Tag Archive for: Anonymous

T-Mobile DDoS Attack Was Just a Network Issue

A tweet meant to spread misinformation sent much of the U.S. into a panic on Monday. A countrywide T-Mobile network outage was mistaken for a Distributed-Denial-of-Service attack when the Twitter account @YourAnonCentral claiming to be Anonymous affiliated tweeted Monday about a major DDoS attack on the U.S. Included in the tweet was a world map claiming to show proof of the large DDoS attack on the U.S.

Marcus Hutchins, a former black hat hacker turned white hat and cyber researcher responsible for stopping the WannaCry ransomware attacks in 2017, along with other cyber researchers, proved these tweets false that same day. About the map, Hutchins said it “show[s] a random sample of global DDoS traffic badly plotted on a world map. It does not indicate an attack against the US, it lacks context to make any inferences at all (other than DDoS attacks are happening all day every day).”

https://twitter.com/MalwareTechBlog/status/1272647109833940992

Other false reports of major outages with other services added to the confusion. The popular site for detecting outages Downdectector did detect outages for other major cellular carriers (Verizon, AT&T, Metro, Sprint, Consumer Cellular, US Cellular). However, Verizon assured DCD that its network was performing well: “We’re aware that another carrier is having network issues. Calls to and from that carrier may receive an error message. We understand Downdetector is falsely reporting Verizon network issues.”

AT&T also reported that its network was working properly.

https://twitter.com/ATTNEWS/status/1272642265056522242

Additional popular services were reported to be under attack, but researchers believe that this may be in consequence of T-Mobile users not being able to reach those services. Among those reported to be having problems were internet providers (Spectrum, Comcast, CenturyLink, Cox), social media platforms (Facebook, Instagram, Twitter, Snapchat, Twitter), gaming services (Fortnite, Roblox, Call of Duty, Steam, Xbox Live, Playstation Network), streaming services (Netflix, Hulu, HBO Now, Twitch), Banks (Chase Bank, Bank of America), and other major services (Doordash, Google, Zoom).

https://twitter.com/MalwareTechBlog/status/1272656800400044032

T-Mobile was able to fix what turned out to be a routing issue by 11 pm Monday evening. T-Mobile’s President of Technology Neville Ray tweeted an apology, with a promise that improvements were made to prevent future events like this.

Even though the panic of Twitter users turned out to be for nothing, this false alarm seems to beg the question, what would have happened if such a large scale DDoS attack had been real?

Many of the reported issues were with services that have become staples to businesses and individuals during this pandemic. Without telecommunication and technology services available, would people know how to survive? Events like this should be a wakeup call to organizations, to review and update their disaster recovery plans, or to create one if they don’t have an existing plan. On this blog, we have focused mainly on ransomware and how to recover from a ransomware attack, but a disaster recovery plan should cover all types of cyber threats, including DDoS attacks.

If your company does not have a disaster recovery plan for DDoS attacks (whether pointed at your organization or the services you use), try asking yourselves questions similar to these: Does your organization have a plan in place if you were to lose cell or internet service? What are your organization’s next steps in the event of a DDoS attack to get your services back up? Have you talked to your service providers about services or tools that can help? Do you have locally backed-up copies of mission-critical data? While creating a disaster recovery plan is time consuming, it will always be worth it.

The Top Cybersecurity Concerns for the Upcoming Elections

2020 has not been our year. We won’t air out its dirty laundry, but we all can remember the events that had plagued these first 6 months, with the Coronavirus Pandemic taking the cake. Across the internet, users are wondering “What is coming next?” The Coronavirus seems to have ruined all of our 2020 plans, including future plans, like large wedding celebrations, summer vacations, and now the 2020 elections. 

Heightened Security Concerns with 2020 Elections

Election officials are concerned about the cybersecurity of the upcoming elections, given the entirely new and unplanned circumstances we’ve found ourselves in. Close to 1 billion dollars have been poured into improving security measures for the elections after the 2016 elections were affected by Russian hackers. However, despite the large sums of money that have been put into the increased security, new concerns have arisen that weren’t originally addressed in the security upgrade because of the pandemic. For example, there are many new costs associated with voting facilities because of the pandemic, namely, hand sanitizer and hand-washing stations, as well as the shortage of space needed in current voting facilities to appropriately distance voters and poll workers, as well as an increase in the number of mail-in ballots. These extra costs are coming at the same time when budgets are imploding, and state and local governments do not have extra money available to fund these extra costs. 

Additionally, officials are concerned about the security (or lack thereof) for new online registration portals, which many states have hastily built to help voters social distance. During the 2016 presidential elections, Russian military intelligence conducted cyberattacks against at least one U.S. voting software supplier and spear phished over 100 local election officials. Concerns are that these registration portals could contain security vulnerabilities because of the speed at which they were built. 

Increased Risk in Government Employees Being Spearphished

The Coronavirus has also increased the possibility of local voting officials falling victim to spearphishing attacks because of the number of government employees working from home. While working from home, employees do not have access to all of the safeguards provided at their offices. Beyond secure networks, less physical interaction with coworkers means less communication and more confusion, leaving them more vulnerable to mistaking spearphishing emails as legitimate. 

Misinformation Campaigns on Social Media

Social Media also presents similar security issues with the upcoming elections. Social media became an essential source of information for the 2016 elections and has become an even more central source of election news and information now because of the pandemic. Experts are saying that they expect to see (and have seen) misinformation campaigns closer to elections, set on confusing and swaying voters with incorrect information. 

Most recently, famous blogger Marcus Hutchins reported on his twitter account, MalwareTech, a case where an “Anonymous” group created a fake K-pop giveaway account to gain followers, only to change the profile and start tweeting about the Black Lives Matter movement. This is a great example of one of the ways that incorrect information can be spread over social media. 

While Election Officials and Security Experts do have security concerns, as voters and citizens, we can educate ourselves about these issues. By educating ourselves, we are minimizing the chances of ourselves being defrauded by a well-crafted spearphishing attack and other cyber threats. The best defense is being aware and ready for attacks in the recent future.