Cayman Islands investment fund left entire filestore viewable by world+dog in unsecured Azure blob
- Reference: 1606822213
- News link: https://www.theregister.co.uk/2020/12/01/investment_fund_data_breach/
- Source link:
Details of the fund's register of members and correspondence with its investors could be freely read by anyone with the URL to its Azure blob, the Microsoft equivalent of an Amazon Web Services S3 storage bucket.
As well as publicly exposing who its shareholders are, how many shares they hold, and the value of those holdings, the fund – which The Register is not naming after it agreed to talk in depth about its incident response process – had also saved a scanned copy of its online banking PIN to the blob. The Register viewed a subset of files from the blob to confirm their ownership and authenticity.
[1]
The fund's online banking PIN was one of the files anyone could have viewed on its unsecured Azure blob
The blob address was indexed by a specialised search engine and was pointed out to The Register by an incredulous infosec source who wisecracked: "Money money money... must be funny... in a rich man's world."
The unnamed fund's incident response consisted of disregarding the initial notification from The Register before asking a staffer with a compsci degree if he thought there was cause for concern. Luckily, that person realised what we were trying to tell them.
[2]
The fund's register of members (shareholders) – one of the things that Cayman Islands companies [3]are not obliged to file with local authorities in the British Overseas Territory
He said: "We use Azure for our server backup, it's not our day-to-day server: people have set that up for us as a backup for disaster recovery and so on."
The person, who described himself as a compsci grad with a strong maths background, said his bosses asked him to look at our email again just in case there was something more to it "than a phishing attempt".
[4]
Sensitive internal documents including itemised bank statements could be viewed by anyone on the Azure blob
Documents seen by The Register in the unsecured blob stretch back years and include: scans of directors' passports; letters to and from investors including commented files sent during commercial negotiations; term sheets; share certificates (including blank copies); documents signed by its directors and more.
The compsci chap continued: "This was the [backup] solution provided by our IT vendor in Hong Kong which we saw as fairly normal cloud provision. Clearly there's some security issue there!"
[5]
Not only were completed share certificates scanned and uploaded but also blank copies, along with directors' signatures
He also added that the fund's IT provider had removed all of its files from its Azure blob as a result of the breach, while expressing some doubts about the IT provider's claim that Microsoft had ignored their requests for help over the weekend.
The fund, which falls into the smaller end of the SME bracket when judged on headcount, appears to have the same level of in-house IT expertise as any other small firm whose main business is not focused on IT; not a lot. They were completely unaware of how Azure operated or how their files had been exposed to anyone with a web browser and appeared to be totally reliant on their IT provider for everything other than basic office productivity software.
[6]
One of the fund's directors had scanned all the identity pages of his passport. This was indexed by a search engine for anyone to view and copy
The firm claims to have $500m under management, with its investors including sovereign wealth funds, prominent financial institutions, corporations and family offices. One of its investors is Rothschild & Co, the well-known investment bank. While Rothschild did not respond to our request for comment, it did pass El Reg 's request to the fund, alerting it to its Azure woes.
Azure blob misconfigurations have been rather lower profile than [7]publicised isses with AWS S3 buckets but, like Amazon, Microsoft has [8]rolled out tools for checking one's storage is secure . Such tools are only useful if they're actually, you know, used.
Last year an Automated Number Plate Recognition (ANPR) operator in the UK [9]left millions of CCTV images accessible online from an unsecured Azure blob that, like this fund's setup, had no login or authentication controls applied to it. ANPR typically works by applying image-recognition software to photos captured by bog-standard CCTV cameras; in that case the raw images were stored in a location that was accessible to anyone with a web browser.
Aaron Zander of HackerOne commented to The Register : "In the past year, hackers on the HackerOne platform earned $260,000 in bounties for misconfiguration-related vulnerabilities."
Just because it ain't AWS doesn't mean it can't be left unsecured. ®
Get our [10]Tech Resources
[1] https://regmedia.co.uk/2020/11/27/auscap1.jpg
[2] https://regmedia.co.uk/2020/11/30/fundregisterofmembers.jpg
[3] https://www.ogier.com/publications/cayman-islands-exempted-companies
[4] https://regmedia.co.uk/2020/11/30/fundbankstatementredacted.jpg
[5] https://regmedia.co.uk/2020/11/30/fundsharecertificate.jpg
[6] https://regmedia.co.uk/2020/11/30/fundpassportscan.jpg
[7] https://www.theregister.com/2020/08/03/leaky_s3_buckets/
[8] https://www.theregister.com/2020/05/18/security_roundup/
[9] https://www.theregister.com/2019/09/20/tesco_parking_app_10s_millions_anpr_photos_exposed/
[10] https://whitepapers.theregister.com/
"When a firm is dependent on IT it's an IT business"
Change IT to electricity - does that still work?
Does electricity have the same risk profile?
It does if you’re the electrician or company installing it, some severe penalties for not following national standards and laws.
Like with electricity: pick a provider that does not leave you in the dark.
(sorry)
The challenge is that nowadays electricity providers are pretty much all very similar. There are way fewer that should be roundin' up cattle (or behave like they would) when compared with IT service providers. The standards for the first are well established. Clearly IT service providers should be certified to a similar level of standards, but many are not and many companies select their IT provider solely on the price. For electricity this works (mostly), nobody is going to install a substandard power line to your house, as there are enforcable rules about that.
"When a firm is dependent on IT it's an IT business"
Change IT to electricity - does that still work?
No, because they don't have to reconfigure the fuse box whenever someone plugs a new table lamp in, nor do they have to worry about Russian hackers gaining control of the kettle if they accidentally leave an MCB socket empty.
The difference being that if you're going to put in a ring main, you have to get an electrician in to do it, which helps prevent you from electrocuting yourself.
If you put all your data into "the cloud", all you need is a means of payment, you don't need to get an IT professional to do it (and many businesses see IT people as an unnecessary expense). This then results in the metaphorical equivalent of standing in a bucket of water while licking a frayed HV cable.
The situations with electricans isn't that different to IT providers. There are qualified and unqualified people around willing to do a job. You can do it yourself - all the necessary parts & tools available at B&Q etc . I believe the legal requirement (in UK) is to have the finished work certified by a registered electrician & I dare say there are also people ready to save you the trouble there and give you a nice piece of paper. The building trade was famed for "cowboys" well before IT got going after all.
Investment management was a thing in the era of ink and quill pens. If computer hardware and software vanished tomorrow, it would still be a business. They've tried to use IT and someone has effed up on their behalf, that doesn't make them an IT business.
The idea that a business is an IT business because it uses IT heavily is promoted to puff up normal run of the mill companies as future Amazons, because being a property firm, taxi firm or pharmaceutical company (*) isn't sexy enough.
* you know who they are
Let's take pharmaceuticals - my daughter works in clinical trials.
You might think that the end product is a medicine. So it is, but before that hits the prescription pads e-prescriptions there's another product - a huge stack of documentation to be submitted for approval. That documentation isn't collated by sorting through bits of paper, it's put together on computers including laptops of people like my daughter.
Those laptops are going to contain personal information about the trial patients - subject to GDPR - and including medical history. I'm not familiar with the regulations regarding that but I assume that it is subject to regulation over and above GDPR. The results of the trial will affect the share price so it's going to be subject to financial regulation as well. Beside all that the fact that it's also company commercial in confidence information is almost a minor consideration. As the trials workers are apt to be based where the patients are and not necessarily in head office there's also a need for secure communications with HO.
Any pharmaceutical business that doesn't think it isn't also an IT business to handle all that with an appropriate degree of securely needs to think again.
it's put together on computers including laptops of people like my daughter.
Those laptops are going to contain personal information about the trial patients - subject to GDPR
Fully-encrypted laptops, one hopes?
"Hi, you've been hacked"
In fairness I think I'd auto-delete an email telling me I'd been hacked - I get too many of them already, usually telling me that my non-existent webcam has caught me engaging in things I don't do.
Re: "Hi, you've been hacked"
Of course you dont do them. Sure....
We've all seen the pics Cederic, dont try and deny it. But if you dont want me posting them to Pornhub, please send 100 Bitcoin to the following address....
Re: "Hi, you've been hacked"
For 100 Bitcoin I'll create the pictures and post them myself!
Re: "Hi, you've been hacked"
The the question isn't really about whether you do it or not, but how much you charge?
Oops.
I wonder how many tax authorities have spotted it.
Would it be possible to pass all these data to the tax authorities worldwide? Just in case someone used this fund located in a tax heaven to avoid to pay his / her fair share of taxes.
Not every investor is a low-life weasel paying 2 quid tax on every 200 million earnings, a lot do pay their share but they have the money to minimise their tax bills. The right school, the right nobby friends and we'd all be doing it!
Don't Panic ...... There's Really Nothing to Worry About from Here to Where We're All Going .....
.... I Kid U Not
The unnamed fund's incident response consisted of disregarding the initial notification from The Register before asking a staffer with a compsci degree if he thought there was cause for concern. Luckily, that person realised what we were trying to tell them.
What would you tell them now El Reg with regard to utilisation and exploitation of compsci degree level concerns ......in ACTive Virtual Applications with Monied Investors ....... Cyber Business Angels ......... Absolute Daemons?
Would you tell not to worry, for there are no problems to boot and repeat/reboot and introduce ....... Present? That would be Helpful and Prescient and probably something Quite Entirely Different ..... Novel and Noble .... and NNobeling? :-) Now there's an Almighty Indulgence questioned for its True Worth and Perceived Value right there, slap bang in the middle of this descriptor paragraph.
Re: Don't Panic ......
My hovercraft is also full of eels.
Stop calling it cloud
this gives them non techys a fluffy feeling of something up there that no-one has access to ...
the reality is more like leaving it in some blokes lockup on an industrial estate
you wouldnt store anything there without checking the security out....
Re: Stop calling it cloud
Except in this case the "lockup" hasn't actually got a padlock on it, so it's more an "unlockup"
any other small firm whose think their main business is not focused on IT
When a firm is dependent on IT it's an IT business whether it thinks it is or not. This sort of thing is the result of thinking it isn't.