UK Banks Best in Europe at Reducing Card Fraud Losses Last Year

UK Banks Best in Europe at Reducing Card Fraud Losses Last Year

New data from FICO has revealed that UK banks achieved the largest reduction in card fraud losses in 2019 compared to other countries across Europe.

That’s according to the updated FICO European Fraud Map, which discovered that UK banks have reduced fraud losses by £52m since 2018.

In contrast, more than half of the 18 European countries included in the data set saw increases in card fraud losses in 2019, with France and Italy seeing the largest increases (€8m and €6m respectively) when taking into account associated values.

However, the FICO European Fraud Map did record a 2% reduction in fraud losses across all 18 of the European countries last year.

FICO partners with the majority of banks in Europe to support their fraud prevention activities,.

“Following a frustrating increase in 2018 – largely caused by an explosion of data compromise ‘bust out’ events – much of Europe has once again turned the tide on fraudsters, achieving a combined 2% overall reduction,” said Toby Carlin, director of fraud consulting in EMEA at FICO. “British consumers should be reassured that the UK achieved the largest single reduction in fraud at 8%. This is a testament to the anti-fraud activities and investments by UK banks, which reduced fraud losses in 2019 by £52 million – that’s a million pounds every week.”

Carlin added that 2020 has been a challenging environment for all, with COVID-19 having significant impacts on the transaction mix and related threats.

“This has exposed many frameworks that were already pressured, with fraudsters now attempting to make up for lost time with increased volume and ferocity of their attacks. While our Fraud Map focuses on plastics fraud and, in particular, card-not-present fraud, this is just part of the story. The biggest threat today comes from digital fraud and scams which continue to increase exponentially across all markets.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Report Looks at COVID-19’s Massive Impact on Cybersecurity

Cynet’s report shares several interesting data points and findings, such as the cyberattack volume change observed in various industry sectors, the increased use of spearphishing as an initial attack vector, and the approaches being used to distribute malware in spearphishing attacks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

How the FIN7 Cybercrime Gang Operates

The Grugq has written an excellent essay on how the Russian cybercriminal gang FIN7 operates. An excerpt:

The secret of FIN7’s success is their operational art of cyber crime. They managed their resources and operations effectively, allowing them to successfully attack and exploit hundreds of victim organizations. FIN7 was not the most elite hacker group, but they developed a number of fascinating innovations. Looking at the process triangle (people, process, technology), their technology wasn’t sophisticated, but their people management and business processes were.

Their business… is crime! And every business needs business goals, so I wrote a mock FIN7 mission statement:

Our mission is to proactively leverage existing long-term, high-impact growth strategies so that we may deliver the kind of results on the bottom line that our investors expect and deserve.

How does FIN7 actualize this vision? This is CrimeOps:

  • Repeatable business process
  • CrimeBosses manage workers, projects, data and money.
  • CrimeBosses don’t manage technical innovation. They use incremental improvement to TTP to remain effective, but no more
  • Frontline workers don’t need to innovate (because the process is repeatable)

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Two Russians Charged in $17M Cryptocurrency Phishing Spree

U.S. authorities today announced criminal charges and financial sanctions against two Russian men accused of stealing nearly $17 million worth of virtual currencies in a series of phishing attacks throughout 2017 and 2018 that spoofed websites for some of the most popular cryptocurrency exchanges.


The Justice Department unsealed indictments against Russian nationals Danil Potekhin and Dmitirii Karasavidi, alleging the duo was responsible for a sophisticated phishing and money laundering campaign that resulted in the theft of $16.8 million in cryptocurrencies and fiat money from victims.

Separately, the U.S. Treasury Department announced economic sanctions against Potekhin and Karasavidi, effectively freezing all property and interests of these persons (subject to U.S. jurisdiction) and making it a crime to transact with them.

According to the indictments, the two men set up fake websites that spoofed login pages for the currency exchanges Binance, Gemini and Poloniex. Armed with stolen login credentials, the men allegedly stole more than $10 million from 142 Binance victims, $5.24 million from 158 Poloniex users, and $1.17 million from 42 Gemini customers.

Prosecutors say the men then laundered the stolen funds through an array of intermediary cryptocurrency accounts — including compromised and fictitiously created accounts — on the targeted cryptocurrency exchange platforms. In addition, the two are alleged to have artificially inflated the value of their ill-gotten gains by engaging in cryptocurrency price manipulation using some of the stolen funds.

For example, investigators alleged Potekhin and Karasavidi used compromised Poloniex accounts to place orders to purchase large volumes of “GAS,” the digital currency token used to pay the cost of executing transactions on the NEO blockchain — China’s first open source blockchain platform.

“Using digital crurency in one victim Poloniex account, they placed an order to purchase approximately 8,000 GAS, thereby immediately increasing the market price of GAS from approximately $18 to $2,400,” the indictment explains.

Potekhin and others then converted the artificially inflated GAS in their own fictitious Poloniex accounts into other cryptocurrencies, including Ethereum (ETH) and Bitcoin (BTC). From the complaint:

“Before the Eight Fictitious Poloniex Accounts were frozen, POTEKHIN and others transferred approximately 759 ETH to nine digital currency addresses. Through a sophisticated and layered manner, the ETH from these nine digital currency addresses was sent through multiple intermediary accounts, before ultimately being deposited into a Bitfinex account controlled by Karasavidi.”

The Treasury’s action today lists several of the cryptocurrency accounts thought to have been used by the defendants. Searching on some of those accounts at various cryptocurrency transaction tracking sites points to a number of phishing victims.

“I would like to blow your bitch ass away, if you even had the balls to show yourself,” exclaimed one victim, posting in a comment on the Etherscan lookup service.

One victim said he contemplated suicide after being robbed of his ETH holdings in a 2017 phishing attack. Another said he’d been relieved of funds needed to pay for his 3-year-old daughter’s medical treatment.

“You and your team will leave a trail and will be found,” wrote one victim, using the handle ‘Illfindyou.’ “You’ll only be able to hide behind the facade for a short while. Go steal from whales you piece of shit.”

There is potentially some good news for victims of these phishing attacks. According to the Treasury Department, millions of dollars in virtual currency and U.S. dollars traced to Karasavidi’s account was seized in a forfeiture action by the United States Secret Service.

Whether any of those funds can be returned to victims of this phishing spree remains to be seen. And assuming that does happen, it could take years. In February 2020, KrebsOnSecurity wrote about being contacted by an Internal Revenue Service investigator seeking to return funds seized seven years earlier as part of the governments 2013 seizure of Liberty Reserve, a virtual currency service that acted as a $6 billion hub for the cybercrime world.

Today’s action is the latest indication that the Treasury Department is increasingly willing to use its authority to restrict the financial resources tied to various cybercrime activities. Earlier this month, the agency’s Office of Foreign Asset Control (OFAC) added three Russian nationals and a host of cryptocurrency addresses to its sanctions lists in a case involving efforts by Russian online troll farms to influence the 2018 mid-term elections.

In June, OFAC took action against six Nigerian nationals suspected of stealing $6 million from U.S. businesses and individuals through Business Email Compromise fraud and romance scams.

And in 2019, OFAC sanctioned 17 members allegedly associated with “Evil Corp.,” an Eastern European cybercrime syndicate that has stolen more than $100 million from small businesses via malicious software over the past decade.

A copy of the indictments against Potekhin and Karasavidi is available here (PDF).

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Businesses Planning for Long-Term Shift to Digital Working

UK Businesses Planning for Long-Term Shift to Digital Working

Over half (56%) of UK businesses plan to increase their digital skills training budgets for staff next year, suggesting changes to working practices as a result of the COVID-19 pandemic will be sustained. This is according to a survey of 200 senior business decision makers in large and medium sized companies by IT services provider Transputec.

The study also found that more than half (53%) of businesses are aiming to grow their IT infrastructure budget next year, while 60% of decision makers are planning to expand the use of digital collaboration tools to enable staff to connect more effectively and improve their well-being.

A third (33%) said they want to recruit a chief digital officer to help facilitate these changes, and 41% are seeking to hire candidates with high levels of digital skills.

In addition, close to half (44%) of UK businesses want to accelerate remote working going forward in order to reduce costs, such as by downsizing office space. Almost half (49%) of those surveyed expect to see growth next year, indicating that many businesses have already adapted well to a remote working model.

Sonny Sehgal, CEO of Transputec, commented: “COVID-19 has already had a devastating impact on UK business, and we’re not out of the woods yet. Fortunately, cutting edge technology has facilitated a mass shift to remote and digital working, and as a result, many businesses have observed benefits of lower overheads and more streamlined and efficient operations through managed services.

“Therefore, we can expect flexible working to stay with us for the long-term, even after it is deemed safe to return to the office on a permanent basis. Therefore, businesses must continue to bolster digital initiatives and prioritize the use of cloud-enabled digital collaboration tools, for example, if they wish to remain buoyant.”

Despite the business benefits of home working, the surge in this practice during COVID-19 has highlighted a number of cybersecurity issues, including the use of insecure video communication platforms and risky security behaviors by remote staff.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Use of Illegal Stream-Ripping Services Increases by 1390%

Use of Illegal Stream-Ripping Services Increases by 1390%

The use of illegal stream-ripping services dramatically increased by 1390% in the period between 2016 and 2019, a study published by PRS for Music has found.

Stream-ripping services, which enable users to illegally create permanent offline copies of audio or video streams, are now “overshadowing all other illegal online music activity in the UK,” according to the research, which was conducted by online rights monitoring company INCOPRO.

Following analysis of data taken from INCORPRO’s Identify database, it was revealed that websites promoting these services now make up 80.2% of the 50 most popular music-infringing sites.

There was, however, a significant drop in the proportion of BitTorrent sites from the top 50, from 14 to six. This is likely due to greater geo-blocking and enforcement efforts across the wider music industry.

The legitimate service most frequently exploited by stream-ripping in this period remained YouTube, with 70 out of 100 services observed found to exclusively offering ‘YouTube ripping’. This is followed by Spotify, which has overtaken SoundCloud, while other heavily targeted licensed platforms included Deezer, Amazon Music and Tidal.

The research also noted that the main source of funding for stream-ripping services was advertising, with the biggest categories generic/other (52%), scams (34%) and malware/potentially unwanted programs (PUPs) (14%).

Simon Bourn, head of IP and litigation at PRS for Music, commented: “This report shows that music piracy is very much still alive and kicking, and that stream-ripping is now responsible for a mammoth proportion of the overall piracy problem. Streaming royalties now account for over 20% of our members’ income, and the popularity of this illegal activity has a severe and direct impact on the royalties we can collect for them from legitimate services. Each time a stream is ripped, the user is then listening to and consuming that rip outside of the licensed ecosystem.”

Andrea C. Martin, CEO at PRS for Music, highlighted the importance of protecting digital income streams in light of the COVID-19 crisis: “The prolonged absence of income from live performance means that revenues generated on legitimate digital platforms are more important than ever. While the report shows that our efforts are going in the right direction, it is equally clear that we must persist and continue to work closely with both government and the wider music industry to foster a secure digital environment for music creators and consumers alike.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk