May 2011
We have seen the old cops and robber shows or TV dramas where a criminal shouts out, "This is a hold up. Give us all your money, or else!" Well, in cyberspace there is a new twist. A trend is emerging where hackers steal information, some hold it ransom, and then try to sell it back to the company they stole it from. It sounds like a bad TV movie doesn't it? The bad guys break into a network at a company and hold the data hostage. It's happened before but now researchers in cyber security say it is happening in what might turn out to be the largest data breach so far - the Sony Playstation network breach. Could your credit card data be in their hands and held for ransom?
Researchers said that alleged hackers have been talking about it in online forums saying they have roughly 2 million credit card numbers from their heist. The hackers offered to sell stolen credit cards back to Sony for $100,000. It is unclear what the next steps will be but FBI Law Enforcement Officials are involved.
5 TIPS TO PROTECT YOURSELF:
1. Set up automated alerts for exisiting credit cards
2. Consider placing high fraud alerts on your credit card accounts through Experian, TransUnion, and Equifax
3. Make sure your password on the game system is not the same or even a variation of your email, banking or social networking accounts
4. Several breaches have happened recently of email addresses - be very suspicious of emails you receive and avoid clicking on links or opening attachments
5. Consider a new credit card if your card was connected to Sony Playstation
This Week’s Word of the week: Nibble (also sometimes spelle NYBBLE or NYBLE)
It sounds like snack time but it refers to storage. This is a geek play on words. A byte of storage has 8 bits so if you only need 4 bits, you just need a "Nibble" and not a full "byte".
Web Resources:
Sony is communicating updates about the most recent breach at:
http://blog.us.playstation.com/2011/04/26/update-on-playstation-network-and-qriocity/
If you want to set up Fraud Alerts, you can go to all 3 credit reporting services:
Experian: https://www.experian.com/fraud/center.html
TransUnion: http://www.transunion.com
Equifax: www.Equifax.com
Other Links of Interest
Contributors
Showing posts with label fraud. Show all posts
Showing posts with label fraud. Show all posts
Wednesday, July 6, 2011
Wednesday, January 5, 2011
The "e" in e-card for cybercreeps means "easy" to get past security
My family and friends know by now that I NEVER open e-cards without calling or emailing them first to ask them 50 questions about the card before I even consider opening it. That might explain the decline in e-cards in my in basket?
Until now, most of my friends and family put up with it because they love me and they all know that like the kid in "6th sense" who "sees dead people", when I look at most anything I "see cyberbadpeople".
So, when I read that bogus White House Christmas e-cards were sent out to people, I absolutely cringed. I knew, before I read the article, that people probably opened them.
According to articles I read, the e-card contained the infamous Zeus malware.
One article mentions that one of the servers used to deliver the e-cards from "the White House" was in Belarus. It is believed that the hackers stole several gigabytes worth of data.
From the site KrebsOnSecurity, he posted the actual message sent to recipients:
“As you and your families gather to celebrate the holidays, we wanted to take
a moment to send you our greetings. Be sure that we’re profoundly grateful
for your dedication to duty and wish you inspiration and success in
fulfillment of our core mission."
The card included links with a picture of a decorated Christmas tree with a file named "card.zip".
The Zeus variant appears to have stolen passwords and used those to steal Word and Excel documents.
Sources:
"White House E-Card Spoof Steals Data", Brian Kalish, NextGov.com, January 4, 2011.
" 'White House' eCard Dupes Dot-Gov Geeks", KrebsonSecurity, January 4, 2011.
Until now, most of my friends and family put up with it because they love me and they all know that like the kid in "6th sense" who "sees dead people", when I look at most anything I "see cyberbadpeople".
So, when I read that bogus White House Christmas e-cards were sent out to people, I absolutely cringed. I knew, before I read the article, that people probably opened them.
According to articles I read, the e-card contained the infamous Zeus malware.
One article mentions that one of the servers used to deliver the e-cards from "the White House" was in Belarus. It is believed that the hackers stole several gigabytes worth of data.
From the site KrebsOnSecurity, he posted the actual message sent to recipients:
“As you and your families gather to celebrate the holidays, we wanted to take
a moment to send you our greetings. Be sure that we’re profoundly grateful
for your dedication to duty and wish you inspiration and success in
fulfillment of our core mission."
The card included links with a picture of a decorated Christmas tree with a file named "card.zip".
The Zeus variant appears to have stolen passwords and used those to steal Word and Excel documents.
Sources:
"White House E-Card Spoof Steals Data", Brian Kalish, NextGov.com, January 4, 2011.
" 'White House' eCard Dupes Dot-Gov Geeks", KrebsonSecurity, January 4, 2011.
Hee Haw - Get Your Video Games and Apple Gift Cards By Way of a Mule?
Was an Apple gift card or video game under the Menorah or Christmas tree this recent holiday season?
Well, it may have come to you via a mule. Slow down PETA members, I'm actually not talking about a new method of transit via animals, I am talking about money mules.
The Feds recently busted a major, multi million dollar ring involving two exchange students in Minnesota. The dynamic duo, from Vietnam, are believed to be the masterminds behind a major scheme using counterfeit credit cards and taking advantage of online auctions and online stores.
It is believed that Apple, Dell, Verizon, Amazon, Paypal, eBay, and even Rosetta Stone lost money due to these alleged cybercriminals.
Investigators believe they have uncovered 180+ eBay accounts and roughly 360 PayPal accounts that were established by this ring under false information. The tally of their evil looting? Possibly $1.25 million.
How did they pull it off? With money mules that wired them the money. Mules are people that might be people duped into "work at home" schemes and have no idea they are part of a mule ring. Some mules know exactly what they are doing. The mules are believed to be US based and the scam ran in the U.S., Vietnam, and Canada.
Sources:
"Cyber crime trail leads to Winona State students - Feds say a transnational cyber crime ring based in Vietnam has ties to two exchange students", Dan Browning, Star Tribune, January 3, 2011.
"Foreign-exchange Students Linked to Vietnamese Cyber-Crime Gang", Camille Tuutti, The New New Internet, January 3, 2011.
" 'Operation eMule' Feds Bust Duo with 500+ eBay, PayPal Accounts", John Leyden, The Register, January 5, 2011.
Well, it may have come to you via a mule. Slow down PETA members, I'm actually not talking about a new method of transit via animals, I am talking about money mules.
The Feds recently busted a major, multi million dollar ring involving two exchange students in Minnesota. The dynamic duo, from Vietnam, are believed to be the masterminds behind a major scheme using counterfeit credit cards and taking advantage of online auctions and online stores.
It is believed that Apple, Dell, Verizon, Amazon, Paypal, eBay, and even Rosetta Stone lost money due to these alleged cybercriminals.
Investigators believe they have uncovered 180+ eBay accounts and roughly 360 PayPal accounts that were established by this ring under false information. The tally of their evil looting? Possibly $1.25 million.
How did they pull it off? With money mules that wired them the money. Mules are people that might be people duped into "work at home" schemes and have no idea they are part of a mule ring. Some mules know exactly what they are doing. The mules are believed to be US based and the scam ran in the U.S., Vietnam, and Canada.
Sources:
"Cyber crime trail leads to Winona State students - Feds say a transnational cyber crime ring based in Vietnam has ties to two exchange students", Dan Browning, Star Tribune, January 3, 2011.
"Foreign-exchange Students Linked to Vietnamese Cyber-Crime Gang", Camille Tuutti, The New New Internet, January 3, 2011.
" 'Operation eMule' Feds Bust Duo with 500+ eBay, PayPal Accounts", John Leyden, The Register, January 5, 2011.
Friday, December 17, 2010
ACH Fraud Hits Texas - One County Government is out $200,000
$690,000 and $200,000. That's the dollar amount of fraud that just hit Gregg County, Texas.
$690,000 was the heist. $200,000 was the amount that could not get recovered and the County is left with the loss.
The culprit? A computer in the tax office became infected with Zeus, that nasty little trojan that steals online banking credentials.
The fix? They have restored back to paper deposits to avoid future cyber theft.
Quote from the Government Information Security Article:
"As long as I'm tax collector, we will never go back to sending out money electronically again," Mr. Kirk Shields, Gregg County's tax assessor and collector.
Schools, Municipalities, and Businesses are not protected under Regulation E, which protects consumers.
In Fall of 2010, Senator Charles Schumer, (D-NY) asked the Senate to consider a bill that would extend Reg E to protect schools and municipalities.
This still leaves businesses unprotected.
Sources:
"ACH Fraud Hits Texas County", Government Information Security Articles, Linda McGlasson, December 15, 2010.
$690,000 was the heist. $200,000 was the amount that could not get recovered and the County is left with the loss.
The culprit? A computer in the tax office became infected with Zeus, that nasty little trojan that steals online banking credentials.
The fix? They have restored back to paper deposits to avoid future cyber theft.
Quote from the Government Information Security Article:
"As long as I'm tax collector, we will never go back to sending out money electronically again," Mr. Kirk Shields, Gregg County's tax assessor and collector.
Schools, Municipalities, and Businesses are not protected under Regulation E, which protects consumers.
In Fall of 2010, Senator Charles Schumer, (D-NY) asked the Senate to consider a bill that would extend Reg E to protect schools and municipalities.
This still leaves businesses unprotected.
Sources:
"ACH Fraud Hits Texas County", Government Information Security Articles, Linda McGlasson, December 15, 2010.
Thursday, November 4, 2010
Another First for the Internet! Information-Cybertheft Surpasses Physical Theft
Kroll just released a study called the Kroll Annual Global Fraud Report. In the report, Kroll states that the losses for businesses due to fraud increased by 20% in the last 12 months. The fastest growing area for fraud? Information theft.
Cybercriminals are stealing information at a rate that has outpaced physical theft for the first time!
Physical theft, as defined by the report, includes cash, assets, and inventory.
Tim Wilson from Dark Reading noted that 88 percent of the companies surveyed said they were a victim of some type of fraud.
Physical theft and fraud is not decreasing, it is just that cybertheft is increasing at a faster rate.
The study noted that if your company does business in China or Colombia, those countries were the top 2 for fraud.
One of the challenges companies face that is a major contributor to fraud? Complex technology infrastructure! Nearly 1/3 said their company infrastructure made it difficult to protect its information.
Some steps you can take to protect yourself:
1. Have technology in place to help you track data leaving your network; for example: analysis of traffic patterns and information packets leaving your network; analysis of email attachment names and sizes; or a thumb drive setting and policy that tracks data downloads or limits who has access.
2. Ability to identify the source of the breach and to insure you have closed any open holes.
Source:
www.Kroll.com
"Information Theft at Global Companies Surpasses all other Forms of Fraud for the First Time", Kroll's Annual Global Fraud Report, Press Release, October 18, 2010.
"Incidence Of Cybertheft Surpasses Incidence Of Physical Theft For The First Time, Study Says", Tim Wilson, Dark Reading, October 19, 2010.
Cybercriminals are stealing information at a rate that has outpaced physical theft for the first time!
Physical theft, as defined by the report, includes cash, assets, and inventory.
Tim Wilson from Dark Reading noted that 88 percent of the companies surveyed said they were a victim of some type of fraud.
Physical theft and fraud is not decreasing, it is just that cybertheft is increasing at a faster rate.
The study noted that if your company does business in China or Colombia, those countries were the top 2 for fraud.
One of the challenges companies face that is a major contributor to fraud? Complex technology infrastructure! Nearly 1/3 said their company infrastructure made it difficult to protect its information.
Some steps you can take to protect yourself:
1. Have technology in place to help you track data leaving your network; for example: analysis of traffic patterns and information packets leaving your network; analysis of email attachment names and sizes; or a thumb drive setting and policy that tracks data downloads or limits who has access.
2. Ability to identify the source of the breach and to insure you have closed any open holes.
Source:
www.Kroll.com
"Information Theft at Global Companies Surpasses all other Forms of Fraud for the First Time", Kroll's Annual Global Fraud Report, Press Release, October 18, 2010.
"Incidence Of Cybertheft Surpasses Incidence Of Physical Theft For The First Time, Study Says", Tim Wilson, Dark Reading, October 19, 2010.
Thursday, October 28, 2010
A Merger You May Have Missed - Zeus and SpyEye reach a teaming agreement
SpyEye hit the radar of security experts December 2009. SpyEye's claim to fame was creating software called "ZeuS Killer" which would remove ZeuS from an infected machine and then install SpyEye.
At their core, their goal is stealing banking credentials and money. Although Zeus deviants have been developed to commit other crimes.
In an article by Brian Krebs, he mentions that the FBI attributes $70 million dollars stolen from 400 organizations to Zeus. In the same article, Krebs has a great quote from Trusteer CEO, Mickey Boodaei, "We are in an arms race with criminals".
In a note to previous Zeus customers, SpyEye welcomes his new customers to the fold and even offers them free support and discounts on future software.
Sounds like SpyEye, also known as, "Haderman", has done a Voice of the Customer session!
Sources:
"SpyEye v. ZeuS Rivalry Ends in Quiet Merger", KrebsonSecurity, 10/24/2010.
"ZeuS-SpyEye merger", Help Net Security, 10/27/2010.
Symantec Reports.
At their core, their goal is stealing banking credentials and money. Although Zeus deviants have been developed to commit other crimes.
In an article by Brian Krebs, he mentions that the FBI attributes $70 million dollars stolen from 400 organizations to Zeus. In the same article, Krebs has a great quote from Trusteer CEO, Mickey Boodaei, "We are in an arms race with criminals".
In a note to previous Zeus customers, SpyEye welcomes his new customers to the fold and even offers them free support and discounts on future software.
Sounds like SpyEye, also known as, "Haderman", has done a Voice of the Customer session!
Sources:
"SpyEye v. ZeuS Rivalry Ends in Quiet Merger", KrebsonSecurity, 10/24/2010.
"ZeuS-SpyEye merger", Help Net Security, 10/27/2010.
Symantec Reports.
Thursday, October 14, 2010
Attention Aldi Shoppers - Cybercrooks stealing credit card info.
Have you visited an Aldi in North Carolina? Especially in Charlotte or Raleigh?
Or, how about those of you in CT, GA, IL, IN, MD, NJ, NY, PA, SC or VA?
Customers in these 11 states had their payment card data at risk as cybercrooks gained access to Aldi to install bogus point of sale terminals.
The bogus terminals drank the credit card data faster than you can chug sweet tea at a bar-b-q.
They pulled name, account number and pin.
By the way, this went on from June 1, 2010 - August 31, 2010.
Sources:
"Grocery Terminals Slurped Payment Card Data", The Register, Dan Goodin, October 8, 2010.
Aldi Foods Press Release
Or, how about those of you in CT, GA, IL, IN, MD, NJ, NY, PA, SC or VA?
Customers in these 11 states had their payment card data at risk as cybercrooks gained access to Aldi to install bogus point of sale terminals.
The bogus terminals drank the credit card data faster than you can chug sweet tea at a bar-b-q.
They pulled name, account number and pin.
By the way, this went on from June 1, 2010 - August 31, 2010.
Sources:
"Grocery Terminals Slurped Payment Card Data", The Register, Dan Goodin, October 8, 2010.
Aldi Foods Press Release
Thursday, September 30, 2010
Don't be tricked into being a money mule
Earlier this week, the UK announced that they had busted a major cybercriminal ring. The crime ring was using the Zeus trojan and it is estimated that they stole $30 million from bank accounts across the globe.
The mules are people that have been recruited by the cybercriminals to open bank accounts and transfer funds. Some mules are drawn in, unknowingly, by sophisticated schemes where they even apply for jobs, interview, and work for a "company". Some mules know exactly what they are working on.
People could get tricked via jobs posted on help wanted web sites and social networking sites.
The cybercriminals and mules used many different companies to spread out their evil. They hit banks in the UK and the US. Ally, Chase, PNC, B of A, TD Bank are some of the banks named in the Wall Street Journal article.
Sources:
"More details emerge on cybercriminal ring that stole $30 million", Byron Acohido, USA Today, 9/30/10.
"Millions Netted in Global Bank Hack", Chad Bray and Cassell Bryan-Low, Wall Street Journal, 10/1/10.
The mules are people that have been recruited by the cybercriminals to open bank accounts and transfer funds. Some mules are drawn in, unknowingly, by sophisticated schemes where they even apply for jobs, interview, and work for a "company". Some mules know exactly what they are working on.
People could get tricked via jobs posted on help wanted web sites and social networking sites.
The cybercriminals and mules used many different companies to spread out their evil. They hit banks in the UK and the US. Ally, Chase, PNC, B of A, TD Bank are some of the banks named in the Wall Street Journal article.
Sources:
"More details emerge on cybercriminal ring that stole $30 million", Byron Acohido, USA Today, 9/30/10.
"Millions Netted in Global Bank Hack", Chad Bray and Cassell Bryan-Low, Wall Street Journal, 10/1/10.
Friday, September 17, 2010
New Identity theft sounds like an HGTV reality show - "Steal My House"
ZDNet reported this week that a Western Australian man was the victim of a new bizarre twist of identity theft.
According to the report, Roger Mildenhall, was contacted by a neighbor saying he had seen one of his investment houses for sale. Mildenhall looked into it and found that it was for sale . He was also surprised to learn that he sold another property in June. In this economy, you might jump for joy. Roger was dumbfounded since he never intended to sell these properties - this was done unauthorized by him.
ALL transactions were made via email, telephone, and fax. No human interaction.
The report indicates that alleged scammers hacked into Mildenhall's email account. From there they were able to get to his personal and property documents. They sold the house and sent the cash to bank accounts in China.
So far, the investigation has not found any wrongdoing by the real estate agent.
In the meantime, Roger Mildenhall, is half a million dollars poorer.
STEPS TO PROTECT YOURSELF:
1. Strong email passwords
2. Do not reuse passwords
3. Avoid sending sensitive information, such as property data, via email
4. U.S. Banks and Mortgage companies may want to review their fraud prevention processes
Sources:
ZDNet, "Crims use hacked email to steal house", Darren Pauli, September 14, 2010
According to the report, Roger Mildenhall, was contacted by a neighbor saying he had seen one of his investment houses for sale. Mildenhall looked into it and found that it was for sale . He was also surprised to learn that he sold another property in June. In this economy, you might jump for joy. Roger was dumbfounded since he never intended to sell these properties - this was done unauthorized by him.
ALL transactions were made via email, telephone, and fax. No human interaction.
The report indicates that alleged scammers hacked into Mildenhall's email account. From there they were able to get to his personal and property documents. They sold the house and sent the cash to bank accounts in China.
So far, the investigation has not found any wrongdoing by the real estate agent.
In the meantime, Roger Mildenhall, is half a million dollars poorer.
STEPS TO PROTECT YOURSELF:
1. Strong email passwords
2. Do not reuse passwords
3. Avoid sending sensitive information, such as property data, via email
4. U.S. Banks and Mortgage companies may want to review their fraud prevention processes
Sources:
ZDNet, "Crims use hacked email to steal house", Darren Pauli, September 14, 2010
Monday, August 30, 2010
Cybercriminals have no shame. They even steal from a church!
Sent to me by Jerry Tylman, Founder of Greenway Solutions:
Organized cyber thieves stole more than $600,000 from the Catholic Diocese of Des Moines, Iowa earlier this month. The funds were spirited away with the help of dozens of unwitting co-conspirators hired through work-at-home job scams, at least one of whom was told the money was being distributed to victims of the Catholic Church sex abuse scandals.
In a statement released last week, the diocese said the fraud occurred between Aug. 13 and Aug. 16, apparently after criminals had stolen the diocese’s online banking credentials. The Diocese it was alerted to the fraud on Aug. 17 by its financial institution, Bankers Trust of Des Moines.
Full article:
Thursday, July 22, 2010
Guest Post - Kevin Elrod - Small Business - The New Focus For Cybercriminals
We have a guest post from Summer Intern, Kevin Elrod.
RESEARCH OUTLINE:
Topic: Cybercrime – Small Business Cases
Research by: Kevin Elrod
Date: 07/22/2010
TEASER/TITLE: Small Businesses – The New Focus for Cybercriminals
SUMMARY PARAGRAPH
For many small business owners, the recent economic downturn has brought a sea of economic challenges. A new threat, however, has emerged which may be the nail in the coffin, and it has come in the form of cybercrime. Hackers and computer criminals have lately been turning away from the impenetrable security systems of large corporations in order to reap the fruits of the vulnerable small business sector. To the careless, or even prepared, entrepreneur this may spell bankruptcy, and the effects could trickle down causing further harm to local economies. Action must be taken in order to insure financial security for small business owners, especially in our current economic climate.
KEY FINDINGS
Cybersecurity insurance is an effective and reasonable way of protecting a small company’s business assets, although according to cio.com only 25% of companies have it
After the development of anti-virus software, the main attack channel has switched from email to the web for many criminals targeting small businesses.
A hefty portion of small business owners have little to no cybersecurity at all. According to a report by Tim Wilson for DarkReading.com, 1/5 of all small businesses don’t use anti-virus software, 60% have unencrypted wireless networks, and 2/3 do not have a proper security plan in place.
BACKGROUND
Since the beginnings of the internet, bad intentioned citizens and criminals have sought to manipulate it for their own personal gain. Cybercrime has evolved tremendously over the past few decades, from the “Melissa” and “I Love You” viruses of the late 1990’s which jumpstarted the growth of anti-virus software to the more recent denial-of-service (DoS) attacks which freeze networks by overloading them with outside data. Now, cybercrime is undergoing a new phase by switching its focus to the susceptible assets of small businesses. According to a survey conducted by the Canadian Chamber of Commerce 85% of all business fraud occurs in small to medium-sized businesses. These companies do not have the means to pay enough attention to these threats due to scarce resources and insufficient time.
After the popular growth of anti-virus software in the late 1990’s most of all cyber attacks have switched from emails to the World Wide Web. Today, the most common threat faced by small businesses is web-based crime. Small company owners must realize that security plans that commit solely to anti-virus software is no longer sufficient to keep themselves protected.
STRATEGIC PLANNING ASSUMPTIONS
Hackers are turning away from the hardened, secure networks of large corporations and turning towards small businesses
Web-based threats are emerging as the most common form of cybercrime. According to the World Economic Forum total online theft for 2009 alone totaled over $1 trillion.
Small companies are becoming increasingly disintegrated and spread out as they begin to rely more heavily on outside consultants and expertise. Mergers also divide the company trust by acquiring rival business staff. These hazards increase the risk of untrustworthy employees who might use company knowledge to steal their electronic assets.
ANALYSIS
Keeping one’s business secure from cyber threats in today’s digital world is no longer as simple as it used to be. Evolution has taken small businesses from cash and checks to regulating most of their finances on the web. Not all small-sized businesses have safely adapted to this change, however. According to David Hogan, senior vice president for the National Retail Federation, only 60% of Level 3 businesses (just one level above mom-and-pop shops) have complied with the Payment Card Industry’s Data and Security Standards (PCI DSS) which strive to protect credit card data. Companies that put off essential security standards can suffer drastic consequences, as can be seen in a case of a California escrow firm. Last March, computer bandits broke into the online banking network of Village View Escrow Inc., a company based out of Redondo Beach, stealing a total amount of $465,000. The culprits then proceeded to make 26 wire transfers to 20 various individuals around the globe who have no relation to the company. Unlike consumers, when businesses lose money online there really isn’t a sure way of retrieving it. Since the incident, the owner of Village View Escrow has had to take out a $395,000 loan at 12% interest to get back on track, and it will surely be some time before that ever happens.
Another similar incident occurred last April at DKG Enterprises, an Oklahoma City party supplies firm. David Green, a manager for DKG, usually only accessed the company’s bank account from a Mac computer in the office. Last April, however, while he was sick and working from his home he found he needed to authorize a company transfer. He decided to use his wife’s PC because he could not get to the office that day. Of course, this was the same computer his children play on, and it had at that time contracted a password-stealing Trojan horse. A few days later, computer hackers had stolen $100,000 from the company account using their stolen password. As of yet, DKG has been able to recover only $22,000 of their losses. Krebsonsecurity.com recommends using a Mac instead of a PC when handling online business accounts because many of the viruses aimed at stealing passwords simply do not work on Macs. In any case, these cases stress the importance of protecting one’s business from cybercrime.
RECOMMENDATIONS
Consider using in third-party security services to manage credit card purchase processes to reduce the risk of cybertheft.
Changing passwords regularly is an effective security policy especially after an employee leaves the company.
Purchasing cybersecurity insurance is one effective measure of protecting a business’ assets. After a recent incident in which cyber thieves stole $35,000 from Brookland Fresh Water Supply District, the company was able to retrieve all of their funds in exchange for a $500 deductable. Without the insurance not only would the company have suffered but so would the 1,300 homes and businesses it provides for.
Encrypt your wireless networks – this needs no further explanation. Consult a computer professional if you are unsure how to do this.
Establish an acceptable use policy for office computers storing company data.
Arrange for all company computers to be equipped with up-to-date security software.
SOURCES
Tim Wilson, Darkreading, March 19, 2009
http://www.darkreading.com/security/perimeter/showArticle.jhtml?articleID=215901301
Brian Krebs, KrebsonSecurity, blog from Jun 10 – July 10 http://krebsonsecurity.com/category/smallbizvictims/
Randy James, Time, June 1, 2009 http://www.time.com/time/nation/article/0,8599,1902073,w00.html#ixzz0thKk6ckI
BusinessPundit.com interview with Robert Gorby, June 17, 2010 http://www.businesspundit.com/interview-protecting-your-small-business-from-cybercrime/
RESEARCH OUTLINE:
Topic: Cybercrime – Small Business Cases
Research by: Kevin Elrod
Date: 07/22/2010
TEASER/TITLE: Small Businesses – The New Focus for Cybercriminals
SUMMARY PARAGRAPH
For many small business owners, the recent economic downturn has brought a sea of economic challenges. A new threat, however, has emerged which may be the nail in the coffin, and it has come in the form of cybercrime. Hackers and computer criminals have lately been turning away from the impenetrable security systems of large corporations in order to reap the fruits of the vulnerable small business sector. To the careless, or even prepared, entrepreneur this may spell bankruptcy, and the effects could trickle down causing further harm to local economies. Action must be taken in order to insure financial security for small business owners, especially in our current economic climate.
KEY FINDINGS
Cybersecurity insurance is an effective and reasonable way of protecting a small company’s business assets, although according to cio.com only 25% of companies have it
After the development of anti-virus software, the main attack channel has switched from email to the web for many criminals targeting small businesses.
A hefty portion of small business owners have little to no cybersecurity at all. According to a report by Tim Wilson for DarkReading.com, 1/5 of all small businesses don’t use anti-virus software, 60% have unencrypted wireless networks, and 2/3 do not have a proper security plan in place.
BACKGROUND
Since the beginnings of the internet, bad intentioned citizens and criminals have sought to manipulate it for their own personal gain. Cybercrime has evolved tremendously over the past few decades, from the “Melissa” and “I Love You” viruses of the late 1990’s which jumpstarted the growth of anti-virus software to the more recent denial-of-service (DoS) attacks which freeze networks by overloading them with outside data. Now, cybercrime is undergoing a new phase by switching its focus to the susceptible assets of small businesses. According to a survey conducted by the Canadian Chamber of Commerce 85% of all business fraud occurs in small to medium-sized businesses. These companies do not have the means to pay enough attention to these threats due to scarce resources and insufficient time.
After the popular growth of anti-virus software in the late 1990’s most of all cyber attacks have switched from emails to the World Wide Web. Today, the most common threat faced by small businesses is web-based crime. Small company owners must realize that security plans that commit solely to anti-virus software is no longer sufficient to keep themselves protected.
STRATEGIC PLANNING ASSUMPTIONS
Hackers are turning away from the hardened, secure networks of large corporations and turning towards small businesses
Web-based threats are emerging as the most common form of cybercrime. According to the World Economic Forum total online theft for 2009 alone totaled over $1 trillion.
Small companies are becoming increasingly disintegrated and spread out as they begin to rely more heavily on outside consultants and expertise. Mergers also divide the company trust by acquiring rival business staff. These hazards increase the risk of untrustworthy employees who might use company knowledge to steal their electronic assets.
ANALYSIS
Keeping one’s business secure from cyber threats in today’s digital world is no longer as simple as it used to be. Evolution has taken small businesses from cash and checks to regulating most of their finances on the web. Not all small-sized businesses have safely adapted to this change, however. According to David Hogan, senior vice president for the National Retail Federation, only 60% of Level 3 businesses (just one level above mom-and-pop shops) have complied with the Payment Card Industry’s Data and Security Standards (PCI DSS) which strive to protect credit card data. Companies that put off essential security standards can suffer drastic consequences, as can be seen in a case of a California escrow firm. Last March, computer bandits broke into the online banking network of Village View Escrow Inc., a company based out of Redondo Beach, stealing a total amount of $465,000. The culprits then proceeded to make 26 wire transfers to 20 various individuals around the globe who have no relation to the company. Unlike consumers, when businesses lose money online there really isn’t a sure way of retrieving it. Since the incident, the owner of Village View Escrow has had to take out a $395,000 loan at 12% interest to get back on track, and it will surely be some time before that ever happens.
Another similar incident occurred last April at DKG Enterprises, an Oklahoma City party supplies firm. David Green, a manager for DKG, usually only accessed the company’s bank account from a Mac computer in the office. Last April, however, while he was sick and working from his home he found he needed to authorize a company transfer. He decided to use his wife’s PC because he could not get to the office that day. Of course, this was the same computer his children play on, and it had at that time contracted a password-stealing Trojan horse. A few days later, computer hackers had stolen $100,000 from the company account using their stolen password. As of yet, DKG has been able to recover only $22,000 of their losses. Krebsonsecurity.com recommends using a Mac instead of a PC when handling online business accounts because many of the viruses aimed at stealing passwords simply do not work on Macs. In any case, these cases stress the importance of protecting one’s business from cybercrime.
RECOMMENDATIONS
Consider using in third-party security services to manage credit card purchase processes to reduce the risk of cybertheft.
Changing passwords regularly is an effective security policy especially after an employee leaves the company.
Purchasing cybersecurity insurance is one effective measure of protecting a business’ assets. After a recent incident in which cyber thieves stole $35,000 from Brookland Fresh Water Supply District, the company was able to retrieve all of their funds in exchange for a $500 deductable. Without the insurance not only would the company have suffered but so would the 1,300 homes and businesses it provides for.
Encrypt your wireless networks – this needs no further explanation. Consult a computer professional if you are unsure how to do this.
Establish an acceptable use policy for office computers storing company data.
Arrange for all company computers to be equipped with up-to-date security software.
SOURCES
Tim Wilson, Darkreading, March 19, 2009
http://www.darkreading.com/security/perimeter/showArticle.jhtml?articleID=215901301
Brian Krebs, KrebsonSecurity, blog from Jun 10 – July 10 http://krebsonsecurity.com/category/smallbizvictims/
Randy James, Time, June 1, 2009 http://www.time.com/time/nation/article/0,8599,1902073,w00.html#ixzz0thKk6ckI
BusinessPundit.com interview with Robert Gorby, June 17, 2010 http://www.businesspundit.com/interview-protecting-your-small-business-from-cybercrime/
Tuesday, July 20, 2010
Guest Post - Ashesh Mamidi - The New Target of Cybercriminals - Small Business
This is a guest post from intern Ashesh Mamidi.
Research Outline
Topic: Small businesses
Research by: Ashesh Mamidi
Date: 07/20/2010
TEASER/TITLE: The new target of cyber criminals
SUMMARY PARAGRAPH:
Small businesses today have shifted from paper records to electronically stored information. This so-called digitalization process has helped small businesses attain a dramatically more efficient way of doing business. On the other hand, this has also opened new doors for cyber criminals to penetrate a small businesses' data system. This trend could result in massive financial and retail security fraud and breaches over the next decade.
Criminals will find new avenues to get malicious software onto a small business' computer systems. There will be attempts to embed malicious software into the downloads of software from reputable vendors. If software isn't authenticated, then attempts will be made to intercept software being downloaded and replace it with malicious versions. This is a wake-up call for small businesses because security issues with the Internet will cause dramatic loss of revenue for these entrepreneurial enterprises in the years ahead.
These small businesses are the easy targets for the cybercriminals and more than money, the criminals are interested in the intellectual property which they can use elsewhere to gain financially.
KEY FINDINGS:
• Criminals are targeting companies that have PII: Personally Identifiable Information (PII) is at risk. The breakdown of identity theft cases is as follows (2009):
• 26% credit card fraud, 18% utilities fraud, 17% bank fraud, 12% employment fraud, 5% loan fraud, 9% government fraud, 13% other.
• Criminals are targeting company bank accounts
• Criminals target other information:
• Data about them or their customers such as Credit card, Social Security and bank account numbers.
• Loss of intellectual and financial property – It is estimated that losses can range from $20 to $90 billion annually to upwards of $240 billion a year.
See statistics at:
http://www.ojp.usdoj.gov/ovc/ncvrw/2005/pg5i.html
METHODS DEPLOYED TO BREAK THE “LOCKS”:
• Virus - Studies in December 2007 have shown that the effectiveness of antivirus software has decreased in recent years, particularly against unknown or zero day attacks. The German computer magazine c’t found that detection rates for these threats had dropped from 40-50% in 2006 to 20-30% in 2007. In general antivirus software removes only one-third of all the viruses.
.
• Malicious software – It gives partial to full control of the computer to do whatever the malware creator wants. The damage done can vary from something slight as changing the author’s name on a document to full control of the machine without our ability to easily find out. Malicious software lurks behind emails, links on social networking sites, and in legitimate downloads.
RECOMMENDATIONS:
SOFTWARE PROTECTION:
• Consider Anti-virus software like Shield Deluxe-Antivirus Protection, Trend Micro Antivirus Internet Security 2010, Norton Antivirus 2010and anti-malware software like Avira, Threatfire, Combofix etc.
• Discuss Implementation of Several Packages: Combining Anti-Virus, with Anti-Spyware, Intrusion Prevention Service, and Application intelligence can deliver stronger network security protection against a comprehensive array of dynamic threats. The combination helps combat viruses, spyware, worms, Trojans and software vulnerabilities such as buffer overflows, as well as backdoor exploits and other malicious code. This provides application layer attack protection not only against external threats, but also against those originating inside the network. The lower layer technologies like SSL/TLS, firewall and IPSec support application layer security.
CLOUD or SaaS: In-the-Cloud security services may offer an easy and affordable solution for small businesses, especially for those that cannot afford an extensive, dedicated IT staff. Some cloud computing services offer better business continuity options and more sophisticated technology than small business do-it-yourself teams can do.
INTERNET USE POLICY - An internet acceptable use policy clearly defines how employees should and should not use the internet at work. For example:
• Instructions on what to do before downloading material, checking the size of the file and its source.
• A warning to abide by any copyright and licensing restrictions on internet-sourced material.
CONTENT FILTER - Content filtering is the technique whereby content is blocked or allowed based on analysis of its content, rather than its source or other criteria. It is most widely used on the internet to filter email and web access; basically used to filter spam.
SEPARATE COMPUTERS: Keep business and home computing separate.
EMPLOYEE AWARENESS – Phishing, a method of capturing confidential information over the internet, mainly takes place by using emails which appear to be coming from a trusted website source. Things to do for employee awareness and email protection:
• Ignoring suspicious mail which ask for personal information
• We should never try to give credit or debit card information in response to emails.
• Change the password regularly.
• Use strong passwords
SAFE INTERNET CONNECTIONS: Wi-fi safety such as using secure sites (a site whose web address starts with https instead of http is always secure), making sure that no one is watching you when you enter personal information or when entering PIN code at an ATM, being careful while sending sensitive data when using a public wi-fi hotspot.
BACKGROUND:
Small businesses are a target now more than ever before. Malicious security threats—particularly those executed via the Web—are abundant as an unprecedented number of botnets, Trojan horses and self-replicating worms, created and executed by organized criminal networks, are unleashed on networks to steal personal and financial information. In 1999, it is estimated that Fortune 1,000 companies sustained losses of more than $45 billion from theft of proprietary information, with insiders to the organization being seen as a higher than average threat. Borrowing software from work for personal use accounts for some of the $12 billion lost to software piracy worldwide.
A lagging economy has caused many companies to rein in their IT budgets, opening small businesses up to attacks simply because they lack the money and staffing for proper security infrastructure.
The lack of resources paired with a lack of awareness about security issues create gaps in small businesses security policies regarding behavior and best practices.
ANALYSIS:
DATA BREACHES: 47% of Small Businesses have lost confidential data in the past and huge percentage of loss came from deliberate theft (52%) as opposed to accidental data loss. Of this figure, 24% was attributed to people outside the organization, and insiders were found to account for 16% of illegal data loss, with loss through partners at 15%. 30% of firms who don't password protect their laptops, are running the very real risk of harming their businesses and reputations through losing confidential data by accident.
Statistics referred from:
http://www.newstatesman.com/technology/2010/06/cyber-attacks-businesses-risk
LACK OF PROTECTION: Nearly one-fifth of small businesses don't even use antivirus software. Sixty percent don't use any encryption on their wireless links, and two-thirds of small businesses don't have a security plan in place. The majority of small businesses and even some medium size businesses do not have the dedicated IT support needed to monitor their computer networks and protect themselves from attack. Finally, many small business owners understandably lack the expertise to deploy the software or hardware solutions available to address ever-changing security challenges.
BUSINESS BANK ACCOUNTS HACKED: Vulnerable businesses, have sustained tens and even hundreds of thousands of dollars in losses, with little hope of recovering the money. Some have filed lawsuits against banks, charging that they failed to detect and stop transactions that were patently fraudulent. For example, Hillary Machinery Inc. filed a lawsuit against its bank, PlainsCapital, after online crooks used stolen credentials to transfer more than $800,000 from its account last year. The bank later recovered about $600,000 of the stolen funds but has so far refused to compensate the Plano, Texas-based manufacturing firm for the remainder.
Statistics referred from:
http://www.computerworld.com/s/article/print/9168458/Cyberattacks_raise_e_banking_security_fears?taxonomyName=Security&taxonomyId=17
IMPLICATIONS:
Businesses of every size rely on the Internet. Innovative use of the Internet can confer a competitive advantage on small and medium sized businesses. That edge can be dulled or even eliminated by cybercriminals and other threats. A single breach in which a business owner or their customer’s data is stolen could literally destroy a small business. Less dramatically, but perhaps as importantly, common Internet risks like spyware and malware can damage computer software and wreak havoc on productivity. So can employee access to non-work related web sites. Blocking certain websites in a work environment is easy to do and greatly reduces risk.
Such cyber thefts have led multiple businesses to file lawsuits against their banks and prompted government regulators to call on financial institutions to improve their security systems.
RECOMMENDATIONS:
There is no one size fits all approach and every business will have its own risk exposures. If you are a business owner, consider having your business evaluated for risks of cyber attack or data loss. Business owners need to stay on top of the threat by implementing a sound data loss and privacy plan.
Research Outline
Topic: Small businesses
Research by: Ashesh Mamidi
Date: 07/20/2010
TEASER/TITLE: The new target of cyber criminals
SUMMARY PARAGRAPH:
Small businesses today have shifted from paper records to electronically stored information. This so-called digitalization process has helped small businesses attain a dramatically more efficient way of doing business. On the other hand, this has also opened new doors for cyber criminals to penetrate a small businesses' data system. This trend could result in massive financial and retail security fraud and breaches over the next decade.
Criminals will find new avenues to get malicious software onto a small business' computer systems. There will be attempts to embed malicious software into the downloads of software from reputable vendors. If software isn't authenticated, then attempts will be made to intercept software being downloaded and replace it with malicious versions. This is a wake-up call for small businesses because security issues with the Internet will cause dramatic loss of revenue for these entrepreneurial enterprises in the years ahead.
These small businesses are the easy targets for the cybercriminals and more than money, the criminals are interested in the intellectual property which they can use elsewhere to gain financially.
KEY FINDINGS:
• Criminals are targeting companies that have PII: Personally Identifiable Information (PII) is at risk. The breakdown of identity theft cases is as follows (2009):
• 26% credit card fraud, 18% utilities fraud, 17% bank fraud, 12% employment fraud, 5% loan fraud, 9% government fraud, 13% other.
• Criminals are targeting company bank accounts
• Criminals target other information:
• Data about them or their customers such as Credit card, Social Security and bank account numbers.
• Loss of intellectual and financial property – It is estimated that losses can range from $20 to $90 billion annually to upwards of $240 billion a year.
See statistics at:
http://www.ojp.usdoj.gov/ovc/ncvrw/2005/pg5i.html
METHODS DEPLOYED TO BREAK THE “LOCKS”:
• Virus - Studies in December 2007 have shown that the effectiveness of antivirus software has decreased in recent years, particularly against unknown or zero day attacks. The German computer magazine c’t found that detection rates for these threats had dropped from 40-50% in 2006 to 20-30% in 2007. In general antivirus software removes only one-third of all the viruses.
.
• Malicious software – It gives partial to full control of the computer to do whatever the malware creator wants. The damage done can vary from something slight as changing the author’s name on a document to full control of the machine without our ability to easily find out. Malicious software lurks behind emails, links on social networking sites, and in legitimate downloads.
RECOMMENDATIONS:
SOFTWARE PROTECTION:
• Consider Anti-virus software like Shield Deluxe-Antivirus Protection, Trend Micro Antivirus Internet Security 2010, Norton Antivirus 2010and anti-malware software like Avira, Threatfire, Combofix etc.
• Discuss Implementation of Several Packages: Combining Anti-Virus, with Anti-Spyware, Intrusion Prevention Service, and Application intelligence can deliver stronger network security protection against a comprehensive array of dynamic threats. The combination helps combat viruses, spyware, worms, Trojans and software vulnerabilities such as buffer overflows, as well as backdoor exploits and other malicious code. This provides application layer attack protection not only against external threats, but also against those originating inside the network. The lower layer technologies like SSL/TLS, firewall and IPSec support application layer security.
CLOUD or SaaS: In-the-Cloud security services may offer an easy and affordable solution for small businesses, especially for those that cannot afford an extensive, dedicated IT staff. Some cloud computing services offer better business continuity options and more sophisticated technology than small business do-it-yourself teams can do.
INTERNET USE POLICY - An internet acceptable use policy clearly defines how employees should and should not use the internet at work. For example:
• Instructions on what to do before downloading material, checking the size of the file and its source.
• A warning to abide by any copyright and licensing restrictions on internet-sourced material.
CONTENT FILTER - Content filtering is the technique whereby content is blocked or allowed based on analysis of its content, rather than its source or other criteria. It is most widely used on the internet to filter email and web access; basically used to filter spam.
SEPARATE COMPUTERS: Keep business and home computing separate.
EMPLOYEE AWARENESS – Phishing, a method of capturing confidential information over the internet, mainly takes place by using emails which appear to be coming from a trusted website source. Things to do for employee awareness and email protection:
• Ignoring suspicious mail which ask for personal information
• We should never try to give credit or debit card information in response to emails.
• Change the password regularly.
• Use strong passwords
SAFE INTERNET CONNECTIONS: Wi-fi safety such as using secure sites (a site whose web address starts with https instead of http is always secure), making sure that no one is watching you when you enter personal information or when entering PIN code at an ATM, being careful while sending sensitive data when using a public wi-fi hotspot.
BACKGROUND:
Small businesses are a target now more than ever before. Malicious security threats—particularly those executed via the Web—are abundant as an unprecedented number of botnets, Trojan horses and self-replicating worms, created and executed by organized criminal networks, are unleashed on networks to steal personal and financial information. In 1999, it is estimated that Fortune 1,000 companies sustained losses of more than $45 billion from theft of proprietary information, with insiders to the organization being seen as a higher than average threat. Borrowing software from work for personal use accounts for some of the $12 billion lost to software piracy worldwide.
A lagging economy has caused many companies to rein in their IT budgets, opening small businesses up to attacks simply because they lack the money and staffing for proper security infrastructure.
The lack of resources paired with a lack of awareness about security issues create gaps in small businesses security policies regarding behavior and best practices.
ANALYSIS:
DATA BREACHES: 47% of Small Businesses have lost confidential data in the past and huge percentage of loss came from deliberate theft (52%) as opposed to accidental data loss. Of this figure, 24% was attributed to people outside the organization, and insiders were found to account for 16% of illegal data loss, with loss through partners at 15%. 30% of firms who don't password protect their laptops, are running the very real risk of harming their businesses and reputations through losing confidential data by accident.
Statistics referred from:
http://www.newstatesman.com/technology/2010/06/cyber-attacks-businesses-risk
LACK OF PROTECTION: Nearly one-fifth of small businesses don't even use antivirus software. Sixty percent don't use any encryption on their wireless links, and two-thirds of small businesses don't have a security plan in place. The majority of small businesses and even some medium size businesses do not have the dedicated IT support needed to monitor their computer networks and protect themselves from attack. Finally, many small business owners understandably lack the expertise to deploy the software or hardware solutions available to address ever-changing security challenges.
BUSINESS BANK ACCOUNTS HACKED: Vulnerable businesses, have sustained tens and even hundreds of thousands of dollars in losses, with little hope of recovering the money. Some have filed lawsuits against banks, charging that they failed to detect and stop transactions that were patently fraudulent. For example, Hillary Machinery Inc. filed a lawsuit against its bank, PlainsCapital, after online crooks used stolen credentials to transfer more than $800,000 from its account last year. The bank later recovered about $600,000 of the stolen funds but has so far refused to compensate the Plano, Texas-based manufacturing firm for the remainder.
Statistics referred from:
http://www.computerworld.com/s/article/print/9168458/Cyberattacks_raise_e_banking_security_fears?taxonomyName=Security&taxonomyId=17
IMPLICATIONS:
Businesses of every size rely on the Internet. Innovative use of the Internet can confer a competitive advantage on small and medium sized businesses. That edge can be dulled or even eliminated by cybercriminals and other threats. A single breach in which a business owner or their customer’s data is stolen could literally destroy a small business. Less dramatically, but perhaps as importantly, common Internet risks like spyware and malware can damage computer software and wreak havoc on productivity. So can employee access to non-work related web sites. Blocking certain websites in a work environment is easy to do and greatly reduces risk.
Such cyber thefts have led multiple businesses to file lawsuits against their banks and prompted government regulators to call on financial institutions to improve their security systems.
RECOMMENDATIONS:
There is no one size fits all approach and every business will have its own risk exposures. If you are a business owner, consider having your business evaluated for risks of cyber attack or data loss. Business owners need to stay on top of the threat by implementing a sound data loss and privacy plan.
SOURCES:
1) "Small Business IT Channel News for VARs and Technology Integrators--ChannelWeb." Channel News, Technology News and Reviews for VARs and Technology Integrators--ChannelWeb. Web. 19 July 2010. .
2) Statesman, New. "New Statesman - Cyber Attacks Cost Small and Medium Businesses £200,000 Annually." New Statesman - Britain's Current Affairs & Politics Magazine. Web. 19 July 2010. .
3) "U.S. Small Businesses Vulnerable to Cyber Attacks, Says VirnetX Research Director -- SCOTTS VALLEY, Calif., Feb. 10 /PRNewswire-FirstCall/." PR Newswire: Press Release Distribution, Targeting, Monitoring and Marketing. Web. 19 July 2010. .
4) Parental Controls, Internet Filter, Online Safety Software and Services | CyberPatrol. Web. 19 July 2010. .
5) Vijayan, Jaikumar. "Cyberattacks Raise E-banking Security Fears - Computerworld." Computerworld - IT News, Features, Blogs, Tech Reviews, Career Advice. Web. 19 July 2010. .
6) 23, Folino | Nov. "Is Your Small Business Cyber-Secure?" Small Business and Small Business Information for the Entrepreneur. 23 Nov. 2009. Web. 19 July 2010. .
7) Goldman, David. "What Cybercriminals Do with Your Information - Sep. 16, 2009." Business, Financial, Personal Finance News - CNNMoney.com. 16 Sept. 2009. Web. 19 July 2010. .
8) "Cyber Liability : Connecticut Business Litigation Blog." Connecticut Business Litigation Blog : Connecticut Business Lawyer & Attorney : N. Kane Bennett : Raymond & Bennett Law Firm : Hartford, Middletown, Glastonbury. Web. 19 July 2010. .
9) Thompson, Steve. "FBI Warns Small Businesses about Rising Cybercrime Dangers." Merchant Account & Credit Card Processing Guide - MerchantAccountGuide.com. Web. 19 July 2010. .
10) "Create an Internet Usage Policy | Business Link." Business Support, Information and Advice | Business Link. Web. 19 July 2010. .
11) "Content Filtering." Wikipedia, the Free Encyclopedia. Web. 19 July 2010. .
12) "Network Security, Firewall & Wireless - Gateway AV, SPY & Intrusion Prevention Service - SonicWALL, Inc." SonicWALL - Select Your Region or Country. Web. 19 July 2010. .
13) http://ezinearticles.com/?What-is-Phishing---Email-Phishing-Protection-Tips&id=4213593
Tuesday, May 4, 2010
Guest Post - Nick Volpe - Identity Theft - 500K American impacted annually
Nick Volpe is a Spring Semester Cybersecurity Research Analyst at Fortalice®, LLC. He is a student at Immaculata University.
Research Outline
Topic: Stolen Identity
Date: 2/23/10
TEASER/TITLE: Don’t be one of the 500,000 Americans that will have their identities stolen this year!
SUMMARY PARAGRAPH: Personal information and the privacy of that information has always been an issue. At the same time, there have always been exploiters of that information and privacy that goes along with it. As technology advances, both information and privacy gets stronger and much more complex and the methods used by thieves must catch up to the technology. According to CBS News, this year 500,000 Americans will have their identities stolen with up to $4 billion in damages.
KEY FINDINGS
(List 3-5 bullets)
- Popular ways identity thieves are stealing personal information:
- Dumpster diving – getting information out of the trash
- Skimming – using a device to steal your credit or bank card number
- Phishing – using trickery usually in the form of SPAM e-mail or Pop-up solicitations to get a victim to reveal personal information
- Change of address – using a change of address form to divert personal mail to another location
- General theft – stealing electronics as well as wallets and purses to gather personal information
BACKGROUND
2-3 PARAGRAPHS
Theft is always a prevalent issue in any society. From mass looting to pick pocketing, criminals come up with new and sneaky ways to make money and satisfy their greed. When it comes to identity, thieves find it to be a very comfortable and sometimes easy way to steal assets from an unknowing victim. All it takes is a phone call with a fake name or some social engineering to convince a company that you are another person.
There are many laws afforded to us by our government that try to protect our right to privacy in terms of identity. Some of those laws include the Identity Theft and Assumption Deterrence Act, the Fair Credit Reporting Act, and the Gramm-Leach-Bliley Act which were put in place to help American consumers gain control over their information.
However, this is still not enough. Protecting oneself from identity theft requires effort and proactive measures.
STRATEGIC PLANNING ASSUMPTIONS:
(3-5 Bullets that talk about any future trends noted for beyond 2010)
- Companies using more and more factors of authentication to protect the identity of their customers/clients (e.g. banks using images and key fobs as a form of authentication)
- Government pressing harder and stricter laws for companies to protect data using multi-factor authentication such as biometrics
ANALYSIS:
2-3 PARAGRAPHS
Identity theives are a new kind of criminal. With vast resources like the internet, they are able to gain valuable personal information on a person with a small amount of effort if the victim is not careful enough. They are using new tactics like phishing and skimming as well as older tactics including dumpster diving and theft. Regardless of how the identity is stolen, a person must be proactive with their own identity and personal information including mail, financial information, and government documents.
Many Americans have had or will have their identity stolen at some point and it will cost them billions of dollars and massive amounts of time cleaning up from it. The cheapest, easiest, and most effective way of recovering from identity theft is never letting it happen by being very cautious and following all recommendations. Consumers must safeguard their information as best as possible in order to keep their identity to themselves.
IMPLICATIONS:
5-10 BULLETS
- You may be a victim of stolen identity if:
- You detect fraudulent charges or unknown payments on your financial accounts such as bank accounts and credit card accounts
- You suspect or know that you aren’t receiving all your mail, especially statements
- You find accounts have been opened in your name without your knowledge
- You are confused or suspicious about information appearing on your credit report
- How to recover from/get out of identity theft:
- Contact your local police department to report the crime
- Keep documents of all contact with financial institutions and authorities
- Place a security freeze or fraud alert on your credit report at all 3 major credit bureaus
- Monitor closely all credit accounts and contact the creditor if fraudulent activity is suspected
- Use a credit monitoring service as a third party method of getting yourself out of identity theft
- Change all your PINs/passwords and close accounts that have been accessed fraudulently
- Contact the DMV, U.S. State Department, the FTC, your local postal inspector, Social Security Administration (SSA) to make sure other documents or assets haven’t been utilized in your name
RECOMMENDATIONS:
5-10 BULLETS
- Tips for protecting personal identity:
- Be aware of what information is out there about identity theft so that you can protect your own
- Sign your name on all credit and debit cards and only carry the ones you need on your person
- Shred documents with personal information including social security number
- Get a free copy of personal credit report annually from all 3 major credit bureaus
- Equifax
- TransUnion
- Experian
- Protect and encrypt personal information stored on laptops and mobile electronics such as smartphones and PDAs
- Always confirm the use of Secure Socket Layer (SSL) certificates on sites where you make financial transactions or deal with financial or personal information like e-merchants and online banking
SOURCES:
- "Fighting Back Against Identity Theft." Federal Trade Commission. FTC, Web. <http://www.ftc.gov/bcp/edu/
microsites/idtheft/index.html> . - "Stolen Identity: A Consumer Nightmare." Infoplease. Pearson Education, Web. <http://www.infoplease.com/
ipa/A0903927.html>. - "What To Do If Your Identity Is Stolen." Nolo. Web. <http://www.nolo.com/legal-
encyclopedia/article-29691. html>. - "If Your Identity Is Stolen." BBB Online. Better Business Bureau, Web. <http://www.bbbonline.org/
idtheft/stolenid.asp>. - Lipka, Mitch. "6 Signs Your Identity May Have Been Stolen." Wallet Pop. 16 Oct 2009. AOL, Web. <http://www.walletpop.com/
fraud/eim/article/6-signs- your-identity-may-have-been/ 721005>. - "Learning Center: Facts and Statistics." Equifax. Equifax, Web. <http://www.equifax.com/cs/
Satellite/EFX_Content_C1/ 1172182371408/5-1/5-1_Layout. htm>. - Reynolds, George. Ethics in Information Technology. 2nd ed. Boston, MA: Cengage Learning, 2007. 105-131. Print.
"More than 27 million Americans have been victims of identity theft in the last five years.... To deal with the problem, consumers reported nearly $5 billion in out-of-pocket expenses."
-The New York Times
"Stealing someone's identity to acquire -- and use -- new credit cards has become one of the most popular white-collar crimes today, according to fraud investigators from across the country."
-Knight Ridder/Tribune Business News
"This year alone more than 500,000 Americans will be robbed of their identities...with more than $4 billion stolen in their names."
-CBSnews.com
"In one notorious case of identity theft, the US Department of Justice reported that the criminal incurred over $100,000 of credit card debt, obtained a federal home loan, and bought homes, motorcycles, and hand guns in the victim's name all the while calling his victim to taunt him."
-US Department of Justice Web site
"The number of identity thefts in the U.S. has skyrocketed during the past 15 months."
-CNN.com
"According to a convicted ID thief in Denver, CO, "On a good day I could make $5,000 in cash and another $7,000 to $8,000 in merchandise..."
-CBSnews.com
"A recent report on identity theft warned that there is likely to be "mass victimization" of consumers within the next two years. The report said consumers should be extra careful to monitor all their financial transactions for unexplained account activity, withdrawals, or fund transfers."
-The Gartner Group, a technology research group
"Every 79 seconds, a thief steals someone's identity, opens accounts in the victim's name and goes on a buying spree."
-CBSnews.com
"Experts report that a victim can spend anywhere from six months to two years recovering from identity theft."
-CNNfn.com
"Most people don't find out they have been a victim of a stolen identity until they are turned down for a loan or credit card. A copy of their credit report explaining the denial may unveil weeks or months of fraud."
-CNNfn.com
Source: Equifax
Guest Post - Nick Volpe - Small Businesses Need More Banking Protection
Nick Volpe is a Spring Semester Cybersecurity Research Analyst at Fortalice®, LLC. He is a student at Immaculata University.
Research Outline
by Nicholas W. Volpe
by Nicholas W. Volpe
Topic: Small and medium sized businesses are getting hacked and their bank accounts wiped out.
Date: 3/22/10
TEASER/TITLE: Small Businesses Need More Banking Protection Like Consumers Do
SUMMARY PARAGRAPH: Cyber-attacks by crooks are being targeted at businesses and their banking institutions. This can be attributed to the fact that small and medium sized businesses do not have all of the protections that consumers have on their banking accounts. This means that many fraudsters will exploit the flaws in the banking system to steal money from companies who may never get that money back.
CASE 1
- Pennsylvania housing development company
- Cumberland County Redevelopment Authority
- Theft took place against their bank, M&T on September 22, 2009
- $479,000+ was stolen from their bank account
- About $109,000 was originally recovered with no record of additional recovered amounts
- The criminals used a Clampi Trojan to infect a computer to get the necessary information required in the theft of the money
- Money was dispersed to other accounts at numerous other banking institutions
CASE 2
- Bullitt County, Kentucky
- $415,000 stolen from the county’s payroll accounts beginning on June 22, 2009 and lasting a few weeks
- Criminals used a key logging Trojan known as “Zeus” or “Zbot” on county treasurer’s PC
- Stolen information is sent via instant message
- Creates a tunnel between infected computer and infector’s computer so that the criminal can log on to the bank account with the infected computer
- Criminals dispersed funds to about 25 co-conspirator third-parties throughout the country
- Some if not all of the co-conspirators, or “money mules”, were recruited via Careerbuilder.com.
- Money was wired to the criminals in the Ukraine
- Bank told county that some of their money probably could be recovered but they weren’t sure of how much could or would be as of the writing of this article
CASE 3
- Western Beaver School District outside of Pittsburgh, PA
- More than $700,000 was stolen from the school district’s account
- The school district filed a lawsuit against their bank, ESB Bank, alleging that the bank should have prevented or flagged the fraudulent transaction because of the excessive amount of transactions in the school district’s account. The lawsuit seems to still be open.
- Criminals used some type of malicious software to steal the funds
- Funds were transferred between December 29, 2008 and January 2, 2009 in 74 transactions to 42 random individuals throughout the country
CASE 4
- Slack Auto Parts in Gainesville, GA
- About $75,000 was stolen from company’s bank account between July 3 and July 7, 2009
- An additional $69,000 theft was attempted but blocked by the bank
- Criminals used malicious Clampi Trojan, or "Ligats" and "Rscan", key logger on the company controller’s Windows PC to steal bank account passwords and access information
- Malicious software was found by a computer investigator to have been present on the system for over a year
- 9 transactions were wired to at least 6 “money mules” all over the country
- The bank was able to reverse $14,000 worth of wire transfers and the CEO of the company worked with the bank to try and recover the rest of the funds
IMPLICATIONS & RECOMMENDATIONS:
5-10 BULLETS
- Consumers are protected from unauthorized transactions by US law
- Businesses are not protected by the same laws
- Many banks do not have algorithms to detect fraud against business transaction processing systems, commonly ACH systems
- Businesses should only do online banking from locked down workstations with web browsing and email disabled
- Businesses need to be more vigilant and constantly checking their account to see exactly what is happening with their money
SOURCES:
- Krebs, Brian. "PC Invader Costs Ky. County $415,000." Security Fix. The Washington Post, 2 July 2009. Web. <http://voices.washingtonpost.
com/securityfix/2009/07/an_ odyssey_of_fraud_part_ii.html> . - Krebs, Brian. "The Growing Threat to Business Banking Online." Security Fix. The Washington Post, 20 July 2009. Web. <http://voices.washingtonpost.
com/securityfix/2009/07/the_ pitfalls_of_business_banki. html>. - "$479,000 heist from small business bank account lends weight to calls for online banking 'lock-down'." Finextra. Finextra Research, 16 Oct. 2009. Web. 23 Mar. 2010. <http://www.finextra.com/News/
fullstory.aspx?newsitemid= 20617>.
Subscribe to:
Posts (Atom)