Cyber Crime on a Global Scale

ScaleOfCyberCrime.jpg

Cyber bad guys operate at all levels, from intercepting your car's bluetooth, to using apps and the Internet to steal private financial details of tens of millions of citizens.
Even a single person can create cybercrime mayhem.
In April 2015, Navinder Singh Sarao, a 36-year-old, appeared in court in the UK wearing baggy sweatpants, running shoes and a hoodie. This small-time investor drove a broken-down car, and lived in his parents' run-down flat near the flight path of Heathrow airport. But back on 6th May 2010, he had used off-the-shelf software to manipulate high-frequency trading algorithms to create the infamous 'flash crash'.
He sent the Dow Jones industrial average on a wild ride up and down some 1000 points. He briefly wiped over $1 trillion from the stock markets. To put that in perspective, that's about 1/60 of the gross domestic product of the entire planet, for a whole year. And along the way, using techniques called 'spoofing' and 'layering', he picked up $40 million, all done using a simple home computer.
Given it's that easy for one person to create havoc, think how much easier it would be for a government with all of its resources. People talk about 'cyber warfare', but it is a fairly vague term, referring to governments attacking other governments. Specifically, what happens when governments use the internet for sabotage, espionage and subversion.
Financial markets, military assets, communication networks, infrastructure of many types, if it's got a computer, it can be hacked.
In September 2010, the nuclear enrichment facilities in Iran were attacked by the Stuxnet-worm.
The Iranians were purifying uranium up to weapons-grade using centrifuges. These centrifuges were taken over by this worm. They spun so quickly they destroyed themselves. But while the attack was actually happening, the control panels of the Iranian operators wrongly indicated that the centrifuges were spinning normally.
This attack delayed the Iranian weapons-grade uranium program by over a year. Who did this? In June 2012, the New York Times claimed that President Obama had authorised this sabotage.
A modern country relies absolutely on infrastructure — sewerage, transport, drinking water, power, and so on. In 2009, President Obama said: "cyber intruders have probed our electrical grids".
Then, in 2012, an American company that monitors over 50 per cent of the gas and oil pipelines in the USA discovered that the Chinese had hacked its computer systems.
Were the Chinese simply looking for industrial secrets? Or were they planting bugs, so that they could shut down the US energy grid if China and the USA were to have a conflict sometime in the future?

In 2012, Iranian hackers took control of 30,000 computers belonging to the world's largest oil producer, Saudi Aramco. We know they changed the Aramco logo to a burning US flag. But what else did they do?

In March 2013, the major banks and broadcasting TV stations in South Korea were hacked. Was North Korea to blame, or was it somebody pretending to be North Korea?
In the Middle East, the Syrian Electronic Army hacked into the Twitter account of Associated Press. They then published a fake news item about a bomb at the US White House. That incident alone sucked $136 billion out of the US Equity Market.
One of the beauties of cyber warfare is its anonymity. While there are suspects, there is often still not enough information to positively identify the culprits.
Cyber warfare can also be done relatively cheaply. But of course, you get better results if you spend more.
In May 2010, the four-star general, Keith Alexander, was put in charge of the newly formed US Cyber Command. By 2014, its budget had jumped from $1 billion to $4.7 billion. They claim they need this money to deal with incessant attacks from other governments.
As part of their recruitment, the US Defense Department has annual competitions with cyber warriors running banks of military computers. Each team typically has to protect five computers (which are running seven different operating systems) against relentless waves of ever-sophisticated cyber attacks. 
China and many other countries are doing the same. After all, since time immemorial, teenagers have been given weapons and told to fight. Apparently this is the 21st-century version.
Ein News:  http://bit.ly/1Llc8Bs

 

« FBI Director says ISIS Could Cyberattack the US
Silicon Valley a Major Player in Cyberwarfare »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

TBG Security

TBG Security

TBG provides a portfolio of services including cyber security, compliance and continuity solutions.

FlashRouters

FlashRouters

FlashRouters offers DD-WRT compatible router models with improved performance, privacy/security options, and advanced functionality.

Atea

Atea

Atea is the market leader in IT infrastructure for businesses and public-sector organizations in Europe’s Nordic and Baltic regions.

BitSight Technologies

BitSight Technologies

BitSight transforms how companies manage information security risk with objective, verifiable and actionable Security Ratings.

ID Experts

ID Experts

ID Experts is a leading provider of identity protection and data breach services for companies and individuals throughout the USA.

Oxford BioChronometrics

Oxford BioChronometrics

By building profiles based on electronically Defined Natural Attributes, or e-DNA, Oxford BioChronometrics protects digital networks, communities, individuals and other online assets from fraud.

Berwick Partners

Berwick Partners

Berwick Partners’ Cyber Security Practice is a leading recruiter of senior management positions in this field; we have an exceptional understanding of the constantly changing Cyber landscape.

Intelligent Business Solutions Cyprus (IBSCY)

Intelligent Business Solutions Cyprus (IBSCY)

IBSCY Ltd is a leading provider of total IT solutions and services in Cyprus specializing in the areas of cloud services and applications, systems integration, IT infrastructure and security.

Tutamantic

Tutamantic

Tutamantic develops software that reduces security risks and weaknesses during the architectural and design stages.

Vanbreda

Vanbreda

Vanbreda Risk & Benefits is the largest independent insurance broker and risk consultant in Belgium and the leading insurance partner in the Benelux.

AiCULUS

AiCULUS

AiCULUS is a global technology company that specializes in API security and Risk Management products.

Darkscope

Darkscope

Darkscope is an award-winning personalised cyber intelligence service provider. Our cutting-edge AI and Deep Artificial Neural Networks lead the world of cyber intelligence solutions.

ID R&D

ID R&D

ID R&D is an award-winning provider of AI-based facial liveness, document liveness, and voice biometrics.

Xoriant

Xoriant

Xoriant is a technology leader and execution partner throughout the Build, Run and Transform lifecycle for companies that create and use technology products.

Trickest

Trickest

Trickest enables Enterprises, MSSPs, and Ethical Hackers to build automated offensive security workflows from prototype to production.

ExactTrak

ExactTrak

ExactTrak provide embedded cyber security solutions for your digital devices – whenever and wherever you need them.