World cyber news is online news media.we bought daily hottest news occuring in the world related to cyber.. We propogate news specially related to hacking, technology updates , cyber world updates....
Saturday, September 24, 2011
Statistics and the 'Cyber Crime Epidemic'
According to the recently released Norton Cyber Crime Report for 2011, 431 million adults worldwide were victims of cyber crime last year. The total cost of those crimes amounts to some $114 billion. This precise statement, however, hides an important problem: We actually lack comprehensive data in assessing the true scale and scope of cyber crime. This is because we primarily rely on businesses to voluntarily self-report incidences of attacks and intrusions without any means to verify their statements. To turn the tide in the fight against cyber crime, we first need to know its true impact on the world economy.
William W. Watt once remarked, "Do not put your faith in what statistics say until you have carefully considered what they do not say." In examining the statistical outpouring of data on cyber crime, one should pay special attention to what those statistics do not say. The recently published report, Second Annual Cost of Cyber Crime Study, by the Poneman Institute, a U.S. based information security policy research center, is another good case in point. The report states that "over the past year, the median cost of cyber crime increased by 56 percent and now costs companies an average of $6 million per year." This statistic was compiled using a self-report survey of 50 U.S. based businesses.
The reason businesses routinely under-report incidents of cyber crime is that most information on cyber crime losses are derived from surveys; that is, statisticians merely send questionnaires to companies and hope they are answered in good faith. Businesses have vested self-interests in under-reporting incidents since they either do not want to lose consumer confidence or be held accountable by shareholders or boards. Consequently, the data we collect from such surveys has very low predictive power and cannot serve as a basis for informed policy formulation.
What most people do not realize is that cyber criminals do not have to be too sophisticated to inflict major damage. Cheap malware that can be purchased online often suffices. The real danger to a country's economy arises from advanced persistent threats (APTs) -- highly sophisticated and long-planned intrusions often executed with state sponsorship. Jeffrey Carr, a U.S. based cyber security expert, recently stated that the biggest threat is the theft of intellectual property in high-value technology and energy assets. Here too under-reporting is endemic.
One report claims that U.S. intellectual property theft -- an APT -- costs 750,000 jobs annually, much of which is conducted via cyber space. The validity of this number, however, is questionable since many APT attacks either are not detected or are kept secret for many years. Most companies do not even know that they are under attack, and if they do know, companies are not willing to share data because we lack a trusted identity to collect it.
There are dozens of public- and private-led cyber security data distribution forums in existence already, but the number, scope, and diversity makes for a complex environment where sharing information is very difficult. What is needed is the equivalent to the U.S. Center for Disease Control and Prevention, an umbrella organization coordinating the different activities of forums and which could conduct broad analysis into cyber space. In the United States the National Security Telecommunication Advisory Committee provides a good model for sharing and normalizing threat data that could be generalized to various initiatives from defense, finance, or information-based industries.
Such a new umbrella organization could induce private sector companies to voluntarily provide at least a modicum of raw statistical data about their performance. For example, the data breach reports should be "anonymized," which will, from a business perspective, facilitate sharing. With this minimal data, rudimentary statistics could be compiled and common responses developed. The main focus here should be on data treatment and distribution. Data must be usable and accurate enough to enable action and suppress vulnerabilities in companies.
The significant disconnect within many corporations, where internal security experts are unable to justify increased security methods or spending due to a lack of measured information, presents a grave danger to the well-being of our global economy. Having trusted measures and performance benchmarks will significantly reduce this information gap between security and executive leadership in organizations. It will help formulate more cost effective defense strategies against cyber crime. Better detection rates of attacks, faster responses to incidents, and sounder policy formulations will make companies more secure and consequently more competitive in the global market. As Gordon Gekko stated in Wall Street: "The most valuable commodity I know of is information." This has never been truer than in the age of cyber space.
Cyber crime: Brokerage firm cheated of Rs 2.32 cr
JAIPUR: A city brokerage firm paid dearly for lapses in computer security after someone hacked into its network and defrauded it of Rs 2.32 crore by extending the share purchase limits of four defunct accounts. The hackers then "purchased" the shares of a company listed on the Bombay Stock Exchange (BSE) on alarmingly high prices using the firm's network.
The police with help of cyber crime experts have now tracked some suspects and shot off a letter to the BSE for seizing payment to the seller of the shares. Police suspect the same gang had been involved in defrauding another brokerage firm in Kolkata of Rs 6 crore. One gang member, belonging to Jhunjhunu, has been identified.
According to the police, Rajesh Kumar, representative of the brokerage firm, Navjeevan, operating out of Apex Mall in Ashok Nagar police station area, lodged a complaint saying some unknown persons hacked into its system.
"The hackers' purchased the shares of a company named Clarus at high prices using Navjeevan's software. The sellers of the shares had hiked the price of them and kept purchasing them until it reached the firm's limit of purchase with the BSE," said Hitesh Choudhary, a cyber crime expert helping the police.
He added that on the basis of the computer's IP address used in the purchase and the study of a similar case, one man has been identified.
The complainant Rajesh Kumar told TOI the fraud took place on September 19 and since then he had been constantly trying to get information regarding the share sellers from the BSE, but he did not get any co-operation.
"Instead, they suspended my firm's BSE membership for not depositing the money used in purchase of the shares. I feel completely helpless as the owner of four accounts which were used to purchase shares will obviously not pay the money," Rajesh claimed.
A senior police officer said the money transaction to the sellers' account has been halted after police wrote to the BSE. "An investigation in on," the officer added.
Thursday, August 25, 2011
Curbing cyber crime the CBI-NASSCOM way
BANGALORE: The Data Security Council Of India (DSCI) of NASSCOM has signed an MoU with the CBI with the view to sharing expert services in managing newer challenges in cyber crime and update officials in the latest technology.
�� The understanding seeks to establish collaboration between law enforcement agencies through Cyber and Hi-Tech Crime Investigation and Training (CHCIT) Centre of the CBI and the IT���� industry through DSCI������ and NASSCOM.
�� As part of the MoU NASSCOM-DSCI cyber lab project, level 2 and level 3 advanced cyber crime investigation courses are being conducted, in which police officers from friendly neighbouring countries such as Nepal and Myanmar police attended, and even appreciated the efforts, Pratap Reddy, IGP and senior director of NASSCOM, told Express.
Main objectives of the CBI-NASSCOM MoU
Sharing awareness on:
emerging technonogies, security standards, best practices of global security agencies, challeges in managing cyber crime
�Preparing stakeholders in their ability to educate and update themselves in emerging cyber technologies leading to cyber crime investigation.
�� As part the understanding, the NASSCOM -DSCI had conducted a five day training programme at CBI Academy to seek expert services from the latter in managing newer challenges in cyber crime and updating officials with latest technologies. The MoU also aims to establish collaboration between law enforcement agencies, training centre of the CBI and the����� IT industry through DSCI and NASSCOM.
�� The Cyber Crime Investigation Cell of the CBI has also been designated as a 24/7 contact point for G8 countries. It is also a member of CTINS (Cyber Crime Technology Information Network System), an initiative of National Police Agency, Japan which has tie-up with several countries. The MoU is aimed at enhancing the capabilities of investigating officers and to help cyber crime investigators achieve excellence. CBI has already initiated steps in this direction by providing laptops and cell phones to all its investigators and prosecutors and by providing them training in handling computers. “We are thankful to the NASSCOM for agreeing to sign this MoU with CBI,” director of CBI says in the official website of CBI.
Wednesday, August 24, 2011
Dubai Police warn against cyber criminals
Dubai: People still fall prey to cyber crime despite their knowledge of risks and repeated warnings from police, with 271 cases reported in the first six months of this year, Dubai Police has said.
Complaints filed this year include 110 scams, 108 cases of stolen phone line and 70 cases of blackmail, threatening and libel.
"Although we issue many warnings through various means to inform the public about lottery and free gift scams which are sent to their emails, some still fall for them," Major Rashid Lootah, Director of cyber evidence at Dubai Police's Forensic Evidence and Criminology Department.
When these people are contacted by scammers who inform them that they had won a prize and need to send their account numbers or transfer money as fees to be able to receive the award, many still comply.
"People respond to these scams and then report them after they lose their money and find that they have been tricked," Maj Lootah said.
He also urged BlackBerry users to be aware and not add strangers to BB Messenger, since police received many complaints from people who were blackmailed after someone they added managed to hack their phone and get hold of their personal information and pictures.
"Do not open links that appear when you browse through your BlackBerry, because most of them contain viruses that enable the other party to hack your phone and view all your files and pictures," he said.
Cyber evidence specialists processed 261 cases in the first half of this year, including piracy, theft, dishonesty, harassment, intellectual copyright violations and others.
Other cases include forgery of credit cards and duplicating the websites of some major companies and service providers, which lure people into logging in and making a payment on these websites using their credit card information.
Wednesday, August 17, 2011
Mumbai police now armed with cyber tool kit
The Mumbai Police has become the first police in the state to acquire Cyber Forensic Tool Kits (CFTK).
This Italian technology will speed up the crime investigations and dependency on Kalina Forensic Science Laboratory. This technology was first used in the J Dey murder case.
According to police sources, the crime branch bought three kits for Rs25lakh each in May. They are being used by the cyber crime investigation cell, cyber crime police station at Bandra Kurla Complex and mobile surveillance department of the city crime branch.
"We have seen that terrorist outfits use the latest communication systems. They use technologyinnovatively while sending terror emails, using SAT phones, smart phones and GPS and GIS tools," said a senior ATS official.
"Due to the shortage of cyber forensic equipment, we had to depend heavily on the FSL, which is burdened with several cases. This used to delay gathering of forensic evidence and investigations."
The cyber forensic equipment will make the task easier for policemen and the investigations would speed up.
He added that during the 26/11 terror attacks, terrorists had spoken to their handlers in Pakistan through SAT phones. The Mumbai police had to take help of the FBI to get details of the call records and transcripts.
"Now collection of technical evidences will be quick. This technology was first used in the J Dey murder case while enhancing video image of CCTV footages," the officer said.
Thursday, August 11, 2011
Soap star loses Rs. 2 lakh to ATM hackers
Mumbai: The country's strides in IT-enabled services have had an unfortunate side-effect - the unethical hacking of ATMs.
Its latest victim is Miss India Earth 2002 Reshmi Ghosh, who became popular as Bhumi from Kyunki saas bhi kabhi bahu thi, who had Rs. 2 lakh stolen from her compromised account.
In the past two weeks, more than three police officers and six others have also registered cases with the Oshiwara police complaining that cash has been withdrawn from their Axis Bank accounts by hackers.
The police have registered FIRs in the cases and forwarded them to the Mumbai police's cyber cell.
On July 27, Ghosh's father, Subroto, deposited a cheque in a Kolkata branch of the Axis Bank when he learnt that Rs. 2 lakh had been withdrawn from the account through a debit card.
Following this, Subroto called Reshmi, but the latter denied withdrawing any cash.
Three days before that, Subroto had withdrawn Rs. 15,000 from the account and the balance had stood at around Rs. 4 lakh.
"It is a joint account held by my father and me, and we have two debit cards for it. My father usually takes care of the transactions.
On July 27, my father called me up to ask about a withdrawal to the tune of Rs. 2 lakh over two days. I was shocked. I rushed to the bank's Lokhandwala branch and immediately stopped all payments," Reshmi said
.
On August 6, Reshmi then registered a case of hacking with the Oshiwara police station.
Cops said that when a debit card is swiped, say, in a mall, hackers are tuned in to the mall's machines using high-tech equipment.
They copy the card's details, including the CVV number, and pass them on to duplicate cards and remove money from the account.
Ghosh's debit card was used at different ATMs between July 25 and 26, including those of Bank of Baroda in Santacruz, where transactions have been made seven times, and Standard Chartered in Koparkhairane, where six transactions happened.
"We have registered a case, but tracing the hackers is difficult. We will now check the CCTV footage from the ATMs when the withdrawals occurred.
The cybercrime department is looking into the technical aspect of the hacking," said PI Vijay Kadam of the Oshiwara police station.
A spokesperson for Axis Bank said, "We have received complaints from a few customers that cash has been withdrawn from their accounts from other banks' ATMs.
While we are investigating these complaints, we would like to inform that on August 1, Axis Bank filed an FIR with the cyber cell police station at Crawford Market about the discovery of an extraneous device attached to one of its offsite ATMs in Mumbai during a routine examination.
We are providing necessary assistance to the investigating agency. Also, we will try to compensate our customers and reimburse the loss they have suffered."
Ghosh has also acted in TV serials Kahe Naa Kahe and Karam Apnaa Apnaa and participated in the dance reality show Nach Baliye 4.
Saturday, August 06, 2011
Techie sends lewd SMSs, held
The accused, Harihara Kumar, 25, of Ramanthapur is a network administrator at an IT firm at Gachibowli. On June 2, the victim, who is Kumar's close relative, complained to the cyber police that she, her friends and family members were receiving abusive emails and SMSs from anonymous persons.
The police obtained email log data, and mobile phone SMS data of the accused from the service providers. As he used SIM cards obtained on fake ID proofs, they found it difficult to track him down. Finally, after questioning several people, they arrested him on Thursday. Police said he bore a grudge against the victim, an engineering student, as she had rejected his marriage proposal.
He hacked into her mail account and created a fake Facebook account in her name and started maligning her character. The court remanded him in judicial custody.
Wednesday, August 03, 2011
City phishing cases traced to Mumbai
They have also proved that the ‘phishing mafia’ is not directly using their e-accounts but is using accounts of others on commission basis.
A CID official of the SP’s rank said that this is a dangerous trend because many such ‘phishing cases’ reported in Bangalore are being traced to Mumbai. “We suspect there could be a mafia which runs anti-social activities after availing money by doing these types of hi tech-robbery,” he added.
The Cyber Crime Police Station (CCPS) registered around 100 such phishing cases in 2009, but for them it is very difficult to trace the accused as they are using benami bank accounts, sources said. Now the CCPS has succeeded in arresting three persons, all from Mumbai in connection with some cases. The police also said that the accused are graduates with the knowledge of computer. The investigations are still on.
Case 1 The cyber police arrested one Abdul Khan Khair (28) from Halav Pool Kurla West Mumbai on Wednesday.
Exactly two years ago, (July 25, 2009) he did phishing on behalf of one Feroze of Rs 1 lakh. He transferred Rs 1 Lakh (Rs 50,000 twice) from the ICICI account of one IT professional Abhishek Malviya, a native of Itarsi, Madhya Pradesh. Malviya, after checking with the ICICI bank, got to know that the money was transferred to the accounts of Atul Javed Khan and Manojkumar Solanki.
Police suspect that the two names are benami and the accused who transferred the money from Malviya’s account through internet banking is Abdul Khan Khair.
Khan told the interrogators that he did this internet fraud as suggested by one Feroze for availing commission amount from the latter, police detailed.
Case 2 The CCPS sleuths arrested one Syed Mohemmed Kafil (27) of Naupada, Bandra West of Maharastra. He was arrested in a case on July 17 which was registered on August 31 of 2009 by an IT professional Babuprasad Chakravarty, an employee with a BPO run by Infosys company. An amount of Rs 30,000 from his ICICI savings bank account was transferred to another account.
When he checked with the bank, they told the money was transferred to an account at Mumbai.
The cyber police have now traced the accused to Mumbai and arrested him, police said.
Case 3 Pratik (25) was arrested from his native Bhayandar of Mumbai on July 17. He had transferred Rs 75,000 through ‘phishing’ from the ICICI account of BS Gurudev, an employee with an IT firm in Indiranagar on August 20, 2009. The money was transferred four times from his account to the account of the accused on the same day, police said.
Friday, July 29, 2011
35m Cyworld, Nate users' information hacked

SK Communications Co. said on Thursday that personal information of its 35 million online users has been hacked, marking South Korea's worst online security breach and sparking fears that the leak could lead to massive online and voice scams in coming weeks.
"The company has confirmed that a leak of customers' information has taken place due to hacking on July 26," SK said in a statement. "The specific scale of the hacking is still being investigated, but it is estimated that some of the personal information of 35 million Nate and Cyworld members have been leaked."
Nate is the country's third-most visited Web search engine and Cyworld is the biggest social networking site with 25 million users, which accounts for half of the South Korean population.
SK Communications, which runs Nate and Cyworld, is a unit of the SK Group whose affiliates include top mobile operator SK Telecom.
Police said they would launch an investigation into the hacking incident at SK. The Cyber Terror Response Center, a police division dealing with crimes in cyberspace, is expected to identify who committed the hacking.
SK Communications said the hacking originated from a malicious code in China, an allegation that has yet to be verified by police investigation.
The hacking of the country's major website comes after a host of Korean online firms suffered from similar cyber attacks amid heightened worries over lack of security protection. A vicious cyber attack paralyzed the computer system of the National Agricultural Cooperative Federation, or Nonghyup, in April and 18 million users of Internet Auction Co., a unit of U.S.-based eBay Inc. had to change their password due to a security breach in 2008.
The latest hacking involves SK users' names, phone numbers, email, resident registration numbers and passwords. SK Communications said the members' password and resident registration numbers are protected through high-level encryption, but plan to set up a hotline for handling the hacking incident to stem secondary damage in the form of voice phishing and spam mail.
As with previous hacking incidents, Cyworld and Nate members are likely to receive more spam messages or fake calls from phishing firms.
SK Communications CEO Joo Hyung-chul issued a formal apology on Thursday: "Concerning this incident, we offer our apology to our customers and have taken all the necessary measures to minimize the impact and identify the cause and retrieve customer information in cooperation with the authorities."
Particularly worrisome is the security breach for Cyworld, the country's most popular social network service, a pioneer that had sparked the boom of photo-sharing among friends and family members. Although Cyworld has seen its popularity decline in the past couple of years, particularly with the introduction of foreign social services such as Twitter and Facebook, the local service still handles a huge amount of data including personal photos, videos and articles generated by its 25 million users.
Nate is a latecomer in the portal service market, but it has risen to rank third here, intensifying its competition with its bigger rivals Naver and Daum. The hacking of Cyworld and Nate, considering the size of the subscriber base at both services and their close integration with mobile phone services of SK Telecom, is expected to have a strong impact on the companies involved.
Shares of SK Communications, listed on the tech-heavy KOSDAQ stock market, plunged 5.95 percent to 17,400 won. Its sister firm SK Telecom saw its share price drop 2.64 percent to close at 147,500 won.