• About
  • Advertise
  • Careers
  • Contact
Friday, March 31, 2023
No Result
View All Result
NEWSLETTER
Cyber360 News
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
No Result
View All Result
Cyber360 News
No Result
View All Result
Home Data Breach

NCR blocked Mint, Quickbooks after attackers take over, drain accounts

by Cyber360 News
November 11, 2019
in Data Breach
0
NCR blocked Mint, Quickbooks after attackers take over, drain accounts
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

For a short while starting late last
month NCR Corp. blocked Mint and QuickBooks from its Digital Insight banking
platform after cybercriminals used the financial data aggregators sites to take
over and tap consumer bank accounts.

Citing a chief security officer at a
credit union, KrebsOnSecurity
reported
that the attackers automated unauthorized logins occurring in
12-hour periods over a one-week period and accessing a new account every five
to ten minutes. The attackers often were able to get in with just a username
and password because Mint and QuickBooks didn’t adhere to multifactor
authentication.

“The weird part is sometimes the attackers are getting the multi-factor challenge, and sometimes they aren’t,” Krebs quoted the source as saying.

“Aggregator traffic is always sensitive because financial institutions have a large percentage of their clients using them legitimately,” said Robert Capps, vice president of market innovation at NuData Security.

“The complexity of the interconnected financial services industry is difficult for the average consumer to comprehend. This complexity provides avenues for attackers to exploit,” said Tim Erlin, vice president, product management and strategy at Tripwire. “A variety of services have grown organically from the more traditional banking system, and while security is often a top concern for each institution, the gaps between them can leave room for risk.”

But financial institutions can use the data gathered through those relationships and services to fighter cybercriminals. “The good news is that banks can leverage data from these aggregators to be able to flag fraudulent behavior,” said Capps. “These types of attacks are sophisticated, and banks need to leverage their security layers to find suspicious patterns.”

Calling the type of attack experienced by
NCR Corp. “highly sophisticated,” Capp said, “by looking at the details of the
attack as well as its behavior, banks can cut down threats without adding
friction to all their good customers by default.”

But Erlin noted that remediating breaches like the NCR incident often has its limitations. “When you have an incident to deal with, you can only take action on the systems where you have control,” he said. “It will be telling to see if this type of incident-driven access control is a recurring theme for the industry.”

Cyber360 News

Cyber360 News

Next Post
Two guilty pleas in Uber and Lynda.com hacking case

Two guilty pleas in Uber and Lynda.com hacking case

Recent Posts

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

October 6, 2021
Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

October 1, 2021
Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

October 1, 2021

Whats New in Kali Linux?

September 14, 2021

Kali Linux 2019.3 Release (CloudFlare, Kali-status, metapackages, Helper-Scripts & LXD)

September 14, 2021

Kali Linux 2021.3 Release (OpenSSL, Kali-Tools, Kali Live VM Support, Kali NetHunter Smartwatch)

September 14, 2021

Kali Linux 2018.4 Release

September 14, 2021

Kali Linux 1.0.5 and Software Defined Radio

September 14, 2021

Kali Tools Website Launched, 1.0.9 Release

September 14, 2021

Kali Linux Dojo at Black Hat Vegas 2016

September 14, 2021

Category

Site Links

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

About Us

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

© 2019 Cyber360 News - Powered by WebSensePro

No Result
View All Result
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us

© 2019 Cyber360 News - Powered by WebSensePro

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In