Showing posts with label computer crime. Show all posts
Showing posts with label computer crime. Show all posts

Wednesday, July 21, 2021

My Threatcon Column: FBI's InfraGard Program Celebrates 25 Years Of Protecting America


 My Threatcon column was posted online today at www.iacsp.com. 

You can read the column below: 

This year marks a milestone for the InfraGard program, a critical partnership between the FBI and the private sector.

According to the FBI, the National InfraGard Program began as a pilot project in 1996 when the Cleveland FBI Field Office asked local computer professionals to assist the FBI in determining how to better protect critical information systems in the public and private sectors. From this new partnership, the first InfraGard chapter was formed to address both cyber and physical threats.

When InfraGard went national in 2001, then-FBI Director Louis J. Freeh applauded the success of the program.

“Computer crime is one of the most dynamic problems the FBI faces today,” Freeh said. ‘I am proud of the progress we have made in dealing with this problem by establishing the InfraGard initiative and opening the lines of communication between the public and private sectors and the law enforcement community. I am confident that we will continue to work together to further develop the capabilities to meet the computer crime problem, in all its facets, head on. Our economy and public safety depend on it.”

The InfraGard program connects business owners within critical infrastructure to the FBI and provides education, information sharing, networking, and workshops on emerging technologies and threats. According to InfraGard.org, vetted membership includes business executives, entrepreneurs, lawyers, security personnel, military and government officials, IT professionals, academia and state and local law enforcement—all dedicated to contributing industry-specific insight and advancing national security.

The requirements to be an InfraGard member includes being a U.S. citizen, 18 years or older. One must be affiliated with a critical infrastructure sector. Members must consent and pass an FBI security risk assessment and periodic re-certifications. Members must notify the FBI of any pending criminal matters. Members must sign and adhere to a confidentiality and non-disclosure agreement and agree to adhere to InfraGard’s Code of Ethics and Information Sharing Policies.

Member Benefits include:

Access to InfraGard’s Secure Web Portal, www.infragard.org

FBI accredited website with secure messaging that promotes communication among members.

FBI and DHS threat advisories, intelligence bulletins, analytical reports, and vulnerability assessments in real time.

Access to iGuardian, the FBI’s cyber incident reporting tool designed specifically for the private sector Unique Networking Opportunities.

FBI and other government agency presentations to InfraGard Member Alliance events • Special Interest Groups (SIGs) • Peer-to-peer collaboration across InfraGard’s broad membership.

Information sharing and relationship building with FBI and law enforcement at all levels Training and Education • Information Sharing Initiative (ISI) training program.

FBI and other government security awareness training programs.

Local and online training and event discounts • Free or discounted local seminar.

Today, the InfraGard National Members Alliance (INMA), a nonprofit 501(c)3 organization, is comprised of 77 chapters—aligned with local FBI field offices—and more than 75,000 members across the United States.

“As Americans, our lifestyle, economy, and national security are supported by a complex framework of businesses and services,” noted the INMA. “The central role of these critical infrastructures and key resources (CIKR), makes them especially vulnerable as targets for both physical and cyber-attacks. The mission FBI is to protect the American people and uphold the U.S. Constitution. Our vision is to remain ahead of the threat through leadership, agility and integration.

“In an era where threats to our country and risks to private enterprise are escalating and intersecting, building mutual respect and cooperation between the FBI and the private sector has never been more important. The majority of infrastructure in the U.S. is owned and operated by the private sector; therefore, cultivating partnerships and incorporating key industry stakeholders is crucial to support the government in protecting critical infrastructure. InfraGard provides a vehicle for seamless public/private collaboration; expedites the timely exchange of information; and promotes mutual learning opportunities relevant to CIKR defense.”

The INMA said it leverages the expertise of a wide range of private sector partners who own, operate, and hold key positions within approximately 85 percent of the nation’s critical infrastructure. The INMA said its InfraGard’s subject matter experts include business executives, entrepreneurs, lawyers, military and government officials, IT professionals, security personnel, academia, and state and local law enforcement. Each of them is dedicated to contributing industry-specific insight and advancing national security. Through this partnership, the INMA noted, both the FBI and private sector gain an improved understanding of the threatscape and share valuable intelligence.

“We are grateful to our hundreds of volunteers, our thousands of dedicated members and our FBI partners for making InfraGard the valuable organization it is and for being such an incredible asset to America’s national security,” said Maureen O’Connell, the President of the InfraGard National Members Alliance. In

Paul Davis, a longtime contributor to the Journal, writes the IACSP online Threatcon column.

Friday, May 22, 2015

The Internet Crime Complaint Center Releases Annual Snapshot Of Internet Crimes


The FBI website offers the below information:

Today, the Internet Crime Complaint Center (IC3) released its annual report highlighting the numbers and common types of complaints it received during 2014 on suspected Internet fraud and other Internet-based crimes.

The report mentions two new trends that took shape during 2014: criminals increasingly taking advantage of personal data found on social media to start relationships with victims and scam them out of their money; and the emerging popularity of virtual currency, which has attracted perpetrators who capitalize on the vulnerabilities of the developing digital currency system.

Other common scams reported to the IC3—which received an average of 22,000 complaints a month during 2014—included auto fraud, impersonation e-mails, intimidation/extortion scams, real estate fraud, confidence fraud/romance scams, and business e-mail compromise schemes.

According to the report, the IC3 adapted its approach to handling complaints during 2014: Analysts began reviewing more recent complaints first and then looked back at older submissions to better identify urgent threats, recognize new trends more quickly, and disseminate information to law enforcement and the general public based on the most recent data.

The IC3—which houses well over three million complaints from consumers in its database—continues to encourage anyone who thinks they’ve been the victim of an Internet crime, regardless of dollar loss, to file a complaint through the IC3 website. The more complaints it receives, the more effective it will be in helping law enforcement gain a more accurate picture of the extent and nature of Internet-facilitated crimes.

You can read the report via the below link:

http://www.fbi.gov/news/news_blog/2014-ic3-annual-report 

Wednesday, February 18, 2015

Russian National Charged In Largest Known Data Breach Prosecution Extradited To United States


The U.S. Justice Department released the below link:

A Russian national appeared in federal court in Newark today after being extradited from the Netherlands to face charges that he conspired in the largest international hacking and data breach scheme ever prosecuted in the United States, announced Assistant Attorney General Leslie R. Caldwell of the Justice Department’s Criminal Division, Secretary Jeh Johnson of the Department of Homeland Security, U.S. Attorney Paul J. Fishman of the District of New Jersey and Acting Director Joseph P. Clancy of the U.S. Secret Service.

Vladimir Drinkman, 34, of Syktyykar and Moscow, Russia, was charged for his alleged role in a data theft conspiracy that targeted major corporate networks, stole more than 160 million credit card numbers, and caused hundreds of millions of dollars in losses.  Prior to his extradition, he had been detained by the Dutch authorities since his arrest in the Netherlands on June 28, 2012.

Drinkman appeared today before U.S. Magistrate Judge James B. Clark and entered a plea of not guilty to all 11 counts charged in the indictment and was ordered detained without bail.  Trial before U.S. District Judge Jerome B. Simandle was scheduled for April 27, 2015.

“Cyber criminals conceal themselves in one country and steal information located in another country, impacting victims around the world,” said Assistant Attorney General Caldwell.  “Hackers often take advantage of international borders and differences in legal systems, hoping to evade extradition to face justice.  This case and today's extradition demonstrates that through international cooperation, and through great teamwork between the Department of Justice and the Department of Homeland Security, we are able to bring cyber thieves to justice in the United States, wherever they may commit their crimes.”

“Drinkman’s extradition on the indictment this office brought more than a year and a half ago shows how relentlessly we will pursue those who are charged with these serious crimes,” said U.S. Attorney Fishman.  “The incredibly sophisticated work with our partners at the U.S. Secret Service to uncover this enormous, far-reaching scheme demanded an equal effort by our colleagues at the Department of Justice Criminal Division in Washington and our law enforcement partners overseas to bring the defendant back to face these charges.”

“This case demonstrates our commitment to fulfilling an important part of our integrated mission; that of protecting our Nation’s critical financial infrastructure,” said Acting Director Clancy.  “Our success in this investigation and other similar investigations is a credit to our skilled and relentless cyber investigators.  Our determination, coupled with our network of foreign law enforcement partners, ensures that our investigative reach can expand beyond the borders of the United States.”

According to the second superseding indictment, unsealed on July 25, 2013, and other court filings, Drinkman and four co-defendants each served particular roles in the scheme. Drinkman and Alexandr Kalinin, 28, of St. Petersburg, Russia, each allegedly specialized in penetrating network security and gaining access to the corporate victims’ systems.  Roman Kotov, 33, of Moscow, allegedly specialized in mining the networks Drinkman and Kalinin compromised to steal valuable data.

 According to allegations in the indictment, the hackers hid their activities using anonymous web-hosting services provided by Mikhail Rytikov, 27, of Odessa, Ukraine.  Dmitriy Smilianets, 31, of Moscow, then allegedly sold the stolen information and distributed the proceeds of the scheme to the participants.

Drinkman and his co-defendants are charged with attacks on NASDAQ, 7-Eleven, Carrefour, JCP, Hannaford, Heartland, Wet Seal, Commidea, Dexia, JetBlue, Dow Jones, Euronet, Visa Jordan, Global Payment, Diners Singapore and Ingenicard.  It is not alleged that the NASDAQ hack affected its trading platform.

Drinkman and Kalinin were previously charged in New Jersey as “Hacker 1” and “Hacker 2” in a 2009 indictment charging Albert Gonzalez, 33, of Miami, in connection with five corporate data breaches, including the breach of Heartland Payment Systems Inc., which at the time was the largest ever reported.  Gonzalez is currently serving 20 years in federal prison for those offenses.  Kalinin is also charged in two federal indictments in the Southern District of New York: one charges Kalinin in connection with hacking certain computer servers used by NASDAQ and the second charges him and another Russian hacker, Nikolay Nasenkov, with an international scheme to steal bank account information from U.S.-based financial institutions.  Rytikov was previously charged in the Eastern District of Virginia with an unrelated scheme.

Drinkman and Smilianets were arrested at the request of the United States while traveling in the Netherlands on June 28, 2012.  Smilianets was extradited on Sept. 7, 2012, and remains in federal custody.  Kalinin, Kotov and Rytikov remain at large.  All of the defendants are Russian nationals except for Rytikov, who is a citizen of Ukraine.

The Attacks

According to allegations in the indictment, the five defendants conspired with others to penetrate the computer networks of several of the largest payment processing companies, retailers and financial institutions in the world, stealing the personal identifying information of individuals.  They allegedly took user names and passwords, means of identification, credit and debit card numbers and other corresponding personal identification information of cardholders. The conspirators allegedly acquired at least 160 million card numbers through hacking.

The initial entry was often gained using a “SQL injection attack.”  SQL, or Structured Query Language, is a type of programming language designed to manage data held in particular types of databases.  The hackers allegedly identified vulnerabilities in SQL databases and used those vulnerabilities to infiltrate a computer network.  Once the network was infiltrated, the defendants allegedly placed malicious code, or malware, on the system.  This malware created a “back door,” leaving the system vulnerable and helping the defendants maintain access to the network.  In some cases, the defendants lost access to the system due to companies’ security efforts, but were allegedly able to regain access through persistent attacks.

Instant message chats obtained by law enforcement reveal that the defendants allegedly targeted the victim companies for many months, waiting patiently as their efforts to bypass security were underway, sometimes leaving malware implanted for more than a year.

The defendants allegedly used their access to the networks to install “sniffers,” which were programs designed to identify, collect and steal data from the victims’ computer networks. The defendants then allegedly used an array of computers located around the world to store the stolen data and ultimately sell it to others.

Selling the Data

After acquiring the card numbers and associated data—which they referred to as “dumps”—the conspirators allegedly sold it to resellers around the world.  The buyers then sold the dumps through online forums or directly to individuals and organizations.  Smilianets was allegedly in charge of sales, selling the data only to trusted identity theft wholesalers.  He allegedly charged approximately $10 for each stolen American credit card number and associated data, approximately $50 for each European credit card number and associated data and approximately $15 for each Canadian credit card number and associated data, offering discounted pricing to bulk and repeat customers.  Ultimately, the end users encoded each dump onto the magnetic strip of a blank plastic card and cashed out the value of the dump by either withdrawing money from ATMs or making purchases with the cards.

Covering Their Tracks

The defendants allegedly used a number of methods to conceal the scheme.  Rytikov allegedly allowed his clients to hack with the knowledge he would never keep records of their online activities or share information with law enforcement.

Over the course of the conspiracy, the defendants allegedly communicated through private and encrypted communications channels to avoid detection.  Fearing law enforcement would intercept even those communications, some of the conspirators allegedly attempted to meet in person.

To protect against detection by the victim companies, the defendants allegedly altered the settings on victim company networks to disable security mechanisms from logging their actions.  The defendants also allegedly worked to evade existing protections by security software.

As a result of the scheme, financial institutions, credit card companies and consumers suffered hundreds of millions in losses—including more than $300 million in losses reported by just three of the corporate victims—and immeasurable losses to the identity theft victims in costs associated with stolen identities and false charges.

The charges and allegations contained indictments are merely accusations and the defendants are presumed innocent unless and until proven guilty.

The ongoing investigation is being conducted by the U.S. Secret Service.  The case is being prosecuted by Trial Attorney Rick Green of the Criminal Division’s Computer Crime and Intellectual Property Section, Chief Gurbir S. Grewal of the District of New Jersey’s Economic Crimes Unit, and Assistant U.S. Attorney Andrew S. Pak of the Computer Hacking and Intellectual Property Section of the District of New Jersey’s Economic Crimes Unit.

The Criminal Division’s Office of International Affairs assisted with the case, as did public prosecutors with the Dutch Ministry of Security and Justice and the National High Tech Crime Unit of the Dutch National Police.

Wednesday, June 4, 2014

U.S. Leads Multi-National Action Against GameOver Zeus Botnet and Cryptolocker Ransomware, Charges Botnet Administrator


The U.S. Justice Department released the below information on June 2nd:

WASHINGTON, D.C.—The Justice Department today announced a multi-national effort to disrupt the GameOver Zeus botnet—a global network of infected victim computers used by cyber criminals to steal millions of dollars from businesses and consumers—and unsealed criminal charges in Pittsburgh, Pennsylvania, and Omaha, Nebraska, against an administrator of the botnet. In a separate action, U.S. and foreign law enforcement officials worked together to seize computer servers central to the malicious software, or malware, known as Cryptolocker, a form of ransomware that encrypts the files on victims’ computers until they pay a ransom.

Deputy Attorney General James M. Cole, Assistant Attorney General Leslie R. Caldwell of the Justice Department’s Criminal Division, FBI Executive Assistant Director Robert Anderson, Jr., U.S. Attorney David J. Hickton of the Western District of Pennsylvania, U.S. Attorney Deborah R. Gilg of the District of Nebraska, and Department of Homeland Security’s (DHS) Deputy Under Secretary Dr. Phyllis Schneck made the announcement.

Victims of GameOver Zeus may use the following website created by DHS’s Computer Emergency Readiness Team (US-CERT) for assistance in removing the malware: https://www.us-cert.gov/gameoverzeus.

“This operation disrupted a global botnet that had stolen millions from businesses and consumers as well as a complex ransomware scheme that secretly encrypted hard drives and then demanded payments for giving users access to their own files and data,” said Deputy Attorney General Cole. “We succeeded in disabling GameOver Zeus and Cryptolocker only because we blended innovative legal and technical tactics with traditional law enforcement tools and developed strong working relationships with private industry experts and law enforcement counterparts in more than 10 countries around the world.”

“These schemes were highly sophisticated and immensely lucrative, and the cyber criminals did not make them easy to reach or disrupt,” said Assistant Attorney General Caldwell. “But under the leadership of the Justice Department, U.S. law enforcement, foreign partners in more than 10 different countries, and numerous private sector partners joined together to disrupt both these schemes. Through these court-authorized operations, we have started to repair the damage the cyber criminals have caused over the past few years, we are helping victims regain control of their own computers, and we are protecting future potential victims from attack.”

“GameOver Zeus is the most sophisticated botnet the FBI and our allies have ever attempted to disrupt,” said FBI Executive Assistant Director Anderson. “The efforts announced today are a direct result of the effective relationships we have with our partners in the private sector, international law enforcement, and within the U.S. government.”

“The borderless, insidious nature of computer hacking and cybertheft requires us to be bold and imaginative,” said U.S. Attorney Hickton. “We take this action on behalf of hundreds of thousands of computer users who were unwittingly infected and victimized.”

“The sophisticated computer malware targeting of U.S. victims by a global criminal enterprise demonstrates the grave threat of cybercrime to our citizens,” said U.S. Attorney Gilg. “We are grateful for the outstanding collaboration of our international and U.S. law enforcement partners in this successful investigation.”

“The FBI has demonstrated great leadership in continuing to help combat cyber crime, and our international and private sector partners have made enormous contributions as well,” said Deputy Under Secretary Schneck. “This collective effort reflects our ‘whole-of-government’ approach to cybersecurity. DHS is proud to support our partners in helping to identify compromised computers, sharing that information rapidly, and developing useful information and mitigation strategies to help the owners of hacked systems.”

GameOver Zeus Administrator Charged

A federal grand jury in Pittsburgh unsealed a 14-count indictment against Evgeniy Mikhailovich Bogachev, 30, of Anapa, Russian Federation, charging him with conspiracy, computer hacking, wire fraud, bank fraud, and money laundering in connection with his alleged role as an administrator of the GameOver Zeus botnet. Bogachev was also charged by criminal complaint in Omaha with conspiracy to commit bank fraud related to his alleged involvement in the operation of a prior variant of Zeus malware known as Jabber Zeus.

In a separate civil injunction application filed by the United States in federal court in Pittsburgh, Bogachev is identified as a leader of a tightly knit gang of cyber criminals based in Russia and Ukraine that is responsible for the development and operation of both the GameOver Zeus and Cryptolocker schemes. An investigation led in Washington, D.C., identified the GameOver Zeus network as a common distribution mechanism for Cryptolocker. Unsolicited e-mails containing an infected file purporting to be a voice-mail or shipping confirmation are also widely used to distribute Cryptolocker. When opened, those attachments infect victims’ computers. Bogachev is alleged in the civil filing to be an administrator of both GameOver Zeus and Cryptolocker. The injunction filing further alleges that Bogachev is linked to the well-known online nicknames “Slavik” and “Pollingsoon,” among others. The criminal complaint filed in Omaha alleges that Bogachev also used “Lucky12345,” a well-known online moniker previously the subject of criminal charges in September 2012 that were unsealed in Omaha on April 11, 2014.

Disruption of GameOver Zeus Botnet

GameOver Zeus, also known as Peer-to-Peer Zeus, is an extremely sophisticated type of malware designed to steal banking and other credentials from the computers it infects. Unknown to their rightful owners, the infected computers also secretly become part of a global network of compromised computers known as a botnet, a powerful online tool that cyber criminals can use for numerous criminal purposes besides stealing confidential information from the infected machines themselves. GameOver Zeus, which first emerged around September 2011, is the latest version of Zeus malware that began appearing at least as early as 2007. GameOver Zeus’ decentralized, peer-to-peer structure differentiates it from earlier Zeus variants. Security researchers estimate that between 500,000 and one million computers worldwide are infected with Gameover Zeus and that approximately 25 percent of the infected computers are located in the United States. The principal purpose of the botnet is to capture banking credentials from infected computers. Those credentials are then used to initiate or re-direct wire transfers to accounts overseas that are controlled by cyber criminals. The FBI estimates that GameOver Zeus is responsible for more than $100 million in losses.

The GameOver Zeus botnet operates silently on victim computers by directing those computers to reach out to receive commands from other computers in the botnet and to funnel stolen banking credentials back to the criminals who control the botnet. For this reason, in addition to the criminal charges announced today, the United States obtained civil and criminal court orders in federal court in Pittsburgh authorizing measures to redirect the automated requests by victim computers for additional instructions away from the criminal operators to substitute servers established pursuant to court order. The order authorizes the FBI to obtain the Internet protocol addresses of the victim computers reaching out to the substitute servers and to provide that information to US-CERT to distribute to other countries’ CERTS and private industry to assist victims in removing the   GameOver Zeus malware from their computers. At no point during the operation did the FBI or law enforcement access the content of any of the victims’ computers or electronic communications.

Besides the United States, law enforcement from the Australian Federal Police; the National Police of the Netherlands National High Tech Crime Unit; European Cybercrime Centre (EC3); Germany’s Bundeskriminalamt; France’s Police Judiciare; Italy’s Polizia Postale e delle Comunicazioni; Japan’s National Police Agency; Luxembourg’s Police Grand Ducale; New Zealand Police; the Royal Canadian Mounted Police; Ukraine’s Ministry of Internal Affairs-Division for Combating Cyber Crime; and the United Kingdom’s National Crime Agency participated in the operation. The Defense Criminal Investigative Service of the U.S. Department of Defense also participated in the investigation.

Invaluable technical assistance was provided by Dell SecureWorks and CrowdStrike. Numerous other companies also provided assistance, including facilitating efforts by victims to remediate the damage to their computers inflicted by Gameover Zeus. These companies include Microsoft Corporation, Abuse.ch, Afilias, F-Secure, Level 3 Communications, McAfee, Neustar, Shadowserver, Anubis Networks, Symantec, Heimdal Security, Sophos, and Trend Micro.

The DHS National Cybersecurity and Communications Integration Center (NCCIC), which houses the US-CERT, plays a key role in triaging and collaboratively responding to the threat by providing technical assistance to information system operators, disseminating timely mitigation strategies to known victims, and sharing actionable information to the broader community to help prevent further infections.

Disruption of Cryptolocker

In addition to the disruption operation against GameOver Zeus, the Justice Department led a separate multi-national action to disrupt the malware known as Cryptolocker (sometimes written as CryptoLocker), which began appearing about September 2013 and is also a highly sophisticated malware that uses cryptographic key pairs to encrypt the computer files of its victims. Victims are forced to pay hundreds of dollars and often as much as $700 or more to receive the key necessary to unlock their files. If the victim does not pay the ransom, it is impossible to recover their files.
Security researchers estimate that, as of April 2014, Cryptolocker had infected more than 234,000 computers, with approximately half of those in the United States. One estimate indicates that more than $27 million in ransom payments were made in just the first two months since Cryptolocker emerged.

The law enforcement actions against Cryptolocker are the result of an ongoing criminal investigation by the FBI’s Washington Field Office, in coordination with law enforcement counterparts from Canada, Germany, Luxembourg, the Netherlands, United Kingdom, and Ukraine.

Companies such as Dell SecureWorks and Deloitte Cyber Risk Services also assisted in the operation against Cryptolocker, as did Carnegie Mellon University and the Georgia Institute of Technology (Georgia Tech). The joint effort aided the FBI in identifying and seizing computer servers acting as command and control hubs for the Cryptolocker malware.

The FBI’s Omaha and Pittsburgh Field Offices led both malware disruptions and conducted the investigation of Bogachev. The prosecution in Pittsburgh is being handled by Assistant U.S. Attorney Shardul Desai of the Western District of Pennsylvania and the prosecution in Omaha by Trial Attorney William A. Hall of the Criminal Division’s Computer Crime and Intellectual Property Section (CCIPS) and Assistant U.S. Attorney Steven Russell of the District of Nebraska. The civil action to disrupt the Gameover Zeus botnet and Cryptolocker malware is led by Trial Attorneys Ethan Arenson and David Aaron of CCIPS and Assistant U.S. Attorney Michael A. Comber of the Western District of Pennsylvania.

The Criminal Division’s Office of International Affairs provided significant assistance throughout the criminal and civil investigations.

The details contained in the indictment, criminal complaint, and related pleadings are merely accusations, and the defendant is presumed innocent unless and until proven guilty.
Anyone claiming an interest in any of the property seized or actions enjoined pursuant to the court orders described in this release is advised to visit the following website for notice of the full contents of the orders at http://www.justice.gov/opa/gameover-zeus.html.

Monday, February 3, 2014

FBI: A Byte Out Of History - A $10 Million Hack, 1994-Style


The FBI web site offers a piece on a computer hacking case from 1994.

It was hardly the opening salvo in a new era of virtual crime, but it was certainly a shot across the bow.

Two decades ago, a group of enterprising criminals on multiple continents—led by a young computer programmer in St. Petersburg, Russia—hacked into the electronic systems of a major U.S. bank and secretly started stealing money. No mask, no note, no gun—this was bank robbery for the technological age.

You can read the rest of the piece via the below link:

http://www.fbi.gov/news/stories/2014/january/byte-out-of-history-10-million-hack-1994-style/byte-out-of-history-10-million-hack-1994-style?utm_campaign=email-Daily&utm_medium=email&utm_source=fbi-top-stories&utm_content=294290 

Saturday, July 13, 2013

FBI Warns Public That Cyber Criminals Continue To Use Spear-Phishing Attacks To Compromise Computer Networks


The FBI web site offers a warning about cyber criminals' use of spear-phishing attacks.

The FBI has seen an increase in criminals who use spear-phishing attacks to target multiple industry sectors. These attacks allow criminals to access private computer networks. They exploit that access to create fake identities, steal intellectual property, and compromise financial credentials to steal money from victims’ accounts.

In spear-phishing attacks, cyber criminals target victims because of their involvement in an industry or organization they wish to compromise. Often, the e-mails contain accurate information about victims obtained via a previous intrusion or from data posted on social networking sites, blogs, or other websites. This information adds a veneer of legitimacy to the message, increasing the chances the victims will open the e-mail and respond as directed.

You can read the rest of the piece via the below link:

http://www.fbi.gov/sandiego/press-releases/2013/fbi-warns-public-that-cyber-criminals-continue-to-use-spear-phishing-attacks-to-compromise-computer-networks?utm_campaign=email-Daily&utm_medium=email&utm_source=fbi-in-the-news&utm_content=240054