• HOME
  • MEMBERSHIP
  • IN THE COMMUNITY
  • MARKETPLACE
    • SECURITY PRODUCTS
  • ABOUT US
    • PARTNERSHIPS
    • OUR TEAM
  • NEWS & EVENTS
    • EVENTS
    • PRESS RELEASES
    • BLOG
    • MEDIA OVERVIEW
    • GALLERY
  • TIPS & ADVICE
  • HOME
  • MEMBERSHIP
  • IN THE COMMUNITY
  • MARKETPLACE
    • SECURITY PRODUCTS
  • ABOUT US
    • PARTNERSHIPS
    • OUR TEAM
  • NEWS & EVENTS
    • EVENTS
    • PRESS RELEASES
    • BLOG
    • MEDIA OVERVIEW
    • GALLERY
  • TIPS & ADVICE

Knowledge Update: 20 October 2017

20-October-2017
-
Blog
-
No comments
-
Posted by Tom Lejava

This week’s Knowledge Update talks about a breach at Pizza Hut that shows the need for board control, a new scam that impersonates VAT forms to deliver malware and a DoubleLocker ransomware that changes PINS and encrypts data.

 

Pizza Hut data breach shows need for board control

 

Pizza Hut, one of the biggest fast food chains in the world has come under fire for failing to notify its affected customers of a data breach that exposed personal information such as customer names, billing details, email addresses and credit card details.

The ICO have suggested that organisations should report personal data breaches to individuals affected by the breach as well as acting quickly in making the assessment. Under the current data protection law, there are no
obligations to notify, however when the GDPR regulation comes into effect on the 25th May, it will be mandatory for
organisations to notify of data breaches that risk harm to individuals. Information on GDPR and how it could affect your business can be found here.

Read more.

 

New scam impersonates VAT form to deliver malware

 

Researchers from ‘Trustwave’ have found a scam that impersonates Her Majesty’s Revenue & Customs (HMRC) to trick victims into downloading malware on their computer or phones.

According to Trustwave the email phishing attack disguised as a HMRC VAT return document was launched on 6 September 2017. The phishing email was sent using a registered HMRC-like domain (hmirc-gov.co.uk) which contained links to the infamous JRAT malware. The email encouraged users to click on a PDF document that said that there had been an error in their recently submitted VAT return which would take the victim to a Microsoft OneDrive Zip file where inside the zip file there would be a malicious Java Jar file.

Staff should be made aware of the threats posed from phishing through training and awareness sessions. Policies in regard to the acceptable use of computer equipment, handling data and payment processes should be implemented and adhered to. Prevention advise for phishing can be found here.

Also, implementing encryption and digital signatures across your business will secure your sensitive data and reduce phishing attacks.

Read more.

 

DoubleLocker Ransomware Changes PIN and Encrypts Data

 

Security researchers are warning Android users that a new breed of Android ransomware, that is designed to encrypt a person’s device as well as lock them out by changing their passwords, is becoming more prevalent.

DoubleLocker is based on a code from a banking trojan called Android.BankBot.211.origin which will force users to grant the DoubleLocker access to the smartphone’s accessibility service. Once the Trojan is launched, normally from a fake adobe flash player app, it will try and obtain accessibility to permissions on your device.

Businesses should look to implement a Bring Your Own Device policy so employees can use personal devices for business securely. An explanation of BYOD and a guide to implementation can be found here.

Also, Anti-virus software should be installed on your device and automatic updates should be enabled.

Read more.

 

Tags
BYOD
Data Security
GDPR
Knowledge Update
Malware
Phishing
Ransomware
← PREVIOUS POST
London Digital Security Centre Partners with Wesleyan to Educate SME’s on Digital Security
NEXT POST →
London Digital Security Centre Hosts City Briefing with the Deputy Mayor for Business
Categories
  • Blog
  • Press Release
Recent Posts
  • Is your business cyber-ready?
  • You’ve Got Mail: 5 Tips to Secure Your Email
  • #OneReset - What could you really lose in a hack?
  • Here’s what GDPR means for your business!
  • Essential Advice for Small Business Cyber Security
London Digital Security Centre

We are a Not for Profit organisation, launched by the Mayor of London as a joint venture with the Metropolitan Police and City of London Police.

Leave a Comment

Your feedback is valuable for us. Your email will not be published.
Cancel Reply

Please wait...
Submit Comment

Related News

Other posts that you should not miss.
GDPR

GDPR – so what…?

25-October-2017
-
Blog

…is it? The General Data Protection Regulation (GDPR) comes into force on May 25th 2018. It outlines how organisations should manage and protect personal information. …does it mean? …

Read More →
Posted by Tom Lejava
2 MIN READ

Here’s what GDPR means for your business!

14-May-2018
-
Blog

Just a few weeks from now, this coming May 25, 2018, the European Union’s General Data Protection Regulation (GDPR) protocol becomes instantiated into law. It is a …

Read More →
Posted by Tom Lejava
6 MIN READ

Leicester Conference Cyber Resilience Week 2017

13-September-2017
-
Blog

What a start to the Digital Leaders Cyber Resilience week! Working with the East Midlands Chamber of Commerce and supported by De Montfort University, NatWest Bank and Identifi …

Read More →
Posted by Tom Lejava
1 MIN READ
Twitter Follow
Tweets by LondonDSC
Social Connect
News
  • 18-March-2019
    Is your business cyber-ready?
  • 05-February-2019
    You’ve Got Mail: 5 Tips to Secure Your Email
  • OneReset
    23-October-2018
    #OneReset - What could you really lose in a hack?
Contact Us

Company Number : 09639299
Mail to : [email protected]
Address : One Wood Street, London,
United Kingdom, EC2V 7WS.

Built by Cyber Rescue
Privacy   T & C
Copyright London Digital Security Centre (LDSC) 2017
Knowledge Update: 20 October 2017 - London Digital Security Centre
 Logo Header Menu
MENU
  • HOME
  • MEMBERSHIP
  • IN THE COMMUNITY
  • MARKETPLACE
    • SECURITY PRODUCTS
  • ABOUT US
    • PARTNERSHIPS
    • OUR TEAM
  • NEWS & EVENTS
    • EVENTS
    • PRESS RELEASES
    • BLOG
    • MEDIA OVERVIEW
    • GALLERY
  • TIPS & ADVICE