Showing posts with label Information Stealing. Show all posts
Showing posts with label Information Stealing. Show all posts

Tuesday, 27 October 2015

Ransomware Threatens With Publishing Encrypted Data


In Germany, new ransomware surfaced that not only encrypts files, but the system locks and threatens private data, to publish photos and videos on the Web. Chimera as the ransomware is called, focuses on companies.

Via so-called vacancies, job applications, contracts and applications are businesses approached. In the e-mails reference is made to a file on Dropbox for further information. This file is the ransomware which kinds of files on the computer encrypts. Furthermore Chimera searches for files on network drives to encrypt. The system then also be locked and a message appears with instructions.

The instructions let victims know that they have to pay almost 2.5 bitcoin, what with the current exchange rate is about 635 euros. The report furthermore states that if there is no paid personal data, photos and videos will appear with the victim's name on the Internet. Traditional ransomware encrypts files often alone. Threatening to steal and publishing of data is therefore not new. Chimera or eventually the data put online as claimed is unknown, said Botfrei.

Wednesday, 21 October 2015

Online Pharmacy Gets High Fine For Selling Customer Data


The leading online pharmacy in Britain, which provides the global medicines, be punished with an almost 180 000 euro to pay on account of the sale of customer data to marketing companies. Pharmacy 2U sold customer names and addresses through online marketing.

The data were, among other things purchased by a company that provides supplements and already was warned for misleading advertising, as well as an Australian lottery company where an investigation has been set. During examination of the UK privacy regulator ICO found that Pharmacy2U customers are not informed about the sale of their data. Also, the data were sold without permission.

"Patient confidentiality is ingrained pharmacies. It is inconceivable that a company in this sector believe that these actions were acceptable," said David Smith of the ICO. He argues that once the data of people are selling their information is often sold several times. In total, data from more than 100,000 customers were offered. Companies had to pay some 180 euros per 1000 records for that. In a statement states Pharmacy2U that it was an incident and there was no foul play.

Friday, 18 September 2015

Trojan Cheat During Online Poker


In the past, there are several Trojans discovered that steal passwords and credit card information from online poker players, but now there is a copy discovered that was created to cheat. Which allow researchers from the Slovak anti-virus company ESET know today.

The Odlaner Trojan is located in popular programs like Daemon Tools or mTorrent offered outside the official website.There are several poker programs out where the malware was added. Once activated, the Trojan makes screenshots of poker players who play PokerStars or Full Tilt Poker and give their ID to the malware creator through. They can look up the poker player using the id line and then joins the table where the infected player at the moment is playing.

Or the malware creator then plays itself whether this is done through a bone is unknown, said the researchers. Most infections with the Odlaner Trojan are located in Eastern Europe, namely Russia (36% of infections) and the Ukraine (35%). In total, it will go to hundreds of casualties. The tactic to take screenshots is not new. In 2012 there was discovered another Trojan that this tactic applied.


SHA1 hashes
18d9c30294ae989eb8933aeaa160570bd7309afc
510acecee856abc3e1804f63743ce4a9de4f632e
dfa64f053bbf549908b32f1f0e3cf693678c5f5a

Wednesday, 16 September 2015

SEC Traders Pay 30 Million For Hacked Releases



Two equity traders have a settlement with the US Securities and Exchange Commission (SEC) is closed and will pay $ 30 million for using hacked press releases. It was recently announced that criminals for years had hacked several media companies to gain access to unpublished press releases.

These press releases were then used to trading in equities. The steal of the releases took place from 2010 to 2014. According to the SEC 34 suspects were reportedly more than 100 million dollars have earned this. The two suspects now reached a settlement earned with information from the press releases stolen 25 million dollars. In total, they have fraudulently obtained $ 30 million, although not announced where the remaining comes from five million dollars. This amount they now pay back, although the court must still approve the settlement. The case against the remaining 32 defendants are still pending.

Tuesday, 21 July 2015

Ashley Madison Lets Users Remove Free Profile



The hacked website for cheaters Ashley Madison offers users the option to remove their profiles free of charge, after an attacker there previously managed the data of 37 million users to steal. It would be profiles with "secret sexual fantasies," nude photos and user calls, including related credit card transactions, real names and addresses.

How the attacker access data to gain knew was not disclosed, but Avid Life Media, the company behind Ashley Madison, says that all "unauthorized access" are closed. There is also with investigating authorities initiated an investigation into the attacker and the company claims that the perpetrator will finally be held accountable.

Delete Function

In addition to the theft of user data, the attacker claimed that the website users cheated. Ashley Madison offers users: the ability to delete their profiles fee of $ 19, but the striker claims that this feature does not work properly. Details of purchases made with a credit card, including real names and addresses, remain as the attacker in the database behind.

In a statement enables Avid Life Media that paid delete function deletes all information related to the user and communication of the user. However, it is unclear whether the card data is included. The delete function last year, the company would have resulted in $ 1.7 million. However, because of the incident, it was decided that users are now free information deleted their profile.

Monday, 20 July 2015

37 Million Users Information Stolen Ashley Madison


Attackers have managed the data of 37 million users of AshleyMadison.com to steal a website for adulterers, and threaten to reveal if the site is not closed. In addition to the user data would also financial information and other business data are stolen.

The attackers threatened to publish the captured data as Ashley Madison and Established Men, a dating site for "young women to find successful men" from the same company can not be taken offline. It would be profiles with "secret sexual fantasies," nude photos and user calls, including related credit card transactions, real names and addresses. Ashley Madison claims to have over 37 million users. Furthermore, will the business documents and e-mails are posted online, says IT journalist Brian Krebs .

Remove Function

Next, the attackers that the delete function offered by the website is not working. Users may remove their profile data for $ 19. This feature, called "full delete", the company last year would have yielded $ 1.7 million. However, not alll data deleted.Details of purchases made with a credit card, including real names and addresses, continue to follow the attackers in the database behind.

Avid Life Media, the company behind the two Web sites, confirms in a statement that it is indeed hacked. According to him, it would have invested in the latest privacy and security, but this could not prevent the intrusion. Furthermore Avid Life Media late declaration know nothing, except that the investigation into the extent of the incident is ongoing.

Wednesday, 20 May 2015

US Bank Reset Passwords After DNS Attack


Attackers are there in late April failed to adjust the DNS settings of a website of a US bank, allowing visitors to a malicious website were redirected where possible their credentials stolen. The attack was directed against the Federal Reserve Bank of St. Louis.

The attackers modified the IP address of the subdomain research.stlouisfed.org , pointing normal to a research site.Through the research site can all kinds of economic data and research information is requested. Of users on 24 April this year on the website tried to log on possible stolen the data, so the bench late in a warning to know which IT journalist Brian Krebs features. Across from CNBC , the bank confirmed the attack. Because of the potential data theft, the bank reset the passwords of all users. How the attackers were able to change the DNS settings is not known.

Tuesday, 19 May 2015

Criminals Steal 460,000 Euros Via E-mail Hack


A British family that sold a house in London and thought to be 460,000 euros richer, has been the victim of an email in which criminals hack the money left over to make their statement. Two days before the home sales mailed the lawyer's family asking for account information.

The homeowner mailed his account details and bank code number back. According to the Daily Telegraph knew criminals to intercept e-mail and sent from the same email account, a new message. It claimed to ignore the previously sent invoice data and make the money to another account. After the sale was the lawyer 460,000 euros to that account. A few days later the property owner contact the lawyer, after the fraud came to light and the police were called and banking.

The account of the crooks was frozen, leaving a small 375,000 euros could be secured. 85,000 euro, however, was already included. According to several law firms there is a trend in which law firms are the target of all kinds of scams. Rob Hailstone of the Bold Legal Group, representing 350 law firms, states that financial information should never be sent via unsecured e-mail.

Both attorneys and clients confidential matters would have to send encrypted as well. In addition, consumers are advised to use a strong password for their email account. The homeowner served both at the law firm and the bank in a complaint. A supervisor argued that the law is indeed responsible. However, the bank denies all liability.

Friday, 15 May 2015

Provider Mobile Spyware Hacked, Customer Data Leaked


Attackers have managed at a popular provider of mobile spyware to break into and subsequently stolen and put online database with customer data. The software in question is mSpy that own words almost 2 million users have.

According to the attackers in the hack, which is unknown how that occurred, captured the data of more than 400,000 people.IT journalist Brian Krebs , however, that the actual number of customers affected can not be determined. However, concerns sensitive information such as emails, text messages, pay and location data, passwords, Apple ID, photos and calendar data.In total, there were hundreds of gigabytes of data stolen.

Through mSpy users can use the phone a different monitors, such as incoming and outgoing calls, text messages, emails, GPS location, chat conversations, Internet and can access the address book and calendar are obtained. For this purpose it is required that the user has physical access to the device of the other, so that the mSpy can be installed. The software itself has not yet responded to the burglary.

Wednesday, 13 May 2015

Starbucks Customers In The US Deprived Through Hacked Accounts


Several mobile customers of coffee chain Starbucks in the United States become the target of criminals.These are consumers who have their Starbucks account linked to their credit so the account is upgraded automatically. Once the attackers access to the account managed to get, they could steal hundreds of dollars within a few minutes, reports journalist Bob Sullivan .

How big the damage and the number of affected victims exactly, is unknown. Sullivan spoke with several victims. Also on Reddit doing different duped clients their story, how the user name, email address and password for their account were changed and then any amount of the associated credit card or PayPal account was debited. A spokesman for Starbucks represent to Geek Wire that the number of incidents is limited and the coffee chain has taken action against fraud.

Additionally advises Starbucks to users to ensure that their information is protected, for example by using strong passwords.How the accounts are hijacked exactly is unknown, but it seems that weak passwords are possible causes. Consumers also get Sullivan advised to automatically upgrade their Starbucks account disable using their credit card or PayPal account.

Saturday, 7 March 2015

British Police Arrest 57 People Due To Cybercrime


British police last week arrested 57 people on suspicion of cybercrime. The arrested persons are suspected of breaking into multinationals and government and steal data, performing DDoS attacks, cyber fraud and developing malware.

This would have a 21-year-old man 400,000 email addresses and passwords of Yahoo stolen and published in 2012. A 33-year-old man is suspected of having a DDoS attack on a competitor performed in order to gain a competitive advantage. A third suspect would have carried out a phishing attack in which £ 15,000 was captured. A 23-year-old man is suspected of breaking into the Pentagon, where he information about a satellite service would have captured.


In addition to maintaining all the suspects said the British National Crime Agency (NCA), which this week also SMEs, hosting companies and ISPs helped identify threats to their infrastructure. So got 60 companies visited by the police and became their IT environment controlled. This resulted in more than 5,500 hacked servers.

Through these servers could send cybercriminals spam, perform DDoS attacks and hosting phishing sites. If organizations follow the advice of the NCA, it could halve the phishing attacks in Britain, according to the investigation department. Police Chief Executive Peter Goodman calls geburikers organizations and therefore to take simple measures that help to be safe on the Internet and make it harder for criminals to get away with it.

Tuesday, 3 February 2015

Skype Malware Steals Battle Plan Syrian Opposition

The Syrian opposition has become the target of attackers who managed to steal confidential documents nearly 8GB via Skype malware, including battle plans, troop locations, names of fighters and lists of deceased soldiers, as well as all sorts of other data. The attackers would logs more than 31,000 Skype calls have stolen and had provided the Skype databases. These databases contain the contacts of the victim and call details.In this way, the attackers were a comprehensive picture of the relationships within the opposition.

To obtain the information the attackers made several Skype accounts with female profile pictures. The profiles were then used against male members of the Syrian opposition. First, a relationship with the targets are built before they were sent via Skype malware. In addition, the attackers asked regularly whether the targets were using Skype on their phone or computer.Probably to determine what needed to be used for malware.

Before the malware was sent the attackers targeted first asked for a photo. Then they sent supposedly a picture of the "woman" behind the profile back. It was a self-extracting RAR archive with a .pif file extension. If the victim opened the so-called photo got to see a picture, while in the background the Dark Comet Remote Access Tool (RAT) was installed. Through this malware, the attackers had full control over the computer.

According to security firm FireEye that the attack campaign discovered the attackers used the stolen Skype databases to select next victims. In addition, would share many opposition members forced computers. Once a computer was infected, the attackers of several people could steal their data. "This information probably fulfilled an important role in the operational plans and tactical decisions of the enemy, but were possible at the expense of human lives," said FireEye.

Monday, 2 February 2015

Business Chat Service HipChat Hacked


Business chat service HipChat has all users reset the password after attackers access to user data managed to get. It would be email addresses, user names, names and encrypted passwords for less than 2% of all users. According HipChat there are no indications that there payment information is compromised.

HipChat states that the passwords are hashed and gesalt. From extra precaution, all HipChat Users reset the password, as well as accounts that use the same email address for other services developer Atlassian. In addition, users are advised to use strong passwords for all websites to choose a separate password. How the attackers access to the data received, the company does not know. Through HipChat users can set up group chats.

Tuesday, 27 January 2015

Group Threatens Malaysia Airlines With publication Data Stolen


A group of cyber vandals Malaysia Airlines has threatened to publish information that would be captured on the website of the airline. The website was launched today, reports the Malaysian Star Online . A group calling itself the "Cyber ​​Caliphate" calls had a photo of a Malaysia Airlines Airbus A380 on the website loaded with the words "404 - Plane Not Found".

Not much later, the site was again the target of an attack, this time by a group calling itself "Lizard Squad - Official Cyber ​​Caliphate" calls. On Facebook Malaysia Airlines announces that the DNS (Domain Name System) has been compromised so visitors were redirected to a website of the attackers. The Domain Name System (DNS) is similar to the directory and translates among other domain names into IP addresses. Meanwhile, the DNS changes would be undone.

"Malaysia Airlines reassures customers that is not hacked the website and this temporary error has no effect on their bookings and their data is safe," said a statement from the airline. The group that calls itself Lizard Squad, however, claims that Malaysia Airlines lying and there are good data stolen, which will soon publish the group claims.