Showing posts with label Industrial Espionage. Show all posts
Showing posts with label Industrial Espionage. Show all posts

Friday, 1 April 2011

Hackers target business secrets

Filing cabinet, Eyewire Many net-savvy thieves are scouring corporate networks for saleable secrets


Intellectual property and business secrets are fast becoming a target for cyber thieves, a study suggests.

Compiled by security firm McAfee, the research found that some hackers are starting to specialise in data stolen from corporate networks.

McAfee said deals were being done for trade secrets, marketing plans, R&D reports and source code.
It urged companies to know who looks after their data as it moves into the cloud or third-party hosting centres.

"Cyber criminals are targeting this information based on what their clients are asking for," said Raj Samani, chief technology officer in Europe for McAfee.

He said some business data had always been scooped up when net thieves compromised PCs using viruses and trojans in a search for logins or credit card details.

The difference now was that there exists a ready market for the data they are finding. In some cases, said Mr Samani, thieves were running campaigns to get at particular companies or certain types of information.

The McAfee report mentioned cases in Germany, Brazil and Italy in which trade secrets were either stolen by an insider or cyber thieves tried to get hold of via a concerted attack.

In some cases, said the McAfee report, companies made the job of the criminals easier because they did little to censor useful information about a corporate's culture or structure revealed in e-mails and other messages.

Such information could prove key for thieves mounting a "social engineering" in which they pose as employees to penetrate networks.

The report detailed efforts by firms to watch casual and contract employees and the use of behavioural analysis software to spot anomalous activity on a corporate network.


Perimeter defences

Thefts of intellectual property or key documents could be hard to detect, said Mr Samani.

"You may not even know it's stolen because they just take a copy of it," he said.

Defending against these threats was getting harder, he said, because key workers with access to the most valuable information were out and about using mobile devices far from the defences surrounding a corporate HQ.

"Smartphones and laptops have crossed the perimeter," said Mr Samani.

The report comes in the wake of a series of incidents which reveal how cyber criminals are branching out from their traditional territory of spam and viruses.

2010 saw the arrival of the Stuxnet virus which targeted industrial plant equipment and 2011 has been marked by targeted attacks on petrochemical firms, the London Stock Exchange, the European Commission and many others.

Mr Samani said that, as firms start to use cloud-based services to make data easier to get at, they had to work hard to ensure they know who can see that key corporate information.

Otherwise, he warned, in the event of a breach, companies could find themselves losing the trust of customers or attracting the attention of regulators.

"You can transfer the work but you cannot transfer the liability," said Mr Samani.

[BBC]

Monday, 14 March 2011

UK Government counts the Cost of Cybercrime

The British government has released a report on the annual cost of cybercrime to the United Kingdom. The study mechanism seems greatly flawed, in that it relies almost exclusively on published reports and expert opinions, rather than on any structured gathering of information from victims.

The news was announced in the press this week, for example in the Independent.

They came up with a 2010 annual cost of cyber crime of £27 billion (or $ 43 billion US Dollars). If the costs were projected evenly from the $ 2.2 trillion UK economy to the $ 14.1 trillion US economy, that would estimate our own costs of cybercrime at $ 275 billion (roughly 6.4 times larger economy.) There is no basis to believe that projection is accurate, but the scale is probably similar.

The study was paid for by the OCSIA, the Office of Cyber Security and Information Assurance. It was conducted by Detica, a BAE Systems company.

The full 32 page report is available from the Cabinet Office

They place costs at:
£3.1 billion to citizens with
£1.7 billion in Identity Theft
£1.4 billion to online scams.
£2.2 billion to the government
£21 billion businesses of which:
£9.2 billion in Intellectual Property theft
£7.6 billion in industrial espionage
£2.2 billion in extortion
£1.3 billion from direct theft
£1 billion in costs related to lost customer data

The Intellectual Property theft was certainly not evenly distributed. They put the most likely industries as:
£1.8 billion = pharmaceuticals & biotech
£1.7 billion = electronic & electrical material
£1.6 billion = software & computer services
£1.3 billion = chemicals
£800 million = automobiles & parts
£800 million = non-profits
£400 million = aerospace & defence

The greatest risk in Intellectual Property theft was believed to be untrustworthy insiders who fell to the pressure of bribery.

The Espionage Impact was largely in three areas:
£2.1 billion = financial services
£1.6 billion = mining
£1.3 billion = aerospace and defence
£900 million = software & computer services      

[GaryWarner] via [ComputerSecurityArticles]

Friday, 4 March 2011

Renault says espionage claim may not be true

A senior Renault executive has for the first time cast doubt on claims the French carmaker was the victim of industrial espionage.

In an interview with Le Figaro, chief operating officer Patrick Pelata said Renault may have been tricked into believing it was the target of spying.

Three executives were sacked and China issued an angry denial amid a whirlwind of allegations about the affair.

Mr Pelata said "a certain number of elements lead us to doubt" the claims.

The issue risks becoming a huge embarrassment for Renault, observers said, and on Friday French finance minister Christine Lagarde weighed into the row.

She told radio station RMC that "what counts today is getting to the truth and getting there quickly, and if the suspicions were unfounded that justice be done, confidence restored and compensation paid".

In January, Renault fired three executives and lodged a legal complaint over suspicions that information about its electric vehicle programme had been passed to a foreign power.

While no country was named, the French media pointed the finger at China, prompting a categorical denial from Beijing.

On Thursday, after unnamed sources were quoted in the French media that investigators had found no evidence, Renault's lawyer said that the intelligence services were still probing the existence of bank accounts in Switzerland and Liechtenstein.

In the Le Figaro interview on Friday, Mr Pelata said Renault had arrived at "two hypotheses".

He said: "Either we are confronted with a case of espionage and a senior security executive is protecting his source despite everything. Or Renault is the victim of a manipulation, which we don't know the nature of, but which could be a fraud.

"In this case, if all the doubts are lifted, we will propose the reinstatement of the three executives and, in any case, Renault will be very careful to make good any injustice."

The three sacked executives have vehemently denied any wrong-doing.

[BBC]