‘Razzlekhan’ released on bond, husband detained ahead of cryptocurrency laundering trial

A U.S. judge Monday determined that Ilya Dutch Lichtenstein, one-half of the couple accused of a massive cryptocurrency laundering scheme, will await trial in prison. His wife and alleged co-conspirator, Heather Morgan, was set free on a $3 million bond package, with the conditions of strict electronic monitoring and limits on her virtual currency accounts. Federal law enforcement arrested the pair earlier this month for allegedly conspiring to launder $4.5 billion worth of cryptocurrency stolen in a 2016 hack of virtual cryptocurrency exchange Bitfinex.  Lichtenstein and Morgan employed sophisticated money-laundering techniques that included the use of a combination of fictitious identities, automatic transactions, and dispersing funds across virtual currency accounts. Prosecutors found access keys to the wallet containing the stolen cryptocurrency in Lichtenstein’s cloud storage, evidence that Judge Beryl Howell of the U.S. District for the District of Columbia called a “smoking gun.” Howell deemed the pair a strong flight risk […]

The post ‘Razzlekhan’ released on bond, husband detained ahead of cryptocurrency laundering trial appeared first on CyberScoop.

Continue reading ‘Razzlekhan’ released on bond, husband detained ahead of cryptocurrency laundering trial

‘Freedom Convoy’ donors exposed in possible cyberattack on GiveSendGo crowdfunding site

Christian crowdfunding website GiveSendGo is offline Monday due to an apparent hack after the company vowed to fight a Canadian court order to stop disbursing donated funds to a trucker convoy protesting COVID-19 measures in Canada. Sunday the website redirected to a domain “givesendgone[.]wtf” which showed a video from the Disney film frozen alongside a message condemning donors, the Daily Dot’s Mikael Thalen reported. As of Monday morning, the GiveSendGo site delivered an error message. The attackers also appear to have leaked donor information, including names, email addresses, zip codes and IP addresses, according to hacktivist group DDoSSecrets, which obtained the unsecured files. The Canadian protestors belong to a larger global “Freedom Convoy” protest movement by truckers seeking the end of vaccine and mask mandates. The protests have caused a state of emergency in parts of Ottawa, where protestors have been accused of aggressive and illegal behavior by law enforcement. The […]

The post ‘Freedom Convoy’ donors exposed in possible cyberattack on GiveSendGo crowdfunding site appeared first on CyberScoop.

Continue reading ‘Freedom Convoy’ donors exposed in possible cyberattack on GiveSendGo crowdfunding site

The new EARN IT Act poses an even greater threat to encryption, experts say

The Senate Judiciary Committee will consider legislation Thursday that privacy advocates are warning could pose a major threat to encrypted technologies. “Everyone who communicates with others on the internet should be able to do so privately,” a diverse group of civil society groups wrote in a letter Wednesday to the committee’s leaders. “But by opening the door to sweeping liability under state laws, the EARN IT Act would strongly disincentivize providers from providing strong encryption.” The Eliminating Abusive and Rampant Neglect of Interactive Technologies Act (EARN IT Act), introduced for the first time in 2020 by Sens. Lindsey Graham, R-S.C., and Richard Blumenthal, D-Conn., would remove legal liability immunity from tech platforms found in violation of federal or state laws regarding child sexual abuse materials (CSAM). The pair reintroduced the bill last month and it drew immediate criticism from privacy and civil liberties advocates who say the bill could jeopardize […]

The post The new EARN IT Act poses an even greater threat to encryption, experts say appeared first on CyberScoop.

Continue reading The new EARN IT Act poses an even greater threat to encryption, experts say

SEC’s breach notification proposal one step closer to a final vote

The Securities and Exchange Commission voted Wednesday 3-1 to approve a recommendation for tighter mandatory cybersecurity requirements for financial institutions. The proposed rule will now open to public comment before a final vote. “The proposed rules and amendments are designed to enhance cybersecurity preparedness and could improve investor confidence in the resiliency of advisers and funds against cybersecurity threats and attacks,”  SEC Chairman Gary Gensler said at the agency’s open meeting. Most critically, the new rule would require confidential reports of any “significant” cybersecurity incidents to the SEC within 48 hours. The proposal also would require advisers and funds to adopt, at a minimum, cybersecurity protections including a risk assessment; user security and access controls; information protection and monitoring to protect systems from unauthorized use; and an annual written review of cybersecurity risks and policies. The report would require review by a board of directors. Commissioners said they want more […]

The post SEC’s breach notification proposal one step closer to a final vote appeared first on CyberScoop.

Continue reading SEC’s breach notification proposal one step closer to a final vote

New York couple accused of laundering cryptocurrency from $4.5 billion Bitfinex hack

Federal law enforcement arrested a Manhattan couple Tuesday for allegedly conspiring to launder $4.5 billion worth of cryptocurrency stolen in a 2016 hack of virtual cryptocurrency exchange Bitfinex. The Department of Justice said it  so far has seized more than $3.6 billion in cryptocurrency tied to the hack, its largest recovery to date. The complaint accuses Ilya Lichtenstein, 34, and his wife, Heather Morgan, 31 of laundering the money over a course of five years, sometimes into their own financial accounts. The DOJ’s announcement does not specify if they were allegedly involved in the initial hack itself. Justice Department officials described the arrest as a warning to criminals trying to use virtual currencies to hide their tracks. “Today’s arrests, and the department’s largest financial seizure ever, show that cryptocurrency is not a safe haven for criminals,” Deputy Attorney General Lisa O. Monaco said in a statement. “Thanks to the meticulous […]

The post New York couple accused of laundering cryptocurrency from $4.5 billion Bitfinex hack appeared first on CyberScoop.

Continue reading New York couple accused of laundering cryptocurrency from $4.5 billion Bitfinex hack

CISA’s new JCDC worked as intended, witnesses say at Senate hearing on Log4Shell bug

Changes in federal cybersecurity leadership over the past year allowed the private and public sectors to quickly work together in responding to the disclosure of the Log4shell bug last month, experts said Tuesday at a Senate hearing. Witnesses at the Homeland Security and Governmental Affairs Committee hearing praised the usefulness of the Joint Cyber Defense Collaborative, a new center launched by the Cybersecurity and Infrastructure Security Agency in August to help federal agencies, the private sector and state and local governments collaborate on cyberthreat response. “Its structure provided a body to scramble a snap call on Saturday afternoon after Log4shell emerged to allow industry competitors act as partners with the government to share raw situational awareness and we must continue building upon this partnership,” said Jen Miller-Osborn, deputy director of threat intelligence at Palo Alto Networks’ Unit 42. The witnesses warned that the fallout from Log4shell — a vulnerability in […]

The post CISA’s new JCDC worked as intended, witnesses say at Senate hearing on Log4Shell bug appeared first on CyberScoop.

Continue reading CISA’s new JCDC worked as intended, witnesses say at Senate hearing on Log4Shell bug

IRS announces it will stop use of facial recognition for identity verification

The Internal Revenue Service will transition away from using a third-party authentication service that deploys facial recognition technology in order to verify new online accounts, the agency announced Monday. The transition will take place “over the coming weeks in order to prevent larger disruptions to taxpayers during filing season,” an IRS news release states. The pullback of the plan comes in response to growing concerns from both advocates and lawmakers that the agency’s decision to put the biometric data of millions of Americans into the private sector’s hands could pose enormous privacy and security risks. The IRS said it is working on developing an authentication process that does not involve facial recognition and will continue to collaborate with government partners to develop new authentication methods to protect taxpayer data. “The IRS takes taxpayer privacy and security seriously, and we understand the concerns that have been raised,” said IRS Commissioner Charles […]

The post IRS announces it will stop use of facial recognition for identity verification appeared first on CyberScoop.

Continue reading IRS announces it will stop use of facial recognition for identity verification

Lawmakers want IRS to address security concerns with use of facial recognition on taxpayers

Democrats and Republicans are turning up the pressure on the Internal Revenue Service to address privacy and security concerns with its plan to use facial recognition on millions of Americans who access the agency’s website for tax documents and payments. Sen. Ron Wyden, D-Ore., asked the agency Monday to reverse its decision and halt its work with facial-recognition-based identity verification provider, ID.me. “While the IRS had the best of intentions — to prevent criminals from accessing Americans’ tax records, using them to commit identity theft, and make off with other people’s tax refunds — it is simply unacceptable to force Americans to submit to scans using facial recognition technology as a condition of interacting with the government online, including to access essential government programs,” Wyden wrote in a letter to IRS Commissioner Charles Rettig, shared with CyberScoop. The letter adds to a growing charge by both Democrats and Republicans demanding […]

The post Lawmakers want IRS to address security concerns with use of facial recognition on taxpayers appeared first on CyberScoop.

Continue reading Lawmakers want IRS to address security concerns with use of facial recognition on taxpayers

Hackers stole more than $320 million in cryptocurrency from DeFi platform Wormhole

A hacker stole $320 million worth of Ethereum cryptocurrency from a decentralized finance platform Wormhole on Wednesday. The attack is the largest against the cryptocurrency industry so far in 2022 and one of the top hacks of the industry to date. As of Thursday morning, all of the stolen funds were “restored,” the trading platform was back up, and an incident report was coming soon, according to tweets by the company. The vulnerability used by the attacker had been fixed, Wormhole said late Wednesday. The platform allows users to send Ethereum and Solana cryptocurrencies across two different blockchains. A preliminary analysis of the attack by blockchain security firm CertiK shared with CyberScoop found that the hacker was able to exploit a vulnerability that allowed it to create a fake Solana transfer that it used to claim real Ethereum. “We seem to be at an awkward point where the demand for […]

The post Hackers stole more than $320 million in cryptocurrency from DeFi platform Wormhole appeared first on CyberScoop.

Continue reading Hackers stole more than $320 million in cryptocurrency from DeFi platform Wormhole

State Department offers $10M for information on Iranian election interference

The State Department is offering a $10 million reward for information on two Iranian hackers who allegedly participated in state-sponsored cyber operations designed to interfere with the 2020 U.S. presidential election. The two individuals, Seyyed Mohammad Hosein Musa Kazemi, 24, and Sajjad Kashian, 27, were charged with computer fraud, voter intimidation and transmission of interstate threats according to a federal indictment unsealed in November. The activity took place between August 2020 and November 2020. The State Department is offering the reward under its “Rewards for Justice” program, which has posted equal bounties for information about ransomware groups DarkSide and REvil. The indictment of the Iranians painted a picture of an extensive operation aimed at fomenting partisan divides ahead of the 2020 election. The campaign included allegedly sending threatening emails to Florida Democrats aimed at intimidating them into voting for Trump, while posing as the right-wing nationalist group Proud Boys. U.S. […]

The post State Department offers $10M for information on Iranian election interference appeared first on CyberScoop.

Continue reading State Department offers $10M for information on Iranian election interference