Showing posts with label Tero Pollanen. Show all posts
Showing posts with label Tero Pollanen. Show all posts

Thursday, 6 September 2012

The Coming “Quiet” War


Cybercrime knows no borders. There are thousands of attacks globally every day and cyber crime costs the UK £27 billion yearly. Tero Pollanen, international expert on cyber crime and security warns that this growing threat on the UK including global networks is a serious threat to economic security. “The magnitude of this threat cannot be overstated.”

With the increasing level of sophistication of attacks from both enemy states and criminal organizations, cyber security is one of the greatest challenges of today. The alarm has been sounded by the government and it has been “quietly” suggested that the UK should in fact declare war on states and criminals that are targeting the country by employing “aggressive retaliatory strikes” hoping to destroy their operatives.

The latest attacks are now focusing on business targets.  This, of course could include core infrastructure grids which, if compromised, would bring the country to its knees. Time after time Tero has reiterated that complacency is the biggest enemy within a company. Often they do not begin to realize that they have been compromised until sensitive information falls into other hands and/or their entire network is under the control of criminals. The bottom line is that companies are not taking this threat seriously.

The government has offered new guidance in it’s “10 Steps to Cyber Security.” But again complacency raises its ugly head as a recent survey has determined that nearly 9 out of 10 UK businesses were confident that they were already adequately protected. It has been said that such confidence is a grave mistake.

Friday, 31 August 2012

Is Your Data Secure?




New information revealed under the Freedom of Information Act shows alarming statistics concerning data breaches in the UK. According to the Information Commissioner’sOffice, data breaches have increased by a factor of ten in the last five years. The good news, however, is that organizations are reporting many more breaches than before.

Tero Pollanen, international fraud prevention specialist has stated time after time the importance of both awareness and stepped up government participation are the keys to turning the tide against cyber crimes. The word is getting out as the ICO’s numbers demonstrate that awareness of the legal requirements on companies to secure information and large fines on companies that “lose” information is precipitating positive change. The telecom sector has actually seen a decrease in the number of information breaches in the past five years.

The ICO provides a wealth of information and guidance across the UK. It should be noted the both health service and government sectors are expected to report serious breaches which involve large volumes of personal data and/or sensitive materials. Again, Tero Pollanen reminds us both to be aware and encourages additional sectors to work with the ICO in reducing the number of data breaches.

Tuesday, 14 August 2012

Tag Team: Father & Son Scam


“Just when we thought we had seen it all, says Tero Pollanen, a well known fraud specialist, we see yet another major institution fall victim.” With all the chatter about the major world banks, now it’s Western Union and a money transferring scam involving a father and son team.  Here we have 2 people, illegal immigrants facing deportation from the UK. The father was bankrupt several years ago and yet became an agent for a Western Union transferring company after “various checks had been carried out”. Apparently these checks were not quite thorough.

The business they set up offered unsustainable transfer rates and was marketed to their own people in India and Pakistan. “..the money transfer service had quickly gone wrong because they were offering such good exchange rates that they made no profit.” 

More than 20 customers over a three month period were defrauded as they used this service which offered “excellent rates on transactions.” The judge that eventually tried the case “described their offenses against their own Asian community as ‘despicable’”. Both men knew they were facing deportation to Pakistan; the elder being fearful of returning there because he received better health services in the UK. Apparently despite his status, he had been receiving free medication.

It seems there is no limit to the depth to which people will sink in these most desperate times. Everyone must be vigilant.

Thursday, 9 August 2012

And The Beat Goes On…


“You never know whom, from where, or what will occur but there is a war going on out there,” says Tero Pollanen, a well-known cyber crime and fraud prevention specialist. The scam of the day comes to you from Bhubaneswar, India where we read of a graduate engineer being arrested for hacking a victim’s credit card and going on a spending spree over the last several months. Over a three month period, he defrauded the victim of nearly £1100
on internet adult sites alone, in addition to purchasing a cell phone and other assorted electronics.

An ongoing investigation is in progress to see it the arrested was simply acting independently or if he is part of an organized crime group. It is sad that here we witness a bright mind whom we would expect to trust and aid in the prevention of such affairs, rather falls into temptation and thus violates our trust.

Tuesday, 7 August 2012

Olympic Size Scam Observed


Bigger, faster, and automated.  We’ve come a long way since Mario Puzo…

Organized crime sophistication we are talking about. “In the latest reincarnation,” Mr. Pollanen, a well respected international financial anti fraud specialist asserts, “we find a banking fraud ring attempting a £2billion heist from large account holdings all over the globe.” These automated attacks move extremely rapidly and yes, cloud based services are becoming more popular by these hi-tech fraudsters. They are so sophisticated that they have developed methods of bypassing chip and pin authentication.

Due to the magnitude and adeptness of this Olympic-Sized threat with alleged organized crime signatures, warnings are being issued for the upcoming Olympic games. Wherever crowds assemble for large scale media and/or sporting events, these modern day pickpockets will gravitate. We will see new phishing scams mushrooming and all should take caution in using WiFi spots that possibly could be intercepted.

“It is very important to be aware of one’s surroundings whether in a business environment, in public, or at home,” according to Mr. Pollanen.  Crime sophistication is on the rise and as we mentioned in a previous blog, new methods of strict, punitive law enforcement efforts must be developed and implemented. 

Further reading: http://www.itpro.co.uk/641386/mcafee-uncovers-europe-wide-bank-fraud-scam

Friday, 20 April 2012

Convicted Criminal? Maybe he can help


As unemployment rises, and competition for jobs gets increasingly stiffer, companies are often spoilt for choice with the creme-de-la-creme of potential employees. With an average of over 30 applicants for each position in London, many businesses are able to appoint higher caliber candidates than ever before.
Many firms are employing individuals capable of innovation and ‘thinking outside the box’ through purposefully hiring convicted criminals. Whilst on first consideration this may appear an odd choice, it appears to be producing the desired results. Some of the more high profile appointments are rumoured to include George Hotz, a hacker hired (reportedly) by facebook. Whilst not officially a convicted criminal, the youngster has settled a previous case out of court.

Many of the biggest names in technology are reputed to have hired hackers in the past too. Whilst few employers would openly admit to it, it is commonly believed that Apple, Microsoft, and Google have done so. Security firms and government agencies such as GCHQ in the UK even entice applicants by setting challenges for wannabe applicants to solve.

Whilst hiring, or even associating with hired hackers and convicted criminals is a risk for and company, it is a calculated risk considered by many to pay off. Not only will it create a certain amount of ‘buzz’ online, if the incentives are deemed sufficient by the individual, they may choose to invest in the company. Being able to manipulate the latest technology to a firms advantage, as well as the ability to see the bigger picture and truly improve and redesign the world in which we live is a genuinely exciting prospect.

In truth, employment in any context becomes a question of risk; how much a firm is content on risking, and how much an employee is prepared to risk in favour of, or indeed against, that position of trust.
Tero Pollanen is a online security specialist with years of experience on advising organisations on online fraud and security, he has experience from both sides of the security world.

Sunday, 8 January 2012

Israel Hack Attack




At a time when credit card fraud and online hacking scams are becoming increasingly common, Israel has become the latest victim. On Saturday, January 7, the country announced that the details of thousands of credit cards had been publicised online.

The exact details and figures of the attack vary according to sources; whilst the credit card companies say the details of  around 25,000 cards (of which over 6,000 were current) had been exposed, the government says as many as 400,000 Israeli people have had their private information compromised. Israel is not used to attacks of this nature, and it is believed that this is the worst of its kind the country has seen. This kind of attack is not uncommon, a large cybercrime wave has recently swept across China, as reported on Tero Pollanen’s Online Fraud blog reports.

The hacker claiming responsibility, OxOmar, said he lives in Saudi Arabia. After initial investigations, there is apparently some evidence that it is infact a teenager living in Mexico. As yet, it is not thought that help from Mexican authorities has been sought.

Israel, clearly riled, has hit back strongly, "vowing to retaliate" according to the BBC. Speaking of such kind of attacks, Danny Ayalon, Deputy Foreign Minister, said they are "a breach of sovereignty comparable to a terrorist operation, and must be treated as such. Israel has active capabilities for striking at those who are trying to harm it, and no agency or hacker will be immune from retaliatory action".

Friday, 30 December 2011

Cybercrime and Phishing Scams Sweeping China



A wave of cybercrime has swept across China this past week, triggering the Chinese government to mount a counter campaign. Whilst the criminals attempt to steal online banking details, the government has sought expert advice on how to combat the issue. One of the key results, is that phishing sites will now appear below those of legitimate banks in search results.

The personal details of over 45 million Chinese people (almost 10% of China’s online population) were stolen during wave of attacks. China’s Ministry of Industry and Information is investigating the crimes, and has said "The department believes the recent leak of user information is a serious infringement of the rights of internet users and threatens internet safety". The phishing scams work by impersonating a legitimate bank (or similar), and sending messages directing people to the fake sites. Once people visit the fake sites, their login details are taken, and then used by the criminals to steal money from the account.

The way in which the Chinese government fought back was to employ SEO (search engine optimisation) tactics; that is to say ensuring what results users get from searching particular terms online. The Chinese government has managed to get the 10 biggest search engines in China on board the anti-phishing campaign. Furthermore, some of the Chinese search engines are going to introduce an icon, confirming the legitimacy of a site. These two techniques combined should reduce the number of people being tricked and scammed.

Phishing scams are common globally, and are relatively easy to avoid if you follow these simple tips:
-        Beware email messages!!
Look out for emails that claim to be from companies asking you to click-through to update your details or rectify a problem with your account. If you’re unsure about the authenticity of an email, don’t open it and contact the company it claims to be from.
-        Keep an eye on your accounts
Be vigilant for any transactions you don’t recognise. Contact your bank or credit card provider to query a transaction if it looks unfamiliar. You should also contact your bank or credit card provider if your statements fail to arrive. They may have been redirected by a fraudster.
-        Avoid attachments!
Genuine banks will never send emails with attachments.
-        View an example
There is a good example of what a phishing email might look like, with annotations of things to look out for on the Lloyds TSB site.

Up to date information, tips and more can be found on online blogs such as http://fightbankfraud.blogspot.com/

Tuesday, 20 December 2011

No More Mr Nice Guy?


Security analysts believe the US should clarify the repercussions of cyberattacks following sustained hacks from China.  It is also believed that the Chinese attacks are carried out by as few as 12 groups directed, for the most part, by the Chinese government. During the cyberattacks, the Chinese groups have stolen billions of dollars' worth of intellectual property and information from US companies and government agencies, according to online security experts.

Thanks to advances in technologies and increasing knowledge amongst experts, more cybercriminals are being identified by their ‘digital fingerprint’. The distinguishing characteristics of each attack is monitored by US experts enabling them to link individuals to particular groups of hackers, and sometimes where they are, or who they are. These techniques have, according to US security experts, shown an intensifying pattern. This escalating issue has sparked the recent concern amongst industry experts. As James Cartwright, a retired Marine general and former vice chairman of the Joint Chiefs of Staff puts it, "If you want to attack me you can do it all you want, because I can't do anything about it. It's risk free, and you're willing to take almost any risk to come after me."

The problems the US has in confronting the issue are the same as any other country has: firstly it is very hard to prove exactly who carried out the attack, and secondly both countries must have mutual agreements on such a situation. Mr Cartwright went on to say that the US "needs to say, 'if you come after me, I'm going to find you, I'm going to do something about it.' It will be proportional, but I'm going to do something ... and if you're hiding in a third country, I'm going to tell that country you're there, if they don't stop you from doing it, I'm going to come and get you."

The question is, how should the US proceed? Due to the nature of what is being stolen, the response is pretty much unanimous from  US government campaigners: a clear and firm message must be sent to those breaking the law. Online security specialist, Tero Pollanen, agrees Cartwright that "the US needs a clear policy on dealing with cyber attacks, and the countries through which the attacks are routed. This way, when an attck is apparent, the US can request the country to stop the attack. If the request is refused, the US then has the right to stop the computer server from sending the attack. "
The problem is, he goes on, "there is no international police force. Enforcing laws in another territory is always going to be tricky to manage."



This article is by Tero Pollanen; an online security and fraud prevention specialist. For the latest online security and financial news, tips and more, check out his blog: http://tero-pollanen.blogspot.com/

Wednesday, 19 October 2011

Was time to make a Blog


Hello,

My name is Tero Pollanen and I am an online Anti Fraud and Financial Crime expert.
I have worked in the cybercrime and fraud space for over 6 years and have also spoken at events such as the RSA eFraud Network and eBay events.

I will be using this blog to comment about trends in the industry and also to talk about possible solutions for how organisations or people can protect themselves against cybercrime and Fraud.

Stay tunned for interesting articles

Tero Pollanen

Some articles about me