Rogue employees present significant financial and cybersecurity risks to organizations. Rapid7 threat researchers and penetration testers are actively observing how malicious actors exploit hiring pipelines to infiltrate businesses. This blog highlights real-world tactics, including:
- Insider Reconnaissance: Rogue applicants leveraging interviews to map office layouts, identify vulnerable devices, and even plant malware during site visits.
Read more…
Source: Rapid7
Related:
- New Zealand: Cyber attacks aimed at school websites surge
October 28, 2018
Schools are reporting an upsurge in cyber attacks, apparently from disgruntled students who are attacking school websites rather than pressing the fire alarm to disrupt classes. Network for Learning (N4L), a Crown company that provides internet services to 98 per cent of New Zealand schools, says six schools were targeted with “dozens of attacks” aimed at taking ...
- French police officer caught selling confidential police data on the dark web
October 3, 2018
A French police officer has been charged and arrested last week for selling confidential data on the dark web in exchange for Bitcoin. The officer worked for Direction Générale de la Sécurité Intérieure (DGSI, translated to General Directorate for Internal Security), a French intelligence agency charged with counter-espionage, counter-terrorism, countering cybercrime and surveillance of potentially threatening ...
- Health insurer Bupa fined £175k after staffer tried to sell customer data on dark web souk
September 28, 2018
International health insurance business Bupa has been fined £175,000 after a staffer tried to sell more than half a million customers’ personal information on the dark web. The miscreant was able to access Bupa’s CRM system SWAN, which holds records on 1.5 million people, generate and send bulk data reports on 547,000 Bupa Global customers to ...
- Ex-CIA employee charged with leaking ‘Vault 7’ hacking tools to Wikileaks
June 18, 2018
A 29-year-old former CIA computer programmer who was charged with possession of child pornography last year has now been charged with masterminding the largest leak of classified information in the agency’s history. Joshua Adam Schulte, who once created malware for both the CIA and NSA to break into adversaries computers, was indicted Monday by the Department of Justice on 13 ...
- IBM bans all removable storage, for all staff, everywhere
May 10, 2018
IBM has banned its staff from using removable storage devices. In an advisory to employees, IBM global chief Information security officer Shamla Naidoo said the company “is expanding the practice of prohibiting data transfer to all removable portable storage devices (eg: USB, SD card, flash drive).” The advisory stated some pockets of IBM have had this policy ...
- Company insiders behind 1 in 4 data breaches – study
April 10, 2018
The admins among you will be unsurprised to discover that, more than a quarter of the time, data breaches across the world originated between the chair and the keyboard of organisation “insiders”. And no, we don’t mean they clicked on a dodgy link… The latest edition of Verizon’s Data Breach Investigations Report (DBIR) found that 25 ...
