Story image

Voter databases available on the dark web - report

31 Oct 2018

Endpoint security service provider Carbon Black has announced the release of its Quarterly Incident Response Threat Report (QIRTR), aggregating key findings from incident response (IR) partner investigations during the last 90 days.

The QIRTR aggregates qualitative and quantitative input from 37 Carbon Black IR partners.

The report’s goal is to offer actionable intelligence for business and technology leaders, fueled by analysis of new threats, and insights on how to stop them.

This is Carbon Black’s second quarterly report since introducing the QIRTR in July.

Carbon Black chief cybersecurity officer Tom Kellermann, one of the report’s authors, says, “Our research found that today’s attackers are increasingly punitive, sophisticated and confident.”

“And because of the dark web, they have access to complex tools and compromised infrastructures, including voter databases. This allows attackers to exploit new security vulnerabilities and operate at a higher level of sophistication than before.”

Carbon Black researchers also found 20 different state voter databases available for purchase on the dark web, several from swing states.

Critical information in these offerings include voter IDs, full names, current / previous addresses, genders, phone numbers, and citizenship status, among other information.

According to the research, the dark web also offers hacking and influence campaigns targeting social media sites, as well as hackers for hire, who offer to target government entities for the purposes of database manipulation, economic/ corporate espionage, DDoS attacks and botnet rentals.

In conjunction with the report’s release, Carbon Black hosted its inaugural Incident Response Partner Advisory Council (IR Council) meeting in Chicago on October 30.

The IR Council provides the Carbon Black Incident Response partner community, which totals more than 100 partners, an opportunity to share knowledge and best practices with peers.

IR Council members include security thought leaders from Ankura, Critical Start, Crowe, Grant Thornton, HALOCK Security Labs, IBM, Kroll, Lifars, Nisos Group, NTT Security, Optiv, Rapid7, Sylint and Trustwave.

IoT and DDoS attacks: A match made in heaven
A10 Network’s Adrian Taylor uses findings from a number of reports to illustrate his point that advances in technology are facilitating cybercrime.
ForgeRock launches Sandbox-as-a-Service to facilitate compliance
The cloud-based testing environment for APIs enables banks to accelerate compliance with Open Banking and PSD2 deadlines.
Cloud application attacks in Q1 up by 65% - Proofpoint
Proofpoint found that the education sector was the most targeted of both brute-force and sophisticated phishing attempts.
Singapore firm to launch borderless open data sharing platform
Singapore-based Ocean Protocol, a decentralised data exchange that promotes data sharing, has revealed details of what could be the kickstart to a global and borderless data economy.
Huawei picks up accolades for software-defined camera ecosystem
"The company's software defined capabilities enable it to future-proof its camera ecosystem and greatly lower the total cost of ownership (TCO), as its single camera system is applicable to a variety of application use cases."
Barracuda expands MSP security offerings with RMM acquisition
Managed Workplace delivers an RMM platform with security tools and services, such as site security assessments, Office 365 account management, and integrated third-party antivirus.
Flashpoint: APAC companies must factor geopolitics in cyber strategies
The diverse geopolitical and economic interests of the states in the region play a significant role in driving and shaping cyber threat activity against entities operating in APAC.
Expert offers password tips to aid a stress-free sleep
For many cybersecurity professionals, the worries of the day often crawl into night-time routines - LogMeIn says better password practices can help.