SlideShare uma empresa Scribd logo
1 de 14
Baixar para ler offline
« Security in e-banking is a shared responsiblity »




                           Belgian Federal Judicial Police
                            Federal Computer Crime Unit

© Luc Beirens
                                  © 2012 FCCU - Luc Beirens
Topics
   Scheme

   2007-2012 Evolution

 Victims
 Money mules
 Criminals


   Future

                    © 2012 FCCU - Luc Beirens
e-banking fraud is only part of the cybercrime




                      © 2012 FCCU - Luc Beirens
Cybercriminals working together




                         © 2012 FCCU - Luc Beirens
Activity spying                5
                                         6                               4     Keylogging                     Local
                                                                                                              storage

                                              Surfing to banking website & Authentication
                        Bank site                                                                eBank user
  10
         Bank account transfer                                 Preparation
                                   Confirmation :
                                                       Money transfer order
                                                                                8
                                   Screen injects
                                   Telephone calls
                                                                                     Proxy


                3
                                                                         Hackers
                                                                         Knowledge
                                                                         database       7
Money Mule


                                                                                                          Trojan
                                                     Proxy           2    Use of                     1    distribution
                                                                          intermediate                    campain
                                                                          systems
                                 Spam                                     to control network


                                        Fake Company
         11



© Luc Beirens                            12       Money collector         13
                     Money Mule
2007-2012 e-banking cases
   Experiences
     e-Banking cases 2007 : handled seperately
     Start of Federal Police - Febelfin cooperation
        Complaints => centralized information & analysis

   Engagement Police – Justice
       Federal Prosecutor’s office coordinating Local Prosecutors
       Investigating ICT traces : FCCU
       Investigating Financial traces : DJF and FJP Bxl
       Cooperation with Europol & Eastern European countries

   Success
     Most with financial traces => money launderers
      ○ Several money mules brought to court in BE & abroad
     Some coders / hackers still under investigation abroad
                          © 2012 FCCU - Luc Beirens
Success ?
   BE : less than 200.000 euro in 2011
     Compared to 36 million euro in Netherlands

   Well protected BE payment systems
   Fast collaboration => know how criminals work
   Fast adaptation of techniques
    for detection, avoidance, damage control

   Awareness to large public
     Press releases / information sessions
     Websites on e-security


                        © 2012 FCCU - Luc Beirens
Victims
   ALL of them were infected with Trojans

   Some of them had several hunderds Trojans

 Very often no AV products
 Operating system / applications not updated


   Unaware of risks / methods

                   © 2012 FCCU - Luc Beirens
Who are behind the fraud ?
   Horizontal organized crime : specialized teams
     Trojan developers
     Botnet managers
     Financial operators => information / operations
     Money launderers => operations department


   Underground economy
     Place where criminal specialists meet
     Using encryption / hiding techniques

                       © 2012 FCCU - Luc Beirens
Underground exhange services
Market of Trojans and botnets
 Zeus, SpyEye
 Self configurable Trojan kits with support
 Infection ways : mail, social media, P2P, web
 Integration of functionalities
       Read, write, install access to harddisk
       Internet connection interception and code injection
       Keylogging
       Screen captures
       Webcam & microphone activation
   Managed over botnets

                          © 2012 FCCU - Luc Beirens
Money mules
   Several levels of money mules
     1st level => in BE / 2nd level => after money transfert

   Organizers
     Recruitment and managing money mules
     Organizing – laundering operations

   New schemes to enable money laundering
     Large expensive orders to shops / hotels – cancelled
     New dating friends asking for money transfers

   Money mules used for different purposes
     E-banking / Internet fraud


                            © 2012 FCCU - Luc Beirens
Evolution
   Trojans and botnets : multipurpose tool
    for cyber crime

   Cooperation Febelfin-Police : detect new modus

   Focus on awareness
     Responsiblity of every party concerned

   Focus European and BE police strategy
     Taking away the weapens of the criminals
     Disrupting / dismantle botnets
     Together with all other partners


                         © 2012 FCCU - Luc Beirens
Contact information

 Belgian Federal Judicial Police
 Direction for economical and financial crime
 Federal Computer Crime Unit
 Notelaarstraat 211 - 1000 Brussels – Belgium

 Tel office             : +32 2 743 74 74
 Fax                    : +32 2 743 74 19

 Head of Unit           : luc.beirens@fccu.be
 Twitter                : @LucBeirens



                          © 2012 FCCU - Luc Beirens

Mais conteúdo relacionado

Semelhante a 20120613 e-banking fraud situation - BE law enforcement reaction

Don zaal a 11.15 11.45 fccu
Don zaal a 11.15 11.45 fccuDon zaal a 11.15 11.45 fccu
Don zaal a 11.15 11.45 fccu
webwinkelvakdag
 
Digitial Development and Mobile Money at USAID
Digitial Development and Mobile Money at USAIDDigitial Development and Mobile Money at USAID
Digitial Development and Mobile Money at USAID
Erin Mote
 
121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...
121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...
121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...
spirecorporate
 
Countering Cross-Channel Fraud Threats
Countering Cross-Channel Fraud ThreatsCountering Cross-Channel Fraud Threats
Countering Cross-Channel Fraud Threats
Vivastream
 
Leandri Jean Jacques
Leandri Jean JacquesLeandri Jean Jacques
Leandri Jean Jacques
Tecnimap
 

Semelhante a 20120613 e-banking fraud situation - BE law enforcement reaction (20)

Don zaal a 11.15 11.45 fccu
Don zaal a 11.15 11.45 fccuDon zaal a 11.15 11.45 fccu
Don zaal a 11.15 11.45 fccu
 
Jon ppoint
Jon ppointJon ppoint
Jon ppoint
 
Dubai 1
Dubai 1Dubai 1
Dubai 1
 
Rake Antifraud Detection
Rake Antifraud DetectionRake Antifraud Detection
Rake Antifraud Detection
 
Digitial Development and Mobile Money at USAID
Digitial Development and Mobile Money at USAIDDigitial Development and Mobile Money at USAID
Digitial Development and Mobile Money at USAID
 
121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...
121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...
121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...
 
Mobile Financial Services
Mobile Financial Services Mobile Financial Services
Mobile Financial Services
 
The enigma of mobile banking
The enigma of mobile bankingThe enigma of mobile banking
The enigma of mobile banking
 
Countering Cross-Channel Fraud Threats
Countering Cross-Channel Fraud ThreatsCountering Cross-Channel Fraud Threats
Countering Cross-Channel Fraud Threats
 
Mobile Security
Mobile Security Mobile Security
Mobile Security
 
Mobile Security
Mobile Security Mobile Security
Mobile Security
 
Hacking Finance: Crypto & Math based Currencies, Smart contracts and Blockch...
Hacking Finance: Crypto & Math based Currencies, Smart contracts  and Blockch...Hacking Finance: Crypto & Math based Currencies, Smart contracts  and Blockch...
Hacking Finance: Crypto & Math based Currencies, Smart contracts and Blockch...
 
Dubai 2
Dubai 2Dubai 2
Dubai 2
 
Josh Moulin: Internet Scams and Identity Theft Prevention
Josh Moulin: Internet Scams and Identity Theft PreventionJosh Moulin: Internet Scams and Identity Theft Prevention
Josh Moulin: Internet Scams and Identity Theft Prevention
 
Risk Factory: Database Security: Oxymoron?
Risk Factory: Database Security: Oxymoron? Risk Factory: Database Security: Oxymoron?
Risk Factory: Database Security: Oxymoron?
 
CyberCrime attacks on Small Businesses
CyberCrime attacks on Small BusinessesCyberCrime attacks on Small Businesses
CyberCrime attacks on Small Businesses
 
Leandri Jean Jacques
Leandri Jean JacquesLeandri Jean Jacques
Leandri Jean Jacques
 
CYBER CRIME
CYBER CRIMECYBER CRIME
CYBER CRIME
 
Introduction to Data
Introduction to DataIntroduction to Data
Introduction to Data
 
Where do we go from here?
Where do we go from here?Where do we go from here?
Where do we go from here?
 

Último

abortion pills in Jeddah Saudi Arabia (+919707899604)cytotec pills in Riyadh
abortion pills in Jeddah Saudi Arabia (+919707899604)cytotec pills in Riyadhabortion pills in Jeddah Saudi Arabia (+919707899604)cytotec pills in Riyadh
abortion pills in Jeddah Saudi Arabia (+919707899604)cytotec pills in Riyadh
samsungultra782445
 
+971565801893>>SAFE ORIGINAL ABORTION PILLS FOR SALE IN DUBAI,RAK CITY,ABUDHA...
+971565801893>>SAFE ORIGINAL ABORTION PILLS FOR SALE IN DUBAI,RAK CITY,ABUDHA...+971565801893>>SAFE ORIGINAL ABORTION PILLS FOR SALE IN DUBAI,RAK CITY,ABUDHA...
+971565801893>>SAFE ORIGINAL ABORTION PILLS FOR SALE IN DUBAI,RAK CITY,ABUDHA...
Health
 
FOREX FUNDAMENTALS: A BEGINNER'S GUIDE.pdf
FOREX FUNDAMENTALS: A BEGINNER'S GUIDE.pdfFOREX FUNDAMENTALS: A BEGINNER'S GUIDE.pdf
FOREX FUNDAMENTALS: A BEGINNER'S GUIDE.pdf
Cocity Enterprises
 
QATAR Pills for Abortion -+971*55*85*39*980-in Dubai. Abu Dhabi.
QATAR Pills for Abortion -+971*55*85*39*980-in Dubai. Abu Dhabi.QATAR Pills for Abortion -+971*55*85*39*980-in Dubai. Abu Dhabi.
QATAR Pills for Abortion -+971*55*85*39*980-in Dubai. Abu Dhabi.
hyt3577
 
Economics Presentation-2.pdf xxjshshsjsjsjwjw
Economics Presentation-2.pdf xxjshshsjsjsjwjwEconomics Presentation-2.pdf xxjshshsjsjsjwjw
Economics Presentation-2.pdf xxjshshsjsjsjwjw
mordockmatt25
 

Último (20)

Technology industry / Finnish economic outlook
Technology industry / Finnish economic outlookTechnology industry / Finnish economic outlook
Technology industry / Finnish economic outlook
 
Female Escorts Service in Hyderabad Starting with 5000/- for Savita Escorts S...
Female Escorts Service in Hyderabad Starting with 5000/- for Savita Escorts S...Female Escorts Service in Hyderabad Starting with 5000/- for Savita Escorts S...
Female Escorts Service in Hyderabad Starting with 5000/- for Savita Escorts S...
 
Pension dashboards forum 1 May 2024 (1).pdf
Pension dashboards forum 1 May 2024 (1).pdfPension dashboards forum 1 May 2024 (1).pdf
Pension dashboards forum 1 May 2024 (1).pdf
 
劳伦森大学毕业证
劳伦森大学毕业证劳伦森大学毕业证
劳伦森大学毕业证
 
Certified Kala Jadu, Black magic specialist in Rawalpindi and Bangali Amil ba...
Certified Kala Jadu, Black magic specialist in Rawalpindi and Bangali Amil ba...Certified Kala Jadu, Black magic specialist in Rawalpindi and Bangali Amil ba...
Certified Kala Jadu, Black magic specialist in Rawalpindi and Bangali Amil ba...
 
Black magic specialist in Canada (Kala ilam specialist in UK) Bangali Amil ba...
Black magic specialist in Canada (Kala ilam specialist in UK) Bangali Amil ba...Black magic specialist in Canada (Kala ilam specialist in UK) Bangali Amil ba...
Black magic specialist in Canada (Kala ilam specialist in UK) Bangali Amil ba...
 
abortion pills in Jeddah Saudi Arabia (+919707899604)cytotec pills in Riyadh
abortion pills in Jeddah Saudi Arabia (+919707899604)cytotec pills in Riyadhabortion pills in Jeddah Saudi Arabia (+919707899604)cytotec pills in Riyadh
abortion pills in Jeddah Saudi Arabia (+919707899604)cytotec pills in Riyadh
 
W.D. Gann Theory Complete Information.pdf
W.D. Gann Theory Complete Information.pdfW.D. Gann Theory Complete Information.pdf
W.D. Gann Theory Complete Information.pdf
 
Significant AI Trends for the Financial Industry in 2024 and How to Utilize Them
Significant AI Trends for the Financial Industry in 2024 and How to Utilize ThemSignificant AI Trends for the Financial Industry in 2024 and How to Utilize Them
Significant AI Trends for the Financial Industry in 2024 and How to Utilize Them
 
Responsible Finance Principles and Implication
Responsible Finance Principles and ImplicationResponsible Finance Principles and Implication
Responsible Finance Principles and Implication
 
cost-volume-profit analysis.ppt(managerial accounting).pptx
cost-volume-profit analysis.ppt(managerial accounting).pptxcost-volume-profit analysis.ppt(managerial accounting).pptx
cost-volume-profit analysis.ppt(managerial accounting).pptx
 
+971565801893>>SAFE ORIGINAL ABORTION PILLS FOR SALE IN DUBAI,RAK CITY,ABUDHA...
+971565801893>>SAFE ORIGINAL ABORTION PILLS FOR SALE IN DUBAI,RAK CITY,ABUDHA...+971565801893>>SAFE ORIGINAL ABORTION PILLS FOR SALE IN DUBAI,RAK CITY,ABUDHA...
+971565801893>>SAFE ORIGINAL ABORTION PILLS FOR SALE IN DUBAI,RAK CITY,ABUDHA...
 
FOREX FUNDAMENTALS: A BEGINNER'S GUIDE.pdf
FOREX FUNDAMENTALS: A BEGINNER'S GUIDE.pdfFOREX FUNDAMENTALS: A BEGINNER'S GUIDE.pdf
FOREX FUNDAMENTALS: A BEGINNER'S GUIDE.pdf
 
FE Credit and SMBC Acquisition Case Studies
FE Credit and SMBC Acquisition Case StudiesFE Credit and SMBC Acquisition Case Studies
FE Credit and SMBC Acquisition Case Studies
 
QATAR Pills for Abortion -+971*55*85*39*980-in Dubai. Abu Dhabi.
QATAR Pills for Abortion -+971*55*85*39*980-in Dubai. Abu Dhabi.QATAR Pills for Abortion -+971*55*85*39*980-in Dubai. Abu Dhabi.
QATAR Pills for Abortion -+971*55*85*39*980-in Dubai. Abu Dhabi.
 
In Sharjah ௵(+971)558539980 *_௵abortion pills now available.
In Sharjah ௵(+971)558539980 *_௵abortion pills now available.In Sharjah ௵(+971)558539980 *_௵abortion pills now available.
In Sharjah ௵(+971)558539980 *_௵abortion pills now available.
 
Economics Presentation-2.pdf xxjshshsjsjsjwjw
Economics Presentation-2.pdf xxjshshsjsjsjwjwEconomics Presentation-2.pdf xxjshshsjsjsjwjw
Economics Presentation-2.pdf xxjshshsjsjsjwjw
 
uk-no 1 kala ilam expert specialist in uk and qatar kala ilam expert speciali...
uk-no 1 kala ilam expert specialist in uk and qatar kala ilam expert speciali...uk-no 1 kala ilam expert specialist in uk and qatar kala ilam expert speciali...
uk-no 1 kala ilam expert specialist in uk and qatar kala ilam expert speciali...
 
Call Girls Howrah ( 8250092165 ) Cheap rates call girls | Get low budget
Call Girls Howrah ( 8250092165 ) Cheap rates call girls | Get low budgetCall Girls Howrah ( 8250092165 ) Cheap rates call girls | Get low budget
Call Girls Howrah ( 8250092165 ) Cheap rates call girls | Get low budget
 
falcon-invoice-discounting-unlocking-prime-investment-opportunities
falcon-invoice-discounting-unlocking-prime-investment-opportunitiesfalcon-invoice-discounting-unlocking-prime-investment-opportunities
falcon-invoice-discounting-unlocking-prime-investment-opportunities
 

20120613 e-banking fraud situation - BE law enforcement reaction

  • 1. « Security in e-banking is a shared responsiblity » Belgian Federal Judicial Police Federal Computer Crime Unit © Luc Beirens © 2012 FCCU - Luc Beirens
  • 2. Topics  Scheme  2007-2012 Evolution  Victims  Money mules  Criminals  Future © 2012 FCCU - Luc Beirens
  • 3. e-banking fraud is only part of the cybercrime © 2012 FCCU - Luc Beirens
  • 4. Cybercriminals working together © 2012 FCCU - Luc Beirens
  • 5. Activity spying 5 6 4 Keylogging Local storage Surfing to banking website & Authentication Bank site eBank user 10 Bank account transfer Preparation Confirmation : Money transfer order 8 Screen injects Telephone calls Proxy 3 Hackers Knowledge database 7 Money Mule Trojan Proxy 2 Use of 1 distribution intermediate campain systems Spam to control network Fake Company 11 © Luc Beirens 12 Money collector 13 Money Mule
  • 6. 2007-2012 e-banking cases  Experiences  e-Banking cases 2007 : handled seperately  Start of Federal Police - Febelfin cooperation Complaints => centralized information & analysis  Engagement Police – Justice  Federal Prosecutor’s office coordinating Local Prosecutors  Investigating ICT traces : FCCU  Investigating Financial traces : DJF and FJP Bxl  Cooperation with Europol & Eastern European countries  Success  Most with financial traces => money launderers ○ Several money mules brought to court in BE & abroad  Some coders / hackers still under investigation abroad © 2012 FCCU - Luc Beirens
  • 7. Success ?  BE : less than 200.000 euro in 2011  Compared to 36 million euro in Netherlands  Well protected BE payment systems  Fast collaboration => know how criminals work  Fast adaptation of techniques for detection, avoidance, damage control  Awareness to large public  Press releases / information sessions  Websites on e-security © 2012 FCCU - Luc Beirens
  • 8. Victims  ALL of them were infected with Trojans  Some of them had several hunderds Trojans  Very often no AV products  Operating system / applications not updated  Unaware of risks / methods © 2012 FCCU - Luc Beirens
  • 9. Who are behind the fraud ?  Horizontal organized crime : specialized teams  Trojan developers  Botnet managers  Financial operators => information / operations  Money launderers => operations department  Underground economy  Place where criminal specialists meet  Using encryption / hiding techniques © 2012 FCCU - Luc Beirens
  • 11. Market of Trojans and botnets  Zeus, SpyEye  Self configurable Trojan kits with support  Infection ways : mail, social media, P2P, web  Integration of functionalities  Read, write, install access to harddisk  Internet connection interception and code injection  Keylogging  Screen captures  Webcam & microphone activation  Managed over botnets © 2012 FCCU - Luc Beirens
  • 12. Money mules  Several levels of money mules  1st level => in BE / 2nd level => after money transfert  Organizers  Recruitment and managing money mules  Organizing – laundering operations  New schemes to enable money laundering  Large expensive orders to shops / hotels – cancelled  New dating friends asking for money transfers  Money mules used for different purposes  E-banking / Internet fraud © 2012 FCCU - Luc Beirens
  • 13. Evolution  Trojans and botnets : multipurpose tool for cyber crime  Cooperation Febelfin-Police : detect new modus  Focus on awareness  Responsiblity of every party concerned  Focus European and BE police strategy  Taking away the weapens of the criminals  Disrupting / dismantle botnets  Together with all other partners © 2012 FCCU - Luc Beirens
  • 14. Contact information Belgian Federal Judicial Police Direction for economical and financial crime Federal Computer Crime Unit Notelaarstraat 211 - 1000 Brussels – Belgium Tel office : +32 2 743 74 74 Fax : +32 2 743 74 19 Head of Unit : luc.beirens@fccu.be Twitter : @LucBeirens © 2012 FCCU - Luc Beirens