Latest news
Reports that a Russian hacker has pleaded guilty of ripping off WorldPay, the online transaction processor, to the tune of $10 million, have met with a grim smile by Lieberman Software.According to Phil Lieberman, the methodology used by the 27-year-old hacker is a potential worst-case scenario that he and his team warn potential and existing clients about.
Not only did this guy manage to hack into WorldPay's systems back in 2008, but he then altered the parameters of the merchant accounts and boosted their online daily limits. From there he withdrew large amounts of cash from ATMs as he traveled the world.
"The case is a fascinating one as, by pleading guilty, it's unlikely we'll ever find out how this team of hackers managed to stiff the former RBS card processing division for an incredibly large sum of money," Lieberman said.
When you think about it, the only way that Yevgeny Anikin could have increased the withdrawal limits on the merchant accounts was by gaining access to an internal management account with the card processor.
The whole affair smacks of a lack of security on privileged accounts, which is an area of security in which we specialize.
As with all major card frauds of this type, however, this case involves the hacker ringleader pleading guilty, thereby preventing the actual processes used by the fraudsters(s) being revealed in an open court.
"We've been through our fraud records and are finding it difficult to come up with a major card fraud case involving hacking where the fraudster(s) have pleaded not guilty, and the case has gone to court," he said, adding that time after time, the fraudsters mysteriously plead guilty, are sentenced and the financial institution gets away without revealing the chinks in their electronic armor.
What are the possibilities of that happening?
"Quite low, actually, especially when you realize that this case was heard in a Siberian court, in a country where all sorts of unusual results come out of the courts, such as political rivals of President Putin mysteriously being incarcerated for years on end," he said.
"The bottom line is that you don't have to be conspiracy theorist to piece together what is happening: the card processing system is far from being infallible, and the banks are going to great lengths to avoid exposing how insecure their systems really are in an open court," he added.
"Of course, if I'm wrong, I'll be perfectly happy to discuss this issue with WorldPay or any other financial institution whose systems have been hacked and defrauded - and where the criminals have pleaded not guilty."


Spotlight

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Is Microsoft is reading your Skype communications?
Posted on 15 May 2013. | The question of whether Skype allows U.S. intelligence and law enforcement agencies to access the communications exchanged by its users has still not been adequately answered by Microsoft.

Internet Explorer best at blocking malware
Posted on 14 May 2013. | While Chrome’s malware download protection improved significantly, Internet Explorer 10 continues to outperform the other browsers with a block rate of 99.96%.

Researcher refuses to help Saudi telco to spy on people
Posted on 14 May 2013. | You would think that a Saudi Arabian telecom firm interested in monitoring its users' mobile communications would not be asking a well-known pro-privacy researcher for help, but you would be wrong.

Malicious browser extensions are hijacking Facebook accounts
Posted on 13 May 2013. | Facebook users - especially those in Brazil - are being targeted with malicious browser extensions trying to hijack Facebook profiles, warns Microsoft.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





