If you hang out with CISOs like I do, shadow IT has always been a difficult problem. Shadow IT refers to refers to “information technology (IT) systems deployed by departments other than the central IT department, to bypass limitations and restrictions that have been imposed by central information systems. While it can promote innovation and productivity, shadow IT introduces security risks and compliance concerns, especially when such systems are not aligned with corporate governance.”

Shadow IT has been a longstanding problem as IT professionals can’t implement security measures and guidelines when they are unaware of its use.

Now that artificial intelligence (AI) is widely used for purposes including work, it is imperative that organizations address its governance, as they previously addressed employees’ use of IT assets. Otherwise, employees will use AI tools without the organization’s knowledge and outside of its acceptable use policies, exacerbating the problem of shadow AI in the organization.

A recent TechRadar article concluded that “you almost certainly have a shadow AI problem.” The risks of having shadow AI in the organization include: “the leakage of sensitive or proprietary data, which is a common issue when employees upload documents to an AI service such as ChatGPT, for example, and its contents become available to users outside of the company. But it could also lead to serious data quality problems where incorrect information is retrieved from an unapproved AI source which may then lead to bad business decisions.” And don’t forget about the problem of hallucinations.

Implementing an AI Governance Program is one way to address the shadow AI problem. AI Governance programs differ depending on business needs, but all of them address who owns the program, AI tools usage, what tools are sanctioned, how AI tools can be used, guardrails around the risks of data loss, data integrity and accuracy, and user training and education. Governing the use of AI tools in an organization is similar to governing the use of IT assets. The most important thing is to get started before shadow AI gets out of hand.

In a win for global law enforcement, Germany’s Bundeskriminalamt (BKA) announced on April 5, 2022, that it had officially taken down the infrastructure of Hydra, a Russian-based, illegal dark-web marketplace that has allegedly facilitated more than $5 billion in Bitcoin transactions since its inception in 2015. In the process of shutting it down, German authorities seized over $25 million in Bitcoin through 88 transaction. According to BKA, it “secured the server infrastructure in Germany of the world’s largest illegal Darknet marketplace ‘Hydra Market.’”

BKA attributed the take down to a collaborative investigation between its Central Office for Combating Cybercrime and U.S. law enforcement authorities since August 2021.

According to BKA, Hydra had 17 million customers and over 19,000 seller accounts registered on its marketplace, and “was probably the illegal marketplace with the highest turnover worldwide.”

Following the takedown in Germany, the U.S. Department of Treasury (Treasury) Office for Foreign Assets Control (OFAC) followed up with sanctions against Hydra, which, according to Secretary of the Treasury, Janet Yellen, sends “a message today to criminals that you cannot hide on the darknet or their forums, and you cannot hide in Russia or anywhere else in the world.”

Treasury’s release states, “Countering ransomware is a top priority of the Administration. Today’s action supports the Administration’s counter-ransomware lines of effort to disrupt ransomware infrastructure and actors in close coordination with international partners” and calls out Russia as “a haven for cybercriminals.”

Therefore, Hydra was designated by OFAC “for being responsible for or complicit in, or having engaged in, directly or indirectly, cyber-enabled activities originating from, or directed by persons located, in whole or in substantial part, outside the United States that are reasonably likely to result in, or have materially contributed to, a significant threat to the national security, foreign policy, or economic health or financial stability of the United States and that have the purpose or effect of causing a significant misappropriation of funds or economic resources, trade secrets, personal identifiers, or financial information for commercial or competitive advantage or private financial gain.”

Treasury further sanctioned virtual currency exchange Garantex, which is in Estonia but operating in Moscow and St. Petersburg, Russia. According to Treasury, more than $100 million in transactions over the exchange were associated with “illicit actors and darknet markets,” including Conti and Hydra.

Therefore, Treasury designated Garantex “for operating or having operated in the financial services sector of the Russian Federation economy” which “reinforces OFAC’s recent public guidance to further cut off avenues for potential sanctions evasion by Russia, in support of the G7 leaders’ commitment to maintain the effectiveness of economic measures.”

These actions by the Department of the Treasury send a strong message to cybercriminals that sanctions related to the war in Ukraine are rapidly spurring additional scrutiny and action by law enforcement against anyone associated with Putin or Russia.

For more on what these sanctions mean for U.S. individuals and businesses, click here.

On April 5, 2022, the U.S. Department of Treasury Office of Foreign Assets Control (OFAC) sanctioned darkweb Hydra Marketplace and virtual currency Garantex and added both to the Specially Designated Nationals List (SDN) [view related post].

On October 1, 2020, OFAC issued a Ransomware Advisory “to alert companies that engage with victims of ransomware attacks of the potential sanctions risks for facilitating ransomware payments.”

OFAC specifically designates “malicious cyber actors and those who facilitate ransomware transactions under its cyber-related sanctions program.” Understanding and adhering to the Advisory is very important for companies that are victims of ransomware attacks if they are considering paying a ransom.

OFAC updates the cyber-related designations, which can be accessed on the Department of the Treasury’s website, as it did on April 5, 2022 with Garantex and Hydra.

When adding Garantex to the designation list and to help prevent fraud, OFAC also listed over 100 digital currency addresses associated with SDN Hydra Marketplace and used to conduct “illicit transactions” so those involved in digital currency are aware that the addresses are illicit.

OFAC explains the implications of U.S. persons transacting any business with sanctioned individuals or entities in its announcement of the sanctions against Hydra and Garantex:

All transactions by U.S. persons or within (or transiting) the United States that involve any property or interests in property of designated or otherwise blocked persons are prohibited unless authorized by a general or specific license issued by OFAC, or exempt. These prohibitions include the making of any contribution or provision of funds, goods, or services by, to, or for the benefit of any blocked person and the receipt of any contribution or provision of funds, goods, or services from any such person.

OFAC has also issued Sanctions Compliance Guidance for the Virtual Currency Industry to assist compliance professionals on how to navigate this space.

We expect to see more activity in cyber designations while the U.S. continues to ramp up sanctions against Russia and its leadership.

Three recent events are prompting me to update our previous blog post on the difficult decision of whether to pay or not to pay ransomware following an attack [view related post].

The first event is the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) issued an advisory on October 1, 2020, “to highlight the sanctions risks associated with ransomware payments related to malicious cyber-enabled activities.” The advisory warns that if a company or a vendor facilitates the payment of a ransom to criminals or adversaries “with a sanctions nexus,” the funds could be used “to fund activities adverse to the national security and foreign policy objectives of the United States.” Therefore, companies, or vendors acting on their behalf that pay a ransom to a sanctioned individual or government are at risk for sanctions under the Financial Crimes Enforcement Network (FinCEN) regulations.

The advisory is a very important consideration to weigh in determining whether or not to pay a ransom for encryption keys or destruction of data. For more on the OFAC Advisory, click here:

The second event was a recent thoughtful analysis on this subject matter by KrebsonSecurity, entitled “Why Paying to Delete Stolen Data is Bonkers.” Referring to a Coveware report, which states that almost half of all ransomware cases include the release of exfiltrated data, Krebs quotes from the report noting, “Unlike negotiating for a decryption key, negotiating for the suppression of stolen data has no finite end.”

Krebs further notes that ransomware victims who pay for the decryption key are relying on hope that the keys will work, which is not always the case.

The final event relates to growing anecdotal evidence that Ransomware as a Service (RaaS) operators, usually less sophisticated than the big boys, are engaging in double extortion scams against their victims. This means that if you have made the business decision to pay the ransomware for either the decryption keys or the destruction of data, these operators are refusing to give you the key or the confirmation of destruction until you pay more ransom – after you have agreed to pay a negotiated amount, and they have initially agreed to hold up their part of the bargain. This behavior is certainly inconsistent with the general assumption of ransomware, namely that the attackers will return what has been ransomed after payment, so future victims can be assured that once they pay the ransom, they will get back their keys or data. This new phenomenon provides a strong argument (in addition to the ones above) to refrain from paying the ransom. They are criminals, after all, and some are more credible and smarter than others. These attackers who engage in double extortion will rapidly get a bad reputation and are shooting themselves in the foot. However, while in the midst of the attack, you just don’t know who you are dealing with, so weighing these risks is challenging at best.

On October 1, 2020, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) issued an advisory “to highlight the sanctions risks associated with ransomware payments related to malicious cyber-enabled activities.”

The advisory acknowledges that the incidents of ransomware attacks on U.S. companies have risen during the COVID-19 pandemic. Although the advisory does not mention that companies have been paying ransoms when they are victimized, it has been publicly reported that companies have paid ransoms, particularly when data has been exfiltrated and the cybercriminals are threatening to post the data online unless a ransom is paid for confirmation of destruction, as is the scheme used by Maze.

The advisory warns that paying ransoms “not only encourage future ransomware payment demands, but also may risk violating OFAC regulations.” The advisory “describes these sanctions risks and provides information for contacting relevant U.S. government agencies, including OFAC, if there is a reason to believe the cyber actor demanding ransomware payment may be sanctioned or otherwise have a sanctions nexus.”

If you want to read a well-written history of ransomware, read the advisory, as it lays out nicely the evolution of ransomware and its effect on businesses.

According to OFAC:

“[F]acilitating a ransomware payment that is demanded as a result of malicious cyber activities may enable criminals and adversaries with a sanctions nexus to profit and advance their illicit aims. For example, ransomware payments made to sanctioned persons or to comprehensively sanctioned jurisdictions could be used to fund activities adverse to the national security and foreign policy objectives of the United States. Ransomware payments may also embolden cyber actors to engage in future attacks. In addition, paying a ransom to cyber actors does not guarantee that the victim will regain access to its stolen data.”

OFAC further states that “[C]ompanies that facilitate ransomware payments to cyber actors on behalf of victims, including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response, not only encourage future ransomware payment demands but also may risk violating OFAC regulations.” These sanctions include civil penalties based on strict liability.

In light of the advisory, OFAC:

encourages financial institutions and other companies to implement a risk-based compliance program to mitigate exposure to sanctions-related violations. This also applies to companies that engage with victims of ransomware attacks, such as those involved in providing cyber insurance, digital forensics and incident response, and financial services that may involve processing ransom payments (including depository institutions and money services businesses (emphasis ours). In particular, the sanctions compliance programs of these companies should account for the risk that a ransomware payment may involve an SDN or blocked person, or a comprehensively embargoed jurisdiction. Companies involved in facilitating ransomware payments on behalf of victims should also consider whether they have regulatory obligations under Financial Crimes Enforcement Network (FinCEN) regulations.”

The OFAC advisory is a stark warning for responding to ransomware attacks and incident response. It lays out important considerations in determining how it may impact your incident response plan, questions to ask your cyber liability insurer about coverage around ransom payments, and the risks associated with a ransomware payment in your enterprise-wide risk management program.

Based on an unprecedented number of college closures, along with complex demographic challenges showing continued reductions in the number of college-aged students, states are struggling to determine how to best protect both students and college employees. Currently, most states have been reactive, and have only taken action after a college has announced its intention to close, often with little notice to employees and students. On the other hand, requiring a college that is just starting to show signs of financial struggle to publicly announce that position would surely chill student applications, encourage transfers, limit financing, and send employees fleeing for other employment. In turn, this could exasperate the college’s financial condition, all but ensuring closure.

In Massachusetts, where 18 colleges have closed or merged in the past five years, the legislature is looking at several options. Specifically, Massachusetts Governor Charlie Baker has proposed a bill that would require notification of “any known liabilities or risks which may result in imminent closure of the institution or jeopardize the institution’s ability to fulfill its obligations to current and admitted students,” with notice to the Massachusetts Board of Higher Education (MBHE). Because the proposed legislation allows the notification to be confidential, it is intended that colleges could still freely pursue financing, merger, and/or the continued enrollment of students in order to try to turn around its financial condition. When notifying the Board, the school must also put forth a contingency plan for notifying students and assisting with transfer in case closure becomes necessary. The bill also would allow the state to request financial data from schools.  If a school failed to provide the requested data, it could be sanctioned by the Board of Higher Education.

The MBHE has issued proposed regulations consistent with this bill. Two or three hearings to allow for public comment on the regulations will be scheduled in early August.

During WWII, Morse Code was an indispensable asset that allowed the allies to transmit sensitive information over long distances with great accuracy. However, it contained an obvious, and potentially fatal, flaw — it provided no built in mechanism for identifying the sender of the messages. In order to combat this, U.S. intelligence officers implemented a methodology known as the “Fist of the Sender,” an early system of “behavioral biometrics” that verified the sender’s identity by analyzing subtle, non-replicable and idiosyncratic “typing” patterns of individual users.

While Morse Code and the “Fist” are laughably archaic by today’s standards, the field of behavioral biometrics has rapidly advanced, and companies today utilize complex algorithms and sensors to determine, track, and record not only your actual “typing” patterns, but also:

  • the angle at which you hold your devices;
  • the exact speeds at which you swipe or scroll on your devices;
  • the manner in which you scroll your mouse; and
  • which fingers you use to swipe on your touchscreens;

By collecting thousands of data points on an ongoing basis, companies create a digital profile of your individual mannerisms that can be used to determine when someone else has accessed your account. As reported by the New York Times in 2018, The Royal Bank of Scotland detected an imposter when the unsanctioned user scrolled the mouse wheel and used the numerical strip on the keyboard (both actions that the account holder had never done).

But as this exciting technology inevitably evolves and industries possess eerily accurate behavioral profiles of their clients, what may the legal/constitutional ramifications be?

  • Will, for example, this kind of information be admissible in court for the purposes of identification?
  • Will companies be limited as to how they can manipulate or sell this kind of data?
  • Will police need a warrant to obtain behavioral biometric data from companies, in light of the recent Supreme Courts recent decision in Carpenter v. United States — and to what degree is this data being “voluntarily” transmitted to third parties?
  • Will courts eventually determine that such an accurate and nuanced profile of one’s idiosyncratic behaviors are so intimate as to constitute intellectual property belonging to the individual and not the organization collecting it?
  • How useful will this information be in creating your robot clone? (I digress)

Our legal system is brilliantly designed to play “catch-up” with an evolving society, but rapid advances in technology, such as behavioral biometrics, will undoubtedly challenge our fundamental understanding of established legal principles in a manner that might even make our Founding Fathers say “new phone, who dis?”

This article authored by guest blogger Kelvin Santos a student at Roger Williams University School of Law.

The regulatory sword of the financial industry came down on a former securities employee for violations involving wire transfers out of a client’s account. The Financial Industry Regulatory Authority (FINRA) provides oversight of the financial industry. According to their website, in 2017, they brought 1,369 disciplinary actions against registered individuals and firms, levied fines totaling $64.9 million and ordered restitution of $66.8 million to harmed investors.

We’ve discussed phishing scams where the imposter sends an email and makes it look like the wire transfer instructions have changed. Unfortunately, both the company employee and the client are scammed as a result. In this case, the former employee of the broker took the imposter’s instructions, acted on them, and then deceived his employer –all to the detriment of the client. FINRA brought an action against the former securities employee.

Why? The difference in this case is that it appears that the former employee failed to follow his employer’s own policies and procedures regarding wire transfers. The former employee processed eight wire transfers from the customer’s account without obtaining verbal verification of the instructions from the actual customer. In total, the former employee processed wire transfers totaling $794,860 in response to the imposter’s requests. The former employee was also alleged to have made false statements to his former employer regarding the transactions, violating FINRA Rule 2010, and causing his employer to file inaccurate financial statements.

The former employee consented to a $5,000 fine and is no longer associated with a FINRA member. The employer was not fined or sanctioned in this matter.

Cisco Talos has discovered a new menace to iPhone users—a sophisticated malware campaign targeting iPhones to trick users into downloading an open-source Mobile Device Management (MDM) solution that gives the hackers control of the phone. It is reported that Cisco and Apple are working together to combat the threat.

According to reports, once the MDM tool is downloaded and the hackers have control of the phone, they can steal information from the infected devices, including the phone number, serial number, location, contact information and basically everything else on the phone.

Cisco reports that the infected phones use iOS versions 10.2.1 to 11.2.6. It believes that the attackers were able to obtain the permissions required to infect the phones through extensive social engineering efforts.

Although the confirmed attacks against particular iPhone users are low, because they used malicious versions of Telegram and WhatsApp, security experts are warning users to be vigilant about downloading apps onto their phone, including mobile device management solutions, and to confirm that the MDM solution is sanctioned by employers or others issuing the solution.

Chinese cyber espionage and cyber-attack capabilities will continue to support China’s national security and economic priorities,” says Dan Coats, the Director of National Intelligence “Americans should not buy Huawei or ZTE products.” In March 2017 the Chinese Telecom company, ZTE, plead guilty to shipping US technology to Iran and North Korea, and reached a settlement to punish the responsible parties for covering up the illegal sales and pay a $1.2 billion penalty. ZTE did not follow through with the settlement deal by not punishing those involved with the cover-up; in fact those employees received bonuses. While investigating ZTE, internal documents named a competitor—code name “F7” which stated that F7 used “‘cutoff companies’ to do business in sanctioned countries and aimed to recruit lawyers with a thorough knowledge of U.S. export controls and compliance. (source:Law360 04/12/17) Investigators have come to believe the Chinese telecommunications company known as F7 is really Huawei Technologies Co Ltd. U.S. government officials have a renewed interest in investigating further into the F7 connection. Meanwhile, concerns have heightened at the Pentagon about consumer electronics being used to track service members. As a result, personnel on U.S. military bases can no longer buy phones and other gear manufactured by the Chinese firms Huawei and ZTE, as the Pentagon said the devices pose an “unacceptable” security risk. (Source:Channel NewsAsia) Pentagon spokesman Major Dave Eastburn said on May 4, 2018, “Huawei and ZTE devices may pose an unacceptable risk to (military) personnel, information and mission.” In March, FCC Chairman Ajit Pai informed Congress he also shared the concerns of U.S. lawmakers about surveillance threats from Huawei. “Hidden ‘back doors’ to our networks in routers, switches—and virtually any other type of telecommunications equipment—can provide an avenue for hostile governments to inject viruses, launch denial-of-service attacks, steal data, and more.” Is an Executive Order imminent?