Photo by Fergus Burnett Photography fergusburnett.com
October is Cyber Security Awareness month when the cyber security profession raise awareness of risks and how to mitigate them. Of course, we need to be aware 365 days a year.
In the newsletter this month we look at:
One of the most common ways data is accessed is not through the hacking of the technological defences of our environments but by logging in using our stolen access credentials. If the cyber criminals or state sponsored hackers have access credentials to your system why bother to find a vulnerability to exploit.
How do these access credentials come to be in the hands of malicious actors?
Unsurprisingly, many come from phishing attacks, we simply give them away. You receive a message creating a sense of urgency and fear it is very difficult not to respond, that is human nature.
Social engineering attacks are remarkably successful because they are manipulating an individual. The cyber criminals after causing the urgency and fear may try to win your trust. Revolut the e-money firm have the most fraud cases, more than the UK's biggest bank Barclays. In many cases the victim receives a message that it is Revolut's cyber security team contacting them and they are helping them. What they are actually doing is letting the attacker into their account and then they watch the account being drained.
Brute force attacks are the original hack and have been used ever since we have had to log-in to accounts. A brute force attack is where all the attack tries to guess the password by firing commonly used passwords, default passwords and variations of them at accounts to see which one works. Instead of picking the lock of your front door a brute force attack is like using a sledge hammer to knock the door down. It is likely to be quickly detected by cyber security teams.
Credential stuffing attacks are the modern sexy close cousin of brute force attacks. A credential stuffing attack uses user name and password combinations already compromised and available on the dark web. It is more likely to be successful than a brute force attack.
One of the reasons cyber security teams focus on development projects is because it is much easier to download already written code from an online library rather than reinvent the wheel. Of course, there is a real risk that there is malware has been inserted into the code. Frequently, this risk materialises and spreads malware that are often password and information stealers.
Using 2 factor accreditation or multi-factor accreditation will go a long way to mitigating the risk of stolen access credential being used to access your data.
I saw a LinkedIn post where people were changing bank accounts from established high street banks to disruptor financial companies for ethical and idealogical reasons. Whilst this is admirable, cyber security should also be fed into the equation.
The disruptor "banks" (not all have a banking licence currently) do not have high street locations and are online only and have grown supersonically. Revolut had 450k customers in 2017 but by last year had 45 million. Starling bank had 43k customers in 2017 and had grown to 3.6 million by last year.
One would hope that in designing their banking app a secure by design approach had been taken and strong security processes had been implemented.
Unfortunately, this has not always been the case. The BBC current affairs programme Panorama covered fraud at Revolut this week where customers were scammed through criminals calling them saying they were Revolut's cyber security team and their account was under attack. A sense of urgency and fear is created and the customers react and follow the instructions because the criminals, then, created trust in themselves. The scam proceeds by the victim exposing enough of their credentials to allow the scammers to take control of the bank account. Many hundreds of thousands of pounds have been lost. The transactions created by the scammers should have triggered Revolut's genuine security and fraud teams to alert the customers and stop the scam.
Starling Bank has been fined £29 million by the Financial Conduct Authority in October 2024 for financial crime failings related to its financial sanctions screening. Their processes did not keep pace with their growth.
Starling bank has also been involved in similar situations as Revolut but since 2023 appears to have improved its cyber security and related processes.
We regularly talk about having long, strong and complex passwords or password phrases and using a password manager. We are regularly asked if my password is x characters long how quickly will it be hacked?
Hive Systems LLC annually produce a table giving us that information!

Please contact us to discuss any of your cyber security, data protection or regulatory compliance issues either on LinkedIn messenger or by email at info@riversidecourtconsulting.co.uk with the message October.
