Cyber Security Insights December 2024

Cyber Security Insights December 2024

Written by Bryan Altimas

I do not actually believe I have just typed December 2024! Welcome to the last edition of Cyber Security Insights of 2024. What a year it has been with supply chain attacks taking a central stage. We have covered supply chain attacks, most notably the Qilin attack on Synnovis which impacted the NHS in London causing the cancellation of thousands of hospital appointments and blood tests. A demonstration of the wider impact of cyber attacks.

We cover another one in this edition under "Why are the Supermarket Shelves Empty?" An attack on Blue Yonder, a US based IT company providing end to end supply chain management software. The attack has caused empty supermarket shelves across the UK.

NHS hospitals in Liverpool are having a torrid time with cyber attacks over the last week. We take a look at what is happening, whether they are linked and is it part of something wider.

As the end of the year approaches reports are issued outlining the threat to the UK from cyber attacks and cyber crime. I have been fortunate, through my membership of the FSB (Federation of Small Businesses not the Russian Federal Security Service FSB!) to have attended 2 events in the last week where the CIFAS reports State of Scams Report 2024 and CIFAS Fraudscape 6 Month Update 2024. Today, the National Cyber Security Centre (NCSC) releases their Annual Review of 2024. Whichever report you look at the UK is under sustained cyber attack with identity fraud the most reported and stolen access credentials increasing significantly.

Of course the UK is not alone and the FBI in the US have just released a public service announcement about the use of AI by criminals to facilitate financial fraud and how to protect ourselves.

I wish you all a Merry Christmas and a Happy New Year!

Why are the Supermarket Shelves Empty?

A major technology supplier to the retail trade suffered a ransomware attack on 21 November. Blue Yonder, a US based global supplier of AI powered systems for fulfilment, delivery and returns for over 3000 companies in 76 countries including the UK. The attack is on the managed service hosted environment.

Morrison's supermarket uses Blue Yonder's warehouse management solution and was implementing back-up processes bu multiple stores reported last week empty shelves. The supermarket is also unable to make deliveries.

Sainsbury's uses Blue Yonder's demand planning, store order planning, warehouse management and fulfilment solutions. They are also using contingency processes and the attack has led to empty shelves of some products.

In the US Starbucks uses Blue Yonder for its team to log their hours, allocate rosters and feed into pay. Again, contingency plans are in use to enable payment before last week's Thanksgiving holiday.

There is no news yet on who the attackers are. However, it is following the pattern of similar attacks this year and is likely to be either a nation state attack or a nation state sponsored attack, the chances are from Russia (although China, Iran and North Korea also attack the UK and US). The attack was primarily focused at the US retail sector ahead of Thanksgiving last week and is part of a continuing strategy to destabilise the west's economies and infrastructure. It is yet another example of how a cyber attack has far reaching consequences.

Talk to us about your supply chain risk either by LinkedIn messenger or by email at info@riversidecourtconsulting.co.uk with the message supply chain.

NHS in Liverpool Under Attack

Hospitals and other medical facilities used to be off limits to threat actors but in 2024 hospitals and doctors' surgeries hold so much sensitive data about us and data is what threat actors are after. Sensitive data is valuable and can be held to ransom.

Alder Hey Children's Hospital have said patient records and other information were compromised. Data has been published online and shared on social media that is purportedly from Alder Hey and Liverpool Heart and Chest Hospital NHS Foundation Trust. The fact that data has possibly been published indicates that a ransom has not been paid. The data published is being verified by the hospitals.

Also attacked in the last week was Wirral University Teaching Hospital NHS Foundation Trust (WUTH). WUTH said in its update "We have reverted to our business continuity processes and are using paper rather than digital in the areas affected. We are working closely with the national cyber security services and we are planning to return to normal services at the earliest opportunity." Some scheduled appointments and procedures have to be re-scheduled. The perpetrators are unknown at this time.

The attackers of Alder Hey, tracked by Microsoft as Vanilla Tempest are a Russian speaking group using Inc ransomware. They have been implicated in many cyber attacks US healthcare organisations. Vanilla Tempest have been active since July 2022.

Talk to us about your cyber security and data protection risk either by LinkedIn messenger or by email at info@riversidecourtconsulting.co.uk with the message risk.

The UK is under Sustained Cyber Attack

Why do I say that? Over the last week I have been invited by the FSB to attend the launch of 2 Cifas reports:

  • State of Scams Report United Kingdom - 2024
  • Cifas Fraudscape 6 month update 2024

In addition today the NCSC released its Annual Review 2024. Richard Horne, CEO of the NCSC, says "We face enduring threats from hostile states and cyber criminals looking to exploit our dependency on the technology that now underpins all aspects of modern life.”

Let's start with the NCSC report. The report calls out China, Russia, North Korea and Iran for conducting nation state or nation state sponsored attacks against the UK with the ultimate aim of destabilising our infrastructure and attacking our democracy.

The NCSC incident response team has responded to 430 incidents requiring their support. 89 incidents were nationally significant and 12 of those were at the top end of the scale of nationally significant incidents. Last year the NCSC incident management team responded to 371 incidents and 62 were nationally significant.

The NCSC believes The NCSC believe that the severity of the risk facing the UK is, widely, underestimated by organisations from all sectors. Basic cyber security practices need to be implemented right across the country. Mass adoption of these measures remains the best way to defend, respond and recover. But it must happen now.

Cifas State of Scams Report 2024

The report conducted by the Global Anti-Scam Alliance (GASA) is astonishing reading. so far in 2024 Britons have lost £11.4 billion (0.4% of GDP) and 50% of the black hole in the economy. The average loss per person was £1,432 ($1,818) and only 18% who lost money were able to recover their losses. A year ago the losses were £7.5bn.

71% do not report the fraud to law enforcement and increase of 5% or do not know who to report it to. For the record it is Action Fraud (https://www.actionfraud.police.uk.

The most common methods of scam delivery remain emails and text/SMS messages, with an 8% increase in SMS scams since last year. Trusted platforms like Gmail, WhatsApp, and Facebook are frequently exploited, with Facebook scams seeing a worrying 12% rise. The continued prevalence of these scams underscores the need for more effective safeguards on popular digital channels.

Shopping scams remain the most prevalent form of fraud in the UK, while investment scams have grown more common since 2023. Victims appear to be drawn in by offers that seem "too good to be true" or by the sense of urgency created and do not verify the legitimacy of these deals.

The mental health impact of falling for a scam cannot be underestimated with 53% of victims reporting a strong emotional toll.

71% of the population have confidence that can spot a scam, however this increased awareness leads to taking more risks.

Cifas Fraudscape 6 Month Update 2024

214,882 cases of fraud were reported to the National Fraud Database (NFD) for the first 6 months of 2024, an increase of 15% over the same period of 2023. The primary reason for the increase is a sharp escalation in account takeover in the telecoms and retail sectors, up by 99% and over 28,000 reports.

The increase in facility takeover reflects a long-term shift in tactics with threat actors increasingly targeting existing accounts to obtain high value products and services. Intelligence suggests that sophisticated attacks allow threat actors to target high volumes of accounts simultaneously, using AI, responding to a growing demand for certain types of compromised data.

Identity fraud rose by 4% but this is driven by impersonations in relation to:

  • Mobile phones up by 102%
  • Personal store cards up 59%
  • Personal current bank accounts up 19%

Cifas members continue to report concerns at the presentation of higher quality false documentation and their use in creating synthetic identities as well as the growing threat of AI technologies to facilitate data harvesting and social engineering. The increasing availability of fraud tool kits and AI platforms provide a route for lower skilled threat actors to create high quality spoofed websites and brand impersonations which are known to offer high success rates and financial returns.

FBI Public Service Announcement in the US

The FBI is warning the public that criminals exploit generative artificial intelligence (AI) to commit fraud on a larger scale which increases the believability of their schemes. Generative AI reduces the time and effort criminals must expend to deceive their targets. Generative AI takes what it has learned from examples input by a user and synthesizes something entirely new based on that information. These tools assist with content creation and can correct for human errors that might otherwise serve as warning signs of fraud. The creation or distribution of synthetic content is not inherently illegal; however, synthetic content can be used to facilitate crimes, such as fraud and extortion. Since it can be difficult to identify when content is AI-generated, the FBI is provides examples of how criminals may use generative AI in their fraud schemes to increase public recognition and scrutiny.

AI is being used in text, images, videos, and deep fake voice cloning to produce high quality content to commit fraud and blackmail.

Tips to Protect Yourself

  • Create a secret word or phrase with your family to verify their identity.
  • Look for subtle imperfections in images and videos, such as distorted hands or feet, unrealistic teeth or eyes, indistinct or irregular faces, unrealistic accessories such as glasses or jewelry, inaccurate shadows, watermarks, lag time, voice matching, and unrealistic movements.
  • Listen closely to the tone and word choice to distinguish between a legitimate phone call from a loved one and an AI-generated vocal cloning.
  • If possible, limit online content of your image or voice, make social media accounts private, and limit followers to people you know to minimize fraudsters' capabilities to use generative AI software to create fraudulent identities for social engineering.
  • Verify the identity of the person calling you by hanging up the phone, researching the contact of the bank or organization purporting to call you, and call the phone number directly.
  • Never share sensitive information with people you have met only online or over the phone.
  • Do not send money, gift cards, cryptocurrency, or other assets to people you do not know or have met only online or over the phone.

Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right