Mystery Fingers on Keyboard in JPMorgan Hack

A key figure is missing in the court documents outlining the biggest computer attack ever of the US financial system: the actual hacker.

The Israeli mastermind of the crime syndicate with global operations -- computer servers in Egypt, online casinos in Ukraine and Hungary, Azerbaijan payment processors and a Florida bitcoin exchange -- created a digital mob without a true home country, according to prosecutors. So when the gang needed a hired gun, in this case a sophisticated computer thief, it apparently turned to a harbor known for some of the best.

The hacker, identified only as co-conspirator 1 in a sweeping indictment unsealed recently, is actually a Russian master of digital break-ins known to federal agents and US spy agencies who have tracked him for years, according to three people familiar with the investigation. Another indictment unsealed this week about the gang provides a little more, citing “a computer hacker who is believed to have resided in Russia” -- one who infiltrated computer networks, located customer databases and exported the profile information to computers overseas.

It is not unusual for prosecutors to withhold names in a continuing investigation. But talks about whether to publicly identify the hacker in this case and whether to indict him reached the upper rungs of government. The prospect was the subject of various discussions at one point by officials of the National Security Agency and the White House, according to one person familiar with the matter, who said it was part of a larger debate within the Administration over how best to confront Russia over hacking amid strained US relations.

Weighing Options
"I think the government’s weighing its options at this point," said Leo Taddeo, a former special agent in charge of the Federal Bureau of Investigation’s cyber division in New York who supervised the case before he left in August and who declined to discuss its specifics. Sometimes, the names of co-conspirators are withheld in hopes they won’t go into hiding and will be easier to apprehend, said Taddeo, now chief security officer of cybersecurity company Cryptzone Inc. in Waltham, Massachusetts.

That is less of a concern in this hacking case, since the arrest and indictment of other suspects, along with the seizure of e-mails and other communications, have already alerted the hacker that US authorities are on his trail. The FBI declined to comment on the investigation, as did the White House National Security Council. The NSA didn’t respond to requests for comment. The Justice Department, which makes decisions on criminal actions independent of the executive branch, also declined to comment.

The FBI’s assessment that the financial hack and related events were purely a criminal caper, not the act of an unfriendly government, has largely been borne out by the investigation.

Still, American intelligence agencies have produced information suggesting co-conspirator 1 may enjoy the protection of the FSB, Russia’s main intelligence agency, two people briefed on the matter said. The information is not all consistent. Some intelligence suggests merely that the FSB tried to recruit the hacker, while other information indicates he may have had a more active role in FSB-directed operations, they said.

The hacker’s profile helped feed differences of opinion early on about the attacks of some of Wall Street’s biggest names. For months after the disclosure of a big systems breach last summer, JPMorgan Chase & Co. officials maintained the attack on the bank should be treated as a national security incident.

Going Undetected
Co-conspirator 1’s shadowy talents are on display throughout the two indictments, one in federal court in New York and the other in Atlanta. He appears to infiltrate some American financial institutions with ease, operating undetected inside their heavily secured computer banks for months or years.

Targeted companies included Fidelity Investments, E*Trade Financial Corp., Scottrade Financial Services Inc., Dow Jones & Co., as well as JPMorgan Chase, which alone spends more than half a billion dollars annually to secure its computers. Fidelity is the one company in this group that has said it has no indication any customer information was taken from its network.
Some of the targets were chosen by Gery Shalon, the Israeli who was the mastermind of the criminal organization spanning bitcoin companies, Internet gambling sites and securities manipulation before his arrest last summer, according to the criminal indictments.

Specialists say co-conspirator 1 may have done more than what Shalon ordered and point out that he remained in the computers of some companies for years, even though e-mail addresses and such can be spirited away quickly.
For example, when disclosing that some customer payment information may have been compromised in October, Dow Jones said that the unauthorized access to its systems occurred at certain times over three years.

Dead End
Data stolen from the targets might also have been shared with others in Russia, if that is where the hacker is working, for his own protection, said Tom Kellermann, chief cybersecurity officer for Trend Micro Inc. "This is not over," Kellermann said. "The real question now is how many backdoors are still in these systems that have yet to be detected."
US authorities almost always hit a dead end, Taddeo said, when an investigation leads to Russia.

With Shalon and some other suspects in custody, however, prosecutors may be able to plumb the inner workings of Russia’s elite cyber underground. At least two of Shalon’s alleged associates, Joshua Aaron and bitcoin operator Anthony Murgio, traveled extensively to Russia and could have met the hacker in person.

The two people familiar with the case said it is unclear if prosecutors are still considering charges against co-conspirator 1 for hacking and related crimes. He could be indicted even though Russia does not extradite its citizens to the West. 

President Barack Obama could also use new executive powers to seize assets and impose other sanctions on foreign nationals involved in cybercrime, measures the White House has yet to tap despite a run of high-profile hacks on companies and agencies.

Information-Management

 

« State-sponsored Cyberspies
Cyber War and Real War Coincide In Ukraine »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

APMG International (APM Group)

APMG International (APM Group)

APM Group is a global accreditation, certification and examination body specializing in certification schemes for individuals, organizations and software.

CLUSIL

CLUSIL

CLUSIL is an association for the information security industry in Luxembourg.

World Wide Technology (WWT)

World Wide Technology (WWT)

WWT is a technology solution provider in the areas of big data, collaboration, computing and cloud, mobility, networking, security and storage.

Simula Research Laboratory

Simula Research Laboratory

Simula Research Laboratory carries out research in the fields of communication systems, scientific computing and software engineering.

Redstor

Redstor

Redstor's complete data management helps you discover, manage and control your data from a single control centre, unifying backup and recovery, disaster recovery, archiving and search and insight.

Extreme Protocol Solutions (EPS)

Extreme Protocol Solutions (EPS)

Extreme Protocol Solutions is an industry leading Data Sanitization Software, Hardware and Onsite Service Provider.

Rede Nacional CSIRT

Rede Nacional CSIRT

Rede Nacional CSIRT is a national network of CSIRTs in Portugal aimed at cooperation and mutual assistance in the handling of incidents and in the sharing of good security practices.

HunCERT

HunCERT

HunCERT's mission is to assist Hungarian Internet Service Providers in applying appropriate procedures to address the risks of computer network incidents and to respond to such incidents.

Cyvatar

Cyvatar

Cyvatar is a technology-enabled cyber security as a service (CSaaS) provider delivering smarter managed security to help you achieve compliance and security faster and more efficiently.

Knowit

Knowit

Knowit support customers in the digital transformation, simplify people’s everyday lives and create secure and innovative solutions enabling a sustainable future.

Icon Information Systems (ICONIS)

Icon Information Systems (ICONIS)

ICONIS is an integrated infrastructure and service provider, offering unified Information Technology (IT) solutions globally.

LevelBlue

LevelBlue

LevelBlue simplify cybersecurity through award-winning managed security services, experienced strategic consulting, threat intelligence and renowned research.

Idenhaus Consulting

Idenhaus Consulting

Idenhaus specializes in Cybersecurity and Identity Management (IAM) Consulting.

Krash Consulting

Krash Consulting

Krash Consulting is a premier provider of Cyber Security solutions, offering a range of services to safeguard businesses against cyber-attacks, minimize fraud, and protect brand reputation globally.

Ransomware Help

Ransomware Help

Ransomware Help is a trusted ransomware recovery company offering fast and effective ransomware recovery services to get your business back on track.

Armilla AI

Armilla AI

Armilla is the world’s only MGA focused solely on AI insurance and offers third-party testing, compliance, risk mitigation, and warranty coverage for enterprises and AI vendors alike.