Week in Review: More telecoms breached, Chase blocks Zelle, more DeepSeek bans
Feb 21, 2025
auto_awesome
In this discussion, TC Niedzialkowski, former CISO at Thumbtack and head of security at Nextdoor, dives into the rising threat landscape, particularly with telecom breaches and the tricky dynamics of digital payments. He addresses JP Morgan Chase’s caution in blocking Zelle payments amidst scam risks. The conversation filters through cybersecurity's geopolitical influences, highlighting recent removals like the DeepSeek app. TC also reflects on youth engagement in tech, sharing anecdotes about learning from mistakes and the evolving security landscape.
Chinese hackers are targeting global telecoms using unpatched devices, emphasizing the need for improved cross-sector cybersecurity collaboration.
JP Morgan Chase's decision to block Zelle payments to social media contacts highlights the urgent need for better consumer safeguards in digital payments.
Deep dives
Ongoing Threats from Chinese Hackers
Chinese hackers from the Salt Typhoon Group have been extending their attacks against global telecommunications through unpatched Cisco iOS network devices. This has resulted in significant breaches affecting telecom providers in the U.S., South Africa, Italy, and Thailand. The issue highlights a disturbing trend of recurring threats, particularly as cybersecurity communities may become desensitized to persistent issues involving the same actors. The complexity of these espionage efforts, coupled with the inadequacies in vulnerabilities management, underscores a critical need for coordinated responses across both public and private sectors.
Chase's Action Against Zelle Scams
JP Morgan Chase has decided to block Zelle payments to social media contacts starting March 23rd in a bid to combat the rising trend of online scams associated with the payment service. Zelle, designed for quick transactions between trusted parties, has been exploited for fraudulent deals on social media due to its lack of purchase protection. This proactive measure, while necessary, comes years after Zelle's launch and raises questions about the adequacy of consumer safeguards built into digital payment platforms. The need for educational awareness among users about the risks associated with fast payment systems remains imperative, especially for vulnerable populations.
Settlement Over False Compliance Claims
Health Net Federal Services and its parent company, Centene Corporation, have settled for over $11 million after being accused of falsely certifying compliance with cybersecurity regulations a decade ago. This unusual and accelerated settlement sheds light on the persistent challenges surrounding cybersecurity compliance in complex supply chains. The fact that internal auditors flagged the compliance issues is concerning, reflecting a broader issue in the industry regarding accountability and the enforcement of cybersecurity standards. Moving forward, reliance on audits to ensure compliance must be reinforced, as the effectiveness of deterrents like financial penalties can be questioned after such an extended duration.
Security Breaches Involving DeepSeek
South Korea has removed the DeepSeek app from its app stores following concerns from multiple government agencies regarding data security vulnerabilities. The ban is part of a larger international response to perceived threats from Chinese-backed platforms and emphasizes the importance of maintaining a secure communication environment amid geopolitical tensions. Although existing users can continue to access DeepSeek through its website, the move highlights the complex interplay of cybersecurity and domestic politics. It also raises critical questions about how governments can better manage the influence of potentially malicious technologies on national security and consumer privacy.
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
All links and the video of this episode can be found on CISO Series.com
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode