September Cyber Security Insights

September Cyber Security Insights

Written by tdrayson

This month we look at:

  • the seeming plague of data loss incidents in the public sector and the excuse of human error is really an opportunity for process improvement.
  • the cyber security risk from AI and the threat from WormGPT and FraudGPT.
  • End to End encryption and the Online Safety Bill and amendments to the Investigatory Powers Act.

Data Loss Incidents

At the start of August there was a plethora of data loss incidents. The Electoral Commission lost 40 million voters information who registered to vote between 2014 and 2022 to a hack. All the other incidents were where organisations posted files to the internet containing personal information:

  • Police Service of Northern Ireland - 10,000 records of police and civilian employees detailing first initial, surname, rank and where they worked. The incident happened whilst responding to a Freedom of Information Act request.
  • Scotlands People website made available the records of adoptions dating back more than 100 years detailing the adopted child's first name and new surname.
  • Norfolk and Suffolk Police released the data of 1,230 victims of and witnesses to crimes including names, addresses and dates of birth. The incident happened whilst responding to a Freedom of Information Act request.
  • Cumbria Constabulary posted to its website the names, position and pay and allowance details of every police officer and police staff.

The one common thread in all of these incidents is that human error was blamed for each incident.

Whilst an unfortunate human being did make a mistake and will forever regret that mistake I argue it was process failure. In each incident, if a review stage was included in the process each incident could have been prevented from occurring. The objective of the review stage would have been to review the file in which the data was included to make sure a data loss incident was not about to occur.

The Cyber Security Risk of Artificial Intelligence (AI)

AI is the buzzword of 2023 with the launch of generative AI models like ChatGPT. What are the risks of using such AI models?

What is AI?

AI is another system. At a high level it works as in the below diagram. The person submitting the query to the chatbot can choose the refine the query depending on the output.

Undefined
High level diagram of generative AI

Risks of AI

  1. All data input into the AI model is stored in the model and used. Samsung is the case study of what can happen when coders submitted code to ChatGPT to debug it and someone shared a recording of a management meeting to produce minutes. The code from 2 coders and the meeting information is now in the wild for ChatGPT to feed on.
  2. Personally identifiable information input to AI will also be permanently in the AI model and be learnt from.
  3. The data feeding AI models is all sourced from the internet and contains the bias of exisitng data on the internet. When Alexa was asked the result of the England v Australia match in the recent FIFA Women's World Cup it replied there was no match. the query was refined to ask for the result of the women's England v Australia match the result was returned. More serious examples of inbuilt bias include:
  • Recruitment systems learning from CV's of previous candidates discriminated against women for roles in science, technology, engineering and mathematics.
  • Research by Boston University into bias in AI in the US judicial system concluded the algorithms in AI can amplify the bias against the black, American Indians and Alaska Natives when the data source itself contains bias or is incomplete.
  1. Lack of Governance - although AI has been around for years, think Alexa, Siri, Netflix recommended watch list etc. the launch of Open AI's ChatGPT really brought AI to the attention of the world. Globally there is a lack of regulation whilst AI continues its rapid development. The UK's ICO has issued non-binding guidance whilst it looks as though the EU will be the first to have legally binding regulation with its AI Act although this will not be in force until 2025.

In the meantime AI will be advancing rapidly with the probability that any laws will already be struggling to be relevant when they come into force.

Threats of AI

Whilst we are all aware of ChatGPT how many of us have heard of FraudGPT and WormGPT. These are AI tools in the threat actors world, the Dark Web.

FraudGPT helps threat actors to perfect phishing emails in any language, even suggesting where to put the malicious link in the email. It could also create fake websites to collect visitors personal information. Other functionality includes creating malicious code, develop "undetectable" malware, find vulnerabilities and identify targets.

WormGPT, like FraudGPT, has no ethical boundaries or limitations. WormGPT writes malicious software. AI cyber security firm SlashNext's researchers got WormGPT to create a business email compromise (BEC) phishing lure to encourage employees to pay a fake invoice. The results were unsettling with WormGPT creating an email that was not only remarkably persuasive but also strategically cunning, showcasing its potential for sophisticated phishing and BEC attacks.

The UK's Online Safety Bill and Investigatory Powers Act updates and End to End Encryption

The UK is looking to introduce a new law (Online Safety Bill) and update an existing one (Investigatory Powers Act) which could have global consequences for end to end encryption in messaging apps.

What both laws are attempting to do is to enable law enforcement agencies to combat child sexual abuse, criminal activity and terrorism. The method of doing this is to require big tech to scan all our messages before they are encrypted, i.e. create a back door into the messaging apps, such as WhatsApp, Signal and Apple's FaceTime and Messages apps.

I do not think that anybody disagrees with the sentiment of these laws but the risks are:

  • once there is a backdoor into an app the threat actors will find a way to take advantage of the vulnerability.
  • whilst the UK Government presumably is not interested in your family WhatsApp group other governments' will use that scanning of messages to find their opponents.

What is going to happen? Big tech are taking on the UK Government and saying that they will stop the WhatsApp, Signal, FaceTime and Messages service in the UK.

The laws are also giving the wrong signal for tech investment in the UK with the tech companies saying there is not an innovative culture and environment to warrant investing in the UK.

As I said above I am sure no-one disagrees with the sentiment of both laws but surely we cannot turn the UK into a technology backwater?


Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right