HACKING PUNISHES

China accused of cyberattacks on New Zealand

The New Zealand secret service has suggested the Chinese government was behind attacks on the country’s networks. New Zealand Prime Minister Helen Clark yesterday assured reporters that no classified information had been compromised but confirmed that she believed foreign government spies were behind the cyberattack. While Clark said officials know which government was behind the attack, she would not name the country suspected.

“Now we have very smart people to provide protection every time an attack is tried. Obviously we learn from that,” she told reporters.
Warren Tucker, New Zealand’s Security Intelligence Service director, hinted to the local newspaper The Dominion Post that the Chinese government was responsible for the attacks, referring to previous allegations about the country’s spying activities by Canada’s secret service.
The allegations come only a week after the Chinese foreign ministry denied that the Chinese government had endorsed attacks on the computer networks of Germany, the US and the UK.
Foreign ministry representative Jiang Yu said in a recent press conference: “Any accusation of Chinese military force attacking computer systems of foreign governments is groundless, irresponsible and out of ulterior motives. As far as I know, up till now, the Chinese police have not received any request for investigation assistance from the relevant countries.”

Online scam crackdown nets worldwide arrests

An international crackdown on internet financial scams this year has yielded more than $2.1bn (ÂŁ1bn) in seized fake cheques and 77 arrests in the Netherlands, Nigeria and Canada, US and other authorities said on Wednesday. The scammers use ploys such as “spam” email offering to pay recipients “processing fees” for depositing cheques, which later turn out to be fake, and sending the ostensible proceeds to the scammer, authorities said.

In the US, the ruses are aided by financial practices that quickly credit a bank customer for deposits even though it can take far longer to discover a fake cheque and reclaim the money from the customer. The victims find themselves out the money they forward when the cheques prove to be fake.
“Most Americans don’t realise they are financially liable when they fall for these scams,” Susan Grant, vice president of the National Consumers League, said at a news conference to publicise the arrests and promote awareness of the frauds.
The crackdown led to16 arrests in Nigeria, 60 in the Netherlands and one in Canada, said Greg Campbell, US Postal Inspection Service inspector in charge of global security.
“We shut down internet cafes, we arrested scammers, and significantly disrupted the flow of fake cheques into the US,” Campbell said.
Law enforcement in England also took part. Nigeria is a recognised hotbed for the financial frauds and the other countries have significant West African populations that include fraud operators, authorities said.
Three suspects from the Netherlands and Nigeria were extradited to New York and are awaiting trial, said US assistant attorney general Alice Fischer. The US is seeking to extradite five others.
The US is a major draw for the scammers. But other English-speaking countries are also targeted, in part because of the widespread use of English on the internet and because of Nigeria’s large English-speaking population, Campbell said.
Nigeria has brought to court 290 cases of suspected fraud, and the prosecutions have been successful in 115 of the cases so far, said Ibrahim Lamorde, head of Nigeria’s Economic and Financial Crimes Commission.
He said Nigeria is doing its best to stamp out the fake cheque operations. It has seized counterfeiting equipment and convened meetings of anti-fraud officials from across Africa. But he acknowledged Nigeria has an image problem.
“The first country that comes to mind is Nigeria,” Lamorde said.
Two-thirds of Americans said they received at least one potential scam contact per week, and 18 percent said they or a family member had fallen for one, in a survey conducted for an alliance of banks, consumer groups and the US Postal Service.
Grant said complaints to her group about fake cheques have risen 60 percent this year, and the average victim loses about $3,000 (ÂŁ1,500) to $4,000.
Some US banks have changed their practices, for example, by training tellers to better inform depositors about risks, Grant said. She called for regulations mandating that bank customers be given clearer information.
Offers can also come in direct mail. Fisher showed handwritten envelopes directed to her at a Justice Department address.
Inside were $850 cheques with a Wal-Mart logo, with letters offering her a 10 percent cut if she would cash the cheques and send the money back. “After you laugh and think how silly it is… this shows [the problem] is just completely rampant,” she said.

F-Secure warning over PDF malware threat

Emails containing malicious PDF files have been putting computers at risk since Friday, Finnish security software firm F-Secure said on Saturday. “The emails, sent in bulk, looked like credit-card statements, and contained an attachment called ‘report.pdf’,” chief research officer Mikko Hypponen said in a statement.

When such PDF files are viewed on vulnerable machines, they start downloading software from servers in Malaysia or Sweden, which are now being cleaned, he said. “There will be more such attacks.”

“We are worried about this case, as PDF attachments are typically not filtered at email gateways.”

A security update for Adobe Reader and Acrobat was made available a few days ago, but many users have not updated the program yet, Hypponen said.

London police hunting online account hackers

Police in London are hunting a gang of online thieves that hacked into bank accounts and stole hundreds of thousands of pounds. According to a report by UK newspaper The Times, the gang hacked into private bank accounts and used confidential customer details to order new debit and credit cards which were used to buy expensive jewellery, electronic goods and euros.

Detective constable Keith Harrington from the Dedicated Cheque and Plastic Crime Unit told reporters that the thieves used a method called ‘account take over’ to gather enough private customer data to convince a bank that they were the legitimate account holders before ordering a new card and PIN.

Harrington says one case involved the gang using a technique called ‘social engineering’ where a gang member called staff and feigned memory loss in order to get customer account data.

Barclays Bank has managed to intercept much of the fraud and is believed to have stopped at least ÂŁ500,000 being stolen from clients, says The Times.

The report says in one case the gang managed to acquire enough data about one victim to have ÂŁ60,000 transferred from his mortgage reserve account to his current account, which it then stole.

Student hackers face 20 years in jail

Two students have been charged with hacking into the California State University database and changing their grades. John Escalera worked at the university helpdesk and is alleged to have gained access to administrative controls in the PeopleSoft student database by setting up false accounts in the names of the registrar and academic records co-ordinator. Escalera is accused of changing his own grades and those of his friend Gustavo Razo Jr in exchange for cash.

“In or about the summer of 2003 officials at Fresno State ran a routine audit,” reads the indictment (PDF).

“During this routine audit, university officials noticed discrepancies between the two systems in terms of grades. In January 2005, a greater audit was performed by Fresno State based on information received from the first audit.”

The pair face a potential 20-year jail term and fines of up to $250,000 for wire fraud and identity theft. They have entered not guilty pleas and their trial will begin later this month.

Back to Top