Retail News CRM

Tag: cyber crime

  • Vietnamese banks sound alarm over cybercrime

    Vietnamese banks sound alarm over cybercrime

    Many banks in Vietnam have reported about customers losing information about their accounts to criminals through phishing attacks and other methods.

    In a recent statement Techcombank said it had detected many cases of fraud and misappropriation of money by faking Western Union transactions.

    The criminals would send victims fake Techcombank messages claiming they had received money through Western Union, and tell them to go to a fake Techcombank website and log in to confirm the transaction, resulting in their account information being stolen.

    Maritime Bank has issued a statement cautioning customers about frauds in which criminals contact them through phone calls, text messages, social networks, and emails pretending to be the bank’s employees. They then ask the victims to provide their account information in return for money, promotions or prizes.

    Other major banks such as VPBank and Vietcombank have also issued similar statements cautioning customers against revealing their OTP codes to anyone, including the banks themselves, under any circumstances.

    They are also told to closely monitor their accounts to detect any abnormal activity, and report immediately to the bank if they receive suspicious calls or text messages.

    According to global statistics recently released by cybersecurity firm Kaspersky Lab, nearly 36 percent of cyberattacks in the second quarter of 2018 were targeted at financial services, including over 21 percent targeting banks and 8.17 percent targeting online shops.

    Financial experts have warned that Vietnam has become a hotbed of cybercrime, with criminals becoming increasingly sophisticated while banks still using old, insecure technologies and their customers lacking awareness of how or why to protect account information.

    To counter the increase in cybercrime, the government has issued a decree requiring banks to secure their customers’ information and not to provide such information to any third party without written consent from customers.

  • Suspected North Korean cyber group seeks to woo bitcoin job seekers

    The surging price of cryptocurrencies in global markets is catching the eye not just of ordinary retail investors but a cybercrime gang with links to the North Korean government, according to cyber researchers tracing the group’s activities.

    The Lazarus cybercrime group is mounting an ongoing scheme to steal the online credentials of bitcoin industry insiders, a report published by researchers at U.S. cyber security firm Secureworks’s Counter Threat Unit (CTU) said on Friday.

    Cybersecurity firms including Secureworks suspect North Korea to be behind the Lazarus group, which they link to an $81 million cyber heist last year at the Bangladesh central bank and a 2014 attack on Sony’s Hollywood studio.

    “Given the current rise in bitcoin prices, CTU suspects that North Korea’s interest in cryptocurrency remains high and (it) is likely continuing its activities surrounding the cryptocurrency,” Secureworks said in a statement to Reuters.

    Prices for the volatile cryptocurrency surged past $10,000 late last month and have continued to race upward toward $20,000. A single bitcoin traded above $17,500 on Friday, up more than 7 percent on the day and more than 18 times in the year to date.

    Secureworks said that as recently as last month it had monitored a targeted email campaign aiming to trick victims into clicking on a compromised link for a job opening for a chief financial officer role at a London cryptocurrency company.

    Those who clicked on the hiring link were infected by malicious code from an attached document in the email that installed software to take remote control of a victim’s device, allowing hackers to download further malware or steal data.

    This malware shares technical links with former campaigns staged by the mysterious cybercrime group Lazarus, which Secureworks has labelled “Nickel Academy”. Secureworks did not say whether anyone who received the email actually clicked on the link.

    The so-called “spearphishing” attempt appears to have been delivered on October 25, but initial activity was observed by Secureworks researchers dating back to 2016. The researchers said in a statement they believe the efforts to steal credentials are still on-going.

    Recent intrusions into several bitcoin exchanges in South Korea have been tentatively attributed to North Korea, it said.

    Secureworks researchers have found evidence dating back to 2013 of North Korean interest in bitcoin, when multiple user names originating from computers using extremely rare North Korean internet addresses were found researching bitcoin.

    The same internet addresses were linked to previous North Korean cyber attacks.

    A spokeswoman for Secureworks said the company was releasing its preliminary findings now and a more complete report would be published later.