International effort to disrupt cybercrime moves into operational phase
- Reference: 1710428413
- News link: https://www.theregister.co.uk/2024/03/14/wef_cybercrime_atlas/
- Source link:
At the time, the public-private collaboration was still in the proof-of-concept stage with one ambitious goal – to [1]map out relationships between criminal groups, their infrastructure, supply chains and other dependencies, and to use this knowledge to break up the entire ecosystem.
The initiative officially launched at the World Economic Forum in July 2023 with founding members Banco Santander, Fortinet, Microsoft, and Paypal.
[2]
"One of the main questions was, is it actually possible, with companies stepping in to invest resources in this type of research? And it became very clear that yes, companies can work together, they are very eager to create this type of knowledge base and to be part of such processes," Tal Goldstein, the WEF Centre for Cybersecurity's head of strategy, told The Register .
[3]
[4]
Its members now include 20-plus law enforcement agencies, private-sector security companies and incident responders, financial institutions, NGOs, and academics.
Over the past year, the investigations group, which now has more than 20 members, meets weekly "to go over intelligence packages, and we're working on profiling for threat actors," said Derek Manky, chief security strategist and global VP of threat intelligence at Fortinet's FortiGuard Labs.
[5]
Manky, who is also one of the group's founding members, said this work includes "the open source intelligence, the correlation, identifying choke points, high-confidence points, points of disruption."
"We've been doing a lot of work on the intelligence side," he told The Register . "And now we want to try to get into how can we actually start to make an impact."
This involves seizing gangs' infrastructure, making arrests, and attributing attacks to criminal gangs, Manky added. It also involves lowering the ROI on cybercrime.
[6]
"This is part of the idea of disruption: it's not only to make an impact, but to send a message back to the cybercriminals that we mean business, and that we can make it more cost prohibitive for them to operate," Manky said.
Making life more difficult for criminals
Sean Doyle, Cybercrime Atlas initiative lead, described it thus: "The first part of the experiment: can we create something new, valuable, and actionable?" The answer to this, he told The Register , is yes.
"The second part of the experiment is: can we use that collaboratively to make life more difficult for cyber criminals? That's what we are testing."
It's a big theory to test. Despite some recent high-profile takedowns of major cybercrime organizations, ransomware, cyber espionage, and all other types of electronic crimes are flourishing.
America's healthcare system is [7]still reeling from a nearly month-old ransomware attack against a single company, Change Healthcare.
The breach happened nearly two months after law enforcement [8]seized ALPHV/BlackCat's infrastructure, which apparently didn't stop the ransomware crew from infecting Change and possibly [9]extorting $22 million from the healthcare IT org.
[10]World Economic Forum wants a global map of online crime
[11]FBI: Critical infrastructure suffers spike in ransomware attacks
[12]UK council yanks IT systems and phone lines offline following cyber ambush
[13]Cybercrime crew Magnet Goblin bursts onto the scene exploiting Ivanti holes
Meanwhile, the [14]British Library is finally beginning its post-ransomware recovery, five months after a Rhysida affiliate shut down nearly all of the library's online services.
In addition to causing chaos and [15]costing victims billions of dollars, however, these gangs have brought cybercrime to the forefront of discussion among CEOs and boards of directors. Cyberthreats are officially on everyone's radars, which is one of the reasons the WEF took on this initiative.
"From the World Economic Forum perspective, this is a very unique project," Goldstein said. "It's really going into a very operational level, which is beyond what the Forum is usually doing."
It also underscored the growing emphasis that the WEF has placed on cybercrime – and cybersecurity – over the past few years.
According to the WEF's Global Risks Report 2024
[16]PDF
published in January, "misinformation and disinformation" is the top short-term global risk, with "cyber insecurity" coming in at number four.In addition to combating digital crime, the international org is also [17]taking on the cyber skills gap to help grow the infosec workforce.
At its annual meeting in Davos this year, the WEF hosted a panel on ransomware disruption. "Many members in the audience were not in a cybersecurity role, but they were very interested," Manky said. "And they very much appreciated the problem as well."
This isn't an isolated event and over time the WEF has received "more requests from our partners, CEOs, chairmen of big companies, saying [the Forum] needs to be involved" in helping organizations improve their cybersecurity posture and resilience," Goldstein added.
"This is not a challenge that any company or any government or international organization can manage by itself," he added. "This is a topic we need to work together to address." ®
Get our [18]Tech Resources
[1] https://www.theregister.com/2022/06/10/atlas_wef_rsa/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfMtKKkj@KBlRikOhxJsCwAAAQY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfMtKKkj@KBlRikOhxJsCwAAAQY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfMtKKkj@KBlRikOhxJsCwAAAQY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfMtKKkj@KBlRikOhxJsCwAAAQY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfMtKKkj@KBlRikOhxJsCwAAAQY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2024/03/12/white_house_pressures_unitedhealth/
[8] https://www.theregister.com/2023/12/19/blackcat_domain_seizure/
[9] https://www.theregister.com/2024/03/04/alphv_ransom_payment/
[10] https://www.theregister.com/2022/06/10/atlas_wef_rsa/
[11] https://www.theregister.com/2024/03/06/fbi_ransomware_cybercrime_costs/
[12] https://www.theregister.com/2024/03/12/leicester_city_council_stays_shtum/
[13] https://www.theregister.com/2024/03/08/magnet_goblin_ivanti/
[14] https://www.theregister.com/2024/03/11/british_library_slaps_the_cloud/
[15] https://www.theregister.com/2024/03/06/fbi_ransomware_cybercrime_costs/
[16] https://www.weforum.org/publications/global-risks-report-2024/digest/
[17] https://initiatives.weforum.org/bridging-the-cyber-skills-gap/about
[18] https://whitepapers.theregister.com/
Re: "brought cybercrime to the forefront of discussion among CEOs and boards of directors"
"there's little point in focusing on the perps"
I dunno. A dozen or so renditions by special forces snatch sqads then live video feeds of the perps being flayed, before being burned alive followed by a "You're Next" list of the names of a bunch of active crims would probably have some impact.
Re: "brought cybercrime to the forefront of discussion among CEOs and boards of directors"
" probably have some impact "
Ignoring for now the illegality of that proposal, it probably wouldn't work anyway as a deterrent for a couple of reasons. First, the adversary has for a long time been organised hierarchically, just like any other corporation, and it's in general only the grunts at the bottom (who do the actual cracking) that are exposed to consequences. Plus, even where a 'leader' is arrested, there's always someone else to take their place. Second, draconian and brutal punishments have historically never deterred crime (and there's plenty of precedent to prove that).
"brought cybercrime to the forefront of discussion among CEOs and boards of directors"
What hasn't joined 'discussion' yet at that 'forefront' is the Board's recognition that, without application of substantial resources most organisations remain wide open to even quite trivial attacks. The myth of the "sophisticated adversary" is for most victims, just that -- a myth.
Until infosec is properly funded and fully integrated into the corporate risk strategy, there's little point in focusing on the perps. Until then, what's needed is recognition of, and response to, the fact of being still a soft target.
Interestingly, the new version of the [1]NIST Cybersecurity Framework , released on Feb 26th, is the first version to incorporate a governance function. Since the framework was first released in 2014, it's only taken a decade for this to register as necessary. This does typify the fundamental problem, doesn't it.
[1] https://www.nist.gov/cyberframework