This week:

3 – What have Harrods, M&S, and Co-Op got in common?

2 – SaaS solutions are quietly enabling cyber attackers

1 – A fool-proof process is no match for a fooled human

 


 

3 – What have Harrods, M&S, and Co-Op got in common?

“Harrods has confirmed it was targeted in a cyberattack, becoming the third major UK retailer to report cyberattacks in a week following incidents at M&S and the Co-op.”

Source: Bleeping Computer

 

What’s the story?

Luxury department store Harrods became the third major UK retailer, after Marks & Spencer and the Co-op, to be targeted in a cyberattack in recent weeks.

Harrods reported attempts to gain unauthorised access to its systems, prompting the company to restrict internet access at its sites. 

M&S has been communicating with customers over the last number of weeks about an incident that they are currently dealing with.

And Co-op has also announced that they are dealing with an attempted attack. Apparently, it has told its 70,000 employees that remote access to many internal systems is currently disabled and instructed them to vigilant when using email and Microsoft Teams, including requiring all staff to turn on their cameras during online meetings so they can confirm their identity.

 

So what?

Perhaps it’s coincidence that 3 similar organisations have suffered similar attacks at the same time.

But perhaps there is one common platform or third party provider that all 3 of these organisations use, and it is the platform or provider that has been the attacker’s access point.

Only time will tell.

 


 

2 – SaaS solutions are quietly enabling cyber attackers

“The widely accepted software-as-a-service (SaaS) delivery model contains significant flaws and is ‘quietly enabling cyber attackers’, introducing widespread vulnerabilities that could undermine the global economic system.”

Source: Computer Weekly (PS Thanks to everyone who sent this letter my way.)

What’s the story?

JPMorgan Chase’s CISO recently published an Open Letter criticising the current SaaS delivery model, as it creates single points of failure and magnifies the impact of security weaknesses. He highlights issues such as insecure authentication tokens, unauthorised privileged access, and the frequent reliance on a long chain of downstream suppliers that SaaS clients are never told about.

He pointed out that over the past three years, JPMorgan Chase has experienced several incidents involving third-party providers, which required swift and decisive action, including isolating compromised providers and dedicating substantial resources to threat mitigation.

The CISO urges SaaS providers to prioritise security of their current platforms over speed of new feature releases, to modernise their security architectures, and to enhance collaboration to make it harder for attackers to gain access to their platforms and their clients’ data.

 

So what?

SaaS* solutions are everywhere in the financial services world (and possibly in the UK retail world too).

They provide excellent solutions and can be deployed quickly. But, one security weakness in a SaaS platform exposes all of the platform’s clients to many operational risks (not just security risks).

When choosing a SaaS solution, we need to ensure we take the time to ensure the platform is secure.

(* Not sure what a ‘SaaS’ is? Common examples are Microsoft 365 or Google Workspace. A very rough rule of thumb is if you log in to a system through a browser to perform some sort of business activity or process, you’re probably logging into a SaaS).

 


 

1 – A fool-proof process is no match for a fooled human

“A fraudster tricked the City of Portland into redirecting $6.7 million meant for a [legitimate] vendor.”

Source: Oregon Live (via Secure The Village)

 

What’s the story?

Last month, the City of Portland almost fell victim to a $6.7 million fraud when a scammer impersonated a vendor associated with a massive infrastructure project. The fraudster managed to reroute a $6.7 million payment to their bank account. It looks like the fraud only failed because a bank spotted the unusual transaction and alerted the FBI and the City. 

While it is unclear how the fraud (almost) succeeded, news reports state that the City has a fool-proof process in place to ensure payment-related requests from vendors are only approved if the requestor responds to an automated verification email sent to the vendor’s verified email address.

The fraudster did not have access to this verified email account, so that should have meant their request would have been ignored.

But..

“The fraudster persisted, and a “deceived” employee responded with a link that let the [fraudster] reset the vendor’s payment information.”

 

So what? 

‘Payment Redirection’ is the most common type of cyber attack.

To defend against it, you must have a fool-proof process in your Finance department.

But you also need fool-proof humans in your Finance department.