17 mars 2020 | Local, C4ISR, Sécurité

Online 'phishing' attacks expected to target housebound staffers as COVID-19 spreads

It's a 'huge opportunity' for online crime, one expert warns

The number of "phishing" attacks meant to steal the online credentials of public servants and corporate sector employees now housebound due to the COVID-19 pandemic is on the rise, one cyber security expert warns.

Many attempts are being made against employees who are working from home on virtual private works (VPNs). Cyber experts are still gathering data to establish a direct correlation between the pandemic crisis and the increase in malicious activity.

But Rafal Rohozinski, chief executive officer of the SecDev Group of Companies, said this pandemic moment — when large numbers of employees are at home and receiving instructions from their workplaces on how to connect to internal networks — offers online thieves a "huge opportunity."

Federal government and corporate sector systems were never designed to support a sudden, mass migration of employees from offices to their homes, he said.

"The opening that creates for those who want to wreak havoc through ransomware and malware is really, really significant," said Rohozinski. "And I don't think we're anywhere near prepared for that.

"What we're seeing is an increase in phishing being used as a means to get people's credentials."

U.S. Health Department attacked

The U.S. Health and Human Services Department's website was hit by a cyber attack over several hours on Sunday, an incident which involved overloading its servers with millions of hits.

Officials said the system was not penetrated, although media reports in Washington described it as an attempt to undermine the U.S. government's response to the coronavirus pandemic — and may have been the work of a foreign actor.

Rohozinski said that while the facts are not all in yet, his "professional guess" is that there's a link between the attack and the COVID-19 crisis.

Last week, Canada's top military commander warned that he'd seen recent indications the country's adversaries intend to exploit the uncertainty, confusion and fear generated by the pandemic.

Gen. Jonathan Vance, chief of the defence staff, was not specific about the potential threats — but experts say they could range from hacking to online disinformation campaigns aimed at discrediting the federal government's response.

Rohozinski said he's concerned about the federal government's technical capacity to support thousands of employees on private networks.

"Everybody's moving on to VPNs. Everybody," he said. "This is an enormous pinpoint and an enormous vulnerability."

Federal Digital Government Minister Joyce Murray's office was asked for a response Monday, but was unable to provide an immediate comment.

Many of the country's leading information technology companies are part of the Canadian Cyber Threat Exchange (CCTE), a nonprofit centre where companies can swap information and insights. A CCTE spokeswoman said the corporate sector is better prepared to face the challenges posed by the mass movement of employees to home networks.

Still, there is reason for concern.

"Given we are moving people to work from home now, companies need to ensure that the work from home environment is as safe as the corporate environment and that people are trained to notice these phishing campaigns, just like they were in the corporate environment," said Mary Jane Couldridge, director of business development at the CCTE.

"It's a matter of keeping our community aware of what is impacting Canada daily so we know how to react to it and prevent it from spreading — and not chase rainbows."

Most corporations have plans they'll activate now to cover the wholesale movement of employees to networks outside of the office, she added.

https://www.cbc.ca/news/politics/online-hacking-phishing-covid-19-coronavirus-1.5499725

Sur le même sujet

  • Ottawa launches lonfyig-awaited competition for purchase of armed military drones

    14 février 2022 | Local, Aérospatial

    Ottawa launches lonfyig-awaited competition for purchase of armed military drones

    The federal government has officially launched a competition for the purchase of armed drones after nearly two decades of delays and discussion around whether Canada should buy the controversial weapons. A formal request for proposals was released Friday to the two companies shortlisted to bid on the $5-billion contract, which could see the Canadian Armed Forces launch a fleet of unmanned aerial vehicles in the next few years. A formal contract is not expected for another year or two, while the first drone isn't scheduled for delivery until at least 2025, with the last to arrive in the early 2030s. The request does not say how many vehicles the government plans to buy, and instead leaves it up to the two companies to say how their bids will satisfy the military's needs while benefiting the Canadian economy. It does reveal the aircraft will be based at 14 Wing Greenwood in Nova Scotia and 19 Wing Comox in British Columbia, while the main control centre will be in the Ottawa area. Yellowknife is also identified as a forward operating location. The drone force will include around 240 air force members, with 55 in Greenwood, 25 in Comox and 160 in Ottawa. While delivery is still years away, the fact the military has reached even this point represents a major step forward after almost 20 years of work to identify and buy a fleet of UAVs to conduct surveillance over Canadian territory and support missions abroad. Aside from purchasing a small number of temporary, unarmed drones for the war in Afghanistan – all of which have since been retired – the military has never been able to make much progress on a permanent fleet. That was despite drones taking on an increasingly important role in militaries around the world. A report in the Royal Canadian Air Force Journal in late 2015 said 76 foreign militaries were using drones and another 50 were developing them. One major reason: no federal government had authorized adding drones as a permanent fixture within the military in the same vein as fighter-jet or helicopter squadrons until the Liberal government included them in its 2017 defence policy. The government and military say the unmanned aircraft will be used for surveillance and intelligence gathering as well as delivering pinpoint strikes from the air on enemy forces in places where the use of force has been approved. Some have previously criticized the decision to buy armed drones given concerns about their potential use in Canada and numerous reports of air strikes by other nations, particularly the United States and Russia, causing unintended damage and civilian casualties. The government has also said little about the scenarios in which force might be used, including whether drones could be deployed for assassinations. Officials have suggested they would be used in the same way as conventional weapons such as fighter jets and artillery. “While the (drones) will be a medium-altitude long-endurance system with a precision strike capability, it will only be armed when necessary for the assigned task,” the Defence Department said Friday. “At all times, employment of precision strike capability will adhere to the Law of Armed Conflict, as well as any other applicable domestic or international laws. Use of force will be applied following rules of engagement applicable to the CAF.”

  • Royal Canadian Navy to start process of replacing aging submarine fleet - National | Globalnews.ca

    15 juillet 2021 | Local, Naval

    Royal Canadian Navy to start process of replacing aging submarine fleet - National | Globalnews.ca

    A dedicated team is being created to start the process, which is sure to be the beginning of a controversial debate around the need for the vessels in the Canadian Navy.

  • Canadian Armed Forces continues 10-year long effort in Counter-Explosive capability building

    2 novembre 2023 | Local, Terrestre

    Canadian Armed Forces continues 10-year long effort in Counter-Explosive capability building

    Approximately 180 Canadian Armed Forces (CAF) members hosted nearly 150 members from partner nations for Exercise ARDENT DEFENDER, an international counter explosive exercise held at 5 Canadian Division Support Base Gagetown, New Brunswick, from October 20 to November 2, 2023.

Toutes les nouvelles