India’s cybersecurity agency warns people of credit card skimming via e-commerce sites

Agencies
July 18, 2020

New Delhi, Jul 18: India's national cybersecurity agency CERT-in, has warned people of credit card skimming spreading across the world through e-commerce platforms.

Attackers are typically targeting e-commerce sites because of their wide presence, popularity and the environment LAMP (Linux, Apache, MySQL, and PHP), the Computer Emergency Response Team (CERT-In) said in a notice on Thursday.

Recently, attackers targeted sites which were hosted on Microsoft's IIS server running with the ASP.NET web application framework, it said.

Some of the sites affected by the attack were found to be running ASP.NET version 4.0.30319, which is no longer officially supported by Microsoft and may contain multiple vulnerabilities, CERT-In said.

The notice also included a list of best practices for website developers including the use of the latest version of ASP.NET web framework, IIS web server and database server.

The advisory is based on research by Malwarebytes which found that this skimming campaign likely began sometime in April this year.

Credit card skimming has become a popular activity for cybercriminals over the past few years, and the increase in online shopping during the pandemic means additional business for them, too, Malwarebytes said in a blog post, adding that attackers do not need to limit themselves to the most popular e-commerce platforms.

Researchers from global cybersecurity and anti-virus brand Kaspersky had warned in December last year that more cybercriminal groups will target online payment processing systems in 2020. 

It said that over the past couple of years, so-called JS-skimming (the method of stealing of payment card data from online stores), has gained immense popularity among attackers. 

Kaspersky researchers in their report said they are currently aware of at least 10 different actors involved in these type of attacks.

Their number will continue to grow during the next year, the report said, adding that the most dangerous attacks will be on companies that provide services such as e-commerce as-a-service, which will lead to the compromise of thousands of companies.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
March 15,2020

Cybercriminals continue to exploit public fear of rising coronavirus cases through malware and phishing emails in the guise of content coming from the Centers for Disease Control and Prevention (CDC) in the US and World Health Organisation (WHO), says cybersecurity firm Kaspersky.

In the APAC region, Kaspersky has detected 93 coronavirus-related malware in Bangladesh, 53 in the Philippines, 40 in China, 23 in Vietnam, 22 in India and 20 in Malaysia. 

Single-digit detections were monitored in Singapore, Japan, Indonesia, Hong Kong, Myanmar, and Thailand. 

Along with the consistent increase of 2019 coronavirus cases comes the incessant techniques cybercriminals are using to prey on public panic amidst the global epidemic, the company said in a statement. 

Kaspersky also detected emails offering products such as masks, and then the topic became more commonly used in Nigerian spam emails. Researchers also found scam emails with phishing links and malicious attachments.

One of the latest spam campaigns mimics the World Health Organisation (WHO), showing how cybercriminals recognise and are capitalising on the important role WHO has in providing trustworthy information about the coronavirus.

"We would encourage companies to be particularly vigilant at this time, and ensure employees who are working at home exercise caution. 

"Businesses should communicate clearly with workers to ensure they are aware of the risks, and do everything they can to secure remote access for those self-isolating or working from home," commented David Emm, principal security researcher.

Some malicious files are spread via email. 

For example, an Excel file distributed via email under the guise of a list of coronavirus victims allegedly sent from the World Health Organisation (WHO) was, in fact, a Trojan-Downloader, which secretly downloads and installs another malicious file. 

This second file was a Trojan-Spy designed to gather various data, including passwords, from the infected device and send it to the attacker.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
January 26,2020

New Delhi, Jan 26: Google on Sunday marked India's 71st Republic Day by dedicating a doodle illustrating the country's rich cultural heritage that permeates and unites the diverse nation.

From its world-famous landmarks like the Taj Mahal and India Gate, to the wide array of fauna such as its national bird (the Indian peafowl), to classical arts, textiles, and dances, the doodle, designed by Singapore-based artist Meroo Seth, brings together the rich cultural heritage of the country.

Republic Day marks the completion of India's transition towards becoming an independent republic after its constitution came into effect. The governing document had taken nearly three years of careful deliberation to finalise, and its eventual enactment was joyfully celebrated across the country.

While the Constitution was adopted by the Indian Constituent Assembly on 26 November 1949, it came into effect on January 26 -- a day when Declaration of Indian Independence (Purna Swaraj) was proclaimed by the Indian National Congress back in 1929, as opposed to the Dominion status offered by the British Regime.

Festivities embody the essence of diversity found in one of the world's most populous nations, celebrated over a three-day period with cultural events displaying national pride.

Last year's doodle on Republic Day, designed by artist Reshidev RK, had featured Rashtrapati Bhavan in the background along with a display of the country's iconic monuments and heritage.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
March 25,2020

In an unprecedented crisis despite Prime Minister Narendra Modi assuring the continuation of essential services like food and groceries, online marketplaces like Flipkart and Amazon along with delivery platforms like Bigbasket, Grofers and FreshToHomes hit a major blockade on Wednesday as local authorities shut warehouses and sent delivery boys back, even harassed them.

Millions of people across cities were left helpless at homes as essential items like fruits and vegetables, dairy and milk, meat and fish etc did not reach their doors despite placing orders well in advance. Later, the orders went dry.

While Grofers' warehouse in Faridabad was closed by the local law enforcement agencies, Bigbasket complained that the police stopped its delivery partners and "some of them were even beaten up by for no fault of theirs".

"We are not operational due to restrictions imposed by local authorities on movement of goods in spite of clear guidelines provided by central authorities to enable essential services. We are working with the authorities to be back soon,' Bigbasket tweeted.

In a statement to IANS, Bigbasket said that it will help to have better coordination between the Centre and state, and between the state and local police to "ensure that our delivery vans and bikes don't get stopped by the police. Bigbasket and bb daily are not taking new orders".

Furious people stormed the social media platforms, writing their plight to NITI Aayog CEO Amitabh Kant on Twitter.

"Sir, all e-commerce are down. Believe me I tried everything (Grofers, Bigbasket, Flipkart, Amazon, Big Bazaar), no delivery till 31st March or Server Down or No Service. Need to think how we can enable them through digital India," tweeted one user.

Kant tweeted back to Bigbasket: "They should give me specifics - State & location. I will act on it by getting in touch with concerned authorities & sorting it out. Govt guidelines exempt them. We will ensure that citizens are not impacted".

Kant also responded to Grofers: "Cold storages & Warehouses as well as delivery of all essentials goods including food, pharma thru E-Commerce are exempted under MHA order. I have spoken to CS & DGP, Haryana . They have taken immediate action to ensure that supply chains efficiently function for the citizens".

The subscription-based hyperlocal delivery startup FreshToHome sent messages to its customers, saying that despite the government declaring food delivery as essential, "we are facing hardships in continuing our operations".

"Please bear with us as we are working hard to unblock local authority hurdles," said the FreshToHome team.

Reports later surfaced that the Department for Promotion of Industry and Internal Trade (DPIIT) has initiated talks with the state Chief Secretaries asking them not to restrict movement of people engaged in home delivery of essential items, mentioned in the list of exempted items circulated by the Home Ministry.

Meanwhile, Flipkart said it has temporarily suspended its operations and services - including grocery items. The marketplace has decided to halt all orders from March 25 for all three supply chains -- groceries, non-large goods and large items.

"Flipkart has temporarily suspended orders as we assess the possibilities of operating in the lockdown. We are prioritising the safety of our delivery executives and seeking the support of the local governments and police authorities to meet the needs of our customers as they stay home during this lockdown," Rajneesh Kumar, Chief Corporate Affairs Officer, Flipkart, said in a statement.

E-commerce giant Amazon said the company has to "temporarily stop taking orders and disable shipments for lower-priority products.

"For all pending customer orders on lower-priority products, we are reaching out to customers and giving them a choice to cancel their orders, and receive a refund for prepaid items," said the company.

Witnessing a surge in demand, supermarket chain Biz Bazaar entered the fray, with launching doorstep delivery services in major cities like Delhi, Mumbai, Bengaluru and Gurugram.

However, within no time, Big Bazaar was flooded with calls, forcing the company to issue a statement, saying that "In light of the recent announcement, we are receiving an unprecedented number of requests for doorstep delivery. There could be a delay due to the restrictions on movements".

Already battling massive surge in demand, the online delivery platforms faced other issues too, including zero access to several high-rises across the country which have gone under complete lockdown with all entry and exit gates locked.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.