Tuesday, October 20, 2015

Crédit Agricole pays $787 million to resolve U.S. sanctions offenses

Oct202015

Crédit Agricole pays $787 million to resolve U.S. sanctions offenses

French bank Crédit Agricole will pay $787 million and hire an independent monitor after violating U.S. sanctions against Sudan, Iran, Myanmar, and Cuba between 2003 and 2008.
The bank will also fire a managing director involved in the violations of U.S. federal law and New York banking law.
Most other employees implicated in the offenses have already left the bank, the New York State Department of Financial Services said Tuesday.
The $787.3 million Crédit Agricole will pay in total includes $385 million to the New York State Department of Financial Services, $90.3 million to the Federal Reserve, $156 million to the Manhattan District Attorney's Office, and $156 million to the U.S. Attorney's Office for the District of Columbia.
A $330 million penalty imposed by the U.S. Department of the Treasury's Office of Foreign Assets Control will be "deemed satisfied" by amounts Crédit Agricole is paying the other agencies.
From at least 2003 to 2008, Crédit Agricole processed more than $32 billion in U.S. dollar payments through its New York branch from its branches in Paris, London, Singapore, Geneva, Hong Kong, and the Arabian Gulf, on behalf of Sudanese, Iranian, Burmese, and Cuban entities.
The bank agreed to hide its clients' identities on transactions through New York that violated U.S. sanctions.
One client described the crisis in the Darfur region of Sudan as "an exaggeration in the media." The bank processed more than 4,000 transactions in violation of U.S. economic sanctions against Sudan.
Crédit Agricole's Geneva employees were encouraged to complete illegal U.S. dollar transactions using a method fabricated by the bank's anti-money laundering committee known internally as the "Sudanese U-turn exception."
U.S. law didn't recognize the "Sudanese U-turn exception." But with no legal basis, the bank's AML committee authorized its use.
Crédit Agricole also made sure Iranian transactions routed through New York didn't mention Iran on the instructions.
The New York regulator said Tuesday,
Compliance staff in the Geneva Subsidiary's Office of the General Secretariat published and disseminated a policy in 2006 entitled, Compliance Embargos, which listed for employees the following non-transparent steps to be taken to effect Iranian-related U.S. dollar transactions: "Transfer instruction (MT 202) sent to Bank A's U.S. correspondent (Bank), WITH NO MENTION OF IRAN … no reference to Iran is made during this [MT 202 coverpayment] transaction."
Similar instructions not to mention Iran in transactions routed through New York went to the bank's head office in Paris, the London branch, and the Geneva subsidiary.
In its resolution Tuesday, Crédit Agricole entered into a deferred prosecution agreement with the U.S. Attorney’s Office for the District of Columbia for violations of the International Emergency Economic Powers Act and the Trading With the Enemy Act.
In May this year, another French bank, BNP Paribas S.A., paid $9 billion after pleading guilty to violating U.S. sanctions against Sudan, Iran, and Cuba.
*     *     *
The New York DFS consent order against Crédit Agricole is here (pdf).
OFAC's settlement agreement with Crédit Agricole is here (pdf).
The Federal Reserve's order against Crédit Agricole is here (pdf).
The DOJ's release is here.
________
Richard L. Cassin is the publisher and editor of the FCPA Blog. He can be contacted here.
- See more at: http://www.fcpablog.com/blog/2015/10/20/credit-agricole-pays-787-million-to-resolve-us-sanctions-off.html#sthash.QnXU1QQb.dpuf

How NSA successfully Broke Trillions of Encrypted Connections


nsa-crack-encryption
Yes, it seems like the mystery has been solved.

We are aware of the United States National Security Agency (NSA) powers to break almost unbreakable encryption used on the Internet and intercept nearly Trillions of Internet connections – thanks to the revelations made by whistleblower Edward Snowden in 2013.

However, what we are not aware of is exactly how did the NSA apparently intercept VPN connections, and decrypt SSH and HTTPS, allowing the agency to read hundreds of Millions of personal, private emails from persons around the globe.
Now, computer scientists Alex Halderman and Nadia Heninger have presented a paper at the ACM Conference on Computer and Communications Security that advances the most plausible theory as to how the NSA broke some of the most widespread encryption used on the Internet.
 

According to the paper, the NSA has exploited common implementations of the Diffie-Hellman key exchange algorithm – a common means of exchanging cryptographic keys over untrusted channels – to decrypt a large number of HTTPS, SSH, and VPN connections.

Diffie-Hellman – the encryption used for HTTPS, SSH, and VPNs – helps users communicate by swapping cryptographic keys and running them through an algorithm that nobody else knows except the sender and receiver.

Sunday, October 18, 2015

Healthcare providers must boost cyber defenses: Accenture

Healthcare providers must boost cyber defenses: Accenture




Healtchare providers need to shore up their defenses.
Healtchare providers need to shore up their defenses.




The continued digitization of the nation's healthcare system will place $305 billion worth of personal and medical information online and squarely in the crosshairs of cybercriminals in the next five years, according to a report by Accenture.
With this enormous target dangling in front of cybercriminals, Accenture said healthcare providers must boost their online defenses to protect customer data.
Accenture estimates that in the next five years one in 13 patients, or 25 million, will have their personal information stolen due to a data breach at their healthcare provider. Six million of these people will subsequently become medical identity theft victims, while another 4 million will end up paying out of pocket expenses to the tune of $65 billion due to the ID theft.
In many cases the victims may end up paying extra without realizing. One crime brought up in the report has criminals using stolen data to charge a victim's insurance company, and if the victim is not careful they could be paying for services they did not use.
“What most healthcare providers don't recognize is that as a result of cyber attacks on medical information, many patients will suffer personal financial loss. In contrast to credit card identity theft, where the card provider generally has a legal responsibility for account holders' losses above $50, victims of medical identity theft often have no automatic right to recover their losses,” the report stated.
Accenture recommended that healthcare providers opt for an active defense to protect the data. This includes developing an understanding of their adversaries, becoming more agile and thus able to reach customers faster by using cloud services, and establishing an end-to-end enterprise-level security program.

Senator presses Experian for details on breach

Senator presses Experian for details on breach


A high-ranking member of the Senate Banking Committee beseeched Experian to cough up additional details about the data breach that compromised the information of 15 million T-Mobile customers.
A high-ranking member of the Senate Banking Committee beseeched Experian to cough up additional details about the data breach that compromised the information of 15 million T-Mobile customers.




A high-ranking member of the Senate Banking Committee beseeched Experian to cough up additional details about the data breach that potentially compromised the information of 15 million T-Mobile customers.
Noting in a letter to Experian that “virtually no consumer can apply for credit without entering your system,” Sen. Sherrod Brown (D-Ohio), the committee's top-ranking Democrat, called for the credit agency to explain more fully how the breach went down and what steps it was taking to thwart future breaches.
Brown noted in the letter, which U.S. News & World Report said was obtained by the Associated Press, that "protection of this information is of the utmost importance, especially because the scope of the information is vast.”
T-Mobile's reputation has taken a hit after the breach, which occurred between Sept. 1, 2013, and Sept. 16, 2015, with hackers obtaining unauthorized access to customers' names, birth dates, addresses and social security numbers,

Payment card breach at Peppermill Resort Spa Casino in Reno

Payment card breach at Peppermill Resort Spa Casino in Reno




An undisclosed number of individuals are being notified that an attack may have compromised credit and debit cards used between October 2014 and February 2015 at the front desk of the Reno, Nev.-based Peppermill Resort Spa Casino.
How many victims? Undisclosed.
What type of personal information? Cardholder names, card numbers, expiration dates, and credit card security codes.
What happened? An attack may have compromised payment cards used at the Peppermill's front desk.
What was the response? New policies and procedures aimed at preventing future security incidents have been implemented. Affected individuals are being notified.
Details: Peppermill became aware of the incident in late April, and notification was delayed due to an ongoing law enforcement investigation. Payment cards may have been affected if used at the Peppermill front desk between Oct. 12, 2014, and Feb. 16.
Quote: “This security incident relates to the unauthorized and illegal acquisition, by criminal hackers, of certain kinds of credit and debit cards used at Peppermill's front desk,” a notification letter said.
Source: oag.ca.gov, “Breach Letter,” Oct. 5, 2015.

0

Laptop theft affects thousands of OU Medicine patients


Roughly 9,300 individuals are being notified that a laptop containing personal information was stolen from a physician who formerly worked for the University of Oklahoma Department of Urology.

How many victims? About 9,300.
What type of personal information? Names, diagnoses and treatment codes and dates, dates of birth or ages, brief descriptions of urological medical treatments or procedures, medical record numbers and treating physician names.
What happened? A laptop containing the personal information was stolen from a physician who formerly worked for the University of Oklahoma Department of Urology.
What was the response? Steps are being taken to prevent similar incidents from occurring, and employees are being given additional training on the importance of securing patient information. All affected individuals are being notified, and offered a free year of credit monitoring services.
Details: The theft occurred during the overnight hours of July 16-17, and the university was made aware of the incident on or about Aug. 14. The University of Oklahoma determined on or about Sept. 18 that the former physician and his current employer had not notified university patients who may have been affected. The Department of Urology was not aware that the former physician had taken patient information when leaving. The personal information was in a database spreadsheet stored on the laptop, which was password protected, but not encrypted. The information related to pediatric urology procedures occurring between 1996 and 2009.
Quote: “The physician is not certain that patient information was on the laptop, but the university wanted to notify patients of this incident and assure them that this matter is being taken seriously,” a notification said.
Source: oumedicine.com, “Notice to Certain Pediatric Urology Patients,” Oct. 9, 2015.

Friday, October 16, 2015

Hacking group stole credit card data of 150K casino customers

Hacking group stole credit card data of 150K casino customers




The personal information of 150,000 customers of an as-yet-unnamed casino was compromised following an incursion by the "Fin5" hacking group.
The personal information of 150,000 customers of an as-yet-unnamed casino was compromised following an incursion by the "Fin5" hacking group.
The personal information of 150,000 customers of an as-yet-unnamed casino was compromised following an incursion by the "Fin5" hacking group, according to The Register.
Barry Vengerik and Emmanual Jean-Georges of FireEye's Mandiant team determined that the hackers, already known for their use of “RawPOS” malware to siphon data from PoS devices, had been in the casino's system for a year. They added that the network lacked basic protections, such as a firewall and logging capabilities.
Vengerik said the gang attacks using stolen credentials, thereby avoiding an initial chance at detection. With a backdoor named Tornhull and a VPN called Flipside, the perpetrators then target Active Directory to gain further credentials.
The incursion illustrates how enterprises should safeguard any egress that third-parties have to corporate networks, Vengerik said.
The casino has since updated its security posture to include two-factor authentication, application whitelisting and more logging.


http://www.scmagazine.com/hacking-group-stole-credit-card-data-of-150k-casino-customers/article/446251/#