CrowdStrike files to go public after losing $140 million last year

CrowdStrike, the cybersecurity vendor best known for investigating the 2016 data breach at the Democratic National Committee, is trying to go public. The California-based company on Tuesday filed for an initial public offering on the Nasdaq under the ticker symbol “CRWD.” The company aims to raise as much as $100 million in the IPO, according to a regulatory filing submitted to the U.S. Securities and Exchange Commission. The IPO is led by backers including Goldman Sachs, JPMorgan Chase, Barclays and Bank of America Merrill Lynch. In the fiscal year that ended on Jan. 31, the company reported a $140.1 million net loss on $249.8 million in revenue, according to the S-1 filing. Most of the firm’s revenue dollars come from its more than 2,500 subscriptions, though those incoming dollars are balanced by a motivation to growth: sales and marketing spending climbed by 66 percent to $172.7 million last year. Google and […]

The post CrowdStrike files to go public after losing $140 million last year appeared first on CyberScoop.

Continue reading CrowdStrike files to go public after losing $140 million last year

‘Typosquatting’ campaign imitated news outlets to spread propaganda for years, report says

Researchers have uncovered a years-long disinformation campaign in which suspected Iranian operatives masqueraded as well known international media outlets and used fake Twitter accounts to amplify fabricated news articles. The group, dubbed Endless Mayfly, published some 135 news articles on sites meant to look like Bloomberg, The Guardian, The Atlantic, Politico and others, according to findings published Tuesday by Citizen Lab, the team of researchers at the University of Toronto. The group impersonated outlets via a technique known as “typosquatting,” in which it used websites like “theatlatnic.com” instead of “theatlantic.com” to avoid detection. Endless Mayfly would use this method to push anti-Saudi narratives and other fabrications that would be picked up on social media and legitimate news outlets, Citizen Lab said. It also involved the use of 11 Twitter personas since 2016. The effort demonstrates how propagandists have adopted the SEO and social media tactics that media outlets and other organizations […]

The post ‘Typosquatting’ campaign imitated news outlets to spread propaganda for years, report says appeared first on CyberScoop.

Continue reading ‘Typosquatting’ campaign imitated news outlets to spread propaganda for years, report says

Twitter says bug gave ad partner access to iOS users’ location information

Twitter may have collected and shared location data from customers using Apple devices then shared that information with an advertising partner, the company announced Monday. The social media company said in a blog post a bug caused its app to collect and share iOS data with a “trusted partner.” The collected data was not retained and existed on Twitter’s systems for only a short time, the company said. Twitter has informed the users whose accounts were affected. “Specifically, if you used more than one account on Twitter for iOS and opted into using the precise location feature in one account, we may have accidentally collected location data when you were using any other account(s) on that same device for which you had not turned on the precise location feature,” the company said. Twitter’s announcement goes on to state that the company had “intended” to remove location data from the data […]

The post Twitter says bug gave ad partner access to iOS users’ location information appeared first on CyberScoop.

Continue reading Twitter says bug gave ad partner access to iOS users’ location information

How scammers made ad fraud a billion-dollar criminal industry

Whoever came up with “thieves rob banks because that’s where all the money is” needs to add “digital advertising” to the updated version of the adage. Criminals simply don’t need to go through all the trouble of stealing money from well-fortified financial institutions when they can just trick advertisers into directly lining their pockets. With internet ad revenue totaling more than $100 billion in 2018, scammers are following that line of money: ad fraud is set to cost the industry as much as $44 billion annually by 2022. But the problem has ramifications for more than just the digital advertising market. Digital ad revenue provides much of the financial underpinning of e-commerce and online-based businesses. Media agencies suffer when their analytics tools report a substantial amount of web traffic, but the amount of revenue doesn’t support the number of visitors tracked by their systems. Online ad fraud has become so profitable that […]

The post How scammers made ad fraud a billion-dollar criminal industry appeared first on CyberScoop.

Continue reading How scammers made ad fraud a billion-dollar criminal industry

Hackers allegedly stole $2.4 million in cryptocurrency in a six-month SIM hijacking spree

Nine people were charged with crimes related to stealing more than $2.4 million in cryptocurrency by hijacking victims’ mobile phone numbers, the U.S. Department of Justice said Thursday. Six men from throughout the U.S. and one from Ireland were named in an indictment unsealed Thursday alleging wire fraud, conspiracy to commit wire fraud, and aggravated identity theft. Stealing mobile phone numbers, also known as SIM hijacking, typically involves hackers posing as their victim in order to transfer a phone number from one device to another. Once an attacker is granted access to the phone number, they can bypass two-factor authentication that relies on one-time codes delivered via SMS messages. The Justice Department indictment alleges that members of the group, known as “The Community,” bribed customer support representatives to provide phone numbers, then used the numbers to subvert two-factor authentication and infiltrate a victims’ accounts, changing their passwords along the way. Three […]

The post Hackers allegedly stole $2.4 million in cryptocurrency in a six-month SIM hijacking spree appeared first on CyberScoop.

Continue reading Hackers allegedly stole $2.4 million in cryptocurrency in a six-month SIM hijacking spree

Alleged FIN7 hacking director Andrii Kolpakov set to be extradited to the U.S.

One of three men who allegedly helped lead the FIN7 hacking group, which the U.S. Department of Justice says is behind the theft of 15 million payment card numbers, is scheduled to be extradited to the U.S., CyberScoop has learned. Andrii Kolpakov, will plead not guilty when he arrives in court from Spain to face charges in U.S. District Court for the Western District of Washington, according to his attorney, Vadim Glozman, who took over the case in April. Glozman said the timing of the extradition is unclear, but another source familiar with the matter said it will be “in the coming weeks.” Spanish police arrested Koplakov in June 2018 at the behest of U.S. authorities. The Ukrainian national, who was 30 when he was taken into custody, faces 26 criminal counts in the U.S., including aggravated identity theft, intentional damage to a protected computer and wire fraud, according to a U.S. […]

The post Alleged FIN7 hacking director Andrii Kolpakov set to be extradited to the U.S. appeared first on CyberScoop.

Continue reading Alleged FIN7 hacking director Andrii Kolpakov set to be extradited to the U.S.

Tracing drug deals and kickbacks, feds arrest alleged operators of Deep Dot Web scheme

Authorities have arrested two men accused of operating Deep Dot Web, a site that helped people find places to illegally buy drugs online. The website, which has been seized by law enforcement as part of the operation, reaped more than $15 million in illegal proceeds since 2013, the Department of Justice said. Two Israeli men, Tal Prihar and Michael Phan, have been charged for allegedly running a scheme that earned commissions whenever Deep Dot Web visitors subsequently made purchases on dark web markets. “Deep Dot Web provided a one-stop information center for people who were trying to access the dark web,” Scott Brady, U.S. Attorney for the Western District of Pennsylvania, said in a press conference. “Not only did they provide links to specific dark web marketplaces, but they also provided tutorials to people who were new to this. … All of that, combined with the kickback scheme, made it the first place […]

The post Tracing drug deals and kickbacks, feds arrest alleged operators of Deep Dot Web scheme appeared first on CyberScoop.

Continue reading Tracing drug deals and kickbacks, feds arrest alleged operators of Deep Dot Web scheme

Binance cryptocurrency exchange blames hackers in theft of $40 million in bitcoin

Thieves have stolen more than $40 million worth of bitcoin from Binance, one of the world’s largest cryptocurrency exchanges, as part of a “large scale” security incident affecting roughly 2 percent of its bitcoin holdings, the company announced Tuesday. Hackers stole two-factor authentication keys, API data, and “potentially other info” through an attack that combined phishing and viruses, Binance said in a May 7 statement. The result was the withdrawal of 7,000 bitcoin, worth nearly $41 million at the time of the heist, from Binance’s “hot wallet” when the time was right. No user funds were affected by the breach. “The hackers had the patience to wait, and execute well-orchestrated actions through multiple seemingly independent accounts at the most opportune time,” the company said. “The transaction is structured in a way that passed our existing security checks. It was unfortunate that we were not able to block this withdrawal before it […]

The post Binance cryptocurrency exchange blames hackers in theft of $40 million in bitcoin appeared first on CyberScoop.

Continue reading Binance cryptocurrency exchange blames hackers in theft of $40 million in bitcoin

Financial crime outpaces espionage as top motivation for data breaches, Verizon report finds

Once again, it all comes back to the money. Seventy-one percent of the data breaches that occurred in the last year were financially motivated, according to Verizon’s annual Data Breach Investigations Report. While there’s been uptick in espionage targeting the manufacturing sector, the overwhelming majority of cybercrime still is carried out by hackers primarily interested in making a buck. Just ask the financial companies: For the first time last year, they reported more instances of fraud when a physical card was not used than when a card was present. “It’s not necessarily that attackers are changing their techniques, or even evolving,” said Alex Pinto, head of security research at Verizon, of the findings. “It’s that attackers are keen to go after whoever is the easiest target … and there was a very sharp uptick on financially motivated social engineering.” Verizon’s DBIR has become a well-regarded barometer of threats, hacking techniques and […]

The post Financial crime outpaces espionage as top motivation for data breaches, Verizon report finds appeared first on CyberScoop.

Continue reading Financial crime outpaces espionage as top motivation for data breaches, Verizon report finds

How many dark web marketplaces actually exist? About 100.

It turns out the dark web is pretty small. Despite a years-long drumbeat of sensational headlines and high profile arrests implying there’s an abundance of criminal masterminds lurking in the hidden corners of the internet, the reality is that the number of sites makes up less than 0.005 percent of the number of web pages on the open internet, according to new research. In findings set to be published Tuesday, the threat intelligence company Recorded Future sought to map the number of so-called .onion sites reachable via the anonymity browser Tor. Researchers found 55,828 different onion domains, and only 8,416 were active, though it’s not clear exactly how many of those are used for criminal activity, Garth Griffin, Recorded Future’s director of data science, told CyberScoop. “We know there are [roughly] 100 live onion sites that are part of the active criminal underground as either high-tier criminal forums, lower-tier but […]

The post How many dark web marketplaces actually exist? About 100. appeared first on CyberScoop.

Continue reading How many dark web marketplaces actually exist? About 100.