00:00:01,086 --> 00:00:05,046
Coinbase refuses to pay a $20
million ransom after hacker's bribe.
2
00:00:05,046 --> 00:00:06,066
Support contractors.
3
00:00:07,461 --> 00:00:11,751
Broadcom patches, VMware tools,
vulnerabilities, allowing file tampering
4
00:00:11,751 --> 00:00:17,171
in virtual machines, and Telegram shuts
down a $35 billion black market operation.
5
00:00:17,291 --> 00:00:23,351
After a blockchain firm raises
the alarm this is Cybersecurity
6
00:00:23,351 --> 00:00:25,391
today, and I'm your host, Jim Love.
7
00:00:26,411 --> 00:00:29,711
In what has been called the largest
takedown of its kind Telegram
8
00:00:29,711 --> 00:00:33,551
shut down two massive illegal
marketplaces that handled more
9
00:00:33,551 --> 00:00:36,311
than $35 billion in transactions
10
00:00:36,551 --> 00:00:41,351
After investigators at blockchain firm,
elliptic uncovered their operations,
11
00:00:41,771 --> 00:00:46,001
Elliptic provides blockchain analytic
solutions for financial crime compliance,
12
00:00:46,001 --> 00:00:50,711
anti-money laundering, and regulatory
requirements in the cryptocurrency sector.
13
00:00:51,701 --> 00:00:56,531
The platforms, Haowang Guarantee and
Xinbi Guarantee acted as escrow services
14
00:00:56,531 --> 00:01:01,841
for illegal goods and services, including
scams, frauds, and even human trafficking.
15
00:01:02,321 --> 00:01:04,961
The majority of the payments were
made using Tether and possibly
16
00:01:04,961 --> 00:01:07,361
other stable coin cryptocurrencies.
17
00:01:07,901 --> 00:01:10,871
Haowang linked to a Cambodian
company called Haowang Group.
18
00:01:11,111 --> 00:01:16,001
Handled over $27 billion and
Xinbi incorporated in Colorado.
19
00:01:16,151 --> 00:01:21,908
Processed $8.4 billion Both operated
openly on Telegram until elliptic
20
00:01:21,908 --> 00:01:26,018
published its findings and media
reports published in Wired triggered
21
00:01:26,018 --> 00:01:28,328
a crackdown following the report.
22
00:01:28,328 --> 00:01:30,698
Telegram banned thousands of accounts.
23
00:01:30,938 --> 00:01:33,578
US financial regulators
then stepped in as well.
24
00:01:33,698 --> 00:01:37,418
Fin send the Treasury Department's
financial crimes unit labeled
25
00:01:37,548 --> 00:01:42,308
Haowang a major money laundering
concern, effectively cutting it off
26
00:01:42,308 --> 00:01:44,108
from much of the financial system.
27
00:01:44,858 --> 00:01:48,848
The take down is a win for cyber crime
investigators, but experts warn the
28
00:01:48,848 --> 00:01:53,438
groups behind these marketplaces may
resurface elsewhere as criminal shift to
29
00:01:53,438 --> 00:01:55,628
encrypted and decentralized platforms.
30
00:01:55,838 --> 00:01:58,118
Enforcement remains a challenge.
31
00:01:59,738 --> 00:02:04,778
Broadcom has released a security patch for
a newly discovered vulnerability in VMware
32
00:02:04,778 --> 00:02:10,148
tools identified as CVE 20 25 22 2 4 7.
33
00:02:10,598 --> 00:02:15,908
This flaw allows users with limited access
to a virtual machine to manipulate local
34
00:02:15,908 --> 00:02:18,638
files, potentially compromising the VMs.
35
00:02:18,638 --> 00:02:19,358
Integrity.
36
00:02:20,078 --> 00:02:24,668
The vulnerability affects VMware
tools, versions 11 and 12 on
37
00:02:24,668 --> 00:02:26,798
Windows and Linux platforms.
38
00:02:27,068 --> 00:02:29,558
It also impacts the
open source counterpart.
39
00:02:29,558 --> 00:02:32,618
Open VM Tools commonly
used in Linux environments.
40
00:02:32,888 --> 00:02:35,318
Mac OS versions remain unaffected.
41
00:02:36,218 --> 00:02:39,098
Broadcom has addressed
the issue in VMware tools.
42
00:02:39,098 --> 00:02:41,378
Version 12.5 0.2
43
00:02:41,858 --> 00:02:45,368
For Linux users, patches will be
distributed through respective vendors
44
00:02:45,368 --> 00:02:47,858
with version numbers varying accordingly.
45
00:02:48,248 --> 00:02:53,648
There are no available workarounds making
the update essential for affected systems.
46
00:02:54,908 --> 00:02:58,868
The vulnerability was privately
reported by Sergey Bliznyuk of
47
00:02:58,868 --> 00:03:03,818
Positive Technologies and has not
been observed in active exploitation.
48
00:03:03,848 --> 00:03:07,598
However, given the potential
risks in multi-user environments,
49
00:03:07,808 --> 00:03:10,358
timely patching would be critical.
50
00:03:11,288 --> 00:03:14,708
organizations utilizing VMware
tools on Windows or Linux should
51
00:03:14,708 --> 00:03:19,598
promptly update 12.5 0.2 to
mitigate potential security risks.
52
00:03:20,679 --> 00:03:26,049
. Hackers stole customer data from Coinbase,
the largest crypto exchange in the us.
53
00:03:26,169 --> 00:03:30,789
They did this by bribing overseas support
contractors and then using that rogue
54
00:03:30,789 --> 00:03:36,819
group, the hackers demanded $20 million in
ransom, which Coinbase refused to pay and
55
00:03:36,819 --> 00:03:41,829
is now turning the tables and offering a
$20 million reward for help catching them.
56
00:03:42,639 --> 00:03:45,489
According to information released
by Coinbase, the attackers got
57
00:03:45,489 --> 00:03:50,019
access to the personal information
of less than 1% of Coinbase users.
58
00:03:50,379 --> 00:03:53,679
Stolen data included names,
addresses, government id,
59
00:03:53,679 --> 00:03:58,209
images, masked, bank details, and
partial social security numbers.
60
00:03:58,359 --> 00:04:02,379
According to the reports, no passwords,
private keys or crypto funds were taken.
61
00:04:03,189 --> 00:04:06,639
The hackers used the stolen
info to impersonate Coinbase
62
00:04:06,639 --> 00:04:10,719
support and tried to trick users
into handing over their crypto.
63
00:04:11,359 --> 00:04:17,179
Months later, Coinbase discovered the
unauthorized access months earlier.
64
00:04:17,209 --> 00:04:21,199
They fired the contractors involved
and notified the affected customers.
65
00:04:21,679 --> 00:04:25,639
The breach highlights the risks tied
to outsourcing customer service.
66
00:04:25,909 --> 00:04:30,409
Coinbase says it is cooperating with
law enforcement and has added stronger
67
00:04:30,409 --> 00:04:34,909
processes to screen contractors and
implemented scam alerts to its platform.
68
00:04:36,239 --> 00:04:39,769
Coinbase public rejection of the
ransom and decision to fight back
69
00:04:39,769 --> 00:04:43,969
with a $20 million bounty Sends
a clear message to Extortionists.
70
00:04:44,529 --> 00:04:48,965
One report said that this had cost
the company over $400 million, but the
71
00:04:48,965 --> 00:04:54,455
company says it's focused on long-term
security and not short-term payoffs.
72
00:04:57,335 --> 00:05:01,985
The cooperative group, the co-op
in the UK successfully thwarted a
73
00:05:01,985 --> 00:05:05,945
significant ransomware attack by
proactively disconnecting its systems
74
00:05:06,125 --> 00:05:11,135
upon detecting suspicious activity,
and thereby preventing further damage
75
00:05:11,435 --> 00:05:14,765
According to BBC News hackers
associated with a cyber crime group,
76
00:05:14,945 --> 00:05:18,365
Dragon Force claimed responsibility
for the attempted attack.
77
00:05:18,665 --> 00:05:22,805
They intended to deploy ransomware
to encrypt co-op systems, but were
78
00:05:22,805 --> 00:05:27,845
impeded when Co-op's IT team took the
initiative to shut down their computer
79
00:05:27,845 --> 00:05:29,915
services disrupting the attack.
80
00:05:29,915 --> 00:05:34,685
In progress, The attackers expressed
frustration over Co-op Swift
81
00:05:34,685 --> 00:05:38,675
action stating Co-op's networks
never ever suffered ransomware.
82
00:05:38,705 --> 00:05:42,455
They yanked their own plug,
tanking, sales burning logistics
83
00:05:42,545 --> 00:05:44,495
and torching shareholder value.
84
00:05:45,275 --> 00:05:48,815
Cybersecurity experts, including
Jen Ellis from the Ransomware Task
85
00:05:48,815 --> 00:05:51,155
Force commended Co-op's decision.
86
00:05:51,245 --> 00:05:54,995
Ellis noted that opting for the
immediate self-imposed disruption
87
00:05:54,995 --> 00:06:00,275
was a strategic move to avoid more
severe criminal imposed consequences.
88
00:06:01,685 --> 00:06:05,285
The same group of hackers also claimed
responsibility for a cyber attack on
89
00:06:05,285 --> 00:06:07,775
Marks and Spencer over the Easter weekend.
90
00:06:07,955 --> 00:06:11,255
unlike co-op Marks, and Spencer
did not detect the breach promptly
91
00:06:11,255 --> 00:06:15,155
resulting in prolonged disruptions,
including suspended online orders
92
00:06:15,245 --> 00:06:17,075
and compromised customer data.
93
00:06:18,335 --> 00:06:20,165
so did Co-op do the right thing?
94
00:06:20,165 --> 00:06:22,115
Is this the right strategy for others?
95
00:06:22,565 --> 00:06:26,765
Well, as noted, it had an upside in that
it appears to have reduced the damage
96
00:06:26,765 --> 00:06:30,935
that the attackers could do, but it
also had some negative consequences,
97
00:06:30,935 --> 00:06:35,825
and these need to be taken into account,
and as I've heard from others, it
98
00:06:35,825 --> 00:06:39,695
could destroy evidence necessary for
investigation and prosecution of hackers.
99
00:06:40,313 --> 00:06:43,283
The point is that you don't
wanna be making those decisions
100
00:06:43,283 --> 00:06:44,903
while you're being attacked.
101
00:06:46,073 --> 00:06:49,043
Companies of any size should have
a playbook considering these things
102
00:06:49,043 --> 00:06:53,093
upfront and getting advice from experts
so that when, and it's probably not
103
00:06:53,093 --> 00:06:58,433
if, but when you get attacked, you can
respond not just quickly, but correctly.
104
00:06:58,703 --> 00:07:01,403
this may be even more important
for retailers since there's every
105
00:07:01,403 --> 00:07:04,343
indication that the group that has
taken credit for attacking Co-op,
106
00:07:04,343 --> 00:07:08,783
Dragon Force operates an affiliate
or ransomware as a service offering.
107
00:07:09,113 --> 00:07:13,553
As a result, no one is sure who has
attacked the retailers, but the tactics
108
00:07:13,553 --> 00:07:17,333
are seen to be similar to that of a
loosely coordinated group of hackers
109
00:07:17,363 --> 00:07:19,433
who have been called Scattered Spider.
110
00:07:19,603 --> 00:07:24,943
Or Octo Tempest, that gang operates
on Telegram and Discord channels
111
00:07:24,943 --> 00:07:27,103
and is English speaking and young.
112
00:07:27,313 --> 00:07:30,963
In some cases they think
possibly only teenagers.
113
00:07:31,383 --> 00:07:34,263
And according to some sources,
they may be taking this attack
114
00:07:34,263 --> 00:07:35,853
to the US in the near future.
115
00:07:36,783 --> 00:07:38,913
And that's our show this weekend.
116
00:07:38,913 --> 00:07:42,453
We have our month in review panel a little
late, but it got bumped by our breaking
117
00:07:42,453 --> 00:07:44,223
story from the whistleblower last week.
118
00:07:44,283 --> 00:07:47,213
And We're back with our panel
and some great discussion.
119
00:07:47,213 --> 00:07:50,273
I hope you can join us Saturday
morning or whenever you're free to.
120
00:07:50,273 --> 00:07:50,633
Listen.
121
00:07:51,263 --> 00:07:53,933
It's our big Canadian holiday
this weekend, and we will not
122
00:07:53,933 --> 00:07:55,373
have an episode Monday morning.
123
00:07:55,433 --> 00:07:59,813
I'll be off and back in the
news chair on Wednesday morning
124
00:07:59,843 --> 00:08:01,943
with more cybersecurity news.
125
00:08:02,123 --> 00:08:03,173
I'm your host, Jim Love.
126
00:08:03,383 --> 00:08:07,313
Thanks for listening, and if you're
in Canada, enjoy the two four weekend.