FB pixel

“Bumbling” NYPD contractor nearly infects fingerprint database with ransomware

“Bumbling” NYPD contractor nearly infects fingerprint database with ransomware
 

The New York Police Department is blaming a “bumbling” contractor for a ransomware infection of roughly two dozen devices connected to the department’s LiveScan fingerprint tracking system, CPO Magazine reports. The ransomware never executed, and the department’s database was reportedly saved by being taken offline overnight.

The infection spread accidentally from a computer used by contractor installing video equipment at a training facility, and was detected within a matter of hours, according to the article. The contractor had plugged an NUC mini-PC into the police network, and was referred to NYPD cyber command and a Joint Terrorism Task Force, though never charged with a crime. Software was reinstalled on some 200 computers system-wide, and the biometric fingerprint database was back up and running the next morning.

“The fact that the malware has worming capability, meaning it can spread from one computer to the next, is reminiscent of the WannaCry attack,” Juniper Threat Labs Head Mounir Hahad explained to CPO Magazine. “We do not know if this attack is WannaCry, but we should all remain cautious about the leftover infections. Threat researchers continue to see a healthy background noise of previously infected computers that continue to infect other devices using the EternalBlue exploit over the SMB protocol. Fortunately, they rarely trigger the encryption routines because of the presence of the kill switch domain.”

Had the attack been successful, it is likely that some or all of the data would have been lost, and possible that it would also be exfiltrated from the system, in what would have been the largest publicly-known theft of biometric data ever. Further, the NYPD kept a database of fingerprints from juvenile delinquency records in direct violation of state law until recently, according to The Intercept.

The NYPD destroyed the database in November, according to Legal Aid, which had been fighting the department over the retention of the data. How long records were accumulating in the database is uncertain, but Legal Aid lawyers estimate their may have been thousands of fingerprints retained illegally.

According to CPO Magazine, public institutions are increasingly targeted by ransomware attacks, and should all put policies and procedures into place to be ready to mount an attack response, as the NYPD was.

The NYPD has been lauded for its use of best practices in using facial recognition to conduct rapid investigations, but the department has also been accused earlier this year of violating best practices with its DNA and facial recognition systems.

Article Topics

 |   |   |   |   |   |   |   | 

Latest Biometrics News

 

Certification becoming trust signal for procurement and market positioning

One consequence of the explosion of synthetic media and AI-generated identities is that trusted identity infrastructure has become strategically valuable…

 

IAD testing set to take off as QTSP deadline passes, EUDI Wallet onboarding begins

Independent assessments of biometric injection attack detection (IAD) are about to become significantly more prominent, with the deadline for Qualified…

 

UK’s proposed OS-level age verification could eliminate part of DVS market

The UK government is mooting device-level restrictions on nude images that could usher in a new era of a kid-friendly…

 

UK promises age assurance for social media, device-level child safety controls

How many times can a head of government pledge to do something about harmful social media platforms before they’re obligated…

 

Aware upgrades biometric orchestration platform with ROC, Mitek integrations

Aware has added ROC and Mitek as biometric technology partners for its digital identity orchestration platform, Awareness, as part of…

 

Appeals board upholds 4 FaceTec biometric liveness detection patents

The U.S. Patent Trial and Appeal Board (PTAB) has ruled in a fight over intellectual property for biometric liveness detection between…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events