Feeds

Cyber gang made £30 MILLION from fake gov certs

Hacked official sites to make phony qualifications

Website security in corporate America

Chinese police are celebrating the arrest of a nationwide cyber crime gang suspected of making over £30 million by selling fake professional qualifications, which they helped to produce by hacking into government web sites.

Police have arrested 165 people so far, scattered across 12 provinces. A whopping 185 government sites are thought to have been breached by the gang, according to China Daily.

The group made their money by selling fake qualifications certifying the recipient in fields such as medicine, financial services and architecture, with over 30,000 people suspected of having bought the dodgy certificates.

The gang’s USP, and the reason it could charge up to 10,000 yuan (£1,000) per certificate, was that it could hack the relevant government site and tamper with the back-end database to ensure that the fake cert’s name and registration number appeared legitimate.

Police in Jieyang, Guangdong province cracked the case when city officials raised the alarm after spotting that an illegal link had been added to one of the local government web sites.

The gang was found to be a highly organised and extensive network of individuals, each with different responsibilities – some would hack the government sites, some would manufacture the certificates and seals, others would advertise their services, and so on.

"The gang tampered with official databases or added links to external databases so that if anyone checked up on the fake certificates, the client's name would appear," said Chen Xiaoping, head of Jieyang police's cyber crime unit.

"They have a strong idea on how not to get caught. They used overseas servers and bank accounts of strangers, whose details were bought online."

Roy Ko, centre manager of the Hong Kong Computer Emergency Response Team (HKCERT), said the news was not surprising, given the huge demand for professional qualifications in China which already leads to widespread cheating at exams.

“Hacker groups will do anything to optimise their profit, by the easiest means. Obtaining personal credentials and re-selling them cannot generate quick money,” he told The Reg.

“There were already channels to get fake certificates. This is just going one step further, to ensure the fake certificates can actually be found on official web sites.” ®

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
'Kim Kardashian snaps naked selfies with a BLACKBERRY'. *Twitterati gasps*
More alleged private, nude celeb pics appear online
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
Freenode IRC users told to change passwords after securo-breach
Miscreants probably got in, you guys know the drill by now
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
BitTorrent's peer-to-peer chat app Bleep goes live as public alpha
A good day for privacy as invisble.im also reveals its approach to untraceable chats
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.