P19 what were up against why good guys do bad things_sherri davidoff_6.12.19
1. What We’re Up Against:
Why Good Guys Do Bad Things
Sherri Davidoff, GCFA, GPEN
LMG Security & BrightWise
June 12, 2019
2. Who Am I?
§Sherri Davidoff
§“Alien” of “Breaking and Entering”
§18 years as a cybersecurity professional
§CEO of LMG Security and BrightWise
§Training: Black Hat, FFIEC/FDIC,
American Bar Association, DoD & more
§COMING SOON! Data Breaches book
2
www.LMGsecurity.comCopyright LMG Security 2017. All rights reserved.
3. www.LMGsecurity.comCopyright LMG Security 2017. All rights reserved. 3
“A trip to Temkin’s is a trip back in time. Abe
was born in this building in 1922. He and his
wife, Annabelle, and daughter Sheila
provide old-fashioned customer service.” –
The Trenton Times, August 9, 1989
Roots
4. §State of Retail Cybersecurity
§The Latest Epidemic – Banking
Trojans
§Protect Yourself & Your Community
Roadmap
www.LMGsecurity.comCopyright LMG Security 2019. All rights reserved. 4
5. POS Hacks are Down… but Not Out
www.LMGsecurity.comCopyright LMG Security 2017. All rights reserved. 5
6. Ecommerce Hacks are On The Rise
www.LMGsecurity.comCopyright LMG Security 2017. All rights reserved. 6
https://arstechnica.com/information-technology/2019/05/more-than-100-commerce-sites-infected-with-code-that-steals-payment-card-data/
11. The Cybersecurity Ecosystem
§Customers get hacked
§Vendors get hacked
§Due to security issues on
their OWN networks
§Retailers lose $$ and
reputation
11
14. §Steal your passwords
§Hijack your online accounts
§Steal your payment card
numbers
§Steal your data
§Control your computer
§Install more malware!
What Can Banking Trojans Do?
www.LMGsecurity.comCopyright LMG Security 2019. All rights reserved. 14
23. I Know Your Balance
www.LMGsecurity.comCopyright LMG Security 2019. All rights reserved. 23
Infected
computers
Web sites
Account Balances
Image source: Manual for Citadel malware
26. All Your Passwords are Belong to Me!
www.LMGsecurity.comCopyright LMG Security 2019. All rights reserved. 26
Cached Password stolen
from Internet Explorer