Computer Crime Research Center

hack/hacker16.jpg

The Cyber Crime Economy

Date: April 10, 2008
Source: Informationweek.co
By: Thomas Claburn

Dot-coms daunted by the financial downturn would be well advised to look to the cyber crime economy.

Cyber criminals "have very sound business models," said Joe St Sauver, manager of Internet2 Security Programs through the University of Oregon at an RSA Conference panel on Wednesday, "better than many corporate business plans I routinely see."

The conference session, "Deconstructing the Modern Online Criminal Ecosystem," offered interesting insight into the way the Internet's black market works.

While most of the security professionals I've spoken with at RSA expressed optimism about dealing with future cyber threats, I find it hard to see where that optimism comes from, given economics of cyber crime as explained by the participating panelists.

One of them was Larry. He provided no last name and asked that his picture not be published, presumably for his safety. He's the chief investigator for Spamhaus.org, a site that tracks spammers. "It's almost impossible to take these [spam Web sites] down because the DNS changes every five minutes or so," he said.

"Almost impossible" is not the stuff of optimism.

As the panelists explained, a single spam message might be tied to as many ten separate organizations and perhaps five suppliers. Every task in the criminal economy has become a separate specialty. Some people sell e-mail lists, others sell lists of compromised IP addresses, there are sellers of credit card numbers, and those who sell access to bot nets. Then there are those who handle product fulfillment for spammers, and those who specialize in laundering money.

All this specialization insulates the network from prosecution by providing a degree of deniability. "You mean my associate was using the names I sold him for spamming?" a cornered cyber criminal might say. "I told him not to do that."
The modern cyber crime economy is a franchise model that scales, explained St Sauver.

And it pays well. Ironport's Patrick Peterson observed that an IT graduate in Romania might be able to earn $400 per month legitimately, compared to several thousand per month in the cyber crime economy. And I've spoken with security researchers who suggest the difference in pay being a security researcher and a security exploiter differs by a factor of ten quite often.

Cyber criminals make so much money in fact that they employ money mules, networks of thousands of people to help them launder money by receiving and sending cash for a commission. Many of them are unaware that they're facilitating crime. And many of them end up being scammed.

A typical scam: They're wired money and asked to send out a lesser amount via Western Union. Only later do they learn that wire transfers can be reversed whereas Western Union money transfers are irrevocable.

And a final factoid from the session: Lawrence Baldwin, chief forensics officer with My Net Watchman, said that in the past few months he was aware of about 30 data breaches at companies and only 2 have been publicly reported.

The trend, Baldwin said, was to go after mid-sized organizations because the big ones have too much security and individuals don't have enough valuable data. Sounds like the recent Hannaford breach to me.


Add comment  Email to a Friend

Copyright © 2001-2013 Computer Crime Research Center
CCRC logo