January 7, 2014

News from Adams Morgan businesses !

AMPBID Board Meeting on January 14 and Marketing Committee Meeting January 21

Holiday tree collection schedule - Mondays

Warning about theft from POS systems and best practices for businesses

CCTV Training Available on Februay 7, 2014 - FREE!

News from Adams Morgan businesses!

We will continue this section of the newsletter each week as long as we have content. Please send us anything you'd like us to mention.

1) CORRECTION: Cali Yogurt at 2473 18th Street, NW has closed and will reopen with new ownership under the name Spoon. We made a mistake and the new business is not affiliated with the national franchise called Spoon Me. Our apologies for the confusion.


They so still hope to be open in the next few weeks and their hours will be Monday-Thursday from 11 am to 11 pm and Friday/Saturday 11 am to 12 midnight, Sundays from 11 am to 9 pm. They will sell yogurt, ice cream, sandwiches, salads and desserts.

2) New business opening in Adams Morgan (just outside the BID boundaries). Prince of Petworth reported yesterday that there is a new gym opening in the vacant corner space near the Harris Teeter Grocery Store.

Cross Fit Hierarchy

1681 KALORAMA RD NW

WASHINGTON, DC 20009

info@crossfithierarchy.com

202.664.3660 phone

From their website http://crossfithierarchy.com/ :

Opening Day is this Saturday January 11th! Come check us out during our Open House, which will feature a WOD for veteran CrossFitters at 11:00am and a free intro class for those new to CrossFit at 1:00pm. Not up for a workout? Feel free to swing by anytime to check out the gym and get to know our awesome coaches.

The official launch party is February 1 at 11:00am! Help us celebrate our grand opening and get to know our awesome community with a workout + BBQ. Everyone is invited, so bring family and friends–the more the merrier! No RSVP necessary. RSVP: info@crossfithierarchy.com

AMPBID Board meeting January 14 and Marketing Committee meeting January 21


T he next Adams Morgan Partnership BID (AMPBID) Board of Directors' meeting will be Tuesday, January 14, 2013 at 5 PM at Maga Design Studios at 1838 Columbia Road, NW.

The December meeting was canceled because of weather so the agenda will be pretty much the same: Lt. John Kutniewski from MPD has been invited to join us to tell us more about the nightlife training for MPD officers.  Also representatives from AFLAC will be there to tell us about their services for employees. AFLAC is supplemental insurance employers can offer employees. Employees pay the full cost. Kristen will also update the board on proposed changes to Circulator Bus service and other surface transit changes.

Hope you can join us!

Board members: Please call or email Kristen at 202-997-0783 or kbarden@adamsmorganonline.org if you are unable to attend otherwise we will assume you are attending. Thanks.

Marketing Committee Meeting - January 21 at 2 pm.  If you would like to participate, please contact Kristen at 202-997-0783 or by email: kbarden@adamsmorganonline.org for the call in numbers.

Holiday tree collection schedule -Mondays

As a reminder, our Clean Team will collect discarded holiday trees on Mondays for the next few weeks from the commercial corridor and limited side streets in Adams Morgan.

If you would like us to collect your tree, please put it in the tree box on Sunday evenings. Thanks.

Warning about thefts from POS systems and best practices for businesses

After the publicity around the Target Stores credit card data theft just before the holidays, we thought it might be helpful to share with our members the following advisory that we recently received.

This advisory was prepared in collaboration with the National Cybersecurity and Communications Integration Center (NCCIC) and United States Secret Service (USSS).

When consumers purchase goods or services from a retailer, the transaction is processed through what are commonly referred to as Point of Sale (POS) systems. POS systems consist of the hardware (e.g. the equipment used to swipe a credit or debit card and the computer or mobile device attached to it) as well as the software that tells the hardware what to do with the information it captures.

When consumers use a credit or debit card at a POS system, the information stored on the magnetic stripe of the card is collected and processed by the attached computer or device. The data stored on the magnetic stripe is referred to as Track 1 and Track 2 data. Track 1 data is information associated with the actual account; it includes items such as the cardholder’s name as well as the account number. Track 2 data contains information such as the credit card number and expiration date.

POS Targeting

For quite some time, cyber criminals have been targeting consumer data entered in POS systems. In some circumstances, criminals attach a physical device to the POS system to collect card data, which is referred to as skimming1. In other cases, cyber criminals deliver malware which acquires card data as it passes through a POS system, eventually exfiltrating the desired data back to the criminal, Once the cybercriminal receives the data, it is often trafficked to other suspects who use the data to create fraudulent credit and debit cards.

As POS systems are connected to computers or devices, they are also often enabled to access the internet and email services. Therefore malicious links or attachments in emails as well as malicious websites can be accessed and malware may subsequently be downloaded by an end user of a POS system. The return on investment is much higher for a criminal to infect one POS system that will yield card data from multiple consumers.

There are several types of POS malware in use, many of which use a memory scrapping technique to locate specific card data. Dexter, for example, parses memory dumps of specific POS software related processes looking for Track 1 and Track 2 data. Stardust, a variant of Dexter not only extracts the same track data from system memory, it also extracts the same type of information from internal network traffic. Researchers surmise that Dexter and some of its variants could be delivered to the POS systems via phishing emails or the malicious actors could be taking advantage of default credentials to access the systems remotely, both of which are common infection vectors. Network and host based vulnerabilities, such as weak credentials accessible over Remote Desktop, open wireless networks that include a POS machine and physical access (unauthorized or misuse) are all also candidates for infection.

POS System Owner Best Practices

Owners and operators of POS systems should follow best practices to increase the security of POS systems and prevent unauthorized access.

Use Strong Passwords: During the installation of POS systems, installers often use the default passwords for simplicity on initial setup. Unfortunately, the default passwords can be easily obtained online by cybercriminals. It is highly recommended that business owners change passwords to their POS systems on a regular basis, using unique account names and complex passwords.

Update POS Software Applications: Ensure that POS software applications are using the latest updated software applications and software application patches. POS systems, in the same way as computers, are vulnerable to malware attacks when required updates are not downloaded and installed on a timely basis.

Install a Firewall: Firewalls should be utilized to protect POS systems from outside attacks. A firewall can prevent unauthorized access to, or from, a private network by screening out traffic from hackers, viruses, worms, or other types of malware specifically designed to compromise a POS system.

Use Antivirus: Antivirus programs work to recognize software that fits its current definition of being malicious and attempts to restrict that malware’s access to the systems. It is important to continually update the antivirus programs for them to be effective on a POS network.

Restrict Access to Internet: Restrict access to POS system computers or terminals to prevent users from accidentally exposing the POS system to security threats existing on the internet. POS systems should only be utilized online to conduct POS related activities and not for general internet use.

Disallow Remote Access: Remote access allows a user to log into a system as an authorized user without being physically present. Cyber Criminals can exploit remote access configurations on POS systems to gain access to these networks. To prevent unauthorized access, it is important to disallow remote access to the POS network at all times.

Consumer Remediation

Fraudulent charges to a credit card can often be remediated quickly by the issuing financial institution with little to no impact on the consumer. However, unauthorized withdrawals from a debit card (which is tied to a checking account) could have a cascading impact to include bounced checks and late-payment fees.

Consumers should routinely change debit card PINs. Contact or visit your financial institutions website to learn more about available fraud liability protection programs for your debit and credit card accounts. Some institutions offer debit card protections similar to or the same as credit card protections.

If consumers have a reason to believe their credit or debit card information has been compromised, several cautionary steps to protect funds and prevent identity theft include changing online passwords and PINs used at ATMs and POS systems; requesting a replacement card; monitoring account activity closely; and placing a security freeze on all three national credit reports (Equifax, Experian and TransUnion). A freeze will block access to your credit file by lenders you do not already do business with. Under federal law, consumers are also entitled to one free copy of their credit report every twelve months through AnnualCreditReport.com.

Consumers may also contact the Federal Trade Commission (FTC) at (877) 438-4338 or via their website at www.consumer.gov/idtheft or law enforcement to report incidents of identity theft.

Contact Information

For questions about this advisory, please feel free to contact the NCCIC at NCCIC@hq.dhs.gov or via phone at (888) 282-0870.

CCTV Training available on February 7, 2014 - FREE!

"CCTV:  What You See Is What You Get"
February 7, 2014
8:00am - 5:00pm
Gray Graphics, 8607 Central Ave, Capitol Heights, MD


The InfraGard Maryland and National Capital Region chapters, FBI Baltimore and Washington Field Offices, and the Maryland Coordination and Analysis Center invite you to a workshop designed to enhance the operational use of Closed Circuit Television (CCTV).

These techniques will improve operators' and managers' abilities to effectively employ CCTV to protect their companies and their local communities against criminal activity.  Designed for retail, campus, commercial, government, large-capacity venues, and law enforcement entities, this program will enhance a preventative posture and benefit response protocols.

Our speaker is Paul Smith, retired British Army Infantry and British Security Service officer.  He has provided instruction to LAPD, VA State Police, Washington DC Fire, and numerous fusion centers.

For more information, and to register, please go to: https://www.eventbrite.com/e/cctv-what-you-see-is-what-you-get-tickets-9935602655

You are welcome to share this invitation to colleagues and other entities/organizations, as this is an open meeting for security professionals who would benefit from this training.

If you have any questions, please contact:

Kara D. Sidener
Special Agent, InfraGard Coordinator
FBI-WFO/Northern VA Resident Agency
kara.sidener@ic.fbi.gov
703.686.6466 (desk)
202.631.2416 (cell)