Showing posts with label Cyber Attack. Show all posts
Showing posts with label Cyber Attack. Show all posts
Thursday, June 13, 2019
Telegram traces cyber-attack during HK protests to China
BEIJING - Encrypted messaging service Telegram suffered a major cyber-attack that originated from China, the company's CEO said Thursday, linking it to the ongoing political unrest in Hong Kong.
Many protesters in the city have used Telegram to evade electronic surveillance and coordinate their demonstrations against a controversial Beijing-backed plan that would allow extraditions from the semi-autonomous territory to the mainland.
Demonstrations descended into violence Wednesday as police used tear gas and rubber bullets to disperse protesters who tried to storm the city's parliament -- the worst political crisis Hong Kong has seen since its 1997 handover from Britain to China.
Telegram announced Wednesday that it was suffering a "powerful" Distributed Denial of Service (DDoS) attack, which involves a hacker overwhelming a target's servers by making a massive number of junk requests.
It warned that users in many regions may face connection issues.
Pavel Durov, Telegram's CEO, said the junk requests came mostly from China.
"Historically, all state actor-sized DDoS (200-400 Gb/s of junk) we experienced coincided in time with protests in Hong Kong (coordinated on @telegram)," he tweeted.
"This case was not an exception."
Telegram later announced on Twitter that its service had stabilised. It also posted a series of tweets explaining the nature of the attack.
"Imagine that an army of lemmings just jumped the queue at McDonald's in front of you -– and each is ordering a whopper," it said, referring to the flagship product of Burger King.
"The server is busy telling the whopper lemmings they came to the wrong place -– but there are so many of them that the server can't even see you to try and take your order."
Evading surveillance
When asked about Durov's claim the attack originated from China, foreign ministry spokesman Geng Shuang said he was not aware of the incident.
"What I can tell you here is that China has always opposed any form of cyber-attacks. China is also a victim of cyber-attacks," Geng said at a regular press briefing in Beijing.
China's cyberspace administration did not immediately respond to AFP's request for comment.
Telegram was launched in 2013, and allows users to exchange encrypted text messages, photos and videos, and also create "channels" for as many as 200,000 people. It also supports encrypted voice calls.
The firm announced last year that it had crossed 200 million monthly active users.
Encrypted messaging apps like Telegram and WhatsApp are preferred around the world by a wide variety of people trying to avoid surveillance by authorities -- from Islamic State jihadists and drug dealers to human rights activists and journalists.
Governments in recent years have devoted significant resources to try and breach or bypass the security features of these apps, according to tech firms and researchers. Some states have outright banned them.
Hong Kong is not behind China's Great Firewall, which heavily restricts internet access in the mainland -- where Telegram is blocked.
The city's special status under its handover agreement allows freedoms unseen in mainland China, but many fear they are under threat as Beijing exerts increasing influence on Hong Kong.
The current protests were sparked by fears the proposed law would allow extraditions to China and leave people exposed to the mainland's politicized and opaque justice system.
source: news.abs-cbn.com
Friday, October 12, 2018
Facebook says hackers accessed data of 29 million users
Facebook said Friday that hackers accessed personal data of 29 million users in a breach at the world's leading social network disclosed late last month.
The company had originally said up to 50 million accounts were affected in a cyberattack that exploited a trio of software flaws to steal "access tokens" that enable people to automatically log back onto the platform.
"We now know that fewer people were impacted than we originally thought," Facebook vice president of product management Guy Rosen said in an online post.
The hackers -- whose identities are still a mystery -- accessed the names, phone numbers, and email addresses of 15 million users, he said.
For another 14 million people, the attack was potentially more damaging.
Cyberattackers accessed that data plus additional information including gender, religion, hometown, birth date, and places they had recently "checked in" to as visiting, according to Facebook.
No data was accessed in the accounts of the remaining one million people whose "access tokens" were stolen, according to Rosen.
The attack did not affect Facebook-owned Messenger, Messenger Kids, Instagram, WhatsApp, Oculus, Workplace, Pages, payments, third-party apps, or advertising or developer accounts, the company says.
- 'Vulnerability' in the code -
Facebook said engineers discovered a breach on September 25 and had it patched two days later.
That breach allegedly related to a "view as" feature -- described as a privacy tool to let users see how their profiles look to other people. That function has been disabled for the time being as a precaution.
"It's clear that attackers exploited a vulnerability in Facebook's code," said Rosen.
"We've fixed the vulnerability and informed law enforcement."
Facebook reset the 50 million accounts it thought could have been affected, meaning users will need to sign back in using passwords.
The breach was the latest privacy embarrassment for Facebook, which earlier this year acknowledged that tens of millions of users had their personal data hijacked by Cambridge Analytica, a political firm working for Donald Trump in 2016.
"We face constant attacks from people who want to take over accounts or steal information around the world," chief executive Mark Zuckerberg said on his own Facebook page when the breach was disclosed.
"While I'm glad we found this, fixed the vulnerability, and secured the accounts that may be at risk, the reality is we need to continue developing new tools to prevent this from happening in the first place."
Facebook said it took a precautionary step of resetting "access tokens" for another 40 million accounts which had accessed the "view as" function. Those users will need to log back in to Facebook.
source: news.abs-cbn.com
Sunday, September 23, 2018
Hackers target real estate deals, with devastating impact
WASHINGTON - James and Candace Butcher were ready to finalize the purchase of their dream retirement home, and at closing time wired $272,000 from their bank following instructions they received by email.
Within hours, the money had vanished.
Unbeknownst to the Colorado couple, the email account for the real estate settlement company had been hacked, and fraudsters had altered the wiring instruction to make off with the hefty sum representing a big chunk of the Butchers' life savings, according to a lawsuit filed in state court.
A report by the FBI's Internet Crime Complaint Center said the number of victims of email fraud involving real estate transactions rose 1,110 percent between 2015 to 2017 and losses rose nearly 2,200 percent.
Nearly 10,000 people reported being victims of this kind of fraud in 2017 with losses over $56 million, the FBI report said.
The Butchers, forced to move into their son's basement instead of their dream home, eventually reached a confidential settlement in a lawsuit against their real estate agent, bank and settlement company, according to their lawyer Ian Hicks.
The problem is growing as hackers take advantage of lax security in the chain of businesses involved in real estate and a potential for a large payoff.
"In these cases, the fraudster knows all of the particulars of the transaction, things that are completely confidential, things they should not know," said Hicks, who is involved in more than a dozen similar cases across the United States.
EMAIL INSECURITY
Numerous cases have been filed in courts around the country seeking restitution from various parties. One couple in the US capital Washington claimed to have lost $1.5 million in a similar fraud scheme.
Real estate is just one segment of what the FBI calls "business email compromise" fraud which has resulted in some $12 billion in losses over the past five years. But for home buyers, the fraud can be particularly catastrophic.
"In these cases, the loss can be devastating and life-altering," Hicks said.
Real estate transactions have become a lucrative target for hackers "because they handle a lot of money and because they have employees who are not the most technically savvy," said Sherrod DeGrippo, director of threat research for the security firm Proofpoint.
Additionally, hackers often do their homework and "sometimes they know more about the business than the employees do," she said.
Consumers may also be less cautious when they are feeling positive about a new home, making it easy to fall prey to scammers, DeGrippo said.
"These social engineering tactics rely on a heightened emotional state, and people can be in that state when it comes to purchase their dream home," she added.
DeGrippo said the schemes appear to originate from overseas, possibly from Russia or Africa, using a variety of techniques to stay ahead of law enforcement.
"They employ a lot of money 'mules,'" she said. "They move the cash from bank to bank to bank."
Banks have been working to counter what is seen as a growing fraud problem but are often unable to prevent scams stemming from hacked emails, said Paul Benda, senior vice president for risk and cybersecurity at the American Bankers Association.
"Banks have very strong controls in place," he said. "But when they are given wiring instructions from a customer they have a responsibility to send it where it was instructed."
Benda said that customers need to know a wire transfer is "just like cash" and may be impossible to recover, especially if it ends up overseas.
WHO'S TO BLAME?
Lawsuits from consumers often target real estate agents, attorneys, escrow agents, banks and settlement companies that prepare documents for deals.
"There are a lot of people involved, and (fraudsters) can hack into any one of these parties," said Finley Maxson, senior counsel at the National Association of Realtors.
"These emails have become much more sophisticated, they are much harder to catch."
Maxson said the Realtors and other associations are moving aggressively to educate all parties involved about the potential for fraud and the need for better security.
"We're telling people they should never give these (wiring) instructions by email," he said.
It may be difficult to establish liability, but Hicks said that "consumers are not going to be careless with their life savings" and that the real estate professionals have a responsibility to ensure the security of their systems, and to give customers adequate information.
The lawsuit filed by Hicks for the Butchers said that "the scam that befell the Butchers was well-known in the real estate industry and easily preventable."
Earlier this year, a Kansas court assigned 85 percent of the liability to a hacked real estate agent and awarded a home buyer defrauded by fake wiring instructions $167,129.
Hicks said that in these cases, "there is a lot of blame to go around," but argued that "unless companies have to pay money they won't do what's necessary to protect the consumer."
source: news.abs-cbn.com
Wednesday, August 22, 2018
Hackers target smartphones to mine cryptocurrencies
PARIS -- Has your smartphone suddenly slowed down, warmed up and the battery drained down for no apparent reason? If so, it may have been hijacked to mine cryptocurrencies.
This new type of cyberattack is called "cryptojacking" by security experts.
It "consists of entrapping an internet server, a personal computer or a smartphone to install malware to mine cryptocurrencies," said Gerome Billois, an expert at the IT service management company Wavestone.
Mining is basically the process of helping verify and process transactions in a given virtual currency. In exchange miners are now and then rewarded with some of the currency themselves.
Legitimate mining operations link thousands of processors together to increase the computing power available to earn cryptocurrencies.
Mining bitcoin, ethereum, monero and other cryptocurrencies may be very profitable, but it does require considerable investments and generates huge electricity bills.
But hackers have found a cheaper option: surreptitiously exploiting the processors in smartphones.
To lure victims, hackers turn to the digital world's equivalent of the Trojan horse subterfuge of Greek mythology: inside an innocuous-looking app or programhides a malicious one.
The popularity of games makes them attractive for hackers.
"Recently, we have discovered that a version of the popular game Bug Smasher, installed from Google Play between 1 and 5 million times, has been secretly mining the cryptocurrency monero on users' devices," said researchers at IT security firm ESET.
The phenomenon is apparently growing.
"More and more mobile applications hiding Trojan horses associated to a cryptocurrency mining programme have appeared on the platforms in the last 12 months," said David Emm, a security researcher at Kaspersky Lab, a leading supplier of computer security and anti-virus software.
"On mobiles the processing power available to criminals is less," but "there is a lot more of these devices, and therefore taking in total, they offer a greater potential," he added.
GOOGLE CLEANS HOUSE
But for smartphone owners, the mining is at best a nuisance, slowing down the operation of the phone and making it warm to the touch as the processor struggles to unlock cryptocurrency and accomplish other task.
At worst, it can damage the phone.
"On Android devices, the computational load can even lead to 'bloating' of the battery and thus to physical damage to, or destruction of, the device," said ESET.
However, "users are generally unaware" they have been cryptojacked, said Emm.
Cryptojacking affects mostly smartphones running Google's Android operating system.
Apple exercises more control over apps that can be installed on its phones, so hackers have targetted iPhones less.
But Google recently cleaned up its app store, Google Play, telling developers that it will no longer accept apps that mine cryptocurrencies on its platform.
CAT AND MOUSE GAME
"It is difficult to know which applications to block," said Pascal Le Digol, the country manager in France for US IT security firm WatchGuard, given that "there are new ones every day."
Moreover, as the miners try to "be as discreet as possible" the apps do not stand out immediately, he added.
There are steps to take to protect one's phone.
Besides installing an antivirus program, it is important to update Android phones to the latest version available, said online fraud expert Laurent Petroque at F5 Networks.
He also noted that "people who decide to download apps from non-official sources are at more risk of inadvertantly downloading a malicious app".
Defending against cyberattacks of all kinds is "a game of cat and mouse", said Le Digol at WatchGuard.
"You need to constantly adapt to the evolution of threats."
In this case he said "the mouse made a large leap", said Le Digol, adding cryptojacking could evolve to other forms in the future to include all types of connected objects.
source: news.abs-cbn.com
Tuesday, August 14, 2018
India's Cosmos Bank loses $13.5-M in cyber attack
MUMBAI - Cyber criminals hacked the systems of India's Cosmos Bank and siphoned off nearly 944 million rupees ($13.5 million) through simultaneous withdrawals across 28 countries over the weekend, the bank has told police.
The co-operative bank said unidentified hackers stole customer information through a malware attack on its automated teller machine (ATM) server, withdrawing 805 million rupees in 14,849 transactions in just over two hours on Aug. 11, mainly overseas.
Apart from the ATM withdrawals, the hackers transferred 139 million rupees to a Hong Kong-based company's account by issuing three unauthorised transactions over the SWIFT global payments network, the bank said in a police complaint, a copy of which was seen by Reuters.
SWIFT, whose messaging system is used to transfer trillions of dollars a day, said it did not comment on individual cases.
Cosmos Bank, based in the western city of Pune, said in a press statement that its main banking software receives debit card payment requests via a "switching system" but it was bypassed in the attack.
"During the malware attack, a proxy switch was created and all the fraudulent payment approvals were passed by the proxy switching system," the bank said.
The bank declined to reveal the countries, citing security risks.
Police said they were investigating the theft.
A police official, who declined to be named, said they had enlisted the help of experts to find out how authorised transactions were conducted simultaneously in various countries.
India's City Union Bank Ltd reported in February that it had suffered three "fraudulent remittances" of nearly $2 million that had been pushed through the SWIFT financial platform.
In 2016, unknown hackers stole more than $81 million from the Bangladesh central bank's account with the Federal Reserve Bank Of New York. Investigators have made little progress in the case.
"While there is growing awareness to regularly update an organisation's cyber preparedness and defence mechanisms, a large number of institutions wake up to this reality only post an incident which often leads to a loss of reputation and/or financial misappropriation," said Nikhil Bedi, a partner with Deloitte India.
($1 = 69.8950 Indian rupees) (Reporting by Rajendra Jadhav; Editing by Adrian Croft)
source: news.abs-cbn.com
Wednesday, April 18, 2018
Microsoft, Facebook vow not to aid gov't cyber attacks
SAN FRANCISCO - Microsoft, Facebook and more than 30 other global technology companies on Tuesday announced a joint pledge not to assist any government in offensive cyber attacks.
The Cybersecurity Tech Accord, which vows to protect all customers from attacks regardless of geopolitical or criminal motive, follows a year that witnessed an unprecedented level of destructive cyber attacks, including the global WannaCry worm and the devastating NotPetya attack.
"We recognize that we live in a new world," Microsoft President Brad Smith said during a speech on Tuesday at the RSA cyber security conference in San Francisco. "We're living amidst a generation of new weapons, and where cyberspace has become the new battlefield."
Smith, who led efforts to organize the alliance, said the devastating cyber attacks in 2017 demonstrated the need for the technology sector to "take a principled path toward more effective steps to work together and defend customers around the world."
It was not clear whether any companies would change their existing policies as a result of joining the accord.
Microsoft did not immediately respond to a series of questions about the accord, including whether the company had previously participated in government-sponsored offensive cyber operations or how the pledge would impact compliance with lawfully obtained surveillance orders in the United States or elsewhere.
The accord also promised to establish new formal and informal partnerships within the industry and with security researchers to share threats and coordinate vulnerability disclosures.
It builds on an idea for a so-called Digital Geneva Convention that Smith rolled out at least year's RSA conference, a proposal to create an international body to protect civilians from state-sponsored hacking.
Countries, Smith said then, should develop global rules for cyber attacks similar to those established for armed conflict at the 1949 Geneva Convention that followed World War Two.
In addition to Microsoft and Facebook, 32 other companies signed the pledge, including Cisco, Juniper Networks, Oracle, Nokia, SAP, Dell and cyber security firms Symantec, FireEye and Trend Micro.
The list of companies does not include any from Russia, China, Iran or North Korea, widely viewed as the most active in launching destructive cyber attacks against their foes.
Major US technology companies Amazon, Apple, Alphabet and Twitter also did not sign the pledge.
source: news.abs-cbn.com
Tuesday, December 19, 2017
White House blames North Korea for cyberattack
The White House on Tuesday publicly accused North Korea of launching a massive cyberattack that hit 150 countries last May -- hobbling networks from Britain's public health system to FedEx.
"After careful investigation, the United States is publicly attributing the massive 'WannaCry' cyberattack to North Korea," said White House homeland security advisor Tom Bossert.
"We do not make this allegation lightly, we do so with evidence and we do so with partners," he added.
Exploiting a security flaw in Microsoft's Windows XP operating system, the malware infected an estimated 300,000 computers demanding ransom to decrypt data.
The United States is the latest country to point the finger of blame at Pyongyang, attribution which comes as part of a drive to exert "maximum pressure" on the regime.
As yet, no retaliatory measures have been announced.
Among the infected computers were those at Britain's National Health Service (NHS), Spanish telecoms company Telefonica and US logistics company FedEx.
London had already blamed North Korea, which hit a third of Britain's public hospitals.
Pyongyang then denied the allegation, saying it went "beyond the limit of our tolerance" and was a "wicked attempt to lure the international community into harboring greater mistrust of the DPRK."
US government under scrutiny
Questions had been raised about whether the US government acted in a timely manner to respond to the attack, with Microsoft accusing Washington of spotting the flaw and using it for its own ends.
"This attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem," Microsoft's Brad Smith said at the time.
"Repeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage," he said, claiming that the National Security Agency of spotting the flaw and saying nothing.
Bossert said that the United States kept only 10 percent of security flaws secret and had no policy of "stockpiling" or withholding information from potential targets.
Since coming to office Donald Trump has sought to put pressure on North Korea, as its reclusive leaders edge ever-closer to developing a ballistic missile that could deliver a nuclear warhead to the United States.
Amid a series of tests Trump's administration has appeared at odds over whether talks could offer a way out of the standoff.
National Security Advisor HR McMaster tried to clean up that question in an interview with the BBC, saying the United States wanted a peaceful solution: "Of course that's what we want but we are not committed to a peaceful resolution."
"We are committed to a resolution, we want the resolution to be peaceful. But, as the president has said, all options are on the table and we have to be prepared if necessary to compel the denuclearization of North Korea without the cooperation of that regime."
Trump's first National Security Strategy released Monday, declared that "North Korea seeks the capability to kill millions of Americans with nuclear weapons."
"Continued provocations by North Korea will prompt neighboring countries and the United States to further strengthen security bonds and take additional measures to protect themselves."
source: news.abs-cbn.com
Thursday, June 29, 2017
New computer virus spreads from Ukraine to disrupt world business
FRANKFURT/MOSCOW/KIEV - A new cyber virus spread from Ukraine to wreak havoc around the globe on Wednesday, crippling thousands of computers, disrupting ports from Mumbai to Los Angeles and halting production at a chocolate factory in Australia.
The virus is believed to have first taken hold on Tuesday in Ukraine where it silently infected computers after users downloaded a popular tax accounting package or visited a local news site, national police and international cyber experts said.
More than a day after it first struck, companies around the world were still wrestling with the fallout while cyber security experts scrambled to find a way to stem the spread.
Danish shipping giant A.P. Moller-Maersk said it was struggling to process orders and shift cargoes, congesting some of the 76 ports around the world run by its APM Terminals subsidiary.
U.S. delivery firm FedEx Corp said its TNT Express division had been significantly affected by the virus, which also wormed its way into South America, affecting ports in Argentina operated by China's Cofco.
The malicious code locked machines and demanded victims post a ransom worth $300 in bitcoins or lose their data entirely, similar to the extortion tactic used in the global WannaCry ransomware attack in May.
More than 30 victims paid up but security experts are questioning whether extortion was the goal, given the relatively small sum demanded, or whether the hackers were driven by destructive motives rather than financial gain.
Hackers asked victims to notify them by email when ransoms had been paid but German email provider Posteo quickly shut down the address, a German government cyber security official said.
Ukraine, the epicentre of the cyber strike, has repeatedly accused Russia of orchestrating attacks on its computer systems and critical power infrastructure since its powerful neighbour annexed the Black Sea peninsula of Crimea in 2014.
The Kremlin, which has consistently rejected the accusations, said on Wednesday it had no information about the origin of the global cyber attack, which also struck Russian companies such as oil giant Rosneft and a steelmaker.
"No one can effectively combat cyber threats on their own, and, unfortunately, unfounded blanket accusations will not solve this problem," said Kremlin spokesman Dmitry Peskov.
ESET, a Slovakian company that sells products to shield computers from viruses, said 80 percent of the infections detected among its global customer base were in Ukraine, with Italy second hardest hit with about 10 percent.
ETERNAL BLUE
The aim of the latest attack appeared to be disruption rather than ransom, said Brian Lord, former deputy director of intelligence and cyber operations at Britain's GCHQ and now managing director at private security firm PGI Cyber.
"My sense is this starts to look like a state operating through a proxy ... as a kind of experiment to see what happens," Lord told Reuters on Wednesday.
While the malware seemed to be a variant of past campaigns, derived from code known as Eternal Blue believed to have been developed by the U.S. National Security Agency (NSA), experts said it was not as virulent as May's WannaCry attack.
Security researchers said Tuesday's virus could leap from computer to computer once unleashed within an organisation but, unlike WannaCry, it could not randomly trawl the internet for its next victims, limiting its scope to infect.
Bushiness that installed Microsoft's latest security patches from earlier this year and turned off Windows file-sharing features appeared to be largely unaffected.
There was speculation, however, among some experts that once the new virus had infected one computer it could spread to other machines on the same network, even if those devices had received a security update.
After WannaCry, governments, security firms and industrial groups advised businesses and consumers to make sure all their computers were updated with Microsoft security patches.
Austria's government-backed Computer Emergency Response Team (CERT) said "a small number" of international firms appeared to be affected, with tens of thousands of computers taken down.
Security firms including Microsoft, Cisco's Talos and Symantec said they had confirmed some of the initial infections occurred when malware was transmitted to users of a Ukrainian tax software programme called MEDoc.
The supplier of the software, M.E.Doc denied in a post on Facebook that its software was to blame, though Microsoft reiterated its suspicions afterwards.
"Microsoft now has evidence that a few active infections of the ransomware initially started from the legitimate MEDoc updater process," it said in a technical blog post.
Russian security firm Kaspersky said a Ukrainian news site for the city of Bakhumut was also hacked and used to distribute the ransomware to visitors, encrypting data on their machines.
CORPORATE CHAOS
A number of the international firms hit have operations in Ukraine, and the virus is believed to have spread within global corporate networks after gaining traction within the country.
Shipping giant A.P. Moller-Maersk, which handles one in seven containers shipped worldwide, has a logistics unit in Ukraine.
Other large firms affected, such as French construction materials company Saint Gobain and Mondelez International Inc, which owns chocolate brand Cadbury, also have operations in the country.
Maersk was one of the first global firms to be taken down by the cyber attack and its operations at major ports such as Mumbai in India, Rotterdam in the Netherlands and Los Angeles on the U.S. west coast were disrupted.
Other companies to succumb included BNP Paribas Real Estate , a part of the French bank that provides property and investment management services.
"The international cyber attack hit our non-bank subsidiary, Real Estate. The necessary measures have been taken to rapidly contain the attack," the bank said on Wednesday.
Production at the Cadbury factory on the Australian island state of Tasmania ground to a halt late on Tuesday after computer systems went down.
Russia's Rosneft, one of the world's biggest crude producers by volume, said on Tuesday its systems had suffered "serious consequences" but oil production had not been affected because it switched to backup systems.
source: news.abs-cbn.com
Monday, May 15, 2017
More disruptions feared from cyber attack; Microsoft slams US govt secrecy
WASHINGTON/FRANKFURT - Officials across the globe scrambled over the weekend to catch the culprits behind a massive ransomware worm that disrupted operations at car factories, hospitals, shops and schools, while Microsoft on Sunday pinned blame on the US government for not disclosing more software vulnerabilities.
Cyber security experts said the spread of the worm dubbed WannaCry - "ransomware" that locked up more than 200,000 computers in more than 150 countries - had slowed but that the respite might only be brief amid fears new versions of the worm will strike.
In a blog post on Sunday, Microsoft President Brad Smith appeared to tacitly acknowledge what researchers had already widely concluded: The ransomware attack leveraged a hacking tool, built by the US National Security Agency, that leaked online in April.
"This is an emerging pattern in 2017," Smith wrote. "We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world."
He also poured fuel on a long-running debate over how government intelligence services should balance their desire to keep software flaws secret - in order to conduct espionage and cyber warfare - against sharing those flaws with technology companies to better secure the internet.
"This attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem," Smith wrote. He added that governments around the world should "treat this attack as a wake-up call" and "consider the damage to civilians that comes from hoarding these vulnerabilities and the use of these exploits."
The NSA and White House did not immediately respond to requests for comment about the Microsoft statement.
Economic experts offered differing views on how much the attack, and associated computer outages, would cost businesses and governments.
The non-profit US Cyber Consequences Unit research institute estimated that total losses would range in the hundreds of millions of dollars, but not exceed $1 billion.
Most victims were quickly able to recover infected systems with backups, said the group's chief economist, Scott Borg.
California-based cyber risk modeling firm Cyence put the total economic damage at $4 billion, citing costs associated with businesses interruption.
US President Donald Trump on Friday night ordered his homeland security adviser, Tom Bossert, to convene an "emergency meeting" to assess the threat posed by the global attack, a senior administration official told Reuters.
Senior US security officials held another meeting in the White House Situation Room on Saturday, and the FBI and the NSA were working to help mitigate damage and identify the perpetrators of the massive cyber attack, said the official, who spoke on condition of anonymity to discuss internal deliberations.
The investigations into the attack were in the early stages, however, and attribution for cyber attacks is notoriously difficult.
The original attack lost momentum late on Friday after a security researcher took control of a server connected to the outbreak, which crippled a feature that caused the malware to rapidly spread across infected networks.
Infected computers appear to largely be out-of-date devices that organizations deemed not worth the price of upgrading or, in some cases, machines involved in manufacturing or hospital functions that proved too difficult to patch without possibly disrupting crucial operations, security experts said.
Microsoft released patches last month and on Friday to fix a vulnerability that allowed the worm to spread across networks, a rare and powerful feature that caused infections to surge on Friday.
Code for exploiting that bug, which is known as "Eternal Blue," was released on the internet last month by a hacking group known as the Shadow Brokers.
The head of the European Union police agency said on Sunday the cyber assault hit 200,000 victims in at least 150 countries and that number would grow when people return to work on Monday.
MONDAY MORNING RUSH?
Monday was expected to be a busy day, especially in Asia, which may not have seen the worst of the impact yet, as companies and organizations turned on their computers.
"Expect to hear a lot more about this tomorrow morning when users are back in their offices and might fall for phishing emails" or other as yet unconfirmed ways the worm may propagate, said Christian Karam, a Singapore-based security researcher.
The attack hit organizations of all sizes.
Renault said it halted manufacturing at plants in France and Romania to prevent the spread of ransomware.
Other victims include is a Nissan manufacturing plant in Sunderland, northeast England, hundreds of hospitals and clinics in the British National Health Service, German rail operator Deutsche Bahn and international shipper FedEx Corp
A Jakarta hospital said on Sunday that the cyber attack had infected 400 computers, disrupting the registration of patients and finding records.
Account addresses hard-coded into the malicious WannaCry virus appear to show the attackers had received just under $32,500 in anonymous bitcoin currency as of (1100 GMT) 7 a.m. EDT on Sunday, but that amount could rise as more victims rush to pay ransoms of $300 or more.
The threat receded over the weekend after a British-based researcher, who declined to give his name but tweets under the profile @MalwareTechBlog, said he stumbled on a way to at least temporarily limit the worm's spread by registering a web address to which he noticed the malware was trying to connect.
Security experts said his move bought precious time for organizations seeking to block the attacks.
(Additional reporting by Jim Finkle, Neil Jerome Morales, Masayuki Kitano, Kiyoshi Takenaka, Jose Rodriguez, Elizabeth Piper, Emmanuel Jarry, Orathai Sriring, Jemima Kelly, Alistair Smout, Andrea Shalal, Jack Stubbs, Antonella Cinelli, Kate Holton, Andy Bruce, Michael Holden, David Milliken, Tim Hepher, Luiza Ilie, Patricia Rua, Axel Bugge, Sabine Siebold, Eric Walsh, Engen Tham, Fransiska Nangoy, Soyoung Kim, Mai Nguyen and Nick Zieminski; Editing by Mark Heinrich and Peter Cooney)
source: news.abs-cbn.com
Sunday, May 14, 2017
Organizations hit by 'unprecedented' global cyberattack
A huge range of organizations around the world have been affected by the WannaCry ransomware cyberattack, described by the EU's law enforcement agency as "unprecedented."
Here are some of the most prominent victims, from Britain's National Health Service (NHS) to French carmaker Renault and the Russian interior ministry.
NHS
The British public health service - the world's fifth-largest employer, with 1.7 million staff -- was badly hit, with interior minister Amber Rudd saying around 45 facilities were affected. Several were forced to cancel or delay treatment for patients.
Pictures on social media showed screens of NHS computers with images demanding payment of $300 (230 pounds, 275 euros) in the virtual currency Bitcoin, saying: "Ooops, your files have been encrypted!"
Renault
The French automobile giant was hit, forcing it to halt production at sites in France and its factory in Slovenia as part of measures to stop the spread of the virus.
Nissan UK's unit in Sunderland was hit by the attack, spokeswoman Lucy Banwell said.
Russian banks and ministries
Russia's central bank was targeted, along with several government ministries and the railway system. The interior ministry said 1,000 of its computers were hit by a virus. Officials played down the incident, saying the attacks had been contained.
Germany railways
Germany's Deutsche Bahn national railway operator was affected, with information screens and ticket machines hit. Travellers tweeted pictures of hijacked departure boards showing the ransom demand instead of train times. But the company insisted that trains were running as normal.
Fedex
The US package delivery group acknowledged it had been hit by malware and said it was "implementing remediation steps as quickly as possible."
Telefonica
The Spanish telephone giant said it was attacked but "the infected equipment is under control and being reinstalled," said Chema Alonso, the head of the company's cyber security unit and a former hacker.
source: news.abs-cbn.com
Saturday, May 13, 2017
British hospitals shut down by cyberattack
LONDON/MADRID - A huge cyberattack brought disruption to Britain's health system on Friday and infected many Spanish companies with malicious software, and security researchers said a dozen other countries may be affected.
Hospitals and doctors' surgeries in parts of England were forced to turn away patients and cancel appointments. People in affected areas were being advised to seek medical care only in emergencies.
"We are experiencing a major IT disruption and there are delays at all of our hospitals," said the Barts Health group, which manages major London hospitals. Routine appointments had been cancelled and ambulances were being diverted to neighboring hospitals.
Telecommunications giant Telefonica was among the targets in Spain, though it said the attack was limited to some computers on an internal network and had not affected clients or services.
Authorities in both countries said the attack was conducted using 'ransomware' - malicious software that infects machines, locks them up by encrypting data and demands a ransom to restore access. They identified the type of malware as 'Wanna Cry', also known as 'Wanna Decryptor'.
A Telefonica spokesman said a window appeared on screens of infected computers that demanded payment with the digital currency bitcoin in order to regain access to files.
In Spain, the attacks did not disrupt the provision of services or networks operations of the victims, the government said in a statement. Still, the news prompted security teams at large financial services firms and businesses around the world to review their plans for defending against ransomware attacks, according to executives with private cyber security firms.
A spokeswoman for Portugal Telecom said: "We were the target of an attack, like what is happening in all of Europe, a large scale-attack, but none of our services were affected."
British based cyber researcher Chris Doman of AlienVault said the ransomware "looks to be targeting a wide range of countries", with preliminary evidence of infections from 14 countries so far, also including Russia, Indonesia and Ukraine.
PM BRIEFED
A spokesman for British Prime Minister Theresa May said she was being kept informed of the incident, which came less than four weeks before a parliamentary election in which national security and the management of the state-run National Health Service (NHS) are important campaign themes.
Authorities in Britain have been braced for possible cyberattacks in the run-up to the vote, as happened during last year's U.S. election and on the eve of this month's presidential vote in France.
But those attacks - blamed on Russia, which has repeatedly denied them - followed a entirely different modus operandi involving penetrating the accounts of individuals and political organizations and then releasing hacked material online.
The full extent of Friday's disruption in Britain remained unclear.
"This attack was not specifically targeted at the NHS and is affecting organisations from across a range of sectors," NHS Digital, the computer arm of the health service, said in a statement.
Britain's National Cyber Security Centre, part of the GCHQ spy agency, said it was aware of a cyber incident and was working with NHS Digital and the police to investigate.
A reporter from the Health Service Journal said the attack had affected X-ray imaging systems, pathology test results, phone systems and patient administration systems.
Although cyber extortion cases have been rising for several years, they have to date affected small-to-mid sized organisations, disrupting services provided by hospitals, police departments, public transportation systems and utilities in the United States and Europe.
"Seeing a large telco like Telefonica get hit is going to get everybody worried. Now ransomware is affecting larger companies with more sophisticated security operations," Chris Wysopal, chief technology officer with cyber security firm Veracode, said.
The news is also likely to embolden cyber extortionists when selecting targets, Chris Camacho, chief strategy officer with cyber intelligence firm Flashpoint, said.
“Now that the cyber criminals know they can hit the big guys, they will start to target big corporations. And some of them may not be well prepared for such attacks,” Camacho said. In Spain, some big firms took pre-emptive steps to thwart ransomware attacks following a warning from Spain's National Cryptology Centre of "a massive ransomware attack."
Iberdrola and Gas Natural, along with Vodafone's unit in Spain, asked staff to turn off computers or cut off internet access in case they had been compromised, representatives from the firms said.
It was not immediately clear how many Spanish organizations had been compromised by the attacks, if any critical services had been interrupted or whether victims had paid cyber criminals to regain access to their networks.
source: news.abs-cbn.com
Wednesday, December 23, 2015
Hyatt Hotels computers infected with malicious software
SAN FRANCISCO, United States - Hyatt Hotels on Wednesday revealed that it recently discovered malicious computer code on computers used for processing payments at locations it manages.
In a short statement, Hyatt did not disclose what, if anything, the cyber attack accomplished but said that the company immediately "launched an investigation and engaged leading third-party cyber security experts."
Hyatt also said it strengthened the security of its systems and that "customers can feel confident using payment cards at Hyatt hotels worldwide."
The hotel group advised customers, as a precaution, to watch payment card account statements for unauthorized charges.
Cyber threats blogger Brian Krebs at KrebsonSecurity.com said in an online post that "Hyatt joins a crowded list of other hotel chains similarly breached in the past year."
Hyatt competitors Hilton, and Starwood Hotels which operates the Sheraton and Westin chains, last month separately announced that payment systems had been targeted by hackers.
US hotel chain Hilton said that hackers infected some of its point-of-sale computer systems with malware crafted to steal credit card information.
Malicious code that infected registers at hotels had the potential to take cardholders' names along with card numbers, security codes and expiration dates, Hilton said in an online post.
Starwood Hotels said that hackers had infected payment systems in some of its establishments, potentially leaking customer credit card data.
The hack occurred at a "limited number" of its hotels in North America, according to Starwood, whose other well-known chains include St Regis and W Hotels.
The cyber attacks on Hilton and Starwood sounded similar to one disclosed earlier in the year by Trump Hotel Collection.
"We believe that there may have been unauthorized malware access to some of the computers that host our front desk terminals and payment card terminals in our restaurants, gift shops and other point-of-sale purchase locations at some hotels," Trump Hotel Collection said at a website devoted to details of the incident.
Locations affected were listed as Trump SoHo New York, Trump National Doral, Trump International New York, Trump International Chicago, Trump International Waikiki, Trump International Hotel & Tower Las Vegas, and Trump International Toronto.
source: www.abs-cbnnews.com
Thursday, October 22, 2015
CIA condemns 'malicious' hack of director's personal email
WASHINGTON - The CIA on Wednesday condemned the hacking of director John Brennan's personal email account, describing it as a crime and saying so far there was "no indication" that any classified information was released.
"The hacking of the Brennan family account is a crime and the Brennan family is the victim," the Central Intelligence Agency said after anti-secrecy campaign group WikiLeaks published documents it said had come from the account.
"The private electronic holdings of the Brennan family were plundered with malicious intent and are now being distributed across the web," it said.
"This attack is something that could happen to anyone and should be condemned, not promoted. There is no indication that any of the documents released thus far are classified."
source: www.abs-cbnnews.com
Sunday, June 14, 2015
Computer in Merkel's office hit by cyberattack - report
BERLIN, Germany - A computer in German Chancellor Angela Merkel's legislative office was hit by a cyberattack that targeted the country's lower house of parliament in May, the Bild newspaper reported on Sunday.
The daily, which did not cite its sources, said the cyberattack was broader and greater than originally anticipated and the Bundestag struggled to control it.
The attack "infected" one of the computers in Merkel's Bundestag office. Bild said the computer was one of the first on which the Trojan Horse-style attack was discovered.
According to the newspaper, the discovery was made on Friday, with officials finding the Trojan Horse software on five computers in the Bundestag.
A spokesman for Merkel's conservative CDU bloc told the newspaper he could "not confirm nor deny" the report.
It was not immediately clear who was responsible for the cyberattack.
Merkel's official website, as well as those of the government and the Bundestag, were blocked in January in an online attack claimed by a pro-Russian group.
source: www.abs-cbnnews.com
Friday, March 6, 2015
Microsoft warns Windows PCs also vulnerable to 'Freak' attacks
BOSTON - Hundreds of millions of Windows PC users are vulnerable to attacks exploiting the recently uncovered "Freak" security vulnerability, which was initially believed to only threaten mobile devices and Mac computers, Microsoft Corp warned.
News of the vulnerability surfaced on Tuesday when a group of nine security experts disclosed that ubiquitous Internet encryption technology could make devices running Apple Inc's iOS and Mac operating systems, along with Google Inc's Android browser vulnerable to cyberattacks.
Microsoft released a security advisory on Thursday warning customers that their PCs were also vulnerable to the "Freak" vulnerability.
The weakness could allow attacks on PCs that connect with Web servers configured to use encryption technology intentionally weakened to comply with U.S. government regulations banning exports of the strongest encryption.
If hackers are successful, they could spy on communications as well as infect PCs with malicious software, the researchers who uncovered the threat said on Tuesday.
The Washington Post on Tuesday reported that whitehouse.gov and fbi.gov were among the sites vulnerable to these attacks, but that the government had secured them. (wapo.st/18KaxIA)
Security experts said the vulnerability was relatively difficult to exploit because hackers would need to use hours of computer time to crack the encryption before launching an attack.
"I don't think this is a terribly big issue, but only because you have to have many ducks in a row," said Ivan Ristic, director of engineering for cybersecurity firm Qualys Inc.
That includes finding a vulnerable web server, breaking the key, finding a vulnerable PC or mobile device, then gaining access to that device.
Microsoft advised system administrators to employ a workaround to disable settings on Windows servers that allow use of the weaker encryption. It said it was investigating the threat and had not yet developed a security update that would automatically protect Windows PC users from the threat.
Apple said it had developed a software update to address the vulnerability, which would be pushed out to customers next week.
Google said it had also developed a patch, which it provided to partners that make and distribute Android devices.
"Freak" stands for Factoring RSA-EXPORT Keys. (Reporting by Jim Finkle; Editing by Jonathan Oatis and Richard Chang)
source: www.abs-cbnnews.com
Saturday, February 28, 2015
These cyber thugs may hold your data hostage
SAN FRANCISCO - Marriage therapist Valerie Goss turned on her computer one day and found that all of her data was being held hostage.
Malicious code referred to as "ransomware" had encrypted her files and locked them away. Cyber criminals demanded $500 in hard-to-trace virtual currency Bitcoin to give her the key. The ransom would jump to $1,000 in Bitcoin if Goss took more than a day to pay.
"I felt shocked; like I had been robbed," the Northern California therapist said. "And, I felt pressed for time to make a rational decision. It felt so surreal."
After online research by her son revealed that in a quarter of more of ransomware cases victims never see their files again even if they pay, Goss refused to pay.
Instead, she bought a new computer and fortified it with security software. She also started backing up data off the machine.
As painful as it was, Goss did the right thing, according to cyber security specialists interviewed by AFP.
"Unfortunately, it is the right thing to do," said Malwarebytes chief executive Marcin Kleczynski.
"If you do pay the ransom, that money is gone and there is no guarantee you will get your data back."
Kidnapping smartphone files
Ransomware has been around a while, but has been making a big comeback, according to Kleczynski and mobile security researchers at Lookout. Gross fell prey to the hacker tactic last year on the computer she used in her home office.
Data kidnappers are also taking aim at smartphones and tablets, particularly models powered by Google-backed Android software, said Lookout consumer safety advocate Meghan Kelly.
Lookout saw mobile malware "encounters" in the United States jump 75 percent in 2014 as compared with the prior year. Ransomware accounted for a big part of the jump, according to Kelly.
The United States seems to be a preferred target zone, perhaps because people here keep a lot of cherished, personal data on mobile devices and computers, or because they are seen as having the money to pay to get it back.
A US study released last year by Lookout revealed that one-in-three people considered pictures, contacts, and other digital files on mobile devices so precious they would pay to get them back.
Goss said that she was willing to pay the ransom, but had no assurance she would actually see her files again even if she did pony up the Bitcoin.
Like other forms of malicious code, ransomware can get into computers, smartphones or tablets when people click on dubious links or open infected email attachments.
Drive-by attacks
People can also be hit with ransomware at legitimate websites that have been unknowingly booby-trapped by hackers to infect visitors in what are referred to as "drive-by" attacks.
"Sometimes you don't have to do anything wrong, just visit a website that has been infiltrated and then all of a sudden you have a piece of malware on your computer," Kleczynski said.
Ransomware locks and encrypts all files on infected devices. Kleczynski said that ransom demanded typically ranges from $100 to $1,000.
Ransomware targeting mobile devices can lock phones, email and more, essentially stripping control from owners, according to Kelly.
"Ransomware is a pretty loud piece of malware," Kelly said. "It is going to be in your face saying you can't navigate away and we want money from you."
People can protect themselves by being wary of what links they click on or files they open, and by keeping operating software up to date so the latest security patches are in place.
It is also recommended to have security software running to intervene before malware takes root, and to keep back-up copies of files in the cloud or elsewhere in case defenses are breached.
"One day ransomware can hit you and you have to prepare for the worst," Kleczynski said.
"The threat is very serious, users are infected all of the time, and the encryption keys are so strong you can't get those files back."
Malwarebytes and Lookout offer free versions of their security applications.
source: www.abs-cbnnews.com
Thursday, February 26, 2015
Lenovo website hacked; Lizard Squad claims responsibility
China's Lenovo Group Ltd website was hacked, the company said on Wednesday, days after the U.S. government advised Lenovo customers to remove a pre-installed virus-like software, "Superfish", on laptops that makes the devices more vulnerable to attacks.
Hacking group Lizard Squad claimed to be behind the attacks, according to its Twitter page.
Lizard Squad has taken credit for several high-profile outages, including attacks that took down Sony Corp's PlayStation Network and Microsoft Corp's Xbox Live network last month. Members of the group have not been identified.
"The domain name service server hosting Lenovo's website was hacked. We do not have any further information at this time to share. We'll update as soon as possible," Lenovo said in a statement to Reuters.
San Francisco-based security firm CloudFlare said hackers transferred the domain to CloudFlare in order to point it to a defacement site.
"As soon as we at CloudFlare noticed, we seized the account and worked with Lenovo to restore service while they worked to recover their domain," Marc Rogers, Principal Security Researcher at CloudFlare, said in an email to Reuters.
Starting 4 p.m. ET (2100 GMT) on Wednesday, visitors to the Lenovo website saw a slideshow of young people looking into webcams and the song "Breaking Free" playing in the background, according to The Verge, which first reported the breach.
"We're breaking free! Soarin', flyin', there's not a star in heaven that we can't reach!," Lizard Squad posted on its Twitter page, quoting the song from the movie "High School Musical".
The hackers also posted a couple of screenshots of an email between Lenovo employees regarding the "Superfish" software.
The Department of Homeland Security said in an alert on Friday that the "Superfish" program makes users vulnerable to a type of cyberattack known as SSL spoofing, in which remote attackers can read encrypted web traffic, redirect traffic from official websites to spoofs, and perform other attacks.
Rogers also said CloudFlare was able to restore service before Lenovo recovered the domain, suggesting that the outage was probably "quite small".
However, Lenovo's website was inaccessible at 7:54 p.m. ET (0054 GMT). A message said the site was unavailable due to system maintenance.
source: www.abs-cbnnews.com
Friday, February 20, 2015
Lenovo laptop users urged to remove Superfish program
BOSTON - The U.S. government on Friday advised Lenovo Group Ltd customers to remove a "Superfish," a program pre-installed on some Lenovo laptops, saying it makes users vulnerable to cyberattacks.
The Department of Homeland Security said in an alert that the program makes users vulnerable to a type of cyberattack known as SSL spoofing, in which remote attackers can read encrypted web traffic, redirect traffic from official websites to spoofs, and perform other attacks.
"Systems that came with the software already installed will continue to be vulnerable until corrective actions have been taken," the agency said.
Adi Pinhas, chief executive of Palo Alto, California-based Superfish, said in a statement that his company's software helps users achieve more relevant search results based on images of products viewed. He said the vulnerability was "inadvertently" introduced by Israel-based Komodia, which built the application described in the government notice.
Komodia CEO arak Weichselbaum declined comment on the vulnerability.
Komodia's website says it produces a "hijacker" that allows users to view data encrypted with SSL technology.
"The hijacker uses Komodia's redirector platform to allow you easy access to the data and the ability to modify, redirect, block, and record the data without triggering the target browser's certification warning," according to the site.
Marc Rogers, a researcher with CloudFlare, said that means companies which deploy Komodia technology can snoop on web traffic.
"These guys can do everything from just collect a little bit of marketing information, all the way to building a profile on you and spying on your banking connections," he said. "It's a very dangerous slope."
Rogers said that use of Komodia's technology in other products makes them vulnerable to the same types of attacks as Lenovo's Superfish.
He said other vulnerable products include two parental filters: One from Komodia known as KeepMyFamilySecure and another from Qustodio.
Komodia's Weichselbaum said his company was investigating reports of vulnerabilities in KeepMyFamilySecure.
Qustodio CEO Eduardo Cruz Chief Executive said his company's Windows parental filter was vulnerable and he hoped to push out a fix within a few days.
Lenovo did not disclose how many machines were affected, but said that only machines shipped from September to December of last year had been pre-loaded with the vulnerable software.
Affected Lenovo products include laptops in its Yoga, Flex and MiiX lines as well as its E, G, U, Y and Z series, according to the company's support website.
source: www.abs-cbnnews.com
Sunday, December 28, 2014
Sony works to restore PlayStation after attack
BOSTON -- Sony Corp worked for a third day on Saturday to restore services to its PlayStation network as the FBI said it was looking into the disruption, which began on Christmas Day.
"We are aware of the reports and are investigating the Sony PlayStation matter," Federal Bureau of Investigation spokeswoman Jenny Shearer said via email. She did not elaborate.
Meanwhile, Sony said on Saturday that the attack had prevented some people who received consoles for Christmas from using their new machines on the PlayStation network, which lets gamers compete with people around the world via the Internet.
"If you received a PlayStation console over the holidays and have been unable to log onto the network, know that this problem is temporary and is not caused by your game console," Sony executive Catherine Jensen said on the company's U.S. PlayStation blog.
Some customers posted complaints about the outage on the blog. "Three days without PSN. That's absurd," said one of them.
"We understand your frustration," Jensen responded early Saturday afternoon. "Our engineers are working to restore service as quickly as possible!"
Later in the day she said the company had restored access for some users and would keep bringing more back online. Sony declined to say how many of PSN's 56 millions users had been affected by the attack.
The blog said the problems were the result of "high levels of traffic designed to disrupt connectivity and online game play," which is widely known as a distributed denial-of-service attack.
It was Sony's second recent high-profile encounter with hackers after an unprecedented attack on its Hollywood studio, which the U.S. government attributed to North Korea and linked to the release of the low-brow comedy "The Interview."
A hacker activist group known as Lizard Squad said it was responsible for the PSN outage as well as delays on Microsoft's Corp's Xbox network; Microsoft quickly fixed the problem.
The group has claimed responsibility for previous attacks, including ones on PSN in early December and August.
The August attack coincided with a bomb scare in which Lizard Squad tweeted to American Airlines that it heard explosives were on board a Dallas-to-San Diego flight carrying an executive with Sony Online Entertainment.
Sony has been the victim of some of the most notorious cyberattacks in history. Besides the breach at its Hollywood studio, hackers stole data belonging to 77 million PlayStation Network users in 2011.
source: www.abs-cbnnews.com
Saturday, December 27, 2014
'The Interview' makes first million in roller-coaster release
LOS ANGELES - "The Interview" took in more than $1 million (642,772 pounds) in a limited Christmas Day release, a decent start for the raunchy comedy that appeared dead after Sony Pictures pulled it from theatres last week following a devastating cyberattack blamed on North Korea.
Even though the film was very much in the zeitgeist and also up for rental on YouTube and Google Play, it was unclear whether the Seth Rogan movie would recoup the $44 million it cost to make, or the additional millions spent on marketing.
The comedy, steeped in gross-out, bathroom humour that depicts a fictional plot to assassinate North Korea leader Kim Jong Un, managed to fill a few hundred theatres that made a last-minute push to screen the film.
"They (Sony) got $1 million in sales, that's a nice bit of gravy... knowing the main release isn't happening the way it should be," said Gitesh Pandya, editor of boxofficeguru.com.
"The Interview" was shown in 331 mostly independent theatres in the United States - less than 10 percent of its planned wide release - after major U.S. movie chains balked at showing the movie due to security concerns.
It was expected to gross at least $20 million over the long holiday weekend if in wide release, according to Boxoffice.com.
Sony Pictures also released the movie online via Google Inc's YouTube and Google Play, Microsoft Corp's Xbox gaming console and Sony's own dedicated website. It is looking for more partners for digital distribution, though hundreds of thousands of people have reportedly downloaded it from pirate sites.
"Considering the incredibly challenging circumstances, we are extremely grateful to the people all over the country who came out to experience 'The Interview' on the first day of its unconventional release," Rory Bruer, Sony Pictures president of distribution, said in a statement.
The controversy gave the film exposure to audiences that might never have gone to see the movie, and many who showed up on Christmas Day said they were there to support free speech.
One of those was David Humdy, 65, an entertainment industry accountant who saw the film in Los Angeles and declared it "silly, entertaining, better than I thought."
So far, Sony has not released online sales figures, but the screwball comedy was the top film on YouTube and Google Play.
Pandya believes Sony Pictures will be able to absorb losses easily, as it is not unusual for a film of its budget to fall short.
"It's hard to find a way that they recoup it all because they did end up spending a lot of money on marketing for a theatrical release that never happened," he added.
Pandya estimated that "The Interview" would have grossed about $5 million on Christmas Day had it been in wide release.
It did take in an estimated $3,142 per screen without the benefit of playing in the largest multiplexes. That is about double the amount if the film had been in wide release.
The two biggest Christmas Day releases, Universal's "Unbroken" and Disney's "Into the Woods," respectively grossed $4,980 and $6,182 per screen, according to studio estimates.
(Additional reporting by Mary Milliken; Editing by Dan Grebler)
source: www.abs-cbnnews.com
Subscribe to:
Posts (Atom)



















