Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassW0rd – 12th December 2018 (Cybercrime Christmas)

PassW0rd – 12th December 2018 (Cybercrime Christmas)

Play

Speaker A: This program is brought to you by Resonance 104.4 FM. If you like what you hear and want to support our work, please make a donation at fundraiser.resonance.fm.

Speaker C: Hello and welcome to Password, taking apart the technology that connects us to each other. It builds our daily lives and can also destroy them. The last Office of National Statistics figures on crime show that nearly 50% of the 10.5 million crimes committed last year either involved high-tech fraud or computer misuse. And we can exclusively reveal that gangs of cybercriminals are now recruiting young would-be hackers at school gates in parts of the United Kingdom. We can also exclusively reveal that the situation is now so bad that come January 2019, in an unprecedented move, the police are undertaking to investigate every cybercrime reported to them. And if the figures are anything to go by, they could be swamped because this year could be dubbed Cybercrime Christmas according to the computer security companies like Carbon Black,, which claims to have seen a 65% increase, and the City of London Police, which runs Action Fraud, who say they have seen a 15% increase in cybercrime year on year since 2015. And the reason for all of this activity is the time of year when people are buying presents online as well as doing all their normal activities. The risk of being ripped off losing your passwords and credit card numbers and even your identity is now higher than ever, just because the number of transactions has increased. Not only are they under the awful Christmas Day deadline, there are those people who are run off their feet and not really checking the delivery emails that they’re answering. And it’s not our fault. Angela Sasse is the Professor of Human-Centred Technology at University College London. She says the technology itself is to blame.

Speaker D: I think it’s just the security story here is just part, you know, to me it’s just part of, of a skills gap that has really opened up. The adoption of technology has really been quite rapid. If you look at the speed at which networking is really, you know, and mobile phone technology has spread that kind of connectivity. I think, you know, the education people are getting in schools, and certainly what do you do about people who’ve, you know, who left school before this kind of technology spread. It’s really, we haven’t really had any effective ways of updating people’s digital skills outside the work context. And arguably, I think actually cybersecurity is an example where even in the work context organizations are struggling to get the right kind of knowledge and skills to their workforce. My research has shown time and time again is that there is a really negative perception of cybersecurity, and it comes from the fact that security specialists are really, as I said, you know, it’s basically one of the— it’s the last area of technology that hasn’t been touched by usability and and really people having proper design and testing and having the kind of right marketing around it and so on. It’s because security is communicated by the current generation of security experts in the way that, oh, security is really important, so just do what I say. And that meant they didn’t actually look at what am I really asking people to do, how much How much would they have to know? How much time would they have to spend on that? Is that reasonable in the context of the tasks they’re doing at work, you know, or what they would have to do at home? And so there have been some sort of pretty unrealistic expectations, as I said, about like, you know, how many that people could have, like dozens of strong passwords and keep them all unique and, you know, not write them down and whatever. And that’s just not possible. And I think similarly, we’re also seeing is that people, you know, when people have to update their devices several times a week, that they get to the point where they’re going like, no, you know, I’m just going to sit a few of them out. And most people would think like doing updates once a month is reasonable, but having to do them several times a week, you go like, that’s just not sensible. And so I think that would have to be the first step, is that you have to make it easy for people to do it. To do the right thing by security. So as much as possible, the work needs to be done by the professionals, by the technology providers. And what they’re asking employees, consumers, citizens to do has to be— there has to be a small number of simple things that we can teach people as, as the right kind of habits and, and things that you do to keep your, your data and your technology Yeah.

Speaker C: As Angela Sasse says, keeping our passwords strong and safe can become a chore, and there are many online offers that tempt us to take a risk in order to save some money or make some. But it would be wrong to see Christmas as the target. Panic is the target. It might sound a bit extreme to describe cybercriminals as predators, but like Kenyan lions and hyenas shadowing wildebeest, They’re opportunistic and they like nothing better than to follow seasonal herds. A new target for the Nigerian advance fee fraud gang 419 are the tutoring agencies and the students who work for them who have got a hefty grant in their bank account and who are catering to the school children who are after grades to get them into schools and universities, and they’re panicking about those results. Charles Ridley, a student at Newcastle University, was a typical target. He thought he had found a foolproof way to get enough cash to pay for transatlantic flights so that he and his girlfriend could visit her parents in Canada.

Speaker E: So I was approached by a tutoring website called Superprof by someone asking if I could tutor their, their son over the Christmas holidays for a whole month. And then he asked if he were to pay me over the amount that I specified, if I could then pay his driver and his son for food and for their lodgings.

Speaker C: What? He said if he were to pay you over the amount you were asking? Yeah. This was an inducement? Yeah. So he was, he was going to pay you more money than you wanted?

Speaker E: Yeah, he was going to pay me £2,500 and my salary for the month would have been £600. And then on cashing the check, I was to let him know. And when I met his driver, I was supposed to give him the balance of the check.

Speaker C: How did you feel about this? What did you think? Did you think, yeah, sounds like a very wealthy man, he’s got a driver?

Speaker E: What did you think? Yeah, I thought I’d hit the big time. I thought, yeah, but even though it didn’t seem too good to be true, I still wanted to believe it.

Speaker C: What, you thought, what a stroke of luck, here you go. ‘Oh, somebody’s going to pay me $600. What’s that in pounds? It’s about, what, £500 or something.’ So you’ve sat there and thought, ‘There’s £500, this is going to be a good Christmas.’ Yeah, yeah, exactly. Okay, so there you are, you’ve been offered that money, and what happened then?

Speaker E: I received the check and I actually came very close to cashing it in if I had not forgotten my PIN. And then, on chatting to my dad, he advised that it was in fact too good to be true and I should at all costs not cash that check.

Speaker C: That check, you know, that looked like the physical proof that this thing was happening, didn’t it? What did you think when you saw that?

Speaker E: I thought, oh, I should cash it as quickly as possible. And it looked very legitimate from— I checked out the bank, it was from a bank from America, everything checked out. And yeah, I thought it would happen. But the only thing that did slightly put me off was the guy did have very poor English, which I think is characteristic of a 419 scam.

Speaker C: But surely that should have just made you think it’s more legit. That’s why he wants tutoring. His English isn’t great, so he’s coming to you. They want to be taught something.

Speaker E: It was the supposed father I was talking to for his son, who was primary school age.

Speaker C: But he must have seen— he must have seemed quite wealthy, mustn’t he? Got a driver. He’s going to send his driver to pick up the balance of the check. He must have thought, whoa, yeah.

Speaker E: I reasoned that he was just a bit strange. I didn’t see too much wrong with it at the time.

Speaker C: So this check, you thought this was real money in your hand? You thought that it’s— I mean, subsequently it was discovered that it was counterfeit, but you thought it was real, did you?

Speaker E: I was not aware that a check clear and then unclear in a way that would leave me liable.

Speaker C: I see. So basically what was going to happen was the sum of money would have shown up in your account as uncleared funds. You would have given them the balance, the— which is what, the $1,900, £1,498? You would have given them that money and then it wouldn’t have gone through your account. You would have been left £1,500, to all intents and purposes, worse off.

Speaker E: Yeah, exactly. I would be incredibly broke. I don’t know how I would have even been able to pay that kind of money off.

Speaker C: So that would have then been a very bad Christmas, wouldn’t it? The opposite of what you, you were thinking.

Speaker E: Yeah, exactly. I’m very fortunate that I, I had the foresight enough to cash it in.

Speaker C: Our own Brad Davies, Password’s computer gaming editor, has been monitoring the various scams that are going on involving getting cut-price gear for his favorite games— new skins, loot boxes, and upgrades, for example. They might be offered on eBay or on specialist auction sites like Blizzard, or in in-game sales venues like those for the games manufacturer Electronic Arts. And then the buyer asks you to deal with them direct. To cut out the middleman, just as 419 tried to do with Charles Ridley. But just as with Ridley, they are booby traps that can leave you without any money and no comeback.

Speaker F: So whatever you get from a loot box, whatever you get from a virtual pack of cards, it can be in the case of Blizzard, the rest of it weapons, the rest of it, but all virtual items that you can pay money for to begin with out of loot box systems or directly, you can sell those on for real cash to to someone else who wants them.

Speaker C: So people are buying weapons, the virtual weapons, of course, of course. And what, virtual costumes and things like that?

Speaker F: Virtual costumes. I’m in the case of FIFA, virtual players, and the best players are put aside on certain modes, and you can buy them for— I’d certainly say a high price, but that’s subjective— and sell them on for a higher price.

Speaker C: So what sort of price are we talking about buying them for, and what sort of price are you talking about selling them on for individually?

Speaker F: That’s down to the player. I have heard, um, transactions, some of the rarer ones going at £50 for one of these players slash cards.

Speaker C: And the virtual player would be who? What, Ronaldinho, Ronaldo?

Speaker F: Yes, yes, yes. As I say, um, I mean, football’s far more your place than mine, Peter, but whoever the top star is at the moment will of course hold the higher value, you know, within that aspect. So, so the more someone’s thought of you know, whatever it is in the world of football, uh, the higher their price at the end of the day.

Speaker C: It’s— and so what? So people make these teams up, they’ll have Ronaldo, they’ll have Messi, they’ll have Mbappé and all of these people. So they’ll have this wonderful team full of top players and they’ll have paid for it if you can afford it. Yes. And so, and when you sell them on, what, you sell them on to somebody else who wants to buy them?

Speaker F: Well, yes, you put it up, um, in the marketplace And, and, and from the marketplace, if someone sees the player, they like the price, they can just buy the player off you. The transfer is done on the internal systems, whether that be, as we say, EA, Blizzard, or any of the—

Speaker C: any of these internal markets.

Speaker F: Yes, it’s any of them, and they’ll take a fee on top of that, and, uh, the sale is transferred across.

Speaker C: And yet people are exploiting this. There’s a practice called scalping. What’s that?

Speaker F: Well, in itself is usually, you know, let’s say you want to sell me a card. Yeah, you— yeah, I approach you and I go, well, yeah, I like the price of that, I like the price of that, but after commission and the rest of it’s taken off, you’ll be getting so-and-so amount. So how about we get rid of that commission, I pay you the full price, you take it off the market, give it to me, we’re both happy.

Speaker C: So you’re doing a deal one-to-one and you’re not in— you’re essentially getting in contact with the seller and that— well, the buyer and seller are getting in contact via the marketplace and then they’re saying, no, actually we want to do a private sale.

Speaker F: Yes, yes. I’ll approach you and go, hold on, here’s my email address. How about you just, uh, you send me a little message so, um, I can then send you a message back? And then from there, I will propose to you that, as I say, no commission, no nothing else. I’ll give you the full value of that, and we can just circumvent this whole thing. It’s a lot easier for you and me.

Speaker C: So what you’re saying is, say it’s a player for £50 for argument’s sake. The person’s got him up for sale at £50. You’ve said, I’ll tell you what, I’ll pay you £45, I’ll get him £5 cheaper, but you’re not paying the commission, so you know, you’re better off.

Speaker F: Yes, we both win, we both win is what I’m saying to you. But of course then, outside of that, I can just comfortably have your virtual item within my possession because you transferred it to me through whichever means that each company has is now sitting safely in my little inventory. And well, from there, do I have to send you money? Who says I have to send you money?

Speaker C: So basically you’re saying that some people are saying that they’re entering into an agreement and then they’re not honoring the agreement.

Speaker F: They are not. And because all this is controlled, you know, within these companies’ own auction houses, their own selling platforms and the rest of it, Once you step outside of that, you’re then outside of their rules and regulations upon that. So they will just straight up not enforce any of that anymore.

Speaker C: So basically you’ve got no protection over the sale that you’ve made, and this person who wanted to offer you a good deal that was going to be a good deal for you and a good deal for them, they’ve got a really good deal because they haven’t paid anything at all. And probably what they could then do is go into that auction site again and sell that in a reputable way and get the money?

Speaker F: Yes, 100%. That’s exactly what they can do. Though, of course, you know, the company can turn around and investigate if they wish, but if it’s done outside their terms and conditions, eBay won’t follow it up. EA have got histories of not following it up. You’ve gone outside of their spectrum and they don’t care about it anymore. You try to cut them out of the loop And now you’re pretty much done.

Speaker C: Okay, and you know of one individual not 100 yards away from here who’s a child, was it?

Speaker F: Oh well, yes, yes, um, young teenager. I believe he was 14 when I heard about this going on, but he was very big on his FIFA and his FIFA Dream Team mode, you know, whereby, as we’re talking about, you can buy virtual players. And yeah, some of them are very expensive. Yeah, I’ve said that, of course, the the more recognized the player is, the higher his price. But of course then as well, rarity comes into it because the more important he is, the rarer you make him to get. It’s like the trading cards from back in the day. But I digress. So you can turn around and go, “Right, I’ve developed this team, I’ve bought it slowly over the course of 6 months,” because everything’s got a shelf life and for games you’re talking about a year or so. So you’ve got this dream team, it’s worth X amount. Let’s say, in this case I believe the price I was told was that this youngster, Tried to sell it on for £280-£300, somewhere in that region, and the quote-unquote buyer gladly took receipt and he didn’t send any money whatsoever, broke off all contact, completely disappeared off the face of the earth as soon as those things came into his possession. The boy did try to go to EA about it, but the response at that time from EA was, well, you worked outside of our rules and regulations, We can’t help you anymore.

Speaker C: When someone gets ripped off by cybercriminals, they have a right to expect help from the police, perhaps reimbursement from insurance companies, and perhaps some emotional help from the victim support line. But for Gary O’Brien— not his real name— none of that was forthcoming. It all started when he wanted to buy a car online.

Speaker G: Well, I was purchasing a car with my partner and we decided we wanted to get a secondhand car from Europe, from Germany, because we needed a right-hand drive car. So we went on a website called AutoScout24, a bit like AutoTrader in the UK, shopped around for a while, eventually found a couple of cars and then focused in on one. And during the process of negotiating that car We basically got defrauded of our money to buy the car. So how much are we talking about? Was this a small— No, it was significant for us for sure. It was around €10,000 at the end of the day, so just over £8,500.

Speaker C: Right, so yeah, I mean, it’s a lot of money. How did you feel about that when you suddenly realized that you may not get the money?

Speaker G: To be honest, we were having our own difficulties at the time and there was a lot of stuff going on. That was a massive blow to us. You know, it’s not like we had that kind of money floating around, but we needed to get a car to be in Eastern Europe to do some work, and it was just a catastrophic kind of impact when we realized we’d been done. You felt extremely foolish but also angry and then really upset, and then the next steps in terms of trying to work out what you could do about it was was even more kind of just demoralizing and kind of upsetting. So actually when we started investigating, when things started going wrong for us, we could see something like 17 cars on the move which were clearly going nowhere through the same scam. So we felt it was extraordinarily well-structured, organized, and incredibly, it was a big thing and it was massive and it seemed to be going on on a grand scale with very sophisticated effort to make it feel real. Until your money was gone. What happened then? Well, so the first thing which I didn’t realize was you can’t actually report it at a police station. So the first thing, I was turned away and given a phone number, a system called Action Fraud, which said all cyber online crime must be reported to Action Fraud. So I dialed in literally the kind of the hour we found out it was happening. I left work. I ran to a police station. I said, look, this is happening. My partner rang the bank and said, look, can you stop? Can you do something about this? But Action Fraud was a phone line which I rang and I talked to somebody for about 15 minutes. They recorded it, gave me a reference number, and said I could track the case with the reference number. And that was it on day 1. What happened that evening was I just went back into the system and just tried to log in the reference number and it didn’t work. So I waited a day. But effectively I was speaking to nobody other than they said they were recording it and they would send it to the police and then I would hear something back. That was my initial situation with reporting the crime.

Speaker C: And you heard nothing back?

Speaker G: Well, it got kind of on top of all the stress of it happening and trying to get the bank, and the bank wouldn’t talk to us because it was, we paid it into a bank which wasn’t our bank, therefore we couldn’t talk to that bank. We had to talk to the bank where we paid from. But actually, Action Fraud, I tried to use the reference number for a couple of days. It didn’t work. So I rang back the helpline and said, look, this number doesn’t work. I can’t get it to work. I’m sure I wrote it down correctly. I called it out 3 times. To be told that actually I couldn’t be told the reference number because for data protection they couldn’t tell me that they recorded the call. So I then went to the police station who said they can’t talk to me about it either. So I actually ended up in this massive limbo land of wondering if it’s even recorded and what’s going on. When I looked into the details—

Speaker C: You must have felt like pulling your hair out.

Speaker G: You must have been— Well, it was incredible. If someone had taken that kind of money off me on the street, I’d expect a police car to be investigating straight away. You know what I mean? So someone would actually respond. But in this situation, I was told I would have to wait up to 45 days for a response, an acknowledgement that actually this thing had been recorded and anyone was doing anything.

Speaker C: And so of course in that time you’re sitting there thinking that the money is just disappearing down a hole in the internet.

Speaker G: Absolutely, because every minute that went by then you’re thinking, you know, the actual bank account we paid the money, although the transaction was on an EU website, the bank account was in the UK, which is one of the reasons why we thought it was okay to do because it’s going into a UK bank account, there’s all sorts of fraud protection, there’s all sorts of therefore this must be legit and if anything happens we must be able to track it. But it was literally, and they didn’t respond in 45 days, it took over 2 months to get a response and then it was to say that we may not investigate your case. It’s not closed but we haven’t actually decided whether to investigate. We’ve been really busy. I mean it’s astonishing at that stage. We just put it behind us and just said like, there’s probably nothing we can do. Actually, at one stage I went to a police station looking at the live crimes that were still happening to report a fresh crime. I said, look, instead of doing what I did the last time, I’ll just go. I had a live laptop. I could see this guy that had sold the car to this organization actually doing it again, sending a car to Italy. I met police officers in the street and they said, oh look, it’s terrible, but there’s nothing we can do. I was like, you’ve got to be kidding me. In this day and age?

Speaker C: So in fact, you’re actually able to watch all of this, although of course he wasn’t sending the car to Italy, he was pretending he was sending the car to Italy. Um, and, and the police aren’t just—

Speaker G: aren’t looking at it, full stop? As far as I can see. I mean, eventually, I think, like after 2 months, they said, oh, we haven’t closed your case, but we’re extremely busy. I’ve got no response. I have never spoken to a person other than the person who logged the call, who said, I work for an agency for the police, and therefore I’m not the police. We’re not allowed to retain the data, therefore I can’t tell you what your reference number is. I did get an email eventually, but it had no follow-up and it said just continue to email. Now over the period of the couple of weeks, I was building up more evidence about who the person was, where they were, the communications. Both websites that were used to purchase the car, one was AutoScout24, both were legitimate websites. The other one was a company called USHIP. And both of those companies I notified and said, look, this could be part of a criminal investigation. Well, AutoScout didn’t really respond from Germany, but YouShip said they would cooperate. I rang the European Agency for Intranet Trade and they gave me a reference number, at least they gave me a reference number, but actually I had loads of evidence being built up and I had nobody to give it to. Nobody wanted it. I was like, this is incredible. How are they going to investigate something if they don’t actually have the evidence?

Speaker C: Now though, theoretically good news, according to policemen that we’ve spoken to, From January, they’re going to investigate every crime that’s— that they have reported to them. How do you feel about that?

Speaker G: Cybercrime, you know, it’s good. The, the police are going to do stuff. But first of all, I can’t believe they’re only starting now. I mean, crime is crime, whether it’s cybercrime, you know, and any kind of online fraud is still fraud. So I don’t understand why they’re just starting now. And number two, if they’re going to use the Action Fraud line, then I don’t think people are going to have much faith in this. Because I’d love to know the statistics of how many crimes they’ve actually collected and investigated up to now. So yes, it’s great if they invest, they should. I don’t understand, it’s the law, you should investigate crime, that’s why we have a police service. But to stand this up considering everything that they haven’t been able to do up to now, I’d like to see the evidence behind that they actually manned up and powered up to do this.

Speaker C: Especially given the fact that according to the police themselves, and in fact the City of London Police who actually run Actionline, They say that they’ve seen online crime going up 15% year on year since 2015.

Speaker G: Yeah, it’s incredible. The amount of money involved. And to be honest, it’s still a crime. It’s still somebody stealing your money. So it affects people as much as if their house was robbed in a way. I mean, and this was a significant— I mean, online crimes tend to be probably more significant in terms of value. And we tend to trust the internet now. We tend to trust banks. So yes, they should, and yes, I hope they do. And I’d love for somebody to actually tell me what they’re going to do about my case. Because actually what happened, which was potentially, which was, we’d virtually given up. The bank actually recovered most of the money. But we have no evidence as to why they didn’t recover it all, what happened, whether the person who owns the bank account or the company is being held accountable, whether other people have suffered. So absolutely they should investigate all cybercrime, but I’d really be fascinated to know in what way they’re going to do it because under the current system nothing’s getting investigated as far as I can see. So you’ve got most of your money, I mean is it your money they’ve recovered or have they compensated you? Well they said they’ve recovered money from the account transfer so at the time again we struggled with two banks, one that paid out, one that received it and we struggled to get information. They were telling us over the phone that they had done something but it wasn’t quite clear what they’d done, whether the account had been frozen. Eventually they just emailed. The bank’s initial response was, we’ve checked, you authorized the payment, therefore it’s closed. So we were left wondering, well, is that it? We sent the money and they’re not going to do anything. And then it was probably 5 months now, it was literally only recently, a letter came out saying we’ve recovered some of your funds. So it was great because we’d virtually written it off, but at the same time, like all the stress and hassle and uncertainty was just hanging there. And I honestly, I’m afraid to look at that website now again. The YouShip one. I’m afraid to look at it to see if someone else has been scammed because I, I feel there’s nothing that can be done.

Speaker C: O’Brien was a fairly typical victim and, like many, reticent to admit to being a victim because he felt foolish, highlighting another trend: the psychological damage, which is another of the factors that people are beginning to identify that occurs due to cybercrime. Researchers are discovering that cybercrime leaves scars and that people feel targeted, vulnerable, and sometimes paranoid. O’Brien, and indeed all of us, will therefore welcome the news that Britain’s police chiefs are about to change their policy on cybercrime. It’s due to be announced in the new year, but I can tell you that the police plan to promise that every cybercrime that’s reported will be investigated and followed up with a prosecution if there is enough evidence. Detective Superintendent Andrew Gould, National Cybercrime Programme Lead for the National Police Chiefs’ Council, insists that cybercrime is now a top priority for every force across the country, and they are actively identifying young hackers to turn them away from the dark side. And not a moment too soon. Believe it or not, Research into 18,000 millennials by University College London found that 7% of 14-year-olds have admitted to hacking, more than the 3% who had smoked and the 6% who had taken drugs.

Speaker H: To this area of criminality, we’ve been quite fortunate in the last couple of years. Government have actually, whilst other areas of policing have had significant cuts, and admittedly we’re building from a base of almost zero. The government have invested an awful lot of money and effort into helping us build a capability. So by next April, every force in England and Wales will have their own dedicated cybercrime unit dedicated to investigating every, as we would describe it, every cyber-dependent crime that comes into Action Fraud. So your hackings and such like. Every one of those where there’s a viable line of inquiry will actually get an investigation now, whereas before that, outside of the odd force, there was very little happening at all. And every, every single victim, irrespective of whether there are lines of inquiry that are worth investigating, every single victim will get advice to hopefully prevent them becoming victims again. We’re also working with organisations and businesses to help them develop their response plans or normal security policies and business policies so they don’t fall foul of this in the first place, and they can get back to business as usual as quickly as possible if they do fall foul of some kind of incident and attack. And then the fourth area we’re focusing on is around identifying young people that are getting into hacking and going down that road. Actually, when we identify them, do something constructive and meaningful with them to kind of point them down a more positive path, because what we find with a lot of the young people we, we have dealings with through investigations, actually a lot of them don’t even realize that what they’re doing is a criminal offense. Now, those that are kind of doing the frauds and taking money for what they’re doing, that’s a different— you know, clearly they’re criminals that know what they’re doing. But actually, a lot of the young people we find that are hacking and trying to test their skills and getting into places don’t realize often the damage that they do and the harm that they cause, or even that they’re committing a criminal offense and could be criminalized as as a result of it. So we’re starting to put together a more meaningful programme of activity with these young people, with offender workshops and other interventions on the kind of the harder criminal justice side, so they do realise that this activity has consequences. But then on the more positive side, looking at what programmes they can get them into where they can develop their skills if appropriate in a safe space, so we can better understand the potential threat they pose if they continue to go down that road., but it also starts to get them some positive development, training, skills, education, but also potential employment opportunities. So we’re looking at trialling what we call intervention panels in London, probably at the beginning of next year, and if that’s successful, then working with industry partners in the voluntary sector and local authorities, if that’s successful, then we’ll look to start to roll that out across the the rest of the country next year. So we’ll actually have something really meaningful to do with these young people to push them into a better space.

Speaker C: This promise comes not a moment too soon, says Professor Ian Robertson, the Royal Academy of Engineering’s visiting professor of computing at Warwick University. According to him, we are experiencing a cybercrime wave that is so sophisticated that the criminals are even using Facebook to do their homework and research their targets.

Speaker B: Yes, I mean, there are obviously cunning ways, clever ways of combining data so that even if each of the databases you’re referencing is suitably anonymised and protected, that doesn’t necessarily mean that the ensemble of several databases taken together wouldn’t actually reveal more information. In fact, there is a small research project which I know of here on the subject of so-called differential privacy to solve that particular problem, or at least to show the level of confidence that you could get of two databases, for example, still not having enough data to actually distinguish personal information from them. So, you know, it can be done. But the level of sophistication in the law and in compliance and in the degree of determination to actually spend money on these things in companies is not sufficient to drive out the criminal activity. Indeed, the kind of approach which the law and companies take at present is usually to minimise the regret to themselves.. In other words, they say, oh well, we’ll insure against this possibility happening, or we’ll include a kind of a sinking fund to cover the cost of these various activities happening, and we’ll make sure we’ve got the right disclaimers in the small print, we’ll make sure our lawyers have kind of worded things correctly. So in some sense, there’s not a particularly strong incentive there to actually do what normal people would regard as the right thing. I’m thinking in particular of banks where I’ve worked on the compliance questions for know your customer and anti-money laundering. It’s quite clear that one can satisfy the requirements of the compliance statements for the law without actually gaining any particular insight into how to do to deter criminals. It’s unfortunate and it would take a great deal more energy on the legal and legislative side to do it properly. But there ought to be almost a kind of reward for doing it properly rather than just a penalty if you happen to mismanage the compliance organisation. There’s certainly a high profile for the scams which depend on psychology. I think probably people are much more upset when they realize they’ve been fooled into clicking or buying or doing something when they’ve been tricked at a psychological level rather than being exploited at the technical level. In other words, a lot of the data which has somehow been lost— and I’m thinking of the British Airways, Vision Express, Cathay Pacific cases recently— has been lost through technical weaknesses, through so-called skimming attacks. Now these work by— you go to the website, you want to buy something, a plane ticket or an equivalent, and the website sends you back a web page which you see on your screen, which contains the boxes which you fill in and buy your goods. What you don’t realize is that the people hosting the website have been somehow misled into hosting other rogue code on that website, and the code has been downloaded to your particular machine, and on your own home computer, as it were, what you type in is also being directed to some third party who are the criminals, clearly. Now, the person who suffers from that particular exploit, and there are clearly millions of them, and credit card numbers and CVV codes have been routinely stolen over several years by those means. This is a routine skimming attack. So, oh well, I couldn’t do anything about it, it’s a fault in the code, you know, I can try and get my money back from somewhere, but it wasn’t me at fault. Whereas the psychology of the one where you receive the sort of the puppy dog sale at the last moment just before Christmas and you click in the wrong place, you kick yourself and you feel so annoyed that you go out of your way to start actions against almost everybody because you feel partly that somebody else must be responsible even if you were slightly foolish and collaborated with the scam. Particularly if you’re a criminal organization, you can almost protect yourself from being exposed in that way by— and I have seen this kind of exploit done— you not only say, oh well, click here and you can get this special offer, and by the way, don’t worry about the fact that the price has changed, just click here. And someone foolishly clicks there, and the byproduct of that is pornography appears on the screen in front of them, or their disk is encrypted, or some other nasty side effect occurs. And so they then feel even more reluctant maybe to go to the authorities and say, ‘Look, I’ve been conned into wasting my money and I want my money back,’ because they know that in fact the authorities might say, ‘Well, we need copies of the disk,’ or, ‘We need copies of the records. Can you show us what was going on?’ And you can see someone saying, ‘Well, actually I’m not too keen on this because there’s all those pictures which have somehow appeared on my computer, you know, and I don’t know quite how I can protect my reputation. Some of them may in fact have been linked to things which I did myself also. So I’m trying to set up a scenario here where not only does a scam occur, but it’s deliberately designed to be one where the criminal protects themselves.

Speaker C: That’s Professor Ian Robertson, and you’re listening to Password on Resonance FM. After this, you can hear “A World in London” with DJ Ritu. What we’ve heard so far might have you anxiously wondering whether you really should change all your passwords, or you may be feeling smug, safe in the knowledge that you have invested in the best cybersecurity software and updated all your systems regularly. Yet even the strongest cyber guard dogs won’t protect you if you actually open the door, so to speak, to the criminals. Here’s Jano Niemelä, principal researcher in the labs at the Finnish cybersecurity company F-Secure. He’s got an intriguing idea: have a shadow identity for the internet and for the predators trying to zero in on you. Don’t use your date of birth. Or your mother’s maiden name. Use one that you make up and get all of that stuff about you off social media. Boasting about how wealthy you are only attracts criminals and envy.

Speaker E: Because what’s the worst is that some service is asking your mother’s maiden name or your favourite pet. Never ever answer that truthfully. The answer has to be unique for each service And it has to be written down the same, same time when you are writing down your password. And also never ever answer your birth date right on anything else than actual official service. Otherwise lie and write the lie down. So the way to use these services is to be a compulsive but consistent liar when it comes to personal information, which is kind of funny because many times when I’m coming to the the hotel, I noticed that on how many places they are using my birthday information. And that kind of has been becoming me as a marker on just, wait a minute, where did they get that information? And the funniest thing was that the clerk didn’t even bat an eye when according to information, I would have to be over 60 already.

Speaker C: So in a sense, what you’re saying is that you should have a completely different personality for the internet. And in a sense, what you’re saying is that the information that Marriott lost is possibly quite dangerous to people because that has presumably details of lots of people’s real identity because it will have their birth dates and their passports. And lots of other extremely useful personally identifiable information.

Speaker E: Indeed, and that is the thing. And you don’t need to have only separate identity for online services. You need to have multiple identities that would put any person with actual identity problems into shape.

Speaker C: John Niemöller of F-Secure. Other security companies are available of course. Of course. One of them is Kaspersky, where David M is the senior security researcher.

Speaker I: You know, we get a lot of variation. I mean, we’ve got everything from very, very organized accounts targeting, let’s say, financial institutions or the telecoms industry or energy sector. Then we’ve got kind of groups who are focused just on, on kind of stealing data of one kind or another from, from ordinary people. Whether that’s bank information, whether it’s, you know, to do with also ransomware and extorting money. So we get varying degrees of this, but actually it’s not that much to avoid scamming, let’s say Russians as an example, because all you do is you do a check for what the country is looking at the IP address and just exclude them from that particular segment of the internet.

Speaker C: It’s interesting that you say that because lots of people say that all of this is new. People talk about the degree of specialization that there was, or that there is, in computer crime. However, in Victorian London, there was just as much specialization in crime. There would be the people who would be specialist pickpockets, there would be the people who were specialist house burglars. There would be people who would specialize in all different parts of the criminal landscape. So that’s all that we’re really seeing, isn’t it?

Speaker I: I think so. I would agree with that. I mean, what, what we’re seeing is a shift to the online world of all of that stuff. And it— and in some senses, you know, you could say also maybe the skill sets, while very different, yeah, much, much the same. You know, that it’s— you, you would have people who are purely opportunistic. You have people with different skill sets within that. You’ll have whole groups operating. And, you know, you think back to Oliver Twist, for example, in the 19th century, and you’re talking there about a group of people being directed by a few others and, and getting involved in crime. So they’re— you know, you’re right, they’ve always been that, but it’s been a real-world thing rather than an online thing.

Speaker C: Okay, now Finally then, Christmas is coming, the goose is getting fat, and all of that. What are the trends, the particular and specific trends that Kaspersky’s seen seeking to take advantage of Christmas credulity?

Speaker I: Well, I think, I mean, we mentioned some of them, you know, the thing of too-good-to-be-true offers, the fact that they’re just looking to catch people off guard, let’s say by having a lookalike domain name with a zero instead of an O in the URL. They’re using phishing techniques to try and trick people out of personal information and spam campaigns, you know, to kind of deliver out offers to people. So they’re doing all the things that we’ve talked about. I think they’re doing it in big numbers because we’re actually spending online in big numbers now. So I think in terms of the You know, I wouldn’t look at Christmas 2018 and say, you know, we’ve got something that’s strikingly different to 2017. I think we’re looking at pretty much the same kinds of approaches. It’s just, you know, they’re taking advantage of a bigger pot.

Speaker C: Some of the most secure businesses are the banks. At least it’s to be hoped they are secure. Ross Martin, head of educational content at UK bank Barclays, admits that human factors can compromise even the most complex encryption, which is why the bank is putting itself at the forefront of an education and awareness-raising initiative.

Speaker A: Where we’re seeing this criminal activity now taken online, very difficult for the police and any law enforcement to actually pinpoint where some of these crimes are taking place. You know, these people can do a lot of this very unnoticed, and actually there’s a good chance they’re going to get away with it. So for that reason, that reason alone is why we’re seeing an increase in this type of crime, and because people are still falling for the tactics they’re using. And as fast as we can educate people and educate ourselves, actually the techniques, the tactics of the fraudsters are always pretty much, you know, 2, 5 steps ahead. So I think all of us need to do the really simple things, and that’s what Barclays is promoting as part of this campaign. There’s lots of things we can do, really simple, that protect ourselves, and one of those is also using public Wi-Fi to make purchases. Unfortunately, what you find is people are using public Wi-Fi as a convenient way to shop online or actually do lots of activities online without realising the implications of doing that. So that’s one thing we should certainly stop doing. But also, you never give out your PIN or your online banking password. And this can be something that’s easily done through a type of phishing email, or if you receive a bogus call. So you always have to question yourself, what are they asking me to do? What are the implications? And again, take 5 before you act on anything. The simple advice being to take 5 minutes away from that scenario, the phishing email, It could be the malicious phone call or what seems to be a real phone call from your bank or an organisation, or it could be when you receive that text message. So keep an eye on your bank account at this time of year because sometimes you may well have had your details compromised and actually you need to be close to, to your balances and your transactions because you need to be able to report that to your bank as soon as possible. And also the shopping online. One of the key things is, apart from, as I said, around verifying websites that you’re using, is do look out for the padlock symbol in the address bar on the website and make sure it is HTTPS, because this tells you there’s a secure connection between your computer and the website that you’re visiting. We should also not forget attachments in emails as well. You click on an attachment or open an attachment, and that could actually start downloading some form of malicious software. Software. So we should have real caution before we do anything or act on anything in, in those type of emails, especially if you weren’t expecting it.

Speaker C: I think that’s a, that’s a very good point, isn’t it? Because those attachments, clicking on an attachment, the moment that you click on an attachment, you’re telling your computer to do something, and you’re basically telling it to run a piece of software. So if you’ve got an email from someone and you’re not expecting it and they’ve sent you an attachment you should be very, very, very suspicious.

Speaker A: Indeed, indeed. You know, again, the email might be of some form of urgent nature, so before you take that 5 minutes to step away, you might just respond to it because there’s something that you’re being told you need to do, otherwise there’s going to be a consequence if you don’t. And that tactic is very clever in actually catching people because they feel if they don’t act now they’re going to find themselves in an even worse situation or scenario.

Speaker C: One of the things that the criminals do, I mean, to go back to psychology, the other thing that they play upon is that people don’t like being seen to be stupid. So when they actually get caught out, people are very reticent to actually say, no, I lost £2,000 online, no, I lost £5,000 online. Because they don’t want people to think that they are stupid, and the criminals are exploiting that too, aren’t they?

Speaker A: They are indeed. Um, one of the things that we’ve done at Barclays is to really encourage people to come forward when they are the victim of a fraud or scam. And you’re spot on that people are too embarrassed to step forward because for some of these people, they actually may work in jobs where they work with technology, they consider themselves to be tech savvy, and I guess for those people in particular, that’s where there is real embarrassment. But no one should be embarrassed that, you know, the tactics we discussed that these fraudsters and cybercriminals use are so sophisticated that unfortunately there will be people who will potentially get caught out, and they should step forward. And if they are a victim, contact their bank because there’s so much that we can do to support people both in the moment where we might actually stop them losing money, but also what we’re finding with fraud and scams is there’s a real emotional, not just a financial impact, but an emotional impact for people, and actually some of these people really do need the support at that moment. So we’re encouraging people to step forward, however much they may have lost, or they may have just been a, they might have been a very near victim in terms of what’s happened, is to come forward and we can certainly offer support.

Speaker C: As well as thinking that you’re stupid, a lot of people do, as you say, that they feel psychologically hurt in some way and they don’t have anybody to talk to about it. They’re actually sitting there and, and they’re, they’re feeling not just stupid, they’ve lost financially, and, and they’re feeling really hurt.

Speaker A: Yeah, but there’s some very vulnerable people out there, and, and I guess this is the people who can actually be impacted the most. They may not have family around them, they may be of the older generation, so actually I think one of the things we can all do is actually reach out to friends, family, people in our local community to make sure they are being supported, and, and I think we really have to have a proactive approach to this. We can’t be waiting to fall victim, we need to make sure that we are doing everything in our power to to make sure that we are protecting ourselves. But think about those people around you who may not be getting the support they need.

Speaker C: So reach out to those people and make sure that we, we can all protect people. But against this wave of deceit, how can ordinary people hope to keep their accounts safe and do their Christmas shopping online without getting hacked, pawned, or robbed? Researchers have found that there are only 7 types of online fraud. As Barclays’ Ross Martin says, don’t respond instantly. Take some time out, make a cup of tea before you click on that email, click on that website, make that decision. As Michael Winner used to say, calm down. It’s advice that Max Bruce, the Cyber Protect Officer of the City of London Police, endorses.

Speaker J: We certainly see the common brands that will always come up, things like computers, so laptops, etc. Those will always be very, very popular, which, you know, it may be a bit older, shall we say, than the toys, but obviously we’ll always see brands and games within games consoles may be a popular sale at this time. But again, these things will change each year about the must-have toys. The criminals will always make sure that they are on trend with whatever they’re offering as well. You know, they won’t be trying to sell something that nobody wants. They’ll always have that thing that’s probably going to be sort of stock limited, and they’re very good at that.

Speaker C: It’s interesting because one other example that we’ve found is of criminals moving into computer games and setting up frauds for computer game skins, allegedly buying somebody’s skins or things from them and then defrauding them of those. Again, it’s very, very interesting that the criminality is now across the board, and it’s anything that involves technology and communication.

Speaker J: Yeah, so I mean, online gaming is something that is becoming more, more and more sort of common, and it is something that we do see reported to us. So the popular game Fortnite, For example, people are trying to get the V-Bucks, which allows them to sort of upgrade their characters, as you mentioned. So again, this is something that, you know, criminals will try and exploit, where they may try and ask, you know, try and offer you free credits or something like that if you give them some— you sign in and give some personal details, or you give them your mobile phone number, say, and then verify some sort of requests that come through, when obviously actually what they’ve really done is just used your number to benefit their own account, and then the charges will come back to you. So they are trying to exploit those things. So again, it’s about thinking, who are you talking to online? Who, who, who’s offering you this? Is this normally how you would get those, you know, V-Bucks or the online gaming currencies that, you know, for whatever game you’re playing? And actually thinking, is this, is this the best way to do it?

Speaker C: One of the trends that we’ve picked up in doing the research for this program. We’ve been told that there is a movement from street crime now into cybercrime, that there is a recognition among what I suppose used to be called petty criminals that it makes much more sense for them to be involved in cybercrime, and that it’s easier and it involves less effort. They don’t have necessarily have to get wet. They, you know, don’t have to go out and break something, or they don’t have to move some physical object to get their return. Is that something that you’re seeing?

Speaker J: Well, I mean, cybercrime and fraud is, is, you know, is a huge, huge issue within crime figures now, and it’s probably about 50% of all crime within the UK. Um, so it’s clearly— we are seeing that movement from sort of traditional crimes towards cybercrime because— and it does it is easier, shall we say. There’s, there’s not that sort of geographical location now as a, as a criminal if you’re using online. You’re also a lot more—

Speaker E: you’re—

Speaker J: the anonymity of it, and you’re— you can be anonymous, and the way you can hide your identity so you don’t have to go outside, you don’t run the risks of being seen as much. And also the way, you know, things like cryptocurrencies is— way allows you to move money easier. So yeah, it is, it is becoming more common, and we are getting more and more reports around fraud and cybercrime. And it’s something that we, you know, is likely to grow. So yeah, no, we, like I say, we are seeing that change, and there are a lot of reasons for that. But again, as an individual, to try and protect ourselves, it’s really important that we do those basic things. We look after our online accounts, we use strong separate passwords for things like our email, which is on most important account. You know, we have those good passwords, we update our operating systems, you know, we update the apps and the software that we use. We keep that up to date because every time those patches come out, they contain really good sort of bug fixes. We make sure we use those.

Speaker A: We—

Speaker J: and all those sorts of things. And like I talked about in terms of taking your time when you get those requests and you don’t suddenly click on links from unsolicited communications, they’re all really simple things that we can do to help prevent us falling victim to cybercriminals.

Speaker C: That’s all from this edition of Password. It was produced by Blue Buffery with help from Sid the Guard Dog and written by Jane Wyatt. I’m Peter Warren, and you can find me at the Future Intelligence website or on Twitter, LinkedIn, and Facebook. But please don’t log into all of them with the same password. I shall feel like I’ve been talking to the wall for the past hour. If you need help to stay safe online, you can check out our cybersecurity website at www.csri.info. And there’s some great advice at victimsupport.org too. Thanks for listening and happy holidays.

Speaker A: This program has been brought to you by Resonance 104.4 FM.

Speaker B: If you liked what you heard and want to support our work, please make a donation at fundraiser.resonance.fm.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00