Category: Breaches

1
Privacy concerns over Westfield’s ticketless parking system
2
Complex ModPOS Malware Infects Point-of-Sale Terminals in Lead up to Christmas Spend Frenzy
3
Hotel Industry Payment Systems Under Attack
4
Ashley Madison Hackers Release User Data
5
Ashley Madison Data Security Breach
6
Breaches Update – July 2015
7
Breaches Update – June 2015
8
Breaches Update – May 2015
9
Primera Blue Cross Cyberattack
10
Malaysia Airlines Breach

Privacy concerns over Westfield’s ticketless parking system

By Cameron Abbott, Meg Aitken and Shirley Chen

Westfield has sidelined the SMS feature of its ticketless parking system this week due to concerns it breached Australian privacy laws.

Westfield’s newfangled ticketless parking system attempted to make parking quicker and easier for shoppers by scanning car number plates on entry and exit of their carparks, and sending an SMS notification to registered parkers recording their entry time and an alert message when their free parking time was nearly up. To register for the service, users were merely required to provide a name, license plate number and phone number (with no verification).

Privacy experts raised the alarm that any person could register false details and track another person’s physical location via the SMS notifications. This was a particular worry for those in domestic violence situations and could also potentially enable stalking or thieves to determine when homeowners had left their houses. The feature’s Terms and Conditions failed to address any of these issues.

The SMS service is currently suspended as internal investigations are conducted, though the rest of the ticketless parking system and app continue to operate.

Learn more about the ticketless parking system here.

Read the ITNews report on the issue here.

 

Complex ModPOS Malware Infects Point-of-Sale Terminals in Lead up to Christmas Spend Frenzy

By Cameron Abbott and Meg Aitken

While the festive season approaches and retailers prepare for their busiest time of the year, a sophisticated form of point-of-sale malware, known as ‘ModPOS’, has reared its ugly head and is targeting payment terminals in the U.S.

It is estimated that the first ModPOS data hacks occurred in 2013 and that millions of credit and debit cards used at a broad variety of U.S. retailers have since been compromised. The unique complexity of the code, which experts say has never been seen before in malware, made it tricky to decipher.

Cyber security experts have warned that ModPOS has the ability to not only “scrape” credit and debit card numbers from the memory of point-of-sale terminals, but that the multifaceted code also records keystrokes of computer operators and transmits stolen data. If that isn’t enough, the malware is particularly difficult to detect and is reportedly capable of infiltrating despite security software and data controls.

More details about ModPOS malware can be found here.

Hotel Industry Payment Systems Under Attack

By Cameron Abbott and Meg Aitken

Stayed at one of Hilton Worldwide Holdings’ (Hilton) hotels between 18 November – 5 December 2014 or 21 April – 27 July 2015? Check your bank statement.

Within the same week, both the Hilton and Starwood Hotels & Resorts Worldwide Inc. (Starwood) have discovered the point-of-sale terminals at a number of hotels across the globe have been infected with malware.

The malicious malware has enabled hackers to pinch the credit and debit card information of Starwood and Hilton customers, however there is apparently no evidence that personal contact information provided as part of the hotels’ guest-reservation system or loyalty rewards program was stolen.

While the attack on Starwood was confined to 54 of its hotels in North America, the Hilton attack affected the chain’s hotels globally, including Australian establishments. The number of cards compromised has not been revealed by either hotel.

Starwood and Hilton hotels are not the only luxury hotel chains to be affected by data hacks in 2015. The Mandarin Oriental and Trump International have also reported data security breaches involving intrusive malware this year. In the case of Starwood the hack occurred over eight months without detection showing how sophisticated some of these attacks are.

Starwood’s media release can be found here. Hilton’s media release can be accessed here.

Ashley Madison Hackers Release User Data

By Cameron Abbott and Melanie Long

On 19 August 2015 the group known as ‘The Impact Team’, who a month earlier hacked into online affair website Ashley Madison, made good on its threat and released a “data dump” of Ashley Madison users’ personal information. A second and larger release of stolen data occurred 2 days later and appears to have included emails sent by Noel Biderman, Ashley Madison’s founder and CEO of parent company Avid Life Media.

Following the release of the stolen data, acting Australian Information Commissioner, Timothy Pilgrim, announced the launch of an investigation into the breach which is to be conducted in liaison with the Office of the Privacy Commissioner of Canada (where Avid Life Media is based). On 28 August 2015 Noel Biderman stepped down from his role as CEO of Avid Life Media.

Read the ABC news’ article in relation to the first data release here.

ABC news’ article relating to second data release can be found here.

The Office of the Australian Information Commissioner’s press release relating to its investigation can be found here.

 

Ashley Madison Data Security Breach

By Cameron Abbott and Melanie Long

On 19 July 2015 the Avid Life Media dating website Ashley Madison, which is aimed at married people who want to have an affair, was hacked by a group known as ‘The Impact Team’. The Impact Team has threatened to release users’ profiles if Ashley Madison and other Avid Life Media websites such as Established Men and Cougar life are not shut down. The Impact Team claims to have stolen the details (including names, addresses, credit card numbers and personal sexual fantasies) of over 37 million users.

The story was broken by Brian Krebs, a former cyber crime writer for the Washington Post, on his blog ‘Krebs on Security’. A link to his article, which includes a statement made by Avid Life Media following the hack, can be found here.

Breaches Update – July 2015

by Jim Bulling and Julia Baldi

U.S. Office of Personal Management (OPM)
The U.S. government has confirmed a second cyber attack on the OPM database. Hackers are confirmed to have stolen the personal information in relation to former, current and prospective federal government employees effecting at least 21.5-mllion people (almost 7% of the entire U.S. population).

See the ABC report here, CNN report here and Guardian report here.

OPM’s website, sets out how person’s may have been affected by the breach and what OPM is doing to assist those affected. OPM has sent notifications to those affected by the incident and is offering free identity theft monitoring and restoration services including identity theft insurance and credit monitoring.

OPM has also outlined a cybersecurity action report, available here.

Read More

Breaches Update – June 2015

by Jim Bulling and Julia Baldi

U.S. Office of Personal Management Breach
The U.S.Government’s Office of Personal Management announced that its database has been subject to a cybersecurity breach. Hackers stole data relating to federal government employees dating back three decades and may effect more than four million people.

See the ABC report here and Forbes report here.

The OPM is offering affected individuals credit monitoring services and identity theft insurance. See the OPM announcement here.

Read More

Breaches Update – May 2015

by Jim Bulling and Julia Baldi

Pacnet
Pacnet, a subsidiary acquired by Telstra in April 2015, was hit by a major data breach affecting thousands of customers including The Australian Federal Police and government agencies. The breach occurred two weeks before the deal to acquire Pacnet by Telstra was finalised but was not disclosed to Telstra. Telstra is reportedly considering its legal options in respect of both the breach and the non-disclosure by the vendors.

See the Sydney Morning Herald article here.

Airline Computer Hacking
The FBI has alleged that a cybersecurity researcher had hacked into airline computers 15-20 times causing aircrafts to climb against pilot instructions.

See the report here.

Read More

Primera Blue Cross Cyberattack

by Jim Bulling and Julia Baldi

Primera Blue Cross, a U.S. health insurer announced up to 11 million customers could have been affected by a cyberattack, with hackers gained access to its computers on May 5 2014, and the breach only being discovered on January 29 2015. Affected customers are eligible for two years of free credit monitoring and identify theft protection services.

See the Primera press release here and a CIO article on the breach here.

Copyright © 2019, K&L Gates LLP. All Rights Reserved.