Showing posts with label Computer hacker. Show all posts
Showing posts with label Computer hacker. Show all posts

Wednesday, June 24, 2015

Alleged Mastermind Of Global Cybercrime Campaigns Extradited To The United States To Face Charges


Earlier today, an indictment was unsealed in a Brooklyn, New York federal court charging Ercan Findikoglu, a Turkish citizen also known as “Segate,” with organizing three worldwide cyberattacks that inflicted $55 million in losses on the global financial system in a matter of hours. 

The defendant’s organization used sophisticated intrusion techniques to hack into the systems of global financial institutions, steal prepaid debit card data and eliminate withdrawal limits.  The stolen card data was then disseminated worldwide and used in making fraudulent ATM withdrawals on a massive scale across the globe.  The charges announced today follow charges previously brought against other members of the organization, including members of a New York City cell charged in May 2013 in connection with their roles in two of the attacks.  The defendant is scheduled to be arraigned at 11 a.m. today before U.S. Magistrate Judge Lois Bloom at the U.S. Courthouse, 225 Cadman Plaza East, Brooklyn, New York.

The charges were announced by Acting U.S. Attorney Kelly T. Currie for the Eastern District of New York and Special Agent in Charge Robert J. Sica of the U.S. Secret Service New York Field Office.

“Cybercriminals, and especially hackers as this defendant is alleged to be, wreak havoc and steal millions of dollars by breaching our information systems and networks with clicks and keystrokes from the perceived anonymity of their computers at locations all over the globe,” said Acting U.S. Attorney Currie.  “However, in doing so they leave traces in digital space that allow law enforcement to identify, apprehend and ultimately hold them accountable for their crimes.”

Acting U.S. Attorney Currie praised the extraordinary efforts of the Secret Service in investigating these complex network intrusions and thanked the authorities in Germany for their assistance in effecting the defendant’s extradition.  

“For the past twenty years, Special Agents assigned to the Secret Service New York Electronic Crimes Task Force have worked closely with our law enforcement partners, the business community and our partners in academia to pursue cybercriminals who have taken aim at our homeland’s financial infrastructure.  Today, we recognize our international law enforcement partners who were instrumental in the extradition of Ercan Findikoglu,” said Special Agent in Charge Sica.  “The significance of this case cannot be understated as Findikoglu is the alleged mastermind behind the global ATM cashout operations which plagued the financial services sector from 2010 until his capture in late 2013.  The Secret Service and its international partners remain committed to solving complex financial crimes as well as tracking down and bringing to justice significant cybercriminals who pose a threat to payment systems worldwide.”

As detailed in the indictment and other court filings, Findikoglu gained unauthorized access to, or “hacked,” the computer networks of at least three payment processors for various types of credit and debit card transactions (the Victim Processors).  He then targeted Visa and MasterCard prepaid debit cards serviced by the Victim Processors, breached the security protocols that enforce withdrawal limits on those cards, and then dramatically increased the account balances on those cards to allow withdrawals far in excess of the legitimate card balances.

Findikoglu allegedly managed a trusted group of co-conspirators who disseminated the stolen debit card information to leaders of “cashing crews” around the world; they, in turn, used the stolen information to conduct tens of thousands of fraudulent ATM withdrawals.  During these operations, Findikoglu allegedly maintained access to the computer networks of the Victim Processors in order to monitor the withdrawals.  These coordinated, calculated cyberattacks are known in the cyber-underworld as “Unlimited Operations,” because the manipulation of withdrawal limits enables the withdrawal of literally unlimited amounts of cash until the operation is shut down.

In one operation on Feb. 27 and 28, 2011, cashing crews withdrew approximately $10 million through approximately 15,000 fraudulent ATM withdrawals in at least 18 countries.  In a second operation on Dec. 22, 2012, cashing crews withdrew approximately $5 million through more than 4,500 ATM in approximately 20 countries.  In a third operation on Feb. 19 and 20, 2013, cashing cells in 24 countries executed approximately 36,000 transactions and withdrew approximately $40 million from ATMs.  During this third operation, in New York City alone, cashing crews withdrew approximately $2.4 million in nearly 3,000 ATM withdrawals over the course of less than 11 hours.
Once the funds were extracted, Findikoglu and high-ranking members of the conspiracy allegedly received the proceeds from other co-conspirators in various forms, including by wire transfer, electronic currency and the personal delivery of U.S. and foreign currency. 

On one occasion, members of a New York City cashing crew transported approximately $100,000 to co-conspirators in Romania.  Findikoglu directed a co-conspirator to destroy evidence of their criminal activities after learning that a member of a New York cashing crew had been arrested.
On Dec. 18, 2013, Findikoglu was arrested in Frankfurt, Germany, and yesterday was extradited to the United States.                      

The government’s case is being handled by the U.S. Attorney’s Office of the Eastern District of New York’s National Security & Cybercrime Section.  Assistant U.S. Attorneys Hilary Jager, Douglas M. Pravda, Richard M. Tucker and Saritha Komatireddy are in charge of the prosecution.  Assistant U.S. Attorney Brian Morris of the Office’s Civil Division is responsible for the forfeiture of assets.  Additional assistance was provided by Marcus Busch and Cristina M. Posa of the Justice Department’s Office of International Affairs.

Wednesday, February 18, 2015

Russian National Charged In Largest Known Data Breach Prosecution Extradited To United States


The U.S. Justice Department released the below link:

A Russian national appeared in federal court in Newark today after being extradited from the Netherlands to face charges that he conspired in the largest international hacking and data breach scheme ever prosecuted in the United States, announced Assistant Attorney General Leslie R. Caldwell of the Justice Department’s Criminal Division, Secretary Jeh Johnson of the Department of Homeland Security, U.S. Attorney Paul J. Fishman of the District of New Jersey and Acting Director Joseph P. Clancy of the U.S. Secret Service.

Vladimir Drinkman, 34, of Syktyykar and Moscow, Russia, was charged for his alleged role in a data theft conspiracy that targeted major corporate networks, stole more than 160 million credit card numbers, and caused hundreds of millions of dollars in losses.  Prior to his extradition, he had been detained by the Dutch authorities since his arrest in the Netherlands on June 28, 2012.

Drinkman appeared today before U.S. Magistrate Judge James B. Clark and entered a plea of not guilty to all 11 counts charged in the indictment and was ordered detained without bail.  Trial before U.S. District Judge Jerome B. Simandle was scheduled for April 27, 2015.

“Cyber criminals conceal themselves in one country and steal information located in another country, impacting victims around the world,” said Assistant Attorney General Caldwell.  “Hackers often take advantage of international borders and differences in legal systems, hoping to evade extradition to face justice.  This case and today's extradition demonstrates that through international cooperation, and through great teamwork between the Department of Justice and the Department of Homeland Security, we are able to bring cyber thieves to justice in the United States, wherever they may commit their crimes.”

“Drinkman’s extradition on the indictment this office brought more than a year and a half ago shows how relentlessly we will pursue those who are charged with these serious crimes,” said U.S. Attorney Fishman.  “The incredibly sophisticated work with our partners at the U.S. Secret Service to uncover this enormous, far-reaching scheme demanded an equal effort by our colleagues at the Department of Justice Criminal Division in Washington and our law enforcement partners overseas to bring the defendant back to face these charges.”

“This case demonstrates our commitment to fulfilling an important part of our integrated mission; that of protecting our Nation’s critical financial infrastructure,” said Acting Director Clancy.  “Our success in this investigation and other similar investigations is a credit to our skilled and relentless cyber investigators.  Our determination, coupled with our network of foreign law enforcement partners, ensures that our investigative reach can expand beyond the borders of the United States.”

According to the second superseding indictment, unsealed on July 25, 2013, and other court filings, Drinkman and four co-defendants each served particular roles in the scheme. Drinkman and Alexandr Kalinin, 28, of St. Petersburg, Russia, each allegedly specialized in penetrating network security and gaining access to the corporate victims’ systems.  Roman Kotov, 33, of Moscow, allegedly specialized in mining the networks Drinkman and Kalinin compromised to steal valuable data.

 According to allegations in the indictment, the hackers hid their activities using anonymous web-hosting services provided by Mikhail Rytikov, 27, of Odessa, Ukraine.  Dmitriy Smilianets, 31, of Moscow, then allegedly sold the stolen information and distributed the proceeds of the scheme to the participants.

Drinkman and his co-defendants are charged with attacks on NASDAQ, 7-Eleven, Carrefour, JCP, Hannaford, Heartland, Wet Seal, Commidea, Dexia, JetBlue, Dow Jones, Euronet, Visa Jordan, Global Payment, Diners Singapore and Ingenicard.  It is not alleged that the NASDAQ hack affected its trading platform.

Drinkman and Kalinin were previously charged in New Jersey as “Hacker 1” and “Hacker 2” in a 2009 indictment charging Albert Gonzalez, 33, of Miami, in connection with five corporate data breaches, including the breach of Heartland Payment Systems Inc., which at the time was the largest ever reported.  Gonzalez is currently serving 20 years in federal prison for those offenses.  Kalinin is also charged in two federal indictments in the Southern District of New York: one charges Kalinin in connection with hacking certain computer servers used by NASDAQ and the second charges him and another Russian hacker, Nikolay Nasenkov, with an international scheme to steal bank account information from U.S.-based financial institutions.  Rytikov was previously charged in the Eastern District of Virginia with an unrelated scheme.

Drinkman and Smilianets were arrested at the request of the United States while traveling in the Netherlands on June 28, 2012.  Smilianets was extradited on Sept. 7, 2012, and remains in federal custody.  Kalinin, Kotov and Rytikov remain at large.  All of the defendants are Russian nationals except for Rytikov, who is a citizen of Ukraine.

The Attacks

According to allegations in the indictment, the five defendants conspired with others to penetrate the computer networks of several of the largest payment processing companies, retailers and financial institutions in the world, stealing the personal identifying information of individuals.  They allegedly took user names and passwords, means of identification, credit and debit card numbers and other corresponding personal identification information of cardholders. The conspirators allegedly acquired at least 160 million card numbers through hacking.

The initial entry was often gained using a “SQL injection attack.”  SQL, or Structured Query Language, is a type of programming language designed to manage data held in particular types of databases.  The hackers allegedly identified vulnerabilities in SQL databases and used those vulnerabilities to infiltrate a computer network.  Once the network was infiltrated, the defendants allegedly placed malicious code, or malware, on the system.  This malware created a “back door,” leaving the system vulnerable and helping the defendants maintain access to the network.  In some cases, the defendants lost access to the system due to companies’ security efforts, but were allegedly able to regain access through persistent attacks.

Instant message chats obtained by law enforcement reveal that the defendants allegedly targeted the victim companies for many months, waiting patiently as their efforts to bypass security were underway, sometimes leaving malware implanted for more than a year.

The defendants allegedly used their access to the networks to install “sniffers,” which were programs designed to identify, collect and steal data from the victims’ computer networks. The defendants then allegedly used an array of computers located around the world to store the stolen data and ultimately sell it to others.

Selling the Data

After acquiring the card numbers and associated data—which they referred to as “dumps”—the conspirators allegedly sold it to resellers around the world.  The buyers then sold the dumps through online forums or directly to individuals and organizations.  Smilianets was allegedly in charge of sales, selling the data only to trusted identity theft wholesalers.  He allegedly charged approximately $10 for each stolen American credit card number and associated data, approximately $50 for each European credit card number and associated data and approximately $15 for each Canadian credit card number and associated data, offering discounted pricing to bulk and repeat customers.  Ultimately, the end users encoded each dump onto the magnetic strip of a blank plastic card and cashed out the value of the dump by either withdrawing money from ATMs or making purchases with the cards.

Covering Their Tracks

The defendants allegedly used a number of methods to conceal the scheme.  Rytikov allegedly allowed his clients to hack with the knowledge he would never keep records of their online activities or share information with law enforcement.

Over the course of the conspiracy, the defendants allegedly communicated through private and encrypted communications channels to avoid detection.  Fearing law enforcement would intercept even those communications, some of the conspirators allegedly attempted to meet in person.

To protect against detection by the victim companies, the defendants allegedly altered the settings on victim company networks to disable security mechanisms from logging their actions.  The defendants also allegedly worked to evade existing protections by security software.

As a result of the scheme, financial institutions, credit card companies and consumers suffered hundreds of millions in losses—including more than $300 million in losses reported by just three of the corporate victims—and immeasurable losses to the identity theft victims in costs associated with stolen identities and false charges.

The charges and allegations contained indictments are merely accusations and the defendants are presumed innocent unless and until proven guilty.

The ongoing investigation is being conducted by the U.S. Secret Service.  The case is being prosecuted by Trial Attorney Rick Green of the Criminal Division’s Computer Crime and Intellectual Property Section, Chief Gurbir S. Grewal of the District of New Jersey’s Economic Crimes Unit, and Assistant U.S. Attorney Andrew S. Pak of the Computer Hacking and Intellectual Property Section of the District of New Jersey’s Economic Crimes Unit.

The Criminal Division’s Office of International Affairs assisted with the case, as did public prosecutors with the Dutch Ministry of Security and Justice and the National High Tech Crime Unit of the Dutch National Police.

Tuesday, October 21, 2014

Computer Hacker Sentenced For E-Mailing Bomb Threat To Shopping Mall


The U.S. Justice Department released the below information:

PHILADELPHIA—David Barnhouse, 24, of Horsham, PA, was sentenced, on October 16, 2014, to 18 months in prison for hacking into his neighbor’s wireless router and using it to post a bomb threat on the website of the Willow Grove Park Mall. As a result of Barnhouse’s actions, the mall paid for increased security and the FBI, after tracing the threat to the neighbor’s router, executed a search warrant on the neighbor’s home. (The practice of making such false reports to bring police action against someone’s house is colloquially known as “swatting”—after the SWAT teams that law enforcement often uses to deal with such situations.)

On June 20, 2013, Barnhouse hacked into the Verizon FiOS router of his neighbor and, using their Internet service, posted the following message:

“We have planted an explosive device somewhere in the mall, and will detonate it unless all members of the Islamic faith imprisoned in the United States are freed by 7 p.m. on June 23. Even if you search the mall for 72 consecutive hours, you will NEVER find it.”

In addition to the prison term, U.S. District Court Judge C. Darnell Jones, II ordered three years of supervised release and restitution to the mall for the costs of the increased security.

The case was investigated by the Federal Bureau of Investigation and was prosecuted by Assistant United States Attorneys Jeanine Linehan and Michael L. Levy.

Tuesday, March 6, 2012

Unmasking The World's Most Wanted Hacker

 
Jana Winter at FoxNews.com offers an interesting piece on the capture of Hector Xavier Monsegur, AKA "Sabu."

The agents were suddenly face-to-face with “Sabu,” the computer genius they had stalked for months, a quarry so elusive they hadn’t pinned down his identity and location until just weeks before. The suspected ringleader of the Anonymous offshoot group LulzSec, Hector Xavier Monsegur and his web minions had just completed a month-long reign of terror, hacking the CIA, Fox, Sony and several financial institutions, causing, according to some estimates, billions of dollars in damage around the world.

The nondescript public housing unit seemed an unlikely nerve center for one of the world’s most wanted criminal masterminds, but the 28-year-old Monsegur himself is a study in such contradictions. An unemployed computer programmer, welfare recipient and legal guardian of two young children, Monsegur did not go to college and is a self-taught hacker. Although his skills and intellect could command a lucrative salary in the private sector, those who know him say he is lazy, an underachiever complacent with his lifestyle.

You can read the rest of the piece via the below link:

http://www.foxnews.com/scitech/2012/03/06/exclusive-unmasking-worlds-most-wanted-hacker/