Showing posts with label cybercrime. Show all posts
Showing posts with label cybercrime. Show all posts

Saturday, 10 September 2011

Ethical hackers battle to prevent 'information security apocalypse'





(CNN) -- Barely a day passes without news of another major computer security breach. Last week a hacking network named "Hollywood Leaks" began their attack on the personal data of celebrities, officially adding the glitterati to a roll of shame that already includes targets as diffuse as Sony, the Church of Scientology and PayPal.

However only a few days before the emergence of this latest hacking outfit, a far less conspicuous but similarly-skilled group met at a London hotel to discuss the other side of all matters of information security, otherwise known as "infosec".

The inaugural 44Con was Britain's first major conference for the good guys of infosec. Among the 300 delegates and speakers were a number of so-called "white hats", programmers and penetration testers specifically employed to discover businesses' weak spots.

Using information from these ethical hackers, manufacturers can remedy or "patch" the problem before its release and companies can take measures to safeguard their data.

Everybody had a look at the Sony thing and thought, 'Oh God, I hope I'm not next.'
Steve Lord, foudner 44Con

Although their more destructive brethren might continue to grab headlines, 44Con demonstrated that the fight against hackers, and other more traditional threats to information security, is also strong.

"The way people use and consume media and share information has drastically changed over the past ten years," said Steve Lord, a security professional and co-founder of 44Con.

"The information that we used to think would stay on a computer, in an increasingly networked world, it goes everywhere. So there is an increasing demand for people to secure that information because otherwise people won't put it there."

44Con attracted representatives from governments and members of the military, alongside risk managers, consultants and students. According to Lord, the roll call included "hackers, freaks, geeks, spooks and kooks," none of whom was required to identify themselves further than a first name.

"It's everyone around the table all looking at the same problems and hopefully coming up with some solutions," Lord said.

High-profile hacking is only one strand of the ongoing battle to protect electronic information from damage or infiltration.

Events at 44Con ran the gamut from workshops demonstrating old-fashioned lock-picking with a paperclip, through discussions of threats to iPads and smart phones and even a presentation of how NASA's transmissions to astronauts have recently been intercepted.

"We've got a serious problem here... like the global financial crisis," said Haroon Meer, a researcher at the infosec consultancy, Thinkst. But although Meer also referred to "our upcoming security apocalypse", others were focused on how intelligence can be used to predict attacks before they occur and, crucially, how to acquire boardroom backing for improved security measures.

We've got a serious problem here... like the global financial crisis.
Haroon Meer, infosec consultant

Infosec professionals often converse in a language that is not always immediately accessible to a layman (executives included), but the result of their endeavors can often be startlingly clear.

"Every single guy at boardroom level that I speak to says, 'Are we going to be the next Sony?'" said Lord, referring to the recent devastating hack on the electronics giant. "Everybody had a look at the Sony thing and thought, 'Oh God, I hope I'm not next.'"

Sony given 'epic fail' award from hackers

Several presentations at 44Con offered chilling demonstrations of the vulnerabilities of common business devices. Alex Plaskett, a consultant at MWR InfoSecurity, who described himself as someone who has been "professionally breaking things" for many years, performed a so-called "drive-by" exploit on a Windows 7 smart phone.

Independent security consultant, Neil Kettle, performed a take-down of the much garlanded online banking security software Trusteer Rapport, running a key-logging program that replicated on screen anything a user might be entering into supposedly secure password fields.

Another security expert Roelof Temmingh showcased the most recent version of Maltego, software that analyzes and compares freely available information from numerous social networking sites.

Using the website of the Executive Office of the President as an example, Temmingh was able to extract specific information such as favored restaurants among White House staffers, as well as other behavioral trends.

"Even if we don't want to attack, what can we learn?" Temmingh asked, before revealing that at least one member of the Bush administration was a fan of Moody's Diner, visited a psychic medium named "Rosemary the Celtic Lady" and was a keen editor of Wikipedia pages.

The examples were deliberately banal and outdated, but the implication was clear. Through similar paths, hackers of more nefarious intentions could determine what versions of browsers are being used in the White House, for instance, and probe specific vulnerabilities. "If you can exploit the browser of a leader, then you've exploited the PC of a president," Temmingh warned.

However it was left to Alexis Conran, a former confidence trickster who appeared in a British TV show called "The Real Hustle", to sum up the challenges still faced by the infosec sector.

"The general public will only take steps to protect themselves if they know what the dangers are," he said.

[CNN]

Cybercrooks prey on 9/11 anniversary

Malware, 'commemorative coin' auctions and fake charity donation



Cybercrooks are gearing up for the 10th anniversary of the 9/11 attacks with a range of malware traps and hacking attempts both on social networks and the wider internet, net security firm BitDefender warns.

The first wave of these attacks comes in the form of the newly established websites offering supposed content such as "Bin Laden alive", "in depth details about the terrorist attack", "police investigation results" and "towers going down" to attract the curious.
The sites are filed with links to scareware and phishing sites. Others have created fraudulent charity donation sites that serve only to line their greedy pockets at the expense of genuine gift-giving sites.

In addition, fraudsters are running fake auctions and sales of items supposedly linked to the devastating attacks such as shards of metal from the twin tower or even "commemorative coins" supposedly minted from silver collected at the attack site.

More scam, perhaps involving malware, can be expected to follow over the coming days.

“Because of the advancement of hacking and spamming technology over the past decade, plus the significance of the anniversary and increased media coverage, Sept 11 this year may prove hectic on the malware front,” said Catalin Cosoi, head of the Online Threats Lab at Bitdefender.

BitDefender says many of the scams likely to be on show are similar to those seen during anniversaries of the London bombings of July 2005.

Cybercrooks marked remembrances of the 7/7 attacks with fake donation requests, spamming of viruses disguised as supposed videos of the assaults and advanced fee fraud email scams. ®

[TheRegister]

People Who Get Malware Also Get Mugged More Than Usual


Our Lifehacker AU comrades point out this interesting fact from Norton's latest Cybercrime report: People who fall victim to malware are statistically more likely to be mugged in real life too. Interesting.
The obvious caveat is that correlation doesn't imply causation, but it is a bit telling to see that these two statistics are linked. Could it be that people who aren't careful online—because honestly, that's what falling victim to malware is—aren't careful in meatspace either?
Norton's internet safety advocate agrees, and says "Clearly these people aren't taking enough care in their real-world interactions and it carries over in their online world." Just think about people you know and how careful they are in their everyday dealings with other people. The more guarded or suspicious you are, the less likely you are to hand over your personal information to a shady site or click a link or open an attachment you're not sure about.
Norton Cybercrime Report (PDF) via [Lifehacker]

Wednesday, 7 September 2011

Cyber crime now bigger than the drugs trade


The global cost of cybercrime is greater than the combined effect on the global economy of trafficking in marijuana, heroin and cocaine, which is estimated at $388bn, a new headline-grabbing study reported.

The Norton Cybercrime Report puts the straight-up financial costs of cyberattacks worldwide at $114bn, with time lost dealing with the crime adding the remaining $274bn, while the global black market in the three drugs costs $288bn.
Every second, 14 adults become the victim of some sort of cybercaper, adding up to over a million victims every day, the report from Norton-maker Symantec said, with young men who access the web on their mobiles the most likely victims.

But despite the large number of victims, people aren't doing enough to stop it for themselves. Although 74 per cent of people say they're aware of cybercrime, 41 per cent of them don't have up-to-date security software and 61 per cent don't use complex, regularly-changing passwords.

“There is a serious disconnect in how people view the threat of cybercrime,” said Adam Palmer, Norton's lead cybersecurity advisor. "Over the past 12 months, three times as many adults surveyed have suffered from online crime versus offline crime, yet less than a third of respondents think they are more likely to become a victim of cybercrime than physical world crime in the next year."

The most common cybercrime issues are malware and viruses, which have affected 54 percent of those surveyed, with online scams second (11 per cent), and phishing catching 10 per cent of adults out.

Cyber-villainy is also on the up on phones, with 10 per cent of adults having been victims of an attack on their mobile, according to the study. The study surveyed almost 20,000 people in 24 countries. ®

[The Register]

Tuesday, 12 April 2011

Corrupt bank worker jailed over Trojan-powered tax scam

A former local business manager at a bank who participated in a £3.2m self assessment tax fraud was jailed for three years and three months on Friday.

Nikola Novakovic, 34, conspired with Oleg Rozputnii, 28, to register over 1,050 fictitious taxpayers on the Income Tax Self Assessment system. The pair claimed fraudulent tax refunds under assumed names before laundering the proceeds of the scam via 200 fraudulent bank accounts.

Personal details needed to pull off the racket were extracted from the computers of consumers using an unspecified computer virus. Rozputnii, an illegal immigrant from the Ukraine, used numerous false identities to help commit the fraud, which also involved Dmytro Shepel, 26, a Ukrainian, also from London.

Joe Rawbone, assistant director of HMRC Criminal Investigation, said: "These men ran an audacious scam stealing millions of pounds. They set up hundreds of false bank accounts using viruses to hack into personal computers to gain information. They used their illegal profits to fund lavish lifestyles, buying performance cars including Porches, Mercedes and Jaguars. HMRC takes tax fraud extremely seriously and we will recover any financial gain from this criminal activity."

The scam netted £3.2m between January 2008 and September 2010 when the racket was uncovered following a lengthy investigation by HM Revenue & Customs (HMRC).

Sentencing, Mr Recorder Singh QC said that Novakovic "had abused his position with the bank" as part of a "sophisticated and orchestrated fraud".

Novakovic and Rozputnii pleaded guilty to cheating the public revenue in March. Rozputnii, the main mover behind the scam, was jailed for three years and nine months on Friday. Shepel was sentenced to three-and-a-half years at an earlier hearing in August 2010.

Pictures of the subjects and their cars can be found in a HMRC statement on the case here. ®

[TheRegister]

Wednesday, 23 March 2011

The Seven Deadly Sins of Cybercrime Victims

Like athletes and chess players, cybercriminals are skilled at identifying their targets’ weak points.
Today’s increasingly online and social world offers a host of techniques for preying on potential victims and their weaknesses.
Following are seven weaknesses that you need to watch out for to avoid falling prey to these scams — whether they take the form of emails, social networking chats, or phone calls.
  • Lust: Scammers try to tempt users into action by masquerading as an attractive man or woman, particularly on social networks. You should assume that a flirtatious advance from someone you don’t know has a less-romantic purpose behind it.
  • Greed: Like the adage says, “If something is too good to be true, it probably is.” If you receive a free iPod offer, or a percentage of a Nigerian wire transfer, resist the urge to make a deal.
  • Vanity: Scammers often try to convince potential victims that they have been chosen, that they’re winners, or that they are somehow part of a select group on the receiving end of an exclusive offer. As harsh as it may sound, you should assume you’re not that special.
  • Misplaced Trust: In some scams, cybercriminals attempt to convince you that they represent a high-profile brand and therefore can be trusted. Other times, scammers pretend to be a “friend of a friend” so that your trust for your friend extends to this unknown person. Question any message or phone call that plays on a trust relationship.
  • Sloth: Criminals rely on our laziness to ensure that poorly written messages and shortened URLs don’t rouse suspicion. For instance, many users will click on a link in an email from their “bank”, instead of calling the bank or visiting the bank’s website to determine if the email is legitimate.
  • Excess Compassion: In 2009, one of the most successful scams on Facebook involved criminals hijacking users’ accounts, then posting status updates claiming that the account holder was stranded somewhere and needed money. Many kindhearted people fell for this ploy. Other similar scams involve requesting donations to nonexistent nonprofits when a major disaster occurs, such as the earthquake in Haiti. Maintain a high level of skepticism toward these types of messages.
  • Urgency: Hand-in-hand with compassionate pleas are scams that insist on a fast response and tell you to “act now” or “time is running out.” Double-check these requests with the sender or a colleague, and don’t feel pressured to respond immediately.
Excerpted and adapted from the Cisco 2010 Annual Security Report


[InfoSecIsland]

Monday, 21 March 2011

CSIS expert lists worst cyber security breaches since January 2010

According to Bank Info Security, testimony was given before the House Homeland Security Committee last week by James Lewis, senior fellow at the Center for Strategic and International Studies (CSIS).

Lewis's testimony included a list of serious security incidents that have taken place since January 2010.

This list is reproduced below, with thanks to Bank Info Security.

Lewis is reported to have stated that the list "is not a record of success". He added "Whatever we are doing is not working...While individual government agencies have made strenuous efforts to improve our cyberdefenses, as a nation, despite all the talk, we are still not serious about cybersecurity."

This looks really rather damning of today's security infrastructure. But, I can't help but wonder how many cyber attacks weren't successful, thanks to the security that is place today? While I would agree that no one should rest on their laurels when it comes to security, I also know that there is no silver bullet.

I wonder if Lewis will also be providing advice on what needs to be done to help better secure against attacks. No one wants to be a victim, and most companies out there are doing what they can to stave off attacks.
January 2010: Google announced that an attack had penetrated its networks, along with the networks of more than 80 other US high-tech companies. The goal of the penetrations, which Google ascribed to China, were to collect technology, gain access to activist G-mail accounts and to Google's password management system. 
January 2010: At the same time, Intel experienced a harmful cyberattack. 
January 2010: Global financial services firm Morgan Stanley experienced a "very sensitive" break-in to its network by the same hackers who attacked Google, according to leaked e-mails. 
March 2010: A number of successful cyberattacks against NATO and European Union networks have increased significantly over the past 12 months, the international organizations revealed. 
March 2010: Australian authorities say there were more than 200 attempts to hack into the networks of the legal defense team for executives from Australian energy company Rio Tinto, to gain inside information on the trial defense strategy. 
April 2010: Hackers break into classified systems at the Indian Defense Ministry and Indian embassies around the world, gaining access to Indian defense and armament planning.
May 2010: A leaked memo from the Canadian Security and Intelligence Service says, "Compromises of computer and combinations networks of the government of Canada, Canadian universities, private companies and individual customer networks have increased substantially. ... In addition to being virtually unattributable, these remotely operated attacks offer a productive, secure and low-risk means to conduct espionage."
October 2010: Stuxnet, a complex piece of malware designed to interfere with Siemens industrial control systems discovered in Iran, Indonesia and elsewhere, results in significant physical damage to the Iranian nuclear program. 
October 2010: The Wall Street Journal reports that hackers using Zeus malware, available in cybercrime black markets for about $1,200, were able to steal over $12 million from five banks in the United States and Britain. 
December 2010: British Foreign Minister William Hague reported last month attacks by a foreign power on the British Foreign Ministry, a defense contractor and other British interests. The attack succeeded by pretending to come from the White House. 
January 2011: The Canadian government reports a major cyberintrusion involving the Defense Research and Development Canada, a research agency for the departments of National Defense Finance and the Treasury Board, Canada's main economic agencies. The intrusions forced the Finance Department and the Treasury Board to disconnect from the Internet. 
March 2011: Hackers penetrate French government computer networks in search of sensitive information on upcoming G-20 meetings. 
March 2011: South Korea said that foreign hackers penetrated its defense networks in an attempt to steal information on the American-made Global Hawk unmanned aircraft, provided to Korea as it considers whether to buy the aircraft.
CSIS experts conduct research and analysis and develop policy initiatives grouped under three themes: defense and security policy, global trends, and world regions. James Andrew Lewis focuses on technology, national security, and the international economy. Before joining CSIS, he worked in the federal government as a foreign service officer and as a member of the senior executive service. His assignments involved Asian regional security, military intervention and insurgency, conventional arms negotiations, technology transfer, sanctions, Internet policy, and military space programs.

[NakedSecurity]

Sunday, 20 March 2011

A Good Decade for Cyber Crime

Cybercrime is one of the most successful and lucrative industries of our time, growing by double digits year after year.

Over the last decade, cyber crooks have developed new and sophisticated ways to prey on an explosion of Internet users, with little danger of being caught.

Meanwhile, consumers face greater risks to their money and information each year.

A few famous exploits illustrate different eras of cybercrime:


“I Love You” worm’s false affection: $15 billion estimated damage
Emails with the subject line “I love you” proved irresistible in 2000. Millions of users downloaded the attached file, which was supposedly a love letter but was actually a virus. This infamous worm cost companies and government agencies $15 billion.


MyDoom’s mass infection: $38 billion estimated damage

This fast-moving worm, which first struck in 2004, tops McAfee’s list in terms of monetary damage. It delivered enough spam to slow global Internet access by 10% and reduce access to some websites by 50%, costing billions of dollars in lost productivity and online sales.


Conficker’s stealthy destruction: $9.1 billion estimated damage

This 2008 worm infected millions of computers. It went a step further than the other two worms on our list, downloading and installing a variety of malware that gave hackers remote control over victims’ PCs.
Some of the most common and nefarious scams include:


Fake antivirus software

Selling fake antivirus software is one of the most insidious and successful scams in recent years.
Cyber criminals play on users’ fears that their computers and information are at risk, displaying misleading pop-ups that prompt the victim to purchase antivirus software to fix the problem.
When victims enter their credit card information, it is stolen and, instead of security software, they wind up downloading malware.


Phishing scams

Phishing, or trying to trick users into giving up personal information, is one of the most common and persistent online threats. Phishing messages can come in the form of spam emails, spam instant messages, fake friend requests, or social networking posts.


Phony websites

In recent years, cyber crooks have become adept at creating fake websites that look like the real deal.
From phony online banking to auction sites and e-commerce pages, hackers lay traps in the hopes that you will be fooled into entering your credit card number or personal information.

For your own peace of mind, consider subscribing to an identity theft protection service such as McAfee Identity Protection, which offers proactive identity surveillance, lost wallet protection, alerts when suspicious activity is detected on your accounts, and access to fraud resolution agents. For additional tips, visit CounterIdentityTheft.com.


Robert Siciliano is a McAfee consultant and identity theft expert. See him explain how to protect yourself from identity theft on CounterIdentityTheft.com. (Disclosures)

[InfoSecIsland]

Inside the Cybercrime Underworld: 100 Billion Spam E-Mails a Month

American and German researchers who infiltrated and crippled one of the world’s biggest spam-producing networks last summer have released a formal paper on the experience, and the numbers are staggering.

The Pushdo/Cutwail “botnet” sent out 1.7 trillion e-mails over 15 months (about 113 billion per month), had 100,000 enslaved “bots” around the world and had about 30 command-and-control servers in

Europe, North America and Russia.

Its Russian cybercriminal operators bought and sold e-mail addresses by the million and compromised PCs by the thousand, with lower prices for less-desirable countries and volume purchases.

[Read the original research paper here (PDF).]

"The interesting things were just the amount of spam that they were sending and how they operate like a professional business, with detailed statistics and error reporting,” Brett Stone-Gross, one of the researchers and a doctoral candidate at the University of California, Santa Barbara, told Kaspersky Lab’s ThreatPost blog. “This is a real business."

The 16 Pushdo/Cutwail servers that the researchers were able to access contained 2.35 terabytes of data, 24 databases full of details about operations and billions of target e-mail addresses.

The researchers estimate that the botnet’s operators have earned between $1.7 million and $4.2 million since June 2009.

Even one sub-botnet — Pushdo/Cutwail was divided into several domains, each under the control of one gang member — was able to pump out 87.7 billion e-mails in the four weeks between July 30 and August 25, 2010.

"I was most surprised by the sheer number of e-mails sent by this one botnet," another researcher, Thorsten Holz of Ruhr-University Bochum in Germany and Lastline, Inc., in Santa Barbara, told UBM TechWeb’s Dark Reading blog. "It turns out this one botnet sent out billions of spam messages."

Symantec Labs estimated last year that 89 percent of all e-mails are spam.


Takedown

The research team got service providers to pull the plug last summer on about 20 of Pushdo/Cutwail’s 30 command-and-control servers. (The other service providers refused.) The botnet was crippled for several months.

Botnets are illicit networks of computers that have been enslaved by malware, which burrows deep into their operating systems and opens “backdoors” that allow control by remote operators, or “bot herders.”
Malware infection usually happens when a user opens a compromised e-mail attachment (a Trojan) or visits a compromised website (a drive-by download).

The bots, ordinary machines scattered across the globe whose users have no idea they are infected, are used to send out spam touting Viagra and pornography, phishing e-mails and Trojans to harvest more bots.

Almost 40 percent of Pushto/Cutwail’s bots were in India, Holz and his colleagues found. Other countries’ shares were far lower; Australia came in second, comprising 9 percent of the compromised PCs.

Holz and his colleagues also got an archived copy of Spamdot.biz, an online forum used by botnet operators for communication and trade, which provided a fascinating look into the world of mid-level cybercriminals.

More than 90 percent of the posts on Spamdot.biz were in Russian, and less than 9 percent in English. It had nearly 2,000 registered members, who had to be recommended by at least two other existing members to be accepted.

E-mail addresses were bought and sold in blocks of a million, with prices ranging from $25 to $50 per block depending on geographical location, status (free Web-based e-mail services such as Gmail or Hotmail were cheaper) and volume.

Specialized groups sold services, such as infecting new batches of computers with the client’s malware. These sold in blocks of 1,000, with prices ranging from $13 for Asian computers to $125 for PCs based in the United States.


Top-notch software

The software used by the Pushdo/Cutwail botnet was remarkably sophisticated. Each server running Cutwail, the spam engine, constantly tested its messages against a built-in copy of the SpamAssassin e-mail filter.

Pushdo, the Trojan used for command and control, used a proprietary, and often encrypted, communications protocol to direct its bots.

Despite the technological efforts and the sheer volume of spam sent out, only 30 percent of Pushdo/Cutwail’s e-mails ever reached their target servers, the researchers estimate. Half went to invalid addresses, and nearly 17 percent were blacklisted.

"That's quite a big loss," Holz told DarkReading. "And even if the mail is received by the targeted mail server, with filtering and SpamAssassin a large chunk of that 30 percent gets filtered and doesn't necessarily reach the inbox of the user."

Still, having all this information isn’t much of a victory in the fight against spammers.

Pushdo/Cutwail has been rebuilt since last summer and is now back up to its pre-takedown size of about 100,000 bots. It’s the second-largest botnet in the world; the Rustock botnet has an estimated 250,000 enslaved PCs.

How can you prevent your computer from being enslaved by a botnet? No method is foolproof, but your odds of infection drop dramatically if you do two things: Don’t open any unrequested e-mail attachments, even those from friends; and install and constantly update and run anti-virus software, even if you’re using a Mac.

Using a Mac instead of a Windows PC also does help, at least for now. Macs are not immune from infection and a few Mac Trojans have been found in the wild, but Apple’s PC market share is still so small that most cybercriminals don’t bother writing malware for it.

[SecurityNewsDaily]

Monday, 14 March 2011

UK Government counts the Cost of Cybercrime

The British government has released a report on the annual cost of cybercrime to the United Kingdom. The study mechanism seems greatly flawed, in that it relies almost exclusively on published reports and expert opinions, rather than on any structured gathering of information from victims.

The news was announced in the press this week, for example in the Independent.

They came up with a 2010 annual cost of cyber crime of £27 billion (or $ 43 billion US Dollars). If the costs were projected evenly from the $ 2.2 trillion UK economy to the $ 14.1 trillion US economy, that would estimate our own costs of cybercrime at $ 275 billion (roughly 6.4 times larger economy.) There is no basis to believe that projection is accurate, but the scale is probably similar.

The study was paid for by the OCSIA, the Office of Cyber Security and Information Assurance. It was conducted by Detica, a BAE Systems company.

The full 32 page report is available from the Cabinet Office

They place costs at:
£3.1 billion to citizens with
£1.7 billion in Identity Theft
£1.4 billion to online scams.
£2.2 billion to the government
£21 billion businesses of which:
£9.2 billion in Intellectual Property theft
£7.6 billion in industrial espionage
£2.2 billion in extortion
£1.3 billion from direct theft
£1 billion in costs related to lost customer data

The Intellectual Property theft was certainly not evenly distributed. They put the most likely industries as:
£1.8 billion = pharmaceuticals & biotech
£1.7 billion = electronic & electrical material
£1.6 billion = software & computer services
£1.3 billion = chemicals
£800 million = automobiles & parts
£800 million = non-profits
£400 million = aerospace & defence

The greatest risk in Intellectual Property theft was believed to be untrustworthy insiders who fell to the pressure of bribery.

The Espionage Impact was largely in three areas:
£2.1 billion = financial services
£1.6 billion = mining
£1.3 billion = aerospace and defence
£900 million = software & computer services      

[GaryWarner] via [ComputerSecurityArticles]

Wednesday, 9 March 2011

Barracuda study shows sharp rise in search engine malware, Twitter crime rate

Search engine malware more than doubled in 2010 and the crime rate on Twitter increased 20%, as cybercriminals continue to sharpen their focus and aim attacks at social networking services, according to a new report from Barracuda Networks.


If you're just randomly searching for a trending topic, your chances of getting malware are significantly increased on Twitter.
Daniel Peck,
research scientist
A 2010 study of search engine malware over a 153-day period found that 1 in 5 search topics are connected to malware. The study was highlighted in the Barracuda Labs 2010 Annual Security Report, which found more than 34,000 malware samples over the monitoring period.

Google served up the lion's share of malware-poisoned results (38%), followed by Yahoo (30%), and Microsoft's search engine, Bing, served up 24% of malware during the testing period. Barracuda said its study found malware writers distributing the malicious code more evenly among the search engines. Google began making strides last year, combing through millions of webpages to reduce search engine malware. While Google served up 69% of malware last June, that number decreased 45% by the end of the year.

For example, when LeBron James left Cleveland to play for the Miami Heat in July, trending links on the first page of Google contained rogue antivirus in the first five results, said Daniel Peck, a research scientist who has been studying search engine poisoning and cybercrime on social networks. "If you get there, it's a pretty good chance you're going to be successful," Peck said.

In addition, Barracuda found popular social network site Twitter serving up 8% of malware during the study, evidence that attackers are continually trying to game the system by spreading malware laden links before Twitter's antimalware engines can detect a problem. In a presentation at SecTor security conference in Toronto last year, Fabrice Jaubert of the Google antimalware team said the company continually deploys more technology and people into the process of weeding out malware, but called it a typical cat-and-mouse game, in which savvy cybercriminals find ways to avoid detection.

Barracuda has been analyzing 26 million Twitter accounts for more than two years, and is finding a steady rise in malicious content, Peck said.

Twitter is becoming a victim of its own success, he said. As users are becoming more active, malicious activity also increases, he said. In 2010, the Twitter crime rate (the number of suspended accounts) increased from 1.6% to 2% (20%) from the first half of 2010 to the second half of 2010.

"If you're just randomly searching for a trending topic, your chances of getting malware are significantly increased on Twitter," Peck said, adding that attackers are using many of the same techniques they use on search engine poisoning campaigns.

In addition to shortened URLs, Barracuda cited hijacked accounts as another concern and the ability of attackers to use automated tools to quickly set up fraudulent accounts and spam users of Twitter based on their tweets. Attackers used the NeoSpoloit exploit kit, redirecting users with shortened URLs to poisoned websites. Many of the sites served up rogue antivirus, Barracuda said.

Twitter has been making strides with security, Peck said. The social network had admitted to the Federal Trade Commission that serious security lapses resulted in the hijacking of many high-profile accounts.
The social networking service agreed to periodic third-party reviews of its security program over the next decade. Since then the service has deployed malware analysis engines and is fairly quick to suspend suspicious accounts, Peck said. In September, Twitter began forcing third-party applications using its APIs to use OAuth, a more secure protocol that uses tokens to better protect usernames and passwords, preventing the potential for account hijacking.

"It's kind of like giving someone the ability to enter your house as needed without giving them your full set of keys," said Paul Judge, chief research officer of Campbell, Calif.-based Barracuda Networks Inc.
Judge said the increased security is welcome, but a lot of Twitter accounts are still tied to weak passwords. Some cybercriminals are just guessing the passwords, Judge said. People are also using passwords that they share across different accounts. When the account credentials of as many as 1.3 million users of Gawker websites were stolen by cybercriminals in December, a few days later a large amount of Twitter accounts were hijacked, Judge said.

Judge said password management is getting better, but password managers need better integration with operating systems and browsers to get the human element out of remembering passwords. Peck said two-factor authentication, which is being rolled out with some Google products, could eventually find its way into some social networks.

[Search Security]

Cyber crime economy – the Spammer side

Not just the people infecting PCs with malware want to earn money – the spammers want their share, too. The most obvious way to earn money for them is of course when people buy the advertised products – fake Viagra, watches, pirated software and so on. But for the spammers there are also affiliate programmes which generate revenue for them.

The affiliate programmes the spammers use work by redirecting traffic to their website; they pay money for visitors redirected to them. It is not the first time that we see this happening as we’ve seen spam for Google Adwords and a “business” model similar to this one, but the whole deal has to be really worth the trouble in order to go and use this method of producing traffic.

The emails the spammers sent this time use social engineering tactics to create psychological pressure and make the recipients click the link.



To be honest, I clicked on that URL (in a VM) concerned that it might drop a Trojan or perform some malicious action. To my surprise, it did not. It opened an intermediate website instead – which is a URL shortener that opened yet another site.



The last website opened was Amazon.de (.de and not .com) and not a random page, but a page advertising an iPhone 3GS sold by Notebook.de.



I don’t know if there is a connection between the spam campaign and the website Notebook.de (which to my knowledge is a clean and respected website).

How this business works gets clear when visiting the URL shortener itself: Register a shortened website and get paid for visitors. But how does the business model work in this case? Well, if you look at the screenshot, you can see a big yellow button with words “SKIP AD”. If you click there, you are redirected to some survey websites which make money with the user’s feedback.



What you can also see is that if you want your website advertised you pay $ 5 for 10.000 visitors. Let’s make a basic ROI calculation for the owners of the URL shortener: According to the text in the blue rectangle, $ 4 are paid for 1000 visitors. Thus for $ 5 the “customer” needs to redirect 1250 visitors.

According to the URL Shortener’s advertisement, they get paid $ 5 for 10.000 visitors but they pay $ 5 for 1250 visitors. This doesn’t sound very smart for a business as obviously they pay more money than they get.

Is the spammer smarter than the company behind the URL shortener? Assuming the spammer gets $ 5 for 1250 visits, and only 1 of 100 recipients of the email clicks onto the link in the mail (or the other 99 emails were blocked), he would have to send 125.000 emails in order to get paid $ 5. Among security experts it is assumed that spammers pay between $ 0.0001 and $ 0.001 (0.01 – 0.1 cents) per email sent.

Thus the spammer would need to pay between $ 1.25 and $ 12.50 to send this amount of emails. So the return of investment is only positive when the cost of sending a spam mail is low (around $ 0.0001 / email).

I don’t know how the spammers really end up, but since we received this email in our inboxes I assume that the ROI is positive for both, the spammers and for the URL shortener service.

I have a problem with this kind of advertisement-links – there is not much to block! I mean, we can’t block bit.ly, we can’t block the URL shortener which pays the $ 4 for 1000 visitors, and we definitely can’t block amazon.de. All I could do was to report the bit.ly shortcut from the email to bit.ly and hope it will be blocked soon. Fortunately, the spam email itself is quite easy to block because it is being sent to 395 recipients at once in a mass mailing action. However, Gmail’s spam filter wasn’t able to stop it – but Avira Antispam marked it immediately with spam level “Very High”.

[ComputerSecurityArticles]

Tuesday, 8 March 2011

Nigerian 419 scammer gets 20 years in jail

Nigerian national Peter Maxson Anyanyueze has just been sentenced to 20 years in prison by the National Prosecuting Authority (NPA) at Germinston Regional Court in South Africa.

According to several media reports, Anyanyueze received the following sentence: ten years for fraud, ten years for money laundering, and two additional years, which will run concurrently, for contravention of the Immigration act.

The scam seems fairly typical: Anyanyueze sent out emails requesting help to manage his cash. The scammer claimed he earned 10.5 million bucks from precious metal sales. His millions, he claimed in the email, were being held in a security company in South Africa, and he needed a third-party to move it out and invest it in Europe.

Saudi Arabian Dr Abdulazziz Alheiraqi Nwasser received this scam email and responded, probably thinking this sounded like a solid investment opportunity.

Instead of transferring the money into Nwasser's account, the scammer requested that he make small payments into nominated bank accounts, based in different countries around the globe.

Nwasser did just that, to the tune of almost $300,000!

I don't know about you, but it doesn't seem like a small amount of money. In any case, Anyanyueze never deposited the millions, so our victim Nwasser found himself seriously out of pocket.

So, what can we learn about this?

First, there is nothing really new here. Scams, where someone tries to dupe another, have been around as long as humans have. 419 scams simply take advantage of people though emails that try to pique recipients' greed or pity. The goal is always money, though that is not always immediately obvious.

If you don't know the person who has emailed you, and/or the email is promising riches for some small investment on your part, go on high alert. The simplest approach is to delete it, though you may also want to report it to your ISP so they can look into blocking these emails in future. Do not respond. You will only be confirming the validity of your email address to an unknown and probably dodgy third party.

***

Quite interesting side fact #1
According to Nigerian-law.org, it seems the Advance Fee Fraud act was established in 2006, three years after Anyanyueze was accused of doing this scam. He was however arrested in 2007, a year after the act was put in place. Hmmmm....

Quite interesting side fact #2
According to this report, the National Prosecuting Authority (NPA) spokesperson
"revealed Anyanyueze had fraudulently entered into a marriage of convenience with a female South African to obtain citizenship. 'The state proved in court that the accused and the female person were never in a bona fide spousal or marital relationship, as the female was living with her South African boyfriend with whom she had a child at the time of the said marriage.'"
As a result of this, they tapped on two extra years to his sentence, which he can serve concurrently with the other twenty.

[NakedSecurity]

10 scammers charged with running 419 scam

Ten people were arrested and are now facing charges of wire fraud in US federal court following a successful investigation that has them pegged as perpetrators of an advanced fee scam.



The ten are allegedly all part of the same gang that took advantage of the gullibility of their victims and convinced them to send modest - and not so modest - amounts of money in order to expedite the settlement of a huge inheritance in their name.

Usually dubbed "Nigerian" or "419" scam, it involves scammers posing as government officials or attorneys who are in charge of finding the heirs of wealthy people and settling the disbursement of munificent inheritances. The victims are taken in by their own greed and naiveté.

25-year-old Claudio Uche Dibe, of of Gardena, California, stands accused of being the ringleader of the gang and sending thousands of spam e-mails to potential victims. He is charged with 15 counts of wire fraud, as are 25-year-olds Bright Amesi, of Gardena, and Briceson Loving, of Lawndale. All three of them have been charged and plead not guilty to the charges.

Of the remaining seven, four have plead not guilty, and three are still waiting to be arraigned. All seven are facing charges on 10 counts of wire fraud each.

Among the evidence that supports the charges is and e-mail between the scammers noting that one victim was claiming after the initial small payment that he didn't have any more money, but that the sender believed him capable of sending "big money, which is what we are all after.”

[Net-Security]

Sunday, 6 March 2011

Cyber Crime Costs Over $1 Trillion Globally?

A recent post on LinkedIn's Information Security Community piqued my attention yesterday with the following teaser for a Webinar:
As you may have read recently, Cybercrime is now costing the UK $43.5 billion and around $1 trillion globally.
The UK government report UK Cyber crime costs UKP 27BN/year published on the BBC’s website offers a top-level breakdown of the costs of cybercrime to Britain and is one of the most dubious reports I have seen recently in a long list of security-vendor and political hype around the cyber crime story.

Regardless of how badly UK businesses are hit by cybercrime, there are several extremely weak points in the work done by Detica for the UK government.

a) First  - they don’t have any empirical data on actual cybercrime events.
Given the number of variables and lack of ‘official’ data, our methodology uses a scenario- based approach.
Which is a nice way of saying
The UK government gave us some money to do a study so we put together a fancy model, put our fingers in the air and picked a number.
b) Second – reading through the report, there is a great deal of information relating to fraud of all kinds, including Stuxnet which has nothing to do with the UK cyber crime space.

Stuxnet does not seem to have put much of a dent in the Iranian nuclear weapons program although, it has given the American President even more time to hem and haw about Iranian nuclear threats.

What this tells me is that Stuxnet  has become a wakeup call for politicians to the malware threat that has existed for several years. This may be a good thing.

c) Third – the UK study did not interview a single CEO in any of the sectors they covered. This is shoddy research work, no matter how well packaged. I do not know a single CEO and CFO that cannot quantify their potential damage due to cyber crime – given a practical threat model and coached by an expert not a marketing person.

So – who pays the cost of cyber crime?

The consumer (just ask your friends, you’ll get plenty of empirical data).

Retail companies that have a credit card breach incur costs of management attention, legal and PR which can always to leveraged into marketing activities. This is rarely reported in the balance sheet as extraordinary expenses so one may assume that it is part of the cost of doing business.

Tech companies that have an IP breach is a different story and I’ve spoken about that at length on the blog. I believe that small to mid size companies are the hardest hit contrary to the claims made in the UK government study.

I would not venture a guess on total global cost of cyber crime without empirical data.

What gives me confidence that the 1 Trillion number is questionable is that it just happens to be the same number that President Obama and other leaders have used for the cost of IP theft – one could easily blame an Obama staffer for not doing her homework….

If one takes a parallel look at the world of software piracy and product counterfeiting, one sees a similar phenomenon where political and commercial organizations like the OECD and Microsoft have marketing agendas and axes to grind leading to number inflation.

I have written on the problems associated with guessing and rounding up in the area of counterfeiting here  and software piracy.

Getting back to cyber crime, using counterfeiting as a paradigm, one sees clearly that the consumer bears the brunt of the damage – whether it’s having her identity stolen and having to spend the next 6 months rebuilding her life or whether you crash on a mountain bike with fake parts and get killed.

If consumers bear the brunt of the damage, what is the best way to improve consumer data security and safety?

Certainly – not by hyping the numbers of the damage of cyber crime to big business and government. That doesn’t help the consumer.

Then – considering that rapid rollout of new and even sexier consumer devices like the iPad 2, probably not by security awareness campaigns. When one buys an iPhone or iPad, one assumes that the security is built in.

My most practical and cheapest countermeasure to cyber crime (and I will distinctly separate civilian crime from terror ) would be education starting in first grade. Just like they told you how to cross the street, we should be educating our children on open, critical thinking and not talking to strangers anywhere, not on the street and not on FB.

Regarding cyber terror – I have written at length how the Obama administration is clueless on cyber terror.

One would hope that in defense of liberty – the Americans and their allies will soon implement more offensive and more creative measures against Islamic and Iranian sponsored cyber terror than stock answers like installing host based intrusion detection on DoD PCs

[InfoSecIsland]

Friday, 4 March 2011

The Spam King is free again, claims his spamming days are over

Robert Soloway, one of the most prolific spammers whose activities earned him the nickname Spam King, has been released from prison after a little less than 4 years inside.



He is allowed to go back online, but according to his plea deal, probation officers will monitor his e-mail correspondence and which websites he visits for the next three years.

“If I send out spam e-mails, that’s a violation of my probation. End of story,” he said to Wired. “I’m being very careful. If I send out an e-mail, I’m not even going probably to CC it. I’ll send a unique e-mail to each person.”

After and estimated 10 trillion spam e-mails sent doing his "career", teaching other people to spam, selling spam packages and using botnets to spread the e-mails - and living the good life during all that time - he now lives in a modest studio apartment in Seattle and works in a print shop.

He says he learned the lesson and now wants to help businesses and consumers avoid spam. “I don’t expect anyone to trust anything I say until they see me making good,” he declared. "I would like to assist in some way by basically revealing what went on inside the cybercrime industry."

[Net-Security]

Thursday, 3 March 2011

Five online criminals sentenced in UK

        You might remember our blog post from last August, discussing an online criminal who posted his bail sheet to an online forum.

He has been convicted today in London and received four years in prison. In the same sentencing, two other males and two females were convicted to jail sentences ranging from 18 months to four years and to community service.

Scotland Yard’s release follows:

A group of young internet fraudsters who set up an online ‘criminal
forum’ which traded unlawfully obtained credit card details and tools
to commit computer offences have today been jailed for a
total of 15.5 years.

[A] Gary Paul Kelly (14.04.89 – 21 yrs) unemployed of Clively Avenue,
Clifton, Swinton, Manchester;

[B] Nicholas Webber (10.10.91 – 19 yrs) a student of Cavendish Road,
Southsea;

[C] Ryan Thomas (8.7.92 – 18 yrs) a web designer of Howard Road, Seer
Green, Beaconsfield, Herts;

[D] Shakira Ricardo (14.11.89 – 21 yrs) unemployed of Flat 13, J Shed,
Kings Road, Swansea SA1;

were sentenced today (Wednesday 2 March) for computer misuse and fraud
offences following a two-day Newton Hearing at Southwark Crown Court.
All pleaded guilty at earlier hearings.

+ [E] Samantha Worley (30.09.88 – 22 yrs) unemployed of Flat 13, J
Shed, Kings Road, Swansea SA1 was sentenced on 14 December 2010 to 200
community service for acquiring criminal property.

The gang are believed to have been responsible for the largest
English-language online cyber crime forum and were all arrested on
various dates in 2009 and 2010, following a complex investigation by
officers the Metropolitan Police Service’s Police Central e-Crime Unit
(PCeU).

During an eleven month investigation detectives uncovered evidence that
the defendants were directly involved in the global forum (used by over
8,000 members) which promoted and facilitated the electronic theft of
personal information; credit and debit card fraud; buying and selling
of personal information (including passwords and PIN numbers); the
creation and exchange of malicious computer programs (malware); the
establishment and maintenance of networks of infected personal
computers (BotNets);and tutorials offering advice on how to commit such
offences, including how to evade and frustrate law enforcement activity
and the exchange of details of vulnerable commercial sites and servers.

Founder of the forum was Webber. Having established a web site named
‘www.GhostMarket.net’, he acted as “administrator” and had overall
control of the site (meaning he was able to allow/ban members, remove
or edit their posts, and alter their status on the forum.)

An examination of the rebuilt forum and its database revealed many
thousands of data entries relating to individuals’ personal details
including names, dates of birth, bank details, passwords, paypal
accounts and social security numbers. Site members are believed to have
traded in compromised databases containing thousands of personal
details including bank account numbers, PIN numbers, passwords and
malware including the Zeus Trojan and other types of criminal software,
including credit card verification programs.

The forum included such topics as: ‘Phishing kits (post free phishing
kits and sell them)’; ‘Show off (show us your skills here)’; ‘Tutorials
(post some useful info here)’; and ‘Cardable (post sites you’ve carded
here)’. There was also advice and tutorials on various methods of
evading law enforcement, how to encode blank plastic with credit card
data, and how to hack into sites, and even recipes for controlled drugs
(crystal meth) and a tutorial on bomb making.

Members of the site communicated anonymously by the use of screen
nicknames. They were able to post messages in various forum topics on
the website and send/receive private secure messages to/from other site
members.

During the investigation detectives recovered from the defendants’
computers more than 130,000 compromised credit card numbers, which at
an estimated industry loss of £120 per card, is a potential £15.8
million financial loss in relation to card numbers alone.

On 3 November 2009 detectives arrested Kelly after executing a search
warrant at his home address. A full search of the property was
conducted, with a number of computers and mobile phones removed from
the address for examination.

It was established that Kelly had independently constructed and
distributed across the web a sophisticated Zeus malicious computer
programme which enabled him to infect and compromise over 15,000
computers in over 150 countries, harvesting from them over 4 million
lines of data ­ including huge quantities of credit card numbers and
other confidential, personal information.

Having been provided with relevant passwords by Kelly, detectives were
able to rebuild the GhostMarket forum and its database using files from
his PC.

Prior to this, on 12 October Webber and Thomas were arrested at a five
star central London hotel for using stolen credit card details to pay
for accommodation in the penthouse suite. They claimed to have
responded to an online advert, saying they had paid money to an
anonymous individual.

Bailed to return whilst officers conducted further inquiries, items
including their laptops were seized. In addition they were found to be
in possession of business cards brandishing the ‘GhostMarket’ logo,
advertising it as “A new era in virtual marketing” with the byline
“I’m a carder, ask about me…”

The duo’s involvement in the ‘GhostMarket’ criminal forum was soon
established and inquiries were made to trace them after they fail to
return on bail in relation to the stolen credit card offence.

It was later discovered that on 31 October the pair had flown out to
Palma, Majorca, where they had been living in a rented flat in Port
D’andrax.

On 29 January 2010 they were arrested at Gatwick Airport as they flew
in from Palma.

The following day a search of Webber’s home address revealed a computer
containing a series of files outlining a step-by-step guide to
committing various criminal offences.

Owing to the volume of evidence to be examined and the complexities of
the case, the pair were released on police bail to return at a later
date.

Officers subsequently travelled to Spain and, accompanied by Spanish
Police, attended the flat Thomas and Webber had rented out. The
property was empty, but local enquiries established that the contents
had been posted back to their UK addresses.

Those items, as well as additional computer equipment, were
subsequently recovered.

Through the forensic examination of seized computers and other digital
storage devices, as well as evidence secured through the rebuilt
Ghostmarket site, officers identified Ricardo, a trusted member of the
forum, and she was traced to Swansea, South Wales. Initially joining
the site as a complete novice, over time Ricardo had progressed to
become directly engaged in card fraud and computer malware activity.
Financial enquiries identified a payment made from Ricardo into her
partner Worley’s bank account, incriminating her in the fraud.

Detective Inspector Colin Wetherill, Police Central eCrime Unit said:
“These defendants were accomplished cyber criminals, engaged in the
systematic mass infection of computers in homes and businesses in the
UK and overseas.

“They unlawfully harvested personal and financial information from
their victims to be exploited for financial gain.

“The GhostMarket crime forum was used by thousands of computer
criminals and fraudsters operating worldwide.

“Through it the defendants built an extensive criminal network to
facilitate the wholesale trade of compromised credit card details,
confidential financial and personal information, malicious computer
programmes, and other sophisticated tools and criminal services.

“The arrest, prosecution and conviction of these individuals represents
a significant step forward in our efforts to tackle cyber crime and
reduce the harm it causes.”

+ A full financial investigation into all four defendants is underway.

[ComputerSecurityArticles]

Twitter crime rate rises 20 percent

Barracuda Labs analyzed more than 26 million Twitter accounts in order to measure and analyze account behavior.

The analysis enabled researchers to model normal user behavior and identify features that are strong indicators of illegitimate account use.



Key highlights from the Twitter research include:
  • In general, activity continues to increase on Twitter: more users are coming online; True Twitter Users are tweeting more often, and even casual users are becoming more active. As users become more active, the malicious activity also increases.
  • The number of real Twitter users increased to 43 percent, up from only 29 percent in June 2010.
  • For every 100 Twitter users, 39 have between one and nine followers, while 50 percent of Twitter users have more than 10 followers.
  • Approximately 79 percent of Twitter users tweet less than once per day.
  • After decreasing at the end of 2009, the Twitter crime rate increased 20 percent from the first half of 2010 to the second half of 2010, going from 1.6 percent to 2 percent.
  • Attackers are distributing malware and exploiting vulnerabilities to achieve their malicious goals.
The complete report is available here.

[net-security]

Teen cybercrime forum boss jailed

A UK teenager who ran a prolific cybercrime forum from home has been jailed for five years.

Nick Webber, 19, maintained the Ghostmarket.net market which boasted 8,000 memberships and facilitated a range of crimes including the sale of stolen credit card and personal details.

Police recovered the details of thousands of credit cards from Webber's machines when he was busted in October 2009 after trying to use a counterfeit credit card to pay for a hotel stay. Confronted by mounds of evidence Webber, from Southsea, Hampshire, pleaded guilty to fraud.

Southwark Crown Court heard that members of the gang may have defrauded banks and individuals anywhere between £12m and £20m, depending on whose estimates you believe. In court, Ghostmarket.net was described as a supermarket for cybercrooks, providing guides on how to commit cybercrimes as well as a marketplace for stolen wares.

The personal details of around 65,000 victims were traded through the site.

Even after his release on bail, Webber continued to engage in cybercrime, an aggravating feature that led to a far tougher sentence than might otherwise have been the case.

Three other convicted suspects were convicted in the same case. Gary Kelly, 21, from Manchester, was also jailed for five years after he also pleaded guilty to the same fraud charges as Webber along with conspiracy to make or supply articles for use in fraud and conspiracy to cause unauthorised modification to computers.

Ryan Thomas, 18, from Beaconsfield in Buckinghamshire, who acted as the site admin for Ghostmarket.net, was jailed for four years. Shakira Ricardo, 21, from Swansea, was imprisoned for 18 months after she pleaded guilty to conspiracy to commit fraud and handling criminal property, the BBC reports.

Webber and Thomas jumped bail soon after their initial arrests in December 2009 before they were captured in Majorca and returned to the UK, The Guardian adds. ®

[The Register]

Tuesday, 1 March 2011

IC3: Internet Crime Up in 2010

IC3Internet crime is on the rise again according to a report recently released by The Internet Crime Complaint Center (IC3). The organization said last week that it received the second-highest number of complaints in its decade long history in 2010.

Released on February 24, the 2010 Internet Crime Report (.PDF) counted 303,809 complaints of Internet crime over the course of the year, down from 2009’s all-time high of 336,655. Nearly 15% of complaints came regarding non-delivery of payment or merchandise, while scams and identity theft rounded out the top three complaints with 13% and 10% respectively.

Cybercriminals are also having success targeting an older demographic than in the past. Complaints from last year came predominantly from the 40-59 year old bracket this year. In the early 2000s, the average age usually fell across the 30-39 age group, IC3 said.

When it came to gender, the IC3 saw even more Internet crime reports coming from males in 2010 as statistics in the report found men reported crime 2.5 to 1 over women.

The heightened complaint numbers over the last several years could be credited to two recent adjustments by the IC3. In 2010 the group added remote access to their database via a Complaint Management System (CMS). In 2009 the IC3 integrated an Internet Complain Search and Investigation System (ICSIS) which allows users of their database to better share information.

[ThreatPost]