Showing posts with label biggest. Show all posts
Showing posts with label biggest. Show all posts

Saturday, 27 July 2013

U.S. indicts hackers in biggest cyber fraud case in history

By David Jones and Jim Finkle

NEWARK, N.J./BOSTON | Thu Jul 25, 2013 6:02pm EDT

NEWARK, N.J./BOSTON (Reuters) - Federal prosecutors said on Thursday they have charged five men responsible for a hacking and credit card fraud spree that cost companies more $300 million and two of the suspects are in custody, in the biggest cyber crime case filed in U.S. history.

They also disclosed a new security breach against Nasdaq, though they provided few details about the attack.

Other companies targeted by the hackers include a Visa Inc licensee, J.C. Penney Co, JetBlue Airways Corp and French retailer Carrefour SA, according to an indictment unveiled in New Jersey.

Authorities have been pursuing the hackers for years. Many of the breaches were previously reported, though it appeared the one involving Nasdaq OMX Group Inc was being disclosed for the first time.

Prosecutors said they conservatively estimate that the group of five men from Russia and Ukraine helped steal at least 160 million payment card numbers, resulting in losses in excess of $300 million.

Authorities in New Jersey charged that each of the defendants had specialized tasks: Russians Vladimir Drinkman, 32, and Alexandr Kalinin, 26, hacked into networks, while Roman Kotov, 32, mined them for data. They allegedly hid their activities using anonymous web-hosting services provided by Mikhail Rytikov, 26, of Ukraine.

Russian Dmitriy Smilianets, 29, is accused of selling the stolen data and distributing the profits. Prosecutors said he charged $10 for U.S. cards, $15 for ones from Canada and $50 for European cards, which are more expensive because they have computer chips that make them more secure.

The five hid their efforts by disabling anti-virus software of their victims and storing data on multiple hacking platforms, prosecutors said. They sold payment card numbers to resellers, who then sold them on online forums or to "cashers" who encode the numbers onto blank plastic cards.

"This type of crime is the cutting edge," said New Jersey U.S. Attorney Paul J. Fishman. "Those who have the expertise and the inclination to break into our computer networks threaten our economic wellbeing, our privacy and our national security."

The indictment cited Albert Gonzalez as a co-conspirator. He is already serving 20 years in prison after pleading guilty to helping mastermind one of the biggest hacking fraud schemes in U.S. history, helping steal millions of credit and debit cards.

Prosecutors say the defendants worked with Gonzalez before his arrest in Miami, then continued on a crime spree after his capture.

Drinkman and Smilianets were arrested in June 2012, while traveling in the Netherlands, at the request of U.S. authorities. Smilianets was extradited last September and is expected to appear in New Jersey Federal court next week. Drinkman is awaiting an extradition hearing in the Netherlands.

Prosecutors declined comment on the whereabouts of the other three defendants.

Tom Kellermann, a vice president with security software maker Trend Micro, said he thinks the prospects are dim that they will be caught because authorities in some countries turn a blind eye to cyber criminals.

"There is an enormous shadow economy that exists in Eastern Europe. In some countries, sophisticated hackers are seen as national assets," he said.

Kalinin and Drinkman were previously charged in New Jersey as "Hacker 1" and "Hacker 2" in a 2009 indictment charging Gonzalez in connection with five breaches.

NASDAQ BREACH

The U.S. Attorney's Office in Manhattan announced two other indictments against Kalinin, one charging he hacked servers used by Nasdaq from November 2008 through October 2010. It said he installed malicious software that enabled him and others to execute commands to delete, change or steal data.

The infected servers did not include the trading platform that allows Nasdaq customers to buy and sell securities, prosecutors said. Officials with Nasdaq said they could not immediately comment.

A source with knowledge of the breach said on Thursday the indictment was not related to a 2010 attack that Nasdaq had previously disclosed, which was targeted against Directors Desk, a service used by corporate boards to share documents and communicate with executives, among other things.

The source, who asked to remain anonymous due to the sensitivity of the matter, said that hackers appear to have used their access to the firm's network to create their own landing page on a Nasdaq website, where users were directed when they wanted to change their passwords.

The second indictment filed against Kalinin in Manhattan, which was unsealed on Thursday, charged that he worked with a sixth hacker, Russian Nikolay Nasenkov, 31, to steal bank account information from thousands of customers at Citibank and PNC Bank from 2005 to 2008, resulting in the theft of millions of dollars.

MAKING PROGRESS

Mark Rasch, a former federal cyber crimes prosecutor, told Reuters that the arrests show that law enforcement is making progress in identifying those responsible for major cyber crimes.

"They involve dozens or even hundreds of people huddled over computer terminals all over the world in a common purpose of stealing of disseminating credit card numbers," said Rasch, who was not involved in bringing the case.

Among the breaches cited in the New Jersey indictment, prosecutors charged that the group was responsible for the theft of more than 130 million credit card numbers from U.S. payment processor Heartland Payment Systems Inc beginning in December 2007, resulting in approximately $200 million of losses. That was the same case for which Gonzalez was convicted and which was the largest case of its kind before the latest indictments.

Heartland released a statement praising authorities for their work: "We hope that this indictment further delivers the message that prolific hacking organizations worldwide will be pursued and charged for crimes such as this one."

The indictment charged that they took approximately 30 million payment card numbers from British payment processor Commidea Ltd in 2008 and 800,000 card numbers from Visa Inc's licensee Visa Jordan in 2011.

An attack on Global Payment Systems that begin in about January 2011 resulted in the theft of more than 950,000 cards and losses of about $93 million, according to the indictment.

It charged the ring with stealing approximately 2 million credit card numbers from French retailer Carrefour SA, beginning as early as October 2007 and said the theft of card numbers from Dexia Bank Belgium resulted in $1.7 million in losses.

Other victims included Dow Jones, Wet Seal Inc and 7-Eleven Inc, according to prosecutors.

Dow Jones said in a statement that there was "no evidence" that information of Dow Jones or Wall Street Journal customers information was compromised as a result of the breaches.

Officials with Carrefour, Global Payments and JCPenney declined comment.

(Reporting by David Jones and Jim Finkle; Additional reporting by John McCrank, Christian Plumb, Phil Wahba, Beth Pinsker, Varun Aggarwal, Jennifer Saba, Beth Gladstone, Aman Shah and David French; Writing by Jim Finkle; Editing by Scott Malone, Alden Bentley and Claudia Parsons)


View the original article here

U.S. indicts hackers in biggest cyber fraud case in history

By David Jones and Jim Finkle

NEWARK, N.J./BOSTON | Thu Jul 25, 2013 6:02pm EDT

NEWARK, N.J./BOSTON (Reuters) - Federal prosecutors said on Thursday they have charged five men responsible for a hacking and credit card fraud spree that cost companies more $300 million and two of the suspects are in custody, in the biggest cyber crime case filed in U.S. history.

They also disclosed a new security breach against Nasdaq, though they provided few details about the attack.

Other companies targeted by the hackers include a Visa Inc licensee, J.C. Penney Co, JetBlue Airways Corp and French retailer Carrefour SA, according to an indictment unveiled in New Jersey.

Authorities have been pursuing the hackers for years. Many of the breaches were previously reported, though it appeared the one involving Nasdaq OMX Group Inc was being disclosed for the first time.

Prosecutors said they conservatively estimate that the group of five men from Russia and Ukraine helped steal at least 160 million payment card numbers, resulting in losses in excess of $300 million.

Authorities in New Jersey charged that each of the defendants had specialized tasks: Russians Vladimir Drinkman, 32, and Alexandr Kalinin, 26, hacked into networks, while Roman Kotov, 32, mined them for data. They allegedly hid their activities using anonymous web-hosting services provided by Mikhail Rytikov, 26, of Ukraine.

Russian Dmitriy Smilianets, 29, is accused of selling the stolen data and distributing the profits. Prosecutors said he charged $10 for U.S. cards, $15 for ones from Canada and $50 for European cards, which are more expensive because they have computer chips that make them more secure.

The five hid their efforts by disabling anti-virus software of their victims and storing data on multiple hacking platforms, prosecutors said. They sold payment card numbers to resellers, who then sold them on online forums or to "cashers" who encode the numbers onto blank plastic cards.

"This type of crime is the cutting edge," said New Jersey U.S. Attorney Paul J. Fishman. "Those who have the expertise and the inclination to break into our computer networks threaten our economic wellbeing, our privacy and our national security."

The indictment cited Albert Gonzalez as a co-conspirator. He is already serving 20 years in prison after pleading guilty to helping mastermind one of the biggest hacking fraud schemes in U.S. history, helping steal millions of credit and debit cards.

Prosecutors say the defendants worked with Gonzalez before his arrest in Miami, then continued on a crime spree after his capture.

Drinkman and Smilianets were arrested in June 2012, while traveling in the Netherlands, at the request of U.S. authorities. Smilianets was extradited last September and is expected to appear in New Jersey Federal court next week. Drinkman is awaiting an extradition hearing in the Netherlands.

Prosecutors declined comment on the whereabouts of the other three defendants.

Tom Kellermann, a vice president with security software maker Trend Micro, said he thinks the prospects are dim that they will be caught because authorities in some countries turn a blind eye to cyber criminals.

"There is an enormous shadow economy that exists in Eastern Europe. In some countries, sophisticated hackers are seen as national assets," he said.

Kalinin and Drinkman were previously charged in New Jersey as "Hacker 1" and "Hacker 2" in a 2009 indictment charging Gonzalez in connection with five breaches.

NASDAQ BREACH

The U.S. Attorney's Office in Manhattan announced two other indictments against Kalinin, one charging he hacked servers used by Nasdaq from November 2008 through October 2010. It said he installed malicious software that enabled him and others to execute commands to delete, change or steal data.

The infected servers did not include the trading platform that allows Nasdaq customers to buy and sell securities, prosecutors said. Officials with Nasdaq said they could not immediately comment.

A source with knowledge of the breach said on Thursday the indictment was not related to a 2010 attack that Nasdaq had previously disclosed, which was targeted against Directors Desk, a service used by corporate boards to share documents and communicate with executives, among other things.

The source, who asked to remain anonymous due to the sensitivity of the matter, said that hackers appear to have used their access to the firm's network to create their own landing page on a Nasdaq website, where users were directed when they wanted to change their passwords.

The second indictment filed against Kalinin in Manhattan, which was unsealed on Thursday, charged that he worked with a sixth hacker, Russian Nikolay Nasenkov, 31, to steal bank account information from thousands of customers at Citibank and PNC Bank from 2005 to 2008, resulting in the theft of millions of dollars.

MAKING PROGRESS

Mark Rasch, a former federal cyber crimes prosecutor, told Reuters that the arrests show that law enforcement is making progress in identifying those responsible for major cyber crimes.

"They involve dozens or even hundreds of people huddled over computer terminals all over the world in a common purpose of stealing of disseminating credit card numbers," said Rasch, who was not involved in bringing the case.

Among the breaches cited in the New Jersey indictment, prosecutors charged that the group was responsible for the theft of more than 130 million credit card numbers from U.S. payment processor Heartland Payment Systems Inc beginning in December 2007, resulting in approximately $200 million of losses. That was the same case for which Gonzalez was convicted and which was the largest case of its kind before the latest indictments.

Heartland released a statement praising authorities for their work: "We hope that this indictment further delivers the message that prolific hacking organizations worldwide will be pursued and charged for crimes such as this one."

The indictment charged that they took approximately 30 million payment card numbers from British payment processor Commidea Ltd in 2008 and 800,000 card numbers from Visa Inc's licensee Visa Jordan in 2011.

An attack on Global Payment Systems that begin in about January 2011 resulted in the theft of more than 950,000 cards and losses of about $93 million, according to the indictment.

It charged the ring with stealing approximately 2 million credit card numbers from French retailer Carrefour SA, beginning as early as October 2007 and said the theft of card numbers from Dexia Bank Belgium resulted in $1.7 million in losses.

Other victims included Dow Jones, Wet Seal Inc and 7-Eleven Inc, according to prosecutors.

Dow Jones said in a statement that there was "no evidence" that information of Dow Jones or Wall Street Journal customers information was compromised as a result of the breaches.

Officials with Carrefour, Global Payments and JCPenney declined comment.

(Reporting by David Jones and Jim Finkle; Additional reporting by John McCrank, Christian Plumb, Phil Wahba, Beth Pinsker, Varun Aggarwal, Jennifer Saba, Beth Gladstone, Aman Shah and David French; Writing by Jim Finkle; Editing by Scott Malone, Alden Bentley and Claudia Parsons)


View the original article here

EU, China resolve solar dispute - their biggest trade row by far

By Robin Emmott and Ben Blanchard

BRUSSELS/BEIJING (Reuters) - China and the European Union defused their biggest trade dispute by far on Saturday with a deal to regulate Chinese solar panel imports and avoid a wider war in goods from wine to steel.

After six weeks of talks, the EU's trade chief and his Chinese counterpart sealed the deal over the telephone, setting a minimum price for panels from China near spot market prices.

European solar panel makers accuse China of benefitting from huge state subsidies, allowing them to dump about 21 billion euros ($28 billion) worth of below-cost solar panels in Europe last year, putting European firms out of business.

Other European industries that have accused China of dumping have faced imports of about 1 billion euros a year.

Europe planned to impose hefty tariffs from August 6 but, wary of offending China's leaders and losing business in the world's No. 2 economy, a majority of EU governments - led by Germany - opposed the plan, which led to the compromise deal.

"We found an amicable solution," EU Trade Commissioner Karel De Gucht said. "I am satisfied with the offer of a price undertaking submitted by China's solar panel exporters," he said, referring to the minimum price for China's imports.

Chinese Commerce Ministry Spokesman Shen Danyang welcomed the deal, hailing a "positive and highly constructive outcome".

An EU diplomatic source said that in the solar agreement, the agreed price was 0.56 euro cents per watt, near the spot price for Chinese solar panels in July in Europe, according to solar exchange pvXchange.

Under the terms of the deal, China will also be allowed to meet about half Europe's solar panel demand, if taken at last year's levels. EU consumption was about 15 gigawatts in 2012, and China will be able to provide 7 gigawatts without being subject to tariffs under the deal, the EU source said.

COURT CHALLENGE

That did not satisfy some EU solar manufacturers who said the minimum import price agreed still constitutes dumping and accused the European Commission of breaking EU law by failing to protect European industry.

European solar panel manufacturer association EU ProSun said it will go to the European Court of Justice in Luxembourg to challenge the deal.

"Even the biggest EU trade conflict ever must still be resolved on the basis of the applicable law," said EU ProSun's president, Milan Nitzschke.

However, China has sold solar panels for as little as 0.38 cents a watt, according to the European Commission, which handles trade issues for EU states, and tariffs would also hurt EU panel installers, who benefit from cheaper Chinese panels.

Chinese manufacturers such as U.S.-listed Trina Solar , Yingli Green Energy and Suntech Power Holdings are among those exporting to Europe.

Chinese solar panel production quadrupled between 2009 and 2011 to more than the world's entire demand as it took advantage of a growing market for renewable energy in the face of concerns about climate change.

But the global financial crisis and ensuing euro zone crisis have forced European governments to withdraw generous subsidies for solar energy. That, along with Chinese imports pushing down prices, have sent many European solar companies into bankruptcy.

German group Conergy filed for insolvency this month.

Still, those concerns have become secondary to the much larger EU-China trade relationship at stake over the panels dispute.

Europe is China's most important trading partner, while for the EU, China is second only to the United States. Chinese exports of goods to the bloc totaled 290 billion euros last year, with 144 billion going the other way.

Responding to the EU's move to impose duties, China launched an anti-dumping inquiry into European wine sales, which may have led to exporters in France, as well as Spain and Italy, being hit with retaliatory duties.

EU and Chinese diplomats now expect that case to be dropped as a goodwill gesture, although officials declined to comment on Saturday.

(Additional reporting by Martin Santa in Brussels; Editing by Louise Ireland)


View the original article here