Connect with us

Infosecurity

Visual Hacking: The Overlooked Security Threat in Financial Services

Published

on

The Silent Data Breach: When a Glance Becomes a Theft

Imagine walking through a bank’s open-plan office. You see rows of monitors displaying account numbers, transaction details, and client information. Now picture doing the same in a coffee shop, where a financial advisor reviews portfolios on a laptop. This isn’t just a privacy concern—it’s a direct security vulnerability called visual hacking.

Financial services firms face immense pressure to protect sensitive data. Regulatory fines, reputational damage, and client trust hang in the balance. While most security budgets focus on digital threats like malware or phishing, a simpler danger often goes unaddressed: someone simply reading what’s on the screen.

It happens more easily than you might think. A recent study found that white-hat hackers attempting visual intrusions succeeded nearly 90% of the time. No malware required, no passwords cracked—just observation.

Why Financial Institutions Are Legally Exposed

Visual hacking isn’t just a theoretical risk; it’s embedded in financial regulations. The Information Commissioner’s Office (ICO) explicitly states in its Data Protection Guide that organizations must position computer screens so they cannot be viewed by casual passers-by.

Although the Financial Services Authority (FSA) no longer exists, its guidance continues to influence the Financial Conduct Authority’s (FCA) penalty decisions. Years ago, the FSA warned specifically about the risk of “high-end mobile phones” being used to photograph customer data displayed on screens.

The legal framework is clear. Under the Financial Services and Markets Act 2000, companies must demonstrate they “took all reasonable precautions and exercised all due diligence.” Failing to address visual privacy could mean failing this test.

Penalties matter. While large banks might absorb ICO fines, smaller financial firms could face devastating million-pound penalties. With the EU pushing for stricter sanctions, prevention isn’t optional—it’s essential.

Practical Defenses Against Shoulder Surfing

The good news? Visual hacking is one of the easiest security threats to mitigate. Awareness alone makes a significant difference. Training staff to be mindful of their screen’s visibility—whether at their desk or in a public space—creates a first line of defense.

Basic technical measures help too. Enforcing screen savers with short timeouts and mandatory logins prevents unattended displays from becoming data leaks. These are simple, low-cost policies with immediate impact.

For stronger protection, privacy filters offer a robust solution. These thin films attach directly to screens, using micro-louver technology to narrow the viewing angle. Information becomes visible only to the person sitting directly in front of the monitor.

Anyone viewing from the side—a colleague walking by, someone at the next café table—sees only a darkened or scrambled screen. The filters also provide physical protection against scratches, and they can be easily applied or removed as needed.

Integrating Visual Security into a Broader Strategy

Visual privacy shouldn’t exist in isolation. It’s one component of a layered security approach that financial institutions must adopt. Think of it as the physical counterpart to digital encryption.

Mobile workforces increase the risk exponentially. Laptops, tablets, and smartphones display sensitive data everywhere—from trains to client offices. A privacy filter transforms any device into a secure workstation, regardless of location.

Implementing these measures demonstrates proactive compliance. It shows regulators and clients that an organization considers every vector of data exposure, not just the obvious digital ones.

In an industry built on trust, controlling what meets the eye isn’t just about avoiding fines. It’s about upholding the fundamental promise of confidentiality that defines financial services.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

China and India ran separate spying campaigns against the same Pakistani police force

Published

on

Pakistani police spying

Two rivals, one target: Balochistan Police

For more than two years, hacking groups tied to China and India ran separate, unconnected espionage operations against the same Pakistani police force. Sometimes they even broke into the exact same systems.

That’s the finding from cybersecurity firm SentinelOne, which published research Thursday detailing the parallel campaigns. The activity ran between February 2024 and April 2026, according to the company’s SentinelLabs research arm.

The target: the Balochistan Police, the force responsible for Pakistan’s southwestern province. That region has been the site of a long-running separatist insurgency, making its police networks a rich prize for intelligence agencies.

Why police networks are such a tempting target

Police networks concentrate a government’s internal-security data in one place. That’s the core insight from SentinelLabs. The compromised systems held criminal records, biometric and fingerprint data, personnel files, hotel and tenant registrations linked to national identity records, and citizen complaints.

Think about what that means. Anyone with access to those systems could identify police officers, track their movements, and potentially compromise them. They could also monitor the local population in a province already simmering with unrest.

The China connection: protecting CPEC interests

The researchers assess that the China-nexus interest was driven primarily by protecting Beijing’s nationals in Pakistan tied to the China-Pakistan Economic Corridor. That’s the massive infrastructure project that’s a cornerstone of Chinese influence in the region.

The report cites a March 2024 suicide bombing and an October 2024 attack near Karachi’s airport as incidents affecting Chinese workers. Those attacks highlighted the security risks facing Chinese nationals in Pakistan.

According to SentinelLabs, the intrusions reflect an effort to assess the threat independently rather than rely on Pakistani security guarantees. In other words, Beijing wanted its own picture of the danger, not just Islamabad’s assurances.

The India angle: rivalry and insurgency

The India-linked activity was likely tied to the rivalry between the two countries, the report assessed. That’s a fraught relationship, to say the least.

Islamabad accuses New Delhi of backing the Baloch insurgency and describes the Balochistan Liberation Army as an “Indian proxy.” India makes parallel accusations over Kashmir. Both governments deny the other’s claims.

SentinelLabs said access to Balochistan Police data would provide visibility into that conflict. For India, that could mean insight into insurgent activities and Pakistan’s counterinsurgency efforts.

How the hacks worked

The report describes the compromise of the Balochistan Police Complaint Management System, a portal used by officers behind a login and by citizens checking the status of complaints.

Here’s where it gets clever. A China-linked operator planted malware disguised as a portal update. The executable displayed a fake “update complete” message while infecting the visitor’s device.

Because both police and members of the public use the site, the tampered portal exposed both groups. That’s a wide net, catching everyone from officers to ordinary citizens filing complaints.

The researchers said forensic traces in the code, including Chinese-language log strings and developer artifacts, indicated a Chinese-speaking author. That’s a pretty strong signal.

Attribution: clusters, not names

Rather than name specific groups, SentinelLabs sorted the activity into clusters by toolset. That’s a more cautious approach than some firms take.

Backdoors shared among Chinese groups, including PlugX and ShadowPad, anchored the China-nexus assessments. The victim pattern also spanned Asian governments and, in one case, Tibetan organizations in Taiwan.

The India-nexus intrusions were tied with lower confidence to an actor the researchers track as TAG-179. That overlaps with clusters others call Bitter and Mysterious Elephant. Part of the evidence: a lure document themed around the repatriation of undocumented foreigners.

The bigger picture: Pakistan’s digitization push

The researchers noted that as Pakistan centralizes and digitizes its policing, supported in part by European modernization programs, it will continue to concentrate high-value data that adversaries may target.

That’s a worrying trend. The more data gets digitized and centralized, the bigger the prize for hackers. And with two nuclear-armed rivals both running espionage campaigns, the stakes are enormous.

Both Pakistan and India are alleged to have conducted cyber espionage campaigns against each other, with attacks targeting Indian government, academic and strategic institutions, as well as Pakistani government agencies and critical infrastructure operators. This latest report shows that the espionage isn’t just about governments — it’s about police forces on the front lines of internal security.

For anyone tracking cyber espionage in South Asia, this is a significant development. It shows that even a provincial police force isn’t off-limits when national rivals are involved.

Continue Reading

Infosecurity

ICO Tells Police Forces to Tighten Data Governance as Facial Recognition Rollouts Accelerate

Published

on

data governance in facial recognition

A Watchdog’s Warning

The UK’s data protection regulator has a blunt message for police forces embracing live facial recognition: your paperwork isn’t keeping up with your technology.

In an article published on August 18, Emily Keaney, deputy commissioner for regulatory policy at the Information Commissioner’s Office (ICO), noted that a growing number of forces are deploying the tech with zero prior experience of using it in public. Some are even experimenting with operator-initiated facial recognition — where officers stop someone on the street and instantly cross-check their face against a watchlist.

That’s a powerful tool, but it’s also a risky one. As Keaney put it: “A false match can have serious consequences for people, including wrongful intervention, accusation or arrest.”

What the Audits Found

To gauge how forces are handling these risks, the ICO audited five police forces across England and Wales. The results, published this week, paint an uneven picture.

“Our audits reveal inconsistencies in data protection compliance across the five forces audited,” Keaney said. “While there was some good practice, significant improvements are still needed.”

Compliance rates were actually higher for live facial recognition (LFR) than for retrospective facial recognition (RFR), which involves scanning stored images after the fact. But in both cases, the ICO flagged several recurring gaps:

  • Insufficient senior oversight, accountability, and training for staff using the technology
  • Poor record-keeping about what personal data is used, where it comes from, and who it’s shared with
  • RFR images sometimes sourced from questionable places and kept longer than necessary
  • Inadequate checks on system accuracy and bias

The last point stings, given a Home Office report on police facial recognition bias published in December 2025. That report found that, in certain situations, the algorithm was more likely to incorrectly include some demographic groups in its search results. Keaney said at the time that the ICO required “urgent clarity on this matter.”

Why Governance Matters

You might wonder: why is the ICO so focused on administrative details like record-keeping? Because, as the regulator argues, public trust is the foundation for any sustainable use of facial recognition in policing. If people believe the system is sloppy or biased, they won’t accept it — no matter how effective it is at catching criminals.

There’s also a legal dimension. The EU AI Act largely prohibits police use of live facial recognition in public spaces, and while the UK has its own path, the ICO’s guidance signals that British regulators expect similar caution.

Next Steps for Police

The ICO says forces have been “willing to engage and make changes” based on the audit findings. That’s encouraging, but the regulator is clear that more work is needed before LFR becomes a standard policing tool.

For forces looking to get ahead of the curve, the ICO’s recommendations boil down to a few practical actions:

  1. Appoint a senior officer responsible for FRT oversight and ensure all staff are properly trained
  2. Maintain clear, auditable records of every use of the technology
  3. Source RFR images only from approved channels and delete them promptly
  4. Regularly test systems for accuracy and bias, and document the results

These aren’t glamorous tasks, but they’re the difference between a tool that protects the public and one that undermines civil liberties. As the ICO’s Keaney put it, strong data protection governance is essential to fostering the trust that facial recognition needs to flourish as a policing tool.

For more context on how these issues are playing out elsewhere, read about the landmark court ruling on police facial recognition and the Home Office’s findings on racial bias in RFR systems.

Continue Reading

Infosecurity

Medusa Ransomware Breaches 500+ Critical Infrastructure Organizations, FBI Warns

Published

on

Medusa ransomware

Medusa Ransomware Expands Its Reach

The FBI, CISA, and the Department of Health and Human Services have issued a joint advisory revealing that Medusa ransomware has now impacted over 500 critical infrastructure organizations as of April 2026. That’s a significant jump from the 300 organizations reported in a March 2025 advisory, which covered activity through February 2025.

The updated warning, published August 18, singles out healthcare as a particularly frequent target. The advisory notes that Medusa actors have been opportunistic, going after victims with unpatched software rather than focusing on specific sectors. But the numbers suggest healthcare has borne the brunt.

Medusa first appeared in June 2021 as a closed operation, then shifted to an affiliate model by early 2023. Since then, it’s evolved into one of the more active ransomware-as-a-service (RaaS) groups around.

Exploiting Vulnerabilities at Breakneck Speed

Unpatched vulnerabilities remain Medusa’s primary entry point. What’s changed is the speed. The advisory says the group has been observed using exploits within 24 hours of public disclosure — often before victims even have a chance to patch.

In some cases, Medusa actors have leveraged exploits up to a week before the vulnerability is publicly announced. That’s a troubling timeline for defenders.

There’s no evidence Medusa develops its own zero-days. Instead, they’re fast followers, weaponizing known flaws quickly and moving on.

Nick Tausek, lead security automation architect at Swimlane, says this speed is creating real problems for security teams. “Shrinking windows put far more pressure on defenders to identify and remediate exposed systems before Medusa can take advantage. Dangerous levels of speed can turn a newly disclosed flaw into an active intrusion before many security teams have even finished assessing their exposure,” he commented.

Interactsh and Verification Tactics

The group has also adopted Interactsh dynamic URLs to verify successful exploitation. This lets them identify compromised hosts and confirm their foothold before moving deeper.

Stealthier Post-Exploitation and Lateral Movement

Medusa’s post-exploitation game has improved significantly. The advisory describes multiple PowerShell stealth techniques of increasing complexity, used to obfuscate payloads. They even delete PowerShell command history to cover their tracks.

New tools are in play for command and control (C2) and stealth. Publicly available tools like Nezha, an operations and maintenance server monitoring tool, give them backdoor visibility into compromised hosts. GSocket allows workstations on different private networks to connect and bypass firewalls.

The group also deploys legitimate remote monitoring and management (RMM) software, often selecting tools already present in the victim’s environment to avoid detection. These are used to move laterally and identify files for exfiltration.

Credential theft has gotten more aggressive. The advisory notes the use of Windows Task Manager Mimikatz to harvest credentials directly from the LSA authentication mechanism, recording plaintext passwords to a log file.

Andrew Costis, engineering manager at AttackIQ, highlighted the implications. “The group is blending legitimate remote management tools into its operations while using new credential theft methods and overriding security policies to maintain access,” he said.

“Stolen Active Directory files are especially concerning because they can be used to forge Kerberos tickets. At that point, Medusa isn’t just encrypting systems. It can potentially impersonate trusted users and move through an entire domain with far fewer obstacles.”

Exfiltration and the Double-Extortion Model

Medusa’s exfiltration playbook is well-established. They use Bandizip to create archives of stolen files and Rclone to move data to their C2 servers, obfuscating rclone.exe and related .conf files by renaming them.

Secure file transfer protocol (SFTP) is used to deliver the encryptor to victim machines. Encrypted files get a .medusa extension. The malware terminates all services, deletes shadow copies, and drops a ransom note.

This enables a double-extortion model: victims pay to restore systems and data, and to prevent stolen data from being published online. The ransom note demands contact within 48 hours. If victims don’t respond, Medusa actors often reach out directly via phone or email.

Ransom demands are posted on Medusa’s leak site, complete with direct hyperlinks to Medusa-affiliated cryptocurrency wallets.

FBI Urges Incident Response Readiness

Beyond prevention, the advisory stresses the need for effective incident response. Security teams should be ready to act when an intrusion occurs, not just before.

Recommended actions include:

  • Use threat hunting to scope the intrusion, including logs left behind by threat actor tooling
  • Remove C2 software like Nezha or any other remote access method used by the organization
  • Remove local administrator accounts and rotate credentials for service accounts and domain administrator accounts
  • Ensure the initial intrusion CVE is patched
  • Use CISA’s Eviction Strategies Tool to assemble countermeasures for a systematic eviction plan

For organizations worried about their exposure, the advisory is a reminder that patch management alone isn’t enough. Speed matters, but so does having a plan for when defenses fail. The FBI’s latest Medusa ransomware advisory offers concrete steps, and security teams should review it closely.

If you’re in healthcare, the stakes are especially high. The sector’s reliance on legacy systems and connected medical devices makes it a prime target. Reviewing healthcare ransomware defense strategies could help close gaps before attackers find them.

And for those tracking broader trends, the rise of ransomware-as-a-service operations shows no signs of slowing. Medusa is just one example of how these groups evolve, adapt, and keep pressure on defenders.

Continue Reading

Trending