Travelex being held to ransom by hackers
bbc.co.uk
bbc.co.uk
The hole in the wall forex place near me has wayyyyyy better rates than an airport’s currency desk.
Practically anyone does.
Fuck you PNC.
Of course you could buy your croissants from the Carrefour, but who would want to do that???
I get better Canadian dollar to Thai Baht rates after I land in Thailand (high demand for stable foreign currency over there), vs trying to buy THB while in Canada, as retailer desks have premiums for holding it.
Wait, so now we should have customer data in more locations?! I'm not disagreeing at all - except that that seems directly contrary to the "intent" of the GDPR in the first place (though you could cynically say that the real intent of the GDPR was to raise money, employ bureaucrats, and shake down mainly-U.S. companies.
Granted this was years ago - I don't know what people do these days if all backend servers are unavailable.
I guess the alternative to "planned maintenance" is the more-accurate message of "OMG - shit's on fire dude!" but that is not appropriate for corporate PR speak ;-)
Sounds to me like someone probably got a "turn everything off while the police investigate - do not touch anything or we'll chop your fingers off/fire you" edict from management, so they wont even put up an unplanned-emergency message for fear of crossing-management/damaging evidence/screwing up while putting up a rushed message/letting hackers back in/etc
They should put up a responsible message and pro-actively notify customers too. I hope they will get the highest possible fine for GDPR violations. This is an appalling response and treatment of customer data.
Travelex should have notified their supervisory authority within 72 hours of the breach, and are also required to notify end users in a timely manner.
https://gdpr-info.eu/art-34-gdpr/
According to the article, end users still have not been notified.
The lack of timely and proper notification as well as the misleading website information can be taken into account by the data protection authority in determining if the company should be fined, and the fines in question can be quite substantial.
To clarify, it's not that Travelex is located in or operates in Europe, it's that they hold data of EU residents. If they operated in Zimbabwe yet held data on EU residents, they would still be bound by GDPR.
But your question is interesting. Imagine an onion service, theoretically perfectly shielded, that took Personal Data from it users and then sold it. Or even a normal Internet service, based in North Korea. GDPR would be unenforceable.
Ultimately we depend on the norms of international agreements, the desire and need to interoperate with global banking systems, etc.
The GDPR text basically says "we'll ask other countries nicely and negotiate with them".
I'll be interested to see how the first real case goes against even a US-based entity that doesn't operate in the EU, much less one based in a country like North Korea.
..they'll ask all the EU ISPs in each of 28 member states to block company X - nicely.
() "EU citizens" meaning potential customers of company X - the "enticement" for company X to pay the EU the fine.
All kinds of companies, from all over the world (eu or not) flooding the GDPR headquarters in Brussels with "pre-emptory warnings". The purpose of course being to let them know how ridiculous (and possibly/probably arbitrary) their regulatory framework
And is anyone else annoyed that since GDPR started, every single website that even so much as stores your username now has a "this website uses cookies" thing you have to click on to get rid of it? And if you turn off cookies, you see this damn intrusive thing every single time. How is this making the web "safer"?! Can "we" (whatever that means) petition them to enact a standard where people can set a preference in their web browsers that says "I don't care unless it's financial/medical/physical-address data" It's a $#%$5# pain in the collective derriere.
I wouldn't be surprised if some websites are doing it as a matter of course, "just in case" - like the "this product contains things that are known to cause cancer cause cancer to the state of California" - applied to everything - in a catalog that sells drill bits (okay, I suppose the couple of nano-grams of drill-bit-dust coming off it). Just to be safe (pun unintended).
I am indeed very annoyed that so many companies are throwing an online tantrum over the very reasonable requirements of GDPR. Most of those cookie banners aren't even GDPR-compliant because they don't let you opt-out of tracking and don't actually tell you what data they are tracking or who they are giving it to.
Just tell people what you are actually fucking doing with their data and let them opt-out of having their data collected. It's not that fucking hard.
In a hypothetical situation of a non EU company significantly breaching GDPR this could be resolved by e.g. seizing all funds belonging to the company in EU banks or in extremes by finding the company's board in contempt of court and then arresting and imprisoning them if they ever travel to a country with a extradition agreement.
I'm puzzled by this:
> "Stealing data essentially gives threat actors additional bargaining chips when it comes to dealing with companies unwilling to pay the ransom. The idea is to weaponise the hefty fines associated with GDPR violations to pressure the company into paying."
I can't imagine that promises from REvil/Sodinokibi that stolen data had been deleted would reduce fines over GDPR violations.
Website's "fine" - it's just waiting to be plugged into something that works.
* https://twitter.com/joetidy/status/1214599174664138757
edit: also they gave a different (spreading virus v. third party issue) statement here earlier: https://eandt.theiet.org/content/articles/2020/01/travelex-t...
has information about this being specific ransomware.
One possible vector for the attack, from that article, is that apparently they had an unsecured pulse Secure VPN which has a known and quite nasty vulnerability, which is being actively exploited.
Looks like they had aspiration to IPO earlier in 2019, imagine this would now not be on the cards for a long time.
I wonder how much the ransom is for. It appears to be an enormously damaging attack - I wonder if paying it is the best option for their business at this stage, then follow the money.
You might not even find out the original entry point, and stop others following. Also it will be expensive.
Sure there are the basic security hygiene steps etc, but what architectural steps can you take to combat this risk?
I have some thoughts (e.g. append-only logs replicated in multiple places, everything 12-factor'd and containerised and ready to re-deploy at a moment's notice etc), but curious what prevailing wisdom is?
The only real form of true immunity to private information theft is to have no private information. It's impossible to lose what you do not have. Everything else is layered controls and policies to detect, alarm, contain, deter, and otherwise enable you to deal with attacks as they come. That's what good defenses looks like for most companies - defense in depth.
In practice, it often looks like aggressive patching policies and administrative controls coupled with careful monitoring, limited access to production, and regular audits. Security is a whole-enterprise problem, rather than a purely technical one that can be entirely addressed by code fixes.
An interesting question is would you rather your bank leaked some personal information about you, or would you rather they lost all your information, and therefore all of your money?
A company outside finance might definitely have these problems!
Gee - how long until the GDPR-o-crats demand a fine from a company (possibly the "right to be forgotten" thing), and the company then uses the defense that "we would have destroyed the information, except for some other EU regulation.. You figure your own way out of that logical puzzle!"
In this case, it means that an append-only data store with a fixed retention time might be a perfectly reasonable way to store certain kinds of records. This means that an append-only data store is not guaranteed to run up against deletion requirements in all cases.
In my opinion, this is particularly salient and worth being aware of when the conversation centers around a financial company, data storage, GDPR, and deletion requirements. It is possibly not always likely to be as simple as "use append-only" or "append-only likely to be illegal".
Of course GDPR defenders tend to take a stance of, anything reasonable is actually not illegal under GDPR even if it might appear to be so at first. It really is a horribly vague and useless piece of law making. I really hope the UK scraps it after Brexit, though I don't hold out much hope.
https://docs.microsoft.com/en-us/windows/security/threat-pro...
Don't get me wrong, the criminals who conducted this should be tracked and brought to justice, but - to use an analogy - if your bank kept your hard-earned cash in a big pile next to the entrance door, wouldn't you feel a tad unhappy with the bank if it got stolen?
And shoudldn't proper reporting paint a slightly more rounded picture of what actually happened (as in: how easy was it for the hackers to circumvent security measures at Travelex?)
Canada doesn’t let you pay hostage ransoms (per law), but has never charged anyone either.
But the article says all computer systems are off which is clearly not the case so who knows...
That said, there has been news of late that these kinds of attacks are indeed stepping up the value chain of stealing, selling, mining the data itself. But I would tend to think not, in this case, as the ransom note would have been much more severe.
Anyone who pays the terrible airport rates for large conversions is probably laundering money.
Literally every other option is better.
Unlike typical ransomware, the threat isn't "we will delete all this data," but "we will sell all this data, and you will amass crippling fines under the GDPR regulations."