Neil Barrett
Neil Barrett

Why online crime never pays

Even the smartest cyber criminals can be caught by old-fashioned police work

Written by Neil Barrett

According to the National Hi-Tech Crime Unit, growing numbers of hackers are finding increasingly sophisticated ways to make money out of vulnerable computer systems.

First it was the distributed denial-of-service (DDoS) attacks against online bookies, for extortion campaigns. The bookies would be knocked off the internet for a time and then threatened with further attacks at regular intervals - especially before important football matches or big races - unless they paid "protection money".

I first saw these attacks several years ago in Hong Kong, was briefed by the NHTCU on the events and then watched in amazement as the "cyber-detectives" managed not only to track the criminals, but to arrest and prosecute them.

Now, though, the criminals have apparently shifted their attention elsewhere. They are targeting other organisations - hacking into systems and launching DDoS attacks, before making demands. No major business in our modern world is proof against attacks such as these; the more we use the internet the more we come to rely upon it and the greater our vulnerabilities. And criminals are good at exploiting vulnerabilities.

DDoS attacks are very effective for attacking computers. Using possibly hundreds of zombie systems, scattered throughout the internet, they make it all but impossible to identify the original source of the attack. One single hacker can work from anywhere - even a hijacked wireless LAN connection - to mount the attack; and with a wide range of more powerful systems under their control, they can do their work with only a small laptop. The hijacked LAN might not retain any records; the zombie systems might not contain records - and with some forms of DDoS there might not even be a trace back to those zombies. From the criminal's perspective, it is a perfect crime, safe from observation.

But the NHTCU has shown that these criminals are not entirely untraceable and can be caught and prosecuted. How? Well, by good old-fashioned police work. The internet connection might be hard to trace, but if the criminals wish to profit from the attack they need some way of obtaining the money - and as in all ransom or extortion demands, it's in the payment, the collection and the disposal of the money that the criminal is at their most vulnerable.

The NHTCU caught the eastern European extortionists not by following their IP trail, but by following the money - tracking the flow of currency from account to account in a painstaking exercise using the most methodical of detective skills. And when the detectives caught up with the money, they caught up with the criminals.

So, the moral of the story is: to be a master criminal on the internet, you don't just need to understand the internet, hacking and TCP/IP masquerade; you must also know about money. So many hackers and crooks have been caught over the years because of their carelessness with cash - whether they were teenage hackers arousing suspicion by a sudden ownership of a top-of-the-range skateboard, or organised criminals. So if you want to succeed, study the finance issues as hard as the technical ones.

See what other readers are saying in our Letters blog and add your own comments instantly.

Tags:

reader comments

related articles

Neil Barrett

Treat digital evidence with care

Firms need good practices to deal with evidence or the culprits will escape 17 Feb 2005

 

Access of evil has many faces

Most online scams are laughably crude, but they could be a lot more devious 04 Nov 2004

Colombian cyber-crook jailed for nine years

Man guilty of $1.4m fraud 14 Apr 2008

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation