Police Crack Multimillion-Dollar Real Estate Fraud Gang

Police Crack Multimillion-Dollar Real Estate Fraud Gang

European police claim to have dismantled an international organized crime group (OGC) that made millions from real estate fraud.

Law enforcers in the Hungarian capital of Budapest, supported by Europol, began operations against the gang back in 2017. However, it was during 10 so-called “action days” between September 2020 and September 2021 that the OGC was taken down.

Its leader was apparently found hiding in the Dominican Republic on fake documents, and extradited to Hungary last week.

Overall, 130 suspects were identified and 116 searches conducted. The group is estimated to have caused losses of around €3.5m ($4m) for over 470 victims.

The fraud gang worked by posting fake ads for properties up for sale or rent — tricking victims into sending deposit money and rent. The OGC also remotely hacked some victims’ PCs, stole financial details and carried out transactions without their knowledge, Europol claimed.

In some cases, COVID-19 was used as an excuse to install remote access software on these machines, it said.

Money mules were recruited in Hungary to open bank accounts, receive and transfer funds and carry out cryptocurrency transactions to help with money laundering — with the illegal proceeds sent to the Dominican Republic.

According to a new Serious and Organized Crime Threat Assessment report from Europol, the drive to digital is creating new opportunities for OGCs and lone cyber-criminals alike.

“The move toward cashless economies creates powerful incentives for payment fraudsters … The steady increase in the number of users and connections creates new vulnerabilities and opens more potential victims to cyber-attacks,” it explained.

“Cybercrime is attractive to criminals due to the potential profits, limited risk of detection and prosecution, which if successful often only results in low sentences.”

Real estate and rental fraud reported to the FBI last year cost victims an estimated $213m off the back of around 13,600 cases. As such it represented one of the top 10 earners for cyber-criminals.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Data Breach Volumes for 2021 Already Exceed 2020 Total

Data Breach Volumes for 2021 Already Exceed 2020 Total

The number of data breaches publicly reported so far this year has already exceeded the total for 2020, putting 2021 on track for a record year, according to the Identity Theft Resource Center (ITRC).

The non-profit’s figures for Q3 breach volumes came in at 446 incidents. Although this is lower than the 491 breaches reported in the second quarter, the total for the year-to-date is now 1291, versus 1108 in 2020.

The all-time high of 1529 breaches was set in 2017, but with phishing and ransomware leading the way in driving volumes up this year, it’s predicted that 2021 could exceed that figure.

Eva Velasquez, president and CEO of the ITRC, said 2021 is just 238 breaches away from tying the all-time record for a single year.

“It’s also interesting to note that the 1,111 data breaches from cyber-attacks so far this year exceeds the total number of data compromises from all causes in 2020,” she added.

“Everyone needs to continue to practice good cyber-hygiene to protect themselves and their loved ones as these crimes continue to increase.”

The ITRC’s figures comprise not only traditional breaches where malicious third parties steal data from organizations, but also cases of cloud misconfigurations that lead to data leaking into the public domain.

Cases of the former in the year-to-date rose 27% versus the whole of 2020.

Cloud leaks often affect large numbers of users, even if the data does not ultimately end up in the wrong hands. To that end, the number of data compromise victims in Q3 (160 million) is higher than Q1 and Q2 2021 combined (121 million). However, that figure is mainly due to unsecured cloud databases, ITRC said.

Interestingly, there have been no reported breaches this year associated with payment skimming campaigns, often dubbed “Magecart.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Infosec Experts: Twitch Breach “As Bad as it Gets”

Infosec Experts: Twitch Breach “As Bad as it Gets”

Gaming and content streaming giant Twitch has confirmed a breach has taken place at the firm, after reports claimed a hacktivist leaked its entire source code, creator info and internal data.

A brief statement from the Amazon-owned firm, posted yesterday afternoon, said: “Our teams are working with urgency to understand the extent of this. We will update the community as soon as additional information is available. Thank you for bearing with us.”

That came after Video Games Chronicle first reported that an anonymous 4Chan user posted a 125GB torrent link to the site containing the data dump. Sources told the site it could have been taken as recently as Monday.

Leaked data reportedly includes all of the firm’s source code; mobile, desktop and console clients; proprietary SDKs and internal AWS services; and “every other property” it owns, including IGDB, CurseForge and an unreleased Steam competitor, dubbed “Vapor.”

Also leaked were red teaming tools used by the firm’s SecOps function and, perhaps most embarrassing, sensitive information on how much it paid its most popular streamers back in 2019 — which reached millions of dollars for some.

It appears the hacker may have been acting in retaliation for what many users saw as Twitch’s inadequate response to the problem of hate raids on the site over the summer. Here, bots were used by trolls to flood the chat section of certain streamers, mainly from minority or marginalized communities, with hateful messages.

In fact, in the original post, the anonymous hacktivist described Twitch as a “disgusting toxic cesspool” and that they were releasing source code from nearly 6000 internal Git repositories “to foster more disruption and competition in the online video streaming space.”

“Jeff Bezos paid $970m for this, we’re giving it away FOR FREE. #DoBetterTwitch,” they added, using the hashtag popular with hate raid protesters.

Cybersecurity experts were quick to ask questions of the internal security posture at one of the world’s biggest gaming platforms.

“This will send a shudder down any hardened infosec professional. This is as bad as it could possibly be,” argued ThreatModeler CEO, Archie Agarwal.

“The first question on everyone’s mind has to be: how on earth did someone exfiltrate 125GB of the most sensitive data imaginable without tripping a single alarm? There’s going to be some very hard questions asked internally.”

He added that user information will probably have been swept up in the breach, so account credentials will need to be reset.

“This incident serves as a reminder that while ransomware attacks are taking up the majority of headlines recently, breaches that result in stolen proprietary data are still a real and persistent threat,” argued Darren McCutchen, principal threat researcher at NetWitness.

“It’s important that enterprises have the ability to detect threats immediately and react quickly to keep threat actors from gaining access to critical systems and then moving laterally to steal seemingly unrelated data and information.”

Most worrying for Twitch is the fact that the initial leak was labelled “part one,” indicating there’s more to come.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

2021 Hispanic Heritage Month Pt. 3: A Celebration of Hispanic Heritage and Hope

Did you know, the timing of Hispanic Heritage Month coincides with the Independence Day celebrations of several Latin American nations?

At McAfee Enterprise, we’re celebrating Hispanic Heritage Month by recognizing some of our amazing employees and asking them about their heritage and the impact it had on their career and journey to cybersecurity. Read my conversation with Zuly Gonzalez below on how her family and culture have impacted her career.

What do you enjoy most about your heritage and what is one of your favorite memories growing up?

My parents moved to mainland US when I was young. During the summers, we’d go on vacation to Puerto Rico and one of my fondest memories growing up are the plane flights to/from Puerto Rico. This was before 9/11, when flying wasn’t what it is today. My sisters and I would keep ourselves entertained playing games. It was an adventure for us and the highlight was always a warm chicken or pasta meal.

What family traditions did you have growing up?

We had two Christmas celebrations, which as a kid, you can’t ask for anything better! We celebrated Christmas on the 25th, which was the big event where we got most of our presents. Then on January 6 we’d celebrate “Día de Reyes” (Three Kings Day) where we would get a few more presents.

What are the three most important things that people should know about your culture?

I’d say three things that are central to Puerto Rican culture are: family, God, and passion/hard work. Puerto Ricans believe in traditional family values. Religion plays an important part in our culture. And the Puerto Rican passion is hard to understate. I have to be careful, because a lot of times my passion leads me to speak very loudly, which can sometimes be misinterpreted by non-Hispanics as anger or aggression, when in fact, it’s just excitement. I saw a T-shirt recently that said, “I’m not yelling. I’m Puerto Rican.” This is so true!

Describe your favorite traditional dish, and how it was prepared. Who usually prepared it for family meals?

One of my favorite dishes growing up, because we didn’t have it often, was sancocho. It’s a rich, comfort soup made with root vegetables and other starchy vegetables common in Puerto Rico. Ingredients include ñame, yautia, pana, papas, platanos, guineos, maiz, and batatas, among other things. A few of the ingredients are hard to find in the US, and when you do find them, are expensive, so we didn’t have it often growing up. But when my mom did make it, it was always a treat!

How have Hispanic individuals helped contribute to where you are today in life and career?

My parents were by far the biggest influence in my life. They taught me that I could be and do anything I wanted in life. They didn’t set limits for what I could achieve and taught me that with hard work anything is possible.

I followed my father’s footsteps by pursuing a career in STEM and attending the same university he attended. In fact, thinking about it now as I answer this question, I think that even more so than my mom, my dad had the biggest influence on who I am today as an individual. He shaped a lot of my personality, my beliefs, and a lot of the decisions I’ve made in my life, both personally and professionally.

Tell us about your journey to a career in technology and how your heritage played a role to where you are today?

Family values are very important in Puerto Rican culture. My dad was a math teacher and growing up he was always ready to help me with my homework. During the summer trip to Puerto Rico before I graduated high school, we took a tour of the university my dad went to. I ended up going to that university, which set me on the path to where I am today in my career. I obtained a degree in Computer Engineering and a co-op opportunity (similar to an internship) at NSA. NSA led me to a career in cybersecurity. At NSA I met Beau Adkins, who later turned into my partner in life and in business. Beau and I founded Light Point Security, which ultimately led us to McAfee Enterprise. But it all started with my parents. Without my parents’ motivation, support, and ultimate push to attend the University of Puerto Rico, I wouldn’t be where I am today.

As the country continues to grow more diverse, what advice would you give to young Hispanic individuals interested in starting a career in cybersecurity?

Same advice I’d give any young person interested in any career path. That is – look for ways to learn outside of a traditional school setting. Getting a hands on experience is so important. First, it shows initiative and passion. Second, to use an analogy: Reading and memorizing a cooking recipe, and even knowing the history behind each ingredient, isn’t necessarily going to translate into a delicious meal, it takes practice. Practice with the equipment, practice with the ingredients, and sprinkle in your own creativity to make an expert dish. One that people will pay money for!

The post 2021 Hispanic Heritage Month Pt. 3: A Celebration of Hispanic Heritage and Hope appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

America Urged to Prepare for Shift to Post-Quantum Cryptography

America Urged to Prepare for Shift to Post-Quantum Cryptography

The Department of Homeland Security (DHS) has teamed up with the Department of Commerce’s National Institute of Standards and Technology (NIST) to release a roadmap on the best way for organizations to navigate the transition to post-quantum cryptography.

The guide provides relevant stakeholders with achievable steps they can take to reduce the risks related to the advancement of quantum computing technology.

“While quantum computing promises unprecedented speed and power in computing, it also poses new risks.  As this technology advances over the next decade, it is expected to break some encryption methods that are widely used to protect customer data, complete business transactions, and secure communications,” said a DHS spokesperson.

“DHS’s new guidance will help organizations prepare for the transition to post-quantum cryptography by identifying, prioritizing, and protecting potentially vulnerable data, algorithms, protocols, and systems.”

Under the new roadmap, organizations are encouraged to follow a seven-step plan that will enable them to hit the ground running when NIST completes its ongoing process to create a new post-quantum cryptography standard. 

Actions that organizations “should consider” include taking stock of their current cryptographic systems and the data being protected, and prioritizing systems for transition.

“Organizations should inventory the most sensitive and critical datasets that must be secured for an extended amount of time,” reads the guidance. 

“This information will inform future analysis by identifying what data may be at risk now and decrypted once a cryptographically relevant quantum computer is available.”

Once the prioritization has been completed, organizations should develop a plan for systems transitions under the guidance of their cybersecurity officials. 

The roadmap’s release follows US Secretary of Homeland Security Alejandro Mayorkas’ identification of the move to post-quantum encryption as a priority.

Speaking on March 31, 2021, Mayorkas said: “The transition to post-quantum encryption algorithms is as much dependent on the development of such algorithms as it is on their adoption. While the former is already ongoing, planning for the latter remains in its infancy.”

He added: “We must prepare for it now to protect the confidentiality of data that already exists today and remains sensitive in the future.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Texan Imprisoned Over COVID-19 Hoax

Texan Imprisoned Over COVID-19 Hoax

A man from Texas has been sentenced to 15 months in federal prison after lying on social media.  

San Antonio resident Christopher Charles Perez, also known as Christopher Robbins, posted two messages on Facebook in April 2020 in which he falsely claimed to have hired a person infected with COVID-19 to lick items on display at grocery stores.

Perez, who is aged 40, said in the messages that goods for sale in several shops in the San Antonio area had been licked. 

The US Attorney’s Office for the Western District of Texas said Perez posted the “threatening” messages “to scare people away from visiting the stores.”

On April 5, 2020, a screenshot of the first message posted by Perez was sent to the Southwest Texas Fusion Center (SWTFC) via an online tip. SWTFC then contacted the FBI office in San Antonio, which investigated the matter and found the threats made by Perez to be false.   

“Perez did not pay someone to intentionally spread coronavirus at grocery stores, according to investigators and Perez’s own admissions,” said the US Attorney’s Office in a statement published October 4.

Following the FBI investigation into his social media posts, Perez was charged with two counts of 18 U.S.C. § 1038, which criminalizes false information and hoaxes related to biological weapons. 

A federal jury found him guilty of the charges, and on Monday Perez was handed a custodial sentence and ordered to pay a $1,000 fine. 

“Those who would threaten to use COVID-19 as a weapon against others will be held accountable for their actions, even if the threat was a hoax,” said FBI San Antonio Division Special Agent in Charge Christopher Combs. “Perez’s actions were knowingly designed to spread fear and panic, and today’s sentencing illustrates the seriousness of this crime.”

US Attorney Ashley Hoff said that “trying to scare people with the threat of spreading dangerous diseases is no joking matter.”

She added: “This office takes seriously threats to harm the community and will prosecute them to the full extent of the law.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains