Back to news

March 17, 2020 | Local, C4ISR, Security

Online 'phishing' attacks expected to target housebound staffers as COVID-19 spreads

It's a 'huge opportunity' for online crime, one expert warns

The number of "phishing" attacks meant to steal the online credentials of public servants and corporate sector employees now housebound due to the COVID-19 pandemic is on the rise, one cyber security expert warns.

Many attempts are being made against employees who are working from home on virtual private works (VPNs). Cyber experts are still gathering data to establish a direct correlation between the pandemic crisis and the increase in malicious activity.

But Rafal Rohozinski, chief executive officer of the SecDev Group of Companies, said this pandemic moment — when large numbers of employees are at home and receiving instructions from their workplaces on how to connect to internal networks — offers online thieves a "huge opportunity."

Federal government and corporate sector systems were never designed to support a sudden, mass migration of employees from offices to their homes, he said.

"The opening that creates for those who want to wreak havoc through ransomware and malware is really, really significant," said Rohozinski. "And I don't think we're anywhere near prepared for that.

"What we're seeing is an increase in phishing being used as a means to get people's credentials."

U.S. Health Department attacked

The U.S. Health and Human Services Department's website was hit by a cyber attack over several hours on Sunday, an incident which involved overloading its servers with millions of hits.

Officials said the system was not penetrated, although media reports in Washington described it as an attempt to undermine the U.S. government's response to the coronavirus pandemic — and may have been the work of a foreign actor.

Rohozinski said that while the facts are not all in yet, his "professional guess" is that there's a link between the attack and the COVID-19 crisis.

Last week, Canada's top military commander warned that he'd seen recent indications the country's adversaries intend to exploit the uncertainty, confusion and fear generated by the pandemic.

Gen. Jonathan Vance, chief of the defence staff, was not specific about the potential threats — but experts say they could range from hacking to online disinformation campaigns aimed at discrediting the federal government's response.

Rohozinski said he's concerned about the federal government's technical capacity to support thousands of employees on private networks.

"Everybody's moving on to VPNs. Everybody," he said. "This is an enormous pinpoint and an enormous vulnerability."

Federal Digital Government Minister Joyce Murray's office was asked for a response Monday, but was unable to provide an immediate comment.

Many of the country's leading information technology companies are part of the Canadian Cyber Threat Exchange (CCTE), a nonprofit centre where companies can swap information and insights. A CCTE spokeswoman said the corporate sector is better prepared to face the challenges posed by the mass movement of employees to home networks.

Still, there is reason for concern.

"Given we are moving people to work from home now, companies need to ensure that the work from home environment is as safe as the corporate environment and that people are trained to notice these phishing campaigns, just like they were in the corporate environment," said Mary Jane Couldridge, director of business development at the CCTE.

"It's a matter of keeping our community aware of what is impacting Canada daily so we know how to react to it and prevent it from spreading — and not chase rainbows."

Most corporations have plans they'll activate now to cover the wholesale movement of employees to networks outside of the office, she added.

https://www.cbc.ca/news/politics/online-hacking-phishing-covid-19-coronavirus-1.5499725

On the same subject

  • Canadian frigate delayed again

    October 16, 2018 | Local, Naval

    Canadian frigate delayed again

    Ian Keddie, Toronto - IHS Jane's Defence Weekly A long-awaited decision on the Canadian Surface Combatant (CSC) frigate replacement programme has been delayed once more, although it is unclear for how long. In the official Public Services and Procurement Canada (PSPC) update document released on 27 September, PSPC indicated no CSC design would be chosen in third quarter 2018, after indicating to Jane's in May 2018 that a decision would be made at that time. In the update document, ‘The National Shipbuilding Strategy in 2018,' which outlines the state of the federal shipbuilding plan, the PSPC said, “Request for Proposals to select the Canadian Surface Combatant (CSC) design and design team has closed. https://www.janes.com/article/83808/canadian-frigate-delayed-again

  • Opinion: It's time to ground Canada's purchase of fighter jets

    July 19, 2021 | Local, Aerospace

    Opinion: It's time to ground Canada's purchase of fighter jets

    Over 100 notable Canadians have released an open letter calling on Prime Minister Justin Trudeau to cancel the fighter jet procurement.

  • Airbus aggressively sourcing more Canadian content

    August 28, 2018 | Local, Aerospace

    Airbus aggressively sourcing more Canadian content

    by Chris Thatcher When Tom Enders, then the chief executive officer of Airbus, announced in October 2017 that Canada would become the company's fifth home country and first outside of Europe, following a deal with Bombardier to acquire a majority stake in the C Series passenger jet, small- and medium-sized Canadian aerospace companies had reason to be optimistic. Canada has typically ranked eighth or ninth among Airbus suppliers. But with the C Series now firmly under the Airbus tent (it was renamed the A220 in July), a contract award in 2016 to provide the Royal Canadian Air Force with 16 C295W fixed-wing search and rescue (FWSAR) aircraft, and looming competitions for a future fighter jet and strategic tanker and transport aircraft, Airbus is aggressively sourcing more Canadian content. Before you make your pitch, however, Ruben Tauste Caro, responsible for Airbus's strategic procurement in North America, has a few words of advice: no bashing the competition, no me-too products, and go easy on the wonders of your new shop floor machinery. “I want you to tell me that you work in a very, very dedicated frequency. And in that frequency, I want you to tell me that you are the expert in a very specific niche. Then you've got me,” he told the Abbotsford Aerospace, Defence and Security Expo in August. Airbus routinely conducts in-person assessments of its prospective suppliers and, while cost, quality, and on-time production are obvious baseline requirements, what interests Tauste Caro are signs of continuous improvement and true innovation. He said companies that claim to build a better mouse trap or be a one-stop shop for all his supply needs are quickly dismissed. “Tell me what you are really, really good at, and if I have an opportunity in the future, that will be yours,” he said. Continuous improvement need not involve large investments. A dashboard with measurable targets will suffice if it clearly shows progress, said Tauste Caro. “Show me your KPIs [key performance indicators]. If you don't [meet] a target that month, do you have an action behind it?” A clear ability to set and reach targets is important, he emphasized, because if there is ever an issue with product quality, “The question is, will you overcome that issue? Do you have the right procedures, the right way of working? Is your workforce engaged?” That's why he also asks questions about innovation. Most companies have a tendency to highlight their shop floor. While new machines and robotics are important, he always looks beyond to the people operating them. “Innovation is people,” he said. “{They] are the key parameters in the innovation equation...[D]on't waste time on machines, tell me your way of working.” In particular, how do ideas move from the shop floor to the C-suite? For suppliers eyeing opportunities with Airbus's commercial aircraft production, an ability to ramp up production and deliver at high rates is critical. “This is extremely important,” he stressed. “We cannot afford to have one aircraft system stopped in the warehouse.” Tauste Caro heads a small four-person team responsible for supplier identification and development throughout North America, so he encouraged companies to call or “knock on the door,” to keep him apprised of product changes, expansion plans, new strategies, and contract awards. “Feed me with that information. That is the daily bread and butter of my job within strategic procurement,” he said, explaining that if he's asked to recommend a supplier, “I have to be able to answer right away.” While ramp-up of A220 production this year and delivery of the first FWSAR aircraft in 2019 might mean more opportunities for Canadian suppliers, Airbus is particularly focused on the value proposition it can offer in a future fighter jet and air-to-air refuelling aircraft competition. “We need to work with you right now,” he told executives at the Abbotsford trade show, to identify industrial and technological benefits (ITBs) proposals for both programs and meet FWSAR obligations. There is a “huge requirement” for ITBs within the fighter jet program, he noted. “We need to be creative, we need the suppliers.” https://www.skiesmag.com/news/airbus-aggressively-sourcing-more-canadian-content

All news