Risky Business #734 -- The number of hacked Microsoft 365 customers is skyrocketing
Jan 30, 2024
auto_awesome
Australia's assistant foreign minister and cybersecurity enthusiast, Tim Watts, discusses the Ermakov sanctions. Highlights include Microsoft 365 customers impacted by SVR campaign & US govt.'s cyber data purchases. Sublime Security CEO talks QR-code phishing. Discussed topics: Medibank hacker details, Wyden's actions, Ivanti's security missteps, and more.
Sanctioning hackers like Aleksandr Ermakov sends a strong message on cybersecurity consequences.
Australia's ASD utilized offensive cyber capabilities to disrupt Medibank Australia hackers.
Australian government supports cybersecurity efforts in Pacific Islands to mitigate digital threats.
Deep dives
Australia Imposes Sanctions on Cyber Criminal for Medibank Australia Hack
Australia's Assistant Foreign Minister, Tim Watts, led the initiative to sanction Alexander Hermakov for his involvement in the Medibank Australia hack, signaling a clear message that there are costs and consequences for targeting Australia. The sanctions include a travel ban and criminal offense for dealing with Hermakov's assets. The public identification of Hermakov is expected to have impacts in the cyber crime world, creating paranoia among associates.
ASD's Massive Effort to Counter Cyber Crime in Response to Medibank Australia Breach
The Australian Signals Directorate (ASD) engaged in a massive effort involving more than 80 staff to respond to the Medibank Australia breach, working closely with the company's incident response team. ASD utilized its offensive cyber capabilities to disrupt malicious cyber intrusions and attacks, including disabling infrastructure and disrupting the sharing or selling of stolen Medibank private data. The government supported these efforts with significant investment in ASD's offensive capabilities.
Disruption and Cooperation in Addressing Cyber Crime
ASD collaborated with Australian law enforcement, international partners, and industry stakeholders to disrupt cyber criminals involved in the Medibank Australia breach. Utilizing offshore offensive cyber capabilities and global intelligence through partnerships, ASD targeted tools and infrastructure used by the actors to disrupt their operations. Specific actions taken against individuals, like Hermakov, are not disclosed due to security concerns and protection of operational tactics.
Response to Cyber Attacks in the Pacific Islands
The Australian government, led by their cybersecurity minister, has been actively engaged in addressing cybersecurity challenges in the Pacific Islands. Recognizing the vulnerability of these nations due to their reliance on digital connectivity for economic development, the Australian government has taken steps to assist in incident response and cybersecurity measures. By deploying cyber rapid teams with expertise in diplomacy and technical aspects, they aim to swiftly mitigate cyber threats and support these nations during digital disasters.
Detection of QR Code Phishing Threats
The podcast delves into the emergence of QR code phishing threats and the challenges they pose to traditional email security systems. Sublime Security, a company specializing in customizable email security solutions, offers a unique approach to combatting such threats by allowing users to create custom rules and query the filtering system. Their adaptive detection engine can address various delivery methods of malicious QR codes, such as image attachments and HTML embeddings, ensuring a comprehensive defense against evolving cyber threats.
In this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They talk about:
More details on sanctioned Medibank hacker Aleksandr Ermakov
More details on alleged Scattered Spider hacker Noah Michael Urban
RUMINT that the number of Microsoft customers impacted by the SVR oauth/365 campaign is huge
Ron Wyden did something useful…
…then did something stupid
Ivanti’s clown car collides with dumpster fire
Much, much more
This week’s feature guest is Australia’s assistant foreign minister (and cybersecurity tragic) Tim Watts. He joins us to talk about why the Australian government sanctioned Aleksandr Ermakob.
Sublime Security founder and CEO Josh Kamdjou is this week’s sponsor guest. He joins us to talk about combating QR-code phishing.