Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Ubiquiti Confirms Extortion Attempt Following Security Breach

Ubiquiti Confirms Extortion Attempt Following Security Breach

Networking device maker Ubiquiti has confirmed that it was the target of an extortion attempt following a January security breach, as revealed by a whistleblower earlier this week.

The company, however, didn’t confirm the whistleblower’s claims that user data was accessed during the incident or that the attackers stole any Ubiquiti source code.

Ubiquiti added that incident response experts hired to investigate the breach didn’t find evidence of customer information being targeted during the breach.

“These experts identified no evidence that customer information was accessed, or even targeted,” Ubiquiti said in a statement.

“The attacker, who unsuccessfully attempted to extort the company by threatening to release stolen source code and specific IT credentials, never claimed to have accessed any customer information.

“This, along with other evidence, is why we believe that customer data was not the target of, or otherwise accessed in connection with, the incident.”

Ubiquiti is cooperating with law enforcement in an ongoing investigation of the incident, which has revealed that the attacker “is an individual with intricate knowledge” of Ubiquiti’s cloud infrastructure.

Although no proof that customer info was accessed, the networking device vendor advises customers to reset passwords and enable two-factor authentication on their accounts.

Also Read: What You Should Know About The Data Protection Obligation Singapore

“All this said, as a precaution, we still encourage you to change your password if you have not already done so, including on any website where you use the same user ID or password,” the company said.

Caption

Whistleblower’s take on Ubiquiti breach

Ubiquiti told customers after the January security incident that the attacker compromised systems hosted at a third-party cloud provider with no indication that users’ accounts were affected in any way.

However, earlier this week, a whistleblower involved in the breach response challenged the company’s story, saying that the incident’s actual impact was massive.

Ubiquiti allegedly discovered the incident in December 2020 after the hacker already gained admin level to the company AWS accounts and databases stored on AWS.

After removing a backdoor used by the attacker in January, the hacker tried to extort the networking device vendor asking for 50 bitcoins not to reveal the breach, saying that he already stole Ubiquiti source code.

As the whistleblower also revealed, Ubiquiti did not have a logging system setup which meant that they could not check what data or systems the attacker accessed.

The company refused to pay the ransom and, instead, found and removed a second backdoor from its systems, changed all employee credentials, and issued the January 11 security breach notification.

As it stands, from all the info surrounding the breach exposed by the whistleblower, Ubiquiti has only confirmed the hacker’s extortion attempt.

Also Read: The Difference Between GDPR And PDPA Under 10 Key Issues

Claims that source code was stolen and customers’ information was accessed during the breach are yet to be confirmed.

Ubiquiti shares have fallen from $349 on March 30 to $290 on April 1, after the whistleblower accused the company of downplaying the breach.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us