08.04.2016

Lessons from Mossack Fonsseca security breach

Lessons from Mossack Fonsseca security breach

twitter icon
Mossack Fonseca Law Firm Breach Reveals Amazingly Lax Network Security

 
The quantity of information taken in the breach of the Mossack Fonseca law firm far exceeds the amount taken by Edward Snowden. The big question is “how this could happen?”

While the details of the attack on Mossack Fonseca haven’t been fully revealed, there is lots in the newspapers reporting details about prominent people who have offshore financial accounts. The really important question however is still “how could this happen?”

What’s clear is a fundamental lack of even the most basic attempt at protecting the firm’s client data.

The firm’s founding partner, Ramon Fonseca, has revealed in an interview that the attack that allowed hackers to make off with over two terabytes of sensitive scans, document images and other information and was an external hack. He said that this was not an inside job. That’s a surprising confession, made only a couple of days after the hack was discovered, and after the contents of the firm’s files were published far and wide in newspapers and on Websites.

So, what did happen then? I’m pretty sure that Mossack Fonseca was the victim of a phishing attack, with an email that released malware that opened up access to the firm’s network. That would make Fonseca’s statement correct, since it doesn’t appear that an insider knowingly unleashed the malware or emailed the data to co-conspirators.

Well placed emails were all that was required to carry out the recent spate of CEO spear-phishing attacks that have recently struck companies of all sizes. A senior person at a company gets an email with a plausible request for information that seems to be from someone they know. The executive provides the requested information and clicks. That’s all it takes.

It’s very easy because lots of senior staff, and indeed staff at all levels, have very little training in security awareness and how to spot plausible phishing emails. Many breaches can be avoided with some fairly straightforward training in recognizing a phishing or malware attack.

 Protecting access is very important, however it doesn’t really matter how access was gained, because once inside the system the hackers seemed able to take data at will. Apparently none of it was segmented, none seemed to have access restricted to specific people, none of it was encrypted and apparently nobody was paying attention to the network traffic. How else can you explain how over two terabytes of data was extracted from the company’s network with no one noticing?

But much of the blame at the firm goes beyond just training employees. It seems there was nothing to prevent someone who had access to the network from getting anywhere on the network they wanted, including some highly sensitive areas that contained the private information of clients. Worse still, there appears to have been nothing in the way of intrusion detection. How can someone move that much data out of a network without anyone noticing? Even if someone had walked into the law firm’s office with a portable hard drive and started copying, the process would have taken hours. If the breach was done remotely as the firm claims, it could have taken days to siphon off all that data.

Regardless of how the perpetrators breached the network, the fact is that lax security practices at Mossack Fonseca must have played a role. Were the files encrypted?

There are important lessons in the Mossack Fonseca breach, not the least of which is to pay more than lip service to security. Even if it’s not possible to eliminate all server breaches, it’s still possible to limit the damage by ensuring user passwords are strong and changed frequently, and that data is stored in an encrypted format.

Ironically, from just £15 a month, the The Cloud 9 Vault system could possibly have provided more security than Mossack Fonseca had in place.

Graham Saul
www.cloud9vault.net


 

 

Welcome to Cloud 9

Cloud 9 is a hosting solution designed for small and medium business. Software applications are…

Follow us for more articles and posts direct from professionals on      

Developing properties developing lives

Developing Properties, Developing Hope Why Housing for Vulnerable Young People Needs a Different Kind of Investor Over…
AI, Agentic AI, Ai adoption, Agentic automation

AI and Automation for single person businesses

I run an AI service business, and most of the people I work with are single-person companies. No teams. No layers. Just…
Outcome, Service as software

Service-as-Software: The Shift From Selling Tools to...

For most of the history of software, one assumption has remained remarkably stable. Software has always been a…

More Articles

Call Answering, Reception services

6 Signs You’re Ready for a Virtual Receptionist

    Running a small business often means wearing every hat in the company. You’re the owner, the salesperson, the…
Tax, HMRC, Crypto, CRYPTOCURRENCY

Crypto Assets and Capital Gains Tax: HMRC to Receive...

Starting 1 January 2026, crypto asset exchanges will be required to share information about their customers’ crypto…
Tax, Accountancy, Tax Allowances

Tax Free Christmas Activites and Parties - let the Taxman...

Before the Budget upsets the vibe, perhaps you want to get your Christmas activites and parties under way before next…

Would you like to promote an article ?

Post articles and opinions on Chester Professionals to attract new clients and referrals. Feature in newsletters.
Join for free today and upload your articles for new contacts to read and enquire further.