Exposing the cyber crime underground

January 2014 Information Security

Advances in technology across industries are yielding significant opportunities for cyber criminals, both organised and otherwise, says KPMG.

Kajen Subramoney
Kajen Subramoney

Kajen Subramoney, associate director at KPMG in South Africa and specialist in forensic technology services, says, “Considering the evolution in technology and the digital age we now find ourselves in, the traditional ‘stick-‘em-up’ bank robbery, for example, has evolved into a far more sophisticated crime – often resulting in lower risk, greater anonymity and even greater financial rewards for such cyber criminals than before. Today, organised criminals tend to focus on the use of an array of services offered in what we call the cyber underground, a criminal cyber network and syndicate that needs to be recognised by both consumers and business alike to mitigate risk.”

For financial institutions, bank accounts and credit cards are the main targets of such crime. In fact, one such financial crime, committed in 2013, simultaneously targeted multiple locations throughout the world, pointing to how criminals relied upon a combination of unrivalled knowledge of ATM systems, processes and the technological prowess of a criminal network.

Continues Subramoney; “Here, hackers gained access to the bank’s databases to compromise hundreds of credit cards linked to seemingly legitimate bank accounts. Apparently with the help of insiders, the hackers were able to gain remote access to a terminal to increase the daily ATM withdrawal limits on each of the cards to more than $100 000. By exploiting this weakness in the bank’s IT security, the hackers essentially created the availability of fake money which could then be accessed through magnetic strip cards with appropriated codes, via ATMs around the world. You can imagine the amount of money withdrawn here and also while unchallenged.”

According to KPMG, this type of robbery is a foretaste of things to come. “We know that criminals are not only acting unilaterally, but today are buying and leasing the services of cyber criminals, and expanding their networks far and wide, using tactics and tools where the criminal literally becomes invisible.”

Mirroring this sentiment, Jason Gottschalk; associate director at KPMG says; “Africa has the strong potential to become a hotspot for cyber crime, especially now that the continent is well recognised on the global map and investment in Africa is becoming rife. This reality could pose a threat on critical infrastructures. In fact, KPMG feels strongly that the cyber security issue is the invisible war that should be a top of mind priority for local businesses now, in order for them to protect themselves.”

Globally, KPMG has seen that cyber criminal activity and security is on the rise, where the topic is now on almost all board agendas. Continues Gottschalk; “These discussions should be leading businesses, in particular, to an outlook of approaching cyber security proactively. Organisations need to undertake internal business IT security infrastructure audits, defining what their security strategies should be and then taking steps forward to implement this.”

According to KPMG, one of the biggest concerns within the local environment around IT security is the reactive versus the proactive approach that the brand sees among businesses. Says Subramoney; “This has to change. Cyber criminals are becoming smarter and with this are finding new ways of performing such criminals attacks daily – ways that we wouldn’t think could be possible, yet can cause severe damage.”





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Claude Mythos wake-up call
Technews Publishing AI & Data Analytics Information Security
AI has crossed a critical cybersecurity threshold and frontier models are accelerating attack lifecycles and will enable attackers to identify and exploit vulnerabilities at scale and speed, through novel methods that were previously the domain of advanced nation-state entities.

Read more...
If you cannot prove identity, you cannot claim security
Access Control & Identity Management Information Security
Cybersecurity planning for 2026 is a structural change in how attacks are executed and how trust is exploited, demanding that companies stop layering tools on top of infrastructure and instead prioritise intelligence and identity.

Read more...
95% do not have full trust in cybersecurity vendors
Information Security Security Services & Risk Management
Trust in cybersecurity vendors is fragile, difficult to measure, and increasingly shaping risk posture at both operational and board levels. Lack of verifiable transparency undermines cybersecurity decision-making, according to Sophos-backed research.

Read more...
Africa’s largest Zero Trust platform
NEC XON Information Security Commercial (Industry)
Africa has reached a significant cybersecurity milestone with the successful deployment of the continent’s largest Palo Alto Networks Prisma Access and Prisma Access Browser Zero Trust environment, supporting secure remote access for more than 40 000 users for a large enterprise in Africa.

Read more...
Supply chain attacks top threat over 12 months
Information Security
Supply chain attacks have become the most prevalent cyberthreat confronting businesses over the past year, according to a new Kaspersky global study, with nearly one-third of companies worldwide experiencing a supply chain threat in the past year.

Read more...
From vibe hacking to flat-pack malware
Information Security AI & Data Analytics
HP issued its latest Threat Insights Report, with strong indications that attackers are using AI to scale and accelerate campaigns, and that many are prioritising cost, effort, and efficiency over quality.

Read more...
NEC XON secures mobile provider’s hybrid identities
NEC XON Access Control & Identity Management Information Security Commercial (Industry)
For a leading South African telecommunications operator, identity protection has become a strategic priority as identity-centric attacks proliferate across the industry. The company faced mounting pressure to secure both human and non-human identities across complex hybrid environments.

Read more...
Microsoft 365 security is a ticking time bomb
Information Security
Across boardrooms and IT departments, a dangerous assumption persists that because data is stored in Microsoft 365 and Azure, it is automatically secure. This belief is fundamentally flawed and fosters a false sense of protection.

Read more...
Rise in malicious insider threat reports
News & Events Information Security
Mimecast Study finds 46% of SA organisations report a rise in malicious insider threat reports over the past year: reveals disconnect between security awareness and technical controls as AI-powered attacks accelerate.

Read more...
New campaign exploiting Google Tasks notifications
News & Events Information Security
New phishing scheme abuses legitimate Google Tasks notifications to trick corporate users into revealing corporate login credentials, which can then be used to gain unauthorised access to company systems, steal data, or launch further attacks.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.