U.S. Agent Lures Romanian Hackers in Subway Data Heist
bloomberg.com
bloomberg.com
The article doesn't explain the discrepancy between the tiny earnings of the hackers and the enormous loss of the banks. Which one of these is it?:
1) The hackers lied and have millions stashed away some place?
2) The middlemen who buy the card data from the hackers and get mules to make fraudulent charges and withdrawals are the ones raking it in?
3) The banks are puffing up their losses in order to get tax deductions or make insurance claims, or maybe just to get the Secret Service interested enough in the case to do an investigation?
The banks can exaggerate their loss in all kinds of ways: including in the loss payments that they were able to later reverse, or including losses that were eaten by the merchants and not the bank, or including the salary of every member of their security and fraud department, etc.
If a system is on the internet, securing it is a cost that has to be born by the retailer.
- stolen goods are hard to sell, and like others have mentioned credit cards are re-sold to others who make most of the profit
- even if there is a suspicion that a card has been stolen, it is often re-issued, causing a lot of operational cost even if it was not actually among those stolen
A lot of other options too like others have mentioned.
To me this is the most interesting part of the whole "hacking chain" and almost nobody can/wants to explain it... And it's also obvious that if law enforcement would concentrate on making this harder to do, the value of stolen cc numbers would very fast o low enough to make the hacker loose any incentive for doing this kind of thing.
It's high risk process involving going to the store so most of the profits go to the mules. Credit card numbers are cheap - just a few dollars per card. There is black market for that stuff - you can google and find a bunch of articles about it.
Maybe one em gambled it all away.
Seems a bit silly to say they're annoyed that they had to spend money to upgrade their broken security.
This is why network security is such a joke, most companies only do enough to mitigate the last disaster instead of designing a system that is actually secure.
Why is his age relevant? Would you be OK with 15 years if he were 30? 50?
> who made 40.000 USD
Why is how much he made relevant, rather than how much he cost his victims?
If I steal millions in precious gems from you, but only sell them for hundreds, would you argue that my crime is only a misdemeanor?
The value of money is relative. Stealing $100M from a hedge fund or a bank could have very little impact on society as a whole. Doing an armed robbery for $1K on the other hand is actually very dangerous because things can get easily out of hand and innocent people can easily get killed.
Now, whether the criminal stole the $100M by pointing a gun at someone's head or threatening to kill someone's family in exchange for some access codes, or he just "hacked" them, that tells you a lot about how dangerous the thief actually is to other people, what other crimes he would be capable of committing and whether he can actually be "rehabilitated" or not, and this is what the sentence should be based on.
(Yeah, I know this is not how the the US legal system works, and I get that there are current advantages to the way it works now, mainly being good-enough at deterring large scale white-collar crime, but still, I think it's just plain wrong...)
See http://lawcomic.net/guide/?p=60 for more on the roles of punishment in the criminal justice system.
Most of these "hackers" are just stupid kids that think along the lines of "hey, I just stole these bits of data from there and then sold them to this other guy for profit". Some even do it simply for the "high", as an antidote for depression or other mental issues, they could probably make even more money by simply finding a decent job that matched their skills set.
These kids are 99% harmless to society because they would never commit any violent crimes like an armed robbery or even a purely financial crime that would involve directly stealing from someone they can identify. Now, put them in jail for XX years, maybe even parole them and force them to work for a lowest payed wage for gov agency ABC (cough, helping it spy on its own citizens, without the risk of "crying wolf" like ES did, cough) to keep their "conditional freedom" (though this probably only happens for the most skilled of them), and at the end of it you will have transformed them into pissed off anti-social criminals that are ripe to engage in real violent criminal activities or ripe for recruitment by teorist cells...
From society's point of view, this is like smoking harder in order to cure your lung cancer...
> The important thing in these cases isn't so much: How did they get in?” O’Neill said. “It's: Where did the data go?
Mhmm. No need to worry about the actual longstanding blatant flaws that allow for any of this. Let's just hope to catch some low hanging fruit with poor opsec so we can pretend that we're controlling the problem.
These problems could go away overnight if banks required more authentication than just an account number to withdraw money.
Also, the most impressive part was that the two hackers were able to actually get to the US :-) (unless they got their visas with some help from the FBI/Secret Service - can they do that?)
> Also, the most impressive part was that the two hackers were able to actually get to the US :-)
No, it's not. Travel visas are easy to get in US-friendly countries (Romania is much more US-friendly or "eager to kiss US ass" than most other European countries). Also, if you read on... "He took the traditional route with Oprea. The U.S. government sought the Romanian’s extradition. It worked". They could've done the same for the rest, the Romanian gov would have just handed them on a silver plate. Also, if they had been trialed in their country they would have most likely gotten similar sentences - $40k is not enough to safely bribe your way through the justice system and the prosecutors would have been either fair or most likely quite harsh on them. Maybe they were unsure they got all the evidence to effectively prosecute them in the US or most likely they just needed the elaborate phishing operation to make themselves look cool and get more funding for their department in the future, hence the excessive media coverage too, wasting tax payers money while jerking off with this role-play...
It's incredibly easy to catch stupid hackers in pro-US states, what they did could probably have been done by a smarter-than-average sysadmin helping a regular us police detective at 1% of the cost of all this "elaborate operation"...
EDIT+: My point is that the ss guys just picked themselves a few very low hanging fruits, got themselves excessive media coverage for it and spent way too much time and money on this.
In this case the Secret Service agent wasn't even able to get a name on his guy until he called the Romanian white collar unit.
From what I can tell the people involved in this actually put some effort into hiding themselves. This seems more like a 3/10.
We can't continue going around calling ourselves "Criminals", and that when we do a brilliant piece of work on an intractable software problem that we really "Hacked" it together, meaning we broke the law to steal it and kept all the money for ourselves.
The word "Hacker" has got to go, it is the same as the word "Criminal", "Burglar" or "Felon" now.
Now? To the majority of the population, it has had that meaning since the 80s.
It's only in tech circles that people have insistent it has another meaning, but that is useless if the majority doesn't share that meaning.