19 ms·
Hackers stole $650k and got away, showing limits to law enforcement’s reach
- whereis 5y agoThey celebrated on reddit.
- yellow_lead 5y agoLink?
- whereis 5y agoLost it, but I might be able to dig up a link a month later from a Buddhist guy who won $650,000 and immediately gave it all away.
- dumpsterdiver 5y agoReporting like this makes me want to stop reading Hacker News. Making unsupported claims and following up with self-indulgent drivel isn't clever, it's just a nuisance.
- whereis 5y agoThe news is 100% legit but it's pursuant to an ongoing investigation into corruption and infiltration by malicious/rogue actors in SV. The article was published for this dual use purpose and my comment supports that secondary use. If this makes no sense, then carry on, nothing to see here.
- whereis 5y agorussian device on front page of hn; metrologists respond with feces joke. rustaceans make fun of being a code spelunker, make a godfather joke. oh, and multi national food corp offers their fake processed food to aliens re: disclosures. all of these are tied together, as is the unfortunate news about defrauding homeless orgs in sf.
- boomboomsubban 5y agoI hate to look at things like this, but by getting a WSJ article and likely other press coverage our of this, there's a fairly good chance that the charity could view the loss as "fundraising" and see a positive return of investment.
- coderintherye 5y agoHad a similar experience with IC3 and FBI though for a much lesser amount. It's nice that both exist but neither seem helpful for amounts that are meaningful to a small business, tens of thousands, but not meaningful at their level. Do any entities exist to try to help find justice for these smaller electronic financial crimes?
- pmorici 5y agoInvestigate it yourself? Police don't have many powers available to them that aren't also available to the average citizen. Hire a private investigator if you don't want to put your own time in.
- coderintherye 5y agoInvestigation is not exactly the problem (as the article notes the non-profit investigated it themselves as well). Rather, the problem is enforcement. In our case, it was relatively easy to track the perpetrator. However, there is generally no provision allowing for vigilante justice in such situations. Going to another country to personally threaten one of their citizens over their financial crime will likely not have a productive result.
- pmorici 5y agoIf you lay all the relevant evidence at the cops feet they are going to be a lot more likely to carry though with the final step of arresting the person.
- watwut 5y agoAnd then you find out perpetrator comes from criminal subculture and has more violent friends then you.
- tehwebguy 5y ago> On Feb. 25, nearly a month later, the FBI assigned a special agent to the case. On March 3, the agent emailed Ms. Williams to say the U.S. attorney’s office in San Francisco had declined to open an investigation. He didn’t explain and the FBI hasn’t been in contact since, she said. More and more people finally realizing the police don’t help them, one crime at a time.
- donkeyd 5y agoSo I recently started working in LE as an IT specialist. The biggest issue is that there's more criminals than there are LEOs/detectives. So often you have to choose between working a physical crime or a digital one. If someone gets robbed of $50 at gun point, that usually gets more attention than $600k stolen by hackers. The reason is that a robbery is deemed to have more impact on the victim. So yes, not every crime gets investigated. No, it's not because they just don't feel like helping people. Also, some people think there are different people working on these types crimes. But because every criminal has a phone, a lot of work in physical crimes is digital. Therefore the amount of people working on on digital crimes is small and they often work on really large cases, like Darknet markets etc.
- filleduchaos 5y agoI have never heard of the US police doing much more than taking a report for someone who was robbed of $50 either. In fact people get mugged/robbed of items that are much higher in value (phones, bicycles, etc) without investigation. My impression has been that if you're out by less than a few thousand dollars in value you might as well not bother.
- donkeyd 5y agoThe $50 was an example, not a benchmark for when police does investigate. Like I said, there are more criminals than LEOs and this general hateful attitude towards LEOs doesn't really make people want to do that job. So if people want computer crimes to be solved, they should start motivating people to take those jobs in stead of hating on people who are working hard to solve crimes.
- avalys 5y agoThis happened to someone I know with a reasonably well-run but not super technical small business. Someone compromised the email account of their accounts receivable person, silently monitored it for a while, and then used it to send a few strategic requests to change the payment account. By the time my friend noticed and politely asked their customers (mid-size businesses all) “Why haven’t you paid this $50,000 bill?”, the hackers had made off with a few hundred thousand - a big deal to my friend, but not so much to law enforcement, who pretty much shrugged and said “Sucks to be you.” Luckily, several of those customers theoretically had policies against changing payment directives without phone confirmation, which were not followed, so they are taking some shared responsibility for this.
- SV_BubbleTime 5y agoI thought cyber insurance was a scam for awhile, but our beezly underwritten policy specifically covers us up to 100k of exactly this scenario. I can recommend their portal/system so far, maybe it’s shit, I don’t think so though.
- geoduck14 5y agoI'm surprised the types of things you can get insurance for. I know one company that got hacked and data (no money) was exposed. There was an insurance pay out (to the company) to pay for "fixing the digital infrastructure". This is like saying: If you leave the door to your house open, and someone robs you, we will pay to show you how to lock your front door.
- woleium 5y agoexcept now imagine the same thing, only you are a blind man with no arms or legs.
- forinti 5y agoThere's a story about when Robert MacNamara arrived at Ford. Accounting was in such disarray that they weighed their invoices and only checked them if X pounds was more than Y dollars. That must have been a scammer's paradise.
- coderintherye 5y agoI wonder if Frost Bank filed a Suspicious Activity Report for these transfers and whether or not they will face any enforcement actions. Having worked with quite a number of banks at this point, they all talk a big game about compliance but yet very few seem to actively mitigate these events. It's not Frost's only such issue: https://www.expressnews.com/business/local/article/Former-officer-manager-of-San-Antonio-dermatology-16171788.php https://www.expressnews.com/business/local/article/Former-of... But they are a fairly large bank so hard to say how they do relative to others for their volume.
- 1123581321 5y agoSARs are no additional help in this situation as they would only report the fraudulently given information, and there is no aspect to this crime that would particularly interest the Treasury department.
- coderintherye 5y agoIt's not so much about helping the situation as it is identifying whether or not the bank is actively monitoring and mitigating money laundering (which this situation would technically fall under as the mule is laundering the money through the bank). If they are failing to identify and report these then it could face regulatory action.
- 1123581321 5y agoI see. I’d be very surprised if those amounts didn’t generate the required SARs. KYC is also not foolproof.
- neonate 5y agohttps://archive.is/ApLtp https://archive.is/ApLtp
- ta1234567890 5y agoAnd here yet again an example of how the system is rigged against the poor and stacked in favor of the rich. If you have enough (and get stolen enough), then you get help, otherwise, too bad. I understand that there’s a resources allocation problem here and the current solution is prioritizing bigger crimes. But given the resources of the victims, maybe the priorities should be inverted. Help the people that can’t pay for their own investigations, or just charge for the investigation services in proportion to the “size of the crime”.
- toyg 5y agoNot just allocation, it's a quality problem too. The type of cops you need for street busts is not the type of cops you need when pursuing interstate (or even international) wire fraud. If your organization is historically unbalanced towards the former, changing towards the latter will take generations (and a lot of political capital).
- KingMachiavelli 5y agoIt should be a inverse U curve. If the amount is relatively inconsequential or occurs in super high frequency then it should be ignored. But if you lose more than 5 million then it's kind of on you I'd estimate orgs with roughly 100k to 5 million in revenue it is mostly small players and assuming margins of 20% they are really only doing 20k to 1 million in profit/discretionary spending. Add in a few factors like charity vs Inc, and it shouldn't be hard to narrow down who LE should assist. Meanwhile the US oil pipeline gets hacked by a exposed password and the whole Federal Government comes in to fix the mess and agrees to spend more money.
- jtbayly 5y agoPerhaps because that affects swaths of the population?
- KingMachiavelli 5y agoWell... the government couldn't even really fix anything besides catch the hackers. At the end of the day it was the limited scope of the attack and some preperation on the companies part that restored functionality as I understand it. Alternitively, these industries are already heavily regulated including extensive safetly regulations - so perhaps a basic level of security practices should also be required. We regulated how high of a ladder an employee can climb without safety equipment but we don't really do anything if a company reuses passwords, runs known vulnerable software, etc. Occasionally there are fines after the fact but that is too late.
- deleted 5y ago[deleted]
- bserge 5y agoThis is literally fraud and maybe identity theft, isn't it? And not even high tech, people used to do the exact same thing with paper cheques by mail. There's a sending bank account, a receiving bank account and a digital trail. With the newer KYC laws, it should be easier to find the criminals. Happens a lot in the UK and they don't do anything about it because the police has been defunded to hell.
- lbriner 5y agoI don't assume it is because the police had been defunded. I think the reality is that it is not worth anyone's time to follow up e.g. £100 theft when the bank will refund you. That could easily cost £5K+ to investigate and prosecute and if the thief doesn't really have anything, they can't get the money back anyway. I had a motorbike jacket stolen once which contained my house keys and wallet. The police found the guy and he was fined £40 or something. I lost the £100 bike jacket and had to pay around £40 to get my keys recut. Was it really worth it?
- pmorici 5y agoThis isn't so much a story about the limits of law enforcement as it is about the reality that they don't expend much time investigating "small" crimes and their definition of small is surprisingly large to the average person.
- londons_explore 5y agoI'm a bit surprised by this... There are only a finite number of people who commit crimes like this, and if you can find them at any point after they have committed one or more crimes, you ought to be able to arrest them. It therefore doesn't really matter the size of the crime - it still enables an arrest of someone who might be involved in large numbers of crimes both big and small, but that you couldn't arrest before for lack of evidence they are involved in crime. In many cases smaller crimes will be less well concealed too (hiding stuff costs money, paying more middlemen costs money, not worth it for smaller crimes)
- Clubber 5y agoYet they will arrest and prosecute to the full extent of the law someone who steals a $15 T-Shirt from JC Penny without blinking.
- alephnan 5y agoThat amount of theft is not illegal in California
- SV_BubbleTime 5y agoAre you mistaking the difference between legal and won’t be prosecuted? It’s the latter. And not for nothing, but I don’t think that policy is working out so well for some businesses specifically in the Bay Area. https://www.msn.com/en-us/news/crime/organized-crime-drives-sf-shoplifting-closing-17-walgreens-in-5-years/ar-BB1gI85R https://www.msn.com/en-us/news/crime/organized-crime-drives-...
- bilbo0s 5y agoTo be fair, that's because JC Penny does 95% of the work of apprehending and gathering evidence against the suspect. If they came to a small business that had a shirt shoplifted but did not apprehended the thief, and had no security cameras, they'd take the report and leave. Vast majority of police departments won't have time for that.
- KirillPanov 5y ago> Authorities are unlikely to pursue a case unless the loss is at least half a million dollars Note to future supervillian self: steal from widows and orphans in increments of $499,999.99.
- thaumasiotes 5y agoTwo things: - No one is fooled by a penny. Do it in increments of $400,000. - You need to prevent your thefts from being tied together; as soon as someone notices that you stole a small-time $400,000 from a widow AND another small-time $400,000 from an orphan, you've become a big-time $800,000 thief.
- Scoundreller 5y agoSeparate corps and nominee directors it is. Biggest problem will be choosing which corporation provider and country to go with. It’s like they’re competing for my incorporating dollar.
- deleted 5y ago[deleted]
- cutler 5y agoWhere are Anonymous now? [deafening silence]
- unnouinceput 5y agoto do ...what exactly?
- cutler 5y agoWhy, counter-hack of course.
- kwdc 5y agoI feel like a bounty system for online crime might help. Let the free market figure out whether this is worth investigating / solving. Registered bounty hunters / investigators could take up the case and operate on it. I sense that a lot of investigation around this case could be done from the comfort of a warm armchair. The rest involves boots on the ground. Its not $650k either, its more like 10 or 20 x 650k. Why? These are criminals operating a business. They will do this again.
- sometimesshit 5y agoWhen Social Engineers become hackers? To me, a hacker is someone who exploit a RCE or something like that. I recall in 90's we had this kids who got access to ton of companies all around the world. They would have conquered the earth along with the FBI.
- goodcanadian 5y agoA similar story from a few years ago: https://www.cbc.ca/news/canada/edmonton/macewan-university-phishing-scam-edmonton-1.4270689 https://www.cbc.ca/news/canada/edmonton/macewan-university-p... It looks like they were able to recover much of the money, but at a cost of $250,000 in legal and banking fees: https://www.cbc.ca/news/canada/edmonton/macewan-university-recovers-most-of-11-8m-online-phishing-scam-1.4604729 https://www.cbc.ca/news/canada/edmonton/macewan-university-r...
- LockDownExposed 5y agoGood for them.
- tyingq 5y agoInteresting that the FBI guy pretty much outlined how to do this and get away with it. Just steal less than $1M from each victim. I suppose the hardest part is recruiting the "money mules" to open the destination bank accounts.
- rapjr9 5y agoSeems like an area that needs innovation to improve efficiency. Perhaps all transactions could be made electronic and reversible within 30 days? Maybe instead of mailing a check or doing a wire transfer something with two factor authentication is needed based on a physical token? Doesn't seem difficult to give your trusted partners and associates a USB key to make sure funds can not go to anyone else. Why is banking mostly not using 2FA already? Any place that can mail me a debit card can mail me a USB key. The card could BE the USB key.
- throwaway248334 5y agoI'm a local law enforcement officer in California who investigates these. I love working on these cases, but there are tons of issues that stop them from being prosecuted successfully other than laziness. Ask me anything.
- kobalsky 5y agothe wire transfer was made to someone. why isn't that person / company on fire?
- throwaway248334 5y agoThere are a couple reasons. Sometimes they are. However, the recipients are often also romance/work from home scam victims. It can be hard/impossible to prove their intent. Best case scenario is, assuming they are in on it, that they are a money mule and will immediately split up the money, transfer it 5-10 times (sometimes to themselves, sometimes to other people), and after several jumps, it usually ends up as bitcoin, if you get that far. Every single transfer of money requires going to a judge and getting a search warrant for the next account or accounts. Each search warrant takes several weeks to a couple months for the bank to respond. So if the money jumps 5 times, we are taking pages and pages of search warrants before we find out where the money truly went. Probably over a year. Probably into crypto. Probably overseas. The prosecutors would love to prosecute the scammer, but are typically left with someone who just passed on the money and says they had no idea there was a scam happening.
- upofadown 5y agoThe root problem here is that someone moved money/resources on the basis of an anonymous (i.e. unsigned) email. If you can't be sure where the email came from you really need to do a manual verification.
- ThePowerOfDirge 5y agoTime to wake up, ban cryptocurrencies so this never happens again, then go back to sleep!
- betwixthewires 5y ago> The pair arrived in Odessa, near the border with New Mexico No, it isn't.