Malwarebytes, which discovered the activity, said it’s “unique in its way to fingerprint users and distribute time sensitive payloads.”
The attack singles out users searching for Notepad++ and PDF converters to
Massachusetts Standards for the Protection of Personal Information of Massachusetts Residents.
Created by Massachusetts to ensure the confidentiality and security of customer information. It applies to all persons who own or license personal information about a resident of Massachusetts.
What it means for you:
Organizations must anticipate threats to protect against malicious actors obtaining protected information. Unauthorized access to protected information or the use of such information should be prevented to avoid harm or inconvenience the consumer.
Why is it important to you:
Failure to comply may result in legal penalties as it is a mandate. Complying also demonstrates you commitment to protecting customer data to your customers. Breaches can damage your companies reputation and trust, implementation helps you reduce the risk of a breach. These proactive measures also prevent substantial harm to consumers.
What you need to do:
1. Create a COMPREHENSIVE Written Information Security Plan (WISP).
2. Make sure it applies to all protected data.
3. Include administrative, technical and physical safeguards (Security in Layers).
4. Designate an Information Security Manager (ISM), congrats, this is probably you.
5. Know the risks associated to paper records.
6. Regularly audit the WISP, actually do this.
7. Limit the data you collect to the data you need wherever possible.
8. Store the records for the proper time.
9. Ensure any data you get rid of is properly disposed of and destroyed.
10. Properly terminate the access of terminated employees.
11. Ensure third-party service providers with any data access are properly vetted.
12. Ensure any third-party service providers are contractually required to protect the protected data.
13. As always, trust then verify.
What else should I know:
Compliance with 201 CMR 17.00 is essential to protect personal information and avoid legal consequences. Organizations should prioritize security measures to prevent breaches and demonstrate due diligence.
There are many different compliances and regulations happening in the United States. Some have been federal mandates but most have been state level. I expect this to be wide spread and happen more often as more attacks on personal data are happening year over year.
Creating a great and effective Incident Response plan is very critical. There are many reasons why people struggle to get one properly implemented despite a lot of different materials out there.
Challenges:
PICERL Incident Response Framework
PICERL is a well-structured framework for incident response that guides organizations through the process of handling security incidents.
PREPARE
Fail to Prepare, Prepare to Fail. When not actively responding to an incident, you are in this phase. Strive to get better with continuous improvement and attack surface reduction. System hardening, vulnerability management, patching, monitoring, documentation, training and practice are some things you should focus on.
IDENTIFY
Something has happened, act quickly and accurately to assess the situation and properly determine if it really is in incident. Make sure to categorize the incident and prioritize the incident based on severity, risk and impact. Make sure to escalate if needed to ensure the proper incident responders are working any confirmed incidents.
CONTAIN
The goal here is to stop the attack from spreading. Do not rush into this to ensure there are no holes in your containment. You need to prevent things from getting worse by being decisive with your actions.
ERADICATE
Get the attacker completely out and keep them out in the future. This should be the more permanent fix that happens after the threat has been contained. Complete any hardening, patching and additional configuration required. Make sure to continue monitoring.
RECOVER
Restore affected systems back to their previous state with additional measures in place to ensure the incident or a similar incident cannot happen again. Test monitor and validate your systems as they are restored. Get things back to normal.
LESSONS LEARNED
Document and Learn. What happened in the incident? How did the incident happen? How was the incident dealt with? What went well with the incident response? What went bad with the incident response? What needs to be changed in the incident response plan?
Stop reading this, go plan your Incident Response!
