Showing posts with label financial. Show all posts
Showing posts with label financial. Show all posts

2017-07-22

Police Takeover of Darknet Markets

Seems like the underground markets are in serious trouble.
a Canadian citizen living in Thailand was arrested in that country and is believed to have committed suicide while in custody after international authorities — including police here — worked to close the AlphaBay criminal marketplace on the Dark Web
AlphaBay's takeover

The users of AlphaBay flocked started migrating over to the Hansa Market, which was already under the control of the Dutch police!

An interesting police intereview

There are rumors that Dream Market may also already be under the police control.

2016-11-14

Tesco Bank Hack

About 9000 customers lost over £2.5 million. The Bank was then forced to refund the money. This is after they froze internet banking for over 20K customers.

2016-10-20

3.2 million debit cards compromised in India

Hackers allegedly used malware to compromise the Hitachi Payment Services platform — which is used to power country's ATM, point-of-sale (PoS) machines and other financial transactions — and stole details of 3.2 Million debit cards!
Amazing

2016-10-12

Distressed Yahoo!

Yahoo is a facing a lot of heat at the moment, with some recent events.

First, 500 million user accounts was stolen in 2014, and got dumped online recently. Then, there is news that Yahoo complied with a secret government order to search the incoming emails of all of its users. This secret initiative was not even known to its internal security team.

Verizon, who has been in talks to acquire Yahoo is now seeking a $1 Billion price cut. Hence, the timing of these revelations couldn't have come at a worse time for Yahoo. 

To make matters worse, to avoid users leaving its platform, Yahoo has disabled email-forwarding. This is totally in bad faith, which will only frustrate it's users.

Update 15-Dec-2016:
Yahoo says an additional 1 Billion users were impacted. This is insane!
More details from Krebs.

Update 14-Jun-2017:
The Verizon deal finally goes thru, and Yahoo's CEO resigns.

Update  04-Oct-2017:
Every single Yahoo account was hacked - 3 billion in all - link

2016-09-10

Israeli Online Attack Service

A super investigation (and DOXing) done by Brian Krebs. A look at how a DDoS for hire service operates and launders money!   Link

Update 13-Sep-2106:
Krebs gets DDoS-ed for this article, by the same botnet company

2016-07-02

Ethereum DAO Hack

The hack makes me think about the reliability of crypto-currency. If we go with the assumption that there is no bug-free software, it is always only a matter of time (hence patching is of utmost importance), then how do we have our faith in bitcoins or any other altcoins?

How can they recover the stolen money? They can't -- at least not without destroying the entire principle of cryptocurrencies

Am very curious to see what this community decides to do now. Hack details.

A synopsis of the hack and the Robin Hood hack.

2016-04-13

Hacking Lottery via Random Num Generator

For several years, Eddie Tipton, the former security director of the US Multi-State Lottery Association, installed software code that allowed him to predict winning numbers on specific days of the year, investigators allege.
Full story!
 

2016-03-20

Bangladesh Bank hit by $1 Billion cyber heist

Four requests to transfer a total of about $81 million to the Philippines went through, but a fifth, for $20 million, to a Sri Lankan non-profit organisation got held up because the hackers misspelled the name of the NGO.
At the same time the unusually high number of payment instructions and the transfer requests to private entities ... made the Fed suspicious, which also alerted the Bangladeshis ...  The transactions that got stopped totalled between $850 million and $870 million
Story here & here.

Update 24-Apr-2016:
The bank's security was in a pitiful condition!
Bangladesh's central bank was vulnerable to hackers because it did not have a firewall and used second-hand, $10 switches to network computers connected to the SWIFT

Update 27-Apr-2016:
A very sophisticated attack, which makes sense knowing the attackers targetted almost $1B from this one bank alone, and maybe others.
That apparently allowed the attackers to delete outgoing transfer requests and intercept incoming requests, as well as change recorded account balances – effectively hiding the heist from officials.
The malware even interfered with a printer to ensure that paper copies of transfer requests didn’t give the attack away.

Update 13-May-2016:
Another bank hit, by the same malware

Update 27-May-2016:
More banks are investigating a potential breach. Ecuador Bank become the third victim !

Update 28-May-2016:
Is North Korea responsible?

An interesting article with all the known facts from the Bangladesh hack.

Update 29-Jun-2016:
Ukrainian Bank loses 10 M, to a swift attack.

Update 11-Nov-2016:
$15M recovered by the Bangladesh Bank, thanks to the courts.

Update 07-Apr-2017:
Lazarus group exposed, with links to N Korea

2016-01-30

HSBC Under Attack

They say, it's a standard DDoS attack, with no threat to client data.... Makes me wonder if there is anything else going on, with the DDoS acting as a smoke screen.

2016-01-16

Cybercriminal Call Centers

There is no limit to how organized the cyber-crime is getting
Crooks who make a living via identity theft schemes, dating scams and other con games often run into trouble when presented with a phone-based challenge that requires them to demonstrate mastery of a language they don’t speak fluently. Enter the criminal call center, which allows scammers to outsource those calls to multi-lingual men and women who can be hired to close the deal.

2015-12-04

Sharjah bank held to ransom by hacker

It’s not clear how the hacker broke into the bank’s computers. In a direct message to this journalist via Twitter, Hacker Buba claimed he is seeking $3 million and has access to the bank database and back up files from all its servers.
Story here

2015-11-21

Health Insurer Excellus: Attackers Breached 10M Records

Excellus has revealed that in August of this year it discovered a nearly 2-year old intrusion campaign in its network that gave hackers access to potentially all its customers’ records. That data includes names, birth dates, Social Security numbers, mailing addresses, telephone numbers, and a variety of account information including claims and financial payment details. 
Full Story 

2015-11-16

ProtonMail DDoS Extortion

the service was extorted by one group of attackers, then taken offline in a large distributed denial-of-service (DDoS) attack by a second group that it suspects may be state sponsored.
Full Story

2015-11-11

Biggest cyber heist in history

How JP Morgan (and others) got hacked, and the story behind pump-n-dump scheme of hackers. And hackers caught.

2015-10-13

Anonymous Threatens Banks!

Operation Black October 2015
Using its conventional approach, the group announced the launching of its latest campaign the Operation Black October through a YouTube video.The hacktivist urged people to take out all their money from the banks as soon as possibl

2015-04-14

Introducing Dyre Wolf

An innovative and daring technique to steal money - using a malware and a call-center team!

While many popular banking Trojans have targeted individuals, Dyre has always been used to target organizations. Since its start in 2014, Dyre has evolved to become simultaneously sophisticated and easy to use, enabling cybercriminals to go for the bigger payout.

2015-02-17

Introducing Carbanak Group

The story:
Kaspersky researchers have discovered the theft of $1 billion from 30 banks over the past two years....
..... criminal activity did not end here. In other cases, the cyberattackers "penetrated right into the very heart of the accounting systems," Kaspersky says. The criminals were able to inflate account balances before fraudulently transferring the money.

2014-11-14

Crypto Currencies

Update 14-Feb-16:
Nasdaq is looking to use block-chain technology in main stream!

Update 03-Jun-15:
Vulnerability in BlockChain's Android app. Causes multiple users to generate the same random number, which lead to a loss of the coins for a few users.

Update 01-Jun-15:
Ross Ulbricht, the mastermind behind Silk Road, gets life in prison without parole

Update 07-Apr-15:
Bitcoin Foundation is at the verge of bankruptcy. Fires almost everyone, except the volunteers. However, that been said, I wonder what is this foundation planning on doing to being with.

Update 05-Apr-15:
Dark Coins - how to be truly anonymous!

Update 04-Apr-15:
Two fed-agents charged with stealing BTC during the SilkRoad investigation

Update 24-Jan-15:
Winklevoss twins plan regulated Bitcoin exchange

Update 10-Jan-15:
Bitstamp has been compromised now (which is another exchange), and warns customers to not deposit the digital currency. $ 5M loss!

Update 08-Nov-14:
SilkRoad2 busted, the founder arrested. Biggest ever raid on Tor hits 410 website, and over 17 people arrested.

Update 10-Nov-13:
Silk road [2] is back online, using tor

Update 04-Oct-13:
hacker breaks into a forum of bitcoin, steals the DB and puts it up on sale for 25 BTC! Hackers have no respect, even for their own community.

Update 03-Oct-13:
The ebay of illegal drugs and weapons (Silk Road) was busted by FBI, which not surprisingly was using bitcoins to do it's dirty business. The bust had a negative impact on the value of the currency!
The feds decide to auction the confiscated bitcoins.

Update 14-Aug-13:
Now there is a court order to multiple digital currency operators

Update 26-May-13:
Liberty Reserve taken down, now attention shifts to Perfect Money. BitCoin still remains the leader of course. It's not a secret that that these services are used for illegal activities.

Update 08-Aug-2016:
Hong Kong based Bitfinex loses $72M in bitcoin. This caused the exchange rate of the currency to take a nose-dive. The worse part is that the exchange has decided to spread the loss across all users. Hence everyone loses 36% of their bitcoins, immaterial of weather they were impacted by the heist or not.

Update 21-Aug-2016:
Nation state (China) attacking the core bitcoin ! Will the network be able to cope with this?

Update 18-Jul-2017:
A ICO hacked, CoinDash

Update 29-Jul-2017:
BTC-e founder (?) arrested. This was the exchange where most of the cyber-criminals used to cash out their dirty coins.


2014-10-03

JP Morgan Loses 83M client info to Russians

This is not going to go well for the Bank, they may get hit by a Regulatory sanction as well.

2014-09-03

Dairy Queen & Home Depot Compormised

Either the hacking activity has increased this year, or maybe the companies are being more honest about public disclosures.

DQ:  A spokesman for Dairy Queen has confirmed that the company recently heard from the U.S. Secret Service about “suspicious activity” related to a strain of card-stealing malware found in hundreds of other retail intrusions.
[update 11-Oct-14] DQ has confirmed the breach at 395 stores

Home Depot:  The latest victim of Russian hackers specializing in point-of-sale (POS) theft appears to be the venerable do-it-yourself store, Home Depot. A large cache of credit- and debit-card information, dubbed ‘American Sanctions,’ has appeared ...