FBI: BEC Losses Soared to $1.8 Billion in 2019

FBI: BEC Losses Soared to $1.8 Billion in 2019

Losses from business email compromise (BEC) attacks soared by hundreds of millions of dollars over the past year, to once again account for half of all cybercrime losses reported to the FBI.

BEC scammers made nearly $1.8 billion in 2019, over half the $3.5 billion total, according to the FBI’s 2019 Internet Crime Report. That’s up from around $1.3bn and a total of $2.7bn in 2018.

A recent evolution in BEC tactics has seen scammers impersonate regular employees rather than C-level execs.

“In this type of scheme, a company’s human resources or payroll department receives an email appearing to be from an employee requesting to update their direct deposit information for the current pay period,” the report explained. “The new direct deposit information generally routes to a pre-paid card account.”

The second biggest earning category of cyber-threat was romance scams, which netted over $475 million, followed by “spoofing” at $300m.

Ransomware was way down in the bottom half of the table with $9m in losses, up significantly from $3.6m in 2018. However, the usual caveats apply that this calculation doesn’t include “lost business, time, wages, files, or equipment, or any third party remediation services acquired by a victim.”

The FBI also admitted that many victims do not report ransomware losses to the Bureau.

When measured according to numbers of reported victims rather than financial losses, phishing (114,702) came top, followed by non-payment/non-delivery (61,8332), and extortion (43,101).

BEC was down in fifth place (23,775) with ransomware even further behind with just 2047 reported cases in 2019 — highlighting the scale of under-reporting.

The FBI also singled out tech support fraud as a growing problem, with some recent complaints involving criminals posing customer support for well-known travel companies, banks and even virtual currency exchanges.

“In 2019, the IC3 received 13,633 complaints related to tech support fraud from victims in 48 countries,” the report said. “The losses amounted to over $54 million, which represents a 40% increase in losses from 2018. The majority of victims reported to be over 60 years of age.”

Total reported cybercrime losses have tripled over the past five years, from just $1.1bn in 2015, amounting cumulatively to $10.2bn for the period.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Fixes 99 Problems This Patch Tuesday

Microsoft Fixes 99 Problems This Patch Tuesday

Microsoft has fixed almost a century of CVEs this month, although experts suggest the workload shouldn’t be too hard on admins.

The 99 vulnerabilities fixed this month feature 12 critical CVEs, including one zero-day, and another four that have been publicly disclosed and so will also need to be prioritized.

The zero-day being exploited in the wild is CVE-2020-0674, a remote code execution flaw in the way the scripting engine handles objects in memory in Internet Explorer. By hosting a specially crafted website designed to exploit the bug, a hacker could gain the same rights as the current user.

Other noteworthy critical bugs include CVE-2020-0729 a remote code execution vulnerability in the way Microsoft processes LNK files.

“Microsoft considers exploitation of the vulnerability unlikely, however, a similar vulnerability discovered last year, CVE-2019-1280, was being actively exploited by the Astaroth trojan as recently as September,” explained Recorded Future senior solutions architect, Allan Liska.

He also highlighted CVE-2020-0662, an RCE vulnerability that could allow any user with a domain account to execute arbitrary code on a victim’s machine at elevated privileges, using a specially crafted packet.

It affects the now-unsupported Windows 7 and Server 2008, as well as later versions.

Todd Schell, senior product manager at Ivanti, argued that despite the sizeable patch load, updating operating systems or browsers “can take the teeth out of the majority of risks this month.”

“The really good news in all of this is 99 CVEs really doesn’t mean a whole lot of extra work for admins this month,” he added.

“The normal updates still apply. OS, browsers, and Office will resolve most of your vulnerabilities from the Microsoft side. SQL and Exchange admins do get a bit of extra work this month as both of those products are included in the updates released.”

Meanwhile, Adobe resolved 17 CVEs for Adobe Reader and Acrobat (APSB20-05), including 12 critical ones, and one critical CVE for Flash Player (APSB20-06). 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Crypto AG Unmasked: CIA Spied on Governments For Decades

Crypto AG Unmasked: CIA Spied on Governments For Decades

A Swiss company thought to have sold among the most secure encryption products in the world was actually owned by US and German intelligence, allowing the CIA and BND to spy on allies and enemies around the world, it has emerged.

A new report from The Washington Post and Germany’s ZDF claims that Crypto AG, founded during the Second World War, struck a deal with the CIA in the 50s and then passed fully into the hands of US and German intelligence two decades later, before being wound up in 2018.

Internal reports about the operation, codenamed “Thesaurus” and then renamed “Rubicon” in the 80s, reportedly claim it was “the intelligence coup of the century.”

“Foreign governments were paying good money to the US and West Germany for the privilege of having their most secret communications read by at least two (and possibly as many as five or six) foreign countries,” the article claimed.

This “five or six” figure would seem to suggest that countries belonging to the Five Eyes intelligence sharing partnership also benefited. In fact, it is claimed that the UK was handed vital intelligence intercepted from the Argentinian military during the Falklands war.

The US was also able to monitor Iranian communications during the 1979 hostage siege and Libyan officials celebrating after terrorists exploded a bomb in a Berlin nightclub in 1984.

Then-President Ronald Reagan raised suspicions about Crypto AG after citing some of these Libyan communications publicly, but the rumors were never confirmed.

It is claimed the Americans didn’t request backdoors be inserted into the Crypto AG products, they simply made sure that the encryption itself was weak enough to crack fairly easily. When countries suspected something may be up, the US/Germany sent representatives like respected academic Kjell-Ove Widman to reassure governments that their products were the most secure in the world.

The revelations may raise new fears about the security or otherwise of platforms like Tor, which arose from a US Defense Department project, and of the potential for China to interfere with Huawei-built equipment.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk