Search This Blog

Showing posts with label theft. Show all posts
Showing posts with label theft. Show all posts

Tuesday, March 27, 2012

Microsoft Joins Financial Services Industry to Disrupt Massive Zeus Cybercrime Operation That Fuels Worldwide Fraud and Identity Theft

News Press Release
Microsoft Joins Financial Services Industry to Disrupt Massive Zeus Cybercrime Operation That Fuels Worldwide Fraud and Identity Theft
Microsoft collaborates with financial services industry in unprecedented cross-industry action against notorious cybercrime operation behind online fraud and identity theft.
REDMOND, Wash. — March 25, 2012 — In its most complex effort to disrupt botnets to date, Microsoft Corp., in collaboration with the financial services industry — including the Financial Services – Information Sharing and Analysis Center (FS-ISAC) and NACHA – The Electronic Payments Association — as well as Kyrus Tech Inc., announced it has successfully executed a coordinated global action against some of the most notorious cybercrime operations that fuel online fraud and identity theft. With this legal and technical action, a number of the most harmful botnets using the Zeus family of malware worldwide have been disrupted in an unprecedented, proactive cross-industry action against this cybercriminal organization.
Through an extensive and collaborative investigation into the Zeus threat, Microsoft and its banking, finance and technical partners discovered that once a computer is infected with Zeus, the malware can monitor a victim’s online activity and automatically start keylogging, or recording a person’s every keystroke, when a person types in the name of a financial institution or ecommerce site. With this information, cybercriminals can steal personal information that can be used for identity theft or to fraudulently make purchases or access other private accounts. In fact, since 2007, Microsoft has detected more than 13 million suspected infections of the Zeus malware worldwide, including approximately 3 million computers in the United States alone.
“With this action, we’ve disrupted a critical source of money-making for digital fraudsters and cyberthieves, while gaining important information to help identify those responsible and better protect victims,” said Richard Boscovich, senior attorney for the Microsoft Digital Crimes Unit. “The Microsoft Digital Crimes Unit has long been working to combat cybercrime operations, and today is a particularly important strike against cybercrime that we expect will be felt across the criminal underground for a long time to come.”
This disruption was made possible through a successful pleading before the U.S. District Court for the Eastern District of New York, which allowed Microsoft and its partners to conduct a coordinated seizure of command and control servers running some of the worst known Zeus botnets. Because the botnet operators used Zeus to steal victims’ online banking credentials and transfer stolen funds, FS-ISAC and NACHA joined Microsoft as plaintiffs in the civil suit, and Kyrus Tech Inc. served as a declarant in the case. Other organizations, including F-Secure, also provided supporting information for the case.
As a part of the operation, on March 23, Microsoft and its co-plaintiffs, escorted by the U.S. Marshals, seized command and control servers in two hosting locations, Scranton, Pa., and Lombard, Ill., to seize and preserve valuable data and virtual evidence from the botnets for the case. Microsoft and its partners took down two Internet Protocol addresses behind the Zeus command and control structure, and Microsoft is currently monitoring 800 domains secured in the operation, which are helping identify thousands of computers infected by Zeus.
This is the second time Microsoft has conducted physical seizures in a botnet operation, and it is the first time other organizations have joined Microsoft as plaintiffs in the legal case for a botnet operation. This is also the first operation for Microsoft that involved the simultaneous disruption of multiple operating botnets in a single action and is the first known time the Racketeer Influenced and Corrupt Organizations (RICO) Act has been applied as the legal basis in a consolidated civil case to charge all those responsible in the use of a botnet.
“As crimes against banks and their customers move from stickups to mouse clicks, we’re also using our own mouse clicks — as well as the law — to help protect consumers and businesses,” said Greg Garcia, a spokesperson for the three major financial industry associations that worked with Microsoft on this initiative. “Disrupting the Zeus botnets is just one strike in our long-term commitment to help defend and protect people.”
Because of the complexities of these targets, unlike Microsoft’s previous botnet operations, the goal of this action was not to permanently shut down all impacted Zeus botnets. However, this action is expected to significantly impact the cybercriminals’ operations and infrastructure, advance global efforts to help victims regain control of their infected computers, and also help further investigations against those responsible for the threat. As with its previous botnet operations, Microsoft will now use the intelligence gained from this operation to partner with Internet service providers and Community Emergency Response Teams around the world to help rescue people’s computers from the control of Zeus, helping to reduce the size of the threat that these botnets pose and to help make the Internet safer for consumers and businesses worldwide. Together, these aspects of the operation are expected to undermine the criminal infrastructure that relies on these botnets every day to make money and to help provide new tools for the industry to work together to proactively fight cybercrime.
Michael Tanji, chief security officer of Kyrus Tech Inc., who helped analyze the Zeus malware and determine which botnets were the most dangerous said, “We are proud to have played a part in this groundbreaking effort and hope that others will start working together to combat malicious activity at the same scale as it is being perpetrated.”
There are steps consumers and businesses can take to better help protect themselves from becoming victims of malware, fraud and identity theft. All computer users should exercise safe practices, such as running up-to-date and legitimate computer software, firewall protection, and antivirus or antimalware protection. People should also exercise caution when surfing the Web and clicking on ads or email attachments that may prove to be malicious. For computer owners worried their computers might be infected, Microsoft offers free information and malware cleaning tools athttp://support.microsoft.com/botnets that can help people remove Zeus and other malware from their computers. For businesses looking for more information about corporate account takeover issues, including those due to malicious software, a fraud advisory from FS-ISAC, the FBI and the U.S. Secret Service can be found at http://www.fsisac.com/files/public/db/p265.pdf.
More information about today’s news and the coordinated action against Zeus is available athttp://www.microsoft.com/presspass/presskits/dcu. Legal documentation in the case can be found athttp://www.zeuslegalnotice.com.
About FS-ISAC
The Financial Services Information Sharing and Analysis Center was formed in 1999 and is a non-profit, private financial sector initiative. It was designed and developed and is owned by financial institutions. Its primary function is to share timely, relevant and actionable information of physical and cyber security threat and incident information to help mitigate the risk associated with these threats. [http://www.fsisac.com/]
About NACHA – The Electronic Payments Association
NACHA manages the development, administration, and governance of the ACH Network, the backbone for the electronic movement of money and data. The ACH Network provides a safe, secure, and reliable network for direct account-to-account consumer, business, and government payments. Annually, it facilitates billions of Direct Deposit via ACH and Direct Payment via ACH transactions. Used by all types of financial institutions, the ACH Network is governed by the fair and equitable NACHA Operating Rules, which guide risk management and create payment certainty for all participants. As a not-for-profit association, NACHA represents more than 10,000 financial institutions via 17 regional payments associations and direct membership. Through its industry councils and forums, NACHA brings together payments system stakeholders to foster dialogue and innovation to strengthen the ACH Network. To learn more, please visit www.nacha.org.
AboutKyrus Tech, Inc.
Kyrus is a security innovation company. We have deep expertise in vulnerability research, reverse engineering, computer forensics and custom software development. We apply those skills to conduct research and develop solutions for the business, critical infrastructure and national security communities. We strive to disrupt the status quo. We believe that approaching security problems from diverse perspectives and without preconceptions is the only way for security to become both a valued and a cost-effective capability.
About Microsoft
Founded in 1975, Microsoft (Nasdaq “MSFT”) is the worldwide leader in software, services and solutions that help people and businesses realize their full potential.

Saturday, March 24, 2012

Armenian Power Member and Three Armenian Power Associates Convicted in Los Angeles for Roles in Identity Theft Ring

Armenian Power Member and Three Armenian Power Associates Convicted in Los Angeles for Roles in Identity Theft Ring 

U.S. Department of JusticeMarch 22, 2012
  • Office of Public Affairs(202) 514-2007/TDD (202) 514-1888
WASHINGTON—After a five week trial, four defendants have been convicted for their roles in one of the largest bank fraud and identity theft schemes in California history, with dozens of victims in four states and millions of dollars in losses.
The convictions were announced by Assistant Attorney General Lanny A. Breuer of the Justice Department’s Criminal Division; U.S. Attorney Andre Birotte, Jr. of the Central District of California; Assistant Director in Charge of the FBI’s Los Angeles Field Office Steven Martinez; and Special Agent in Charge of the U.S. Secret Service (USSS) Joseph Beaty.
Arman Sharopetrosian, Karen Markosian, Artush Margaryan, and Kristine Ogandzhanyan were found guilty of conspiring to commit bank fraud, attempted bank fraud, and various counts of aggravated identity theft. Sharopetrosian, Markosian, and Ogandzhanyan waived a jury trial and consented to trial by the judge, and Margaryan proceeded with a jury trial.
Yesterday, U.S. District Judge David O. Carter found Ogandzhanyan, 28, of Burbank, California, guilty of one count of bank fraud conspiracy, two counts of attempted bank fraud, and four counts of aggravated identity theft. On March 16, 2012, the judge found Sharopetrosian, 33, of Burbank, guilty of one count of bank fraud conspiracy, four counts of bank fraud, and seven counts of aggravated identify theft. On March 16, 2012, the judge also found Markosian, 39, of Glendale, California, guilty of one count of bank fraud conspiracy, one count of attempted bank fraud, and two counts of aggravated identity theft. A jury convicted the fourth defendant, Artush Margaryan, 28, of Van Nuys, California, on March 16, 2012 of one count of bank fraud conspiracy, one count of attempted bank fraud, and three counts of aggravated identity theft.
Evidence was presented at trial that Sharopetrosian is a member of the Armenian Power organized crime group, and Margaryan, Markosian, and Ogandzhanyan are Armenian Power associates.
According to evidence presented at trial, Sharopetrosian directed the massive fraud scheme along with co-defendant Angus Brown while the two were incarcerated at Avenal State Prison. Using cellular telephones that were smuggled into the prison, Sharopetrosian and Brown worked from behind bars to coordinate with others, including Ogandzhanyn, Markosian, and Margaryan, to obtain confidential bank profile information and steal money from victim account holders. Often targeting high-value bank accounts, the defendants used account holders’ personal identifying information—including names, Social Security numbers, and dates of birth—to impersonate victims in phone calls to the bank. The defendants gathered account information, transferred funds between victims’ accounts, and placed unauthorized check orders for the accounts. They then stole the checks, obtained the victims’ signatures from public documents, and paid conspirators to cash the forged checks. Over the course of the six-year conspiracy, the defendants and their co-conspirators caused more than $10 million dollars in losses to victims in Southern California, Nevada, Arizona, and Texas.
“These defendants, including two individuals who were operating from a prison cell, perpetrated a massive fraudulent scheme on behalf of a dangerous criminal enterprise,” said Assistant Attorney General Breuer. “As members and associates of Armenian Power, they stole sensitive personal and financial information from innocent consumers and caused millions of dollars in losses. Whether organized criminal groups traffic in drugs, commit financial fraud or wreak other havoc to keep themselves going, they must be stopped. We are doing everything possible to shut down dangerous gangs like Armenian Power.”
“The safety and sanctity of confidential financial information is paramount in today’s society,” said U.S. Attorney Birotte. “Identity theft is a fundamental invasion of consumer privacy that cannot be tolerated. These convictions demonstrate that violators, whoever and wherever they may be, will be caught and will be prosecuted to the fullest extent of the federal law.”
“The defendants were convicted in a trial that uncovered a sophisticated and lengthy scheme that targeted victims in multiple states and included disturbing details, such as orders made from within prison walls and assistance from bank insiders enlisted by the defendants,” said FBI Assistant Director Martinez. “This case is also indicative of the growing trend of gang or organized crime-affiliated groups now engaging in identity theft and other financial crimes in furtherance of their enterprise.”
These defendants are four of 20 defendants who were charged with operating the bank fraud and identity theft scheme in one of a series of federal indictments unsealed on February 16, 2011. The indictments allege various federal crimes against members and associates of the Armenian Power criminal organization. To date, 19 of the 20 defendants charged in the bank fraud indictment have been convicted, including Brown. One defendant, Faye Bell, was arrested earlier this year and is still awaiting trial.
Sharopetrosian, Margaryan, Markosian, and Ogandzhanyan face maximum sentences of 30 years in federal prison for each count of bank fraud, 30 years for each count of conspiracy to commit bank fraud, and additional mandatory two year sentences for each count of aggravated identity theft.
Sentencing for all four defendants is scheduled for August 6, 2012 before Judge Carter.
The case is being prosecuted by Assistant U.S. Attorneys Martin Estrada and Joseph McNally of the Central District of California and Trial Attorney Cristina Moreno of the Organized Crime and Gang Section in the Justice Department’s Criminal Division. The case was investigated by the Eurasian Organized Crime Task Force, which includes the FBI, the USSS, the Los Angeles Police Department, the Glendale Police Department, the Burbank Police Department, the Internal Revenue Service, and the U.S. Immigration and Customs Enforcement.

Friday, March 23, 2012

Checkpoint Systems wins prestigious industry award with Nano Gate™

Monday, March 19, 2012

Checkpoint Systems wins prestigious industry award with Nano Gate™

Handel Award Nano Gate 2012
Checkpoint Systems, a global leader in high-theft solutions has been honoured with a prestigious industry award by readers of the German publication, Handelsjournal.
Checkpoint scooped the “Best Retail Product” award in the economic efficiency category for its Alpha Nano Gate antenna, a small gate that offers big protection against theft. The award celebrates the industry’s most inventive products and services designed to help retailers increase sales, improve profitability and enhance operations.
Nano Gate is an innovative, small security antenna, which can be easily installed in retail stores, in “unprotected zones” where thieves tend to hide or attempt to remove security devices. Nano Gate works together with Checkpoint’s Alpha® 3 Alarm™ technology products, extending their reach and enhancing their value, while serving as a comprehensive security solution.
Wolfgang Meltzner, store manager of A.T.U in Cologne-Mülheim, who has used Nano Gate in his outlets, commented: “When high-priced motor oils and tools began to disappear from our shelves, we decided to do something about it. We began using Nano Gate in our stores together with matching Alpha components. From the first day, we not only noticed the deterrent aspect, we also saw a decrease in shoplifting, which is what we hoped for.”
Commenting on the award win, Kai Beilenhoff, Vice President for Alpha Europe at Checkpoint Systems, added: “Nano Gate offers an innovative and easy-to-implement solution for securing high-theft products. It has already paid dividends for many retailers around the globe and we’re delighted to have won this award. Our nomination reaffirms that Checkpoint is meeting the retail industry’s requirements for robust anti-theft solutions.”
Available since early 2011, Nano Gate has an aesthically pleasing design and is simple to install. Nano Gate triggers Alpha’s 3 Alarm technology, preventing thieves from taking retailers’ high-risk merchandise into restrooms, emergency exits, elevators, fitting rooms, or similar unprotected areas within their stores. Merchandise protected with 3 Alarm technology alerts retail staff when products are being tampered with in-store. It activates an Electronic Article Surveillance (EAS) alarm when unpaid merchandise leaves a store and starts a continuous alarming for five minutes when stolen merchandise has left the store. Most thieves end up dropping the stolen merchandise and running away.
Nano Gate is particularly suitable for small retailers who do not have a traditional EAS system installed but still want to protect their high-theft items. It enables store operators to maintain an attractive, consumer-oriented shopping environment while ensuring that merchandise is kept secure. For large retail stores using EAS, Nano Gate provides additional security to prevent goods from being readily moved from proposed sale areas into other sections of the store.

Thursday, March 22, 2012

Real Cost of a Cyber Attack

A new surbey reveals malicious hacking of government and corporate data accounted for more than half of all data thefts last year.  A CNBC interview provides insight on the cost of security threats, with Janet Napolitano, Department of Homeland Security secretary.


http://video.cnbc.com/gallery/?video=3000080031

Friday, March 9, 2012

News Release from Symantec - GALAXY

Norton Mobile Security Protects Samsung GALAXY Smartphone Users Worldwide


Share on Facebook Tweet
MOUNTAIN VIEW, Calif. – March 6, 2012 – Norton by Symantec (Nasdaq: SYMC) today announced that Samsung Electronics will provide Norton Mobile Security, an application for Android OS, to select smartphone users worldwide. Samsung will offer a full-featured, complimentary 90-day subscription of Norton Mobile Security in multiple languages to Samsung GALAXY users through Samsung Apps.

“We are pleased to extend our valued relationship with Samsung by helping to protect more of its customers’ devices and data from theft, loss and mobile threats,” said Janice Chaffin, group president, Consumer Business Unit, Symantec. “With smartphone sales now outpacing PC sales, cybercriminals are devising new threats everyday to steal from mobile users. Consumers need to be protected more than ever.”

Norton Mobile Security combines anti-theft features with powerful antimalware to protect user’s important data from loss, theft, viruses and other threats through the following features:
  • Remote Locate — Shows you the location of your smartphone so you can find if it’s lost or stolen.
  • Remote Lock — Lets you remotely lock your lost or stolen phone via the Internet or SMS to keep critical data safe and block unauthorized access.
  • Remote Wipe — Lets you remotely erase the data on your phone via SMS, blocking access to your private information. In addition, your phone is instantly locked if its SIM card is removed or replaced, so it can’t be used with another SIM card.
  • Anti-malware — Scans all files and application updates downloaded to your mobile phone and automatically detects and removes threats without slowing you down.
  • SD Card Scanning — Gives you the option of automatically scanning SD (Secure Digital) memory cards for threats when you plug them into mobile phone.
  • Automatic LiveUpdate — Automatically downloads and installs security updates keeping you a step ahead of cybercriminals.
Norton Mobile Security can be downloaded from the ‘Utility’ category in Samsung Apps or by entering ‘Norton Mobile Security’ into the search query at the Samsung Apps. Norton Mobile Security supports all Samsung Galaxy Android smartphones, including Galaxy S2 LTE, Galaxy S2, Galaxy Neo, Galaxy S Hoppin and Galaxy A. It is available in nine languages, including Korean, English, French, German, Italian, Japanese, Simplified Chinese, Spanish, and Traditional Chinese languages. A one-year license costs $29.99USD.

Tuesday, March 6, 2012

Employee Theft

Former Cessna Employee Sentenced to 18 Months for Stealing Parts from Airplanes

U.S. Attorney’s Office March 05, 2012
  • District of Kansas (316) 269-6481

WICHITA, KS—A former Cessna employee has been sentenced to 18 months in federal prison for selling stolen aircraft parts on eBay, U.S. Attorney Barry Grissom said today. He also was ordered to pay $130,000 restitution.

Diego Alejandro Paz-Teran, 35, Wichita, Kansas, pleaded guilty to one count of interstate transportation of stolen property. In his plea, Paz-Teran admitted he stole aircraft parts from Cessna and sold them on eBay. According to court documents, the investigation began in November 2008 when an employee of a Rockwell Collins Company distributor saw a Collins AHC-3000 Attitude Reference Computer offered for sale on eBay for $9,000. Knowing that the part was valued at more than $45,000, he contacted the seller and asked for serial numbers. Cessna tracked the serial numbers to a part that was removed from an XLS Plus aircraft while it was being painted.

Investigators found other stolen aircraft parts being sold on the same eBay account and followed records on the account to Teran at his home in Wichita.

Grissom commended the U.S. Department of Transportation-Office of Inspector General, the Sedgwick County Sheriff’s Office, the Federal Bureau of Investigation, and Assistant U.S. Attorney Matt Treaster for their work on the case.

Thursday, February 16, 2012

Texas Man Convicted of Medicare Fraud in Kansas

News release from the FBI, Kansas City Division:


Texas Man Convicted of Medicare Fraud in Kansas

U.S. Attorney’s Office February 16, 2012
  • District of Kansas (316) 269-6481
— filed under: ,

KANSAS CITY, KS—A Texas man has been convicted of fraudulently billing Medicare for power wheelchairs and other medical devices, U.S. Attorney Barry Grissom said today.

A jury convicted Edmund Nwaudobi, 48, Sugar Land, Texas, on one count of conspiracy to defraud Medicare, two counts of health care fraud, and one count of aggravated identity theft.

“Health care fraud is a widespread problem,” said U.S. Attorney Barry Grissom. “We are working hard to protect the American people and safeguard precious taxpayer dollars.”

During trial, federal prosecutors presented evidence that from 2004 to 2009 Nwaudobi conspired with co-defendants Tom Alabraba, Iyaye Ishmael, and George Tasie to fraudulently bill Medicare for power wheelchairs and other medical devices, such as leg and body braces. In some instances, Medicaid was billed for devices that were not medically necessary, including leg braces for an individual who had previously had his legs amputated, and who never received the braces. In other instances, Medicare was billed for medical devices that Medicare recipients never received.

Nwaudobi conducted business on behalf of Good Care, Inc., an Overland Park, Kan., company that supplied durable medical equipment such as orthotics. Nwaudobi shared patient information with Tom Alabraba, who owned or operated Tal-Med, Inc., a Kansas City, Kan., company that supplied durable medical devices; George Tasie, who owned or operated Central Medical, Inc., a Kansas City, Kan., company that supplied durable medical devices; and Iyaye Ishmael, who was a manager of Central Medical, Inc.

The companies billed more than $2.9 million in Medicare claims for 397 beneficiaries living in Missouri and Kansas, and received more than $1.5 million from those claims.

Prosecutors presented evidence at trial that Nwaudobi:
  • Submitted false statements to Medicare that physicians had prescribed durable medical devices;
  • Provided durable medical devices to Medicare recipients that were different than stated in bills to Medicare;
  • Did not require Medicare recipients to make co-payments required by Medicare; and
  • Used doctors’ identities without permission to make fraudulent claims to Medicare.
Brian Truchon, FBI Special Agent in Charge, said: “The FBI is fully committed to investigating health care fraud and working with our law enforcement partners to stop individuals or groups that commit fraud against government sponsored programs such as Medicare and Medicaid as well as fraud against private insurance companies. This verdict puts those individuals on notice that these crimes will be fully investigated and brought to successful prosecution.”

Tom Alabraba and Iyaye Ishmael are fugitives. George Tasie, who pleaded guilty to one count each of conspiracy and health care fraud, failed to appear for sentencing.

Sentencing is set for April 30. Nwaudobi faces a maximum penalty of 20 years in federal prison and a fine up to $250,000 on the conspiracy count, a maximum penalty of 20 years and a fine up to $250,000 on each of the health care fraud counts, and a mandatory two years consecutive to any other sentence and a fine up to $250,000 on the identity theft count.

Grissom commended the Federal Bureau of Investigation, HHS-OIG and Assistant U.S. Attorneys Chris Oakley and Jabari Wamble for their work on the case.

In all cases, defendants who have been indicted are presumed innocent until and unless proven guilty. The indictments merely contain allegations of criminal conduct.

Wednesday, February 15, 2012

Chinese Official to Hear Trade Theft Tale

Excerpt from an article in The New York Times
Wednesday, February 15, 2012

Chinese Official to Hear Trade Theft Tale 

By JONATHAN WEISMAN

WASHINGTON — China’s next leader, Xi Jinping, may never have heard of American Superconductor Corporation before he arrived here Monday, but by the end of his visit United States officials hope to make the small Massachusetts wind-energy company an object lesson in the impact of Chinese trade secret theft on American business.

Senator John Kerry, chairman of the Senate Foreign Relations Committee and a Massachusetts Democrat, plans to raise personally with Mr. Xi the case of a company that saw 70 percent of its business evaporate last year after a Chinese partner enticed one of its employees to steal the crown jewel of its technology.

“It’s a very clear and, in our judgment, egregious, palpable demonstration of the practice that we are deeply concerned about,” Mr. Kerry said, “but it’s not the only one. There are so many things: cyberattacks, access-to-market issues, espionage, theft. These are major points of discussion between us and China.”

Both President Obama and Vice President Joseph R. Biden Jr. warned Mr. Xi on Tuesday that they had been hearing more and more from United States businesses about intellectual property and trade secret theft, but they did not specifically mention American Superconductor. However, background material on the company’s experience was included in briefing papers distributed before the arrival in Washington of Mr. Xi’s delegation, and a top administration official said the Chinese were aware of United States frustration over the case.

Saturday, February 11, 2012

Electronic Security & Digital Espionage


Excerpt from an article in The New York Times
Saturday, February 11, 2012

Electronic Security a Worry in an Age of Digital Espionage 

By NICOLE PERLROTH

SAN FRANCISCO — When Kenneth G. Lieberthal, a China expert at the Brookings Institution, travels to that country, he follows a routine that seems straight from a spy film.

He leaves his cellphone and laptop at home and instead brings “loaner” devices, which he erases before he leaves the United States and wipes clean the minute he returns. In China, he disables Bluetooth and Wi-Fi, never lets his phone out of his sight and, in meetings, not only turns off his phone but also removes the battery, for fear his microphone could be turned on remotely. He connects to the Internet only through an encrypted, password-protected channel, and copies and pastes his password from a USB thumb drive. He never types in a password directly, because, he said, “the Chinese are very good at installing key-logging software on your laptop.”

What might have once sounded like the behavior of a paranoid is now standard operating procedure for officials at American government agencies, research groups and companies that do business in China and Russia — like Google, the State Department and the Internet security giant McAfee. Digital espionage in these countries, security experts say, is a real and growing threat — whether in pursuit of confidential government information or corporate trade secrets.

“If a company has significant intellectual property that the Chinese and Russians are interested in, and you go over there with mobile devices, your devices will get penetrated,” said Joel F. Brenner, formerly the top counterintelligence official in the office of the director of national intelligence. Theft of trade secrets was long the work of insiders — corporate moles or disgruntled employees. But it has become easier to steal information remotely because of the Internet, the proliferation of smartphones and the inclination of employees to plug their personal devices into workplace networks and cart proprietary information around. Hackers’ preferred modus operandi, security experts say, is to break into employees’ portable devices and leapfrog into employers’ networks — stealing secrets while leaving nary a trace.

Tuesday, February 7, 2012

Man Sentenced for Medicare Fraud Scheme

News release from the FBI:


Los Angeles Man Sentenced to 77 Months in Prison for Medicare Fraud Scheme Resulting in More Than $18.9 Million in Fraudulent Claims to Medicare

U.S. Department of Justice February 07, 2012
  • Public Affairs Specialist Laura Eimiller (310) 996-3343

WASHINGTON—A Los Angeles-area man was sentenced yesterday to 77 months in prison for organizing and leading a medical clinic fraud scheme that used the stolen identities of physicians to submit more than $18.9 million in fraudulent claims to Medicare, the Department of Justice, the FBI and the Department of Health and Human Services (HHS) announced.

Eduard Aslanyan, 38, of Sherman Oaks, Calif., was sentenced by U.S. District Judge Consuelo B. Marshall in the Central District of California. In addition to his prison term, Aslanyan was sentenced to three years of supervised release and was ordered to pay $10.8 million in restitution.

Aslanyan pleaded guilty in April 2011. He admitted that between March 2007 and September 2008, he established a series of fraudulent medical clinics in and around Los Angeles to defraud Medicare. Carolyn Vasquez, who previously pleaded guilty to conspiring with Aslanyan to defraud Medicare, recruited physicians to serve as the medical directors of Aslanyan’s fraudulent medical clinics. The physicians did not perform services at the clinics and were rarely present at the clinics. Physician assistants were hired by Aslanyan and Vasquez and were complicit in the fraud scheme at the clinics.

According to court documents, Aslanyan hired patient recruiters to find Medicare beneficiaries who were willing to provide the recruiters with their Medicare billing information in exchange for expensive, high-end power wheelchairs and other medical equipment which the patient recruiters told the beneficiaries they could receive for free. Often, the Medicare beneficiaries did not have a legitimate medical need for the power wheelchairs and equipment. The patient recruiters then provided the beneficiaries’ Medicare billing information to Aslanyan or brought the beneficiaries to Aslanyan’s clinics. Aslanyan paid the patient recruiters cash kickbacks in exchange for recruiting the Medicare beneficiaries.

In court documents, Aslanyan admitted that he and Vasquez instructed and paid physician assistants who worked at his clinics to prescribe medically unnecessary power wheelchairs, medical equipment and diagnostic tests for the Medicare beneficiaries. The physician assistants used stolen identities of physicians who did not supervise them or work at the clinics.

According to court documents, Aslanyan profited from the scheme at his fraudulent medical clinics in several ways. Aslanyan admitted that he allowed fraudulent diagnostic testing facilities to use the Medicare billing information he purchased from patient recruiters to submit false claims to Medicare for tests ordered at the clinics. In exchange, the fraudulent diagnostic testing facilities paid Aslanyan cash kickbacks that were disguised as rent payments to Aslanyan.

Aslanyan also profited from the scheme by selling fraudulent prescriptions and documents generated at his clinics to the owners and operators of fraudulent durable medical equipment (DME) supply companies, which used the prescriptions and documents to submit false claims to Medicare. Aslanyan also used the fraudulent prescriptions and documents to submit false claims to Medicare through his own fraudulent DME supply companies, Vila Medical Supply Inc. and Blanc Medical Supplies.

According to court documents, as a result of Aslanyan’s conduct, he and his co-conspirators submitted approximately $18.9 million in fraudulent claims to Medicare.

Currently, Aslanyan is serving a three-year state sentence for assault. On Jan. 9, 2012, Judge Marshall sentenced Vasquez to 60 months in prison for her role in the fraud scheme and ordered her to pay more than $6.2 million in restitution to Medicare. A second co-defendant, David James Garrison, a physician assistant who worked at the fraudulent medical clinics with Vasquez and Aslanyan, is scheduled for trial on Feb. 7, 2012. Defendants are presumed innocent until proven guilty at trial.

The sentence was announced by Assistant Attorney General Lanny A. Breuer of the Justice Department’s Criminal Division; U.S. Attorney André Birotte Jr. for the Central District of California; Glenn R. Ferry, Special Agent in Charge for the Los Angeles Region of the HHS Office of Inspector General (HHS-OIG); Steven Martinez, Assistant Director in Charge of the FBI’s Los Angeles Field Office; and Tony Sidley, Assistant Chief of the California Department of Justice, Bureau of Medi-Cal Fraud and Elder Abuse.
The case is being prosecuted by Trial Attorney Jonathan T. Baum of the Criminal Division’s Fraud Section. Former Special Trial Attorney Joseph Hudzik participated in the prosecution. The case is being investigated by the FBI. The case was brought as part of the Medicare Fraud Strike Force, supervised by the Criminal Division’s Fraud Section and the U.S. Attorney’s Office for the Central District of California.

Since their inception in March 2007, strike force operations in nine districts have charged more than 1,160 defendants who collectively have falsely billed the Medicare program for more than $2.9 billion. In addition, the HHS Centers for Medicare and Medicaid Services, working in conjunction with the HHS-OIG, are taking steps to increase accountability and decrease the presence of fraudulent providers.

To learn more about the Health Care Fraud Prevention & Enforcement Action Team, go to: www.stopmedicarefraud.gov.

Monday, February 6, 2012

Defendant Sentenced for Stealing from 136 Housing Clients

Press release from the FBI, Buffalo Division:


Defendant Sentenced for Stealing from 136 Housing Clients

U.S. Attorney’s Office February 02, 2012
  • Western District of New York (716) 843-5700

BUFFALO, NY—U.S. Attorney William J. Hochul, Jr. announced today that Lori J. Macakanja, 35, of Dunkirk, New York, who was convicted of mail fraud and theft of government money, was sentenced to 72 months in prison and three years’ supervised release by U.S. District Court Judge Richard J. Arcara. Judge Arcara also ordered the defendant to pay $298,639.00 in restitution to the victims.

Assistant U.S. Attorney Trini E. Ross, who handled the case, stated that Macakanja, in her capacity as a housing counselor employed by HomeFront, Inc., inappropriately requested money from clients. The defendant told HomeFront clients that the money would be used toward loan modifications to prevent foreclosure on their homes. However, after receiving the funds, Macakanja used the money for her own personal use, including gambling, and failed to obtain the loan modifications for the victims. A total of 136 HomeFront clients were defrauded with losses totaling approximately $300,000. In addition, Macakanja also obtained federal grant monies from the Buffalo Urban Renewal Agency (BURA) for HomeFront clients. On two occasions, she diverted $2,000 worth of BURA money to pay her own personal mortgage.

“Many Americans are struggling to hold on to the American dream, ownership of a home,” said U.S. Attorney Hochul. “The victims turned to the defendant for help in keeping their home. Instead, the defendant abused their trust and stole their money. Unfortunately, because of the defendant’s actions, some of the victims lost their homes. Our office, along with our federal law enforcement partners, will work vigorously to protect federal funding targeted to help those who are struggling. We will also continue to prosecute those, like this defendant, who attempt to take advantage of those who are most vulnerable.”

“Lori Macakanja abused her position and violated the trust of distressed homeowners in the interest of personal gain,” said Cortez Richardson, Special Agent in Charge, U.S. Department of Housing and Urban Development, Office of Inspector General New York Region. “Her actions further jeopardized the assets of the Federal Housing Administration and unnecessarily complicated the lives and financial security of individuals already feeling the adverse impact of a volatile housing crisis. Today’s judicial action signals HUD’s Office of Inspector General’s firm commitment to working with our law enforcement partners to investigate and prosecute any individuals seeking to profit illegally from the nation’s mortgage crisis.”

“Macakanja preyed on the most vulnerable homeowners,” said Christy Romero, Deputy Special Inspector General for SIGTARP. “While an employee of a federally approved housing counselor, she illegally solicited and received payments from 136 homeowners facing foreclosure with the promise that the funds would be used to secure mortgage modifications. Little did the homeowners know, the payments were being used by Macakanja to support her gambling habit and to pay her own mortgage. SIGTARP will aggressively investigate and pursue those who exploit the federal government’s aid to homeowners under TARP and, with the help of its partners in law enforcement, ensure that they are brought to justice.”

SIGTARP investigates fraud, waste, and abuse related to HAMP and all other TARP-funded programs. HAMP encourages loan servicers and investors to modify mortgages to reduce the monthly payments of homeowners who are risk of default. There is no fee to homeowners to apply for a modification under HAMP.

The plea is the result of an investigation by the Mortgage Fraud Task Force of WNY, which includes agents and personnel from the U.S. Postal Inspection Service under the direction of Inspector in Charge Robert Bethel; the Housing and Urban Development Office of Inspector General, under the direction of Cortez Richardson, Special Agent in Charge, New York Region; SIGTARP, under the direction of Special Agent in Charge John Feiter; the United States Secret Service under the direction of Special Agent in Charge Tracy Gast; the Federal Bureau of Investigation under the direction of Special Agent in Charge Christopher M. Piehota; and the Internal Revenue Service under the direction of Special Agent in Charge Charles R. Pine. The Mortgage Fraud Task Force of WNY is led by the U.S. Attorney’s Office and also includes Veterans Affairs Office of Inspector General and the U.S. Bankruptcy Trustee.

Thursday, February 2, 2012

Malware Creation Hit Record High in 2011


News release from Panda Security:

January 31, 2012


Malware Creation hit a New Record High in 2011 with 26 million samples

  • Trojans continue to be the most pervasive malware threat
  • China, Thailand and Taiwan are the world’s most infected countries
  • Data theft, social media and cyber-war take the spotlight
  • The full report is available at http://press.pandasecurity.com/press-room/reports/
PandaLabs, the antimalware laboratory of Panda Security, has released its 2011 Annual Security Report, which details an extremely interesting year of data theft, social networking attacks and cyber-warfare. According to the report, malware creation hit a new record high in 2011 with 26 million new strains in circulation, nearly one-third of all malware that has ever existed and been classified by the company (88 million).
These figures show cyber-criminals’ sheer capacity to automate the creation of new malware variants, further evidenced by the average number of new threats created and released every day increasing from 63,000 to 73,000 since last year. Panda Security leverages Collective Intelligence, a cloud-based proprietary system that automatically detects, analyzes and classifies 99.4 percent of all malware received, leaving just 0.6 percent to be dealt with manually. In November 2011, PandaLabs announced that Collective Intelligence had reached a historic milestone by processing 200 million files, and this number has already reached 210 million.
Malware
In 2011, Trojans dominated the threat landscape more than ever before. Whereas in 2009 Trojans made up 60 percent of all malware, the percentage dropped to 56 percent in 2010. Last year, however, the percentage jumped up to 73 percent, so that three out of every four new malware strains created were Trojans, followed by viruses (14.24 percent) and worms (8.13 percent).
The countries leading the list of most infections are once again Thailand, China and Taiwan, with 60, 56 and 52 percent of infected computers respectively. These are actually the only countries that exceed the worldwide average of 38.49 percent.
2011: The year of cyber-attacks, social media and cyber-war
The report offers a general view of the most important events regarding computer security in 2011. Sony suffered a massive breach that led to the theft of data belonging to 100 million user accounts in what is probably the largest-ever Internet security break-in, whereas the Steam video game service, used by 35 million people, was also compromised by hackers.
Social networking sites, mainly Facebook and Twitter, play a vital role in the life of Internet users and are extensively covered in the report. 2011 witnessed the launch of a new social media service in a bid to rival Facebook: Google+. Despite its rapid growth, with more than 25 million users registered in just few weeks, Google+ is still far away from its direct competitor, Facebook, which makes it less of a target for cyber-crooks.
Cyber-war also grabbed headlines in 2011. The number of cyber-attacks multiplied all over the world, affecting governments and government contractors -like weapons manufacturers- alike.  Besides offering an overview of the most significant events in the computer security field, the 2011 Annual Security Report also forecasts future trends for 2012.
The full report is available at: http://press.pandasecurity.com/press-room/reports/. Visit the PandaLabs blog for more information about these and other threats:  http://pandalabs.pandasecurity.com/