Saturday, March 2, 2013

E-Mail Fraud Hides Behind Friendly Face

But what if the e-mail appears to come from a colleague down the hall? And all he asks is that you add some personal information to a company database?

This is spear phishing, a rapidly proliferating form of fraud that comes with a familiar face: messages that appear to be from co-workers, friends or family members, customized to trick you into letting your guard down online. And it has turned into a major problem, according to technology companies and computer security experts.

On Wednesday, Google disclosed that it had discovered and disrupted an effort to use such pinpoint tactics to steal hundreds of Gmail passwords and monitor the accounts of prominent people, including senior government officials. Secretary of State Hillary Rodham Clinton said Thursday that the F.B.I. would investigate Google’s assertion that the campaign originated in China.

Such tactics were also used in an attack on a company called RSA Security, which security experts say may have given hackers the tools to carry out a serious intrusion last month at Lockheed Martin, the world’s largest military contractor.

The security specialists say these efforts are a far cry from more standard phishing attempts, which involve spraying the Internet with millions of e-mails that appear to be from, say, Citibank in the hope of snaring a few unfortunate Citibank customers. Spear phishing entails sending highly targeted pitches that can look authentic because they appear to come from a trusted source and contain plausible messages.

As such, the specialists say, the overtures are becoming very difficult for recipients to detect.

“It’s a really nasty tactic because it’s so personalized,” said Bruce Schneier, the chief security technology officer of the British company BT Group. “It’s an e-mail from your mother saying she needs your Social Security number for the will she’s doing.”

Mr. Schneier said the attacks are more like a traditional con game than a technically sophisticated intrusion. “This is hacking the person,” he said. “It’s not hacking the computer.”

Symantec, the computer security company, said it intercepted around 85 targeted attacks a day in March, including efforts to steal personal information through phishing or with links to nefarious software that could ultimately expose corporate files. The only month with more attacks was March 2009, when a surge coincided with a Group of 20 summit meeting.

Symantec said the most common targets were government agencies and senior managers and executives; the phishing of such big game is commonly referred to as “whaling.” Manufacturing firms were the targets of 15.9 percent of the attacks, compared with 8 percent for the financial sector and 6.1 percent for technology companies, Symantec said.

Hackers taking aim at corporations are often seeking new product designs and may focus on engineers at a defense contractor, for example, to get data they can sell on the black market.

Enrique Salem, Symantec’s chief executive, gave the example of an e-mail sent to the head of a company that appears to be from the Internal Revenue Service. The message raises questions about the tax implications of an acquisition, and the chief executive passes the message to others inside the company. Someone opens the attachment, giving the attacker access to the company’s internal network.

“It’s about getting you to do something to compromise the system,” Mr. Salem said.

In the case of the Gmail attacks, Google said they appeared to originate from Jinan, China, and were aimed at users like Chinese political activists, military personnel, journalists and South Korean officials.

The Chinese Foreign Ministry said Thursday that the government had no involvement in any such attacks, and that it “consistently opposes any criminal activities that damage the Internet and computer networks, including hacking, and cracks down on these activities according to law.”

It is not clear how the attackers obtained the Gmail addresses they used, although they could have been found inside other compromised accounts, including corporate or government accounts whose addresses are often easier to guess.

The attackers may have hoped to find some work-related e-mail in their victims’ personal Gmail accounts.

Mila Parkour, an independent security researcher who helped alert Google to the attacks, said she was tipped off to the campaign when one of the victims let her examine some suspicious messages.

John Markoff contributed reporting.


View the original article here

Sunday, February 24, 2013

Fight Over Debt Ceiling Risks Credit Rating, Moody’s Warns

The warning, from one of the agencies whose assessments of creditworthiness help determine interest rates, amounted to a stern reminder from Wall Street to Washington that global financial markets are watching the budget battle closely and that a standoff or brinksmanship could have economic consequences.

Both sides seized on Moody’s statement to reinforce their bargaining positions, with Republicans demanding that President Obama get more serious about deep spending cuts and Democrats saying that Republicans are risking a financial crisis in pursuit of an ideological agenda.

Moody’s said a review of the credit rating was “likely” in July, given that “the risk of continuing stalemate has grown.” Its warning followed a similar one from another major ratings firm six weeks ago, and it came as the administration met Thursday with both House Republicans and Democrats in search of a deal.

The treasury secretary, Timothy F. Geithner, met on Capitol Hill with House freshmen, including Republicans who have suggested that they see little or no risk in a showdown over the debt limit. Citing the Moody’s statement, Mr. Geithner urged them to support raising it or risk an economic crisis.

“We didn’t create this mess,” one Republican told Mr. Geithner, according to a person in the room.

Independent analyses have shown than more than half of the $14.3 trillion debt is from policies enacted during the past decade when Republicans controlled both the White House and Congress, and much of the rest from lost revenues and stimulus spending and tax cuts since Mr. Obama took office at the height of the financial crisis and recession.

Mr. Geithner, as he left the Capitol, told reporters: “I’m confident two things are going to happen this summer. One is we are going to avoid a default crisis. And we are going to reach agreement on a long-term fiscal plan.”

Representative Austin Scott, the Georgia Republican who is the leader of the freshman class, said after the meeting that House Republicans had a “fundamental” difference with Democrats on taxes: instead of new tax revenues, the Republicans want additional tax cuts to increase economic growth. Still, he said, “I think we are all hopeful we will get to a resolution.”

Earlier, Mr. Obama and Mr. Geithner met privately with House Democrats at the White House about debt-reduction matters, following a similar session on Wednesday with House Republicans.

“Just as he discussed with the Republican caucus, the president highlighted the need for both parties to work together to take a balanced approach to deficit reduction, one that allows us to live within our means without hurting our ability to invest in the future or burdening our middle class or seniors,” an administration official said. 

House Democrats said they would support Mr. Obama if he reached a compromise with Republicans that included long-term spending cuts, but not to Medicare benefits, as well as higher tax revenues, according to those briefed on the meeting.

The House speaker, John A. Boehner, said in a statement, “The White House needs to get serious right now about dealing with our deficit and debt.” He interpreted the Moody’s report as bolstering his contention that “a credible agreement means the spending cuts must exceed the debt-limit increase.”

Moody’s, however, made no mention of how a deficit-reduction agreement should be structured.

The Moody’s report was unexpected. In April, Standard & Poor’s lowered its outlook for the AAA rating on United States debt — but not the rating itself — to negative from stable. Moody’s cautionary note was more pointed in that it was pegged to the current political maneuvering over the debt limit and it urged a resolution weeks sooner than the White House and Congressional leaders were aiming for.

Its warning was two-pronged. First, Moody’s said, if Congress does not increase the Treasury’s borrowing authority in coming weeks, the nation’s credit rating may be lowered “due to the very small but rising risk of a short-lived default.” That is likely to translate into higher interest rates at a time when the recovery shows signs of slowing again.


View the original article here