Two Charged in SIM Swapping, Vishing Scams

Two young men from the eastern United States have been hit with identity theft and conspiracy charges for allegedly stealing bitcoin and social media accounts by tricking employees at wireless phone companies into giving away credentials needed to remotely access and modify customer account information.

Prosecutors say Jordan K. Milleson, 21 of Timonium, Md. and 19-year-old Kingston, Pa. resident Kyell A. Bryan hijacked social media and bitcoin accounts using a mix of voice phishing or “vishing” attacks and “SIM swapping,” a form of fraud that involves bribing or tricking employees at mobile phone companies.

Investigators allege the duo set up phishing websites that mimicked legitimate employee portals belonging to wireless providers, and then emailed and/or called employees at these providers in a bid to trick them into logging in at these fake portals.

According to the indictment (PDF), Milleson and Bryan used their phished access to wireless company employee tools to reassign the subscriber identity module (SIM) tied to a target’s mobile device. A SIM card is a small, removable smart chip in mobile phones that links the device to the customer’s phone number, and their purloined access to employee tools meant they could reassign any customer’s phone number to a SIM card in a mobile device they controlled.

That allowed them to seize control over a target’s incoming phone calls and text messages, which were used to reset the password for email, social media and cryptocurrency accounts tied to those numbers.

Interestingly, the conspiracy appears to have unraveled over a business dispute between the two men. Prosecutors say on June 26, 2019, “Bryan called the Baltimore County Police Department and falsely reported that he, purporting to be a resident of the Milleson family residence, had shot his father at the residence.”

“During the call, Bryan, posing as the purported shooter, threatened to shoot himself and to shoot at police officers if they attempted to confront him,” reads a statement from the U.S. Attorney’s Office for the District of Maryland. “The call was a ‘swatting’ attack, a criminal harassment tactic in which a person places a false call to authorities that will trigger a police or special weapons and tactics (SWAT) team response — thereby causing a life-threatening situation.”

The indictment alleges Bryan swatted his alleged partner in retaliation for Milleson failing to share the proceeds of a digital currency theft. Milleson and Bryan are facing charges of wire fraud, unauthorized access to protected computers, aggravated identity theft and wire fraud conspiracy.

The indictment doesn’t specify the wireless companies targeted by the phishing and vishing schemes, but sources close to the investigation tell KrebsOnSecurity the two men were active members of OGusers, an online forum that caters to people selling access to hijacked social media accounts.

Bryan allegedly used the nickname “Champagne” on OGusers. On at least two occasions in the past few years, the OGusers forum was hacked and its user database — including private messages between forum members — were posted online. In a private message dated Nov. 15, 2019, Champagne can be seen asking another OGusers member to create a phishing site mimicking T-Mobile’s employee login page (t-mobileupdates[.]com).

Sources tell KrebsOnSecurity the two men are part of a larger conspiracy involving individuals from the United States and United Kingdom who’ve used vishing and phishing to trick work-at-home employees into giving away credentials needed to remotely access their employers’ networks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

(CS)2AI and KPMG Release Inaugural Control Systems Cybersecurity Report

(CS)2AI and KPMG Release Inaugural Control Systems Cybersecurity Report

KPMG and the Control System Cyber Security Association International (CS)2AI today released their first annual report on the cybersecurity of Control Systems (CS) and Operational Technology (OT).

The inaugural “CS/OT Cyber Security Report” is based on the findings of a survey that questioned 16,000 professionals responsible for protecting and defending assets and systems worth millions to billions in capital investment. 

“The survey reveals a clear relationship between the failure to focus on the data and metrics needed to enhance security, as well as inadequate levels of maturity for OT security programs,” said Derek Harp, founder and chairman of (CS)2AI.

“This report, the first of multiple research products our organization is proud to initiate, offers insight into points of failure and areas of success in this industry.”

A key finding of the survey highlighted by Harp was the revelation that fewer than 25% of companies have incorporated an active defense of their control systems and assets. 

Notable findings shared in the report were that 47% of organizations with more mature CS security programs use managed CS security services versus just 6% of those with less mature programs. And, while 63% of those with mature programs frequently replace vulnerable CS hardware or software after assessment, this was true of only 34% of those with less mature programs.

End-to-end security assessments were found to be conducted more frequently by organizations with mature CS security programs. And, while monitoring of all CS networks was carried out by over half (53%) of these organizations, this action was only taken by 16% of organizations with less mature programs.

“Enterprise organizations continue to struggle to address cybersecurity vulnerabilities across control systems and operational technology environments, which can have a material impact on human safety and their businesses’ bottom line,” said Walter Risi, global cyber IoT leader and technology consulting practice leader, KPMG in Argentina. 

The CS/OT cybersecurity report was launched to provide business leaders and practitioners with valuable data-driven insights that will help them create an actionable plan.

“If businesses don’t take appropriate action soon to mitigate risks, regulators and governments will,” said Risi.  

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US City Fined Over Former Employee’s Data Theft

US City Fined Over Former Employee’s Data Theft

A city in the United States has been fined over $200k for failing to terminate the access rights of a former employee who stole protected health information. 

New Haven, Connecticut, agreed to pay a $202,400 financial penalty to the Department of Health and Human Services’ Office for Civil Rights and adopt a corrective action plan that includes two years of monitoring to resolve a HIPAA (Health Insurance Portability and Accountability Act) violation case. 

The OCR launched an investigation in May 2017 after receiving a data breach notification from New Haven in January of that year. OCR found that the city’s health department had failed to remove the access rights of an employee who had been fired the previous summer during her probationary period.

After being terminated by the health department on July 27, 2016, the former employee left work only to return with a union representative eight days later. 

The OCR stated: “Using her work key, the former employee entered her old office and locked herself and the union representative inside. While inside the office, the former employee logged into her old computer, with her user name and password, and downloaded information off of her computer onto a USB drive.”

A student intern witnessed the former employee gathering boxes containing personal items and paper documents before leaving the building with the union representative.

A file containing the protected health information of nearly 500 patients was among the data stolen by the employee. Information exposed in the security incident included the results of tests for sexually transmitted diseases along with patients’ names, addresses, dates of birth, gender, and race/ethnicity.

The fired employee had shared her login credentials with an intern, who used them to access PHI on the network. The intern continued to access the data after the employee had been terminated. 

OCR investigators found that New Haven failed to conduct an enterprise-wide risk analysis and failed to implement termination procedures and access controls such as unique user identification.

“Medical providers need to know who in their organization can access patient data at all times. When someone’s employment ends, so must their access to patient records,” said OCR Director Roger Severino. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk