Information security photograph

Information Security

Use attributes for filter !
Date of Reg.
Date of Upd.
ID1113959
Send edit request

About Information Security


Information security, sometimes shortened to infosec, is the practice of protecting information by mitigating information risks. It is part of information risk management.

Data theft: Police officers and staff not informed for month

Data theft: Police officers and staff not informed for month
Aug 12,2023 2:11 pm

... " Our Information Security Unit were informed on 27th July, " he said...

TikTok banned on all London City Hall devices amid security concerns

TikTok banned on all London City Hall devices amid security concerns
Mar 25,2023 5:40 am

... A GLA spokesperson told BBC London: " The GLA takes Information Security extremely seriously...

BBC advises staff to delete TikTok from work phones

BBC advises staff to delete TikTok from work phones
Mar 20,2023 10:10 am

... " Staff with the app on a personal phone that they also use for work have been asked to contact the corporation s Information Security team for further discussions, while it reviews concerns around TikTok...

China hits out at US over TikTok ban on federal devices

China hits out at US over TikTok ban on federal devices
Feb 28,2023 8:11 am

... The US Federal Chief Information Security Officer Chris DeRusha said the move emphasised the Biden administration s " ongoing commitment to securing our digital infrastructure and protecting the American people s security and privacy"...

Hostile states are targeting you, Speaker warns MPs

Hostile states are targeting you, Speaker warns MPs
Nov 16,2022 3:01 pm

... One MP told the BBC the warning was necessary because " we are hopelessly slack" about Information Security...

Twitter drama continues with blue-tick confusion

Twitter drama continues with blue-tick confusion
Nov 11,2022 10:50 am

... The sudden departure of the head of trust and safety, the chief Information Security officer, and both the chief privacy and compliance officers is a dramatic development...

How Ukraine is winning the social media war

How Ukraine is winning the social media war
Oct 15,2022 9:01 pm

... More on the information war: The current social media environment, says Ihor Solovey, head of Ukraine s Centre for Strategic Communication and Information Security, reflects a rare convergence of official and popular sentiment...

IHG hack: 'Vindictive' couple deleted hotel chain data for fun

IHG hack: 'Vindictive' couple deleted hotel chain data for fun
Sep 17,2022 5:11 am

... " IHG employs a defence-in-depth strategy to Information Security that leverages many modern security solutions, " she added...

IHG hack: 'Vindictive' couple deleted hotel chain data for fun

Jul 3,2022 10:45 pm

Hackers have told The Bbc they carried out a destructive cyber-attack against Holiday Inn owner Intercontinental Hotels Group (IHG) " for fun".

Describing themselves as a couple from Vietnam, they say they first tried a ransomware attack, then deleted large amounts of data when they were foiled.

They accessed the FTSE 100 firm's databases thanks to an easily found and weak password, Qwerty1234.

An expert says the case highlights the vindictive side of criminal hackers.

UK-based IHG operates 6,000 hotels around The World , including The Holiday Inn, Crowne Plaza and Regent brands.

On Monday last week, customers reported widespread problems with booking and check-in.

For 24 hours IHG responded to complaints on Social Media by saying that The Company was " undergoing system maintenance".

Then on the Tuesday afternoon that it had been hacked.

" Booking channels and other applications have been significantly disrupted since yesterday, " it said in an official notice lodged with the London Stock Exchange .

The hackers, calling themselves TeaPea, contacted The Bbc on the encrypted messaging app, Telegram, providing screenshots as evidence that they had carried out the hack.

The images, which IHG has confirmed are genuine, show they gained access to The Company 's internal Outlook emails, Microsoft Teams chats and server directories.

" Our attack was originally planned to be a ransomware but The Company 's IT team kept isolating servers before we had a chance to deploy it, so we thought to have some funny [sic]. We did a wiper attack instead, " one of the hackers said.

A wiper attack is a form of cyber-attack that irreversibly destroys data, documents and files.

Cyber-security specialist Rik Ferguson, vice-president of security at Forescout, said The Incident was a cautionary tale as, even though The Company 's IT team initially found a way to fend them off, the hackers were still able to find a way to inflict damage.

" The hackers' change of tactic seems born out of vindictive frustration, " He Said . " They couldn't make money so they lashed out, and that absolutely betrays the fact that We Are Not Talking about 'professional' cybercriminals here. "

IHG says customer-facing systems are returning to normal but that services may remain intermittent.

The hackers are showing No Remorse about the disruption they have caused The Company and its customers.

" We don't feel guilty, really. We prefer to have a legal job here in Vietnam but the wage is average $300 per month. I'm sure our hack won't hurt The Company a lot. "

The hackers say no customer data was stolen but they do have some corporate data, including email records.

TeaPea say they gained access to IHG's internal IT network by tricking an employee into downloading a malicious piece of software through a booby-trapped email attachment.

They also had to bypass an additional security prompt message sent to The Worker 's devices as part of a two-factor authentication system.

The Criminals then say they accessed The Most sensitive parts of IHG's computer system after finding login details for The Company 's internal password vault.

" The username and password to The Vault was available to all employees, so 200,000 staff could see. And the password was extremely weak, " they told The Bbc .

Surprisingly, the password was Qwerty1234, which regularly appears on lists of most commonly used passwords worldwide.

" Sensitive data should only be available to employees who need access to that data to do their job, and they should have the minimum level of access [needed] to use that data, " said Mr Ferguson, after seeing the screenshots.

" Even a highly complex password is just as insecure as a simple one if it is left exposed. "

An IHG spokeswoman disputed that the password vault details were not secure, saying that the attacker had to evade " multiple layers of security" but would not give details about The Extra security.

" IHG employs a defence-in-depth strategy to Information Security that leverages many modern security solutions, " she added.



Source of news: bbc.com

Information security Photos

Related Persons

Next Profile ❯