Original URL: http://www.theregister.co.uk/2007/06/12/carson_city_spyware/
Hackers attempted to swipe $450,000 after stealing login credentials associated with bank accounts run by the city of Carson, California. Police are working on the theory that the password for the general fund account was stolen after miscreants planted key-logging spyware onto a PC used by city treasurer Karen Avilla.
All but $45,000 of the stolen money was recovered after city officials spotted a pair of suspicious transfers and notified their bank, according to city treasurer Karen Avilla. Investigators are working to trace the destination of the remaining funds.
The use of malware is beginning to replace spam-vertised phishing sites as a means for crooks to obtain sensitive login information. Normally such attacks are targeted as consumers. Carson City's experiences show large enterprises are also vulnerable. It's unclear whether or not Carson City was targeted by fraudsters.
The two unauthorised transfers involve $90,000 sent to a "Diego Smith" in North Carolina and a blocked attempt to wire $358,000 to a bank in Kalamazoo, Michigan, the LA Times reports. The fraudulent transactions took place on 23 and 24 May, respectively.
"Although officials claim that any losses are covered by the city's insurers, I fully expect the city's insurance premium to rise at the next renewal date," said Geoff Sweeney, CTO at behavioural analysis software specialist Tier-3. Prevention is better than cure, he added. ®
DoJ alerts US citizens to spam attack (29 June 2007)
http://www.theregister.co.uk/2007/06/29/doj_issues_spam_warning/
Spammer faces 11 years in prison (12 June 2007)
http://www.theregister.co.uk/2007/06/12/spammer_pleads_guilty/
Phony BBB email dupes more than 1,400 execs (30 May 2007)
http://www.theregister.co.uk/2007/05/30/bbb_spear_phishing/
eBay users targeted by advanced Trojan (6 March 2007)
http://www.theregister.co.uk/2007/03/06/ebay_trojan/
Trojan phishing attack claims multiple victims (23 February 2007)
http://www.theregister.co.uk/2007/02/23/trojan_phishing_attack/
Phishers haul in money from Nordic bank (19 January 2007)
http://www.theregister.co.uk/2007/01/19/phishers_attack_nordea/
Trojans fuel ID theft boom (16 January 2007)
http://www.theregister.co.uk/2007/01/16/mcafee_id_theft_trends/
FBI-led probe nets phishing gang (3 November 2006)
http://www.theregister.co.uk/2006/11/03/operation_cardkeeper_phishing_arrests/
ID thieves target enterprises (11 October 2004)
http://www.theregister.co.uk/2004/10/11/corporate_id_theft/
ID theft: a $1bn a year crime (28 March 2003)
http://www.theregister.co.uk/2003/03/28/id_theft_a_1bn/
© Copyright 2008