The State of Information Security Sucks

Robert Siciliano Identity Theft Expert
The sheer volume of potential targets coupled with the vast amounts of money to be made has captured the attention of the global criminal hacking community.
Enterprise networks are becoming hardened and they are still vulnerable. Some are being penetrated directly while others are accessed through 3rd parities such as their clients [...]



 Fostering Awareness & Improving Security Education

Robert Siciliano Identity Theft Expert
Financial institutions have the most to lose and the most to gain by improving security education of their clients and employees.
A while back I appeared on a local TV show talking about phishing. Amazingly, still, not everyone knows what phishing is. A good friend saw the show and was shocked [...]



 Diploma Mills Facilitate Identity Theft

Robert Siciliano Identity Theft Expert
Diploma mills were born along with elearning institutions who are actually legitimate and accredited bodies. Degrees and diplomas issued by diploma mills are frequently used for fraudulent purposes, such as obtaining employment, promotions, raises, or bonuses on false pretenses. They can also be used as a form of fake ID when [...]



 mCrimes Morph Into mBotnets

Robert Siciliano Identity Theft Expert
Botnets are robot networks of computers connected to the Internet that sit in our homes and offices. A botnet is generally banks of multiple PC’s from the 10’s to 10,000’s to millions. There are no hard numbers on botnets but last figure I saw was somewhere between 3-5 million. Another stat [...]



 EFT Point of Sales Hackers Net $50 Million

Robert Siciliano Identity Theft Expert
Readers of these posts are familiar with ATM skimming. ATM skimming is a billion dollar problem and growing. A relatively new scam over the past few years is electronic funds transfers at the point of sale (EFTPOS ) skimming. People commonly swipe both credit and debit cards through the in-store machines [...]



 Citizens Need to be More Involved in Cybersecurity

Robert Siciliano Identity Theft Expert
In the University of Cincinnati’s Journal of Homeland Security and Emergency Management, the authors write “The general population must be engaged as active security providers, not simply beneficiaries of security policy, because their practices often create the threats to which government responds.” Somebody is saying to take personal responsibility and start [...]



 Targeted Injection Attacks on the Rise

Robert Siciliano Identity Theft Expert
In the latter half of 2009, criminal hackers went from mass SQL injection campaigns to targeted attacks. SQL is abbreviation of Structured Query Language. Pronounced ”Ess Que El” or ”Sequel”. The attackers shift in strategy focused on targeting high-profile websites, concluded Websense’s State of Internet Security report for the third [...]



 3 Nabbed in Massachusetts ATM Skimming Ring

Robert Siciliano Identity Theft Expert
Police believe they may have uncovered an international ATM “skimming” ring responsible for stealing money from hundreds of local accounts. Izaylo Hristov, 28, of Ontario, Canada, a Bulgarian citizen, was arrested at an ATM in the Boston area along with Viadiclav Vladevo and Anton Venkov. Venkov had $99,100 in $20 bills [...]



 Crimeware: Do It Yourself Criminal Hacking

Robert Siciliano Identity Theft Expert
For $400-$700 you too can be a criminal hacker. Phishing hacking and spoofing software has been around for a few years. Heres what may be an example.
The ease and availability of this good for nothing other than crime software has made it easier, cheaper and more user friendly than ever to [...]



 Meet Raoul Chiesa: UN Interregional Crime & Justice Research Inst.

Robert Siciliano Identity Theft Expert
In my quest to learn more about what makes a criminal hacker tick, I came across Mr Chiesa when he commented on a blog post I wrote “How I Wasted 4 Hours with a Criminal Hacker”. He warned me I was treading on dangerous ground due to the fact that when [...]