🧐 ProPicks AI October update is out now! See which stocks made the listPick Stocks with AI

Canadian miners, casinos hit by hacker eyeing new targets -FireEye

Published 2017-06-16, 08:00 a/m
© Reuters.  Canadian miners, casinos hit by hacker eyeing new targets -FireEye
TECK
-
DGC
-
GG
-
MNDT
-
BTC/USD
-

By Alastair Sharp

TORONTO, June 16 (Reuters) - The same hacker targeting Canadian casinos and mining companies for extortion since 2013 is planning more attacks, researchers at cyber security company FireEye Inc FEYE.O said in a report on Friday.

FireEye said it believes that a single hacker or hacking group that it dubbed FIN10 is behind the breaches due to similarities in method: how they broke into corporate systems, stealing gigabytes of sensitive data and demanding ransom paid in Bitcoin, and publicizing the stolen information by alerting bloggers.

While FireEye declined to identify victims by name, the methods described in their report echoed those used in attacks on Goldcorp G.TO , the world's third-biggest gold miner by market value, smaller operator Detour Gold DGC.TO , and the Casino Rama Resort.

FireEye said FIN10's degree of operational success makes more campaigns "highly probable" and that it had evidence suggesting the group had targeted additional victims.

FireEye said FIN10 used the moniker Angels_of_Truth at least once, claiming to attack in retaliation for Canadian sanctions against Russia. More often, it borrowed the name Tesla Team from a group of Serbian hacktivists.

FireEye believes FIN10 was flying 'false flags' with those names, with no backing from a nation-state or affiliation with organized criminals.

Angels_of_Truth was the name used by hackers who contacted a databreaches.net blogger between April and June 2015 claiming credit in Russian and English for the Detour intrusion.

The same blogger, alerted to a breach at Goldcorp in April 2016, published details on the Daily Dot website before Goldcorp acknowledged the compromise. L2N17V25A

The Vancouver-based miner has since modified its IT processes, increased network security protocols, and worked to educate its staff about cyber risks, a spokeswoman said.

After that breach, a mining industry group formed a network to share information on cyber threats. At least six members, including Teck Resources Ltd TECKb.TO , will take the project live next month.

FIN10 is still in contact with some victims and more targets may "become aware of the threat in the coming weeks or months," said Charles Carmakal, vice president at FireEye's Mandiant unit.

Detour Gold did not respond to requests for comment. Nor did Casino Rama, which said in November that sensitive customer, employee and vendor data had been stolen. Some was reportedly later posted online, and they now face a class action lawsuit over the breach.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.