Russian national pleads guilty to being part of $568 million fraud ring

A 33-year-old Russian man has pleaded guilty to being part of a cybercriminal enterprise that caused more than $568 million in losses through identity theft and stolen payment cards, the U.S. Justice Department announced Friday. Sergey Medvedev is accused of being a leader of the Infraud Organization, an online forum that trafficked in stolen financial data, malware “and other contraband,” the department said in a press release. Medvedev, also known as “Stells,” “segmed” and “serjbear,” pleaded guilty to RICO conspiracy in federal court in Nevada, U.S. officials said. Infraud was founded a decade ago by a Ukrainian national who wanted to make it the internet’s top spot for “carding,” or buying things with stolen credit card data, according to the indictment. Infraud members routed interested buyers to the automated sites of members, which offered malware and stolen financial and personal data, according to prosecutors. The organization’s slogan was, “In Fraud We Trust,” prosecutors […]

The post Russian national pleads guilty to being part of $568 million fraud ring appeared first on CyberScoop.

Continue reading Russian national pleads guilty to being part of $568 million fraud ring

Cybercriminals Leak ExecuPharm Internal Documents After Ransomware Attack

A successful ransomware attack was deployed on March 13 against ExecuPharm, a subsidiary of the U.S. Biopharmaceutical giant Parexel, according to a recent announcement made by the company. Unlike typical ransomware attacks, where bad actors encrypt da… Continue reading Cybercriminals Leak ExecuPharm Internal Documents After Ransomware Attack

Hackers file fake tax returns in scheme to steal IRS refunds

It may be open season for coronavirus scammers, but tax frauds aren’t letting up, either. Attackers tried obtaining large tax refunds by posing as clients of Weber and Company, the California-based accounting firm revealed last week. The scammers apparently accessed clients’ personal data — including, perhaps, Social Security numbers and bank account information — and used that to file fraudulent returns, Weber and Company said in a notification to California’s attorney general. The IRS and the FBI are investigating the matter, the company said. The number of attempted IRS scams tends to increase every year in March and April in the U.S., as legions of crooks try to steal Americans’ refunds. Earlier this month, the IRS said attackers exploiting the COVID-19 crisis could use stolen data to commit tax fraud. In 2016, the IRS said attackers had attempted to breach its online filing portal and steal Social Security numbers. For years, lawmakers have debated the proper response to incidents of this kind. It was not immediately clear […]

The post Hackers file fake tax returns in scheme to steal IRS refunds appeared first on CyberScoop.

Continue reading Hackers file fake tax returns in scheme to steal IRS refunds

Data breach: U.S. retailer J.Crew reveals 2019 security incident to customers

J.Crew suffered a credential stuffing attack that may have compromised the personal data of customers, the U.S. clothing retailer disclosed earlier this week. Fraudulent activity was apparently noticed last spring, but the firm did not reveal the numbe… Continue reading Data breach: U.S. retailer J.Crew reveals 2019 security incident to customers

US charges four Chinese military members with Equifax hack

The indictment suggests the hack was part of a series of major data thefts organized by Chinese military and intelligence agencies. Continue reading US charges four Chinese military members with Equifax hack

Cybercrooks busted for multimillion-dollar identity fraud

Organizations were attacked for employees’ data, including names, addresses and birthdates used to set up hundreds of bank accounts. Continue reading Cybercrooks busted for multimillion-dollar identity fraud

Children’s apparel company Hanna Andersson discloses data breach

Hanna Andersson, a children’s clothing company with stores across the country, has told customers that their card payment data may have been compromised in a security breach last year. For nearly two months from mid-September to mid-November, an “unauthorized third party” had access to card payment information that certain customers entered as they were checking out at Hanna Andersson’s website, Mike Edwards, the company’s CEO, said in a Jan. 15 letter to customers viewed by CyberScoop. The exposed data included payment card numbers, expiration dates, and CVV codes, along with customers’ names, billing addresses, and shipping addresses. Law enforcement officials recently told executives at Portland, Oregon-based Hanna Andersson that there was evidence of a breach, Edwards said. It is unclear how many customers were affected by the incident. While it doesn’t appear that every customer who visited the website during the two month period was victimized, Edwards said, the company […]

The post Children’s apparel company Hanna Andersson discloses data breach appeared first on CyberScoop.

Continue reading Children’s apparel company Hanna Andersson discloses data breach

What Are the Risks of the IoT in Financial Services?

The nature of financial business means that both the promise and the risks of the IoT in financial services are great.

The post What Are the Risks of the IoT in Financial Services? appeared first on Security Intelligence.

Continue reading What Are the Risks of the IoT in Financial Services?

For criminal hackers, Brazilian hotel networks appear to be easy targets

Cybercriminals have gone on a spree in Brazil’s hospitality industry, infecting the networks of hotels and tourism companies with malware that steals credit card data, according to researchers at Kaspersky. All told, the hackers have struck hospitality organizations in eight states across Brazil, and 20 hotels in that country and others around the world, Kaspersky said last week. Active since 2015, the hackers have stepped up their activity this year.  They are brazenly selling access to hotel networks they’ve breached to whoever is buying.  Some Brazilian criminals tout the extracted credit card data “as high quality and reliable” because it came from a hotel administration system, the researchers wrote in a blog post. The breaches often begin with spearphishing emails in fluent Portuguese to hotel employees. Once clicked, the emails open up malware capable of capturing data that flows downstream during the reservation process from popular sites like Booking.com. The findings underscore Brazil’s longstanding struggles […]

The post For criminal hackers, Brazilian hotel networks appear to be easy targets appeared first on CyberScoop.

Continue reading For criminal hackers, Brazilian hotel networks appear to be easy targets