News: 1632201365

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Mafia works remotely, too, it seems: 100+ people suspected of phishing, SIM swapping, email fraud cuffed

(2021/09/21)


Police arrested 106 people suspected of carrying out online fraud for an organized crime gang linked to the Italian Mafia, Europol said on Monday.

Most of those detained were cuffed in Spain, and the rest in Italy, by Spanish National Police, Italian National Police, Europol, and Eurojust, we're told.

It's claimed the suspects scammed hundreds of victims using phishing; SIM swapping attacks, in which crooks typically take control of people's cellphone numbers to get account login tokens texted to them; and so-called business email compromise, in which fraudsters typically use bogus invoices and the like to trick company staff into transferring money to the thieves.

[1]

According to the Euro plod, the alleged criminals were essentially based in Tenerife, one of Spain’s Canary Islands, and targeted mainly Italian nationals – plus Spanish, English, German, and Irish folks. Money extracted via phishing, social engineering, and hijacked online bank accounts was then laundered via money mules and shell companies. All in all, the enterprise made about €10m (£8.6m, $11.7m) profit, it is claimed.

[2]

[3]

“This large criminal network was very well organised in a pyramid structure, which included different specialised areas and roles,” said Europol in a [4]canned statement .

Within this crime syndicate, Europol said, some members were computer experts who created phishing websites and executed cyber-fraud; others were recruiters and money-mule organizers; and some were money-laundering experts who sometimes used cryptocurrencies. The cops said some of those cuffed have "links to mafia organisations." We wouldn't be surprised at all if the mob has or had ties to other phishing and cyber-fraud rings.

[5]International law enforcement op nukes Russian-language DoubleVPN service allegedly favoured by cybercriminals

[6]Australian cops, FBI created backdoored chat app, told crims it was secure – then snooped on 9,000 users' plots

[7]Euro police forces infiltrated encrypted phone biz – and now 'criminal' EncroChat users are being rounded up

An investigation into the Tenerife affair resulted in 16 house searches and 118 frozen bank accounts. In the process, officers seized many electronic devices, 224 credit cards, SIM cards, and point-of-sale terminals, plus a marijuana plantation and associated farming and distribution equipment.

It took the authorities over a year to infiltrate and break up the operation, which included some work-abroad opportunities for the three analysts and one forensic expert at the Hague-headquartered Europol dispatched to Tenerife and Italy.

[8]

Spanish National Police have more details [9]here . The Italians have a similar breakdown of the operation [10]here .

For instance, we're told by the Italian police that the stolen funds "were later recycled through the purchase of cryptocurrency or reinvested in further criminal activities, such as prostitution, drug production and trafficking, and arms trafficking."

Breaking up such cybercrime is not a new gig for Europol and its pals. In the past, the law enforcement agency [11]busted an operation that involved fraudsters hijacking companies' email systems to send messages that convinced those businesses' customers to wire payments to the crooks' bank accounts. The cops also [12]raided homes of suspected users of Droidjack, a strain of Android malware.

[13]

You have to hand it to the Mafia for keeping up with the times and trends as phishing, business email compromise, and SIM swapping are truly crimes of the era. Google [14]claims it stops more than 100 million harmful emails from going into Gmail accounts per day, and during the peak of the pandemic last year, there were 18 million daily malware and phishing emails related to COVID alone. ®

Get our [15]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YUmtZVNK-4f3p0xcMfqtYgAAAE8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUmtZVNK-4f3p0xcMfqtYgAAAE8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YUmtZVNK-4f3p0xcMfqtYgAAAE8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.europol.europa.eu/newsroom/news/106-arrested-in-sting-against-online-fraudsters

[5] https://www.theregister.com/2021/06/30/doublevpn_police_takedown/

[6] https://www.theregister.com/2021/06/08/operation_ironside_anom/

[7] https://www.theregister.com/2020/07/02/encrochat_op_venetic_encrypted_phone_arrests/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUmtZVNK-4f3p0xcMfqtYgAAAE8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.policia.es/_es/comunicacion_prensa_detalle.php?ID=9841#

[10] https://www.poliziadistato.it/articolo/13614847bf29a37759385024

[11] https://www.theregister.com/2015/06/12/operation_triangle_crushes_obtuse_global_phishing_ring/

[12] https://www.theregister.com/2015/10/30/droidjack_raids/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YUmtZVNK-4f3p0xcMfqtYgAAAE8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.theregister.com/2021/02/10/google_phishing/

[15] https://whitepapers.theregister.com/



SIM swapping attacks

Mike 137

The truth about SIM swapping had to surface eventually. We've been told in thepast that it only targets the "elite". We've been led to believe SMS token authentication is a robust system. However at least a decade ago it was being shown to be vulnerable, and a couple of years back EUROPOL publicly declared it should be avoided.

Yet now we're being forced by our banks to implement SMS token based "security" for online banking. That's insecure "security" on top of insecure transactions.

Re: SIM swapping attacks

Chris G

My Spanish bank has insisted that for all online purchases, an app must be installed and purchases authorised by an SMS token.

I was less than impressed by their IT skills after trying to install the app for over three weeks, it would show the entry page and freeze.

In the end my local branch got it to load by talking to their IT hell desk while it loaded.

The bank has also sent sensitive info in plain text via email on more than one occasion and does not respond to suggestions.

Re: SIM swapping attacks

Anonymous Coward

Most Spanish banks stop the entire of the internet logging into your account with your ID number (known by many businesses, can often be leaked) and a four-digit PIN. It's madness.

E.g. your teleco's customer service support drone knows enough about you (ID number, DOB, phone number, bank, possibly the PIN you use to log into your teleco's website is the same PIN to log into your bank's website) to SIM swap you and empty your bank account, should they feel so inclined.

confusing

Cederic

The bit that gets me is that the technical skills, logistics and management needed to create and run an operation like this could enjoy tremendous success in legitimate business.

I guess the marketing side of things works differently.

Worst Vegetable of the Year:
The brussels sprout. This is also the worst vegetable of next year.
-- Steve Rubenstein