{"id":22199,"date":"2016-04-15T18:15:58","date_gmt":"2016-04-15T10:15:58","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=22199"},"modified":"2016-04-15T18:15:58","modified_gmt":"2016-04-15T10:15:58","slug":"cyberattacks-bad-guys","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2016\/04\/15\/cyberattacks-bad-guys\/","title":{"rendered":"Cyberattacks: Who are the bad guys?"},"content":{"rendered":"<p>Just recently, the website of the Commission on Elections (Comelec) was hacked by hacktivist group Anonymous Philippines, leaking personal information of 55 million registered Filipino voters, including 1.3 million passport numbers of Filipinos overseas and 15.8 million records of fingerprints. This could expose those affected to identity theft.<\/p>\n<p>While governments are always the target of hacking, private companies have also been attacked by some form of cyber attack. Thousands of multinational companies generate revenue from the simple information you provide them through surveys or application forms\u2014your data is stored and classified for marketing purposes. Your email address is worth more or less a single cent in USD and the basic information on your credit card plays between $20 to $50. Taken singularly if that were stolen, that doesn\u2019t look like much of a profit.<\/p>\n<p>But ever since crime syndicates realized how lucrative selling information was, companies now have to deal with an even greater horror\u2014their data, their livelihood, being held for ransom through encryption.<\/p>\n<p>Bill Gates\u2019 Trustworthy Computing memo issued 14 years ago triggered Microsoft\u2019s relentless efforts on building the most secure software and platforms that customers and businesses enjoy today, and for good reason.<\/p>\n<p>\u201cThe most attacked entity in the world is The White House,\u201d said Pierre Noel, Microsoft Chief Security Officer for Asia. \u201cCan you guess who\u2019s number two? It\u2019s Microsoft, and that is why there is no other company as the world that\u2019s more vigilant about security than we are.\u201d<\/p>\n<p>At a Security Summit spearheaded by Microsoft Philippines for businesses and government agencies, Noel identified types of cyber culprits that may be lurking within or around unsecure networks and infrastructure.<\/p>\n<p><strong>The Hacktivists<\/strong><\/p>\n<p>Anonymous, one of the most infamous \u201chacktivists\u201d in the world, has taken credit for the hacking of an estimated 38 government websites along with social media accounts of various celebrities. They\u2019ve been observed to utilize different Denial-of-Service (DDoS) attacks\u2014flooding their target\u2019s network with traffic such as spam to incapacitate the target from utilizing any measures to arrest the attack.<\/p>\n<p>\u201cUsually, this group is harmless. Unlike the other cybercrime rings, these people attack you because they simply don\u2019t like you. It\u2019s personal. And they try to make a point by defacing your website or instigating DDoS attacks,\u201d Noel warned.<\/p>\n<p>\u201cHowever, when I see a DDoS attack, you have to be wary of one thing: you are being distracted from a real attack that is happening underneath it.\u201d<\/p>\n<p><strong>Cyberwarfare<\/strong><\/p>\n<p>Despite the popular notion that countries engage in cyberwarfare to declare war, Noel contradicts this by saying, \u201cCyberwarfare is there to nudge you or steal information from you\u2014a form of espionage.\u201d<\/p>\n<p>He further addressed government organizations to acknowledge themselves as targets of these attacks, focusing on building a cyber resilient system rather than a security-centered system: \u201cYou should know that you are subject to cyberwarfare. If these people will try to attack you, no matter how much money you spend or how many people you employ to try and stop these attacks, they will succeed. What you need to do is to make sure that these attacks will not impact your organization in a significant way through resiliency.\u201d<\/p>\n<p><strong>Organized Crime<\/strong><\/p>\n<p>Noel identified organized crime associations that take a more terrorist approach to cybercrime, employing ransom and blackmail attacks to extort money in the form of Bitcoins and other currencies from their victims.<\/p>\n<p>\u201cThe first thing to know about these cyber criminals is that they are very much like terrorists\u2014they follow no rules. They will do everything in their power to extort from you,\u201d he said. \u201cThey just want money.<\/p>\n<p>\u201cInstead of stealing your data, they encrypt your data demanding you to pay money to have it back.\u201d<\/p>\n<p><strong>Company Personnel<\/strong><\/p>\n<p>Lastly, companies were reminded to be weary of their own employees, and emphasized the importance of setting clear policies, access restrictions, and clear accountability among any personnel who handle sensitive company data and information.<\/p>\n<p>\u201cAll it takes is for one of them to wake up one day and decide that they don\u2019t like you anymore,\u201d he said. Citing the massive credit card data theft in South Korea, where a computer contractor stole credit card data from 20 million Koreans through his company\u2019s system by simply using a thumb drive to collect the information he eventually sold off to marketing agents, Noel urged them to lessen human dependence in systems.<\/p>\n<p>\u201cYou can do whatever background check you want, but know that you can only trust human beings at a certain point,\u201d he advised, \u201cMake sure that there is minimal human interaction with your administration accounts.\u201d<\/p>\n<p><strong>Tips to keep security a top of mind practice<\/strong><\/p>\n<p>\u201cFirst you must start with simple data classification,\u201d Noel advises. \u201cIdentify which of your data is critical to your business and then identify your risks.\u201d<\/p>\n<p>Despite his earlier reminder that behind every security concern is a human being, he persists that companies still need one man to stay in charge of their security network. \u201cSomeone must be ultimately responsible but you need to keep that person under strict control. Like for example, forbidding them from using administrative accounts for email and browsing,\u201d he said \u201cthat\u2019s the person who will work hard to keep your security practices up and keep the admin accounts right under strict control. He\u2019s also the same person you fire when things go wrong,\u201d he added jokingly.<\/p>\n<p>Once employees are kept in check, Noel also urged business owners to have even the most basic of antiviruses on every machine and asked them to desist from using pirated software on any of the office machines. He ended by imploring them to religiously patch operating systems and applications when updates arise. \u201cAlways, always patch your software,\u201d he said \u201cHackers are always multiple steps ahead of you in the security game and a sure way you can keep up with them is if you keep upgrading your systems with the latest versions of the applications.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Just recently, the website of the Commission on Elections (Comelec) was hacked by hacktivist group Anonymous Philippines, leaking personal information of 55 million registered Filipino voters, including 1.3 million passport numbers of Filipinos overseas and 15.8 million records of fingerprints. This could expose those affected to identity theft. While governments are always the target of [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":791,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[4267,495,3800,286,3362],"class_list":["post-22199","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-anonymous","tag-cybersecurity-and-cybercrime","tag-hacking","tag-it-security","tag-microsoft"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/22199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=22199"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/22199\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/791"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=22199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=22199"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=22199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}