Posts Tagged: security fix blog

Mar 10

Bring Back ‘Live’ Web Chats?

I’ve been hearing from a number of readers who followed me here from the Security Fix blog at The Washington Post, asking if I plan to resume my bi-weekly “live” chats wherein I attempt  to field questions from readers about security, privacy and other tech-related matters.

I hosted roughly 50 of these live Web chats with readers between Jan 2008 and the end of 2009. They were usually fun, but almost always took up a lot of time. I’m amenable to restarting them at Krebs on Security, but I’d like to get a better feel for public interest in this. So, I’ll put it to a vote. Please take a moment to list your response in the poll below.

Would You Read/Participate in a Live Online, Bi-Weekly Chat with Krebs on Security?

View Results

Loading ... Loading ...

Jan 10

Money Mules Helped to Rob W. Va. Bank

I have written a great deal about how organized cyber gangs in Eastern Europe drained tens of millions of dollars from the bank accounts of small- to mid-sized businesses last year. But new evidence indicates one of the gangs chiefly responsible for these attacks managed to hack directly into a U.S. bank last year and siphon off tens of thousands of dollars.

On July 30, 2009, at least five individuals across the United States each received an electronic transfer of funds for roughly $9,000, along with instructions to pull the cash out of their account and wire the funds in chunks of less than $3,000 via Western Union and Moneygram to three different individuals in Ukraine and Moldova.

The recipients had all been hired through work-at-home job offers via popular job search Web sites, and were told they would be acting as agents for an international finance company. The recruits were told that their job was to help their employers expedite money transfers for international customers that were — for some overly complicated reason or another — not otherwise able to move payments overseas in a timely enough manner.

The money was sent to these five U.S. recruits by an organized ring of computer thieves in Eastern Europe that specializes in hacking into business bank accounts. The attackers likely infiltrated the bank the same way they broke into the accounts of dozens of small businesses last year: By spamming out e-mails that spoofed a variety of trusted entities, from the IRS, to the Social Security Administration and UPS, urging recipients to download an attached password-stealing virus disguised as a tax form, benefits claim or a shipping label, for example. Recipients who opened the poisoned attachments infected their PCs, and the thieves struck gold whenever they managed to infect a PC belonging to someone with access to the company’s bank accounts online.

Continue reading →

Dec 09

Story-Driven Résumé: My Best Work 2005-2009

I began writing for The Washington Post in 1996, and started covering computer and Internet security in 1999. Below are links to what I believe is some of my best work over the past four years or so. Virtually all of the stories and blog posts listed here were either Washington Post/Security Fix exclusives, or were the result of my investigative reporting and research aimed at shining a light on the Internet’s darkest corners, and educating readers about the importance of security.

Continue reading →