ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Hackers steal one million credit cards

Will Knight ZDNet.co.uk

Published: 09 Mar 2001 12:53 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Computer hackers based in Eastern Europe have carried out a year-long crime spree cracking scores of online banks and stealing more than a million credit card details, according to FBI computer experts.

More than 40 e-banking and e-commerce sites have been targeted and compromised by teams of Russian and Ukrainian hackers, said experts at the FBI's SANS (System Administration, Networking, and Security) Institute on Thursday.

The hackers are highly organised and interested in more than a few illegal credit card transactions. According to the FBI, many of the victim Web sites were blackmailed by the hackers, who threatened to reveal details of their exploits and use stolen credit card details if a ransom was not paid. Federal investigators also exposed details of protection rackets operated by these hackers, were companies were assured they would not suffer a potentially costly and damaging break-in in return for a fee.

Security analyst at Information Risk Management, Richard Stagg, said the development is worrying. "There's a trend emerging in Eastern Europe to get in touch with companies and say, 'wouldn't it be a shame if you got hacked'. It's like the East End protection rackets of the 60's."

Stagg said the cost of such attacks is likely to be spread between retailers, credit card companies and consumers, but believes that the damage done to consumer confidence may ultimately be more serious. "In the end you have a loss confidence and people saying that they don't want to buy online anymore."

The Eastern European computer criminals are thought to have relied on well-known weaknesses in Microsoft's Window's NT operating system to carry out the crime spree. The FBI believes that the break-ins represent such a major threat that they have released details of the exploits as well as tools for counteracting them.

"The FBI and Secret Service are taking the unprecedented step of releasing detailed forensic information from ongoing investigations because of the importance of the attacks," said Alan Paller, director of research at the SANS Institute in a statement.

The FBI's National Infrastructure Protection Centre (NIPC) has investigated into a boom in European computer crime in recent months. It says that four major vulnerabilities affecting Windows NT have spawned the increase.

The first is a bug that allows a user to take control of Microsoft's ISS Web server, another allows Microsoft's SQL database software to be compromised and a further two give a hacker to opportunity to take control of a Windows NT machine itself.

Take me to Hackers

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
61 out of 117 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:













Related Jobs

NT/CITRIX SYSTEMS ENGINEER - FINANCIAL TRADING COMPANY - C.LONDON

An experienced NT Systems Engineer with extensive experience of Windows Administration, Citrix, Exchange and Active Directory is required to join a ...

AS400\\ iSeries\\ NT Windows Support Analyst: Hetfordshire

Role will involve supporting users across NT and AS400 platforms. As400. Computer Futures' As400 team are seeking An iSeries support analyst for end ...

IT Manager - hands on - Leics - Up to 30,000

The role will be providing all IT support to 2 Leicestershire based sites covering hardware and software installation and maintenance, maintenance of ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation