Tag: criminals

  • Surge in Hong Kong Cybercrime

    Surge in Hong Kong Cybercrime

    Hong Kong has experienced a surge in fraudulent banking websites this year. In August alone, there were 15 reports of such incidents, compared with only two cases of fake websites or phishing attempts in the same month a year ago, according to the Hong Kong Monetary Authority (HKMA). In September, seven incidents were reported, up from one a year ago.

    And the trend seems to continue, with eight cases reported in October so far. Customers of DBS, Hongkong and Shanghai Banking Corporation, as well as Dah Sing have been among the targets of the criminals. With the rise of financial technology firms and mobile banking apps, experts predict that novice mobile banking users will become prime targets.

    Digital Banks Attract Attackers

    While the use of digital banking tools is spreading quickly, the technology is also attracting the attention of cybercriminals, said cybersecurity specialist Securelist in a report earlier this year. «We are sure that the world of cybercrime will see increasing attacks against this type of banks and their customers,» Securelist said in its report

    Fraudsters have long tried to trick users to visit fake bank website via e-mail messages pretending to be from the bank. On these fake websites, they try to trick account holders into revealing their access credentials. On mobile devices, the connection with the bank is typically via an application, rather than a website.

    Tricks Of Criminals

    Banks’ usage of chat applications increases the possibility that criminals could try impersonating the bank in social media chats and try to trick users into downloading and installing an «updated» version of the bank’s app. In reality, such an app would be malicious and could help attackers steal credentials from the phone.

    «Other social engineering scams have emerged which try and trick the genuine user into revealing the authentication code for their chat app and hence lose control of the account. Even if this is only temporary, it may allow enough time for a fraud to be perpetrated,» Jackson said in an interview.

    Attacks Focused On Smaller Vendors

    Experts predicts there could be more attacks on fintechs or payment providers going forward. This is due to lower investments into cybersecurity versus traditional banks, and criminals’ evolving technological skills.

    «Large financial organizations invest considerable resources in cybersecurity, thus the penetration of their infrastructure is not an easy task. However, a threat vector that is likely to be actively used by cybercriminals in the coming year is attacks on software vendors supplying financial organizations,» Securelist said. Most of these vendors have a lower level of protection compared with the financial organizations themselves.

    Attacks Via Software

    For the coming year, the cybersecurity experts expect criminals to stage attacks via software for the finance business, including such for ATMs and PoS terminals. «A few months ago we registered the first attempts of this kind, when attackers embedded a malicious module into a firmware installation file, and placed it on the official website of one of the American ATM software vendors,» Securelist wrote.

    Based on a 2017 study by Accenture, the financial services industry posted annual costs of nearly $18.3 million per firm from cyber attacks.

  • Cybercriminals use insiders to attack telcos

    Cybercriminals use insiders to attack telcos

    Cybercriminals are using insiders to gain access to telecommunications networks and subscriber data, recruiting disaffected employees through underground channels or blackmailing staff using compromising information gathered from open sources.

    This is among the findings of a Kaspersky Lab intelligence report into security threats facing the telecommunications industry.

    Telecommunications providers are a top target for cyber-attacks. They operate and manage the world’s networks, voice and data transmissions and store vast amounts of sensitive data. This makes them highly attractive to cybercriminals in search of financial gain, as well as nation-state sponsored actors launching targeted attacks, and even competitors.

    To achieve their goals, cybercriminals often use insiders as part of their malicious ‘toolset’ to help them breach the perimeter of a telecommunications company and perpetrate their crimes.

    New research by Kaspersky Lab and B2B International reveals that 28% of all cyber-attacks and 38% of targeted attacks now involve malicious activity by insiders. The intelligence report examines popular ways of involving insiders in telecoms-related criminal schemes and gives examples of the things insiders are used for.

    Compromising employees

    According to the Kaspersky Lab researchers, attackers engage or entrap telecoms employees in the following ways:

    • Using publicly available or previously stolen data sources to find compromising information on employees of the company who they intend to hack. They then blackmail targeted individuals – forcing them to hand over their corporate credentials, provide information on internal systems or distribute spear-phishing attacks on their behalf.
    • Recruiting willing insiders through underground message boards or through the services of “black recruiters”. These insiders are paid for their services and can also be asked to identify co-workers who could be engaged through blackmail.

    The blackmailing approach has grown in popularity following online data breaches such as the Ashley Madison leak, as these provide attackers with material they can use to threaten or embarrass individuals. In fact, data-leak related extortion has now become so widespread that the FBI issued a Public Service Announcement on June 1, warning consumers of the risk and its potential impact.

    The insiders most in demand

    According to the Kaspersky Lab researchers, if an attack on a cellular service provider is planned, criminals will seek out employees who can provide fast track access to subscriber and company data or SIM card duplication/illegal reissuing. If the target is an internet service provider, the attackers will try to identify those who can enable network mapping and man-in-the-middle attacks.

    However, insider threats can take all forms. The Kaspersky Lab researchers noted two non-typical examples, one of which involved a rogue telecoms employee leaking 70 million prison inmate calls, many of which breached client-attorney privilege. In another example, an SMS center support engineer was spotted on a popular DarkNet forum advertising their ability to intercept messages containing OTP (One-Time Passwords) for the two-step authentication required to login to customer accounts at a popular fintech company.

    “The human factor is often the weakest link in corporate IT security,” Kaspersky Lab security expert Denis Gorchakov said.

    “Technology alone is rarely enough to completely protect the organization in world where attackers don’t hesitate to exploit insider vulnerability. Companies can start by looking at themselves the way an attacker would. If vacancies carrying your company name or some of your data start appearing on underground message boards, then somebody somewhere has you in their sights. And the sooner you know about it, the better you can prepare.”