Security

The Business Of Fraud

Comment

Image Credits: wk1003mike (opens in a new window) / Shutterstock (opens in a new window)

Steve Jillings

Contributor

Steve Jillings is the CEO of TeleSign.

When you visualize a hacker, what do you see?

Do you envision a young computer enthusiast coding in their basement, pounding Red Bull? A futuristic robot plugged into hundreds of servers deep inside a secret warehouse in the desert? A person from another country sporting a shaved head, smoking a cigarette, banging away on their keyboard? Chris Hemsworth from the movie Blackhat? Okay, that last one might be a stretch…

As this question crossed your mind, chances are you didn’t picture a global executive working for a well-organized business, complete with a high-tech infrastructure and employees and partners all working together with a common goal of achieving the best ROI (return on investment) possible?

Over the past decade, hackers have evolved beyond the individual hobbyists once portrayed in popular movies. Today, they collectively operate as both competing and collaborating global businesses supported by a full-blown cybercrime supply chain capable of generating billions of dollars annually. It is this hardcore business-like mentality driven through finely tuned enterprise-like operations that has allowed the hacker community to perpetrate many of the massive, record-breaking data breaches we’ve seen in the headlines over the past few years.

Their success in stealing billions of dollars and countless records from some of the world’s largest brands could suggest that the top hackers are demonstrating what’s possible. Or, their success could suggest that the best in the world are those whose methods remain undetected, unreported. Either way, the lure of big (“easy”) money has sent the business of fraud booming and cybersecurity professionals around the world scrambling to keep from crumbling under the pressure of pending doom.

With so many types of specialized hackers taking to their keyboards to exploit a growing number of unknown, undisclosed and unpatched vulnerabilities, fighting back against the hackers can feel like a never-ending uphill battle. Whether or not the cybersecurity professionals can win this battle has yet to be seen, though one thing has become abundantly clear — if we are to dismantle this massive fraud network, we must first understand how it all works.

The Product

Before the outbreak of big data breaches that have captured national and global attention, common sentiment about hackers was they were just seeking credit card data which they could either use themselves to buy stuff or sell to the highest bidder on the black market so they could buy stuff. While these two methods remain a major aspect of the business of fraud, it is clear that there is also a ton of value in the other data being accessed via these same attacks, namely account credentials.

Once an attacker gains access to a victim’s account credentials, he can typically see all of the sensitive data stored inside the victim’s account, including user name and address, phone, email, account details, methods of payment, financial and business contracts, intellectual property and more. This data is ripe for the picking — it just needs to be harvested, packaged, priced, sold and supported.

The Business

Maximizing profits is the focus of just about every business, and this is no different in the business of fraud. For today’s fraud business, achieving a positive ROI means focusing efforts on building efficiencies of scale that can return consistent results with minimal effort and money.

While there are some groups that aim for the big scores, these are few and far between. More often, these businesses will go after large groups of valuable account credentials, which can provide access to all sorts of information across the Internet: email accounts, social media accounts, mortgage accounts, tax portals, enterprise business systems, partner portals and more.

Who Will Buy The Data?

The initial compromise and extraction of credentials is just the start. This information isn’t always used by the people who originally performed the hacks and obtained the data. Rather, other hackers buy the information as a means to extract other valuable data from the individual or business, with the primary goal of making a quick buck. Different buyers have different skills and will focus on acquiring the data that will be of most value to them.

By and large, the transactions surrounding the stolen data are handled through deep web hacker forums dedicated to the listing and sale of this information. There are far too many of these black market sites to list, and they change all the time.

Suffice to say, the sellers know where to list their data and the buyers know how to get their hands on the information most valuable to them from the most reputable sources possible. Funny enough, the business of fraud is one driven by reputation. The better the data offered, the more repeat sales will be seen, coupled with higher prices.

What Will They Pay For It?

Prices fluctuate based on a variety of variables. This breakdown of the different costs of items stolen by hackers gives a clear picture of what is most valuable in today’s world of fraud:

image005

Based on these figures, one thing has become evident: It is more important to protect your email account than it is to secure your credit card. Why? Because if your email account is compromised, there is so much more at risk versus a credit card. Think of all the items contained in your email account; for example, if you’ve ever sent a loan application by email, it has everything needed to open new credit accounts, get loans and create false identities. It is the gateway to fraud, and can create personal online destruction if not protected.

The Supply Chain

Obtaining the credentials is only the first step. As with most goods sold, they have to make their way through the supply chain before reaching the end consumer. This is where the cybercriminal supply chain comes into play. While the system can certainly be much more complex than is described below, when it comes to the business of fraud, there are typically four main types of hackers who each have their own specialties.

First, there are the hackers who specialize in acquiring the credentials. They will look for easy prey, oftentimes a third-party vendor that does business with the real target from whom they want to extract data. They will research these targets, probing high and low for vulnerabilities in their networks that can be exploited in order to steal the troves of valuable credentials. Techniques by these hackers vary, from phishing scams to social engineering and more, but the road to success is always reliant on taking advantage of system and human weaknesses wherever they can be found.

Second, there are the hackers who focus on selling the stolen credentials. This is done primarily through online hacker forums. These forums set the prices according to the value and longevity of the credentials and ads posted anonymously.

Next, there are the hackers who use the credentials to gain access to the consumable goods: credit card numbers, personally identifiable information, intellectual property, business contracts and more.

Of course, there are the hackers who specialize in using the stolen information. They search unique ways to bypass fraud monitors that would otherwise block their use of information they’ve acquired. In the case of a stolen credit card number, this means utilizing the card details to purchase goods online that they can later sell. They will often lure unsuspecting people to serve as middlemen, getting them to agree (through payment or blackmail) to accept goods on their behalf, then forward them to the hackers so they can avoid detection for the crime.

Beyond the hackers and the end consumers of the stolen data, you’ll find a lot of people and organizations not directly involved in the hack but who indirectly support the hackers — sometimes unbeknownst to them. Whether advertising on hacker forums or establishing private networks for hackers to communicate and interact, they too are making some serious money just by being part of this “ecosystem.”

The Future

The business of fraud continues to grow and evolve every day. Companies continue to innovate and deliver new technologies that require credentials, and hackers continue to find these new platforms to exploit using new techniques to profit from the information they steal through the compromised credentials.

Sure, there are ways to protect user credentials so their accounts are safe, but individuals and companies fail miserably to follow the best practices and employ the appropriate technologies in the places that matter most — email for example. One effective and proven method to protect accounts is to turn on two-factor authentication wherever it is available. If it’s not clear how and where this can be accomplished, you can gain an initial view of how it can be applied to the most common web properties at www.turnon2fa.com.

Startling Growth In Mobile Fraud

Stolen credit cards on mobile devices are becoming harder to track, and mobile e-commerce fraud is affecting enterprises around the world — to the tune of billions of dollars annually.

But it’s not just about credit cards; mobile devices are home to a number of personal and business applications, many of which have access to sensitive, private or otherwise confidential information. With 19 percent of companies surveyed by TeleSign reporting that up to half of their fraud incidents were due to mobile, it’s clear this environment provides for a nice landscape for credential harvesting. And, given 1 in 4 business currently lack a requirement for log-in identification for mobile users, there is tremendous room for improvement.

Is There Hope?

Many businesses and groups are beginning to make big strides in developing new systems and techniques to block hackers in the places they work most. Governments are also taking steps to better assist their citizens on the wild frontier of the Internet. As two examples, the United States recently instituted a cybersecurity sprint to address vulnerabilities in key networks, and the U.K. is in the process of installing new regulations to better protect the financial sector and their customers.

These measures, while demonstrating a desire to tackle fraud, represent only one step of many that must be pursued with constant attention. Hackers have shown they have the upper hand and are adept at evolving to stay ahead of the security professionals. And, at the end of the day, the business of fraud will continue to develop. It is on all of us, as individuals, groups and organizations, to do our part in protecting ourselves and building a better, safer online experience for all.

More TechCrunch

The Series C funding, which brings its total raise to around $95 million, will go toward mass production of the startup’s inaugural products

AI chip startup DEEPX secures $80M Series C at a $529M valuation 

A dust-up between Evolve Bank & Trust, Mercury and Synapse has led TabaPay to abandon its acquisition plans of troubled banking-as-a-service startup Synapse.

Infighting among fintech players has caused TabaPay to ‘pull out’ from buying bankrupt Synapse

The problem is not the media, but the message.

Apple’s ‘Crush’ ad is disgusting

The Twitter for Android client was “a demo app that Google had created and gave to us,” says Particle co-founder and ex-Twitter employee Sara Beykpour.

Google built some of the first social apps for Android, including Twitter and others

WhatsApp is updating its mobile apps for a fresh and more streamlined look, while also introducing a new “darker dark mode,” the company announced on Thursday. The messaging app says…

WhatsApp’s latest update streamlines navigation and adds a ‘darker dark mode’

Plinky lets you solve the problem of saving and organizing links from anywhere with a focus on simplicity and customization.

Plinky is an app for you to collect and organize links easily

The keynote kicks off at 10 a.m. PT on Tuesday and will offer glimpses into the latest versions of Android, Wear OS and Android TV.

Google I/O 2024: How to watch

For cancer patients, medicines administered in clinical trials can help save or extend lives. But despite thousands of trials in the United States each year, only 3% to 5% of…

Triomics raises $15M Series A to automate cancer clinical trials matching

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Tap, tap.…

Tesla drives Luminar lidar sales and Motional pauses robotaxi plans

The newly announced “Public Content Policy” will now join Reddit’s existing privacy policy and content policy to guide how Reddit’s data is being accessed and used by commercial entities and…

Reddit locks down its public data in new content policy, says use now requires a contract

Eva Ho plans to step away from her position as general partner at Fika Ventures, the Los Angeles-based seed firm she co-founded in 2016. Fika told LPs of Ho’s intention…

Fika Ventures co-founder Eva Ho will step back from the firm after its current fund is deployed

In a post on Werner Vogels’ personal blog, he details Distill, an open-source app he built to transcribe and summarize conference calls.

Amazon’s CTO built a meeting-summarizing app for some reason

Paris-based Mistral AI, a startup working on open source large language models — the building block for generative AI services — has been raising money at a $6 billion valuation,…

Sources: Mistral AI raising at a $6B valuation, SoftBank ‘not in’ but DST is

You can expect plenty of AI, but probably not a lot of hardware.

Google I/O 2024: What to expect

Dating apps and other social friend-finders are being put on notice: Dating app giant Bumble is looking to make more acquisitions.

Bumble says it’s looking to M&A to drive growth

When Class founder Michael Chasen was in college, he and a buddy came up with the idea for Blackboard, an online classroom organizational tool. His original company was acquired for…

Blackboard founder transforms Zoom add-on designed for teachers into business tool

Groww, an Indian investment app, has become one of the first startups from the country to shift its domicile back home.

Groww joins the first wave of Indian startups moving domiciles back home from US

Technology giant Dell notified customers on Thursday that it experienced a data breach involving customers’ names and physical addresses. In an email seen by TechCrunch and shared by several people…

Dell discloses data breach of customers’ physical addresses

Featured Article

Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

The Israeli startup has raised $5.5M for its platform that uses “statistical AI” to generate synthetic data that it says is as good as the real thing.

15 hours ago
Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

Hydrow, the at-home rowing machine maker, announced Thursday that it has acquired a majority stake in Speede Fitness, the company behind the AI-enabled strength training machine. The rowing startup also…

Rowing startup Hydrow acquires a majority stake in Speede Fitness as their CEO steps down

Call centers are embracing automation. There’s debate as to whether that’s a good thing, but it’s happening — and quite possibly accelerating. According to research firm TechSci Research, the global…

Retell AI lets companies build ‘voice agents’ to answer phone calls

TikTok is starting to automatically label AI-generated content that was made on other platforms, the company announced on Thursday. With this change, if a creator posts content on TikTok that…

TikTok will automatically label AI-generated content created on platforms like DALL·E 3

India’s mobile payments regulator is likely to extend the deadline for imposing market share caps on the popular UPI (unified payments interface) payments rail by one to two years, sources…

India likely to delay UPI market caps in win for PhonePe-Google Pay duopoly

Line Man Wongnai, an on-demand food delivery service in Thailand, is considering an initial public offering on a Thai exchange or the U.S. in 2025.

Thai food delivery app Line Man Wongnai weighs IPO in Thailand, US in 2025

Ever wonder why conversational AI like ChatGPT says “Sorry, I can’t do that” or some other polite refusal? OpenAI is offering a limited look at the reasoning behind its own…

OpenAI offers a peek behind the curtain of its AI’s secret instructions

The federal government agency responsible for granting patents and trademarks is alerting thousands of filers whose private addresses were exposed following a second data spill in as many years. The…

US Patent and Trademark Office confirms another leak of filers’ address data

As part of an investigation into people involved in the pro-independence movement in Catalonia, the Spanish police obtained information from the encrypted services Wire and Proton, which helped the authorities…

Encrypted services Apple, Proton and Wire helped Spanish police identify activist

Match Group, the company that owns several dating apps, including Tinder and Hinge, released its first-quarter earnings report on Tuesday, which shows that Tinder’s paying user base has decreased for…

Match looks to Hinge as Tinder fails

Private social networking is making a comeback. Gratitude Plus, a startup that aims to shift social media in a more positive direction, is expanding its wellness-focused, personal reflections journal to…

Gratitude Plus makes social networking positive, private and personal

With venture totals slipping year-over-year in key markets like the United States, and concern that venture firms themselves are struggling to raise more capital, founders might be worried. After all,…

Can AI help founders fundraise more quickly and easily?