Showing posts with label Epsilon data breach email names spear phishing social engineering risks attacks. Show all posts
Showing posts with label Epsilon data breach email names spear phishing social engineering risks attacks. Show all posts

Tuesday, April 19, 2011

Epsilon: What attacks could be executed with the stolen information

Nota: Este post está disponible en Español

In my last post titled “Epsilon Data Breach” I made a brief introduction to Epsilon’s incident and made some remarks on the risks that this attack implied. In this post I want to go deeper into the possible actions that the attackers could take.

One could think that the stolen information is simply names and e-mail addresses, and that these do not represent a risk. But actually, they do represent a risk to the affected companies. This information is the key to launch a variety of attacks against them or their customers.

Let us do an analysis of the different actions that attackers could perform with the information stolen:
The first action could be as simple as selling the information to Epsilon’s Competitors, which would be very valuable to them because it contains enough data to perform a direct marketing campaign. Although this action is a possibility, it does not represent an important risk to the end users affected because, in a worst case scenario, they will be victims of SPAM.

The second action could be a phishing attack. This massive social engineering attack has as primary objective to deceive its victims by obtaining certain information, like user IDs, passwords and identity data among others. How would this attack take place? It is actually quite easy, since the attacker already possesses all the information necessary about final users.  For example, the attacker could simulate a personal e-mail from the US Bank, Citi or Best Buy, stating that customers should change their password of their home banking or on-line accounts due to the Epsilon breach.  Of course, this would be performed in a web site controlled by him, where he would be able to collect the desired information.

This attack vector was the main reason that forced Epsilon’s customers to notify their own customers about the incident, since this one represents a real risk and it is well known that a Phishing attack wave is imminent.

The third action could be a Spear Phishing attack. In contrast to a traditional Phishing, this technique is targeted to a specific organization or group with the aim to achieve unauthorized access to their systems, and is normally used as part of a mayor attack (like obtaining information stored in an organization’s corporate network).

An example of an anatomy of attack that uses both this technique and the information stolen from Epsilon could be the following:
1.      
  1. The attacker will analyze the information stolen from Epsilon in order to find one or more persons that work at a company of interest (ej. Home Depot Credit Card). To achieve this goal, he will do an extensive research using search pages and social networks (i.e. Google and LinkedIn). Once he has finished their homework, he will end up with a list of persons (victims) , that work at the targeted company, and another list of services / preferences that these people use (i.e. account at US Bank or Citigroup).
  2. Once he has the list of victims, he will design the fake e-mails. The success key factor here will be the information stolen from Epsilon, since it will give the con a feeling of authenticity. The e-mail will also contain an attachment that will exploit a known vulnerability (or unknown / zero day) in order to install a backdoor into the system (a hidden program for remote management). As an example, he could send an e-mail faking to be from the US Bank, addressed to one of the victims (using their full name) that contain an attachment that says “Promotions”.
    If the victim falls prey of the Spear Phishing by opening the attachment, the attacker would have achieved the goal of installing the backdoor that will allow him to access to the system when needed. 
  3. Once inside the corporate network, the attacker would search, with regular hacking techniques, the credentials needed to achieve his objective (i.e. steal credit card information from Home Depot Credit Card). 
  4. Once the attacker gained access to the information, he will extract it through the Internet to an external server controlled by him. Probably he will compress the information with a password in order to prevent being detected. 
  5. His final move will be to erase all the evidence of this unauthorized access.

Is this attack possible? 

If we go back a couple of weeks, we might be able to remember the RSA incident, which shows us that this kind of attack is possible and probable.

These attack vectors are the real risks that companies and end users might be exposed based on the information stolen from Epsilon. It is shown in this post that personal information, even if they are e-mail address or preferences, must be protected not only because of their value, but for their utility to launch a major attack.

What should affected companies do?

First of all, conduct and awareness and training to their employees focusing on social engineering, such as Phishing. If they use their e-mails as a form of Identification and Authentication, they should consider changing it or at least changing their passwords to a strong one (or even better, implement a two-factor authentication mechanism).

Secondly, establish an 0-800 or any toll free number in order to their customers or employees to report any strange e-mail or make inquires. This will allow the company to be alerted for any attack attempt that could happen.

Monday, April 18, 2011

Epsilon: Que ataques se podrían realizar con la información extraída

En mi último post titulado "Robo de datos a Epsilon" hice una breve introducción al incidente de Epsilon y comenté cuales eran  a grandes rasgos los riesgos que implicaba este ataque. En este post quiero profundizar las diferentes acciones que podrían tomar los atacantes.

Inicialmente uno puede llegar a pensar que la información extraída son solo nombres y direcciones de correo electrónico y que en sí no representan un riesgo, pero ésta representa un alto riesgo para las Compañías afectadas, dado que son la piedra fundamental para iniciar diversos ataques contra ellas mismas ó sus clientes.

Hagamos un análisis de las diferentes acciones que podrían tomar los atacantes con la información extraída:

La primera acción que podrían tomar es la simple venta de la información extraída  a la competencia,  ya que ésta les sería de mucho valor dado que contiene datos suficientes para realizar una campaña de Marketing directa. Sin embargo, esta es la acción que menor riesgo para los clientes afectados de Epsilon, ya que en el peor caso, sus clientes serán victimas de SPAM.

La segunda  acción podría ser un ataque del tipo Phishing. Éste es un ataque de ingeniería social masivo que tiene como objetivo engañar a sus víctimas para así lograr su objetivo (obtener información, como ser usuarios, contraseñas y datos de identidad, entre otros).  ¿Cómo se ejecutaría este ataque? Bastante sencillo, ya que consideramos que el atacante posee toda la información necesaria sobre los usuarios finales. A modo de ejemplo,  éste podría simular un correo personalizado del US Bank, Citi ó Best Buy invitando a los clientes a cambiar las contraseñas de su home banking ó cuentas on-line  a causa del robo de información sufrido. Claro que estas acciones se llevarán a cabo en un sitio controlado por el atacante y así  éste obtendrá la información que desea.

Este vector de ataque fue el principal motivo por el cual los clientes afectados de Epsilon notificaron a sus propios clientes sobre el  incidente, ya que éste representa un riesgo y es sabido que una ola de ataques de Phishing es inminente.  

La tercera acción podría ser un ataque del tipo Spear Phishing. A diferencia del Phishing tradicional, este  tipo de ataque es dirigido a una organización ó grupo específico con el objetivo de ingresar a los sistemas y normalmente  se utiliza como parte de un  ataque mayor,  como ser robar información de una compañía.

Un ejemplo de una anatomía de ataque que utilice tanto esta técnica como la información extraída de Epsilon podría ser el siguiente:
  1. El atacante analizará la información extraída de Epsilon en búsqueda de una ó varias personas que trabajen en un objetivo de interés (ej. Home Depot Credit Card). Para esto, realizará un arduo trabajo de inteligencia utilizando buscadores  y redes sociales (por ejemplo Google y LinkedIn). Al finalizar esta etapa, tendrá un listado de personas que trabajan en el objetivo y los servicios / preferencias que éstos posean (ej. Cuenta bancaria en el US Bank ó Citigroup).
  2. Una vez definidas las personas, diseñará el correo electrónico a enviar. Para esto, la información extraída de Epsilon juega un factor importante, dado que le da realismo al engaño. También incluirá en el correo un adjunto que hará uso de alguna vulnerabilidad conocida (ó desconocida / Zero Day Exploit) para lograr instalar un backdoor (programa oculto de administración remota) en el sistema. A modo de ejemplo, podría diseñarse un correo del US Bank dirigido a la persona (con su nombre y apellido) que contenga un adjunto que diga “promociones”.
  3. Si la victima cae presa del Spear Phishing abriendo el adjunto, el atacante habrá logrado instalar el  backdoor  que le  permitirá  ingresar al sistema cuando lo desee.
  4. Una vez dentro de la red corporativa, el atacante buscará, mediante técnicas de hackeo tradicionales,  las credenciales necesarias para alcanzar el objetivo del ataque (ej. robar información de tarjetas de crédito de Home Depot Credit Card).
  5. Una vez conseguido el acceso a la información, la misma será extraída por Internet a un servidor externo, también bajo el control del atacante. Lo más probable es que comprima la información con una contraseña para evitar ser detectado.
  6. Para finalizar, el atacante borrará toda evidencia de su acceso no autorizado a los sistemas.

¿Cuán factible es este ataque? Si recordamos el incidente sufrido por RSA no hace mucho, nos indica que este escenario es posible realizar y muy probable que suceda.

Estos vectores de ataque representan los verdaderos riesgos que enfrentan las compañías y clientes finales afectados por el robo de información a Epsilon. Queda demostrado que toda información personal, ya sean direcciones de correo ó preferencias, deben ser protegidas no solo por su valor en sí, sino también por su utilidad en ataques mayores.

¿Qué es lo que deben hacer las compañías afectadas?
Primero que todo, educar a sus clientes y empleados sobre técnicas de ingeniería social, como ser Phishing. Si utilizan la dirección de correo electrónico como medio de Identificación y Autentificación, deberían considerar realizar un cambio de la misma ó al menos cambiar la contraseña a una contraseña fuerte (ó en el mejor de los casos, implementar un sistema de autentificación en base a dos factores).

En segundo instancia, establecer números de llamadas gratuitas para que los clientes y empleados puedan denunciar intentos de ataques ó realizar consultas. Esto le permitirá a la compañía estar alerta ante los posibles intentos que puedan suceder.