Holiday hacking: Cyber-attacks on Cyber Monday

Justin Fier, Director of Cyber Intelligence | Friday November 18, 2016

Every year, on the first Monday after Thanksgiving, two things happen. First, online retailers slash prices and the internet goes on its annual shopping spree. And second, criminals swarm on unwitting businesses, launching large-scale hacks and clever scams.

Digital sales reach up to $3.19 billion on Cyber Monday. Amazon alone generated 36 percent of all online sales last Cyber Monday, accounting for an estimated $1 billion. With so much money changing hands over the internet, the ramifications of a cyber-attack would be huge.

What happens if a DDoS attack hits Amazon’s service provider? The website goes down. Digital sales grind to a halt. And millions in revenue go down the drain as they watch their most lucrative day of the year pass them by.

On Cyber Monday 2014, a DNS provider was hit with a fairly rudimentary DDoS attack. While it lacked the large-scale impact of today’s Mirai botnets, their clients lost vital business. In another holiday attack, criminals hacked Target and stole sensitive data from 70 million customers.

Disruption and data-theft have become tried-and-true tactics for criminals on Cyber Monday. And with Mirai botnets capable of launching massive DDoS attacks, these could become even more devastating, reminiscent of the Dyn attack but with more far-reaching monetary consequences.

However, in their current form, DDoS attacks are still relatively simple. They work by exploiting a fundamental flaw in the Internet. But what if this Cyber Monday, a highly targeted and sophisticated DDoS attack took an organization hostage? By overwhelming a company — or a series of companies — with junk traffic, an attacker could demand a large sum to stop the attack. Whether to manipulate the market or for financial gain, all signs point toward increasingly advanced DDoS attacks.

The implications for this Cyber Monday are clear — businesses need to be prepared. From DDoS to ransomware, every organization can expect to be hit. Companies should bolster their cyber defense well before the holidays, because in security, as in life, you should expect the best, but prepare for the worst.

To learn more about the types of attack you could face, check out my thoughts on DDoS and the IoT.

Justin Fier

Justin is one of the US’s leading cyber intelligence experts, and holds the position of Director for Cyber Intelligence & Analytics at Darktrace. His insights on cyber security and artificial intelligence have been widely reported in leading media outlets, including the Wall Street Journal, CNN, The Washington Post, and VICELAND. With over 10 years of experience in cyber defense, Justin has supported various elements in the US intelligence community, holding mission-critical security roles with Lockheed Martin, Northrop Grumman Mission Systems and Abraxas. Justin is also a highly-skilled technical specialist, and works with Darktrace’s strategic global customers on threat analysis, defensive cyber operations, protecting IoT, and machine learning.

2016: The year of election tampering?

Justin Fier, Director of Cyber Intelligence | Friday November 4, 2016

The 2016 U.S. election is roiled by fears over election tampering and cyber-warfare. While such anxiety threatens to undermine confidence in the results, the up-side is that for the first time since 2000, the election is generating thoughtful discussion on the intersection of cyber-security and voting.

After the high-profile hack of the Democratic National Committee, and after attacks on voter registration databases in 20 states, these fears are certainly justified. After all, we live in a new era of threat, where foreign powers don’t hesitate to use cyber-tools for economic and political gain. The White House has now formally blamed Russia for the DNC hack, but they’re hardly the only nation-state willing to engage in cloak-and-dagger cyber-warfare.

Further complicating matters is that our voting machines are in desperate need of an overhaul. In 2006, computer scientists proved that in less than a minute, an e-voting machine could be hacked and installed with vote-changing malware, and it can even be done remotely. But intentional manipulation may not even be our biggest concern — in 2004, North Carolina lost 4,438 votes because of a system error.

If you’re thinking paper ballots are the answer, I don’t blame you. Most states would agree: only five states currently use digital voting alone, and 75 percent of all voting is done on paper ballots.

But after the 2000 election, when the infamous ‘hanging chads’ forced millions of votes to be invalidated, it became clear that paper ballots are not only cumbersome, but inaccurate. Two years later, Congress passed the Help America Vote Act and introduced digitized voting and registration databases across America. Unfortunately, the new machines were plagued with errors, and many of them are still in use today.

Growing concern over election tampering prompted 33 state election agencies to petition the Department of Homeland Security for aid. The DHS responded by offering “cyber hygiene scans on Internet-facing systems as well as risk and vulnerability assessments.”

This is a good start, but hardly a long-term solution. Cyber-security for the future has to go beyond one-off scans and retrospective assessments. The answer has to involve intelligently monitoring and analyzing millions of devices — from voting machines to vulnerable IoT devices — in order to mitigate risk from unknown threats. Whether it be a state-sponsored hack or tampering from a politically motivated insider, the integrity of our elections is at stake, and its security deserves the utmost attention.

To hear more of my thoughts on the modern threat landscape, sign up for my webinar on November 9.

Justin Fier

Justin is one of the US’s leading cyber intelligence experts, and holds the position of Director for Cyber Intelligence & Analytics at Darktrace. His insights on cyber security and artificial intelligence have been widely reported in leading media outlets, including the Wall Street Journal, CNN, The Washington Post, and VICELAND. With over 10 years of experience in cyber defense, Justin has supported various elements in the US intelligence community, holding mission-critical security roles with Lockheed Martin, Northrop Grumman Mission Systems and Abraxas. Justin is also a highly-skilled technical specialist, and works with Darktrace’s strategic global customers on threat analysis, defensive cyber operations, protecting IoT, and machine learning.