<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Krebs on Security &#187; Search Results  &#187;  money+mules</title>
	<atom:link href="http://krebsonsecurity.com/search/money+mules/feed/rss2/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Thu, 09 Feb 2012 22:39:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Busy Signal Service Targets Cyberheist Victims</title>
		<link>http://krebsonsecurity.com/2011/12/busy-signal-service-targets-cyberheist-victims/</link>
		<comments>http://krebsonsecurity.com/2011/12/busy-signal-service-targets-cyberheist-victims/#comments</comments>
		<pubDate>Tue, 20 Dec 2011 10:00:47 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[A Little Sunshine]]></category>
		<category><![CDATA[Web Fraud 2.0]]></category>
		<category><![CDATA[telephone ddos]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13011</guid>
		<description><![CDATA[A new service on the cyber criminal underground can be hired to tie up the phone lines of any targeted mobile or land line around the world. The service is marketed as a diversionary tactic to assist e-thieves in robbing commercial customers of banks that routinely call customers to verify large financial transfers.]]></description>
			<content:encoded><![CDATA[
<p>A new service on the cyber criminal underground can be hired to tie up the phone lines of any targeted mobile or land line around the world. The service is marketed as a diversionary tactic to assist e-thieves in robbing commercial customers of banks that routinely call customers to verify large financial transfers.</p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2011/12/phoneddos.png"><img class="alignright  wp-image-13018" title="phoneddos" src="http://krebsonsecurity.com/wp-content/uploads/2011/12/phoneddos-150x150.png" alt="" width="317" height="175" /></a>For just $5 an hour, or $40 per day, you can keep anyone&#8217;s phone so tied up with incoming junk calls that the number is unable to receive legitimate calls.</p>
<p>The seller offers discounts for frequent buyers of his service, and promises that each call to the targeted number will appear to come from a unique phone number, thereby foiling any efforts to block the bogus calls by caller ID. The vendor also is offering this service under escrow payment, which many fraud forums use to ensure both parties to a transaction are happy before payment is rendered.</p>
<p>The FBI first warned about these attacks <a title="FBI.gov: The Latest Phone Scam Targets Your Bank Account" href="http://www.fbi.gov/news/stories/2010/june/phone-scam" target="_blank">in June 2010</a>, advising that that receiving rapid-fire &#8220;dead air&#8221; calls could be a sign that your bank account is being emptied. From that advisory:</p>
<blockquote><p>&#8220;Denial-of-service attacks, by themselves, are nothing new—computer hackers use them to take down websites by flooding them with large amounts of traffic.&#8221;</p>
<p><em>&#8220;In a recent twist, criminals have transferred this activity to telephones, using automated dialing programs and multiple accounts to overwhelm the phone lines of unsuspecting citizens.&#8221;</em></p>
<p>&#8220;Why are they doing it? Turns out the calls are simply a diversionary tactic: while the lines are tied up, the criminals—masquerading as the victims themselves—are raiding the victims’ bank accounts and online trading or other money management accounts.&#8221;</p></blockquote>
<p><span id="more-13011"></span>The easy availability of this criminal offering highlights once again how nearly every aspect of the cyber underground has been converted into a service for hire. Take cyber heists, for instance: Everything about them can now be outsourced to third party services.</p>
<p>You can rent a botnet to send your Trojan-laced emails and steal online banking credentials from thousands who click the booby-trapped attachments. You can purchase Web injects that allow you to change the behavior of targeted bank Web sites as they are displayed in the victim&#8217;s browser. If you want help hauling the loot, you can rent access to money mules that are hired by mule recruitment gangs. And if you need a diversion to distract or otherwise occupy your victims while you rob them, you can rent this service.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/12/busy-signal-service-targets-cyberheist-victims/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>NY ID Theft Ring Used Insiders, Gang Members</title>
		<link>http://krebsonsecurity.com/2011/12/ny-id-theft-ring-used-insiders-gang-members/</link>
		<comments>http://krebsonsecurity.com/2011/12/ny-id-theft-ring-used-insiders-gang-members/#comments</comments>
		<pubDate>Fri, 16 Dec 2011 22:42:35 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Other]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13050</guid>
		<description><![CDATA[Authorities in Manhattan today unsealed indictments against 55 people suspected of operating an identity theft and financial fraud ring, including a number of insiders at banks and companies throughout New York who allegedly helped to steal more than $2 million from hundreds of customers and clients. Prosecutors say the 18-month-long investigation is notable because it [...]]]></description>
			<content:encoded><![CDATA[
<p>Authorities in Manhattan today unsealed indictments against 55 people suspected of operating an identity theft and financial fraud ring, including a number of insiders at banks and companies throughout New York who allegedly helped to steal more than $2 million from hundreds of customers and clients.</p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2011/12/cashgraf.jpg"><img class="alignright  wp-image-13057" title="cashgraf" src="http://krebsonsecurity.com/wp-content/uploads/2011/12/cashgraf.jpg" alt="" width="283" height="212" /></a>Prosecutors say the 18-month-long investigation is notable because it underscores the ways in which traditional street crooks are moving their activity online: New York authorities maintain that more than a dozen of the defendants have violent criminal records and belong to different street gangs in Brooklyn.</p>
<p>At the center of the alleged conspiracy are employees at New York institutions that had access to large amounts of sensitive consumer and business data. Among those being arraigned today in a New York state court are <strong></strong><strong>JP Morgan Chase</strong> employees <strong>Karen Chance</strong>, <strong>Mercy Adebandjo</strong> and <strong>Joanna Gierczack</strong>; <strong>Tracey Nelson</strong>, an employee of the <strong>United Jewish Appeal-Federation</strong>; <strong>Roberto &#8220;Robbie&#8221; Millar</strong>, a car salesman for <strong>Open Road-Audi in Brooklyn</strong>; and Nicola Bennett, a compliance officer employed by <strong>AKAM Associates Inc.,</strong> a residential property management company.</p>
<p>&#8220;These insiders used their positions to gain access to client data, and then sold that data to make money for themselves and their accomplices,&#8221; District Attorney Vance<strong></strong> said in <a href="http://www.manhattanda.com/press-release/da-vance-and-nypd-55-defendants-indicted-widespread-%E2%80%9Cinsider%E2%80%9D-cyberfraud-scheme" target="_blank">a written statement</a>. &#8220;We will continue to work with our partners to build significant cases to disrupt identity theft and dismantle these criminal organizations.”</p>
<p>The indictments allege that middlemen named in the conspiracy purchased personal information on customers and donors from Nelson and Millar, and then either re-sold the data or used it themselves to commit fraudulent financial transactions.</p>
<p>Prosecutors also charge that the Chase employees abused their access to steal personal data on account holders, and sold the information to counterfeit check makers and to individuals who specialized in setting up and executing fraudulent bank transfers.</p>
<p>Some of the defendants are alleged to have recruited other indicted members for the purpose of using their bank accounts to conduct fraudulent transactions. Prosecutors say the recruiters played a dual role: trafficking in stolen personal information bought from others, and recruiting people to provide bank accounts through which they could commit fraud.</p>
<p>These so-called &#8220;collusive account holders&#8221; &#8212; effectively complicit money mules &#8212; make up the bulk of the individuals named in the indictments. New York authorities charge that when defendants wanted to withdraw money quickly from collusive accounts, they purchased US Postal Service money orders with the debit cards linked to the accounts.</p>
<p>The indictments state that some the defendants arraigned today used automated systems set up by <strong>Citibank</strong> and <strong>TD Bank</strong> to change the personal information on ID theft victims&#8217; bank records, including the victims&#8217; contact address, phone numbers and email addresses.</p>
<p>For example, prosecutor alleged that one of the defendants,  <strong>Josiah &#8220;Pespi&#8221; Boatwains</strong>, would request that stolen credit cards be mailed to an address where a co-conspirator Richard Ramos, an employee at <strong>United Parcel Service</strong> (UPS) would intercept the cards on Boatwain&#8217;s behalf in exchange for money.</p>
<p>Boatwains and two other defendants allegedly then used those stolen cards to purchase luxury items that other defendants sold to co-conspirators named in the indictments. Other defendants allegedly used hijacked credit card account numbers to make online purchases buying airline tickets, movie ticket, credit reports, pizza and iTunes products.</p>
<p>A statement of facts filed with the New York State Supreme Court notes that there is a large amount of violent activity that surrounds the defendants in this case. The statement reads:</p>
<blockquote><p>&#8220;During the course of our investigation 2 targets of the investigation were murdered. One of the deceased was brutally murdered. When his body was found by the police, they recovered personal identifying information of victims linked to our case. Specifically, on his person, a copy of a check was found that was from one of our identity theft victims that had donated to the United Jewish Appeal.&#8221;<span id="more-13050"></span></p>
<p>&#8220;In addition, we are informed by the police department that many of these defendants are members of the Brooklyn Gang called &#8220;The Outlaws,&#8221; and others are Bloods and Crypts [sic]. Many of our defendants have violent criminal convictions.&#8221;</p></blockquote>
<p>New York authorities say they expect the dollar losses to increase as the investigation continues.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/12/ny-id-theft-ring-used-insiders-gang-members/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>DDoS Attacks Spell &#8216;Gameover&#8217; for Banks, Victims in Cyber Heists</title>
		<link>http://krebsonsecurity.com/2011/11/ddos-attacks-spell-gameover-for-banks-victims-in-cyber-heists/</link>
		<comments>http://krebsonsecurity.com/2011/11/ddos-attacks-spell-gameover-for-banks-victims-in-cyber-heists/#comments</comments>
		<pubDate>Wed, 30 Nov 2011 15:04:24 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[A Little Sunshine]]></category>
		<category><![CDATA[Latest Warnings]]></category>
		<category><![CDATA[Target: Small Businesses]]></category>
		<category><![CDATA[Web Fraud 2.0]]></category>
		<category><![CDATA[Arbor Networks]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[Dirt Jumper]]></category>
		<category><![CDATA[Gameover Trojan]]></category>
		<category><![CDATA[Jose Enrique Hernandez]]></category>
		<category><![CDATA[Jose Nazario]]></category>
		<category><![CDATA[NACHA]]></category>
		<category><![CDATA[National Automated Clearing House Association]]></category>
		<category><![CDATA[Prolexic]]></category>
		<category><![CDATA[Russkill]]></category>
		<category><![CDATA[ZeuS Trojan]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=12647</guid>
		<description><![CDATA[The FBI is warning that computer crooks have begun launching debilitating cyber attacks against banks and their customers as part of a smoke screen to detract attention away from simultaneous high-dollar cyber heists.

The bureau says the attacks coincide with corporate account takeovers perpetrated by thieves who are using a modified version of the ZeuS Trojan that's being called "Gameover." The thefts come after a series of heavy spam campaigns aimed at deploying the malware, which arrives disguised as an email from the National Automated Clearing House Association (NACHA), a not-for-profit group that develops operating rules for organizations that handle electronic payments. The ZeuS variant steals passwords and gives attackers direct access to the victim's PC and network.]]></description>
			<content:encoded><![CDATA[
<p>The <strong>FBI</strong> is warning that computer crooks have begun launching debilitating cyber attacks against banks and their customers as part of a smoke screen to prevent victims from noticing simultaneous high-dollar cyber heists.</p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2011/11/gameover.png"><img class="alignright size-medium wp-image-12674" title="gameover" src="http://krebsonsecurity.com/wp-content/uploads/2011/11/gameover-300x99.png" alt="" width="300" height="99" /></a>The bureau says the attacks coincide with corporate account takeovers perpetrated by thieves who are using a modified version of the ZeuS Trojan called &#8220;Gameover.&#8221; The rash of thefts come after a series of heavy spam campaigns aimed at deploying the malware, which arrives disguised as an email from the <strong>National Automated Clearing House Association</strong> (NACHA), a not-for-profit group that develops operating rules for organizations that handle electronic payments. The ZeuS variant steals passwords and gives attackers direct access to the victim&#8217;s PC and network.</p>
<p>In several recent attacks, as soon as thieves wired money out of a victim organization&#8217;s account, the victim&#8217;s public-facing Internet address was targeted by a network attack, leaving employees at the organization unable to browse the Web.</p>
<p>A few of the attacks have included an odd twist that appears to indicate the perpetrators are using <a title="Top 10 Ways to Get Fired as a Money Mule" href="http://krebsonsecurity.com/2010/01/top-10-ways-to-get-fired-as-a-money-mule/" target="_blank">money mules</a> in the United States for at least a portion of the heists. According to an FBI <a href="http://www.fbi.gov/denver/press-releases/2011/fbi-denver-cyber-squad-advises-citizens-to-be-aware-of-a-new-phishing-campaign" target="_blank">advisory</a>, some of the unauthorized wire transfers from victim organizations have been transmitted directly to high-end jewelry stores, &#8220;wherein the money mule comes to the actual store to pick up his $100K in jewels (or whatever dollar amount was wired).&#8221;</p>
<p>The advisory continues:</p>
<p>&#8220;Investigation has shown the perpetrators contact the high-end jeweler requesting to purchase precious stones and high-end watches. The perpetrators advise they will wire the money to the jeweler’s account and someone will come to pick up the merchandise. The next day, a money mule arrives at the store, the jeweler confirms the money has been transferred or is listed as &#8216;pending&#8217; and releases the merchandise to the mule. Later on, the transaction is reversed or cancelled (if the financial institution caught the fraud in time) and the jeweler is out whatever jewels the money mule was able to obtain.&#8221;</p>
<p>The attackers also have sought to take out the Web sites of victim banks. <strong>Jose Nazario</strong>, manager of security research at <a title="Arbor Networks Web site" href="http://www.arbornetworks.com/" target="_blank">Arbor Networks</a>, a company that specializes in helping organizations weather large cyber attacks, said that although many of the bank sites hit belong to small to mid-sized financial institutions, the thieves also have taken out some of the larger banks in the course of recent e-heists.</p>
<p>&#8220;It&#8217;s a disturbing trend,&#8221; Nazario said.</p>
<p>Nazario said the handful of attacks he&#8217;s aware of in the past two weeks have involved <a title="Wikipedia: DDoS" href="http://en.wikipedia.org/wiki/Denial-of-service_attack" target="_blank">distributed denial-of-service</a> (DDoS) assaults launched with the help of &#8220;Dirt Jumper&#8221; or &#8220;Russkill&#8221; botnets. Dirt Jumper is a commercial crimeware kit that is sold for a few hundred bucks on the hacker underground, and is made to be surreptitiously installed on hacked PCs. The code makes it easy for the botnet owner to use those infected systems to overwhelm targeted sites with junk traffic (KrebsOnSecurity.com <a title="DDoS Attack on KrebsOnSecurity.com" href="http://krebsonsecurity.com/2011/11/ddos-attack-on-krebsonsecurity-com/" target="_blank">was the victim of a Dirt Jumper botnet attack</a> earlier this month).</p>
<p>Security experts aren&#8217;t certain about the strategy behind the DDoS attacks, which are noisy and noticeable to both victims and their banks. One theory is that the perpetrators are hoping the outages will distract the banks and victims.</p>
<p>&#8220;The belief is the DDoS is used to deflect attention from the wire transfers as well to make them unable to reverse the transactions (if found),&#8221; the FBI said.</p>
<p><span id="more-12647"></span></p>
<p>That strategy seemed to have worked well against <strong>Sony</strong>, which focused on weathering a DDoS attack from Anonymous while information on more than 100 million customers was being siphoned by hackers.</p>
<p>&#8220;In the chaos of a DDoS, typically network administrators are so busy trying to keep the network up that they miss the real attack,&#8221; said <strong>Jose Enrique Hernandez</strong>, a security expert at <a title="Prolexic.com" href="http://www.prolexic.com/index.html" target="_blank">Prolexic</a>, a Hollywood, Fla. based DDoS mitigation company. &#8220;It&#8217;s a basic diversion technique.&#8221;</p>
<p>Another theory about the DDoS-enhanced heists holds that the thieves are trying to prevent victim organizations from being able to access their accounts online. One crime gang responsible for a large number of cyber heists against small to mid-sized U.S. businesses <a title="NY Firm Faces Bankruptcy From $164,000 eBanking Loss" href="http://krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/" target="_blank">frequently invoked the &#8220;kill operating system&#8221; command</a> built into the ZeuS Trojan after robbing victims.</p>
<p>Organizations that bank online should understand that they are liable for any losses stemming from cyber fraud. I have consistently advised small to mid-sized entities to consider using a dedicated computer for online banking &#8212; one that is not used for everyday Web surfing &#8212; and preferably a non-Windows system, or a <a title="Security Fix: Avoid Windows Malware - Bank on a Live CD" href="http://voices.washingtonpost.com/securityfix/2009/10/avoid_windows_malware_bank_on.html" target="_blank">&#8220;live CD&#8221; distribution</a>.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/11/ddos-attacks-spell-gameover-for-banks-victims-in-cyber-heists/feed/</wfw:commentRss>
		<slash:comments>23</slash:comments>
		</item>
		<item>
		<title>Title Firm Sues Bank Over $207k Cyberheist</title>
		<link>http://krebsonsecurity.com/2011/11/title-firm-sues-bank-over-207k-cyberheist/</link>
		<comments>http://krebsonsecurity.com/2011/11/title-firm-sues-bank-over-207k-cyberheist/#comments</comments>
		<pubDate>Mon, 14 Nov 2011 05:01:55 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Target: Small Businesses]]></category>
		<category><![CDATA[Alvarez Here and Now Inc.]]></category>
		<category><![CDATA[capital one]]></category>
		<category><![CDATA[Chevy Chase Bank]]></category>
		<category><![CDATA[Dorin Codreanu]]></category>
		<category><![CDATA[Dwaine Peterson]]></category>
		<category><![CDATA[Global Title Services]]></category>
		<category><![CDATA[j1 mules]]></category>
		<category><![CDATA[Key Marius Import LLC]]></category>
		<category><![CDATA[money mules]]></category>
		<category><![CDATA[Priya Aurora]]></category>
		<category><![CDATA[PWD Properties]]></category>
		<category><![CDATA[Sharp and Bright Designs Inc.]]></category>
		<category><![CDATA[ZeuS Trojan]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=11140</guid>
		<description><![CDATA[A title insurance firm in Virginia is suing its bank after an eight-day cyber heist involving more than $2 million in thefts and more than $200,000 in losses last year. In an unusual twist, at least some of the Eastern European thieves involved in the attack have already been convicted and imprisoned for their roles in the crime.]]></description>
			<content:encoded><![CDATA[
<p>A title insurance firm in Virginia is suing its bank after an eight-day cyber heist involving more than $2 million in thefts and more than $200,000 in losses last year. In an unusual twist, at least some of the Eastern European thieves involved in the attack have already been convicted and imprisoned for their roles in the crime.</p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2011/11/globaltitlellc.png"><img class="alignright size-full wp-image-12171" title="globaltitlellc" src="http://krebsonsecurity.com/wp-content/uploads/2011/11/globaltitlellc.png" alt="" width="198" height="215" /></a>Sometime before June 2010, crooks infected computers of Vienna, Va. based <a title="MyGlobalTitle.com" href="http://www.myglobaltitle.com/" target="_blank">Global Title Services</a> with the ZeuS Trojan, giving them direct access to the company&#8217;s network and online banking passwords at then-<strong>Chevy Chase Bank</strong> (now<strong> Capital One</strong>). On June 1, 2010, the thieves made their move, and began sending a series of unauthorized wire transfers to money mules, individuals who were hired to help launder the funds and relay them to crooks overseas.</p>
<p>The first three wires totaled more than $200,000. When Global Title&#8217;s owner <strong>Priya Aurora</strong> went to log in to her company&#8217;s accounts 15 minutes prior to the first fraudulent transfers went out, she found the account was locked: The site said the account was overdue for security updates.</p>
<p>When Aurora visited the bank local Chase branch to get assistance, she was told she needed to deal with the bank&#8217;s back office customer service. Between June 2 and June 8, the thieves would send out 15 more wires totaling nearly $1.8 million. The bank ultimately was able to reverse all but the first three fraudulent wires on June 1.</p>
<p>Capital One declined to comment for this story, citing the ongoing litigation.</p>
<p>Global Title is suing Capital One, alleging the bank failed to act in good faith and failed to implement commercially reasonable security procedures for its online banking clients. The lawsuit notes that at the time of the breach, Capital One&#8217;s online banking system used single-factor authentication; it allowed commercial clients to log in and to transfer millions of dollars using nothing more than a username and password.</p>
<p><span id="more-11140"></span>&#8220;By operating a single factor identification online banking system, Capital One lefts its customers open to identity theft and failed to take sufficient safeguards to prevent unauthorized access to its client’s online banking accounts, including the ability to send wire transfers,&#8221; the company charged in its complaint.</p>
<p>Global Title also alleges that Capital One should have known that the transfers were fraudulent and unauthorized.</p>
<p>&#8220;Capital One was put on notice through Ms. Aurora’s phone call at 2:09 on June 1, 2010, and on subsequent calls that same day, that Global Title had no access to its online banking system,&#8221; the complaint states. &#8220;Accordingly, Capital One knew or should have known that any wire transfer that afternoon would be unauthorized.&#8221;</p>
<p>BUSY, BUSY MULES</p>
<div id="attachment_12165" class="wp-caption alignleft" style="width: 149px"><a href="http://krebsonsecurity.com/wp-content/uploads/2011/11/codreanu.png"><img class="size-full wp-image-12165" title="codreanu" src="http://krebsonsecurity.com/wp-content/uploads/2011/11/codreanu.png" alt="" width="139" height="203" /></a><p class="wp-caption-text">Dorin Codreanu</p></div>
<p>Some of the fraudulent activity was tied to money mule activity that was busted up by federal prosecutors last year. Two wires totaling more than $234,000 were sent to <strong>Key Marius Import LLC</strong>, a company flagged by federal investigators as a fraudulent front for organized cyber thieves.  In November 2010, Wisconsin police <a title="Authorities Nab More Zeus-Related Money Mules" href="http://krebsonsecurity.com/2010/11/authorities-nab-more-zeus-related-money-mules/" target="_blank">arrested two men</a> who were wanted as part of a crackdown in late Sept. 2010 on so-called &#8220;J1&#8243; money mules who were in the United States on work/travel visas. According to <a title="New York FBI Press Release" href="http://www.fbi.gov/newyork/press-releases/2010/nyfo093010.htm" target="_blank">an FBI press release from last fall</a>, Key Marius and the commercial bank account attached to it were set up by one of those men, <strong>Dorin Codreanu</strong>, a Moldovan who pleaded guilty to conspiracy charges earlier this year.</p>
<p>Codreanu was sentenced to three years in prison, and ordered to pay restitution of more than $110,000 to his victims. The <a title="Codreanu Judgment" href="http://krebsonsecurity.com/wp-content/uploads/2011/11/codreanu-judgment.pdf" target="_blank">court judgment against him</a> (PDF) states that the company Codreanu was ordered to pay restitution was not Global Title but a <strong>Dinkels Bakery</strong>; the remainder of the $110,000 restitution was to be paid to court services, Level One Bank and JP Morgan Chase.</p>
<p>Other companies that received large wire transfers may also have been fronts set up in advance of the attack. Key Marius Import LLC was established in April 2010, as were; <a title="California Business Filings: Alvarez Here and Now, Inc." href="https://businessfilings.sos.ca.gov/frmDetail.asp?CorpID=03287618" target="_blank">Alvarez Here and Now, Inc.</a> of Ontario, Calif, which received a fraudulent wire of $39,560 on June 2; <a title="California Secretary of State Record: Sharp and Bright Designs LLC" href="http://krebsonsecurity.com/wp-content/uploads/2011/11/sharpandbrightdesigns.png" target="_blank">Sharp and Bright Designs Inc.</a> of Simi Valley, Calif., which was sent a bogus wire of $19,583 from Global Title on June 2; <a title="Delaware Secretary of State: PWD Properties" href="http://krebsonsecurity.com/wp-content/uploads/2011/11/pwdproperties.png" target="_blank">PWD Properties</a>, incorporated in late January 2010 in Wilmington, Del., was sent a fraudulent wire of $28,582 on June 2.</p>
<p>Capital One was able to reverse all but the first three fraudulent wires ($119,500 to Key Marius, $39,560 to Alvarez Here and Now, and $48,698 to a <strong>Dwaine Peterson</strong>), leaving Global Title with a $207,758 loss. As a result, it was forced to take out a loan to make the required cash distributions from the firm&#8217;s escrow account.</p>
<p>UNCERTAIN LEGAL GROUND</p>
<p>Banks in the United States are supposed to adhere to online banking authentication guidance issued in 2005 by regulators at the <strong>Federal Financial Institutions Examination Council</strong> (FFIEC), but many institutions have been slow to comply with the guidelines.</p>
<p>Several victims of corporate account takeovers have sued their banks, claiming similar negligence, but with mixed results. In June 2011, a Michigan court <a title="Court Favors Small Business in eBanking Fraud Case" href="http://krebsonsecurity.com/2011/06/court-favors-small-business-in-ebanking-fraud-case/" target="_blank">held Comerica Bank liable</a> for more than half a million dollars stolen in a 2009 cyber heist. Two months later, a district court judge in Maine <a title="Judge Nixes Patco's eBanking Fraud Case" href="http://krebsonsecurity.com/2011/08/judge-nixes-patcos-ebanking-fraud-case/" target="_blank">ruled</a> that banks which protect accounts with little more than passwords and secret questions are in compliance with the FFIEC&#8217;s security guidance.</p>
<p>Faced with <a title="Krebs on Security Category: Small Business Victims" href="http://krebsonsecurity.com/category/smallbizvictims/" target="_blank">an explosion of corporate account takeovers</a> in the past two years, the FFIEC <a title="Regulators Issue Update eBanking Security Guidelines" href="http://krebsonsecurity.com/2011/06/regulators-issue-updated-ebanking-security-guidelines/" target="_blank">recently updated its guidance</a>, which calls for &#8220;layered security programs&#8221; to deal with riskier commercial banking transactions, including methods for detecting transaction anomalies, the use of out-of-band verification, and enhanced customer awareness campaigns. Those requirements, which will inform the activities of bank security examiners, are set to take effect on Jan. 1, 2012.</p>
<p>Avivah Litan, a fraud analyst with <strong>Gartner Inc.</strong>, said many banks are still out of compliance with the FFIEC&#8217;s older guidance.</p>
<p>&#8220;The new guidance isn&#8217;t that radical, and it basically re-affirms the previous guidelines and clarifies some points,&#8221; Litan said. &#8220;This case sounds like a clear violation of the FFIEC guidance, which says put controls in place that are commensurate with the risk, and many banks still aren&#8217;t doing that.&#8221;</p>
<p>Global Title is asking the court for a $500,000 judgment, plus pre- and post-judgment interest and attorney&#8217;s fees. Their legal challenged has cleared its first major set of procedural hurdles, and unless both parties settle before then, the case is scheduled to go to trial on April 10, 2012.</p>
<p>A copy of the company&#8217;s complaint is available <a title="Amended Complaint Global Cap One" href="http://krebsonsecurity.com/wp-content/uploads/2011/11/Amende-Complaint-Global-Cap-One.pdf" target="_blank">here</a> (PDF).</p>
<p>Update, 12:36 p.m. ET: Fixed the link to Global Title&#8217;s complaint filing.</p>
<p>Update, Nov. 15, 4:53 p.m. ET: Capital One provided the following statement in response to this article:</p>
<p>&#8220;Capital One&#8217;s authentication controls protecting our commercial platforms are compliant with the federal multifactor authentication guidance. These controls are the subject of annual risk assessments to ensure they remain appropriate in light of the threat environment. In the funds transfer realm, among the controls utilized are hard tokens and out-of-band confirmation of payment instructions.</p>
<p>As part of our broader security measures, Capital One provides security &#8211; and safe computing &#8211; related &#8216;best practice&#8217; tips and recommendations to let our small business and commercial clients know what they can do to protect themselves and reduce their fraud risk.&#8221;</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/11/title-firm-sues-bank-over-207k-cyberheist/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>ZeuS Trojan Gang Faces Justice</title>
		<link>http://krebsonsecurity.com/2011/10/zeus-trojan-gang-faces-justice/</link>
		<comments>http://krebsonsecurity.com/2011/10/zeus-trojan-gang-faces-justice/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 16:48:02 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Target: Small Businesses]]></category>
		<category><![CDATA[Donetsk]]></category>
		<category><![CDATA[Karina Kostromina]]></category>
		<category><![CDATA[Valerij Milka]]></category>
		<category><![CDATA[Yevhen Kulibaba]]></category>
		<category><![CDATA[Yuriy Konovalenko]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=11753</guid>
		<description><![CDATA[Authorities in the United Kingdom have convicted the 13th and final defendant from a group arrested last year and accused of running an international cybercrime syndicate that laundered millions of dollars stolen from consumers and businesses with the help of the help of the ZeuS banking Trojan. The news comes days after U.S. authorities announced the guilty plea of the 27th and final individual arrested last year in New York in a related international money-laundering scheme.]]></description>
			<content:encoded><![CDATA[
<p>Authorities in the United Kingdom have convicted the 13th and final defendant from a group arrested last year and accused of running an international cybercrime syndicate that laundered millions of dollars stolen from consumers and businesses with the help of the help of the <strong>ZeuS</strong> banking Trojan. The news comes days after U.S. authorities announced the guilty plea of the 27th and final individual arrested last year in New York in a related international money-laundering scheme.</p>
<div id="attachment_5463" class="wp-caption alignright" style="width: 160px"><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2010/09/kuli.jpg"><img class="size-thumbnail wp-image-5463" title="kuli" src="http://krebsonsecurity.com/wp-content/uploads/2010/09/kuli-150x150.jpg" alt="Yevhen Kulibaba" width="150" height="150" /></a><p class="wp-caption-text">Yevhen Kulibaba</p></div>
<p>According to the <a href="http://www.met.police.uk/pressbureau/Bur03/page07.htm" target="_blank">Metropolitan Police</a>, the U.K. courts have convicted 13 members of the gang, including four who were <a href="http://krebsonsecurity.com/2010/09/11-charged-in-zeus-money-mule-ring/" target="_blank">profiled</a> last year by KrebsOnSecurity shortly after their initial arrest and charging. The gang is thought to have used the ZeuS Trojan to steal nearly £3 million (USD $4.6M) from banks in the U.K.. They are believed to be responsible for aiding in the theft of at least USD $3 million from U.S. banks and businesses in the past two years.</p>
<div id="attachment_5400" class="wp-caption alignleft" style="width: 160px"><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2010/09/karinak.jpg"><img class="size-thumbnail wp-image-5400" title="karinak" src="http://krebsonsecurity.com/wp-content/uploads/2010/09/karinak-150x150.jpg" alt="" width="150" height="150" /></a><p class="wp-caption-text">Karina Kostromina</p></div>
<p title="Metro: Computer Hackers Stole £44million">Among those convicted were the husband-and-wife ringleaders of the gang, 33-year-old Ukrainian property developer <strong>Yevhen Kulibaba, </strong>and his wife, <strong>Karina Kostromina</strong>, 34. According to British prosecutors, the two lived a &#8220;jet set&#8221; lifestyle and spent money on holidays, cars and property. Kostromina was cleared of conspiracy charges but convicted of money laundering, and sentenced this week to two years in prison. Kulibaba is awaiting sentencing on charges of conspiracy to defraud.</p>
<p><span id="more-11753"></span></p>
<div id="attachment_5465" class="wp-caption alignright" style="width: 160px"><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2010/09/konov.jpeg"><img class="size-thumbnail wp-image-5465" title="konov" src="http://krebsonsecurity.com/wp-content/uploads/2010/09/konov-150x150.jpg" alt="" width="150" height="150" /></a><p class="wp-caption-text">Yuriy Konovalenko</p></div>
<p>An individual described as Kulibaba&#8217;s right-hand man &#8212; 29-year-old <strong>Yuriy Konovalenko</strong>, aka &#8220;Pavel Klikov&#8221; &#8212; is due to be sentenced, also for conspiracy. <strong>Valerij Milka</strong>, a 30-year-old Ukrainian whom U.K. police say was a building laborer and fourth member of the conspiracy, was jailed for three years after admitting his role.</p>
<div id="attachment_5408" class="wp-caption alignleft" style="width: 160px"><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2010/09/milka.jpg"><img class="size-thumbnail wp-image-5408" title="milka" src="http://krebsonsecurity.com/wp-content/uploads/2010/09/milka-150x150.jpg" alt="" width="150" height="150" /></a><p class="wp-caption-text">Milka &quot;Valera&quot; Valerij</p></div>
<p>News of the convictions in the United Kingdom comes days after authorities in the United States announced <a href="http://www.fbi.gov/newyork/press-releases/2011/nikolay-garifulin-pleads-guilty-in-manhattan-federal-court-to-involvement-in-global-bank-fraud-scheme-that-used-zeus-trojan-to-steal-millions-of-dollars-from-u.s.-bank-accounts" target="_blank">the guilty plea</a> of the 27th and final individual arrested last year in New York as part of <a title="KrebsOnSecurity: US Charges 37 Alleged Money Mules" href="http://krebsonsecurity.com/2010/09/u-s-charges-37-alleged-money-mules/" target="_blank">a major law enforcement sweep against Russian and Eastern European exchange students-turned-money mules</a>. U.S. prosecutors have charged a total of 37 Russian and Eastern European students in connection with last year&#8217;s law enforcement sweep; According to the FBI, two defendants have entered into deferred prosecution agreements, and eight defendants are fugitives and are being sought in the United States and abroad.</p>
<p>It should be noted that these individuals were only a small part of a much larger fraud ring. According to sources close to the investigation, the true masterminds of these ZeuS-powered bank heists reside in Donetsk, Ukraine, and have yet to be charged with any crime. Authorities in Ukraine this time last year <a title="KrebsOnSecurity: Ukraine Detains 5 Individuals Tied to $70 Million in U.S.  eBanking Heists" href="http://krebsonsecurity.com/2010/10/ukraine-detains-5-individuals-tied-to-70-million-in-ebanking-heists/" target="_blank">detained five individuals </a>identified by the FBI and other national law enforcement authorities as the &#8220;coders and exploiters&#8221; in the fraud operation, but the men were released and have not been charged with a crime.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/10/zeus-trojan-gang-faces-justice/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Monster Spam Campaigns Lead to Cyberheists</title>
		<link>http://krebsonsecurity.com/2011/10/monster-spam-campaigns-lead-to-cyberheists/</link>
		<comments>http://krebsonsecurity.com/2011/10/monster-spam-campaigns-lead-to-cyberheists/#comments</comments>
		<pubDate>Mon, 03 Oct 2011 04:17:47 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Target: Small Businesses]]></category>
		<category><![CDATA[Center for Cancer Care]]></category>
		<category><![CDATA[City of Oakdale]]></category>
		<category><![CDATA[John Ziak]]></category>
		<category><![CDATA[Mary Sugg Lovejoy]]></category>
		<category><![CDATA[Modesto Bee]]></category>
		<category><![CDATA[North Putnam Community School Corporation]]></category>
		<category><![CDATA[Oak Valley Community Bank]]></category>
		<category><![CDATA[Oncology Services of North Alabama]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=11607</guid>
		<description><![CDATA[Phishers and cyber thieves have been casting an unusually wide net lately, blasting out huge volumes of fraudulent email designed to spread password-stealing banking Trojans. Judging from the number of victims who reported costly cyber heist in the past two weeks, many small to medium sized organizations took the bait.]]></description>
			<content:encoded><![CDATA[
<p>Phishers and cyber thieves have been casting an unusually wide net lately, blasting out huge volumes of fraudulent email designed to spread password-stealing banking Trojans. Judging from the number of victims who reported costly cyber heists in the past two weeks, many small to medium sized organizations took the bait.</p>
<div id="attachment_11619" class="wp-caption alignright" style="width: 310px"><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2011/09/commtouchnacha2.png"><img class="size-medium wp-image-11619" title="commtouchnacha2" src="http://krebsonsecurity.com/wp-content/uploads/2011/09/commtouchnacha2-300x181.png" alt="" width="300" height="181" /></a><p class="wp-caption-text">These fake NACHA lures were mailed the week of Sept. 19, even though the sent date on the message says Aug. 3. Source: Commtouch.</p></div>
<p>Security firm Symantec <a title="Symantec Intelligence Reports" href="http://www.symanteccloud.com/globalthreats/overview/r_mli_reports" target="_blank">says</a> it detected an unprecedented jump in spam blasts containing &#8220;polymorphic malware,&#8221; &#8212; malicious software that constantly changes its appearance to evade security software. One of the most tried-and-true lures used in these attacks is an email crafted to look like it was sent by <strong>NACHA</strong>, a not-for-profit group that develops operating rules for organizations that handle electronic payments, from payroll direct deposits to online bill pay services.</p>
<p>Using NACHA&#8217;s name as bait is doubly insulting because victims soon find new employees &#8212; <a title="KrebsonSecurity Stories involving money mules" href="http://krebsonsecurity.com/tag/money-mules/" target="_blank">money mules</a> &#8212; added to their payroll. After adding the mules, the thieves use the victim&#8217;s online banking credentials to push through an unauthorized batch of payroll payments to the mules, who are instructed to pull the money out in cash and wire the funds (minus a commission) overseas.</p>
<p>On Sept. 13, computer crooks stole approximately $120,000 from <strong>Oncology Services of North Alabama</strong>, a component of the <strong>Center for Cancer Care</strong>, a large medical health organization in Alabama. <strong>John Ziak</strong>, director of information technology at the center, said he suspects the organization&#8217;s accounting firm was the apparent source of the compromise. That means other clients may also have been victimized. He declined to name the accounting firm.</p>
<p><span id="more-11607"></span></p>
<p>Ziak said the bank was able to block some of the fraudulent transfers, but that it was too soon to say how much the thieves got away with. But the center may have better leverage than most victims in convincing the bank to accommodate them: Many of its doctors are on the board of directors of the organization&#8217;s bank.</p>
<p>&#8220;We still don&#8217;t know how much is going to be coming back,&#8221; Ziak said. &#8220;We can chalk it up to lessons learned, but we&#8217;re going to be making some changes with the bank&#8230;forcing them to implement a higher level of security for our account.&#8221;</p>
<p>Last month, computer crooks also robbed the <strong>North Putnam Community School Corporation</strong>, which serves the children of six northern townships of Putnam County, Indiana.</p>
<p><strong>Mary Sugg Lovejoy</strong>, superintendent of the K-12 school system, said thieves stole about $98,000 from school coffers, sending the money to numerous individuals who had no prior business with the school district. Fortunately for North Putnam, all of the fraudulent transfers were returned shortly after the attack, Lovejoy said.</p>
<p>In a separate attack on a public institution, malicious hackers last month struck the<strong> City of Oakdale, Calif.</strong>, according to <a title="Modesto Bee: Cybercriminals Targeted City" href="http://www.modbee.com/2011/09/21/1871130/cyber-criminals-targeted-city.html#disqus_thread" target="_blank">a story in the Modesto Bee</a>. High-tech criminals stole $118,000 from a city bank account, the publication reported last week. Oakdale city officials are confident that its insurance carrier would reimburse the loss, minus a $2,500 deductible.</p>
<p>But that story ended on a sour note. The reporter quoted officials from the city&#8217;s bank, Oak Valley Community Bank, wrongly laying blame for the incident on a lack of technology and security.</p>
<p>&#8220;It&#8217;s the same story we hear from a lot of institutions,&#8221; Oak Valley President <strong>Chris Courtney</strong> said. &#8220;It&#8217;s about safekeeping the information on your computers, scanning for viruses and having a state-of-the-art security system.&#8221;</p>
<p>Blocking these attacks has little to do with state-of-the-art computer systems or scanning files with anti-virus. It&#8217;s not clear what malware family was used in any of these attacks, although the first two mentioned in this story involved a cyber gang that favors the ZeuS Trojan (the fraudulent NACHA messages in the screen shot above contained a malware dropper that installs ZeuS). But organizations should understand that these attacks have far more to do with social engineering and tricking humans than with defeating technology and security solutions.</p>
<p>As I&#8217;ve noted in past stories, all of the victims I&#8217;ve interviewed were running anti-virus software: Very few of them had protection against the malware used in the attack <em>until after their money was stolen</em>.</p>
<p>Most commercial banks have significant room for improvement in securing the transaction and authentication space for their customers. But businesses that rely on their financial institutions to detect fraudulent activity are setting themselves up for an expensive lesson.</p>
<p>No single approach or technology will stop all of these account takeovers, but preventing the theft of your online banking credentials is a critical first step. That&#8217;s why I continue to advise that small- to mid-sized organizations use a dedicated computer for online banking. Using a non-Windows PC &#8212; such as a <a href="http://voices.washingtonpost.com/securityfix/2009/10/e-banking_on_a_locked_down_non.html" target="_blank">Live CD</a> or a <strong>Mac</strong> &#8212; is the safest approach, but not necessarily the most practical or affordable. An alternate approach is to access bank accounts from an isolated PC that is locked-down, regularly updated, and used for no other purpose than online banking.</p>
<div id="attachment_11688" class="wp-caption aligncenter" style="width: 611px"><a href="http://krebsonsecurity.com/wp-content/uploads/2011/09/ZTavdet.png"><img class="size-full wp-image-11688" title="ZTavdet" src="http://krebsonsecurity.com/wp-content/uploads/2011/09/ZTavdet.png" alt="" width="601" height="190" /></a><p class="wp-caption-text">Zeustracker.abuse.ch tracks antivirus detection rates for new variants of the ZeuS Trojan. The average detection rate is about 38 percent.</p></div>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/10/monster-spam-campaigns-lead-to-cyberheists/feed/</wfw:commentRss>
		<slash:comments>27</slash:comments>
		</item>
		<item>
		<title>Experienced Money Mule, Will Travel</title>
		<link>http://krebsonsecurity.com/2011/08/experienced-money-mule-will-travel/</link>
		<comments>http://krebsonsecurity.com/2011/08/experienced-money-mule-will-travel/#comments</comments>
		<pubDate>Mon, 29 Aug 2011 17:23:03 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Target: Small Businesses]]></category>
		<category><![CDATA[AMR Company]]></category>
		<category><![CDATA[Back Office Group]]></category>
		<category><![CDATA[Jackson Properties]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10283</guid>
		<description><![CDATA[I&#8217;ve written a great deal about &#8220;money mules,&#8221; people looking for part-time employment who unwittingly or willingly help organized cyber thieves launder stolen funds. The most common question I get about money mules is: &#8220;Do any of them ever get prosecuted?&#8221; The answer is generally &#8220;no&#8221; because it&#8217;s hard to prove that these mules weren&#8217;t [...]]]></description>
			<content:encoded><![CDATA[
<p>I&#8217;ve written a great deal about &#8220;money mules,&#8221; people looking for part-time employment who unwittingly or willingly help organized cyber thieves launder stolen funds. The most common question I get about money mules is: &#8220;Do any of them ever get prosecuted?&#8221; The answer is generally &#8220;no&#8221; because it&#8217;s hard to prove that these mules weren&#8217;t scammed. But recently, I encountered a mule who made it abundantly clear that he understood exactly what he was doing.</p>
<div id="attachment_11345" class="wp-caption alignright" style="width: 310px"><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2011/08/reggie-sarah.png"><img class="size-medium wp-image-11345" title="reggie-sarah" src="http://krebsonsecurity.com/wp-content/uploads/2011/08/reggie-sarah-300x251.png" alt="" width="300" height="251" /></a><p class="wp-caption-text">A complicit mule negotiating a new deal.</p></div>
<p>In June 2011, I was investigating an online banking heist against a company called <strong>Jackson Properties</strong>. Thieves had broken into Jackson&#8217;s computers and stolen the firm&#8217;s online banking credentials. They added a half dozen money mules to the company&#8217;s payroll account, using mules they&#8217;d acquired from a gang I call the <a title="eThieves Steal $217,000 from Arena Firm" href="http://krebsonsecurity.com/2011/08/ethieves-steal-217k-from-arena-firm/" target="_blank">Back Office group</a>. This mule gang uses multiple bogus corporate names, and the Back Office front company that supplied the mules in this attack was called <strong>AMR Company</strong>.</p>
<p><strong>Reginald, </strong>a 45-year-0ld Texas resident,<strong></strong> was among the mules hired by AMR Company. Reggie communicated with the mule recruiters by logging into a Web site set up by the fake company, and checking for new messages. A source who had figured out how to view the administrator&#8217;s account (and hence, all messages on the server) sent me some choice screenshots from several mule communications.</p>
<p>On June 7, the mule recruiters sent Reginald a transfer of $4,910, claiming that Jackson Properties was its client. Reginald was to withdraw the money in cash and wire it overseas, minus a small commission. The payment never landed in his account; it was blocked when Jackson detected the fraudulent transactions and worked with its bank to get them reversed.</p>
<p>But that apparently did not deter our Reginald, who told his recruiter and manager at AMR Company that he understood the whole thing was a scam, and that he had done this sort of thing before. He said he was ready and willing to open additional bank accounts to help with future fraud schemes.</p>
<p>On June 8, Reggie signed into his account at AMR Company and wrote the following to Sarah, his erstwhile boss:</p>
<blockquote><p>&#8220;Let me say from the start. I knew what this was about. I&#8217;ve had success working with others like yourself in the past, especially comrades from Russia. I know this game well. If you want to have an ally in the US, I&#8217;m your guy. I have more accounts. I&#8217;d like us to try again, with another account…<em>Listen Sarah, I am all for making some money. I couldn&#8217;t care less about our banking system, anything we can get out [sic] it</em>. Lets [sic] do it. I cant do this without you. I can open up accounts in different names, that&#8217;s easy for me. But I have no way of funding them like you do. Think it over and see if there&#8217;s a way we can make some money. Even if we only succeed one time…we will still succeeded. I have another account ready to go. Respond to me and I will send you the name, routing, account num, etc.&#8221;</p></blockquote>
<p><span id="more-10283"></span></p>
<p>The eager mule ended his proposal with a startling declaration:</p>
<blockquote><p>&#8220;Have a great day, Sarah, and thanks for trying. <em>I assure you the only victim on my side will be the banks.</em> I can easily set up active checking or savings with info I have.&#8221;</p></blockquote>
<p>Sarah wrote back that she was interested in his idea:</p>
<p>&#8220;Dear Reginald,</p>
<p>We are interested in your offer if you can set up different accounts. What percentage would you like to get for you part of the job We can not offer you a fixed price.&#8221;</p>
<p>Reginald replied:</p>
<p>&#8220;I think 40 percent is fair. That&#8217;s what the Russians give me.&#8221;</p>
<p>Apparently, Reggie&#8217;s percentage was too high; he never heard from Sarah again, even after he offered to lower his cut to 30 percent of future fraudulent transfers.</p>
<p>I could not reach Reginald at the number he gave to AMR Company; the line was disconnected. But a search on his email address revealed more information about his current activities. He is currently the registered contact for a shady-looking enterprise that has all of the hallmarks of a <a title="The Problem with MLM Schemes" href="http://www.vandruff.com/mlm.html" target="_blank">multi-level marketing or pyramid scheme</a>.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/08/experienced-money-mule-will-travel/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>eThieves Steal $217k from Arena Firm</title>
		<link>http://krebsonsecurity.com/2011/08/ethieves-steal-217k-from-arena-firm/</link>
		<comments>http://krebsonsecurity.com/2011/08/ethieves-steal-217k-from-arena-firm/#comments</comments>
		<pubDate>Tue, 16 Aug 2011 04:00:43 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Target: Small Businesses]]></category>
		<category><![CDATA[AV Company]]></category>
		<category><![CDATA[Back Office Group]]></category>
		<category><![CDATA[Erik Rhoden]]></category>
		<category><![CDATA[Lea French]]></category>
		<category><![CDATA[MECA]]></category>
		<category><![CDATA[Metropolitan Entertainment & Convention Authority]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10931</guid>
		<description><![CDATA[Cyber thieves stole $217,000 last month from the Metropolitan Entertainment &#038; Convention Authority (MECA), a nonprofit organization responsible for operating the Qwest Center and other gathering places in Omaha, Nebraska.]]></description>
			<content:encoded><![CDATA[
<p>Cyber thieves stole $217,000 last month from the <strong>Metropolitan Entertainment &amp; Convention Authority</strong> (MECA), a nonprofit organization responsible for operating the <strong>Qwest Center</strong> and other gathering places in Omaha, Nebraska.</p>
<p><strong><a href="http://krebsonsecurity.com/wp-content/uploads/2011/08/mecaOMAHA.png"><img class="alignright size-medium wp-image-11101" title="mecaOMAHA" src="http://krebsonsecurity.com/wp-content/uploads/2011/08/mecaOMAHA-300x120.png" alt="" width="300" height="120" /></a>Lea French</strong>, MECA&#8217;s chief financial officer, said the trouble began when an employee with access to the organization&#8217;s online accounts opened a booby-trapped email attachment containing password-stealing malware.</p>
<p>The attackers used MECA&#8217;s online banking credentials to add at least six people to the payroll who had no prior business with the organization. Those individuals, known as &#8220;money mules,&#8221; received fraudulent transfers from MECA&#8217;s bank account and willingly or unwittingly helped the fraudsters launder the money.</p>
<p>French said the attackers appeared to be familiar with the payroll system, and wasted no time setting up a batch of fraudulent transfers.</p>
<p>&#8220;They knew exactly what they were doing, knew how to create a batch, enter it in, release it,&#8221; she said. &#8220;They appear to be very good at what they do.&#8221;</p>
<p>Prior to the heist, MECA refused many of the security options offered by its financial institution, <strong>First National Bank of Omaha</strong>, including a requirement that two employees sign off on every transfer.</p>
<p>&#8220;We had declined some of the security measures offered to us, [but if] we had those in place this wouldn&#8217;t have happened to us,&#8221; French said. &#8220;We thought that would be administratively burdensome, and I was more worried about internal stuff, not somebody hacking into our systems.&#8221;</p>
<p>MECA was able to reverse an unauthorized wire transfer for $147,000 that was destined for a company called <strong>Utopia Funding U.S.A. </strong>The organization was not as lucky with the remaining transfers.<strong><br />
</strong></p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2011/08/avcompanybackoffice.png"><img class="alignleft size-medium wp-image-11105" title="avcompanybackoffice" src="http://krebsonsecurity.com/wp-content/uploads/2011/08/avcompanybackoffice-300x201.png" alt="" width="300" height="201" /> </a>The funds stolen from MECA were sent to money mules recruited through fraudulent work-at-home job offers from a mule recruitment gang that I call the &#8220;Back Office Group.&#8221; This gang is one of several money mule recruitment outfits, and they appear to be among the most active. Like many other mule gangs, they tend to re-use the same format and content for their Web sites, but change their company names whenever the major search engines start to index them with enough negative comments to make mule recruitment difficult.</p>
<p>The mules used in the MECA heist were recruited through a Back Office Group front company named AV Company. Mules were told they were helping the company&#8217;s overseas software engineers get paid for the work they were doing for American companies. In reality, the mules were being sent payments to transfer that were drawn on hacked accounts from victims like MECA.</p>
<p>More than $9,000 of MECA&#8217;s money was sent to <strong>Erik Rhoden</strong>, a resident of Fleming Island, Fla. Rhoden was recruited in June by the Back Office Group. Rhoden successfully transferred the funds to three individuals in Eastern Europe, but says he didn&#8217;t profit from the work. His story matches that of other mules recently recruited by Back Office, and indicates a devious shift in tactics which ensures that mules never receive a payment for their work.</p>
<p><span id="more-10931"></span></p>
<p>Typically, the Back Office group had instructed mules to withdraw transfers in cash, pocket eight percent as a commission, and wire the remainder of the funds to specific individuals overseas. Recently, the Back Office group changed its policy, and began telling mules to transmit the entire amount. In place of commissions, mules are now promised a payday at the end of the month. That payday almost never comes.</p>
<p>&#8220;They said I was going to get benefits, a salary, and a bonus for each transaction, but that was all a lie,&#8221; said Rhoden, who recently landed a job as a drink server in a local bar.</p>
<p>MECA lost more than $70,000 from the heist, although French said she believes their Travelers cyber security policy will help recoup some or all of the loss.</p>
<p>&#8220;We have a $25,000 deductible, plus the cost of an ongoing forensic investigation, which is going to be pretty expensive,&#8221; she said.</p>
<p>MECA has since added more security features to its online banking account, and access to that account is only possible through a locked-down, dedicated computer.</p>
<p>&#8220;All of this is a day late and a dollar short, I guess,&#8221; French said. &#8220;Why isn&#8217;t someone out shouting on the rooftops about this fraud? People need to understand how exposed they are.&#8221;</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/08/ethieves-steal-217k-from-arena-firm/feed/</wfw:commentRss>
		<slash:comments>40</slash:comments>
		</item>
		<item>
		<title>FBI Investigating Cyber Theft of $139,000 from Pittsford, NY</title>
		<link>http://krebsonsecurity.com/2011/06/fbi-investigating-cyber-theft-of-139000-from-pittsford-ny/</link>
		<comments>http://krebsonsecurity.com/2011/06/fbi-investigating-cyber-theft-of-139000-from-pittsford-ny/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 17:05:11 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[A Little Sunshine]]></category>
		<category><![CDATA[Latest Warnings]]></category>
		<category><![CDATA[Target: Small Businesses]]></category>
		<category><![CDATA[Web Fraud 2.0]]></category>
		<category><![CDATA[Canandaigua National Bank & Trust]]></category>
		<category><![CDATA[money mules]]></category>
		<category><![CDATA[Town of Pittsford]]></category>
		<category><![CDATA[William Carpenter]]></category>
		<category><![CDATA[ZeuS Trojan]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10269</guid>
		<description><![CDATA[Computer crooks stole at least $139,000 from the town coffers of Pittsford, New York this week. The theft is the latest reminder of the widening gap between the sophistication of organized cyber thieves and the increasingly ineffective security measures employed by many financial institutions across the United States.

The attack began on or around June 1, 2011, when someone logged into the online commercial banking account of the Town of Pittsford, a municipality of 25,000 not far from Rochester, N.Y. The thieves initiated a small batch of automated clearing house (ACH) transfers to several money mules, willing or unwitting individuals in the U.S.A. who had been recruited by the attackers prior to the theft. The mules pulled the money out of their bank accounts in cash and wired it to individuals in Saint Petersburg, Russia and Kiev, Ukraine via transfer services Western Union and Moneygram.]]></description>
			<content:encoded><![CDATA[
<p>Computer crooks stole at least $139,000 from the town coffers of <strong>Pittsford, New York </strong>this week. The theft is the latest reminder of the widening gap between the sophistication of organized cyber thieves and the increasingly ineffective security measures employed by many financial institutions across the United States.</p>
<p><a href="http://krebsonsecurity.com/wp-content/uploads/2011/06/pittsford.jpg"><img class="alignright size-full wp-image-10271" title="pittsford" src="http://krebsonsecurity.com/wp-content/uploads/2011/06/pittsford.jpg" alt="" width="257" height="239" /></a>The attack began on or around June 1, 2011, when someone logged into the online commercial banking account of the Town of Pittsford, a municipality of 25,000 not far from Rochester, N.Y. The thieves initiated a small batch of automated clearing house (ACH) transfers to several <a title="KrebsOnSecurity Stories involving money mules" href="http://krebsonsecurity.com/?s=money+mules&amp;x=0&amp;y=0" target="_blank">money mules</a>, willing or unwitting individuals in the U.S.A. who had been recruited by the attackers prior to the theft. The mules pulled the money out of their bank accounts in cash and wired it to individuals in Saint Petersburg, Russia and Kiev, Ukraine via transfer services <strong>Western Union</strong> and <strong>Moneygram</strong>.</p>
<p>Over the next four business days, the thieves initiated another three fraudulent batch payments to money mules. Some transfers went to money mules who owned businesses, such as a $14,750 payment to Mission Viejo, Calif. based Art Snyder Software. Most money mules were sent payments of less than $5,000.</p>
<p>Pittsford town supervisor <strong>William Carpenter</strong> said the<strong> FBI</strong> is investigating the incident, and that many of the details of how the attackers got in remain unclear. He said the FBI told him the thieves most likely stole the town&#8217;s online banking password using a banking Trojan. He added that the town has recovered just $4,800 of the stolen funds, the proceeds of a single transfer. I left a message with the FBI field office in New York but haven&#8217;t yet heard back.</p>
<p>&#8220;We have good firewalls and anti-virus software, and we weren&#8217;t at all lax in our security systems,&#8221; Carpenter said. &#8220;We thought we were pretty secure.&#8221;</p>
<p>Carpenter said the fraud went undetected for days. He said the town normally does its direct deposit payroll bi-weekly on Wednesdays, and that the first fraudulent transfers happened during a non-payroll week.</p>
<p><span id="more-10269"></span>The attack happened shortly after Pittsford opened an account with <strong>Canandaigua National Bank &amp; Trust</strong> (CNB), a regional institution based in Canandaigua, N.Y. Carpenter said that prior to banking at Canandaigua, the town held its online accounts at a different bank, where all transactions had to be approved by at least two town officials. But he said the town hadn&#8217;t yet established these dual controls over their account at Canandaigua at the time of the fraud.</p>
<p>Carpenter said he was not fully versed in the security mechanisms in place for the bank&#8217;s commercial customers, but a review of the security procedures displayed on Canandaigua&#8217;s Web site indicate that they include a user name, password, a set of security questions. Customers also have the option of registering their computers, which involves downloading a CNB certificate or cookie. According to the bank&#8217;s site, &#8220;when you log in from a registered computer you are not required to answer a security question to complete the process.&#8221;</p>
<p>CNB spokesman <strong>Steve Martin</strong> declined to respond to any specific questions about the incident, but he confirmed the information about the bank&#8217;s authentication procedures.</p>
<p>The question of how far commercial banks should go to authenticate their customers was the subject of <a title="Court: Passwords + Secret Questions = ‘Reasonable’ eBanking Security" href="http://krebsonsecurity.com/2011/06/court-passwords-secret-questions-reasonable-ebanking-security/" target="_blank">a court battle I wrote about earlier this week</a>. The lawsuit was brought by a Maine construction firm that lost $345,000 in May 2009 when thieves used the ZeuS Trojan to steal the company&#8217;s online banking credentials and defeat their bank&#8217;s online security measures, which were eerily similar to CNB&#8217;s: passwords, secret questions and registered computers. That case also involved a series of fraudulent transfers that took place over the course of a week.  A magistrate in that case issued a recommended decision earlier this month that said the bank&#8217;s security measures were sufficient to meet federal guidelines on ebanking authentication.</p>
<p>The proliferation of commercial banking thefts involving the ZeuS Trojan and other sophisticated attack tools underscores the asymmetry between the attackers and defenders. As I have detailed <a href="http://krebsonsecurity.com/category/smallbizvictims/" target="_blank">in more than 75 stories on this topic</a>, ZeuS allows attackers to manipulate the victim&#8217;s browser and to log in to the victim&#8217;s bank account using the victim&#8217;s own PC, effectively negating any security that a device fingerprint or registered computer may provide.</p>
<p>Unfortunately, these attacks will continue; I&#8217;ve been in touch with three other organizations in the past week that have experienced losses from ebanking thefts but have asked not to be named. There are millions of towns, cities, nonprofits, churches and small businesses that remain dangerously exposed to this type of attack, and far too many banks that are not doing enough to educate their customers about the threat and to implement systems capable of detecting the attacks when they occur.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/06/fbi-investigating-cyber-theft-of-139000-from-pittsford-ny/feed/</wfw:commentRss>
		<slash:comments>65</slash:comments>
		</item>
		<item>
		<title>FBI: $20M in Fraudulent Wire Transfers to China</title>
		<link>http://krebsonsecurity.com/2011/04/fbi-20m-in-fraudulent-wire-transfers-to-china/</link>
		<comments>http://krebsonsecurity.com/2011/04/fbi-20m-in-fraudulent-wire-transfers-to-china/#comments</comments>
		<pubDate>Wed, 27 Apr 2011 14:19:00 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Other]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=9376</guid>
		<description><![CDATA[The Federal Bureau of Investigation warned this week that cyber thieves have stolen approximately $20 million  over the past year from small to mid-sized businesses, through a series of fraudulent wire transfers sent to Chinese economic and trade companies located near the country's border with Russia.

The FBI said that between March 2010 and April 2011, it identified twenty incidents in which small to mid-sized organizations had fraudulent wire transfers to China, and that the total losses from the fraud was about $11 million. The alert was sent out Tuesday, in cooperation with the Internet Crime Complaint Center and the Financial Services Information Sharing and Analysis Center (FS-ISAC), an industry consortium.]]></description>
			<content:encoded><![CDATA[
<p>The <strong>Federal Bureau of Investigation</strong> warned this week that cyber thieves have stolen approximately $20 million  over the past year from small to mid-sized U.S. businesses through a series of fraudulent wire transfers sent to Chinese economic and trade companies located near the country&#8217;s border with Russia.</p>
<p><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2011/04/heil2.jpg"><img class="alignright size-medium wp-image-9379" title="heil2" src="http://krebsonsecurity.com/wp-content/uploads/2011/04/heil2-259x300.jpg" alt="" width="259" height="300" /></a>The FBI said that between March 2010 and April 2011, it identified twenty incidents in which small to mid-sized organizations had fraudulent wire transfers to China after their online banking credentials were stolen by malicious software. The  alert was sent out Tuesday in cooperation with the <a title="Internet Crime Complaint Center" href="http://www.ic3.gov" target="_blank">Internet Crime Complaint Center</a> and the <strong>Financial Services Information Sharing and  Analysis Center</strong> (FS-ISAC), an industry consortium. The alert notes that actual victim losses are $11 million, suggesting that victim banks were able to claw back some of the fraudulent transfers.</p>
<p>The FBI says it doesn&#8217;t know who is behind these fraudulent transfers, but that the intended recipients are companies based in the <strong>Heilongjiang</strong> province of the People&#8217;s Republic of China, and that these firms are registered in port cities that are located near the Russia-China border. The agency says the companies all use the name of a Chinese port city in their names, such as Raohe, Fuyuan, Jixi City, Xunke, Tongjiang, and Donging, and that the official name of the companies also include the words &#8220;economic and trade,&#8221; &#8220;trade,&#8221; and &#8220;LTD&#8221;. The recipient entities usually hold accounts with a the Agricultural Bank of China, the Industrial and Commercial Bank of China, and the Bank of China.</p>
<p>From <a title="China Wire Transfer Fraud Alert" href="http://krebsonsecurity.com/wp-content/uploads/2011/04/ChinaWireTransferFraudAlert.pdf" target="_blank">the advisory</a> (PDF):</p>
<blockquote><p>&#8220;In a typical scenario, the computer of a person within a company who can initiate funds transfers on behalf of the U.S. business is compromised by either a phishing email or by visiting a malicious Web site. The malware harvests the user&#8217;s corporate online banking credentials. When the authorized user attempts to log in to the user&#8217;s bank Web site, the user is typically redirected to another Web page stating that the bank Web site is under maintenance or is unable to access the accounts. While the user is experiencing logon issues, malicious actors initiate the unauthorized transfers to commercial accounts held at intermediary banks typically located in New York. Account funds are then transferred to the Chinese economic and trade company bank account.&#8221;</p></blockquote>
<p><span id="more-9376"></span>The alert said the unauthorized wires range in value from $50,000 to $985,000. While most transfers tend to be toward the upper end of that spectrum, &#8220;the malicious actors have been more successful in receiving the funds when the unauthorized wire transfers were under $500,000.&#8221; In addition, the attackers initiated fraudulent automated clearing house (ACH) transfers to money mules in the United States within minutes of conducting the overseas wire transfers.</p>
<p>According to the alert, the thieves  used a variety of malicious software to steal victim online banking credentials, including the <a title="ZeuS Trojan Stories on KrebsOnSecurity.com" href="http://krebsonsecurity.com/?s=ZeuS&amp;x=0&amp;y=0" target="_blank">ZeuS Trojan</a>, <strong>backdoor.bot</strong> and <strong>Spybot</strong>, all malware families that let the crooks steal passwords and control infected systems remotely.</p>
<p>None of this should be news to anyone who has followed <a title="Target: Small Businesses" href="http://krebsonsecurity.com/category/smallbizvictims/" target="_blank">my reporting on this type of crime</a>. I&#8217;ve written more than 70 stories over the past two years about these type of attacks. Earlier this year, victims at three Iowa banks <a href="http://www.desmoinesregister.com/article/20110420/BUSINESS/104200352/-1/GETPUBLISHED03wp-content/Businesses-often-must-swallow-loss-cyber-thefts-" target="_blank">lost about $2 million</a> in a series of fraudulent wire transfers to  Hong Kong. Last fall, thieves <a title="Cyber Thieves Steal Nearly $1 Million from University of Virginia" href="http://krebsonsecurity.com/2010/09/cyber-thieves-steal-nearly-1000000-from-university-of-virginia-college/" target="_blank">stole close to $1 million in a single fraudulent wire transfer from the University of Virginia</a> to the Agricultural Bank of China.</p>
<p>It is vital for small business owners to understand the risks they face when banking online, and to get a sense of the sophistication of today&#8217;s attackers. Unlike consumers — businesses do not have the same protection against  fraud that consumers enjoy. Indeed, most companies that get hit with  this type of fraud quickly figure out that their banks are under no  legal obligation to reimburse them. Small business owners wondering what they can do to protect themselves should read the tips at <a title="Ebanking Guidance for Banks and Businesses" href="http://krebsonsecurity.com/2010/04/e-banking-guidance-for-banks-businesses/#more-1991" target="_blank">this post</a>. One of the surest ways that business owners can avoid becoming the next victim is for the person handling the company&#8217;s books to bank online <a title="Using Windows for a Day Cost Mac User $100,000" href="http://krebsonsecurity.com/2010/06/using-windows-for-a-day-cost-mac-user-100000/" target="_blank">only</a> from a dedicated machine &#8212; preferably one that is not Windows-based (since all of the malware used in the attacks to date won&#8217;t run on anything but Windows). Using a <strong>Mac</strong> or a <a title="Avoid Windows Malware: Bank on a Live CD" href="http://voices.washingtonpost.com/securityfix/2009/10/avoid_windows_malware_bank_on.html" target="_blank">Live CD approach</a> may seem expensive or impractical, but losing hundreds of thousands of dollars because your PC got a virus infection isn&#8217;t so great either.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/04/fbi-20m-in-fraudulent-wire-transfers-to-china/feed/</wfw:commentRss>
		<slash:comments>51</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 1/45 queries in 0.017 seconds using memcached
Object Caching 1093/1236 objects using memcached

Served from: www.krebsonsecurity.com @ 2012-02-11 22:10:12 -->
