Showing posts with label Cybercrime. Show all posts
Showing posts with label Cybercrime. Show all posts

Tuesday, October 29, 2019

SECURITY - Ransomware Hunting League Hero




"The Ransomware Superhero of Normal, Illinois" by Renee Dudley, ProPublica 10/28/2019

Thanks to Michael Gillespie, an obscure programmer at a Nerds on Call repair store, hundreds of thousands of ransomware victims have recovered their files for free.

This story was co-published with the Chicago Sun-Times and The Pantagraph.

ProPublica is a nonprofit newsroom that investigates abuses of power.  Sign up for ProPublica’s Big Story newsletter to receive stories like this one in your inbox as soon as they are published.


About 10 years ago, Michael Gillespie and several classmates at Pekin Community High School in central Illinois were clicking on links on the school’s website when they discovered a weakness that exposed sensitive information such as students’ Social Security numbers.  They quickly alerted their computer repair and networking teacher, Eric McCann.

“It was a vulnerability that nobody even knew about,” McCann said.  “They did a quick search on passwords and student accounts, and lo and behold, that file is sitting out there.”

A shy, skinny teenager whose hand-me-down clothes didn’t fit him, and who was often ridiculed by schoolmates, Gillespie was already working after school as a computer technician.  “He was full of information all the time,” McCann said.  “We’d bounce ideas off each other.  You could tell his passion for technology, for computers, for figuring out things.  That definitely made him stand out.”

Without crediting the students, school administrators closed the breach and changed everyone’s passwords.  Gillespie’s anonymous protection of the school’s cyberdefenses was a harbinger of his future.  Like a real-life version of Clark Kent or Peter Parker, the self-effacing Gillespie morphs in his spare time into a crime-foiling superhero.  A cancer survivor who works at a Nerds on Call computer repair shop and has been overwhelmed by debt — he and his wife had a car repossessed and their home nearly foreclosed on — the 27-year-old Gillespie has become, with little fanfare or reward, one of the world’s leading conquerors of an especially common and virulent cybercrime: ransomware.  Asked what motivates him, he replied, “I guess it’s just the affinity for challenge and feeling like I am contributing to beating the bad guys.”

Each year, millions of ransomware attacks paralyze computer systems of individuals, businesses, hospitals and medical offices, government agencies, and even police departments.  Often, files cannot be decrypted without paying a ransom, and victims who haven’t saved backup copies and want to retrieve the information have little choice but to pony up.  But those who have recovered their data without enriching criminals frequently owe their escapes to Gillespie.

The FBI and local law enforcement agencies have had little success in curbing ransomware.  Local departments lack the resources to solve cybercrime, and the ransoms demanded have often been below the threshold that triggers federal investigations.  Security researchers like Gillespie have done their best to fill the gap.  There are almost 800 known types of ransomware, and Gillespie, mostly by himself but sometimes collaborating with other ransomware hunters, has cracked more than 100 of them.  Hundreds of thousands of victims have downloaded his decryption tools for free, potentially saving them from paying hundreds of millions of dollars in ransom.

“He took that deep dive into the technical stuff, and he just thrives on it,” said Lawrence Abrams, founder of a ransomware assistance website called BleepingComputer.com.  “Every time a new ransomware comes out, he checks it out.  ‘Can it be decrypted?  Yes, it can be decrypted.  OK, I’ll make the decryptor.’  And it’s just nonstop.  He just keeps pumping them out.”

Gillespie downplays his accomplishments.  “IT [Internet Technology] moves so fast, there’s always something to learn, and there’s always someone better than you,” he said.

Gillespie’s tools are available on BleepingComputer.com, and they can be accessed through a site he created and operates, called ID Ransomware.  There, victims submit about 2,000 ransomware-stricken files every day to find out which strain has hit them and to obtain an antidote, if one exists.

As hackers and their corporate enablers, including cyber insurance providers and data recovery firms whose business models are based on paying ransoms, profit directly or indirectly from cybercrime, one of ransomware’s greatest foes lives paycheck-to-paycheck.  Under his internet alias, demonslay335, Gillespie tackles ransomware either in his downtime at Nerds on Call or at night in the two-story bungalow he shares with his wife, Morgan, and their dog, rabbit and eight cats.  Surrounded by pets, he lies on his living room couch, decoding ransomware on his laptop and corresponding with victims desperate for his help.

Although the FBI honored him in 2017 with an award for his website, it doesn’t systematically recommend ID Ransomware — meaning that some victims may never learn of a resource that could help them avoid paying a ransom.  Many of his friends, relatives and colleagues don’t know the extent of his war on ransomware.  “They do not have a clue because of Michael’s modesty,” said his wife’s grandmother, Rita Blanch.  “Honestly, I don’t think anyone in the family knows what he does for free.  I barely know.”  When he got the FBI award, she added, “I sent out a family text, and they’re like: ‘What?  What?  Our Michael?’”

McCann wasn’t aware of Gillespie’s accomplishments either.  “It kind of gives me goosebumps,” the teacher said.  “He’s sitting here doing all this for free.  That’s incredible.”

On a humid morning in July, Gillespie sat on his covered front porch.  His hair was pulled back into a low ponytail, and he sported scraggly facial hair and a V-neck striped shirt.  Brown leaves left over from the previous autumn and birdseed from a feeder were scattered on the ground.  Gillespie said hello to a cardinal — the Illinois state bird, he pointed out — and a squirrel with a “wonky eye.”  He said a family of groundhogs resides under the porch and eats from the front-yard mulberry tree, but they didn’t make an appearance.

He opened his Twitter account.  “Like right now, I have 58 PMs and 120 notifications,” he said.  Most were pleas for help from victims of a ransomware strain, STOP Djvu, which he can sometimes decrypt.

Gillespie’s love of computers and electronics started early.  His paternal grandmother, a video gamer, introduced him to online role-playing games such as RuneScape.  He played Donkey Kong Country on a used Super Nintendo that his uncle gave him.  As emergency services volunteers, his parents communicated with tornado spotters via ham radios.  His father, a land surveyor, taught him how to repair electronics by soldering the radios.

Gillespie gleaned from his mother’s father, a police lieutenant in Florida, the importance of protecting the public.  Reinforcing the message, his parents went out of their way on family trips to pass through Metropolis, Illinois, which proclaims itself to be Superman’s hometown, and pay their respects at the Man of Steel’s bronze statue.  Gillespie was also fascinated by cryptography.  He liked the idea of having secret codes that no one else could figure out — and cracking other people’s.

Struggling financially, his family sometimes had to move in with friends or relatives.  When he was in high school, his parents filed for bankruptcy in the Central District of Illinois, court documents show.

At Pekin High, he helped protect not only the website but also his classmates’ belongings.  One day, noticing that other students were pre-setting codes to the combination locks on their lockers for convenience, he pulled down on every lock in his aisle.  About a quarter of the lockers opened.  He left a Post-it note in each one, admonishing the user to be more careful.

By then, he and Morgan Blanch were becoming close.  They lived down the street from each other but didn’t become friends until their freshman year at Pekin.  They began hanging out at each other’s houses and messaging on Myspace.  They were both in the school show choir and eventually sang in a national competition on the Grand Ole Opry stage in Nashville, Tennessee.

Both sometimes felt like outcasts.  She was overweight.  Gillespie, she said, was “that one kid at school that everybody knows who they are because they’re weird or they’re the butt of people’s jokes.”

But they could rely on each other.  “We’d get annoyed because our other friends were more flighty,” she said.  “They weren’t dependable, whereas if Michael and I made a plan, we stuck to it.  And we liked that about each other.” They started dating during Christmas break of their junior year.

When he graduated in 2010, Gillespie was named a Prairie State Scholar and an Illinois State Scholar, based on his standardized test scores and class rank.  Instead of going to college, he began working full time at the Nerds on Call store in Normal, Illinois.  Even with financial aid, he said, college would have been too expensive, and he already had everything he wanted.  “I got a job, got a car, got a girlfriend.  Boom.  Life together,” he said.

“He just felt that he could learn better on his own than in a classroom setting,” Morgan Gillespie said.  “He doesn’t really like to be restrained by protocol or by doing the ‘typical’ route of things.  He likes to get in there and figure it out and do whatever it is he feels like he wants to do.”

She enrolled at Millikin University in Decatur, Illinois, but missed Gillespie and dropped out after two months.  They moved into a new apartment close to his job and were married in October 2012, with Rita Blanch officiating.  For the bachelor party, Gillespie and his Nerds on Call friends went to a nearby farm and shot up old computers with his father’s firearms.  “Nobody who was too tipsy got to hold the rifles, but we put a few rounds through some old monitors,” said his best man, former co-worker David Jacobs, who organized the party.

The couple honeymooned in Peoria, Illinois.  The next year, with a Federal Housing Administration loan for lower-income borrowers, they purchased their $116,000 bungalow in a working-class neighborhood in Bloomington, Illinois.  There they could hear Amtrak’s Lincoln Service roar by on its way to Chicago.

At Nerds on Call, Gillespie was known as the Swiss Army Knife for his versatility.  So when a client was hit by TeslaCrypt ransomware in 2015, Gillespie was assigned to recover the files.

He embraced the task.  Not only was it an opportunity to expand his skills, but he also objected to the very idea of paying a ransom.  “I say hell no,” he said.  “There’s all the stuff about how it’s funding terrorism, funding bad stuff.  But more so, it’s just encouraging [criminals] to keep going.”

Gillespie “lives so heavily in the tech world, I think having bad actors involved just bothers him,” Jacobs said.  “Sometimes it’s also a little bit of competition.  ‘It’s me versus the bad guys and I want to win.  I want to be able to outdo their schemes.’”

Gillespie immediately consulted BleepingComputer.com.  Established in 2004 by Abrams to provide free advice for any computer problem through tutorials and forums, it had become the go-to site for ransomware assistance.

Sure enough, a BleepingComputer member known as BloodDolly had figured out how to crack TeslaCrypt.  But Gillespie still had to create a key for the client, which required running complex software for hours or days at a time.  “I wanted to post a success story for one of my customer’s systems that was hit this week,” he proudly announced on the forum in August 2015.  “I’ve just successfully decoded a few sample files at home.  … My customer is going to be thrilled we can get her photos back.”

Gillespie realized that Abrams, BloodDolly and other ransomware researchers were overwhelmed with requests for help.  He soaked up everything they could teach him.  Soon he was running software from both his home computer and computers under his desk at work, generating customized keys for scores of TeslaCrypt victims who had posted on BleepingComputer or on social media.

“It was huge, it was insane,” Abrams recalled.  “We were cracking keys left and right.  And Michael got the bug from that.  He came to the site, started cracking keys, starting helping.”

Gillespie also began exchanging private messages on BleepingComputer with U.K.-based ransomware expert Fabian Wosar.  Wosar, now the chief technology officer of antivirus provider Emsisoft, was working to break other strains of ransomware, and he referred TeslaCrypt victims to Gillespie.  Wosar, too, shared his knowledge with Gillespie.

“Sometimes, when people seem genuinely interested, I just ask them if they want to come along,” Wosar said.  “I just open a screen share, and they can watch what I’m doing.  And I explain to them what I am doing and why, and what all this different stuff means.”

Wosar, Gillespie, Abrams and a handful of other volunteers worldwide began communicating over the messaging platform Slack, forming a group they dubbed the Ransomware Hunting Team.  Abrams would hear about a new type of ransomware through users’ posts on his website and send a sample to his teammates.  If they could solve it, they would.

Gillespie creates 90% of the decryptors available on BleepingComputer, Abrams said.  Since May, when Abrams began tracking statistics, decryptors on the site have been downloaded more than 320,000 times.

While BleepingComputer makes money from advertisers, members of the hunting team from time to time have discussed charging for their services.  Each time, “it left a sour taste,” Abrams said.  He recalled a mother who contacted him to say she’d lost photos of her son, a fallen Army veteran, to ransomware.  Abrams helped to decrypt her files.  “I couldn’t charge for that,” he said.

Wosar and Gillespie have each created more free, public decryptors than anybody else in the world.  The two have much in common: neither went to college and both consider themselves autodidacts, learning mostly from internet research.  Both found a home and friendships on BleepingComputer.  And both, Wosar said, suffer from imposter syndrome — feelings of inadequacy that persist despite their success.

“I think we’re all kind of misfits,” Wosar said, referring to members of the team.  “We all have weird quirks that isolate us from the normal world but come in handy when it comes to tracking ransomware and helping people.  That’s why and how we work so well together.  You don’t need credentials, as long as you have the passion and the drive to teach yourself the skills required.  And Michael clearly has it, right?”

As ransomware became increasingly prevalent, the Ransomware Hunting Team had trouble staying abreast of new variants.  “It just got to the point where we just couldn’t keep track any more,” Abrams said.

Gillespie quietly began working on a solution.  “I’m a programmer,” he said.  “What do I do?  I automate.”

At night, on his couch, Gillespie developed a site where victims could upload a ransomware-encrypted file and automatically learn what type it was, whether a decryptor existed and, if so, how to get it.  In March 2016, he launched ID Ransomware with an announcement on Twitter and on BleepingComputer.  “All too often after a ransomware attack, the first question is, ‘what encrypted my files?’, followed by ‘can I decrypt my data?’” he wrote.  “This web service aims to help answer those questions, and guide a victim to the correct information relating to their infection.”

The site took off immediately.  Victims, ransomware recovery firms and other researchers sent encrypted files for analysis.  When they submitted files infected by an unidentified type of ransomware, Gillespie added it to his database.  As before, he and other members of the team worked to create decryptors for newly discovered strains.  ID Ransomware currently can detect more than 780 strains, of which almost 40% have free decryptors, most of them developed by Gillespie or Wosar, and others by cybersecurity firms such as Kaspersky, Avast and Bitdefender.

He’s developed other free applications for victims, which are available on BleepingComputer.  RansomNoteCleaner removes ransom notes left behind after an infection — eliminating the time-consuming task of removing them manually — and CryptoSearch locates encrypted files and makes it easier to back them up, in the hope that a solution may someday be discovered.  ID Ransomware also cross-references the submitter’s IP address with Shodan, a site that can show a computer’s vulnerabilities.  If it detects an open port, which could have allowed the hackers in, ID Ransomware flags the vulnerability — and, like the notes Gillespie stuck in the high school lockers, suggests fixing it.

Gillespie worked nonstop.  “I felt like I never saw him,” his wife said.  “We would be hanging out in the evening, and he would be like, ‘Oh my gosh, I have to go do this.’ And he would just disappear for hours.”

Volunteers around the world have translated ID Ransomware into two dozen languages, from Swedish to Nepali.  Only 26% of submissions to the site have come from the U.S.  “He collects amazing data because so many people use it,” Abrams said.  “He has tons of information.  You can see statistics, trends, what kinds of attacks are happening and when.  Everyone uses it.”

Those users include law enforcement, on both sides of the Atlantic.  Europol and Netherlands police flattered ID Ransomware by imitation, launching a similar but less comprehensive site.  An FBI agent from the Springfield, Illinois, field office asked to meet Gillespie, and they got together with another agent at a local Panera restaurant.

“The first meeting was nerve-wracking for me because, you know, why does the FBI want to talk to me?” Gillespie recalled.  “I was so awkward at that meeting.  I wasn’t thinking, ‘Am I gonna get arrested.’  But I did have in the back of my mind, ‘Am I gonna say something stupid?’”

The FBI needed help.  Victims often don’t report attacks to the bureau because they don’t want investors or the public to learn of their security lapses.  In 2018, the FBI received only 1,493 reports of ransomware — compared with the 2,000 queries daily to Gillespie’s site from about 750 different IP addresses worldwide.

At first, the agents sought information about the origins of a specific ransomware attack, something Gillespie does not investigate.  Then they began requesting lists of IP addresses that had uploaded files to ID Ransomware, which could help identify victims, as well as ransom notes and other material.  Gillespie, who discloses on the ID Ransomware homepage that email or bitcoin addresses uploaded to the site may be shared with “trusted third parties or law enforcement,” complied.

His assistance appears to have paid off.  Gillespie said agents indicated to him that his information may have been instrumental in last year’s indictment of two Iranian hackers wanted in connection with SamSam ransomware, which paralyzed computer networks across North America and the U.K. between 2015 and 2018.  Although the suspects have not been arrested, it was the U.S. government’s first indictment of cyberattackers for deploying a ransomware scheme.

Gillespie continues to meet regularly with FBI agents.  He tips them off, for instance, when a ransom note or extension on a file uploaded to the site identifies the targeted business.  Cooperation from such victims could help law enforcement learn more about the source of the ransomware, he said.

Some other ransomware hunters are warier of the FBI.  Abrams expressed concern that, despite the ID Ransomware acknowledgment, there could be “repercussions” from victims who might be upset that Gillespie identified them to the bureau.  Gillespie “is a little too trusting” of law enforcement, Abrams said.  “I do think that he’s not very worldly and that he sees things a little more black and white than with a lot of shades of gray.  And I think in that case he could be easily manipulated and taken advantage of.”

In 2017, the FBI awarded Gillespie a Community Leadership Award for his “public service, devotion and assistance to victims of ransomware in the United States and Internationally.”  Gillespie prominently displays the award in his home.  In April 2018, he and his wife flew to Washington for the award ceremony, accompanied by his boss at Nerds on Call.  The joke around the office was that the boss “went with him to try to nerf anybody trying to recruit him,” said Gillespie’s former co-worker, Jacobs.  “He would be very difficult to replace.”

Philosophically opposed to charging victims, Gillespie keeps ID Ransomware free.  He put up a link for donations to help cover the costs of running the site, but he didn’t bother to register it as a nonprofit, which would have enabled donors to deduct gifts from their taxes.  Contributions were scarce.  One $3,000 donation through PayPal proved to be a scam — Gillespie speculated that it may have been revenge by hackers whose ransomware he disabled — and PayPal demanded the money back.  He couldn’t repay it and switched to another service.

Gillespie “doesn’t chase money,” Jacobs said.  “If he were chasing money, he would have been living on the East or West Coast by now and doing something for some company that we’d all heard of instead of a little service provider in the Midwest.  But he’s one of those guys, he operates very heavily on principle.”

To make ends meet, Gillespie supplemented his Nerds on Call salary with a 2 a.m. paper route, delivering the local newspaper on his bike.  While he had enjoyed having a paper route in junior high, the job now depressed him.  But the family bills were mounting, especially for health care.  Morgan Gillespie struggled with diabetes and other medical issues.  Over the years, Michael Gillespie noticed blood in his urine, and in the fall of 2017, his wife finally made him see a doctor.  The physician removed a tumor and diagnosed bladder cancer, which rarely affects young adults.  Gillespie took one day off for surgery and one to recover before returning to work.  He underwent immunotherapy treatment weekly for two months, and the cancer has been in remission since.  Although he was insured through Nerds on Call, the costs for his care still added up.

The couple reached a financial breaking point.  They racked up credit card debt and fell behind on payments on Morgan Gillespie’s Nissan.  They rotated which utility bills they would pay; one month their electricity would be turned off, and the next month it would be gas.  They surrendered the car to the bank, which sold it at a loss at auction and forced them to make up the difference.  Last year, around the time his wife lost her job as a nanny, they missed four mortgage payments on their house and began to receive foreclosure notices, Michael Gillespie said.

Gillespie said he’s considering charging other security researchers for the statistics he gathers on the site, but he will always keep the tools free for victims.  Friends and family members nagged Gillespie to collect fees from ID Ransomware users.  Even his wife’s grandmother, whom Gillespie calls “grammy,” brought it up.  “I try to not interfere in that area,” Rita Blanch said.  “Unless, being silly at times, when I would say to him, ‘Babe, you need to charge, you could, like, be rich.’”

Other relatives “have been like: ‘Why isn’t he charging?  Why isn’t he making money off of this?’” said his wife, who recently found a part-time job as a babysitter.  “They think it’s almost dumb, the fact that he does what he does.  But that was just never what the deal was for us.  He just doesn’t want to take advantage of people who are already being taken advantage of.”

Instead, his fellow ransomware hunters stepped in.  Abrams covered the $400 cost of obtaining a certificate that lets users know they’re downloading from a trustworthy site.  Wosar began donating to ID Ransomware, and his employer, Emsisoft, hired Gillespie part-time this year to create Emsisoft-branded decryptors.  The money enabled the Gillespies to catch up on mortgage payments.

“He’s doing so much, how do you not support him if you can?” Abrams said.

After dinner one summer evening, Gillespie took a visitor to the Normal office of Nerds on Call, one of the company’s three locations in central Illinois, nestled in a strip mall between a check-cashing store and a Great Clips hair salon.  Gillespie, who has worked for Nerds on Call for 11 years, has keys, so he was able to open the office and disable the alarm system.  In the back, behind the retail area, is his desk, adorned with framed photos of his cats.

As his wife’s relatives often remind him, he could earn three times as much somewhere else.  But he’s happy at Nerds on Call, which gives him the freedom to work on ransomware in his downtime.  This year, he figured out fixes for the STOP Djvu ransomware, which was infecting files through pirated software.  Victims — who were unlikely to seek law enforcement assistance since they were committing a crime themselves — continue to press Michael for help unceasingly.  “It’s borderline harassment,” he said.

His frustration with the deluge of entreaties occasionally boiled over in his tweets.  “Everything you could possibly need to know is IN THE FUCKING FAQ, and its in BIG BOLD RED LETTERS,” he once responded.  “I’m losing sleep, losing time at my job, losing fucking sanity at this point.”

Some STOP Djvu victims thanked Gillespie.  Adam Hegedus of Szolnok, Hungary, was surfing the internet on his girlfriend's laptop in August when he disabled the anti-virus and firewall protections.  Ransomware crippled the computer, and a text file demanded $1,000 to restore access.  Hegedus' girlfriend is a teacher, and her lesson plans, thesis and other important documents were encrypted.  Hegedus felt so guilty that he couldn't sleep, and he sought assistance from several forums, including BleepingComputer.com.  This month, Gillespie replied with some good news; he had a decryption key.  Hegedus called his girlfriend, who rushed home and was delighted to be able to use her files again.

"You cannot imagine how grateful I am," Hegedus wrote to Gillespie.  "Everything has been decrypted and this is only because of your hard work." Hegedus offered a donation, but Gillespie declined.

Gillespie hopes that someday his services will no longer be needed, because businesses and people will have learned proper cybersecurity.  “If the world had backups, then we wouldn’t have ransomware,” he said.

In the meantime, he said, he plans to keep plugging away, even as hackers and their enablers pile up profits.  “There’s a time in every IT person’s career where they think, ‘I’m on the wrong side,’” he said.  “You start seeing the dollar amounts that are involved.  But nah, I can’t say that I ever have.  I just don’t care to go that way.”

ProPublica research reporter Doris Burke contributed to this article.

Monday, September 11, 2017

DATA SECURITY - The Equifax Hack


"Hackers accessed personal data from 143 million Equifax customers.  Here's what we know." by Erica R. Hendry, PBS NewsHour 9/7/2017
Equifax, a major credit reporting agency, announced Thursday that hackers had gained access to personal data from approximately 143 million of its customers.

Here's what we know.

What happened?

Sometime between mid-May and July, hackers breached an Equifax web application, gaining access to the names, birth dates, addresses, Social Security numbers and, in some cases, driver's license numbers of some 143 million customers, the company said in a blog post Thursday.

Equifax discovered the breach July 29.  The company says it has “no evidence of unauthorized activity on Equifax's core consumer or commercial credit reporting databases.”

Who's affected?

Equifax is one of the three major credit tracking companies in the country.

The number of customers affected in this breach amounts to nearly half of the entire U.S. population, which was 324 million in a U.S. census count in January, CNBC points out.

Along with the sensitive personal data, hackers also gained access to credit card numbers of 209,000 U.S. customers and documents related to credit report disputes from another 182,000 American consumers.

TechCrunch says citizens of Canada and the UK were also affected by the breach.

How bad is this?

As TechCrunch put it:  “pretty bad.”

Reporter Ron Miller writes:

This is not the worst breach of all time by a long shot in terms of pure numbers.  That distinction goes to Yahoo, now part of Oath (which was acquired by our parent company, Verizon).  They had a leak involving more than a billion users.

But this leak is particularly worrisome because Equifax is a credit reporting service and tracks a history of your consumer life, credit cards, credit scores and more — and it gives the black market a potential gold mine of information about people's financial lives.

“In addition to the number [of victims] being really large, the type of information that has been exposed is really sensitive,” said Beth Givens, executive director of the Privacy Rights Clearinghouse, told the Washington Post.  “All in all, this has the potential to be a very harmful breach to those who are affected by it.”

What's next?

Equifax's stock fell 9 percent after the news broke, USA Today noted.

The company has set up a website — www.equifaxsecurity2017.com — for consumers to see whether, and how much of, their data was breached.  It's offering free credit monitoring to all those affected by the hack.

Meanwhile, law enforcement and an independent cybersecurity firm are investigating the scope of the hack and how it occurred.  They're expecting to release their findings in the coming weeks.



"Did the Equifax hack put your personal data at risk?  Here's what to do now." PBS NewsHour 9/8/2017

Excerpt

SUMMARY:  Half of all Americans could have had their sensitive data compromised by a security breach at the credit reporting agency Equifax.  William Brangham joins John Yang to discuss what happened and what consumers should do to safeguard their credit.

Monday, February 09, 2015

INTERNET - Hacking Insurance Companies

"Why are hackers targeting insurance companies?" PBS NewsHour 2/5/2015

Excerpt

SUMMARY:  Hackers broke into a database at Anthem, the nation’s second largest health insurance provider, which contained names, social security numbers, income data and addresses of 80 million people.  Judy Woodruff speaks with Mark Bower of Voltage Security about who might be behind the attack and why they would want to target an insurer.

JUDY WOODRUFF (NewsHour):  Today’s disclosure of a major hacking attack on the nation’s second-largest health insurer, Anthem, is setting off alarms about cyber-crime at a new level.

Hackers were able to crack a database that included records for 80 million people.  The cyber-criminals were able to get names, addresses and e-mails, as well as Social Security numbers and income.  But hospital and doctor information related to patients wasn’t hacked.

Bloomberg News reported that investigators believe Chinese state-sponsored hackers are involved.

Mark Bower is a noted expert on these issues.  He’s also a vice president at Voltage Security in California.

Mark Bower, welcome.

So, compared to the hacks we have seen until now, how serious is this one?

MARK BOWER, Voltage Security:  Well, certainly, we have just started the year off with a bang in terms of data breaches; 80 million records is a very substantial amount, so this is quite a serious attack

And the nature of the data, you have got lots of personal data that can potentially be monetized.  It’s going to be very inconvenient for those individuals and also quite costly for the organization that this affects.

Monday, December 15, 2014

INTERNET - Hackers vs Hollywood

"Hollywood studios check security after hackers leak Sony’s salaries, embarrassing emails" PBS NewsHour 12/12/2014

Excerpt

JUDY WOODRUFF (NewsHour):  It’s been just about two weeks since word broke of cyber-criminals hacking into Sony Pictures.  And each day seems to bring more damaging, embarrassing or worrisome revelations.

The hackers have released a steady flow of information, ranging from salaries, to personal e-mails, Social Security numbers, and health records of employees, to internal messages showcasing industry hardball.

The past couple of days have been even worse for the company, if you can believe that.

And again to Hari, who is in our New York studios tonight.

HARI SREENIVASAN (NewsHour):  The latest e-mails put new pressure on Amy Pascal, the co-chair of Sony Entertainment and one of the most powerful executives in Hollywood.  It’s focused on confidential e-mails between Pascal and Scott Rudin, a powerful producer.

Before a fund-raiser for President Obama, they exchanged messages in which they try to guess the president’s favorite movies, all with African-Americans.  Pascal writes: “Should I ask him if he liked ‘Django’?” referring to “Django Unchained.”

Rudin writes back, “12 Years,” for “12 Years a Slave.”

Pascal responds:  “Or ‘The Butler? Or ‘Think Like a Man?’”

Both apologized yesterday.  It’s not yet clear who’s behind the hacking.  But they call themselves the Guardians of Peace.

We turn to two watching this closely, Sharon Waxman, editor in chief of The Wrap, an industry news site, and James Lewis, a cyber-security expert at the Center for Strategic and International Studies.

Sharon, I want to start with you.

You’re one of the few people to get in touch with Ms. Pascal yesterday.  How significant is this hack?  Put this in perspective.  Is this what folks in Tinseltown are all talking about right now?

Monday, November 24, 2014

CYBER ATTACKS - Outdated Internet Browsers

"Your outdated Internet browser is a gateway for cyber attacks" PBS NewsHour 11/18/2014

Excerpt

JUDY WOODRUFF (NewsHour):  Major U.S. government agencies have been the target of cyber-attacks of late.  The State Department is the latest.  During the past week, officials had to temporarily shut down an unclassified e-mail system after a suspected hacking.  In recent months, the White House, the Postal Service and the National Weather Service all have been targeted.

Meanwhile, as the holiday season approaches, retailers and the business world are on the lookout for breaches.

A new book breaks down the pervasiveness of what’s happening.

Jeffrey Brown has our conversation.

JEFFREY BROWN (NewsHour):  Hardly a week goes by anymore without a report of some major cyber-breach, whether it’s targeting retailers, the government, or any and all of us.  The attacks are generated in a new netherworld of crime, some of it individualized, even chaotic, other parts of it extremely well-organized.

Writer and journalist Brian Krebs has uncovered some major breaches, including the one on Target that compromised the credit card data of tens of millions of people.  He writes about all of this on his blog Krebs on Security and now in his new book, “Spam Nation.”

And welcome to you.

BRIAN KREBS, Author, “Spam Nation”:  Thank you.

JEFFREY BROWN:  You are peering a world of cyber-crime that few of us ever see.  What does it look like?

BRIAN KREBS:  It’s a pretty dark place.

JEFFREY BROWN:  It is?

BRIAN KREBS:  Yes, absolutely.

But it’s not as dark as you might imagine.  If you’re somebody who doesn’t know their way around, there are plenty of people willing to show you the way.  They might take a cut of the action to help you do that, but it’s not as dark…

Monday, October 06, 2014

CYBER ATTACK - Major Assault on JPMorgan Chase

"Hackers’ Attack Cracked 10 Financial Firms in Major Assault" by Matthew Goldstein, Nicole Perlroth, and David E. Sanger; New York Times 11/3/2014

The huge cyberattack on JPMorgan Chase that touched more than 83 million households and businesses was one of the most serious computer intrusions into an American corporation.  But it could have been much worse.

Questions over who the hackers are and the approach of their attack concern government and industry officials.  Also troubling is that about nine other financial institutions — a number that has not been previously reported — were also infiltrated by the same group of overseas hackers, according to people briefed on the matter.  The hackers are thought to be operating from Russia and appear to have at least loose connections with officials of the Russian government, the people briefed on the matter said.

It is unclear whether the other intrusions, at banks and brokerage firms, were as deep as the one that JPMorgan disclosed on Thursday.  The identities of the other institutions could not be immediately learned.

The breadth of the attacks — and the lack of clarity about whether it was an effort to steal from accounts or to demonstrate that the hackers could penetrate even the best-protected American financial institutions — has left Washington intelligence officials and policy makers far more concerned than they have let on publicly.  Some American officials speculate that the breach was intended to send a message to Wall Street and the United States about the vulnerability of the digital network of one of the world’s most important banking institutions.

“It could be in retaliation for the sanctions” placed on Russia, one senior official briefed on the intelligence said.  “But it could be mixed motives — to steal if they can, or to sell whatever information they could glean.”

The JPMorgan hackers burrowed into the digital network of the bank and went down a path that gave them access to information about the names, addresses, phone numbers and email addresses of account holders.  They never made it into where the more critical financial information and personal information are stored.

The bank’s security team, which first discovered the attack in late July, managed to block the hackers before they could compromise the most sensitive information about tens of millions of JPMorgan customers, said several security experts and others briefed on the matter.  The attack was not completely halted until the middle of August and it was only in recent days that the bank began to tally its full extent.

American officials say they have been working with JPMorgan since the intrusion was detected, chiefly through the Treasury, the Secret Service and intelligence agencies that seek to find the source of the attacks.  But that is slow work and one official cautioned against leaping to conclusions about the identities or the motives of the attackers.

“We’ve been wrong before,” he said.

JPMorgan, the nation’s largest bank, has begun contacting customers and making clear that no money was taken from any accounts.  There has been no evidence of any fraudulent use of customer information.  Most of the household accounts belong to United States residents.  The hackers ended up with the addresses, email addresses and phone numbers of everyone who logged into JPMorgan’s websites and mobile applications in the recent past.

Still, the recent attacks on the financial firms raise the possibility that the banks may not be up to the job of defending themselves.  The attacks will also stoke questions about regulations governing when companies must inform regulators and their customers about a breach.

“It was a huge surprise that they were able to compromise a huge bank like JPMorgan,” said Al Pascual, a security analyst with Javelin Strategy and Research.  “It scared the pants off many people.”

Several financial regulators have warned that a coordinated attack on the banking system could set off another financial crisis.

On Friday, George Jepsen, the Connecticut attorney general, opened an investigation into the breach at JPMorgan, while Benjamin M. Lawsky, New York’s top financial regulator, began calling bank officials to warn them to take the threat more seriously.

“There needs to be far more urgency,” Mr. Lawsky said in an interview.

JPMorgan has also been working with law enforcement, including the F.B.I., since shortly after detecting the intrusion, which affected about 90 of the bank’s computer servers.  The bank said it believed that its systems were now secure and that the threat of the hackers’ returning was over.

“To date, we have not seen any unusual fraud activity related to this incident,” said Kristin Lemkau, a bank spokeswoman.  “We have identified and closed the known access paths.  We have no evidence that the attackers are still in our system.  We have apologized to our customers.”

But much remains unanswered about the intrusion, including just who the hackers are, which other financial institutions were hit and why the hackers went down a path inside JPMorgan’s computer system that contained troves of customer information, but not financial data.

The intrusion also highlights a possible gap in United States regulations.  Banks are not required to report data breaches and online intrusions unless the incident is deemed to have resulted in a financial loss to customers.  Breach notification laws differ by state, but most laws require only that companies disclose a breach if customer names were stolen in conjunction with other information like a credit card, Social Security number or driver’s license number.

In some states, companies can wait up to a month to inform customers of a breach.  Other state laws are more vague.

In California, for example, banks, companies and large organizations must inform the state attorney general’s office and consumers about a breach without unreasonable delay — a rule that some companies interpret liberally, officials say.  This year, Kamala Harris, the California attorney general, sued the Kaiser Foundation Health Plan, saying that it took more than a year for the foundation to disclose to some employees that their personal information may have been compromised.

For years, there have been attempts in Congress to force companies to inform customers more quickly when their information has been compromised, but recent bills have failed to muster enough support.  One bill, sponsored by Senator Edward J. Markey, Democrat of Massachusetts, would create a clearinghouse where companies could exchange information about attacks.

United States bank executives say privately that they already share intelligence informally about attacks, which are occurring frequently on their systems.

This summer, Treasury Secretary Jacob J. Lew called on Congress to pass legislation that he said would bolster the information sharing process.

“As it stands, our laws do not do enough to foster information sharing and defend the public from digital threats,” Mr. Lew said.

That the hackers were apparently able to move around JPMorgan’s computer system undetected for several weeks is perhaps the most troubling aspect of the recent breach, officials at other large banks say.

The hackers were able to attain high administrative privileges within JPMorgan’s network, rooting more than 90 servers and rummaging through customer databases with detailed information for 76 million households and seven million small-business online accounts.

As they looked around, according to one person with knowledge of the breach, the hackers gleaned some critical details of customers’ accounts.  With these, the hackers were able to determine whether the accounts fell within the private bank or in other business categories like mortgages.

Some people briefed on the results of the attack contend that it was only a matter of time before attackers could have gained access to customer funds and critical personal data.

Weeks into the attack, in mid-July, unusual behavior on the bank’s network was spotted, and the attackers were stopped before they had a chance to pull any customer data back to their servers abroad.

But they did make off with one file which has unnerved executives.  That file contained a list of every application and program deployed on standard JPMorgan computers that hackers can crosscheck with known, or new, vulnerabilities in each system in a search for a backdoor entry.

Swapping out those programs is costly and time-consuming, people say, because the bank would have to renegotiate licensing deals with technology suppliers and swap out programs and applications for hundreds of thousands of bank employees.

As one former employee explained:  “It’s as if they stole the schematics to the Capitol — they can’t just switch out every single door and window pane overnight.”

The attack came after a recent turnover within JPMorgan’s information security group.

A number of staff members followed Frank Bisignano, JPMorgan’s former co-chief operating officer, to First Data last year.  This year, First Data agreed to pay JPMorgan over accusations that by wooing other executives to the payment processor, Mr. Bisignano had violated the terms of his former employment contract.

By then, First Data had already hired JPMorgan’s chief information officer, Guy Chiarello; its cybersecurity czar, Anthony Belfiore; its head of compliance, Cindy Armine; and Tom Higgins, JPMorgan’s head of operation control.

Anish Bhimani, the bank’s chief information risk officer, remained.  Mr. Bhimani, who is well respected in the cybersecurity industry, is a co-author of a 1996 book on cybersecurity, “Internet Security for Business.”

Ms. Lemkau said the bank was pleased with its current cybersecurity personnel.  “This is the highest-quality team we have ever had,” she said.

Last December, JPMorgan hired Dana Deasy as chief information officer from BP. Greg Rattray, a former Air Force lieutenant colonel who specialized in cyberdefense was named the head of information security in June.

Challenges quickly followed.  That same month, hackers found a way into the bank’s systems.

Monday, August 11, 2014

INTERNET - Criminals Steal 1.2 Billion Web Credentials

"After criminals steal 1.2 billion web credentials, how to protect personal info from data breaches" PBS NewsHour 8/6/2014

Excerpt

GWEN IFILL (NewsHour):  Computer hacking and the breaches of privacy that come with them are becoming a regular and unwelcome feature of our wired world.

Now The New York Times and a security firm based in the Midwest are reporting a massive one that includes the collection of more than a billion username and password combinations and more than 500 million e-mail addresses.  What’s more, the perpetrators appear to be a shadowy Russian crime ring.

Details, including the names of the victims, are hard to come by.  But the news has raised eyebrows around the world.  So, how serious is it?

For that, we turn to Dmitri Alperovitch, co-founder and chief technology officer of CrowdStrike, a Web security firm.

Mr. Alperovitch, tell us just in context of all these other breaches we have had in the past year, say, how — relative to those, how big is this?

DMITRI ALPEROVITCH, CrowdStrike:  Well, the number is certainly striking; 1.2 billion credentials is a lot.  In the past, we have seen some big breaches that numbered in the hundreds of millions.

But this is certainly the biggest one that I — that I can remember.

Monday, January 20, 2014

CYBERCRIME - Who Orchestrated the Target Breach

"Were criminal gangs involved in the Target security breach?" PBS Newshour 1/18/2014

Excerpt

HARI SREENIVASAN (Newshour):  Another story that we wanted to follow up on tonight is the state of credit card security, or lack of it.  This following discourse is about major security breaches at big retailers, including Target and Neiman Marcus.  Now new details are emerging about who was behind it, and how it was accomplished.  For more we are joined now, from Washington, by Mike Riley with Bloomberg News.  So, there was a big report out - it started to layout the details.  How do these hackers get all the credit card numbers?

MIKE RILEY, Bloomberg News:  So, they have a pretty sophisticated piece of malware that goes on the point of sales system itself, so that is the terminal that sits in front the the cash register that we all swipe our cards on.  So, the malware goes there and it takes advantage of a quirk, where within that machine, all that information that is taken off that card is sent from one memory chip to another.  It is not encrypted in that process, and they grab it right there.

HARI SREENIVASAN:  And so, who is writing this malware?

MIKE RILEY:  It looks like it is Eastern European or Russian criminal gangs.  Some of the most sophisticated hackers in the world are Russian or Eastern European.  What they have done is they have gotten really good systems.  It is like a supply chain that you can buy pieces of malware.  If you are good enough, as in this case - they have bought a specific piece of malware, called Black POS.  It is a pretty good piece of malware to begin with, but then they customized it.  They made it better.  They made it harder to find, and then they figured out a scheme to get into Target's computers, and stuck it on the point of sales system.  It is also pretty clear that the same gang, or a group of different hackers using the same malware, are targeting other retailers.  We have not seen the end of this.

Wednesday, January 15, 2014

CYBERCRIME - Can Shoppers Protect Their Personal Information?

My answer, you cannot completely secure your information when using ANY form of online commerce, which includes the card scanners at stores.  "If you build a 10ft firewall, hackers will build a 12ft ladder."

All you can do is closely monitor ALL your statements (bank and credit) and use at least on well known credit protection service.  One example is LifeLock.  These services are worth every penny.

The government does need to make it easier, AND faster, for consumers to clear their credit and identity from Identity-Theft.

"How can shoppers keep their information secure amid retail hacks?" PBS Newshour 1/14/2014

Excerpt

GWEN IFILL (Newshour):  New revelations have come to light in the past several days about the massive hacking attack of consumers' information affecting customers of some major retail stores.  They're raising more concerns over how many people may be at risk and what individuals need to know to protect themselves.

The holiday shopping season is over, but the data breach that hit retail giant Target is still growing.  The company now acknowledges that information on up to 110 million accounts was compromised.  Initial estimates were 40 million.

Today, two U.S. senators demanded answers from Target's CEO.  Commerce Committee Chairman John Rockefeller and fellow Democrat Claire McCaskill said in a letter:  "We expect that your security experts have had time to fully examine the cause and impact of the breach and will be able to provide the committee with detailed information."

The breach has scared some shoppers away from pulling out their credit cards.

WOMAN:  I would rather just use -- try and use cash here until they straighten everything out.  So, it seems a little scary.

GWEN IFILL:  While others say they're just going about their business.

MAN:  Yes, I use a credit card, but it wouldn't deter me, because, really, Target is like all the big businesses, you know?  Cyber-theft is cyber-theft.

Friday, January 10, 2014

CYBERCRIME - Update, 70 Million Additional Target Customers At Risk by Breach

"Target:  Up to 70 million more customers were hit by December data breach" by Amrita Jayakumar, Washington Post 1/10/2014

Target said Friday that the massive cyber attack it suffered during the height of the holiday shopping season may have affected an additional 70 million customers and swept up far more information than it originally reported.

The giant retailer told customers in December that up to 40 million customers’ credit and debit card information had been stolen.  But now the company says that an additional 70 million customers also may have had their personal information — including names, mailing addresses, e-mail address and phone numbers — stolen.

There could be some overlap between the groups, said Target spokeswoman Molly Snyder, but the total number of shoppers affected by the attack may be more than 100 million.

Friday’s announcement is the result of an ongoing investigation into the security breach, Target said.  The company is working with the Secret Service and the Department of Justice to determine who was behind the attack.

“I know that it is frustrating for our guests to learn that this information was taken, and we are truly sorry they are having to endure this,” Gregg Steinhafel, Target’s chairman, president and chief executive officer said in a statement.  “I also want our guests to know that understanding and sharing the facts related to this incident is important to me and the entire Target team.”

Affected customers will be sent an e-mail providing them with general security tips, the retailer said.  No personal information would be requested in the e-mail.  In addition, Target is offering one year of free credit monitoring and identity theft protection to shoppers whose payment data was stolen. Customers are not liable for any fraudulent charges made to their cards as a result of the breach, the company said.

The company has a list of tips for shoppers as well as follow-up measures on its Web site.

Customers should be on the lookout for “consumer scams,” Snyder said.

The attack that was reported in December resulted in the theft of credit card and debit card data from Target customers who had shopped at the store between Nov. 27 and Dec 15.  The 3-digit security code found on the back of payment cards was also taken at the time.

The breach highlighted vulnerabilities in the massive, interconnected shopping systems used for billions of dollars of retail transactions every day.  Customers at Target’s nearly 1,800 stores in the United States were potentially affected, though those who shopped online were not, the company said.

Target’s breach was already one of the largest ever reported, according to security experts, and occurred during the critical holiday shopping season.  Already fearing that budget-strapped consumers would scale back their spending, the company offered 10 percent off all in-store purchases after the attack.

“In light of the recent data breach, our top priority is taking care of our guests and helping them feel confident in shopping at Target,” John Mulligan, Target’s chief financial officer, said in a statement.

Target also cut its fourth-quarter earnings forecast and said it expects sales to decline by 2.5 percent in that quarter.

“While we are disappointed in our 2013 performance, we continue to manage our business with great discipline and leverage our expense optimization efforts to reinvest in multichannel initiatives that generate long-term value for our shareholders,” Mulligan said.

Friday, December 20, 2013

CYBERTHEFT - Target Inc. Gets Hacked For Customer Credit Card Info

"U.S. consumers have many protections but no guarantees against credit card fraud" PBS Newshour 12/19/2013

Excerpt

GWEN IFILL (Newshour):  The retail chain Target confirmed that hackers breached tens of millions of credit card and debit accounts at the height of the shopping season, just before Thanksgiving and right up until Dec. 15.

The theft occurred when people swiped their cards in store, not online.  The retailer confirmed that customers' names, credit card and debit card numbers and security codes were stolen.  It's the latest in a series of major breaches in recent years.

We explore them with Steve Surdu of Mandiant, a cyber-security firm.

How did 40 million accounts get compromised?

STEVE SURDU, Mandiant:  Well, we don't know the details at this point in time.  They're still investigating.

But, obviously, information had to be siphoned off from the organization.  Attackers almost certainly came in from outside, put software in place that allowed them to aggregate the information over time and then remove it, so that they could use it.

THAT IS:  Hackers installed a Trojan virus that allowed external access to Target systems.

Wednesday, May 29, 2013

CYBERCRIME - OnLine $6 Billion Heist

"Online Currency Exchange Accused of Laundering $6 Billion" by MARC SANTORA, WILLIAM K. RASHBAUM, and NICOLE PERLROTH; New York Times 5/28/2013

Excerpt

The operators of a global currency exchange ran a $6 billion money-laundering operation online, a central hub for criminals trafficking in everything from stolen identities to child pornography, federal prosecutors in New York said on Tuesday.

The currency exchange, Liberty Reserve, operated beyond the traditional confines of United States and international banking regulations in what prosecutors called a shadowy netherworld of cyberfinance.  It traded in virtual currency and provided the kind of anonymous and easily accessible banking infrastructure increasingly sought by criminal networks, law enforcement officials said.

The charges announced at a news conference by Preet Bharara, the United States attorney in Manhattan, and other law enforcement officials, mark what officials said was believed to be the largest online money-laundering case in history.  Over seven years, Liberty Reserve was responsible for laundering billions of dollars, conducting 55 million transactions that involved millions of customers around the world, including about 200,000 in the United States, according to prosecutors.

Richard Weber, who heads the Internal Revenue Service’s criminal investigation division in Washington, said at the news conference that the case heralds the arrival of “the cyber age of money laundering,” in which criminals “are gravitating toward digital currency alternatives as a means to move, conceal and enjoy their ill-gotten gains.”

“If Al Capone were alive today, this is how he would be hiding his money,” Mr. Weber said.  “Our efforts today shatter the belief among high-tech money launderers that what happens in cyberspace stays in cyberspace.”

Just as PayPal revolutionized how people shop online, making it possible to buy a microwave oven or concert tickets with the click of a button, Liberty Reserve sought to create a similarly convenient way for criminals to make financial transactions, law enforcement officials said.

The charges detailed a complicated system designed to allow people to move sums large and small around the world with virtual anonymity, according to an indictment, which was unsealed in federal court in Manhattan.

“As alleged, the only liberty that Liberty Reserve gave many of its users was the freedom to commit crimes — the coin of its realm was anonymity, and it became a popular hub for fraudsters, hackers and traffickers,” Mr. Bharara said at the news conference, where officials from the Justice and Treasury Departments, as well as the Secret Service and Homeland Security Investigations, also spoke.  “The global enforcement action we announce today is an important step toward reining in the ‘Wild West’ of illicit Internet banking.  As crime goes increasingly global, the long arm of the law has to get even longer, and in this case, it encircled the earth.”

Liberty Reserve surfaced as a preferred vehicle to transfer money between parties in a number of recent high-profile cybercrimes, including the indictment of eight New Yorkers accused of helping to loot $45 million from bank machines in 27 countries, officials said.

Liberty Reserve was incorporated in Costa Rica in 2006 by Arthur Budovsky, who renounced his United States citizenship in 2011, and was arrested in Spain on Friday.  He was among seven people charged in the case; five of them were under arrest, while two remained at large in Costa Rica.  All were charged with conspiracy to commit money laundering, conspiracy to operate an unlicensed money-transmitting business, and operating an unlicensed money-transmitting business.  The money laundering count carries a maximum sentence of 20 years in prison, and the other two charges carry a maximum of 5 years each.

In addition to the criminal charges, five domain names were seized, including the one used by Liberty Reserve.  Officials also seized or restricted the activity of 45 bank accounts.

The closing of Liberty Reserve last week seemed to have an immediate chilling effect on its customers, who were suddenly unable to access their funds and who posted anxious comments in underground forums, according to law enforcement officials.  Mr. Bharara said the exchange’s clientèle was largely made up of criminals, but he invited any legitimate users to contact his office to get their money back.

The charges outlined how the money transfer system operated, offering a glimpse into the murky world of online financial transactions where money bounces between accounts from Cyprus to New York in the blink of an eye.

To transfer money using Liberty Reserve, a user needed only to provide a name, address and date of birth. But users were not required to validate their identity.

“Accounts could therefore be opened easily using fictitious or anonymous identities,” the indictment states.  Prosecutors cited “blatantly criminal monikers” used by Liberty Reserve clients, like “Russia Hackers.”

Essentially, all a customer needed to open an account was an e-mail address.

One undercover agent was able to register accounts under names like “Joe Bogus” and describe the purpose of the account as “for cocaine” without being questioned, officials said.  That no-questions-asked verification system made Liberty Reserve the premier bank for cybercriminals, prosecutors said.

Monday, May 13, 2013

CYBERCRIME - Robbers Hit ATMs Worldwide for $45 Million

"Cyber ATM Robbers Grab $45 Million Worldwide Within Hours" (Part-1) PBS Newshour 5/10/2013

JEFFREY BROWN (Newshour):  And we turn to a major cyber-theft, global in scope and raising new questions about our vulnerabilities in the digital age.

The thefts took place in broad daylight at ATM machines, and the thieves wore no disguises.

U.S. ATTORNEY LORETTA LYNCH, Eastern District Of New York:  This was a 21st century bank heist that reached through the Internet to span the globe.

JEFFREY BROWN:  U.S. authorities say the reach of the international cyber-crime was wide; 27 countries -- Russia, Japan, Egypt, Colombia, Canada and beyond.

The criminals hacked into companies that process prepaid debit cards for two banks in the Middle East, stole the data and then copied it onto doctored cards with magnetic strips.  Yesterday in New York, U.S. Attorney Loretta Lynch explained what happened next.

LORETTA LYNCH:  They become a virtual criminal flash mob, going from machine to machine, drawing as much money as they can before these accounts are shut down.

JEFFREY BROWN:  On Dec. 21st, thieves hit 4,500 ATMs in some 20 countries, stealing five million dollars.  Then on Feb. 19th, they upped their game.  In 10 hours, they stole $40 million dollars in 36,000 transactions worldwide.

In Manhattan alone, a team of eight so-called "cashers" allegedly made their way from ATM to ATM making 2,900 withdrawals totaling $2.4 million dollars.

Two of the suspects took photos of themselves and the stacks of cash they allegedly stole.  To round out the crime, authorities say the suspects laundered the money by purchasing luxury goods in the form of Rolex watches, Gucci bags and expensive cars.


"International ATM Cyber Hackers Hid 'in Plain Sight' to Overcome Computer System" (Part-2) PBS Newshour 5/10/2013

Excerpt

SUMMARY:  The global network of thieves who targeted ATMs struck 2,904 machines over 10 hours in New York alone, withdrawing $2.4 million.  For more on the attack and the aftermath, Jeffrey Brown talks with Loretta Lynch, the U.S. attorney for the eastern district of New York and the federal prosecutor in the heist case.

Monday, February 25, 2013

CYBERCRIME - Social Networking Hacking

"Twitter Hackings Put Focus on Security for Brands" by TANZINA VEGA and NICOLE PERLROTH, New York Times 2/24/2013

Excerpt

While most Americans were winding up their holiday weekends last Monday, the phones at the Vancouver headquarters of HootSuite, a social media management company, began to ring.

Burger King’s Twitter account had just been hacked.  The company’s logo had been replaced by a McDonald’s logo, and rogue announcements began to appear.  One was that Burger King had been sold to a competitor; other posts were unprintable.

“Every time this happens, our sales phone lines light up,” said Ryan Holmes, the chief executive of HootSuite, which provides management and security tools for Twitter accounts, including the ability to prevent someone from gaining access to an account.  “For big brands, this is a huge liability,” he said, referring to the potential for being hacked.

What happened to Burger King — and, a day later, to Jeep — is every brand manager’s nightmare.  While many social media platforms began as a way for ordinary users to share vacation photos and status updates, they have now evolved into major advertising vehicles for brands, which can set up accounts free but have to pay for more sophisticated advertising products.

Burger King and Jeep, owned by Chrysler, are not alone.  Other prominent accounts have fallen victim to hacking, including those for NBC News, USA Today, Donald J. Trump, the Westboro Baptist Church and even the “hacktivist” group Anonymous.

Those episodes raised questions about the security of social media passwords and the ease of gaining access to brand-name accounts.  Logging on to Twitter is the same process for a company as for a consumer, requiring just a user name and one password.

Twitter, like Facebook, has steadily introduced a number of paid advertising options, raising the stakes for advertisers.  Brands that pay to advertise on Twitter are assigned a sales representative to help them manage their accounts, but they are not given any more layers of security than those for a typical user.

Ian Schafer, the founder and chief executive of Deep Focus, a digital advertising company that also fielded a few phone calls from clients concerned about the Burger King attack, argued that Twitter bore some responsibility.

“I think Twitter needs to step up its game in providing better security,” Mr. Schafer said.  In a memo to his staff about such attacks, he called on social networks like Facebook, Twitter, Pinterest “and anyone else serious about having brands on their platform” to “invest time in better understanding how brands operate day to day.”

“It’s also time for these platforms to use their influence to shape security standards on the Web,” he wrote.

The risk for Twitter is in offending potential business partners as the company tries to build its advertising dollars, which make up the bulk of its revenue.  In 2012, the company grew more than 100 percent, earning $288.3 million in global advertising revenue, according to eMarketer.

On Wednesday, it introduced a product that would allow advertisers to create and manage ads through third parties like HootSuite, Adobe and Salesforce.com.  Advertising is estimated to account for more than 90 percent of the company’s revenue.

“This is not something we take lightly,” said Jim Prosser, a Twitter spokesman, in an interview last month.  (The company declined to comment on the Burger King hacking, saying it did not discuss specific accounts.)  Mr. Prosser said Twitter had manual and automatic controls in place to identify malicious content and fake accounts, but acknowledged that the practice was more art than science.

Mr. Prosser said Twitter had taken an active role in combating the biggest sources of malicious content.

Last year, the company sued those responsible for five of the most-used spamming tools on the site.  “With this suit, we’re going straight to the source,” it said in a statement.  “We hope the suit acts as a deterrent to other spammers, demonstrating the strength of our commitment to keep them off Twitter.”

But security experts say, and the recent hacks of Burger King, Jeep and other brands have demonstrated, that Twitter could do more.

“Twitter and other social media accounts are like catnip for script kiddies, hacktivists and serious cybercriminals alike,” said Mark Risher, chief executive at Impermium, a Silicon Valley start-up that aims to clean up social networks.  “Because of their deliberately easy access and liberal content policies, accounts on these networks prove irresistibly tempting.”

Wednesday, August 15, 2012

CYBER WORLD - Guarding Personal Information

"A Perilous Cyber World: Guarding Personal Information from Hackers and Thieves" PBS Newshour 8/14/2012

Excerpt

JEFFREY BROWN (Newshour): And we begin an occasional series about the way we live ever more of our lives online in the digital age, and some of the risks and rewards connected with this evolution.

In coming segments, we will discuss the connections and disconnections of online life, the differences between engaging online and in the physical world, and what does it mean exactly when a video go viral.

We begin with a look at just how much of us, our identities, are online, and how vulnerable that can make us.

Mat Honan learned this firsthand recently when he was hacked and lost control of his phone, email and personal computer. He told the tale in "Wired" magazine, where he's a technology writer.

Also joining us is Peter Pachal, who watches this world closely as the technology editor for the Web site Mashable.


As a long-time computer & IT professional, my advice for Laptop and Desktop PCs:

  • The HIGHEST security is NOT to be online unless you need to be, this includes turning off your system when you are not using it
  • Passwords - The old advice about NOT using any part of your name or your wife's or children's, even your pets', applies
  • Passwords - Do NOT use any part of an address where you have lived, worked, or gone to school
  • Passwords - Do NOT use your nickname(s)
  • Passwords - Do NOT use birthday dates; yours nor your family's (not even if you reverse or scramble, more later)
  • Passwords - DO have one Master Password that is for very limited use, examples: system Administrator Account (NEVER have a blank password for Administrator), access to a password management tool you use, access to your ISP or eMail providers
  • ALWAYS, always run a good Antivirus Utility (and "free" antivirus utilities are NOT good), one that includes protection against Root-Tool-Kit, Trojans, etc, and KEEP THE DEFINITIONS UP-TO-DATE
Here's the 'more later': If you've seen the move "True Lies" with Arnold Schwarzenegger, there is a scene where one member of the 3-man team (the computer geek) has to hack into information stolen from a target's hard drive. Arny and the other member walk away making a comment that they will come back much later. They are only 5 paces away when the geek says he's in. The password was the target's wife's birth-month, the son's birth-year in reverse, and the daughter's birth-day (or something like that). This IS what hackers can do with information that is just out there on record.

Thursday, August 09, 2012

POLITICS - What Our Federal Legislature Leaves Undone (Part-2)

"Critical U.S. Infrastructure Vulnerable to Cyber Attack, Congress Fails to Act" (Series Part-2) PBS Newshour 8/8/2012

Excerpt

JUDY WOODRUFF (Newshour): Next, another look at some of the work Congress failed to finish before leaving for its August recess.

Tonight, the subject is cybersecurity.

Margaret Warner has the story.

MARGARET WARNER (Newshour): America is increasingly exposed to the threat of cyber-attacks, as hackers go after money, intellectual property and other data from individuals, the financial industry, corporations, government and the defense business.

Last Thursday, the U.S. Senate took up a bill to address the vulnerability in one key sector: the country's critical infrastructure, including the electrical grid, nuclear power plants, oil and gas lines, water supply, and transit systems.

MAN: The motion is not agreed to.

MARGARET WARNER: But Republicans filibustered the measure, and it fell well short of the 60 votes needed to cut off debate. With that, lawmakers left for the August recess, leaving the bill's co-sponsors, Joe Lieberman and Susan Collins, frustrated.

NOTE: The title of the video, at this time, in incorrect

Significant excerpt

JOEL BRENNER, author, America the Vulnerable: ...Department of Homeland Security began keeping figures on this in 2009, there were four such attacks. Last year, there were 198. The numbers are pretty -- they really tell the story.

So now Republicans sacrifice our nation's security to their no-regulation doctrine.

Monday, December 19, 2011

CYBERCRIME - Battle Over Online Piracy

"Film, Music Industries Battle Leading Internet Companies Over Online Piracy"
PBS Newshour 12/15/2011


Excerpts

JEFFREY BROWN (Newshour): Alright.

Markham Erickson, first, do you acknowledge piracy is a problem? I mean, all over the Internet, one can get copyright -- there are copyright violations.

MARKHAM ERICKSON, Open Internet Coalition: Well, sure. People are doing bad things on the Internet. And we agree that there are ways to try to deal with the very real problem of sites that are located outside of the jurisdiction of our court system and our legal system that are engaging in theft and illegal activity.

JEFFREY BROWN: What's the problem with the way they are proposing?

MARKHAM ERICKSON: The problem is, the proposals in Congress right now are not targeted to the problem of dealing with offshore illegal piracy.

We think there is a way to deal with that. And we've proposed a solution, which is to follow the money. The offshore sites are there to make money. They're there to profit from illegal activity. The companies I represent -- represent are some of the biggest ad networks and payment processors in the Internet ecosystem.

And they want to work with the rights-holders that, when an offshore site is engaged in illegal activity, they will shut off the economic lifeblood to those sites. And, if they do that, those sites will disappear.
----
JEFFREY BROWN: And what -- Mr. O'Leary, what about the proposed other -- the alternative route for dealing with this that he raised?

MICHAEL O'LEARY, Motion Picture Association of America: Well, I think that it's the -- to look at it from a positive perspective, it's encouraging to see a recognition that something has to be done about this problem.

I think that what we have concerns with the alternative proposal is that it sets up a separate court in the ITC. And that is not something which is necessarily used to deal with copyright. It's slow. It's bureaucratic. And, frankly, when someone is stealing from you, you don't have 12 to 18 months to work -- to let the bureaucratic court process work.

What we're proposing, what has bipartisan support, we have a broad support from not just the political spectrum, but across all types of American businesses is something which is a tool which will allow law enforcement to go after bad actors that are hiding overseas. We think it's more effective and more efficient.

COMMENT: As a techie in this area I support Mr. Erickson's view.

Note that Mr. O'Leary is NOT a computer network expert, he's only repeating what others have told him. His assertion that the proposed law is "more efficient" is wrong. Having the online payment processors shut-down payments to illegal sites is actually more efficient because it would NOT *require* courts at all. This could be done by the online payment processors themselves.

What the copy right industry SHOULD be doing is making a partnership with online payment processors to identify then block illegal sites. What I am proposing is that the film, music, and book industries with the online payment processors start their own origination to find, track, then block illegal sites.

The courts would only intervene IF a site disputes being blocked. Note that the online payment processors have total rights and control on just who they allow to use their services.

What is wrong with the proposed laws is that they will NOT work, because it can ONLY effect organizations within U.S. jurisdiction. They will have little effect on sites overseas that they are so concerned about.

Wednesday, November 30, 2011

INTERNET - Open Letter on "IP Act" and "Online Piracy Act"

"An open letter to Senator Leahy regarding Internet censorship" on Newsgroups: alt.politics.usa.constitution


Dear Senator Leahy;

I am very concerned about the over-reaching authority which appears to be in the Protect IP Act and the Stop Online Piracy Act.

References:

Protect_IP_Act

Stop_Online_Piracy_Act

I am a software developer on the Internet. My main site is nodes.net which I have owned since 1998. I am working on a "quality discernment system" to advance the concept of an "intelligent web."

An integral part of the vision I hold is for individuals to "endorse" specific URL's on the web. These URL's could be something I call "metalinks" which are basically re-programmable re-directs to other web sites. These MetaLinks allow people to make a short, easy-to-
remember link for a web search or a web page.

For example, http://oil.nodes.net will redirect you to Energy Prices at Bloomburg. http://occupy.news.nodes.net will produce a search of news for "occupy" at Google news. There are many other search engines which are being included in this syntax at nodes.net

For example, http://vermont.wiki.nodes.net will take people to Wikipedia's entry for Vermont. I didn't program this metalink specifically. It is automatic. You can search for any word or phrase by substituting your word(s) for "vermont" in this URL.

In similar fashion http://05401.weather.nodes.net will take people to the weather for Burlington, VT and http://paris.time.nodes.net will take people to the current time in Paris. There are several dozen of these interfaces to other web sites and there will be hundreds, even thousands more in the near future.

I am concerned that the legislation currently being considered will limit the development of new technology to create an "intelligent web."

While the Metalinks currently in use have all been defined by someone I plan to allow intelligent software to create metalinks in the future.

It would be unwise to restrict the use of intelligent software to define links in my opinion. It's wrong to assume that all links are created by individuals operating independent of each other. Links could be a result of composite or collaborative intelligence.

In the future, metalinks will represent our "collective intelligence" or "community wisdom." That's what I'm working on now. I'm working to
create an "intelligent web." The concept I am working with is "augmented human intelligence" rather than "artificial intelligence."

I am asking you to put this legislation on the shelf for a minimum of 30 days, until 2012, so that there can be more input by the public and
a more careful analysis of what it means for all of us.

Consideration is a virtue. Please consider the effects this legislation would have on me and others who are working to advance the evolution of human intelligence on the Internet.

Sincerely,

Steve Moyer
Internet Developer
Founder, NODES Network
http://steve.nodes.net ( see what can be done with my technology )

P.S. You can see a link of all the Metalinks currently in existence, not including automatic search interfaces, at http://metalinks.nodes.net

LAW - Effectiveness of DoJ Cyber Monday Crackdown

"How Effective Is Justice Department Crackdown on Counterfeit Goods Dealers?" PBS Newshour 11/29/2011

Excerpt

GWEN IFILL (Newshour): We look now at the government crackdown on the online sale of counterfeit goods. The Justice Department used Cyber Monday, the biggest online shopping day of the year, to shut down 150 websites that were allegedly peddling fake shoes, sporting goods and handbags. But was this the right approach?

Joining us to discuss that are Steve Tepp, chief intellectual property counsel at the U.S. Chamber of Commerce, and Larry Downes, author of "The Laws of Disruption," a book about law and innovation in the digital age.



More significant excerpts

STEVE TEPP, U.S. Chamber of Commerce: It's a massive problem that's growing every day, because many of these sites are located outside the United States, where there is no remedy.

For the sites located in the U.S., or at least where their domain name is registered in the U.S., dot-com, dot-net, then our enforcement agencies, like the Immigration and Customs Enforcement and the Department of Justice, who are both doing fantastic work on this, protecting the American people, can go to court and seize those domains with a court order.

That's what happened yesterday, and that's 150 domain names that will not be used to steal American jobs, to harm American consumers today.
----
LARRY DOWNES, "The Laws of Disruption": Well, first, it should be noted that, you know, what we're seizing here is not the website itself, just the domain name. It's a largely symbolic act.

What happens is, the site is still there. It can be accessed directly from the I.P. address. Or what often happens is the site comes back a little bit later under another domain name. So whether that is effective or not, it doesn't matter.

Tuesday, September 13, 2011

CYBERWAR - Attack Using Internet Certificate System

This has to make one wonder about what type of internal (on site) security these companies, who are responsible for the security of the internet, have.

"Hacker Rattles Security Circles" by SOMINI SENGUPTA, New York Times 9/11/2011

Excerpt

He claims to be 21 years old, a student of software engineering in Tehran who reveres Ayatollah Ali Khamenei and despises dissidents in his country.

He sneaked into the computer systems of a security firm on the outskirts of Amsterdam. He created fake credentials that could allow someone to snoop on Internet connections that appeared to be secure. He then shared that bounty with people he declines to name.

The fruits of his labor are believed to have been used to tap into the online communications of as many as 300,000 unsuspecting Iranians this summer. What’s more, he punched a hole in an online security mechanism that is trusted by millions of Internet users all over the world.

Comodohacker, as he calls himself, insists he acted on his own and is unperturbed by the notion that his work may have been used to spy on antigovernment compatriots.

“I’m totally independent,” he said in an e-mail exchange with The New York Times. “I just share my findings with some people in Iran. They are free to do anything they want with my findings and things I share with them, but I’m not responsible.”

In the annals of Internet attacks, this is likely to go down as a moment of reckoning. For activists, it shows the downside of using online tools to organize: an opponent with enough determination and resources just might find a way to track their every move.

It also calls into question the reliability of a basic system of trust that global Internet brands like Google and Facebook, along with their users, rely upon. The system is intended to verify the authenticity of a particular Web site — to ensure, in effect, that Gmail is Gmail, and that the connection to the site is encrypted and difficult for an outsider to monitor.

Hundreds of companies and government authorities around the world, including in the United States and China, have the power to issue the digital certificates that the system relies upon to verify a site’s identity. The same hacker is believed to be responsible for attacks on three such companies.

In March, he claimed credit for a breach of Comodo, in Italy. In late August came the attack on the Dutch company DigiNotar. On Friday evening, a company called GlobalSign said it had detected an intrusion into its Web site, but not into more confidential systems.

Armed with certificates stolen from companies like these, someone with control over an Internet service provider, like the Iranian authorities, could trick Internet users into thinking they were safely connected to a familiar site, while eavesdropping on their online activity.

Fearing the prospect of other breaches similar to those carried out by this hacker, Mozilla, the maker of the Firefox Web browser, last week issued a warning to certificate authority companies to audit their security systems or risk being booted off Firefox.

“It is a real example of a weakness in security infrastructure that many people assumed was trustworthy,” said Richard Bejtlich, the chief security officer of Mandiant Security in Alexandria, Va. “It’s a reminder that it is only as trustworthy as the companies that make up the system. There are bound to be some that can’t protect their infrastructure, and you have results like this.”