[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help]  [Register] 

Status: Not Logged In; Sign In

45 Funny Cybertruck Memes So Good, Even Elon Might Crack A Smile

Possible Trump Rally Attack - Serious Injuries Reported

BULLETIN: ISRAEL IS ENTERING **** UKRAINE **** WAR ! Missile Defenses in Kiev !

ATF TO USE 2ND TRUMP ATTACK TO JUSTIFY NEW GUN CONTROL...

An EMP Attack on the U.S. Power Grids and Critical National Infrastructure

New York Residents Beg Trump to Come Back, Solve Out-of-Control Illegal Immigration

Chicago Teachers Confess They Were told to Give Illegals Passing Grades

Am I Racist? Reviewed by a BLACK MAN

Ukraine and Israel Following the Same Playbook, But Uncle Sam Doesn't Want to Play

"The Diddy indictment is PROTECTING the highest people in power" Ian Carroll

The White House just held its first cabinet meeting in almost a year. Guess who was running it.

The Democrats' War On America, Part One: What "Saving Our Democracy" Really Means

New York's MTA Proposes $65.4 Billion In Upgrades With Cash It Doesn't Have

More than 100 killed or missing as Sinaloa Cartel war rages in Mexico

New York state reports 1st human case of EEE in nearly a decade

Oktoberfest tightens security after a deadly knife attack in western Germany

Wild Walrus Just Wanted to Take A Summer Vacation Across Europe

[Video] 'Days of democracy are GONE' seethes Neil Oliver as 'JAIL' awaits Brits DARING to speak up

Police robot dodges a bullet, teargasses a man, and pins him to the ground during a standoff in Texas

Julian Assange EXPOSED

Howling mad! Fury as school allows pupil suffering from 'species dysphoria' to identify as a WOLF

"I Thank God": Heroic Woman Saves Arkansas Trooper From Attack By Drunk Illegal Alien

Taxpayers Left In The Dust On Policy For Trans Inmates In Minnesota

Progressive Policy Backfire Turns Liberals Into Gun Owners

PURE EVIL: Israel booby-trapped CHILDRENS TOYS with explosives to kill Lebanese children

These Are The World's Most Reliable Car Brands

Swing State Renters Earn 17% Less Than Needed To Afford A Typical Apartment

Fort Wayne man faces charges for keeping over 10 lbs of fentanyl in Airbnb

🚨 Secret Service Announces EMERGENCY LIVE Trump Assassination Press Conference | LIVE Right Now [Livestream in progress]

More Political Perverts, Kamala's Cringe-fest On Oprah, And A Great Moment For Trump


Science/Tech
See other Science/Tech Articles

Title: Firm uncovers more hacks on U.S. retailers
Source: [None]
URL Source: [None]
Published: Jan 18, 2014
Author: staff
Post Date: 2014-01-18 04:34:27 by Tatarewicz
Keywords: None
Views: 14

A cybercrime firm says it has uncovered at least six ongoing attacks at U.S. merchants whose credit card processing systems are infected with the same type of malicious software used to steal data from Target Corp.

Andrew Komarov, chief executive of the cybersecurity firm IntelCrawler, told Reuters that his company has alerted law enforcement, Visa Inc and intelligence teams at several large banks about the findings. He said payment card data was stolen in the attacks, though he didn't know how much.

IntelCrawler's findings are the latest sign that the cyberattacks disclosed by Target Inc and upscale department store Neiman Marcus are part of a wider assault on U.S. retailer customer data security.

On Thursday, the U.S. government and the private security intelligence firm iSIGHT Partners warned merchants and financial services firms that the BlackPOS software used against No. 3 U.S. retailer Target had been used in a string of breaches at retailers - but did not say how many or identify the victims. Government officials declined to discuss current investigations.

Komarov, an expert on cybercrime who has helped law enforcement investigate previous attacks, told Reuters on Friday that retailers in California and New York were among those compromised by BlackPOS. Reuters was unable to confirm the retailers' names.

Komarov said he has not directly contacted those merchants. Security experts typically report cybercrimes through law enforcement rather than going directly to victims because the process can be time-consuming and victims are often suspicious when they first learn of attacks.

BlackPOS was developed by a hacker whose nickname is “Ree4” and who is now about 17 years old and living in St. Petersburg, Russia, according to Los Angeles-based IntelCrawler.

The teenager sold the malicious software to cybercriminals who then launched attacks on merchants, said Komarov, who has been monitoring Ree4's activities since March.

Komarov declined to specifically identify the sources of his intelligence, though he said he has been monitoring criminal forums where Ree4 sells his software and posted an excerpt of a chat with a client on the IntelCrawler website.

Officials with the Russian Interior Ministry could not be reached for comment when Reuters attempted to contact them after office hours on Friday.

The bulk of the attacks have occurred in the United States, but about 30 percent have occurred in other countries, including Australia and Canada, Komarov said.

Target last month disclosed the theft of some 40 million payment card numbers in a breach uncovered over the holiday shopping season, and later reported that 70 million customers' records had also been taken.

Neiman Marcus last week said that it too was victim of a cyberattack. Sources have told Reuters that at least three other well-known national retailers have been attacked. 1/8 ID: nL2N0KM01D 3/8 .

John Watters, chief executive of iSIGHT Partners, which is helping the U.S. Secret Service with its investigation into the attacks, said that he expects the pace of assaults on merchants to pick up.

Copycats will pile on, using similar software, which can be purchased on underground forums, and similar techniques to launch attacks on retailers, he said. “They are saying: ‘This is a great idea.’”

BlackPOS is a type of RAM scraper, or memory-parsing software, which enables cybercriminals to grab encrypted data by capturing it when it travels through the live memory of a computer, where it appears in plain text.

It is derived from code that has been floating around underground cybercrime forums since at least 2005 and may be related to malicious software used in attacks as early as 2003, said Shane Shook, an executive with cybersecurity firm Cylance Inc who has helped investigate major breaches at retailers.

While the technology has been around for many years, its use has increased as retailers have improved their security, making it more difficult for hackers to obtain credit card data using other approaches.

It succeeded in evading detection by anti-virus software when it infected the Windows-based point-of-sales terminals at retailers like Target, according to the report that the government privately distributed to merchants on Thursday, which iSIGHT Partners helped prepare.

A spokeswoman for Visa said she could not immediately comment on the report of ongoing cyberattacks but noted that consumers should not be concerned about incurring losses from payment card fraud.

“For consumers, I would point to zero liability. They are protected,” spokeswoman Rosetta Jones said in an email.

Officials with the Secret Service could not immediately be reached for comment.

Copyright © 2014, Reuters . The Tribune is using Facebook comments on stories. To post a comment, log into Facebook and then add your comment.

Post Comment   Private Reply   Ignore Thread  



[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help]  [Register]