Cybercrime fight hurt by apathy, law enforcement hurdles

By Michael Cooney, Network World |  Security Add a new comment

General public apathy and collaboration with the law enforcement community assure that cybercrimes of all sorts will continue to rise.

That was one of the conclusions from a congressional hearing this week called "Hacked Off: Helping Law Enforcement Protect Private Financial Information."

A big problem we are facing in the fight against financial crimes is that the criminal complaint has almost disappeared. Even when a police report is filed, it is often "so the bank will give you your money back. Case closed," said Gary Warner, director of research in computer forensics with the University of Alabama at Birmingham.

MORE SECURITY NEWS: Despite controversy, federal, state wiretaps on the rise

"The understandable hesitation of law enforcement to 'work a case' in these areas has led to an unfortunate form of apathy by the consumer as well as the financial institutions. Large banks lose millions of dollars each year to phishing and malware, but they reimburse the cost to customers and structure the losses into the cost of doing business. Consumers have been trained that if they experience financial losses they should contact their financial institution rather than the police. If they have had their money returned by their financial institution, there is little incentive to share that information with law enforcement," Warner stated.

These activities make it less likely consumers will ever report their victimization in a way that lets intelligence-driven policing Internet crimes occur. "Without a mechanism to gather basic complaint data into a data mine, it becomes very difficult to understand the scope and nature of the crimes we are facing," Warner testified.

Warner added: "Website owners hosting their small business and personal websites in the United States, have had their servers hacked for use by phishing criminals more than 40,000 times so far in 2011. At the present time, I am unaware of a single situation where the hacker was arrested. Because of the experience of the crime 'going overseas' many law enforcement officers are hesitant to take these cases and local law enforcement officers question whether it is even appropriate for them to be involved in a case that is potentially international."

Warner noted that the Federal Trade Commission (FTC) collects consumer complaints from a large number of sources, including the Internet Crime and Complaint Center, the Better Business Bureau, the U.S. Postal Inspection Service, and many state attorney general's offices.

"But there is still an enormous amount of unreported crime. The most recent FTC Consumer Sentinel Report indicates 1.3 million complaints were received from consumers, however the best estimates indicate that there are now more than 11 million identity theft victims per year in the United States. One of the challenges is how to make sure these additional victims can have the crimes against them documented. If even the minor cases are documented properly, data mining of the complaint data can lead to significant cases being brought by linking the smaller cases together," he stated.

It is often the case that while portions of the crime may go overseas, parties to the conspiracy are located in the United States. Many financial cybercriminals have found it is easier to work with U.S.-based accomplices to remove money from bank accounts. The most common method of doing so is to recruit a "money mule" to receive the stolen funds into an established local bank account.


Originally published on Network World |  Click here to read the original story.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question