Monday, March 2, 2015



Complete DHS Report for March 2, 2015

Daily Report

Top Stories

· A former American Pension Services executive was indicted in a U.S. District Court in Utah February 26 for allegedly running a scheme that defrauded over 5,000 customers out of approximately $24 million by fraudulent representations of material facts to obtain the funds used to make personal investments. – KSTU 13 Salt Lake City See item 9 below in the Financial Services Sector

 · A failed bleach pump at the Fall River Regional Wastewater Treatment in Massachusetts prompted the discharge of an estimated 600,000 gallons of non-disinfected wastewater to spill into Mount Hope Bay February 25. – Fall River Herald News

16. February 27, Fall River Herald News – (Massachusetts; Rhode Island) Fall River wastewater plant fails, spills 600,000 gallons into Mount Hope Bay. According to the Rhode Island Department of Environmental Management (DEM) a failed bleach pump at the Fall River Regional Wastewater Treatment in Massachusetts prompted the discharge of an estimated 600,000 gallons of non-disinfected wastewater February 25. The spill prompted the DEM to close both Mount Hope Bay and Kickemuit River to shellfishing until March 5 after technicians rebooted the computer system and restarted the pumps. Source: http://www.tauntongazette.com/article/20150226/NEWS/150227201

 · The Lee Correctional Institution in South Carolina was under lockdown for 9 hours after several inmates attacked 7 guards February 26. – WCBD 2 Charleston

20. February 26, WCBD 2 Charleston – (South Carolina) 9-hour lockdown ends after guards attacked at SC prison in Lee County. The Lee Correctional Institution in Bishopville was under lockdown for 9 hours after several inmates attacked 7 guards February 26. Guards secured an inmate dorm after a prison staff member tried to search an inmate, resulting in several inmates attacking the officer. Source: http://www.counton2.com/story/28214754/sc-prison-in-lee-county-on-lockdown-after-hostage-reports

 · The Federal Communications Commission (FCC) approved net-neutrality regulations February 26 that gives the government expanded power over Internet access and allows the FCC to bar Internet providers from practices that unreasonably interfere with the ability to reach web services for users. – Nextgov See item 24 below in the Information Technology Sector

Financial Services Sector

8. February 26, Kent Reporter – (Washington) Two Kent residents indicted as part of large bank fraud ring. A 10-member bank fraud ring in Washington was indicted during the week of February 23 for allegedly using stolen checks from 7 banks to make fraudulent deposits into 219 different bank accounts to inflate the bank accounts and withdraw more than $987,000 in cash from November 2010 to present. Source: http://www.kentreporter.com/news/294295531.html

9. February 26, KSTU 13 Salt Lake City – (Utah) Draper man indicted for 15 counts of mail fraud after allegedly misappropriating $24 million. A former American Pension Services executive was indicted in a U.S. District Court in Utah February 26 for allegedly running a scheme from 1998-2014 that defrauded over 5,000 customers out of approximately $24 million by using false and fraudulent representations, promises, and omissions of material facts to obtain the funds that were used to make personal, high-risk investments. Source: http://fox13now.com/2015/02/26/draper-man-indicted-for-15-counts-of-mail-fraud-after-allegedly-misappropriating-24-million/

Information Technology Sector

22. February 27, Softpedia – (International) Apps bypass Google Play verification and spew tempest of ads. Bitdefender security researchers discovered 10 apps hosted in Google Play that use social engineering to trick users into installing ad-spewing software and relied on deceptive tactics to ensure persistence on users’ devices. None of the apps linked to Web sites hosting malware, allowing the apps to bypass Google Play quality controls. Source: http://news.softpedia.com/news/Apps-Bypass-Google-Play-Verification-and-Spew-Tempest-of-Ads-474466.shtml

23. February 27, Securityweek – (International) Critical vulnerability found in Jetty web server. Security researchers from Gotham Digital Science discovered a critical vulnerability dubbed JetLeak in the Eclipse Foundation’s Jetty Web server that allows remote, unauthenticated attackers to read arbitrary data from requests previously submitted by users to the server, including cookies, authentication tokens, anti-CSRF tokens, usernames, and passwords. The flaw was addressed February 24 with the release of Jetty version 9.2.9 while the Jetty development team reported an anticipated fix for the vulnerability in version 9.3.0. which is in beta. Source: http://www.securityweek.com/critical-vulnerability-found-jetty-web-server

24. February 26, Nextgov – (International) It’s official – FCC enacts expansive net-neutrality rules. The Federal Communications Commission (FCC) approved sweeping net-neutrality regulations February 26 that gives the government expanded power over Internet access, and allows the FCC to bar Internet providers from blocking Web sites, selectively slowing down any content, or offering bandwidth increases for specific content with payment. The rules also classify the Internet as a telecommunications service under Title II of the Communications Act. Source: http://www.nextgov.com/cio-briefing/2015/02/its-officialfcc-enacts-expansive-net-neutrality-rules/106242/

Communications Sector

See item 24 above in the Information Technology Sector

Friday, February 27, 2015



Complete DHS Report for February 27, 2015

Daily Report

Top Stories

 · A 30-mile stretch of northbound Interstate 95 between Newport and Bangor, Maine was closed for approximately 5 hours February 25 due to a multi-vehicle crash caused by heavy snowfall that injured at least 17 people. – WLBZ 2 Bangor; Associated Press

6. February 25, WLBZ 2 Bangor; Associated Press – (Maine) I-95 in Maine partially reopened after 75-vehicle pileup. A 30-mile stretch of northbound Interstate 95 between Newport and Bangor was closed for approximately 5 hours February 25 due to a multi-vehicle crash caused by heavy snowfall that involved at least 75 vehicles and left at least 17 people injured. Source: http://www.usatoday.com/story/news/nation/2015/02/25/interstate-95-crash-maine/23989051/

 · About 12 ships, including a cruise ship, were stranded in the Gulf of Mexico outside Tampa Bay, Florida, while 10 cargo ships were unable to leave from Port Tampa Bay February 24 due to sea fog February 23 that prompted the port to come to a near standstill. – Tampa Tribune

8. February 24, Tampa Tribune – (Florida) Cruise ship returns as fog halts port traffic. Nearly a dozen ships, including a cruise ship, were stranded in the Gulf of Mexico outside Tampa Bay while 10 cargo ships were unable to leave from Port Tampa Bay February 24 due to sea fog February 23 that prompted the port to come to a near standstill. The Royal Caribbean cruise ship was escorted to the port by U.S. Coast Guard vessels while freighters and tankers were ordered to remain in the Gulf until the fog cleared. Source: http://tbo.com/news/transportation/fog-closes-tampa-port-strands-cargo-ships-buckeye-cruise-20150224/

 · Officials announced February 26 that vandalism caused an Internet, cellphone, and landline outage in northern Arizona for more than 6 hours February 25 after CenturyLink employees and Phoenix police found a cut cable. – Associated Press

17. February 26, Associated Press – (Arizona) Arizona authorities probe vandalism that cut off Internet, phones for hours. Officials announced February 26 that vandalism caused an Internet, cellphone, and landline outage in northern Arizona for more than 6 hours February 25 after CenturyLink employees and Phoenix police found a cut fiber-optic cable. Crews restored services that impacted a 100-mile area stretching between Phoenix to Flagstaff. Source: http://www.foxnews.com/us/2015/02/26/arizona-authorites-probe-vandalism-that-cut-off-internet-phones/

 · A frozen water pipe burst inside the David Stott building in Detroit, Michigan, between February 22-23 causing about 2 million gallons of water ran throughout the structure unnoticed for approximately 1 day. – WWJ 62 Detroit

18. February 26, WWJ 62 Detroit – (Michigan) Cleanup continues at flooded David Stott building in Detroit. Cleanup crews continued working February 26 after a frozen water pipe ruptured inside the David Stott building in Detroit between February 22-23 and millions of gallons of water ran throughout the building unnoticed for approximately 1 day. About 2 million gallons of water was pumped from the building into the city’s sewer system February 25, while the bottom floor of the structure was reportedly still under water. Source: http://detroit.cbslocal.com/2015/02/26/cleanup-continues-at-flooded-david-stott-building-in-detroit/

Financial Services Sector

3. February 25, Associated Press – (Massachusetts) Founder accused of defrauding investors in $40M mutual fund. A Massachusetts financier was charged with securities fraud, wire fraud, aggravated identify theft, and obstruction of justice February 25 for allegedly issuing fictitious consumer loans as co-portfolio manager of GL Beyond Income Fund, and diverting the fund’s assets for use on business and personal expenses. Source: http://abcnews.go.com/US/wireStory/founder-accused-defrauding-investors-40m-mutual-fund-29226096

4. February 25, Reuters – (National) MetLife unit to pay $123.5 million for alleged mortgage fraud. The U.S. Department of Justice announced February 25 that Met Life Home Loans LLC will pay $123.5 million to resolve accusations that the company, doing business as MetLife Bank at the time of the alleged infractions, knowingly violated the False Claims Act from September 2008 to March 2012 by originating and underwriting mortgage loans insured by the Federal Housing Administration (FHA) that did not meet underwriting requirements. MetLife was allegedly aware of the accused violations through its internal quality control measures and reportedly downgraded its sub-standard FHA loans to appear to have fewer issues. Source: http://www.reuters.com/article/2015/02/25/us-metlife-usa-loans-idUSKBN0LT1ZR20150225

Information Technology Sector

16. February 26, Securityweek – (International) Lizard Squad hijacks Lenovo website, emails. Lizard Squad hackers hijacked the Lenovo Web site and email servers by using CloudFlare IP addresses to modify DNS records in Lenovo domain registrar accounts and redirect users to defacement pages, and changed mail server records to allow the group to intercept emails sent to Lenovo email addresses. The hijacking mirrored a similar attack that targeted Google Vietnam during the week of February 23. Source: http://www.securityweek.com/lizard-squad-hijacks-lenovo-website-emails

Communications Sector

17. February 26, Associated Press – (Arizona) Arizona authorities probe vandalism that cut off Internet, phones for hours. Officials announced February 26 that vandalism caused an Internet, cellphone, and landline outage in northern Arizona for more than 6 hours February 25 after CenturyLink employees and Phoenix police found a cut fiber-optic cable. Crews restored services that impacted a 100-mile area stretching between Phoenix to Flagstaff. Source: http://www.foxnews.com/us/2015/02/26/arizona-authorites-probe-vandalism-that-cut-off-internet-phones/

For another story, see item 15 below from the Emergency Services Sector

15. February 26, Yavapai County Daily Courier; Chino Valley Review – (Arizona) Prescott-area police, fire, 911 service hit hard by outage. Emergency 9-1-1 calls to the Prescott Regional Communications Center in Arizona were rerouted February 25 to the backup dispatching center at the Yavapai County Sheriff’s Office after a CenturyLink fiber cable near New River was damaged causing an Internet and telephone outage. The Chino Valley Police Department was also impacted by the outage, along with the sheriff’s office in Yavapai County which suffered landline and Internet outages. Source: http://dcourier.com/main.asp?SectionID=1&SubSectionID=1&ArticleID=142272