Entries from October 2, 2016 - October 8, 2016

Thursday
Oct062016

Interesting article from RPost about a socially engineered eMail caused the loss of $480k

image

Businesses cannot rely solely on cyber insurance policies to protect themselves and their clients from certain cybercrimes. In a recent case, Chubb Insurance refused to cover a cyber security loss of $480,000 despite the fact that Chubb had insured the victimized company for computer funds transfer fraud.
The case involved a cyber insurance policy issued to Houston-based Ameriforge Group Inc. (AFGlobal Corp.) by a division of Chubb Group. Criminals impersonating AFGlobal’s CEO convinced the company’s accountant to wire $480,000 to a bank in China. When the fraud was discovered, investigators learned that the foreign bank account had already been emptied and closed.  Source
As it turns out, cyber insurance policies such as the one held by Ameriforge Group may cover forgery of financial instruments (such as checks or drafts), but insurers may not recognize informal email correspondence containing financial instructions or wire information as qualifying financial instruments. Sending financial instructions encrypted in Registered Email messages may add sufficient formality to trigger cyber insurance coverage.
Fund transfer fraud often involves emails that appear to come from a company employee -- in this case, the CEO. The fact that the email has the weight of the CEO’s authority makes this particular tactic effective, as it is difficult to verify an email’s authenticity unless the sender uses a sender authentication service such as the Digital Seal® sender authentication feature included in the RMail service.
In the Chubb case, it is noted that the fraudster seemed familiar with the nature of the longstanding and trusting relationship between the accountant and the CEO, suggesting that the fraudster may have had access to emails between the two. These “fake CEO email” tactics often include email correspondence written with context, vocabulary and style matching the CEO’s normal email interactions. As always, using the RMail email encryption service when corresponding about sensitive transactions is an important preventative measure. 
In this case, the fake CEO email to the accounting director Glen Wurm allegedly said: “Glen, I have assigned you to manage file T521. This is a strictly confidential financial operation, to which takes priority over other tasks. Have you already been contacted by Steven Shapiro (attorney from KPMG)? This is very sensitive, so please only communicate with me through this email, in order for us not to infringe SEC regulations. Please do no speak with anyone by email or phone regarding this. Regards, Gean Stalcup.” Wire instructions followed in a subsequent email with a request to transfer $480,000 for due diligence costs associated with a purported acquisition.

Wednesday
Oct052016

Google Home to be release Nov 4th

Now available for preorder for $129 which is less expensive than the full blown Amazon Echo device. The Verge discussed a unit that they were able to test  that they felt was smarter than Siri and the Alexa stating that it was able to understand context in a question and find information from around the web.

It is going to be available in different colors, and they felt the speakers had better quality than the Echo. Google Home works with YouTube Music and Google Play Music, six months of YouTube Red,  and integrates with Spotify, Pandora, iHeartRadio and TuneIn. Any of the third-party services can be used as the default music service if you like.

Home also acts as a Chromecast Audio receiver, so you can choose to cast the music to any Chromecast-connected television or speakers in the house, and you can play music in multiple rooms at once.

Click here to see The Verge’s article here.

Tuesday
Oct042016

Special offer on Amazon’s Echo Dot

imageAt $49.99, this device is pretty interesting. Dan Seifert from the verge did a quick review that goes over the basic new functions that are coming out that make this very interesting. With Google coming out with its own product to rival this one we are in for some interesting new options in this market. Its worth a quick read above if you interested in this technology.