773-516-5658 | Se Habla Español

LOGO_COLOR_EXT_SMLLOGO_COLOR_EXT_SMLLOGO_COLOR_EXT_SMLLOGO_COLOR_EXT_SML
  • Home
  • SERVICES
    • In-store Services
      • Mobile Device Repair
      • Screen Repair
    • In-store Support
    • Remote Support
      • Why Remote Support?
    • Small Business Support
  • MEMBERS
    • Become a Member
    • Member Access
    • Pay Online
    • RESET USER PASSWORD
  • STORES
  • TECH BLOG
  • ABOUT US
    • FAQS
    • Videos & Testimonials
    • Partners and Certifications
  • CONTACT US

Cyberthreats and the finance sector

March 6, 2019

The financial sector has long been heavily targeted by cybercriminals. Over the years, the number of attacks that involved extortion, social engineering, and credential-stealing malware has surged rapidly. This means that financial institutions should strive to familiarize themselves with the threats and the agents behind them. Here are seven new threats and tactics, techniques, and procedures that security professionals should know about.

Extortion
Distributed denial of service (DDoS) attacks, which are typically delivered from massive botnets of zombie computers or internet of things (IoT) devices, have been used to bring down banking networks. This occurs when a targeted server or system is overwhelmed by multiple compromised networks. It’s essentially like a traffic jam clogging up the highway, preventing regular traffic from arriving at its intended destination.

Some cybercriminals are relentless with DDoS attacks and follow them up with cyberextortion, demanding payment in return for release from costly downtime. Banks cannot defend against these attacks alone, so they rapidly share information among themselves through organizations such as FS-ISAC4 and rely upon the ability of their internet service provider to handle and redirect massive quantities of traffic.

Social media attacks
This happens when fraudsters use fake profiles to gather information for social engineering purposes. Thankfully, with new regulations such as the General Data Protection Regulation (GDPR), big companies like Facebook and Twitter have significantly enhanced their security and privacy policy with regards to their data handling practices. The unprecedented reach of social media is something companies cannot afford to ignore because of the possible implications a data breach can have on businesses.

Spear phishing
Spear phishing is an attack where cybercriminals send out targeted emails ostensibly from a known or trusted sender in order to trick the recipient into giving out confidential information. Over the years, hackers have upped their game and cast a bigger net, targeting unwitting employees to wire money. This attack is called business email compromise (BEC), where a fraudster will purport to be a CEO or CFO and request for large money transfers to bogus accounts.

Point-of-sale (PoS) malware
PoS malware targets PoS terminals to steal customer payment (especially credit card) data from retail checkout systems. Cybercriminals use a memory scraper that operates by instantly detecting unencrypted type 2 credit card data, which is then sent to the attacker’s computer to be sold on underground sites.

ATM malware
GreenDispenser is an ATM-specific malware that infects ATMs and allows criminals to extract large sums of money while avoiding detection. Recently, reverse ATM attacks have also emerged. Here, PoS terminals are compromised and money mules reverse transactions after money is withdrawn or sent to another bank account. In October 2015, issuers were mandated to shift to EMV or Chip-and-PIN system to address the weakness of the previous payment system.

Credential theft
Dridex, a well-known credential-stealing software, is a banking Trojan that is generally distributed through phishing emails. It infects computers, steal credentials, and obtain money from victims’ bank accounts.

Other sophisticated threats
Various data breach methods can be combined to extract data on a bigger scale. Targeting multiple geographies and sectors at once, this method normally involves an organized crime syndicate or someone with a highly sophisticated setup. For example, the group Carbanak primarily targeted financial institutions by infiltrating internal networks and installing software that would drain ATMs of cash.

Additionally, with the rise of cryptocurrency, cybercriminals are utilizing cryptojacking, a method that involves the secret use of devices to mine cryptocurrency.

The creation of defensive measures requires extensive knowledge of the lurking threats, and our team of experts is up to date on the latest security information. If you have any questions, feel free to contact us to find out more about TTPs and other weapons in the hacker’s toolbox.

Published with permission from TechAdvisory.org. Source.

Related posts

November 23, 2019

What you need to know about Android malware


Read more
November 20, 2019

Simple tips to prevent Mac ransomware


Read more
November 7, 2019

Fix these enterprise security flaws now


Read more

Recent Posts

  • What you need to know about Android malware
  • Simple tips to prevent Mac ransomware
  • Save on electricity with these PC tips
  • The benefits of Google Tasks
  • Ways Office 365 migrations fail

Archives

  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • August 2017
  • July 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • May 2015
  • April 2015
  • March 2015

Categories

  • Android
  • Android Phone
  • Android Tablet
  • Apple
  • Apple Mac OS
  • Business
  • Business Continuity
  • Business Value
  • Cloud-Google Apps
  • Cloud-Office 365
  • Google
  • Hardware
  • Healthcare
  • Internet Social Networking and Reputation Management
  • iPad
  • iPhone
  • Microsoft Office
  • Microsoft Windows News & Tips
  • Mobile
  • Mobile General
  • Motion
  • Office
  • Photography
  • Productivity
  • Security
  • Social Media
  • Uncategorized
  • Virtualization General
  • Web & Cloud
  • Windows
  • Windows Phone

South Holland Store

  • 516 E 162nd St
    South Holland, IL 60473
  • Phone: 708-333-2700

 

In-store hours

  • 11am – 6:30pm Mon – Sat

 

 

Remote Services

  • 9am – 6:30pm Mon-Fri
  • Phone: 773-516-5658

 

 

©2019 Chicago Computer Club All Rights Reserved.   Privacy Policy