Showing posts with label Cyber Attack. Show all posts
Showing posts with label Cyber Attack. Show all posts

Monday

New Zealand central bank hit by cyber attack

WELLINGTON - New Zealand's central bank said Sunday it was responding with urgency to a "malicious" breach of one of its data systems, a third-party file sharing service that stored "sensitive information".

Reserve Bank of New Zealand governor Adrian Orr said the breach had been contained and the system was taken offline but it would take time to determine what information had been accessed.

"We are working closely with domestic and international cyber security experts and other relevant authorities as part of our investigation and response to this malicious attack," Orr said.

"The nature and extent of information that has been potentially accessed is still being determined, but it may include some commercially and personally sensitive information," he added.

"It will take time to understand the full implications of this breach, and we are working with system users whose information may have been accessed."

In its latest report, the government agency CERT (Computer Emergency Response Team) said cyber attacks had increased 33 percent year-on-year in New Zealand. 

The country's stock exchange was targeted by sustained DDoS (distributed denial of service) attacks last August, forcing trading to be halted on four consecutive days.

Agence France-Presse

Wednesday

Flights canceled as British Airways hit by computer problem


LONDON — British Airways (BA) canceled almost 100 flights to and from London airports on Wednesday after its check-in systems were hit by computer problems.

The airline said a “systems issue” was causing delays and cancellations for short-haul flights from Heathrow, Gatwick, and London City airports.

British Airways said it was relying on back-up and manual systems, and canceled 81 flights due to operate to, or from Heathrow, and 10 Gatwick flights, stranding some 15,000 passengers. More than 200 other flights were delayed.

“A number of flights continue to operate but we are advising customers to check ba.com for the latest flight information before coming to the airport,” the airline said in a statement.

BA said short-haul passengers due to travel Wednesday could re-book for another day.

In May 2017, tens of thousands of passengers were stranded when a global computer failure grounded hundreds of British Airways flights over three days. BA passengers were also hit with severe delays in July and September 2016 because of problems with the airline’s online check-in systems.


The airline is also set to be fined 183 million pounds ($222 million) over a cyberattack on its security systems last year in which the personal data of up to 500,000 customers were stolen. /kga

source: newsinfo.inquirer.net

Thursday

Kaspersky warns of more fake supply chain attacks


More fake supply chain attacks are expected given the heightened cyberheist activities of the notorious Lazarus group, Russian cybersecurity firm Kaspersky Lab AO said Thursday.

Seonsgu Park, Kaspersky’s senior security researcher in the Global Research and Threat Analysis Team (GReAT), warned that more fake supply chain attacks are expected.

“With major attacks up its sleeves—such as the Bangladesh Bank heist and the WannaCry ransomware, to name a few—the Lazarus group is like a constant presence in the world of cybersecurity and it is getting quite adept at hiding and spreading its evil schemes,” said Park.

Kaspersky found that the Lazarus group—an advanced persistent threat (APT)—has developed new malicious operations which at first glance looks like a supply chain.

Dubbed as AppleJesus, the APT’s attack compromised users through the Trojanized trading application Celas Trade Pro, developed by a legitimate company Celas Limited.

Once Trojanized, a software is infected by a malware which, once activated, enables cybercriminals to spy on users, steal sensitive data, and gain backdoor access to systems.

“The extensive effort it exerts to create malware for the supposedly safer MacOS environment, and the intricate details needed to create a legitimate-looking application and software company, prove it is far from stopping,” said Park.

“There are more attacks to come, and we had better be ready because it won’t get any easier,” he warned.

Kaspersky said individuals should be more prudent in choosing third-party vendors and more cautious in trusting legitimate-looking software applications, certificates, and developers.

“We have observed how the Lazarus group has constantly evolved—from waging cyber espionage campaigns worldwide to financial attacks against major banks. Last year, we warned that they are not after your data anymore. And indeed, they aren’t,” said Park.

“These state-backed attackers are now ramping up the sophistication of their attacks and widening their reach to steal more money and trick the cybersecurity industry,” he said. —Jon Viktor Cabuenas/VDS, GMA News

source: gmanetwork.com

Sunday

Iran hit by global cyber attack that left US flag on screens


DUBAI - Hackers have attacked networks in a number of countries including data centers in Iran where they left the image of a US flag on screens along with a warning "Don't mess with our elections", the Iranian IT ministry said on Saturday.

"The attack apparently affected 200,000 router switches across the world in a widespread attack, including 3,500 switches in our country," the Communication and Information Technology Ministry said in a statement carried by Iran's official news agency IRNA.

The statement said the attack, which hit internet service providers and cut off web access for subscribers, was made possible by a vulnerability in routers from Cisco which had earlier issued a warning and provided a patch that some firms had failed to install over the Iranian new year holiday.


Cisco did not immediately respond to requests for comment.

A blog published on Thursday by Nick Biasini, a threat researcher at Cisco's Talos Security Intelligence and Research Group, said: "Several incidents in multiple countries, including some specifically targeting critical infrastructure, have involved the misuse of the Smart Install protocol...

"As a result, we are taking an active stance, and are urging customers, again, of the elevated risk and available remediation paths."

Iran's IT Minister Mohammad Javad Azari-Jahromi posted a picture of a computer screen on Twitter with the image of the US flag and the hackers' message. He said it was not yet clear who had carried out the attack.

Azari-Jahromi said the attack mainly affected Europe, India and the United States, state television reported.

"Some 55,000 devices were affected in the United States and 14,000 in China, and Iran's share of affected devices was 2 percent," Azari-Jahromi was quoted as saying.

In a tweet, Azari-Jahromi said the state computer emergency response body MAHER had shown "weaknesses in providing information to (affected) companies" after the attack which was detected late on Friday in Iran.

Hadi Sajadi, deputy head of the state-run Information Technology Organization of Iran, said the attack was neutralized within hours and no data was lost. — Reuters

Thursday

North Korean hackers expand from political to financial targets


SEOUL—The messages are alluring, the pictures are attractive. But the women seeking to beguile South Korean bitcoin executives could actually be hackers from North Korea in disguise, experts warn.

In the face of sanctions over its banned nuclear and ballistic missile programs, cash-strapped North Korea is deploying an army of well-trained hackers with an eye on a lucrative new source of hard currency, they say.

Its cyberwarfare abilities first came to prominence when it was accused of hacking into Sony Pictures Entertainment to take revenge for “The Interview,” a satirical film that mocked its leader, Kim Jong-un.

But Pyongyang has rapidly expanded from political to financial targets, such as the central bank of Bangladesh and bitcoin exchanges around the world, with Washington this week blaming it for the WannaCry ransomware that wreaked havoc earlier this year.

Shutdown

And a South Korean cryptocurrency exchange shut down on Tuesday after losing 17 percent of its assets in a hacking—its second cyberattack this year, with North Korea accused of being behind the first.

According to multiple South Korean reports citing Seoul’s intelligence agency, North Korean hackers approach workers at digital exchanges by posing as beautiful women on Facebook, striking online conversations and eventually sending files containing malicious code.

They also bombard executives with e-mails posing as job seekers sending resumés—with the files containing malware to steal personal and exchange data.

Moon Jong-hyun, director at Seoul cybersecurity firm EST Security, said North Korea had stepped up online honeytrap tactics targeting South Korea’s government and military officials in recent years.

“They open Facebook accounts and maintain the online friendship for months before backstabbing the targets in the end,” Moon told a cybersecurity forum, adding many profess to be studying at a US college or working at a research think tank.

Criminal enterprise

Simon Choi, director of Seoul cybersecurity company Hauri, has accumulated vast troves of data on Pyongyang’s hacking activities and has been warning about potential ransomware attacks by North Korea since 2016.

The United States has reportedly stepped up cyberattacks of its own against North Korea.

But Choi told Agence France-Presse (AFP): “The North’s hacking operations are upgrading from attacks on ‘enemy states’ to a shady, lucrative moneymaking machine in the face of more sanctions.”

Pyongyang’s hackers have showed interest in bitcoin since at least 2012, he said, with attacks spiking whenever the cryptocurrency surges—and it has soared around 20-fold this year.

US cybersecurity company FireEye noted that a lack of regulations and “lax antimoney laundering controls” in many countries make digital currencies an “attractive tactic” for North Korea.

Cryptocurrencies, FireEye said in a September report, were “becoming a target of interest by a regime that operates in many ways like a criminal enterprise.”

The company documented three attempts by Pyongyang to hack into Seoul cryptocurrency exchanges between May and July as a way to “fund the state or personal coffers of Pyongyang’s elite.”

In October, Lazarus, a hacking group linked with North Korea, launched a malicious phishing campaign targeting people in the bitcoin industry with a fake but lucrative job offer, according to US cybersecurity firm Secureworks.

Hacking attacks targeting digital currencies are only the latest in the long list of alleged online financial heists by North Korea.

North Korea is blamed for a massive $81-million cyberheist from the Bangladesh central bank in 2016, as well as the theft of $60 million from Taiwan’s Far Eastern International Bank in October.

Although Pyongyang has angrily denied the accusations—which it described as a “slander” against the authorities—analysts say the digital footprints left behind suggest otherwise.

Proceeds from such actions are laundered through casinos in the Philippines and Macau or money exchanges in China, said Lim Jong-in, a cybersecurity professor at Korea University in Seoul, making it “virtually impossible” to trace. —AFP

source: technology.inquirer.net

Wednesday

What we currently know about the global cyberattack


NEW YORK — The danger from a global cyberattack that spread to some 150 nations continues to fade, and that’s only some of the good news.

After two security researchers greatly slowed down that attack , which effectively held people’s documents, photos and other digital files hostage, hard-hit organizations such as the UK’s National Health Service seem to be bouncing back. While it’s a crude measure of the impact, it also appears that relatively few of those affected were desperate enough to actually pay the ransom demanded by the attackers.

On the other hand, the attack has served as a live demonstration of a new type of global threat, one that could encourage future hackers.

Here’s what we currently know about the ransomware known as WannaCry, which locked up digital photos, documents and other files to hold them for ransom.

Where it came from


Researchers are still puzzling out how WannaCry got started. Figuring that out could yield important clues to the identity of its authors.

The malware spread rapidly inside computer networks by taking advantage of vulnerabilities in mostly older versions of Microsoft Windows. That weakness was purportedly identified and stockpiled for use by the US National Security Agency; it was subsequently stolen and published on the internet.

But it remains unclear how WannaCry got onto computers in the first place. Experts said its rapid global spread suggests it did not rely on phishing, in which fake emails tempt the unwary to click on infected documents or links. Analysts at the European Union cybersecurity agency said the hackers likely scanned the internet for systems that were vulnerable to infection and exploited those computers remotely.

Once established, WannaCry encrypted computer files and displayed a message demanding $300 to $600 worth of the digital currency bitcoin to release them. Failure to pay would leave the data scrambled and likely beyond repair unless users had unaffected backup copies.

Ransom payments

Investigators are closely watching three bitcoin accounts associated with WannaCry, where its victims were directed to send ransom payments. The digital currency is anonymized, but it’s possible to track funds as they move from place to place until they end up with an identifiable person.

So far, there have been no withdrawals from those accounts.

Given the scope of the attack, relatively few people appear to have actually paid the ransom. According to a Twitter account that monitors those accounts , they’ve received only about 250 payments worth a total of slightly more than $72,000.

North Korea


Several sets of investigators have now reported tentative findings that suggest hackers linked to North Korea might have been involved with WannaCry. But they could all be drawing conclusions from a very small set of clues.

On Monday, the Russian security firm Kaspersky Lab said portions of the WannaCry program use the same code as malware previously distributed by the Lazarus Group, a hacker collective behind the 2014 Sony hack. Another security company, Symantec, related the same findings, which it characterized as intriguing but “weak” associations, since the code could have been copied from the Lazarus malware.

Two law enforcement officials likewise said US investigators suspect North Korea based on code similarities; the officials called that finding preliminary. The officials spoke to The Associated Press on condition of anonymity because they aren’t authorized to speak publicly about an ongoing investigation.

But WannaCry remains a puzzle, in part because some of its elements seemed amateurish. Salim Neino, CEO of the Los Angeles-based security firm Kryptos Logic, said the WannaCry worm was “poorly designed” — patched together and consisting of a “sum of different parts” with an unsophisticated payment system.

Typical ransomware also generates a unique bitcoin account for each payment to make tracing difficult. That wasn’t done here.

Digging out 



One of the organizations hardest hit by WannaCry — the UK’s National Health Service — appears to be recovering. On Friday, many NHS hospitals had to turn away patients after WannaCry locked up computers, forcing the closure of wards and emergency rooms.

NHS Digital, the body that oversees cybersecurity in Britain’s health system, said that as of now, it has “no evidence that patient data has been compromised.” The agency told hospitals to disconnect all infected computers, apply a Microsoft patch that closes the vulnerability, then “roll back” the infected computers and restore them from backed-up files.

UK hospitals are supposed to back up data frequently and at multiple locations. It’s possible that some data that wasn’t backed up could be lost.

Sign of hacks to come

WannaCry could also serve as a kind of template for future cyberattacks.

Neino of Kryptos Logic, for instance, said the leak of the NSA hacking tools have significantly narrowed the gap between nations and individuals or cyber gangs.

“The concern has always been, when are the real bad guys, the ones that don’t care about rules of engagement, the ones who are really out to hurt us, will they become cyber-capable?” he said in an interview Monday night with The Associated Press. “I think today we found out that those who really want to hurt us have begun to, because they became cyber-capable the moment that the NSA cybertools were released.”

source: technology.inquirer.net

Sunday

5 Ways Small Businesses Must Protect their Data



Cyber security is a new concern for all businesses. Big hacks, like the Target, Home Depot, and Sony attacks, have only emphasized how much small businesses need to protect themselves. Large businesses have a lot of resources to do this, but small businesses often do not have the budget or knowledge to perform due diligence against cyber security attacks. Here are 5 ways a small business can protect itself from data threats.

Protecting Small Business Data: Backup
The new threat on the block is ransomware. Symantec estimates that 60% of small businesses face significant financial hardships after being attacked by ransomware. Some of these businesses even discontinue service or go out of business as a result of the attacks. Ransomware encrypts important files, like documents, pictures, and CAD files, on a PC. The local PC isn’t the only victim either. Ransomware will also attempt to reach out to other PCs on the network, especially mapped network drives. Once the ransomware finishes encrypting files and drives, the software demands money to un-encrypt the data that the business can no longer access. The ransom can be expensive.

Small business can’t afford that kind of monetary hit. However, if a system gets attacked by ransomware and the business has a quality backup, the business can simply wipe the PC and start over. Re-imaging a PC and restoring data only takes a day or two and saves the business thousands of dollars. Backing up and protecting small business data is easy. There are a lot of good, online services that automate this process for an affordable yearly fee. Likewise, it’s easy enough to setup on your own. The important thing is to keep 3 different backups for the 3 different time periods for each PC. Each backup set needs to be kept on-site, off-site but local, and not local. This ensures that data is saved in case a business goes up in flames or the offsite backup is hit by a natural or man-made disaster. Data storage is cheap today so there’s a backup is an easy choice..

Protecting Small Business Data: Switch to the Cloud
The cloud is still a scary thing for businesses. I understand why. Using a cloud infrastructure means that businesses have to hand over control of their IT systems and depend on another business to stay in business. Think of it this way, though, cloud businesses build their business on reliability, speed, and security. Microsoft’s Azure and Amazon’s S3 services are incredibly powerful. They both have over a 99% uptime guarantee in their Service Level Agreements. Both replicate data in servers throughout the country. Both backup data. Microsoft has the advantage of adding their entire Office Suite in the cloud, too. Best of all, cloud services can lower ownership expenses.

Protecting Small Business Data: Purchase, Update Quality AV
Antivirus protection is still needed in today’s environment. By now we shouldn’t have to warn anyone to install a quality antivirus program and keep it up-to-date. So many businesses still don’t follow this basic rule, though. This is something that any small business can implement in a few hours and automate.

Protecting Small Business Data: Restrict Admin Accounts
Most small businesses buy a few PCs and attach them to a small local area network. They don’t use domain services or group policies. That’s okay. It’s not always appropriate for a small business to utilize these kinds of services. It is important to make sure that employees aren’t using admin accounts on their PCs, though. Admin accounts are setup by default. Changing a user’s profile from being an admin to a standard user eliminates 90% of virus and attack-ware threats. Employees can always elevate privileges on the PC when they need to install software.

Protecting Small Business Data: Education
Nothing is more important than education. Employee education can significantly reduce the threat of cyber attacks. Even simple reminders to avoid opening links or attachments in email will significantly reduce the chances of an attack. Hold monthly education meetings or assign a “security guru” to send out weekly or monthly newsletters for employees to read and act on. These are basic steps but speaking to the last point, awareness and education is a significant part of the battle against data breach and data corruption. Please let us know if you have other questions. The needs of our customers frequently grow in one area or the other, such as the recent spike in ransomware. We might bring your concerns to the blog to help others, as well.

source: securedatarecovery.com

Wednesday

Bangladesh central bank chief forced to resign over $81-M heist


DHAKA—Bangladesh’s central bank chief has resigned after hackers stole $81 million from the nation’s foreign reserves in one of the biggest bank heists in history, the finance minister announced on Tuesday.

The audacious cybertheft has embarrassed the Bangladesh government, triggered outrage in the impoverished country and raised alarm over the security of the country’s foreign exchange reserves of over $27 billion.

On Tuesday, the finance minister said he had asked Atiur Rahman to resign following revelations that the governor of Bangladesh Bank—the country’s central bank—had failed to inform authorities of the theft for a month.

“He called me Tuesday and I’ve asked him to resign. And he has resigned today,” Finance Minister A.M.A. Muhith told Agence France-Presse (AFP), adding that the government has ordered an investigation of the heist.

On Feb. 5, hackers stole $81 million from a current account that Bangladesh Bank held with the Federal Reserve Bank of New York and transferred the cash electronically to accounts in the Philippines.

The hackers attempted to steal almost $1 billion, but they were prevented from taking more because of a basic typing error, the Bangladesh Bank’s deputy governor told AFP last week.

Before his resignation, an emotional Rahman said he was alarmed by the hack, but he did not comment on why he took so long to report the missing money.

“This event was almost like a militant attack, almost like an earthquake. I did not realize how it happened, from where it originated and who had done it,” he said, choking back tears.

“When I was informed I was so puzzled. Fearing that it might destroy our economy, I quickly took opinion of the experts. I brought them to the country from abroad and ensured security so that it did not occur again,” he added.

Due to retire

Rahman, a 64-year-old economist and former university professor, was appointed governor of Bangladesh Bank in 2009 and had been due to retire in August.

As details of the scandal emerged last week, he flew to India to attend an International Monetary Fund meeting, leaving junior officials scrambling to explain how the hackers managed to take such large sums from Bangladesh Bank.

Some of the funds have been recovered and Philippine authorities have frozen the stolen money following court orders. Bangladesh Bank suspects the hackers were Chinese.

The thieves, who bombarded the New York bank with dozens of transfer requests, attempted to steal a further $850 million, but the bank’s security systems and typing errors in some requests prevented the full theft.

The hack took place on a Friday, when Bangladesh Bank is closed, while the Federal Reserve Bank in New York is closed on Saturday and Sunday.

The US reserve bank, which manages the Bangladesh Bank reserve account, has denied its own systems were breached.

The $81 million was transferred to four accounts at Rizal Commercial Banking Corp. (RCBC) in the Philippines—and were then transferred to fictitious bank account.

The money was then transferred to Philippine casinos, Julia Bacay-Abad of the Philippine Anti-Money Laundering Council told a Senate hearing on Tuesday.

The RCBC account has been frozen.

Mystified by attack

Rahman launched a series of populist policies to take bank services to the doorstep of millions of rural poor in Bangladesh.

But his tenure was marred by a spate of high-profile banking scams in which state-owned banks lost hundreds of millions of dollars in bad loans.

On Tuesday, Rahman said authorities were still mystified by the attack as he defended his decision to delay informing the government.

He added that making the news public earlier would have risked tipping off the hackers.

“I don’t deny that I took time [to inform the finance minister]. It was a cyberattack and even today we don’t know from where it originated,” he said. AFP

source: globalnation.inquirer.net

Friday

iOS users warned versus spy app

 
Mobile securit researchers warn of a mobile app that may have been used to collect users' personal data as part of an  "economic and political cyber-espionage operation" targeting military, governments, defense, and media—with civilians unwittingly caught up as collateral damage.

Users of Apple's iPhone, iPad and iPod touch running iOS were warned this week against an espionage app being used in a targeted attack campaign.
 
Trend Micro said the app is used in Operation Pawn Storm, an "economic and political cyber-espionage operation" whose targets include the military, governments, defense and media.
 
"We believe the iOS malware gets installed on already compromised systems, and it is very similar to next stage SEDNIT malware we have found for Microsoft Windows’ systems," researchers Lambert Sun, Brooks Hong and Feike Hacquebord said in a blog post.
 
According to the researchers, they found two malicious iOS applications in Operation Pawn Storm.
 
One of the two, IOS_ XAGENT.B, uses the name of a legitimate iOS game "MadCap." The second was identified as XAgent (IOS_XAGENT.A).
 
Both apps are related to SEDNIT, which the researchers said aims to personal data, record audio, make screenshots, and send them to a remote command-and-control server.
 
"As of this publishing, the C&C server contacted by the iOS malware is live," Trend Micro said.
 
XAgent, once installed on iOS 7, hides its icon and runs in the background immediately.
 
"When we try to terminate it by killing the process, it will restart almost immediately," the researchers said.
 
But on iOS 8, the icon is not hidden and it cannot restart automatically.
 
"This suggests that the malware was designed prior to the release of iOS 8 last September 2014," they said.
 
The researchers said the app is designed to collect all kind of information on an iOS device and can:
 
  • Collect text messages
  • Get contact lists
  • Get pictures
  • Collect geo-location data
  • Start voice recording
  • Get a list of installed apps
  • Get a list of processes
  • Get the Wi-Fi status
 
Even works on un-Jailbroken phones
 
What is potentially dangerous is that the iOS device "doesn’t have to be jailbroken per se," the researchers said.
 
"We have seen one instance wherein a lure involving XAgent simply says 'Tap Here to Install the Application.' The app uses Apple’s ad hoc provisioning, which is a standard distribution method of Apple for iOS App developers," they said.
 
Via ad hoc provisioning, the researchers said the malware can be installed simply by clicking on a link. — Joel Locsin/TJD, GMA News
 
source: gmanetwork.com

Saturday

George Clooney criticizes Hollywood in Sony cyber attack


Oscar winner George Clooney slammed Hollywood power players for not supporting Sony Pictures following the cyber attack on the company over the satirical comedy "The Interview" about North Korean leader Kim Jong Un.

Sony on Wednesday pulled the Christmas Day release of the film depicting a fictional assassination of Kim after major theater chains said they would not show it due to unspecified threats made by the hackers.

Clooney, in an interview Friday with online trade publication Deadline.com, said no one would sign a petition he and his agent circulated to top Hollywood figures supporting the film's release.

The actor-director, whose past two directorial efforts were Sony releases, also criticized the media for failing to link the cyber attack to North Korea. The United States on Friday blamed the country for the devastating cyber attack, calling it an unacceptable act of intimidation and vowing to impose "costs and consequences" on those responsible.

"We're talking about an actual country deciding what content we're going to have. This affects every part of business that we have," Clooney said. "We cannot be told we can't see something by Kim Jong Un."

In the cyber attack on Sony and its employees, hackers released a stream of embarrassing emails and demanded that the film's release be scrapped.

"We have a responsibility to stand up against this. That's not just Sony, but all of us, including my good friends in the press who have the responsibility to be asking themselves: What was important? What was the important story to be covering?" Clooney added.

The news media's early coverage of the hack largely focused on the content of leaked emails between Sony employees and film producers.`

Clooney, who won Oscars for Best Actor in a Supporting Role for the film "Syriana" in 2005 and Best Picture for "Argo" in 2012, said he is concerned about content in films and that it will now be judged differently.

"The movies we make are the ones with challenging content, and I don't want to see it all just be superhero movies. Nothing wrong with them, but it's nice for people to have other films out there," he added. -- Reuters

Tuesday

Facebook users warned vs. Christmas scam for 65in TV


As Christmas draws even closer, cybercriminals are becoming more creative in drawing up scams targeting users of social networking giant Facebook.
One of the latest scams involves a supposed offer of 250 Samsung 65-inch Ultra 4k HD curved TVs, Online Threat Alerts reported.
"The scam will attempt to trick you into commenting on,liking it, sharing it and completing surveys, by claiming that you have a chance of receiving one of the 250 Samsung 65" Ultra 4K HD Curved TVs that are being given away," it said.
While the scam is not associated with the companies supposedly offering to give away the curved TVs, it is meant to get Facebook users to like, share or comment on the post.
Such actions could spread the scam and bait more potential victims.
Users who fall for the scam are asked to complete surveys where the scammers will get a commission.
 "If you receive the same post on your Facebook Wall or Timeline, please report it as spam and then delete it," the site advised. — Joel Locsin/TJD, GMA News

source: gmanetwork.com