Showing posts with label Spamming. Show all posts
Showing posts with label Spamming. Show all posts

20 Million Credit Cards stolen in South Korea, 40% Population affected by the Data Leak

Since all threats to data security and privacy often come from outside, but internal threats are comparatively more dangerous and a difficult new dimension to the data loss prevention challenge i.e. Data Breach. The "Insider threats" have the potential to cause greater financial losses than attacks that originate outside the company.



This is what happened recently with three credit card firms in South Korea, where the financial and personal data belonging to users of at least 20 million, in a country of 50 million, was stolen by an employee, who worked as a temporary consultant at Korean Credit Bureau (KCB).

“Confidential data of customers ranging from the minister-level officials to celebrities, including their phone numbers, addresses, credit card numbers, and even some banking records, have been leaked from Kookmin Bank, Shinhan Bank and several other commercial banks”,

The stolen data includes the bank account numbers, customers' names, social security numbers, phone numbers, credit card numbers and expiration dates, according to the estimate by the Financial Supervisory Service (FSS).

The arrested employee behind the theft, later sold the data to phone marketing companies, whose managers were also arrested earlier this month.

"The credit card firms will cover any financial losses caused to their customers due to the latest accident," the FSS said and assured that the Regulators have launched investigations into security measures at the affected firms.

"Their parent firms seem to be taking a step back (from the issue) and not showing any responsible attitude, We will hold them fully responsible for the data leak if their sharing of client data among affiliates and internal control turn out to be the cause."

Now this is not the first time when a company is facing data breach because of Insider Threat, last month an employee of Citibank Korea was arrested for stealing the personal data of 34,000 customers. In 2012, two South Korean hackers were arrested for data from 8.7 million customers in the nation's second-biggest mobile operator.

Facebook Scam: Win a Disney Cruise with $2,000 Spending Money

Cammers have created Facebook pages called “Walt Disney World” on which they claim to be giving users the chance to win a trip via Disney Cruise.

“Great news, we're giving you a chance to get a Disney Cruise for you and 5 friends to 50 people from us with $2,000 spending money for a date of your choice. To enter Just Share this video then go here: www.disney-cruise-lines.com,” the posts entitled “Win a Disney Cruise with $2,000 spending money” read.



The so-called competition has nothing to do with Disney. Furthermore, the link doesn’t actually point to the Disney Cruise Lines website, but to a site where users are instructed to complete a survey in order to allegedly win various prizes, Hoax Slayer warns.

Each time one of these surveys is completed, the scammers make some money via affiliate networking services. Furthermore, some of the sites also instruct users to hand over personal information, which can also be monetized in various ways.

Finally, by tricking users into liking their bogus Facebook pages, the cybercrooks are actually increasing their values. Pages with a large number of likes can be worth a lot of money on the underground market since they can be repurposed for other shady activities.


If you’re a victim of this scam, remove the post you’ve shared on your timeline. If you’ve completed the survey and handed over some personal information, watch out for other scams, since it’s likely that you’ve ended up on the scammers’ list of potential victims.

I’ve seen three of these fake “Walt Disney World” pages, but others might appear soon. The ones that are currently online have harvested as many as 21,000 likes. If you come across such pages, report them to Facebook.

Naughty Nurse Sakura Shiratori tries to Infect Defence Firm with Malware

We’ve seen a large number of files spammed out to various organisations, exploiting the CVE-2012-0158 vulnerability.

Victims have not be
en limited to defence companies, but have also included government departments, charities and recruitment agencies.

One of the latest attacks we have seen was sent to a defence contractor, using the subject line “if you want sex pictrue!”.
Attached to the email is a file called sexpicture.rar that contains a number of naked pictures of Japanese model Sakura Shiratori.

Harmless enough you might think. However, alongside the seedy snapshots are two files.

An apparent screensaver, short-SEXGPJ_1.SCR, is malicious – and detected by Sophos products as Mal/Behav-043.

Another file, short-SEX_ST_1.DOC, is detected by Sophos products as Troj/DocDrop-AF, and attempts to install further malicious code onto victims’ computers by exploiting the CVE-2012-0158 vulnerability.

Although the email appears to have come from the Taiwanese branch of Yahoo, the “from:” address has been forged by whoever sent out the attack. I’m also going to make the fairly safe assumption that Miss Shiratori is not aware of how her images are being abused.

Make sure that the staff at your firm are wary of opening unsolicited email attachments, and that computers are defended with up-to-date anti-virus software and the latest security patches.

Microsoft released its patch for the vulnerability back in April – if you haven’t already rolled it out across your Windows PCs, do so now.

Microsoft Confirm hackers Spam in Android Devices


A spam engineer at Microsoft has warned that hackers can use Android powered tablets and smartphones to send spam emails.  Android users should be cautious to install any mobile apps that do not come from the Google Play Store or the Amazon Appstore since a new malware app has been reportedly sending spam emails through affected devices.  Terry Zink says that a new app is sending out emails with the signature “Sent from Yahoo Mail on Android” and the messages are starting to come from a number of locations including Indonesia, Chile, Lebanon, Oman, Philippines, Russia, Saudi Arabia, Ukraine and Thailand.


Zink wrote on an MSDN blog, “I’ve written in the past that Android has the most malware compared to other smartphone platforms, but your odds of downloading and installing a malicious Android app is pretty low if you get it from the Android Marketplace, but if you get it from some guy in a back alley on the Internet, the odds go way up.”  The malware affected app logs into your Yahoo account through your Android device and then starts by sending out spam messages.

The app does not seem to be coming from Google’s Play Store, so that is a little less to worry about, but users who attempt to download hacked, pirated or other versions of official apps should be aware they could contain the malware code.  Malware type apps have appeared in the past and sent spam text messages from users phones in order to rack up phone bills to unsuspecting smartphone users.  The “botnet” virus gives the hacker just enough access to your account to send the spam messages.  The messages have not been sent anywhere in the United States yet, but that does not mean you are 100 percent safe either.

Users can avoid malicious content from mobile app download stores if they stick to official stores like the Amazon Appstore and Google Play Store which scan for potentially harmful mobile apps and remove them from the store or deny their submission altogether.  If you are concerned about downloading the wrong type of mobile app you can follow a couple easy steps.  Before the app is installed on your device, the Android software will show you what permissions it has on your phone.  If you are downloading a game app, you might want to make sure it does not have access to your contact list.  You can get more tips for downloading safe apps online.

Hacker who swindled $3m held in Dubai hotel

According to media reports, the incident came to light when a UAE trader who lost $3million filed a complaint with Dubai Police. The victim, who had business connections with the said Chinese firm, received an email from the company requesting him to transfer $3million to its account.



He duly transferred the amount because he was used to dealing with huge sums of money with the company. He never confirmed with the officials in China if they received the amount because such transactions were common between them, he told investigating officials.

However, a few days later he learnt that the email he received was not sent by the company.

He immediately filed a complaint and investigations by the anti-crimes department of Dubai Police revealed that the company website had been hacked by the suspect. He not only obtained important data but also used the offical email id to contact its clients and defraud millions.

The suspect was tracked down and arrested from a Dubai hotel. His bank accounts are frozen and he is referred to Public Prosecution.


Anonymous Rattles A Chinese Web Giant

Anonymous may be best known for knocking websites offline or stealing data, but one faction of the movement is subverting figures of power in a more circumspect way — by trawling through documents and computer code.

The sub group Anonymous Analytics released a damning report yesterday about Qihoo, the Chinese web giant that claims to be the No. 1 provider of Internet and mobile security products and services in China, as measured by its user base.


Qihoo distributes antivirus software called 360 Safeguard and has a browser called 360 Secure Browser, but in recent years has restructured it business to focus on selling online advertising space, in particular from a single directory page, hao.360.cn. The company claims to get approximately 90% of its advertising revenue “directly or indirectly” from this page and its sub pages; advertising accounted for 73% of the company’s total revenue in 2011 of $22.9 million.

That figure marked an increase of 136% from the year before, meaning hao.360.cn is a serious money-maker for Qihoo. Qihoo recently said that it charged, on average, 1 million yuan  ($156,000) per month, per link on the “Famous Sites” section of its directory page — a breed of e-commerce widely known to have dwindled in Western cyberspace.

Anonymous Analytics says there’s something fishy about Qihoo’s directory page. Qihoo recently claimed on its fourth quarter conference call that the page was getting 20% more web traffic than dominant-player Baidu’s similar page and its sub pages, hao123.com. Qihoo confirmed this with me, citing a table of figures from iResearch.

But the Anonymous group claims that Qihoo is “grotesquely exaggerating” its traffic advantage, and their evidence comes in the form of a recent change in the source code of hao.360.cn. Having been monitoring the site since last year, the group noticed that a comScore tag had been added to Qihoo’s HTML source code. (ComScore is the best-known, third-party verifier of a web site’s traffic.)

This seemed fine, until the tag was removed on or around June 20, 2012. Why? Anonymous Analytics thinks that Qihoo didn’t like the figures it was seeing. The group then managed to get what it claims are the actual comScore figures through unnamed third parties — “people we trust,” according to the group’s representative — who had bought them from comScore. The figures show that in the months of February, March and April 2012, Qihoo’s all-important directory page had 56%, 51% and 52% less traffic than Baidu’s.

Anonymous Analytics provided me with what appears to be a legitimate document from comScore showing web traffic figures for Baidu and Qihoo’s main directory pages in April 2012. It states that Baidu’s directory page had 84.689 million unique visitors from China, while Qihoo’s had 40.877 million.

The activist group believes that before Qihoo balked at the figures, it had added the comScore tag to appease analysts, investors and critics, “who have called for management to provide independent verification of Qihoo’s traffic claims.”

The group further believes that management installed the tag with a view figuring out how to manipulate comScore’s traffic analytics. “We are so certain of this that we invite engineers at comScore to analyze data coming out of hao.360.cn since the beginning of the year,” Anonymous Analytics says.

Australian Death Threat Text Scam under Investigation

Thousands of Australians have received a "death threat" text, demanding they pay 5,000 Australian dollars ($5,140, £3,311) or face being murdered.

The scale of the scam has surprised the police authorities.

At a press conference in Queensland, Det Supt Brian Hay said: "Do not respond. Delete it immediately and don't panic... because that's what they prey upon."

The fraud is believed to be the work of an organised crime gang.
Huge scale




The message, which began to hit people's phones on Monday, reads: "Sum1 paid me to kill you. Get spared, 48hrs to pay $5000. If you inform the police or anybody, death is promised."

It directs people to a Yahoo email account which police have now disabled.

Mr Hay told reporters that enquiries were ongoing as to whether the criminals were based in Australia.

Some people had already fallen for the scam, mainly those with little experience of text messaging, he revealed.

He said that the scale of the scam was "unprecedented".

"We've never see this anything like this before - to have so many people contacted at the same time."

"There is an extraordinary amount of Australian consumer data that they are exploiting," he added.

He added that the scam was likely to be the work of organised criminals rather than an individual.

Related Posts Plugin for WordPress, Blogger...