Showing posts with label cyber criminals. Show all posts
Showing posts with label cyber criminals. Show all posts

Tuesday, July 16, 2013

The bank robbery of the future: cyberattacks.

Bank robbers no longer need to leave the comfort of their own home to rob a bank. No more guns, no more masks. Instead, they hide behind their computer screens and cover their digital tracks.

In today's world, there are multiple ways for cybercriminals to make money long before cash is actually transferred out of a bank account. Robbing a bank has become one of the last cogs in a much broader operation.

Online theft is almost always part of a much grander scheme. Though sometimes a high-skilled individual or single group of cybercriminals will handle all parts of an operation, most cybercrime is split up into several steps, each handled by a different player, according to Vikram Thakur, a principal manager at Symantec Security Response.

Most bank account thefts begin with a single malware developer who sells malicious software on an underground black market to hackers.

On those dark channels of the Internet, criminal hackers can buy tools to steal users' bank account credentials, services to bring down websites, or viruses to infect computers.

"There's more variety and more choices than me going to my local Costco," said Raj Samani, a chief technical officer at the security company McAfee.

It is easier than ever before to find and use these services, Samani said. Hiring a criminal hacker is easy, because today's malware requires hackers to have little technological knowledge to infect hundreds or thousands of computers.

And some services are fairly cheap. For instance, getting a hold of 1 million email addresses can cost just $111. That means there are more and more cybercriminals hoping to get in on an operation.

Once unsuspecting victims' credentials or bank account information has been collected, hackers may resell that data to someone who repackages it in a useful way and redistributes it on the black market.

Not all information has equal value. Often criminals are looking for credentials of wealthy individuals with accounts at financial institutions where they are familiar with the security systems.
"All the mature, smart criminals sell the goods to somebody else and cut themselves out of the operation, out of the cross hairs," said Thakur.

Up to this point in the operation, no money has been stolen -- but thousands or millions of dollars have already exchanged hands.

The cybercriminal who ultimately buys the bank account information may use it to transfer money out -- but that's a much higher-risk endeavor.

At this stage of the heist, cybercriminals may hire a "money mule" to increase what distance still exists between them and the act of cashing out. Mules sometimes use international wire transfers, make online purchases with stolen credit cards or actually go to the ATM using a stolen PIN and a spoofed debit card.

Money mules are often given a small share of the takings for their work, despite the fact that they're the easiest targets for law enforcement.

"There's a huge shortage of those people because they're actually at risk of being caught," said Thakur.

Most of us have at one time or another discovered our debit or credit card was used somewhere across the country. But even if the thieves take money from your account undetected, your financial institution typically covers the loss.

"Even though the threat is substantial, it does not always translate to people losing money," said Thakur.

And the banks are getting better at stopping breaches so that it's harder for criminals to successfully take money out at all.

The number of breaches have gone up slightly over the past year, but the trend is uneven. The Identity Theft Resource Center tracked 662 breaches at both banking and non-financial institutions in 2010, 419 breaches in 2011, and 470 breaches last year.

Financial institutions have gotten 10 times better at preventing data breaches since 1990, said Doug Johnson, vice president of risk management policy at the American Bankers Association.

"It's not a straight march forward," said Johnson. "But I think we clearly recognized that electronic fraud is going to increase."

Source: CNN Money

Tuesday, April 16, 2013

Cyberspies are now targeting small businesses as opposed to large corporations. Is your business protected?

­Cybercriminals are taking greater pains to infect the computers of certain employees at specific companies, and are increasingly targeting smaller organizations for sophisticated cyber espionage campaigns.

Those findings were released today by Symantec based on the security giant's analysis of malicious attacks that circulated globally on the Internet in 2012.

Symantec tracked a 42% increase targeted attacks over 12 months, with the greatest growth coming in network intrusions directed at companies with fewer than 250 employees.

Why are small businesses being targeted?
Small businesses often lack adequate security practices. Attackers are moving down the supply chain and choosing to breach the lesser defenses of a small business that may have business relationships with a larger company.

What can or should small businesses do?
The first step is knowing what information needs to be protected. Small businesses should look at where their important information is stored and how it is used, and should first look to protect those areas accordingly.

How can IES help?
We provide the best IT consulting services around! (Yes, that's what all of our competitors say too). But ask any of our current clients and they'll tell you the same. From basic virus protection to securing an entire network, IES technicians are there for our customers 24 hours a day, 7 days a week.

Give us a call today at 781-81-MY-IES (781-816-9437) to secure you business.

Source: Symantec, USA Today