Connect with us
...

Tech

Vindictive deleted hotel chain data for fun

Published

on

Hackers have told the BBC they carried out a destructive cyber-attack against Holiday Inn owner Intercontinental Hotels Group (IHG) “for fun”.

Describing themselves as a couple from Vietnam, they say they first tried a ransomware attack, then deleted large amounts of data when they were foiled.

They accessed the FTSE 100 firm’s databases thanks to an easily found and weak password, Qwerty1234.

An expert says the case highlights the vindictive side of criminal hackers.

UK-based IHG operates 6,000 hotels around the world, including the Holiday Inn, Crowne Plaza and Regent brands.

On Monday last week, customers reported widespread problems with booking and check-in.

For 24 hours IHG responded to complaints on social media by saying that the company was “undergoing system maintenance”.

Then on the Tuesday afternoon it told investors that it had been hacked.

“Booking channels and other applications have been significantly disrupted since yesterday,” it said in an official notice lodged with the London Stock Exchange.

The hackers, calling themselves TeaPea, contacted the BBC on the encrypted messaging app, Telegram, providing screenshots as evidence that they had carried out the hack.

The images, which IHG has confirmed are genuine, show they gained access to the company’s internal Outlook emails, Microsoft Teams chats and server directories.

“Our attack was originally planned to be a ransomware but the company’s IT team kept isolating servers before we had a chance to deploy it, so we thought to have some funny [sic]. We did a wiper attack instead,” one of the hackers said.

A wiper attack is a form of cyber-attack that irreversibly destroys data, documents and files.

Trader on a bicycle with wares protected against the rain
IMAGE SOURCE,GETTY IMAGES
Image caption,

The average wage in Vietnam is about $300 (£270) per month

Cyber-security specialist Rik Ferguson, vice-president of security at Forescout, said the incident was a cautionary tale as, even though the company’s IT team initially found a way to fend them off, the hackers were still able to find a way to inflict damage.

“The hackers’ change of tactic seems born out of vindictive frustration,” he said. “They couldn’t make money so they lashed out, and that absolutely betrays the fact that we are not talking about ‘professional’ cybercriminals here.”

IHG says customer-facing systems are returning to normal but that services may remain intermittent.

The hackers are showing no remorse about the disruption they have caused the company and its customers.

“We don’t feel guilty, really. We prefer to have a legal job here in Vietnam but the wage is average $300 per month. I’m sure our hack won’t hurt the company a lot.”

The hackers say no customer data was stolen but they do have some corporate data, including email records.

TeaPea say they gained access to IHG’s internal IT network by tricking an employee into downloading a malicious piece of software through a booby-trapped email attachment.

They also had to bypass an additional security prompt message sent to the worker’s devices as part of a two-factor authentication system.

English computer keyboard
IMAGE SOURCE,GETTY IMAGES
Image caption,

Qwerty1234 is a popular password because it comprises the first five letters and the first four numbers of an English keyboard

The criminals then say they accessed the most sensitive parts of IHG’s computer system after finding login details for the company’s internal password vault.

“The username and password to the vault was available to all employees, so 200,000 staff could see. And the password was extremely weak,” they told the BBC.

Surprisingly, the password was Qwerty1234, which regularly appears on lists of most commonly used passwords worldwide.

“Sensitive data should only be available to employees who need access to that data to do their job, and they should have the minimum level of access [needed] to use that data,” said Mr Ferguson, after seeing the screenshots.

“Even a highly complex password is just as insecure as a simple one if it is left exposed.”

An IHG spokeswoman disputed that the password vault details were not secure, saying that the attacker had to evade “multiple layers of security”, but would not give details about the extra security.

“IHG employs a defence-in-depth strategy to information security that leverages many modern security solutions,” she added.

Reports /TrainViral/

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech

Ex-Google ad boss builds free search engine

Published

on

By

An advert- and tracker-free search engine launches in the UK, France and Germany on Thursday.

Neeva has 600,000 users in the US, where it launched last year.

Creator Sridhar Ramaswamy, who worked at Google for 16 years and ran its ad business, told BBC News the technology sector had become “exploitative” of people’s data, something he no longer wanted to be a part of.

Trackers share information about online activity, largely to target adverts.

Neeva has raised $77.5m (£68m) from investors.

It offers free-to-use search, with other features such as password-manager access and virtual-private-network (VPN) service to be made available on a subscription basis.

Users are asked to create an account, to build subscriptions at a later date.

And the UK price was likely to be about £5 per month, Mr Ramaswamy said.

“We felt the traditional search engines had become about advertising and advertisers – and not really about serving users,” he said.

“Google has a dominant position in the marketplace – and the incentive for them to truly innovate, to truly create disruptive experiences, is not really there.

“And then also as a company they feel obligated to show more and more revenue and profit to their shareholders, so they just keep increasing the number of ads.”

Trying out Neeva

Search the word “migraine” on both Google and Neeva, and the first page of the results are fairly similar – links to news articles and factual information.

Neeva creator Sridhar Ramaswamy
Neeva creator Sridhar Ramaswamy

But with a brand, the difference becomes more stark.

When I try “BMW”, both search engines lead with links to the carmaker’s website and Wikipedia entry.

But while Google follows with a map, social-media feeds and links to used-car dealers, Neeva sticks with different BMW official pages.

Google certainly has more variety – but it is also blatantly pushing me towards buying a car.

Neeva’s Chrome browser extension lists the trackers installed on web pages visited.

I tried a few:

  • the Daily Mail had 351 trackers.
  • the BBC four, two of which were internal tools
  • Tesco five
  • Sainsbury’s 10
  • parenting forum Mumsnet 27
  • the front page of Reddit three
  • Amazon three – all its own

And almost all – but not the BBC – had at least one belonging to Google, meaning Google is receiving anonymised information about users visiting those pages.

While I had the extension activated, no ads displayed around the editorial content.

But ultimately, none of Neeva’s other rivals has dented the dominance of Google search.

“To Bing” or “to Duckduckgo” – another privacy-focused service – are not verbs in the way “to google” is.

And asked if Mr Ramaswamy could ever topple his former employer, Steph Liu, an analyst at Forrester specialising in privacy and search, said: “Realistically, no.

“It’s a sort of David and Goliath story. Google has too many users, it has too much revenue.

“The ultimate goal is to offer an alternative for the consumer base who are worried about their privacy, who don’t want Google hoovering up their data and targeting ads based on their search history”.

Continue Reading

Tech

Elon M Twitter deal back on in surprise U-turn

Published

on

By

Billionaire Elon Musk has apparently changed his mind about buying Twitter, again, and is now willing to proceed with his takeover of the social media platform.

In a letter to the firm, Mr Musk agreed to pay the price he offered months ago before trying to quit the deal.

The surprise reversal comes just weeks before the two sides were due in court.

Twitter, which had sued Mr Musk to force the takeover to move forward, was seen as having the stronger case.

In the letter, attorneys for Mr Musk said he intended to move ahead to complete the transaction, pending receipt of the financing and an end of the legal fight.

A spokesperson for Twitter acknowledged the firm had received the proposal, adding “the intention of the company is to close the transaction at $54.20 per share” – the price that Mr Musk promised in April.

The apparent win for Twitter sent its shares soaring more than 20% to more than $52 apiece. But the value remained lower than the takeover price, in a sign of lingering investor doubts the deal will go through.

Later on Tuesday, Mr Musk wrote in a tweet: “Buying Twitter is an accelerant to creating X, the everything app”.

Elon Musk and Parag Agrawal
Elon Musk and Twitter boss Parag Agrawal have feuded publicly

When Mr Musk first revealed plans to buy Twitter in a $44bn deal, he said he wanted to clean up spam accounts on the platform and preserve it as a venue for free speech.

But the billionaire, a prolific Twitter user known for his impulsive style, balked at the purchase just a few weeks later, citing concerns that the number of fake accounts on the platform was higher than Twitter claimed.

Twitter executives denied the accusations, arguing that Mr Musk – the world’s richest person with a net worth of more than $220bn – wanted out because he was worried about the price.

The back-and-forth followed a sharp downturn in the value of technology stocks, including Tesla, the electric car company that Mr Musk leads and is the base of much of his fortune.

The fight, which was scheduled to go to trial 17 October, saw the two sides face off in lengthy court filings, private messages and bitter public spats on Twitter, where Mr Musk has more than 100 million followers.

In one such exchange, Mr Musk responded to Twitter boss Parag Agrawal with an emoji for faecal matter.

Preparation for the trial had ensnarled many of the biggest names in tech, as lawyers for the two companies demanded communications about the deal.

Mr Musk, who could have paid a $1bn break-up fee to walk away, was set to be interviewed ahead of the trial this week.

Some industry watchers, who were taken by surprise by the development, questioned whether the latest twist was a concrete offer or a delay tactic.

A dramatic turnaround

It’s hard to keep track with this deal. On, off, now – it appears – on again.

However there’s a lot to read into Twitter’s brief statement.

The “intention” to go through with the deal suggests a nervousness that this is a delaying tactic from Musk’s team.

The statement effectively can be read as – ‘We are going to pursue this sale, whatever Elon Musk says or does’.

The way Twitter also, so pointedly, says it will sell the company at $54.20 suggests they are still worried about Musk lowballing.

So far Musk has been a highly erratic negotiating partner – hot and cold. Keen one minute, looking for the exit the other.

You can see why Twitter is playing it cautiously.

At Twitter, which has been thrown into turmoil since Mr Musk first turned his attention to the firm, staff told the BBC that their bosses were initially silent on the matter, even as the report spread widely.

Investors have long been sceptical that the takeover would go forward, especially since Mr Musk was seen as offering a heady price for a firm struggling to attract users and grow.

Twitter shares had been trading below $43 apiece at the start of the day.

News that Mr Musk had proposed to honour the original agreement sent shares in the company soaring almost 13% before trading was halted.

Wedbush Securities analyst Dan Ives said Mr Musk’s chance of winning in court was “highly unlikely”.

“Being forced to do the deal after a long and ugly court battle in Delaware was not an ideal scenario and instead accepting this path and moving forward with the deal will save a massive legal headache,” he wrote in a report after the news.

But he added, that Mr Musk’s ownership of the platform, a top venue for politicians and journalists to spread news and opinion, would still likely cause a “firestorm of worries and questions” in Washington and beyond.

Reports /TrainViral/

Continue Reading

Tech

Uber chief convicted for concealing a felony

Published

on

By

Uber’s former chief security officer has been convicted of failing to tell US authorities about a 2016 hack of the company’s databases.

A jury in San Francisco found Joe Sullivan – fired from Uber in 2017 – guilty of obstruction of justice and concealing a felony.

Increasingly, companies negotiate with ransomware hackers.

But investigators said they must “do the right thing” when their systems are breached.

The conviction is a dramatic reversal for Sullivan, who had at one point in his career prosecuted cyber-related crime for the San Francisco US attorney’s office.

After Sullivan’s conviction his lawyer, David Angeli, said “Mr Sullivan’s sole focus, in this incident and throughout his distinguished career, has been ensuring the safety of people’s personal data on the internet,” the Washington Post reported.

But prosecutors said the case was a warning to companies.

“We expect those companies to protect that data and to alert customers and appropriate authorities when such data is stolen by hackers,” US attorney Stephanie M Hinds said.

Ms Hinds accused Sullivan of working to hide the data breach from US regulator the Federal Trade Commission (FTC), adding he “took steps to prevent the hackers from being caught”.

At the time, the FTC was already investigating Uber following a 2014 hack.

When it was hacked again, the attackers emailed Sullivan and told him they had stolen a large amount of data, which they would delete in return for a ransom, according to the US Department of Justice (DOJ) .

Staff working for Sullivan confirmed data, including about 57 million Uber users’ records and 600,000 driving-licence numbers, had been stolen.

According to the DOJ, Sullivan arranged for the hackers to be paid $100,000 (£89,000) in bitcoin in exchange for them signing non-disclosure agreements to not reveal the hack to anyone,

The hackers were paid in December 2016, even though they had refused to provide their true names.

The payment was disguised as a “bug bounty”, a reward used to pay cyber-security researchers who disclose vulnerabilities so they can be fixed.

The Washington Post reported that the process enabled Uber to gather clues about the two hackers. The firm eventually identified the pair – both of whom have since been convicted of criminal offences – in January 2017 and required them to sign new agreements in their own names.

This conviction has sent shivers down the spines of many cyber-security executives.

With organised ransomware gangs, government-backed hacking teams and anarchist kids targeting companies, being a chief information security officer is already a daunting job.

Sullivan being personally convicted for a decision taken on behalf of his employer sets a scary precedent, some say.

For observers, the crimes Sullivan committed in 2016 also read as odd by today’s standards.

Negotiating with hackers and paying them to keep quiet is literally done every day now by corporations hit by ransomware gangs.

The key difference here, the jury found, is that Sullivan tried to cover it up.

Giving cyber-criminals what they want no longer carries the seriousness it once did, but companies, then and now, must always be transparent about how they respond to cyber-incidents that affect them and their customers.

The DOJ said that Sullivan “orchestrated these acts despite knowing that the hackers were hacking and extorting other companies as well as Uber, and that the hackers had obtained data from at least some of those other companies”.

A new management team at Uber eventually reported the breach to the FTC in 2017 after carrying out their own investigation.

In 2018, Uber paid US states $148m to settle claims that it had been to slow to reveal the hack.

Shock ruling

The verdict was a surprise to many working in computer security. At the time Sullivan had reportedly informed some senior figures at Uber about the threat.

The court also heard that internal legal advice had suggested that there was no need to disclose the hack if the attackers were identified, and agreed to delete the data and not spread it further.

Responding to the judgement, Dr Ilia Kolochenko, founder of ImmuniWeb, and a member of Europol Data Protection Experts Network, wrote, “The Uber case is just another illustrative example of the unfolding global trend to hold cyber-security executives accountable for their companies’ data breaches.

“Serious misconduct, such as deliberate concealment of a data breach despite the regulatory requirement to report the breach to mitigate harm, may even entail criminal sanctions.”

Dr Kolochenko said cyber-security executives should urgently check that their employment contracts address issues such as coverage of legal fees in case of a civil lawsuit or prosecution in relation to their professional responsibilities. The contracts should also contain a guarantee that their employer will not sue them – as victimised companies may also do this in case of security incidents, she added.

Sullivan has not yet been sentenced, and may appeal against the judgement.

Reports /TrainViral/

Continue Reading

Trending

Copyright © 2024 TechDaja News.