Transcript
Jim Love (0:02)
The FBI warns of growing emergency data email hack attacks Canada orders TikTok to close operations, there's been an arrest in connection with massive Ticketmaster AT&T data breaches, and a Brampton landlord falls victim to an E transfer interception scam. This is Cybersecurity Today. I'm your host Jim Lub. The FBI has issued a warning to Gmail and Outlook users about a new wave of phishing attacks involving compromised government email credentials. Cyber criminals are selling these high quality government email addresses along with stolen subpoena documents for just $100 on dark web forums. These credentials enable attackers to pose as law enforcement officers and request sensitive information using fraudulent emergency data requests. The scam often convinces targets to bypass typical security checks due to the urgent nature of the emergency requests, leading to potential data theft, extortion and ransomware attacks. The first signs of this method appeared in 2023, but the volume and sophistication of these attacks has escalated dramatically in 2024. The FBI recommends several mitigation strategies to combat this threat, including monitoring third party vendor security, using strong password protocols and enabling two factor authentication, but most of all, applying critical thinking when handling unexpected emergency data requests. Additionally, the FBI stressed the importance of verifying the legitimacy of such requests before acting. The FBI and the RCMP in Canada can be contacted to verify the legitimacy of a request by law enforcement and of course use the publicly available number and not any phone details provided by a scammer. Law enforcement agencies around the world are taking these threats very seriously. Interpol, alongside other international agencies, has dismantled a major email phishing and infostealer criminal network in an operation called Synergia 2. This crackdown resulted in 41 arrests and the seizure of numerous devices linked to ransomware and phishing schemes across 95 countries. But as usual, like the mythical hydraulic as one of these scammers gets taken down, others will appear. The Canadian government has ordered TikTok to wind down its Canadian operations, citing national security risks. This decision follows a national security review of the popular video app led by Canada's security and intelligence community. However, Canadians will still be able to use TikTok as the government is not blocking access to the app. Innovation Minister Francois Philippe Champagne said TikTok's operations in Toronto and Vancouver posed a potential threat to national security. We came to the conclusion that these activities would be injurious to national security, champagne told CBC News, without providing further details. Despite shutting down operations, Canadians can continue to use TikTok as we said. Though Champagne urged users to be cautious, parents and Anyone who wants to use the app should be mindful of the risk, he said. Critics claim that TikTok, owned by Chinese firm ByteDance, could expose user data to the Chinese government, a claim that TikTok has denied. TikTok plans to challenge the shutdown order in court, calling the decision harmful to Canadian jobs. The move comes after the US Raised similar concerns, flagging the risk that Chinese authorities could compel Byte Tents to provide access to user data. Authorities in Canada have arrested Alexander Connor Mucha, a suspect in a series of data breaches affecting approximately 165 companies, including Ticketmaster and AT&T. The breaches involved Snowflake's cloud storage services with stolen customer information later posted on Hacking forums. Mucha was arrested on October 30 following a request from the US government. The breaches targeted companies such as Santander Bank, Advanced auto parts and LendingTree with compromised login credentials allowing access to sensitive data. A Brampton landlord, Jai Walia, said he's in shock after two E transfers totaling $4,500 meant for rent payments were intercepted by scammers. Despite his tenants sending the payments, Walia never received the money in his account. The fraud occurred when Walia's email account was hacked. Scammers used the compromised email to set up a fraudulent bank account with auto deposit, and this meant when his tenants sent in E transfers, the funds were automatically deposited into the scammer's account instead of Walia's. Walia was relying on security questions to receive transfers, but once the auto deposit was set up using his email, those funds bypassed him completely. One tenant managed to recover their money, but another remains out to $2,000. Wally has since switched to auto deposit for his own account to prevent this from happening again. Interact Personal transfers have become the most popular way that Canadians exchange funds on a person to person basis, with estimates ranging in the hundreds of thousands of of these transfers every day. While this is dwarfed by the millions of commercial transactions, it's an important means of payment for everyday Canadians. Cybersecurity expert Nick Biasini highlights the importance of securing email accounts, knowing that once fraudsters gain access, they can use it to reset passwords and control linked services. He urges users to enable auto deposit and strengthen email security to avoid similar risks for our American listeners who have different methods. It may be time also to raise awareness that individuals and small businesses are not exempt from these scams. And that's our show for today. You can find links to reports and other details in our show notes@technewsday.com we welcome your comments, tips and the occasional bit of constructive criticism at editorialchnewsday ca. I'm your host, Jim Love. Thanks for listening.
