Advertisement
Promo

Online business Toolkit

Thousands of companies are paying off online extortionists

Dan Ilet ZDNet.co.uk

Published: 08 Oct 2004 14:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Alan Paller, director of research for security organisation SANS, said today that online extortion was rife and that cybercrime was set to get worse.

"Six or seven thousand organisations are paying online extortion demands," said Paller on Friday at the SANS Institute's Top 20 Vulnerabilities conference. "The epidemic of cybercrime is growing. You don't hear much about it because it's extortion and people feel embarrassed to talk about it."

"Every online gambling site is paying extortion," Paller claimed. "Hackers use DDoS [distributed denial-of-service] attacks using botnets to do it. Then they say 'pay us $40,000 or we'll do it again'."

Paller added he was concerned that the same techniques used for extortion -- i.e. DDoS attacks -- could easily be used to target organisations in the critical national infrastructure (CNI).

The director of the National Infrastructure Security Co-ordination Centre, Roger Cumming, shared Paller's concern.

"There's an enormous amount of extortion," said Cumming. "We are concerned about the technologies of extracting money could be used to endanger the CNI. One of the things we are talking about is how to mitigate that threat."

Paller called for vendors raise their game -- he said that security vulnerabilities were their responsibility to fix and that their products should comply with the SANS top 20 vulnerabilities.

"Applications breaking after patching is the operating system vendor's fault," he said. "They tell developers to build applications on unprotected systems. But the other half of the game is that application vendors should have to test their products on safer systems – you do that with procurement."

A spokesman for at least one prominent UK gambling site said that he would rather not comment on the whole issue.

The SANS conference is taking place at the Department of Trade and Industry today.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
91 out of 176 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Sentry Posts Blog

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment

Nokia Siemens denies Iran web snoop

Nokia Siemens has denied providing deep packet inspection capabilities to the Iranian authorities, following an article in the Wall Street Journal on Monday. The WSJ published the... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of the Google Chrome launch

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters