Feeds

Feds charge three in brain-ache $15m Pentagon payroll pillage plot

Alleged Ukrainian cyber bandits still at large

Internet Security Threat Report 2014

Three men have been indicted in the US for trying to steal at least $15m by hacking into the Department of Defence's payroll service and customer accounts at 14 different financial institutions.

The US Attorney's office in New Jersey has charged two men from Kiev in Ukraine, Oleksiy Sharapka and Leonid Yanovitsky, and a third man from New York, Richard Gundersen, with conspiracy to commit wire fraud, conspiracy to commit access device fraud and identity theft and aggravated identity theft.

According to prosecutors, Sharapka led the conspiracy with the help of Yanovitsky, while Gundersen allegedly facilitated the movement of the proceeds from the hacks. The New Yorker is in custody, but both Ukrainians are currently fugitives.

The hackers were able to gain access to bank accounts of over a dozen financial institutions and businesses, including Citibank, JP Morgan Chase, PayPal, Nordstrom Bank and Veracity Payment Solutions. Once they were in, they diverted cash from the accounts to their own bank accounts or on to pre-paid debit cards.

After that, they allegedly hired crews of individuals to "cash out" the stolen money. These "cashers" withdrew the funds from ATMs and by shopping for fraudulent purchases in the US. To help do this, the men stole US identities, which could be used to file fraudulent tax returns and to transfer money to.

The men are facing a maximum potential sentence of 27 years for the charges against them as well as a maximum fine of $250,000 or twice the gross amount of the gains they made from their offences and another $500,000 for laundering the money through international wire transfers and other means. ®

Internet Security Threat Report 2014

More from The Register

next story
George Clooney, WikiLeaks' lawyer wife hand out burner phones to wedding guests
Day 4: 'News'-papers STILL rammed with Clooney nuptials
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.