Search This Blog

Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Saturday, March 31, 2012

Chinese Company and Employee Deny Any Involvement in Hacking Attacks

Excerpt from an article in

The New York Times
Saturday, March 31, 2012

Chinese Company and Employee Deny Any Involvement in Hacking Attacks

By DAVID BARBOZA

SHANGHAI — Tencent, a Chinese Internet company, denied on Friday that one of its employees had been involved in a recent breach of computers belonging to Japanese and Indian companies, as well as Tibetan activists.

The company and the employee suggested that his identity might have been confused with someone else’s.

The company released a statement soon after Trend Micro, a computer security company with headquarters in Tokyo, released a report on Friday describing the breach. It was the result of a nearly yearlong effort to hack into computers and steal information from hundreds of companies and individuals in several countries, the report said.

The report never identified a hacker by name. But it linked the attacks to an alias used by a graduate of Sichuan University in western China who wrote several articles on computer hacking and defense. The researchers found the alias through its connection to an e-mail address and a QQ number, the Chinese equivalent of an instant messaging screen name.

The New York Times identified the owner of the alias as Gu Kaiyuan, based on online records of his writing. Mr. Gu is now an employee at Tencent, which offers social networking, instant messaging, online gaming and other online features.

On Thursday, when asked about the attacks, Mr. Gu said, “I have nothing to say.” On Friday, however, he denied involvement.

With Advance Warning, Bracing for Attack on Internet by Anonymous

Excerpt from an article in

The New York Times
Added on Saturday, March 31, 2012

With Advance Warning, Bracing for Attack on Internet by Anonymous

By SOMINI SENGUPTA

SAN FRANCISCO — On a quiet Sunday in mid-February, something curious attracted the attention of the behind-the-scenes engineers who scour the Internet for signs of trouble. There, among the ubiquitous boasts posted by the hacking collective Anonymous, was a call to attack some of the network’s most crucial parts.

The message called it Operation Global Blackout, and rallied Anonymous supporters worldwide to attack the Domain Name System, which converts human-friendly domain names like google.com into numeric addresses that are more useful for computers.

It declared when the attack would be carried out: March 31. And it detailed exactly how: by bombarding the Domain Name System with junk traffic in an effort to overwhelm it altogether.

There was no way to know for sure whether this was a pre-April Fool’s Day hoax or a credible threat. After all, this was Anonymous, a decentralized movement with no leaders and no coherent ideology, but a track record of considerable damage. The call to arms would have to be treated as one would treat a bomb threat called in to a high school football game. The engineers would have to prepare.

Those preparations turned into a fast-track, multimillion-dollar global effort to beef up the Domain Name System. They offer a glimpse into the largely unknown forces that keep the Internet running in the face of unpredictable, potentially devastating threats.

Among those leading the effort was Bill Woodcock, whose nonprofit based in San Francisco, Packet Clearing House, defends vital pieces of Internet infrastructure. By his calculation, the Anonymous threat was as good a reason as any to accelerate what might have been done anyway over the next several months: fortify the network, chiefly by expanding the capacity of the root servers that are its main pillar.

“Whether or not Anonymous carries out this particular attack, there are larger attacks that do happen,” Mr. Woodcock said. “A forewarning of this attack allowed everyone to act proactively for a change. We can get out in front of the bigger attacks.”

Florida Man Pleads Guilty to Computer Intrusion and Wiretapping Scheme Targeting Celebrities

Florida Man Pleads Guilty to Computer Intrusion and Wiretapping Scheme Targeting Celebrities 

U.S. Attorney’s OfficeMarch 26, 2012
  • Central District of California(213) 894-2434
LOS ANGELES—A Florida man pleaded guilty today to a series of cyber-related crimes relating to his hacking into the personal e-mail accounts of more than 50 individuals associated with the entertainment industry.
Christopher Chaney, 35, of Jacksonville, Florida, pleaded guilty to nine felony counts of a 28-count first superseding indictment, including unauthorized access to protected computers in furtherance of wiretapping and wire fraud, unauthorized damage to protected computers resulting in more than $5,000 loss and physical harm, and wiretapping. At the conclusion of the hearing, United States District Court Judge S. James Otero ordered Chaney taken into custody.
During the hearing, Chaney admitted that from at least November 2010 to October 2011, he hacked into the e-mail accounts of Scarlett Johansson, Mila Kunis, Renee Olstead, and others by taking the victims’ e-mail addresses, clicking on the “Forgot your password?” feature, and then re-setting the victims’ passwords by correctly answering their security questions using publicly available information he found by searching the Internet. Once Chaney gained exclusive control of the victims’ e-mail accounts, he was able to access all of their e-mail boxes. While in the accounts, Chaney also went through their contact lists to find e-mail addresses of potential new hacking targets.
In pleading guilty to the wiretapping charges, Chaney admitted that, for most victims, he also changed their e-mail account settings by inserting his alias e-mail address into the forwarding feature so that a duplicate copy of all incoming e-mails to the victims—including any attachments—would be sent virtually simultaneously to Chaney without the victims’ knowledge. Most victims did not check their account settings, so even after they regained control of their e-mail accounts, Chaney’s alias address remained in their account settings. As a result, for many victims, copies of their incoming e-mails, including attachments, were sent to Chaney for weeks or months without their knowledge, causing Chaney to receive thousands of victim e-mails. In addition, when a victim reset his/her password to regain control of the account, Chaney sometimes hacked into the account again and reset the password, sometimes multiple times, in order to continue illegally accessing that victim’s account.
Chaney admitted that as his hacking scheme became more extensive, he began using a proxy service called “Hide My IP” because he knew what he was doing was illegal and wanted to “cover his tracks” so that law enforcement agents could not trace the hacking back to his home computer. Even after his home computers were seized by law enforcement agents pursuant to a federal search warrant, but before he was arrested, Chaney used another computer to hack into another victim’s e-mail account.
Chaney further admitted that as a result of his hacking scheme, he obtained numerous private communications, private photographs, and confidential documents from the victims’ e-mail accounts. The confidential documents included business contracts, scripts, letters, driver’s license information, and Social Security information. On several occasions, after hacking into victim accounts, Chaney sent e-mails from the hacked accounts to friends of the victims, fraudulently posing as the victims to request more private photographs. Chaney downloaded many of the confidential documents and photographs he stole to his home computer, where he saved them on his hard drive in separate computer file folders. Chaney e-mailed many of the stolen photographs to others, including another hacker and two gossip websites. As a result, some of those stolen photographs, several of which were explicit, were later posted on the Internet.
“Today’s guilty pleas shine a bright light on the dark underworld of computer hacking,” said United States Attorney AndrĂ© Birotte, Jr., whose office prosecuted the case. “This case demonstrates that everyone, even public figures, should take precautions to shield their personal information from the hackers that inhabit that dark underworld. It also demonstrates that the Department of Justice will take whatever steps are necessary to protect Americans from harm in cyberspace.”
“Mr. Chaney’s admission to compromising victim accounts, utilizing both technically and socially engineered means, demonstrates the persistence and extent to which a hacker will go to obtain private information,” said Steven Martinez, Assistant Director in Charge of the FBI’s Los Angeles Field Office. “This case sends an important message to all users of Internet-accessible media that practicing good computer security makes us less vulnerable to this type of attack. The FBI remains committed to investigating cyber adversaries who target protected computers, whether of private citizens or the nation’s critical infrastructure.”
Each charge of unauthorized access to a protected computer carries a maximum of five years in prison, each charge of unauthorized damage to a protected computer carries a maximum charge of 10 years in prison, and each charge of wiretapping carries a maximum of five years in prison. As a result of all of today’s guilty pleas, Chaney faces a total statutory maximum sentence of 60 years in federal prison. In addition to the possible prison term, as part of his plea agreement filed in federal court, Chaney agreed to forfeit his computers and related devices seized during the investigation, to pay restitution to all of the victims for any losses they suffered, and to comply with strict restrictions regarding his future use of computers and computer-related devices. In exchange, the government agreed to dismiss the remaining counts, including nine counts of aggravated identity theft, at the time defendant is sentenced.
Chaney is scheduled to be sentenced by United States District Judge S. James Otero on July 23, 2012.
The investigation of this case was led and conducted by the Federal Bureau of Investigation.

Friday, March 30, 2012

Visa & MasterCard Security Breach

Note to Visitors:  We have moved!  For current news and information, please visit us at our successor blogs:  http://JBK-BizTech.blogspot.com and http://JBK-Current-Events.blogspot.com.  Thank you.


CNBC's Mary Thompson has the details on MasterCard and Visa investigating a potential data breach at a 3rd party processor.  To see videos, click the links below:

http://video.cnbc.com/gallery/?video=3000081506

http://video.cnbc.com/gallery/?video=3000081531

Thursday, March 22, 2012

2011 Was the Year of the 'Hacktivist'

2011 Was the Year of the 'Hacktivist,' According to the 'Verizon 2012 Data Breach Investigations Report'
Attacks Are Increasingly Motivated by Political and Social Intent; Majority of Breaches Avoidable With Sound Security Measures
News Release ShareThis
NEW YORK – March 22, 2012 –
The "Verizon 2012 Data Breach Investigations Report" reveals the dramatic rise of "hacktivism" -- cyberhacking to advance political and social objectives.

In 2011, 58 percent of data stolen was attributed to hacktivism, according to the annual report released today from Verizon.  The new trend contrasts sharply with the data-breach pattern of past several years, during which the majority of attacks were carried out by cybercriminals, whose primary motivation was financial gain.

Seventy-nine percent of attacks represented in the report were opportunistic.  Of all attacks, 96 percent were not highly difficult, meaning they did not require advanced skills or extensive resources.  Additionally, 97 percent of the attacks were avoidable, without the need for organizations to resort to difficult or expensive countermeasures.  The report also contains recommendations that large and small organizations can implement to protect themselves.

Now in its fifth year of publication, the report spans 855 data breaches across 174 million stolen records - the second-highest data loss that the Verizon RISK (Research Investigations Solutions Knowledge) team has seen since it began collecting data in 2004.  Verizon was joined by five partners that contributed data to this year's report: the United States Secret Service, the Dutch National High Tech Crime Unit, the Australian Federal Police, the Irish Reporting & Information Security Service and the Police Central e-Crime Unit of the London Metropolitan Police.

"With the participation of our law enforcement partners around the globe, the '2012 Data Breach Investigations Report' offers what we believe is the most comprehensive look ever into the state of cybersecurity," said Wade Baker, Verizon's director of risk intelligence.  "Our goal is to increase the awareness of global cybercrime in an effort to improve the security industry's ability to fight it while helping government agencies and private sector organizations develop their own tailored security plans."

The report findings reinforced the international nature of cybercrime.  Breaches originated from 36 countries around the globe, an increase from 22 countries the year prior.  Nearly 70 percent of breaches originated in Eastern Europe, with less than 25 percent originating in North America.

External attacks remain largely responsible for data breaches, with 98 percent of them attributable to outsiders.  This group includes organized crime, activist groups, former employees, lone hackers and even organizations sponsored by foreign governments.  With a rise in external attacks, the proportion of insider incidents declined again in this year's report, to 4 percent.  Business partners were responsible for less than 1 percent of data breaches.

In terms of attack methods, hacking and malware have continued to increase. In fact, hacking was a factor in 81 percent of data breaches and in 99 percent of data lost.  Malware also played a large part in data breaches; it appeared in 69 percent of breaches and 95 percent of compromised records.  Hacking and malware are favored by external attackers, as these attack methods allow them to attack multiple victims at the same time from remote locations.  Many hacking and malware tools are designed to be easy and simple for criminals to use.

Additionally, the compromise-to-discovery timeline continues to be measured in months and even years, as opposed to hours and days.  Finally, third parties continue to detect the majority of breaches (92 percent).

(NOTE:  Additional resources supporting the "2012 Data Breach Investigations Report" are available, including high-resolution charts,  B-roll available upon request.)

Key Findings of the 2012 Report

Data from the 2012 report also demonstrates that:

  • Industrial espionage revealed criminal interest in stealing trade secrets and gaining access to intellectual property.  This trend, while less frequent, has serious implications for the security of corporate data, especially if it accelerates.
  • External attacks increased. Since hacktivism is a factor in more than half of the breaches, attacks are predominantly led by outsiders.  Only 4 percent of attacks implicate internal employees.
  • Hacking and malware dominate. The use of hacking and malware increased in conjunction with the rise in external attacks in 2011.  Hacking appeared in 81 percent of breaches (compared with 50 percent in 2010), and malware appeared in 69 percent (compared with 49 percent in 2010). Hacking and malware offer outsiders an easy way to exploit security flaws and gain access to confidential data.
  • Personally identifiable information (PII) has become a jackpot for criminals. PII, which can include a person's name, contact information and social security number, is increasingly becoming a choice target. In 2011, 95 percent of records lost included personal information, compared with only 1 percent in 2010.
  • Compliance does not equal security.  While compliance programs, such as the Payment Card Industry Data Security Standard, provide sound steps to increasing security, being PCI compliant does not make an organization immune from attacks.
"The report demonstrates that unfortunately, many organizations are still not getting the message about the steps they can take to prevent data breaches," said Baker.  "This year, we have segmented our recommendations for enterprises and small businesses in the hope that this will make our suggestions more actionable. Additionally, we believe greater public awareness about cyberthreats and user education and training are vitally important in the fight against cybercrime."
Recommendations for Enterprises
  1. Eliminate unnecessary data. Unless there is a compelling reason to store or transmit data, destroy it.  Monitor all important data that must be kept.
  2. Establish essential security controls. To effectively defend against a majority of data breaches, organizations must ensure fundamental and common sense security countermeasures are in place and that they are functioning correctly. Monitor security controls regularly.
  3. Place importance on event logs. Monitor and mine event logs for suspicious activity - breaches are usually identified by analyzing event logs.
  4. Prioritize security strategy. Enterprises should evaluate their threat landscape and use the findings to create a unique, prioritized security strategy.
Recommendations for Small Organizations
  1. Use a firewall. Install and maintain a firewall on Internet-facing services to protect data. Hackers cannot steal what they cannot reach.
  2. Change default credentials. Point-of-sale (POS) and other systems come with pre-set credentials. Change the credentials to prevent unauthorized access.
  3. Monitor third parties. Third parties often manage firewalls and POS systems.  Organizations should monitor these vendors to ensure they have implemented the above security recommendations, where applicable.
The DBIR can be downloaded in full at: www.verizon.com/enterprise/2012dbir/us.
The Verizon 2012 DBIR will be available in seven languages. The initial report is in English, and translations will be available June 6 in French, German, Italian, Japanese, Spanish and Portuguese.

Verizon, through its Terremark subsidiary, helps organizations protect their core asset: data.  The company does this through a robust suite of security services -- including governance, risk and compliance solutions; identity and access management solutions; investigative response; data protection services; threat management services; and vulnerability management services -- delivered in the cloud or on premises.  For more information, visit us at verizonbusiness.com/products/security.  For ongoing security insight and analysis from some of the world's most distinguished security researchers, read the Verizon Security Blog at securityblog.verizonbusiness.com.

Verizon Communications Inc. (NYSE, Nasdaq: VZ), headquartered in New York, is a global leader in delivering broadband and other wireless and wireline communications services to consumer, business, government and wholesale customers.  Verizon Wireless operates America's most reliable wireless network, with nearly 108 million total connections nationwide.  Verizon also provides converged communications, information and entertainment services over America's most advanced fiber-optic network, and delivers integrated business solutions to customers in more than 150 countries, including all of the Fortune 500.  A Dow 30 company with $111 billion in 2011 revenues, Verizon employs a diverse workforce of nearly 194,000.  For more information, visit www.verizon.com.

####

Tuesday, March 6, 2012

Six Hackers Charged

Six Hackers in the United States and Abroad Charged for Crimes Affecting Over One Million Victims 
Four Principal Members of “Anonymous” and “LulzSec” Charged with Computer Hacking and Fifth Member Pleads Guilty; “AntiSec” Member also Charged with Stealing Confidential Information from Approximately 860,000 Clients and Subscribers of Stratfor

U.S. Attorney’s OfficeMarch 06, 2012
  • Southern District of New York(212) 637-2600
Five computer hackers in the United States and abroad were charged today, and a sixth pled guilty, for computer hacking and other crimes. The six hackers identified themselves as aligned with the group Anonymous, which is a loose confederation of computer hackers and others, and/or offshoot groups related to Anonymous, including “Internet Feds,” “LulzSec,” and “AntiSec.”
RYAN ACKROYD, a/k/a “kayla,” a/k/a “lol,” a/k/a “lolspoon”; JAKE DAVIS, a/k/a “topiary,” a/k/a “atopiary”; DARREN MARTYN, a/k/a “pwnsauce,” a/k/a “raepsauce,” a/k/a “networkkitten”; and DONNCHA O’CEARRBHAIL, a/k/a “palladium,” who identified themselves as members of Anonymous, Internet Feds, and/or LulzSec, were charged in an indictment unsealed today in Manhattan federal court with computer hacking conspiracy involving the hacks of Fox Broadcasting Company, Sony Pictures Entertainment, and the Public Broadcasting Service (“PBS”). O’CEARRBHAIL is also charged in a separate criminal complaint with intentionally disclosing an unlawfully intercepted wire communication.
HECTOR XAVIER MONSEGUR, a/k/a “Sabu,” a/k/a “Xavier DeLeon,” a/k/a “Leon,” who also identified himself as a member of Anonymous, Internet Feds, and LulzSec, pled guilty on August 15, 2011 in U.S. District Court to a 12-count information charging him with computer hacking conspiracies and other crimes. MONSEGUR’S information and guilty plea were unsealed today. The crimes to which MONSEGUR pled guilty include computer hacking conspiracy charges initially filed in the Southern District of New York. He also pled guilty to the following charges: a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Eastern District of California related to the hacks of HBGary, Inc. and HBGary Federal LLC; a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Central District of California related to the hack of Sony Pictures Entertainment and Fox Broadcasting Company; a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Northern District of Georgia related to the hack of Infragard Members Alliance; and a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Eastern District of Virginia related to the hack of PBS, all of which were transferred to the Southern District of New York, pursuant to Rule 20 of the Federal Rules of Criminal Procedure, in coordination with the Computer Crime and Intellectual Property Section (“CCIPS”) in the Justice Department’s Criminal Division.
Late yesterday, JEREMY HAMMOND, a/k/a “Anarchaos,” a/k/a “sup_g,” a/k/a “burn,” a/k/a “yohoho,” a/k/a “POW,” a/k/a “tylerknowsthis,” a/k/a “crediblethreat,” who identified himself as a member of AntiSec, was arrested in Chicago, Illinois and charged in a criminal complaint with crimes relating to the December 2011 hack of Strategic Forecasting, Inc. (“Stratfor”), a global intelligence firm in Austin, Texas, which may have affected approximately 860,000 victims. In publicizing the Stratfor hack, members of AntiSec reaffirmed their connection to Anonymous and other related groups, including LulzSec. For example, AntiSec members published a document with links to the stolen Stratfor data titled, “Anonymous Lulzxmas rooting you proud” on a file sharing website.
The following allegations are based on the indictment, the information, the complaints, and statements made at MONSEGUR’s guilty plea:
Hacks by Anonymous, Internet Feds, and LulzSec
Since at least 2008, Anonymous has been a loose confederation of computer hackers and others. MONSEGUR and other members of Anonymous took responsibility for a number of cyber attacks between December 2010 and June 2011, including denial of service (“DoS”) attacks against the websites of Visa, MasterCard, and PayPal, as retaliation for the refusal of these companies to process donations to Wikileaks, as well as hacks or DoS attacks on foreign government computer systems.
Between December 2010 and May 2011, members of Internet Feds similarly waged a deliberate campaign of online destruction, intimidation, and criminality. Members of Internet Feds engaged in a series of cyber attacks that included breaking into computer systems, stealing confidential information, publicly disclosing stolen confidential information, hijacking victims’ e-mail and Twitter accounts, and defacing victims’ Internet websites. Specifically, ACKROYD, DAVIS, MARTYN, O’CEARRBHAIL, and MONSEGUR, as members of InternetFeds, conspired to commit computer hacks including: the hack of the website of Fine Gael, a political party in Ireland; the hack of computer systems used by security firms HBGary, Inc. and its affiliate HBGary Federal, LLC, from which Internet Feds stole confidential data pertaining to 80,000 user accounts; and the hack of computer systems used by Fox Broadcasting Company, from which Internet Feds stole confidential data relating to more than 70,000 potential contestants on “X-Factor,” a Fox television show.
In May 2011, following the publicity that they had generated as a result of their hacks, including those of Fine Gael and HBGary, ACKROYD, DAVIS, MARTYN, and MONSEGUR formed and became the principal members of a new hacking group called “Lulz Security” or “LulzSec.” Like Internet Feds, LulzSec undertook a campaign of malicious cyber assaults on the websites and computer systems of various business and governmental entities in the United States and throughout the world. Specifically, ACKROYD, DAVIS, MARTYN, and MONSEGUR, as members of LulzSec, conspired to commit computer hacks including the hacks of computer systems used by the PBS, in retaliation for what LulzSec perceived to be unfavorable news coverage in an episode of the news program “Frontline”; Sony Pictures Entertainment, in which LulzSec stole confidential data concerning approximately 100,000 users of Sony’s website; and Bethesda Softworks, a video game company based in Maryland, in which LulzSec stole confidential information for approximately 200,000 users of Bethesda’s website.
The Stratfor Hack
In December 2011, HAMMOND conspired to hack into computer systems used by Stratfor, a private firm that provides governments and others with independent geopolitical analysis. HAMMOND and his co-conspirators, as members of AntiSec, stole confidential information from those computer systems, including Stratfor employees’ e-mails as well as account information for approximately 860,000 Stratfor subscribers or clients. HAMMOND and his co-conspirators stole credit card information for approximately 60,000 credit card users and used some of the stolen data to make unauthorized charges exceeding $700,000. HAMMOND and his co-conspirators also publicly disclosed some of the confidential information they had stolen.
The Hack of International Law Enforcement
In January 2012, O’CEARRBHAIL hacked into the personal e-mail account of an officer with Ireland’s national police service, the An Garda Siochana (the “Garda”). Because the Garda officer had forwarded work e-mails to a personal account, O’CEARRBHAIL learned information about how to access a conference call that the Garda, the FBI, and other law enforcement agencies were planning to hold on January 17, 2012 regarding international investigations of Anonymous and other hacking groups. O’CEARRBHAIL then accessed and secretly recorded the January 17 international law enforcement conference call, and then disseminated the illegally-obtained recording to others.
***
MONSEGUR, 28, of New York, New York, pled guilty to three counts of computer hacking conspiracy, five counts of computer hacking, one count of computer hacking in furtherance of fraud, one count of conspiracy to commit access device fraud, one count of conspiracy to commit bank fraud, and one count of aggravated identity theft. He faces a maximum sentence of 124 years and six months in prison.
ACKROYD, 23, of Doncaster, United Kingdom; DAVIS, 29, of Lerwick, Shetland Islands, United Kingdom; and MARTYN, 25, of Galway, Ireland, each are charged with two counts of computer hacking conspiracy. Each conspiracy count carries a maximum sentence of 10 years in prison.
O’CEARRBHAIL, 19, of Birr, Ireland, is charged in the indictment with one count of computer hacking conspiracy, for which he faces 10 years in prison. He is also charged in the complaint with one count of intentionally disclosing an unlawfully intercepted wire communication, for which he faces a maximum sentence of five years in prison.
HAMMOND, 27, of Chicago, Illinois, is charged with one count of computer hacking conspiracy, one count of computer hacking, and one count of conspiracy to commit access device fraud. Each count carries a maximum sentence of 10 years in prison.
DAVIS is separately facing criminal charges in the United Kingdom, which remain pending, and ACKROYD is being interviewed today by the Police Central e-crime Unit in the United Kingdom. O’CEARRBHAIL was arrested today by the Garda.
The case is being prosecuted by the U.S. Attorney’s Office for the Southern District of New York. The investigation was initiated and led by the FBI, and its New York Cyber Crime Task Force, which is a federal, state, and local law enforcement task force combating cybercrime, with assistance from the PCeU; a unit of New Scotland Yard’s Specialist Crime Directorate, SCD6; the Garda; the Criminal Division’s CCIPS; and the U.S. Attorneys’ Offices for the Eastern District of California, the Central District of California, the Northern District of Georgia, and the Eastern District of Virginia; as well as the Criminal Division’s Office of International Affairs.
The charges contained in the indictment and complaints are merely accusations, and the defendants are presumed innocent unless and until proven guilty.

Monday, March 5, 2012

The Bright Side of Being Hacked

Excerpt from an article in

The New York Times
Monday, March 05, 2012

The Bright Side of Being Hacked

By SOMINI SENGUPTA and NICOLE PERLROTH

SAN FRANCISCO — Hackers operating under the banner Anonymous have been poking a finger in the eye of one private company after another for two years now.

They steal files from inside corporate computer systems and occasionally, as in the case of Stratfor last week, dump company e-mail online for all to see.

The Stratfor hack, in which Anonymous claimed to have joined forces with WikiLeaks, drove home a clear lesson about the era of ubiquitous “hactivism,” or hacking as a form of protest.

Despite the arrests of dozens of suspected members of Anonymous and its offshoots worldwide, it is far from diminished. Nor have most of its corporate targets been irreparably damaged by the attacks.

Rather, what Anonymous has done, experts said at the big RSA computer security conference here last week, is raise the alarm about the unguarded state of corporate computer systems.

By and large, the Anonymous break-ins take advantage of gaping computer holes and gullible human beings. The hackers ferret out weak passwords and take advantage of unencrypted e-mail stashes. They persuade company employees — one is all it takes — to click on rogue Web sites or divulge a confidential piece of information, in an exercise known as social engineering.

“Anonymous is a wake-up call,” said Roger Cressey, senior vice president of Booz Allen Hamilton, a defense and intelligence contractor that was attacked by the group last summer. “Any company that is patting themselves on the back and saying that they’re not a target or not susceptible to attack is in complete and utter denial.”

More to the point, a company that is a target of Anonymous may also be the target of a far more potent adversary. The social engineering tactics that Anonymous members have repeatedly used are often similar to those used by criminal hackers and state-sponsored actors who penetrate company systems in order to steal valuable secrets, whether for monetary gain or competitive edge.

Wednesday, February 22, 2012

News Release from the FBI

New Twists to Telephone Collection Scam Related to Delinquent Payday Loans 

Washington, D.C.February 21, 2012
  • FBI National Press Office(202) 324-3691
The Internet Crime Complaint Center (IC3) continues to receive complaints from victims of payday loan telephone collection scams. As previously reported in December 2010, the typical payday loan scam involves a caller who claims the victim is delinquent on a payday loan and must make payment to avoid legal consequences.
Callers pose as representatives of the FBI, “Federal Legislative Department,” various law firms, or other legitimate-sounding agencies and claim to be collecting debts for companies such as United Cash Advance, U.S. Cash Advance, U.S. Cash Net, or other Internet check-cashing services. The fraudsters relentlessly call the victim’s home, cell phone, and place of employment in attempts to obtain payment. The callers refuse to provide information regarding the alleged payday loan or any documentation and become verbally abusive when questioned.
The IC3 has observed variations of this scam in which the caller tells the victim that there are outstanding warrants for the victim’s arrest. The caller claims that the basis of the warrants is non-payment of the underlying loan and/or hacking. If it’s the latter, the caller tells the victim that he or she is wanted for hacking into a business’ computer system to steal customer information. The caller will then demand payment via debit/credit card; in other cases, the caller further instructs victims to obtain a prepaid card to cover the payment.
The high-pressure collection tactics used by the fraudsters have also evolved. In one recent complaint, a person posed as a process server and appeared at the victim’s job. In another instance, a phony process server came to a victim’s home. In both cases, after claiming to be serving a court summons, the alleged process server said the victim could avoid going to court if he or she provided a debit card number for repayment of the loan.
If you are contacted by someone who is trying to collect a debt that you do not owe, you should:
  • Contact your local law enforcement agencies if you feel you are in immediate danger;
  • Contact your bank(s) and credit card companies;
  • Contact the three major credit bureaus and request an alert be put on your file;
  • If you have received a legitimate loan and want to verify that you do not have any outstanding obligation, contact the loan company directly;
  • File a complaint at www.IC3.gov.

Wednesday, February 15, 2012

Researchers Find Flaw in Online Encryption Method

Excerpt from an article in The New York Times
Wednesday, February 15, 2012

Researchers Find Flaw in an Online Encryption Method 

By JOHN MARKOFF

SAN FRANCISCO — A team of European and American mathematicians and cryptographers have discovered an unexpected weakness in the encryption system widely used worldwide for online shopping, banking, e-mail and other Internet services intended to remain private and secure.

The flaw — which involves a small but measurable number of cases — has to do with the way the system generates random numbers, which are used to make it practically impossible for an attacker to unscramble digital messages. While it can affect the transactions of individual Internet users, there is nothing an individual can do about it. The operators of large Web sites will need to make changes to ensure the security of their systems, the researchers said.

The potential danger of the flaw is that even though the number of users affected by the flaw may be small, confidence in the security of Web transactions is reduced, the authors said.

The system requires that a user first create and publish the product of two large prime numbers, in addition to another number, to generate a public “key.” The original numbers are kept secret. To encrypt a message, a second person employs a formula that contains the public number. In practice, only someone with knowledge of the original prime numbers can decode that message.

For the system to provide security, however, it is essential that the secret prime numbers be generated randomly. The researchers discovered that in a small but significant number of cases, the random number generation system failed to work correctly.

The importance in ensuring that encryption systems do not have undetected flaws cannot be overstated. The modern world’s online commerce system rests entirely on the secrecy afforded by the public key cryptographic infrastructure.

The researchers described their work in a paper that the authors have submitted for publication at a cryptography conference to be held in Santa Barbara, Calif., in August. They made their findings public Tuesday because they believe the issue is of immediate concern to the operators of Web servers that rely on the public key cryptography system.

Saturday, February 11, 2012

Electronic Security & Digital Espionage


Excerpt from an article in The New York Times
Saturday, February 11, 2012

Electronic Security a Worry in an Age of Digital Espionage 

By NICOLE PERLROTH

SAN FRANCISCO — When Kenneth G. Lieberthal, a China expert at the Brookings Institution, travels to that country, he follows a routine that seems straight from a spy film.

He leaves his cellphone and laptop at home and instead brings “loaner” devices, which he erases before he leaves the United States and wipes clean the minute he returns. In China, he disables Bluetooth and Wi-Fi, never lets his phone out of his sight and, in meetings, not only turns off his phone but also removes the battery, for fear his microphone could be turned on remotely. He connects to the Internet only through an encrypted, password-protected channel, and copies and pastes his password from a USB thumb drive. He never types in a password directly, because, he said, “the Chinese are very good at installing key-logging software on your laptop.”

What might have once sounded like the behavior of a paranoid is now standard operating procedure for officials at American government agencies, research groups and companies that do business in China and Russia — like Google, the State Department and the Internet security giant McAfee. Digital espionage in these countries, security experts say, is a real and growing threat — whether in pursuit of confidential government information or corporate trade secrets.

“If a company has significant intellectual property that the Chinese and Russians are interested in, and you go over there with mobile devices, your devices will get penetrated,” said Joel F. Brenner, formerly the top counterintelligence official in the office of the director of national intelligence. Theft of trade secrets was long the work of insiders — corporate moles or disgruntled employees. But it has become easier to steal information remotely because of the Internet, the proliferation of smartphones and the inclination of employees to plug their personal devices into workplace networks and cart proprietary information around. Hackers’ preferred modus operandi, security experts say, is to break into employees’ portable devices and leapfrog into employers’ networks — stealing secrets while leaving nary a trace.

Sunday, January 29, 2012

Atlanta Man Sentenced on Computer Hacking Charge

Press release from the FBI, Atlanta Division:


Atlanta Man Sentenced on Computer Hacking Charge
McNeal Illegally Accessed Database of Competitor’s Medical Practice

U.S. Attorney’s Office January 10, 2012
  • Northern District of Georgia (404) 581-6000


ATLANTA—ERIC McNEAL, 38, of Atlanta, Georgia, was sentenced today by United States District Judge Willis B. Hunt, Jr. for intentionally accessing a protected computer of a competing medical practice without authorization, including personal information of the patients, in order to send marketing materials to these patients.

United States Attorney Sally Quillian Yates said, “Anyone who gives their personal information to a doctor or medical facility does not expect that their information will be hacked and used to make money. The cost of medical care is already high enough without patients having to pay a heavier cost with the loss of their privacy. This is cybercrime. Electronic information is bought, sold and stolen, often by someone who knows a system and, with a few keystrokes, makes our community vulnerable.”

McNEAL was sentenced to one year and one month in prison, to be followed by three years of supervised release, and was ordered to perform 120 hours of community service. McNEAL pleaded guilty to the charge on September 28, 2011.

According to United States Attorney Yates, the charge,s and other information presented in court: McNEAL worked as an information technology specialist for “A.P.A.,” a perinatal medical practice in Atlanta.

McNEAL separated from employment with A.P.A. in November 2009, and subsequently joined a competing perinatal medical practice, which was located in the same building as A.P.A. In April 2010, MCNEAL used his home computer to hack into A.P.A.’s patient database without authorization. MCNEAL downloaded the names, telephone numbers, and addresses of A.P.A.’s patients, and then “wiped” A.P.A.’s database, deleting all the patient information from A.P.A.’s system. McNEAL subsequently used the patient names and contact information to launch a direct-mail marketing campaign for the benefit of his new employer. There is no evidence that McNEAL downloaded or misused specific patient medical information.

This case was investigated by special agents of the Federal Bureau of Investigation.