Cybercrime is on the rise and shows no sign of abating. As quickly as cybersecurity experts discover and remedy one form of threat, another pops up in its place.
With sophisticated ready-to-use hacker tools readily and cheaply available to purchase, cyber crime is no longer the domain of the technically gifted.
2019 saw a number of high-profile data breaches and the Information Commissioner’s Office hand out two record making fines one to British Airways and the other to Marriott Hotels.
And, although GDPR has raised overall awareness of cybersecurity a significant number of organisations are not equipped to handle a major IT disaster.
Now, as we look towards the 2020 cybersecurity horizon the team at DIGIT have decided to share with you some of the most stand out cyber attacks of 2019.
1 – Apple Group FaceTime Bug
In January, Teenager Grant Thompson discovered a huge security flaw in the iPhone marker’s Group FaceTime feature. Thompson discovered that while group FaceTimming with friends, he was able to listen in on someone who had not picked up when he called.
Thompson’s discovery revealed that it was possible for a caller to call a contact and, before they answered, add themselves as an additional participant. This meant that while the phone was ringing the microphone would be enabled so the caller could hear them, even if the phone was locked.
This bug meant that a hacker could secretly listen in on and watch a target via their phone. Apple responded by deactivating the feature while it dealt with the issue.
Since then, Apple has fixed the bug and reactivated the chat feature. In a statement at the time of the fix, the company said: “Today’s software update fixes the security bug in Group FaceTime. We again apologise to our customers and we thank them for their patience.
“In addition to addressing the bug that was reported, our team conducted a thorough security audit of the FaceTime service and made additional updates to both the FaceTime app and server to improve security. This includes a previously unidentified vulnerability in the Live Photos feature of FaceTime.”
2 – Tesco Parking App Data Leak
Tesco was forced to take its parking validation web app offline after it was discovered that tens of millions of unsecured ANPR images sitting in a Microsoft Azure blob.
Images of cars entering 19 Tesco car parks across the UK were left exposed online and discovered by The Register. The cars’ numberplates were highlighted and visible although the drivers were not visible in the low-res images seen by The Register.
The Azure blob, which was used to power Tesco’s outsourced parkshopreg.co.uk website, had no login or authentication controls.
Tesco admitted that “tens of millions” of timestamped images were stored on it, adding that the images had been left exposed after a data migration exercise.
The images were readily available to anyone who could correctly decipher the format of the required HTTP POST request.
Tesco car parks affected by the breach include Braintree, Chelmsford, Chester, Epping, Fareham, Faversham, Gateshead, Hailsham, Hereford, Hove, Hull, Kidderminster, Woolwich, Rotherham, Sale (Cheshire), Slough, Stevenage, Truro, Walsall and Weston-super-Mare.
A Tesco spokesman told The Register: “Whilst no images of people, nor any sensitive data were available, any security breach is unacceptable and we have now disabled the app as we work with our service provider to ensure it doesn’t happen again.”
The web app remains offline to this day. The supermarket giant says it is not responsible for the incident because it purchased the parking lot monitoring services from a third party, and therefore, the third party was responsible for protecting the data it collected and stored under the law.
Recommended
- Top EU Court Rules Airbnb is Not a Real Estate Agency
- How to Protect Your Business from Phishing and Whaling Scams
- Twitter Trolls Target People with Epilepsy Using Strobing Images
3 – Hackers Rob French Gas Station
A five-man team of criminals stole over 120,000 litres of fuel from Total gas stations around Paris using a special remote to unlock the pumps. The tool, which the men bought online, can open the particular brand of gas pump used by Total gas stations.
The men were able to carry out their attack because some of the station managers had failed to change the gas pump’s default lock code from 0000. Using this easily guessable PIN code, the men were able to reset fuel prices and remove any fill-up limits.
Working in small teams the men visited the gas stations to tank up at night using two vehicles. The first man would drive up in a car to unlock the pump.
A second would then pull up in a van and then fill up a giant tanker installed in the back of the vehicle with as much as 2,000 or 3,000 litres in one go.
The men only targeted Total gas stations across the Ile-de-France province surrounding Paris.
The crooks then flogged the stolen fuel on social media. Before they were caught, French authorities said they made around €150,000 from selling the stolen fuel at a reduced price.
4 – ‘Words with Friends’ Hack
One of the world’s most successful social game developers, Zynga, the company behind “FarmVille” and “Words with Friends” admitted in October that a hacker had accessed account log-in information in September.
The hacker also accessed usernames, email addresses, log-in IDs, some Facebook IDs, some phone number and Zynga account IDs of about 218 million customer, according to the company.
Those affected were customers who had installed iOS and Android versions of the game before September 2nd 2019.
The company said it had instigated an investigation as soon as the intrusion was discovered. The hacker, who goes by the moniker, Gnosticplayers, told The Hacker News that he had hacked data belonging to some other Zynga-developed games, including Draw Something and the discontinued OMGPOP game, which allegedly exposed clear text passwords for more than 7 million users.
5 – Capitol One Hack
Earlier this year Capital One, the US’s seventh largest commercial bank suffered a massive data breach that saw the details of more than 100 million US credit card applicants compromised– as well as six million in Canada.
The Social Security numbers of around 140,000 credit card customers, along with 80,000 linked bank account numbers were compromised in the breach.
The hacker also obtained portions of credit card customer data, including credit scores, credit limits, balances, payment history, contact information and fragments of transaction data.
Paige A. Thompson was arrested by the FBI on a charge of computer fraud and abuse over the data breach, which is possibly the largest ever to hit a financial services firm.
Thompson, who goes by the online handle “erratic” inadvertently flagged herself as the perpetrator to authorities by boasting about her actions online.
She previously worked at an unidentified cloud computing company that provided data services to Capital One. Thompson was also accused of hacking 30 other organisations by the FBI.
Following her arrest, she told authorities she did not sell or share any of the stolen data. US officials say that there is no evidence to suggest that she lied, which could potentially reduce the extent of the breaches she is accused of.
Honourable Mention – Cyber Crime in Space
A top female NASA astronaut, Anne McClain, made cyber crime history when she was accused of hacking into her estranged spouse’s bank account while on-board the International Space Station. Potentially this could be the fist criminal allegation from space.
When McClain’s ex-spouse, Summer Worden, became suspicious she might have been hacked she contacted her bank for details of the locations of logins to the account. Worden was shocked to find out that her login details had been used on a computer that was registered to NASA.
The two are embroiled in a painful divorce and are battling for custody of Worden’s six-year old child. McClain told investigators that she had accessed Worden’s account while she was on six-month mission aboard the iSS in preparation for her role in NASA’s first all-female spacewalk, according to The Times.
Rusty Hardin, a lawyer for McClain said: “she strenuously denies that she did anything improper” and “is totally cooperating”.
Hardin said she had been monitoring the account out of concern for the well-being of the child, who they had both been raising, and used the same password she had used throughout their relationship.
“I was pretty appalled that she would go that far. I knew it was not OK,” Worden told The Times. NASA officials said they did not know of any crimes that had been committed on the ISS.





