Maksim Boiko, an accused money launderer and part-time rapper, to plead not guilty

A Russian man caught carrying $20,000 in cash through the Miami airport earlier this year will plead not guilty to laundering money on behalf of a transnational cybercriminal organization, his attorney said Friday. An FBI complaint unsealed in March charges that Maksim Boiko, 29, was a “significant cybercriminal” who converted stolen money into cryptocurrency for a group called QQAAZZ. Boiko was taken into custody in Florida earlier this year, though he’s due to be arraigned via teleconference in the Western District of Pennsylvania soon, defense attorney Arkady Bukh told CyberScoop. “My client will plead not guilty,” he said. Boiko, known as “gangass” among other accused cybercriminals, was arrested in March at a Miami condominium on March 28 after entering the U.S. with his wife through the Miami airport in January. An FBI complaint unsealed the next day included pictures of Boiko driving a BMW with bundles of U.S. cash on […]

The post Maksim Boiko, an accused money launderer and part-time rapper, to plead not guilty appeared first on CyberScoop.

Continue reading Maksim Boiko, an accused money launderer and part-time rapper, to plead not guilty

Zoom acquires Keybase to beef up encryption, ease security questions

It looks like Zoom is putting some money behind its plans to quickly upgrade its security measures. The San Jose-based company behind the now-popular videoconferencing software announced Thursday it has acquired Keybase, known for its secure messaging and file-sharing services. The plan, Zoom says, is to integrate Keybase’s personnel to build end-to-end encryption throughout the service. Terms of the deal were not disclosed. “Our goal is to provide the most privacy possible for every user case, while also balancing the needs of our users and our commitment to preventing harmful behavior on our platform,” Zoom said in a statement. “Keybase’s experienced team will be a key part of this mission.” The deal comes after Zoom chief executive Eric Yuan said the company had failed to prioritize data protection during a period when its number of daily users skyrocketed to 200 million, up from roughly 10 million users prior to the coronavirus […]

The post Zoom acquires Keybase to beef up encryption, ease security questions appeared first on CyberScoop.

Continue reading Zoom acquires Keybase to beef up encryption, ease security questions

Facebook removed Russian propaganda network only after accounts got sloppy

Two networks of inauthentic Facebook accounts and pages removed last month had spent years leveraging the social media company’s reach to amplify thinly-veiled Russian propaganda criticizing the U.S. and antagonists of the Kremlin. Facebook announced Tuesday it removed 91 accounts, 46 pages, two groups and one Instagram page connected to Crimea-based media agencies, News Front and South Front, which researchers now say have connections to Russian intelligence services. Both outlets have existed for years, though Facebook removed them last month after detecting that they used fake accounts to post content and generate engagement. It’s a dichotomy that exemplifies Facebook’s approach to information operations: The company historically has been reluctant to remove political misinformation or conspiracy theories, but acts against account operators caught misrepresenting their identity. “The disclosure of this network is not necessarily new, but its amplification through the use of coordinated and inauthentic behavior is,” the Atlantic Council’s Digital […]

The post Facebook removed Russian propaganda network only after accounts got sloppy appeared first on CyberScoop.

Continue reading Facebook removed Russian propaganda network only after accounts got sloppy

Facebook scrubbed accounts related to QAnon and a designated hate group in April

Facebook said Tuesday it has removed a number of pages and accounts dedicated to a far-right conspiracy theory that’s gained traction among  President Trump’s supporters. In the company’s first action against the QAnon group, Facebook says it removed 20 accounts, six groups and five pages caught fabricating personas to like and comment on their own posts to build engagement. Some 133,000 accounts followed one or more of the pages, while 30,000 accounts were involved in at least one of the groups, according to Facebook. That large influence network came without the individuals behind the effort spending more than $1 on Facebook ads. Including that action, the company said Tuesday it removed a total of eight networks of inauthentic user sites, including 732 accounts and 793 pages, that were operating in 15 languages and focused on 30 countries through all of April. Much of the activity was linked to individuals in Russia, Iran […]

The post Facebook scrubbed accounts related to QAnon and a designated hate group in April appeared first on CyberScoop.

Continue reading Facebook scrubbed accounts related to QAnon and a designated hate group in April

US financial regulator warns of ‘widespread’ phishing campaign

An influential financial oversight organization is urging U.S. brokerage firms and securities organizations to be on the lookout for an ongoing email scam that aims to steal usernames and passwords. The Financial Industry Regulatory Authority, an industry-run organization overseeing brokers and exchange markets, published an alert Monday about an “ongoing” phishing campaign in which attackers are posing as FINRA executives. The messages typically include the name of the target organization in the subject line, and encourage recipients to download an attachment that requires “immediate attention.” In fact, the attachment may direct a user to a website that prompts them to enter their credentials for Microsoft Office or SharePoint, a corporate collaboration software. The notice did not cite any specific security incidents that may have inspired the bulletin. “FINRA reminds firms to verify the legitimacy of any suspicious email prior to responding to it, opening any attachments or clicking on any embedded links,” the advisory […]

The post US financial regulator warns of ‘widespread’ phishing campaign appeared first on CyberScoop.

Continue reading US financial regulator warns of ‘widespread’ phishing campaign

Indonesian e-commerce giant probes reported breach of 91 million credentials

Indonesia’s largest e-commerce platform says it’s investigating a possible data breach in which hackers claim to have stolen data about 91 million customers. Tokopedia, which is backed by $2 billion in funding from investors including SoftBank and Alibaba, told Reuters Saturday it was investigating an alleged theft of user data, though it maintained that user passwords were still encrypted. Indonesia’s Minister of Communication and Information Technology, Johnny G. Plate, on Sunday urged Tokopedia to “immediately improve its security system to prevent a further breach in data.” The government also has summoned the board of directors to clarify the current state of the investigation in a meeting Monday. The statement followed a series of tweets from Under the Breach, a data breach monitoring service, including screenshots, apparently from a vendor on a cybercriminal forum, advertising 15 million names, email addresses and hashed passwords. The same account then marketed 91 million records […]

The post Indonesian e-commerce giant probes reported breach of 91 million credentials appeared first on CyberScoop.

Continue reading Indonesian e-commerce giant probes reported breach of 91 million credentials

Trial delayed for former SEC watchdog accused of abusing computer access

A federal judge in New York has agreed to postpone the trial of a former U.S. government official accused of abusing his position at the Securities and Exchange Commission to access information about his new employer. U.S. prosecutors last year charged Michael Cohn, a former examiner for the SEC, with unauthorized access of a computer and obstruction of justice. During negotiations for a job at a private equity firm, GPB Holdings, Cohn told the company he possessed inside information about an SEC investigation into their behavior, according to an indictment. The exact technical nature of the alleged crime is not clear, based on the indictment. Cohn has pleaded not guilty.  U.S. District Judge Gary Brown, of the Eastern District of New York, on Wednesday agreed to delay the start of trial to September, after it was initially scheduled to begin on June 15, Law360 first reported. The decision came in response to a letter […]

The post Trial delayed for former SEC watchdog accused of abusing computer access appeared first on CyberScoop.

Continue reading Trial delayed for former SEC watchdog accused of abusing computer access

LabCorp investors file lawsuit, alleging ‘persistent’ failure to secure data

LabCorp investors have filed a lawsuit against the company following a major data breach last year that was one of three cybersecurity incidents the company has faced since 2018. The suit, filed by shareholder Raymond Eugenio on behalf of LabCorp investors, alleges that the medical testing company’s chief executive, chief financial officer, chief information officer and its board of directors failed to address “persistently deficient” data protection measures regarding the theft of data about millions of people. The legal complaint, first reported by Bloomberg, involves a hack on the American Medical Collection Agency (AMCA), a debt collection agency which made collections on behalf of LabCorp and other medical companies. Hackers stole data about roughly 20 million people, including some 7.7 LabCorp patients, between August 2018 and March 2019. In a separate incident, LabCorp exposed 10,000 medical documents, including patient test results, according to a TechCrunch article published in January. Burlington, […]

The post LabCorp investors file lawsuit, alleging ‘persistent’ failure to secure data appeared first on CyberScoop.

Continue reading LabCorp investors file lawsuit, alleging ‘persistent’ failure to secure data

Scammers are abusing mobile ad networks in an attempt to phish Android app users

A network that delivers ads to hundreds of Android apps also is directing users to malicious websites that could help scammers steal their information or overrun their device with spam. At least 400 apps in Google’s Play Store come embedded with proprietary software that is designed to help app developers monetize their program by serving ads. Scammers are exploiting that process, though, by inserting malicious ads into the software development kits (SDKs) which are meant to help developers earn a living. Domains and URLs sent in ads from the distribution framework known as StartApp flood users with links to malicious sites or push notifications for spam, according to new findings from mobile security firm Wandera provided exclusively to CyberScoop. StartApp, created and run by a New York-based marketing firm, does not appear to be behind any malicious content, though it is compensated by other firms that supply it with the malicious ads. StartApp did not […]

The post Scammers are abusing mobile ad networks in an attempt to phish Android app users appeared first on CyberScoop.

Continue reading Scammers are abusing mobile ad networks in an attempt to phish Android app users

How China’s government used social media against movements in Taiwan, Hong Kong

The Chinese government has adopted known disinformation techniques and utilized social media harassment campaigns to try to increase its influence in Asia, according to new findings that add to a growing body of research. In recent months, two distinct Chinese internet campaigns have sought to influence public opinion with fake news ahead of an election in Taiwan, and intimidate pro-democracy protesters in Hong Kong by posting their personal data online. Both efforts mimic similar Russian operations, and reflect how governments’ use of social media for propaganda efforts have become an everyday reality for much of the world’s population. The latest research, published Wednesday by the threat intelligence firm Recorded Future, comes after international journalists and nongovernmental organizations also have detailed the interference in semi-autonomous Hong Kong and the disputed region of Taiwan over the past year. “From a tactical standpoint, the mainland Chinese government views both Taiwan and Hong Kong as domestic information space,” […]

The post How China’s government used social media against movements in Taiwan, Hong Kong appeared first on CyberScoop.

Continue reading How China’s government used social media against movements in Taiwan, Hong Kong