Fish hack, no seriously..

Image result for fish face

Credit: Getty Images. NB. not the actual fish involved

We have talked about phishing before and warned you of the dangers of phishing emails that spread malware, ransomware and other toxic payloads. Today however we are talking fish. Actual fish.

It was never going to be long before the obsession with web-enabling everything from air conditioning to kettles, caused a bit of a problem. In this case, a web-enabled fish tank (stay with us) was hacked and using this fish tank’s connection, criminals managed to move through the network and steal data from the fish home a ‘smart tank’  in a casino…

If you consider the use web-enabled equipment, including any animal enclosures, please risk assess it thoroughly and please protect it properly from fishers, phishers and other cyber botherers. Criminals will head for the point of least resistance every time and you need to know where that is before they do.

If you want to view some free content of ours on cyber protection, head over here.

 

Nine years worth of data swiped from Ontario casino – hacker claims

Nine years worth?! OK hackers make as lot of claims, but data going back nine years is almost as impressive as the MySpace hack that reminded everyone that once had a MySpace page.

Does beg the question why they were keeping this old data though…collect it for what you need it for and delete safely!

Full story…

Four Winds casino hit by hackers

Stack of Chips(US) Michigan casino Four Winds has discovered that cardholder data including all of the data stored on the mag strip, has been stolen by hackers and the casino is warning users between October 2014 and October 21, 2015 , that their information may have been compromised and/or stolen.

Cybercrime knows no geography, so it is important not to be distracted by the location of the crime. This may have happened in Michigan, but the criminals could be anywhere.

phishThere are no details available yet on how the hackers managed to upload the code that allowed this information to be copied from the casino system. Phishing of employees is one of the most popular and successful routes into a business and ensuring employees are able to spot phishing and its more aggressive and successful big brother, spear phishing, is imperative. Employees are always going to be the Achilles heel of a security strategy and that is why businesses that handle personal information, need to ensure they place enough importance on training and re-training them with security awareness and the latest threats.

Advent IM HMG accreditation concepts trainingInsider threat is often a worry for many businesses too and it is the other end of the human threat; when the nefarious individual is already on the inside. Obviously, we don’t know what happened in this instance but this offers all such businesses a warning to review security training, vetting and overall strategy.

Hackers slurp 150k credit cards from casino….there could be more

The Register has today reported the theft of 150k credit card details from an unnamed casino. Apparently, the casino was a virtual security-free zone, not even sporting a firewall. Experts say there may be six more casinos targeted by the Fin5 hacker gang.

Read the full story here

cropped-istock_000012299872medium.jpg

US accuses Iran of Las Vegas Hack….

Full story here from The Register 

US director of National Intelligence James Clapper has accused Iran of the 2014 hack of the Las Vegas Sands casino.

This attack bought down parts of the gambling giant’s IT infrastructure, like email, but they assured users that personal information such as credit cards were not vulnerable…

Multi million dollar poker game halted by cyber attack

1,937 participants in Winning Poker Tournament (WPN) mega event have been left disappointed as a cyber attack has caused the tournament to be stopped.

The Distributed Denial of Service (DDoS) attack swamped and disrupted initial games and WPN had no choice but to shut down and refund early players. No responsibility for the attack has been established as yet.

The event has been re-scheduled for February.

More details and original story can be found on the online casino reports website.

ddos attackl