Live data from Hacker News

Snapchat Employee Data Leaks Out Following Phishing Attack

techcrunch.com

41–50 of 62 posts

Re: Snapchat Employee Data Leaks Out Following Phishing Attack

#42
post #37

Earlier quoted context omitted.

Sending requests by mail with official looking letterheads for example.

Or fake invoices. I get them regularly.

This got to the point where I actually tossed a real invoice thinking it was a fake one... That lesson cost me 40 euros in extra fees.

Re: Snapchat Employee Data Leaks Out Following Phishing Attack

#43
post #5

Earlier quoted context omitted.

Social engineering attacks will probably be a thorn in security's side for a very long time, if not indefinitely... There's a sort of fundamental disconnect inherent in "Trust the system! It's secure! Except be careful because sometimes something that is not the system will pretend to be the system..."

We keep treating falling for phishing emails as a user error. But, perhaps, having our most "official" means of communicating online (email) be a protocol that has no identity verification, no authentication and no encryption, is actually a technical bug, not a human one. I mean, you would expect that we should at least be able to tell that if you get a x@snapchat.com email in your y@snapchat.com inbox, it actually c…

I thought we had this through SPF. Ie. Your mail server can reject mail if the domain doesn't match spf records in dns.

Maybe it's time to start something like an SPF Everywhere campaign.

Re: Snapchat Employee Data Leaks Out Following Phishing Attack

#45
Based on recent experiences with the hip new investment company that administer's my employer's 401(k) as well as HR, I wouldn't be surprised if much of the data wasn't even considered confidential by the people handling it.

Minor rant: The 401(k) provider regularly sends a plaintext deposit confirmation email (deposit amount, confirmation number) with each payroll cycle. Any time a change in contribution amount is changed, they send a plaintext email with the new contribution percentage. Occasionally they send plaintext statements containing dividend amounts.

When asked to stop sending these e-mails, the 401(k) administrator replied that it wasn't possible, supposedly due to the way they integrate with they integrate with a 3rd party mail provider. (what?)

Re: Snapchat Employee Data Leaks Out Following Phishing Attack

#46
post #43

Earlier quoted context omitted.

We keep treating falling for phishing emails as a user error. But, perhaps, having our most "official" means of communicating online (email) be a protocol that has no identity verification, no authentication and no encryption, is actually a technical bug, not a human one. I mean, you would expect that we should at least be able to tell that if you get a x@snapchat.com email in your y@snapchat.com inbox, it actually c…

I thought we had this through SPF. Ie. Your mail server can reject mail if the domain doesn't match spf records in dns. Maybe it's time to start something like an SPF Everywhere campaign.

SPF Everywhere would be a start. But, as currently deployed, at least, SPF is nowhere near enough. I do research in security, and even I often have no clue, when faced with a new corporate email system, whether the email addresses I see can or can't be forged, depending on domain.

Hell, if I get bob@company.com on my Gmail inbox, I cannot really tell whether even the @company.com part has been authenticated or not. There isn't even an HTTPS like lock icon or anything, let alone a "Google has verified that this email comes from Amazon.com" assurance.

Re: Snapchat Employee Data Leaks Out Following Phishing Attack

#47
post #37

Earlier quoted context omitted.

Sending requests by mail with official looking letterheads for example.

Or fake invoices. I get them regularly.

Phone calls too

http://consumerist.com/2016/02/04/arizona-wendys-jack-in-the...

An unknown person told the manager on the phone that they were with the fire department and needed to conduct a diagnostic test on the fire system, police said. The manager followed instructions and turned on the restaurant’s fire suppression system. The caller then said what the manager had done had caused a gas leak, so everyone had to evacuate the restaurant and the employee was told to break all the windows to avoid an explosion.

Wendy’s employees complied and smashed every single window, while waiting for the fire department to show up. Once officials arrived, they confirmed the call was a hoax.

Re: Snapchat Employee Data Leaks Out Following Phishing Attack

#48
post #7

Every company should inform their employees of the email impersonation scams going around. > In the scam, a criminal mimics a chief executive’s email account and directs an employee to wire money to an overseas bank account. By the time the company realises it has been duped, the money is gone. > [This scam] has cost businesses around the globe more than $2bn in little over two years, according to the US Federal Bure…

I'd go a step further and say it's a failing of management and process at said company if any employee felt that the CEO emailing for payroll information was "normal".

Agreed. We setup our bank account to require two signers to approve any wires, and they gave us a Key Fob for two factor authentication for wires.

As the company scales, we may add other people like a CFO to the bank account, but we will always require two people to authorize wire transfers.

Re: Snapchat Employee Data Leaks Out Following Phishing Attack

#49
I manage a small Security team where I work. We have a very good security awareness training program we've built out over the years. I'm biased, of course. I helped build it. We may never solve the human aspect of security entirely. However, we have one thing in particular that works well.

The most effective part of our program is the internal phishing attempts. They aren't annually or quarterly but almost monthly and sometimes weekly. It works very, very well and keeps phishing at the top of everyone's mind. There is nothing quite like teaching someone how easy it is to be caught off guard by showing them how easily someone can be phished and how they took the bait. It disarms them and the ego part of the conversation. It makes it a psychologically safe element of the corporate culture. It changes the conversation from "You're a dummy It's an interesting part of our security awareness program. In fact, we've built out a small application that sends the phishing email with a remote to track the email view(see the bait).

We then track them hitting the link through a unique URL (taking the bait), and track the final push of a login button or web-form (swallowing the hook entirely.)

It allows us to track how effective the campaign is and understand who may need some remedial training and of course how we can better improve the security awareness training because if a high percentage take the bait, the security awareness training wasn't effective.

In fact, I sent this article around the office this afternoon and sometime mid-week, plan to send another phishing attempt to see if it helped.

This strategy of course requires an organization to be fairly emotionally intelligent and have the right corporate culture. One of trust and transparency in a psychologically safe environment where people aren't mocked or made fun of but properly educated if they take the bait. I know that this kind of culture may not be the norm.

NOTE: We don't have as much to secure as a SnapChat and we aren't a high profile target. We just figured these things were the bare-minimum things to do to protect our employees and our customers.

Re: Snapchat Employee Data Leaks Out Following Phishing Attack

#50
I previously worked for a large Bank and they had authenticated email using Lotus Notes. While i would not recommend using that, it was nice to see them taking this serious. It was required to use it for every internal communication and actually made it seriously easy to use without knowing much about how it really works.

Its much easier to teach people to access their emails using a particullar application then it is to make them aware for phising attacks which sometimes can be very sophisticated.

While this does not work if you have to receive emails from unknowns, it is a no brainer to use something like this at a comapny level for all online communication. In my opinion not doing so is really careless behaviour especially for a tech company...

Post reply on HN