17 mars 2020 | Local, C4ISR, Sécurité

Online 'phishing' attacks expected to target housebound staffers as COVID-19 spreads

It's a 'huge opportunity' for online crime, one expert warns

The number of "phishing" attacks meant to steal the online credentials of public servants and corporate sector employees now housebound due to the COVID-19 pandemic is on the rise, one cyber security expert warns.

Many attempts are being made against employees who are working from home on virtual private works (VPNs). Cyber experts are still gathering data to establish a direct correlation between the pandemic crisis and the increase in malicious activity.

But Rafal Rohozinski, chief executive officer of the SecDev Group of Companies, said this pandemic moment — when large numbers of employees are at home and receiving instructions from their workplaces on how to connect to internal networks — offers online thieves a "huge opportunity."

Federal government and corporate sector systems were never designed to support a sudden, mass migration of employees from offices to their homes, he said.

"The opening that creates for those who want to wreak havoc through ransomware and malware is really, really significant," said Rohozinski. "And I don't think we're anywhere near prepared for that.

"What we're seeing is an increase in phishing being used as a means to get people's credentials."

U.S. Health Department attacked

The U.S. Health and Human Services Department's website was hit by a cyber attack over several hours on Sunday, an incident which involved overloading its servers with millions of hits.

Officials said the system was not penetrated, although media reports in Washington described it as an attempt to undermine the U.S. government's response to the coronavirus pandemic — and may have been the work of a foreign actor.

Rohozinski said that while the facts are not all in yet, his "professional guess" is that there's a link between the attack and the COVID-19 crisis.

Last week, Canada's top military commander warned that he'd seen recent indications the country's adversaries intend to exploit the uncertainty, confusion and fear generated by the pandemic.

Gen. Jonathan Vance, chief of the defence staff, was not specific about the potential threats — but experts say they could range from hacking to online disinformation campaigns aimed at discrediting the federal government's response.

Rohozinski said he's concerned about the federal government's technical capacity to support thousands of employees on private networks.

"Everybody's moving on to VPNs. Everybody," he said. "This is an enormous pinpoint and an enormous vulnerability."

Federal Digital Government Minister Joyce Murray's office was asked for a response Monday, but was unable to provide an immediate comment.

Many of the country's leading information technology companies are part of the Canadian Cyber Threat Exchange (CCTE), a nonprofit centre where companies can swap information and insights. A CCTE spokeswoman said the corporate sector is better prepared to face the challenges posed by the mass movement of employees to home networks.

Still, there is reason for concern.

"Given we are moving people to work from home now, companies need to ensure that the work from home environment is as safe as the corporate environment and that people are trained to notice these phishing campaigns, just like they were in the corporate environment," said Mary Jane Couldridge, director of business development at the CCTE.

"It's a matter of keeping our community aware of what is impacting Canada daily so we know how to react to it and prevent it from spreading — and not chase rainbows."

Most corporations have plans they'll activate now to cover the wholesale movement of employees to networks outside of the office, she added.

https://www.cbc.ca/news/politics/online-hacking-phishing-covid-19-coronavirus-1.5499725

Sur le même sujet

  • Peraton expands Calgary operations to advance Canada defence program support

    25 septembre 2018 | Local, Aérospatial

    Peraton expands Calgary operations to advance Canada defence program support

    As a leading provider of high value logistics and support to Canadian defence for more than 35 years, Peraton recently completed its Calgary facility operations expansion and modernization. The new facility will enable broader support of Canada's CF-188 fighter fleet and position the company for future growth on fighter platforms and programs. Peraton's Calgary facility, at 76,000-plus square feet, now with an engineering lab for operational design and development, is a “one-stop-shop” for integrated logistics support. The site provides full life-cycle supply chain management for the largest allocation of government-owned materiel in Canada. “With our proven record of efficiency, having reduced costs for the CF-188 fleet, we are well equipped and ready to scale to support Canada's future fighter program,” said Gus Bontzos, president, Defence and Electronic Warfare sector. “We are also proud partners in spurring enterprise development, with 60 per cent of our supplier base in Canada comprised primarily of small to medium sized businesses.” Peraton's investment is helping to propel Calgary's economic growth, sparking renewed growth in specialized high-tech jobs. With its development of a platform-agnostic, scalable sustainment model that can optimize program performance for any platform–air, land, or sea, the Peraton model represents the next generation of cooperative military advancement. https://www.skiesmag.com/press-releases/peraton-expands-calgary-operations-to-advance-canada-defence-program-support

  • Four staff working on modernizing military recruitment process but no timeline set for improvements

    21 septembre 2022 | Local, Autre défense

    Four staff working on modernizing military recruitment process but no timeline set for improvements

    The Canadian Forces does not yet have an idea when it wants improvements to be put in place, defence officials say.

  • Frigate design decision challenged in Federal Court, putting $60B program in limbo

    23 novembre 2018 | Local, Naval

    Frigate design decision challenged in Federal Court, putting $60B program in limbo

    Murray Brewster · CBC News Winning bid 'incapable of meeting three critical mandatory requirements,' says Alion Canada One of the losing bidders in the competition to design the navy's next generation of warships has asked the Federal Court to overturn the recent decision to award the contract to a group of companies led by Lockheed Martin Canada. Alion Science and Technology Corp. and its subsidiary, Alion Canada, asked for a judicial review on Friday — a challenge that could mean more delays to the $60 billion program. The company had pitched the Dutch-designed De Zeven Provinciën Air Defence and Command (LCF) frigate as their solution for the Canadian navy. It's asking the court to set aside an Oct. 19 decision to select Lockheed Martin Canada the preferred bidder and to prevent the federal government from entering into negotiations with the company, which has offered up the BAE Systems-designed Type 26 frigate. In their court filing, Alion officials argue that the winning bid was "incapable of meeting three critical mandatory requirements" of the design tender. Notably, they say the Type 26 cannot meet the mandatory speed requirements set out by the navy and that both Public Services and Procurement Canada and Irving Shipbuilding, the yard overseeing the construction, should have rejected the bid outright. Alion said it "submitted a fully-compliant and conforming bid at enormous expense" and argued it "has been denied the fair treatment (it was) owed." The court application also points out that the design tender was amended 88 times during the 22 months it was under consideration and that the changes "effectively diluted the [warship] requirements" and allowed the government and Irving to select "an unproven design platform." Rising cost estimates Over two years ago, the Liberal government said it wanted to select a "mature design" for the new frigates, rather than designing a warship from scratch. Former public works minister Judy Foote said it would be a faster, cheaper solution. Unlike its two competitors, the Type 26 has yet to enter service with the Royal Navy and competitors have privately knocked it as "paper ship." Navantia, a Spanish-based company, was the other failed bidder. It headed a team that included Saab and CEA Technologies and proposed the F-105 frigate design, a ship in service with the Spanish navy. The Liberal government plans to build 15 new warships and hoped to get construction underway in the early 2020s. The program, which has been beset with delays and rising cost estimates, is intended to replace the navy's aging Halifax-class frigates, the backbone of the nation's maritime fighting force. Federal procurement officials had hoped to nail down a complete design contract with Lockheed Martin by the winter. The court challenge now puts that timeline in doubt. It also has enormous implications for Irving, which has been concerned about a slowdown in warship production between the current Arctic Offshore Patrol Ship program and the frigate replacements, which are formally titled 'Canadian Surface Combatants'. No one at Public Works or Lockheed Martin was immediately available for comment on Wednesday. https://www.cbc.ca/news/politics/frigate-design-decision-challenged-in-federal-court-putting-60b-program-in-limbo-1.4915501

Toutes les nouvelles