Security analysts have warned users of the Monster.com website of a phishing attack by Turkish hackers.
Almost a year ago hackers stole the details of 1.3 million users from Monster.com. Even more recently a group used an identity harvesting tool to extract information from resumes posted on Monster and other job sites.
Now a security analyst a McAfee, Greg day, has issued a warning of a new phishing attack at Monster.com that targets both recruiters and those looking for jobs, according to Vnunet.
Day said:
"Scammers are trying more and more diverse and sophisticated techniques to obtain information that can be of financial reward.
"With concerns about potential job cutbacks, many people are looking to the internet to find potential employment opportunities and see what's available to provide some reassurance in the current climate.
"Unfortunately, scammers are getting wise to this as we have seen with a recent influx of phishing attacks looking to steal personal details by gaining access to online job hunting profiles or tempting victims with information of potential jobs."
The sam involves e-mails purportedly from Monster.com sent to users, urging them to click on a link to update their profiles. McAfee has traced the attack back to a Turkish botnet, but said that if they’re able to obtain plenty of resumes, the potential for ID theft is large.
Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts
Thursday, July 17, 2008
Wednesday, July 16, 2008
Beware! Your online tax records 'can be hacked' - Sify.com - 15 Jul 2008
If you are thinking of filing your income tax returns online, think twice. It is very easy for anyone to hack into your account and have access to your income tax details.
How can this be done? All a hacker needs to know is your name, permanent account number (PAN) and your date of birth.
He first needs to log onto the e-filing website (https:www.incometaxindiaefiling.gov.in).
A ‘taxing’ exercise indeed! | Double pension tax liability | More India business stories | Get the latest Sensex update
After this, all he needs to do is click on the login link and then click on the 'forgot password' link that appears. Having clicked on the 'forgot password' link, a screen that allows him to change the password appears. There the hacker needs to choose method 1.
In order to change the password, the hacker first needs to know the login. The login in this case is the individual's PAN.
After entering the login data, he needs to enter your name and then finally your date of birth, or date of incorporation in case of a Hindu undivided family (HUF).
This done, he needs to enter the new password twice and click on the reset password button. And, voila, he has hacked your account. It is as simple as that.
After changing the password, he can access the account using the new password and have access to your tax records. This would include information like your gross income for the year, the amount of tax saving investments you made, the amount of tax deducted at source and the tax refund you may get. He would also have access to your phone number and address
Vivek Kaul/ DNA MONEY
How can this be done? All a hacker needs to know is your name, permanent account number (PAN) and your date of birth.
He first needs to log onto the e-filing website (https:www.incometaxindiaefiling.gov.in).
A ‘taxing’ exercise indeed! | Double pension tax liability | More India business stories | Get the latest Sensex update
After this, all he needs to do is click on the login link and then click on the 'forgot password' link that appears. Having clicked on the 'forgot password' link, a screen that allows him to change the password appears. There the hacker needs to choose method 1.
In order to change the password, the hacker first needs to know the login. The login in this case is the individual's PAN.
After entering the login data, he needs to enter your name and then finally your date of birth, or date of incorporation in case of a Hindu undivided family (HUF).
This done, he needs to enter the new password twice and click on the reset password button. And, voila, he has hacked your account. It is as simple as that.
After changing the password, he can access the account using the new password and have access to your tax records. This would include information like your gross income for the year, the amount of tax saving investments you made, the amount of tax deducted at source and the tax refund you may get. He would also have access to your phone number and address
Vivek Kaul/ DNA MONEY
Five Things Kevin Mitnick Knows About Security - PCworld.com - 15 Jul 2008
Reformed hacker-turned-security-consultant Kevin Mitnick served five years in federal prison for breaking into phone and software company networks. He talks about his past hacking exploits, computer security, and how he turned an illegal hobby into a useful career.
Hacking wasn't always illegal. I started off in what they call "phone phreaking" in the late 70s. This is the same hobby Apple founders Steve Jobs and Steve Wozniak had. At this time, 1978, there were no laws against hacking. The first law that criminalized hacking was passed in 1980 in California. I was doing this before it was illegal. And my interest was entertainment -- the pursuit of knowledge, challenge and the trophy of the stolen information. There was no motive for money or malicious intent to use, disclose or destroy the data.
Learn the rules before you play the game. I knew hacking was sneaky when I started, but I didn't think it would get me into trouble. Back in my day, they didn't teach us about ethics in respect to hacking or using computers. Now, I tell kids to not follow in my footsteps. As computers become more accessible, there are more ethical ways to learn about computer security. Plus, there are laws now.
Not everyone takes security seriously. I've been testing a company -- a financial institution -- and they are governed by Sarbanes-Oxley and other regulations. I've done their security assessments for the last four years and each time I get in the same way. It's surprising that these companies do security audits to find their vulnerabilities but don't do much about them. They are required by law to do the audits so you'd think the auditors would require them to fix the issues, but in a lot of cases they don't.
Use your powers for good, not evil. When I was released from custody in 2000, the U.S. government asked for my help. U.S. senators Fred Thompson and Joseph Lieberman invited me to testify before Congress about the government's computer security vulnerabilities. Once the restrictions of my release were up, I went into full-fledged security work, such as training, security assessments and product evaluations. It's a reversal of fortune. Before, I was doing something exciting -- but it was unauthorized and illegal. Now, I do the same thing that got me in trouble, except I do it with authorization. Clients hand me their network and tell me to break in so they can fix security vulnerabilities. To me, it's the same act but it helps my clients and it's legal and ethical, so it's a win-win situation. It's interesting that you can take a criminal activity like hacking and make it into a legitimate enterprise. I can't think of any other illegal activity you can do that with.
Even hackers get hacked. Attackers found a way onto my Web server. However, my website is hosted by a third-party hosting company, so when my site gets hacked it's the hosting service's security shortcomings, not my own. Of course it's embarrassing and I don't like it. Fortunately, I don't have any proprietary information on my public-facing servers. The downside is that people think my company was hacked, but it was really this hosting company's network and not my own site that was breached.
By Jarina D'Auria, CIO.com
Hacking wasn't always illegal. I started off in what they call "phone phreaking" in the late 70s. This is the same hobby Apple founders Steve Jobs and Steve Wozniak had. At this time, 1978, there were no laws against hacking. The first law that criminalized hacking was passed in 1980 in California. I was doing this before it was illegal. And my interest was entertainment -- the pursuit of knowledge, challenge and the trophy of the stolen information. There was no motive for money or malicious intent to use, disclose or destroy the data.
Learn the rules before you play the game. I knew hacking was sneaky when I started, but I didn't think it would get me into trouble. Back in my day, they didn't teach us about ethics in respect to hacking or using computers. Now, I tell kids to not follow in my footsteps. As computers become more accessible, there are more ethical ways to learn about computer security. Plus, there are laws now.
Not everyone takes security seriously. I've been testing a company -- a financial institution -- and they are governed by Sarbanes-Oxley and other regulations. I've done their security assessments for the last four years and each time I get in the same way. It's surprising that these companies do security audits to find their vulnerabilities but don't do much about them. They are required by law to do the audits so you'd think the auditors would require them to fix the issues, but in a lot of cases they don't.
Use your powers for good, not evil. When I was released from custody in 2000, the U.S. government asked for my help. U.S. senators Fred Thompson and Joseph Lieberman invited me to testify before Congress about the government's computer security vulnerabilities. Once the restrictions of my release were up, I went into full-fledged security work, such as training, security assessments and product evaluations. It's a reversal of fortune. Before, I was doing something exciting -- but it was unauthorized and illegal. Now, I do the same thing that got me in trouble, except I do it with authorization. Clients hand me their network and tell me to break in so they can fix security vulnerabilities. To me, it's the same act but it helps my clients and it's legal and ethical, so it's a win-win situation. It's interesting that you can take a criminal activity like hacking and make it into a legitimate enterprise. I can't think of any other illegal activity you can do that with.
Even hackers get hacked. Attackers found a way onto my Web server. However, my website is hosted by a third-party hosting company, so when my site gets hacked it's the hosting service's security shortcomings, not my own. Of course it's embarrassing and I don't like it. Fortunately, I don't have any proprietary information on my public-facing servers. The downside is that people think my company was hacked, but it was really this hosting company's network and not my own site that was breached.
By Jarina D'Auria, CIO.com
Police may offer 18-year-old computer hacker a job - Telegraph.co.uk - 15 Jul 2008
New Zealand police are so impressed by the skills of a teenager at the centre of a global credit card scam worth millions of pounds that they are considering offering him a job fighting cyber-crime.
In a surprising development, Owen Thor Walker, 18, who used the online name 'Akill', was discharged without conviction in the High Court at Hamilton after admitting his role in a sophisticated operation by a worldwide group of criminals calling themselves the 'A-Team'.
Detectives were astonished last November when, at the culmination of a year-long investigation involving the FBI and authorities in the Netherlands, they discovered that the 'mastermind' they were seeking was Walker, who was using a computer in his bedroom in the small rural town of Whitianga.
They described him as a 'botherder', the controller of a 'botnet' in which more than a million computers around the world were infected with a virus that gave him control over them.
Software he designed and sold to the criminal gang allowed members to steal user names and passwords, as well as credit card details.
The FBI estimated the combined economic losses from the 'skimming' activities and damage caused to computer systems by the group at more than $20 million (£10 million).
The crime came to light after one attack caused computers to crash at the University of Pennsylvania in 2006.
In court yesterday, Walker, who has Asperger's syndrome, a mild form of autism, smiled as he heard the prosecution describe how international investigators considered his programming to be 'amongst the most advanced' they had encountered.
Judge Judith Potter described him as a young man with a bright future and ordered him to pay damages and costs of £5,500, but did not record a conviction.
She said that Walker was immature and unable to set proper boundaries for himself in relation to his 'undoubted expertise' in computers.
If he had been convicted, he could have faced five years' imprisonment on each of the charges.
Both the prosecution and defence counsels said in court that police were interested in talking to him about a job 'on the right side of the law'.
Detective Inspector Peter Devoy said that while 'there is no offer on the table, the option is being kept open'.
Maarten Kleintjes, head of the police e-crime laboratory, said the self-taught Walker had a unique ability and was 'at the top of his field'.
Outside the court, Walker, who is also being headhunted by several computer programming companies, said he would be very interested in putting his skills to use for the police.
By Paul Chapman
In a surprising development, Owen Thor Walker, 18, who used the online name 'Akill', was discharged without conviction in the High Court at Hamilton after admitting his role in a sophisticated operation by a worldwide group of criminals calling themselves the 'A-Team'.
Detectives were astonished last November when, at the culmination of a year-long investigation involving the FBI and authorities in the Netherlands, they discovered that the 'mastermind' they were seeking was Walker, who was using a computer in his bedroom in the small rural town of Whitianga.
They described him as a 'botherder', the controller of a 'botnet' in which more than a million computers around the world were infected with a virus that gave him control over them.
Software he designed and sold to the criminal gang allowed members to steal user names and passwords, as well as credit card details.
The FBI estimated the combined economic losses from the 'skimming' activities and damage caused to computer systems by the group at more than $20 million (£10 million).
The crime came to light after one attack caused computers to crash at the University of Pennsylvania in 2006.
In court yesterday, Walker, who has Asperger's syndrome, a mild form of autism, smiled as he heard the prosecution describe how international investigators considered his programming to be 'amongst the most advanced' they had encountered.
Judge Judith Potter described him as a young man with a bright future and ordered him to pay damages and costs of £5,500, but did not record a conviction.
She said that Walker was immature and unable to set proper boundaries for himself in relation to his 'undoubted expertise' in computers.
If he had been convicted, he could have faced five years' imprisonment on each of the charges.
Both the prosecution and defence counsels said in court that police were interested in talking to him about a job 'on the right side of the law'.
Detective Inspector Peter Devoy said that while 'there is no offer on the table, the option is being kept open'.
Maarten Kleintjes, head of the police e-crime laboratory, said the self-taught Walker had a unique ability and was 'at the top of his field'.
Outside the court, Walker, who is also being headhunted by several computer programming companies, said he would be very interested in putting his skills to use for the police.
By Paul Chapman
Saturday, July 12, 2008
Hacked personal e-mail accounts used to scam contacts - echannelline.com - 11 Jul 2008
In Symantec Corp.'s July 2008 edition of its monthly spam report, one of its findings noted that hackers were using personal e-mail accounts to scam contacts in a user's address book.
The twist was that the e-mail came from a user's hacked webmail account and was sent to their personal list of contacts. People on this list would receive an e-mail request for financial assistance and were urged to respond via e-mail only. As the hacker took over the users account, the real owner would not have known about the e-mail if the recipients fell for the scam. As a further stamp of authentication, the auto-signature typically used by the account owner was included at the end of the message. The Symantec report indicated that this scam was a variation of the Nigerian spam.
However, the account owner was quickly notified by a friend via telephone of the scam, and immediately contacted the webmail service providers to get his account access back. This proved to be difficult because the hacker had changed the account details such as password, address and secret question.
According to Kelly Conley, manager of anti-spam research with Symantec Security Response, hackers were able to obtain this information because they replied to an e-mail request for an account update.
"You never want to respond to account expiration or update notifications because there is a good chance those are spammers trying to scam personal account information," she said.
Symantec stressed that this scam was not isolated to one particular webmail provider or organization. This scam also serves as a timely reminder that users should always keep passwords secure and never share them with anyone.
As well, Conley said that if a person were to receive such an e-mail, it should immediately raise a red flag.
"They should be suspicious, especially if it is out of the ordinary for the character of the person," she noted.
Also in the July spam report, Symantec discovered that spammers were simplifying their e-mail harvesting technique. To obtain e-mail addresses spammers used spambots which crawl the Internet looking for e-mail addresses, bombarded an e-mail server with e-mail addresses and storing the addresses that do not bounce, or bought lists of e-mail addresses from other spammers.
They used these addresses to send messages whose recipients were interested in receiving certain offers and encouraging these people to e-mail them back. The list of e-mail addresses that may be compiled would be very useful for the spammer. Not only were these people interested in buying the kind of products that the spammer was offering, but its a bona fide opt-in list, one that the spammer can now send messages to freely without concern that he will be sending to spamtraps, or that the message will be blocked by spam filters.
As well, the report noted spammers were using the recent earthquake tragedy in China to spread viruses by sending e-mails with news headlines, hoping it would entice the reader to open the message.
A video was embedded into the link that was in the e-mail which users were then lured into playing the video, which in turn opened an executable file. This executable file has been detected as Trojan.Peacom.D by Symantec AntiVirus software. Trojan.Peacomm.D is a Trojan horse that gathers system information and e-mail addresses from the compromised computer. Users should be aware of such attempts, and avoid opening e-mails and clicking on suspicious links.
Additionally, spammers turned to old techniques to lure in victims. Symantec noted in June that they were using bogus news headlines in an e-mail subject header to get recipients to open the message and click on a link that directs them to a spam offer.
Some of the headlines include: White House hit by lightening, catches fire; Donald Trump missing, feared kidnapped; and Obama quits presidential race.
Symantec warned that curiosity killed the cat and may result in people becoming an unwitting target for spammers. Conley advised that people use a reputable news source to confirm these headlines.
Other findings of the report noted spam targeting the Japanese mobile phone market. As people spend more time using mobile devices to check e-mail, the growth of these types of mobile spam messages is expected to continue. Conley said that the majority of spam noted were adult-related and was sent purely as spam and not to obtain personal information.
Also, as the Beijing Olympics nears, so do more spam related to them. In the latest scam, messages claiming to originate from the Beijing Olympic committee have been observed where fraudulent messages purport to declare the winners of the lottery for an Olympic promotion.
"People should exercise due diligence when checking out their e-mail, don't give out personal information and be suspicious of scams as there are a lot of scams going on these days," stressed Conley.
By Vanessa Ho
The twist was that the e-mail came from a user's hacked webmail account and was sent to their personal list of contacts. People on this list would receive an e-mail request for financial assistance and were urged to respond via e-mail only. As the hacker took over the users account, the real owner would not have known about the e-mail if the recipients fell for the scam. As a further stamp of authentication, the auto-signature typically used by the account owner was included at the end of the message. The Symantec report indicated that this scam was a variation of the Nigerian spam.
However, the account owner was quickly notified by a friend via telephone of the scam, and immediately contacted the webmail service providers to get his account access back. This proved to be difficult because the hacker had changed the account details such as password, address and secret question.
According to Kelly Conley, manager of anti-spam research with Symantec Security Response, hackers were able to obtain this information because they replied to an e-mail request for an account update.
"You never want to respond to account expiration or update notifications because there is a good chance those are spammers trying to scam personal account information," she said.
Symantec stressed that this scam was not isolated to one particular webmail provider or organization. This scam also serves as a timely reminder that users should always keep passwords secure and never share them with anyone.
As well, Conley said that if a person were to receive such an e-mail, it should immediately raise a red flag.
"They should be suspicious, especially if it is out of the ordinary for the character of the person," she noted.
Also in the July spam report, Symantec discovered that spammers were simplifying their e-mail harvesting technique. To obtain e-mail addresses spammers used spambots which crawl the Internet looking for e-mail addresses, bombarded an e-mail server with e-mail addresses and storing the addresses that do not bounce, or bought lists of e-mail addresses from other spammers.
They used these addresses to send messages whose recipients were interested in receiving certain offers and encouraging these people to e-mail them back. The list of e-mail addresses that may be compiled would be very useful for the spammer. Not only were these people interested in buying the kind of products that the spammer was offering, but its a bona fide opt-in list, one that the spammer can now send messages to freely without concern that he will be sending to spamtraps, or that the message will be blocked by spam filters.
As well, the report noted spammers were using the recent earthquake tragedy in China to spread viruses by sending e-mails with news headlines, hoping it would entice the reader to open the message.
A video was embedded into the link that was in the e-mail which users were then lured into playing the video, which in turn opened an executable file. This executable file has been detected as Trojan.Peacom.D by Symantec AntiVirus software. Trojan.Peacomm.D is a Trojan horse that gathers system information and e-mail addresses from the compromised computer. Users should be aware of such attempts, and avoid opening e-mails and clicking on suspicious links.
Additionally, spammers turned to old techniques to lure in victims. Symantec noted in June that they were using bogus news headlines in an e-mail subject header to get recipients to open the message and click on a link that directs them to a spam offer.
Some of the headlines include: White House hit by lightening, catches fire; Donald Trump missing, feared kidnapped; and Obama quits presidential race.
Symantec warned that curiosity killed the cat and may result in people becoming an unwitting target for spammers. Conley advised that people use a reputable news source to confirm these headlines.
Other findings of the report noted spam targeting the Japanese mobile phone market. As people spend more time using mobile devices to check e-mail, the growth of these types of mobile spam messages is expected to continue. Conley said that the majority of spam noted were adult-related and was sent purely as spam and not to obtain personal information.
Also, as the Beijing Olympics nears, so do more spam related to them. In the latest scam, messages claiming to originate from the Beijing Olympic committee have been observed where fraudulent messages purport to declare the winners of the lottery for an Olympic promotion.
"People should exercise due diligence when checking out their e-mail, don't give out personal information and be suspicious of scams as there are a lot of scams going on these days," stressed Conley.
By Vanessa Ho
Palestinian hackers breach Likud Web site - jpost.com - 07 Jul 2008

The Likud Party's official Web site was hacked into twice Monday morning by Palestinian activists seeking to display political messages. The messages appeared primarily in English, although some were in Hebrew and Arabic. The main banner on the hacked page displayed an English message, "Only free men can negotiate," above a line that read, "Palestine. Dying to live," accompanied by the image of a Palestinian flag.
According to a Likud spokesperson, the first hacking took place at 5 a.m., and then again at 11:30 a.m. after the site had been restored to normal. The group responsible for the breach called themselves "Cold z3ro - Team Hell Crew."
In a separate Hebrew message, the hackers posted they referred to a prisoner exchange for captured Cpl. Gilad Schalit, stating, "You think that Gilad Schalit is returning? When he returns, we will capture four like Gilad Schalit."
Another message, also in Hebrew, stated "You are killing Palestinian children in Gaza."
Sani Sanivich, government affairs adviser to Likud chairman Binyamin Netanyahu, insisted that there would be no response.
"I don't understand why we should respond to an illegal action by a fanatical group that tries to break into our Web site."
As far as whether or not Likud will respond to the messages displayed on the site, Sanivich said that no one would dignify the words by giving them time.
"I didn't even think about it. We didn't read it." He added that Netanyahu had not and would not read the messages, either.
Likud representatives were unsure if charges would be pressed in response, but Sanivich said, "We don't care for these people. It's a lost fight," admitting that they cannot control similar events happening in the future.
The hackers seemed to know this, as they posted another Hebrew message on the site warning, "We will breach all of your Web sites."
Nate.com Troubled by Chinese Hacking Claim - english.chosun.com – 10 Jul 2008
The claims of an unidentified Chinese hacker have alarmed Korea's Internet portals.
Nate.com, a leading Korean portal run by SK Communications, is dismayed by a message left on a Chinese website. Claiming to be a hacker, the writer offered to sell the personal information of 12 million Nate.com members for one million yuan (W100 million, US$1=W1,006). As if to prove the claims, the writer revealed the information of five or six Koreans.
SK Communications was thrown into panic. If the claims are true, it would be the largest leak ever of Koreans' personal information, even topping the Auction.com leak in which data on 10.8 million members was hacked.
But the Chinese poster did not reveal any more information and deleted the message, making it impossible to confirm whether the hacking was real or a hoax.
An official with the Seoul Metropolitan Police cyber crime squad said it will take time to get the facts as it is an overseas case.
But SK is worried. An official there said an internal probe has found no trace of hacking, but to be safe Nate.com members will be required to change their passwords every six months.
The new password policy took effect Tuesday. Only members who change their online passwords can access Nate.com and Cyworld.com.
A portal employee said, "There's no particular measures against such hit-and-run Chinese hackers. Actual hacking cases are rare, but taking a lesson from the Auction incident, portals are always on high alert."
(englishnews@chosun.com )
Nate.com, a leading Korean portal run by SK Communications, is dismayed by a message left on a Chinese website. Claiming to be a hacker, the writer offered to sell the personal information of 12 million Nate.com members for one million yuan (W100 million, US$1=W1,006). As if to prove the claims, the writer revealed the information of five or six Koreans.
SK Communications was thrown into panic. If the claims are true, it would be the largest leak ever of Koreans' personal information, even topping the Auction.com leak in which data on 10.8 million members was hacked.
But the Chinese poster did not reveal any more information and deleted the message, making it impossible to confirm whether the hacking was real or a hoax.
An official with the Seoul Metropolitan Police cyber crime squad said it will take time to get the facts as it is an overseas case.
But SK is worried. An official there said an internal probe has found no trace of hacking, but to be safe Nate.com members will be required to change their passwords every six months.
The new password policy took effect Tuesday. Only members who change their online passwords can access Nate.com and Cyworld.com.
A portal employee said, "There's no particular measures against such hit-and-run Chinese hackers. Actual hacking cases are rare, but taking a lesson from the Auction incident, portals are always on high alert."
(englishnews@chosun.com )
Wednesday, July 9, 2008
Hackers post Soviet symbols on Lithuanian sites -
Unidentified hackers broke into several hundred Lithuanian Web sites over the weekend, plastering them with communist symbols, government officials said Monday.
The hackers posted Soviet symbols - the hammer and sickle, as well as the five-pointed star - and scathing messages with profanities on Web sites based in the ex-Soviet nation, officials said.
"More than 300 private and official sites were attacked from so-called proxy servers located in territories east of Lithuania," said Sigitas Jurkevicius, a computer specialist at Lithuania's communications authority.
The hackers hit Web sites from both the government and private sector, including the Baltic state's securities commission and ruling Social Democratic Party. Others included a car dealership and a grocery chain.
Many believe the attacks were a backlash against legislation approved by lawmakers two weeks ago banning the public display of Soviet and communist symbols. President Valdas Adamkus signed the law Friday.
Lithuania and the other two Baltic countries, Estonian and Latvia, gained independence from the Soviet Union in 1991.
The law prohibits the public display of the Soviet flag, military uniforms and the five-pointed Soviet star, as well as the playing of the Soviet national anthem.
It has drawn strong condemnation from Moscow, but Lithuanian officials stopped short of pinning blame on Russian hackers.
"Lithuania has experienced a serious attack on the Internet resources. I cannot rule out there is a direct link with our recent legislation," Defense Minister Juozas Olekas told reporters.
The hacking incident was also reminiscent of a series of cyberattacks on Estonian Web sites after the neighboring Baltic state angered Russia by moving a Soviet war monument and nearby war grave.
By LIUDAS DAPKUS - Associated Press Writer
The hackers posted Soviet symbols - the hammer and sickle, as well as the five-pointed star - and scathing messages with profanities on Web sites based in the ex-Soviet nation, officials said.
"More than 300 private and official sites were attacked from so-called proxy servers located in territories east of Lithuania," said Sigitas Jurkevicius, a computer specialist at Lithuania's communications authority.
The hackers hit Web sites from both the government and private sector, including the Baltic state's securities commission and ruling Social Democratic Party. Others included a car dealership and a grocery chain.
Many believe the attacks were a backlash against legislation approved by lawmakers two weeks ago banning the public display of Soviet and communist symbols. President Valdas Adamkus signed the law Friday.
Lithuania and the other two Baltic countries, Estonian and Latvia, gained independence from the Soviet Union in 1991.
The law prohibits the public display of the Soviet flag, military uniforms and the five-pointed Soviet star, as well as the playing of the Soviet national anthem.
It has drawn strong condemnation from Moscow, but Lithuanian officials stopped short of pinning blame on Russian hackers.
"Lithuania has experienced a serious attack on the Internet resources. I cannot rule out there is a direct link with our recent legislation," Defense Minister Juozas Olekas told reporters.
The hacking incident was also reminiscent of a series of cyberattacks on Estonian Web sites after the neighboring Baltic state angered Russia by moving a Soviet war monument and nearby war grave.
By LIUDAS DAPKUS - Associated Press Writer
Helping prevent online fraud - - southbendtribune.com – 06 Jul 2008
As if identity theft wasn't scary enough, last month's string of fraudulent withdrawals from hundreds of accounts at local financial institutions gave area residents more reason to worry.
Luckily, in some cases consumers can prevent scams with the right defensive measures.
Some strategies should be obvious. For example, don't use "password" as a password, shred old bills, and don't keep pin numbers written down in a wallet or purse.
But as crooks get smarter, common sense may not be enough to stave off scams.
While 1st Source Bank officials said an online data breach was most likely to blame for scams related to their ATMs, Ray Miller, owner of Michiana Mobile Computer Repair, speculates that skimmers may have been part of the problem.
Skimmers are devices that can read a card's magnetic strip when placed over an ATM card slot.
"Skimmers will have a little pinhole camera mounted in them so they can see the key presses and store the pin numbers there," Miller said.
Miller, who deals with security issues daily in his business, also warns against card catchers. These devices are thin strips of metal or plastic a thief places inside the card slot, allowing cards to be inserted but not ejected. Victims believe their cards have been "eaten" by the ATM, and when they leave to report the problem to their local branch, the thief can remove both the strip and the card.
1st Source Bank's online breach is not the norm in causes of identity theft, according to a study by the Better Business Bureau in 2005.
The study found that the theft of online information accounted for only 11.6 percent of identity fraud cases. In addition, the study found that half of all identity thefts were committed by someone the victim already knew.
To prevent against offline fraud, the identity theft protection company LifeLock recommends dropping off outgoing mail in official post office boxes rather than leaving it in a home mailbox.
"A lot of criminals will steal people's mail for credit card numbers or account numbers and steal that information," Miller said. "People stealing trash is not as frequent but it still happens, so people should use shredders."
Though paper is the biggest target of identity theft, public computers and wireless Internet connections present dangers that users often don't think about, Miller said.
"What most people aren't aware of is that when they use Wi-Fi hot spots, anyone who's on the same hot spot can use any shared folders or files they have on their computer," Miller said.
He also warns against packet monitoring software, which hackers can use to intercept and log traffic passing through the network.
"For any traffic they're sending back and forth in a Wi-Fi hot spot, anyone who's on the same network can view what they're sending," Miller said.
Keylogging software may also be a danger on public computers, Miller said. Someone could install such software on a public computer, store the keystrokes users type with a USB device, and collect the user names and passwords logged weeks later.
Some recent legislation aims to protect consumers against fraud. Because of the Fair and Accurate Credit and Transactions Act of 2003, consumers can receive a free annual credit report from one of the three major bureaus, Equifax, TransUnion, or Experian. Consumers who suspect fraud on their accounts can receive credit reports for free as well.
While prevention may be the best weapon against identity theft, people can minimize damages by checking on their accounts daily via the Internet, Miller said.
"ATM debit cards are really easy to keep track of," he said. "For myself, every day I'm downloading and updating transactions and comparing them to things my wife and I have done."
By SUPRIYA SINHABABU
Luckily, in some cases consumers can prevent scams with the right defensive measures.
Some strategies should be obvious. For example, don't use "password" as a password, shred old bills, and don't keep pin numbers written down in a wallet or purse.
But as crooks get smarter, common sense may not be enough to stave off scams.
While 1st Source Bank officials said an online data breach was most likely to blame for scams related to their ATMs, Ray Miller, owner of Michiana Mobile Computer Repair, speculates that skimmers may have been part of the problem.
Skimmers are devices that can read a card's magnetic strip when placed over an ATM card slot.
"Skimmers will have a little pinhole camera mounted in them so they can see the key presses and store the pin numbers there," Miller said.
Miller, who deals with security issues daily in his business, also warns against card catchers. These devices are thin strips of metal or plastic a thief places inside the card slot, allowing cards to be inserted but not ejected. Victims believe their cards have been "eaten" by the ATM, and when they leave to report the problem to their local branch, the thief can remove both the strip and the card.
1st Source Bank's online breach is not the norm in causes of identity theft, according to a study by the Better Business Bureau in 2005.
The study found that the theft of online information accounted for only 11.6 percent of identity fraud cases. In addition, the study found that half of all identity thefts were committed by someone the victim already knew.
To prevent against offline fraud, the identity theft protection company LifeLock recommends dropping off outgoing mail in official post office boxes rather than leaving it in a home mailbox.
"A lot of criminals will steal people's mail for credit card numbers or account numbers and steal that information," Miller said. "People stealing trash is not as frequent but it still happens, so people should use shredders."
Though paper is the biggest target of identity theft, public computers and wireless Internet connections present dangers that users often don't think about, Miller said.
"What most people aren't aware of is that when they use Wi-Fi hot spots, anyone who's on the same hot spot can use any shared folders or files they have on their computer," Miller said.
He also warns against packet monitoring software, which hackers can use to intercept and log traffic passing through the network.
"For any traffic they're sending back and forth in a Wi-Fi hot spot, anyone who's on the same network can view what they're sending," Miller said.
Keylogging software may also be a danger on public computers, Miller said. Someone could install such software on a public computer, store the keystrokes users type with a USB device, and collect the user names and passwords logged weeks later.
Some recent legislation aims to protect consumers against fraud. Because of the Fair and Accurate Credit and Transactions Act of 2003, consumers can receive a free annual credit report from one of the three major bureaus, Equifax, TransUnion, or Experian. Consumers who suspect fraud on their accounts can receive credit reports for free as well.
While prevention may be the best weapon against identity theft, people can minimize damages by checking on their accounts daily via the Internet, Miller said.
"ATM debit cards are really easy to keep track of," he said. "For myself, every day I'm downloading and updating transactions and comparing them to things my wife and I have done."
By SUPRIYA SINHABABU
One in four Asian banks hit by online scam attempts – The Economic Times - 7 Jul 2008
SINGAPORE: More than 25 percent of banks in the Asia-Pacific region have been hit by attempts to steal online information over the last 12 months, but beefing up security is still not viewed as a prime concern, a study said on Monday.
The survey by security software specialist ReadiMinds was conducted by Web and telephone polls across 11 economies including Malaysia, Hong Kong, Bangladesh, Vietnam, Cambodia and Singapore.
In such internet scams, crooks typically pose as the websites of financial institutions and attempt to "phish" for information including user names and online banking passwords, the study said.
In most Asian countries, "regulations are still catching up with the strengthening of their online security regime," a ReadiMinds spokesman told The Business Times. "Asian countries with weaker regulatory frameworks have therefore attracted the extra attention of online fraudsters."
Singapore banks are the exception, fortifying their defences to counter the on slaught of new threats. Online security is still not regarded as a prime concern by the majority of the regional banks. Seventy-five percent of the respondents said they were not aware of the impact of cyber security on their operations.
More than 60 percent of the banks polled did not set aside a budget for online security, lumping it instead into the overall technology budget. Only 20 percent have adopted measures to strengthen internet-based transactions, the report said.
Underscoring the lax security stance, the survey found 80 percent of the banks queried have no formal plans for raising consumer awareness against threats such as identity theft and financial fraud. Individual country breakdowns were not revealed to protect the confidentiality of the banks involved.
The survey by security software specialist ReadiMinds was conducted by Web and telephone polls across 11 economies including Malaysia, Hong Kong, Bangladesh, Vietnam, Cambodia and Singapore.
In such internet scams, crooks typically pose as the websites of financial institutions and attempt to "phish" for information including user names and online banking passwords, the study said.
In most Asian countries, "regulations are still catching up with the strengthening of their online security regime," a ReadiMinds spokesman told The Business Times. "Asian countries with weaker regulatory frameworks have therefore attracted the extra attention of online fraudsters."
Singapore banks are the exception, fortifying their defences to counter the on slaught of new threats. Online security is still not regarded as a prime concern by the majority of the regional banks. Seventy-five percent of the respondents said they were not aware of the impact of cyber security on their operations.
More than 60 percent of the banks polled did not set aside a budget for online security, lumping it instead into the overall technology budget. Only 20 percent have adopted measures to strengthen internet-based transactions, the report said.
Underscoring the lax security stance, the survey found 80 percent of the banks queried have no formal plans for raising consumer awareness against threats such as identity theft and financial fraud. Individual country breakdowns were not revealed to protect the confidentiality of the banks involved.
Sunday, July 6, 2008
Fake profiles of Mahesh Bhatt, Paresh Rawal crop up online - dnaindia.com - 04 Jul 08
Bollywood bigwigs Paresh Rawal and Mahesh Bhatt have lodged a complaint with the Cyber Crime Investigation Cell (CCIC) of the Mumbai crime branch alleging that their fake profiles have been created on the social networking website Facebook. They said they apprehended that the profiles had been created for misuing them.
Joint commissioner of police (crime) Rakesh Maria said the complaints were lodged on Tuesday night. He said the profiles could have been posted to lure youngsters and wannabe actors and actresses into providing sensitive information and to then use the information against them.
Messages asking people to send in their photographs and personal details have been posted on the website. The website has had many visitors hoping to interact with Rawal and Bhatt, Maria said. Social networking websites, such as Facebook, can be used for casting couch, he said.
“This is for the first time that we have a complaint of a fake profile on Facebook,” he said. The previous complaints concerned Orkut, he said.
The cyber crime sleuths may face some obstacles in this case. Maria said. If the server on which the profile has been uploaded is situated in a foreign country then it becomes difficult to block such websites, he said.
The police on Thursday wrote to the agency concerned to block the website or erase the profiles.
Mahesh Bhatt said he came to know about the profile from his dentist. “He told me he had scrapped me on Facebook in past few days. I was shocked to hear this. I told him I am not registered on Facebook,” he told DNA.
“Later Paresh (Rawal) called me and said his fake profile said that he was looking for girls (newcomers) for films,” he said. He said the content was posted from the United States. Attempts were made to contact Paresh Rawal. But his secretary said he was in Mauritius.
Joint commissioner of police (crime) Rakesh Maria said the complaints were lodged on Tuesday night. He said the profiles could have been posted to lure youngsters and wannabe actors and actresses into providing sensitive information and to then use the information against them.
Messages asking people to send in their photographs and personal details have been posted on the website. The website has had many visitors hoping to interact with Rawal and Bhatt, Maria said. Social networking websites, such as Facebook, can be used for casting couch, he said.
“This is for the first time that we have a complaint of a fake profile on Facebook,” he said. The previous complaints concerned Orkut, he said.
The cyber crime sleuths may face some obstacles in this case. Maria said. If the server on which the profile has been uploaded is situated in a foreign country then it becomes difficult to block such websites, he said.
The police on Thursday wrote to the agency concerned to block the website or erase the profiles.
Mahesh Bhatt said he came to know about the profile from his dentist. “He told me he had scrapped me on Facebook in past few days. I was shocked to hear this. I told him I am not registered on Facebook,” he told DNA.
“Later Paresh (Rawal) called me and said his fake profile said that he was looking for girls (newcomers) for films,” he said. He said the content was posted from the United States. Attempts were made to contact Paresh Rawal. But his secretary said he was in Mauritius.
Sunday, June 29, 2008
Wards didn't tell consumers about credit card hack - 29 Jun 2008
NEW YORK - An old name in retail was hit by a modern scourge — a hack of its customers' credit card numbers — but didn't inform the consumers, revealing how data breaches might be heavily undercounted even with new notification laws.
At least 51,000 records were exposed in the breach at the parent company of Montgomery Ward. The venerable Wards chain that began in 1872 went out of business in 2001, but in 2004 a catalog company, Direct Marketing Services Inc., bought the brand name out of bankruptcy. It now runs a Wards.com Web site along with six other sites, including three with Sears brands it has acquired: SearsHomeCenter.com, SearsShowplace.com and SearsRoomforKids.com.
Direct Marketing Services' CEO, David Milgrom, said the financial company Citigroup detected the computer invasion in December. By going through HomeVisions.com, another Direct Marketing Services site, hackers had plundered the database that holds account information for all the company's retail properties.
Milgrom said Direct Marketing Services immediately informed its payment processor and Visa and MasterCard. Then, Milgrom said, Direct Marketing Services closely followed a set of guidelines, issued by Visa, on how to respond to a security breach. That included a report to the U.S. Secret Service. He said he believed by the end of December that Direct Marketing Services had met its obligations.
However, those guidelines from Visa are largely technical, and they do not cover a key additional step: that notification laws in nearly every state generally require organizations that have been hacked to come clean to the affected consumers, not just to the financial industry.
Companies that fail to comply can be hit with fines or be sued by affected customers, depending on the state.
As a result, scores of breaches covering hundreds of millions of consumer accounts have been disclosed by banks, universities, corporations and retailers in recent years.
After being asked about those laws by The Associated Press, Milgrom said Direct Marketing Services now plans to contact consumers.
This hack might have stayed quiet except for online chatter detected in June by Affinion Group Inc.'s CardCops, a group of investigators who track payment-card theft for financial institutions. In Internet chat rooms frequented by card thieves, CardCops spotted hackers touting the sale of 200,000 payment cards belonging to one merchant. CardCops then intercepted several hundred of the records, along with the online handles belonging to hackers whose real names remain unknown.
Along with the card numbers, their three-digit "security codes" and expiration dates, the thieves had the cardholders' names, addresses and phone numbers. The data had been organized in the same way, indicating the numbers likely came from the same database. CardCops' president, Dan Clements, also noticed that the vast majority of the cardholders were women, a clue that the records came from a merchant catering to a certain demographic.
When he began calling them, the first eight said they had bought things online or through mail order from Montgomery Ward. At that point, Clements realized, "there's a high probability the entire database of Montgomery Ward was breached."
It is not clear to Clements, though, whether the hackers were inflating their claim when they offered 200,000 records or whether Milgrom's number of 51,000 is accurate.
The credit card industry's response to the breach varied.
A spokeswoman for Discover Financial Services LLC, Mai Lee Ua, said her company had addressed the problem by sending new cards to its cardholders who appeared in the compromised records. Ua said they weren't told which merchant had been breached.
Visa declined to comment. MasterCard issued a statement Friday acknowledging it was aware of the breach at Direct Marketing Services, and had notified the banks that issue MasterCards, telling them to monitor the accounts for suspicious charges.
Linda Jeffers of Latrobe, Pa., decided not to take any chances in waiting. Jeffers, a MasterCard cardholder whose data were found online, canceled her card this month after being contacted by CardCops.
She told the AP she had used the card for Internet shopping only once, from her son's computer — she bought a desk from Montgomery Ward — and was surprised to hear her account had been compromised.
Such silence was the norm in the industry for years. But in response to fears of identity theft, 44 states have passed laws that generally require organizations holding consumer data to tell people when their information has leaked, according to the National Conference of State Legislatures.
Clements and other security analysts say that despite those laws, many breaches still are kept quiet, judging by the data being hawked in online black markets. Avivah Litan, an analyst at Gartner Inc., believes unreported data breaches might still outnumber the ones that do get publicized.
Litan says it especially is the case with online merchants. She believes it happens because of a lack of pressure from credit card companies, which are not responsible for fraudulent charges in "card not present" transactions over the Web and mail order. Until fraud actually appears on the card, they'd rather avoid the cost of voiding compromised cards and giving consumers new ones, she said.
"What it reveals is the convoluted banking system," she said. "If this had taken place at a grocery store, we all would have heard about it."
In fact, because of the silence that still sometimes follows data breaches, even people who have never been informed one of their records has leaked should assume their information is floating online, Litan said.
"Probably every one of our cards is up there somewhere now," she said.
At least 51,000 records were exposed in the breach at the parent company of Montgomery Ward. The venerable Wards chain that began in 1872 went out of business in 2001, but in 2004 a catalog company, Direct Marketing Services Inc., bought the brand name out of bankruptcy. It now runs a Wards.com Web site along with six other sites, including three with Sears brands it has acquired: SearsHomeCenter.com, SearsShowplace.com and SearsRoomforKids.com.
Direct Marketing Services' CEO, David Milgrom, said the financial company Citigroup detected the computer invasion in December. By going through HomeVisions.com, another Direct Marketing Services site, hackers had plundered the database that holds account information for all the company's retail properties.
Milgrom said Direct Marketing Services immediately informed its payment processor and Visa and MasterCard. Then, Milgrom said, Direct Marketing Services closely followed a set of guidelines, issued by Visa, on how to respond to a security breach. That included a report to the U.S. Secret Service. He said he believed by the end of December that Direct Marketing Services had met its obligations.
However, those guidelines from Visa are largely technical, and they do not cover a key additional step: that notification laws in nearly every state generally require organizations that have been hacked to come clean to the affected consumers, not just to the financial industry.
Companies that fail to comply can be hit with fines or be sued by affected customers, depending on the state.
As a result, scores of breaches covering hundreds of millions of consumer accounts have been disclosed by banks, universities, corporations and retailers in recent years.
After being asked about those laws by The Associated Press, Milgrom said Direct Marketing Services now plans to contact consumers.
This hack might have stayed quiet except for online chatter detected in June by Affinion Group Inc.'s CardCops, a group of investigators who track payment-card theft for financial institutions. In Internet chat rooms frequented by card thieves, CardCops spotted hackers touting the sale of 200,000 payment cards belonging to one merchant. CardCops then intercepted several hundred of the records, along with the online handles belonging to hackers whose real names remain unknown.
Along with the card numbers, their three-digit "security codes" and expiration dates, the thieves had the cardholders' names, addresses and phone numbers. The data had been organized in the same way, indicating the numbers likely came from the same database. CardCops' president, Dan Clements, also noticed that the vast majority of the cardholders were women, a clue that the records came from a merchant catering to a certain demographic.
When he began calling them, the first eight said they had bought things online or through mail order from Montgomery Ward. At that point, Clements realized, "there's a high probability the entire database of Montgomery Ward was breached."
It is not clear to Clements, though, whether the hackers were inflating their claim when they offered 200,000 records or whether Milgrom's number of 51,000 is accurate.
The credit card industry's response to the breach varied.
A spokeswoman for Discover Financial Services LLC, Mai Lee Ua, said her company had addressed the problem by sending new cards to its cardholders who appeared in the compromised records. Ua said they weren't told which merchant had been breached.
Visa declined to comment. MasterCard issued a statement Friday acknowledging it was aware of the breach at Direct Marketing Services, and had notified the banks that issue MasterCards, telling them to monitor the accounts for suspicious charges.
Linda Jeffers of Latrobe, Pa., decided not to take any chances in waiting. Jeffers, a MasterCard cardholder whose data were found online, canceled her card this month after being contacted by CardCops.
She told the AP she had used the card for Internet shopping only once, from her son's computer — she bought a desk from Montgomery Ward — and was surprised to hear her account had been compromised.
Such silence was the norm in the industry for years. But in response to fears of identity theft, 44 states have passed laws that generally require organizations holding consumer data to tell people when their information has leaked, according to the National Conference of State Legislatures.
Clements and other security analysts say that despite those laws, many breaches still are kept quiet, judging by the data being hawked in online black markets. Avivah Litan, an analyst at Gartner Inc., believes unreported data breaches might still outnumber the ones that do get publicized.
Litan says it especially is the case with online merchants. She believes it happens because of a lack of pressure from credit card companies, which are not responsible for fraudulent charges in "card not present" transactions over the Web and mail order. Until fraud actually appears on the card, they'd rather avoid the cost of voiding compromised cards and giving consumers new ones, she said.
"What it reveals is the convoluted banking system," she said. "If this had taken place at a grocery store, we all would have heard about it."
In fact, because of the silence that still sometimes follows data breaches, even people who have never been informed one of their records has leaked should assume their information is floating online, Litan said.
"Probably every one of our cards is up there somewhere now," she said.
Asianet Reality show portal hacked - Express News Service - 28 Jun 2008
KOCHI: The portal of popular reality show ‘Idea Star Singer’ telecast on Asianet has been hacked.
The High-tech Cell at Police Headquarters, Thiruvananthapuram, has started investigation into a complaint filed by Asianet regarding the issue.
According to a complaint filed about one month ago, the portal of `Idea Star Singer’ has been hacked by someone.
It has been found that some of the pictures posted on the portal were deleted by someone other than the administrator.
The Police High-tech Cell has sought assistance from C-DAC for analysing the login details of the portals. “We have been inspecting the login details from various IP addresses into this website. We have found that the portal has been logged in more than 2,000 times. The details of login by the administrators, including the time of login and the duration, are available with us. Hence now we have to find out the details of others who logged in on the portal,” high-tech cell sources said.
The investigation team has found out that the password of the portal has been hacked.
Investigation is on to find out the hackers who gained access to the portal. Sources said that the issue began with an e-mail message that received by the portal saying that ‘site is not secure’.
The High-tech Cell at Police Headquarters, Thiruvananthapuram, has started investigation into a complaint filed by Asianet regarding the issue.
According to a complaint filed about one month ago, the portal of `Idea Star Singer’ has been hacked by someone.
It has been found that some of the pictures posted on the portal were deleted by someone other than the administrator.
The Police High-tech Cell has sought assistance from C-DAC for analysing the login details of the portals. “We have been inspecting the login details from various IP addresses into this website. We have found that the portal has been logged in more than 2,000 times. The details of login by the administrators, including the time of login and the duration, are available with us. Hence now we have to find out the details of others who logged in on the portal,” high-tech cell sources said.
The investigation team has found out that the password of the portal has been hacked.
Investigation is on to find out the hackers who gained access to the portal. Sources said that the issue began with an e-mail message that received by the portal saying that ‘site is not secure’.
Israeli hackers penetrate Hamas website - Israel News - 26 Jun 2008
Israeli hackers boasted Thursday about breaking into the website of Izz al-Din al-Qassam, Hamas’ military wing, which now displays a white screen and words in Arabic announcing technical difficulties.
The hacker group, which calls itself Fanat al-Radical (the fanatical radicals), also said that it broke into additional terror organizations’ sites and those of various leftist movements.
In a Ynet interview, a group representative who refused to reveal his name said, “We searched for relevant sites with the criteria we look for, whether leftist or anti-Zionist, and looked for loopholes. Our emphasis was always on the al-Qassam site.
"The criteria are defined as anti-Zionist or anti-Jewish sites that support or assist in harming Zionism and the existence of Israel as a Zionistic, Jewish state”.
According to him, the group consists of young adults from 16 to 18 years of age.
In addition to the Hamas military wing’s site, they also broke into the Balad political party site, that of the Hagada Hasmalit (the left bank), the Kibush (occupation) site and more.
The hacked sites are now equipped with an Israeli flag, the words of the Israeli national anthem "Hatikva" with vowels and pictures of Palestinian babies and children dressed as suicide bombers. A short explanation of why this specific site was broken into to begin with is also included.
The Left Bank site, considered by the group as “another site identifying with the left,” was broken into “due to its blatant anti-Zionist contents.”
More to come
Despite the fact that the slogan, “Kahane was right” appears and with it, the symbol of the Kach party, a yellow and black fist, the groups’ members clarified that they are in no way connected to the Kahane Chai party, “except for many common opinions and agreement with Kahane’s ways, out of the understanding that there is no other choice.”
Fanat al-Radical is a new group of hackers whose members were members of another group called Kamikaz Team. “Since we didn’t want to include politics in Kamikaz, we created a parallel group that supports the destruction of Arab sites.
“This is our first operation under the new name but it isn’t the first time we have done similar things to Arab, anti-Zionistic sites,” said the representative.
When asked if he believes that hacking can lead to change, he said, “We want to convey the message that there are still people who care and who are sick and tired of governmental apathy. We believe in all ways of fighting back and our means is the internet. We will do anything that causes damage.”
The group feels that its first hacking campaign was successful, but they do not intend on stopping here. They said that they plan on orchestrating an additional attack in the future.
Politically and nationally-motivated site hacking is not new. Two months ago the Bank of Israel site was penetrated by a Muslim hacker that left messages against Israeli occupation and of the US invasion of Iraq.
The hacker group, which calls itself Fanat al-Radical (the fanatical radicals), also said that it broke into additional terror organizations’ sites and those of various leftist movements.
In a Ynet interview, a group representative who refused to reveal his name said, “We searched for relevant sites with the criteria we look for, whether leftist or anti-Zionist, and looked for loopholes. Our emphasis was always on the al-Qassam site.
"The criteria are defined as anti-Zionist or anti-Jewish sites that support or assist in harming Zionism and the existence of Israel as a Zionistic, Jewish state”.
According to him, the group consists of young adults from 16 to 18 years of age.
In addition to the Hamas military wing’s site, they also broke into the Balad political party site, that of the Hagada Hasmalit (the left bank), the Kibush (occupation) site and more.
The hacked sites are now equipped with an Israeli flag, the words of the Israeli national anthem "Hatikva" with vowels and pictures of Palestinian babies and children dressed as suicide bombers. A short explanation of why this specific site was broken into to begin with is also included.
The Left Bank site, considered by the group as “another site identifying with the left,” was broken into “due to its blatant anti-Zionist contents.”
More to come
Despite the fact that the slogan, “Kahane was right” appears and with it, the symbol of the Kach party, a yellow and black fist, the groups’ members clarified that they are in no way connected to the Kahane Chai party, “except for many common opinions and agreement with Kahane’s ways, out of the understanding that there is no other choice.”
Fanat al-Radical is a new group of hackers whose members were members of another group called Kamikaz Team. “Since we didn’t want to include politics in Kamikaz, we created a parallel group that supports the destruction of Arab sites.
“This is our first operation under the new name but it isn’t the first time we have done similar things to Arab, anti-Zionistic sites,” said the representative.
When asked if he believes that hacking can lead to change, he said, “We want to convey the message that there are still people who care and who are sick and tired of governmental apathy. We believe in all ways of fighting back and our means is the internet. We will do anything that causes damage.”
The group feels that its first hacking campaign was successful, but they do not intend on stopping here. They said that they plan on orchestrating an additional attack in the future.
Politically and nationally-motivated site hacking is not new. Two months ago the Bank of Israel site was penetrated by a Muslim hacker that left messages against Israeli occupation and of the US invasion of Iraq.
Turkish hackers crack ICANN - vnunet.com- 28 Jun 2008
Turkish hacking group NetDevilz have successfully hacked the web sites for the Internet Corporation for Assigned Names and Numbers (ICANN) and Internet Assigned Numbers Authority (IANA).
The two organizations are key to the running of the internet and the hacking attack is highly embarrassing to the site’s administrators. Visitors to the page were redirected to an atspace.com dotcom domain hosting a message from the hackers.
"You think that you control the domains but you don't! Everybody knows wrong. We control the domains including ICANN! Don't you believe us?"
It is signed off as by NetDevilz, who describe themselves as a ‘loveable Turkish hacker’s group’.
The attack is particularly embarrassing for the groups involved since this week has seen ICANN approve generic domain names in what it calls ‘a milestone’ in the development of the internet.
The NetDevilz are same group was behind a similar attack earlier this year against the pornography web site Redtube.
by Iain Thomson
The two organizations are key to the running of the internet and the hacking attack is highly embarrassing to the site’s administrators. Visitors to the page were redirected to an atspace.com dotcom domain hosting a message from the hackers.
"You think that you control the domains but you don't! Everybody knows wrong. We control the domains including ICANN! Don't you believe us?"
It is signed off as by NetDevilz, who describe themselves as a ‘loveable Turkish hacker’s group’.
The attack is particularly embarrassing for the groups involved since this week has seen ICANN approve generic domain names in what it calls ‘a milestone’ in the development of the internet.
The NetDevilz are same group was behind a similar attack earlier this year against the pornography web site Redtube.
by Iain Thomson
Dutch police have arrested a 20-year-old man suspected of hacking on the internet and stealing the details of 50,000 credit cards- 28 Jun 2008.
Dutch police have arrested a 20-year-old man suspected of hacking on the internet and stealing the details of 50,000 credit cards.
The man, detained in Maastricht on Tuesday (local time), is also alleged to have hacked into the server of a US gamemaker and stolen a copy of award-winning videogame Enemy Territory: Quake War - while it was in development.
Police seized the man's computer and a gun during their search of his home.
He is thought to have used the credit card identities, obtained through a British ticketing agency, to make numerous online purchases, racking up $US20 million of infrastructure damage along the way.
The man, detained in Maastricht on Tuesday (local time), is also alleged to have hacked into the server of a US gamemaker and stolen a copy of award-winning videogame Enemy Territory: Quake War - while it was in development.
Police seized the man's computer and a gun during their search of his home.
He is thought to have used the credit card identities, obtained through a British ticketing agency, to make numerous online purchases, racking up $US20 million of infrastructure damage along the way.
Rightist hackers place Israeli flag, Kach images on pro-Palestinian Web sites - haaretz.com -
Rightists on Thursday hacked into three Web sites associated with the Israeli Arab and Palestinan causes, and embedded on their pages an image of the Israeli flag, the words to the Israeli national anthem and the symbol of an outlawed ultra-rightist movement.
The perpetrators hacked into the Web site of the Israeli Arab Balad party; Arabs48.com, an Arabic-language site; and Mahsom.com, which is written in Hebrew. Both site represent the Israeli Arab and Palestinian cause.
In addition to the flag and the words of "Hatikva," the hackers embedded the symbol of the Kach movement, an ultra-rightist organization founded by Rabbi Meir Kahane that was banned from the Knesset in 1988 and later deemed a terrorist organization by Israel. The symbol appeared with the words "Kahane was right."
Pictures were also embedded on the sites showing Palestinian children strapped with explosives under the words "murderers from birth."
In a statement also printed on the site, the rightists wrote, "This site was hacked into due to its blatantly anti-Zionist contents. Israel is not interested in people like you who are burdens on the process of proper decision-making in the government. If you oppose what you call the 'Israeli occupation' then there's no place for you here."
Arabs48.com, which is popular in Arab states and in Israel, prints news on Israel and the Middle East from a pro-Palestinian, pan-Arabist perspective. Mahsom.com is a self-proclaimed alternative media source meant for a primarily Jewish audience.
The manager of Arabs48.com, Az a-Din Badran, said in response that the "hacking of the site is intended to sabotage the a central media outlet, which provides a critical and different look at everything connected to the Arab-Israeli conflict. It seems that the exposure enjoyed by the site, in Israel and in the Arab world, drives the right-wing crazy."
"The site is constantly suffering from repeated hack attempts, which have interfered in the past with the regular maintenance of the site, but not to this extent. We view with great severity the attempt to silence the site, which reflects factual and analytical loyalty to the Arab and Palestinian perspective in the ongoing conflict. The Kahane terrorists and their followers from the Israeli-Zionist right will not weaken our power, like they haven't in the past," the statement continued.
The perpetrators hacked into the Web site of the Israeli Arab Balad party; Arabs48.com, an Arabic-language site; and Mahsom.com, which is written in Hebrew. Both site represent the Israeli Arab and Palestinian cause.
In addition to the flag and the words of "Hatikva," the hackers embedded the symbol of the Kach movement, an ultra-rightist organization founded by Rabbi Meir Kahane that was banned from the Knesset in 1988 and later deemed a terrorist organization by Israel. The symbol appeared with the words "Kahane was right."
Pictures were also embedded on the sites showing Palestinian children strapped with explosives under the words "murderers from birth."
In a statement also printed on the site, the rightists wrote, "This site was hacked into due to its blatantly anti-Zionist contents. Israel is not interested in people like you who are burdens on the process of proper decision-making in the government. If you oppose what you call the 'Israeli occupation' then there's no place for you here."
Arabs48.com, which is popular in Arab states and in Israel, prints news on Israel and the Middle East from a pro-Palestinian, pan-Arabist perspective. Mahsom.com is a self-proclaimed alternative media source meant for a primarily Jewish audience.
The manager of Arabs48.com, Az a-Din Badran, said in response that the "hacking of the site is intended to sabotage the a central media outlet, which provides a critical and different look at everything connected to the Arab-Israeli conflict. It seems that the exposure enjoyed by the site, in Israel and in the Arab world, drives the right-wing crazy."
"The site is constantly suffering from repeated hack attempts, which have interfered in the past with the regular maintenance of the site, but not to this extent. We view with great severity the attempt to silence the site, which reflects factual and analytical loyalty to the Arab and Palestinian perspective in the ongoing conflict. The Kahane terrorists and their followers from the Israeli-Zionist right will not weaken our power, like they haven't in the past," the statement continued.
Friday, June 27, 2008
China's cyber warfare against India - indiapost.com
China's intensified cyber warfare against India is becoming a serious threat to national security. The desire to possess 'electronic dominance' over India has compelled Chinese hackers to attack many crucial Indian websites and over the past one and a half years, they have mounted almost daily attacks on Indian computer networks - both government and private.
In October 2007, for example, Chinese hackers defaced over 143 Indian websites. Phishing is a term derived from fishing, and is a fraudulent activity on the Internet to acquire personal information. In phishing, the hackers use spoofed e-mails to lure innocent Internet users and get their personal information like bank account number, credit card details, and password and so on.
In April 2008, Indian intelligence agencies detected Chinese hackers breaking into the computer network of the Ministry of External Affairs forcing the government to think about devising a new strategy to fortify the system. Though the intelligence agencies failed to get the identity of the hackers, the IP addresses left behind suggested Chinese hands.
While hacking is a normal practice around the world, the cyber warfare threat from China has serious implications. At the core of the assault is the fact that the Chinese are constantly scanning and mapping India's official networks.
According to India's CERT-In, in the year 2006, a total of 5,211 Indian websites were defaced, on an average of about 14 websites per day. Of the total number of sites that were hacked and defaced, an overwhelming majority were in the .com domain (90 cases) followed by 26 in the .in domain. As many as 11 defacement incidents were also recorded in the .org domain.
Of all hacking incidents in October, about 61 per cent related to phishing, 27 per cent to unauthorized scanning and 8 per cent to viruses/worms under the malicious code category. India, like the western countries, has been witnessing a massive rise in phishing attacks with incidents in 2006 180 per cent higher than in 2005, and the trend carrying through into 2007.
Though the maximum defacements have been recorded during August, in 2007, February and March recorded the highest such cases with 858 and 738 websites defaced respectively. August, by contrast, saw only 345 websites defaced. While other countries treat Chinese cyber attacks as security breaches, India considers these intrusions as the equivalent of Internet-based terrorist attacks.
An Indian Army commanders' conference held in New Delhi on 26 April, voiced concern over mounting attacks on the country's networks. In the US, in June 2007, the Pentagon's computers were shut down for a week as a result of hacking.
At the frequency and aggressiveness of cyber attacks President Bush, without referring directly to Beijing, had said last year that "a lot of our systems are vulnerable to attack." The Chinese military hacked into the US Defence Secretary's computer system in June 2007 and regularly penetrated computers in at least ten of the UK's Whitehall departments, accessing also military files. German Chancellor, Angela Merkel, too has complained to Chinese Premier, Wen Jiabao, over suspected hacks of its government systems.
Although Beijing vehemently denies all allegations of state-controlled cyber snooping and hacking, the Chinese government as well as its society hails the practice of hacking for the national cause. The formation of Honker Union in China in 1999, in retaliation to the US bombing of the Chinese embassy in Belgrade, was aimed at widespread hacking under the guise of patriotism and nationalism, mostly of government-related websites around the world.
Unless India takes adequate steps to protect itself from external cyber threats, the world famous IT giant could be facing a grim situation. Cyber attacks are dangerous for India because of the growing reliance on networks and technology to control critical systems that run power plants and transportation systems. Cyber attacks on banks, stock markets and other financial institutions could likewise have a devastating effect on a nation's economy.
As a countermeasure, the Indian armed forces are trying to enhance their C4ISR capabilities, so that the country can launch its own cyber offensive if the need arises. Given Chinese cyber attacks, there is need for the army to fight digital battles as well.
According to Indian Army Chief, General Deepak Kapoor, the army has already ramped up the security of its information networks right down to the division level, while the Army Cyber Security Establishment has started conducting periodic cyber-security audits as well. However, the question remains: is this enough to stop Chinese cyber attacks?
In October 2007, for example, Chinese hackers defaced over 143 Indian websites. Phishing is a term derived from fishing, and is a fraudulent activity on the Internet to acquire personal information. In phishing, the hackers use spoofed e-mails to lure innocent Internet users and get their personal information like bank account number, credit card details, and password and so on.
In April 2008, Indian intelligence agencies detected Chinese hackers breaking into the computer network of the Ministry of External Affairs forcing the government to think about devising a new strategy to fortify the system. Though the intelligence agencies failed to get the identity of the hackers, the IP addresses left behind suggested Chinese hands.
While hacking is a normal practice around the world, the cyber warfare threat from China has serious implications. At the core of the assault is the fact that the Chinese are constantly scanning and mapping India's official networks.
According to India's CERT-In, in the year 2006, a total of 5,211 Indian websites were defaced, on an average of about 14 websites per day. Of the total number of sites that were hacked and defaced, an overwhelming majority were in the .com domain (90 cases) followed by 26 in the .in domain. As many as 11 defacement incidents were also recorded in the .org domain.
Of all hacking incidents in October, about 61 per cent related to phishing, 27 per cent to unauthorized scanning and 8 per cent to viruses/worms under the malicious code category. India, like the western countries, has been witnessing a massive rise in phishing attacks with incidents in 2006 180 per cent higher than in 2005, and the trend carrying through into 2007.
Though the maximum defacements have been recorded during August, in 2007, February and March recorded the highest such cases with 858 and 738 websites defaced respectively. August, by contrast, saw only 345 websites defaced. While other countries treat Chinese cyber attacks as security breaches, India considers these intrusions as the equivalent of Internet-based terrorist attacks.
An Indian Army commanders' conference held in New Delhi on 26 April, voiced concern over mounting attacks on the country's networks. In the US, in June 2007, the Pentagon's computers were shut down for a week as a result of hacking.
At the frequency and aggressiveness of cyber attacks President Bush, without referring directly to Beijing, had said last year that "a lot of our systems are vulnerable to attack." The Chinese military hacked into the US Defence Secretary's computer system in June 2007 and regularly penetrated computers in at least ten of the UK's Whitehall departments, accessing also military files. German Chancellor, Angela Merkel, too has complained to Chinese Premier, Wen Jiabao, over suspected hacks of its government systems.
Although Beijing vehemently denies all allegations of state-controlled cyber snooping and hacking, the Chinese government as well as its society hails the practice of hacking for the national cause. The formation of Honker Union in China in 1999, in retaliation to the US bombing of the Chinese embassy in Belgrade, was aimed at widespread hacking under the guise of patriotism and nationalism, mostly of government-related websites around the world.
Unless India takes adequate steps to protect itself from external cyber threats, the world famous IT giant could be facing a grim situation. Cyber attacks are dangerous for India because of the growing reliance on networks and technology to control critical systems that run power plants and transportation systems. Cyber attacks on banks, stock markets and other financial institutions could likewise have a devastating effect on a nation's economy.
As a countermeasure, the Indian armed forces are trying to enhance their C4ISR capabilities, so that the country can launch its own cyber offensive if the need arises. Given Chinese cyber attacks, there is need for the army to fight digital battles as well.
According to Indian Army Chief, General Deepak Kapoor, the army has already ramped up the security of its information networks right down to the division level, while the Army Cyber Security Establishment has started conducting periodic cyber-security audits as well. However, the question remains: is this enough to stop Chinese cyber attacks?
Monday, June 23, 2008
Exiled Tibetans wage cyber attack on China - Sify.com - 23 Jun 2008
Dharamsala (Himachal Pradesh): They might not have the guns and the numbers to match the might of the world's biggest army in China, but determined Tibetans living in exile in India and other parts of the world are turning to the internet to wage a 'virtual' war against China.
Scores of Tibetan websites and links have come up in the last couple of years to put forth demands of a 'free Tibet' and highlight the alleged rights violations in Tibet. And it is not Tibetans alone who are in the midst of this struggle.
They are being supported by hundreds of sympathisers across the globe, many of them information technology (IT) specialists, and even Indian friends.
Tibet Special: Blood on the Roof of the World
The Tibetan government-in-exile here uses the internet as a potent weapon to draw attention to the Tibetan cause and counter the Chinese propaganda. While the exiled Central Tibetan Administration (CTA) has its own website (www.tibet.net), other arms of the Tibetan establishment too rely heavily on the Internet.
The Tibetan Solidarity Committee (TSC), which came into being in March to coordinate the Tibetan issue after violent anti-China protests broke out in the run-up to the Beijing Olympics, also has its own website that is updated daily.
“The internet is a good weapon to have at times to counter Chinese propaganda. But this is a short-term thing because the Chinese manage to block Tibetan websites inside China. These websites cannot exist inside Tibet or China for more than three-four days,” points out the exiled government's Prime Minister (Kalon Tripa) Samdhong Rinpoche.
"Using the internet to highlight the Tibetan cause is a good weapon for us," Rinpoche told IANS.
Tibetan spiritual head the Dalai Lama has his own website (www.dalailama.com) and so also the Karmapa Lama - the third highest figure in Tibetan religious hierarchy.
In fact, a single website, www.tibetsites.com, provides links to scores of Tibetan websites across the globe. These include websites of the exiled government and its several agencies, Tibetan NGOs like Tibetan Youth Congress, Friends of Tibet and Students for Free Tibet.
It’s cultural genocide in Tibet: Dalai Lama
Some sites like www.phayul.com deal with news about Tibetans from around the globe.
Tibetans living in this Himalayan abode of the Dalai Lama say the world wide web (www) also helps them keep in touch with Tibetans living in Tibet.
"Using the internet helps us to highlight information about what we are doing. Many sympathisers of the Tibetan cause have got in touch with us through the websites. This also helps in getting funding and support," Lobsang, a Tibetan activist says as he scans websites at a cyber-café in Mcleodganj - India's little Lhasa near here.
India is home to some 100,000 Tibetan exiles, many of whom fled their homeland along with the Dalai Lama in 1959 following a failed anti-China uprising. The Tibetan government-in-exile in Dharamsala is not recognised by any country.
In the last three years, efforts are being made by IT professionals from abroad to set up the 'air jaldi' wi-fi network in and around Mcleodganj and Dharamsala to provide wireless access to Tibetans and others.
NGOs are also running computer and technology centres around Dharamsala to train Tibetan youth in computers, software and other related technology.
Tibetans seek help of technology professionals to make sure that their websites are not hacked by Chinese hackers. This has happened several times in recent years and the CTA's website, www.tibet.net, was also hacked three months ago.
Scores of Tibetan websites and links have come up in the last couple of years to put forth demands of a 'free Tibet' and highlight the alleged rights violations in Tibet. And it is not Tibetans alone who are in the midst of this struggle.
They are being supported by hundreds of sympathisers across the globe, many of them information technology (IT) specialists, and even Indian friends.
Tibet Special: Blood on the Roof of the World
The Tibetan government-in-exile here uses the internet as a potent weapon to draw attention to the Tibetan cause and counter the Chinese propaganda. While the exiled Central Tibetan Administration (CTA) has its own website (www.tibet.net), other arms of the Tibetan establishment too rely heavily on the Internet.
The Tibetan Solidarity Committee (TSC), which came into being in March to coordinate the Tibetan issue after violent anti-China protests broke out in the run-up to the Beijing Olympics, also has its own website that is updated daily.
“The internet is a good weapon to have at times to counter Chinese propaganda. But this is a short-term thing because the Chinese manage to block Tibetan websites inside China. These websites cannot exist inside Tibet or China for more than three-four days,” points out the exiled government's Prime Minister (Kalon Tripa) Samdhong Rinpoche.
"Using the internet to highlight the Tibetan cause is a good weapon for us," Rinpoche told IANS.
Tibetan spiritual head the Dalai Lama has his own website (www.dalailama.com) and so also the Karmapa Lama - the third highest figure in Tibetan religious hierarchy.
In fact, a single website, www.tibetsites.com, provides links to scores of Tibetan websites across the globe. These include websites of the exiled government and its several agencies, Tibetan NGOs like Tibetan Youth Congress, Friends of Tibet and Students for Free Tibet.
It’s cultural genocide in Tibet: Dalai Lama
Some sites like www.phayul.com deal with news about Tibetans from around the globe.
Tibetans living in this Himalayan abode of the Dalai Lama say the world wide web (www) also helps them keep in touch with Tibetans living in Tibet.
"Using the internet helps us to highlight information about what we are doing. Many sympathisers of the Tibetan cause have got in touch with us through the websites. This also helps in getting funding and support," Lobsang, a Tibetan activist says as he scans websites at a cyber-café in Mcleodganj - India's little Lhasa near here.
India is home to some 100,000 Tibetan exiles, many of whom fled their homeland along with the Dalai Lama in 1959 following a failed anti-China uprising. The Tibetan government-in-exile in Dharamsala is not recognised by any country.
In the last three years, efforts are being made by IT professionals from abroad to set up the 'air jaldi' wi-fi network in and around Mcleodganj and Dharamsala to provide wireless access to Tibetans and others.
NGOs are also running computer and technology centres around Dharamsala to train Tibetan youth in computers, software and other related technology.
Tibetans seek help of technology professionals to make sure that their websites are not hacked by Chinese hackers. This has happened several times in recent years and the CTA's website, www.tibet.net, was also hacked three months ago.
Hackers make mirror image of Citadel site - denverpost.com - 22 Jun 2008
Web-savvy criminals are preying on consumers' financial information more and more often, security experts say.
CHICAGO — The famously discreet Citadel Investment Group draws many of the shrewdest minds from Wall Street to Chicago. Shanghai too.
Unknown people in that Chinese city cloned Citadel's website, set up a link for investor passwords and exposed the $17 billion hedge fund to a "grave risk of theft of confidential information," according to a federal lawsuit that shut down the fake site.
These kinds of nefarious schemes have become shockingly routine for financial institutions, security experts say, and exhibit an increasing level of brashness by people using search engines and customer identities to hijack sensitive data.
"It's not that they're heading in through the back door," said David Fisher, chief executive of the Chicago-based online brokerage OptionsXpress. "It's people coming in through the front door with a user name and password."
Even if companies defuse scams without suffering any losses, as Citadel did, the culprits usually vanish like phantoms. The vast majority escape investigation and prosecution due to an inadequate framework of domestic and international laws.
"Over the next few years, these issues are going to come so far to the forefront that there are going to be more efforts by lawmakers to provide specific laws to remedy these harms," said lawyer Scott Kamber, who represents customers of the brokerage TD Ameritrade in a class-action lawsuit. "It's incumbent on corporate America to get religion on fortifying their security. If they don't, it's going to get very expensive for them."
Investment bank Sandler O'Neill and Partners is trying to determine who penetrated its website, forcing it to shut down for four days last week.
The bank hosted a conference about electronic trading, streaming live video of presentations by 35 companies, including the CME Group, parent company of the Chicago Mercantile Group and Chicago Board of Trade.
Hackers linked some to an overseas website that secretly downloaded a malicious program onto their computers, said someone who reviewed the incident for the bank. While the program was not harmful, the bank instantly notified clients about the incident.
TD Ameritrade is awaiting the settlement of a class-action lawsuit after hackers accessed the accounts of some 6.3 million customers.
The hackers then sent spam to the customers in a scheme to pump up the prices of certain stocks that would then be dumped on unsuspecting buyers.
Kamber compared defending a financial company from these scams to stopping a submarine from sinking: The water can rush into the smallest of cracks.
Dangerous programs infect about 6,000 sites each day, almost one every 14 seconds, according to research by Sophos, an anti-spam and antivirus software company.
Companies such as OptionsXpress take precautions to defend against more complex attacks. One involved keystroke programs downloaded onto hotel computer kiosks in Thailand that capture the passwords of tourists checking their accounts.
A Colombian citizen, Mario Simbaqueba Bonilla, was convicted in April for a similar three-year scam that stole $1.4 million by lifting information from computers at hotels and Internet lounges worldwide, according to the Justice Department.
Federal agents caught and arrested him last year when he flew to the U.S. His baggage included a laptop containing the names, passwords and other financial information of 600 people.
In Citadel's case, the thieves probably wanted to "phish" for investor passwords that would help them access data from the real site. The fake site might also have served as a front to cheat naive investors eager to entrust their money with Citadel.
Citadel said the bogus site produced no unusual activity on its own website.
What distinguished the scam was its apparent reliance on search engines. If you typed "Citadel," "hedge" and "fund" into Google in December, a curious site called "cita del-group.net" popped up.
It bore the hedge fund's turreted logo, but the site contained some unique alterations, such as contact information written in Chinese.
The real Citadel is headquartered in a Chicago skyscraper. A replica of an ancient Greek sculpture and alert security guards watch over its ground floor.
"No writing is allowed here," a guard barked as a visitor with a notebook approached the statue last week.
By Joshua Boak
CHICAGO — The famously discreet Citadel Investment Group draws many of the shrewdest minds from Wall Street to Chicago. Shanghai too.
Unknown people in that Chinese city cloned Citadel's website, set up a link for investor passwords and exposed the $17 billion hedge fund to a "grave risk of theft of confidential information," according to a federal lawsuit that shut down the fake site.
These kinds of nefarious schemes have become shockingly routine for financial institutions, security experts say, and exhibit an increasing level of brashness by people using search engines and customer identities to hijack sensitive data.
"It's not that they're heading in through the back door," said David Fisher, chief executive of the Chicago-based online brokerage OptionsXpress. "It's people coming in through the front door with a user name and password."
Even if companies defuse scams without suffering any losses, as Citadel did, the culprits usually vanish like phantoms. The vast majority escape investigation and prosecution due to an inadequate framework of domestic and international laws.
"Over the next few years, these issues are going to come so far to the forefront that there are going to be more efforts by lawmakers to provide specific laws to remedy these harms," said lawyer Scott Kamber, who represents customers of the brokerage TD Ameritrade in a class-action lawsuit. "It's incumbent on corporate America to get religion on fortifying their security. If they don't, it's going to get very expensive for them."
Investment bank Sandler O'Neill and Partners is trying to determine who penetrated its website, forcing it to shut down for four days last week.
The bank hosted a conference about electronic trading, streaming live video of presentations by 35 companies, including the CME Group, parent company of the Chicago Mercantile Group and Chicago Board of Trade.
Hackers linked some to an overseas website that secretly downloaded a malicious program onto their computers, said someone who reviewed the incident for the bank. While the program was not harmful, the bank instantly notified clients about the incident.
TD Ameritrade is awaiting the settlement of a class-action lawsuit after hackers accessed the accounts of some 6.3 million customers.
The hackers then sent spam to the customers in a scheme to pump up the prices of certain stocks that would then be dumped on unsuspecting buyers.
Kamber compared defending a financial company from these scams to stopping a submarine from sinking: The water can rush into the smallest of cracks.
Dangerous programs infect about 6,000 sites each day, almost one every 14 seconds, according to research by Sophos, an anti-spam and antivirus software company.
Companies such as OptionsXpress take precautions to defend against more complex attacks. One involved keystroke programs downloaded onto hotel computer kiosks in Thailand that capture the passwords of tourists checking their accounts.
A Colombian citizen, Mario Simbaqueba Bonilla, was convicted in April for a similar three-year scam that stole $1.4 million by lifting information from computers at hotels and Internet lounges worldwide, according to the Justice Department.
Federal agents caught and arrested him last year when he flew to the U.S. His baggage included a laptop containing the names, passwords and other financial information of 600 people.
In Citadel's case, the thieves probably wanted to "phish" for investor passwords that would help them access data from the real site. The fake site might also have served as a front to cheat naive investors eager to entrust their money with Citadel.
Citadel said the bogus site produced no unusual activity on its own website.
What distinguished the scam was its apparent reliance on search engines. If you typed "Citadel," "hedge" and "fund" into Google in December, a curious site called "cita del-group.net" popped up.
It bore the hedge fund's turreted logo, but the site contained some unique alterations, such as contact information written in Chinese.
The real Citadel is headquartered in a Chicago skyscraper. A replica of an ancient Greek sculpture and alert security guards watch over its ground floor.
"No writing is allowed here," a guard barked as a visitor with a notebook approached the statue last week.
By Joshua Boak
Subscribe to:
Posts (Atom)