13 ms·
Checkout.com hacked, refuses ransom payment, donates to security labs
- junaru 11mo ago[flagged]
- worthless-trash 11mo agoI believe you may be misusing the term gaslighting.
- deleted 11mo ago[deleted]
- junaru 11mo agoTo me this looks like getting hacked, donating to some public non-profit, deduct it via taxes (essentially spending nothing) and spin it online as a positive.
- laylower 11mo agoEven if it were, it'd be much more than anything others that got hacked have been doing..
- ritzaco 11mo agoI've met a few people who genuinely believe that 'tax deductible' equates to 'essentially spending nothing' or somehow equate that the amount you donate would be an amount you would otherwise give to the Government in taxes so from your perspective it doesn't change anything. This is definitely not the case. If you make $100 profit and you would have had to pay 20% corporate tax, then you pay $20 in taxes, you'd be left with $80 to buy chocolate or whatever you want. If you donate $20 and deduct it from your profit, then your profit is now calculated at $80. So you pay $16 in taxes. So you saved $4 but spent $20, so you're $16 dollars down and now you only have $64 for chocolate, so not 'essentially nothing'.
- tobyhinloopen 11mo agoWhat if I buy chocolate as a corporate gift to my clients?! /jk
- retsibsi 11mo ago> deduct it via taxes (essentially spending nothing) Unless you're positing some very specific, unusual situation, this isn't how tax deductibility works. The dollar amount of a tax deductible donation is subtracted from your taxable income, not from your tax bill. So you're getting a discount on the donation equal to your marginal tax rate.
- tobyhinloopen 11mo ago> deduct it via taxes (essentially spending nothing) That's not how tax deduction works.
- saberience 11mo agoThat’s not how tax deductions work because a tax deduction doesn’t give you the full amount of your donation back it only reduces your taxable income, not your tax bill dollar-for-dollar. Example: You earn $100,000. You donate $10,000 to a qualifying charity. You can now deduct that $10,000, i.e. you’ll be taxed as if you earned $90,000, not $100,000. If your marginal tax rate is 30%, you’ll save 30% of $10,000 = $3,000 in taxes. So you’re still out $7,000 in real money.
- yazmeya 11mo agoThough if that 100K to 90K move had actually changed your tax bracket, you'd stand to maybe save a bit more.
- ben-schaaf 11mo agoIt changes nothing. If you get taxes 20% til 90k and 30% above that, then donating 10k still saves you 3k in taxes, you're still out 7k and you're still paying 18k in taxes on the 90k.
- Cyclone_ 11mo agoIt's not gaslighting. They were transparent enough to own their mistake. The donation isn't really the main story.
- tobyhinloopen 11mo agoSomething being tax deductible doesn't mean it is free. It still costs money, you just don't pay taxes over that money.
- misiek08 11mo agoThis one doesn't change that much like others said, but it is still burning money. Universities and their projects waste a lot of money - from buying hardware via complicated processes to projects wasting millions of USD (in cases I know it is EUR). Sponsored by companies like Samsung or Siemens, not releasing anything useful for years and still extending projects for "further research" :( It's their money in this case so they can burn it any way they want and great to see they didn't support script kiddies here (assuming it was some leftover files on forgotten object storage bucket, sadly unencrypted or with keys available nearby).
- squigz 11mo agoLots of companies waste money too. I'd rather see universities spend it on research and studies than companies developing useless products and shutting down after a year.
- blitzar 11mo agoJerry, all these big companies, they write off everything.
- throwaway2037 11mo agoI love this part (no trolling from me): > We are sorry. We regret that this incident has caused worry for our partners and people. We have begun the process to identify and contact those impacted and are working closely with law enforcement and the relevant regulators. We are fully committed to maintaining your trust. I know there will by a bunch of cynics who say that an LLM or a PR crisis team wrote this post... but if they did, hats off. It is powerful and moving. This guys really falls on his sword / takes it on the chin.
- M4v3R 11mo agoWords are cheap, but "We are sorry." is a surprisingly rare thing for a company to say (they will usually sugarcoat it, shift blame, add qualifiers, use weasel words, etc.), so it's refreshing to hear that.
- sunaookami 11mo agoThis is a classic example of a fake apology: "We regret that this incident has caused worry for our partners and people" they are not really "sorry" that data was stolen but only "regret" that their partners are worried. No word on how they will prevent this in the future and how it even happened. Instead it gets downplayed ("legacy third-party","less than 25% were affected" (which is a huge number), no word on what data exactly).
- koliber 11mo agoHow would the apology need to be worded so that it does not get interpreted as a fake apology? In terms of "downplaying" it seems like they are pretty concrete in sharing the blast radius. If less than 25% of users were affected, how else should they phrase this? They do say that this was data used for onboarding merchants that was on a system that was used in the past and is no longer used. I am as annoyed by companies sugar coating responses, but here the response sounds refreshingly concrete and more genuine than most.
- 11mo ago
- lexlambda 11mo agoThe donation is more or less virtue signaling rather than actual insight. The problem can not be helped by research research against cybercrime. Proper practices for protections are well established and known, they just need to be implemented. The amount donated should've rather be invested into better protections / hiring a person responsible in the company. (Context: The hack happened on a not properly decomissioned legacy system.)
- varispeed 11mo agoThere is not much to research. If companies want security, they should pay for security.
- dspillett 11mo ago> If companies want security, they should pay for security. Or just properly follow best-practise, and their own procedures, internally.⁰ That was the failing here, which in an unusual act of honesty they are taking responsibility for in this matter. -------- [0] That might be considered paying for security, indirectly, as it means having the resources available to make sure these things are done, and tracked so it can be proven they are done making slips difficult to happen and easy to track & hopefully rectify when they inevitably still do.
- rollcat 11mo agoSecurity is an arms race. Don't expect a leap; do your part to stay ahead.
- walletdrainer 11mo agoIt is virtue signaling, especially considering the fact that doing the hard to swallow thing of paying the ransom would probably be the best outcome from a customer perspective. Yes there are negative externalities in funding ransomware operations, not paying is still much more likely to hurt your customers than paying.
- saberience 11mo ago
- pm2222 11mo agoCould this be aws s3?
- dave1999x 11mo agoyeh, I am skeptical about "third party"
- thedougd 11mo agoI’m thinking a SFTP or file sharing gateway. Think MoveIT, GoAnywhere, ShareFile, etc. IMO, these aren’t safe to use anymore.
- saberience 11mo agoI was guessing it's a OneDrive, Google Drive, DropBox or something. Probably someone was phished and they still had access to an old shared drive which still had this data. Total guess but reading between the lines it could be something like this.
- prodigycorp 11mo agoIf i was a customer id be pissed off, but this is as good as a response you can have to an incident like this. - timely response - initial disclosure by company and not third party - actual expression of shame and remorse - a decent explanation of target/scope i could imagine being cyclical about the statement, but look at other companies who have gotten breached in the past. very few of them do well on all points
- walletdrainer 11mo ago> as good as a response you can have to an incident like this. From customer perspective “in an effort to reduce the likelihood of this data becoming widely available, we’ve paid the ransom” is probably better, even if some people will not like it. Also to really be transparent it’d be good to post a detailed postmortem along with audit results detailing other problems they (most likely) discovered.
- croemer 11mo agoDepends. Not paying ransom decreases the likelihood of being attacked in the future.
- walletdrainer 11mo agoProbably not that significantly, these are primarily crimes of opportunity. An attacker isn’t likely to do much research on the company until they already have access, and that point they might as well proceed (especially since getting hit a second time would be doubly awkward for the company, presumably dramatically increasing the chances of payment) And selling the data from companies like Checkout.com is generally still worth a decent amount, even if nowhere close to the bigger ransom payments.
- jacquesm 11mo agoNo, that would not help me as a customer. Because I would never believe that that party would keep their word, besides, it can't be verified. You'll have that shadow hanging around for ever. The good thing is that those assholes now have less budget to go after the next party. The herd is safe from wolves by standing together, not by trying to see which of their number should be sacrificed next.
- dmoreno 11mo agoWhen they say "The episode occurred when threat actors gained access to this third party legacy system which was not decommissioned properly. " for me it sounds like a not properly wiped disk that got into the the bad guys hands. It would be interesting to know more to be prepared for proper decommissioning of hardware.
- actionfromafar 11mo agoOr a cloud server which was never turned off.
- nektro 11mo agosounds like an S3 bucket that wasn't deleted
- arbll 11mo ago> The attackers gained access to a legacy, third-party cloud file storage system. I think the answer is ok but the "third-party" bit reads like trying to deflect part of the blame on the cloud storage provider.
- zwnow 11mo agoThe whole codebase & tools at whatever company I ever worked at was using 99% legacy stuff. Its wild... Often times it would have been easier to rebuild the whole project over trying to upgrade 5-6 year old dependencies. Ultimately the companies do not care about these kinda incidents. They say sorry, everyone laughs at them for a week and then after its business as usual, with that one thing fixed and still rolling legacy stuff for everything else.
- weird-eye-issue 11mo ago> Often times it would have been easier to rebuild the whole project Sure buddy, sure
- zwnow 11mo agoI inherited a few codebases as solo dev and I am confident in my abilities to refactor each of them in 1-2 months without issues. I can imagine that in a team that might be harder, but these are glorified todo apps. I am well aware that complete rebuilds rarely work out.
- mrguyorama 11mo agoThe company that bought mine spent two years trying to have Team A rewrite a part of our critical service as a separate service to make it more scalable and robust and to enable it to do more. They wanted to do stupid things like "Lets use GRPC because google does!" and "Django is slow" and "database access is slow (but we've added like six completely new database lookups per request for uh reasons)" They failed so damn bad and it's hilariously bad and I feel awful for the somewhat competent coworker who was stuck on that team and dealt with how awful it was. Then we fired most of that team like 3 times because of how value negative they have been. Then my coworker and I rebuilt it in java in 2 months. It is 100x faster, has almost no bugs, accidentally avoided tons of data management bugs that plague the python version (because java can't have those problems the way we wrote it) and I built us tooling to achieve bug for bug compatibility (using trivial to patch out helpers), and it is trivially scalable but doesn't need to because it's so much faster and uses way less memory. If the people in charge of a project are fucking incompetent yeah nothing good will ever happen, but if you have even semi-competent people under reasonable management (neither of us are even close to rockstars) and the system you are trying to rewrite has obvious known flaws, plenty of time you will build a better system.
- nashashmi 11mo agoSometimes cyber insurance will come to the rescue. That’s why companies Don’t pay.
- saberience 11mo agoSo, I used to work in the fintech world and it looks to me like what was hacked was merchant KYB documents. I.e. when a merchant signs up for a PSP they have to provide various documentation about the business so the PSP can underwrite the risk of taking on this business. I.e. some PSPs won't deal with porn companies or travel companies or companies from certain regions etc. This sort of data is generally treated very differently to the actual PANs and payment information (which are highly encrypted using HSMs). So it's obviously shitty to get hacked, but if it was just KYB (or KYC) type information, it's not harming any individuals. A lot of KYB information is public (depending on country). Fair play on them for being open about this.
- globalise83 11mo agoIt's not just business data though - usually it will include ultimate beneficial owner and directors' passports, tax ID, etc. So there is a risk of identity theft there of potentially some very wealthy individuals.
- globalise83 11mo ago"The system was used for internal operational documents and merchant onboarding materials at that time" To me it seems most likely that this is data collected during the KYC process during onboarding, meaning company documents, director passport or ID card scans, those kind of things. So the risk here for at least a few more years until all identity documents have expired is identity theft possibilities (e.g. fraudsters registering their company with another PSP using the stolen documents and then processing fraudulent payments until they get shut down, or signing up for bank accounts using their info and tax id).
- saberience 11mo agoPassport or ID card scans would never be be stored alongside general KYB information, e.g. the standard forms PSPs use. If you read between the lines of the verbiage here, it looks like a general archived dropbox of stuff like PDF documents which the onboarding team used. Since GDPR etc, items like passports, driving license data etc, has been kept in far more secure areas that low-level staff (e.g. people doing merchant onboarding) won't have easy access to. I could be wrong but I would be fairly surprised if JPGs of passports were kept alongside docx files of merchant onboarding questionnaires.
- globalise83 11mo agodocx files of merchant onboarding questionnaires Why would merchants fill out docx files? They would submit an online form with their business, director and UBO details, that data would be stored in the Checkout.com merchants database, and any supporting documents like passport scans would be stored in a cloud storage system, just like the one that got hacked. If it was just some internal PDFs used by the onboarding team, probably they wouldn't make such a big announcement.
- bostik 11mo agoIf you are dealing with financial services (and payment provider most certainly would), you will be forced to interface with infuriating vendor vetting and onboarding questionnaire processes. The kinds that would make Franz Kafka blush, and CIA take notice for their enhanced interrogation techniques. The sheer amount of effectively useless bingo sheets with highly detailed business (and process) information boggles the mind. Some time ago I alluded to existence and proliferation of these questionnaires in another context: https://bostik.iki.fi/aivoituksia/random/crowdstrike-outage-was-inevitable.html https://bostik.iki.fi/aivoituksia/random/crowdstrike-outage-...
- ashanoko 11mo ago[dead]
- zara762 11mo ago[dead]
- lateforwork 11mo agoThis should be law. Any company that is hacked should be required by law to make a sizeable investment in a third-party security research company.
- yreg 11mo agoSecurity reasearch lab during the day day, ransomware org at night conspiracy coming soon.
- blitzar 11mo ago"Firefighter arson is a persistent phenomenon involving a very small minority of firefighters who are also active arsonists ... It has been reported that roughly 100 U.S. firefighters are convicted of arson each year."
- ishouldbework 11mo agoInteresting, that number is much higher than I would expect.
- squigz 11mo agoIt wouldn't require a conspiracy for these companies to 'invest' in security companies they have ties to. Throw in tax incentives and loopholes and whatnot and it turns out not to hurt the original company at all.
- walletdrainer 11mo agohttps://news.risky.biz/risky-bulletin-us-indicts-two-rogue-cybersecurity-employees-for-deploying-ransomware/ https://news.risky.biz/risky-bulletin-us-indicts-two-rogue-c... US indicts two rogue cybersecurity employees for ransomware attacks
- amelius 11mo agoIsn't it illegal in many countries to pay a ransom? (If not, why not?) (Imho, it would make sense if only the state can pay ransoms)
- vntok 11mo agoTypically, companies wouldn't really pay an actual ransom like unmarked bills stacked in a paper bag and thrown out from a bridge onto a passing barge. Instead, you would pay (exhorbitant) consulting fees to a foreign-based "offensive security" entity, and most of the time get some sort of security report that says if you'd simply plug this and that holes, your systems would now be reasonably safe.
- amelius 11mo ago> Typically, companies wouldn't really pay an actual ransom like unmarked bills stacked in a paper bag and thrown out from a bridge onto a passing barge. Yes, that's why cryptocurrencies are a gift from heaven for these hacker groups. Therefore, even if paying ransom money (somehow) must be legal, maybe it should be illegal to use crypto for it. You don't want to make it too easy to run this type of criminal business.
- walletdrainer 11mo agoCriminals are plenty capable of accepting bank transfers, many of the same people running ransomware now were operating banking bots for years and years and stealing hundreds of millions from US businesses with wire transfers before crypto even existed. You go on some Russian crime forum and find a plenty of people offering to process bank transfers like these for some percentage of the money. As these particular payments would be somewhat consensual, you wouldn’t even have to worry about the funds getting frozen on the way.
- walletdrainer 11mo ago>Instead, you would pay (exhorbitant) consulting fees to a foreign-based "offensive security" entity Lots of US based incident response companies handling ransomware payments, this isn’t the domain of some sketchy foreign offsec joints.
- dizhn 11mo agoGiving me MBA vibes. Will they close up shop and go when it's the remaining 75% of their infrastructure next time?
- nalekberov 11mo agoAt this point I think we all understand that we will never be able to trust any company in this world with our data. In most cases they can get away with "We are sorry" and "Trust me, bro" attitude.
- vntok 11mo ago> Checkout.com hacked, refuses ransom payment, donates to security labs This submission's edited title reads like the "target headline" from The Office (US): > Scranton Area Paper Company - Dunder Mifflin - Apologizes - to Valued Client - Some Companies - Still Know - How - Business - is - Done
- betimd 11mo agoI have checkout.me domain, and it is for sale. email me if you want to get it.
- system2 11mo agoHow much do you want for it?
- zetanor 11mo agoThey're "sorry", they want to be "transparent" and "accountable", they want your "trust", but not enough to publicly explain what happened or what kind of data got taken (is a full CRM backup from 6 years ago considered "legacy" "internal operational documents"?). There's not even a promise to produce more information about their mistake. > Jimmy, where did the cookies go? > Something that was on the counter is gone! I don't know how! It might not even be my fault! But I'm sorry! What kind of an apology is that? It's not. It's marketing for the public while they contact the "less than 25% of [their] current merchant base" whose (presumably sensitive) information was somehow in "internal operational documents". Oh but also took some of what they charge their customers and gave that (undisclosed?) sum away to a university. They must be really sorry.
- antonyh 11mo agoI don't think they meant OXCIS, that seems to be a centre for Islamic Studies https://en.wikipedia.org/wiki/Oxford_Centre_for_Islamic_Studies https://en.wikipedia.org/wiki/Oxford_Centre_for_Islamic_Stud... I can't quite work out who they donated to - it seems there are a number of Oxford Uni cybersec/infosec units. Any idea which one?
- saberience 11mo agoI guess it just means this: https://www.cybersecurity.ox.ac.uk/ https://www.cybersecurity.ox.ac.uk/ "Cyber Security Oxford is a community of researchers and experts working under the umbrella of the University of Oxford’s Academic Centre of Excellence in Cyber Security Research (ACE-CSR)."
- antonyh 11mo agoProbably, I'm not sure it's not https://gcscc.ox.ac.uk/ https://gcscc.ox.ac.uk/ I don't think it's https://www.infosec.ox.ac.uk/ https://www.infosec.ox.ac.uk/ There's also this AI security research lab, https://lasr.plexal.com/ https://lasr.plexal.com/ It looks like Oxford are quite busy in this space.
- joshmn 11mo agoIt’s notable that there were ShinyHunters members arrested by the FBI a few years ago. I was in prison with Sebastian Raoult, one of them. We talked quite a bit. The level of persistence these guys went through to phish at scale is astounding—which is how they gained most of their access. They’d otherwise look up API endpoints on GitHub and see if there were any leaked keys (he wasn’t fond of GitHub's automated scanner). https://www.justice.gov/usao-wdwa/pr/member-notorious-international-hacking-crew-sentenced-prison https://www.justice.gov/usao-wdwa/pr/member-notorious-intern...
- ants_everywhere 11mo ago> (he wasn’t fond of GitHub's automated scanner Do you mean they thought the scanner was effective and weren't fond of it because it disrupted their business? Or do you mean they had a low opinion of the scanner because it was ineffective?
- joshmn 11mo agoHe would complain that it disrupted their business, and that it doesn't catch all keys—it catches the big ones that he certainly found to be very valuable.
- rkozik1989 11mo agoGenerally speaking, humans are more often than not the weakest link the chain when it comes to cyber security, so the fact that most of their access comes from social engineering isn't the least bit surprising. They themselves are likely to some extent the victims of social engineering as well. After all who benefits from creating exploits for online games and getting children to become script kiddies? Its easier (and probably safer) to make money off of cyber crime if your role isn't committing the crimes yourself. It isn't illegal to create premium software that could in theory be use for crime if you don't market it that way.
- deleted 11mo ago[deleted]
- 11mo ago
- WhereIsTheTruth 11mo agoThey are downplaying the severity of the data theft, which most likely includes user identification documents, the most dangerous type of breach, since it directly enables identity theft Reading between the lines reveals the severity they're obfuscating, with contradictions: > This incident has not impacted our payment processing platform. The threat actors do not have, and never had, access to merchant funds or card numbers. > The system was used for internal operational documents and merchant onboarding materials at that time. > We have begun the process to identify and contact those impacted and are working closely with law enforcement and the relevant regulators They stress that "merchant funds or card numbers" weren't accessed, yet acknowledge contacting "impacted" users, this begs the question: how can users be meaningfully "impacted" by mere onboarding paperwork?
- thrdbndndn 11mo agoYeah, they keep repeating what wasn't accessed but never say what actually was.
- system2 11mo agoThey are pro at misdirection, that's for sure.
- another_twist 11mo agoI dont understand some of the cynicism in this thread. This is a bold move and I support. It is impossible to not have incidents like this and until theres a proper post mortem we wont really know how much of it can be attributed to carelessness. They could have just kept is hush hush but I appreciate that they came forward with it and also donated money to academia. The research will be open and everybody benefits.
- whimsicalism 11mo agoIt’s hacker news, people feel that cynicism elevates them in some way.
- system2 11mo agoCynicism? The post they published is blaming the 3rd party and "legacy" bs. They are talking about "credit cards are safe," but 25 god damn percent of their merchants' data have been leaked. This is messed u, and they play it cool by saying "we donated money because the issue wasn't o big deal". I read that posts as a professional deflection.
- begueradj 11mo agoIf everyone refuses to pay, such incidents would largely reduce.
- skeeter2020 11mo agoInteresting spin for a core infrastructure provider who deals with the most sensitive part of most businesses, tries to bury the lede of getting hacked with a tale of their virtuous refusal to pay a ransom; is this supposed to make them attractive or just have people skip the motivating events? Swing and a miss in my books.
- JohnMakin 11mo agoWhile a nice gesture, I'm not so certain that if I were one of their "less than 25%" of customers impacted that I'd be so pleased. Why not compensate them instead?
- whimsicalism 11mo agoBravo - I find this incredibly courageous and will consider being their customer in the future.
- system2 11mo agoWhat is courageous about having a crappy infrastructure and blaming a 3rd party with fancy words like "legacy"? They got hacked and leaked 25% of their merchants' very critical onboarding data. What do you find courageous about this?
- whimsicalism 11mo agoMost people pay ransom payments.
- system2 11mo agoWhat does it change, paying or not paying? The hackers already have the data.
- whimsicalism 11mo agoThe incentive structure
- yieldcrv 11mo ago> The threat actors do not have, and never had, access to merchant funds or card numbers. > The system was used for internal operational documents and merchant onboarding materials at that time. Ah so just all of your KYC for founders, key personnel, and the corporation to impersonate business accounts > We estimate that this would affect less than 25% of our current merchant base. Yikes, this affects 25% of their current merchant base.
- cindyllm 11mo ago[dead]
- amatecha 11mo ago"Checkout.com hacked" -> links to checkout.com lol
- tsoukase 11mo agoI wish they disclose the donated amount and if the target departments will help the company in any way in reverse.
- user3939382 11mo agoWhen you build a computing stack thats inside out and architecturally makes no sense you get fun stories like these.
- luna11 11mo ago[flagged]
- more_corn 11mo agoSomeone should make a bounty market for hunting and destroying ransomware organizations.