How hackers are stealing ­company secrets

1 July 2014 Security Services & Risk Management, Information Security

Recent research carried out by information security firm MWR InfoSecurity, supported by CPNI (Centre for the Protection of National Infrastructure), has revealed current and new techniques being used by cyber criminals to steal sensitive information from companies. The papers also show what companies can do to protect themselves.

Amongst these techniques, researchers have found that it is possible to exfiltrate a large amount of information through a number of popular websites such as Facebook, Flickr, YouTube and LinkedIn.

Alex Fidgen, director at MWR InfoSecurity, which is one of the small number of companies certified under the CESG/CPNI Cyber Incident Response Scheme, said, “There are two disturbing facts that every major organisation needs to accept. First, that it certainly possesses commercially sensitive information, such as intellectual property, intended acquisitions or resource development plans, which – if it fell into the wrong hands – could prove deeply damaging to the future of the enterprise. And secondly, that a sophisticated cyber attack targeting that data is almost certain to succeed.

“Modern organisations have networks that are complex and large. However, they often have few security controls in place, meaning that attackers encounter few barriers to stop them and are able to sidestep or compromise the few controls they do encounter. Once inside the network, attackers will move between computers, hunting the information they seek and then exfiltrating that data back to themselves.”

MWR researcher and lead author of the whitepapers Dr David Chismon said: “As there are few restrictions, attackers typically transfer files the same way any technical user would do. Many use the connections they have set up for command and control. HTTP and HTTPS (web traffic) are highly common and the File Transfer Protocol (FTP) is often used as well.

“Others use emails, employing simple techniques like setting up an email forwarding rule for the target so any email they receive is copied to the attacker. Others are increasingly using cloud storage such as Google Drive and Microsoft OneDrive. Interestingly, attackers have been seen deploying tools to use cloud storage, but not using them as there are other options available to them.”

He added: “If organisations block access to websites to prevent attackers, they can use popular websites that are likely to be permitted as vectors to exfiltrate data. In an experiment we carried out it was possible to exfiltrate 1 TB of data via Flickr in 200 mb. It was also possible to exfiltrate 20 GB via YouTube in a single chunk, and smaller amounts via popular websites such as Facebook and Tumblr.

“Increasing use of mobile devices, remote working and VPNs (virtual private networks) will present new opportunities for attackers, who are using more covert methods to exfiltrate the data, such as hiding it as other data types.”

MWR extrapolated business and technology trends as well as techniques attackers are just beginning to use, and identified new methods that may be used to steal data in the future. Chismon said: “Attackers, who are often state sponsored, are already being seen using forensics tools and methods to both find information they otherwise wouldn’t and to better hide the data they are stealing. This is likely to become more common.

“Cloud storage and email services are likely to be the predominant method in the future. Connections are encrypted and the services will be used normally by employees, making it hard for investigators to find the malicious connections and it obscures the final destination of the data. As more organisations use cloud services for business functions and remote work, attackers can compromise passwords for these services and get the data directly from there rather than needing to obtain it from the organisation’s network.”

Modern networks are becoming increasingly complex, meaning that there will always be routes that an attacker can take to access sensitive data. In the whitepapers, MWR details what organisations can do to better protect themselves.

Chismon commented: “Sadly, there is no magic bullet that can prevent attackers from obtaining data. To stand the best chance of detecting and deterring advanced attackers, organisations need to force them through controlled routes. They then need to increase the number of actions attackers would have to take to access the data and finally, develop and hone their ability to detect suspicious actions or movements to effectively investigate alleged breaches.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

SA’s strained, loadshedding-prone grid faces cyberthreats
Power Management Information Security
South Africa’s energy sector, already battered by decades of underinvestment and loadshedding, faces another escalating crisis; a wave of cyberthreats that could turn disruptions into catastrophic failures. Attacks are already happening internationally.

Read more...
Almost 50% of companies choose to pay the ransom
News & Events Information Security
This year’s Sophos State of Ransomware 2025 report found that nearly 50% of companies paid the ransom to get their data back, the second-highest rate of ransom payment for ransom demands in six years.

Read more...
Risk management and compliance enforcement
Security Services & Risk Management
Having a risk management and compliance programme (RMCP) is not just a procedural formality; it is a legal requirement under Section 42 of the Financial Intelligence Centre Act (FICA).

Read more...
The dangers of poor-quality solar cables
Security Services & Risk Management Smart Home Automation
Reports indicate that one in six fires attended by South African firefighters is linked to substandard solar installations, often due to faulty wiring or incompatible components.

Read more...
Growing risks for employers
Security Services & Risk Management
With South Africa’s unemployment rate exceeding 32% and expected to rise beyond 33% this year, desperation is fuelling deception in the job market. Trust is no longer a given, it is a gamble.

Read more...
Chubbsafes celebrates 190 years
Gunnebo Safe Storage Africa News & Events Security Services & Risk Management
Chubbsafes marks its 190th anniversary in 2025 and as a highlight of the anniversary celebrations it is launching the Chubbsafes 1835, a limited edition 190th-anniversary collector’s safe.

Read more...
New law enforcement request portal
News & Events Security Services & Risk Management
inDrive launches law enforcement request portal in South Africa to support safety investigations. New portal allows authorised South African law enforcement officials to securely request user data related to safety incidents.

Read more...
Continuous AML risk monitoring
Access Control & Identity Management Security Services & Risk Management Financial (Industry)
AU10TIX, launched continuous risk monitoring as part of its advanced anti-money laundering (AML) solution, empowering businesses to detect behavioural anomalies and emerging threats as they arise.

Read more...
Back-up securely and restore in seconds
Betatrac Telematic Solutions Editor's Choice Information Security Infrastructure
Betatrac has a solution that enables companies to back-up up to 8 TB of data onto a device and restore it in 30 seconds in an emergency, called Rapid Access Data Recovery (RADR).

Read more...
Growing risks for employers
Security Services & Risk Management
With South Africa’s unemployment rate exceeding 32% and expected to rise beyond 33% this year, desperation is fuelling deception in the job market. Trust is no longer a given, it’s a gamble.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.