Thursday, 26 September 2013

Barclays employee fined £3,360 for illegally accessing customer data

barclays87
A former employee of Barclays Bank has been fined £3,360 after being found guilty of illegally accessing a customer’s data.
Jennifer Addo was sentenced at Croydon Magistrates Court and prosecuted under section 55 of the Data Protection Act (DPA). The court ordered her to pay a fine of £2,990 for 23 offences, £250 prosecution costs and a £120 victim surcharge.
The case came to light when a customer of the bank was concerned someone had accessed his information to gather details on his children, which was then passed to his partner at the time.
The customer informed the bank of his concerns and it then investigated the incident. Barclays found that Addo had illegally accessed the customer’s details on 22 occasions between 10 May 2011 and 8 August 2011. Her employment with Barclays ended soon after the complaint was raised.
The case again highlights the lack of real enforcement powers that exist with section 55 offences under the DPA, a point repeatedly made by the Information Commissioner’s Office (ICO).
ICO head of enforcement, Stephen Eckersley, reiterated this after the ruling. "This case proves, yet again, why we need a more appropriate penalty for the crime of personal data theft,” he said.
“With the law as it stands, this prosecution isn’t even recorded on the police national computer, which means that an offender could apply for a job in a high street bank tomorrow and the potential employer wouldn’t be informed about the offence. The current 'fine only' regime is clearly not deterring people from breaking the law.”
Eckersley also noted how hard it is for firms such as Barclays to fully ensure data is protected when its is abused by staff in this manner.
“The banking industry has rigorous procedures and safeguards in place to make sure customers’ details are kept secure. However banks rely on the honesty and professionalism of their staff to ensure that the privileged access given to their records is not abused for personal gain."
The ICO has been pushing for stronger sentencing for some time, with the Ministry of Justice said to be looking into the situation.

Wednesday, 25 September 2013

Newly launched E-shop offers access to hundreds of thousands of compromised accounts

In a series of blog poststhe ongoing commoditization of hacked/compromised/stolen account data (user names and passwords) have been highlighted , the direct result of today’s efficiency-oriented cybercrime ecosystem, the increasing availability of sophisticated commercial/leaked DIY undetectable malware generating tools, malware-infected hosts as a service, log files on demand services, as well as basic data mining concepts applied on behalf of the operator of a particular botnet. What are cybercriminals up to these days in terms of obtaining such type of data? Monetization through penetration pricing on their way to achieve stolen asset liquidity, so hosts can be sold before its owner becomes aware of the compromise, thereby diminishing its value to zero.
A newly launched E-shop is currently offering access to hundreds of thousands of compromised legitimate Mail.ru, Yahoo, Instagram, PayPal, Twitter, Livejournal, Origin, Skype, Steam, Facebook, and WordPress accounts, as well as 98,000 accounts at corporate SMTP servers, potentially setting up the foundation for successful spear-phishing campaigns.

Sample screenshot of the inventory of the service:
EShop_Hacked_Compromised_Accounts_Sale_Sell_Buy_Purchase_Cybercrime The prices are as follows:
  • 50, 000 hacked/compromised accounts go for $10
  • 100,000 hacked/compromised accounts go for $15
  • 500,000 hacked/compromised accounts go for $45
  • 1,000,000 hacked/compromised accounts go for $80
The service is also offering a discount for orders beyond 3,000,000 hacked/compromised accounts, which in this case are offered for $70 for “every other million”. This underground market proposition is a great example of several rather prolific ‘common sense’ monetization tactics applied by a decent percentage of cybercriminals who are attempting to monetize their fraudulently obtained assets:
  • Penetration pricing – penetration pricing is a common pricing technique aimed at quickly gaining market share, and in this particular case, efficiently supplying the stolen assets to potential customers. What’s also worth emphasizing on is that on the majority of occasions, the cybercriminal will automatically ‘break-even’ even if he’s actually invested hard cash into the process of obtaining the hacked/compromised accounting data at a later stage
  • Timeliness of a stolen asset in terms of achieving asset liquidity – whether it’s due to the (perceived) oversupply of a particular commoditized underground market item — like for instance compromised accounting data — or the plain simple logic that the fact that it’s been stolen will sooner or later come to the attention of its owner, cybercriminals are no strangers to the concept of achieving financial asset liquidity, and would do their best to reach out to potential customers as quickly as possible
We expect to continue witnessing the commoditization of hacked/stolen accounting data, with more similar propositions eventually popping up on our radars.