Blockbuster indictment against 80 fraud suspects details a complex global scam operation

The U.S. Department of Justice on Thursday unsealed charges against 80 people for their alleged involvement in email scams that defrauded victims out of at least $6 million and attempted to steal another $40 million. The indictment, initially filed on June 27, lays out a complex web of money laundering, identity theft and internet fraud campaigns, including alleged business email compromise (BEC) and romance scams. Most of the defendants are based in Nigeria, though others, including 14 people arrested on Thursday, were located in the U.S. The 145-page indictment includes more than 400 “overt acts” outlining an email fraud scheme in more detail than perhaps any other indictment in recent memory. “Today, we have taken a major step to disrupt criminal networks that use BEC schemes, romance scams and other frauds to fleece victims,” U.S. Attorney Nick Hanna said in a statement. “This indictment sends a message that we will […]

The post Blockbuster indictment against 80 fraud suspects details a complex global scam operation appeared first on CyberScoop.

Continue reading Blockbuster indictment against 80 fraud suspects details a complex global scam operation

Hacking group targets organizations focused on North Korea’s missile program

Hackers using web infrastructure associated with a known North Korean threat group are behind a dormant phishing campaign that’s targeted the ministry of foreign affairs in at least three countries, as well as a number of research organizations, according to findings shared exclusively with CyberScoop before their publication Wednesday. Researchers from Anomali, a threat intelligence company based in California, found a network of malicious websites that appear to be login portals for the French Ministry for Europe and Foreign Affairs, the Ministry of Foreign and European Affairs of the Slovak Republic, Stanford University, and a U.K. think tank, among other targets. Each of the targets has focused in some way on North Korea’s nuclear efforts, or the international sanctions issued as punishment for it. By tricking diplomats or other victims into entering their credentials into a malicious website, the hackers behind this apparent espionage effort could then use that information to […]

The post Hacking group targets organizations focused on North Korea’s missile program appeared first on CyberScoop.

Continue reading Hacking group targets organizations focused on North Korea’s missile program

LinkedIn stopped more than 21 million fake accounts this year, but legitimate users are the real challenge

All that corporate jargon filling up your LinkedIn feed actually could be one of the social media website’s best defenses against state-sponsored disinformation. The Microsoft-owned professional networking platform on Tuesday announced it’s blocked or removed 21.6 million fake accounts between January and June of this year. Some 19.5 million of those accounts were blocked at the registration stage, meaning they never became active, while employees caught another 2 million and members flagged roughly 67,000 more accounts. LinkedIn largely has been spared from the deluge of propaganda on Twitter and Facebook because so many users act like they do in the workplace, the New York Times reported last week, meaning that when one user starts raving with incoherent grammar, others notice. “We want to make sure our community continues to be a valuable resource for you; one that creates opportunities to find jobs, make connections and grow careers,” Paul Rockwell, LinkedIn’s […]

The post LinkedIn stopped more than 21 million fake accounts this year, but legitimate users are the real challenge appeared first on CyberScoop.

Continue reading LinkedIn stopped more than 21 million fake accounts this year, but legitimate users are the real challenge

Twitter, Facebook scrub coordinated activity targeting Hong Kong demonstrations

Facebook and Twitter collectively have removed hundreds of accounts that were participating in a state-backed information campaign against the pro-democracy movement in Hong Kong. Twitter on Monday said it suspended 936 accounts that “were deliberately and specifically attempting to sow political discord in Hong Kong” from inside mainland China. The company said it has “reliable evidence to support” the conclusion the government was behind the effort. Facebook announced its own removal of seven pages, three groups and five accounts that altogether had fewer than 20,000 followers. “Specifically, we identified large clusters of accounts behaving in a coordinated manner to amplify messages related to the Hong Kong protests,” Twitter said in a blog post. “The accounts we are sharing today represent the most active portions of this campaign; a larger, spammy network of approximately 200,000 accounts – many created following our initial suspensions – were proactively suspended before they were substantially […]

The post Twitter, Facebook scrub coordinated activity targeting Hong Kong demonstrations appeared first on CyberScoop.

Continue reading Twitter, Facebook scrub coordinated activity targeting Hong Kong demonstrations

Chinese state media bought Twitter ads to spread disinformation about Hong Kong protests

Twitter was posting advertisements on behalf of Chinese state media that portrayed the pro-democracy movement in Hong Kong as “increasingly violent,” according to the social media bookmarking site Pinboard. Ads originating with Xinhua News Agency, the Chinese government’s official media outlet, falsely reported that “All walks of life in Hong Kong called for a brake to be put on the blatant violence and for order to be restored,” according to Pinboard, a platform where ads and social media activity are catalogued and analyzed. Chinese officials are trying to disrupt international media coverage showing that the protests, known as the Umbrella Movement, are mostly peaceful. There have been eruptions of violence, such as when police fired bean bags at demonstrators, injuring one woman’s eye, and when authorities dispersed protesters by beating them with clubs. An estimated 1.7 million people marched Aug. 18 in a peaceful protest calling for reforms such as […]

The post Chinese state media bought Twitter ads to spread disinformation about Hong Kong protests appeared first on CyberScoop.

Continue reading Chinese state media bought Twitter ads to spread disinformation about Hong Kong protests

Amazon Web Services finds no ‘significant issues’ at other companies allegedly breached by Paige Thompson

If the alleged Capital One hacker also took information from dozens of other companies, as investigators suspect, then Amazon Web Services isn’t aware of it, according to the cloud computing giant. The company outlined its findings in a letter to Sen. Ron Wyden, D-Ore., who had sought more detail on how a reported misconfiguration in Capital One’s AWS server would have made it possible for a single individual to steal information about more than 100 million people. The letter said AWS is not aware of any breaches at other “noteworthy” customers, cautioning that there “may have been small numbers of these that haven’t been escalated to us.” This follows court filings indicating government investigators are probing whether the accused hacker, Paige Thompson, also took data from more than 30 other companies, along with Capital One. Wyden asked whether any vulnerabilities in the AWS cloud service — which serves millions of customers – contributed to the […]

The post Amazon Web Services finds no ‘significant issues’ at other companies allegedly breached by Paige Thompson appeared first on CyberScoop.

Continue reading Amazon Web Services finds no ‘significant issues’ at other companies allegedly breached by Paige Thompson

Cloudflare acknowledges risk from customers like 8chan, Daily Stormer in IPO filing

Internet services company Cloudflare has filed to go public, a long-anticipated move that comes amid ongoing controversy surrounding the firm’s reluctance to drop websites that allow hate speech. The San Francisco-based company on Thursday filed its S-1 document with the U.S. Securities and Exchange Commission, the first step in a process that will result in shares trading on the New York Stock Exchange under the “NET” symbol. It had 74,873 paying customers in the first half of this year, reporting a $36.8 million net loss on $129.2 million in revenue, according to the filing. Revenue was up 48% from the first half of 2018, the company said. Cloudflare aims to raise $100 million under the initial public offering. It offers distributed domain name server services, making it one of a handful of companies charged with ensuring vast swaths of the internet run smoothly and without interruption. Cloudflare also provides mitigation for distributed […]

The post Cloudflare acknowledges risk from customers like 8chan, Daily Stormer in IPO filing appeared first on CyberScoop.

Continue reading Cloudflare acknowledges risk from customers like 8chan, Daily Stormer in IPO filing

Financial hacking teams FIN7, Cobalt Group update tactics to haunt banks and retail

It’s starting to look like the global private sector might have a real problem on its hands. Despite international media attention and a series of high-profile arrests, some of the world’s most prolific cybercriminals only seem to be accelerating their hacking sprees. Financially motivated hacking groups including FIN7, Cobalt Group and the Contact Crew remain active, staying busy well into this year, according to Accenture Security’s 2019 Threatscape report. The cybercrime syndicates, which have haunted financial and retail companies since at least 2016, have spent the first half of 2019 updating their malicious software tools and expanding their reach. The findings are more bad news for international companies, which last year saw cyberattacks rank among the biggest risks for companies worldwide, according to the World Economic Forum. Now, if Accenture’s 102-page report is any indication, the world’s most capable hackers only are fine-tuning their techniques to carry out targeted intrusions. This comes […]

The post Financial hacking teams FIN7, Cobalt Group update tactics to haunt banks and retail appeared first on CyberScoop.

Continue reading Financial hacking teams FIN7, Cobalt Group update tactics to haunt banks and retail

Big name cybersecurity vendors are trying to buy their way to the top

Flush with cash and buzzing on the confidence that comes with sitting near the top of an emerging market during a strong economy, a handful of cybersecurity giants are lining up for a race where the winner could emerge as the nascent industry’s first dominant player. Major cybersecurity companies spent the first half of 2019 exploring business deals meant to complement their core product offering: device security. The entire industry has been in on the action, though, with more than 80 mergers or acquisitions in the first half of this year totaling more than $22 billion, according to numbers compiled by Cybersecurity Ventures. Compare that to the 58 deals totaling roughly $24 billion over the same period last year, though the financial terms in many of the deals in both years were not disclosed. The uptick is the result of a strong economy, and high valuations for security vendors that make it easier […]

The post Big name cybersecurity vendors are trying to buy their way to the top appeared first on CyberScoop.

Continue reading Big name cybersecurity vendors are trying to buy their way to the top

Peter Thiel says he doesn’t trust the FBI to safeguard an encryption backdoor

Peter Thiel says a U.S. law enforcement plan to access Americans’ protected communications is a bad idea. Thiel, founder of big data analytics platform Palantir and vocal supporter of President Donald Trump, told Fox News Sunday he supports the use of encryption to protect U.S. data. His comments come as government officials including, U.S. Attorney General William Barr, have threatened legislation that would require companies like WhatsApp and Apple to make it possible for the FBI to access encrypted messages. Thiel, a billionaire venture capitalist with a Silicon Valley background, suggested the FBI would not be able to ensure outsiders wouldn’t be able to use the same mechanisms to read communications that now are safe from prying eyes. “Maybe the FBI gets the information, maybe other people get it,” he told the Sunday morning show “Fox News Futures.” “I don’t trust the FBI to keep it protected inside the FBI…The […]

The post Peter Thiel says he doesn’t trust the FBI to safeguard an encryption backdoor appeared first on CyberScoop.

Continue reading Peter Thiel says he doesn’t trust the FBI to safeguard an encryption backdoor