Digital Forensics Incident Response Program
Special thanks to Technical Special Agent, Edward Sakocius, of the United States Secret Service for providing an overview of the Digital Forensics Incident Response Program. TSA Sakacius spoke about Business Email Compromise and Ransomware.
Business Email Compromise (BEC) is one of the largest areas of cyber crime experienced by businesses and institutions. Often it is a started through phishing emails with suspicious links and false senders that go undetected by protective software and users. With Artificial Intelligence, the ability to create emails with proper spelling and formatting will increase and could lead to even more vulnerabilities. Most companies are using Multi Factor Authentication (MFA) to minimize fraudulent emails – however there are now cases where adversaries are getting in the middle of MFA and are able to obtain credential information. The point is – attackers are adjusting and becoming more sophisticated. Agent Sakacius pointed to Evilginx as an example of open source software that provides the basis for phishing attacks. Many of these fraud programs are searching for transactions that they can get into the middle of and redirect payments. The Secret Service suggests notifying their office when a phishing email is found from a legitimate source. They also strongly suggest using a phishing resistant MFA program and doing routine and real-life testing with employees. Logs should be maintained for 60-90 days to be able to track history in the event of an incident.
BEC Incident Response Recommended Actions:
1. Contact bank / financial institution immediately
2. Contact US Secret Service
3. File IC3.gov complaint
4. Investigate root cause and make sure passwords have been updated
5. Inform your cyber insurance company.
Ransomware is a malware attack that encrypts and hijacks company data. Ransom payments are requested to restore the data back to the company. Agent Sakacius pointed out that this is a highly unreported crime – IC3 reported $34M of payments in one year – the estimated amount of true ransomware payments is estimated at >$1B.
Many companies point to the backups they have – the problem can be is that the backups can contain he same malware or leaks that initiated the original ransomware attack.
Zero-Day Attack -- is a cyberattack vector that takes advantage of an unknown or unaddressed security flaw in computer software, hardware or firmware. "Zero day" refers to the fact that the software or device vendor has zero days to fix the flaw because malicious actors can already use it to access vulnerable systems. A similar but separate concept, zero-day malware, is a virus or malware for which the signature is unknown or as yet unavailable, and therefore undetectable by many antivirus software solutions or other signature-based threat detection technologies.
Speed of response to ransomware attack is paramount. This is where contacting law enforcement / Secret Service can be of significant help in responding faster than insurance based teams.
Agent Sakacius outlined the following actions that that every organization should take concerning ransomware and other attacks:
- Understand and document your network (even if just a basic networking diagram and asset inventory). Document how remote access is obtained.
- Maintain a current effective cyber incident response plan.
- Minimize the damage an attack can do. Know what data needs to be encrypted. Ensue appropriate monitoring to provide visibility to any attacks.
- Make sure data is backed up and will remain unaffected – isolated and disconnected from the network.
- Do penetration (Pen) testing – consider moving to Gray Pen Testing.
