Hackers obtained the credit card details of some 380,000 British Airways travelers during a two-week data breach this summer that leaves the customers vulnerable to financial fraud, the airline says.
BA's CEO, Alex Cruz, said Friday that enough data was stolen to allow criminals to use credit card information for illicit purposes, and that police are investigating.
We know that the information that has been stolen is name, address, email address, credit card information; that would be credit card number, expiration date and the three-letter code in the back of the credit card, Alex Cruz said.
He added that no passport data had been obtained in what he called a very sophisticated, malicious criminal attack.
It advises people to contact their bank or credit card company if they used the airline's website and mobile app to make or change a booking between 10:58 p.m. London time on Aug. 21 and 9:45 p.m. London time on Sept. 5.
The recommendation does not apply to customers who bought tickets or changed reservations outside those times.
The airline promised to reimburse any financial losses suffered by customers directly because of the theft of this data.
British Airways faces another public relations nightmare as the company has advised that their mobile app and website were the target of a cyber breach which has compromised personal data, specifically the payment card information, of at least 380,000 customers.
The breach was announced on Thursday and customers affected are those who made or changed bookings on the company’s platforms over a 15-day period between 21:58 GMT on August 21 and 20:45 GMT on September 5.
British Airways CEO Alex Cruz issued an apology and appeared on various media on Friday to apologize further for the very sophisticated malicious criminal attack.
Cruz reassured customers that the sites were now secure and investigations were underway as to how the criminals accessed the payment card information of the customers, which included the three-digit CVV number on the back of credit and debit cards.
The CVV is legally not allowed to be stored by companies which is of particular concern in the investigation.
Also of concern is the length of time that the harvesting of customer details was able to continue for over two weeks, with the airline only noticing something was awry on Wednesday night and concluding the serious extent of the criminal activity on Thursday.
Emirates President Sir Tim Clark was speaking at the annual Aviation Festival in London on Friday and offered his rivals some words of consolation saying that BA was dealt a dose of bad luck.
Sir Tim added that airlines can expect further breaches as digital transformation of the business increases.
He said, At Emirates we have strengthened and added resources to the cyber security units. The fact is if you do not spend time and money you are going to be hugely exposed.
IT news site The Register quoted an unnamed expert as saying the cause of the breach may probably come down to either not having an update tested before it goes live, cost-cutting resulting in the site not being tested as often as it should have been or lower quality support, not patching the servers.
The site also reported that on August 1 BA’s Group IT Service Effectiveness Manager had advised staff that management had approved a proposal to outsource the airline’s cyber security to IBM and that a consultation process with affected staff would be initiated.
BA has been under scrutiny in the last few years for the cost-cutting measures and business model changes which have been implemented across the airline under Cruz.
With regard to those customers affected by the breach, Alex Cruz said that: we will compensate them for any financial hardship that they may have suffered.
What that compensation will be is yet to be determined with BA customers taking to social media to express their anger and frustration against the airline.
Affected customers should first seek advice from their bank, then monitor bank and credit card statements closely for signs of possible fraudulent activity.
There could be possible phishing scams in which hackers would try to trick affected consumers into revealing personal information like pincodes or banking passwords.
Some customers are relating stories of being stranded in foreign countries without access to funds as their banks have advised them to cancel their payment cards.
Further concern is being raised of the opportunities the criminals have to use the data obtained in a myriad of fraudulent practices such as creating fake accounts with other companies.
Some angry travelers complained that they had already noted bogus activity on credit cards that had been used to make British Airways bookings during the time when the breach was undetected.
The hack once again puts the spotlight on the strength of the IT systems at major companies as they expand their digital services.
British Airways experienced an IT-related crisis in May last year when roughly 75,000 passengers were stranded after the airline cancelled more than 700 flights over three days because of system problems.
In the UK, the incident is also being investigated by the Information Commissioner’s Office; the National Crime Agency; and National Cyber Security Centre.
If BA is found to be in breach of recent EU GDPR legislation, introduced in May, they may face a fine equivalent to four percent of their annual global revenue.
For the airline, this would equate to £489m in addition to the passenger compensation.
When attempting to access BA’s online Media Center on Friday afternoon to retrieve further updates on the situation, users are prevented from doing so and faced with a Privacy Error message which reads: Attackers might be trying to steal your information from mediacentre.britishairways.com (for example, passwords, messages or credit cards).
In the U.S., Delta Airlines said in April that payment-card information for several hundred thousand customers could have been exposed by a malware breach months earlier.
The same breach also hit Sears Holdings Corp., which operates Kmart stores.
British Airways revealed the new hack Thursday evening and began notifying customers.
Britain's National Crime Agency says it is investigating.
Tourism Observer
Showing posts with label National Cyber Security Centre. Show all posts
Showing posts with label National Cyber Security Centre. Show all posts
Sunday, 9 September 2018
Saturday, 13 May 2017
Cyber Attacks Fast Wreak Havoc Worldwide
A fast-moving wave of cyberattacks swept the globe Friday, apparently exploiting a flaw exposed in documents leaked from the US National Security Agency.
The attacks which experts said affected dozens of countries used a technique known as ransomware that locks users' files unless they pay the attackers a designated sum in the virtual currency Bitcoin.
Affected by the onslaught were computer networks at hospitals in Britain, Russia's interior ministry, the Spanish telecom giant Telefonica and the US delivery firm FedEx and many other organizations.
Britain's National Cyber Security Centre and its National Crime Agency were looking into the UK incidents, which disrupted care at National Health Service facilities.
"This is not targeted at the NHS, it's an international attack and a number of countries and organizations have been affected," British Prime Minister Theresa May said.
Russia's interior ministry said that some of its computers had been hit by a "virus attack" and that efforts were underway to destroy it.
The US Department of Homeland Security's computer emergency response team said it was aware of ransomware infections "in several countries around the world."
Jakub Kroustek of the security firm Avast said in a blog post update around 2000 GMT, "We are now seeing more than 75,000 detections in 99 countries."
Kaspersky researcher Costin Raiu cited 45,000 attacks in 74 countries, saying that the malware, a self-replicating "worm," was spreading quickly.
In a statement, Kaspersky Labs said it was trying to determine whether it is possible to decrypt data locked in the attack with the aim of developing a decryption tool as soon as possible.
It's unequivocally scary, said John Dickson of the Denim Group, a US security consultancy.
Dickson said the malware itself, which exploits a flaw in Windows, was not new but that adding the ransomware "payload" made it especially dangerous.
I'm watching how far this propagates and when governments get involved, he said.
The malware's name is WCry, but analysts were also using variants such as WannaCry.
Forcepoint Security Labs said in a statement that the attack had "global scope" and was affecting networks in Australia, Belgium, France, Germany, Italy and Mexico.
In the United States, FedEx acknowledged it had been hit by malware and was "implementing remediation steps as quickly as possible."
Britain's National Health Service declared a "major incident" after the attack, which forced some hospitals to divert ambulances and scrap operations.
Pictures posted on social media showed screens of NHS computers with images demanding payment of $300 (275 euros) in Bitcoin, saying: "Ooops, your files have been encrypted!"
It demands payment in three days or the price is doubled, and if none is received in seven days, the files will be deleted, according to the screen message.
A hacking group called Shadow Brokers released the malware in April claiming to have discovered the flaw from the NSA, Kaspersky said.
Although Microsoft released a security patch for the flaw earlier this year, many systems have yet to be updated, researchers said.
"Unlike most other attacks, this malware is spreading primarily by direct infection from machine to machine on local networks, rather than purely by email," Lance Cottrell, chief scientist at the US technology group Ntrepid.
The ransomware can spread without anyone opening an email or clicking on a link.
The sort of ransom demands have been growing precedent at medical facilities. In February 2016, a Los Angeles hospital, the Hollywood Presbyterian Medical Center, paid $17,000 in Bitcoin to hackers who took control of its computers for more than a week.
Ransomware becomes particularly nasty when it infects institutions like hospitals, where it can put people's lives in danger, said Kroustek, the Avast analyst.
A spokesman for Barts Health NHS Trust in London said it was experiencing "major IT disruption" and delays at all four of its hospitals.
"We have activated our major incident plan to make sure we can maintain the safety and welfare of patients," the spokesman said. "Ambulances are being diverted to neighboring hospitals."
Two employees at St Bartholomew's Hospital, which is part of Barts Health, told AFP that all the computers in the hospital had been turned off.
Caroline Brennan, 41, went to the hospital to see her brother, who had open heart surgery.
"They told us there was a problem. They said the system was down and that they cannot transfer anyone till the computer system was back up," Brennan said.
Some said the attacks highlighted the need for agencies like the NSA to disclose security flaws so they can be patched.
"These attacks underscore the fact that vulnerabilities will be exploited not just by our security agencies, but by hackers and criminals around the world," said Patrick Toomey of the American Civil Liberties Union.
The attacks which experts said affected dozens of countries used a technique known as ransomware that locks users' files unless they pay the attackers a designated sum in the virtual currency Bitcoin.
Affected by the onslaught were computer networks at hospitals in Britain, Russia's interior ministry, the Spanish telecom giant Telefonica and the US delivery firm FedEx and many other organizations.
Britain's National Cyber Security Centre and its National Crime Agency were looking into the UK incidents, which disrupted care at National Health Service facilities.
"This is not targeted at the NHS, it's an international attack and a number of countries and organizations have been affected," British Prime Minister Theresa May said.
Russia's interior ministry said that some of its computers had been hit by a "virus attack" and that efforts were underway to destroy it.
The US Department of Homeland Security's computer emergency response team said it was aware of ransomware infections "in several countries around the world."
Jakub Kroustek of the security firm Avast said in a blog post update around 2000 GMT, "We are now seeing more than 75,000 detections in 99 countries."
Kaspersky researcher Costin Raiu cited 45,000 attacks in 74 countries, saying that the malware, a self-replicating "worm," was spreading quickly.
In a statement, Kaspersky Labs said it was trying to determine whether it is possible to decrypt data locked in the attack with the aim of developing a decryption tool as soon as possible.
It's unequivocally scary, said John Dickson of the Denim Group, a US security consultancy.
Dickson said the malware itself, which exploits a flaw in Windows, was not new but that adding the ransomware "payload" made it especially dangerous.
I'm watching how far this propagates and when governments get involved, he said.
The malware's name is WCry, but analysts were also using variants such as WannaCry.
Forcepoint Security Labs said in a statement that the attack had "global scope" and was affecting networks in Australia, Belgium, France, Germany, Italy and Mexico.
In the United States, FedEx acknowledged it had been hit by malware and was "implementing remediation steps as quickly as possible."
Britain's National Health Service declared a "major incident" after the attack, which forced some hospitals to divert ambulances and scrap operations.
Pictures posted on social media showed screens of NHS computers with images demanding payment of $300 (275 euros) in Bitcoin, saying: "Ooops, your files have been encrypted!"
It demands payment in three days or the price is doubled, and if none is received in seven days, the files will be deleted, according to the screen message.
A hacking group called Shadow Brokers released the malware in April claiming to have discovered the flaw from the NSA, Kaspersky said.
Although Microsoft released a security patch for the flaw earlier this year, many systems have yet to be updated, researchers said.
"Unlike most other attacks, this malware is spreading primarily by direct infection from machine to machine on local networks, rather than purely by email," Lance Cottrell, chief scientist at the US technology group Ntrepid.
The ransomware can spread without anyone opening an email or clicking on a link.
The sort of ransom demands have been growing precedent at medical facilities. In February 2016, a Los Angeles hospital, the Hollywood Presbyterian Medical Center, paid $17,000 in Bitcoin to hackers who took control of its computers for more than a week.
Ransomware becomes particularly nasty when it infects institutions like hospitals, where it can put people's lives in danger, said Kroustek, the Avast analyst.
A spokesman for Barts Health NHS Trust in London said it was experiencing "major IT disruption" and delays at all four of its hospitals.
"We have activated our major incident plan to make sure we can maintain the safety and welfare of patients," the spokesman said. "Ambulances are being diverted to neighboring hospitals."
Two employees at St Bartholomew's Hospital, which is part of Barts Health, told AFP that all the computers in the hospital had been turned off.
Caroline Brennan, 41, went to the hospital to see her brother, who had open heart surgery.
"They told us there was a problem. They said the system was down and that they cannot transfer anyone till the computer system was back up," Brennan said.
Some said the attacks highlighted the need for agencies like the NSA to disclose security flaws so they can be patched.
"These attacks underscore the fact that vulnerabilities will be exploited not just by our security agencies, but by hackers and criminals around the world," said Patrick Toomey of the American Civil Liberties Union.
Subscribe to:
Posts (Atom)