Coin Ninja CEO Admits Operating Darknet Bitcoin Mixer

Coin Ninja CEO Admits Operating Darknet Bitcoin Mixer

A CEO from Ohio has pleaded guilty to being the operator of a darknet-based Bitcoin ‘mixer’ service that laundered more than $300m

Akron resident and CEO of Bitcoin media site Coin Ninja Larry Dean Harmon was at the helm of underground cryptocurrency laundering service Helix for three years, from 2014 to 2017. 

During that time, the 38-year-old creator of crypto-wallet provider DropBit conspired with darknet vendors to launder over 350,000 Bitcoin generated through drug trafficking and other illegal activities.

Helix partnered with several darknet markets, including AlphaBay, Evolution, and Cloud 9, to provide its customers with a way to send Bitcoin to designated recipients while concealing the source or owner of the cryptocurrency.

In exchange for a 2.5% fee, Helix would ‘mix’ or ‘tumble’ customers’ Bitcoin so that it was untraceable. Harmon advertised Helix on the darknet as a way for customers to conceal their transactions from law enforcement.

Court documents showed that Helix was linked to and associated with the leading search engine on the darknet, “Grams,” which was also run by Harmon. 

Harmon was placed in custody in February 2020, shortly after a warrant was put out for his arrest. On August 18, he pleaded guilty to his part in the Helix money-laundering conspiracy. 

As part of his plea, Harmon agreed to the forfeiture of more than 4,400 Bitcoin, currently valued at more than $200m, and other seized properties that were involved in the criminal conspiracy.

A date has not been set for Harmon’s sentencing. The crypto criminal could be handed a maximum prison sentence of 20 years and be ordered to pay a fine of up to $500,000 or twice the value of the property involved in the transaction.

Harmon could further be sentenced to a term of supervised release of not more than three years, and mandatory restitution.

“Darknet markets and the dealers who sell opioids and other illegal drugs on them are a growing scourge,” said Acting US Attorney Channing Phillips for the District of Columbia. 

“They may try to hide their identities and launder millions in sales behind technologies like Helix. But the department and its law enforcement partners will shine a light on their activities, dismantle the infrastructure such criminal marketplaces depend on, and prosecute and convict those responsible.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

JPMorgan Chase Notifies Customers of Data Breach

JPMorgan Chase Notifies Customers of Data Breach

American banking and financial services company JPMorgan Chase is warning customers in Montana that a technical glitch may have presented their personal data to other customers.

The malfunction allowed users of the website chase.com or the Chase Mobile app to view the banking information of other customers whose personal details were similar for nearly two months earlier this year. 

Data that may have been compromised included customers’ names, account numbers, account balances, and details of their transactions. 

“We learned of a technical issue here that may have mistakenly allowed another customer with similar personal information to see your account information on chase.com or in the Chase Mobile app, or receive your account statements,” wrote JPMorgan Chase in a data breach notification letter available via the Montana attorney general’s website.

The data breach was reported to the Montana Office of the Attorney General on August 13 as having begun on May 24 and having ended on July 14. 

JPMorgan Chase advised customers: “The other customer might have seen information about your accounts, including balance(s) and transactions as well as your name and account numbers.”

The bank said that no evidence has been found to suggest that the personal information of customers who were impacted by the data breach has been “used inappropriately.”

Customers were informed that they will not be held liable “for any fraudulent activity on your Chase accounts that you promptly tell us about,” and were encouraged to check their accounts regularly for suspicious activity.

After apologizing for the accidental data exposure, JPMorgan Chase offered the seven customers who were impacted by the breach one year of free credit monitoring. 

The data breach is the second to be reported to the Montana Office of the Attorney General by JPMorgan Chase. Last year, the company notified two customers that between April and November 2020 a call center employee may have allowed an unauthorized third party to overhear phone calls in which personal information about their Chase account was shared.

Data compromised in the 2020 breach may have included name, address, account number, Social Security number and email address. The breach was reported on December 23, 2020. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Data Stolen as Social Housing Group Suffers Ransomware Attack

Data Stolen as Social Housing Group Suffers Ransomware Attack

Hackers have stolen data from a Salford-based social housing group that houses thousands of tenants and other clients.

ForHousing and Liberty, which manage and maintain homes across the North West, were reportedly victims of a ransomware attack. The organizations confirmed that no data of tenants or staff were accessed, but a ‘small amount’ of data was compromised, which resulted in the systems being taken offline as a precautionary measure

Ransomware is a type of malware that employs encryption to steal a victim’s information at ransom. The information is encrypted so files, databases or applications cannot be accessed.

Ray Jones, group managing director of Liberty, said the investigations into the incident have now ended. He said, “We can confirm that a small amount of data was compromised during the incident.

“We have liaised with the relevant authorities, and are currently working closely with any of our partners who have been affected to allow them to be extra vigilant.”

ForHousing and Liberty are part of the ForViva group, based in Eccles.

ForViva group CEO Colette McKune said, “Tenant and staff safety is our priority and this includes the safety and integrity of their data.”

“We have informed tenants about this incident and confirmed that their data is safe.”

Other housing associations have been attacked recently. In November 2020, a housing association in East Anglia was hit by a ransomware attack. The attack forced Flagship Group to take its IT systems offline after the Sodinokibi strain entered the company via a phishing attack. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

IT Leaders: Nation State Campaigns Are Inspiring Cybercrime Attacks

IT Leaders: Nation State Campaigns Are Inspiring Cybercrime Attacks

Nearly three-quarters (72%) of IT leaders are concerned that tools and techniques used by nation-states will eventually end up in the hands of cyber-criminals and be used to attack their organization, according to HP.

The findings come from a poll of 1100 IT decision-makers in the UK, the US, Canada, Mexico, Germany, Australia and Japan.

Ian Pratt, global head of security, personal systems at HP, argued that such concerns are well-founded. He cited recent events such as the Kaseya attack on MSPs which appear to be partly inspired by the Kremlin’s SolarWinds campaign.

“Now the return on investment is strong enough to enable cyber-criminal gangs to increase their level of sophistication so that they can start mimicking some of the techniques deployed by nation-states,” he noted.

“The [Kaseya attack] is the first time I can recall a ransomware gang using a software supply chain attack in this way.”

Independent software vendors (ISVs) in particular must be extra alert to similar “stepping stone” attacks in the future, even if they don’t have major enterprise customers, Pratt warned.

Respondents to the HP poll also flagged their concerns about direct attacks from nation-states. Over half (58%) said they were worried about such an eventuality, while 70% said they could become collateral damage in a cyber-war.

The top concerns among IT decision-makers were sabotaged data and systems, disruption to operations, theft of data and impact on revenue.

The poll follows a significant report by HP released in April, which warned that the world has never been closer to a full-scale war, waged due to state-backed cyber-attacks.

President Biden seemed to acknowledge this point when he warned last month that if the US ended up in a “real shooting war” with another major power, it would likely result from a severe cyber breach.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Census Bureau Slammed for 2020 Breach

US Census Bureau Slammed for 2020 Breach

The US Census Bureau has been heavily criticized by a government inspector after a 2020 breach which could have been prevented by prompt patching.

Although the attacker was not able to access servers used for the 2020 census, they could modify user account data to prepare for remote code execution, according to the US Office of Inspector General (OIG) report.

Fortunately, the attacker’s attempt to maintain access to the system by creating a backdoor was unsuccessful, thanks to the Bureau’s firewalls. However, the report highlighted a string of failures by the Bureau, which directly led to the attack and complicated incident response efforts.

First, it failed to patch a critical vulnerability on its remote access servers that was exploited by the attacker, despite the vendor publishing a fix more than three weeks earlier.

Second, it failed to promptly discover and report the incident because its SIEM was not set up to analyze suspicious activity in real-time. That created a delay of two weeks before the incident was detected.

Third, an incident investigation was hindered because none of the Bureau’s remote access servers sent system logs to its SIEM platform.

According to the report, the organization also operated servers no longer supported by the vendor and did not prioritize decommissioning these, further exposing it to attacks.

Finally, the Census Bureau didn’t hold a formal “lessons learned” session with incident responders and other stakeholders, which could have improved its processes in preparation for future breaches.

The Census Bureau welcomed the feedback from the OIG and repeated that “no systems or data maintained and managed by the Census Bureau on behalf of the public were compromised, manipulated, or lost because of the incident highlighted in the OIG’s report.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains