Translate

Posts mit dem Label Data Breach werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Data Breach werden angezeigt. Alle Posts anzeigen

5/08/2014

U.S. NAVY MILITARY HACK 2012:

Nicholas Paul Knight & Daniel Trenton Krueger

charged with Hacking US Navy Computer Systems & Sites


Daniel Trenton Krueger, 20, of Salem, Illinois and Nicholas Paul Knight, 27, of Chantilly, Virginia, were accused of conspiring "to hack computers and computer systems as part of a plan to steal identities, obstruct justice, and damage a protected computer" from April 2012 to June 2013, court documents and prosecutors said.

USS Harry S. Truman

Knight, a former systems administrator in the nuclear reactor department of the USS Harry S. Truman, was the self-proclaimed leader and publicist of "Team Digi7al," prosecutors said. He used the names Inertia, Iner7ia, Logic and Solo and has been a hacker since the age of 16, charging documents say. He was discharged from the Navy after he was caught trying to hack a Navy database while at sea.

In an interview with a reporter for the website Softpedia, parts of which are quoted in charging documents, "Iner7ia" said that he was originally a White hat hacker, who found and reported security vulnerabilities. But he became bored and said "the people I did work for were ungrateful and sometimes they wouldn't take me seriously."

He admitted being a member of the United States Navy, and said that he worked for the people of the U.S. hacking primarily government sites, not the government. "I believe that if we can't protect ourselves against a cyber attack, then how can we trust the government to protect against anything else?"


He said that he uses a separate computer to avoid being caught, and at one point said, "I just hope that I can retire knowing I was never caught and arrested. Haha"

Krueger, who was studying network administration at an undisclosed college, did the hacking "out of boredom," prosecutors said. He went by the names Thor, Orunu, Gambit and Chronus.

Charging documents say that in June of 2012, the Naval Criminal Investigative Service (NCIS) detected a breach of a Naval database located in Oklahoma that contains the Social Security numbers, names, and birth dates of roughly approximately 220.000 members of the military.


"The Navy quickly identified the breach and tracked down the alleged culprits through their online activity, revealing an extensive computer hacking scheme committed across the country and even abroad," said U.S. Attorney Danny C. Williams of the Northern District of Oklahoma.

U.S. Attorney Danny C. Williams
The NCIS and Defense Criminal Investigative Service identified Knight and Krueger as the hackers of the Navy database as well as systems belonging to the U.S. National Geospatial-Intelligence Agency, the Department of Homeland Security, AT&T U-verse, Universities, Police Departments in Toronto and Alabama and the entire email account of the Peruvian ambassador to Bolivia.

They posted links to the data via Team Digi7al's Twitter account, and one co-conspirator said they released the data because they were "somewhat politically inclined to" but also because it was "fun, and we can," prosecutors said.

The U-verse hack compromised the personal information of 3.500 customers. The June 2012 Navy hack left 700 overseas military members unable to access the system and get "logistical support" for their transfers for more than 10 weeks and cost the Navy more than 500.000 US-Dollars documents say.

The U.S. National Geospatial-Intelligence Agency

After the NCIS searched Knight's Virginia home in February of 2013, he admitted "many" of his Team Digi7al activities and agreed to cooperate, but told a juvenile co-conspirator to delete data, documents say.

That juvenile and two others who hacked for Team Digi7al were not charged.

1/14/2014

Cybercrime Review 2013:
The largest Hacking Scam in US history is prosecuted
The NASDAQ Hack (Aleksandr Kalinin)

Four Russians and a Ukrainian have been charged in what prosecutors call "the largest hacking and data breach scheme in US history".

The five plotted in a "worldwide scheme that targeted major corporate networks, stole more than 160 million credit card numbers and resulted in hundreds of millions of dollars in losses," said Paul Fishman, the U.S. Attorney for the District of New Jersey.


US Attorney Paul Fishman
Companies that have been focused included Citibank, 7-Eleven, PNC Financial Services Group, France's largest retailer Carrefour and computers used by the Nasdaq Stock Market.

US prosecutors in New York separately indicted one of the five men and another Russian in another hacking scheme that targeted 800.000 bank accounts. Two of the men are in custody.


On June 25th, 2013, Preet Bharara, the United States Attorney for the Southern District of New York, announced the unsealing of an indictment against Aleksandr Kalinin, aka “Grig,” aka “g,” aka “tempo,” for hacking certain computer servers used by the NASDAQ Stock Market. In a separate indictment also unsealed, Kalinin and another Russian hacker, Nikolay Nasenkov were charged in the same matter.
Both, Kalinin and Nasenkov remain at large.

Fishman said: "This type of crime is the cutting edge. Those who have the expertise and the inclination to break into our computer networks threaten our economic wellbeing, our privacy and our national security."

US Attorney Preet Bharara
Preet Bharara said: “As today’s allegations make clear, cyber criminals are determined to prey not only on individual bank accounts, but on the financial system itself. But would-be cyber thieves should take note: Because of the close and growing collaboration between the U.S. government and the private sector on issues of cyber security, our ability to unmask and prosecute the anonymous perpetrators of cyber crimes - wherever they may be located - has never been stronger.”

FBI Assistant Director in Charge George Venizelos said: “As alleged, Kalinin infiltrated NASDAQ’s servers, allowing for the manipulation and theft of sensitive data. In a series of separate schemes, Kalinin and Nasenkov stole hundreds of thousands of bank account numbers, PINs, and other code to withdraw millions of dollars from victim accounts. Today, their password has expired.”
FBI (AD) George Venizelos

                                   The NASDAQ Hack
From November 2008 through October 2010, Kalinin hacked various computer servers used by the NASDAQ to conduct its business operations. During the courses of these hacka, Kalinin installed on certain NASDAQ servers malicious software (Malware) which permitted him and his companions to secretly access the compromised NASDAQ servers to execute commands on those servers, including commands to delete, change or steal data. (The infected servers did not include the trading platform that allows NASDAQ customers to buy and sell securities.)

                      The Citibank and PNC Bank Hacks
From December 2005 through November 2008, Kalinin and Nasenkov allegedly stole bank account information from financial institutions through computer hacking. Kalinin, Nasenkov, and their co-conspirators then used that account data to access the bank accounts of thousands of individual victims without authorization and without those victims’ knowledge, resulting in the theft of millions of dollars from those accounts.
The Cybercriminals then fraudulently obtained bank account numbers, customer identification numbers (a unique number embossed or printed on the front of an ATM card. See picture), card security codes (a security feature which helps authenticate an ATM card. See picture), and personal identification numbers (PINs) for victims’ accounts at financial institutions, including Citibank and PNC Bank, through computer intrusion and other hacking techniques. As part of the scheme, the defendants and their co-conspirators then encoded the stolen account data onto the magnetic strips of blank plastic ATM cards so that those ATM cards could be used to access individual victims’ bank accounts through ATMs. The ATM cards were then used, along with the stolen account PINs, to access individual victims’ accounts through ATMs located around the world, including the United States, Estonia, Canada, Great Britain, Russia, and Turkey, and to withdraw from those accounts millions of dollars.
CSC

In January 2006, the PINs for hundreds of customer accounts were compromised as a result of a cyber attack launched against PNC Bank’s online banking website. Nasenkov allegedly supplied stolen account information, including PINs, from the compromised bank accounts to co-conspirators who, in return, used the stolen account information to encode blank ATM cards and withdraw approximately 1.3 million USD from victims’ accounts.

In 2007, Kalinin, placed malware on a computer network that processed ATM transactions for Citibank and other financial institutions. This malware recorded data passing over the network and exported it to an outside computer. Using this malicious computer code, Kalinin stole bank account information for approximately 500.000 bank accounts, including approximately 100.000 Citibank accounts. The stolen account information was used to create ATM cards that in turn were used to withdraw approximately 2.9 million USD from Citibank customers’ accounts.

In 2008, Nasenkov used a computer program to mount an attack against Citibank’s online banking website that resulted in the theft of account information for more than 300.000 accounts. The stolen account information was used to create ATM cards that in turn were used to withdraw approximately 3.6 million USD from the compromised accounts.

Kalinin, 26, of St. Petersburg, Russia, is charged with one count of computer hacking in connection with the NASDAQ hack, which carries a maximum sentence of 10 years in prison. In connection with the scheme to steal bank account information, Kalinin is charged with one count of conspiracy to commit bank fraud, which carries a maximum sentence of 30 years in prison; 4 counts of bank fraud, each of which carries a maximum sentence of 30 years in prison; one count of conspiracy to commit access device fraud, which carries a maximum sentence of seven and a half years in prison; one count of aggravated identity theft, which carries a mandatory sentence of two years in prison; and one count of conspiracy to commit computer intrusion, which carries a maximum sentence of 5 years in prison. All in all Kalinin could be sentenced to 174 years and a half in prison.

NASENKOV, 31, of St. Petersburg, Russia, is charged with one count of conspiracy to commit bank fraud, which carries a maximum sentence of 30 years in prison; 4 counts of bank fraud, each of which carries a maximum sentence of 30 years in prison; one count of conspiracy to commit access device fraud, which carries a maximum sentence of seven and a half years in prison; one count of computer intrusion to obtain information, which carries a maximum sentence of five years in prison; one count of computer intrusion to further fraud, which carries a maximum sentence of five years in prison; one count of aggravated identity theft, which carries a mandatory sentence of two years in prison; one count of conspiracy to commit money laundering, which carries a maximum sentence of 20 years in prison; and one count of conspiracy to commit computer intrusion, which carries a maximum sentence of five years in prison. All in all Nasenkov could be sentenced to 219 years and a half in prison.

Albert Gonzalez
The men conspired with Albert Gonzalez, a Miami hacker serving 20 years in prison for stealing 130 million credit- and debit-card records from Heartland Payment Systems.

Other defendants from the Hacker-Ring (also known as the "Moscow-Five") charged are:
  • Roman Kotov, 32, of Moscow
  • Vladimir Drinkman, 32, of Moscow
  • Dmitriy Smilianets, 29, of Moscow
  • Mikhail Rytikov, 26, of Odessa, Ukraine
Offical Link to the indictment : HERE (Pdf-File)

12/27/2013

After TARGET Data Breach: There is a Need to target on Web Security

As multinational banks as other financial institutes struggle to protect clients after a massive data breach at retail giant Target, small service companies also should be concerned about their Online Security. Its just not tough enough to be protected in a secure way, as Online Fraud is increasing every year in a more and more faster way.


Between November 27th and December 15th, cybercriminals hurried off with data from 40 million credit and debit card accounts of people who shopped regulary at Target’s 1.924 stores in the United States and in Canada.

So far, at least three class-action lawsuits have been filed.

The U.S. Small Business Administration says cyber threats are an issue for everyone, and small businesses are becoming more common targets for such threats and crimes because they often have fewer preventive or responsive resources, as being or getting protected in a competent way also increases the costs. But Security start with yourself.

USSBA Seal
The USSBA though offers in its latest online training course some of the Basics in: “What is cybersecurity?”. (See Link at the end of this post beneath)

With the help of technology and best practices, cybersecurity is the effort to pro-tect computers, programs, networks and data from fraudulent Attacks. Or to ask in other words:

Why is cybersecurity important ?

 

Consider all the information you have that needs to be secure, like personal information for employees, Businesspartner information, sensitive information for consumers, and also sensitive and secret business information.

It’s essential to do your part to keep these details safe and out of the hands of those who could use your data to compromise you and everything surrounding your business.

CNN reported, that nearly half of the data breaches that Verizon has recorded in 2012, took place in companies Staff with less than one thousand. Symantec reports show that 31 % of all Cyberattacks in 2012 happened to businesses that had less than 250 employees. In 2011 Attacks were rising up to 81 percent.

The Methods

 

The Range of ways getting compromised is Vast. This Range might vary between Web site tampering, data breach, DoS up to Malware and Trojans.

Website tampering is a form of Web-based attack in which certain parameters in the Uniform Resource Locator (URL) or Web page form field data entered by a user are changed without the Webmasters authorization. This finally directs the browser to a link, page or site other than the one the user intended (although it may look exactly the same to the usual client).

Parameter tampering can be employed by Cybercriminals and identity thieves to stealthily obtain personal or business information about the user. Countermeasures specific to the prevention of parameter tampering involve the validation of all parameters to ensure that they conform to standards concerning minimum and maximum allowable length, allowable numeric range, allowable character sequences and patterns, whether or not the parameter is actually required to conduct the transaction in question, and whether or not null is allowed.

A denial-of-service attack DoS happens on a CPU or Web site and locks the computer and/or crashes the system, resulting in stopped or slowed work flow.

Malware code and/or viruses are sent over the Internet and aim to find and send your files, find and delete critical data, or block your computer or system. They can hide in programs or documents and make copies of themselves  without your knowledge.

What Prevention measures YOU should take

The main first step secureing the critical information of your business, is to create a far-reaching firm security policy. Second Step: keep them up-to-date. Third Step: convincing your employees to keep the proprieties according to the policies.

  • Be ensured that your computer hardware and software are updated regularly. 
  • Change passwords periodically and use firewalls to protect your systems. 
  • You should back up your data on a regular basis so that if something is compromised, you have a secure copy.

If interested, the following Link brings you to the Small Business Learning Center at www.sba.gov and will take 30 Minutes:

Click to Start Your Course now !