pGz9O
via IFTTT
Companies victimized by ransomware and firms that facilitate negotiations with ransomware extortionists could face steep fines from the U.S. federal government if the crooks who profit from the attack are already under economic sanctions, the Treasury Department warned today.
Image: Shutterstock
In its advisory (PDF), the Treasury’s Office of Foreign Assets Control (OFAC) said “companies that facilitate ransomware payments to cyber actors on behalf of victims, including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response, not only encourage future ransomware payment demands but also may risk violating OFAC regulations.”
As financial losses from cybercrime activity and ransomware attacks in particular have skyrocketed in recent years, the Treasury Department has imposed economic sanctions on several cybercriminals and cybercrime groups, effectively freezing all property and interests of these persons (subject to U.S. jurisdiction) and making it a crime to transact with them.
A number of those sanctioned have been closely tied with ransomware and malware attacks, including the North Korean Lazarus Group; two Iranians thought to be tied to the SamSam ransomware attacks; Evgeniy Bogachev, the developer of Cryptolocker; and Evil Corp, a Russian cybercriminal syndicate that has used malware to extract more than $100 million from victim businesses.
Those that run afoul of OFAC sanctions without a special dispensation or “license” from Treasury can face several legal repercussions, including fines of up to $20 million.
The Federal Bureau of Investigation (FBI) and other law enforcement agencies have tried to discourage businesses hit by ransomware from paying their extortionists, noting that doing so only helps bankroll further attacks.
But in practice, a fair number of victims find paying up is the fastest way to resume business as usual. In addition, insurance providers often help facilitate the payments because the amount demanded ends up being less than what the insurer might have to pay to cover the cost of the affected business being sidelined for days or weeks at a time.
While it may seem unlikely that companies victimized by ransomware might somehow be able to know whether their extortionists are currently being sanctioned by the U.S. government, they still can be fined either way, said Ginger Faulk, a partner in the Washington, D.C. office of the law firm Eversheds Sutherland.
Faulk said OFAC may impose civil penalties for sanctions violations based on “strict liability,” meaning that a person subject to U.S. jurisdiction may be held civilly liable even if it did not know or have reason to know it was engaging in a transaction with a person that is prohibited under sanctions laws and regulations administered by OFAC.
“In other words, in order to be held liable as a civil (administrative) matter (as opposed to criminal), no mens rea or even ‘reason to know’ that the person is sanctioned is necessary under OFAC regulations,” Faulk said.
But Fabian Wosar, chief technology officer at computer security firm Emsisoft, said Treasury’s policies here are nothing new, and that they mainly constitute a warning for individual victim firms who may not already be working with law enforcement and/or third-party security firms.
Wosar said companies that help ransomware victims negotiate lower payments and facilitate the financial exchange are already aware of the legal risks from OFAC violations, and will generally refuse clients who get hit by certain ransomware strains.
“In my experience, OFAC and cyber insurance with their contracted negotiators are in constant communication,” he said. “There are often even clearing processes in place to ascertain the risk of certain payments violating OFAC.”
Along those lines, OFAC said the degree of a person/company’s awareness of the conduct at issue is a factor the agency may consider in assessing civil penalties. OFAC said it would consider “a company’s self-initiated, timely, and complete report of a ransomware attack to law enforcement to be a significant mitigating factor in determining an appropriate enforcement outcome if the situation is later determined to have a sanctions nexus.”
from Krebs on Security https://ift.tt/3lgZpIv
via IFTTT