Forensic Update

Reflections on information management within the legal and regulatory arena

  • Follow @ForensicUpdate

    Follow @ForensicUpdate
  • Follow on Linked In

    Follow @ Linked In
  • Recent Tweets

  • Enter your email address to subscribe to this blog and receive notifications of new posts by email.

    Join 45 other subscribers

Archive for the ‘Information Security’ Category

Today’s #GoodGuysPrevail Update…

Posted by Johnny Lee on February 5, 2024

In mid-December 2023, Microsoft took drastic action against a known #cybercrime gang known as #Storm1152. Like so many criminal gangs, this group has commoditized its “offering” to facilitate other criminals in their online efforts to infiltrate and harm companies and individuals globally.

More specifically, Microsoft obtained a court order from the Southern District of New York, allowing it to seize the U.S.-based infrastructure used by the criminal outfit. Microsoft estimates that this infrastructure supported the creation of approximately 750 million fraudulent websites and accounts – enabling in turn, an untold number of ransomware, data theft, extortion, CAPTCHA-avoidance gambits – as well as other generalized scumbag behavior.

This infrastructure seizure is a major victory, as it degrades a significant attack vector faced by countless cyber defenders – the world over. Kudos to the investigative teams at Microsoft. With luck, their referral to #lawenforcement will net some arrests and convictions in the months ahead.

#cybercrime #AisA #karma #justice #extortion #ransomware #digitalforensics #cyberattack #forensicinvestigation #accounttakeover #fraud #fraudinvestigations #criminalinvestigation

Posted in Computer Forensics, cryptocurrency, CyberSecurity, Data Breach, Fraud, Information Security, Investigations, Privacy, ransomware | Comments Off on Today’s #GoodGuysPrevail Update…

Today’s #GoodGuysPrevail Update…

Posted by Johnny Lee on October 26, 2023

Late last week, Europol confirmed that it had seized and shut down the infrastructure of the notorious #RagnarLocker ransomware group. The agency also confirmed that it had arrested a 35-year-old man in Paris earlier this month, alleged to be the ringleader of the criminal gang.

Equipment and infrastructure was seized in numerous European countries in the coordinated take-down sting. The criminal gang, commonly linked to Russia, has targeted organizations since 2020 – including at least 52 U.S. entities across 10 critical infrastructure sectors, according to reports from the Federal Bureau of Investigation (FBI).

The thieves have attacked and extorted from nearly 170 different companies across Europe and the U.S., demanding between $5-70M per ransom scheme. Kudos to the international #lawenforcement teams that brought this group down – at least temporarily, including the Atlanta Field Office of the FBI.

0

#ransomware #cybercrime #AisA #justice #karma #cyberscam #dataexfiltration #extortion #ransom #bribery #internetmafia #digitalforensics #databreach #incidentresponse

Posted in Computer Forensics, CyberSecurity, Data Breach, Fraud, Information Security, Investigations, Privacy, ransomware | Tagged: , , , | Comments Off on Today’s #GoodGuysPrevail Update…

Today’s #GoodGuysPrevail Update…

Posted by Johnny Lee on August 29, 2023

INTERPOL recently dismantled a Phishing-as-a-Service platform used by over 70,000 individuals. The platform (16shop) came down at the culmination of a global investigation by the international #lawenforcement cooperative.

The take-down is significant for manifold reasons. Not only was this a “user-friendly” platform (allowing malign users to launch a #phishing attack with a few clicks), but it fostered a wide variety of for-hire criminal #hacking tools since late 2017. Interpol estimates that over 150k phishing domains were created via 16shop toolkits.

While the arrests focused on suspects based in Asia, the servers used by the platform were hosted in the U.S. This is a significant victory for the good guys, as the ability to automate cyberattacks of this kind is very dangerous.

#ransomware #cyberattacks #cybercrime #databreach #credentialtheft #AisA #infosec #cybersecurity

Posted in Computer Forensics, CyberSecurity, Data Breach, Fraud, Information Security, Investigations, Privacy, ransomware | Tagged: | Comments Off on Today’s #GoodGuysPrevail Update…

Today’s #GoodGuysPrevail Update…

Posted by Johnny Lee on July 13, 2023

The U.S. Department of Justice has announced an unprecedented indictment against an individual committing #fraud by attacking a #smartcontract on a #decentralizedexchange.

Employing many of the traditional tools of #financialcrime investigations and #digitalasset tracing, the #SDNY brought this novel case – in conjunction with international #lawenforcement.

#fraudinvestigations #cryptoccrime #digitalforensics #karma #AisA #digitalassets #crypoassets #cybercrime #cyberattack

Posted in Computer Forensics, cryptocurrency, CyberSecurity, Data Breach, Digital Assets, Forensic Accounting, Fraud, Information Security, Investigations, Privacy | Comments Off on Today’s #GoodGuysPrevail Update…

Today’s #GoodGuysPrevail Update…

Posted by Johnny Lee on March 15, 2023

International #lawenforcement have arrested two individuals, believed to be core members of the odious #DoppelPaymer crime gang. For those who can’t keep all of these gangs straight, this is the group that shut down the University Hospital in Düsseldorf, employing the equally odious #emotet #malware.

The DoppelPaymer group victimized dozens of companies over several years. The US-based victims alone were extorted out of nearly €40M.

Kudos to the diligent #digitalforensic and #lawenforcement collaboration required to perform the attribution and tracing efforts that led to these arrests. Among those involved were the German Regional Police, the Ukrainian National Police, Europol, the Dutch Police, and the United States Federal Bureau of Investigation (FBI).

With any luck, the materials seized during these raids will lead to even more arrests!

0

#ransomware #cybercrime #forensicinvestigation #ruleoflaw #AisA #digitalanalytics #extortion #criminallaw #cyberattack #cyberrisk

Posted in Computer Forensics, cryptocurrency, CyberSecurity, Data Breach, Digital Assets, eDiscovery, Forensic Accounting, Fraud, Information Security, Investigations | Tagged: | Comments Off on Today’s #GoodGuysPrevail Update…

Today’s #GoodGuysPrevail Update…

Posted by Johnny Lee on August 14, 2022

The U.S. Department of Justice recently extradited the alleged operator of illegal cryptocurrency exchange #BTCe. This extradition is the culmination of over 5 years of litigation, and the 2017 indictment states that the BTC-e exchange ostensibly laundered over $4 billion (USD) in criminal proceeds.

Like other exchanges that have been sanctioned and/or shut down in recent years, BTC-e enabled users to anonymously trade bitcoin, allowing them to cash out proceeds from various #ransomware#identitytheft#drugtrafficking, and #taxrefund schemes. Defendant Alexander Vinnik, a Russian national, made his first appearance in federal court last week in San Francisco.

In addition to facing criminal charges, Vinnik also faces Dept of the Treasury/Financial Crimes Enforcement Network civil money penalties for: failing to have an #AML process or program; failing to register as a money services business with the U.S. Department of the Treasury, and failing to have a system for appropriate #KYC verification. The 2017 #FinCEN civil money penalty assessment was for $88.6M USD for BTC-e and $12M USD for Vinnik personally.

This extradition marks another milestone for the DoJ’s ongoing efforts to collaborate with international #lawenforcement and to disrupt organized #cybercrime#Kudos to both American and Greek law enforcement for a remarkable coup in bringing this saga to its final chapter. Plaudits also belong to the Federal Bureau of Investigation (FBI), the IRS Criminal Investigation division, U.S. Department of Homeland Security, and the U.S. Secret Service for their roles.

#AisA #ruleoflaw #justice #digitalforensics #forensicinvestigation #cryptocrime #digitalassets #fraudinvestigations #cryptoassets #digitalassettracing #digitalassetrecovery #forensicaccounting #karma #cryptocurrency

Posted in Computer Forensics, cryptocurrency, CyberSecurity, Data Breach, Digital Assets, Forensic Accounting, Fraud, Information Security, Investigations, Privacy, ransomware | Comments Off on Today’s #GoodGuysPrevail Update…

Today’s #GoodGuysPrevail Update…

Posted by Johnny Lee on August 8, 2022

The U.S. Department of Justice recently charged six defendants in four separate crypto-related fraud cases:

  • the largest known #NFT scheme charged to date;
  • a global #Ponzi scheme involving unregistered securities;
  • a fraudulent #ICO; and
  • a fraudulent investment fund.

Like prior #GGP updates, these cases reflect the herculean efforts of coordinated #lawenforcement and #digitalforensic efforts. Kudos to the Federal Bureau of Investigation (FBI), the United States Attorneys’​ Offices, the Department of Homeland Security, Office of Inspector General.

If you believe that you are a victim of the Baller Ape Club, EmpiresX, TBIS, and Circle Society schemes, please visit the DOJ website for details on how to submit your “Victim Impact Statement” (and thereby register as a victim).

#ruleoflaw #fraudinvestigations #cybercrime #cryptoassets #digitalassettracing #digitalassetrecovery #forensicinvestigation #forensicaccounting #karma #AisA #digitalassets

Posted in Computer Forensics, cryptocurrency, Digital Assets, eDiscovery, Forensic Accounting, Information Security, Investigations, Privacy | Tagged: | Comments Off on Today’s #GoodGuysPrevail Update…

Today’s #GoodGuysPrevail Update…

Posted by Johnny Lee on August 4, 2022

The U.S. Department of Justice seized assets worth $500k USD from North Korean hackers targeting U.S.-based #healthcare organizations. The seized North Korean assets were either monies directly extorted from companies or monies used in laundering #ransomware payments.

In addition to the general #karma of this action, there was an object lesson about public-private sector collaborations as well. The prompt reporting by one healthcare victim allowed the Federal Bureau of Investigation (FBI) to identify a new strand of North Korean ransomware.

Of course, $500k is a pittance compared against the hundreds of millions of dollars stolen by North Korean cyber actors in recent years. Just the same, it’s important to trumpet the “wins” wherever we can find them.

justice #cyberfraud #statesponsored #northkorea #digitalforensics #lawenforcement #ruleoflaw #forensicinvestigation #cyber

Posted in Computer Forensics, cryptocurrency, CyberSecurity, Data Breach, Fraud, Information Security, Privacy, ransomware | Comments Off on Today’s #GoodGuysPrevail Update…

Today’s #GoodGuysPrevail Update…

Posted by Johnny Lee on April 13, 2022

While the use of the verb “forfeit” in the headline of this story may seem confusing, it’s a GREAT turn of events. Simply put, U.S. Department of Justice, Criminal Division prosecutors in the Southern District of Florida have secured one of the largest #cryptocurrency #forfeiture actions ever filed in this country.

0

This story really resonates with me, as it represents a rather elegant intersection of #cyber and #crypto. The forfeiture action netted about $34M in cryptocurrency, all tied to the illegal #darkweb activity of a South Florida resident — specifically, the sale of online account credentials.

Of additional interest is the method by which this case was brought. In yet another example of inter-agency collaboration among federal, state, and local #lawenforcement, the investigators “followed the money” through a tortuous path, owing to the target’s use of cryptocurrency “tumblers”, “chain hopping”, and other (failed) #moneylaundering techniques.

Kudos to the Internal Revenue Service‘s Criminal Investigation group, the Federal Bureau of Investigation (FBI), the U.S. Department of Homeland Security, the United States Postal Service Inspection Service, and the Drug Enforcement Administration for its combined investigative efforts here.

#ruleoflaw #digitalforensics #digitalassets #assettracing #assetrecovery #forensicinvestigation #justice #karma #AisA

Posted in Computer Forensics, CyberSecurity, Data Breach, eDiscovery, Forensic Accounting, Fraud, Information Security, Investigations | Comments Off on Today’s #GoodGuysPrevail Update…

Today’s #GoodGuysPrevail Update…

Posted by Johnny Lee on March 17, 2022

A mere 8 months after his (alleged) involvement in the Kaseya #ransomware attacks, a Ukrainian national has been extradited to the United States and been formally indicted in a Dallas courtroom. This is the way…

0

#ruleoflaw #justice #revil #cybercrime #fraud #extortion #lawenforcement #cyberfraud #digitalforensics #dfir #incidentresponse #cybersecurity #crimedoesntpay

Posted in Computer Forensics, CyberSecurity, Data Breach, Information Security, Investigations, Privacy | Comments Off on Today’s #GoodGuysPrevail Update…