MOVEit global security incident
maine.gov
maine.gov
Start an activism movement to draw big ugly expensive attention to this whole Social Security Number misuse situation.
My understanding is Americans can get new Social Security Numbers. There is a process for this, requiring at least evidence that their SSN is being used by someone.[1] So take a reasonable interpretation of "used by" ... leaked and/or stolen recently in Maine, now in nefarious hands. Sounds like they "know" a cybercriminal group has this data. Intent to use? Not a stretch, so run with it. Good enough for common sense and popular support.
Yes, maybe this doesn't stand up to courts or IRS judgement but it's not an unreasonable request and an application from every taxpayer in Maine might stir up useful attention or change. i.e. question the half-baked status quo of "let's use SSNs for everyone's key in every database"
The media might enjoy it and keep this issue alive a little longer before it's yet another massive event quickly forgotten.
Or wishful thinking on my part. Sorry, Maine, this sucks.
Yeah, the situation sucks.
But, it was standard practice for at least every medical insurance company and hospital I encountered.
I of course thought this was a bad idea, and found out about the law. Every time I went to interact with a new insurer or hospital, they'd assk for my SSN. I'd say that my SSN can NOT be my ID number, and invariably get in a 5-15 minute argument with the rep. I'd end up telling them to go check with their higher managers. They always came back saying "yes, we can use a different number, here's yours", or with a form filled in with "Assign ID" in the place of my SSN. Once I had my assigned ID, and just kept telling reps that ID when asked for my SSN, things were mostly fine.
Evidently, the main corporate policy was to break the law until someone called them out. Seems it would have been so much easier to just use the database UniqueID function for everyone...
FWIW mine has been laminated since my childhood and decades after the fact I’ve had no real issues with agencies about its lamination
The fact that a criminal knows your SSN doesn't absolve companies of being defrauded by those criminals through their own lax verification.
You should not be liable when entity-A leaks your data and entity-B suffers a loss to someone who has your data. There is no way you could have prevented that eventuality and none of the responsibility should fall on you.
Data security and identity verification will not improve so long as we tolerate laws that pretend we are the victims of these attacks and should suffer the losses, instead of recognizing that the entity that failed to properly identify a criminal is the actual victim.
The losses must be borne by the parties that are truly capable of preventing "identity theft," or nothing will change.
Honestly sounds like a great system. Not a single flaw here.
Government: Here's a number unique to you just for tax-related purposes. No, you can't change it and no, there's no security besides the anti-forgery measures on the card, which is why you can't laminate it. Here it is, you can't have spares, and getting a replacement is annoying, so keep it safe.
Companies: Cool! You've got a tax-filing number? We're gonna use that as your personal secret password for all sorts of important shit because that's super-easy on our end. Remember, if anybody else abuses it then it's totally your fault and not ours. [0]
What alternative exists in countries without an ID system such as the US or UK? Rely on names, date of birth, place of birth? Conflicts are possible in big cities. Not everyone will have a driver's license. So yeah, it's quite easy to decide to use a unique number that everyone already has.
The best alternative is the state ID. In every state you can get a state ID and/or a driver's license (which in almost all states is also a state ID).
They contain a unique identifier and that identifier can be changed by the state if needed down the line.
A federal ID standard would be nice of course but that's never going to happen due to some reasonable concerns (poor implementations resulting in loss of privacy) as well as some absolutely batshit insane ones (the ID system is the mark of the devil).
I'd personally prefer that we establish a standard for a sane distributed trust federated ID system and then pressure the states into gradually adopting that rather than pushing it up to the federal level where it'll then get fucked up and everyone will be stuck with it forever.
https://en.wikipedia.org/wiki/Real_ID_Act
However:
"... on April 27, 2020, the extended deadline after which identification documents would have to satisfy the Real ID Act standards to be accepted by federal agencies was again extended, by one year to October 1, 2021. On May 3, 2021, it was further extended to May 3, 2023, and on December 5, 2022, it was extended once more to May 7, 2025."
But if there's a gold star on your federated state's driver's license, you have it.
That's not the type of solution I'm talking about.
I'm talking about having an independent standards organisation (hell even NIST) produce a standard that supports federation and gradual onboarding by states and territories and then having the states each adopt it until it becomes a defacto national standard without any congressional involvement beyond the federal government also agreeing to accept it.
Real ID is a mess because it's not an ID system. It's really just an ID card system with a few other bits attached to address specific federal government concerns. That's not meaningfully useful for providing unique (and preferably privacy preserving) identifiers for companies, banks, and other non-government entities like what many european countries have.
You should be able to get replacements, but there is a lifetime limit of 10 replacements after 12/17/2005 [1]. I think that means the one from when I lost my wallet in my bedroom doesn't count! (lol, I know, but I had given up all hope, and then months later found the wallet just hanging out between the mattress and the bed frame)
SSA says you can, but with a caveat that a victim should've "attempted to fix problems resulting from the misuse but continues to be disadvantaged by using the original number". I don't know how much of a barrier there is, but theoretically the number is changeable.
I wish that was a joke.
My wife (American) has found it utterly impossible to replace her social security card that went missing at least 7 years ago, despite several attempts. It would be nice to have so she can interact with the DMV when back in the US, and suchlike.
At least where we live now, the equivalent card is infinitely replaceable within days with a simple online form, and the person number is of extremely limited value to fraudsters.
Admittedly, I got the last one close to 20 years ago, but it was an easy process then (I walked into a building, requested it, they mailed it). My parents gave me the other two.
I once looked into getting a replacement card because I'm not sure where mine is, and I didn't bother after reading this (https://www.ssa.gov/number-card/replace-card): "You may not need to replace your card if you know your Social Security number. In most cases, a physical card isn't necessary."
I thought, yeah, I guess I've never actually needed it, so if SSA isn't worried then I won't worry either.
Equifax provided 140 million people's information to the world. It was "shielded" behind a default password that was never changed.
Their penalty? Profits, because they bought an identity protection firm, provided 2 years of free monitoring, for a lifetime problem, then gleefully charged fees for the protection, that their own malfeasance literally caused.
Ok, chances are good you’d just get some other compromised ID, what’s the upside?
Maybe there is something better than some numeric characters?
They had 7 months to fix this, if the cyber security providers and SOCs would do their job correctly.
How can this happen if all of their EDR tech stack, firewall subscriptions and overpriced data enrichment pipelines are supposed to warn about this?
"On May 31, 2023, the State of Maine became aware of a software vulnerability in MOVEit... The software vulnerability was exploited by a group of cybercriminals and allowed them to access and download files belonging to certain agencies in the State of Maine between May 28, 2023, and May 29, 2023."
"Why Am I Hearing About This Now? The State of Maine carried out an extensive evaluation to identify the individuals whose information may have been impacted."
It's not like cl0p was quiet about this. Pretty much any hacking related channel was making fun of the RCE and bypass when "thenoc" was hacked, their and all their customers' (mostly lawyers) stuff was leaked, and cl0p devs bragged about it everywhere on Telegram.
Maybe you should change your cyber intelligence provider if it's just as good as the NVD/NIST databases.
Zero days like this can be easily caught if you have the right sources and don't rely solely on your splunk and fortinet tech stack, you know.
We’re talking about hundreds of organizations running MoveIt. Are they all culpable for not having threat intelligence better than disclosed vulnerabilities in COTS software? Or worse, in their vendors’ software? What should they subscribe to?
So it didn't matter what you were subscribed to as long as that was more than zero things. The ongoing miss everywhere is less about detection or awareness than about response.
Problem is there's lots of these across old back office I.T. stuff all the time, so much noise, and MOVEit is not a "top of mind" tech even though every legacy company uses it or a competitor to exchange files because they haven't heard of Box. So they didn't realize they use MOVEit and didn't think to dig in.
That's the actual issue: not knowing what your firm runs on.
https://www.rapid7.com/blog/post/2023/06/14/etr-cve-2023-343...
Admittedly there are some macro effects that are causing security to be taken more seriously by companies in general. The proliferation of compliance programs especially SOC2 had made basic security the default for a large portion of b2b tech companies. Cyber insurance requirements are increasing. Newer state regulations and SEC regulations have pushed other companies to increase resources dedicated to security.
That said this is an uphill battle after a decade or so of companies having no security with passwords or SSNs in plaintext and everyone having access permissions.
GDPR has such provisions, if the company didn't do enough to protect the data. E.g. British Airways were fined for bad practices and because their website had a card scraper for multiple days which they should have detected.
Now I am not saying it was not stolen, it probably was, seeing as it was a third party service that was compromised. But stealing data(getting an illegal copy of it) is a very different thing than ransomware (the data may have never been copied. but access to it has been lost)
ransomware is the term usually reserved for when the data was not leaked but the owner is unable to access it anymore(unless they pay the ransom).
update: the link was changed to a much better article, so this question no longer makes sense. The data was stolen.
monthly reminder that AML/KYC is a joke if all the banks only think they are dealing with people that would pass AML/KYC
English here to slap you with the Correct Use of the Incorrect.
In the second case, depending on your dialect, you could remove either 'has' or 'just', but not both. In the first case, you can't substitute 'has' with 'just', but you can use both. That's because "(has|just) had" is an idiomatic expression with different rules than "has (just) been".
Without any real laws/enforcement we gwt what we have now: excuses and not taking the responsibiliy seriously.
You can go back to sending letters with your SSN for employment, taxes, etc and ideally that should mean that your information doesn’t go on the internet.
But you’re in the minority in wanting that hassle.
1. Email / web-submit forms
2. Someone saves requests onto a disc and swivel chairs to load them into the offline system for processing
3. Results are written back to disc, which is swivel chaired back to net-connected systems
Congratulations. You've just made physical access (or a much more difficult poisoned data bug) a requirement for data leaks.If you insist on keeping all of this data online, how do you propose preventing what happened with Maine from happening again? Surely you must be willing to acquiesce that there is an increased level of security with OP's proposal in this regard, in spite of a lack of convenience?
Tactically, what could have been done to minimize or prevent this particular incident, while continuing to use MoveIT software:
- Encrypt the files before dropping them onto the file transfer site. Communicate the key out-of-band. This one simple step would have avoided catastrophe. Unfortunately, many MoveIT site operators would not allow their customers to encrypt files sent to them.
- Limit MoveIT site access, by IP address. This is a fairly common practice for file transfer sites.
- Use a frontend, such as a load balancer or reverse proxy, that enforces authentication in front of MoveIT.
- Disable the web site and only allow use of the SFTP (SSH) site.
We have the means to properly secure data, barring internal absolute human malice or incompetence which nothing can defend against anyway.
The problem is most people simply don't want to.
Their whole pattern is “find 0day in some shit -> mass exploitation -> massive data theft -> extortion”.
I can't remember if it was approved or denied, but I have strong suspicion that there's going to be some politicking about this, because people don't understand technology.
It's just a thought, people, relax.
It's easier to downvote you than engage in dialog.
>> I have strong suspicion that there's going to be some politicking about this
Presumably the decision to use MOVEit had to do with political donations /s
Lucky the Director and CIO had traded-out before the hack became public /s
> people don't understand technology.
The people making the technical decisions don't understand the technology /s