Mystery Fingers on Keyboard in JPMorgan Hack

A key figure is missing in the court documents outlining the biggest computer attack ever of the US financial system: the actual hacker.

The Israeli mastermind of the crime syndicate with global operations -- computer servers in Egypt, online casinos in Ukraine and Hungary, Azerbaijan payment processors and a Florida bitcoin exchange -- created a digital mob without a true home country, according to prosecutors. So when the gang needed a hired gun, in this case a sophisticated computer thief, it apparently turned to a harbor known for some of the best.

The hacker, identified only as co-conspirator 1 in a sweeping indictment unsealed recently, is actually a Russian master of digital break-ins known to federal agents and US spy agencies who have tracked him for years, according to three people familiar with the investigation. Another indictment unsealed this week about the gang provides a little more, citing “a computer hacker who is believed to have resided in Russia” -- one who infiltrated computer networks, located customer databases and exported the profile information to computers overseas.

It is not unusual for prosecutors to withhold names in a continuing investigation. But talks about whether to publicly identify the hacker in this case and whether to indict him reached the upper rungs of government. The prospect was the subject of various discussions at one point by officials of the National Security Agency and the White House, according to one person familiar with the matter, who said it was part of a larger debate within the Administration over how best to confront Russia over hacking amid strained US relations.

Weighing Options
"I think the government’s weighing its options at this point," said Leo Taddeo, a former special agent in charge of the Federal Bureau of Investigation’s cyber division in New York who supervised the case before he left in August and who declined to discuss its specifics. Sometimes, the names of co-conspirators are withheld in hopes they won’t go into hiding and will be easier to apprehend, said Taddeo, now chief security officer of cybersecurity company Cryptzone Inc. in Waltham, Massachusetts.

That is less of a concern in this hacking case, since the arrest and indictment of other suspects, along with the seizure of e-mails and other communications, have already alerted the hacker that US authorities are on his trail. The FBI declined to comment on the investigation, as did the White House National Security Council. The NSA didn’t respond to requests for comment. The Justice Department, which makes decisions on criminal actions independent of the executive branch, also declined to comment.

The FBI’s assessment that the financial hack and related events were purely a criminal caper, not the act of an unfriendly government, has largely been borne out by the investigation.

Still, American intelligence agencies have produced information suggesting co-conspirator 1 may enjoy the protection of the FSB, Russia’s main intelligence agency, two people briefed on the matter said. The information is not all consistent. Some intelligence suggests merely that the FSB tried to recruit the hacker, while other information indicates he may have had a more active role in FSB-directed operations, they said.

The hacker’s profile helped feed differences of opinion early on about the attacks of some of Wall Street’s biggest names. For months after the disclosure of a big systems breach last summer, JPMorgan Chase & Co. officials maintained the attack on the bank should be treated as a national security incident.

Going Undetected
Co-conspirator 1’s shadowy talents are on display throughout the two indictments, one in federal court in New York and the other in Atlanta. He appears to infiltrate some American financial institutions with ease, operating undetected inside their heavily secured computer banks for months or years.

Targeted companies included Fidelity Investments, E*Trade Financial Corp., Scottrade Financial Services Inc., Dow Jones & Co., as well as JPMorgan Chase, which alone spends more than half a billion dollars annually to secure its computers. Fidelity is the one company in this group that has said it has no indication any customer information was taken from its network.
Some of the targets were chosen by Gery Shalon, the Israeli who was the mastermind of the criminal organization spanning bitcoin companies, Internet gambling sites and securities manipulation before his arrest last summer, according to the criminal indictments.

Specialists say co-conspirator 1 may have done more than what Shalon ordered and point out that he remained in the computers of some companies for years, even though e-mail addresses and such can be spirited away quickly.
For example, when disclosing that some customer payment information may have been compromised in October, Dow Jones said that the unauthorized access to its systems occurred at certain times over three years.

Dead End
Data stolen from the targets might also have been shared with others in Russia, if that is where the hacker is working, for his own protection, said Tom Kellermann, chief cybersecurity officer for Trend Micro Inc. "This is not over," Kellermann said. "The real question now is how many backdoors are still in these systems that have yet to be detected."
US authorities almost always hit a dead end, Taddeo said, when an investigation leads to Russia.

With Shalon and some other suspects in custody, however, prosecutors may be able to plumb the inner workings of Russia’s elite cyber underground. At least two of Shalon’s alleged associates, Joshua Aaron and bitcoin operator Anthony Murgio, traveled extensively to Russia and could have met the hacker in person.

The two people familiar with the case said it is unclear if prosecutors are still considering charges against co-conspirator 1 for hacking and related crimes. He could be indicted even though Russia does not extradite its citizens to the West. 

President Barack Obama could also use new executive powers to seize assets and impose other sanctions on foreign nationals involved in cybercrime, measures the White House has yet to tap despite a run of high-profile hacks on companies and agencies.

Information-Management

 

« State-sponsored Cyberspies
Cyber War and Real War Coincide In Ukraine »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Australian Information Security Association (AISA)

Australian Information Security Association (AISA)

AISA champions the development of a robust information security sector by building professional capacity and advancing the cyber security of the public, business and governments in Australia.

Tinfoil Security

Tinfoil Security

Tinfoil is a simple, developer friendly service that lets you scan your website for vulnerabilities and fix them quickly and easily.

Athena Dynamics

Athena Dynamics

Athena Dynamics focuses on Cyber Security, especially in Critical Information Infra-structure Protection and Enterprise IT Operation Management products and Services.

Bunifu Technologies

Bunifu Technologies

Bunifu Technologies is an Information Security and Custom Software Development Company.

Penacity

Penacity

Penacity, LLC provides strategic consulting technology services and Information Security Services to commercial and government organizations.

CYBRScore

CYBRScore

CYBRScore is a premium, performance-based cyber skills training and assessment provider that quantifies a user’s ability to defend a network.

HB-Technologies

HB-Technologies

HB-Technologies is pioneer in Africa, in digital security, embedded electronic and IT solutions based on highly secure smart cards that comply with international standards and norms.

Celera Networks

Celera Networks

Celera Networks is a managed services provider specializing in cybersecurity, cloud and managed IT services.

Aceiss

Aceiss

Aceiss empowers access security, providing unprecedented visibility and insights into user access.

CertiProf

CertiProf

CertiProf has been enhancing professional lives since 2015, offering a wide range of IT certifications and agile framework training.

Limes Security

Limes Security

Limes Security GmbH is the leading OT Security expert in the German-speaking region of Europe.

DATS Project

DATS Project

DATS Project enables the utilization of high computing power across a number of cybersecurity services, all on a pay-as-you-go basis, eliminating the need for upfront investment costs.

CyPro

CyPro

CyPro is a cyber security expert firm that specialises in providing cyber security services tailored for high-growth companies at every stage of their journey.

Dream

Dream

Dream is developing an AI platform that enables cyber resilience and protects nations from hostile nation-states cyber attacks.

CyberMindr

CyberMindr

CyberMindr is a SaaS platform for Automated & Continuous Attack Path and Threat Exposure Discovery helps you to proactively identify & assess your attack surface to mitigate associated threats.

TIVIT

TIVIT

TIVIT is a Brazil-based multinational company that offers enterprise-level digital solutions, and operates in ten countries in Latin America