All Article Properties:
{
"access_control": false,
"status": "publish",
"objectType": "Article",
"id": "558658",
"signature": "Article:558658",
"url": "https://staging.dailymaverick.co.za/article/2020-02-13-nedbank-client-records-stolen-in-online-heist/",
"shorturl": "https://staging.dailymaverick.co.za/article/558658",
"slug": "nedbank-client-records-stolen-in-online-heist",
"contentType": {
"id": "1",
"name": "Article",
"slug": "article"
},
"views": 0,
"comments": 0,
"preview_limit": null,
"excludedFromGoogleSearchEngine": 0,
"title": "Nedbank client records stolen in online heist",
"firstPublished": "2020-02-13 23:22:31",
"lastUpdate": "2020-02-13 23:22:31",
"categories": [
{
"id": "9",
"name": "Business Maverick",
"signature": "Category:9",
"slug": "business-maverick",
"typeId": {
"typeId": "1",
"name": "Daily Maverick",
"slug": "",
"includeInIssue": "0",
"shortened_domain": "",
"stylesheetClass": "",
"domain": "staging.dailymaverick.co.za",
"articleUrlPrefix": "",
"access_groups": "[]",
"locale": "",
"preview_limit": null
},
"parentId": null,
"parent": [],
"image": "",
"cover": "",
"logo": "",
"paid": "0",
"objectType": "Category",
"url": "https://staging.dailymaverick.co.za/category/business-maverick/",
"cssCode": "",
"template": "default",
"tagline": "",
"link_param": null,
"description": "",
"metaDescription": "",
"order": "0",
"pageId": null,
"articlesCount": null,
"allowComments": "1",
"accessType": "freecount",
"status": "1",
"children": [],
"cached": true
},
{
"id": "29",
"name": "South Africa",
"signature": "Category:29",
"slug": "south-africa",
"typeId": {
"typeId": "1",
"name": "Daily Maverick",
"slug": "",
"includeInIssue": "0",
"shortened_domain": "",
"stylesheetClass": "",
"domain": "staging.dailymaverick.co.za",
"articleUrlPrefix": "",
"access_groups": "[]",
"locale": "",
"preview_limit": null
},
"parentId": null,
"parent": [],
"image": "",
"cover": "",
"logo": "",
"paid": "0",
"objectType": "Category",
"url": "https://staging.dailymaverick.co.za/category/south-africa/",
"cssCode": "",
"template": "default",
"tagline": "",
"link_param": null,
"description": "Daily Maverick is an independent online news publication and weekly print newspaper in South Africa.\r\n\r\nIt is known for breaking some of the defining stories of South Africa in the past decade, including the Marikana Massacre, in which the South African Police Service killed 34 miners in August 2012.\r\n\r\nIt also investigated the Gupta Leaks, which won the 2019 Global Shining Light Award.\r\n\r\nThat investigation was credited with exposing the Indian-born Gupta family and former President Jacob Zuma for their role in the systemic political corruption referred to as state capture.\r\n\r\nIn 2018, co-founder and editor-in-chief Branislav ‘Branko’ Brkic was awarded the country’s prestigious Nat Nakasa Award, recognised for initiating the investigative collaboration after receiving the hard drive that included the email tranche.\r\n\r\nIn 2021, co-founder and CEO Styli Charalambous also received the award.\r\n\r\nDaily Maverick covers the latest political and news developments in South Africa with breaking news updates, analysis, opinions and more.",
"metaDescription": "",
"order": "0",
"pageId": null,
"articlesCount": null,
"allowComments": "1",
"accessType": "freecount",
"status": "1",
"children": [],
"cached": true
},
{
"id": "38",
"name": "World",
"signature": "Category:38",
"slug": "world",
"typeId": {
"typeId": "1",
"name": "Daily Maverick",
"slug": "",
"includeInIssue": "0",
"shortened_domain": "",
"stylesheetClass": "",
"domain": "staging.dailymaverick.co.za",
"articleUrlPrefix": "",
"access_groups": "[]",
"locale": "",
"preview_limit": null
},
"parentId": null,
"parent": [],
"image": "",
"cover": "",
"logo": "",
"paid": "0",
"objectType": "Category",
"url": "https://staging.dailymaverick.co.za/category/world/",
"cssCode": "",
"template": "default",
"tagline": "",
"link_param": null,
"description": "",
"metaDescription": "",
"order": "0",
"pageId": null,
"articlesCount": null,
"allowComments": "1",
"accessType": "freecount",
"status": "1",
"children": [],
"cached": true
}
],
"content_length": 6257,
"contents": "<span style=\"font-weight: 400;\">The nightmare is not over for the 32 million subscribers to Ashley Madison who had their private information including names, passwords, phone numbers and other private details dumped on the dark web by hackers in 2016. </span>\r\n\r\n<span style=\"font-weight: 400;\">It appears that criminals have revived a “sextortion” scheme that targets these subscribers who used the dating website to cheat on their partners.</span>\r\n\r\n<span style=\"font-weight: 400;\">Victims are receiving emails threatening to expose their intimate secrets and emails to family and friends on social media and via email unless they pay a Bitcoin ransom.</span>\r\n\r\n<span style=\"font-weight: 400;\">US cybersecurity firm Vade Secure </span><a href=\"https://www.vadesecure.com/en/ashley-madison-data-breach-fuels-new-extortion-scam\"><span style=\"font-weight: 400;\">says it</span></a> <span style=\"font-weight: 400;\">detected several hundred examples of this extortion scam in February 2020 alone. The scammers are primarily targeting users in the US, Australia and India. </span>\r\n\r\n<span style=\"font-weight: 400;\">“Seeing that more than 32 million accounts were made public as a result of the Ashley Madison data breach, we expect to see many more in the coming weeks,” the company says.</span>\r\n\r\n<span style=\"font-weight: 400;\">The emails are personalised with information from the Ashley Madison data breach. The subject includes the target’s name and bank. The body includes everything from the user’s bank account number, telephone number, address and birthday. The email may also reference private content or communication between individuals on the site itself. </span>\r\n\r\n<span style=\"font-weight: 400;\">The example below refers to past purchases for “male assistance products”.</span>\r\n\r\n<img loading=\"lazy\" class=\"aligncenter size-full wp-image-558662\" src=\"https://www.dailymaverick.co.za/wp-content/uploads/BM-Sasha-Nedbank.png\" alt=\"\" width=\"1381\" height=\"689\" />\r\n\r\n<span style=\"font-weight: 400;\">“The more of your personal information that a cybercriminal has, the more power they have to manipulate you,” says John McLoughlin, CEO of cybersecurity company J2 Software. In this case, the targets are victims of “sextortion”, but criminals can just as easily use your information to win over your trust.</span>\r\n\r\n<span style=\"font-weight: 400;\">“Someone could phone pretending to be from one of your financial service providers and warn you that you have been the victim of a crime which they are working to solve. The individual will not ask for your personal details, but will have your details and ask you to confirm them. </span>\r\n\r\n<span style=\"font-weight: 400;\">“This establishes trust. It is a small matter for them to ask you to authenticate something — perhaps using a one-time pin or similar. Because trust has been established, you unwittingly reveal that information or execute the step.”</span>\r\n\r\n<span style=\"font-weight: 400;\">Thus, although it’s a completely different case from the Ashley Madison breach and there is no direct overlap, Nedbank customers who have had their personal information compromised need to be extra vigilant, he says.</span>\r\n\r\n<span style=\"font-weight: 400;\">On Thursday 13 February Nedbank warned that a data breach had occurred at the premises of a third-party service provider, Computer Facilities Ltd. This is a direct marketing company that issues SMS and email marketing information on behalf of Nedbank and a number of other companies.</span>\r\n\r\n<span style=\"font-weight: 400;\">A subset of the potentially compromised data at Computer Facilities included personal information (names, ID numbers, telephone numbers, physical and/or email addresses) of some Nedbank clients.</span>\r\n\r\n<span style=\"font-weight: 400;\">The bank added that no Nedbank systems or client bank accounts were compromised or are directly at risk as a result of this data issue. In fact, the company concerned had no direct links to Nedbank systems, said Nedbank’s group chief information officer, Fred Swanepoel.</span>\r\n\r\n<span style=\"font-weight: 400;\">Nedbank identified the data security issue as part of its routine and ongoing monitoring procedures.</span>\r\n\r\n<span style=\"font-weight: 400;\">“Once we became aware of the issue, we engaged as a matter of urgency with the service provider and leading forensic experts to conduct an extensive investigation,” the bank said.</span>\r\n\r\n<span style=\"font-weight: 400;\">“We have moved swiftly to secure and destroy all Nedbank client information held by Computer Facilities from Nedbank Retail relating to about 1.1 million active clients.</span>\r\n\r\n<span style=\"font-weight: 400;\">“The matter is receiving our urgent attention,” added CE Mike Brown. “The safety and security of our clients’ information is a top priority.”</span>\r\n\r\n<span style=\"font-weight: 400;\">Nedbank has focused on securing all client data at the smaller company and is communicating directly with affected clients as well as the relevant regulators and authorities.</span>\r\n\r\n<span style=\"font-weight: 400;\">“We have seen a massive spike in third-party compromise,” says McLoughlin. “These are often smaller companies that do business with larger entities. They are a target because hackers use them as a stepping stone to the ultimate goal which is the bigger organisations and their customers.” </span>\r\n\r\n<span style=\"font-weight: 400;\">The reason smaller companies are targeted, he says, is that they don’t have the same controls and measures in place as bigger companies. </span>\r\n\r\n<span style=\"font-weight: 400;\">And while the big companies do audit their suppliers, they often rely on “a piece of paper”, in other words, a written reply to a risk assessment and questionnaire. “The question is, do they actually examine a supplier’s policies and understand how they control and monitor adherence to these policies?” he asks.</span>\r\n\r\n<span style=\"font-weight: 400;\">This is not to say that Nedbank was negligent. The fact that the bank itself picked up the hack suggests its monitoring systems are vigilant.</span>\r\n\r\n<span style=\"font-weight: 400;\">The problem is that because we live in an increasingly connected world this type of crime will only increase.</span>\r\n\r\n<span style=\"font-weight: 400;\">As a criminal, where would you invest your money — in the weapons, people and vehicles necessary to carry out cash-in-transit heists? Or in some smart hackers who can send out a million emails a day using targeted information they have bought or hacked? With that information even if you harvest the bank information from 1% of the emails it’s easy money. </span>\r\n\r\n<span style=\"font-weight: 400;\">Even worse is that the information that was hacked in 2019 or even before that (ask the Ashley Madison clients), is still available for sale on the black market.</span>\r\n\r\n<span style=\"font-weight: 400;\">According to </span><span style=\"font-weight: 400;\">Vade Secure,</span><span style=\"font-weight: 400;\"> there were more than 5,183 data breaches reported in the first nine months of 2019, a 33% increase from the previous year. In total, 7.9 billion records were exposed. Many of these records, including troves of usernames and passwords, were stolen through phishing campaigns and are for sale on the black market.</span>\r\n\r\n<span style=\"font-weight: 400;\">Those exposed records will give hackers everything they need to improve their email campaigns.</span>\r\n\r\n<span style=\"font-weight: 400;\">“</span><span style=\"font-weight: 400;\">There are more breaches, compromise and attacks than one imagines,” says McLoughlin.</span>\r\n\r\n<span style=\"font-weight: 400;\">“Be wary. Look around. Be vigilant. Take every question with a bigger pinch of salt. Ask yourself, is this legitimate, is this the normal way of communicating, question it. If you are concerned, use old technology — pick up the telephone and ask!” </span><span style=\"text-decoration: underline;\"><b>BM</b></span>",
"teaser": "Nedbank client records stolen in online heist",
"externalUrl": "",
"sponsor": null,
"authors": [
{
"id": "32038",
"name": "Sasha Planting",
"image": "https://www.dailymaverick.co.za/wp-content/uploads/Y3LcnSrs_400x400.jpeg",
"url": "https://staging.dailymaverick.co.za/author/sasha-planting-2/",
"editorialName": "sasha-planting-2",
"department": "",
"name_latin": ""
}
],
"description": "",
"keywords": [
{
"type": "Keyword",
"data": {
"keywordId": "10244",
"name": "Cybercrime",
"url": "https://staging.dailymaverick.co.za/keyword/cybercrime/",
"slug": "cybercrime",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Cybercrime",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "10897",
"name": "Nedbank",
"url": "https://staging.dailymaverick.co.za/keyword/nedbank/",
"slug": "nedbank",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Nedbank",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "61625",
"name": "Hackers",
"url": "https://staging.dailymaverick.co.za/keyword/hackers/",
"slug": "hackers",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Hackers",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "66411",
"name": "Mike Brown",
"url": "https://staging.dailymaverick.co.za/keyword/mike-brown/",
"slug": "mike-brown",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Mike Brown",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "174792",
"name": "hack",
"url": "https://staging.dailymaverick.co.za/keyword/hack/",
"slug": "hack",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "hack",
"translations": null
}
}
],
"short_summary": null,
"source": null,
"related": [],
"options": [],
"attachments": [
{
"id": "31771",
"name": "",
"description": "",
"focal": "50% 50%",
"width": 0,
"height": 0,
"url": "https://dmcdn.whitebeard.net/dailymaverick/wp-content/uploads/groundup-nedbank-1000x581.jpg",
"transforms": [
{
"x": "200",
"y": "100",
"url": "https://dmcdn.whitebeard.net/i/vW181qhINGK9DBqF7EdIcwz82Ws=/200x100/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/groundup-nedbank-1000x581.jpg"
},
{
"x": "450",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/cQ0aukoMODhN8IeGn3e-ChH0JAw=/450x0/smart/file/dailymaverick/wp-content/uploads/groundup-nedbank-1000x581.jpg"
},
{
"x": "800",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/nSuZ003xXhZG8oYWgPr4uNLt0FE=/800x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/groundup-nedbank-1000x581.jpg"
},
{
"x": "1200",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/i0kUdSC5lCR-9NYIgAE9FSvE8vE=/1200x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/groundup-nedbank-1000x581.jpg"
},
{
"x": "1600",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/hmrdKxVYQgMN-G-0smQdoQ34MGI=/1600x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/groundup-nedbank-1000x581.jpg"
}
],
"url_thumbnail": "https://dmcdn.whitebeard.net/i/vW181qhINGK9DBqF7EdIcwz82Ws=/200x100/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/groundup-nedbank-1000x581.jpg",
"url_medium": "https://dmcdn.whitebeard.net/i/cQ0aukoMODhN8IeGn3e-ChH0JAw=/450x0/smart/file/dailymaverick/wp-content/uploads/groundup-nedbank-1000x581.jpg",
"url_large": "https://dmcdn.whitebeard.net/i/nSuZ003xXhZG8oYWgPr4uNLt0FE=/800x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/groundup-nedbank-1000x581.jpg",
"url_xl": "https://dmcdn.whitebeard.net/i/i0kUdSC5lCR-9NYIgAE9FSvE8vE=/1200x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/groundup-nedbank-1000x581.jpg",
"url_xxl": "https://dmcdn.whitebeard.net/i/hmrdKxVYQgMN-G-0smQdoQ34MGI=/1600x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/groundup-nedbank-1000x581.jpg",
"type": "image"
}
],
"summary": "Cybercrime is on the increase and everyone is a target.",
"template_type": null,
"dm_custom_section_label": null,
"elements": [],
"seo": {
"search_title": "Nedbank client records stolen in online heist",
"search_description": "<span style=\"font-weight: 400;\">The nightmare is not over for the 32 million subscribers to Ashley Madison who had their private information including names, passwords, phone numbers and other private",
"social_title": "Nedbank client records stolen in online heist",
"social_description": "<span style=\"font-weight: 400;\">The nightmare is not over for the 32 million subscribers to Ashley Madison who had their private information including names, passwords, phone numbers and other private",
"social_image": ""
},
"cached": true,
"access_allowed": true
}