The Register® — Biting the hand that feeds IT

Feeds

Microsoft unveils one-stop service for reporting stolen accounts

Matching banks with pilfered creds

Agentless Backup is Not a Myth

Microsoft on Thursday unveiled a program to alert banks and online services when accounts they oversee are compromised.

The Internet Fraud Alert will serve as a centralized repository for stolen account credentials and personal information, Microsoft said in a press release announcing the system. It creates a single place for researchers to match researchers who discover large caches of pilfered passwords and payment card numbers with the organizations responsible for the compromised accounts. The service is supported by almost a dozen online businesses and fraud-prevention groups.

The vast amount of stolen credentials stashed on servers and sites such as Pastebin.com often makes it hard for people who discover the information to bring it to the attention of the service providers, retailers and other groups whose customers are affected by the breaches. What's more, many organizations don't provide a prominent email address or weblink where compromises can be reported. The Anti-Phishing Working Group alone received more than 410,000 unique phishing reports last year.

Microsoft is billing Internet Fraud Alert as a secure location where researchers can systematically report information about compromised accounts. The service then alerts the proper banks, service providers or authorities.

Microsoft developed the technology underpinning the service and donated it to the National Cyber-Forensics and Training Alliance, a group that trains law enforcement agents, academics and public- and private-sector groups to combat online crime. The new project is supported by eBay, PayPal, the American Bankers Association, Citizens Bank, and the Federal Trade Commission, among others.

It goes into effect immediately. More information, including how to participate, is available here. ®

Steps to Take Before Choosing a Business Continuity Partner

Latest Comments

@ Tech33

Well they probably thought lets start with the 99% of desktop users then work from there ;)

0
0

The world's largest repository of stolen bank details.

With MS's security on it?

What Could Possibly Go Wrong?

0
0

How long until...

Someone breaks into the system?

And the crooks starts using it to verify which CC numbers are 'still good'?

0
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?